A10 Networks, Inc. (ATEN) Earnings Call Transcript & Summary
July 13, 2023
Earnings Call Speaker Segments
Unknown Executive
executiveHello, everyone. Thank you for attending today's webinar, Bridging the Security Gap for Regional broadband presented by A10 Networks. I'm Andrea Anderson and I'll be monitoring this webinar. I'd like to start off by introducing today's speakers, Terry Young, Director of Service Provider Product Marketing, A10 Networks, and Jeff Heynen, Vice President, Broadband Access and Home Networking Del'oro Group. You can read their full bios on the left side of your window by selecting the speaker's tab. Just a few notes before we begin. To access additional resources for today's presentation, please click the handouts tab button on the left side of your screen. You can access closed captions from the bottom right corner of the video player. This webinar is being recorded and will be available to watch on demand within 24 hours. We'd love to hear from you during the presentation. Please submit any questions you have using the questions and answers tab on the left side of your screen. Time permitting, we will conclude with a Q&A session. All right, let's begin. Jeff, please go ahead.
Jeff Heynen
executiveAll right. Thank you so much, Andrea, and thanks, everybody, for attending today. Before we get into the heart of the webinar today, Terry's presentation about security. I wanted to provide just some context about investment levels that are going into broadband networks now. And just why after this phase, this build-out phase that we're seeing now in order to maintain sustainable networks, how operators are going to have to change their present motive of operation and start thinking about security, new services in new ways to compete. So clearly, what we're seeing, and this is no surprise to anybody. I've been tracking the broadband market for almost 20 years now. And there have been very few instances of a massive build-out phase, a massive consensus in terms of infrastructure purchases that we've seen over the last few years especially brought on by the pandemic and everybody's understanding now of just how important broadband is as a service. It's very clear that across the board, broadband remains a key investment focus for all operators of all sizes. We're going to see this continued cycle of spend being fueled by increasing competition, operators moving into different areas, having those edge out projects subsidized and we're also seeing now new competition, new technologies that are making broadband expansion easier, especially fixed wireless on the lower end and of course, fiber at the high end. And the valuations of these networks, although they are down from their peak, certainly, there is a consensus that those valuations at some point are going to come back. And that, of course, is fueling major out-of-market expansion. We're also seeing interest levels from open access networks, neutral host provider in the fiber space. Things that we've seen in international markets in Europe before, now also moving into the North American market. So that also introduces an interesting new dynamic in terms of competition. When you look at the North American market, in particular, subscriber numbers, cable has dominated for the last decade, right? And I think we're at around a 64% share for cable operators now in terms of broadband subscribers overall. But -- and what goes up, sometimes it must come down, right? And the fiber and fixed wireless providers certainly see cable operators as vulnerable. The cable operators don't feel that way, and they're obviously addressing speed deficiencies in their networks in their own way. But really, I think the key takeaway here is, certainly for rural providers, including utilities, co-ops, new entrants the subsidization environment presents really a once-in-a-decade opportunity to economically and finally transition away from copper and get fiber into the ground and out to customers. And obviously, we're seeing those fiber commitments and overall expansion plans continue to grow. We are looking at and projecting a number of around 113 million to 115 million households and businesses that will ultimately be passed by fiber by the year 2030. And that's up from just a little under 75 million homes and businesses today. Within that larger number, we certainly expect to see rural operators, municipalities and those utilities and co-ops they are expected to pass nearly 27 million homes and businesses by 2030. And our expectation is that within that particular segment, they'll have roughly 9 million to 10 million of their own fiber connections there. So take rates are solid. They're in line with typical industry expectations and obviously, growing and using the subsidies to grow those fiber networks. Obviously, the subsidy environment is critical here. I've been keeping an eye out and measuring really about growth expectations and looking historically, for example, at the BIP and BTOP programs, CAF and CAF II as well as some historical precedent for growth here. Between all of the programs that have been funded thus far, certainly, the BIP program that is just now getting underway as the states are being awarded their allocations for that $42.5 billion for expansion. And we see obviously some of the largest states here with their allocations and then from there, it's up to each state then to fund individual projects within each of their states. And we expect to see -- and we're also starting to see in early states here, some of the bidding for these projects beginning now, some awards being announced and really through 2024, I think that process is going to continue. And we're really going to see the money begin to flow into those projects beginning in late 2024. And then with the bulk of those being flowing into the equipment providers really in 2025. We also still have a considerable amount of RDOF money that has yet to be spent. If you recall, there was a portion that was returned in the Phase 1 process. We still have -- we still are deciding on a Phase 2 and what the details are