Fortinet, Inc. (FTNT) Earnings Call Transcript & Summary

June 3, 2021

NASDAQ US Information Technology Software conference_presentation 45 min

Earnings Call Speaker Segments

Mark Moerdler

analyst
#1

Welcome, everyone. My name is Mark Moerdler, and I welcome you to our video-based version of the SDC. I hope you're enjoying all the meetings so far. I'm very pleased to have the senior management team from Fortinet here for a fireside chat. We have Ken Xie, Founder, Chairman and CEO of Fortinet; and Keith Jensen, CFO. You already have the ability to be able to ask questions and to vote on questions. So I would ask you to please add your questions online. I will be watching those and mixing them in with the questions I already have in hand. So I'm looking forward to the conversation. Let me first hand it off to Keith for some opening remarks.

Keith Jensen

executive
#2

Thank you, Mark. Specifically, our safe harbor statement, which reads, I'd like to remind everyone that we may make forward-looking statements during today's fireside chat. These forward-looking statements are subject to risks and uncertainties that could cause actual results to differ materially from those projected in these statements. Please refer to our SEC filings, in particular the risk factors in our most recent Form 10-K and Form 10-Q, and to other reports that we may file from time to time with the SEC for additional information on factors that may cause actual results to differ materially from our current expectations. All forward-looking statements reflect our opinions only as of the date of this presentation, and we undertake no obligation and specifically disclaim any obligation to update forward-looking statements. Thank you, Mark. Back to you.

Mark Moerdler

analyst
#3

Thank you so much. Maybe I'll start with a high-level question. The pandemic and work-from-home has had a big impact on the overall economy in many industries, and there's been a lot of talk about the impact on the cybersecurity market. Do you have any thoughts on how that impact is within the market in general and your own company? And how do you think that's going to affect going forward the demand and need for cybersecurity?

Ken Xie

executive
#4

We definitely see kind of a little bit different pattern during the pandemic. Like 1 year ago, a lot of companies, they are rushed to supporting work from home. So just whatever the way they can get people connected, they're all fine. And -- but now after over a year during the pandemic and even some countries, some regions starting to reopen now, we're also starting to see some companies starting to rebuild the infrastructure supporting this work-from-home more permanently, which making like some of the remote connection more reliable, more secure, leverage some new technology, whether SD-WAN or 5G and, same time, changing the infrastructure to supporting, we call, Zero Trust Network Access, and at the same time, also working with some carrier service provider because most of, like connectivity service also provide the carrier, they also want to kind of support in certain securities, some others including SASE. So we do see pretty healthy demand right now. And also if you're going forward in the next 1 to 2 years, a lot of companies were rebuilding a new infrastructure to supporting whether work-from-home or some secure whole infrastructure we call the fabric, make sure not just the traditional security, just secure the working environment in the campus, in the company, but also remotely the mobile device. And it's kind of the new infrastructure, make sure cover all the tech age starting kind of a -- draw out more quickly with all this kind of pandemic. Basically, I think pandemic also accelerated some of these, we call the, whole infrastructure security concept, not just protect the company, but also go to the WAN like secured SD-WAN, also go internal like a security Wi-Fi, security internal segmentation, protect the server, protect the department, protect the data from ransomware. So it's kind of -- the whole infrastructure security become more and more important.

Mark Moerdler

analyst
#5

Makes complete sense. Creates some interesting opportunities. Maybe I'll go into products a bit and then look at some of the questions online. Starting with -- Fortinet is known for having proprietary security processing units. What is special about the technology? What's the edge that it gives you versus your competitors?

