Sales Plays

Better Together
Bundles

Cross-platform sales plays that combine multiple PAN products for maximum customer value and competitive displacement.

10 Combined Plays

Cross-Platform Sales Plays

Each bundle combines products that are stronger together — solving customer problems that no single product addresses alone.

VPN Modernization
GlobalProtect Prisma Access Prisma Browser

Legacy VPN creates performance bottlenecks, backhauling traffic to data centers. No ZTNA 2.0 continuous inspection. Unmanaged/BYOD devices lack security controls at the browser layer.

Same GP agent transitions to Prisma Access 6.2 cloud delivery — no new client software, and GlobalProtect is not retired (this is a migration to the Prisma Access Agent, not an EOL). Prisma Browser extends protection to unmanaged/BYOD devices. Only enterprise browser natively integrated with SASE — and, as of PAN-OS 12.2, identified natively by the NGFW.

Eliminate DC backhauling ADEM experience scoring Per-app ZTNA access
Zscaler ZPA Island Browser Cisco AnyConnect
GP VPN customers with on-prem gateways. Organizations with BYOD/contractor workforce. Heavy SaaS adoption causing latency complaints.
Management Modernization
PA-Series Refresh SCM Pro Strata Copilot

Aging PA-Series approaching end of support — PA-7000 Series went end-of-sale Dec 31, 2025, PA-5450 goes end-of-sale Nov 22, 2026, and the K2-Series reached end-of-life Feb 28, 2026. Panorama on-prem hardware is expensive to maintain. No AI-driven posture assessment. No unified visibility across firewalls + SASE + SD-WAN.

New hardware on PAN-OS 12.2 "Ceres" provides quantum readiness (Quantum-Safe Security GA Jan 30, 2026; PQC now extends to GlobalProtect). SCM replaces Panorama with cloud-native management + Strata Copilot AI assistant and six AI Network Security Agents. SCM shipped Panorama-migration tooling mid-2026. SCM has exactly two tiers — Essentials (free) and Pro (paid) — and SCM Pro is bundled into the ESA via a single auth code.

174% ROI (Forrester) 229% SCM ROI 65% fewer manual investigations 80% faster deployment
Fortinet refresh play Check Point migration
PA-3000/5000/7000 customers at EoL; PA-5450 owners facing the Nov 22, 2026 end-of-sale (replacement: PA-5500 Series). Panorama customers on M-Series hardware — Panorama has no EOL, but multi-tenancy closed to greenfield Apr 15, 2026. Organizations preparing for post-quantum cryptography.
SOC Transformation
Cortex XDR Cortex XSIAM

XDR provides endpoint detection but SOC still manages separate SIEM and SOAR. Alert fatigue from multiple consoles. Legacy SIEM (Splunk) is expensive at scale.

XSIAM 3.6 is a superset of XDR 5.2 — existing agents and data upgrade directly. No new agent deployment. Adds SIEM + SOAR, with ASM, Exposure Management and ITDR 2.0 available as modules. XSIAM Professional Assistant maps Splunk rules automatically. Tiers are NG-SIEM, Enterprise and Premium (Enterprise Plus is retired).

98% MTTR reduction 85% auto-resolved 75% less manual work 30–50% cost reduction
Splunk Enterprise Security Microsoft Sentinel CrowdStrike NG SIEM
Existing Cortex XDR customers with Splunk/Sentinel SIEM. SOC teams with 3+ analysts. 5,000+ endpoints. Customers approaching Splunk renewal. Reference scale: 740 XSIAM customers, >$600M ARR, >17 PB/day ingested.
Endpoint + Browser Protection
Cortex XDR Prisma Browser

EDR protects the OS but has limited visibility into in-browser activity. 70–80% of credential theft begins in browser sessions. Phishing attacks increasingly happen entirely in-browser with no file download (no EDR signal).

