Cisco Systems, Inc. (CSCO) Earnings Call Transcript & Summary

May 7, 2024

NASDAQ US Information Technology Communications Equipment conference_presentation 39 min

Earnings Call Speaker Segments

Heather Whitfield

attendee
#1

Hello, everyone. Thank you for joining. I'm Heather, your Webex host for today's event. In a moment, I will turn things over to our speakers. So before doing so, I have a few housekeeping notes to cover. Please note you've been muted. Should you have any questions, please ask them by using the Q&A panel, which is down at the bottom right of your screen. When submitting a question, please be sure to select all panelists. And if you happen to experience any issues, please reach out to me directly. With that, let's get started.

Marty Palka

executive
#2

This is Marty Palka, Cisco's Investor Relations. Welcome to Cisco's tech talk on our securities business. I would like to introduce today's speakers, Jeetu Patel, Executive Vice President of Security and Collaboration; and Tom Gillis, Senior Vice President of Security at Cisco. Jeetu and Tom will have an interactive conversation with Tal Liani, Managing Director and Research Analyst of Security and Networking at Bank of America. [Operator Instructions] Before we begin, I'd like to remind you that we will be making forward-looking statements today. Actual results may differ materially from those forward-looking statements and are subject to the risks and uncertainties found in our 10-Q and 10-K. With that, I'll turn it over to Tal Liani, Bank of America Managing Director.

Tal Liani

analyst
#3

Thanks, Marty. Thank you very much for joining us. We recently upgraded Cisco, and one of the reasons was expected improvements in security after Jeetu joined the group about 18 months ago, if I'm not wrong?

Jeetendra Patel

executive
#4

Tom joined 18 months ago. I joined 3 years ago.

Tal Liani

analyst
#5

Three years ago.

Jeetendra Patel

executive
#6

Build out the team.

Tal Liani

analyst
#7

Yes, I know. And we're going to talk about basically the market and Cisco in the market and how Cisco is changing to address changing needs of the market. So with that, I want to just welcome you, Jeetu and Tom. Thank you very much for doing this.

Jeetendra Patel

executive
#8

Thank you for having us.

Tal Liani

analyst
#9

And I want to start with a high-level question because we want to understand when we ask your competitors about how is Cisco in security, you're obviously one of the largest companies, if not the largest company in the space -- in certain markets. And they're talking about some share losses, and you made changes in your strategy. So what is the strategy of Cisco in cybersecurity? What are the markets you're addressing? And what are you leveraging? As a leading networking and security company, what are you leveraging out of all your assets in order to improve your position in cybersecurity?

Jeetendra Patel

executive
#10

It's a great question. There's a couple of questions in there. So let me just unfold them. Firstly, I think if you looked at us 5, 6 years ago, we had some work to do on the product portfolio to make sure that the portfolio is world class. And Chuck's talked about that at earnings. And we have gotten to work about 3, 3.5 years ago to make sure that we built a world-class platform because I think the industry is moving from a lot of point solutions to integrated platforms. And as we -- so about 2 years ago, we launched this vision around the Cisco Security Cloud, which was our platform that abstracts security services from hyperscalers. And you can basically acquire this in all traffic to any of the cloud providers. And as you move your workforce from one to the other, you can process policy. The interesting part of it here was, as we thought about it, what are the big problems we want to solve in the Security Cloud. There are a few that I can remind that's how we structure. The first one was we have to make sure that it's built in the foundation of our own. But we want to protect the user from many threats and attacks that they might have in the IP that they might actually use them. So user protection was the first objective. Second one was cloud infrastructure and cloud protection. And then the third one was breach protection. So you could actually make sure that in near real time, you can detect, respond, remediating the cover from a breach. As we started building that and the definition of a platform that's traditionally understood in the industry is you have to have common login, common telemetry, common design language, common sort of policy objects so that you could have one way to go manage all of these solutions rather than having a bunch of different piece parts. We actually agreed to all of those, and we've done all those, but we've taken one step further, which is I don't think in today's day and age especially with AI being weaponized against humans that you can have a platform that is actually not built natively with AI for the defenses. But one of the things we did was we said we have to have deep hooks into the infrastructure. To your point of like, what are you doing with networks, I think networking and security are coming together. And if you don't have deep hooks into the infrastructure and deep hooks into the applications, I just don't think you would effectively do well. So the last point I'll make on where the strategy is really differentiated because if you assume for a moment that the endpoint is compromised and that the attackers are going to be in your system, and you assume that the end-to-end traffic is always encrypted, it's really hard to see what's happening and what's transpiring and what anomalies can we detect for the packets that are going through the network unless you have presence also on the server. You can see every IO operation and every process that instantiates on the server as well. And so not only do we have presence on the endpoint. Not only do we have presence on what's happening on the network but we also have presence now in the server, build that out. We hired almost the entire NSX team to go do that. I mean it was -- it's actually been a fantastic -- and they'll be generally available in the late July, August time frame, but we are oversubscribed on early access. We cannot take that many more customers because that much demand coming. So that's basically what we've done, our move to the platform, AI and the fabric, identity of the fabric, user protection, cloud protection, breach protection on the foundation of firewall.

