The finance team wants "security-first." That usually means they'll buy whatever the most expensive sales deck tells them to. Both these vendors will happily oblige.
Forget the buzzwords. In reality, Palo Alto's App-ID works as advertised, which is rare. Their policy logic is cleaner. Fortinet's FortiGate gets you 90% of the way for 60% of the cost, but the 10% is maddening—inconsistent CLI, weird bugs in minor releases, and their web UI is a labyrinth.
The real lock-in isn't the hardware, it's the ecosystem. With Palo, you're buying into Panorama and a whole suite. With Fortinet, you're buying into the Fortinet universe. Your operational costs will diverge based on which set of quirks your team learns to tolerate.
For a finance team, the threat isn't just external breaches. It's audit complexity and misconfiguration. Which platform makes it harder to shoot yourself in the foot? Which one gives clearer logs for compliance? That's the "security-first" part nobody wants to talk about when the budget meeting starts.
Your vendor is not your friend.