Setting the Stage
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Introduction and Setting the Stage (5 Minutes)
1. Good Morning/Afternoon, everyone. Welcome to the session on Cortex Cloud Application Security. My name is Sreekanth Gangula,
and I am a Cloud Security Architect in the Principal Architect’s team here at Palo Alto Networks.
2. Over the next 45 minutes, we will explore how Cortex Cloud platform is redefining application security from code to cloud - helping
organizations move faster without sacrificing security
3. By the end of this session, you should be able to:
○ Articulate the key challenges AppSec and DevOps leaders face today
○ Explain how Cortex Cloud Application Security addresses those challenges
○ Differentiate our approach from other vendors
○ Ask the right discovery questions when engaging customers
○ And finally, understand the pricing model for the AppSec add-on.
4. So let's get READY FOR TAKEOFF
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Development at the Speed of Light
Today, software development is happening faster than ever - almost at the speed of light
1. Over 90%+ of enterprises now operate in the cloud — meaning everything is distributed, dynamic, and constantly changing.
2. 75% of teams are releasing new code more than once a month — some even multiple times a day.
3. And now, AI is writing code, which is accelerating development but also introducing new, hard-to-detect risks.
This velocity is great for innovation, but it also means security needs to keep up — we can’t rely on manual reviews or traditional testing
cycles anymore.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
AI’s Impact on AppSec
One of the biggest things in the market is the “AI-Generated Code.
1. Today, about one-third of AI-generated code is vulnerable, and by 2030, up to 95 percent of all code could be written by AI. That
means insecure code will multiply faster than we can manually review it.
2. This is why traditional AppSec scanning alone will not scale. We need automation and contextual intelligence
……And that is exactly what Cortex Cloud AppSec provides
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Remediating Security Issues in Production is a losing battle
Now, let’s talk about one of the most painful realities in application security - remediation in production.
1. We have all seen this pattern : vulnerabilities are discovered late in the life-cycle, often in production. By then, the damage is done -
patches take days or weeks, developers have moved on, and the backlog of unresolved issues keeps growing
2. To solve in Cortex Cloud, we have taken the approach of find and fix in development. Instead of firefighting in production, we shift
prevention earlier into the pipeline. Issues are detected in the IDE, pull requests or build stage - and fixed in hours, not days - with no
backlog building up.
Cortex Cloud Application Security operationalizes this approach by embedding security directly into development workflows, automating
the remediation at the source.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Why Current Approaches Don’t Work
“Even with all the ‘shift-left’ talk, most organizations still struggle because:
Security enforcement is weak — teams fear slowing down dev.
Visibility is fragmented across tools.
Ownership is unclear.
Prioritization lacks runtime or business context.
● Cloud Security itself is not new, the industry has been solving it for a while.
● Quite for sometime, the cloud security landscape has evolved into a collection or set of disconnected tools,
each addressing a specific [Link] are separate tools built for application security, cloud posture, runtime
protection, and SOC functions.
● As a result, organizations ended up with a siloed architecture averaging 16 different security tools and
generating a staggering amount of findings as each of these tools were generating massive findings.
● And this siloed approach introduced significant complexity in architecture and leaves critical gaps in protection.
And as you know, security teams are struggling to operationalize these tools, spending lots of time and
resources trying to integrate disparate backends and workflows.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Market Opportunity
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
ASPM Market Oppotunity
“Let’s zoom out for a moment and look at the market landscape for Application Security Posture Management — or ASPM.
● Today, the application-security market overall is worth about $34 billion, and within that, ASPM already represents a $3.5 billion
sub-segment - and it is growing roughly 30% every year
● The is tremendous momentum, especially because this space is still greenfield - meaning it is dominated by small, fast-moving
startups rather than established enterprise platforms.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Introducing Cortex Cloud
AppSec
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
What is needed for a Successful AppSec Program
So, what makes a successful AppSec program?
Four things:
1. Complete Visibility - Centralize and normalize findings from all your scanners
2. Intelligent Prevention - Guardrails that stop risky behavior before it ships
3. Contextual Prioritization - Correlate data from code, cloud, and runtime
4. Automated Remediation - Fix issues right at the source
Cortex Cloud AppSec brings all four together in one platform.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
How Cortex Cloud AppSec Works
Let's break it down
1. First Comprehensive Visibility
a. We aggregate results from both native and third-party scanners - SAST, DAST, SCA, Secrets, IaC, you name it - into one unified view.
2. Second Intelligent Prevention:
a. We apply policies that automatically block insecure pull requests or builds - without slowing down development.
3. Third, is the Risk Prioritization:
a. By combining code, cloud and runtime context, we surface the issues that really matter
4. And finally, Automatic Remediation
a. Developers get precise fix recommendations directly in their workflow - in IDE, PR or CI/CD
Cortex Cloud AppSec brings all four together in one platform.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Introducing Cortex Cloud Application Security
Now, let's take a closer look at how all these components come together inside Cortex Cloud Application Security.
1. At the center of this diagram is the Application Security Posture Management layer - this is where the real magic happens.
a. It brings together centralized visibility, risk correlation and prioritization, and the unified policy framework - all built on top of
same Cortex Cloud platform that powers our broader Cloud and SOC solutions.