Ken Xie

executive
#6

I've been doing the network security for 30 years. Fortinet started 21 years ago. It's the third company starting in this space. So I see the security needs much more computing power to process the same data, same traffic compared to routing and switching. You only need about 30x, even 100x more computing power to process the same traffic. But also network security need to be in the middle of the network traffic to stop the bad content, bad traffic there. So they cannot slow down the whole things, but also need huge computing power. So using a general-purpose CPU is not enough. So that's where the ASIC can give huge computing advantage and a huge computing power to process a lot of security function, which is too slow to be processed using a general-purpose CPU. So on average, if you move some software function from general-purpose CPU to the designed ASIC, just like how the GPU processes, the graphic processes AI, the TPU the same thing. If they can improve performance for the same function 10 to 100x and also lower the cost and also add additional performance, so that's the reason from day 1 we started the company, we wanted to design ASIC 21 years ago. But also design ASIC take a long time to see the result and also big investment, need to have a big commitment also. So that's where we have to be -- commit early, have to have a huge investment and also need to have some economy of scale. Like you need to have the quantity to make ASIC working. Otherwise, per chip costs will be too high and will not make it working. I think after all these 21 years of investment, we're starting to see the huge benefit of leveraged ASIC, which every new product release, we also gave, we call it, secure computing rating. So on average, we have 5 to 10x better performance compared to all the competitors on the same function for the same cost. So that's because the ASIC benefit have a huge performance advantage because huge computing power being kind of added on the system because of the ASIC. So that's also kind of not just applied for the network security, but also some other function like SD-WAN, the 5G and some other internal segmentation or the other things. We see it's a long-term investment, gave us huge advantage over competitor if they only want software on the general-purpose CPU. We also use the same general-purpose CPU as any other competitors. But the additional ASIC have a huge computing power advantage and give additional function, additional performance, also lower cost. So that's the reason kind of we feel -- and also going forward, we see ASIC also can expand into the other tech service like from smart city, from OT/IoT space and connect the car. And just like Gartner, they said, going forward in the next few years, the edge computing, edge immersive technology was starting to replacing, we call, the mobile, which leveraged a lot of ASIC computing power in edge and can process a lot of data quickly in real time locally. So that we see as -- going forward, we still have a huge advantage with ASIC. May Keith...

Mark Moerdler

analyst
#7

Yes, go on. Sorry.

Ken Xie

executive
#8

Yes. Keith may add some more.

Keith Jensen

executive
#9

I think the 2 ways that I look at it very simply to kind of package up what Ken said is, one, it's created a moat, right? You always want a moat when you're running a company or an investment in a market. And that barrier to entry is the ASIC Advantage that he has worked on for 21 years. And secondly, he mentioned the economies of scale. And to add a data point to that, we've shipped probably over close to 7 million units in our history. And so that chip cost, if you will, Ken talks about the economies of scale, you can see how it's getting amortized over a very, very large set of units.

Mark Moerdler

analyst
#10

Makes sense. Does the fact that you're using effectively a custom chip, an ASIC, but still a customized chip create an additional level of security since using something that they wouldn't run into an attacker if they were attacking more generic hardware?

Ken Xie

executive
#11

Because they add huge computing power, we can process more function, faster speed. At the same time, they can free up the CPU to add additional new function. So that's where on average, our firewall gateway, FortiGate can have much more function and a much higher process speed, can also enable like more function to connect with other part of infrastructure. Like certain part of infrastructure, they need very low-latency, high-processing speed, which ASIC fit in quite well. But also ASIC, whatever you want, a function of ASIC you need around in the software first. And then once this is stabilized, then you move to the ASIC, which takes some time. But on the other side, they free up the general-purpose CPU. The ASIC also is programmable, right? So you can also, just like any other DSPs, some other processor, that's we call security processing unit, more like a GPU and the TPU is very programmable to adopt any new attack. At the same time, we're still using a general-purpose CPU to process some other function needed.

Mark Moerdler

analyst
#12

Makes sense. On your flagship FortiGate appliance, how do you see the future evolving? Particularly, we're hearing a lot, and we cover companies such as VMware and others in the space, we're hearing a lot of increased preference for software-defined networking and generic hardware. How should we think about -- how does that affect your future? Or does it not affect? Is it not competitive? Thoughts.

