-+ 0.00%
-+ 0.00%
-+ 0.00%

Palo Alto (PANW.US) Q4 conference call: AI security ARR soared 63%, smart body traffic surged 9 times in nine months, AI wave spawned trillion-dollar opportunities

Zhitongcaijing·09/02/2026 07:17:10
Listen to the news

The Zhitong Finance App learned that the latest performance report released by cybersecurity supergiant Palo Alto Networks (PANW.US) shows that all financial indicators at the Q4 level for fiscal year 2026 surpassed management guidelines. Order volume accelerated for two consecutive quarters. Revenue for the fourth quarter increased 34% year over year to US$3.41 billion, and revenue for the full fiscal year increased 24% to US$11.5 billion; remaining performance obligations (RPO) broke through US$20 billion for the first time, reaching a record high of US$21.2 billion, with a year-on-year increase of 34%, of which the current RPO reached 9.3 billion US dollars The dollar grew 34% year over year. In terms of the 2027 financial outlook that the market is focusing on, the company expects the full-year adjusted earnings per share guide to be $4.16 to $4.19, higher than analysts' average expectations of $4.11. Meanwhile, the company's revenue guidance range for the first fiscal quarter of fiscal year 2027 was 3.3 billion to 3.31 billion US dollars, which also exceeded analysts' expectations of 3.21 billion US dollars.

In the fourth quarter of fiscal year 2026, the next-generation security business annual recurring revenue data (NGS ARR, or AI security ARR) increased 63% to US$9.1 billion, with a net increase of nearly US$1 billion in a single quarter, nearly doubling from the previous year. The full-year business revenue of the three major platforms of network and artificial intelligence security, Cortex and Idira was US$8.35 billion, US$1.92 billion, and US$1.26 billion under the Pro Forma (Pro Forma) financial caliber, up 17%, 25%, and 21% respectively.

Large orders accelerate simultaneously with customer expansion

For the first quarter of fiscal year 2027, the company expects next-generation security annual recurring revenue of 9.54 billion to 9.56 billion US dollars, up 63% year over year; remaining performance obligations are expected to be 20.8 billion to 20.9 billion US dollars, an increase of 34% — 35%; the revenue outlook range is expected to be 3.3 billion to 3.31 billion US dollars, an increase of 33% — 34%; and adjusted non-GAAP diluted earnings per share of $0.96 to 0.98.

For the full fiscal year 2027, the company's next-generation security annual recurring revenue is expected to be $11.075 billion to $11.175 billion, up 22% — 23%; remaining performance obligations are expected to be between $25.2 billion and $25.4 billion, up 19% — 20%; the revenue range is expected to be $14.1 billion to $14.2 billion, up 23% — 24%; operating margin is projected at 29.5%, with non-GAAP diluted earnings per share expected to be $4.16-4.19, and an adjusted free cash flow margin of 38%.

The company added a net of about 220 platform-based projects in the fourth quarter, setting a new company record. The scale was more than double that of when it began disclosing this indicator two years ago; the net revenue retention rate of the platform-based customer base exceeded 120%. The company still plans to achieve more than 4,000 platform-based projects by fiscal year 2030, and thereby support the next generation security annual recurring revenue data of 20 billion US dollars.

Palo Alto management said that the fourth quarter's landmark orders include signing a $126 million agreement with a leading global telecommunications company, a $72 million deal with a major information technology service provider, and signing a $53 million platformization agreement with a global payment platform, which also invested seven digits of dollars in Prisma AIRS.

Platformization not only expands the range of products adopted by a single customer, but also integrates cybersecurity, Cortex, Idira, artificial intelligence security, and observability into a unified architecture, thereby strengthening contract renewals, cross-selling, and customer wallet shares.

Artificial Intelligence Reshaping Cybersecurity Needs: From a “Big Model” to an “Autonomous AI Agent and Open Source Weighting Model”

Management believes that the AI market has experienced three key transitions in the past six months: OpenClaw has pushed enterprises from traditional big language models to autonomous intelligent actions; Mythos proved that deep field training can reduce the speed of vulnerability discovery and utilization from months to minutes; and the rapid spread of open weight and open source models has led to a significant increase in enterprises' proprietary models, internal data, and sovereign AI deployments.

In the future, enterprise employees can simultaneously orchestrate thousands of autonomous agents. Each agent will continuously generate network traffic, telemetry data, and machine identity credentials, thereby greatly expanding the market boundaries of identity security, network defense, cloud security, terminal security, and observability. Palo Alto management predicts that global AI infrastructure capital expenditure in the next five years will exceed the sum of the previous 20 years; during the Q&A session, management further assumed the 5 trillion US dollar AI capital expenditure over the next five years, and also pointed out that the world's cybersecurity technology debt needs to be modernized urgently.

CEO Nikesh Arora (Nikesh Arora) said during the earnings call that the latest developments in the AI field are pushing cybersecurity to the top of the corporate CIO priority list and will be a “lasting tailwind.” He highlighted that the global cybersecurity infrastructure of about $1 trillion is unprepared to deal with AI threats, and this gap will provide the industry with room for long-term growth. “Any system deployed seven to ten years ago was unprepared to respond to AI threats at machine speed, and businesses must rethink their cybersecurity architectures. The world's approximately $1 trillion cybersecurity debt is in urgent need of modernization to counter the threat of automation operating at an instant speed.” CEO Alola said during the performance conference call.

SASE and cybersecurity continue to seize share: smart device traffic increased 9 times in nine months

In fiscal year 2026, network and artificial intelligence security platform business revenue increased 17% to US$8.35 billion; annual recurring revenue for software firewalls increased 29% in the fourth quarter, and demand for fifth-generation hardware equipment was strong. SASE's annual order volume increased 40%, and Access, SD-WAN, and secure browsers all performed well.

The company replaced traditional vendors among nearly 100 customers, and a pre-prepared statement expressed the total contract value as over $400 million. The chief financial officer later confirmed during the Q&A session that this figure was $200 million year-to-date at the end of the third quarter and reached 450 million US dollars for the full year of fiscal year 2026. Palo Alto has risen to second place in the SASE market and plans to become the market leader for the next five to seven years.

At the performance conference call, management emphasized that business traffic associated with AI agents has increased 9 times in the past nine months. At the same time, Palo Alto can block more than 30 billion attacks in a single day with its machine speed detection capabilities refined over 20 years.

Prisma AIRS was officially commercialized for only four quarters, and its annual recurring revenue exceeded 100 million US dollars, making it the fastest expanding product in Palo Alto's history; the number of customers has grown to about 800, and most of the largest transactions use multiple modules. The smart terminal strategy formed after the acquisition of Koi has also been initially verified. The number of related customers has exceeded 100, an increase of 2.5 times compared to when the integration was completed.

XSIAM's annual recurring revenue exceeded $700 million, up 70% year over year, and the number of customers surpassed 1,000; customers using the platform have reduced the average response time from days or weeks to less than 10 minutes. Unit 42 simulated a complete AI-driven attack in less than 30 minutes, while the response time for traditional industry defense reports was about four days.

Since completing the Chronosphere acquisition in the second fiscal quarter, the company's observable annual recurring revenue has more than doubled and surpassed $500 million, far higher than the $85 million at the time of the acquisition. In the fourth quarter, the company signed a $20 million agreement with a high-growth artificial intelligence inference service provider that processes tens of trillions of terms per day; xSIAM cross-selling contributed 50% of Chronosphere's new customers during the quarter, including multiple million-dollar transactions.

