Welcome to the 208th Pari Passu newsletter.

In November 2016, Francisco Partners and Elliott Management bought the Dell Software Group and split it into two companies. Quest Software was sold to Clearlake five years later for a reported $5.4bn, roughly double what the sponsors had paid for the pair. SonicWall, a thirty-year-old network security business serving small and mid-sized companies, saw less interest. After a failed 2021 sale process, the sponsors instead recapitalized the business, increasing leverage and leaving the company dependent on continued growth to carry the debt.

By 2026, that plan had failed. Growth stalled, margins deteriorated, and a September 2025 breach of firewall configuration backups accelerated the decline. With only a few months of liquidity remaining, SonicWall raised $113mm of new first-out debt, exchanged existing debt at par into second-out paper, and extended maturities to 2030. What makes the transaction interesting is that it left leverage higher than it found it, the sponsors kept 100% of the equity, and lenders took amortization and covenants instead, in a structure that can serve as a template for future distressed software credits. 

We will start with an overview of SonicWall's business model and four product families. From there, we will trace the ownership history and the capital structure Francisco and Elliott built, then walk through the operating deterioration, refresh-cycle problems, and breach that drove the company into distress. We’ll finish by covering the 2026 transaction, what the sponsors traded to retain control, and how much debt SonicWall can realistically support going forward.

Part of a firm that might benefit from a group subscription and full access to our Research and Data? Learn more and email us at: [email protected]

Why did Carta put a 25-foot magic eight ball in Grand Central?

Because "outlook uncertain" is no longer an acceptable answer.

PE professionals are split on AI, and reasonably so. Hallucination anxiety is real when fund data is on the line. But the problem isn't AI, it's AI that guesses instead of references.

Carta's new Claude Plugin doesn't approximate your portfolio. It reads it. Over $5.4T in equity, 50,000+ cap tables, 9,000+ funds—structured, verified, and first-party. No model can reconstruct that from the outside.

Fund AI has arrived. Ask your fund anything.

Business Model 

Every business that connects to the internet has to decide what is allowed through that connection. Take a fifty-person manufacturer. Its employees browse the web and exchange files with customers, its accounting system sits on the company network, security cameras and phones are connected to the same infrastructure, and outside vendors occasionally need remote access to troubleshoot equipment. All of that traffic ultimately passes between the company's private network and the open internet. Sitting at that boundary is a firewall, inspecting what comes and goes and deciding in real time which connections are legitimate and which should be blocked.

At a large bank, that firewall is one piece of a security operation staffed by hundreds of specialists and supported by millions of dollars of software. At the manufacturer, the entire IT function may be one employee or an outsourced local provider. Attackers do not sort their targets by headcount, leaving millions of smaller businesses exposed to many of the same threats without the people or budget to defend against them. That gap is the reason SonicWall exists.

SonicWall is headquartered in Milpitas, California, and has sold network security to small and mid-sized businesses (SMBs) for more than thirty years. The company builds firewalls, the physical appliances that sit at the edge of a network and filter what passes through, alongside three adjacent product families: secure remote access, endpoint software that protects individual devices, and managed security services that perform the ongoing monitoring customers cannot handle themselves. Roughly 70% of revenue is recurring, arriving through subscription and support renewals. The remaining 30% comes from the hardware itself, bought once and replaced every several years on a refresh cycle [2]. 

What separates SonicWall from most competitors is how it reaches those customers. It does not sell directly to the manufacturer; it sells to the local IT provider the firm has hired to install, configure, and manage its technology. SonicWall operates a 100% channel model through more than 17,000 distributors, resellers, and managed service providers (MSPs). Because SonicWall never sells around its partners, the MSP is in many ways the company's true customer, and the product line is built around MSP economics: one console for managing hundreds of client networks, predictable recurring billing, and deployment simple enough for a small IT shop to handle [1].