Ken Xie

executive
#13

Some of -- they call the, SDN or SD-WAN, we do have that function around an ASIC. Because once you have certain function can be processed in a hardware level is in a much higher speed compared to the general-purpose CPU. And yes, I do believe some of the SD-WAN compound with security has a great future and ASIC is the one to close the gap between how fast the network can go and how the security gateway can be processed. Because right now, if you look at other security gateway, so on average, they are probably 100x slower than the routing and switching there because you have to process the data in like much more computing power to processing data; and on the other side, also much more expensive. It's probably like 50 to 100x more expensive to processing data compared to routing, switching. It's all because of the computing power required to process all secure data. So with ASIC, we can close that gap, lower the cost, add speed and can deploy more broadly into some new environment, in the past probably were costly or pretty much too slow, impossible to be deployed. That's how the ASIC has the advantage compared to only using general-purpose CPU software only. But on the other side, ASIC is also kind of a CPU. You can also quickly change in adopters like CPU can change it. So it's design architecturally process some security content, security encryption and intrusion and also the networking function like SDN and SD-WAN.

Mark Moerdler

analyst
#14

Makes sense. So interesting, you're also offering FortiGate, et cetera, for a virtual environment. What's the primary target market? And how should we think about your ability to -- the ability to deliver that level of performance and capability when you're using in a virtual world versus in ASIC world?

Ken Xie

executive
#15

I think the -- if you look, they do have certain security function application move to the cloud into the virtual environment. And ASIC can also lower that cost a lot. Because once the secure computing requirement in the cloud in virtual environments starting to get bigger and bigger, you also need to consider how to lower that computing cost, cost by the security function there, which ASIC can easily apply into that environment and easily lower the cost by 10 to 100x applied ASIC in that virtual environment, which we already see some of the service provider, cloud providers starting to kind of leverage that advantage now.

Mark Moerdler

analyst
#16

Interesting. I'm going to change gears for a second. We have some questions up. Hopefully, people will add additional ones. Maybe I'll throw one at you, Keith. Change of gears and we'll come back onto the hardware -- the technology levels in a moment. We see that current levels of growth, you're targeting mid-20s operating margins. Can you give us a sense of longer-term margin trajectory?

Keith Jensen

executive
#17

Yes. I think that we've been very transparent in terms of establishing a framework that we want to operate within. If you look back at our Analyst Day in March, we talked about, in 2023, we wanted to be at $5 billion for our midterm growth [Technical Difficulty] of billings, $4 billion in revenue. And then we thought we'd average 25% on the operating margin line. I think the -- within that framework, certain years may bias a little bit more towards growth and other years may bias a little bit more towards operating margin. And again, I think we've been pretty clear that in 2021, just as we started at the beginning of 2020, but -- and then we changed things on us a bit. But in 2021, we feel the bias is towards growth. And when we look at our first quarter numbers, we felt that the tailwinds that we had in terms of the level of hacking activity that was going on, the public discussion, budget changes, if you will, technology innovations, even GDP numbers that we thought it was going to be a year for growth felt very good coming into the quarter. And I think we came out at 27% billings growth, a 25% product revenue growth. And so those things that we felt we saw at the beginning of the year that this would be a year that would tilt towards growth, but still within that framework that we established of averaging 25% operating margin. But perhaps a little higher growth this year as we go through it.

Mark Moerdler

analyst
#18

Excellent. Follow-up question. The pandemic for a lot of companies in the tech space have work-from-home or a lack of T&E has a positive effect on margins, but it's also changed the way people work. How does -- how do you think it changed long-term Fortinet's way of doing business in terms of the mix of work from home and work in the office as well as the T&E expense line?

Keith Jensen

executive
#19

Yes. I'll take the T&E expense line and then kind of set it up for Ken to talk about how we seize the employee group going forward. The number that we gave was about 150 basis points of benefit in 2020 in the operating margin line because obviously you didn't have travel and you did not have marketing events. We expect that both of those activities would come back online in 2021, and we are indeed seeing that. When we talk to salespeople and we talk to marketing events people, et cetera, and customers and partners, there seems to be a very high level of getting out and about, again, getting on airplanes and going and seeing people. So I'm pretty convinced that, that benefit that we got last year is probably going to be a 1-year event for us. On the flip side, we had operating margins. I think FX this year could be a little bit more of a headwind for us, about the same number, if you will. Work-from-home, study-from-home, et cetera, those types of things, we're a very diverse company with offices and people in over 80 different countries. It's very geographically specific in terms of what people are doing and where different countries are in terms of health regulations and the pandemic, et cetera. But if Ken wants to speak more philosophically about what you'd like to see for the employee group, I'll let him do that.

