Good day everyone. I am Clay Bilby, Palo Alto Networks Head of Investor Relations. Thank you for joining our 2021 Analyst and Investor Day. A few logistics for today. Today's event is being webcast live and recorded. The presentation material will be available on our website after the event at investors.paloaltonetworks.com. During today's presentation, we will make forward-looking statements that are subject to risks and uncertainties, which could cause actual results to differ materially. These statements are based on our current beliefs and information available to management as of today. We will also discuss non-GAAP financial measures. We have included tables in the appendix to the presentation, which provide reconciliations between non-GAAP and GAAP financial measures. As always, please refer to our most recent Form 10-K and the Safe Harbor in the presentation deck for more information. Today's event will run a bit over three hours.
This includes a five-minute break in the middle, plus time at the end for live Q&A.
[Presentation]
Good morning, everyone, welcome to Palo Alto Networks' Virtual Analyst Day. We've all been through a lot over the last year and a half through the pandemic, and things were tough, both personally and professionally for a lot of people. The resilience of all of our employees, the resilience of mankind, has managed to get us through all of this. We thought it would be an appropriate time now to share with you how we feel about the next three years going forward in terms of the prospects for our business. Before we do that, I think it's important to recap. If you look at where we were three years ago, we were known for the strength and scale of our next-generation firewall business. There was this interesting trend in security businesses.
Security companies would find a sweet spot, would find an attack vector with a huge TAM, then go ahead, keep innovating in their swim lane. Over time, they would try and make sure that every customer out there was leveraging their technology to secure themselves. As I observed the market when I came to Palo Alto Networks three years ago, I realized that our customers wanted more. Our customers were ready to take a security company, partner with them, as long as they were convinced that that partner was going to be with them along the entire journey. There were discussions about fragmentation, there were discussions about how integration is required by our customers instead of us doing it for them. As we've seen over the last many years, that the sophistication of cyber threats has gone up.
As we've seen, the world has become more and more reliant on technology. It's almost impossible for most of our customers to actually take on the mantle of integrating all these solutions by themselves and be able to stop these threats while they're happening or mid-flight. Towards that end, we set ourselves an ambitious target. We said we are going to be the innovator in cybersecurity, and we're going to make sure we're relevant in every important field of cybersecurity where our customers need us to be right next to them. With that in mind, we set about our tasks. Before we did that, we said, "Well, where is the puck going? Where do we believe the world is going?
Where do we need to be ready with solutions for our customers?" Well, having spent 10 years at Google, having watched the internet sort of scale and explode in my life, said this public cloud thing is real. Just for the same reason, sophistication in cloud deployment was increasing, sophistication in running data centers was getting higher and higher, and every business was going to become reliant on technology. Towards that end again, it's impossible for every business to go out there and build the capabilities in-house to leverage all those capabilities that the public cloud offers. From that end, we took a bet. We took a very active bet that we believe that this shift to the cloud is going to be mainstream. Not only is it going to be mainstream, customers are going to end up on multiple clouds.
We, as Palo Alto Networks, need to be ready not only to protect our customers in their transition to cloud, but also provide them simple, integrated tools which are best in class so that they can actually protect themselves as we go there. We did not want to make the same mistakes we've made in enterprise security, infrastructure security in the last 20 years. We also realized that this pace of technological adoption was not going to slow down. Digital transformation was here, pretty much any company that was getting created for the future was fundamentally based on customers, employees, partners, being able to access their entire infrastructure, their entire business remotely from anywhere, which is my app should work from any country. I should be able to access content. I should be able to interact with customer service.
I should be able to interact with my bank account from anywhere I want. That requires huge amount of technological sophistication, and we believe that sophistication was going to drive the need for security. Adding to that, given the whole world is watching storage and compute become cheaper, we also made a bet that artificial intelligence machine learning, whilst big words, they would get embedded in almost everything. They'll get embedded in how you see ads. They get embedded in how things are recommended to you. They get embedded in how we secure things. Towards that end, we, as Palo Alto Networks, had to become smarter and better with our data so that we could actually provide meaningful insight and meaningful actionable events to our customers, because otherwise the notion of manually trying to solve these problems was going to take too much time.
Last but not the least, all these trends were going to create a more intense security landscape, which has come out true in spades. We've watched all the hacks over the past few months, if not years, where the hacks are getting more sophisticated, more widespread, attacking supply chains and actually crippling businesses if we are not able to act. With that in mind, we have been working hard for the last few years trying to deliver on our bets. We think we've done a tremendous amount of work and made tremendous amounts of progress. We have actually fundamentally anticipated the need for network security transformation. We went ahead and built a whole SASE portfolio from pretty much scratch. We had 26 engineers three years ago.
Now we have 600+ people working on that topic because we believe as people move to the cloud, you are going to continue to see this transformation happen. For those of you who believe that transformation is only pandemic related, let me tell you, that train has just left the station. We're just getting started. This thing's going to be a mega trend for the next 5 - 10 years, where we will see networks re-engineer, transform, and continue to look at how to build a more global network where every employee, every branch, every office, every consumer becomes part of the extended network of the enterprise.
Towards that end, we have worked hard and vigorously towards making sure our solutions, which are built on best-in-class network security technology when the company was founded, has been extended not just to the public cloud use case or the hybrid use case, but also to the remote work use case and to basically a diversified infrastructure where you can deliver the capabilities across the board consistently without having to solve the problem with various point products. It is our commitment that we will continue to do that over the course of our existence. As new ideas come along, as new technological transformations happen, Palo Alto Networks will be there to be able to continue to transform the network security paradigm. We have actually built a comprehensive cloud security platform from scratch.
In the last few years, we got an early start by doing a series of acquisitions because we were behind the eight ball. We needed to catch up. We had to pay technological debt. We went ahead, instead of trying to build it ourselves, we canvassed our customers, we talked to them, asked them what is working. We went out, found those amazing entrepreneurs. We had them come join Palo Alto Networks. They worked really hard towards integrating their solutions. I think we are one of the companies in the industry who has done a great job of not only acquiring the best companies out there, but also being able to integrate them in a fashion where the people stay with us, they're motivated, they lead, they want to win, and we make sure that we truly integrate the products.
Our Prisma Cloud platform, which is the combination of acquisitions being integrated and a lot of homegrown organic product development, is now one of the largest, or the largest cloud security platform that has been created in the last few years. We declared we have $300 million in ARR in Prisma Cloud. That is something we're very proud of, but we still again believe this is the very early innings of cloud security as in the next 10 years, 50% of the compute out there gets to the public cloud. We believe we'll be right there protecting our customers as they make that transition to cloud. Last but not the least, we set about looking at security operations and trying to figure out how to actually take that field, take that area, and apply more artificial intelligence, more machine learning towards that, and more automation.
We believe the only way to solve the security ops problem is actually to deploy technology towards that problem. I know there's a lot of conversation around the world that we have scarce cybersecurity talent. There aren't enough people in the world because we need to train the people. I think, yes, that is important, but what I also believe is we have to deploy a lot more automation, a lot more integration, a lot more technology because the bad actors are. They're going to out-innovate us if we are not careful in making sure we're deploying and using the same techniques that are being deployed by people out there against our customers and against us.
Now, you don't become a leader in cybersecurity without being innovative because one great insight for cybersecurity companies, over 2,000 companies are funded every year and the reason is because the bad actors are always innovating. They're always looking for that one attack vector which you missed out on. They're always looking for a way to compromise your entire infrastructure or compromise even more exciting for them is to compromise a fundamental piece of supply chain because that allows them to then penetrate various companies and various customers of ours out there. Towards that end, we actually made a very clear commitment at Palo Alto Networks to make sure that we will be the innovation leader. As we shared with you in the past, we have delivered 65 products in the last few years, a lot more than the company delivered in its entire existence to then.
Across these three commitments of solving the problem of network security, solving the problem of cloud security, and solving the problem of SOC security. I'm excited to say that we are continuing down that path and we intend to be there scanning the market, watching carefully to make sure we are creating the solutions for our customers as new threats emerge. As a consequence of all this work, we are now clearly well established in three platform categories. Platform categories where actually to be honest, there are full companies trying to compete with us in the Strata Prisma SASE use case for network security. There are firewall companies out there are SASE companies out there, and we believe we are the largest network security business in the world as it relates to securing our customers.
Not only that, as I've shared, we are the largest cloud security business and platform in the world with 300+ million of ARR. Last but not the least, we're making lots of inroads and progress on SOC security, where we believe we have now from scratch come to a place where we're second in the industry in an aspiration to get close to the first players or the collection of first players in the space. We would continue to innovate and continue to make a lot of progress in our SOC security focus. Of course, there's a lot of conversation around Zero Trust, we will share more as part of today's proceedings about how we plan to establish that we are actually a fully integrated Zero Trust player and have been since the inception of Palo Alto Networks.
The last few years, building great products is one part of it, if those products don't get to customers and you don't have product market fit and doesn't get validated by the market, it's just purely innovation for the sake of innovation. Three years ago, we had 2,500 core salespeople. Now we have over 4,000 people selling for Palo Alto Networks. Not only that, we're taking on customers from 542 customers who are million-dollar accounts to 921 customers with million-dollar accounts. That's interesting, what's even more interesting is we've started focusing on the top of our customer pyramid, where we're slowly trying to make sure that our customers deploy all three Palo Alto Networks platforms. BJ will talk more about how that is making progress and how we intend to continue to make progress.
We're going from $1 million customers - $10 million customers because we think for us to continue to grow and be the leader in cybersecurity, we need to aspire to larger and larger deployments across our customers, which is in line with the trend of the industry where the customers want less fragmentation, less point products, and more consolidated platforms which offer you best-in-class capability. Not second, but the best in class. We had the privilege of sharing with you some targets for ourselves almost two and a half years ago. I'm delighted to report that we exceeded all the targets we set out except the part where we said we're going to manage to a certain margin. That was necessitated because we needed to continue to invest to drive faster growth.
We've beaten our targets for revenue and billings at the top line handily. Part of that required us to invest in those, and we will share more with you today in terms of how we're setting targets for the next few years and how we intend to leverage our capabilities of extracting more margin from the business to make sure that we're being financially prudent. That was great. That was a quick overview of what's gone on for the last few years and why we are where we are as a company and why we feel so confident in our prospects going forward. What's important is what's going to happen going forward. What are our bets for the future? How do we think about what's going to transpire in the next few years?
What I'm going to do is I'm going to lay out for you how we are thinking about the next few years, and then my colleagues will come and share with you how we intend to make progress against those targets. The next few years, we believe, as I said, the bad actors are getting more innovative. They're getting more consequent. As I've said, cybercrime has gone from being a hobby to a profession. As you can see, we're seeing a proliferation of ransomware attacks. We're seeing the professionalization of that industry. We think that trend is going to continue because it's a lot easier to create disruption sitting in a remote country or in a basement than having to actually go do that physically. We think that trend is here to stay. There's going to be more and more attempts at cyber hacking, at cyber compromise.
Towards that end, we have to make sure we stay vigilant. We have to make sure we continue at the pace of innovation that we have deployed in the company. As I said, two years ago, we started a lot of technical debt. We've been able to bridge the gap. We've been able to, through acquisitions and organic development, come to a point where we believe we are at the bleeding edge of innovation in many of our categories. We intend to do a lot more of that work organically at Palo Alto Networks because it's a lot easier for us to use our platforms and build on top than actually try and buy and integrate because now we're in all the spaces we want to be in.
We know that we think over time, slowly and steadily, we're observing as we deploy our network security platform, for example, with nine security services, customers are deprecating point products. I think that trend is here to stay. I think customers want the integration because as we've discovered with all these attacks, all these ransomware attacks, these cyber hacks, that having a lot of point products, which are best of breed, has not protected those customers. What they're realizing is that they need to get more integrated. They need to get ahead of the curve. We will demonstrate today how we have eaten our own dog food and been able to take that capability we deliver to our customers, deploy it internally, and get as close to real-time threat detection and prevention at Palo Alto Networks.
We also believe we're still in the early stages of deploying AI and machine learning into our platforms. I think we need to get more and more consequent as an industry of being able to leverage the data and being able to deploy it in our solutions across the board because that's the only way we get to autonomous security or real-time security. In line with that, from a point product solution perspective, it's going to be harder and harder for smaller vendors to be able to go and actually solve the large problems that our customers have because everything's getting integrated, everything's together. It works in synchronicity, and that's why it's very important for us to make sure that our integrated platform is available and we at Palo Alto Networks stay at the bleeding edge of trying to solve those problems.
Last but not the least, it's my personal opinion, talking about opinions, that cybersecurity companies have provided lots of capability, but not a lot of opinion to our customers because our customers' environments are so varied that our customers have been left to solve the problem by themselves. Towards that end, we're going to start seeing more opinions in our industry where our customers will be told, "Please do this like this and execute like this. That's the way you'll be protected." Our customers are getting more outcome-oriented because they do not want to be caught on the wrong side of the cybercriminals. From that perspective, we think security is going to start getting delivered with an opinion. With that as the sort of North Star for the next three to five years, our strategy is going to be executed in line with those convictions.
You are going to see us keep driving innovation. You are going to see us better our platforms. You are going to see us try and embed more and more artificial intelligence and machine learning in our products. You are going to see us become that partner at scale, the cybersecurity partner of choice as Palo Alto Networks. In that same vein, you are going to see us become more of a trusted partner. We have now been able to get into the incident response business. We have now been able to go from just being a peacetime product company to being a wartime conciliator. You will see that more and more is going to be demanded by our customers. We're ready to provide those capabilities to them. With that as the framework, we're going to walk you through today our capabilities.