around that. So there is still plenty of subsidy money to go around. And how that's translated into growth in terms of overall fiber equipment purchases, just in terms of the North American market, when we look here at total broadband equipment, what I'm showing here are purchases of cable and fiber equipment both on the infrastructure side as well as the CPE side. And you can see really in 2019 and before, there was a pretty steady state of investment in broadband if we go -- if we take this chart back even 5 years. And then 2020, pandemic and then all the infrastructure investments that were made. And you can see that from 2020 to 2021 and then 2021 to 2022, double-digit percentage growth in each year. Now 2023 is going to slow a little bit. That was an inevitable outcome here after 2022 showed such high growth. Supply chain started to ease at the end of the year. And that offered service providers an opportunity to get some of their backlog filled, get that equipment so that they could start to deploy that. And so what we're going to see as a result here this year is a slowdown in the amount of purchasing of equipment, but obviously, a focus on getting that equipment that's already been purchased deployed. So real no slowdown per se in the interest levels of operators to continue their fiber network expansion, certainly on the rural side. But macroeconomic conditions kind of are dictating that there is less subscriber growth. Obviously, subscriber growth is typically determined largely by new housing starts as well as people moving. And those two metrics certainly have slowed and so we're already seeing a bit of a slowdown in terms of the CPE purchases that have occurred thus far. On the infrastructure side, we do expect things to remain healthy, if not the growth just slowing a bit this year, as I mentioned. And you can see some of the larger growth here in terms of equipment due partially to the Tier 1s, but then -- you can see that anywhere from 20% to 35% of these [indiscernible] ports, we estimate go to rural operators in the Tier 3 market on an annual basis. That represents a pretty healthy $200 million to $300 million in revenue for the equipment providers for [indiscernible] equipment into those markets. And of course, it's important to note that not all of that spending is related directly to the subsidies. The subsidies should be accretive to those numbers. So we continue to see expectations or have expectations for continued growth of fiber networks. At the same time, we also expect to see fixed wireless as a viable broadband technology continuing to grow. So you hear obviously about both T-Mobile and Verizon being very aggressive with their 5G at home services. Both of those operators, particularly T-Mobile, have driven here in the early stages, a lot of heavy volumes of these CPE shipments. And then ultimately, the addressable market flows and then we get more of a linear growth pattern as we see in more mature markets. For wireless ISPs, obviously, there's some limitations as to how much they can grow their current fixed wireless services and networks in many -- much of the bead funding requires some type of license spectrum. Many of those WISPs have deployed their fixed wireless services based on unlicensed spectrum. And so for many WISPs they see kind of the writing on the wall if they can get subsidies to go ahead and overbuild with fiber, that's what they're doing. They'll still maintain their fixed wireless networks and in some cases, we'll acquire license spectrum in the sub-6, perhaps a CBRS range to continue to expand their footprint, but they're also going to complement that with continued fiber growth as well. So again, I think the key message here is look, fixed wireless, cable, fiber, we've got a very dynamic broadband marketplace that's shaping up here. And so for operators now, the question after the build-out occurs is, how do I create a sustainable business. Now that I have 1, 2 maybe even more competitors where before, I may have not had any or maybe have just had one competitor. So all providers are facing this. And, at some point speed becomes less relevant for them as a competitive differentiator. Cable success in the early rollouts and deployments of broadband was based on the fact that it was significantly faster than DSL. Well, now with more competition, more technologies at your disposal, speed becomes less relevant. There are other factors, latency, packet loss, overall reliability. These are becoming more important and more critical for subscribers as they make their decision as to who their broadband provider is going to be. In addition to that, consumers are becoming savvier about what type of relationship they want with their service provider, meaning manage WiFi? Do they want security services, do they want parental controls over how their children use the broadband services. All of these things are clearly elements that subscribers are willing to pay for and so operators they want to be a partner with those customers. And so security becomes a very critical path, if you can say, look, we protected you from 15,000 denial of service attacks. We protected you from a phishing scheme. Those kinds of things are becoming extremely relevant and a way for operators to differentiate their services. And we're starting to see that, of course, with operators now. Verizon on the business side for their fixed wireless service, they have 2 tiers of security packages that they're offering. And certainly, we're going to see those kinds of tiers and services proliferate especially as broadband expands, speed through fiber expand. We've got -- with fiber networks, we have operators that have residential sharing footprint across the residential business, lease line access, schools, hospitality. And so the SLAs and the experience that they provide to each of those customers is different. However, in order to remain sustainable, security and those types of services that are differentiated based on SLAs are going to be extremely important going forward. So with that, I want to now hand things over to Terry.
