Could Nadav Zafrir Accelerate Check Point's Growth?
When Check Point chose a startups guy to replace Gil Shwed, investors hoped for him to shake things up at the sleepy company and accelerate growth. This isn't happening so far, and might never will.
A visionary founder is often succeeded by a more financially-responsible grown-up leader (Tim Cook taking over Apple after Steve Jobs is the canonical example). Check Point’s case, however, was quite the opposite. Founder Gil Shwed himself played the Tim Cook role of a grown-up who prioritizes margins over making risky investments; Nadav Zafrir, a cybersecurity VC and former 8200 commander, took over 18 months ago, with the task of bringing innovation and startup culture to drive growth. In other words, to be Steve Jobs. So far though, it is proving to be harder than investors initially thought.
Growth CEO?
Check Point’s stock jumped in the summer of 2024 when the company announced Nadav Zafrir as its next CEO, in hopes that he could finally bring back growth. The previous CEO, Check Point founder Gil Shwed, had struggled with growth the last 15 years. Shwed is credited with inventing the firewall – and the network security industry at large – and building Check Point as a leader in this category; he is also criticised for missing the 2010 cloud security boom. Check Point grew revenue at an impressive 20% CAGR for nearly two decades after Shwed started it in 1993, but it’s been 15 years since it last reported double-digit revenue growth. The inflection point arrived later that decade, when archrival Palo Alto Networks surpassed Check Point’s revenue while capturing the emerging SaaS and cloud security markets. Check Point was left behind, growing at a ~6% clip since 2011 and steadily losing market share.

I wrote last year after Zafrir took over as CEO:
It’s almost as if Shwed views Check Point high margins, alongside its fortress balance sheet holding over a billion dollars in cash, as a financial firewall of sorts. It sure helped protect Check Point against the adversary markets of the dot-com bust and the global financial crisis. Yes, growth is important, but Shwed is not the kind of CEO that would simply remove a critical protection layer, and increase its company’s exposure to financial risks.
Back in 2012, when asked about Palo Alto Networks going public, Shwed mentioned that “during our 16 years of being a public company, we’ve seen 4 generations of competitors come and go”. But what was the right call for Check Point’s first 16 years of existence – being prepared for a slowdown – did not turn out to be the rewarding mode of operation over the next 16 years. The golden age of SaaS and Cloud and Mobile created a rapid expansion of the cybersecurity market, only a small portion of which ended up being captured by Check Point; a far larger portion was captured by Palo Alto Networks, which today is a cybersecurity juggernaut valued at over $120B, roughly 6-times Check Point’s market cap. Its net margin, however, doesn’t come near Check Point’s impressive level of profitability.
A new CEO would probably be needed, in order to reconfigure the financial guardrails and re-architect how Check Point allocates its resources; that is exactly the job of its new chief executive, Nadav Zafrir.
Previously, Zafrir co-founded and managed Team8 – a cybersecurity-focused combination of an accelerator and VC fund – so as a startup guy, a common narrative went, he must know a thing or two about innovation and growth. Perhaps he could shake things up inside sleepy Check Point. The stock rally peaked above $230/share 2 quarters into Zafrir’s tenure, but has since completed a 50% decline. While AI-related concerns loom in the background, the immediate reason seems to be disappointing revenue growth.
Not for lack of trying: Zafrir increased expenses on both sales and R&D, and bought five cybersecurity startups; yet the company only grew sales by less than 7% during his first year on the role, and is now projecting less than 5% growth for 2026, Zafrir’s second year.
So why aren’t investors seeing returns on investments made by their new CEO? As we’ve discussed in previous articles, investments only generate returns when they’re made within a business moat. Which brings us to the question of, does Check Point have a moat?
Check Point’s Castle and Moat
Check Point’s moat was rooted in selling, well, the actual moats of the castle-and-moat security paradigm: the firewalls guarding the on-premise enterprise network. The transition to the cloud required a new security paradigm: zero-trust, which in turn created a new market for cybersecurity products. While it was other companies – like Palo Alto Networks, Crowdstrike and ZScaler – who captured the new cloud security market, not everyone moved to the cloud overnight. Check Point’s security products are still well entrenched within the laggards. Yes, that term from the book Crossing The Chasm.

While the focus of Silicon Valley is naturally given to how new technologies get adopted and penetrate the mainstream market, the interesting dynamics on the other end of the spectrum go unnoticed. In Crossing The Chasm, Geoffrey Moore defined laggards as people who “simply don’t want anything to do with new technology, for any of a variety of reasons, some personal and some economic,” and that they are “not worth pursuing” as customers. That is exactly what makes them so compelling for an incumbent who had gotten displaced1.
Risk-averse organizations that were the last to adopt the cloud – such as financial services, healthcare providers, government agencies, telecom giants – were also most hesitant to migrate off of their Check Point firewalls. As long as Check Point does a decent job providing incremental new capabilities they will remain Check Point customers.
