Amid the consolidation and convergence trend in the cybersecurity industry, a platform debate unfolds between two giants: CrowdStrike and Palo Alto Networks, each with a distinct vision of what a true security platform should do.
Meanwhile, a question looms large: In the relentless pursuit of cybersecurity supremacy, who will emerge as the winner?
The origins of CrowdStrike and Palo Alto Networks platforms
Founded in 2011, CrowdStrike offers a cloud-native platform called Falcon for protecting endpoints, cloud workloads, identities, and data.
CrowdStrike’s CTO, Elia Zaitsev, told SDxCentral the original business plan was a platform with a single agent, a single console, and a unified data layer that collects data once and reuses it many times. “Twelve or so years ago, there is a story [CrowdStrike cofounder George Kurtz] likes to tell where they sketched out the vision for the company on a cocktail napkin before they got the Series A funding to start it.”
“We started in EDR [endpoint detection and response]. We had threat intelligence from day one; we were doing incident response and threat hunting,” he said. “We have grown the breadth of the platform by going into additional areas over time.”
With a longer history, Palo Alto Networks was founded in 2005 and now offers a wide range of products that leverage threat intelligence in three platforms: network security, cloud security, and security operations (DevOps).
Palo Alto Networks cofounder and CTO Nir Zuk recalled that they started the company with a vision to initially build a network security platform. “Back then, cybersecurity was 100% on premises,” he told SDxCentral. “One of the things I did at Palo Alto Networks is to take these network security functions and turn them into a SaaS (Software-as-a-service) delivered service on top of the firewall.”
Around 2014, the vendor decided to expand the platform from network security to other areas such as security operations center (SOC) and cloud security, he said.
Philosophical divide: What is a 'true platform'?
The debate between CrowdStrike and Palo Alto Networks over what constitutes a true platform has intensified with comments made by both companies' CEOs during recent earnings calls, in the media, and on social media platforms.
“It's great to hear everyone kind of catching up to the terminology. A little bit frustrating, though; I think people want to use this term of platform, but they're not necessarily building and delivering a platform,” Zaitsev said.
For CrowdStrike, “the way we look at it is a platform means a few basic non-negotiables: one console, one agent, multiple capabilities that you can seamlessly deliver to that system,” he added.
This approach is not merely about bundling disparate technologies under one brand, because that’s still multiple systems from the data and users’ perspective, Zaitsev said. “If you've got to log into multiple consoles, if I've got to install and configure several different agents, that's not a platform.”
“The approach that they're taking there, it's been around for 20, 30 years,” Zaitsev added. “McAfee and Symantec, I guess they don't call them that anymore, but that's what they did. They bought a bunch of technology and sold you a bunch of things, but none of them were integrated. I mean, Microsoft has been doing this for years with 35 bundles.”
According to Zaitsev, a true platform simplifies management, reduces costs and complexity, enhances efficiency for security analysts, and improves threat detection and response capabilities for vendors.
In contrast, Palo Alto Networks’ Zuk presents a definition of a platform from a different angle, stressing the importance of covering needed security functionalities integrated under one umbrella.
For Zuk, a true platform must first cover a substantial portion of the functionality the market needs within its domain. Second, what differentiates a portfolio from a platform is the measurable integration, which means a platform where disparate functions converge to produce outcomes unattainable by individual components operating in silos.
“Portfolio or bundling doesn't really provide any additional value other than: OK, you buy once, you pay once, and you get 10 different things,” Zuk said. “In a platform, if you run four different functions, you get much better results than running just the four individual functions.”
Zuk disputes the notion that a platform can be just defined by offering a single agent or console or the consolidation of its data sources alone. “I think that these are small parts of a platform. Running one agent doesn't mean that you perform all the functions that cover the industry … you can still have five different functions in the agent that are completely separate from each other.”
Palo Alto Networks vs. CrowdStrike: Two different platform approaches
Zuk said that Palo Alto Networks’ three core platforms cater to distinct aspects of cybersecurity.