Terry Young
executiveThanks, Jeff. Hi, everyone. Thanks for joining us. Well, as Jeff has mentioned, this is a onetime opportunity to replace copper with more advanced access technologies. It's also a onetime opportunity to upgrade the core network as well. And to provide the security and resilience that is not necessarily always available even in the urban environments, the areas that are considered well served at this point. I'm Terry Young and I'm with A10 Networks. And in this part of the webinar, I will be talking about some of those elements within the core network that should be focused on. And that really need to be considered in the early stages of the design as service providers build out and extend their networks to unserved and/or underserved areas. I'll also talk about a few case studies and some of the specific technologies that we offer for security and for salability. It's been a challenging time over the last few years. All of us have stories about the pandemic. I think it's also been challenging for service providers. I've heard a lot of really inspiring stories of service providers really stepping up to provide their communities with the connectivity in their schools and their hospitals and throughout the community to allow people to work, to play, to continue for the children to learn at home and during the pandemic. There's predictions of a recession this year. So the challenging times do not -- have not ended and we're in July now. If the knock on wood, maybe we're going to avoid that recession. But the point is that in spite of all the funding that's being provided for largely to regional ISPs to build out that access. It's still a very difficult job. I mean not only our regional ISPs face with the technical challenges and often geographic challenges of extending broadband into areas that have been really underserved in the past. They may lack believe the expertise or the resources to continue to do that. So in spite of all those challenges, the demand and the desire for more connectivity just remains unrelenting and unabated and service providers are continuing to build out networks to meet that demand. I also want to point out that financial incentive is not the only incentive for many of the regional ISPs that have been awarded the funding. Many of them, that's really a much more personal incentive that they really want to help their communities to progress. And for many municipalities, many communities, the opportunities that they can provide to the community to attract more business and better the lives of their subscribers on the people that live there is tremendous with broadband. So for many it's really more about having to create that connectivity and provide that quality of service to the community as well. And really, although the media may talk about rural broadband, especially as an opportunity for rural communities to catch up with where urban communities are really in a lot of cases, I think it's leaping forward. because they can have, there's an opportunity to provide a level of service, the level of connectivity and resilience that is in security that's, as I said, not available even in many urban environments as well. I mean I live in the Bay Area. I don't have fiber to the home in my community. I don't think they've been willing to tariff the streets in the urban area. So it's really an opportunity that I think service providers should take advantage of and should plan for from the beginning as they're extending their networks. A10 Networks, if you're not familiar with us, we are a global company. We provide technology that helps secure and scale the core network. We have very specific elements that we focus on. We focus on service providers. We provide technology globally. We have 250-some customers all over the world, including 100-and-so regional ISPs here in the U.S. as well. The technology that we develop is all within the core. We don't provide any access technology. So it includes Carrier-Grade networking, TPS rear protection system, which is DDoS detection litigation, load balancing, Carrier-class firewall and DNS security as well. All these components that we help will enable service providers to build a more resilient network and to create a more sustainable business for themselves and provide better subscriber experience for the subscribers. So what is the needed subscriber experience today? And how do you build that? Jeff has alluded to this as well, high speed and low price are no longer enough. We -- I attended a Fiber Connect conference in Taco a few weeks ago. And this is the theme that came up consistently is that historically, Tier 1s that have not had a good track record as far as providing customer service through NPS scores are generally, are pretty low. And for the Tier 2 and Tier 3, they are now building out to try to compete against them, the subscriber experience is everything. And where I think in the past -- and you still see this today, there's a lot of focus on competition with how fast is your network, what's the price point. But I really think subscribers are starting to ask different questions. In part because of the pandemic, they do want to know how fast is the network, but they also want to know how safe is your network. Can I allow my children to use your network to access their services and how resilient is your network? Is your network going to be there when I need it to be, if I have to like, god forbid, that there's another shutdown in our pandemic and I have to like depend upon the network to be able to continue to be employed or if I just want to work from home a few days a week or a short time my child is sick, is the network going to be there when I need it. And I think those questions of safety, of security, availability and speed are now a critical component of how a subscriber is going to evaluate the network going forward for those service providers that are building out now to new areas, really building out into an environment that's changed significantly in the last few years, largely due to the pandemic posed from the subscriber expectations that I just mentioned, but also from the cyber security landscape and how much that has evolved over the last few years as well. And these are things that need to be considered as the networks have been designed and built for the future. So let me focus on one of those areas that is often a source of disruptive subscriber experience, and that is DDoS attacks. DDoS is distributed denial of service and it's a whole range of