Chronosphere is designed for massive telemetry data in the age of artificial intelligence. Management says its total cost of ownership is on average 30% to 40% lower than major traditional observability solutions. After integrating Embrace's real user monitoring capabilities and synthetic monitoring functions, the company expects to develop full competitiveness in the traditional enterprise market within the next six months, and eventually develop observability into a multi-billion dollar annual recurring revenue business. The combined annual recurring revenue of XSIAM and observability businesses has now exceeded 1 billion US dollars.

CyberArk changes its name to iDira: identity security becomes a new pillar of growth in the smart age

Just two quarters after completing the CyberArk acquisition, the related integration and collaboration progress is three to six months ahead of the original plan. Idira's exam preparation revenue for fiscal year 2026 was US$1.26 billion, up 21% year over year; the two sides jointly created more than 400 sales leads and acquired more than 200 new customers from Palo Alto's existing customer base. The number of transactions with a total contract value of more than $5 million in the fourth quarter increased 50% year over year.

Management said the company will drive CyberArk's profit margin increase by more than 1,000 basis points within nine months, and plans to eventually expand it by about 1,100 basis points. The newly launched Modern PAM extends traditional privileged access management to modern environments, and Idira's long-term strategic value is to govern non-human identities and artificial intelligence agents to ensure that every machine operation is authorized, the scope of authority is clear, and fully audited.

The following is the full text of the Palo Alto Networks performance conference call (artificial intelligence tool assisted translation, Palo Alto Networks Chinese translation):

Management presentation session

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

Hello everyone, welcome to Pioneer Network's FY2026 fourth quarter results conference call. I'm Hamza Fordwala, senior vice president of investor relations and strategic finance. Please note that this conference call is being recorded on Tuesday, September 1, 2026 at 1:30 p.m. Pacific time.

Today, I am attending the conference call to discuss the company's fourth fiscal quarter results with Chairman and CEO Niche Arora, and Chief Financial Officer Deepak Golecha. You can find press releases and other information supplementing today's discussions on the company's website at investors.paloaltonetworks.com. After entering the website, please click on the quarterly results link to view supplementary financial information for the fourth quarter of fiscal year 2026 and presentation materials for the fourth quarter results.

In today's conference call, we'll be making forward-looking statements and predictions about the company's business operations, financial performance, and recent acquisitions. These statements made today are subject to a number of risks and uncertainties, which may cause differences between the company's actual performance and these forward-looking statements. Please review our press releases and recent documents submitted to the US Securities and Exchange Commission for an explanation of these risks and uncertainties. We are under no obligation to update any forward-looking statements in today's presentation.

The presentation also included non-GAAP financial measures and key metrics relating to the company's past and anticipated future performance. Non-GAAP financial measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial measures and their reconciliation statements are included in the appendix to the press release and investor presentations. Unless otherwise specified, all results and comparisons are on a year-on-year basis for the fiscal year.

Next, I'll leave the conference call to Niche.

Chairman and CEO Nikish Arora:

Thank you, Hamza. Hello everyone, and thank you all for joining us to discuss the company's progress. As you can see, our execution drove this fiscal year to a record end. Every financial indicator in the fourth quarter surpassed the company's guidelines, and order momentum accelerated for the second consecutive quarter. This performance is directly due to the new record scale of platform-based adoption, and the urgency for customers to reinforce defense systems is increasing at a time when artificial intelligence is fundamentally reshaping the security landscape.

Our remaining performance obligations set a record, breaking the $20 billion mark for the first time, ending the current fiscal year with $21.2 billion, an increase of 34% over the previous year. Next Generation Security Annual Recurring Revenue (AI Security ARR) reached $9.1 billion, an increase of 63% year over year, enabling us to achieve one of the largest annual recurring revenues for Next Generation Security to date that exceeded expectations. Most notably, the net increase in annual recurring revenue for Next-Generation Security alone was close to $1 billion this quarter.

I remember attending Analyst Day for the first time in 2019. When I first joined the company not long ago, we set a lofty goal: to reach $1 billion in next-generation security business revenue by fiscal year 2022; at that time, we were beginning to move from a single-product firewall vendor to a unified security platform. Today, this transformation journey has reached a critical inflection point, and the scale of our current success is a testament to our original vision.

The fourth quarter showed broad momentum across all of our platforms. As the largest business in cybersecurity, it has achieved outstanding results in the fields of SASE and software and hardware firewalls. XSIAM continued its strong momentum, and Prisma AIRS achieved an important milestone: within four quarters of official commercial use, annual recurring revenue surpassed $100 million. This is the fastest expanding product in the history of Pietuo Networks.

The 2026 fiscal year marks a critical inflection point in our transformation journey. We completed two of the largest acquisitions in the company's history, CyberArk and ChronoSphere, both of which surpassed initial expectations. Both businesses have gained significant momentum in our platform-based architecture, and they are expanding faster than during the previous period of independent operation. These results attest to the ability to execute and the deep collaboration demonstrated by the thousands of new colleagues who joined the company over the past year. We look forward to continuing this shared momentum in the 2027 fiscal year.

The fourth quarter was the first time we saw the profound impact of models capable of cyber attacks. As I said before, artificial intelligence is a long-term success for the cybersecurity industry. Although these models are getting better at finding bugs, discovery is just the beginning. To truly verify problems, interpret relevant context, and solve problems, a broad range of cybersecurity platforms and cutting-edge artificial intelligence are required to work collaboratively. This collaboration is critical for environmental stress testing, managing agent behavior, and fixing machine speed when threats occur.

Defending at this speed requires establishing a unified data architecture that allows artificial intelligence to process every signal and reduce response times from days to just a few minutes. Platformization is the only viable strategy to achieve real-time defense and use artificial intelligence against artificial intelligence. In the fourth quarter, this concept continued to resonate strongly with customers.

In the fourth quarter, we achieved a net addition of about 220 platform-based projects, surpassing the previous record. The scale is more than double that of when we started using this indicator two years ago. This performance validates that the concept of real-time defense through a unified architecture continues to gain high acceptance. In addition to initial adoption, using our platform as a standard will also lead to better customer retention and business expansion; in the fourth quarter, the net revenue retention rate of the platform-based customer base exceeded 120%.

Looking ahead, we are still making steady progress towards our long-term goal of more than 4,000 platform-based projects in FY2030, which is the foundation for achieving the $20 billion next-generation security annual recurring revenue target. The largest orders in the fourth quarter showed how platformization was put into practice. In the fourth quarter, we signed an agreement worth $126 million with a leading global telecommunications company. The agency switched to using our cybersecurity platform as a uniform standard, replacing traditional proxy service providers with Prisma Access for SASE while scaling up next-generation firewall deployments.

We also secured a $72 million deal with a leading information technology service provider. The customer has fully adopted platformization in the cybersecurity, Cortex, and Idira sectors, and has invested eight digits of dollars in each field, fully validating the strong momentum of cross-selling in the fourth quarter. Another highlight was a $53 million platform-based transaction with a leading global payments platform. In addition to unifying cyber defenses and architectures to our standards, the customer invested a high seven-digit dollar in Prisma AIRS to accelerate its enterprise artificial intelligence program.

The 2026 fiscal year has become an iconic period in the rapid evolution of artificial intelligence, and the past six months have seen three very different turning points. Every change is fundamentally redefining how artificial intelligence interacts with businesses, and in turn changes its impact on the cybersecurity landscape. To effectively lead and protect customers, we must remain at the forefront of these structural changes.

The first turning point was the advent of OpenClaw. Earlier this year, OpenClaw became a catalyst for moving from traditional big language models to intelligent actions, fundamentally changing the relationship between human operators and artificial intelligence systems. Just a year ago, artificial intelligence was still largely defined by a single human user issuing prompts. It is a type of simultaneous multi-round conversation, where tasks are completed in a closed loop with individual participation. Almost overnight, we saw the emergence of fully autonomous intelligence. These agents are entities that can run continuously for long periods of time and can execute complex workflows without direct supervision.