Ken Xie

executive
#20

It's -- I think for Fortinet, because a lot of like service or supporting we do is treated as an essential work even during the pandemic, so that's why we do have quite some people keeping -- working in office, in the lab during the pandemic. And also even like last night, I attended an event. They also estimate in the U.S. about 140 million worker during this time -- during the pandemic, I think it's close to 100 million people still working. And since -- the pandemic changing the way some people working, and I found that maybe some job can be done remotely, but they definitely have some other things that have to be working globally together, whether in the office and the lab environment also has to be on site, right? So that's what we see. They also need to protect the infrastructure, also supporting both how to remote access, how this kind of important data and at the same time -- and how to support another mobile device and the different kind of work environment there. So that's where we do see during the pandemic, the IT spending for security parts have gotten higher percentage compared to before. So we do see some healthy demand in the security -- service security environment, especially the network security, which is supporting how to secure remote access and protect all this kind of ransomware, all these other things. That's also the reason we feel like this is the time to invest in growth. And also we're starting like -- last year, we do see some pretty healthy growth recently.

Mark Moerdler

analyst
#21

Makes sense. Turning to the cloud. Help us understand what role does third-party security products play in a cloud environment? Isn't security provided guaranteed by the cloud vendor sufficient? How do you think about that?

Ken Xie

executive
#22

I think cloud is a part of infrastructure. And so if you look by market data, so by the next 3, 4 years, the network security still has about $40 billion a year total addressable market. And the cloud probably from, right now maybe a few billion dollars go after the $10 billion. And at the same time, there's endpoint, there's all this kind of different, different part of security infrastructure market there. So I do see cloud as an important part of the infrastructure, but not the only infrastructure needed to support in business environment. So even to access the cloud, you still need all these SD-WAN, you still need all this kind of networking 5G to access the cloud, the data there. So that's where we see as a hybrid environment going forward. Cloud is important, but also just one part of the whole infrastructure need to be secured.

Mark Moerdler

analyst
#23

So you're a big believer that we are in a hybrid world for a long period of time. And if so, I guess, has Fortinet been more relevant, equally relevant?

Ken Xie

executive
#24

I think we're positioned to be meeting all this whole infrastructure security kind of environment. If you look at some study from Gartner, they even say the edge and the immersive will be replacing the cloud mobile in a few years. They're probably even more kind of aggressive view that the world is changing, stay away from cloud. But we do believe cloud will always a part of infrastructure and same thing for like mobile and even the edge computing, the immersive technology is coming up very quickly, which we're also supporting that. But on the other side, a lot of our legacy traditional product infrastructure still function -- is existing quite well.

Mark Moerdler

analyst
#25

Makes sense.

Keith Jensen

executive
#26

And probably -- Mark, I'd probably add to that. I think there's a conversation to be had in here around the platform strategy. And why that's relevant is in the hybrid world particularly, when you talk to CIOs and you talk to CISOs, one of the items is top of mind right now is just vendor proliferation. They simply have so many different point solutions that they're being forced to manage, and they're talking to us about it takes an army of people to manage these. And when you open up a new attack surface where you bring on a new technology vendor, that simply makes that challenge then even more challenging. And so in a hybrid world, what we'd like to describe it as is security anywhere in any form factor. And yes, we certainly have the appliances and the ASIC strategy, if you will, for the on-premise solutions. And to your earlier question, we also have the virtual solutions, which can be in the form of pay-as-you-go to the cloud provider or bring your own license, et cetera. And what we're trying to satisfy there for the CIO and the CISO is some sort of -- some form of vendor consolidation. I'm not talking about buying a bunch of companies in the industry, but giving them a single management platform for that hopefully at least a subset of their security providers. And so when Ken talks about the hybrid world and why we're very comfortable and confident we're going to be relevant is because of that demand that we're seeing for vendor consolidation, some easing of the pain that they have on labor resources and managing point solutions.

