How Palo Alto Networks just reshaped its entire IP strategy with a $25 billion bet on identity security: inside the 2,500-patent portfolio that now includes CyberArk's landmark privileged access management technology.
Palo Alto Networks Patent Landscape: A Comprehensive Intellectual Property & Cybersecurity Innovation Analysis
An in-depth analysis of 2,531 patent documents spanning three decades of network security innovation — from foundational firewall and threat prevention architecture through cloud security, AI-driven threat detection, and identity security technology acquired via the landmark $25 billion CyberArk transaction — mapping Palo Alto Networks' global IP portfolio across 14 jurisdictions and 1,028 distinct patent families.
Executive Summary: Palo Alto Networks Patent Portfolio — Network Security Leadership Reshaped by the Landmark CyberArk Acquisition
Palo Alto Networks — the global cybersecurity leader best known for its next-generation firewall platform and increasingly comprehensive AI-powered security ecosystem — has entered a transformative new chapter in its intellectual property history with the February 2026 completion of its $25 billion acquisition of CyberArk, the global leader in identity security and privileged access management. This patent landscape report, prepared by IIPRD as an exemplary technology intelligence analysis, examines a corpus of 2,531 patent documents organised across 1,028 distinct patent families, capturing both Palo Alto Networks' own three-decade filing history and the substantial identity security IP estate now consolidated through the CyberArk transaction.
The portfolio's technology architecture is overwhelmingly anchored in network security and cryptographic protocol technology: H04L (1,590 CPC documents) — transmission of digital information — dominates the portfolio, encompassing firewall packet inspection, secure network transmission, and the cryptographic key management and authentication technology central to both Palo Alto Networks' network security platform and CyberArk's privileged access management systems. The substantial G06F (710 documents) — computing architecture — and emerging G06N (57 documents) — machine learning — clusters confirm the portfolio's dual foundation in traditional network security infrastructure and the AI-driven threat detection capabilities increasingly central to modern cybersecurity platforms.
The legal status composition reveals an exceptionally healthy and actively managed portfolio: 1,468 granted patents (58.0%), 712 pending (28.1%), 262 lapsed (10.4%), 80 expired (3.2%), and 9 revoked (0.4%). An outstanding 86.1% alive ratio (2,180 documents) confirms this is one of the most commercially active and enforceable cybersecurity patent portfolios in the industry. Geographically, the United States (1,790 documents) anchors the filing strategy overwhelmingly, with the European Patent Office (192), WIPO PCT (165), Japan (119), and China (110) providing the essential international coverage tier reflecting the global enterprise customer base that both Palo Alto Networks and CyberArk serve.
This patent landscape analysis provides critical intelligence for IP professionals, cybersecurity industry investors, identity security technology strategists, and competitive intelligence analysts seeking to understand how the CyberArk acquisition is reshaping Palo Alto Networks' IP positioning at the convergence of network, cloud, and identity security. Note: this analysis excludes approximately 140 unrelated third-party records (including unaffiliated legacy telecom companies and citation-network artifacts) that surfaced in raw search results but share no confirmed corporate relationship with Palo Alto Networks or CyberArk.
A Decade of Accelerating Cybersecurity Innovation: How Palo Alto Networks Built Sustained Filing Momentum Toward a Record 2023
The temporal distribution of the combined Palo Alto Networks and CyberArk patent portfolio reveals a filing history of remarkable and sustained acceleration, reflecting both companies' parallel growth as leaders in their respective cybersecurity specialisations. While isolated priority filings trace to 1994 through CyberArk's earliest privileged access management research, the modern filing era begins meaningful acceleration in 2011 with 70 priority filings, corresponding with Palo Alto Networks' rapid post-IPO expansion and CyberArk's own growing prominence in the emerging privileged access security category.
The years 2017–2023 demonstrate an almost uninterrupted growth trajectory — 160, 185, 176, 199, 230, 269, and a record 336 priority filings in 2023 — representing sustained year-over-year filing increases that place both companies among the most prolific patent filers in the global cybersecurity industry. This extended growth period reflects Palo Alto Networks' Security Fabric platform expansion, its acquisition-driven diversification into cloud security (Twistlock, CloudGenix, Zingbox) and AI-driven threat intelligence, alongside CyberArk's own accelerating investment in privileged access management, secrets management (through its Conjur acquisition), and identity threat detection technology as identity has become the primary attack vector in modern enterprise breaches.
