Research Note · Security · Licensing

Cybersecurity platform licensing: CrowdStrike, Palo Alto and peers.

Security vendors have mastered using urgency and fear to suppress commercial discipline at renewal. This note cuts past the threat narrative to what governs cost: per-endpoint and per-user models, module bundling, platform consolidation, hidden overlap with tools you already own, and the negotiation levers that reliably deliver 20–35% reductions without weakening security.

By James Hill-WoodUpdated Jul 20249 min readEmerging tech research cluster
Bottom line

There is no single cheapest security platform — only estates that are right-sized and estates that are not. Most large enterprises now carry multi-vendor security stacks of $10–30M annually, renewed under security urgency rather than commercial discipline, with annual list increases of 15–25%. The highest-value move is a module-by-module bundle audit that strips unused capability and surfaces overlap with tools already owned — typically 20–35% of spend before any competitive negotiation begins.

01 Key findings

  1. Security urgency is the pricing lever, not the technology. Vendors use legitimate continuity concerns to limit competitive evaluation, manage renewals close to expiry, and inflate the baseline with bundled modules of unclear current value.

  2. Bundles are priced to be over-bought. CrowdStrike Falcon Enterprise, Palo Alto platform bundles and Zscaler Elite consistently license more identities, ingestion, resources or premium tiers than are actually deployed. The bundle audit alone recovers 15–25%.

  3. You are probably double-paying for endpoint. Organisations carrying Microsoft E5 Security while separately buying CrowdStrike or SentinelOne overlap on endpoint protection — a $2–8M annual duplication at large scale.

  4. Consumption defaults are inflated. Palo Alto XSIAM ingestion assumptions overstate real logging needs by 2–3x; Prisma Cloud bills on peak rather than average resource counts unless negotiated otherwise.

  5. A credible alternative is worth 15–30%. A proof-of-concept SentinelOne, Cloudflare One or Microsoft Entra evaluation drives incumbent discounts that never materialise from renewal conversations alone — without any switch being required.

02 Vendor licensing models

Each platform meters differently, and the metering unit dictates where the cost risk sits. Endpoint vendors bill per agent; network security bills per user; consumption platforms bill on data and resources you must forecast in advance.

VendorPrimary metricBundle structureConsolidation playCost risk
CrowdStrikePer-endpoint; per-identity; per-cloud-workloadFalcon Go / Pro / Enterprise / EliteSingle agent, module-by-module (Falcon)Unused modules bundled into Enterprise tier
Palo Alto NetworksConsumption (GB/day) + endpoints, resourcesCortex XDR, XSIAM, Prisma Cloud / AccessPlatformisation across the full stack (Cortex)Over-forecast ingestion; peak resource billing
ZscalerPer-user, per-yearBusiness / Transformation / EliteZIA + ZPA + ZDX zero-trust suiteElite tier deployed to all, not target users
Microsoft DefenderPer-user (P1 / P2)Bundled in M365 E5 & E5 SecurityIncumbency via existing E5 estatePaid twice when overlapping standalone EDR
SentinelOnePer-endpointSingularity Core / Control / CompleteDisplacement pricing vs CrowdStrikeDisplacement discounts fade after year one

03 Cost at scale

Indicative list pricing per protected endpoint per year for comparable EDR/XDR tiers. The Defender line is the headline point: for E5 Security estates that capability is already paid for, so a separate agent duplicates it. Negotiated pricing deviates materially — model it net of committed volume.

CrowdStrike Falcon Enterprise
~$185/endpoint/yr
Palo Alto Cortex XDR Pro
~$165/endpoint/yr
SentinelOne Singularity Complete
~$140/endpoint/yr
Microsoft Defender P2 (in E5)
~$61/user/yr
Note

Zscaler prices per user on a separate axis (network security), with the Business-to-Elite premium typically 2–3x per user — making tier selection, not headline price, the decisive variable for large deployments.

04 The module-bundle overlap trap

The single most expensive pattern in enterprise security is capability paid for in more than one place. Bundles are designed to simplify procurement; left unaudited, they quietly accumulate modules that are licensed but never operationalised, and overlap with platforms the organisation already owns.

Highest-value tactic

The fully-deployed Defender assessment: before renewing any standalone endpoint contract, establish whether existing Microsoft E5 Security investment is actually being used. Defender for Endpoint P2 — EDR, threat hunting and vulnerability management — is genuinely competitive with CrowdStrike and SentinelOne where an organisation has deployed and operationalised it. Enterprises paying separately while carrying equivalent E5 capability are double-paying for endpoint security by $2–8M annually at large scale.

