The Total Economic Impact™ Of Palo Alto Networks CDSS

Cost Savings And Business Benefits Enabled By CDSS

A Forrester Total Economic ImpactTM Study Commissioned By Palo Alto Networks, November 2023

As network architecture becomes more complex, security teams increasingly struggle to adapt and provide consistent security to all devices and data traversing their networks and clouds. Forrester research found IoT devices to be the most common target of external attacks . Subscription-based security services are a growing piece of most organizations’ security strategies, enabling rapid scalability of protection with up-to-the-minute updates and simplifying the deployment and management of security.

Palo Alto Networks Cloud-Delivered Security Services (CDSS) is a set of solutions that offer specialized security depending on different use cases and are designed to defend against known, unknown, and advanced evasive threats. The different solutions include Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, DNS Security, Enterprise IoT Security, SaaS Security, and Enterprise DLP.

Palo Alto Networks commissioned Forrester Consulting to conduct a Total Economic Impact™ (TEI) study and examine the potential return on investment (ROI) enterprises may realize by deploying its CDSS.1 The purpose of this study is to provide readers with a framework to evaluate the potential financial impact of its CDSS on their organizations.

To better understand the benefits, costs, and risks associated with this investment, Forrester interviewed four representatives with experience using Palo Alto Networks CDSS. For the purposes of this study, Forrester aggregated the interviewees’ experiences and combined the results into a single composite organization that is a distributed enterprise with 50,000 employees and $7 billion in annual revenue.

Prior to deploying Palo Alto Networks for network security needs, the customers leveraged various point solutions to secure their environments. The organizations lacked modern security technology as security and IT teams tried to keep up with evolving business needs. Digital transformation initiatives pushed more data, applications, and processes to the cloud, while other core business functions remained on-premises. Adding to the complexity was the need for the organizations to support more flexible and remote work options for their employees as employee expectations and other environmental factors drove up demand for remote access to critical applications and data. This piecemeal approach left organizations with many different vendors in their security stacks, making it challenging for security operations (SecOps) teams to integrate technologies, benefit from analytics, apply consistent policies, and deliver a consistent experience to end users.

Additionally, the lack of a unified platform and next-generation firewall capabilities left the organizations stuck in a cycle of devoting valuable resources to management, operations, and maintenance activities while work on new initiatives and enhancements fell by the wayside.

After the investment in Palo Alto Networks CDSS, the customers were able to realize various operational efficiencies across different activities, which significantly reduced investigational effort and freed up valuable resources to focus on enhancements and securing more of the network.

Key results from the investment are highlighted by efficiency gains for IT, security, and networks operations teams; business end users; and in-store workers. Further, interviewees’ organizations benefited from a reduced likelihood of a data breach, as well as reduced costs associated with licensing and managing legacy point-solution infrastructure.

Key Findings

Quantified benefits. Three-year, risk-adjusted present value (PV) quantified benefits for the composite organization include:

  • Reduced number of security incidents requiring manual investigation by 25% to 60%, decreased mean time to resolution (MTTR) by 20%, and reduced number of endpoint devices requiring reimaging, all resulting in $1.1 million saved over three years. By using Palo Alto Networks CDSS in combination with the other solutions implemented in its security environment, the composite organization is able to reduce the number of security incidents requiring manual investigation, the time to respond and resolve incidents, and the number of endpoint devices requiring reimaging. This is a result of being able to track the performance and usage of the different implemented solutions across the organization in one place, giving the SecOps and IT ops teams the ability to quickly identify and respond to potential threats. Over three years, this time savings totals $1.1 million to the composite organization.
  • Improved end-user productivity with better system availability and less intrusion to the network, totaling $5.2 million in business value over three years. The composite organization also realizes end-user productivity gains by minimizing disruption caused by its security investigations, as well as just overall better system availability of the environment. This is a product of the better integration and compatibility of the different Palo Alto Networks solutions, as well as overall performance. Over three years, this end-user productivity increase is worth nearly $5.2 million to the composite organization.
  • Decreased likelihood of a data breach by 50% after three years. The different tools that fall under CDSS provide a more secure environment for various activities and use cases across the composite organization. As a result, it decreases the likelihood of a significant data breach. Over three years, this reduced risk from a data breach is worth close to $2.8 million to the composite organization.
  • Avoided and rationalized security infrastructure, saving $3.4 million over three years. Using CDSS also allows the composite organization to consolidate its spending on security tech stack vendors. Over three years, this cost savings from vendor consolidation totals $3.4 million to the composite organization.
  • Reallocated roughly 50% full-time security professionals to higher-value initiatives due to management efficiencies from a common platform, saving $378,000 over three years. Related to the vendor consolidation benefit, the composite organization also realizes efficiencies for its employees who manage the different tools. By having a common platform to manage all Palo Alto Networks solutions, the composite organization can potentially repurpose certain employee time or even entire team members to other prioritized or higher-value work. Over three years, this efficiency generates $378,000 in value to the composite organization.

Unquantified benefits. Benefits that provide value for the composite organization but are not quantified for this study include:

  • Improved visibility in the security environment. With Palo Alto Networks CDSS monitoring and tracking various security activities and use cases across the organization, the composite organization realizes improved visibility to its security environment. In addition to the time savings and efficiencies related to this visibility, the composite organization also now has more robust information to act on or react to, which allows it to further improve its situation, if needed.
  • Better integration with tools and platforms in the security tech stack. The composite organization also benefits from the fact that CDSS solutions integrate better with one another and with the other Palo Alto Networks solutions implemented in the environment. In addition to the productivity gain quantified above, this also gives peace of mind to the SecOps, IT ops, and NetOps teams, while also well-positioning the organization for further development of its security environment.
  • Better employee experience. The combination of the increased visibility and better integration means that the composite organization also improves the employee experience. All employees, whether part of the security organization or general end users, realize some sort of ease, comfort, and confidence that they are well protected from potential attacks and threats. In addition to the productivity boost quantified above, this can also potentially improve their attachment to the organization and the brand from the perspective of both internal and external stakeholders.