The publication trend delivers the most striking confirmation of current momentum: 491 publications in 2025 and an extraordinary 527 already recorded in the partial year 2026 — figures that dramatically exceed any prior year and confirm that the massive 2022–2024 filing cohort from both companies is now flowing through patent office examination at an unprecedented rate. With 712 pending applications currently under active prosecution — representing over a quarter of the combined portfolio — the newly consolidated Palo Alto Networks-CyberArk patent estate is positioned for substantial continued expansion through 2027 and beyond.
CPC Classification Confirms H04L Dominance as the Unified Technical Core Spanning Network and Identity Security
The Cooperative Patent Classification (CPC) distribution of the combined Palo Alto Networks-CyberArk patent portfolio delivers a striking confirmation of technical convergence between the two companies' core competencies. The overwhelmingly dominant CPC class is H04L (1,590 documents — 68.3% of CPC-classified patents) — transmission of digital information — a concentration far higher than typical even for network security companies, reflecting the fact that both Palo Alto Networks' firewall and secure transmission technology and CyberArk's privileged access management and credential security systems fundamentally depend on cryptographic protocol, secure authentication, and network transmission control innovations classified within this single dominant CPC subclass.
The G06F (710 documents — 30.5%) cluster — general computing architecture — captures the broader software platform innovations spanning both companies: Palo Alto Networks' FortiOS-equivalent security operating system architecture and virtualization security technology, alongside CyberArk's privileged session management and credential vaulting software architecture. Together, H04L and G06F account for 98.8% of the CPC-classified portfolio, confirming that despite their distinct market positioning — Palo Alto Networks in network perimeter security, CyberArk in identity and access management — both companies' patent estates are fundamentally built upon the same underlying cryptographic and computing architecture foundations, a technical convergence that strongly validates the strategic logic behind the acquisition.
The smaller but strategically significant H04W (96 documents) wireless communication cluster and emerging G06N (57 documents) machine learning cluster reflect Palo Alto Networks' investment in secure wireless access technology and the AI-driven behavioral analytics increasingly central to both network threat detection and CyberArk's identity threat detection capabilities — a technology domain likely to see substantial combined investment growth as the merged entity develops unified AI-powered security operations spanning network, cloud, and identity domains simultaneously.
IPC Analysis Reveals a Slightly More Balanced H04L-G06F Split Reflecting the Portfolio's Dual Network-Identity Foundation
The International Patent Classification (IPC) distribution provides cross-jurisdictional validation of the combined portfolio's technology taxonomy, applied consistently by examiners at the USPTO, EPO, JPO, and CNIPA across the portfolio's primary filing jurisdictions. The H04L cluster (1,331 documents) remains dominant but proportionally smaller in IPC relative to its CPC representation, while G06F (989 documents) shows meaningful expansion under the broader IPC classification net — together these two classes still account for the overwhelming majority of the portfolio, but the somewhat more balanced IPC distribution better reflects the genuine dual technical foundation spanning network transmission security and computing platform architecture that now characterises the combined Palo Alto Networks-CyberArk IP estate.
This IPC-CPC divergence is analytically meaningful for IP professionals conducting comprehensive prior art searches or freedom-to-operate analyses across the combined portfolio's technology domains — the broader IPC classification net for G06F captures additional privileged access management, session recording, and credential vaulting software architecture innovations from CyberArk that may be more narrowly classified under specific CPC sub-hierarchies, meaning comprehensive searches must span both classification systems to fully capture the portfolio's identity security technology breadth.
The H04W (86 documents) and G06N (46 documents) clusters maintain consistent proportional representation across both classification systems, confirming wireless network security and machine learning-driven threat detection as stable, well-classified technology pillars. The presence of smaller clusters including H04N (8 documents) and G06Q (7 documents) reflects limited but present investment in video/image security applications and security-focused business process management, rounding out a portfolio whose technology breadth remains tightly focused on the core cryptographic, network, and identity security domains central to both companies' commercial platforms.
