Fortinet, Inc. (FTNT) Earnings Call Transcript & Summary
February 11, 2020
Earnings Call Speaker Segments
Brian Essex
analystAll right. We'll kick it off. So good afternoon, everyone. My name is Brian Essex. I'm Goldman Sachs' security software analyst. We're very fortunate today to have Michael Xie. He's the Co-Founder, CTO and President of Fortinet. And we have Keith Jensen, who is the Chief Financial Officer and Chief Accounting Officer as well. So thank you. So we'll do -- I'll do brief -- we'll let Keith read a safe harbor agreement. And then what I'll do is a little bit of Q&A, and we'll leave 10, 15, maybe 10 minutes at the end for Q&A from the audience as well. So with that, again, welcome again. Thank you for coming. And Keith, why don't you kick it off with your carefully prepared remarks.
Keith Jensen
executiveThank you, Brian. I'd like to remind everyone that we may make forward-looking statements during today's fireside chat. These forward-looking statements are subject to risks and uncertainties that could cause actual results to differ materially from projected -- those projected in these statements. Please refer to our SEC filings, in particular the risk factors, in our most recent Form 10-K and forms 10-Q and to other reports that we may file from time to time with the SEC. For additional information on factors that may cause additional -- pardon me, actual results to differ materially from our current expectations. All forward-looking statements reflect our opinions only as of the date of this presentation, and we're going to take no obligation and specifically disclaim any obligation to update forward-looking statements. Thank you, Brian.
Brian Essex
analystThat's amazing. So yes, thank you. And again, thank you for joining us here. Really fortunate to have Michael on stage. So maybe what I want to do is kick it off a little bit. Michael, as kind of a co-founder maybe help with the evolution of Fortinet, how the company got started, the focus of the business on SMB instead of large enterprise, how did you kind of develop the core foundation of the company.
Michael Xie
executiveSure. Thank you, Brian, and very glad to be here. So I think at Fortinet, the ambition has always been in the cybersecurity industry, and our mission has been to build like effective tools to help our customers running a secure network to keep the hackers away. And I think we started probably 20 years ago when, if you remember, there's a lot of these virus, what they call the worms, on the Internet, attacking the PCs automatically. So we had to start to have this technology. We say, okay, we have a better firewall that you put in front of your servers, it's actually going to stop these worm attacks. I remember the very first customer, we -- actually and we brought them the device in a car trunk. And then we installed on -- in front of his server, we just turned it on. We just tell him that this is the configuration and how it works. And then if you like it, a week later, we'll come back with -- give you a new one to sell it to you. If you don't like it, you don't need to pay, we'll take it away. I think just the next day, the customer called us, it's a great equipment, I'm going to keep it and come in and I'll write you a check. So we came in and we say, okay, it's good that you really like it, and we want to take the equipment away for next evaluation customers and then we'll ship you a new one as soon as we get back. But the customers said, no, no, you're not taking this off. Like if you take that away, then there's so many attacks and worms that I see. That's making my network really dangerous. So he actually refused to take the device away. He wrote us a check right away. So it's just -- for me, it gave me a great pleasure to see our customers using our devices and protecting their assets and that we can keep these attacks away. But of course, over the years, we start to gradually grow from sort of smaller offices and then to try to scale up the bigger ones. And then you mentioned the service providers. At some point during our growth, I think a lot of the service providers see that opportunity. So they purchase our firewalls. They protect their, sort of, their subscribers. And then we have to basically develop a lot of features like multi tenancy so that they can put in an appliance or protection virtual clients, and then it's going to segregate that into a lot of the different virtual instances providing their multi-tenant customers. And also, I think that also drove some of our fundamental technology as I think some of the -- you guys may know like we develop our own ASIC. And it all came from that request of higher performance and keeping the things sort of relatively affordable. That's sort of all the way came from there until today.
Brian Essex
analystGot it. And really kind of part of the secret sauce of the company is in that ASIC chip and the development of speed and efficacy of the appliances that you built. How do you think about how that sets you apart? And how should we think about the life cycle of your solutions, particularly relative to who you get compared to most frequently that have more large enterprise-focused customers?