Tal Liani

analyst
#11

That's the strategy. Where are you on the journey to achieve your goals in terms of product availability, in terms of go-to-market, everything that makes the strategy into reality?

Jeetendra Patel

executive
#12

Go ahead, Tom.

Tom Gillis

executive
#13

So the name of the game is product excellence, putting these pieces together in a way that it's easier for the customer to deploy and create a better security outcome. The user protection suite is the most advanced in this regard. So we've taken what used to be 7 separate functions: firewall, IPS, VPN, zero trust, browser isolation. We built this into a single integrated console, one login, one set of policies, one set of capabilities a customer can deploy it, works on-prem, works in the cloud. That's the direction that we're going. The breach protection suite is probably next in terms of its maturities. So we introduced a new technology we call Cisco XDR. And so it's a real-time analytics engine that can identify unique sources of telemetry to build automated actions necessary. And then the cloud protection suite is a place where we're putting the current amount of focus. Hypershield is a premier part of the cloud protection suite. That's where we're at the journey.

Jeetendra Patel

executive
#14

I'll say on sort of pure evolution, we have -- since we launched the capabilities in the platform, in 2023, we probably have had more innovation in security than we did in the history of -- in the past previous decade combined. And I think '24 will see multiples of '23. So what you have seen as kind of rate and pace of change within Cisco has actually just never been experienced before. And I think we have -- overall the entire leadership team, we've invested a lot of dollars into this. And you're starting to see meaningful change in sentiment in the market from both partners and customers alike. We recently had at the St. Regis probably 2 months ago, 41 CISOs that came in that we wanted to give them early access to some of the stuff. They all came in slightly skeptical. They were not really sure. By the time they were leaving, 100% of them said this is one of the most game-changing strategies we've seen. And you're showing execution because everything we showed against that strategy were products being built on the ground up that are in general availability other than hyperscale. So our SSC product, available in market today. Our XTR product, available in the market today. Multi-cloud defense, available in market today. Identity intelligence will be available in market by this month. You talked about Hypershield, will be available in the market by August. So like there's a fair amount of innovation that's happening to take these products to market.

Tal Liani

analyst
#15

We touched on many things, and I want to go back to something you said. You talked about the platformization platform. And what Palo Alto spoke about is, Microsoft is doing, but what -- first of all, what is the difference between bundling and between platformization? And where are you on the platformization? What are the benefits that you bring to customers that will enable you to gain share on top of -- as you said, on top of the firewall that you're having today?

Jeetendra Patel

executive
#16

Yes, it's a great question. And so let's break this down a little bit because I think there's 3 stages that companies go through. The basic stage, which is just bundling, is just purely a discounting exercise. So it's interesting, but not consequential. What actually gets me really, really interesting is when you brought a common way of managing identity across the products. We have a true way to make sure that you can manage their policies. Your policy objects are commonly set so even if you set them in different places, there's actually no contention between the policies. You have a common design language, which we have between not just our security products but between networking and security. So those are the sort of -- and common telemetry. So the first aspect of the platform is common identity, common design language, common telemetry, common design language. And then the second piece, which is what I talked about earlier, is deep hooks into the infrastructure. So if we happen to have Hypershield that we built, which is basically a distributed security fabric, you can have multiple enforcement points, and you take security to the workload. If you want to show go out and secure a factory floor, you can do that. An IoT and OT device, you can do that. If you want to go secure a microservice or Kubernetes container, you can do that. And security gets distributed in this hyper -- in a highly distributed network. As you do that, one of the key things is, where does that security actually get enforced. We can -- over time, we will be able to enforce security on a GPU sitting on a net, on a server or even a top-of-rack switch. That is deep hooks into the infrastructure. The way you think about this, if you've taken security, melted it with the fabric of the network. That's something, by the way, that no one else does quite the way that we do because we are -- if you think about what is the name of the game in security, it is to prevent lateral movement, assuming that the attacker is already in your environment. And they're going to make tops to help you steal data, right, and cause harm. Who knows the most about lateral movement? Cisco. Who has the most -- where does lateral movement happen? On the network. And so the more you can go out and detect lateral movement, the better off you're going to be. And that's what we've been able to do. That, we believe, is when you actually have a true platform, you have hooks into the infrastructure. Anything to add, Tom?