We're going to have Lee Klarich and Nir Zuk talk to you about how this strategy is going to translate into continued product innovation at Palo Alto Networks. BJ Jenkins, who's joined us, our new president, in partnership with Amit Singh, who's our Chief Business Officer. BJ will talk about how we're going to take that and leverage that with our customers and secure them. The key ingredient of executing in this market, executing technology, is our people. The pandemic has made us even more concentrated on building a great culture, having a great set of people around us, and our people have shown in this process, as Lee is going to come talk about, how we manage that part of the equation, and how we make sure that people are the center of everything we do.
Last but not the least, I know you guys are here to understand how does that translate into numbers, and how is that going to eventually manifest itself in how the capital markets will deal with us for that. Dipak Golechha, our CFO, will come and bring it all together and tell you what targets we're setting ourselves for next year. With that, let me take the opportunity and welcome Lee Klarich. Lee?
Thank you, Nikesh.
Over to you.
As you just heard from Nikesh, the cybersecurity market is one that is very vibrant and often changing with new trends, new needs from our customers, and really new opportunities for us to innovate and bring market-leading solutions to the market. If I think back to some of the really big market trends that we identified early, and we embraced, and we understood the impact they would have, it was the shift to an increasingly hybrid workforce. It was the accelerated adoption of cloud amongst our customers. It was the importance that AI and ML would bring to everything that enterprises do in their business, not just cybersecurity. The pandemic accelerated all of these trends across the customer base and around the world.
This acceleration, it expanded the attack surface that enterprises had to secure, that they had to deal with in terms of how they would run their cybersecurity operation. This expansion, quite frankly, was the fastest I've seen in the history of cybersecurity. It accelerated so fast with the pandemic, and enterprises have had to adapt much more quickly than typical to these changing market needs. Just to compound that from a challenge perspective is the changing attack landscape. We never used to talk about nation-state-level attackers. When we did, we would've talked about them really only in the context of nation-state-to-nation-state type attacks. If you look at just over the last two years, there's been an increase in nearly 100% of nation-state-level attacks where they're actually attributed to nation states.
In many cases, the targets have become private industry in addition to governments around the world. On top of that, the number of cyberattacks is also increasingly rapidly. You can see through many of the examples shown here that not only is the number of attacks increasing, but the target of the attack is recognizing that expanded attack surface, recognizing that the cloud is now vulnerable, recognizing that a hybrid workforce brings expanded opportunity to find weaknesses and exploit those amongst the enterprise base. In some cases, even getting, when you combine these together, you start to see how that sophistication plays out relative to, in some cases, spending months or even years to first compromise a part of the supply chain, knowing that that will eventually work its way into the target environments for them to then take advantage from the inside out.
That expanded attack surface, combined with a growing number of cyberattacks and growing sophistication of cyberattacks, is what has been leading to an expanded addressable market for us. This TAM is a result of enterprises needing to secure more. More of their network, more of their cloud, and to drive better and better security operations across that entire enterprise estate. When you put all of that together, what you see is our market opportunity growing very quickly, and we project in 2024 to about $110 billion of market opportunity for us to address. Now, what's really important about that, of course, is how we are positioned to address that and how we have recognized these trends. Recognized these trends early, embraced them, and then innovated with our three security platforms across Network Security, Cloud Security, and Security Operations.
Typically, the market would have you believe that you have to choose whether you want best-in-class capabilities delivered as point products or a more comprehensive solution delivered as a platform or a combination of capabilities. You would have to give up best-in-class to do that. I believe those are not the only two options, and that what we have been able to accomplish over the last several years is to deliver three industry-leading platforms that combine best-in-class capabilities and deliver them in an integrated platform approach to our customers. By doing so, our customers get the best of both worlds. They get best-in-class security, which is absolutely and fundamentally important for their security posture, delivered as a platform that allows them to much more easily adopt and operate their entire cybersecurity estate. That plays out in the success we've had across these platforms.
It plays out in the market and the results that you've seen. It's also nice, of course, when we get the recognition from the market that we are in fact delivering best-in-class capabilities across these platforms. What you see here is over the last few years, going from being a market leader in one product category to being a market leader in seven product categories. Quite frankly, I believe this list would be much longer, except that some of our market-leading solutions are ahead of the market, and the market hasn't yet defined the categories yet for where we are leading in a number of areas. I expect that what you will see over the coming couple of years is this list expanding and becoming even more representative of the leadership that we're driving across our platforms.
With that, what I would like to now do is invite some of my team up to talk through each of our security platforms and share with you more details about the market trends that we're seeing and how that is evolving the market needs, and how we are delivering these three leading cybersecurity platforms. We're going to start with network security. For that, I would like to invite Anand Oswal up to walk you through what we're doing in network security, how we are leading across that. Anand leads network security as our product area. He also leads our network security speed boat and is very well-positioned to walk you through how we're approaching that.
As Lee indicated, I'm going to give an update on the network security business. First, let's talk about the evolution of network security. Long back, when applications were only in the data center and we, the users, predominantly worked in the offices, networking was the way security was delivered. The firewall was bolted on to networking as a centralized form factor. As applications began to rise, both benign applications as well risky applications, security vendors developed point products to solve specific use cases. IPS for threat vulnerabilities, secure web gateway to prevent web traffic, and malware was solved by sandboxing technologies. This led to complexity, many point products, and not a good experience. As applications continued to move to the cloud and users became more and more mobile, all this traffic was then backhauled to a centralized security stack in the data center.
This led to very poor end-user experience. Today, applications are everywhere, users are everywhere, and enterprises are recreating security stacks. In addition to the hardware security stack in the data center, we have a software stack for the public cloud. We have a SASE stack for remote users. This leads to a problem for manageability, multiple solutions for them, complexity, and poor end-user experience. At Palo Alto Networks, we believe this industry needs a network security platform, a platform that delivers best-in-class security across the entire enterprise. Any user, any application or any location, consistent best-in-class security. If you think about it, nobody in the industry today has a comprehensive and complete portfolio like this. Hardware firewalls to secure the consolidated data center, software firewalls for private and public clouds, and a SASE solution for remote workers. Point products and point solutions will not cut it.
Enterprises are looking for a comprehensive end-to-end security, which is best in class and able to take care of the needs for the future. They also want unified manageability across the entire portfolio from day zero to day N, ensuring that their policy management is consistent across the entire enterprise. When I'm in the office, I'm working remotely from home, and I'm going to different security stacks, I have that comprehensive, consistent security. Let's talk about the components of this platform, starting first with firewalls. We've been a leader in the firewalls for now more than a decade. We continue to innovate. A year ago, we launched the industry's first machine learning-powered Next-Generation Firewall. Last quarter, we introduced the 4th generation of our hardware appliances.
I've been here in the company now for 18 months. One of the first things we started was we realized that we want to have a larger footprint in the distributed enterprise. The new platforms we introduced, both the high-end and the low-end. On the low end, we have a 9x performance than the previous generation, perfectly fit for the distributed enterprise. As customers look to refresh their appliances, we are super well positioned for this. Third, we're also the leader in the software firewall market, protecting virtualized and containerized workloads. As 5G is reaching an inflection point and service providers are building cloud-native 5G infrastructures, we are well-positioned for that. We're excited to partner with DISH Network for the U.S. first Open RAN 5G infrastructure. Next, let's talk about SASE.
SASE is the convergence of networking and security delivered as a massively distributed service from the cloud. Prisma SASE is the industry's most complete, most comprehensive solution. We have the best-in-class SD-WAN and the best-in-class network security across the entire industry, bringing those two things together seamlessly, unified manageability, unified insights for our customers so they have the best experience. We continue to lead in industry-first innovations. Recently, we launched Autonomous Digital Experience Management, which helps IT have segment-by-segment visibility from user to application to help them troubleshoot any problems that they see and automatically remediate those. We are continuing to work on new innovations. Next-Generation CASB, integrated 5G SD-WAN with our appliances, and last Friday, we launched Okyo Garde.
As remote workers continue to be the norm, Okyo Garde brings Prisma SASE to the home, ensuring that we have enterprise-grade security with consumer simplicity to protect the home networks, to protect small businesses. This will be an amazing addition to our Prisma SASE portfolio. Let me now talk about our security services. Three years ago, we had only four security services, and today we have nine. We continue to see high attach rate of our services. Let me give you an example of how it works. We launched DNS Security roughly two years ago, and today we are seeing roughly a 30%+ attach rate on our hardware firewalls and a 90%+ attach rate on our SASE portfolio. These services are consistently delivered across all form factors: hardware, software, and SASE.
We continue to look at adding newer services on the portfolio as customers look to consolidate their point products and solutions. Machine learning plays a critical role for security services, especially to provide real-time security. Last year, we introduced inline embedded machine learning onto the platforms to prevent against file and fileless attacks. Q4 last fiscal year, we announced advanced URL filtering to prevent day zero web attacks for our customers. We'll continue to use the power of AI and ML across our entire portfolio. This amazing innovation that you've seen and the customer success is helping us in getting industry analysts validating it. We're the leader in every single product category, firewalls, Next -Generation SD-WAN, Prisma SASE, and we're extremely proud about these accomplishments. If you think about it, this platform approach addresses a large and growing network security market.
The SASE market is growing a lot as customers look to secure the remote workforce, look to bring networking and security together into a unified cloud-delivered service. As applications continue to move to the cloud, software firewalls will play a critical role. We're super excited about the newer services, IoT Security, Data Loss Prevention, and next-generation CASB on the entire platform. If you think about it, we have a lot of customers using our platform. 85,000+ customers use our firewall. Very happy customers. Our SASE business has been more than doubling every year for the last two years, growing at an amazing rate with newer customers. On security services, as we attach more and more services, look to consolidate point products that our customers have onto the platform, we continue to see amazing attach rates.
As we start building newer services, we expect this will continue. In summary, I'm super excited about our network security business. This is the largest business that we have in the industry, successfully executing on our transformation. Thank you.
Thank you very much, Anand. That was fantastic. Next up, you'll hear from Ankur Shah. Ankur leads our Prisma Cloud, cloud security platform product team, as well as our Prisma Cloud speed boat. He is very well positioned to be able to describe the market trends that we're seeing in cloud security and how we are well positioned with Prisma Cloud to address our customers' needs in a very unique way with that platform.
[Presentation]
Well, with that commercial, I hope you got a taste of what we are building at Prisma Cloud.
I'm here to talk about our vision and strategy for the product. Hello, everyone. This is Ankur Shah, SVP and GM for cloud security business, Prisma Cloud. What you heard from my colleague was our vision for enterprise-wide network security platform to secure access to the cloud application. I'm here to talk about securing the applications in the cloud. Organizations are now spending over $150 billion in moving their proprietary apps to the cloud. Over the next three years, we expect this to reach over $300 billion, growing at 25% CAGR. This represents a huge opportunity for us to secure the applications in the cloud. Over the last several years, as organizations started their digital journey to the cloud, they simply moved their workloads from the data center to the cloud to leverage the economies of scale that the cloud offers.
There was no rewrite of the applications, they simply lifted and shifted apps as is. This category of application still represents a lion's share of what we see in the cloud today. What we are starting to see, though, is a paradigm shift in how these applications are built and deployed. Increasingly, developers are taking advantage of containers, PaaS services, continuous integration and delivery, often referred to as CI/CD workflows, to build and deploy applications at greater velocity. Some of our largest customers in the SaaS business have bulk of their apps that are cloud-native. They're able to rapidly deploy applications to the cloud by leveraging cloud-native services. Last but not the least, there are still a number of applications that are still rewritten to take advantage of cloud-native application, but are still deployed in private cloud.
These applications are highly sensitive in nature. Customers want to still deploy that in hybrid cloud-type environments. The reality, though, is that the large percent of the organizations that we talk to don't use one or the other use cases. They have combination of all three. As a matter of fact, one of the largest retailers in the world, who happens to be a Prisma Cloud customer, has thousands of applications deployed using a combination of three deployments. We expect this trend to continue over the next several years as customers slowly but surely move their applications to take advantage of more cloud-native services. In these highly dynamic environments with multi-cloud, hybrid cloud, legacy and cloud-native apps, organizations need comprehensive security controls across their cloud infrastructure and applications.
They need visibility, compliance, and governance across cloud infrastructures to detect advanced threats like cryptominer, which seems to be in use every day nowadays. They need modern vulnerability management tools and runtime solutions that work for cloud-native workloads. Cloud networks are software-defined and are highly dynamic. Customers want a network security stack that prevents advanced network threats. A lot of the cloud data breaches that we have seen over the last year were because of account compromise and stolen credential, and this is why securing identities in the cloud is really critical. The thing that I want to end you with is that we also need a fundamentally different paradigm to secure the cloud. There are 26 million developers and growing, and there are only 3 million security professionals. Worse yet, there is a massive knowledge gap in the security industry about cloud knowledge.
In this new world order, we must have security go to where the developers are and not the other way around. That is the only way to secure your cloud infrastructure. The good old days of command and control, having centralized team managing a complex cloud security simply does not work in cloud. The security industry, however, is in the process of repeating the sins from the past. We're gonna see more and more point solutions and legacy product solving individual problems. There are open-source technologies out there that solve one of the use cases. There are legacy technologies that do vulnerability management that simply don't work in the cloud environment. There are legacy identity solution, and again, they simply don't work in the cloud environment. This is why we built Prisma Cloud, the industry leader in cloud network security.