Michael Xie
executiveSo we're starting to spin our own ASIC. We actually -- we have a better name, it called SPU, Security Processing Unit versus like GPU or CPU. So I think that's the right role. It helps to accelerate a lot of the security processing that's very hard to do in the general purpose CPU. And we just make it like 100x more effective than doing it in our -- in ASIC. And over the years, we have always been investing into that area. And Keith can attach, we always have a good portion of R&D budget into like research and development. And we -- over the years, we just going to make it scalable to bigger performance and then more inspection capabilities. So it's part of the strategy. It seems to be always working, right? I mean although from time to time, I think people are coming to say, all things are going to cloud. It does. But then we see that more like in addition to these on-prem security and the need for that has never sort of decreased, but it's over time increased. And then the customers, as the -- the attack surface expands to get more vulnerable from the like of hackers on different places, there's still a lot of need for very high-performance effective inspection engine just put in front of their on-prem infrastructure where we find ASIC strategy is a very effective way to deliver that promise.
Brian Essex
analystGot it. And maybe I don't know if either you or Keith wants to take this one. But particularly considering the origins of your initial customer base, a lot of investors will ask questions about firewall refresh cycles. Interestingly, your product revenue growth this past quarter is quite robust when everyone else's went down. So help me understand what you're seeing in the market on the product revenue side, your ability to sell appliances in the market, and how sensitive are you to firewall refresh cycles.
Michael Xie
executiveI might -- could just comment on sort of the more general, I think, on impression, and I'll let Keith because he is really good with the numbers. So I think from the technology side, we see there's definitely lot of demands on the newer technology trends, whether from the cloud. There's the segmentation. There's the security incident response. And then -- but they don't conflict with the more traditional firewall because firewall helps the enterprise to build effective parameter, just like if you have a castle, you want to have fences, you have moats, those are still there. But then the additional capability just allow you to build -- but there's 2 things. One, it allows you to build this in a virtualized, whether it's cloud or like a private cloud environment. And the second is adding more capability. So that in addition to fences or the parameter, you have like fully wired alarm and everything inside the cameras to catch the burglars. So just as an analogy, we also see the demands for these newer technology without seeing a decrease of the demand on the basic parameter building the task.
Keith Jensen
executiveYes. I think the -- Brian, I think framing up the conversation about the refresh cycle, I'd probably harken back to a few data points that we offered in the Analyst Day related to our diversification. So if you look at our customer segment mix, very round numbers, probably 1/3 SMB, 1/3 mid-enterprise, 1/3 enterprise give or take a little bit. And those probably have very different churn rates, if you will, and refresh rates. Keep also in mind the geographic diversification that we offer as a business model, which is probably a little bit different than some other tech companies and some of our competitors. I think a lot of the conversation about a refresh cycle, maybe a little bit U.S.-centric, a little bit enterprise-centric. And with us, our business, we've provided this metric recently, 80 countries represent 50% of our business. No one of which is 3% of our total business. And yes, we do have the 6 economies that make up the other 50%. But that diversification for us is probably spread out some of the impact of what some others may have experienced at the refresh cycle. And then it would also offer the product suite. Michael and his team have produced about 75 different firewall vendors -- or pardon me, models, all of which are going through different stages of the product maturity curve. And so you're getting a fair amount of leveling from that. And then, of course, now we're a different company than we were in 2014, '15, if you will, where we probably, like some of our competitors, we're very much a firewall-centric company and very exposed to what was happening in the firewall market. Now you're looking at a business that more than 25% of it is fabric solutions, plus the SD-WAN solution on top of it. So I think all those things are really coming together to produce the results that you saw in 2019 despite some of the headline commentary going into the year.
Brian Essex
analystRight. And maybe if you could unpack a little bit. The strength that we saw in the product revenue side, how much was that -- how much of that was from existing customers replenishing upgrading to better technology? How much of it was new security applications that you're addressing? And how much of it was expansion into new markets with a geography or going upmarket into like larger enterprise?