2. On the left, you see different types of scanning data we bring in:
a. Native Scanning - these are the scanners built right into the platform for Infrastructure as Code (IaC), Software Composition
Analysis(SCA), and Secrets detection
b. Supply Chain Security - scanning the full pipeline, your CI/CD tools, container images, and SBOMs
c. Third-party Scanning - and this is key - we don’t force customer to replace their existing tools. We ingest findings from best-in-class
scanners like Snyk, Veracode, Checkmarx, and many others, unifying all that data into one consistent model.
3. At the bottom, the Cortex Cloud platform fuses all this through AI and automation, powered by unified data from code to cloud to
SOC. That means it can correlate signals across:
a. Application Infrastructure and Runtime
b. Identities and Access Patterns
c. Data Exposure
d. And even AI model usage
4. On the right, this unified intelligence drives two outcomes
a. One is Prevention: Intelligence guardrails at the IDE, pull request, or build level stop risky code before it is ever deployed
b. Remediation: When issues are found, Cortex automatically suggests or triggers fixes at the source
This is what we mean by prevention-first ASPM approach - a unified, automated approach that is built for scale and speed of modern
development
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Drastically reduce MTTR
Now that we have seen how the architecture works, lets talk about the impact
1. First - we prevent 92% of issues from ever reaching production. That is massive shift in how organizations manage risk.
2. Second - we accelerate remediation of existing issues by 52%
a. Because Cortex Cloud correlates findings with precise code context, developers know exactly where to fix. And when remediation
starts at the source, turnaround time drops from weeks to hours
3. And third - we reduce developer time spent fixing issues by 90%
a. Think about what that means for productivity. Security does not have to be a blocker, it becomes an enabler or accelerator.
Developers can spend their time building new features instead of patching vulnerabilities.
And when you combine all three - prevention, acceleration and efficiency - you drastically cut your mean time to remediation and
eliminates the ever-growing backlog that plagues traditional AppSec programs.
This is why we call Cortec Cloud Application Security the definitive prevention-first ASPM - it is not just finding issues; it is fundamentally
changing how and when they get resolved.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Analyst Feedback
This is the slide to highlight external validation of what we are saying and the pain points we are solving
1. IDC recognizes that application risks in production remain one of the biggest pain points for security teams.
2. As development speed increases, the real challenge isn’t finding vulnerabilities — it’s knowing which ones actually matter.
3. Katie Norton highlights that Cortex Cloud ASPM connects AppSec with the live threat landscape, allowing teams to focus on real risk,
not noise.
4. The outcome? Organizations can stop threats faster and operate more efficiently — exactly what our prevention-first model is built
for.
🗣 (Optional closing line):
“So this IDC validation reinforces what we’ve been saying — visibility and context are key, but it’s the ability to connect security to active
threats that really changes the game.”
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Go To Market Lens
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Ideal Customer Profile
Lets first define who we are speaking to and the pain points they face.
Ideal Customer Profile typically includes:
1. Our sweet spot is medium to large enterprises with more than 100 developers
2. Typically, these are organizations in finance, healthcare, government, tech and SaaS - industries that face high regulatory pressure and
need both speed and assurance
3. They are usually in the middle of digital transformation, adopting cloud-native technologies like Kubernetes, Containers, Serverless
and multi-cloud environments.
4. They already have multiple AppSec tools but need correlation, automation, and visibility across them
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Path for Expansion
Now that we know who our ideal customers are, let’s talk about where the expansion opportunities lie - both within our existing base
and in new accounts.
First, existing Prisma Cloud or Cortex Cloud customers - these are the ones already using us for Cloud Posture Security (CSPM) or Cloud
Workload Protection but not yet AppSec.
We usually see three main categories here:
1. They don’t have an AppSec solution at all - these are perfect entry points for us to introduce Application Security as a natural next
step in their cloud security journey.
2. They already have multiple AppSec tools from different vendors - this is where the value of unification and correlation really lands.
We can show them how Cortex Cloud connects those fragmented scanners into one context-driven platform.
3. They already use some of our AppSec capabilities - these are ripe for expansion. Maybe they started with IaC or SCA, and now we can
grow into full Application Security Posture Management.
Then we have new customers - organizations that are currently overwhelmed by tool sprawl. They have got Anyk here, Veracode there,
Checkmarx in another team - and yet no one has a single view of application risk.
These customers are often asking for consolidation, efficiency, and visibility - exactly what Cortex Cloud AppSec provides.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Key Personas and Pain Points
There are few key personas you can look out on the customer side, who is responsible for AppSec conversations
1. First is AppSec Practitioner - she is managing risk, triaging alerts, and constantly under pressure to deliver security outcomes faster
2. Head of DevOps or DevSecOps: His/her focus is on speed and reliability. He fears that security controls will slow down pipeline or
break builds
3. The Developer: He/She is frustrated when vulnerabilities appear late in the cycle and he has no context to fix them.
Most important to take a note is these are the pain points that Cortex Cloud is designed to remove.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Discovery Questions
Now lets talk about discovery - because the best way to position Cortex Cloud AppSec is not by pitching features, but by asking the right
questions.
