Check Point Software Technologies Ltd. (CHKP) Earnings Call Transcript & Summary

November 30, 2020

NASDAQ US Information Technology Software conference_presentation 31 min

Earnings Call Speaker Segments

Brad Zelnick

analyst
#1

Good morning. Good afternoon. Welcome, everybody. I'm Brad Zelnick, software analyst with Crédit Suisse, and truly delighted today to be joined by the good folks from Check Point Software. We have Founder and CEO, Gil Shwed; CFO and COO, Tal Payne; and Kip Meintzer, who is the Global Head of Investor Relations. Before we begin, Kip, let me turn it over to you. If you would, please have the honors of reading the safe harbor.

Kip Meintzer

executive
#2

Thank you, Brad. During the course of this presentation, Check Point representatives may make certain forward-looking statements covered by the safe harbor provided by the Securities Acts of the early 1900s. Because these statements pertain to future events, they are subject to risks and uncertainties. Actual results could differ materially from Check Point's current expectations, beliefs. Factors that could cause or contribute to such differences are contained in our latest earnings release and other factors and risks, including those discussed in Check Point's latest annual report on Form 20. Check Point assumes no obligation to update these information concerning its expectations or beliefs, except as required by law. Back to you, Brad, and thank you.

Brad Zelnick

analyst
#3

Thank you so much, Kip, and thank you all for being here. Just the format of this presentation, we will have about the next half hour for a fireside chat where I will be asking both Gil and Tal questions about the business and all sorts of things. If you would like to ask a question of them, please send me an e-mail to brad.zelnick@creditsuisse.com; and if time permits, we'll try to work it into the conversation. But with that, Gil and Tal, thank you so much for being here.

Gil Shwed

executive
#4

Hi, Brad. Good day, everyone.

Tal Payne

executive
#5

Great to be here.

Brad Zelnick

analyst
#6

Thank you so much. Maybe to start, Gil, 2020 has been a crazy year in a number of ways and challenging for many. Maybe you can talk about the challenges organizations faced when COVID-19 initially shut down areas of the world, where we are now? And what were the priorities then? And how have those priorities shifted since?

Gil Shwed

executive
#7

So first, I think we've all faced it, so I'm not sharing anything you didn't face. But we, overnight, needed to change everything we knew about work. Initially, it was about connecting all the employees from work from home. It was about dealing with the supply chain. Remember, in the first few months, all the manufacturing facilities in China -- we don't manufacture in China, but like everyone, we are dependent on Chinese manufacturers for some components. Everything was shut down completely there to the point that there was even almost no communication. We didn't know what customers are going to do. It was the middle of March towards the end of quarter. Will customers hold off? Will customers continue? And I think we managed to do quite well. We shifted our entire workforce in terms of our development and so on. We always worked from the office. I always believed in the collaboration in the office environment, and we shifted. I mean, over like a period of a week or 2, everybody's worked from home. I think the world is -- I mean the level of uncertainty that we see in the world is still high, but we kind of got you to that situation of working from home. In terms of cybersecurity, that means that we've really, really increased the attack surface. We need -- before, our crown jewel were always were with our trading systems in financial companies or source code in development environment or test environment in a high-tech environment or factory floor in a factory. This was all well contained, secured. Today, we've really explored all of that. Now thousands of people can access it from outside the company. Many of them are using even computers that are insecure to access them. We've done some checks and turns out that like 40% of users at home don't even have basic capabilities for security on their home computers, which means that any key logger can take over the computer and find out how to penetrate the company. So the attack surface has really increased. The level of attacks has also increased. We've also seen attacks that are following the pandemic, like when people were interested in information in the early days or mobile application pretending to give you health information but were actually malware. Then when there were more websites that will -- that you do financial transaction, will get government paid, phishing sites or becoming these sites and get your credentials. And we see that phenomena going on all the time. I think now people do realize that, okay, we've opened up everything. Now we need to secure it. Again, in the early days, we thought it's for 2, 3 weeks. It's for maybe a month. Now we realize it's going to be not just for a whole year like the corona is, but most organizations are actually going to continue in a kind of hybrid mode work model in the future. So we need to secure that for the future, too. And I think that definitely presents some interesting opportunities and also a few challenges for people in our industry. How do you secure all that environment? How do you create a more holistic approach? Consolidation is becoming more and more important. When you have people that are trying to avoid being in the same room together or being even in the office, you want pure systems. So I think that plays well into our strategy at Check Point, but definitely accelerate a lot of the process that we were doing.