Tom Gillis

executive
#17

No, I think that's it. Yes.

Tal Liani

analyst
#18

So we're a financial analyst, and we look at things in dollars and cents. And the question is, when you -- at the end of the day, in the last few quarters, you've grown submarket, meaning you've grown 3%, 4%. And there were times that you grew 10% and above. Two questions. Number one, can you break down your growth in the last few quarters for us? What are the growing parts? What are the declining parts? I'm sure it's a mix. And then second, how long does it take you or will it take you to translate all this innovation into better world?

Jeetendra Patel

executive
#19

I can't comment about it. We're in a quiet period right now, so I can't comment too much about specifics, but I'll give you some macro pieces on growth. In general, when you take something, you take on an endeavor like what we had taken on a few years ago. We basically rebuilt our platform, right? And there's a few things that need to happen. You have to make sure that you're building out the products, and you've actually got market recognition that, that's happening. But there is a level of that, that's organic, where you can't just go tell them. People have to tell each other. You're now finally starting to see that momentum start to shift. And we've only seen that happen now in the past quarter or 2, where you could probably see the difference in sentiment in partners and in customers. And we're now starting to replace some competitors as well, which is great. I think it's still a long game. It's not going to be something that next quarter, all of a sudden, you can see that. This is a consistent, steady movement. And the way that we think about this is we're in this for the long haul. We've built capabilities that we're going to continue to keep investing in. And we're going to make sure that we have deep hooks into the network. And we're going to use our advantage that we have in the network to also make sure that we drive security because where security meets the network is where we shine the most.

Tal Liani

analyst
#20

Two questions. Competition and pricing. Is -- cybersecurity is one of the most resilient spending in the network. But we see a lot of competition. For example, Microsoft, that turned from a small player to a giant player in the space. How do you view competition? What are the areas where you think you're going to excel versus competition? And where do you see bigger competition? And then secondly, how is pricing environment in cybersecurity? Is there any price element of the competition? Or it's more about product, technology, benefits of platformization, et cetera?

Jeetendra Patel

executive
#21

It's a great question. Why don't you start and then I'll actually add on to it?

Tom Gillis

executive
#22

Yes. So customers care about outcomes. And so we think about how we deliver a better outcome than our competitors. Now when we think about in the eyes of the customer, who are the stalwarts of their IT structure? Microsoft is still at the top of that list. So we don't view Microsoft as a direct competitor. We view ourselves as complementing Microsoft. They have unique capabilities on the endpoint and the application. We have unique capabilities that connects the endpoints to the application. So folks think much more into our competitive targets are going to be folks that are in that network security, Palo Alto networks supporting that. Zscaler, they are much more in that domain. And the way we can win is not just like coming up with some security feature that they could copy. It's by coming up with things that are uniquely advantaged by integration into the network. And that's our core is what can we do to put security into the fabric of the network that allow us to be more effective for our customers. And I think the market has been looking for that, frankly. The opportunity, in my opinion, is fairly obvious. And it's up to us to be able to articulate here's how that works and your customers can experience. So as we start to roll this stuff out, we expect continued growth in terms of just our awareness, presence in the market and customer adoption.

