Skip to content
Notifications
Clear all

Thoughts on the new Cortex XDR Pro tier? The price jump is huge.

3 Posts
3 Users
0 Reactions
3 Views
(@jacksonr)
Estimable Member
Joined: 1 week ago
Posts: 66
Topic starter   [#9058]

Just got the quote for our annual renewal, and wow — the jump from Cortex XDR Pro Per Endpoint to the new Pro Tier is significant. We're looking at roughly a 40% increase for our ~500 agent deployment. I know Palo Alto rolled in a bunch of new modules (Identity Threat Detection, Advanced WildFire, etc.), but it feels like a forced bundle.

From a pure cloud cost lens, this is like moving from On-Demand Instances to a pricey, all-inclusive enterprise license. You're paying for a lot you might not use. In our case, the new Identity module is great, but we already have a robust cloud identity solution. The bundle doesn't feel flexible.

Has anyone done a deep dive on the true ROI of the new Pro features versus the old à la carte model? I'm trying to build a FinOps-style business case:

* What's the actual per-incident time savings with the new automated playbooks?
* Is the Advanced WildFire data actually leading to fewer breakout incidents, quantifiably?
* For teams mostly using core EDR/XDR, does the price hike feel justified?

I love the platform's capabilities, but this pricing shift is a major cost center shock. Would love to hear from others who've negotiated or crunched the numbers. Are you accepting the bundle, pushing back, or exploring alternatives?

— Jackson


Right-size everything


   
Quote
(@devops_rookie_22)
Reputable Member
Joined: 4 months ago
Posts: 157
 

Yeah, that's a big jump. I'm not at the renewal stage yet, but seeing these posts makes me nervous for when we get there.

From my beginner perspective, your FinOps-style questions are spot on. I'd struggle to justify the cost without clear answers to exactly that, especially about time savings and breakout incidents. Have they shared any case studies with that data?

I wonder if this push to bundles is happening elsewhere, too. Feels like a trend.



   
ReplyQuote
(@data_diver_42)
Estimable Member
Joined: 4 months ago
Posts: 123
 

> without clear answers to that, especially about time savings and breakout incidents

This is the real sticking point. When our team looked at it, the sales deck was full of "advanced prevention" claims, but the actual incident data was vague. We pushed for metrics from our own PoC environment - things like mean time to contain (MTTC) for similar threat types before and after enabling the new modules. Even those were tough to isolate.

The bundling trend is everywhere. Look at the big cloud platforms - same playbook. You end up subsidizing features for other customers. Makes a true cost-per-value analysis almost impossible.

What's your current stack? Might be worth running a side-by-side PoC with your existing tools vs. the Pro bundle features to see if the delta is real for your environment.


Data is the new oil - but it's usually crude.


   
ReplyQuote