Brad Zelnick

analyst
#8

That makes a lot of sense. And maybe if I can ask you, Tal, as we look across the globe right now, I think it's fair to say we're entering a second wave of COVID. How does that impact your go-to-market strategy? How have you adapted to this new world? And how do you see that playing out?

Tal Payne

executive
#9

I don't think I see a big difference between the first wave and the second wave. Since the first wave, when everybody had to practice their remote accessibility, we made a lot of changes, forced to make these changes; but it turns up to be quite a lot of opportunities as a result of the ability to work remotely. So I'll give you just a few examples. Marketing, everything moved to be now either digital, or even events are Zoom events or any other platform event, but everything is not face to face. It's an opportunity because we succeed. We talked about it before. We succeed to get much more people into these events, get new customers, existing customers, partners. So that's an example of a shift that had to happen very quickly. And we see many, many, many events as a result of that. It's just easier than finding a hotel and location and preparing and choosing the food and so on. So I think it's quite a nice ability to improve and touch much more people than you could in the past. So that's one example. Operationally, we had to learn to be agile. You remember, in the first wave, there was a lot of issues that might have related with the delivery of the units between the countries. We are very agile. We had a few issues, but we solved them like on the fly. So that was actually quite good because we were -- our model is running quite well in the way of preparing to the demand. So that works very well, and that continues to work very well. So that's required a different type of communication also with the vendors and preparation of the inventory and so on, just not to find yourself suddenly in a lockdown that doesn't enable you to deliver into the country. In terms of all the employees, collaboration tools, so the first wave, you had to practice how to do this collaboration. How do you make your meetings with the employees, with the customers, with the partners? Now everybody is well trained, and people are up and running. And majority of the people report much higher productivity than before, so that's nice to see. Mood-wise, I think it swings because all of us humans, when we check the mood of the people, then you see that, second wave, people were a bit upset about it, not with the company but with the situation. Everybody felt like, okay, after the first wave, we're coming out slowly and it felt nice. So everybody was a bit upset to get into the second wave, but we're investing a lot of time and energy and keep our people morale up and productivity up. So that's working pretty well, I think.

Brad Zelnick

analyst
#10

Yes. I think there is a little bit of fatigue in many companies. I don't want to tell you all about Crédit Suisse, but I hear this from other software companies as well, especially in places where we're getting into winter, more times indoors, less daylight out. I think people are looking forward to this time next year. Maybe moving on to a big quick picture question for you, Gil. Just I think you're credited as being one of, if not, the inventors of the stateful inspection firewall from many years ago. So I want to ask about security architecture. Recently, Check Point put out a press release highlighting that 81% of enterprises have adopted mass remote working, with 74% planning to enable it permanently. How does this change the way organizations need to think about security architecture for the future? Like do you believe this causes a fundamental shift towards security being delivered from the cloud?