Jeetendra Patel

executive
#23

Let me add a little bit more color because I think this is where our acquisition of Splunk will be very strategic as well. And so what we've done with our surveillance and then how all of these things come in. So firstly, what is our high-level areas of differentiation? Three things. We want to make sure that we can have meaningful differentiation and efficacy. Efficacy should be higher because we've actually got an end-to-end view of everything that's happening in the endpoint on the network as well as on the server and the host. Number two, our experience has to be better. The way in which we manage, we've got generative AI now as a user interface paradigm across most of our products at this point in time. We've got a software system, we've got a firewall system. You could set policies and just natural language and English. And number three, the total cost of ownership for customers. The economics will be more favorable, right? Now as you think about this from a competitive standpoint, I think it's important that we understand where unique differentiation for us is. Like Tom said, when you think about who has the data on the endpoint and telemetry -- Cisco is a data game, right? And security is a data game. And the one who has the most data that can be most effectively correlated with, we've got over 250 million endpoints with AnyConnect. We've got a fair amount of traffic that traverses our networks at every packet and every e-mail forward is -- and every web request that's happening. And we now have presence on the host with [indiscernible] DBPF and with Hypershield that we built, where we will now have every single IO operation and process that's getting kickstarted in the kernel without actually being in the kernel that's sitting in the user space. That combination of telemetry then combined with Splunk is something that is very hard to go up and replicate overnight by competition. So when customers are rethinking their architecture for AI-related data centers or for enterprise data centers or for the public cloud workloads, and they say, what's the one end-to-end platform that we can bank on? What we're starting to see is the lightbulbs are going up, and Cisco has the best and the integration at this point, where things like ThousandEyes just seamlessly integrated into our product than we've ever had before. And so it does -- our challenge right now is how quickly we can see awareness in the market. But we are starting to see that curve to be pretty exciting to see.

Tal Liani

analyst
#24

And just my second question was on pricing. Is there any pricing pressure in cybersecurity on cybersecurity exhibitions?

Jeetendra Patel

executive
#25

I think the pricing dimensions are interesting because what's happening on pricing is we've been spending more money in security year after year every year for the past couple of decades. If you sit on any audit committees, one of the first conversations that CISOs have is we need more money to go out and keep ourselves protected, our security posture in line. But what ends up happening is ransomware has not reduced any. And you're still being old. And so the challenges that are there in pricing is it's more around the total cost of ownership that you have where point solutions are just no longer feasible because of the complexity and because of the amount of cost it takes to manage 70, 80 different policy engines. On average, most customers have about 70 different product spend, right? And so from a pricing standpoint, I think there's a lot of economics that comes into play, where we can increase our ASP while simultaneously reducing the cost for the customer. So I don't think those are mutually exclusive.

Tal Liani

analyst
#26

Okay. Maybe we'll -- I want to talk about your solutions and drill down the solutions. And you mentioned Hypershield multiple times. Can you take us through it? What is it? What value does it bring to customers, et cetera?

Jeetendra Patel

executive
#27

There's a man who actually all about it. So I will let him talk.

Tom Gillis

executive
#28

Sure thing. If you think about the way security controls have been built for decades, they've been built -- they come in a box. And the lock sits in a place in the network, usually at the edge of the network. And that's fine, but it has limited granularity and therefore, limited effectiveness. So what we did is we said, we want to security everywhere, not just kind of the perimeters and corners, but everywhere. And this is increasingly important in a world where applications are more spread out. Remember the 3-tier web app, web server apps, server database through big giant VMs. Now it's 300 or 3,000 microservices. And conversely, users more so, probably don't need to elaborate, but it's iPhones and Android tablets and not just users, but smart devices that are running in the factory floor or a hospital environment, et cetera. Hypershield is designed to address exactly those trends. So it allows us -- it's distributed system that allows us to put the security enforcement where you need right next to the application with a level of understanding of the application that wasn't available before. Jeetu talked about the new software constructs, one of which is called EDPF. It's kind of a nerdy name, but it's really powerful capabilities. It's an interface in Linux and Windows operating systems that lets us tier into the memory and the heart of the system, and deeply understand the application. And that allows us to tune our security policies to match the vulnerabilities of an application. Now with AI, we have the ability to provide management for these systems that wasn't possible before. So this is literally a system that can write its own rules, they can test its own rules, deploy its own rules, life cycle manage its own rules, remove them when they're not needed and then upgrade itself with no human intervention. When customers see that, it's startling leap forward, right? It's not an incremental improvement. And this is something that's unlike anything they've ever received before.

