Summary
- NTT DATA and Palo Alto Networks announced a multi-year alliance targeting $1 billion in joint business by the end of three years, in 2029.
- The commitment joins platform access, threat intelligence and more than 2,000 certified professionals, but the announcement discloses no customer contract, booked revenue or measured security outcome.
The number is designed to travel. One billion dollars over three years gives the alliance a commercial horizon and gives both companies a way to organize sales, engineering and executive attention. It is not, however, a result. NTT DATA and Palo Alto Networks described the figure as a target for joint business by the end of 2029. They did not name a customer, a signed order, a revenue-recognition schedule or a regional allocation.
The operating commitments are more informative. NTT DATA is to receive early access to new Palo Alto Networks platform features. The companies promise joint engineering, co-innovation, coordinated delivery and dedicated Forward Deployed Engineers. More than 2,000 Palo Alto Networks-certified professionals sit inside a larger NTT DATA security footprint of over 7,500 professionals, more than 70 delivery centers and more than 20 Cyber Defense Centers.
Those resources are aimed at six workstreams: autonomous security operations, AI governance, identity security, Zero Trust and SASE, resilient cloud, and firewall modernization. This is broad enough to touch policy, data, identity, network enforcement, cloud posture and incident response. It is also broad enough for responsibility to blur. A platform may generate an alert; an integrator may tune it; a customer may approve remediation; a regulator may judge the record after an incident. “One solution” does not make those decisions one responsibility.
The alliance builds on an established relationship. A 2020 partnership expansion already combined NTT managed services with Prisma Access and Cortex XSOAR and referred to more than 2,000 NTT security specialists. Palo Alto Networks’ current partner page describes joint SASE, cloud-security and security-operations offerings. The 2026 agreement therefore increases coordination and ambition; it does not start from zero.
That history creates a fairer benchmark. The relevant question is not whether two capable companies can announce an integrated offer. It is whether the expanded model improves outcomes that a buyer can audit: time to detect and contain, false-positive load, policy coverage, configuration drift, identity exposure, recovery time and the proportion of recommended actions that require human reversal.
Early feature access deserves particular scrutiny. It can shorten the route from product change to managed service, but it also moves change risk closer to customer operations. A credible delivery contract should state which features are preview, which are production, who validates model behavior, how rollback works and which party owns an error introduced by a new control.
The announcement gives the alliance scale, a product-service architecture and priority industries. It does not yet provide the ledger that converts those inputs into resilience. That ledger will be the difference between a sales channel and an operating model.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