Network Security:

A firewall is a physical piece of hardware that sits between the building and the internet, and every piece of traffic going in either direction passes through it. When an employee opens an invoice attachment that turns out to be ransomware, the firewall is supposed to catch it in transit. A small appliance in a closet has to inspect traffic, much of it encrypted, in both directions without becoming the reason the office internet feels slow, and much of SonicWall's engineering effort over the years has gone into managing that tradeoff [1].

The product itself comes in three forms. TZ appliances serve branch offices and smaller sites, NSa appliances serve larger networks, and NSv virtual firewalls perform the same function as software inside cloud environments rather than through a physical box. Hardware is where the relationship starts, but the recurring revenue comes from the subscription bundled alongside it, which keeps threat intelligence current and, at the higher tiers, includes an embedded cyber warranty of up to $200,000 against a breach. Many SMB buyers cannot easily evaluate security software on its technical merits, so the warranty offers a financial backstop as well. The current generation is Gen 8, the prior generation is Gen 7, and the Gen 6 appliances still in the field are being retired, which will matter later [1]. Hardware is still an active part of the business, with SonicWall continuing to sell new appliances rather than simply supporting the installed base. 

Figure 1: SonicWall TZ Series Firewall Appliance 

Secure Access:

While the firewall protects the office, secure access protects everyone who is not in it. For two decades, the standard answer was a virtual private network, or VPN, which creates an encrypted tunnel back into the corporate network and treats the remote laptop as though it were plugged into the wall. The weakness is the same one we walked through in our Ivanti writeup: once the tunnel opens, the user is trusted across much of the network. A stolen password can therefore expose far more than the single application the employee needed. The newer “zero-trust” architecture grants access application by application and continuously checks both the user and the device, so a compromised login opens one door instead of the building.

SonicWall sold the older approach for years through a line of remote access appliances and still supports them. In December 2023, it acquired Banyan Security, a San Francisco company specializing in application-level access, and launched the resulting product as Cloud Secure Edge the following July. The pitch to partners is that they can pull out a customer's aging VPN, which is frequently unpatched, and replace it with something delivered from the cloud that requires no appliance at all [1].

Endpoint Security:

Endpoint software runs directly on the device and watches how programs behave rather than checking them against a list of known bad files. It also keeps a record of what happened on the machine, so that after an incident somebody can reconstruct how the attacker got in and what they touched. The feature partners tend to demonstrate first is the ability to roll a machine encrypted by ransomware back to its state before the attack, which is a concrete thing to show a small-business owner who will not follow a discussion of detection methodology. As with the firewalls, it is sold in tiers, and the top tier is the one where SonicWall stops selling the customer a tool and starts selling them the labor of using it [1].

Managed Services:

Owning security tools and monitoring them at three in the morning are different businesses, and the second is where SonicWall has been pushing hardest. A managed service provider running IT for forty small companies cannot staff a security operations center around the clock. Continuous coverage requires analysts on rotating shifts, which is more headcount than most MSPs employ in total, and threat hunting is a different discipline from the helpdesk and patching work that fills the rest of their day. SonicWall runs the center on their behalf and sells the coverage back as a white-label service the MSPs resell under their own name. Under the SonicSentry brand, SonicWall's analysts monitor alerts, hunt for threats, and respond when something goes wrong across all of a partner's client networks. If you’ve read our Optiv writeup, the service is similar to Optiv’s managed services segment, except instead of working with a large enterprise, SonicSentry supports an MSP serving dozens or hundreds of SMBs. The layering matters, as SonicWall's analysts watch the MSP's clients while the MSP owns the relationship, putting SonicWall two steps from the business actually being defended. That capability also came through acquisition. In November 2023, SonicWall bought Solutions Granted, a Virginia managed security provider serving hundreds of channel partners. Notably, SonicSentry monitors competitors' endpoint software alongside SonicWall's own, including CrowdStrike and SentinelOne. An MSP’s installed base is almost always mixed, and refusing to cover products SonicWall did not sell would mean giving up the engagement. That willingness signals the same shift many sponsor-backed cybersecurity vendors attempt: becoming an embedded operating partner, rather than just a vendor [1]. 