XDR secures the OS layer; Prisma Browser secures the browser layer. This is now a shipping product integration, not a roadmap story: Prisma Browser native integration with Cortex XDR and XSIAM shipped with XDR 5.2 (Jul 20, 2026), so browser telemetry lands in the Cortex data lake and XSIAM correlates endpoint + browser events into unified incidents. PAN-OS 12.2 adds NGFW-native Prisma Browser identification. Covers managed + unmanaged devices, and Agentic Endpoint Security (AES) is integral to the 5.2 agent with zero additional deployment.

Native XDR 5.2 integration Eliminates browser blind spot 1,000+ data classifiers Blocks malicious extensions
Island Browser CrowdStrike (no browser) Zscaler RBI
Financial services, healthcare, legal. Significant BYOD/contractor access. Enterprises targeted by phishing campaigns. Existing XDR customers adding zero-trust browser controls.
Network + SOC Convergence
Prisma SASE Cortex XSIAM

Network security and SOC operate in silos. SASE detections must be manually exported to SIEM. ADEM user experience data is isolated from security investigations.

Prisma SASE natively sends telemetry to the Cortex XDL 2.0 data lake (15+ PB/day across 1,100+ integrations). XSIAM's ML models run across both endpoint AND network telemetry. If XSIAM detects a compromised user, it triggers Prisma Access to revoke the ZTNA session automatically. Enhanced Application Log (EAL) ingestion became free in XSIAM 3.5, cutting Prisma SASE ingestion cost ~10–15%.

30% TCO reduction 15–20% SIEM storage savings Automated cross-layer response
Zscaler + Splunk Zscaler + CrowdStrike
Organizations replacing both SASE and SIEM. 2,000+ remote workers + mature SOC. Dissatisfied with Zscaler + Splunk total cost. Financial services/healthcare with 24x7 SOC.
Cloud Security + Observability
Cortex Cloud 2.2 Chronosphere Telemetry Pipeline

Security and SRE teams use separate tools (CNAPP vs. Datadog/Dynatrace) for the same cloud environment. Datadog's opaque pricing creates unpredictable costs. High-cardinality AI/ML metrics overwhelm legacy monitoring.

Chronosphere Telemetry Pipeline routes telemetry to both observability AND security from a single collection layer, and is natively integrated with Cortex XDL 2.0. Security anomalies gain application performance context. 30%+ data volume reduction before XSIAM ingestion. Cortex Cloud 2.2 covers the four current modules — Application Security, Cloud Posture Security, Cloud Runtime Security, Security Operations. Naming discipline: the brand is Chronosphere (acquisition closed Jan 29, 2026, >$300M ARR); there is no product called "Cortex Observability", and the deeper Cortex AgentiX tie-in is not yet GA.

30–50% lower observability cost 30%+ data reduction 20x less infrastructure
Datadog Splunk Observability Dynatrace
Kubernetes-heavy organizations. $500K+/year Datadog spend. AI/ML-intensive workloads. Existing XSIAM customers looking to reduce ingest costs.
Network Security + SOC
Strata NGFW Cortex XSIAM Strata Logging Service

Firewall logs are the richest network telemetry but SIEMs receive aggregated data, losing context. Threat hunting requires correlation of firewall + endpoint + identity. SOAR can't trigger firewall changes without custom scripting.

Strata Logging Service feeds XSIAM natively — full-fidelity firewall logs in real time, no ETL. XSIAM playbooks push dynamic block lists back to the NGFW. Threat detected at endpoint → blocked at firewall within seconds.

15–20% SIEM savings 85% auto-resolution Bi-directional response
Splunk (log aggregator) Fortinet FortiSIEM
Existing Strata NGFW customers not yet using XSIAM. Organizations using Splunk primarily as NGFW log aggregator. High firewall log volumes (datacenter, large enterprise).
Full Platformization
Strata Prisma SASE XSIAM Cortex Cloud Idira Chronosphere

CISOs managing 15–30 security vendors. Integration overhead consuming 30%+ of security budget. Disparate tools generate siloed data. Board demands proof of consolidated risk posture.