Jeetendra Patel

executive
#29

Let me just brag about Tom and his team over here for a second. And I'll tell you this, if you might see a change of tone in my enthusiasm this year compared to ever before in security because I feel like the work we are doing is not just products that someone else has built, that we've built a slightly better mouse trap. We are reimagining architectures that have never been done before. This is not the next generation of something that exists. It is literally the first generation, something completely new. And so 3 key problems tactically that Tom talked about that are really important for everyone to understand the result. If you assume that the attacker is already in your environment and you're trying to contain lateral movements, the way that you do it right now is by isolating the attacker through this technological segmentation. And segmentation is really hard, especially as you go into hyper distributed environment and microservices that are sitting on Kubernetes containers and everywhere else. What we've done is provide something that actually does autonomous segmentation of AI. So that's the first problem resolved. The second big problem resolved is if you look at the amount of time it takes from when a vulnerability is announced in the market to when an exploit happens, some of the most recent vulnerabilities that we had was a 3-day elapsed time between announcement -- announcing of the vulnerability to exploit happening. But it takes about 20 to 45 days to actually have a patch test that we deployed. So you've got this window that's really critical and has exposure for an organization of 45 days, but an exploit can happen as early as 3 days. And I think that's going to go down to hours and minutes. So the exploit time is getting compressed, but the actual vulnerabilities or the patching of the vulnerability is elongating because of the amount of vulnerabilities that you're detecting, about 1,000 of CDs. So when you start looking at that, how do you go out and solve for that? We have a way that within minutes, you can get an automated compensating control in place to prevent you during that exposure time while you're testing and deploying the patch. So that's number two. And number three is updates are really hard. You usually have 2 change control windows a year. We've got a firewall. We've actually done a lot with our firewall to upgrade it. Every single time someone uses the new version of a firewall, you have between 20 and 40 points of NPS improvements. But only 40% of our customers are using the new version of firewall because updates are hard. You have 2 change control windows a year. We now have a way to use upgrades and security infrastructure, just like you do it on your iPhone where there is a self-qualifying update. But because of hardware acceleration, you can now do things that just weren't possible before. So what Hypershield is, is not just a new product. It is an entirely new architecture to enable distributed kind of -- an enterprise data centers as well as hyperscalers to be able to utilize this technology in various way. And I think this is probably one of the -- we talked about this when we launched it a few weeks ago at McLaren. This is the most consequential innovation we have had in Cisco in the area of cybersecurity in the past 4 years.

Tal Liani

analyst
#30

Your target customers, are they mostly enterprise? You mentioned a lot of hyperscalers. Who are your target customers?

Tom Gillis

executive
#31

Enterprise customers buying...

Jeetendra Patel

executive
#32

[indiscernible] for hyperscalers, and we're bringing it to them. At NB enterprise, we target the networking folks, and we target the CISO, and we target SOC app. So those are the 3 areas that we focus on as buying centers.

Tal Liani

analyst
#33

Okay. you mentioned Cisco Security Cloud, and you mentioned 3 components. Can you delve into it? First of all, what is the problem that this solution is solving? And how are you positioned better than others? How are you approaching this problem?

Jeetendra Patel

executive
#34

So we take user protection suites. So by the way, what we did was we said not only are we going to make sure that we solve these 3 problems. We're going to take our 30 products and thousands of SKUs. And now people can also transact as 3 suites if you want to. That's the follow-up. And so we're simplifying the ability for people to do business with us. But in user protection suite, in each one of the suites that we have, we have a lead product that we can actually enter in with, right? And so in user protection suite, we have this product that we built called Secure Access, might compete with Zscaler, might compete with Palo Alto. And Secure Access essentially is one single experience whether you happen to be an employee or contractor, whether you happen to be at home or at work, whether you happen to be connected to a private application or a public application, a SaaS application or private application. One experience, one management console, one way, and you don't have to worry about oh, I'm a user, I'm connecting to Jira, I need to log on to my VPN. I'm a user. I need to connect Salesforce, I'm going to use ZTNA. We do all of the plumbing behind the scenes. All you do is we call it one of the most boring demos. So you open your laptop, you log in, you can actually get to work. There's nothing to demo, right? But that wasn't enough. That was -- that's interesting and that's better than what the market has today by a long shot. So we wanted to do more. So what we've done is we've also hydrated that with identity intelligence. And so we acquired a company called Port, which actually does identity threat detection and response. And we built an identity graph that can correlate data [Audio Gap]. If I want to connect to Salesforce, the way that I do it today is an SSD product will ask an identity provider, hey, is Jeetu's... [Technical Difficulty]

Heather Whitfield

attendee
#35

I'm so sorry, we lost audio. Thank you. If we could go back a few minutes.

Jeetendra Patel

executive
#36

Sorry, I think we got dropped off. We got automatically muted for some reason. That's also my fault because I want the next -- so I don't know when we got muted. So maybe someone can...