We started our journey three years ago. Now have built out a platform that is fully integrated, has best-of-breed capabilities, and protects the full application stack. When we started this journey, we built out our first pillar, cloud security posture management, which now supports more cloud services and more cloud types than any other vendor in the industry. We ingest more cloud data than any other cloud-native tool out there in the market. We quickly added the cloud workload protection pillar, by providing the best-in-class host container and serverless capability, as well as a solution that protects web applications and APIs. We added a cloud network security component that builds a cloud-native and Kubernetes-native micro-segmentation capability. We rounded that platform out with cloud infrastructure and entitlement management, which is something we introduced just six months ago, and we're seeing a phenomenal growth.
Already, we have more customers than point solutions in the market. We're not done yet. We're hard at work to quickly integrate our recent acquisition, Bridgecrew, to build out a DevSecOps module that really makes the entire security work across the entire application life cycle. If history is an indicator, we're gonna do a phenomenal job once again to integrate one more capability into the product and build this best-in-class and most comprehensive platform in the market. I believe that this is the right approach to securing your cloud infrastructure. This is why we do what we do. This is why the industry, instead of needing individual point solution, needs a comprehensive platform like Prisma Cloud to secure their journey to the cloud across different use cases.
Our vision is to keep building on top of the strong foundation with new capabilities and deliver better security outcomes for our customers in their journey to the cloud. I'm confident that with our vision, we'll continue to leapfrog the market just as we have over the last three years. The addressable market for us is in excess of $10 billion and is expected to be over $20 billion in three years. As the early mover and the leader in the market, we expect to capture a lion's share of this TAM in the coming years. Recognized by industry analysts as one of the leading vendors, we're securing more cloud assets, workloads, and process more events than any other vendor in the market. We have seen close to 50% year-over-year growth in our install base. We are now at 2,700+ customers.
We are protecting over 25% of the Global 2000 customers. As I wrap this up, I couldn't be more excited about the future of Prisma Cloud as we help secure our customers' journey to the cloud. Thank you.
Thank you so much, Ankur. That was awesome. As we all know, cloud security is so important to every organization out there as they accelerate their adoption to cloud. I'd now like to turn our attention to our third cybersecurity platform, Cortex, which is focused on security operations. I'd like to start by providing a bit of context around what security operations even is. What you see here is the enterprise, to accomplish cybersecurity goals, they deploy more and more security products. All of these are obviously designed to try to prevent attacks. The side effect of that is they also generate lots of alerts, and those alerts go to what we call the SOC or the Security Operations Center. This is the team that is responsible for looking at all of those alerts, figuring out which ones matter, investigating and responding.
Ultimately, their goal is to be able to detect and respond to all threats as quickly as possible. It's a big job. It's effectively the backbone of cybersecurity in most enterprises. Their job is getting harder. As you just heard from my other teams, more and more products are being deployed to provide greater and greater levels of security, expanding their network security stacks, expanding into the cloud, expanding onto more and more hosts and endpoints. As they do that, which is all really good stuff, it generates more and more data for the SOC, the SOC is being overrun by that data. The average number of alerts that many SOCs deal with is 11,000 per day. Actually, in large organizations, that number can reach hundreds of thousands, even millions of alerts per day.
What they do with that then is they end up ignoring a lot of it. That's no good, obviously, because those alerts could be very meaningful. They could be the next cyber attack that gets through their defenses. On top of that, even the alerts they do get to often are taking four or more days to actually investigate and figure out whether they're real and how to respond. Obviously, everyone understands that this is not an acceptable solution. This is not acceptable place to be. Guess what? The cybersecurity industry responded with lots of point products. It unfortunately tends to be the answer to a lot of cybersecurity problems, and this was no different. This is how EDR was born. This is how NTA was born, or network traffic analysis, and other type of solutions like that.
The challenge with this is it took specific data, married it up with a point product in order to try to provide analytics on a single data source. Guess what? It's not working. Putting your data into silos, all it does is generate more alerts. Those more alerts make it even harder for the SOC to get their job done. One of the main reasons for that is when you put data into silos, you end up losing your source of truth, your source of really understanding what is happening, such that you can correlate all of your other data sources to drive real analytics. The net result of this is a very alarming statistic that has been well cited publicly in the past, which is it takes roughly 287 days on average for an enterprise to know about and respond to a data breach.
287 days. That is truly alarming. This is not an area where we need an evolutionary approach. This is an area where we need a revolutionary approach. One where 100% of alerts and data are analyzed, one where 100% of attacks are able to be detected using analytics, AI, ML, et cetera, one where an enterprise is able to respond to all attacks in minutes, not days, not weeks, not months. That is what we've been building with Cortex Xpanse, XDR, and XSOAR. Let me share a bit of how we think about this going forward, and it starts with XDR. We view XDR as the foundation of a next-generation security operations center. What XDR has been able to do, to be clear, XDR is a market and a product category that we invented a couple of years ago because we recognized this problem.
We recognized this problem and the need to solve it. We started by solving the endpoint part of this problem, which is how do you not only protect the endpoint, but use that to generate a rich set of data, a source of truth that all other data sources can be analyzed with to really understand across an entire enterprise what is happening, when is there attack, how do you respond to it? We've built XDR into actually the best EDR solution in the market, as evidenced from a number of different places, including, most recently, the MITRE results. Second, we took that data and we cross-correlated it with network data, starting with our own Next-Generation Firewalls. Even that one step resulted in amazing results, where we were able to reduce the number of alerts that the typical enterprise has to deal with by 50x-100x.
That is a game changer for most SOCs. We took that, we extended it to third-party network security devices, because, unfortunately, not every company in the world has our next-gen firewalls, although, of course, we'd like them to. We extended to third parties. We started looking at additional data sources. We extended to identity. Identity of users and authentication and everything that happens with that is so important from a cybersecurity perspective. We took our ability to collect, stitch, and analyze data to the cloud. The cloud is basically like a complete enterprise ecosystem delivered, meaning it has hosts, it has network data, it has identity, and it has additional data sources as well. With XDR 3.0, we applied all of our innovation to the cloud in coming out with XDR for cloud, an industry first.
All of that data is brought together, stitched, and normalized in order to drive a growing set of analytics to truly give security operations the ability to detect, investigate, and respond to attacks in the way that they need. I'd like to also share with you how we're taking XDR and combining it with the other Cortex products. For that, I would like to ask Tim Junio, our Head of Cortex Products and the Cortex speedboat and the former CEO and Founder of Expanse, to talk you through how Xpanse is changing the game as well.
Thank you, Lee. Cortex Xpanse is our attack surface management product. What does attack surface management mean? That's a pretty new term. What we do with Xpanse is discover every public Internet-facing asset for enterprise networks. This is critically important because adversaries who are looking to attack companies and government agencies start by looking for weaknesses on the public Internet. First starting point for any attacker. What we do with Xpanse is ensure that we know about everything that is exposed on the public Internet and its security status, meaning its configuration, what software is running on it, and for our customers can inform them of any weaknesses that an attacker might want to exploit, thereby removing all targets from the Internet when a customer is fully deployed.
When we see major Internet events, such as in the last year, the Microsoft Exchange Server incident, exposures associated with VMware software products, and with the SolarWinds attack last year, Xpanse is able to discover all of them on the global Internet and identify what organization is operating them. As a customer of Cortex and as a SOC user, we'd be able to inform of immediately any exposures when a critical exploit is released. It's part of the pattern of what we do at Cortex Xpanse to, for every major software incident, find all of them in the world and automatically notify our customers such that they can go and remediate those exposures and eliminate the risk.
Before Xpanse put this product to market, what we were seeing is averages that were coming up on a year of large organizations having assets hanging out on the public Internet in an insecure state that they didn't know about. For our customers, we can reduce the amount of time that assets are exposed to days or even hours when customers are well-optimized. One of the ways in which Xpanse gets best operationalized in a modern SOC environment is with Cortex XSOAR. XSOAR is our product that creates playbooks, which is our term for software automations. Our goal is to replace as much of what SOC analysts do repeatedly and manually as possible within Cortex XSOAR.
An example of one of the integrations that we built that saves our customers a lot of time between Xpanse and XSOAR is the ability to, when an exposure shows up in a cloud environment, automatically trigger the vulnerability scanning that's required to know the software patch state, and potentially to even look up the identity of the person who configured that cloud asset and send them a notification via email or other systems to acknowledge whether or not they had a business case for that asset that was exposed. In the event that we see exposure showing up in cloud environments that should not ever have been there, we can now have the entire process within seconds from an Xpanse discovery through XSOAR closing out the incident. When we put all three of these products together, we have a transformative modern SOC environment.
Lee, back over to you.
Thanks, Tim. We have a number of customers that start with XDR, even with an XDR, sometimes they just start with EDR to EDR, with the strategic intent and ability to expand the number of data sources. Sometimes they start from the network traffic, expand from there as well. Xpanse, from my perspective, is a must-have tool for every SOC out there. XSOAR from an automation perspective is, you have to move toward a more and more automated fashion. Really, it's when we bring these together that we showcase the magic of this more revolutionary approach to security operations. Let me walk you through how we at Palo Alto Networks have accomplished that.
First and foremost, across our security infrastructure, it probably goes without saying, but we have fully operationalized our network security platform, XDR for endpoint protection, and of course, all of our cloud security capabilities. Actually, that's very important because by simplifying and moving toward a platform approach, first and foremost, that provides a better security foundation. Second, it provides actually better, cleaner data coming into the SOC. Now, let's talk about security operations at Palo Alto Networks. Using Xpanse, which we do every day, and automating proactively any exposed attack surface we find is the first step in reducing what we're dealing with in security operations. With XDR, we collect a very large amount of data every day to be analyzed, understood, for detecting attacks, and investigating.
Just to give you one data point here, we at Palo Alto Networks were actually able to detect and prevent the SolarWinds attack in our own environment. Something we believe that we are the only, if not the only, one of the only companies in the world who have been able to do. That speaks to the strength of XDR and how we utilize it. We use XSOAR extensively to automate the vast majority of what our security operations team needs to deal with, leaving our SOC analysts able to focus on the most important things. Now, here's where it gets really interesting. Let me give you some data of what we've been able to accomplish based on how we've operationalized this. In our environment, we collect over 16 billion events a day. We translate that into alerts. Alerts then, using XDR, are integrated together, de-duplicated into incidents.
From incidents, we use XSOAR to automate. On a typical day, our SOC analysts typically only have to deal with about nine alerts or incidents that they need to investigate and respond to manually. 16 billion down to nine. What that allows us to do is to be able to detect and respond within seconds, on average, a minute in some cases, to new attacks that we see at Palo Alto Networks. This is revolutionary, and this is what we are bringing to all of our customers as we think about the vision of Cortex. In doing so, that allows us to address a very large and growing market for security operations. This is a market made up of a number of products across different categories, from EDR and XDR to automation, attack surface management, vulnerability management, SIEM, et cetera.
That is the market we are disrupting with our approach to security operations. The early indication of success with our customers across this is a very rapidly growing set of customers that are adopting these products and starting to integrate them together in order to achieve the kind of results that we at Palo Alto Networks have been able to achieve in our own security environment. With now 74 of the Fortune 100 customers as customers of Cortex, we see just tremendous potential for Cortex going forward. We'd like to talk about zero trust. Maybe first, if I could, I'd like to provide a little bit of my perspective on zero trust. From the very beginning of Palo Alto Networks, we always viewed every product that we built to be zero trust enabled.
Whether that was our Next-Gen Firewall or SASE or with Prisma Cloud and Cortex, each and every one of our products is Zero Trust enabled. In fact, that means many of our customers are very well-positioned to embrace Zero Trust because of that foundational approach that we've taken. You look at our Next-Gen Firewalls and how they effectively eliminate implied trust in policy in order to truly identify who the user is, what the application is, whether they should have access to it, and then to secure every connection. That's one example. With SASE, we extend that out to all remote users and branches. With Prisma Cloud and our approach to IAM security and micro-segmentation and other aspects, it allows us to extend Zero Trust into the cloud. Of course, within Cortex and XDR, extending Zero Trust out to the endpoint.
We believe Zero Trust actually needs to be done at an enterprise architecture level, that CIOs and CSOs are thinking about and need to think about how to approach this as an entire architectural approach, not just individual products. What Nir Zuk, our Founder and CTO, will talk through now is how to bring these pieces together and how we need to be thinking about this in a much more comprehensive manner.
Hi, everyone, thank you for being here. We heard Nikesh talk about our strategy. We heard Lee and his reports talk about our products and platforms and offering. There is a question: What is it that Palo Alto Networks delivers to its customers? Is it 30, 40 different solutions, features? Is it four platforms, network security platform, Prisma Cloud, the cloud security platform, Cortex, the security operations center platform, and the newly released Okyo, the home security, small business security platform? Is it really one big thing that Palo Alto Networks is delivering? What I want to do in my session today is to show you that big thing that we're delivering, and I'm going to do it within the context of Zero Trust and specifically the Zero Trust enterprise. You probably hear about Zero Trust from all vendors and customers, and everybody's talking about Zero Trust.