Michael Xie
executiveSo we built a product like more integrated fashion. We took basically a security platform that we call the security fabric. So this means a lot of times -- for example, like SD-WAN, right? It opens a lot of door for us. But the SD-WAN feature is integrated into our security and firewall features. So it opens a lot of doors. But at times, it actually helps our higher revenue. Although it's a opportunity with a large SD-WAN component integrated into that, right? So I think -- again, I'd refer to Keith for some more quantitative numbers.
Keith Jensen
executiveYes. I think the -- I don't think we're over-indexed one way or the other in terms of new customers or selling into the installed base. I think we've seen growth in both instances. It's -- on a quarterly basis, if you look at new logos for us, and you can see that in some of the information that we provided elsewhere. You're talking several thousands of new logos that we add each quarter. And those are primarily mid-enterprise and enterprise. If you move down the SMB, you start getting to an even larger number. So there is a constant influx of new customers, if you will. And then as Michael alluded to, the ability to come back to follow-on sales, other fabric solution to our customers that have acquired a firewall. But I would also not lose sight of the fact that when a customer becomes a firewall customer, there's also new use cases that typically evolve inside that customer base where they come back and buy firewalls, whether they're appliances or they're virtual form factors.
Michael Xie
executiveIf I may add a couple more points. I think I see a lot of reference to firewall, like refresh cycle. But in our perspective, we almost see that as continuous. I think from some larger financial institutions more like the carriers, they -- each of them has their own cycles. But the technology evolves, like, for example, we constantly add hundreds of features every release. And a lot of our competitors does as well because they need to have that to keep up with the threats, right? And then combine that with the diversity in the geography and then auto industry, it's almost like continuous, like every day, there's another -- maybe 500 customer trying to refresh or purchase new capabilities of firewall. So it's less seasonal. I don't know whether your number points another way. But from like a product perspective, we almost see a continuous demand of refreshing to newer firewall technologies.
Brian Essex
analystOkay. And then another question I get quite a lot is the debate around do firewalls need to exist in a longer period of time. I know you mentioned micro segmentation. There are a number of other different use cases. What is your -- and I understand you might be a little bit biased here. But what is your view of firewalls from a longer-term perspective? Where do you think the market eventually evolves to? Are we in eventually going to get to a primarily software-defined security environment? Or what is the debate in favor of long-term persistent use of firewalls in the network?
Michael Xie
executiveI -- a lot of time, I try to make sort of analogies, comparisons. I think cybersecurity, in a way, similar to the sort of physical security at home. I think that I [ triggered ] up the locks and keys, they were invented maybe 100 years ago. I don't see that goes away, right? I mean it provides a good like a parameter against like illegal entries. It's just going to make it more secure. So I think firewall is sort of like that sort of lock component. It keeps your -- like your parameter relatively secure -- like it doesn't do everything. And then the hackers today, they get creative with their tools. They can break the windows and then there's alarm systems. There's security cameras. Like altogether, they basically have a more security -- physical security on the homes or businesses. Cyber, it's kind of similar, right? If -- let's say, we say the firewall is the lock, what's different is the form of this lock, right? I mean if it's on-prem, it used to be hardware appliances, just to put it in front of your routers. But now because of the virtualized environment, the cloud. But still, the firewall is still in that position, except like in the cloud, it become a cloud gateway and there's like in the VMware kind of private cloud, it gets into sort of that hypervisor layer, but still it provides similar capability. So I think the security is evolving. That lock and key seems to be always need to be there, except that it's transforming into different forms of installation to fit into whatever the computing infrastructure the customer has. But on the other hand, there's also the need for these additional pieces to raise incidents and alarms and be able to respond to the security threats. And those are, I think, where we also invest heavily into building the security fabric.
Brian Essex
analystGot it. That's helpful. I want to spend a little bit of time on SD-WAN because it's top of mind, I think, for everybody. And maybe could you frame for investors why SD-WAN matters for you? And how you're well-positioned to offer this functionality in your appliances versus some of the competitors that you see out there?