Gil Shwed doesn’t get enough credit considering how well he executed this playbook for the last 15 years: while he did miss the emerging cloud security market, he was able to defend Check Point’s position as the security vendor for the cloud-laggards, while protecting his own company’s profit margins. He was a good fit for this customer profile, as employees often described Shwed himself as skeptical and slow to adopt new technologies.
The laggards playbook doesn’t expand the customer base, but it does have opportunities for growth through upselling new products to existing customers. Those products are often sourced by acquiring local startups. Israel has a bustling cybersecurity startup scene, and it’s not unusual for several companies to be built around the same security category2. Industry leaders often bid aggressively once a winner emerges, in several cases paying hundreds of millions of dollars to integrate the category leader into their platform. Palo Alto Networks in particular is known for building its platform by purchasing startups at steep ARR multiples, enabling it to increase revenue nearly tenfold over the last decade. Check Point, with a much smaller customer base over which to amortize acquisitions, needed a different playbook. Serving slower moving customers, Shwed could afford to wait longer, and often acquired the category runner-up or an adjacent technology3 at meaningfully lower valuations.
I’m using the castle-and-moat metaphor here in two distinct senses: one is the security paradigm of the on-premise era, where the castle represented the organization’s internal network, and the moat was the firewall protecting its perimeter. The other is the moat as something that represents a competitive advantage, an analogy popularized by Warren Buffett. Here he is explaining it in Berkshire’s 2000 annual meeting:
Every business that we look at we think of as an economic castle. And castles are subject to marauders. And in capitalism, any castle you have, whether it’s razor blades, or soft drinks, or whatever, you have to expect, and you want the capitalistic system to work in a way that, millions of people are out there with capital thinking about ways to take your castle away from you, and appropriate it for their own use. And then the question is, what kind of a moat do you have around that castle that protects it?
In Check Point’s case, the two analogies align: the legacy castle-and-moat security architecture is what powers the company’s business moat, and as long as Check Point invests within that perimeter, it earns attractive returns. The catch is the size of the castle. The laggards segment is defensible but limited, and slowly shrinking. To accelerate growth, Check Point would need to invest beyond the perimeter of its moat.
“What can you do in order to change the growth trajectory?”
During the last earnings call, Zafrir was faced with a frustrated analyst’s question about the disappointing growth trajectory:
Tal Liani BofA Securities, Research Division – MD, Head of Technology Supersector & Senior Analyst
Nadav, I’m going to come back to the same question. You joined the company a few years ago with hope that growth is going to accelerate. You’ve done many things on sales, on products, and growth has decelerated instead of accelerating in the sense that we are now at a 5% environment. It’s just not big enough for such a great space, there could not be a better space for you to grow and accelerate revenue growth.
So the question is, what is not working with the strategy? How can you change the growth trajectory to the point that we see double-digit -- sustainable double-digit growth? And really to synthesize the question, the issue is what is the problem? Meaning, is it about sales execution? Is it about the portfolio? Is it about the employee composition and the fact that maybe culture needs to change? I’m trying to understand. What can you do in order to change the growth trajectory?
Nadav Zafrir Check Point Software Technologies Ltd. – CEO & Director
So first, Tal, I totally agree that we couldn’t be in a better industry right now. And I think that, like you said, that’s why I’m here, and that’s what I’m here to do. Look, as we said before, yes, some of it is execution, and that’s why we’re making these changes that we just spoke about, which are meaningful, hundreds of people getting new accounts, moving seats, putting new leaders. I think it’s essential, giving us a short-term headwind, but I think we’ll drive that sustainable growth that you’re looking for.
At the same time, I do want to say that when you look at the total product portfolio that we have, although it’s still not the biggest part of what we do, if you look at the emerging technologies that we have, right, e-mail, CTEM, SASE and hopefully -- and now joining with security for AI, that as we spoke about before, is growing really, really fast and becoming a bigger piece of what we’re doing.
So all in all, I think that the vision and the strategy are there. We’re making the changes that we need to do. It does take time, and we need to continue course and have the patience to get there because we need to do it with discipline, and that’s what we’re doing, and it’s going to take time, but I believe that we’re in the right business with the right products. In every one of the pillars that I spoke about, we’re also looking at acquisitions. And I believe that when you bake all that together with the leadership that we’re putting in place, we’ll be in a good place in the future.
I am not sure Zafrir has “the vision and the strategy” to accelerate Check Point’s growth! And not because he isn’t hard-working or talented enough; just like Buffett found out through Berkshire’s doomed textile investments, or BlackBerry’s failed post-iPhone pivots, it’s the reality of business economics.
If you were in Zafrir’s shoes, what could you do to grow faster than Shwed’s 6%? There are a few strategic alternatives:
Invest within Check Point’s existing moat. Make more tuck-in acquisitions, build more features, and sell them aggressively to the existing customer base.
Expand the customer base into less conservative customers.
Bet heavily on AI security through aggressive investments and acquisitions to establish a dominant position.