For employees who could only manage one task at a time, now the same person can orchestrate thousands of autonomous agents. This has a profound impact on businesses. Each agent continuously generates traffic, interacts with models, creates internal data, and communicates with other tools and agents around the clock. This will generate massive amounts of telemetry data that must be observed, and each agent will need to have its own set of credentials. What we now want to protect is a new class of machine identity with autonomous rights. The surge in traffic, data, and identity complexity has brought significant long-term benefits to each of our platforms.

The second turning point was the “Mythos Moment,” which proved that deep domain training can bring artificial intelligence to an unprecedented level of professionalism. In our industry, this is reflected in artificial intelligence being weaponized to identify and exploit vulnerabilities at scale. This change has exposed deep technical debt within companies: legacy flaws and long-term misconfigurations that used to take months for humans to discover can now be exploited within minutes.

In an AI-driven threat landscape, there's no place to hide. For customers, the “Mythos moment” shifts the core of security challenges from visibility to speed. Organizations must now identify risk exposures before they are weaponized and respond at machine speed. Because of this, real-time defense has moved from a project in the future roadmap to a real requirement today.

To address this trend, we expanded our cutting-edge artificial intelligence defense services last month to introduce a multi-modal testing framework that enables businesses to stress test their environments. This service leverages the most advanced cyber attack capability models available; we're also proud to be Mythos 5's first certified commercial partner.

A third turning point is taking shape, and we expect it to dominate cybersecurity industry discussions over the next few quarters. Over the past 90 days, the market has moved from a few cutting-edge models to a diversified ecosystem composed of open weights and open source architectures. Companies are paying more and more attention to sovereign control over their own artificial intelligence, thus promoting the deployment of professional models that are deeply integrated with proprietary data. We expect this trend to accelerate significantly as organizations use internal telemetry data to fine-tune models for customized enterprise use cases.

While cutting-edge models will continue to define the highest standards of intelligence, the broader market is rapidly becoming fragmented and massively dispersed. Crucially, every new deployment adds infrastructure that needs to be hardened, as well as sensitive data that needs to be protected. The attack surface requiring platform-based protection is expanding dramatically. Each of the three critical moments had a unique impact, yet they all point to the same conclusion: as the relationship between humans and artificial intelligence continues to evolve and the number of deployments continues to increase, a unified real-time defense has never been more necessary.

It's still in its early stages, but we're already beginning to see how these trends are impacting the company's business, first reflected in the cybersecurity of our biggest business. Artificial intelligence is a significant long-term tailwind. While expanding the overall potential market for cybersecurity, it also further proves that platformization is the only viable strategy for modern enterprises. As global artificial intelligence construction continues to advance, every new data center will become a critical infrastructure. Whether the firewall is provided natively by a cloud service provider or delivered through a unified security platform, it needs to be reinforced with powerful software and hardware firewalls. The ecosystem driving infrastructure expansion has reached a critical inflection point; currently, we are seeing the emergence of a new generation of buyers composed of sovereign states, new cloud service providers, and cutting-edge laboratories, all competing to deploy huge computing power that must be protected. We made strong early progress with these customers in the 2026 fiscal year, including multiple million-dollar orders in the fourth quarter.

Overall, the execution of the firewall business drove an accelerated increase in order volume this fiscal year, driven by strong demand for the latest fifth-generation hardware and continued momentum for software products as customers expand cloud and artificial intelligence workloads. As such infrastructure matures and autonomous agents are deployed, we expect a significant increase in agent traffic across all network and cloud environments.

This impact is already evident on the SASE platform, where the traffic volume of its smart devices has increased 9 times over the past nine months. Defending at this scale requires detection at machine speed — a core capability we've honed for 20 years, enabling the company to stop more than 30 billion attacks in a single day. Ultimately, artificial intelligence further highlights the urgent need for a unified platform to provide real-time defense.

In the 2026 fiscal year, our platform advantage drove the SASE business to achieve outstanding results. Order volume increased by 40%, and Access, SD-WAN, and secure browsers all performed well. We have successfully replaced traditional market leaders in nearly 100 customers, and the total value of related contracts is over $400 million, nearly double the size of a year ago. Although we have quickly risen to second place in this market, our goal is to win the market and we are on a clear path to becoming the SASE leader for the next five to seven years.

This transformation is still in its early stages, and the future requires a unified architecture that can provide defense at machine speed while protecting human identity and machine identity. The organization is advancing the AI program from the pilot phase to full production, and each new deployment will significantly expand the boundaries that need to be defended. Prisma AIRS continues to adapt its capabilities and evolve along with these adoption cycles to address the unique risks that arise at every stage of the AI development process.

Although we initially focused on the era of generative artificial intelligence centered on chatbots, our vision has now expanded to provide a complete smart security architecture. This unified solution starts with protecting machine identity and credentials, covers deep observability of the agent's activity footprint, and extends to terminals that analyze behavioral intent. By directing this traffic to an artificial intelligence gateway, we can ensure that security policies are enforced in real time with every interaction.

Prisma AIRS achieved an extraordinary milestone in the fourth quarter: after only four quarters of official commercial use, annual recurring revenue surpassed $100 million, making it the fastest expanding product in the company's history. The relevant customer base has expanded to 800; in the fourth quarter, most of our largest deals included the adoption of multiple modules.

Following the acquisition of Koi, our smart terminal strategy was also significantly validated early. As AI development tools migrate to desktop environments, we think the terminal is reaching a critical inflection point. This change expands the attack surface, where agents will autonomously manage files and access sensitive credentials. Traditional safety tools often fail to understand the underlying intentions and reasoning logic behind these machines' speed operations. In this environment, visibility alone and failure to act is far from enough.

Our platform-based approach provides end-to-end transparency from initial prompts to final execution, enabling inline defense and running at machine speed. This ability is becoming a basic requirement for businesses. We've won over 100 customers, a 2.5 times increase from when Koi integration was completed earlier this year.

At the end of the day, when detection and defense are unified into one platform, the two work best together, and XSIAM acts as the central nervous system for this critical telemetry data. Earlier this year, Unit 42 researchers demonstrated the astonishing speed of modern threats by simulating a full-scale AI-driven attack that took less than 30 minutes. In contrast, the response time for industry standard defense reports is four days, and it is clear that traditional methods are no longer sustainable.

Customers using XSIAM as their unifying standard are changing the way they operate, drastically reducing average response times from days or weeks required in the past to less than 10 minutes, and we are still relentlessly advancing true real-time defense. In the fourth quarter, XSIAM continued its outstanding momentum, with annual recurring revenue exceeding US$700 million, an increase of 70% over the previous year, while the number of platform customers surpassed 1,000.

The strength of our architecture is that real-time telemetry data already resides in XSIAM, enabling the company to seamlessly unlock new value through a unified data lake. Expand your deployment without the friction of integrating new products; you can simply query existing data in new ways. As of Q4, most customers have taken advantage of this platform, using multiple modules including risk exposure management and cloud security.

Let's talk about observability. We continue to see the world's top artificial intelligence-native and cloud-first organizations use our technology as a uniform standard. All entities pioneering the frontier of artificial intelligence generate telemetry data on a scale that traditional tools cannot handle. Chronosphere is specifically designed for this massive amount of data, and can capture every training run and every agent cycle. This quarter, we signed a $20 million deal with a rapidly growing artificial intelligence inference service provider that processes tens of trillions of words per day. There's nothing more powerful than the designers of the AI ecosystem trusting us to monitor their own infrastructure and validate our platform.