Marty Palka

executive
#37

Heather, you know -- could you -- you know when mute went off?

Heather Whitfield

attendee
#38

I know it was just a few seconds like a...

Marty Palka

executive
#39

Okay. All right. That's fine. Perfect.

Tal Liani

analyst
#40

So we spoke about platforms. And we spoke about products that are within a complete strategy and vision. What about point solutions? Or where are customers when it comes to purchasing point solutions and then you need to compete product by product versus buying a platform, meaning how advanced is the market to get to this point of thinking the way you think, thinking about the journey of the packet from the user to the end?

Jeetendra Patel

executive
#41

I think the thing that more and more customers are starting to get around is efficacy is name of the game, and ease of management is name of the game. And when you think about efficacy, it is not that the features don't create efficacy but the cross-use of telemetry so that you have better insights is what creates efficacy. And so it's not -- this notion -- I actually dispelled a notion that best-of-breed is even a thing because the reality is it's point solutions that have a very tunnel vision view versus a broader aperture. And you can't take shortcuts in the product. You have to build great products, but those are great products that have to integrate with other pieces seamlessly so that when we integrate our Secure Access product with Duo, with Identity, with ThousandEyes, the combined experience you get is very different because it's not just that you get a great experience. But when the experience is not great, we can tap into ThousandEyes and tell you exactly what the issue is. Is it your ISP? Is it your router? Is it your connection? Is it your application? And you'd be able to troubleshoot that in a very, very different way. And so the -- our ability to connect between networking, security, observability and the data platform with Splunk actually gives us an advantage, which is pretty exciting. And the more -- where customers are right now is when you talk to them and walk them through the vision, the lightbulbs go off. Our challenge is getting to that message at scale. And we -- that's why it's going to take a few more quarters because that's what we need to do.

Tal Liani

analyst
#42

What's happening behind the scenes at your level to enable this? Meaning do you need to build the cloud? How big is the cloud? How much investment? Like what do you need to do to enable this kind of services because some of these are services and not products.

Jeetendra Patel

executive
#43

Well, one of the things we've been able to do is we kind of know how to build at scale cloud infrastructure, right? I mean we've built Webex that has hundreds of millions of users going out -- it's got 75 different data centers. And so our data center know-how on how to go out and build for not just the private cloud, our own data centers, but also hyperscalers and public cloud tends to be pretty strong. And so what we've been able to do is utilize that know-how in the company to build capabilities. But the infrastructure has never been an issue for us because we are so good at that. We are an infrastructure company. And so when you think about what we did with Secure Access, our data centers are managed by the same team that actually manages Webex. And so you're able to go out and drive this and get the scale portion from an enterprise data center.

Tom Gillis

executive
#44

So the question was what are our target markets? Cisco is fairly unique in that we have a very, very broad market reach. And we can build products that meet the most sophisticated customers in the market, the very, very top of the market. But we also focus on simple, easy-to-use solutions that are often purchased in a self-serve motion. Customers hear about it, they're like, oh, do I want to like run an authentication? As you know what, while we're sitting on this call, I think we just closed a deal. Look, we just closed another one, right? So that machine is running down into the small and medium [Audio Gap] is just the easiest to use. And when you combine -- you bring those 2 elements together, you can build better products across all of these segments. So the answer is yes to our target customer, right, with lots of them.

Jeetendra Patel

executive
#45

I think it's important to also serve every segment in security because the weakest link typically in security is -- determines the strength of the entire value chain. And if you don't have technology that actually not only supports your customers with their customers all the way through, that network effect is a pretty important one.

Tal Liani

analyst
#46

Got it. Another question is, when you saw Cisco has a stated strategy as a corporate to migrate more to SaaS and subscription revenues, et cetera, talk about how you help the corporate to get to their goal? Because when you look historically at Cisco, majority of your revenues came from all-prime solutions. So talk about the journey from a business model from a way you charge like how your new strategy helps you to get to these goals.