For example, network security includes physical firewalls, virtual firewalls and secure access service edge (SASE), he said. “I think network security will always be a separate platform.”
“I think that it's gonna be very hard to find a way to make network security and SecOps one platform. So network security is feeding SecOps with data. But it's completely two different things,” he added.
The division into three platforms is largely influenced by market patterns and purchasing behaviors within the industry. Zuk outlined: Network security is often procured by networking teams rather than cybersecurity teams; cloud security is typically purchased by cloud-focused teams; DevOps solutions are sought after by SOCs.
“The management platforms are being used by different people in the organization,” he added. “It could be that customers will start demanding it because they're going to merge the teams that do that. I think it's going to take a while.”
Despite the present separation, Palo Alto Networks is open to future integration based on market demand and customer needs. “If it ever changes and there's going to be one decision, then there's going to be one platform probably.”
However, CrowdStrike’s Zaitsev disagrees. “Saying you've got three different platforms immediately tells you it's not a true platform because if it was, they'd be moving them into a single unified platform … It's just three different products with three different interfaces for three different users.”
“They're basically doing it through bundling and discounting. They're not actually unlocking these advanced capabilities of a true platform by bringing all the information together in one place,” he added.
Zaitsev said CrowdStrike never has a multiple-agent approach, even with acquisitions. “If we do acquire technology that has a separate console that has a separate agent, the first thing that comes out in the press release is our intent to consolidate it all.”
“I think we're the only ones who are consistently taking a true platform approach. Again, single agent, single console, collected data once we use it many times,” he said, adding that this approach can unlock more value from different datasets and capabilities, such as artificial intelligence (AI).
From the data perspective, Palo Alto Networks’ Zuk pointed out for CrowdStrike, “They don’t have network data. They only have endpoint data. And also in the cloud, they only do one or two functions.”
But Zaitsev said CrowdStrike aims to create an open platform, allowing customers to bring in datasets or other capabilities that the vendor doesn’t offer, such as information from Palo Alto Networks’ network hardware appliances.
“You can still take automated response capabilities across endpoint, network, email, whatever security domain you want, but you're doing it much more efficiently because the analyst only has to go to one location to gain insight into all that. We're building artificial intelligence models that consume and leverage all that information as well,” he added.
Who will win the security market?
Both CrowdStrike and Palo Alto Networks, along with several other leading security players, acknowledge the shift toward platform-centric solutions in cybersecurity.
When asked about why there is now a push and debate about the platform approach in the industry, Zuk and Zaitsev both said that their company is winning the market.
“Because we're becoming a clear winner in this space. And imitation is the sincerest form of flattery,” Zaitsev said.
Similarly, Zuk said, “We're killing them in the market … I think that you've never seen vendors as big as Palo Alto Networks in the space.”
He added that vendor consolidation happens in many other industries, such as customer relationship management (CRM), enterprise resource planning (ERP), and office software, which ended up with one or very few big winners. “It happened in networking. Today, you buy all your networking from one favorite like Cisco.”
“Everybody understands that it's now happening in cybersecurity,” he said. “And the only way to compete against Palo Alto Networks is to say, ‘Oh, we are a platform.’ No, you're not if you have two out of 10 functions, you are not a platform.”
Looking ahead, Zuk posits that the cybersecurity industry may coalesce around one or two vendors. “If I have to guess, I think these two vendors are going to be Palo Alto Networks and Microsoft.”
Crowdstrike's Zaitsev concurs that vendor consolidation is inevitable. “Customers are telling us consistently that they're getting overwhelmed with the costs … alert fatigue, trying to make sense and jump around between all the different products. They're just hitting a breaking point; they just can't handle any more point solutions.”
But he warns against the dangers of a monopoly. “I do think we are increasingly seeing the security market consolidate on a handful of winners. Those winners will be the ones that do offer the most robust platform, the most sophisticated AI-native capabilities,” Zaitsev said.
“So yes, there is going to be that consolidation, [but] to a single one? I doubt that. If it's not good for the ecosystem – you always want competition, right? You always want a couple of vendors to push each other to do innovation,” he added.
Comments