Ken Xie

executive
#27

Yes. The other point may impact the cloud also, there's certain other regulation like GDPR in Europe. And also in California, there's a certain regulation. We have to make the data vis-à-vis in a company within a state to protect the privacy, certain consumer right, all these kind of things. That may also impact how to balance them among cloud, among the edge, among the immersive, among the mobile device. So it's -- I do agree, it's a hybrid world going forward. I don't see that kind of changing because each infrastructure have their kind of own advantage, disadvantage in a certain way to provision.

Mark Moerdler

analyst
#28

That makes sense. Sorry, my system dropped for a second. That makes perfect sense. I remember when I was -- I've been going to the RSA conference for many years. And so much of the pushback from the CISOs has been the fact that there are Noah's Ark of different technologies and the interest in being able to consolidate. And I guess the argument you would make is the hybrid cloud makes that Ark even bigger.

Ken Xie

executive
#29

Yes. We want to give the customer, the CISO the freedom to select whatever the infrastructure fits them the best instead of we try to force them one way or another. So we're basically supporting position to help them to make the whole infrastructure very secure.

Mark Moerdler

analyst
#30

Makes sense. How do you see the dynamics with the cloud vendors? Amazon, Microsoft, GCP, especially Microsoft, we're seeing them pushing aggressively into the security space. Does that create concern for you? Do you see them as competitors or coopetition? Where do they play? And how do you think about it?

Ken Xie

executive
#31

I think we are more partnered with Microsoft, and they do have their position like in certain office tool, in certain like operating systems side. But on the other side, they also need other part infrastructure to work with them from the networking side, from some other like e-mail, web and other part. And at the same time, Microsoft itself becomes some kind of target, need to be protected also. So that's where we do view as the partner. At the same time, we're more confident on the networking side. And even to use in the Microsoft and or even using Amazon and Azure, you also need to have like remote access, whether from home use SD-WAN or some other way to access that infrastructure cloud data there. So that's where we see it could be a good partner to keep it working together. Probably Keith also -- Keith is working a lot with this kind of ownership deals. So any...

Keith Jensen

executive
#32

Yes. I think the common theme here is I think that we realize that regardless of the vendor of the company, the better security that's out there, the better for the world. And to enable that, it really requires an openness about integration and sharing about threat information and regardless of the form and what have you. And so to the extent that there's more integration and more data sharing amongst the different players inside the industry, I think the world is going to benefit and I think the corporations inside the industry are going to benefit. There is a role for applications that are in the cloud and for what's described sometimes a lighter security touch that the cloud providers can currently provide. But I think when you get in larger organizations, it really varies by use case in terms of how much security and where and what type of security they want to apply to it. And again, there's just simply so many security technologies out there, I would not necessarily isolate singly on any one cloud provider on what they can and can't do it at this stage.

Mark Moerdler

analyst
#33

Makes sense. Okay. Changing gears a little bit, 5G. Network infrastructure software providers see a lot of opportunity in 5G. What is 5G? You mentioned this before, Ken. Can you drill in and tell me what does 5G mean for your products? How does it affect the products and the market opportunity? What does it create for you in terms of opportunities?

Ken Xie

executive
#34

I think probably 5G is the first time they connect more device and connect people. That's where we see in a lot of vertical, whether in the health care, the manufacturer, the smart cities, some others like connected car also leverage all this 5G. And that's also kind of more related to the OT/IoT space. So we do see a lot of opportunity. So when you connect all this device, you definitely need to have some protection because whether the data or some part of infrastructure that support get very critical, very important once they connect online there. So that's where we see it's a huge opportunity. And also, we do believe we call secure-driven networking. So when you design a networking infrastructure, you better consider security at the same time, whether one connection like 5G or SD-WAN. But even within the data center within the cloud, you also need to make sure you're designing security within that infrastructure to protect from the very beginning. So that's why we see 5G is a huge opportunity. And especially a lot of service provider carrier waiting for that for quite a while. So we do see it since starting to ramp up. So we believe like later this year, next year is a huge growing opportunity in the 5G environment.

Mark Moerdler

analyst
#35

Following up on that, I guess, you've talked about the partnerships with AT&T and BT and the other telecom providers. How exactly does that partnership work? And what are you delivering versus what are they delivering? And how would you talk about the size or the depth of that opportunity?