Just Google Zero Trust and see how many different results you see. Different vendors talk about it differently. You have the network security vendors talk about it in one way, and you have the proxy and the cloud vendors talk about it in another way, and the endpoint security vendors talk about it in a third way, and the Identity and Access Management vendors talk about it, and cloud security vendors. Everybody's talking about Zero Trust in a different way. What I want to do is I want to show you what is the Zero Trust enterprise and how you take all these different Zero Trust components and put them into one thing. The first thing we know about Zero Trust is that it's very, very important.
Even the President of the United States has mandated zero trust architecture within the government, it has to be very, very important. We don't know what it is, it has to be very, very important. To understand what Zero Trust is, let's talk about trust first. If you really think about what the cybersecurity industry has been delivering for the last, I don't know, I started 27 years ago in the industry, the last 30 years, it's all about trust. Can I trust this connection? Well, here is a firewall to help you to decide whether to trust the connection or not based on IP addresses. Can I trust the file that just showed up on an endpoint? Here is antivirus for you. Can I trust the user? Well, here's two-factor authentication, mid-1990s. Can I trust the content of the connection? Well, IDS, IPS.
Can I trust the URL? Here is URL filtering. Can I trust this? Can I trust that? Each one of these concepts is really about can I trust something or can I not trust something, and that was the industry has been delivering for the last 30 years in a whack-a-mole approach, right? Every time there was a new thing that we had doubts as to whether we can trust that thing or not, a new set of vendors was created to address that specific concern and to help customers decide whether to trust something or not trust something, no matter what that was. That's how the industry has been built for the last 30 years. Take, as an example, a user sitting in an office trying to access an application in a local data center. Most customers will have a project for that.
They'll call it a data center firewall project. They'll buy a data center firewall. They do some tests here, some checks there for the user traffic, and be happy with that. If you take the same user using the same laptop, sitting in a coffee shop trying to access a cloud application, a public cloud application, there'll be completely different projects for that. They'll call it a Zero Trust network access, ZTNA, and it will look at proxy in the cloud and other solutions. The same user trying to access a SaaS application, that will be a third project. It will be a CASB project. In each of these cases, we're going to check different things. We'll have a different policy.
We're going to look for different things, which means that we're going to trust or not trust different things, which brings us to the concept of implied trust. If I have two solutions for two different use cases for the same user and the same application, just different solutions, whether the user is here or there, or whether the application is here and there, by definition, I check for different things. In this case, I'll have some things that I trust and some things that I implicitly trust. In the other case, there will be other things that I trust and other things that I implicitly trust. There will be implicit trust in my decisions, which is the complete opposite of Zero Trust. Zero Trust is about removing all implicit trust. It doesn't matter who the user is, where they are, what type of device they're using.
Are they using Windows or Mac? Are they using Android or iOS? Is it a corporate-issued device? Is it their own, bring your own device? It doesn't matter which technology they use to connect, SD-WAN or IPsec or client VPN, clientless VPN, proxy. It doesn't matter what they use. It doesn't matter what the application is. It's a SaaS application deployed in a public cloud, an application deployed in a traditional data center, in private cloud. It doesn't matter what it is. I'm not going to trust anything. I'm going to do everything I can, no matter what the situation is, to decide whether I can trust or not trust each aspect of what it is that the user is trying to do. That's what Zero Trust is about. The interesting about Zero Trust is, number one, it makes the organization more secure.
If I don't have any implicit trust, if I go and check each and everything, no matter what the situation is, I'm more secure. The other thing that it does, it also makes the infrastructure simpler. I don't have 10 different use cases anymore. One use case for a local user going to a data center, another use case going to a SaaS application, a third use case in a coffee shop going to public cloud. I don't have all these different use cases. I have one use case. That makes the infrastructure simpler. That's why you're hearing more and more about Zero Trust. It's more secure. It makes things easier. It's cheaper. It's better. Of course, you're going to hear more and more about Zero Trust.
I had this interesting conversation with a CISO of a major U.S. corporation a few weeks ago. In that discussion, we talked about a Zero Trust project that they have. We were competing against one of the leading proxy in the cloud vendors. We talked about that. She explained to me what they're trying to do and so on. Then I knew that they have an SD-WAN project as well that we're competing on against other vendors. I asked her, "What about that SD-WAN project? What do you plan to do with that?" She said, "No, no, we're not talking about that.
We're talking about Zero Trust network access." I said, "Okay." What you're saying is that users that come in through SD-WAN or in a branch office using SD-WAN versus users sitting elsewhere at home or on the road using their laptop to connect to cloud applications, these are different use cases. Yes. You're going to run different checks here and different checks there. Yes. You're going to implicitly trust things here that you don't trust here, and implicitly trust things here that you don't trust here. Yes. How is that Zero Trust? Within a few minutes, the CISO understood that she probably needs to take these projects and look at them at once.
Yeah, we are on a mission out here to educate the market and show the market that Zero Trust is really a big thing. There are actually three different aspects of Zero Trust. There is Zero Trust for users, where it's a user, no matter where they are, no matter what they're trying to do, trying to access an application. We cannot trust their identity. We'll do whatever we can to make sure that they are who they say they are. We are not going to trust the device that they use, whether it's a laptop or a phone or a tablet. We have to assume nothing and have Zero Trust around anything that has to do with their device.
We're going to not trust anything about the access, whether they're allowed to access something, whether they are allowed to access a function within an application, whether they are allowed to do different things. We're not going to trust that. We're going to check it each and every time they try to do something, and then we're not going to trust the transaction itself. Even if we allow them to access something, that doesn't mean it's the end of the road. We're going to look at the transaction and make sure there's no malware going there and no command and control traffic and no data leakage, and so on. These are the different things that we need to do in order to implement Zero Trust for users. There is Zero Trust for applications.
Traditionally, applications were running in a data center behind a big firewall, and when applications were talking to each other, or components of applications, what we call microservices, were talking to each other, there was almost no security. We assume that they can do whatever they want. Now that applications are in public data centers, in public clouds, for some reason, customers view them differently, and they want to run more and more and more checks. Of course, the Zero Trust philosophy is if you're going to do it in the public cloud, you have to do it in the traditional data center, you have to do it in private cloud as well. Here also we have four things that we need to check. We have to identify the application itself.
When application A talks to application B or component A talks to component B, no matter where they are, we need to make sure that these are the right things talking to each other and that nothing has been replaced. We cannot trust the workload on which the application is running, whether it's a server or a VM or a container and so on. We have to trust nothing about that and verify each and every aspect of that. When applications talk to each other, access each other, we cannot trust that. We have to run a full suite of checks there. Also, once we allow application A to talk to application B, we have to look inside and make sure that there's nothing funky going in within that transaction. Then the third aspect of Zero Trust is Zero Trust for infrastructure.
Infrastructure meaning our routers and our switches and all the other traditional infrastructure, IoTs, whether these are industrial IoTs, corporate IoTs like TVs, cameras, and so on, medical devices and other healthcare-related IoTs, whatever it is. Also all the software and other things that we buy from our suppliers. Whether it's something like SolarWinds or source control management system, whatever it is, we can trust it. We cannot trust the identity of our users that are using it, our administrators. We cannot trust the device itself. Was it switched on the way? The DLL we just downloaded into SolarWinds, is that real or not? Can we trust it or not? We cannot trust the workload, the device, the access. We need to implement least privilege access whenever we allow our users to access these services or these devices.
The transaction itself, we have to make sure that it is not a component trying to connect to a place they are not supposed to connect, that there is no malware running inside, and so on. Very similar to Zero Trust for users and Zero Trust for applications, we have Zero Trust for infrastructure. If we take those three together and put them into a matrix, it looks like that. Very similar. We have to do similar things no matter whether it is Zero Trust for users, for applications, or for infrastructure. It is always about identity, about the device or the workload, about the access, and about the transaction.
The funny thing is, when you talk to different vendors in the industry that claim to do Zero Trust, what they really are doing is they focus on a single cell in this 12-cell matrix, and sometimes even on less than that. For example, when you talk to endpoint security vendors, of course, they do Zero Trust. What they really do is they do Zero Trust for users when it comes to the device. It's a small aspect of it. When you talk to the proxy and the cloud vendors, "Of course we do Zero Trust. We are the Zero Trust." In reality, what they do is the access part for Zero Trust for users.
If you want to secure the device, you go to this partner of theirs, if it's a SaaS application, you go to this CASB partner of theirs, if you want to secure the transaction, they partner with Joe Security, whatever, on this aspect of security, and so on. The same is true for Zero Trust for applications. You have different cloud security vendors that focus on a different, not even a complete cell, part of a different cell that you see here, and the same is true, of course, for Zero Trust for infrastructure.
Really, if you want to be a Zero Trust enterprise, meaning you want to take those three different aspects of Zero Trust, users, applications, and infrastructure, and you want to implement it across everything, you will have to start whacking moles again and work with 20 different vendors and integrate everything together. You can come to Palo Alto Networks. Once you choose your identity and access management vendor, with our platforms, you can achieve complete Zero Trust enterprise. You can become a Zero Trust enterprise by taking our network security platform and implementing it here, where you see the yellow cells. You take Cortex XDR, this is where you see the green cells. You take Prisma Cloud, where you see the blue cells, plus your favorite identity and access management vendor, and you have complete Zero Trust. You implement the Zero Trust enterprise.
Believe it or not, customers are subscribing to this, and they're buying the platforms more and more because they have a Zero Trust strategy, because they believe that with Zero Trust, they can get much better security and much simplified infrastructure. I believe that going into the future, this is going to become more and more important in decision-making as to whether to use specific vendors that sell specific feature like proxy cloud vendors, endpoint security vendors, cloud security vendors, this or that, and so on, or whether to use Palo Alto Networks for the complete set for the platform. Now that we understand what is Zero Trust, what is the Zero Trust enterprise, and how the different things that Palo Alto Networks does deliver together the Zero Trust enterprise, I would like to thank you very much for listening and to turn back to Nikesh.
Well, thank you very much, Nir. I hope you guys enjoyed the product download and the confirmation how we're going to stay ahead of the innovation curve. Well, listening to all this product portfolio stuff and watching our growth over the last years, it gives me great comfort to say that we believe that over the next few years, we will be able to sustain growth both at a billings level and a revenue level. Hence, we believe that we can get past $8 billion in revenue in FY 2024, and coupled with obviously crossing the $10 billion mark on billings in FY 2024. Which would give us a sustained growth rate of 23% on revenue and 22% on billings over the next three years, which is, again, higher than the guidance we'd given last time for three years going forward.
This is a testament to the comfort we have around our product portfolio, our product market fit, and the continued amount of innovation that we have delivered, which we believe is going to scale in the market over the next few years, and the innovation we have, which we are going to launch over the next few years as we get to our targets in FY 2024. You don't get there on products without actually going and having a scale go-to-market engine. I'm delighted to welcome and introduce, welcome BJ Jenkins to Palo Alto Networks, and introduce him for the first time as our President who's going to help drive those numbers. BJ, your targets are set. You ready?
I'm ready to go, Nikesh. Thank you very much. I'm very excited to be here today to talk to you about our go-to-market model that helps secure our customers. As you heard from Nikesh, Lee, Nir, and our product leaders, we have a best-in-class portfolio across three platforms, and we've built a strong go-to-market engine to bring them to our customers. It starts with our core sales teams of 3,200 professionals around the world. This team was built up with a strong foundation of network security sales skills, and we've augmented that with 850+ sales and technical sales specialists who bring focus and strong domain knowledge across our three platforms. We've created a cohesive selling motion between them that is driving strong results, 95% CAGR in Speedboat product sales with over 220 accounts delivering over $1 million in Speedboat sales.
We've seen the core sales team improve their productivity 5% annually with over 50% of our reps selling two or more Speedboat products. Our opportunity is to drive scale and even better execution. It starts with a one-team mindset and aligned leadership team with a common set of goals. We build joint account plans across the teams that help us land new customers with the right offering, but then quickly expand into other Speedboat areas. We back up these plans with an incentive model that rewards results and collaboration. We invest in enablement that helps our core reps become more proficient in selling the full portfolio. The results of all of these efforts will be to scale the business to reach more customers with a full portfolio in a highly efficient manner.
Supporting the efforts of our Palo Alto Networks go-to-market team is a thriving ecosystem that gives us further reach and leverage. As our customers accelerate their digital transformations, the move to public cloud, or fully implement hybrid work environments, they look to trusted VARs, system integrators, service providers, and cloud service providers to help them on their journey. We have invested in these partners to create a robust environment for us to collectively grow our business. If we look today, we have 8,000+ NextWave partners. We drove over $1 billion in sales with our system integrators and service provider partners last year, and we have over $250 million in sales with AWS, GCP, and Azure last year.
Going forward, you can expect us to continue to invest to create deeper and even more strategic partnerships that help bring the full portfolio to more customers. As we deliver those solutions, a key focus of our go-to-market model is creating trusting and loyal relationships with our customers through our services and support. We've succeeded at cultivating these trusted relationships as we have doubled the number of offerings since fiscal year 2019. We've achieved this with a world-class team, along with investment in automation and knowledge bases that have allowed us to resolve issues more quickly while reducing the amount of resources required. Our team and these investments have resulted in a 90% CSAT rating and TSIA and J.D. Power awards for the last seven years for our leading customer service. This model helps us continue to build loyalty and larger long-term relationships with our customers.