Gil Shwed

executive
#11

I think we are going to see a lot of things from the cloud, and that started before corona. I'm not sure if necessarily security is going to be delivered from the cloud. Some capabilities of security -- I mean, first, I mean, if you look at our architecture, there are many things we are sharing from the cloud. We have our ThreatCloud at the center of our architecture or Infinity architecture. That's an amazing, I mean, real-time system that provides constant real-time updates and collects real-time information all the time from all over the world. And that's a cloud-based service, by the way, which is a great value because if we are seeing a malicious file in one part of the world and recognizing it, in the same second, it will be blocked all over. So it's a great architecture. There's other things like all these updates and all these information sharing and analogies that are very well done by the cloud. On the other hand, routing your traffic to the cloud, which gets analyzed, that sometimes makes sense. But a lot of the time, it's actually not the perfect solution. It slows down things. It's sort of the resource, and then the cloud are more expensive than the resources on the edge. And sometimes, when you talk about an individual machine, for example, when I'm connecting to the remote site, I can do the remote connectivity through the cloud, and that's fine. But to make sure that my home computer or my mobile phone are secure, that's something that, in many cases, requires an agent on the machine. By the way, the agent can work in a hybrid mode. Like, I showed my mobile, which is a great place, actually, when people are underinvesting because almost no company's using security software to secure the mobile, and yet the level of mobile incident is increasing all the time. Most of the analogies is down on the cloud, but you still need an agent to verify and check every application that you download or every website you're accessing to. So I mean the world will be hybrid. There will be many things that will be delivered from the cloud. But I think we still need a lot of edge software or even edge hardware, and that depends really on the circumstances.

Brad Zelnick

analyst
#12

That makes sense. And I appreciate that. Maybe to turn to what has become such a buzzword, I think, across many security companies out there and customers, which often happens when you get an industry analyst that comes and creates a new term or a buzzword, but I want to ask about SASE. You recently acquired a company, Odo Security, which I believe, you mentioned, will be the basis for Check Point's SASE solution. What does Odo bring to the table? And what are the other gaps that you need to fill to roll out on this complete SASE vision that I know that Gartner has?

Gil Shwed

executive
#13

So I think that the overall vision will take some time and it has a lot of components. Some will happen. I'm talking about the industry, not just in Check Point. Some may not happen, like every new technology shift. What we've done with Odo is -- or what we will be doing, we've -- although we just acquired the company, it's a small startup with very, very cool technology, seamless, clientless remote access powered by the cloud, can be provisioned in a matter of minutes and can be used by the end user in a very simple way. As a user, you go to a simple portal, and you can access all your assets. And now your assets may be on the corporate data center like they used to be for many years. They can be cloud-based assets. They can be with third party. And all the access to these assets, all the connectivity and all the security is managed and done smoothly by Odo. It's also multiprotocol. Unlike many other remote access solution, it's not just HTTP or web-based protocol. It also knows how to handle protocols like remote desktop and like remote SSH for management terminals and so on. So it's a very, very comprehensive solution, very small, very cool, and I think it's a great basis for a lot of the access that we will be providing.

Brad Zelnick

analyst
#14

Got it. And maybe just to look to another area within the SASE definition if you will. SD-WAN, which is core to any SASE implementation, you choose to partner for these capabilities. Other folks out there are looking to acquire. Why is partnership versus building out your own capability the right strategy? And might that evolve over time?

Gil Shwed

executive
#15

So first, we are likely to do both. Have some SD-WAN capabilities built into our edge gateways and have some that we will share and partner with others. And the reason is because kind of SD-WAN is on the edge between networking technology, and there is obviously, for every networking technology, there's also security elements to that. Now where it will end up, it will end up being a technology that security provider's owning or, like many other technologies, networking technology that's provided by the communication companies. That's a very good question. The leaders right now are not in the security space. It's companies like Cisco, VMware, and I think, eventually, the telco will be more and more active there. So we will, for sure, provide the added layer of security. That's what we've been doing forever, take every challenge in the IT space and provide the layer of security. How much of the connectivity layer we will need to implement in our product, that remains to be seen. So whether we will compete with Cisco or AT&T or VMware in building a cloud-based network to deliver traffic, that remains to be seen. I'm not sure that we will. And maybe it's better to cooperate with them. We will provide the added level of security, and we will provide because our gateways at the end, our edge devices, we will have the basic SD-WAN, or maybe not basic, maybe the more sophisticated SD-WAN capabilities built into our gateways around the world.