Since completing the Chronosphere acquisition in the second fiscal quarter, our observable annual recurring revenue has more than doubled, breaking the $500 million mark. This performance significantly exceeded the initial target and was the fastest expansion in the company's history after completion of the acquisition. The cross-selling strategy is bearing real results; through multiple million-dollar agreements, xSIAM contributed 50% to Chronosphere's net new customers this quarter.

We are also further enriching our technology stack through the acquisition of Embrace, integrating real user monitoring capabilities to complement core metrics, logs, and link tracking. This expansion enables the company to provide a complete end-to-end observability platform from core infrastructure coverage to end user experience. Together, XSIAM and observability now contribute more than $1 billion in annual recurring revenue; a remarkable achievement for a data-intensive platform that wasn't included in the product portfolio a few years ago.

One of the cornerstones of the company's success during my time at Pietuo Networks was the ability to identify top technology and world-class talent and integrate them seamlessly into the corporate culture. Although the scale of this year's acquisition naturally increased the complexity of the consolidation effort, the results were outstanding. In the fourth quarter, this success was most evident in the performance of CyberArk — now known as iDira.

Just two quarters after completing our largest acquisition to date, we were able to accelerate growth while achieving synergy effects ahead of schedule; this is a rare achievement that demonstrates the company's ability to integrate engines. These results prove the deep collaboration between us and our new colleagues. From the perspective of market expansion, the joint efforts of the two sides have generated more than 400 shared sales leads and brought in more than 200 net new customers from Pietuo's existing customer base. Customer commitments have also clearly moved to a larger scale, and the number of transactions with a total contract value of more than $5 million in the fourth quarter increased 50% year over year.

However, the most significant challenge and opportunity remains the rise of intelligent artificial intelligence. By definition, an intelligent body has the ability to act autonomously, so it must have a machine identity and the precise context and permissions required to execute a workflow. As companies deploy thousands of such autonomous entities, many of which remain outside of formal governance systems and often lack well-defined areas of authority. This summer sounded the alarm: uncontrolled agents have invaded the environments of several cutting-edge artificial intelligence laboratories.

In one notable case, an agent escaped the sandbox and exploited a system flaw because its access was never properly restricted. Fundamentally speaking, this means that the company is facing a fundamental identity crisis, and this is the strategic mission behind the Idira platform. Idira extends advanced identity security and privilege control to artificial intelligence agents to ensure that every machine operation is authorized, the scope of authority is limited, and fully audited.

By integrating these agent control capabilities with the AI gateway in Prisma AIRS, we're helping organizations execute security policies and maintain defenses in real time. The 2026 fiscal year was a year of transformation for Pioneer Networks and the wider industry. We remain convinced that the artificial intelligence tailwind driving cybersecurity needs will only be further strengthened in the future.

First, the construction of global artificial intelligence infrastructure is attracting trillions of dollars in investment. We expect capital expenditure over the next five years to exceed the previous 20 years combined. This massive expansion was driven by demand that continued to exceed supply. For artificial intelligence to deliver on its promises, the volume of traffic and data must expand; as both grow, every bit needs to be tested, and every byte needs to be observable.

The surge in critical infrastructure is a permanent tailwind for the cybersecurity industry, and the acceleration of cybersecurity and observability business momentum this year already reflects this trend. Second, the industry is strategically shifting to real-time defense. Cyber attacks now run at machine speed, and traditional tools that are fragmented are no longer viable. The world's roughly $1 trillion cybersecurity technology debt must be modernized to protect against automated threats. Since artificial intelligence can act instantly, this modernization must be done on a unified platform. Platformization is the only solution for real-time defense that ensures telemetry data and policies are coordinated at every point of control. We are still in the early stages of this structural transformation.

Third, artificial intelligence has opened up a new cybersecurity market. The rise of autonomous agents will significantly expand the cyber attack surface that needs to be strengthened. Strong artificial intelligence governance and safety barriers have changed from optional features to corporate necessities. Although this market is rapidly evolving, we believe the future belongs to an architecture that provides end-to-end control, and we are fulfilling this vision with Prisma AIRS.

Finally, I do want to mention the latest news: we completed the acquisition of Console today. Console introduces an AI-first approach to product development in the field of information technology and security operations. Andre and his team will join the Cortex business to advance the intelligentization of our capabilities and accelerate our journey into the age of artificial intelligence. I would also like to welcome the Embrace and Console teams to Pietro Networks. Both acquisitions were completed this quarter.

As the company enters the 2027 fiscal year with strong momentum, we know that maintaining our leadership position must be won through strict implementation every quarter. I would like to thank all of our employees for their outstanding performance during this landmark fiscal year, as well as our customers for their unwavering cooperation.

Next, I'll leave the conference call to Deepak.

Executive Vice President and Chief Financial Officer Deepak Golecha:

Thank you, Niche, and good afternoon everyone. Relying on strong performance across platforms and early success in integration efforts, we ended a record fiscal year with strong results. The team strictly enforced it, and every indicator surpassed the guidelines. Before going into details, please note that, where applicable, I will discuss performance according to both reporting and exam preparation standards to provide a standardized comparison of growth. Unless otherwise specified, all growth percentages are year-over-year.

Let's look at revenue-related metrics first. Remaining performance obligations in the fourth quarter surpassed $20 billion for the first time, ending the current fiscal year with $21.2 billion, an increase of 34% over the previous year. In the context of test preparation, the success of the platform-based strategy accelerated the growth rate of order volume for the second consecutive quarter. As contract terms remained stable year over year, short-term remaining performance obligations reached [US$9.3 billion], and similarly [34% increase]. Next-gen security's annual recurring revenue also hit a record, reaching $9.1 billion in the fourth quarter, up 63% year over year. As Nixch emphasized, most notably, the net increase in annual recurring revenue of Next-Gen Security in the fourth quarter was close to $1 billion, almost double the same period last year; this is a milestone that only a few types of technology companies have achieved.

I still remember my first quarter as CFO, the third quarter of FY2021, when the company's total annual recurring revenue for Next Generation Security had just surpassed $970 million. Today, we've added roughly the same amount of revenue in just one quarter. This proves that the company's business has multiple growth drivers. Five years ago, SASE was still in its infancy, and XSIAM hadn't even been launched. Today, these businesses have either surpassed $1 billion in annual recurring revenue or are nearing that threshold.

To further improve the transparency of growth drivers, we will be disclosing the revenue of each platform for the first time in accordance with my forecast for the previous quarter. The three platforms are Cyber and AI Security, Cortex, and Idira. We have provided historical data and product composition of these platforms in the appendices of the performance presentation materials published on the company's website.

Before we dive into the revenue of each platform, please note that the network and artificial intelligence security platform includes the certificate lifecycle management business we acquired with CyberArk, which has since changed its name to Next Generation Trust Security, or NGTS. In fiscal year 2026, NGTS contributed approximately US$85 million to network and artificial intelligence security revenue. Additionally, the revenue for each platform I'm going to discuss does not include some projects such as professional services; as shown in the appendices of the performance presentation materials, these projects are classified as “other”.

Let's first take a look at cyber and artificial intelligence security. The platform's revenue increased 17% to $8.35 billion throughout the 2026 fiscal year. The cybersecurity business continued to achieve double-digit growth above the market, reflecting the company's strong competitive position and the huge market opportunities for the largest platforms in the future. For example, we continue to expand our market share in the SASE sector, where order volume and annual recurring revenue are growing significantly faster than the overall market. The software firewall business accelerated again, with annual recurring revenue growth of 29% in the fourth quarter. Within the first year of official commercial use of Prisma AIRS, annual recurring revenue surpassed $100 million. Finally, the hardware firewall business achieved another strong quarter, driven by customer adoption of the latest fifth-generation devices.