US-Anchored Global Strategy: How the Combined Portfolio's Filing Geography Reflects Enterprise Cybersecurity's Global Reach
The combined Palo Alto Networks-CyberArk patent filing geography presents a jurisdiction map heavily anchored in the United States while maintaining meaningful international coverage across the world's most important enterprise technology markets. The United States dominates with 1,790 patent documents (70.7%) — an exceptionally high concentration reflecting Palo Alto Networks' Santa Clara headquarters, CyberArk's substantial US operations despite its Israeli origins, and the critical importance of USPTO protection for enforcement against competitor cybersecurity vendors including CrowdStrike, Okta, and Microsoft in the world's largest enterprise security software market.
The European Patent Office (192 documents) and WIPO PCT (165 documents) together provide the essential international coverage tier for the combined portfolio's most commercially significant innovations, reflecting the substantial enterprise customer base both companies serve across European financial services, government, and critical infrastructure sectors where identity security and network protection compliance requirements are increasingly stringent. Notably, CyberArk's Israeli heritage is directly visible in the portfolio's Israel filing presence (24 documents) — a relatively modest absolute figure but strategically significant given Israel's position as CyberArk's founding jurisdiction and continued major engineering center.
The Japan (119 documents), China (110 documents), and South Korea (79 documents) jurisdictions reflect the growing strategic importance of Asia-Pacific enterprise cybersecurity markets, where both network perimeter security and identity access management solutions are experiencing rapid adoption growth as regional enterprises modernise their security infrastructure in response to escalating ransomware and nation-state threat activity. This calibrated jurisdiction strategy — concentrated in the US with targeted international coverage in the world's largest secondary technology markets — positions the combined entity's IP estate for effective enforcement across its most commercially critical global markets.
An Exceptional 58% Grant Rate: Assessing the Combined Portfolio's Outstanding Prosecution Quality and Efficiency
The legal status distribution of the combined Palo Alto Networks-CyberArk patent portfolio reveals an exceptionally strong and disciplined IP prosecution practice across both constituent companies. The 1,468 granted patents (58.0%) represent a grant rate considerably higher than typical for the cybersecurity software industry, where patent eligibility challenges for software-implemented security innovations frequently create heightened examination scrutiny. Achieving this grant rate reflects both companies' sophisticated, technically precise patent drafting practices and well-structured claim architecture that has proven resilient to the more demanding subject matter eligibility standards applied to cybersecurity software patents in recent years.
The 712 pending applications (28.1%) constitute a substantial and commercially significant active prosecution pipeline — representing over a quarter of the entire combined portfolio and concentrated heavily in the 2022–2025 filing cohorts covering AI-driven threat detection, cloud security posture management, and the identity threat detection technology increasingly central to modern enterprise security architecture. This large pending inventory signals that the combined entity's enforceable patent estate will expand substantially over the coming 24-36 months as these applications complete examination across the USPTO, EPO, and other major jurisdictions.
The 262 lapsed patents (10.4%) reflect normal and expected portfolio rationalisation across both companies' filing histories, while the remarkably low 9 revoked patents (0.4%) is a particularly strong quality indicator — confirming that the combined portfolio's granted patents have faced minimal successful post-grant invalidation challenges despite operating in the technically dense and competitively contested cybersecurity patent landscape where companies routinely challenge each other's claims through inter partes review proceedings.
86.1% Alive: An Outstanding Vitality Ratio Confirming the Combined Portfolio's Commercial Relevance and Enforceability
The Alive/Dead binary classification of the combined Palo Alto Networks-CyberArk patent portfolio delivers one of the strongest vitality metrics observed across comparable cybersecurity industry portfolios. With 2,180 patent documents classified as Alive (86.1%) against just 351 Dead (13.9%), the combined entity's portfolio vitality ratio is exceptional even among high-growth technology companies — a direct consequence of the portfolio's concentration in relatively recent filings from both companies, where the substantial majority of documents originate from the 2015–2025 period and have not yet approached any natural lifecycle completion point.