The only vendor delivering a unified, AI-driven security platform across all seven pillars: Network (PAN-OS 12.2), SASE (Prisma Access 6.2 + Prisma Browser), SOC (XSIAM 3.6), Cloud (Cortex Cloud 2.2), AI Security (Prisma AIRS 3.0), Identity (Idira, formerly CyberArk — acquisition closed Feb 11, 2026, GA May 12, 2026) and Observability (Chronosphere). Single AI platform detects → correlates → responds across every layer in seconds.

174% ROI (Strata) NGS ARR $8.13B, +60% y/y $7.33M avg annual value 98% MTTR reduction 80% faster breach response
Fortinet CrowdStrike Zscaler Wiz Okta/SailPoint Datadog
Fortune 1000, Global 2000. CISOs with 3+ year consolidation mandates. $20M+/year security spend across 15+ vendors. Customers with 2+ existing PAN pillars. Companies building AI/agentic applications.
AI Security for NGFW Customers
Prisma AIRS 3.0 Strata NGFW SCM

Organizations deploying AI applications have no inline security for AI-specific threats: prompt injection, data poisoning, sensitive data leakage through LLM APIs. AI agents create new privileged access paths.

AIRS uses the same PAN-OS infrastructure and the same Software NGFW Credits — a VM-Series can become an AIRS instance via license toggle. Managed from the same SCM console. App-ID/User-ID/Content-ID framework identifies and inspects AI model API calls. Prisma AIRS 3.0 (Mar 23, 2026) spans AI Model Security, AI Runtime Security, AI Agent Security, AI Red Teaming and AI-SPM, with Portkey (closed May 29, 2026) as the AI Gateway. It is also the named replacement for CN-Series, which goes end-of-sale Nov 1, 2026 — AI Runtime Firewall is the successor.

Zero new infrastructure Same SCM management Prompt injection prevention
Cloudflare AI Gateway Fortinet FortiWeb
Existing NGFW customers (immediate: no new infra). CN-Series customers who must act before the Nov 1, 2026 end-of-sale. Deploying internal GPT/LLM applications. Building AI-powered products with external LLM APIs. Regulated industries with AI compliance risk — EU AI Act and ISO 42001 alignment sits with Prisma AIRS 3.0.
Identity + SOC / Zero Trust
Idira Cortex XSIAM ITDR 2.0

Identity-based attacks are the #1 initial access vector. PAM and SIEM operate in silos. Machine identities outnumber humans 80:1 and are largely unmanaged. Zero trust requires real-time enforcement — current PAM is too slow.

Real-Time Privilege Revocation: XSIAM detects a compromised credential → triggers Idira (formerly CyberArk) to revoke access across all systems. Two pieces of this are now shipping product, not vision: Idira Endpoint Privilege Manager integrates with XSIAM via Cortex Marketplace as of XSIAM 3.5 (May 3, 2026), and ITDR 2.0 landed in XDR 5.2 with Conditional Access Policies for Okta, Entra and on-prem AD, Active Directory Security Posture Management, 17 new detectors and granular RBAC. Attack Stories include full identity context. Portfolio: Idira Privileged Access Manager, Idira Secrets Hub, Certificate Manager, Idira Secure AI Agents — plus Next-Generation Trust Security (Mar 23, 2026) for certificate lifecycle inside SCM.

80% faster breach response Idira EPM × XSIAM shipped 3.5 ITDR 2.0 in XDR 5.2 >90% blast radius reduction
Microsoft Entra + Sentinel CrowdStrike Identity + SIEM BeyondTrust + Splunk
Regulated industries (financial services, healthcare, critical infrastructure). Significant privileged user populations. Enterprises deploying AI/agentic workflows. Organizations building zero trust architecture. Existing CyberArk installed base — lead with the Idira rebrand and the XSIAM integration as the reason to consolidate.