Brad Zelnick

analyst
#16

Got it. That makes a lot of sense. And maybe just taking that a step further, thinking about all the things that you've said about architecture, SASE and your approach to -- or thoughts about SD-WAN and how you're positioning in both partnering and delivering your own capabilities, I think -- and maybe this is just investors that get caught up in the distinction between proxies and firewalls. And I don't want to go back to the very simple of definitions. But -- and I appreciate your comments earlier about there being a need to service the edge in a very highly performant way. That will always exist. But as we think about what's happening as data and process proliferates out to clouds and we think about the distinction between a cloud proxy versus putting a firewall stack in the cloud, I think that there's a perception, at least among investors, that there's an advantage to the cloud proxy approach. Is that thinking flawed? And how do you distinguish -- are these comparing apples and oranges?

Gil Shwed

executive
#17

You can say it's apples and oranges. Both are fruit. Both you can enjoy them, but they are not exactly the same. Now sometimes it doesn't make -- by the way, for you, if you look for something sweet and a fruit, then maybe an apple will do it. Maybe an orange will do it. But they are not exactly the same. Now the proxies are much more limited in terms of what protocols they can handle and how we can handle that. And therefore, reach -- to this model when you, for example, handle mainly web trap, so when a proxy can do a pretty good job -- and again, especially if many, many things around the world are already configured, so we can easily just change the configuration and forward all your traffic to the proxy and without the need of additional layers. There's other application when you cannot change the routing of the traffic or let's say it doesn't use HTTP and it use the very more dedicated protocols, all the other Internet protocols that we have, in that case, the proxy won't work. For you, as a user, you don't really care. What you care is that your data is being secured, that you have -- by the way, where you do, do that solution, for example, we can do on the browser, inside the browser agent, which is lightweight, automatically being installed. Tons of the work with other vendors require a proxy. When you do it on the browser, you get many benefits. You get much, much faster. You don't introduce additional latency or delay. You don't share your data. One of the risks in any kind of gateway or proxy in the cloud is that your data is being now shared with the provider, and you may not want them to see what you're doing. I mean -- so privacy is much better when you're doing it inside your browser. So -- but for you, as a user, you don't really care. What you want is to log in and see that you can access the resources, that when you download the file from the Internet, the file is being inspected. I mean, for example, I use our solution, and when I download the file and tell me, analyzing the file, protect, cleaning up malicious content or cleaning up active content and gives me a file, I feel confident that I can open website. Or when I'm accessing a website and my browser checks that website, again, things that we have today, if it's a sort of legitimate website or a phishing website that imitates the Crédit Suisse website, for example, I feel very confident about it. I don't really care if it's done by an agent on my desktop or if it's done by a cloud service somewhere else. In our case, by the way, it's usually hybrid. The agent routes the traffic, gets the fastest route, gets the easiest way to do that. On the other hand, the wisdom, the sharing of information is usually done by what I mentioned before, the ThreatCloud that serves that. So that would be the preferred architecture for me, but we will also have a lot of components that are done holistically in the cloud in cases where customers want to route all their traffic to us.

Brad Zelnick

analyst
#18

Thank you for that perspective, Gil. And you know what, I've got so many topics. We're not going to get through all of them, so let me jump around. What I want to make sure I touch on with you, Gil, is this debate in security, which is going on for years amongst vendors, investors -- heck, Kip and I have had this debate many times. But talking about the strategy of just best-of-breed versus a platform approach. And we've all seen the limitations of platforms from years ago, some that were built around end point technologies and statistics that are still out there of large enterprises still having 50-, 60-, 70-plus different controls in their environment. If we think about the value proposition of Infinity, for example, is this something that organizations are really looking for versus best-of-breed point solutions? And why would a platform approach work now versus in the past?