The power of our sales team, ecosystem partners, and world-class customer services leaves us in an enviable position. As a veteran of the information protection and security markets for more than 30 years, I believe this is the most exciting opportunity I have seen. From the outside in, I always had respect and admiration for Palo Alto Networks. Over the past three years, I saw the innovation and disruption in the three platforms they delivered and the product-market fit that resulted out of that. I saw a proven go-to-market model that was driving expansion in areas like the Global 2000, where over 70% of our customers have deployed two or more platforms. Now that I'm 30 days in, I'm more convinced than ever about the opportunity in front of us.
My goal is to supercharge the model going forward, to continue to innovate and drive scale and efficiency in our model to grow to our full potential as the true multi-platform cybersecurity leader. I'm excited to be a part of this team and eternally grateful for the opportunity.
BJ, we're so incredibly grateful that you're here. It's amazing that you've joined us. Talking of BJ and Lee, they have talked about their go-to-market strategy and our product portfolio and all that we have that is exceptionally special. As a leadership team, though, we know that the one thing that necessitates our ability to do our job well is that we hire the best people, and we motivate them to do an incredible job. I'm just going to take you for about 10 minutes through our ESG strategy. I'm going to talk you through our approach, and I'm going to talk you through our extraordinarily lofty goals. Quite simply, we really do believe that we can be the best company to work for. There is nothing that can stop us.
We believe that we can really be an exceptional steward of our environment, that our social agenda is amazing for our communities and our people, and the very nature of our product is integrity itself, and our governance is a manifestation of that. Let's talk about the environment. Now, for each of these slides, I'm going to take the same approach. I'm going to give you a sense of what we've achieved over the last three years and what we intend to achieve over next year. In 2019, regarding the environment, we did something that we do time and time again. You'll see this theme emerging. We went to our staff, and we said, "What do you think is important?" And we set up our own green teams.
At that time, we believed the thing that we should do more than any other thing was make sure that our real estate portfolio was LEED certified. In 2020, we gained that certification for 85% of our entire portfolio. Over this last year, we have committed to 100% renewable energy, not in 2050, but in 2030, a mere nine years away. We are going to have high quality offset of our carbon. In 2022, we will again move forward with partnership, and we will work with our suppliers to make sure that we can hit our science-based targets together. Finally, as if all of that is not enough, we are absolutely committed to securing a CDP leadership rating, a Carbon Disclosure Project rating. We all understand how very important that is, and we are well on our way.
As I just said when I started this presentation, our success is predicated on having the very best people and enabling them to do the very best work of their careers. In 2019, we set out to do three things, and three things really well. One, to hire the very best leadership team that we could from the iconic companies that you know in the Valley. Today, we have an extraordinarily spread of amazing leaders. Secondly, to make sure that we set up all of our hiring processes so that we could hire big numbers of diverse employees. Thirdly, as I'm sure you've appreciated this morning, we're a company that is disruptive. We went out of our way to ensure that we could hire the best early in career talent.
You will see subsequently, we have earned several awards for what we have done for our new employees that are younger in career. The pandemic hit in 2020, and it was an intensely interesting moment for us because what we saw as we closed our office doors and our employees went home, what we saw was that they could be equally, if not more productive, without control and without needing to be inside of the office. This gave us the idea that if that paradigm could be shattered, so many other paradigms could be. We decided to really investigate the nature of work. We looked at benefits, and we looked at learning, and we looked at location. Instead of keeping our employees as cohorts, we decided that we could individualize and personalize each and every one of those things. The Flex Coalition was born.
We teamed up with other companies to think through what should the nature of work be going forward, and how do we make sure that our employees are as motivated and as engaged as they could possibly be. In 2021 and 2020, we also achieved fair pay, promotion, performance, and mobility for diverse people, underrepresented minorities, and women. We have no difference in any of those processes at all in Palo Alto Networks. I think what I found most gratifying this year, as we sat through the difficulty of the pandemic, is during our employee survey, 81% of our people told us they were highly engaged and highly motivated working for Palo Alto Networks. I also saw something that I have never seen in my entire career. There was no diversity differential.
Our underrepresented minorities and our women were as equally highly engaged as our white and Asian men. I felt so proud of Palo Alto Networks at that moment. During COVID, we worked together again with our employees, and we set up our COVID fund to help those less fortunate than ourselves. We set up a fund also to help with racial injustice. Just as we have involved our people all the way through, we went with the causes that they cared most about. As we move into 2022, honestly, we think we're on a winner. We know how to motivate our employees. We know how to take work forward going into the future. So we're just going to continue doing more and more and more. We are absolutely committed to be the top cybersecurity company for diversity, bar none.
Of course, as I mentioned, education has been part of everything that we believe in. In 2019, we set up a partnership with the Girl Scouts. 260,000 badges have been given to girls to keep them safe online, to show that they understand cybersecurity. In 2022, we're going to take that learning, we're going to build adult material for incarcerated people and other people who need access to free education in cybersecurity. We really hope that we can reach 20 million people by 2025, which I think is a knockout goal. That leads me to governance. I said it at the start, our product is integrity. Our product is cybersecurity. Our governance structures just have to be a manifestation of that integrity. In 2019, we set everything up for our employees. In 2020, we introduced ESG into our board and into our subcommittees of the board.
Moving forward into 2022, our executive, part of their bonus will be based on ESG. That's how important we believe this to be. Now, at Palo Alto Networks, we're rather humble, and we're not out to try to get validation from external bodies. Our employees are starting to tell people and tell external bodies how great it is to work here. Over the last year, we have won awards for our diversity programs, for our internships, for our culture, and lately, even for our totality of our ESG agenda. It is fantastic to see that our Glassdoor movement has been 0.7x in less than a year. We're just around four, which means we're about a top 100 company to work for already. I want to close by talking about our values. Now, I'm sure virtually every company that you talk to talks about their values.
I'm going to tell you something different. We don't stick them on walls. We don't put them on T-shirts. Our values came out of our people. As a leadership team, we sat down, and we picked up the pen, and we decided to write the values. We put down the metaphorical pen very, very quickly. Instead, we decided to crowdsource our values from our people. We asked every single employee to tell us, what are we proud of? Who are we? What do we represent? They came up with these five words. We are a disruptive company. We execute flawlessly at scale continuously. We collaborate. I've talked about our partnerships with our suppliers. I've talked about the involvement of our employees. We act with integrity continually. I believe we are one of the most inclusive companies on the planet.
Thank you so much for your attention. It has been a complete joy to talk to you today. We are now going to take a five-minute break. Thank you.
[Break]
Well, we're back. You heard from BJ, you heard from Liane, you heard from the entire product team. Before I bring Dipak Golechha, our CFO, on to talk about specific guidance and how we're going to put this all into a framework for you to be able to model and look at how we're going to perform as a company over the next years. I wanted to give you a quick take as to how I see this. We're operating three very strong platform-oriented businesses at Palo Alto Networks, and we're operating them with a one team philosophy. If you look at the three different presentations that you saw today, or three major platform presentations you saw today. The first one around our network security strategy and our SASE strategy.
I do not believe there is a company out there in the network security space which has the ability to deliver a single architected platform solution across all form factors, whether it is on the hardware business or it is in the software firewall business or it is in the SASE business. The beauty of this is that you can start with any of those three products from Palo Alto Networks and over time expand your footprint to the other parts. You might have some other solution in play today, but because of the single policy pane, because of single architecture, you're actually able to make those transitions in an extremely seamless fashion. Our teams are working hard to make those transitions even easier, because we're noticing that many of our SASE customers that we're acquiring are net new to Palo Alto.
We're fully committed, and we believe these customers over time are going to work backwards and integrate our hardware firewalls into that business. Long term, I believe the network security business is going to be shaped by the movement to the public cloud as well as the movement to remote security and redefinition of MPLS to SD-WAN. In that process, I think the industry is going to end up being more than half-delivered to software, which is great because software has a lower total cost of ownership for our customers, as well as higher security efficacy for us because we're able to keep our systems up to date at that point in time. I believe our firewall business is the largest cybersecurity network business in the world.
It has phenomenal cash flow profile, and we think that it will gain in stature and in cash flow generation and in size over the next few years to continue to be the largest firewall security business in the world. If you look at Cortex, we believe we've come from nowhere in 18 months and built a solid business in XDR. We've also done a phenomenal job in putting automation out there, where we now boast more than $400 million in ARR. We think we're going to take that business and use that as the underpinning of transforming the SOC. I think XDR in the future will become the new SOC management platform for the future because that part of the industry needs an entire overhaul. It has been somewhat similarly in the same space where endpoint used to be about three or four years ago.
I think that overhaul is coming, and we think we're very well positioned to go deliver that in the market and aspire to be one of the leaders in the security operations space. Last but not the least, Prisma Cloud, something we started from scratch and part-acquisitioned three years ago. We believe that is a phenomenal blue ocean opportunity. It's a product category where the consolidated platform is not available for many other competitors, and we think we're about 18 to 24 months ahead in our innovation life cycle in that product. We will continue to keep our eye on that innovation pipeline. We'll continue to make sure that over time we deploy the platform in most cloud adoption companies.
I couldn't be more excited about the fact that we have three very clear businesses which we're building through a one-team approach where our products talk to each other, integrate with each other, but also can be bought independently depending on the maturation of the customer and where the customer is in re-architecting their security architecture. Not only that, we also are able to do that with the efficiency and scale that comes from having 4,000 salespeople out there and running them as one team with a strong underpinning of a values-based culture. With that, let me bring in Dipak, because Dipak is going to give you very precise numbers and guidance around how you think about this from a modeling perspective and a financial perspective, and he will also share how all this is going to be done in a financially prudent manner.
With that, our CFO, Dipak Golechha.
I'd like to tie what you have heard today back to the impact on numbers you see us discuss and also how we're looking at driving total shareholder value. The takeaway you should have had from Nikesh , Lee , Liane, BJ, and others is that we're focused on driving accelerated growth while simultaneously driving scale and efficiency to grow the bottom line faster than our revenue. From my vantage point, I see these goals tied up in the broader goal of focusing on each of the components of total shareholder return. At Palo Alto Networks, this comes down to an all-encompassing focus across these four drivers of value, which I will walk you through. Starting with revenue, you all saw our Q4 results where we showed strong momentum across all major top-line metrics.
Our view is that this momentum is not an accident, but it's a result of accelerating industry trends and predictable execution in the business you heard about from others on the management team. We believe these drivers are sustainable. Beyond revenue, this was clear in billings and also remaining performance obligation. Greater predictability of revenue is a benefit of the transformation that's on the way in our business towards NGS, as most of these products have recurring revenue with a growing renewal pipeline and opportunity for expansion. RPO is a measure of future revenue that is contractually committed. This metric includes both revenue that is on our balance sheet in the form of deferred revenue, as well as customer commitments that have not yet been invoiced. You can see the clear relationship between prior year ending RPO and our current year revenue.
The revenue coverage in our current RPO has steadily grown from 49% entering fiscal year 2020 to 58% entering this year. This gives us a greater degree of predictability entering the year, enabling us not only to forecast with more confidence, but also to invest with more confidence. We expect revenue coming from our current RPO will continue to increase as we proceed through our transformation journey over time. Now, I wanted to dive into some of the details of our revenue drivers. What I want you to take away is the attractive combination of high growth in our NGS portfolio, along with stability in our core firewall business. We use NGS as a measure of the significant progress and our investments where we are driving transformation within our business. Our NGS portfolio is well diversified and we're seeing strong growth contributions across the board.
This ranges from transformation to software within our core firewall business, our leverage to hyperscale public cloud deployments, and the demand we're seeing around automation security operations. The strength of our NGS portfolio and the pipeline of expected new products gives us the confidence to target a 40% CAGR in NGS ARR through fiscal year 2024. As part of this NGS growth, we continue to see a transformation of our firewall as a platform business to software. This trend was in its infancy in fiscal year 2019, and in fiscal year 2022, we expect software to be north of 40% of our FWAP billings, with a target to be well ahead of this level as we look out to fiscal year 2024. Lastly, I mentioned consistency in our product business.
As you heard earlier, we're launching our 4th generation hardware releases. We've given guidance for FY 2022 on our product line. As we look out over the three-year period from FY 2021 to FY 2024, we expect to grow product revenue at a compounded rate in the mid-single digits. Moving on to profitability. I wanted to focus on our cost of revenue and sales and marketing expense, which are our two largest cost items. At the same time, I want to make sure investors understand that we're focused across every element of our cost structure to drive benefits from our scale and focus on efficiency. We've seen relatively stable gross margins over the last three years. We expect this trend to continue in FY 2022, with gross margins in line with our current level.
What we've seen happen underneath that trend is growth in our NGS portfolio, which was less than 15% of the total business in fiscal year 2019, and will likely be more than double this in its contribution by fiscal year 2022. Within NGS, we have a number of products that are early in their lifecycle, and as a result of their smaller scale, have lower gross margins. We've seen consistent year-over-year improvement in the gross margin of these early lifecycle products as we have increased revenue faster than our public cloud costs and benefited from leverage in our customer support around these products. As we manage the balance of growth and profitability, we're looking at the returns of various investment opportunities and prioritizing these opportunities accordingly. We're ultimately managing this under the margin framework we've given to you.