Ken Xie

executive
#36

Yes. We have been a long-term partner with most of the carrier worldwide, including AT&T, BT, you mentioned. And we do believe the carrier service provider has the best position to supporting whole infrastructure security because they're also doing the Internet connection, some [kind of stories,] some other part of connection supporting for the consumer or for the enterprise. And that also -- security need more and more kind of a new knowledge, expertise to supporting that. A lot of time, some customer need to depend on carrier service provider to offer additional support, additional service there. So that's where we do see the service provider get more and more important. And on the other side, there's a certain new technology like SD-WAN -- secured SD-WAN, also the 5G we just mentioned, and also some SASE and certain Zero Trust Network Access, which also service provider can play a very, very important role. Even during the pandemic, we do see a lot of companies starting to see how it can working with a service provider to supporting this work-from-home, not only just Internet access, but also in the more secured and reliable environment, more like the traditional branch office, so the home become a new branch kind of environment to supporting this work-from-home permanently and also very reliably, securely. So that's also need working with the carrier service provider to do all this together. So that's why we see the partnership with all these carriers as a huge opportunity. And the carrier service provider is the #1 vertical market. Like a few years ago, it's a high 20, like 27%, 28% of business come from carrier service provider. But I have to say, in the last 2, 3 years, they're kind of a little bit behind on the investment, whether they're waiting for the 5G or SD-WAN changing, transition or some other things like this cloud provider, how to position that. But now I'm starting to see they're starting ramp up, starting to take out quickly to supporting all these enterprise security, all these service provider and secure SD-WAN, the 5G, the SASE, the Zero Trust Network Access to remote working from home. So the carrier service provider starting very actively to quickly ramp up their engagement, their involvement in the cybersecurity space.

Mark Moerdler

analyst
#37

Interesting. Questions from the audience. In the future, do you see the public cloud providers becoming -- I guess this is a follow-up to our discussion on the cloud. Do you see the public cloud providers becoming larger customers and not to think about them as competitors, but to think of them as big customers for you?

Ken Xie

executive
#38

We do partner with some cloud provider, especially help them to reduce certain security and computing power cost, leverage whether the ASIC or some other advantage we have and also share certain intelligent information. On the other side, some cloud provider also offer certain security function with certain application themselves, which we also are working with them. I think they have some of their own advantage, but also they also have their own kind of limitation. So that's the way we try to find a way to partner together and to making the whole infrastructure more secure. Probably Keith also maybe have some other...

Keith Jensen

executive
#39

Yes. I think the -- we shouldn't lose sight of the fact that the NP7 chip which is a real beast of a chip, and I mean that in a very positive way in terms of its capacity, what it can do, very much targeted at the hyperscalers, right? And when you put that into a large, more complex appliance, it's going to go through a normal certification and testing cycle. And we -- before that, we need to roll it out into our products. And we're still largely through the high-end devices with the NP7 chip. So I think that's just got to go through its normal cycle in terms of perhaps creating some opportunity for us in hyperscalers, not just cloud providers, but some of the large content companies as well.

Mark Moerdler

analyst
#40

Makes sense. Following up on that, the chip shortage has been in the news for the last couple of months. Is this a concern for you? Does it create supply chain delivery issues? And how does that relate to your high-end ASIC chips?

Ken Xie

executive
#41

Because we design and manufacture our own chip and the same time, have our own operation and inventory, so we have a better position compared to most of the competitors. Like Keith always mentions that our inventory turn is basically 2. That mean on average, we can keep about 6 months of inventory. And that's kind of probably much longer, bigger inventory compared to some of our competitors, but on the other side, give us a very stable like a safe net if there's an urgent need or there's a certain shortage, we probably can have a better position compared to some other players in the space. I think we -- yes, we do plan some of this ahead of time, like, starting last year, we also started to increase on the inventory. So we continue to keep improving our position there. But at the same time, we also closely monitor whether that service -- I mean, the semiconductor industry or certain customer demand or the whole cybersecurity since -- because so far, we have been -- we're doing quite well so far. I don't think it's much, much issue for us right now. But we do kind of want to closely monitor any change in the space.