Let's take a look at Cortex, which includes a secure operation and observability platform. FY2026 revenue increased 25% to $1.92 billion. As previously mentioned, xSIAM continues to be a key driver for Cortex, with annual recurring revenue growth of 70% in the fourth quarter. In terms of observability, annual recurring revenue surpassed $500 million and more than doubled since the completion of the Chronosphere acquisition in the second fiscal quarter. Note that, as we indicated last quarter, the net increase in annual recurring revenue in the fourth quarter includes USD 100 million in revenue from the migration of a major big language model customer from their original vendor to Chronosphere.

Finally, there is Idira, which consists of an identity security platform formed after the company completed the acquisition of CyberArk in the early third quarter of fiscal year 2026. As previously mentioned, iDira does not include revenue from the certificate lifecycle management business acquired from CyberArk. According to exam preparation standards, Idira's revenue for the 2026 fiscal year reached US$1.26 billion, an increase of 21% over the previous year. Order volume growth in the fourth quarter surpassed revenue growth, proving the success of early integration and market expansion collaboration.

Overall, fourth-quarter revenue increased 34% to US$3.41 billion; full-year revenue reached US$11.5 billion, up 24% year over year. From a regional perspective, all regions achieved strong growth: the Americas grew 33% year over year; Europe, Middle East, and Africa grew 39%; Japan and Asia Pacific grew 34%.

Keep looking down at the income statement. Total gross margin for the fourth quarter was 74.8%, down 100 basis points year on year; gross margin for the whole year was 75.8%, down 60 basis points year on year. This decline reflects a trend in the revenue structure towards faster growing software-as-a-service products; such products are continuing to expand along with the platform, but have yet to reach mature gross margin levels. Looking ahead, cloud services and software-as-a-service will increasingly account for the majority of revenue, and we expect this structural change will cause cloud hosting costs to grow faster than total revenue in FY2027.

Let's talk about the supply chain. We expect commodity costs in the hardware business to continue to rise, particularly those associated with memory and storage products. It's important to note that while we are satisfied with the strong performance of hardware demand, hardware revenue accounts for only about 10% of the company's total revenue. We continue to manage component cost exposure through strategic supplier relationships and selective pricing adjustments in our hardware product portfolio. At the end of the day, our primary focus remains to optimize the company's overall operating profit and margin, and our fourth quarter and full year results reflect this focus.

Non-GAAP operating margin for the fourth quarter was 29.6%. The full-year operating margin reached 29.2%, an increase of 40 basis points over the previous year. This annual expansion is particularly noteworthy because it includes some of the annual effects of the company's largest acquisitions, and the operating margins of these acquired entities were much lower when operating independently.

We have made excellent progress in this regard. As far as CyberArk's synergy is concerned, the integrated collaboration target is still three to six months ahead of the original plan. Looking ahead to fiscal year 2027, we expect that as the company efficiently expands and realizes merger and acquisition collaborations, the continued release of operating leverage will be sufficient to offset higher sales costs.

The company's focus on operating leverage drove fourth-quarter non-GAAP earnings per share to $1.02, which was $0.04 above the upper limit of the guidance range. Adjusted free cash flow for the fourth quarter reached $1.9 billion — sorry, it was $1.29 billion, up 35% year over year. The adjusted free cash flow for the full year of fiscal year 2026 was US$4.41 billion, and the profit margin on free cash flow was 38.4%, an increase of 40 basis points over the previous year. Thanks to strong free cash flow generation capabilities, we ended fiscal year 2026 with a solid balance sheet, which included a total of $7.9 billion in cash, cash equivalents, and short-term investments.

On a longer time scale, over the past three years, we have proven that the company can achieve lasting and profitable growth. Our execution has contributed to a cumulative increase in operating margins of more than 500 basis points. At the same time, driven by industry-leading R&D investments, we have also expanded our market share in several new categories.

Operating leverage is also directly converted into cash flow. The adjusted free cash flow margin reached 38% or more in each of the past four years. Even as we need to absorb the impact of major mergers and acquisitions, and customers are increasingly shifting from multi-year settlements to annual settlements, we have maintained a strong ability to generate cash flow. This track record of being able to maintain profits during expansion is the cornerstone of the company's financial model. It allows us to offset potential cost resistance while funding the innovation engine; the innovation engine is both the company's ultimate competitive advantage and the catalyst for customers to begin the platformization process.

Looking ahead, our visibility into free cash flow continues to increase, driven by the steady expansion of operating margins and the smooth shift of our core business to deferred settlement or annual settlement. To provide some context: Annual settlement's share of order value rose sharply from 6% in FY2020 to 27% in FY2025. At present, growth has stabilized; in the 2026 fiscal year, the share of annual settlements increased by only a few percentage points lower than the previous year, reaching about 30% of the total order amount. With this structural transformation now basically stable, the company will have a highly predictable cash flow engine that can continue to grow compounded in the future. This cash flow visibility, combined with our continued focus on margin expansion and sustained double-digit order volume growth, further strengthened the company's confidence in achieving the FY2028 free cash flow margin target of 40%.

Before introducing the guidelines, I'd like to take a step back and explain the growth opportunities ahead. As I said before, years of industry-leading R&D investment have fueled the company's innovation engine and expanded market opportunities into new business categories. Continued investment has earned us recognition from leaders in almost every major category of participation. The company began as a standalone firewall business, but has now grown into a platform with multiple billion dollar annual recurring revenue businesses, and several other businesses are close to this milestone.

Facing a total potential market of $340 billion by 2030, our current penetration rate is still low. We believe artificial intelligence will only expand the company's market opportunities while further strengthening the need for platform-based and real-time cyber defense. This puts us on track to reach our goal of $20 billion in annual recurring revenue for next-generation security in fiscal year 2030.

Under this long-term framework, the guidance for the first quarter and full year of fiscal year 2027 is presented below. Please note that the recently completed acquisitions of Console and Embrace have no material impact on the FY 2027 guidance. For the first quarter of fiscal year 2027 — the first quarter of fiscal year 2027, we expect the next generation safety annual recurring revenue of 9.54 billion to 9.56 billion US dollars, up 63% year over year; remaining performance obligations of 20.8 billion to 20.9 billion US dollars, up 34% to 35% year over year; revenue of 3.3 billion to 3.31 billion US dollars, up 33% to 34% year over year; fully diluted shares of 837 million to 844 million shares; non-GAAP diluted earnings per share are expected to be $0.96 to 0.98.

For the full fiscal year 2027, we expect the next generation security to have annual recurring revenue of $11.075 billion to $11.175 billion, up 22% to 23%; remaining performance obligations of $25.2 billion to $25.4 billion, up 19% to 20% year over year; and revenue of $14.1 billion to $14.2 billion, up 23% to 24% year over year. Operating margin guidance is 29.5%, non-GAAP diluted earnings per share are estimated at $416 to $4.19, fully diluted shares are expected to be between 844 million and 847 million shares, and the adjusted free cash flow margin is expected to be 38%.

We've listed commonly provided modeling points in the appendix to the presentation materials for your reference, but I'd like to point out a few things in particular. First, as previously mentioned, the net increase in annual recurring revenue for Next-Generation Security in FY2026 includes the billion dollar revenue generated by the migration of a major big language model customer from their original supplier to Chronosphere. Our outlook assumes that the end of this migration will continue into the first quarter of fiscal year 2027, and that the net additional annual recurring revenue contributed by this migration will be lower than the fourth quarter. This will affect the seasonal distribution of net additional recurring revenue for the next generation security year in FY2027, making the first quarter larger than normal. We anticipate that 60% to 61% of the net increase in annual recurring revenue for Next-Generation Security in fiscal 2027 will be concentrated in the second half of the year.