different types of attacks whose basic purposes to prevent legitimate traffic from getting through to their destination. You probably read large volume metric attacks regularly make the headlines. Microsoft, not by 2 years ago, had a major attack. They were able to mitigate successfully was 2.3 terabit size attack. So the attacks get bigger and more intense and more frequent every year. There are estimates that DDoS attacks will increase like 170% this year compared to last year. So it's just a continuing on slide attacks towards both the telecom infrastructure as well as their downstream subscribers. We track what we call DDOS weapons. These are IoT devices largely in servers that are just out there in the world in the Internet that have been compromised in some ways and they are available for cyber criminals to use the launch of DDoS attacks. So today, because of these weapons, really attacks can be launched from anywhere to anywhere from anybody. So we see attacks from students, a lot of universities to have their students DDoS them usually during final suite. There are, of course, the hacktivists and the state level kind of cyber criminals as well, but most DDoS attacks are small. They're kind of launched by kind of common criminals, if you will, who are able to use the tools that are available on the dark web. You don't have to have a huge volume of attack to make an impact on your network or to take out one of your most important customers. So these are things that, as you're trying to attract new businesses into municipality into community, these are things that, that business will certainly be aware of and we'll certainly be looking for as far as what can you provide them in terms of additional protection. I also just want to point out that for our service providers, actually, there's multiple domains that must be protected. We focus a lot on the production network on the actual network that customers access. But really, service providers have several networks. And depending on the size, so that they may be physically different networks, so they may be combined networks, but they have -- that includes the customer-facing like web-interfaced, website, the telecom IT network, the internal IT network as well as the production network. This last year, I think all of the Tier 1s have reported cybersecurity incidents, none of them had to do with the production network. They all had to do with either supply chain impact or -- another area of the network, reaching customer records through the internal IT network, they still make the headlines. So there's multiple areas, the protection network is clearly very, very important for service providers, but all these areas must be protected. And all of them can be a source of damage to grant our reputation and how your subscribers view your service and your network. So these are multiple areas of protection that other companies may not necessarily have to think about it as much as the service providers. Most -- telecom and the telecom infrastructure is heavily targeted, but most -- DDoS attacks are actually focusing on a downstream customer. So service providers are kind of like collateral damage. If it's going to pass through your network to get to your end customer. So historically, service buyers have really focused on for DDoS protection, making sure that their network stays up and running. The protecting against the volumetric attack so that you can't really impact the network itself, the availability of the network. That will often include us overprovisioning various network elements just to handle the extra traffic that's carried by DDoS attacks. That doesn't particularly help the downstream customers. So the common response is to if there's a DDoS attack is to block that IP that is being targeted. But when in the fact that it still puts the -- or at least damages the downstream customer, that's the victim of the attack, and in effect, you're kind of helping the cybercriminal achieve its objective, which is to disrupt service for somebody. So this is something that we're seeing service providers we're taking a look at and how can they provide a better quality of service for the downstream customers [indiscernible] as a managed service or some other type of arrangement. And we are seeing even the small regional ISPs look at this very heavily as far as how can they provide a next level of service that maybe they went -- had really done so in the past. I think rural communities are kind of especially vulnerable, mostly because for the same reasons that there's probably been an underinvestment in infrastructure in general, there's been underinvestment in security infrastructure also. Contrary to what people might believe -- cybercriminals are very non-discriminating. I mean they don't care if you're a world hospital, if you're the only hospital within like 100 miles that they can target with DDoS or ransomware, that's really just a money game for them. So there's been a number of attacks against hospitals, in particular, mostly by as a result of the Ukraine conflict. And so this is a quote from the American Health Association, really saying that hospitals and especially small hospitals, which most rural hospitals or smaller hospitals need to really check and see the DDoS protection is available. So rural communities are not immune from DDoS attacks or any other cyber threat for that matter.
Jeff Heynen
executiveTerry, I was going to ask you just really quickly. And you kind of mentioned this, is the underinvestment that you've seen typically. Is that a contributing reason why rural ISPs and smaller ISPs are more vulnerable to these attacks?
Terry Young
executiveWell, that's part of it that although I could argue that there's underinvestment by Tier 1s as well. It's not just the rural service providers. I think security has been often kind of near as a checklist item in the past by service providers. So they haven't been as heavily targeted. And so I don't think I pay as much attention as even the enterprise. But I think for rural communities, it's kind of because they're more desperate. I mean the situation is -- I mean, they don't have -- like I mentioned, there's a hospital that's only one within 100 miles. So they're more vulnerable. So I don't know so much is that they get targeted more as and when they do get targeted, the impact is really great. And I think that's kind of what service providers that are serving those communities and we -- that may be a customer, those are things that they should consider.