Gil Shwed

executive
#19

I think what's being called best-of-breed point solution is not really best. And again, I'm not -- there are good vendors. There are mediocre vendors. I'm not criticizing every vendor. Again, there's many good entrepreneurs and many good technologies. I'm not trying to be better than all of it. What I do know that if the solutions don't work together, it won't give you good security. The fact that I know that a certain file is malicious or a certain website is malicious, if I now access it through a different vector, on my mobile, on my browser, on an e-mail server, and that server doesn't know that I already recognize that, that means it won't be secured. So we need all the components to cooperate. They cooperate best if they are coming under the same architecture. The architecture can be open. You can have additional components, but a shared architecture is better. You've already said about the fact that enterprises use 50, 60, 70 solutions for security. It simply doesn't make any sense. I mean security is not the #1 priority for -- it's not the #1 business for any enterprise, maybe except us. And nobody wants to deal with so many vendors. And when you deal with so many vendors, the investment is big, and mainly it's not secure. They don't cooperate with each other. You never implement all the technologies that you need. You're always busy maintaining it, and maintaining it means that you don't invest in creating the security level up. So I think there is bound to be consolidation in our market. What level consolidation, whether we will move from 55 vendors to 5, 25 or 2, it's a good question. It's probably -- I mean, I think that we can be the one. And we are, by the way, using that kind. But I think in the real world, there will be multiple vendors. But I think solutions will consolidate. And by the way, when you look at security startups, they're not just security. 99% of the business models are not about we will be the largest stand-alone company, but we're about we will be acquired and be part of a bigger platform. Everybody recognizes that the customer cannot absorb so much technology and the world will be effective. So yes, we will need best architecture. In the Infinity architecture, it's not just a platform. It's really, I think, best-of-breed architecture. It solves a lot of problems. And again, it's not done. We have a constant road map and a vision that would last for many years to make that reality happen.

Brad Zelnick

analyst
#20

That's -- I think that's fair. And I think people will continue to debate this, but I guess the goal of getting from where we are today to something that is easier to manage and that has greater efficacy, it's the desire of every customer. So it would seem inevitable that a company like Check Point should at least, in some part, be able to deliver that for them. Again, one more maybe for you, Gil, and I've got a couple I want to squeeze in here for Tal. I realize we're running out of time. But Gil, I wondered -- and if everybody can just suspend their disbelief for a moment, if you were to step away from Check Point tomorrow, take all of your experience with you and start a new cybersecurity company, what opportunity would you pursue?

Gil Shwed

executive
#21

Well, I wish I knew. I think, today, I would say the market is way oversaturated. I'm not sure I would start my own company from the beginning. I think when I started, I realized that there was this huge opportunity of a tiny market that's growing very fast that I believed will change the future. I mean I think I was right. I never -- but I was wrong in few orders of magnitude. I mean a company that would have been 100x smaller than Check Point probably would be my dreams, and it became much bigger. The Internet became much bigger, not just Check Point. But I think, today, I'm not sure that opportunity exists. I mean, today, the market is saturated. Every play you go, there is plenty of companies. And today, I'm not sure I would -- I mean, today, Check Point being a major vendor, I think we can change the world. Starting my own startup, I'm not sure I would have that opportunity again, not in cyber at least.

Brad Zelnick

analyst
#22

Fair enough. Maybe, Tal, with the remaining time, if I could, if we look at the company's recent performance, execution has been impressive of late. Billings growth has accelerated over the last 2 quarters, growing 6% and 7% in Q3 and Q2, the strongest we've seen in at least the last couple of years. What do you say to the skeptic that thinks that this is just the result of organizations needing capacity as the workforce goes remote. How durable should we think of where you are right now and the execution of performance that we're seeing?

Tal Payne

executive
#23

I usually say nothing to the skeptics. I think it's not for that thing.

Brad Zelnick

analyst
#24

I just ask for them. I ask for them.

Tal Payne

executive
#25

No, in the sense that...

Brad Zelnick

analyst
#26

It's my job.