This slide gives you a good baseline, but I want to emphasize the ones that are landing really well in the field
1. Which AppSec tools are you using today - and how do your teams use them?
a. Start broad. You will uncover both the tool sprawl and process gap
b. Listen for words like Snyk, Veracode, Checkmarx, custom dashboards, or we built something in-house
c. Cortex Cloud Fit: (a) AppSec integration layer: Ingots 3rd party results (b) ASPM: Normalizes findings and correlates across tools ©
Unified visibility Dashboard - provides one view from code to cloud to runtime
2. When a production resource is found vulnerable - what happens next?
a. This one always lands
b. You will hear pain points like “we create a Jira ticket and hope someone fixes it or we manually trace ownership
c. That’s your entry point to talk about how Cortex Cloud enables automated attribution (pushes fix recommendations directly into
JIRA or IDE), guardrails and shift-left prevention
3. How are you prioritizing which vulnerabilities to fix first?
a. This is a golden question for uncovering context gaps
b. If they say “based on CVSS” - they are clearly missing runtime or business context
c. That is where we bring value with risk correlation across code, cloud and runtime
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Discovery Questions - Contd(1)
1. What security guardrails are you enforcing in your pipelines?
a. Great for DevSecOps conversations
b. It reveals whether they are scanning or actually blocking risky code or PRs and builds
c. If they are hesitant, it means there is a friction between dev and security - exactly the gap Cortex bridges
2. How are remediation tasks assigned and tracked?
a. The pain here is almost universal - “too many tickets, not enough context”
b. This opens the door to our automatic remediation, owner mapping and workflow integration with Jira and IDEs
3. Roughly how many developers commit code to protected repositories?
a. Always ask this toward the end - it is your sizing question for pricing
b. The sweet sport is 100+ developers, that is where automation and correlation really scale.
And other questions
- How are you handling AI-generated code today?
- This one sparks great conversations
- Many customers haven’t even considered that AI-written code can introduce unknown risks
- It positions Cortex Cloud perfectly as the nest-gen AppSec platform built for AI-era development
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Competition
CNAPP Vendors — Wiz, CrowdStrike
● These players are strong in cloud and runtime protection, but they’re now trying to move into AppSec by partnering with third-party
code scanners.
● The gap? They lack deep AppSec expertise — no native understanding of how vulnerabilities emerge in code, pipelines, or supply
chains.
● Cortex Cloud Advantage: We bring the AppSec brain into the cloud — correlating code, runtime, and identity data natively. That’s
something Wiz or CrowdStrike can’t fully do today.
💬 Line to use: “They start from the cloud down — we start from the code up.”
1. Wiz announced integrations with Snyk and GitHub Advanced Security for code scanning, but it’s federated ingestion, not native
scanning.
2. CrowdStrike introduced early AppSec capabilities via acquisitions (Bionic, and more recently, Flow Security), but again — it’s
runtime-centric: observing APIs and data flows, not developer pipelines.
3. Neither vendor offers first-party code scanners (SAST, SCA, IaC, Secrets) nor direct enforcement at the IDE, PR, or build level — which
are core AppSec prevention points.
4. Their AppSec motion is therefore integration-driven, not natively architected.
CrowdStrike introduced early AppSec capabilities via acquisitions (Bionic, and more recently, Flow Security), but again — it’s runtime-centric: observing APIs and data flows, not developer [Link] introduced early AppSec capabilities via acquisitions (Bionic, and
more recently, Flow Security), but again — it’s runtime-centric: observing APIs and data flows, not developer pipelines.
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Competition(1)
2⃣ AppSec Vendors — Snyk, Checkmarx, Veracode
1. These vendors have strong developer relationships and great scanning technology.
2. But their blind spot is runtime — they can’t connect vulnerabilities in code to risk exposure in production.
3. They also don’t ingest third-party AppSec tools, so customers still get fragmented visibility.
4. Cortex Cloud Advantage: We unify it all — native scanning (IaC, SCA, Secrets), plus third-party ingestion, plus runtime correlation.
5. That means one consistent view from code → cloud → runtime, not three disjointed dashboards.
💬 Line to use: “They can tell you what’s wrong in code. We can tell you which of those issues actually matter in the real world.”
3⃣ Startups — Ox, Apiiro, Cycode
1. Startups have done a great job of innovating in the ASPM category with broad integrations and lightweight scanning, but they struggle with
enterprise scale and context.
2. They often lack visibility across complex hybrid environments and can’t tie findings back to live workloads.
3. Cortex Cloud Advantage: Enterprise-grade platform, native integration with CSPM, CWP, and SOC workflows, and AI-driven correlation at scale.
💬 Line to use: “Startups give you features. Cortex Cloud gives you outcomes — backed by the enterprise ecosystem you already trust.”
Wrap-up (30 s)
“So across all three categories, Cortex Cloud delivers what no one else does — a prevention-first AppSec platform that brings together AI,
automation, and unified data from code to cloud to SOC.”
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Closing and Activation
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Pricing and Packaging
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Resources
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
Questions
© 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.