Jeff Heynen
executiveThat makes sense. And before you get back, I'll just remind the audience, think about questions, please feel free to -- because we're going to have some time afterwards for your questions. So go ahead and log those in now as Terry is going through the presentation. So sorry, back to you Terry.
Terry Young
executiveThanks, Jeff. So A10 has a solution called threat protection assistance, the DDoS detection and mitigation system. And this is just kind of describing the full life cycle that service provider enterprise too, for that matter, should consider as they're looking at DDoS protection. There's an auto learning phase where you really have to establish a profile of what kind of traffic gets considered normal and what those thresholds should be and how you should set your profiles and then there's a whole cycle of detection and looking at the traffic, and then we have five layers of adaptive mitigation depending upon the threat level and what you want to do for different types of traffic, a different type of situation. So there's a whole series of things that are done before traffic is deemed as being a threat and it goes through a scrubbing center. And then once that traffic is that has been mitigated as a reporting system as well so you can look at and see what's happened, why it happened and try to protect yourself better and to learn and apply it for the next time as well. So this is a system that we sell to a lot of Tier 1 operators, cloud providers as well as quite a number of the smaller Tier 2, Tier 3 ISPs that are in the middle of a world broadband build-out today. I also want to mention DDoS attacks is about anything. And they're also going to attack IPv4 address pools. This is an example of a customer that we worked with at a electric co-op. And they're about 15,000 subscribers. Now I think at this point, the -- when we first started talking to them, they had about 1,000 subscribers. They're actually a carrier-grade networking customer. And we also include a DDoS protection within the carrier-grade networking products. So as they were looking at trying to expand their network, they were getting DDoS by gamers primarily, and we're requiring them to have to like reset their IT approvals that you want specific IP address that we targeted, they have we take out the whole pool. So by putting in our solution that not only save money for the carrier-grade network that I'll talk about in a minute, they also mitigated those DDoS attacks prevented people having to get out in the middle of the night and fix the problem. So it's also important to maintain the high-speed experience. I know speed is a big topic of fiber versus fixed wireless access and it's all about speed, but really -- you can have the fastest fiber network in the world and have a histocore network, and there's some element that is not performing properly, that high-speed experience is going to get stopped. But the subscribers going to your experience is the network is slow. And this is going to be true for really a lot of different network elements, but especially true for the DNS infrastructure. So if you have DNS infrastructure and that's domain name system, and that infrastructure is not performing properly or if it's been subjected to a DDoS attack, but the subscriber's going to experience is slow page loads or an unresponsive network, and they're just going to say the network is slow. And so all that investment is not going to help create that high-speed experience that you're underinvesting in your DNS infrastructure. We provide a number of solutions that maintain the experience of speed. And that includes several different solutions that basically -- by augmenting the capacity of the DNS servers and even in the recursive function of providing DDoS protection for unauthoritative DNS. We provide extra processing capability that enables that DNS to perform more -- to perform better and to maintain the capabilities and process the traffic faster than [indiscernible]. Low-balance, we also buy DNS over a [GPS]. And as I mentioned, threat protection for the DNS infrastructure as well as DDoS threat protection. This is another example of one of our customers. This is MSO in Brazil. They had -- they were a CGN customer. That's our Carrier-Grade networking product. They had a low balancing for their DNS servers because our appliances are so high performance. They are basically able to not replace the DNS system, but to augment it with the additional capacity for our system. So typically, in a typical use case we have is that we are augmenting capacity for the DNS that's not replacing it altogether. But so they were able to display almost 90% of their back-end DNS servers performing the recursive function and take them OpEx and [indiscernible] cuts of the power and just generally provide a better performing system and a better subscriber experience for the subscribers. So another important aspect of trying to provide a stable, a long-term stable business as a stabilized and with sustainable businesses to stabilize the operating expense. One is that network is built on that capital expense is overcome, operators have usually fairly thin margins in terms of the operating expense to continue to provide to make money and to provide the quality of service that those subscribers want to see that will keep those existing subscribers and attract new ones. One area that we focus on and we work with a lot of regional ISPs, in particular, the Tier 2 and Tier 3 ISPs is on the dilemma of IPv4 versus IPv6. And if you're not familiar with this at all and some of those that aren't familiar, maybe I think why are we still talking about this. But I'll just give a brief overview of what the dilemma actually is, every connected device needs to have an IP address of some kind in the original adjusting scheme, which is IPv4 ran out of IPv4 addresses some time ago. The replacement, IPv6 is readily available, but the dilemma for service providers is basically they have to support both. The adoption rates are