Michael Xie
executiveSure. So we -- I think we started the SD-WAN development probably 7 or 8 years ago. When customers actually just came to us, and then basically they were asking for features, right? So they have a firewall and then they usually have, like a number of like WAN providers. Because it gives them better redundancy and have better performance. And then they want to find ways to better low balance them and then provide the sort of the security -- sorry, the service level agreement, called SLA. When they make like a phone call or like a video streaming, they want to maintain the quality of those. It's critical for their business. So we started to invest into these areas. And then that combined with some of the VPN technology that we actually have an advantage on our ASIC platform. And gradually, we're struggling to name what this is. It's clearly related to our firewall. Essentially, the customer wanted to central manage them. We've been giving different names, call it like a link low balancer, kind of hybrid WAN, coordinator, to put all things until, eventually, I think, probably Gartner said this is SD-WAN. Okay, fine, SD-WAN it is. So from that point, we saw it's -- I really like that terminal because it's -- exactly communicate the capabilities and the customers understand that. And then our unique is, like we combine that with the firewall security. So you have an SD-WAN, then the customer don't have to maintain all the complexity of separately manage that. But once they configure that, they see that as like one pipe, even if there is very complex logic underneath the hood, right? So it's just provides like a lot of the new opportunities for us. And I think Keith has the percentage of our deals of SD-WAN related, and I think we grew from 0 to like -- I don't know.
Keith Jensen
executiveHigh single digits, be careful. Jump into [indiscernible]. You're too precise with your engineering background. I don't want you to say something...
Michael Xie
executiveSo...
Brian Essex
analystAnd how has that been relative to your initial expectations? That's part A. Part B is how has the penetration of that market evolved? Are you getting into larger enterprise deals for SD-WAN? And how is that mix now relative to when you first started out?
Michael Xie
executiveWe do. Yes, we -- I think SD-WAN almost from day 1 is for like large-scale. I mean you see those with a couple of sites. They sort of use a subset of that. But then to us the true SD-WAN, the bigger names are those with thousands or even tens of thousands sites and then with a whole bunch of hubs and now with more complex like tunnel routing and like things like the forward error correction with packet duplication. So these are very advanced complicated deployments. So we have -- I don't think we should tell the names that we have like a lot of these Fortune 500 or 100 that deploy very significant number of SD-WANs and rolling out to like thousands or tens of thousands of sites. So it just seems to be something that customers really like to deploy.
Brian Essex
analystRight. And where do you think we are in terms of the adoption cycle, still early stages. You think like the Gartner, IDC estimates of how large the market can be is maybe understating a little bit?
Michael Xie
executiveI think the Gartner start to calling out SD-WAN maybe only like for like 2 years. I think if I -- well, plus or minus 1 year maybe. So the -- I think initially, there are more like pure SD-WAN vendors or startups. But as you probably see, like technology guys have the Magic Quadrant for SD-WAN. I think there's 2 leaders left, the VMware and Silver Peak. We're just right on the border. It's almost, I don't know when they're going to move, but it's to the leaders, but we're quite close. I think we're -- we can almost claim now we're the third leader in SD-WAN vendor. And there's like a whole bunch of call it niche players. I think the way that I think because the -- a lot of these features tends to get more matured. And then these like a really large-scale customers started to have -- at least have a preference on who should that there -- be their vendors, it almost feels like SD-WAN is evolving like a feature on the firewall. To me, I mean, definitely in our favor, but then I mean a technology person, I -- it's just my opinion, seems to be -- it's not complicated enough to be like stand-alone products for a very long time. It just -- I've seen similar things happen in the industry before. It still starts to feel like this could be a good feature on the firewall.
Brian Essex
analystRight. Great. I want to move on to NP7. And I want to really get an understanding of what you see in the marketplace is an opportunity now that you've got the speed and capability of NP7. How you think it might be rolled out into the marketplace? And maybe some use cases, specifically around hyperscale. And if you say hyperscale, people automatically think of like AWS and GCP. But what is your definition? How broad can that hyperscale market be?