Second, although we do not intend to provide revenue guidance by platform, we are currently providing initial modeling points to help you establish revenue growth trajectories for each platform within the framework of the company's overall guidelines. For the 2027 fiscal year, we expect network and artificial intelligence security revenue to achieve low double-digit year-on-year growth; Cortex's revenue to increase by about 30% year over year; and Idira's revenue to be around US$1.5 billion, achieving a year-on-year increase of nearly 20% to 20% year over year under exam preparation.

Next, I'll return the conference call to Hamza and move on to the question and answer session.

Q&A session (AI-assisted summary and translation):

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

OK, thank you, Deepak. [Operator's note] The first question came from Rob Owens of Piper Sandler (Piper Sandler), followed by Brian Essex of J.P. Morgan Chase.

Robbie Owens, Piper Sandler Research Department:

Very nice, thank you Hamza. Nikish, in your prepared statement, you mentioned the many good things the company is currently seeing in the field of cybersecurity. I think the strong order performance also proves this; you also mentioned that the growth rate accelerated for the second consecutive quarter. However, the performance in the overall market environment is uneven, and clearly, manufacturers with scale and broad product coverage capabilities have played an important role here.

So as we look ahead to the new fiscal year, how are you considering mergers and acquisitions? Given how rapidly the market is changing, how can you consider another deal that could be transformative for Pietuo Networks? Given what you've done in the past and your ability to take advantage of market changes, what future actions are you considering?

Chairman and CEO Nikish Arora:

Rob, thanks for the question. For the sake of simplicity, I'll just send you the names of those companies so I don't have to answer this question in such detail — you should thank me, right? As I've always insisted, mergers and acquisitions are not a strategy; mergers and acquisitions are the result of everything we do from a product development perspective.

For example, if you—I just talked about the three major shifts that have taken place in the field of artificial intelligence in the past seven months. Everyone has seen the market move from a big language model to an intelligent entity, and now it's moving towards an open weighting model. Every technology shift on the customer side clearly requires a slightly different security architecture. How can these agents be protected? How do you ensure that the open weighting model is protected and that agents don't get out of control?

Obviously, we have our own internal views, and we are building in this direction from a product development perspective. But sometimes you might be caught off guard because the company originally followed one path, but the market suddenly turned elsewhere. We had the opportunity to look at the overall cybersecurity landscape and see that 450 companies in this category have already received financing. Afterwards, you may suddenly realize that another company has found the right strategy, and this is the moment we step in and implement the acquisition.

Therefore, the acquisition was carried out because these companies have correctly grasped technology trends; we would rather quickly accept their direction and enter this field so that customers can quickly acquire corresponding capabilities. Frankly speaking, as you've seen after Mythos, customers are willing to try out a large number of AI deployments, but before actually deploying, they want to make sure they have a robust security testing framework around them. The questions we hear most often include what should I do about the bugs Mythos will find in my environment? How should it be solved today, and how should it be continuously tracked over the long term? Or what happens if we deploy an agent and then the agent gets out of control? How can we ensure that our smart body doesn't run onto the Hugging Face by itself?

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

OK, thank you, Rob.

Chairman and CEO Nikish Arora:

I'll remember your request; as soon as I buy that company, I'll send you the name of the company.

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

OK, thanks for the question Rob. Next is Brian Essex of J.P. Morgan Chase, followed by Sakit Carya of Barclays.

Brian Essex, J.P. Morgan Chase Research Department:

Nikish, it's great to see CyberArk's performance accelerate. Currently, we have received only about 200 net new customers from Pietuo's existing customer base. I'd love to know exactly what these customer conversations are like? How large are these deals compared to other transactions on the CyberArk platform?

Also, you still have a sizable existing customer base. I think a lot of people focus on cost synergy while ignoring revenue synergy. How high do you think the CyberArk platform can reach in Pietuo's existing customer base?

Chairman and CEO Nikish Arora:

I'm really excited about CyberArk. I think if you look at it from both sides, as you accurately pointed out, we really quickly got to the point. In terms of cost coordination, everyone has seen that in just about two quarters, our profit margins are returning to the same level as when operating independently. We believe profit margins will stabilize as we enter the next quarter.

So being able to transform a large company like CyberArk in nine months and increase its profit margin by 1,000 basis points or more is already an excellent job at the cost level. But as you said, we didn't buy it because of cost synergy. We implemented the acquisition because we believed that the market needed identity security, and this was an inflection point.

From our perspective, the first stage is not to disrupt the existing business and accelerate its growth momentum. As you've seen, we've successfully done this. Last quarter, we just hired our new leader, Sonny Singh. He is currently attending our sales conference in Asia to cheer up the CyberArk team. The team successfully integrated into the Pietuo network. I think the collaboration between the two teams is excellent, and I am very excited. We've just launched a new product called Modern PAM. CyberArk used to be in the traditional privileged access management business, but Modern PAM is an extended category of privileged access management, an area where the company hasn't invested much time before. The product team at CyberArk — or iDira as it should now be called — was able to embrace this direction, and did a fantastic job. The product is now fully marketed. We plan to try upgrading all existing traditional privileged access management customers to this product.

So, whether it's upselling and business expansion, or net new sales, we're doing a lot of work. As long as the business grows faster than when CyberArk previously operated independently and increases profit margins by [1,100] basis points, I think this would be an excellent acquisition for us; not to mention that the company is also in a leading position to help companies manage non-human identities and intelligence in the future, as it is a brand new field that has yet to form established leaders.

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

Thank you, Brian. Next up was Sakit Kalya of Barclays, followed by Fatima Blarney of Citi.

Sakit Kalya, Barclays Research Department:

The end of the fiscal year was excellent. Nikesh, this question might be for you. You said Mythos wasn't a brief moment; it was just the beginning. So my question is: As AI threats become the new normal, how are you seeing customer buying behavior change? Specifically, are customers more willing to adopt platformization? Has the sales pipeline grown more than expected? Are customers more appreciative of value and less sensitive to price? I'm just wondering if you can explain this new beginning in conjunction with some of the trading developments we've seen this quarter and the past few quarters?

Chairman and CEO Nikish Arora:

Make sure to have the candy delivered to Hamza's home a week in advance, otherwise you won't be able to get the first questioning seat later. Regarding business momentum, indeed, I said Mythos was just the beginning. I've been trying to get CEOs' attention to cybersecurity for the past eight years, but I haven't been able to; but Dario has done an extraordinary job with Mythos. Because now every CEO wants to discuss: What does this mean for us? How do we get permission to use it? How do you test yourself from a vulnerability perspective?

They are smart, though. They sit down and say, “Listen, I understand this is the new normal. People will be able to find bugs faster, so how can I fix this for the long term? This is where the conversation really begins. The only long-term solution to this problem is: if certain threats break through borders, they must be quickly discovered and shut down. This involves modernizing cybersecurity assets, platforming, and establishing a security operation center driven by artificial intelligence.

That's why we've been able to have so many discussions about infrastructure modernization. Each discussion is not about further dividing a customer's technology assets or buying more products from smaller vendors, but rather about finding an integrated way to use a platform as a uniform standard and evaluate it. I think this is a huge success for the big players in the industry. Obviously, some startups will launch unique or niche products that can enter the market faster, and customers will also use these products during the transition period. But I think this is definitely a long-term change; it can be said that it will change the duration and trajectory of growth.

Because if you think about it carefully, the open source model can now compete with Mythos' abilities, and this ability will only get stronger, not weaker. If this happens and corresponding capabilities become common, we only have a short window to make up the cybersecurity technology debt that has been accumulated over many years and has not been repaid, so that our defense capabilities can reach the proper level. I suspect there will be some major security incidents in the next few years, as customers still have time to complete the transformation. Overall, this will be a good start for all of our businesses in this field.