not consistent across websites, subscriber devices and networks. So service providers have to provide connectivity for everyone to everywhere. And so they have to support both matter how much they want to totally transition IPv6. So this is just a few data points talking about the IPv4 supply. There are some -- Aaron is a net registry that manages this. There's some small quantities of IPv4 addresses available, people turn them in. And so it should always be something has to be checked if you need more IP address space, you should also check because those are free. But generally speaking, as we're trying to add on unconnected locations that means they have to have IP addresses. And so there's big subscriber demand. There's a lot of competing providers, a lot of competition. As Jeff has mentioned, there's like thousands of regional ISPs that are jumping on trying to build out broadband to the local communities. There's also municipalities and all kinds of different public-private partnerships that are happening. One thing I think is really interesting is that AWS and this is true for a lot of the big cloud providers, AWS has acquired like 100 million IPV4 addresses. So they are busy acquiring a mass amount of IPv4 addresses. So there's competition for the few remaining IPv4 addresses that you may be able to get even from the broker. And there's a limited supply. As I said, Aaron has some -- but most -- usually our service providers have to get IP addresses on a public market to a broker sometime. As I mentioned, the basic dilemmas, they both have to coexist service providers have to support both. There's been major websites and major Google and Facebook and major content providers that support IPv6, but there's a ton of websites out there, of course, and just collectively less than 30% of the websites globally are IPV6 addressable. So therefore, your subscribers are going to want to reach those websites some of the time and you as a service provider is up to provide that capability. The other chart is the adoption rate between IPv4 and IPV6, right now, it's around 40% IPV6 versus this is in terms of the traffic and based on Google's numbers, and about 60% IPV4 probably is going to flip in a few years, but it's still not 100%. So regardless of how small that number gets is still something that has to be addressed by service providers throughout. It's not just a U.S. problem. I also want to talk about the price of IPv4 addresses. I mean, usually, when we have discussions about pros and cons of IPv4 versus IPv6, it kind of becomes a very technical discussion, what works better, what's more secure. And of course, as I mentioned, most of the time, if you have to need IPv4 address space, you have to get it from the open market from a broker. Over the last few years, the price has gone up significantly, like last year and the year before, it was $50, $60 per IPv4 address. So if you had 10,000 subscribers, you're trying to look at adding up $600,000. That's a big chunk of money for most regional ISPs. And what happened this year as the price has dropped. And so if you bought IPv4 space, 1 year ago, 1.5 years [indiscernible] to keep going up. It's going to increase in value. Well, it didn't increase in value this year. So it's kind of like the real estate market. So basically, this is -- this is a very volatile component. And the question we ask is that this is something you want to continue to invest in. And so our recommendation is that you do what you can, for example, using our CGNAT product to minimize your investment in IPV4 space because it's -- it's not an investment you can count on and the adoption rate is continuing to grow over time.
Jeff Heynen
executiveTerry, does the volatility in that IPV4 pricing, does that make it difficult? I mean we've got -- we've talked about so many new entrants and smaller operators that are expanding their networks. Does that put them in a competitive disadvantage with that volatility?
Terry Young
executiveYes. Well, I put a [minor] disadvantage you have to have to get them at all. Most of the -- I mean, most larger companies, Tier 1s, especially these are issues they've already resolved. I mean they either have Carrier-Grade CGNAT solution in place or they have adequate IPv4 space. And then they have -- they're also transitioning to IPv6 at the same time. So it's not like they're ignoring IPv6. But for a small ISP and especially they haven't looked at this for a while. It could take considerable expense, and we have talked to companies that they were -- they've been fine with their existing IPv4 space for years, and now all of a sudden, they're trying to grow. And so they're looking at this like for the first time in a long time, and they're a little shocked. What's happened with the market and how much of an investment that can cost. So yes, if they are in a place where they have to make an additional investment to grow, it could be a considerable cost. Now what we try to do, of course, is with the Carrier-grade NAT product is to try to mitigate that cost and allow the expand their IPv4 space, so they don't have to buy additional I agree for and to maintain their competitive advantage. So our [indiscernible] CGNAT tender helps to stabilize the operating expense. So you don't have to continually buy IPv4 addressing it as you grow and it also protects against this uncertainty of how quickly IPv6 will be adopted because the same device can provide both the transition technology between IPv4 and IPv6, as well as the Carrier-grade NAT which allows you to oversubscribe your IPv4 addresses and run public IPv or IPv4 address conserved by 32 in some cases, even 64 subscribers. So really best expands, right, the capabilities of IPv4 space. It also memorized some of the business risks and concerns that operators have in terms of get off the tax and IPv4 as well as this -- if you acquire IPv4 addresses, you really don't know whether or not they've been blacklisted somewhere. And so there's some concern about the quality of the IP addresses as well