For example, we launched Okyo on Friday, and you heard a bit about that opportunity earlier. This is an investment we have had on the way for over a year, culminating in the products that we just announced. Our overall management of gross margins has enabled this Okyo investment. Sales productivity is a key driver of our ability to drive operating margins also. In fiscal year 2020, Nikesh and the team very intentionally made investments in the business to drive transformation towards software and cloud. This included transforming the way we sell our products. We embarked on this breadth and depth strategy that BJ highlighted, as well as some new ecosystem partnerships such as the cloud service providers. You see how this investment impacted our productivity in fiscal year 2020, as we added a large number of people to the go-to-market organization.
As we moved through fiscal year 2020, we started to see productivity out of these hires, and we've doubled down on hiring in fiscal year 2021 as we saw productivity improve. We expect to continue to see additional improvements in fiscal year 2022, driven by a balance of driving productivity in fiscal year 2021 hires, and also an overall moderation in our headcount additions. We expect a 5% increase in core sales productivity in fiscal year 2022. Moving on to cash conversion. We look to bring the benefits of scale and efficiency that I spoke about in our profitability to cash conversion. Historically, many of the same investments we made related to our transformation had a similar, if not greater, impact on our cash flow as we saw our core NGFW business slow and invested in specialized sales resources.
As we gain greater comfort in some of the impacts of efforts we have underway around cash conversion, we have confidence in a range of 32%-33% adjusted free cash flow margin in fiscal year 2022. This is ahead of the initial guidance we gave back on August 23rd of greater than 30%. Some of these efforts include driving improvements in large deal motions, incremental discipline in collections, and ensuring that we're operating at or ahead of industry benchmarks in our working capital management. We are also focused on implementing a highly disciplined billings plans exceptions process. We believe beyond fiscal year 2022, we can expand adjusted free cash flow margins ahead of operating margin expansion at the rate of 100-150 basis points through fiscal year 2024.
When we step back and look at our cash conversion, the data already shows that for software companies over $3 billion in revenue, we're near the top of our peer group with our combination of forward revenue growth and adjusted free cash flow margin. These are the sorts of companies we look at in benchmarking to help drive cash conversion and our balance of growth and profitability. With our goals around growth and all on the way to keep the focus on adjusted free cash flow margin, we aspire to drive improvement here towards a combination that would put us near 60%. Moving on to capital allocation, the final component of total shareholder return. Over the last three years, we've matured significantly in how we manage our sources and uses of cash within a broader capital allocation umbrella.
During 2018 and 2020, we issued convertible debt to take advantage of favorable conditions and finance some of our M&A activity. We also returned about 1/3 of the cash we generated in the form of share repurchase. Looking forward, we've given some framework for how we are thinking about cash generation. If you use that framework, you'll see we plan to generate over $6 billion in adjusted free cash flow over the next three years. We also have a $1.5 billion convert maturing in fiscal year 2023, where our base case is to repay this. Beyond this, you should think about share repurchases as being the focus of our external use of cash. Related to our capital structure, we continue to make progress reducing our stock-based compensation expense as a proportion of our revenue.
We're doing this while balancing our need to compete for top talent in a very competitive industry, and the geographies in which we do business. One nuance within our stock-based compensation that many of you may not be familiar with is that a significant portion is being driven by our M&A activity. Here we have used stock grants as part of our acquisition consideration for retention and to reinvest founder-owned equity. This reached a peak in fiscal year 2021. We're focused on managing stock-based comp lower through reducing SBC per employee. We expect in fiscal year 2022, we will see overall SBC as a percent of revenue decrease, and look to continue that trend beyond fiscal year 2022. Bringing this all together, we believe we can drive an attractive financial profile over the next three years, in line with what you heard from Nikesh in my presentation.
In review, we expect to achieve $8 billion in revenue in fiscal year 2024, a 23% CAGR over three years, driven by growth in our overall TAM, share gains, and a favorable mix towards higher growth markets within our revenue. Within our revenue, we expect product growth at a compounded rate in the mid-single digits over this period. Driving this revenue level, we expect $10 billion in fiscal year 2024 billings at 22% CAGR over the next three years. Lastly, we expect $3.25 billion in fiscal year 2024 NGS ARR of 40% CAGR. With many of the investments needed to build our platform behind us, stable gross margins, and positive trends in sales and productivity, we expect to expand our operating margins by 50- 100 basis points beyond fiscal year 2022.
We see opportunities to improve cash conversion and drive 100 - 150 basis points in cash flow margin expansion beyond FY 2022, where we have sharpened our adjusted free cash flow margin guidance to FY 2022 to 32%-33%. We combine this with a balanced approach to capital allocation, with buyback being the focus of our external use of cash. With that, I'd like to turn it back to Nikesh ahead of our Q&A.
I'm Clay, and I'll introduce the team for Q&A while we get things set up. Participating in the Q&A will be Nikesh Arora, Chairman and CEO, Dipak Golechha, Chief Financial Officer, Lee Klarich, Chief Product Officer, BJ Jenkins, President, Amit Singh, Chief Business Officer, and Liane Hornsey, Chief People Officer. To allow for broad participation, I would ask that each person ask only one question. The first question will be from Brent Thill of Jefferies, with Keith Weiss of Morgan Stanley to follow. Brent, you may ask your question.
Great. Thanks for taking the time. Just as relates to the go to market, I'm curious if you could just talk through the integration of the networking cloud teams and any synergies you're now seeing as it relates to the go to market on sales and marketing.
The next question will be coming from Keith Weiss of Morgan Stanley. Keith, you may ask your question.
Hey, guys. Can you guys hear me all right?
Yeah.
Yeah.
Yep.
Awesome. I don't know if you guys caught Brent's question there. I don't want to just skip over it. Brent was asking about sales productivity gains that you guys expect to see out of the integration of the core network security teams with all the speedboat teams. Maybe we could start out with that one, just in terms of overall sales productivity, enumerating where you guys expect to see these ongoing productivity gains on a go forward basis, and then I could sneak in my question after that.
Sure, Keith. Thank you for helping Brent with his question. He couldn't hear it. I am glad you could. Well, since BJ Jenkins is new to Palo Alto Networks, we set a target on him to drive sales productivity. I don't know, BJ, if you want to take it, and Amit, you want to assist?
Yeah. Sounds good. Thanks, Brent, and thanks, Keith, for transferring the question over. I think, like I said in my presentation, this is about a model that's working. It's got good harmony between the speedboats and the core sales force. My job is to drive scale with efficiency. What we do in that model is obviously invest in the speedboats to really capture leadership in these new innovation areas. While we're doing that, through incentives and enablement, keep the teams working well together, but make the core sales force able to represent the full portfolio over time. To date, we've been experiencing about 5% annually in core productivity increases. My job, as we keep going forward, is to keep those productivity gains going. Scale with efficiency and that ratio you've seen where we've got about 5% productivity annually, I think is a good benchmark.
I believe I can continue to improve on that.
Amit, did you want to add something?
Yeah. Keith, one measure of productivity gain is going to come from very large deals. What ends up happening is our clients have been investing in parts of the portfolio, firewalls, virtual firewalls. They might use cloud. In some cases, they might use Cortex. Increasingly, some of the largest customers are going with a platform approach. They're deciding that instead of, you heard from Nir talk about the Whac-A-Mole approach, they don't want to do that anymore. It's actually more expensive and less secure. Hence, they're actually standardizing on Palo Alto Networks end to end. We had several deals, as Nikesh and Dipak shared in the earnings call, that were over $50 million, where customers are committing to us for the long term. We actually believe that's going to be a long-term driver of productivity gains across all the large customers that we support.
Outstanding. My question, I wanted to ask a more product-focused question around Cortex, and maybe this is more of a market question. We've seen a lot more focus on data and data analytics driving better security outcomes from Palo Alto Networks, but also from a lot of different vendors out there. Can you help us understand, when we think about Cortex and that growth opportunity over the next couple of years, how much of that comes from displacing existing solutions and really creating the Next -Generation of a SIEM, if you will, versus how much of it is adjacent selling or sort of new market opportunity as data becomes more ingrained in more aspects of the security architecture and what the security guys are doing on a day-to-day basis? How much of this is greenfield versus a replacement opportunity, I guess, is the crux to the question?
Thanks, Keith, for the question, and I'll try and do my best, and I'll have Lee jump in and assist. Look, the endpoint strategy, and I'll highlight endpoint because that industry actually tried to reinvent itself with EDR. You saw a lot of the traditional endpoint ventures, endpoint vendors step back or newer players come in with the EDR strategy. Funnily enough, we were the first people to anoint or coin the term XDR because we felt you could build more integration with data from the endpoint and the firewall. Towards that end, Cortex XDR collects the most amount of data, and as Lee highlighted in our presentation, we ingest terabytes of data on a daily basis from Cortex because that allows us to take a look at all the data, run analytics against it.
What the teams have successfully done is they have taken more and more security data and ingested in and cross-correlated that with Cortex XDR. I think this is fundamentally the new paradigm for SOC operations and SIEMs in the future. I think the current paradigm of ingesting all data without being able to make sense of it or normalize it is going to be gone because the amount of efficacy and security you can bring in with being able to cross-correlate and normalize data is going to be so much higher and so much more relevant that you will see that unless the traditional SIEM players evolve, they're going to be left behind. I don't think it's going to be a conversation of XDR versus SIEM.
I think XDR is a set of analytic solutions provided by collecting endpoint data and commingling them with firewall data. You'll see that happen more and more. Effectively, I think XDR or the new incarnation of XDR will replace the SIEM. I don't know, Lee, if you want to add to that.
Yeah, I just want to maybe add quickly. I feel like too many companies, too many vendors all talk about ingesting data. The reality is that very, very few products were actually designed to be able to ingest data. Most SIEMs out there, and even most products out there, were designed to ingest alerts, maybe logs, but not data. When we talk about data, we're talking about going very deep. For example, from a single endpoint host, we'll collect well north of 100 MB per day of data. We collect data from the network. We collect data from identity. We're collecting data from cloud with the introduction of XDR 3.0 for cloud.
The unique difference with XDR is that it's actually designed from the ground up, oriented around being able to actually collect data from all these different sources, stitch it together, and then drive a whole new breed of analytics on top of that for not only detecting attacks, but being able to streamline the investigation and then ultimately to be able to automate the response. That's how we achieve the numbers that you saw earlier today when we talked about being able to get down to basically sub-minute average response time.
Our next question comes from Matt Hedberg of RBC.
Great, guys. Thanks for taking my question and congrats on this presentation. I think it's been very helpful. Your $10 billion billings target and $8 billion revenue target by FY 2024, I think, was above where any of us had expected and super exciting. I actually wanted to focus on the margin side with Dipak. I think the margin side is equally exciting to us and I think a lot of the long-term investors here. You talked about some of the drivers like cash collection and sales productivity improvements. In addition to that, I wanted to understand how you expect M&A to potentially impact margins through FY 2024 and also your assumption on billings contract duration as well through FY 2024.
Matt, I'm going to take the first part of that, and then Dipak will jump in with the margin conversation. I think there are two very important things to understand. Three years ago when we set about giving guidance and doing the Analyst Day, we didn't quite appreciate the amount of product development we had to do in the company, both from an organic perspective as well as acquisitions. At this point in time, I'd say all three of our platforms are 90 %+ there. It's very hard for us to acquire into those platforms and integrate, which is where you saw a lot of our M&A activity. We were acquiring literally new capabilities, absorbing them into the company, hiring more people, driving more growth.
I think we're at a point where we have a phenomenal amount of products in our portfolio. We have to spend the next two, three years really selling them out there. That's why we're focused more on scaling with sales productivity as opposed to creating more product. You saw we launched Okyo on Friday, which was actually all internally developed. Literally, we stood up a team. All those expenses go into our cost, but we can't talk about all that product development expense until we actually launch the product. I'd say, majority of our products are out there. Now the job is to sweat the assets and go out and sell them more. Hopefully we'll see our product development expenses normalize.
You will see less M&A because we're not looking to acquire larger businesses, doing just because we believe we are in all the space we want to be in. As a consequence, you will see that we will create margin expansion. Dipak can talk more about the operating margin expansion and the free cash flow expansion.
Yeah. Thanks, Matt. Just beyond the prepared remarks where I think you hopefully see the power of the portfolio come into effect because we're seeing margin improvement product by product year -after -year, and that's just the balance of NGS and our core leads to flat gross margin. I think what I would say is we've also reached the scale where we can take a lot of the innovations in our stride. Okay? It's already factored. Our three-year model is very much the reflection of a product-by-product line analysis. I think for the most part, we've captured everything that we can think of. To Nikesh's point, we're only expecting incremental M&A, but I think overall we've got a portfolio play, and within that portfolio play we feel pretty comfortable with our overall margin guidance.
Great. Our next question comes from Brian Essex of Goldman Sachs. Brian, you may ask your question.
Great. Thank you for taking the question. Maybe Nikesh or Lee, I'd like to touch on, I think we've talked in the past about the shift from form factors within network security from physical to virtual and the impact that might have on revenue. I think maybe what's misunderstood or underappreciated is actually the installed, the kind of global installed base there. I think Cisco's ASA business alone would probably be a top two or three network security vendor on a standalone basis. I'd like to know, what's your visibility and maybe what should some of the puts and takes investors should think about be as we think about the level of confidence you have in that kind of mid-single-digit network security tag, or how much visibility do you have there?