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

Thank you, Sackett. Next is Citi's Fatima Blarney, followed by Royal Bank of Canada's Matt Herdberg.

Fatima Blarney, Citigroup Research Department:

Nikish, you mentioned the concept of technical debt. So I'd like to take a step back and ask a question in connection with the “Frontier Artificial Intelligence Key Defense” you announced earlier this week or a few weeks ago. We haven't necessarily heard you discuss the concept of operational technology in detail, and the implications that this application scenario may reach a critical scale, particularly in the context of the company's own platformization strategy.

Now, we know that the model can implement extremely powerful vulnerability chains for parts of the technology environment that have been underinvested for a long time and have also accumulated large amounts of technical debt. So, what constraints does the company face in further speeding up the acquisition of customer wallet shares? Related to this, how will the continuous relationship between the company and some of its cutting-edge laboratory partners, from cooperation to competition, be reflected in operational technology, a market opportunity that seems perfect for further penetration?

Chairman and CEO Nikish Arora:

Fatima, there are a lot of questions in this. First, I think nine months ago, all companies in the cybersecurity and software industry were convicted, or even almost condemned to death, because cutting-edge artificial intelligence would eat all of our breakfasts, lunches, and dinners. Obviously, the past six to nine months have proven that this is not going to happen. We will enjoy this feast together.

In terms of cooperation, we've seen OpenAI, Anthropic, and even Google all sit at the negotiation table. We can use these models ahead of time, test them, and test their cybersecurity capabilities. As I said in my prepared statement, we were — or are currently — the first commercial partner to be approved to include Mythos in a testing framework. We are already using OpenAI 5.6 in our testing framework and are able to provide customers with multiple models.

Because customers will soon be disappointed with the idea of “finding more bugs.” What they really want to know is what they should do about these vulnerabilities themselves. The last thing they want is more security issues, because there are enough existing ones. So the conversation quickly turned to: How should I resolve these issues? And it is in this kind of discussion that the platform requirements I mentioned earlier arise.

Specifically, when it comes to operational technology, I think the challenge is even more prominent because operational technology is difficult to patch. Even if you find a bug in an example or deployment of an operational technology, imagine how to repair an oil rig far offshore, or how to fix a large amount of technical equipment that can't be remotely accessed or remotely updated—you have to go to the site to repair it yourself. The good news is — Lee isn't here this week, so now it's up to me to play Lee. We've actually built the ability to signature and deploy operational technology bugs and open source vulnerabilities in less than four hours. In other words, we can uncover open source bugs or operational technology flaws, deploy fixes within four hours, and then propagate them to software and hardware firewalls to stop malicious actors on the spot. This is in stark contrast to the current 55-day industry standard — open source bugs or operational technology vulnerabilities in real-world environments usually take 55 days to be patched. This capability will enable customers to block malicious actors exploiting any network-related operational technology or open source vulnerabilities in less than four hours.

So, you're asking what the constraints are, is a good question. The real constraint is that customers need to take time to understand what major changes they must implement, carry out proof of concepts, assess the current state of the environment, and think about which vendors they want to deploy before finally entering the deployment phase. This isn't something that customers will do right away — they'll take time to gradually move forward with the deployment. Therefore, I think this is a long-term success, and everyone will begin to see that the industry continues to perform more than expected on a quarterly basis. But it won't generate the kind of annual recurring revenue we've seen in the field of artificial intelligence—I'm really envious of that, but it's true.

Fatima Blarney, Citigroup Research Department:

This is a nice Li style answer, but [sideburns don't work - Lee style sideburns].

Chairman and CEO Nikish Arora:

Hmm, that's easy to fix.

Hamza Fordwala:

OK, thanks for the question Fatima. Next was Matt Herdberg of Royal Bank of Canada, followed by Michael Thurin of Wells Fargo.

Matthew Herdberg, Capital Markets Research Department, Royal Bank of Canada:

Nikish, you have long held on to your vision of being the number one supplier in a category. I mean, you won't enter a market unless you think you can be a market share leader. So, putting on Lee's hat once again, you've clearly achieved a great deal of success in the field of observability. On the basis of an independent Chronosphere, you added Embrace — synthetic monitoring, or you developed synthetic monitoring. From a functional perspective, where do you currently stand compared to some of the longstanding market leaders in this field? How much of this opportunity comes from a shift in market share, and how much is simply due to artificial intelligence driving the market itself to expand, and you believe you can get the largest share of it?

Chairman and CEO Nikish Arora:

The basic premise of Chronosphere is that it is a brand-new technology designed specifically for the age of artificial intelligence. Chronosphere's design logic is: given that the field of observability is generating massive amounts of data, its architecture allows customers to obtain a lower total cost of ownership. As a result, Chronosphere costs an average of 30% to 40% less than any major traditional observability solution on the market.

From a functional parity perspective, we were initially very good at meeting the needs of AI native environments for link tracking, logs, and metrics. As a result, most of Chronosphere's customers are native AI customers, including a very large cutting-edge AI lab. By integrating Embrace and developing synthetic monitoring functions, we will reach the same level as some market leaders in terms of cross-functional capabilities, thus being able to enter the traditional enterprise market. This will also enable all Pioneer Network sales staff to start selling Chronosphere. Currently, we are still limiting sales of Chronosphere to AI native customers because it is more applicable in this field. But I expect that in the next six months, we will reach a stage where Chronosphere will be a competitive product in its category compared to other traditional enterprise market players.

At that time, we will have both AI priority capabilities and cost advantages. As the field matures, I am very excited that these advantages should eventually enable Chronosphere to grow into a multi-billion dollar business with annual recurring revenue. When we bought it, it had annual recurring revenue of $85 million; it has now surpassed $500 million. We can clearly see that this business will continue to expand in the next few quarters and is expected to further cover traditional enterprise markets. Remember, to achieve our vision of becoming a larger enterprise, we need to have multiple multi-billion dollar annual recurring revenue businesses. Observability has such a total potential market, security information and event management has such a total potential market, and the cybersecurity and identity business clearly has a total potential market of a similar scale.

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

Thank you, Matt. Next up was Wells Fargo's Michael Turin, followed by BTIG's Grey Powell.

Michael Turin, Wells Fargo Securities Research Department:

The end of the fiscal year was excellent. Regarding the initial 2027 guidance, I would like to know how to carry out this forecasting work in a context where the entire cybersecurity industry is forming an inflection point? You mentioned that the company has seen three major AI transitions, and discussions across the industry about the 2027 cybersecurity budget are still in the early stages. So can you explain the benchmark assumptions used in the guidance, and which key drivers we should also focus on that could lead to upside?

Chairman and CEO Nikish Arora:

Michael, we are very careful in formulating the guidelines. We review the level of consistent market expectations, ensure that we evaluate the underlying operating plans of each business, and determine whether the company can meet, exceed, or significantly exceed your agreed expectations. We are pleased to see that, with corresponding execution and good luck in the industry, the company is expected to exceed your agreed expectations, and this is how we have developed our guidelines.

Michael Turin, Wells Fargo Securities Research Department:

Very clear. We're looking forward to seeing the results.

Executive Vice President and Chief Financial Officer Deepak Golecha:

Yes. Michael, we're really going to look at a lot of different input factors. As we look at various trends, we look at how the sales pipeline has changed, whether it is gaining momentum, and what trends are emerging in some new areas. We absorb all of this information to assess resource requirements; this also involves sales area planning and many other matters. In fact, that's how we set our guidelines.