Market Dynamics:

Above SonicWall sit enterprise-first vendors such as Palo Alto Networks and Cisco, whose products are generally priced and built for organizations with dedicated security staff rather than thirty-person offices. The competitor that matters most, however, is Fortinet, which spans both markets and has spent years targeting SonicWall's installed base directly. Channel checks describe a consistent pattern: SonicWall wins on price-to-performance and ease of deployment, then loses when a customer grows large enough to benefit from Fortinet’s larger portfolio [1]. 

Lastly, SonicWall's business rests on an installed base of appliances that customers replace on a refresh cycle, and each refresh is a rare moment when the vendor decision gets reopened. The moat is therefore the 17,000-partner channel and the inertia of the boxes already on the wall. Both depend on partners continuing to believe those boxes are doing their job quietly. What happens when that belief comes under pressure is the subject of the rest of this piece. 

Corporate History

Two brothers, Sreekanth and Sudhakar Ravi, founded SonicWall in 1991 as Sonic Systems, selling Ethernet hardware that connected Apple computers to local networks. The pivot that produced the company today came in 1997, when it shipped a dedicated hardware appliance combining a firewall and VPN software, aimed at businesses that could not afford anything else. The product was renamed SonicWALL in 1998, the company took the product's name in 1999, and it went public on Nasdaq under the ticker SNWL that same year. The founding proposition has not changed since: affordable, adequate security for organizations that cannot buy the expensive kind. The company’s commitment to selling through channels arrived early, with a formal program for managed security providers launched in 2005, two decades before that route to market became the industry's consensus answer for the small-business segment [3]. 

The first take-private came in June 2010, when an investor group led by Thoma Bravo, alongside Ontario Teachers' Pension Plan, agreed to acquire the company at $11.50 per share, valuing it at roughly $717mm, with a premium of about 28% over the prior close. Thoma Bravo held it for less than two years [4]. 

In May 2012, Dell bought SonicWall for a reported $1.2bn. Dell was actively assembling a software portfolio to sell alongside its hardware, and it bought Quest Software the same year for $2.4bn. Between 2010 and 2015, Dell spent roughly $4.2bn building its software group, but that strategy did not survive its merger with a larger company. When Dell agreed to acquire EMC for $67bn in 2015, it needed cash and reversed course, doubling down on hardware, and the software group was the obvious thing to sell. In June 2016, Dell agreed to sell the entire Dell Software Group to Francisco Partners and Elliott Management for over $2bn, taking a ~50% loss on the portfolio, with the deal closing that November [5].

The buyers immediately split the package back into two companies, Quest and SonicWall, on the reasoning that the businesses served different markets and had nothing operationally to gain from each other. However, the split was not perfectly clean. The valuable identity and access management business, roughly $200mm of revenue that had originally come in through SonicWall, was moved to Quest because it sold directly rather than through channels, so SonicWall emerged from the carve-out meaningfully smaller than it went in. Francisco then sold Quest to Clearlake Capital in November 2021 at a reported $5.4bn, more than doubling the price paid for both companies together. SonicWall, acquired in the same transaction, has not been sold despite efforts.

Once separated, SonicWall took on a capital structure of its own, and in 2018 it raised a $452mm 1L term loan due May 2025, and a $175mm 2L term loan due May 2026, alongside a $50mm revolving credit facility. A significant portion of proceeds went toward funding a sponsor dividend. Total funded debt of roughly $627mm sat against a business far less profitable than it would soon become. Margins were only about 15% at the separation, which, on the revenue base of the time, implies EBITDA somewhere in the $50-60mm range and leverage in the low double digits [7]. 

In June 2021, Francisco and Elliott engaged Morgan Stanley and prepared to launch a sale process, targeting a valuation above $2.5bn. The company was generating close to $400mm of revenue and approximately $125mm of EBITDA and growing at around 10% a year, which put the target at roughly 20x EBITDA. For a performing software business in mid-2021, this was a bold but not unreasonable figure, but the process did not produce a sale [6]. 