None of these is easy.
I mean, the first option is rather easy, since it’s essentially continuing the Shwed playbook; but why would it lead to a faster growth than Shwed was able to achieve? Shwed executed it quite well. It’s just that Check Point’s existing customer base, all the way at the end of the Crossing The Chasm diagram, doesn’t offer that much opportunity to capture additional revenue.
The second option is essentially Check Point making investments outside its moat. Why should they earn decent returns then? Industry leaders have been spending several times as much as Check Point on R&D and Sales, year after year after year, in order to establish wide moats around the more pragmatic segments of the market; how could Check Point expect to penetrate these moats? While it may work on the margin – it is possible to sign an additional customer through discounting or custom tailored features – the returns diminish quickly. There is a reason Shwed stayed in his lane for the last decade.
The existing moats, however, are relevant for the current market structure. Another shake up might be coming. The current leaders of the security industry weren’t even around back when Check Point was a leader, during the golden age of on-premise network security. It’s just that the cloud paradigm shift changed the market structure, rewarding those who invested early and aggressively.
Which leads to option number 3. Organizations are already terrified with the security implications of AI. There is going to be a new adoption cycle. Which could result in a different market structure. Could Check Point do to Palo Alto Networks what PAN once did to it? That scenario could make for an incredible article in this blog, but it seems very unlikely. Indeed, Check Point recently appointed a general manager for its AI security business division. A critical condition for disruption, however, is for the incumbent to ignore and dismiss the new thing. That doesn’t seem to be the case, as AI security is already the hottest category in cybersecurity. Palo Alto Networks closed its ~$500M acquisition of Protect AI in mid-2025 to anchor a new platform called Prisma AIRS, and just months later announced a $25B deal for CyberArk, explicitly framed as building “the end-to-end security platform for the AI era.” Google, meanwhile, completed its $32B acquisition of Wiz – the biggest in its history – a few months back. Check Point’s $13B market cap pales in comparison. While Check Point could (and should) sell AI security products to its existing customers, it is hard to envision how AI could improve its market position.
The thing with the growth vs. margin dilemma is that it is not a perfect trade-off; you can’t simply forfeit 1% of profit margin in exchange for an additional 1% of revenue growth. Zafrir has increased spending on R&D and sales, but since growth hasn’t accelerated, the only outcome so far is lower profits.
Businesses must first establish a moat around some market segment – which requires capital, effort, patience, and some amount of luck – before they can enjoy high returns on investments within that moat. And there just doesn’t seem to be a viable path for Check Point to establish a moat around a bigger market segment.

Perhaps Zafrir is already starting to come to terms with this reality, as Check Point announced last week that it is expanding its share repurchase authorization. Which might imply that it is still following Shwed’s playbook and prioritizing prudent capital allocation rather than taking large bets. One sentence stood out to me:
Since the beginning of the share repurchase program, Check Point has repurchased approximately 230 million shares for a total purchase price of approximately $17.4 billion.
$17.4B spent on share buybacks4! That money can buy roughly half of Wiz in 2026, but the numbers in the industry were much smaller back in Check Point’s glory days.
It’s interesting to imagine what would happen in an alternative universe, where Shwed would have stepped down 15 years ago, in the early days of SaaS and Cloud. Where a more daring CEO would have used this money to make aggressive early bets on Cloud security, back when Check Point still had more resources than Palo Alto Networks or ZScaler.
At this point, however, executing Shwed’s playbook and buying back shares is probably the best thing Zafrir could do. If he could come to terms with the fact that growth is not going to accelerate.
Not financial advice. This post is for educational and general purposes only and should not be relied upon for investment decisions.
Loyal readers of this blog may identify that a similar dynamic occurred around IBM’s mainframe business.
In some cases, these companies are founded by ex-Check Point employees.
Check Point often mentions e-mail security is an example for an underlooked niche that it was able to take over through the acquisition of Avanan.
This also means that Check Point had bought back shares at an average price of $75, significantly below where the stock currently trades, which is good news for investors.



הי מתן
יש צפי לחזרה של אופטיקאי מדופלם?
זה לא אותו יום שישי בלי זה....
תודה!
I sold my position as soon as the company shifted from being debt-free to carrying debt.
I had been holding the stock for 5 years and originally bought during the COVID crash, so this was not a short-term ownership for me. I've never missed an earnings call. But the direction the company started taking changed my view completely.
The Lakera acquisition also looked questionable from the start. Check Point paid $300M for the company, yet when you look into Lakera’s research page and some of the backgrounds of their team members, it raises legitimate questions about how thorough the due diligence process really was.
For example, one of Lakera’s Senior Research Engineers previously worked on a small "AI" party game project with friends before joining Lakera. For a cybersecurity AI startup valued at $300M, that is not exactly the type of background you would expect to justify such a valuation.
As we say in Hebrew, it feels like Check Point bought a “cat in a sack”, paying first and asking questions later.