Tal Payne

executive
#27

In the sense that you have like -- there's theories and there's fact. So the facts are very clear. You're right. We had very strong 2 quarters. We saw it coming from many areas. So when you look at the details beneath it, you see it's coming from many sources, pretty much almost across all geographies. We see product was strong. We saw it not only in the dollars but also in the number of units. So that's also always a nice thing to see. We saw cloud very strong. We saw Infinity very strong. So I'll call it the focus areas was strong. And we also saw new customers increase, so that's the third focus area. So say, when we talk about the actual results, it was good for 2 quarters. So that's good. On what drives it, now, I call it -- this is theories now, also my theory in the sense that what drives the customers at the end of the day to buy more units, it's a question that the answer, it's not necessarily clear. So it can be because maybe they need to expand the gateways when they moved into remote. But that happened, my belief -- and that's why I'm differentiating the facts from theories -- my belief, which is a theory is that, in the beginning, it was relevant. It probably wasn't relevant in -- towards the end of Q2 and Q3 because I think this is something that you needed immediately. You took care of most of it in the first quarter, so it doesn't explain the Q3 strength in that regard. We have a new appliance family. That can be part of the explanation. It's strong product, which has better throughput, connected to Maestro, enables scalability for customers and was introduced also with SandBlast package in it. So it gives a lot more security to the customers in similar prices. So maybe that's part of the driver. Remote -- the discussion about mobile access VPN, that was very low. It wasn't like tens of million. It was a few low millions. So again, that's not the source of explanation. Will it stay? This is now looking at the future. I don't know. We gave a guidance for Q4. I definitely hope it will stay. We invest a lot in focusing the marketing and the sales and the -- continue to develop a great road map. So I think it's good 2 quarters of strength. Second wave started towards end of Q3, Q4. I think you all see what's happening in Europe in the second wave. I hope it will not have an effect, but I don't have a crystal ball to forecast the future. I know we are focused on the long term, and we're doing the right thing that will translate into strength in the future.

Brad Zelnick

analyst
#28

Thank you, Tal. I'm going to squeeze one more in here, which is one of the key debates with investors around the margin profile of your business. I think since I've met you, you've always said that you don't think in terms of percentages. You think in terms of dollars. But if we look at this year, like many other companies, you've benefited from lower T&E expense in recent quarters. And many are anchored on the idea of operating margins being plus or minus 50% on a non-GAAP basis going forward. How should we think about the balance between growth and the necessary investments? Should we expect margins to hover around 50% for the foreseeable future?

Tal Payne

executive
#29

I would just say, first, I'm not relating to the margin because we are managing profit and good investments. And if we need to invest tens of millions in something that produce hundred of millions, we will do it gladly. So we really are not managing the percent. Having said that, if you look at the guidance at the beginning of the year, before the COVID, you see that actually, if you put the numbers, our indication was more around maybe 47%, 48%. The reason you see it around the 50% is actually because of the savings that's related to the T&E. We didn't intend to. When the world will open, probably majority of it will come back. So I would say, 50% is not -- I don't think it's the profile now. It's probably more around 47%, 48%, like we guided in the beginning of the year. With the caution statement, this is maybe it will be slightly higher or slightly lower. It depends on what we learn for next year. So now we're living in COVID, and it doesn't look like it's going to disappear tomorrow. I think there might be another, I don't know, maybe half a year in that environment and how the world would look after that and what will be the cost structure after that relating to the T&E, which is the major change is actually the T&E. You have some facilities and so on, but the major one is the T&E. So I don't know what to predict going forward in a regular universe. But having said that, we are already, I'll say, somewhere between the 45% and the 50%, depends which quarter. Obviously, Q4 is the highest, and Q1 and -- Q1 and 3 is the lowest -- Q1 and 2 are the lowest.

Brad Zelnick

analyst
#30

Thank you for that, Tal. And with that, we're out of time. Gil, Tal, Kip, really appreciate you attending the 24th Annual Credit Suisse Conference this year once again, and we hope to see everybody soon.

Gil Shwed

executive
#31

Thank you very much.

Tal Payne

executive
#32

Thanks to you.

Kip Meintzer

executive
#33

Thanks, Brad.

Tal Payne

executive
#34

Thank you.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Check Point Software Technologies Ltd. transcript — plus 252,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Check Point Software Technologies Ltd. earnings transcripts and 252,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.