Michael Xie
executiveSo the NP7 is the -- our latest ASIC, the security processing unit, right? So compared with the last generation, which is NP6 that came out, I think, about 6 years ago, depending on like various metric, the security inspection, the encryption, the VPN, I think on the average, we see like 3 -- 500%, in some cases, even more processing power to be wrapped into that single chip, and then we typically start to build the 40k, the hardware appliances or chassis based on these chips on each appliance or like chassis could have from one to I think dozens of these chips inside. And then they work together to form that inspection engine. So we haven't -- we announced NP7, but we haven't announced the product, but you can expect we're going to know something pretty soon. We've seen a lot of interest from, for example, the carrier. When they ask about these capabilities, they start to think about what it means for them to have a 5G network. They could potentially see the traffic coming like 5, 10x of what they have today. And there are some unique challenges like we call like elephant's flow. It's just -- all of a sudden, like a huge amount of data out of nowhere. It goes through their back in their work. How they can effectively handle these? On the enterprise level, we see there's users asking about how the -- the firewall is great, right? But if you're building a parameter around the -- around their network, how would they be able to build segmented network, right? So I think analogy I used to make is like a submarine, they're compartmentalized. And then like if you got like somebody torpedo-ed one of the compartments blown away, but then the whole ship still kept afloat. So that's the newer network in design using a similar, I guess, thinking is to build a segmented firewall. So even if you had a breach somewhere, which inevitably is going to happen then it wouldn't affect your whole population, sometimes hundreds of thousands of hosts, but it's limited to that perhaps 2 or maybe like 5 hosts and then allow a faster response to clean them up before they really do any damage. But in order to build that large segmentation, you have to have the capability to inspect, we call it, the east-west traffic flowing through these segments versus the south-north when they try to go to the Internet, right? And for that requires such a scale that's traditional firewall or the CPU, the general purpose CPU wouldn't be able to provide. So I think NP7 opens up a lot of these opportunities. So I don't know if there's something else just on the top of my head.
Keith Jensen
executiveI'm going to stay away from NP7 conversion and let you...
Michael Xie
executiveWell. Okay.
Brian Essex
analystI want to talk -- one quick question, then I open up for the audience for the one after that. But I want to talk about hardware versus software within your company and fabrics becoming a much more substantial part of the platform as well. From an engineering standpoint, how do you manage hardware development versus software? And how are those groups growing and working together as you develop the next iterations of your kind of product road map?
Michael Xie
executiveSo it's -- we're kind of unique in our industry. I think in the cybersecurity, a lot of companies are pure software. And we're just fortunate and that we have a team of hardware expertise and then we were able to leverage that since day 1, giving us a good advantage over the competition. And I think it's the way that we organize our R&D that they became sort of part of that, like innovation engine, right? Because a lot of the time these hardware chips takes anywhere between 5, 7 years to kind of get a new generation, and then we'll be able to get them to sit down with the software team to sort of understand what are the new features likely to make sense in this new generation, what are the capacity provided by the hardware that we weren't able to do it to the software-only previously, but now enables us to put in those stores. So it's just -- there's just 1 team. So it just give us -- it on the one hand, make the problem more complicated. But I think on the other hand, it opens a lot of doors that we're not able to open if we are pure hardware, pure software thinking.
Brian Essex
analystOkay. That's helpful. And with that, I want to see if anyone in the audience might have a question. Okay. We'll keep moving on. I guess one of the things that you commented on in the Analyst Day with regard to NP7 is that you were working with customers on the development of that chip. What's the level of their involvement, then? And how much confidence does that give you in the market for NP7 once you productize it and bring it to market?
Michael Xie
executiveSo we kind of run our road map in a very customer-driven way. And then -- so basically, we spin our ASIC generation-after-generation. So when NP6 came out about, I think, 6 years ago, we started to engage with customers. And then a lot of times, it's from their perspective and sharing with us their challenges. And then sometimes the NP6 wouldn't be able to deliver that. And then so it provides a good reference for us to design the next generation. And then it's not just pure from a performance perspective. A lot of time, it's also from functionality. So for example, when the device is placed into data center, there's always new protocols like VXLAN or something newer that customer would like to use and that older generation wouldn't provide. So when we have the newer generation, then the team can talk about how to like basically work around those tunnel headers and then putting them into the right sessions. So it's just a -- I guess we've been primarily driven by the demands of customer because if they try to put together a solution then they see there's certain pieces not doing what they hope to achieve, we just have more tools in our tool chest, right? Should we spin some more software to help us solve that or should we put in together like a fabric solution or maybe the next generation of ASIC can help solve that problem.