The 2,180 alive documents represent the combined entity's complete actionable IP arsenal spanning the full breadth of both companies' commercial technology ecosystems: Palo Alto Networks' next-generation firewall packet inspection and threat prevention platform, Security Fabric architecture integrating cloud and network security, SD-WAN and secure access technology, and CyberArk's privileged access management, secrets management (via Conjur), and identity threat detection capabilities. This vast active patent estate provides Palo Alto Networks with substantial defensive protection and licensing leverage across its expanding platform strategy as it competes against CrowdStrike, Zscaler, Okta, and Microsoft in an increasingly consolidated cybersecurity vendor landscape.
The 351 Dead patents predominantly represent earlier-generation innovations from both companies' pre-2010 filing histories, covering network security and access management approaches that have been technically superseded by subsequent architectural generations. These Dead patents nonetheless retain meaningful defensive prior art value, particularly in foundational firewall and privileged access management domains where both companies' historical patents established comprehensive early disclosure that continues to constrain competitor patent scope in these mature but still commercially vital technology categories.
Patent Family Architecture: A Singleton-Heavy Portfolio Reflecting Two Companies' Distinct US-Centric Filing Traditions
Patent family analysis of the combined Palo Alto Networks-CyberArk portfolio reveals a structure dominated by singleton and small families, reflecting both companies' historically US-centric prosecution strategies prior to their combination. The 452 single-member families (44.0% of all 1,028 families) and 302 size-2 families (29.4%) together account for nearly three-quarters of the entire portfolio, confirming that the substantial majority of innovations from both Palo Alto Networks and CyberArk have historically been protected primarily within the United States or with minimal additional international coverage, a pattern consistent with companies whose largest enterprise customer concentration remains domestically US-based even as their platforms serve global markets.
The medium-family cohort — sizes 3–9, accounting for 235 families (22.9%) — represents the commercially validated core of innovations warranting broader multi-jurisdictional protection, typically extending coverage to the European Patent Office, Japan, and WIPO PCT routes for technology deemed to have meaningful cross-border enterprise commercial relevance. This pattern reflects a calibrated international prosecution strategy that reserves the additional cost of broader geographic coverage specifically for innovations with demonstrated global enterprise customer relevance.
At the extreme high end, the portfolio's maximum family size of 28 members represents the combined entity's single most globally protected invention, alongside a secondary large family of 27 members — these substantial families almost certainly correspond to foundational firewall architecture or core privileged access management technology that has been prosecuted across the full range of both companies' most important commercial jurisdictions, reflecting the singular strategic importance of these inventions to the combined entity's competitive positioning in global network and identity security markets.
Corporate IP Ecosystem: How the $25 Billion CyberArk Acquisition Transformed Palo Alto Networks Into an Identity Security Leader
The assignee distribution within this patent portfolio captures a genuinely historic moment in the cybersecurity industry's competitive landscape — the February 2026 completion of Palo Alto Networks' $25 billion acquisition of CyberArk, one of the largest cybersecurity M&A transactions in industry history. PALO ALTO NETWORKS (combined across all naming variants — 2,132 documents, 84.2%) represents the company's own organic patent filing activity, encompassing three decades of network security, firewall, and cloud security innovations developed across its Santa Clara headquarters and global engineering centers.
CYBERARK SOFTWARE (combined — 277 documents, 10.9%) represents the substantial identity security and privileged access management patent estate now consolidated into Palo Alto Networks' portfolio through the landmark acquisition completed on February 11, 2026. CyberArk's foundational technology in privileged credential vaulting, session monitoring, and access control has been widely recognised as the identity security industry's technical benchmark, and its integration establishes identity security as what Palo Alto Networks' leadership has explicitly described as a "core pillar" of the company's platformization strategy, extending privileged identity protection to human, machine, and increasingly autonomous AI agent identities.