Mark Moerdler

analyst
#42

Makes sense. Changing gears, service revenue. You've seen quite consistent growth in your service offering over the years, but -- despite some volatility in product revenue. Can you help us understand what's driving the strength in the services revenue?

Ken Xie

executive
#43

I think we have a pretty good growth on the product revenue in the last few years, probably the only vendor in the security space has continued double-digit product revenue growth. On the service revenue also, we're very healthy. But also on the other part, we do have some service, which competitors charge a lot of money, we kind of leave it free or kind of bundle as a free offering there, which we do believe can potentially add additional value or additional business for us. But at this stage, I do feel because the ASIC Advantage we have, we have more computing power, more function, which also enabled more service. So making a service kind of a potential huge growth opportunity, that's where the product revenue, I think we are pretty close to be the #1 in the whole space. And that's enabled a lot of future service going forward, which we can also helping customers, supporting customers.

Mark Moerdler

analyst
#44

Is there services more professional services? Or is it just security subscription or technical support? How should we think about that?

Ken Xie

executive
#45

So we have 2 kind of service. The supporting service we call the FortiCare. We already transitioned from a traditional 8x5 now mostly go to the 24/7. And then also, we have a new service starting few years ago, we called it FortiCare 360, also help the customer to monitor, to regularly checking the healthy status of the deployment of this kind of -- and proactively help them to fix issue there. So that also service is starting to ramp up very, very quickly. So that's the supporting part. On the other part, we do have subscription service we call the FortiGuard, which is including like 5, 6 different kind of service from like intrusion prevention, antivirus intrusion, spam and web content URL and like all the other things we have. Not kind of -- that part of service is also doing quite well, but we also offer a lot of free service within that one because especially with the FortiOS 7.0 release, we do add quite a lot of new function, which also come up with a lot of additional service like including from the Zero Trust Network Access and some others like support SD-WAN, 5G and CASB and all the SASE. Right now, we kind of bundle a lot of the service kind of within OS for free. But going forward, there's -- definitely we'll keep enhancing the service and also provide additional service to the customer, both on the subscription and also on the supporting side. Also, I think the service right now is probably 2/3 of the company business right now. 1/3 comes from the product. 2/3 come from service. And FortiGuard probably a little bit bigger than the FortiCare, right? Keith probably know the detail.

Keith Jensen

executive
#46

Yes. The split is very consistent. You're very good at the numbers today, Ken, very impressed. It's about a 55-45 split. So I think we're very -- and just for people who are new to the name, just to make sure you understand that, when we install a firewall, whether it's virtual or whether it's physical, we prefer to attach both those service contracts, 1 for support and 1 for security updates that Ken has talked about. The security updates are a bundle of services, and we think that gives us -- our customers an economic advantage to use those services. And I think the -- and we're very excited about 88% gross margin. I should -- as a CFO, I want to get that back into the conversation naturally. But I would also use this to link back to the beginning of the conversation, Mark, you and Ken were having about the ASIC Advantage and not lose sight of the fact that when you talk about the ASIC Advantage, speeds and feeds and so forth, but it also -- it creates that capacity so that you can add the operating system as Ken says, OS 7 and add more features and functions and embed that into the operating system. SD-WAN is a very recent example -- well not as recent example, I guess, as it once was, of exactly that. SD-WAN is embedded in the operating system of the firewall. Prior to that, it was SSL encryption and decryption. The ASIC Advantage allows Ken and the team to embed those features and functions without a degradation in performance. The degradation in performance is catastrophic in our industry.

Mark Moerdler

analyst
#47

Makes a lot of sense. A question from the audience here. You mentioned free services. What other incentives are you using to gain share? And as a follow-up, how have sales dynamics changed post-COVID?