The same discipline applies within a single vendor: CrowdStrike Enterprise agreements routinely carry Falcon Identity Protection licences for more identities than are actively protected, premium threat intelligence unused by the internal team, and Falcon Complete MDR bought where internal MDR capacity already exists. Removing genuinely unused modules or downgrading over-specified tiers delivers 15–25% before competitive negotiation begins.

05 Vendor profiles

CrowdStrike
Endpoint / XDR leader
Best for: organisations wanting a single-agent platform with deep endpoint, identity and cloud coverage — and the discipline to license only deployed modules.
Levers
  • Bundle audit strips unused Falcon modules (15–25%)
  • Credible SentinelOne PoC drives 15–25% renewal discount
  • Multi-year deals cap escalation at 2–3%
Watch-outs
  • Annual list escalation of 15–22% in unadvised renewals
  • Identity / MDR modules over-licensed vs deployment
  • Enterprise tier bundled beyond actual need
Palo Alto Networks
Platformisation strategy
Best for: buyers consolidating endpoint, SIEM/SOAR, cloud and network security — provided consumption tiers are modelled independently.
Levers
  • Independent log-source analysis before XSIAM ingestion tiers
  • Average, not peak, resource pricing on Prisma Cloud
  • Platform bundle discounts against point-product incumbents
Watch-outs
  • XSIAM ingestion defaults over-forecast by 2–3x
  • Multi-year platform lock-in for short-term discounts
  • Migration effort understated in initial proposals
Zscaler & Microsoft
Zero trust & incumbent
Best for: zero-trust network access (Zscaler) and endpoint economics already funded through E5 (Microsoft Defender).
Levers
  • Right-size Zscaler tiers to user populations (20–30%)
  • Cloudflare One / Microsoft Entra as credible ZTNA alternatives
  • Operationalise E5 Security before renewing standalone EDR
Watch-outs
  • Elite tier deployed to all users, not just high-risk
  • Business-to-Elite premium of 2–3x per user
  • Defender value unrealised without deployment investment

06 Optimisation framework

Effective cybersecurity vendor management applies the same commercial disciplines as any enterprise software category, adjusted for the security-urgency dynamic vendors exploit. Four moves drive the outcome.

Factor 01

Reclaim the timeline

Begin at least 12 months before expiry. A genuine lead time removes the timeline pressure vendors engineer by managing renewals close to the deadline.

Factor 02

Audit modules and overlap

Establish actual deployment value for each licensed component, and map overlap with tools already owned — especially Microsoft E5 Security against standalone endpoint.

Factor 03

Benchmark consumption

Compare ingestion volumes, resource counts and per-unit pricing against market rates for comparable deployments before accepting vendor-default tiers.

Factor 04

Introduce a credible alternative

Run at least one viable competitor to each incumbent — SentinelOne, Cloudflare One, Microsoft Entra — to a proof-of-concept stage. The evaluation need not end in a switch to move price.

07 Our recommendation

CrowdStrike renewal
Audit before you negotiate

Strip unused Falcon modules and over-licensed identities first, then bring a credible SentinelOne evaluation to the table and lock a multi-year escalation cap of 2–3%.

Palo Alto platform
Model consumption independently

Do your own log-source analysis before committing to XSIAM ingestion tiers, price Prisma Cloud on average resource counts, and weigh platform lock-in against the short-term bundle discount.

Zscaler & Microsoft
Right-size and de-duplicate

Deploy Zscaler premium tiers only to the populations that need them, and confirm whether E5 Security already covers endpoint before paying twice.

08 Negotiation sequencing

The highest-value process choice at security renewal is refusing the vendor's preferred timeline and evaluation frame:

Advised & benchmarked Recommended

A 12-month runway, an independent module audit, consumption benchmarking and a live competitive evaluation. This consistently delivers 20–35% reductions without compromising security outcomes.

Urgency-driven Weaker

Renewal managed close to expiry, no competitive alternative, bundle accepted as presented. Timeline pressure and fear suppress commercial discipline — and price rises 15–25%.

Facing a security platform renewal?

Our vendor negotiation practice audits your security estate, benchmarks pricing and coordinates a competitive process across CrowdStrike, Palo Alto, Zscaler and Microsoft.

Get a confidential assessment →

The Licensing Edge

Weekly cloud and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.