The presence of CyberArk's own prior strategic acquisitions — CONJUR (7 documents), a secrets management platform for DevOps and cloud-native environments acquired by CyberArk in 2017, and VAULTIVE (13 documents) and VIEWFINITY (7 documents), both Israeli security technology companies acquired by CyberArk in 2018 and 2015 respectively — confirms that the newly combined entity inherits not just CyberArk's organic innovation but an additional layer of specialised identity and endpoint security IP. Meanwhile, Palo Alto Networks' own acquisition history remains visible through entities including EXPANSE/QADIUM (42 documents combined), VENAFI (25 documents combined), ZYCADA NETWORKS (17 documents combined), and TALON CYBER SECURITY, TWISTLOCK, ZINGBOX, and CLOUDGENIX — collectively illustrating a comprehensive, multi-decade M&A strategy spanning attack surface management, machine identity security, network optimisation, and cloud-native security that now converges with CyberArk's identity security leadership into what may be the cybersecurity industry's most comprehensive unified security platform.
A pending US patent application by CyberArk Software covering advanced privileged access threat detection and anomaly identification architecture — protecting innovations in behavioral analysis of privileged credential usage patterns that identify potential compromise or insider threat activity in real time. This filing represents exactly the type of identity threat detection capability that Palo Alto Networks' leadership has identified as central to securing the "agentic AI" era, where autonomous AI agents increasingly require privileged access controls comparable to human users.
A pending US patent application by Palo Alto Networks covering advanced network threat prevention and cryptographic authentication architecture — protecting core innovations relevant to the company's next-generation firewall and Security Fabric platform. This filing reflects Palo Alto Networks' continued organic investment in foundational network security technology even as the company simultaneously integrates CyberArk's identity security capabilities into its broader platform strategy.
A recently granted European patent by Palo Alto Networks covering advanced secure network session establishment and management protocols — protecting cryptographic handshake and session security innovations essential to the company's firewall and VPN product lines. This granted patent provides broad protection across European Patent Office member states, reinforcing Palo Alto Networks' enforcement capability in one of its most commercially significant international markets.
A recently granted US patent by CyberArk Software covering advanced credential vaulting and privileged access control architecture — protecting core innovations in secure storage and rotation of privileged credentials that form the technical foundation of CyberArk's industry-leading privileged access management platform. This granted patent represents exactly the type of foundational identity security IP that motivated Palo Alto Networks' strategic decision to acquire CyberArk, providing enforceable protection for technology now central to the combined entity's identity security pillar.
Innovation Trajectory: Palo Alto Networks' IP Evolution from Firewall Pioneer to Unified Network-Identity Security Platform
The innovation trajectory of Palo Alto Networks, as illuminated through this comprehensive patent landscape analysis, is now defined by one of the most consequential strategic moves in recent cybersecurity industry history — the $25 billion acquisition of CyberArk that formally establishes identity security as a core pillar of the company's platformization strategy. The combined portfolio's 2,531 documents chronicle two parallel innovation journeys — Palo Alto Networks' evolution from firewall pioneer to comprehensive Security Fabric platform, and CyberArk's parallel rise to global leadership in privileged access management — now converging into what CEO Nikesh Arora has explicitly framed as the technology foundation needed to "secure every identity: human, machine, and agent" in an era of rapidly proliferating autonomous AI systems.
The portfolio's exceptional health metrics — a 58.0% grant rate and 86.1% alive ratio, both considerably stronger than typical cybersecurity industry benchmarks — combined with the extraordinary 527 publications already recorded in partial-year 2026, confirm that the newly consolidated entity possesses both a technically robust historical IP foundation and an actively accelerating innovation pipeline precisely as identity security emerges as the cybersecurity industry's most critical growth vector. As AI agents increasingly require the same privileged access governance previously reserved for human users and service accounts, the technical convergence between Palo Alto Networks' network security expertise and CyberArk's identity security leadership positions the combined entity's patent portfolio as a potentially decisive competitive asset in defining how enterprises secure the emerging agentic AI computing paradigm.
For IP professionals, cybersecurity industry investors, identity security technology strategists, and competitive intelligence analysts, the newly combined Palo Alto Networks-CyberArk patent landscape represents a landmark case study in how strategic M&A can rapidly reposition a company's intellectual property estate to address an entirely new and increasingly critical security domain, building comprehensive technical coverage spanning network perimeter security, cloud security, and now identity security within a single unified competitive platform.