Brian, as you can imagine, we went through a bit of an overhaul in the industry with the pandemic, we introduced a whole new set of form factors not too long ago. Looking at that, looking at the pipeline, looking at where we are in the cycle of refreshes that are going to happen, we have ample visibility, and we feel very comfortable around the mid-single digit growth on the product side. Also, couple that with the virtual firewalls that we're selling. What you see, at the end of the day, the customers are making an active choice. Either they're deploying the public cloud, going to the public cloud, starting all the work there, starting to shrink their data center footprint, then using virtual firewalls to keep track of the incremental capacity needs.
Which for us is a better gross margin business, to be honest, a lower cost of ownership for us and for the customer, easier to provide security. From that perspective, the form factor shift actually is more profitable for us when it happens with hardware and software firewalls. At the same time, people are deploying software firewalls against the public cloud as well. I think SASE is a unique opportunity, which is, in my mind, underappreciated what we have been able to achieve in the last 18- 24 months. 24 months ago, we were not as relevant in SASE. Today, SASE is our fastest-growing business. To your point, it's a combination of security and actually network, right?
It's actually we're targeting not just the security TAM, because there's a network TAM that is fast growing a whole series of transformation, whether it's people going from MPLS to SD-WAN, whether it's people going for remote security from 10% to 100%. I think that's a huge market. Add that to the mix. We believe the firewall industry continues to grow in the higher single-digit sort of space between SASE and firewall virtual and hardware. We still believe we're going to keep at the clip we are with the double-digit number around firewall as a platform with a two-handle profit.
Great. Thank you. Our next question comes from Saket Kalia of Barclays.
Okay, great. Hey, thanks for taking my question here, guys, and very helpful session. Nikesh, maybe just to double click on that last topic just a little bit deeper around firewall refresh, independent of form factor, both in terms of your own sort of appliance families as well as some customer cohorts. I was just wondering if you could just go one level deeper, maybe into what parts of your base you expect to refresh, and by extension, I think a theme here has been the broader platform, how you can sort of sell the broader platform at that time of refresh?
Well, I'm going to ask Amit to jump in and answer that question because he's been helping drive our hardware and network security fire speedboats, Amit.
Saket, thank you for your question. Think of it in three different areas. On the hardware side, we have brand-new form factor, right? You've seen our RAPTOR line, our Bearcat line refreshed, built on a new ASIC platform, and that's going through acceleration, frankly, as customers who sweated their assets maybe during the pandemic are coming back and refreshing everything. Think of it that way. We actually believe since we were a bigger player in the enterprise cohort, that we actually going to see some pretty good acceleration in the high end as people come back to work. At the same time, for the first time, we have a competitive low-end appliance, the PA-400, that is seeing massive acceleration. It's actually incredibly competitive internationally, incredibly competitive through our disti channel. We actually feel good about that overall portfolio.
As you move to the virtual form factors, we are uniquely positioned because we provide very high performance VM firewalls with all the security subscriptions to all our large, medium-size, and small customers, and they can choose which one they want to deploy depending on their cloud journey. Lastly, as the last question, even the prior questioner asked, is the SASE form factor then brings it all together where you can deploy any of these services as cloud delivered services from us for remote users, for branches, for data center, for private access, and have end-to-end visibility. The last part, people can use all of this as a platform. What's happening is clients are saying, "Oh, my God, my employees might stay home for the foreseeable future. Let me get a remote access solution." Guess what?
It's the same code base, the same security profile, the same exact set of services that they already deployed in the firewall for the data center. For us, it allows us to present the entire end-to-end portfolio. That's why you're seeing the acceleration of that business, the firewall as a platform business. Frankly, as our bookings have grown, our growth rate has actually stayed the same or accelerated, which is very, very unique with these series of factors that Nikesh and Lee talked about.
Great. Our next question comes from Irvin Liu of Evercore. Irvin, you may ask your question.
Thanks for the presentation today. I actually had a question on Prisma Access. I guess this question is probably perhaps best suited for Nikesh or Lee. As SASE becomes a cornerstone of security and secured connectivity, you are seeing Prisma Access customer count growing quite nicely. I wanted to better understand the technical infrastructure required to support your growing user base and whether growth in this product segment would necessitate incremental infrastructure build-outs or investments.
We're going to have Lee Klarich answer that question for you.
Great question. We made a very conscious decision when we built Prisma Access that we foresaw the build-out of infrastructure and global networks from the CSPs, the cloud providers, and how that infrastructure build-out would happen and accelerate. Instead of building proprietary data centers, we chose to leverage the investment that the CSPs were making. By doing so, it has allowed us to leverage the global network footprint to be able to reach hundreds of locations around the world to leverage the compute footprints and run all of our security stacks there. In doing that, we've been able to test this out. We've been able to prove it with our customers.
We can provide the just amazing performance for the end user, wherever they might happen to be connecting in from around the world or wherever the branch offices might be and wherever they're connecting to. The other aspect of this to remember is these users are trying to reach applications, and the CSPs and the application, SaaS application, et cetera, are almost always either co-mingled, co-hosted, or have direct connections in these big global POPs. That's the approach we've taken, and as such, we don't have the infrastructure investment required. Instead, we're simply driving that as cost of the service that we're deploying to our customers as we deploy to our customers.
Just to add to that, the benefit is as we scale our consumption of the CSPs, we actually see scale effects on the cost, hence the gross margin of our business in a very linear fashion.
Okay. Our next question comes from Keith Bachman of BMO, with Michael Turits on deck.
Thank you very much, and appreciate the presentation. Lots of good stuff in here. One of the key themes I think is consolidation of spend or consolidation of vendors. I wanted to focus with that as the backdrop on going back to Cortex. I want to try to understand, there's a number of solutions within Cortex, Xpanse, XSOAR and others. Where are you today in terms of the mix? What I mean by that, in terms of when you're selling Cortex today, is there an average number of solutions that you're selling to these customers? How do you envision this changing through your FY 2024 targets that you've established? It seems like that's a rich opportunity. If I just take a step back, too, you've given some TAM analysis or information on Cortex, both today and where it's going to be in 2024.
How should we think about that as we impute the growth of Cortex in the broader financial top-line targets that you've given? In other words, will Cortex grow at those type of rates or above those type of rates? How should we just generally be thinking about that? Many thanks.
Well, Keith, as I said, I'll go a step further and say the transformation we've seen in network security and the transformation we've seen in cloud security has yet to happen to the entire SOC space. The SOC has still been a collection of a lot of point solutions. I think the reason we had Lee talk about what we have been able to achieve at Palo Alto Networks is take it down from 67 odd thousand alerts down to 60 odd events and be able to remediate those in seconds, if not in minutes. That's what every SOC aspires to. You can't get there until the overhaul happens of your infrastructure over time. It's not just getting a better SOC tool that solves the problem.
You actually have to have the right component parts that drive the right, to use Lee's word, data into your SOC, you can actually analyze and do something with it. We believe this is going to be one of the biggest opportunities out ahead, not just next three years, the next 5 -1 0 years. I think that's where the most amount of innovation is going to happen and most amount of consolidation is going to happen in the next three to five years. Now, you've seen we were very deliberate in our XDR strategy, where the endpoint is not just an alert generation device or endpoint protection device. It actually is a data sensor and a data collection device. We went the other way from the industry.
Our endpoint has capabilities that four vendors would have to be added to put one agent out there to make that happen. We've made a very deliberate strategic decision to do that that way. We think in terms of the way you think about it, obviously, we expect to grow fast in the TAM that is out there in the industry because we are going to expand our capability set very aggressively over the next 12 months and 24 months. You should hope to see customers over time start consolidating their SOC operations with something like Cortex XDR as the base where they cross-correlate that with XSOAR, and then depending how big their external footprint is, they add Xpanse or not.
You'll obviously see us doing more and more integration between the products because that way you wouldn't have to go deal with three different SKUs, perhaps get a consolidated solution from Palo Alto Networks.
Great. Our next question comes from Michael Turits of KeyBanc with Adam Tindle on deck.
Hey, guys. Good afternoon. I just wanted to ask you, Nikesh, about the mid-single digit product growth guide. A couple of years ago, not even that long ago, it was pretty much flat. Now you got to do closer to 7% or 8% for this year. What's changed and what gives you that much more confidence that product can grow? I know you went through some of that just now around the product refresh and answering Saket's question.
I think, Mike, there's two or three things. One is, I think as people are coming out of the pandemic, what has happened is the volumes in the industry have grown much faster than anybody expected. Because of the big shift to technology, almost all of our customers are reaching the capacity in the data centers, but they actually haven't gone back in and upgraded data centers that added more capacity. You're seeing the capacity return, and I don't believe it's a capacity spurt. I think that is the new normal. I think what you're seeing is the industry has established itself to a new normal. That coupled with the refresh Amit talked about, and obviously it's time for us to start thinking about refresh for certain other parts of our portfolio.
The third piece, the form factors in certain segments of the market, which we have not traditionally played in, whether it's adding Okyo to the mix or whether it's adding the 400s to the mix. I think combination of all those three factors gives us comfort that we can sustain those growth rates over the next two years.
Our next question comes from Adam Tindle of Raymond James with Gray Powell on deck.
Okay, perfect. Nikesh, I wanted to ask a question on Prisma Cloud. You called it blue ocean and a one of a kind business, so I thought it might be important to ask you a question on it. There's no lack of capital being thrown at security companies. Why do you think others aren't chasing this opportunity the way that you are? As you think forward, what do you think the competitive environment looks like over the next three to five years, call it? Do you think hyperscalers themselves might begin to offer these capabilities?
I was going to say that Usain Bolt and there's people chasing Usain Bolt. Well, I said it anyway. Look, there's a lot of capital being thrown at that problem. You are seeing the CSPs deliver solutions which solve some of these problems. I think the reason we are where we are is we got ahead of this 18 months ago. When people were busy doing cloud workload protection, we were adding container security capabilities. When people were busy doing container security, we were adding serverless capability, adding IAM, WAAP, RASP to the product portfolio. When people are now busy chasing those, we added micro-segmentation capabilities. Now that people are trying to figure out how that works, we added shift left capabilities with Bridgecrew.
What we've done is we've tried to anticipate the solution that our customers need, and we've made sure they're deployed consistently across all five clouds out there. Yes, can I get a solution from one of the CSPs out there that solves some of these problems? Yes. Most of our larger customers in the enterprise space are ending up on multiple clouds. You've got to make sure you run three different stacks where this solves for AWS as one way, GCP is another way, Azure is a third way, Oracle, Alibaba. You're back to managing five different silos and five different policy. You want to manage permissions in AWS using their tools. You want to manage them on GCP using their tools.
The benefit of having a single tool that allows you to be consistent across those cloud installs is way higher than actually the people needed to go run these five different ways from Sunday. I think the blue ocean opportunity is in that integration, is in that platform, and also in the fact that many of our customers in a hybrid solution where they already deploy some of our products, now we're able to take some of the cloud data, integrate our XDR. You are seeing us trying to leverage the power of the portfolio, yet also stay far ahead in the bleeding edge of the cloud security curve.
Great. Our next question comes from Gray Powell with Gregg Moskowitz on deck. Gray?
Okay, great. Thanks for letting me ask some questions here. Really appreciate it. How should we think about the free cash flow margin profile of the cloud and AI security business versus the core network security business within the context of that 35% free cash flow margin target for FY 2024? Just how much should we expect the ClaiSec business to scale over the next couple of years?
Well, the ClaiSec business is a significant component of the NGS ARR that Dipak highlighted. The fact that the NGS ARR is going to grow at a 40% CAGR, a lot of that growth is driven by ClaiSec and SASE. You should expect that ClaiSec will grow. From the numbers we shared with you at the end of last year, you know that our ClaiSec business was slowly and steadily turning less free cash flow negative. You would expect that to be a net contributor to cash flow over the next three years, as opposed to a draw on free cash flow. Add to that some of the cash flow management plans that Dipak talked about. I think part of it which maybe you insight for is we swept PANFS an year and a half ago.
Some of the financing we've done for our customers is a draw on our free cash flow and just managing that draw, managing our annual billings and getting that to a point of stability. Adding back the fact that our ClaiSec business is going to be cash flow margin positive and contributing faster than it can be operating margin contributor gives us more comfort that our cash flow margins will grow faster than our operating margin growth.
Our next question comes from Gregg Moskowitz of Mizuho Securities with Justin Roach on deck.
Okay, thank you, and appreciate the time today. Earlier you outlined Zero Trust as a 12-cell matrix, and you also highlighted your ability to handle nine of these areas across Cortex and Prisma Cloud and network security while partnering with identity management vendors in the other three areas. Two questions around this, if I may. First, how much more customer education around Zero Trust do you think is necessary? Second, do you have any aspirations for Palo Alto to eventually deliver a full Zero Trust architecture with your own IP? Does it make more sense to continue to partner on the identity side going forward? Thanks.
Gregg, the answer to your first question is a lot. As in a lot of our customers and even the U.S. government, they're talking about Zero Trust, and as Nir highlighted in his own special way, that a lot of people are still trying to figure out what that means. Towards that end, literally what you saw today is something Nir has started talking about. He always talks about it, but he started talking about it more vocally. The last month, we made it a part of our sales kickoff. We will make it a significant part of our customer education programs. We're going to launch a whole bunch of websites and assets, educate our own teams, as well as provide perhaps Zero Trust consulting to our customers to get them to a place where they understand that Zero Trust is not a product-by-product solve.