Instead, the lack of buyer interest led to another dividend recapitalization later that year that added $210mm of debt and took leverage to 7.9x. The dividend was funded via a $185mm add-on to the 1L term loan and a $25mm add-on to the 2L, bringing total facility sizes to $637mm and $200mm, respectively. Together with the 2018 dividend, we estimate the sponsors had pulled something in the high hundreds of millions out of the business by the end of 2021. And while no buyer was willing to pay 20x, debt detaching at 8x on a sticky software business looked relatively safe at the time [7]. 

Figure 2: 2021 Dividend Recap Cap Table

Path to Distress

In the summer of 2023, SonicWall was carrying the debt the 2021 dividend recapitalization had left behind. The first lien term loan came due in May 2025 and the revolver the preceding February, which put the company within two years of a maturity wall. Refinancing was the obvious move, and the loan market was relatively receptive. The new 1L term loan came to market at $725mm but was cut to $650mm during syndication, priced at S + 5.00%, a 150 bps increase from the existing loan’s S+3.50% spread and a fairly standard coupon bump for a refinancing of this kind. 

When the deal was launched at $725mm, SonicWall planned to repay the $613mm existing 1L term loan and $100mm of its 2L, extending the first lien maturity from May 2025 to May 2028 and the upsized revolver from February 2025 to February 2028 [8]. However, with the loan cut to $650mm, we’ll assume SonicWall only repaid $50mm of the 2L, leaving a $150mm stub, and funding the uncovered portion of the paydown with balance sheet cash. The $150mm stub reconciles with the $152mm incremental 1L tranche that SonicWall would later raise to repay the remaining 2L.

The reported pro forma metrics looked defensible. Pro forma leverage came in around the mid-7x area. The company had roughly $79mm of cash, revenue of approximately $400mm for the twelve months to April 2023, about 71% of it recurring, with an adj. EBITDA margin of 26.5%, up from roughly 15% at the 2018 separation. That last figure is the one that made the credit work. A business that had nearly doubled its margin in five years while growing was a reasonable thing to lend against at seven times [8]. 

Figure 3: 2023 Refinancing Cap Table

Despite a justifiable leverage profile, the interest bill was substantial in a 2023 rate environment. Applying the 26.5% margin to roughly $400mm of revenue gives EBITDA of approximately $106mm, which cross-checks against Moody's mid-7x leverage on roughly $800mm of total debt. With SOFR above 5.3% in August 2023, the $650mm 1L term loan carried an all-in rate above 10%, producing roughly $67mm of annual cash interest. The remaining second lien added another approximately $19mm, bringing total cash interest to roughly $86mm and interest coverage to only about 1.2x. 

There was still a clear underwriting case: roughly 75% of the installed base had yet to migrate to the Generation 7 platform, creating a large refresh cycle directly in front of the company. Cloud offerings were about 16% of revenue and growing, recurring revenue remained above 70%, margins had been improving for years, and both agencies expected low-single-digit organic growth with leverage drifting lower over time. Moody's said it did not expect SonicWall to draw on the revolver at all over the following 12 to 18 months, reinforcing that positive trajectory [2]. 

SonicWall later raised a $152mm incremental 1L term loan to refinance the remaining 2L, effectively moving that debt into the first-lien stack before any downturn. 

Through the first seven years of Francisco and Elliott's ownership, SonicWall made essentially no acquisitions. Then, in a ten-week window beginning weeks after the refinancing closed, it made three. It bought Trapmine, a Turkish endpoint and malware detection specialist, in October 2023. It bought Solutions Granted, a Virginia managed security services provider supporting hundreds of channel partners, in November, and installed its chief executive to run SonicWall's managed services. It bought Banyan Security, a San Francisco zero trust access company, in December. Banyan became Cloud Secure Edge when the platform launched in July 2024, and Solutions Granted became the operations center that SonicSentry rents back to partners [1].