when you're looking to acquire them in the open market. This is one of our customers. We have this video on our website. You can listen to the video, and this customer, I think they have over 100,000 subscribers now. But -- they use our carrier-grade NAT product and are very happy with it and save them consuming money from having to continually invest in IPv4 address space. Just going to quickly, another area that operators really should consider, and we're trying to have more and more conversations with even some of the smaller SPs, about how they can leverage their existing investments for more for revenue, or more to monetize. And its just a few examples here. One is that you can sell -- if you have excess IP address, there are some offers that talked to that are planning on -- when they sell the [indiscernible] like a broker and getting it reassigned for a fee. And so the considerable amount of money that if you have excess space after you put in the CGNAT solution that you can get just from leasing or on time on a month-to-month basis, your excess IPv4 space. So that's one option. Also, we don't think operators do more and more as far as buying DDoS protection services for their downstream customers, and this is one of our customers who put in our TPS system, and they don't charge extra for it, but they consider part of the value-added service and part of why they should choose them, the differentiator in the market is this additional DDoS protection that they offer. Other examples, we have one company that is offering a DDoS detection service as a -- basis a managed service provider to other ISPs as well as to government agencies within the region, they kind of operate a network that they offer DDOS protection as part of that network service for a fee. The chart is just pointing out that this is just a representative chart showing that -- if you're thinking about offering DDoS protection as a service, it may not take as many customers as you may think. And really, what we find is that it doesn't take less than 10 customers to really kind of break even on what the investment might be. So it's something that we lot to talk to companies about and think we should be considered. So this is our portfolio for regional service providers. As I mentioned, it includes our thunder conversion firewall, which is a number of different firewall for protection products, including some specific for mobile networks and our Threat Protection System, which is DDoS detection mitigation. Harmony Controller is our overall management and analytics platform. We have Thunder ADC, which is a low balancing and also for DNS firewalls in the course of DNS and functions that I mentioned earlier. And our thunder CGN, which is carried right now looking for IPV4 preservation as well as the IPV4-IPV6 transition capabilities. So that said, we -- as I mentioned, we focus on some core network capabilities that we think are really important to maintaining a good subscriber experience and for helping operators build a resilient and sustainable business for the long term. And that's all I have.
Jeff Heynen
executiveGreat. Thanks, Terry. That was really, really helpful. And this is a fairly new area for me. So I learned a lot. So I appreciate it. I'll remind the audience, please submit your questions. We've got a few that have come in. We've got about 10 minutes to address some of these questions. So while you're considering adding yours in, I'm going to go ahead and scroll through. And we've got one here that's come in. So you mentioned that smaller ISPs and regional ISPs have typically found and have not invested or underinvested in security. I mean, how do you -- how do you get them to do that? What -- how do you suggest that they make it more affordable now?
Terry Young
executiveWell, I think, first of all and this is happening in the industry already. But I think there has to be a recognition of the need to invest more, period. And I think they have to start by convincing whoever it is that's not agreed upon on the company already. I agreed upon that this is something that needs to have greater attention and that there just needs to be funds applied to it. I think that there's -- because there's so much focus on the production, how there's a lack of focus or have been, I think, for service providers on the rest of those network elements. And -- on the non-protection network, the databases, the websites and the components that they have offer. And in many cases, in the research that we've done is that service providers have not invested as much even as their enterprise counterparts have. And so what we would suggest like in regard to DDOS protection, there's -- if there's no DDoS protection at all is that you don't have to buy DDoS protection for like the highest possible 1.2 terabit attacks that you read about because Cybercrime is not going to waste that level of attack on a small service. They don't need to. I mean, they're going to be renting DDoS weapons, they're going to unfortunately, will attack where we'll have an impact. So I think it's more affordable than oftentimes people think and often, you can like -- if you have some existing system plays off and you can supplement it with a higher performing or upgraded DDoS mitigation, maybe you have detection in place, you don't want to replace that. So we -- our these solutions, we work with a lot of other vendors to provide a total DDoS solution.
Jeff Heynen
executiveSome flexibility and, I guess, scalability are important metrics here, right, knowing what you need to protect, given the scale of your network.
Terry Young
executiveYes, yes.
Jeff Heynen
executiveWe had another question here. And of course, we're talking various, I guess, specifically about the North American market here, but we've seen in other markets, particularly in the U.K., where they pass the Telecommunication Security Act. And we know of other countries in the EU, for example, that are looking at similar policies. Do you think that will have an impact on U.S. policies at all?