Jeetendra Patel

executive
#47

I think the first thing, we are now 50% recurring revenue as of last quarter. I think that was announced in the last earnings call. So the transition to recurring revenue has been a pretty successful launch for Cisco over the years. All the new products that we're building that we talked about, SSE, XTR, Hypershield, multi-cloud defense, identity intelligence, all of these products are SaaS products, right? And we want to make sure that the way in which we -- and SaaS is not just a pricing model for subscription. It's a whole new way of building products weekly and daily updates and build. There's rapid innovation. There's kind of -- it's offered as a service. But we want to make sure that we're also deeply integrating that into our core networking platform. So Hypershield is a SaaS product that can actually have an enforcement point on a server or potentially over time on a switch -- on top of that switch. So what we are doing is we are taking advantage of our franchise on the hardware side, but we want to make sure that we build SaaS offerings. And the combination of those 2 is what -- I think this kind of distinction of hardware versus SaaS, I mean, it's interesting. But the thing that we have to think about is how do we make sure that both of them together provide a complete solution for the customer.

Tal Liani

analyst
#48

Is it -- is your position in hardware firewall appliances, does it help to get to your journey? Does it mean that our -- does the fact that the customer -- I'm thinking about it in simple terms. The fact that the customer is already a Cisco customer on -- a firewall Cisco customer, how does it help them to get into the new strategy?

Jeetendra Patel

executive
#49

I'll give you a very concrete example. Our firewall customers use something called the Cisco Defense Orchestrator to manage the firewalls. Guess what they use to manage Hypershield? Cisco Defense Orchestrator. And so when you have common management across our brand software, that's one big area that helps. I also feel like you want to make sure that you provide customers a choice. So we provide customers deployment choice. You can actually go out and deploy those hardware plans. You can deploy it as a virtual machine in the cloud or you can deploy it as a full multitenant firewall. And then we've got Hypershield, which is a really different architecture. All of those being managed by the same management plane.

Tal Liani

analyst
#50

Got it. We only have a few minutes left. Do we have any questions from the audience? No. Okay. So I want to ask you about the SOC. Why is SOC so important?

Jeetendra Patel

executive
#51

I think you have to assume that it is not if a breach happens, but when a breach happens. And when a breach happens, what customers do to be resilient to recover from the breach is almost more important than doing the things to prevent yourself of the breach occurring in the first place. And so the recovery time from when breach occurs to when you can get back to operational rhythm within your business is super important. That typically requires near real-time detection of a breach, remediation, response and recovery from that breach, right? And that happened to the SOC. And the beauty about the SOC is what we can do is we can correlate multiple data sets that would have otherwise when looked at in isolation made you ignore certain alerts that you can now graduate. For example, if I have a funny-looking e-mail that comes in, 80% of the breaches that happen still start from e-mail. A funny-looking e-mail that comes in from a prince from an exotic country that says click on this link, download your $10 million. That funny-looking e-mail by itself might have gotten ignored. When you see that, that funny-looking e-mail directed you to a website that didn't exist 2 hours ago, that downloaded some pieces of software on your device, which was malware that kickstarted a process in our shell, that then started creating lateral movement within the organization, correlating those breaches so that you can graduate -- correlating that telemetry, so you can graduate something as a breach versus just an alert that you should ignore is what the SOC does effectively when you actually can take a data platform-based approach. And that's between what Splunk can do and between what we do in this area, it is phenomenal because Splunk has been very good at going out and solving and building the SOC of the future. What we've done is we add network telemetry, endpoint telemetry and identity telemetry to it. So you've enriched the data of -- with other kinds of telemetry that just allows you to better correlate their stuff. Anything to add, Tom?

Tom Gillis

executive
#52

Well, I think that the technical building blocks that we have at our disposal, AI, distributed compute and GPU that Jeetu was talking about, these new software constructs is going to allow us to change the procedures of the security operation center like dramatically, not incremental change but fundamentally change what the SOC is capable to do. As Jeetu said, it's about responding to the breach. The breaches are going to happen. So it's about how you respond. And we think we can create much more automated, much more real time, much more guided responses. So the next couple of years are going to trigger a significant change, change for its winners and users as we talked about. And that Cisco is positioned to capitalize on these changes and be accelerating our position in market.

Tal Liani

analyst
#53

Unfortunately, we ran of time. Tom and Jeetu, thank you so much for the very, very detailed description of Cisco Security. And it is a new company, and I agree with you. Thank you.

Tom Gillis

executive
#54

Thank you, Tal.

Marty Palka

executive
#55

Thank you very much, Tal. And we look forward to Jeetu and you continuing the conversation at the BofA tech conference, June 6. So we'll have our quarterly call on May 15 and our Investor Day, June 4. Heather, you may close the call.

Tal Liani

analyst
#56

Thank you.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Cisco Systems, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Cisco Systems, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.