It's actually an enterprise solve that's needed. To your point, yes, we're going to do a lot of effort, expend a lot of effort in the next 6-12 months to drive the understanding around Zero Trust enterprise, because it's helpful for us because it will lead to more product sales for Palo Alto. In terms of the three boxes you saw we don't cover, actually the same box, identity access management, which is more the traditional identity players out in the marketplace. There's a very simple API integration with any identity provider that a customer chooses to deploy, which we can connect with and deliver the entire Zero Trust solution at Palo Alto Networks. I don't think our shareholders would like us to go out and acquire or build independent identity capability just to be able to replace something which is working just fine.
From our perspective, we're very happy to integrate and partner. It's not a special partnership. It's a simple API integration that is needed to deliver our solutions. The complexity is more in the policy aspects of it and how do you go make sure that you're inspecting the traffic across any form factor in a consistent basis, not in integrating with an API from identity.
All right, our next question comes from Justin Roach of Piper Sandler with Adam Borg on deck.
Hey, guys, this is Justin on f or Rob, thanks for taking the question. I just wanted to ask around the newly announced Okyo Garde solution, how should we think about this product within the three-year framework of revenue and billings growth? How much do we realistically think it could add over the next three years and maybe the size of this market could reach?
Look, Okyo is part of our overall product portfolio. We're not separating out guidance for Okyo. If you saw the Okyo launch, it's a product very near and dear to my heart and aspirations for our company. I think it's unique in its ability to solve an enterprise security problem at home for our users, where they want the simplicity of deployment, both at the home, to be honest, and also on the SMB front. We have a lot of expectations from the product. We're not separating them out. It's part of the overall envelope we've shared with you of trying to achieve north of $8 billion in revenue and $10 billion in billings. Hopefully in, we just launched it literally three days ago.
As we get more experience, more understanding, perhaps in a future analyst day or a future quarterly call, we'll give you more insight into how it is progressing. For now, really excited about what the teams have built, really excited about the technology that's going to get deployed, and look forward to good success from it.
All right, our next question comes from Adam Borg of Stifel with Catharine Trebnick on deck.
Great. Thanks so much for taking the questions. Just on the service provider vertical, I was just hoping you could give a broader update here. I know we talked about it a little bit today. What opportunities really excite you here and your efforts to really further penetrate it? Thanks so much.
Lee, you want to take this one, Lee?
Sure. I'd say there's a couple areas that are particularly important that we've been spending a lot of time on, and we've shared a bit with you over the last year in terms of some of this focus. One is, if we look at 5G, obviously there's a tremendous opportunity to not just sell 5G security to the providers in order to secure their environment, but actually to partner with them, because one of the key aspects of 5G is it opens up an opportunity to really provide value-add services on top of the connectivity. We're seeing, I would describe that as being very early days still, but a very interesting opportunity as 5G potentially becomes a mechanism for a lot more enterprise critical infrastructure and other types of connectivity to shift from more traditional networks. That's one.
Anand talked about that in his presentation earlier this morning, and so we're seeing some of the early opportunities there, and it's exciting and interesting. The second is really around SASE, and we believe that there's a unique opportunity for us in being the most comprehensive SASE solution, which is combining Prisma Access with the cloud-delivered security, with Prisma SD-WAN, and to actually deliver that as an integrated solution through our service provider partners, where they can actually help migrate their customers to a full SASE solution as opposed to doing MPLS to SD-WAN trade-outs, which is sort of the typical motion that we've seen over the last few years. By going to a full SASE solution, it's a much bigger opportunity for them, and it's an opportunity that we're much more uniquely positioned to be able to partner with them on to deliver.
Great. Our next question is from Catharine Trebnick of Colliers with Ben Bollin on deck.
Hi, thank you for taking my question. Mine's around automation of data. You talked about that quite a bit in your presentation. Could you, Lee, perhaps give an example of where you see that in 2024 that would be more expedient and more secure versus integration of the different three pillars? Thank you.
Sure. Where I see it is basically, hopefully, every one of our customers achieving the metrics that I shared with you earlier this morning. That being able to easily ingest all relevant security data. To be able to drive the security analytics as much as possible, obviously inline prevention, but where needed to be able to drive real-time detection of potential threats and attacks. I know that sounds really simple, but there's actually a lot of technical work that will need to go into making that a reality across the industry, like what we've been able to accomplish. The second is, I have this view that in three years, I'm hoping I'm here telling you that we're going to accomplish 100% automation in a fair number of customer environments. I just believe that manual response work can't be the answer.
It simply can't scale, particularly when the attackers, the attack landscape, they are using automation to run their attacks. We as defenders can't then respond to that with manual response mechanisms. We have to automate everything we possibly can in order to be able to keep up with and get ahead of these attacks. I believe it's possible. I believe we're seeing through the automation that we've been able to build out with XSOAR, the ability where we've integrated that with XDR and Xpanse. We've proven that we can connect these dots together, that we can connect data analytics and automation to drive these outcomes. Now it's just a matter of scaling that up, making it more broadly consumable from our customers.
Our next question comes from Ben Bollin of Cleveland Research with Yun Kim on deck.
Good afternoon, everyone. Thank you for taking the question. Nikesh, I was hoping you could talk a little bit about the consolidation opportunity that you see into the future. Maybe you could share a little bit more about which technologies or services you think are on more of the front end of that opportunity, and which technologies you feel are perhaps later and maybe a little bit longer tail over time. Thank you.
Ben, as you've seen from a scale perspective, we are seeing slow and steady consolidation in the network security stack, right? As the pandemic has caused a surge in SASE. It's kind of interesting, customers who are now deploying SASE from Palo Alto Networks, we're having conversations with them if they're not a firewall customer, that perhaps their next iteration when their firewalls come end of life with some other vendor, they can actually reverse into Palo Alto firewalls because they already have deployed the policy frameworks and all the remote security aspects from our SASE solution. We're actually seeing SASE lead, firewalls follow in certain cases where we have not had the opportunity to replace hardware in some of our customer situations. There is that cross-product consolidation that is happening from a SASE perspective.
Cloud is very new. I think there's three types of cloud customers. Customers who have either scaled on the cloud and they need a platform solution, their existing solution is not working, which is where we find our sweet spot on Prisma Cloud. There are customers who are still dealing with single cloud. They're actually comfortable with the CSP solutions that are provided. We expect as they get into more complex hybrid cloud environment, we'll see them come adopt the Prisma Cloud platform. Last but not least, is the customers who are still dealing with open source security solutions, which we don't understand why they would do so because you shouldn't use open source solve for security. We think as they get up to maturity curve, they're going to come chase the Prisma Cloud opportunity.
On the Cortex front, I think the consolidation will happen in a more measured fashion as the capability of something like the XDR platform expands, where it can replace other ingestion type-only technologies and other SIEMs which need a whole bunch of overhaul. I think that's a longer 3- 10 years outcome, but that will happen. I think in terms of rank order, network security first and XDR and SIEMs after.
Our next question comes from Yun Kim of Loop Capital with Nehal Chokshi on deck.
Thank you. Another question on Cortex side of the business, especially the SOAR. Very impressive performance metrics on your SOC and SIEM solutions. Just curious on how much of that data that your SIEM solution or SOC operation to SOAR is really analyzing the data from Palo Alto Networks's product versus other security software vendors who may be your competitors, maybe a point solution providers. Also, are you finding any issue getting access to data from non-Palo Alto security products? Just wondering how cooperative everyone is in this security software industry in letting other competing vendors analyze their own data when almost everyone seems to have their own analytics products. Thanks.
Sure. Really the data access, data ingestion is more of an XDR aspect. I'd say with maybe just one or two exceptions, we're able to get access to and work with security vendors and other vendors to easily get access to that data to understand it, be able to ingest it and utilize it. I think that's a motion that the security industry at large understands needs to be done and to some extent is driven by the end customer. End customers are just unwilling to buy products that basically ring-fence their data and won't share it with others because really at the end of the day, they need the right security outcome. On the XSOAR front, maybe if I could, I'll share with you a little bit of just how quickly the ecosystem around XSOAR has increased. About a year ago, we had about 350 playbooks.
These were the automation programs, if you will. About 350 of these in our marketplace for XSOAR. Today we are closing in on 750 of these content packs for playbooks in XSOAR, well over 100 of those were contributed by partners and customers and even in some cases, security competitors that understand that having a playbook optimized for their product in XSOAR is actually good for them. At XSOAR, we continue to drive a very open ecosystem that allows us to automate everything that a customer may have, and make it as good as we can possibly do given the data and the APIs that they have available.
Great. Our next question comes from Nehal Chokshi of Northland Securities with Imtiaz Koujalgi . Next.
Yes. Thank you. I enjoyed Nir's presentation, especially, and I like the way he simplified Zero Trust architecture across the different elements and broke it down into 12 cells here. Is it really necessary to conduct Zero Trust across all 12 cells? Aren't some of these overlapping? Does it just represent basically an unnecessary hit on performance or unnecessary additional costs if you were to do that across all 12?
Which one would you like to not do it on? Sorry, I'm going to have Lee answer the question. The vulnerability is where whichever you don't do it on, you leave yourself open for bad actors to go intercept your business. Lee, did you want to give it a more, much better response than I can?
Well, no. I think that's actually in some ways the right response. The whole point of Zero Trust is you have to remove the implicit trust that is baked into most security architectures. As soon as you ignore one of those boxes in what Nir described, you're basically accepting implied trust. Everywhere that you accept implied trust, you are opening yourself up to risk. I don't believe that there is a performance or scalability trade-off in doing so. Actually, Nir made a very salient point that may not have been immediately recognized when he said, by taking a Zero Trust enterprise approach that he was describing, it actually makes security operations easier, because instead of thinking about all these different aspects as unique use cases that you have to customize for, it actually all effectively becomes a single use case that you simply apply everywhere.
I see scalability benefits to being consistent in your approach to Zero Trust. That's the Zero Trust enterprise sort of architecture view and enablement and thought leadership that we're now going to go drive in the market over the next six, 12 months.
Our next question comes from Imtiaz Koujalgi of Guggenheim , with Pierre Ferragu next.
Hi, guys. Thanks for taking my question. I have a question on the firewall as a platform growth going forward. Regarding to mid-single-digit growth in product, we're seeing a form factor shift towards software, towards SASE. When you combine the product growth of mid-singles and growth and shift towards SASE and software firewalls, what does that mean for firewall as a platform growth going forward? How should we think about that bucket?
Dipak?
Yeah. Imtiaz, thanks a lot for the question. I think, look, we've had very strong results in firewall as a platform, as you know, like strong double-digits with a two handle, as Nikesh mentioned before. There's no reason to assume that won't be the trend going forward. We feel very strong about all the different components, about what we have there, about our software transition. As Nikesh has said, the firewall hardware refresh, people coming back from the pandemic, it's just an addition to what is a trend that we've been seeing for a while. Nothing more.
Great. Thank you.
You guys mute them all.
Our next question comes from Pierre Ferragu of New Street Research, and our last question comes from Shaul Eyal up next.
Thanks for taking my question. It's about Zero Trust security again. When I looked at the presentation of Nir, I thought there might be maybe one dimension missing in the diagram, which is artificial intelligence and machine learning. You're leveraging more and more in that in your architecture, and that creates an area where the question of trust arise again in a different way, which is that you end up having a very rich set of features to protect the infrastructure and applications of your clients. As you process them more and more through machine learning and AI, it creates a trust issue, which that part of the process in some ways remain the black box. Is that something you're looking at and something that is a concern, and you have that in your thinking when you're looking at your architecture?
I'm not sure if I fully understand the concern aspect. What we see is everything that Nir described relative to removing the implicit trust, verifying the identity of the user, verifying the identity of the device, verifying the identity of the application and content, and enforcing policy based on that. From my perspective, where the data AI ML analytics layer in is once we allow a connection, you still need to continuously monitor that connection and make sure that it's still adhering to what you anticipated it was going to look like when you allowed it in the first place.
For example, if I'm connecting to an application, there's a certain assumption about who I am, why I'm accessing the application, why that connection is allowed. Now the data collection AI ML layer that comes in is to then monitor that connection to make sure that it's still behaving the way that was anticipated. To be able to do that at scale across an entire enterprise, and to be able to do that in an automated fashion because obviously that becomes far more data than any human can analyze. We see that as a fundamentally important aspect to a comprehensive approach to Zero Trust, that integrates very nicely with everything associated with the initial sort of Zero Trust access policy enforcement.
Our final question is coming from Shaul Eyal of Cowen. Shaul, you may proceed.
Thank you for squeezing me in. Thanks for providing your profitability guidance and the qualitative commentary around it. Maybe Dipak or Liane, can you talk to us about your organic hiring plans within the timeframe between now and FY 2024, percentage-wise or maybe how many employees you plan on adding within this timeframe, give or take?
Yes, of course I can. As you will have noticed over the last year, we hired a significant number of people and we're now over 10,000 people. By the end of the year, obviously we're unsure about attrition, although it's rather low at the moment as you can imagine. We think we'll be about 12,500 people.
With that, we will conclude the Q&A portion of our event. I will now turn this back over to Nikesh for his closing remarks.
Well, first of all, I want to thank all of you for taking a substantial amount of time in your day to spend with us and listen to our plans over the next few years. Couldn't be more excited about our team, our employees at our company who have done a phenomenal job in getting us here, our customers and our partners who are part of the journey in us trying to be the cybersecurity partner of choice. I also want to thank my team, who worked laboriously and diligently over the last few weeks to try and get us to a place where we are able to share our strategy with you. With that, thank you and I look forward to meeting all you guys in person in the near future.