Ken Xie

executive
#48

I think we feel we are running a healthy business with a graceful margin and, at the same time, give the customer as much better as possible is also pretty important. And for us, we definitely see there's certain service right now we offer for free, which is also customers do benefit from that. But also going forward, we are keeping evaluate with reasonable -- we have a reasonable margin, we'll be happy to offer additional service or something free to supporting customers. And also because the whole security, there's a lot of thing come up every year and a lot of new things need to be supported. On the other side, if we do see certain margin pressure as some of the service we may start in kind of add a little bit fee to supporting our cost. So that also we'll be kind of discussing with the partner, with customers, to try to see what's the best way to continue to give them the best support in. So that's where we do see -- like Keith mentioned, we do have a lot of function into whether the FortiGate or some other fabric product there, there's 20, 30 different product in the fabric for e-mail, web, endpoint, all these other things. And the service is a pretty healthy business for us. That's also for us, we kind of -- I think right now, the growth is probably keeping -- gaining some market share is a little bit more important. So we do see this actually as a growth opportunity. So that's why we probably want to leverage this one to keeping grow faster right now. But it's -- but also we want to create certain balance among the growth and the profitability because the company has been at profit 11, 12 years ago since IPO. So we always want to balance among the growth and the profitability. We want to keep it close, instead of just too much tilt to the one side. And so far, I think this strategy is working quite well.

Keith Jensen

executive
#49

Ken has being far too humble, Mark. The reality is, if you read Gartner and you read NSS Labs, he simply built a product that is better than just about anybody else's and the price for performance advantage is clear to everybody. And so with that in mind, I'll bring it back to the market share. Now it's a matter of bringing on sales capacity. And we feel very comfortable that third parties have made clear references to the superiority of the product. And now it's a matter of -- within that framework that we talked about earlier, a 25% operating margin is continuing to add the sales capacity. And that's what's driving the market share gain, I think. So it's really the product and then the go-to-market approach.

Mark Moerdler

analyst
#50

Makes sense. Another question from the audience. How are you currently thinking about M&A?

Ken Xie

executive
#51

I think we do see the cybersecurity space has a lot of new things come up. And many a times, the new company, small company, they are much quicker, ahead of other competitor to come up with a new solution. We're also -- very important to achieve the internal innovation. But also very important for us, for any acquisition, we also think about how to integrate, how to make the whole solution better for the customer instead of just to create some separate product and then leverage sales and marketing force to run for a few years and then give up or kind of make it -- keep it separate going forward. So that's why whenever we do merger and acquisition, we always think about how to integrate this become part of the whole platform, the whole fabric infrastructure, supporting the whole solution there. That's also the reason, so far we're keeping more acquired in the early stage of the company, which they have a pretty good engineer resource, R&D, and at the same time, is making integration more and more easier.

Mark Moerdler

analyst
#52

Makes sense. Time is running out, so I'm going to ask one last one. If -- you have 2 minutes left, what are the things that you believe the Street should -- could better understand about the company and the opportunity?

Ken Xie

executive
#53

We do have some -- quite some long-term investment strategy come from like early days submission of our ASIC, which needs about 5- to 10-year investment to see the benefit. And also when we develop our own kind of fabric product, whether the e-mail, web, endpoint, the SIM and all the other NAC, all these things, which also need a long-time investment to see the result. But once they have it be ready, integrate better, it's working together with other part of fabric better and have a more long-term benefit. So that's where we see is a company. Definitely, we want to set a lot of a long-term strategy to keep in pace, to balance among the growth and profitability and at the same time to see how to position better within the 5- to 10-year time frame and even longer going forward. Keith probably had some other finance...

Keith Jensen

executive
#54

Great growth, great margins. What more could you ask for? Like I think the diversification of the business, right, I think that it's so geographically diversified and is diversified across customer sizes that a lot of the conversations that we have today about cloud and digital transformation are probably extremely relevant to very large enterprises and very large economies. For us, that is a segment of our business, but it's not all of our business, right? And we have solutions in different form factors that are available for companies of all sizes, if you will, in all geographies.

Mark Moerdler

analyst
#55

Perfect. Excellent. Ken, Keith, I'd love to keep talking, but they're going to kick us off anyway in a moment. So I really do appreciate. Thank you for your time and your effort in making all of this happen. And if anyone else has any questions, you can reach out to the IR team at Fortinet or to the team at Bernstein. Thank you very much, and have a great day.

Ken Xie

executive
#56

Thank you, Mark.

Keith Jensen

executive
#57

Thank you, Mark.

Mark Moerdler

analyst
#58

My pleasure.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Fortinet, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Fortinet, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.