Brian Essex
analystThat's helpful. Maybe, Keith, one for you. Maybe if you could talk a little bit about guidance. I think top line revenue growth was a bit higher than investors initially expected. And I understand at your Analyst Day, you said, over 15% over the next, like, 3 years. But maybe put that in context, do you feel as though you have the appropriate amount of cushion in that guidance? What gives you the confidence to guide to that number? And then maybe just an overall market demand from your perspective in 2020 versus 2019? Is the overall demand environment materially better? Or is the -- and maybe it's both, but is the guidance primarily driven by product cycles, both SD-WAN and NP7 kind of over the next year or 2?
Keith Jensen
executiveYes. I kind of covered a lot there, and I'll start things real quick. So no real incremental change because NP7 and the guidance setting that if something happens on that it would be a nice upside for us as well. When I look at -- when we go through the process of setting guidance for the full year, one of the starting points is really looking at Gartner and what they expect market rate growth to be. Gartner does treat SD-WAN separately from the firewall market, as do we when we look at it internally. So we look at growth expectations for SD-WAN with growth expectations for the firewall market through any part of it and also, growth expectations for the fabric. We look at our history, and that starts to give us a framework, if you will, of what our expectations are. You can then look at that as well in terms of we have historically taken market share. We expect to continue to take market share. We look at our pipeline, we look at what the pipeline is telling us in terms of growth year-over-year. We then look at commitments that we have from our sales team for the full year together with interlocking that with the marketing team. We get a lot of input even down to the country level in terms of their level of comfort for making the numbers. We're looking at sales capacity, and we're looking at sales productivity. I don't want to be in a position where the guidance presumes an increase in sales productivity. If that happens, it will be to the upside. So that gives you kind of a sense of how we look at it. And again, when I look at those -- coming back to the beginning, when I look at those 3 growth drivers on the product side, SD-WAN, the firewall business use case in different models as well as fabric, I think we feel very comfortable with the guidance that we've set for the year.
Brian Essex
analystAnd then your -- basically just to touch on your feeling of the spending environment this year versus last year?
Keith Jensen
executiveYes. I think the -- we kind of go -- we're doing the guidance or building up the budgets for the year. It's kind of at the same point in time we're seeing surveys come out from analysts and so forth about expectations. And I think the expectation was that maybe 2020 was shaping up to be just a tad bit higher on IT budgets than 2019 had been. So that's a bit of a tailwind for us. We certainly look at the securities component of budgets. Security spending has done very, very well in terms of its percentage of IT budgets both in a rising economy. And we think we see some information about if the economy just start to move in the other direction, it seems fairly well insulated from it. And then the last one again would be what I'm hearing back from pipeline and what I'm getting back from customers and conversations with them, together with what I see in the product road map.
Brian Essex
analystGot it. Maybe one last one on enterprise versus service provider mix. Do you see that changing over the next year or so? Where do you see most of the strength in your core business materializing from?
Keith Jensen
executiveYes. We provided some commentary previously that if you look at the 3 SMB, mid-enterprise, enterprise, all 3 outgrew the market in 2019. Yes, there was a bias towards enterprise and mid-enterprise growing faster than SMB, but it wasn't that there was something unusual happening in the SMB. Carrier, I think, by most accounts, carrier was a very good year for people that were selling in the carrier space in 2018. And I think -- and that's with different technology. As you look at 2019, that suffered from the compares a little bit. As we move into 2020, I do think it's a market that's going through a fair amount of disruption. We're very pleased with the MSSP part of that business. But as the carriers are working their way through 5G and some other initiatives, I'm not ascribing a large outpaced growth to the carrier space in 2020 for us.
Brian Essex
analystGot it. With that, I think we're about out of time. So Michael, Keith, thank you very much for joining us. And thank you all as well for attending. Appreciate it.
Michael Xie
executiveThank you.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Fortinet, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Fortinet, Inc. earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.