As a reminder, SonicWall closed the refinancing with roughly $79mm of unrestricted cash and an expectation of roughly $15mm of annual free cash flow, and then spent a meaningful portion of the cash on three acquisitions inside a single quarter. SonicWall had no history of tuck-in acquisitions and now carried substantial execution and integration risk. The company that entered 2024 was running a materially thinner balance sheet than the August closing figures suggest.

Over the next two years, the operating case never arrived. The hardware refresh that was supposed to help SonicWall instead became a point of vulnerability. Generation 6 hardware was reaching end of support during FY’26, which meant customers had to replace appliances they may not have thought about in years. That should have created a natural upgrade cycle for SonicWall, but it also gave customers a reason to compare alternatives, and the upgrade cycle the 2023 credit case had counted on did not translate into growth. Revenue was approximately $400mm in April 2023 and only about $405mm over the next two years, effectively flat across the period the company was supposed to be growing into its leverage. Adj. EBITDA margin fell from 26.5% at the refinancing to roughly 19.2% in FY’25 (ending January 2025), which on a flat revenue base represents roughly $29mm of lost EBITDA. By 2025, SonicWall began drawing the revolver Moody's had said it would not need [9]. 

Compounding the issues above, in September 2025, SonicWall disclosed that an unauthorized party had accessed firewall configuration backup files for every customer using its cloud backup service. Those files can contain the rules that govern a customer's firewall, the services exposed to the internet, and information tied to credentials and access. In other words, the breach exposed the blueprint for how those networks were protected. For a company selling security infrastructure to small businesses and MSPs, that was an especially damaging failure, because the company’s entire value proposition to a small business is that the customer does not have to think about any of this. 

The September 2025 breach was not an isolated event. SonicWall products have appeared 14 times on the U.S. government’s list of actively exploited vulnerabilities since late 2021, nine in connection with ransomware campaigns [15]. In 2021, attackers exploited a flaw in SonicWall’s remote access products against the company’s own systems, while three separate weaknesses in its email security products were used against customers. In March 2023, a suspected Chinese group installed malware on older remote access devices that could remain even after software updates. The following year, attackers began exploiting a serious flaw in SonicWall’s operating system and VPN products, with one security firm tracking more than thirty intrusions through that weakness over the next two months [16].

That same weakness resurfaced in July 2025, producing roughly forty attacks in three weeks. SonicWall later found that many of the affected devices were firewalls that had been moved from Generation 6 to Generation 7 without resetting locally stored VPN passwords. The refresh cycle lenders had underwritten as a growth opportunity was also the period when customers were replacing hardware and carrying old settings into new devices, creating another opening for attackers [15]. 

The September 2025 breach was different, though, as this time attackers reached SonicWall’s own cloud backup service. SonicWall initially said on September 17 that fewer than 5% of its installed base was affected. On October 8, after an investigation with Mandiant, a cybersecurity firm, it said backups for every customer using the service had been accessed [15]. For MSPs that had spent three weeks telling clients the exposure was limited, that reversal was tough to convey to customers. 

The immediate damage showed up less in churn than in new business. Customers did not leave in large numbers due to the recurring nature of contracts, but new sales slowed sharply as SonicWall dealt with remediation and prospects delayed purchasing decisions. The MSPs that distribute SonicWall also had to explain the breach to their own customers. That was made worse by both the string of prior incidents and SonicWall’s handling of this one, mishandling the damage of the September 2025 hack. In the third quarter of FY'26, ended October 2025, billings fell roughly 33% and revenue fell roughly 15%. Because billings tend to lead reported revenue, the drop pointed to continued weakness beyond the quarter itself [9]. 

Margins continued to deteriorate. Adj. EBITDA margin fell to roughly 16% to 18% in FY'26 from about 19.2% the year before and 26.5% at the 2023 refinancing. Lower revenue was compounded by the cost of incident response, customer remediation, and additional security work. Leverage reached approximately 10x for the twelve months to October 2025, up from the mid-7x area at the refinancing, implying an EBITDA decline to the low $80mm range. 