Costs. Three-year, risk-adjusted PV costs for the composite organization include:

  • Installation and deployment costs totaling $843,000 over three years. Time and labor are required to deploy and install the various components of the Palo Alto Networks solution throughout the composite organization. Deployment of CDSS solution relative to other Palo Alto Networks solutions (i.e., NGFW and Strata SASE) is assumed to require 25% of the implementing staff’s time.
  • Training costs and ongoing management time investment totaling $63,000 over three years. Palo Alto Networks required less training than legacy solutions and interviewees and respondents reported that the provided training was more effective and efficient, allowing employees to get up to speed faster and expand their skill sets. Once trained, the team spends some time maintaining and managing the system on an ongoing basis.
  • Palo Alto Networks CDSS annual licensing costs totaling $1.9 million over three years. The composite organization is able to purchase hardware upfront and leverage three-year contract terms to add the CDSS, helping reduce the overall costs of Next-Generation Firewall (NGFW); IPS/IDS; SWG; web proxy; VPN; Advanced URL Filtering; malware analysis (e.g., sandboxing); and DNS, SaaS application, and Enterprise IoT Security solutions. Combining this with services like Strata Access allows the CDSS to be extended for branch offices or remote workers, and organizations can scale up and down based on usage and needs.

The representative interviews and financial analysis found that a composite organization experiences benefits of $12.85M over three years versus costs of $2.81M, adding up to a net present value (NPV) of $10.04M and an ROI of 357%.

Annual tech stack spend savings from vendor consolidation

20%

“The main value of CDSS is having a better understanding of our assets in the potential deficiencies those assets may have from a security perspective, the vulnerabilities and exposure that we could have, from the biases that govern the network access into the organization.”

Information security architect and CSIO, healthcare

Key Statistics

  • icon icon

    Return on investment (ROI):

    357%
  • icon icon

    Benefits PV:

    $12.85M
  • icon icon

    Net present value (NPV):

    $10.04M
  • icon icon

    Payback:

    <6 months

Benefits (Three-Year)

Security and IT operations efficiency End-user productivity Data breach risk reduction Security infrastructure cost reduction and avoidance Security stack management efficiency from common platform

TEI Framework And Methodology

From the information provided in the interviews, Forrester constructed a Total Economic Impact™ framework for those organizations considering an investment in Palo Alto Networks CDSS.

The objective of the framework is to identify the cost, benefit, flexibility, and risk factors that affect the investment decision. Forrester took a multistep approach to evaluate the impact that Palo Alto Networks CDSS can have on an organization.

Forrester Consulting conducted an online survey of 351 cybersecurity leaders at global enterprises in the US, the UK, Canada, Germany, and Australia. Survey participants included managers, directors, VPs, and C-level executives who are responsible for cybersecurity decision-making, operations, and reporting. Questions provided to the participants sought to evaluate leaders' cybersecurity strategies and any breaches that have occurred within their organizations. Respondents opted into the survey via a third-party research panel, which fielded the survey on behalf of Forrester in November 2020.

  1. Due Diligence

    Interviewed Palo Alto Networks stakeholders and Forrester analysts to gather data relative to Palo Alto Networks CDSS.

  2. Interviews

    Interviewed four representatives at organizations using Palo Alto Networks CDSS to obtain data about costs, benefits, and risks.

  3. Composite Organization

    Designed a composite organization based on characteristics of the interviewees’ organizations.

  4. Financial Model Framework

    Constructed a financial model representative of the interviews using the TEI methodology and risk-adjusted the financial model based on issues and concerns of the interviewees.

  5. Case Study

    Employed four fundamental elements of TEI in modeling the investment impact: benefits, costs, flexibility, and risks. Given the increasing sophistication of ROI analyses related to IT investments, Forrester’s TEI methodology provides a complete picture of the total economic impact of purchase decisions. Please see Appendix A for additional information on the TEI methodology.

Disclosures

Readers should be aware of the following:

This study is commissioned by Palo Alto Networks and delivered by Forrester Consulting. It is not meant to be used as a competitive analysis.

Forrester makes no assumptions as to the potential ROI that other organizations will receive. Forrester strongly advises that readers use their own estimates within the framework provided in the study to determine the appropriateness of an investment in PANW CDSS.

Palo Alto Networks reviewed and provided feedback to Forrester, but Forrester maintains editorial control over the study and its findings and does not accept changes to the study that contradict Forrester’s findings or obscure the meaning of the study.

Palo Alto Networks provided the customer names for the interviews but did not participate in the interviews.

Consulting Team:

Adi Sarosa

Isabel Carey

Cookie Preferences

Accept Cookies

A cookie is a small text file that a website saves on your computer or mobile device when you visit the site. It enables the website to remember your actions (data inputs, website navigation), so you don’t have to re-enter data when you come back to the site or browse from one page to another.

Behavioral information collected by our web analytics vendor is used to analyze data pertaining to visitor trends, plan website enhancements, and measure overall website effectiveness. We may also use cookies or web beacons to help us offer you products, programs, or services that may be of interest to you and to deliver relevant advertising. We may use third-party advertising companies to help tailor website content to users or to serve ads on our behalf. These companies may also employ cookies and web beacons to measure advertising effectiveness.

Please accept cookies and the collection of behavioral information to receive full functionality and enhance your experience. If you decline cookies, some features of the website may not function normally.

Please see our Privacy Policy for more information.