It's a highly mature, world-class process. Not much has changed from a process perspective during my time as Chief Financial Officer for the past five or six years. I think we've always maintained a high level of transparency and have been able to include several key inflection points in our forecasting criteria.

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

Thank you, Michael. Next up is BTIG's Grey Powell, followed by Morgan Stanley's Mehta Marshall.

BTIG Research Division Grey Powell:

Very good, congratulations to the company for such strong results. I just wanted to make sure I understood a piece of data correctly. I think you mentioned last quarter that the value of SASE contracts obtained through competitive replacement over the past nine months was $200 million. This quarter, that figure jumped to $450 million. So I'd like to confirm if these two figures are comparable? If comparable, the fourth quarter's performance was really strong. Either way, the numbers are impressive. What is the driving force behind the increase in the speed of SASE replacement and the overall improvement in performance compared to peers?

Chairman and CEO Nikish Arora:

Grey, if I remember correctly, that figure should be $400 million. Is it $450 million? OK, $450 million. Very good. Obviously, we performed well in the fourth quarter, which is clearly reflected in the financial data. So yeah, the fourth quarter did perform well.

The replacement of the SASE business was the result of a combination of two events. First, when the SASE category first appeared, it was largely an Internet-driven phenomenon, mainly driven by demand for Internet access. But the COVID-19 pandemic changed everything. After the outbreak of the pandemic, people wanted to continue to have private network access and internet access at the same time, and private access is our traditional area of strength. Obviously, at present, our product capabilities in the field of Internet access have reached, or even far surpassed, existing competitors.

What really worked was the integration of SASE and SD-WAN, and we moved in that direction early on. We were the first vendor to acquire CloudGenix and integrate it into the SASE architecture. Since our SASE architecture is consistent with the hardware and software firewall architecture, customers using Pietuo Network Firewall will naturally switch to our SASE solution rather than choosing another vendor. Furthermore, if customers want to consolidate vendors and adopt a single platform, this will also make the choice easier because they are already using our console, Strata Cloud Manager, and related services in hardware and software firewall application scenarios. Therefore, further adoption of our SASE won't seem like a huge shift. In many cases, our terminal agents have already been deployed in customer environments; agents used in the past for virtual private network products are now unified SASE agents.

As a result, we have actually surrounded existing SASE vendors with a complete platform. If the customer chooses to replace the SASE part, using our platform as a uniform standard is an easier choice since other components already use our products. Sometimes this is the reason, and sometimes simply because customers want to modernize their SASE infrastructure.

Executive Vice President and Chief Financial Officer Deepak Golecha:

Further clarification: in the third quarter, the year-to-date figure was $200 million; for the full year of fiscal year 2026, it was $450 million.

BTIG Research Division Grey Powell:

OK, so that means the fourth quarter actually contributed a pretty big figure. Thanks, those explanations are all very reasonable.

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

OK, next up is Morgan Stanley's Mehta Marshall. The final question will come from Brad Zelnick of Deutsche Bank.

Mehta Marshall, Morgan Stanley Research Department:

Very nice. Nikish, you just talked about settling the $1 trillion technology debt. Platforms can help businesses repay these technical debts in certain ways. However, judging from professional services, investments, or other methods that can help customers resolve technical debts faster in a reduced time, how do you think about this issue?

Chairman and CEO Nikish Arora:

Meta, as you know, when we launched our platformization strategy a few years ago, we already established a very clear model in the market: companies were willing to accept installments, coordinate customer contract terms, or deploy ahead of time before existing suppliers had to be replaced to speed up the platformization process. We make all of these arrangements available to our customers.

Frankly speaking, the constant limitation is that the customer's work schedule is already full. They are advancing a range of things they want to accomplish within the company. Today, in the context of artificial intelligence, there are many AI transformation jobs in the market. Companies want to transform customer support, actively promote programming applications, and deploy big language models. Therefore, cybersecurity modernization is another focus that must be managed within an overall framework of priorities.

Therefore, customers always need to strike a balance. That's why they don't go out of their way to say “replace everything tomorrow.” They'll sit back and develop a more coherent and intelligent transformation plan. If a transformation plan takes five years, that's too long and must be completed sooner.

As a result, the final typical cycle is usually one to three years, but this isn't something that can be done in a quarter. Customers want to advance first, then move forward gradually. They want to complete the work when another vendor's product reaches the end of its life cycle or when the contract is about to be renewed. All I can say is that if products from large manufacturers meet or exceed the most advanced level in the market, the trend of customers wanting to use them as a uniform standard or implement platformization is becoming more and more obvious; overall, this is beneficial to us.

Hamza Fordwala, Senior Vice President of Investor Relations and Strategic Finance:

Thank you, Mehta. Last but not least, Brad Zelnick of Deutsche Bank.

Brad Zelnick, Deutsche Bank Research Department:

Very nice, thank you very much, Hamza. Glad to meet you all. Nikish, you have now established a strong reputation in mergers and acquisitions. Today's acquisition of Console also appears to be in line with the direction of further moving towards autonomous secure operations. Of course, I could simply ask why they bought Console; but let's say that after five years, Pioneer Networks has far surpassed your most optimistic expectations, and what is the most valuable activity that customers will completely stop doing on their own, because Pietuo Network is already completing this work for them?

Chairman and CEO Nikish Arora:

That's a great question, Brad. I now understand why Hamza kept you last. If AI capital expenditure reaches 5 trillion US dollars in the next five years, then Pioneer Networks is based on the premise that artificial intelligence will create great value in the enterprise sector. Otherwise, there is no point in investing $5 trillion in related construction.

Therefore, I am an optimist and believe that we will use artificial intelligence to complete a large number of intelligent tasks. If this judgment holds true, cybersecurity operations must reduce manual operations and increase the degree of automation, and let us take on more work rather than continue to be done by customers themselves, because malicious actors also use artificial intelligence. This means we must ensure that customers can be intelligentized like bad actors. Obviously, this cannot be achieved without the right data. As we have seen in various industries, to effectively deploy artificial intelligence, we must have the right data; we need to establish an appropriate data foundation, and we must break down information silos.

Therefore, it is necessary to form a unified and coherent data lake, whether it is an enterprise information technology data lake, an observable data lake, or a secure data lake. From a strategic perspective, our transformation direction over the past few years shows that Pietuo Network has become a data-first enterprise. We absorb data through XDR; the security information and event management platform currently processes 19 terabytes of data per day, and the number of customers already exceeds 1,000. We also have observability data, including data from a leading language model lab; the lab's data is being connected to the platform to achieve observability.

We're becoming a data-first, artificial intelligence-first cybersecurity company. The company's vision is to reduce manual intervention in the cybersecurity field from detection, prevention to disposal. This is our “North Star.” The next question is how to achieve this goal, and the company is fully advancing in this direction.

Looking ahead to five years, if Pietuo Networks succeeds far beyond the most optimistic expectations, we can say to customers, “Let's replace a product.” The company's intelligence can complete the relevant workflow: understand the customer environment and complete the OLF exchange in less than a week. The number of personnel required for customers will also be reduced; our products can automate policy configuration and deployment, and customers are mainly responsible for review and confirmation without having to personally handle execution details. This is because we have accumulated relevant experience in a large number of customer environments and are able to apply this knowledge to new deployments.

Currently, when facing every new customer, traditional enterprise products look like a new product with no experience, even if it has served a large number of customers before. Artificial intelligence enables products to learn from different customers and athy deployments. As a result, the product will be smarter when it comes to serving the next customer. That's our vision.

Hamza Fordwala:

I would like to take this opportunity to thank everyone once again for attending this conference and thank our customers, shareholders, and all employees; fiscal year 2026 was an extraordinary year for everyone at Pietuo Network.