Cybersecurity platform licensing: CrowdStrike, Palo Alto and peers.
Security vendors have mastered using urgency and fear to suppress commercial discipline at renewal. This note cuts past the threat narrative to what governs cost: per-endpoint and per-user models, module bundling, platform consolidation, hidden overlap with tools you already own, and the negotiation levers that reliably deliver 20–35% reductions without weakening security.
There is no single cheapest security platform — only estates that are right-sized and estates that are not. Most large enterprises now carry multi-vendor security stacks of $10–30M annually, renewed under security urgency rather than commercial discipline, with annual list increases of 15–25%. The highest-value move is a module-by-module bundle audit that strips unused capability and surfaces overlap with tools already owned — typically 20–35% of spend before any competitive negotiation begins.
01 Key findings
Security urgency is the pricing lever, not the technology. Vendors use legitimate continuity concerns to limit competitive evaluation, manage renewals close to expiry, and inflate the baseline with bundled modules of unclear current value.
Bundles are priced to be over-bought. CrowdStrike Falcon Enterprise, Palo Alto platform bundles and Zscaler Elite consistently license more identities, ingestion, resources or premium tiers than are actually deployed. The bundle audit alone recovers 15–25%.
You are probably double-paying for endpoint. Organisations carrying Microsoft E5 Security while separately buying CrowdStrike or SentinelOne overlap on endpoint protection — a $2–8M annual duplication at large scale.
Consumption defaults are inflated. Palo Alto XSIAM ingestion assumptions overstate real logging needs by 2–3x; Prisma Cloud bills on peak rather than average resource counts unless negotiated otherwise.
A credible alternative is worth 15–30%. A proof-of-concept SentinelOne, Cloudflare One or Microsoft Entra evaluation drives incumbent discounts that never materialise from renewal conversations alone — without any switch being required.
02 Vendor licensing models
Each platform meters differently, and the metering unit dictates where the cost risk sits. Endpoint vendors bill per agent; network security bills per user; consumption platforms bill on data and resources you must forecast in advance.
| Vendor | Primary metric | Bundle structure | Consolidation play | Cost risk |
|---|---|---|---|---|
| CrowdStrike | Per-endpoint; per-identity; per-cloud-workload | Falcon Go / Pro / Enterprise / Elite | Single agent, module-by-module (Falcon) | Unused modules bundled into Enterprise tier |
| Palo Alto Networks | Consumption (GB/day) + endpoints, resources | Cortex XDR, XSIAM, Prisma Cloud / Access | Platformisation across the full stack (Cortex) | Over-forecast ingestion; peak resource billing |
| Zscaler | Per-user, per-year | Business / Transformation / Elite | ZIA + ZPA + ZDX zero-trust suite | Elite tier deployed to all, not target users |
| Microsoft Defender | Per-user (P1 / P2) | Bundled in M365 E5 & E5 Security | Incumbency via existing E5 estate | Paid twice when overlapping standalone EDR |
| SentinelOne | Per-endpoint | Singularity Core / Control / Complete | Displacement pricing vs CrowdStrike | Displacement discounts fade after year one |
03 Cost at scale
Indicative list pricing per protected endpoint per year for comparable EDR/XDR tiers. The Defender line is the headline point: for E5 Security estates that capability is already paid for, so a separate agent duplicates it. Negotiated pricing deviates materially — model it net of committed volume.
Zscaler prices per user on a separate axis (network security), with the Business-to-Elite premium typically 2–3x per user — making tier selection, not headline price, the decisive variable for large deployments.
04 The module-bundle overlap trap
The single most expensive pattern in enterprise security is capability paid for in more than one place. Bundles are designed to simplify procurement; left unaudited, they quietly accumulate modules that are licensed but never operationalised, and overlap with platforms the organisation already owns.
The fully-deployed Defender assessment: before renewing any standalone endpoint contract, establish whether existing Microsoft E5 Security investment is actually being used. Defender for Endpoint P2 — EDR, threat hunting and vulnerability management — is genuinely competitive with CrowdStrike and SentinelOne where an organisation has deployed and operationalised it. Enterprises paying separately while carrying equivalent E5 capability are double-paying for endpoint security by $2–8M annually at large scale.
The same discipline applies within a single vendor: CrowdStrike Enterprise agreements routinely carry Falcon Identity Protection licences for more identities than are actively protected, premium threat intelligence unused by the internal team, and Falcon Complete MDR bought where internal MDR capacity already exists. Removing genuinely unused modules or downgrading over-specified tiers delivers 15–25% before competitive negotiation begins.
05 Vendor profiles
- Bundle audit strips unused Falcon modules (15–25%)
- Credible SentinelOne PoC drives 15–25% renewal discount
- Multi-year deals cap escalation at 2–3%
- Annual list escalation of 15–22% in unadvised renewals
- Identity / MDR modules over-licensed vs deployment
- Enterprise tier bundled beyond actual need
- Independent log-source analysis before XSIAM ingestion tiers
- Average, not peak, resource pricing on Prisma Cloud
- Platform bundle discounts against point-product incumbents
- XSIAM ingestion defaults over-forecast by 2–3x
- Multi-year platform lock-in for short-term discounts
- Migration effort understated in initial proposals
- Right-size Zscaler tiers to user populations (20–30%)
- Cloudflare One / Microsoft Entra as credible ZTNA alternatives
- Operationalise E5 Security before renewing standalone EDR
- Elite tier deployed to all users, not just high-risk
- Business-to-Elite premium of 2–3x per user
- Defender value unrealised without deployment investment
06 Optimisation framework
Effective cybersecurity vendor management applies the same commercial disciplines as any enterprise software category, adjusted for the security-urgency dynamic vendors exploit. Four moves drive the outcome.
Reclaim the timeline
Begin at least 12 months before expiry. A genuine lead time removes the timeline pressure vendors engineer by managing renewals close to the deadline.
Audit modules and overlap
Establish actual deployment value for each licensed component, and map overlap with tools already owned — especially Microsoft E5 Security against standalone endpoint.
Benchmark consumption
Compare ingestion volumes, resource counts and per-unit pricing against market rates for comparable deployments before accepting vendor-default tiers.
Introduce a credible alternative
Run at least one viable competitor to each incumbent — SentinelOne, Cloudflare One, Microsoft Entra — to a proof-of-concept stage. The evaluation need not end in a switch to move price.
07 Our recommendation
Strip unused Falcon modules and over-licensed identities first, then bring a credible SentinelOne evaluation to the table and lock a multi-year escalation cap of 2–3%.
Do your own log-source analysis before committing to XSIAM ingestion tiers, price Prisma Cloud on average resource counts, and weigh platform lock-in against the short-term bundle discount.
Deploy Zscaler premium tiers only to the populations that need them, and confirm whether E5 Security already covers endpoint before paying twice.
08 Negotiation sequencing
The highest-value process choice at security renewal is refusing the vendor's preferred timeline and evaluation frame:
Advised & benchmarked Recommended
A 12-month runway, an independent module audit, consumption benchmarking and a live competitive evaluation. This consistently delivers 20–35% reductions without compromising security outcomes.
Urgency-driven Weaker
Renewal managed close to expiry, no competitive alternative, bundle accepted as presented. Timeline pressure and fear suppress commercial discipline — and price rises 15–25%.
Facing a security platform renewal?
Our vendor negotiation practice audits your security estate, benchmarks pricing and coordinates a competitive process across CrowdStrike, Palo Alto, Zscaler and Microsoft.
The Licensing Edge
Weekly cloud and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.