By late 2025, the issues above had translated into significant liquidity pressure. At the end of the third quarter of FY'26, in October 2025, SonicWall had roughly $60mm of liquidity. That figure comprised $24mm of balance sheet cash and the roughly $38mm still undrawn on its $75mm revolver, with $37mm already outstanding. $60mm did not last long, as FY’26 (ended January 2026) cash burn reached approximately $70mm including term loan amortization [11]. 

By the end of April 2026, the revolver was fully drawn, and SonicWall held roughly $20mm of cash against it. The company had gone through the whole $60mm cushion in two quarters, and at the prevailing burn rate, what remained was about a quarter of runway. The transaction we cover next was not optional [11]. 

The loan market reached the conclusion very quickly. SonicWall's first lien term loan traded around par into September 2025, then began falling after the breach. It was quoted in the mid-80s by mid-December, the mid-60s around year-end, and the mid-50s by the week of mid-January 2026. By late February it traded in the low 30s [12]. With roughly $862mm of funded first lien claims and nothing meaningful sitting beneath them, a 32-cent recovery implied a value of only ~$275mm. That compares with the roughly $2.5bn valuation Francisco and Elliott had sought in 2021. 

SonicWall was also trying to raise money in an ugly market. Software loans were the worst-performing sector in the leveraged loan market in early 2026, down roughly 3.5% in the opening weeks of the year against a 0.9% decline for loans generally, as investors reassessed whether software businesses were structurally exposed to artificial intelligence. That thesis fit SonicWall poorly. Nobody is replacing a firewall appliance with a language model, and it was later argued that AI-enabled attacks increase rather than reduce demand for purpose-built network security. Regardless, while the AI/software backdrop did not create the company's distress, it meant SonicWall was looking for capital at the same moment investors were becoming more skeptical of anything that even looked like software. Let alone software with a history of hacks. 

By January 2026, SonicWall had retained Kirkland & Ellis and PJT Partners, while lenders organized with Gibson Dunn and Centerview. Advisors on both sides were under confidentiality by late February, and minority lenders later formed separately. Talks were not smooth, and by April members of the majority lender group had threatened to leave negotiations, while Gibson Dunn was working to assemble a cooperation agreement. By then the debt was in the low 30s, and liquidity was measured in months [12].

The 2026 Transaction 

In June 2026, roughly five months after advisor talks began, SonicWall closed its comprehensive new money and amend-and-extend transaction.

You are about to reach the midpoint of the report. This is where the story gets interesting.

Free readers miss out on the sections that explain:
• Breakdown of the 2026 LME (with Detailed Economics and a Focus on Amortization)
• Why the Deal Stayed Consensual
• The Sponsors’ Equity Option
• Pro Forma Debt Capacity
• Key Takeaways and Lessons

Upgrade to Pari Passu Premium to access the remainder of this deep-dive, the full archive with over 200 editions, and our restructuring drive.

Professionals accessing Pari Passu in connection with their work at a financial institution, investment firm, law firm, consulting firm, or any other commercial enterprise are required to upgrade to the Research Tier.

All subscriptions are licensed for a single user. No subscription, at any tier, may be shared, forwarded, or made accessible to other employees, colleagues, or a shared/group inbox. Firms with multiple users must obtain a group subscription. To set up group access for your team, please contact [email protected]

Our LME Tracker is reserved for group subscriptions

logo

Unlock the Full Analysis and Proprietary Insights

A Pari Passu Premium subscription provides unrestricted access to this report and our comprehensive library of institutional-grade research

Upgrade Now

A subscription gets you:

  • Institutional Level Coverage of Restructuring Deals
  • Full Access to Our Entire Archive
  • 200+ Reports of Evergreen Research
  • Full Access to All New Research
  • Access to the Restructuring Drive
  • Join Thousands of Professional Readers

Keep Reading

View more