Terry Young
executiveYes. Well, the UK Telecom Act, if you're not familiar with it is, I think it was like 1.5 years ago that it was passed and it's in the state of kind of legislation and operationalizing it basically. But what it does, it establishes a framework that service providers have to adhere to that provide some standards and some capabilities that they say we have as we're following this framework by a secure network and to provide the network availability. And this is kind of a result of the pandemic as well. What it also does, and this is kind of like a key part of it also provides penalties, significant penalties if a service provider has a breach or has an attack or has an outage, and they haven't followed this framework. And the penalties are something like 10% of revenue. It's like huge -- and so I don't think that the U.S. would ever adopt something that's strenuous. But I think what it has done is really kind of set the bar higher for what's expected of service providers. And we're starting to see that now with the Biden administration is put out to executive boards having to do with the security of critical infrastructure, and we're seeing more and more kind of recommendations and focus on this, that wasn't true a few years ago. So I don't think that it will go as far as with the U.K. has done just because of the culture that we have here, but I definitely think that it's made a difference in how that telecom operators can expect be held to account much more in the future than they have been in the past and that there's going to be more expected them oversight than it has been in the past.
Unknown Executive
executiveOkay. One thing that was interesting to me in your presentation, and I have not looked at this in such a long time, but I was really surprised at the fact that there was still so much of attention on IPV4. Do you think service providers are still using IPV4 in their networks?
Terry Young
executiveWell, because they don't have -- because they kind of have to. And no, especially mobile operators have been big proponents of moving to IPV6. And if you look at some of the public information on like T-Mobile, for example, I think something like 90-some percent of the traffic is IPv6. And mobile operators are in a little bit different situation, I think, because for mobile devices. They have customers that are regularly trained to turn in new devices and they regularly upgrade their network like 3G to 4G to 5G. So every time they do that, the IPV6 has been baked into the standards to know that -- the network migration. But basically, the reason that operators don't move as fully as maybe they would like to, is that they either have some customer segments or customer devices that are difficult to change out or expensive to change out that are not IPV6 compatible. They may have specific elements within their networks that are not fully IPV6 compatible or like the [indiscernible] defense have been trying to move to IPv6 I think, for 10 years. And so it's a very -- it's a complex operational thing to manage. And if you're a network admin, and just you're trying to keep the network up and running like day-to-day, the thought of putting in something different and new is kind of daunting. So it's kind of one of those things that there may be elements that we can upgrade, IPV6 or do more, but it's like, hey, it's working. It's working now, so that's not -- that's not some changes. But as I mentioned before, there's a lot of IPv4 out there. Most traffic, most devices, most websites are still IPv4 based. So if you're a service provider, you have to support growth somehow. And you have to put in some -- and even dual stack requires IPV4 addresses in addition to IPV6 addresses. You kind of can't get around it. So it's one of those things that's continuing to evolve, but it takes time and service providers are the ones that have to kind of like manage this kind of hybrid in between environment in the meantime.
Jeff Heynen
executiveI know we're at the top of the hour. We have one more question that I picked out here that I think is appropriate with the last one. So with that IPv4, I mean -- so I'm guessing why are some operators hesitant to deploy like CGNAT solution for that limited block of IPv4 addresses that they have?
Terry Young
executiveYes. I think again, it's something that's new. If they haven't done it before, it's something new that they have to try figure out. And I think also there's a lot of kind of history of like when IPV6 was first introduced, and CGNAT was first introduced as a recommendations, I don't know that the technology was as mature as it is now. I mean our technology now has been around for a long time. And what we hear from customers that they install it and they don't have to worry about it. They don't think about it anymore. We have tens of customers that say, basically set and forget it, that's -- we're the company they never have to talk to because the Carrier-grade technology works so well. So I think part of it is kind of a from the past. And sometimes, they're just in a rush, so I get the network build out, and this kind of -- the [indiscernible] thought it through. Sometimes we're also very concerned about specific things like gamers and code requirements of things. And these are issues that have been dealt with and other solutions for within our technology. So I think most of those concerns can be mitigated when they look at it more carefully.
Jeff Heynen
executiveGot you. Well, cool. Thank you, Terry. Thank you so much for this. This was extremely helpful. And again, I learned a ton hopefully, everybody in the audience did as well. I'm going to hand things back to Andrea to close things out.
Unknown Executive
executiveThank you for attending this Fierce telecom webinar and for submitting so many great questions. I'd like to thank our speakers for participating in A10 Networks for presenting today's webinar. A recorded version of this webinar will be available for you to access within 24 hours using the same audience link that was sent to you earlier. Thank you again for joining, and we look forward to seeing you at future events.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete A10 Networks, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to A10 Networks, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.