Fortinet, Inc. (FTNT) Earnings Call Transcript & Summary
August 10, 2021
Earnings Call Speaker Segments
Ittai Kidron
analystAll right. Hello, everyone, and thanks for joining us on the 2nd day of Oppenheimer's 24th Annual Technology Conference. My name is Ittai Kidron and I'm a technology analyst at the firm. And I've got the pleasure of hosting Fortinet here with us and more specifically Keith, the CFO; John, who's got lots of hats. John, boy, you're a busy guy. EVP of Products, Chief Marketing Officer and probably a bunch of other things that are not listed here because we're out of space. And -- but before we get started, of course, Keith has to do a little tango. So Keith, I'll kick it to you and we'll get started. And we'll start with a fireside chat, and then open it up also for the audience for questions. Keith?
Keith Jensen
executiveHappy to. I just want to make reference to our safe harbor slide and language that appears here. I will not take the precious time up and read through it, but I do suggest that you take a chance to check through that. Thank you very much. Bye.
Ittai Kidron
analystVery good. Short and painless. So let's get into business, guys. Quite an impressive quarter this last quarter: product revenue, 41%; services, 24%; billings, 35%. These are very high numbers and point to an acceleration in your business. So help me understand what's behind this. I mean it can't be the traditional firewall place is growing that much. So what's driving the growth for you?
Keith Jensen
executiveYes. I just -- we'll get into more detail as it essentially goes on, I'm sure. Obviously, we're really pleased with the results of the execution by the team in the quarter. I think from a high level, I would say that both the benefit from the cost performance advantage certainly resonated with our customers throughout the quarter. We saw that both in the FortiGate, the firewalls, where our cost of performance, I think, is fairly well known, whether you measure on throughput or features or functions. And we also saw it in what we call the non-FortiGate of the platform, that broad set of products that we have. And there, I think it's not as -- in addition to the unit cost, it's also the management cost. When you offer a broad suite of products that are integrated, you're really enabling customers to take cost out of the organization. We saw that segment of business put up 40% growth for back-to-back quarters. And I think that's affirmation of our strategy. I would also say that I think the backdrop of the heightened awareness of security events throughout 2021 has brought probably a lot of new companies and customers that we want to the table that may have renewed or a heightened sense of concern about their own security architecture. And some of the things that we bring and offer in terms of cost performance and the broad suite of products, I think, played very, very well. It was a good quarter for us. We're happy.
Ittai Kidron
analystVery good. Let's break it down a little bit more, perhaps, focusing on the FortiGate business more specifically. Clearly, you're outgrowing competition. But is there a point -- a way to a point of focus the finger, Keith, on how much of this is cost versus performance that's resonating with customers?
Keith Jensen
executiveYes. It's a great question. I think the combination of the ASIC, which enables the operating system or the OS 7. The history of the ASIC, together with the operating system, is one in which we just continue to add features and functions to it. SD-WAN is probably a very clear example of that. We try and encourage our salespeople not to lead with price because we've already won the price argument. Not the easiest thing sometimes with sales people to break that out, if you will. So where value comes into play versus performance, I'd like to argue it's all performance, but I suspect that there's some pricing actions in there as well. Look, I think we also benefit from having a very broad customer footprint when you look at the size of our customers, the geographic diversity, the industry that they're in. And so when you have this wide range of use cases and functionalities in the operating system, as we see customers now pushing more to the edge and having more conversations about micro segmentation, us having the ability to push back into the data center, I think it really wraps up very nicely in turn...
John Maddison
executiveDid we lose Keith?
Ittai Kidron
analystKeith is frozen. John, do you want to pick up perhaps on the features? As I think about the FortiGate platform, when I think about what features are resonating more and interesting more to customer or higher priority, I would like to call it, for customers more here and now versus what was the case perhaps a year ago, is there a big change?
John Maddison
executiveThere's a subtle change. And as you go back -- if you go back 15 years of firewall's a firewall, well, there's probably 10 different applications now that can sit on there. 3, 4 years ago, we integrated SD-WAN in there, which has proven to be a very good decision. About 2 years ago, we decided the Zero Trust architecture needed that network proxy as well. Not only you can do it in the cloud, but you can do it in the data center. You can do it on-premise. So you just continue -- a lot of times people go, "Well, you build these specialized ASICs so that you can run faster and faster and faster." Yes, we can. We announced a couple of quarters ago 1 terabit per second next-gen firewall. That's fine. There's only a certain number of customers who can take that.
Ittai Kidron
analystRight.
John Maddison
executiveWhat's more important is if I'm a customer, I can run my SSL inspection. I can run my -- I now got a Zero Trust capability in there. I can switch on SD-WAN. The more things you switch on, regardless who you are, it takes more compute. And the specialized ASICs inside there offload. Just like a GPU does on a gaming system, it offloads the CPU so you can run more applications on there and get more value. So it's not just performance, it's adding applications on there so that they can get more value and they can start to consolidate. There was an interesting Gartner survey done late last year, stating that about 25% of enterprises and businesses now are thinking about consolidating. That's going to rise to 75% over the next 2 years. So performance is good. But the ability to run, consolidate multiple appliances and services on to the same system is just as important to customers.
Ittai Kidron
analystGot it. Got it. Interesting. Keith, we're glad to have you back. That was probably Cisco router that kind of failed there. But let's talk about SD-WAN, John. John did a very good job of picking up the baton, Keith. Let's talk about SD-WAN here. Clearly, an area you're kind of shifting and focusing on and you seem to have a very good, strong early success with. Can you give me a sense of how much of your business today in FortiGate is driven by SD-WAN? And how frequent is the discussion with customers in this? I know SASE is something that people talk about long term. But how much of a focus is it really here and now for people that, "I got to make this move here now"? Or this is a multiyear planning process execution?
Keith Jensen
executiveI'll jump in with some quick numbers. And then maybe John can give you some good insights into the customer buying cadence. It's up to 14% of our total billings now. It pretty much came from a standing start in 2018, '19, when we entered the market, too. So to be at that level is very good. The pipeline is very strong. And our goal is, of course, to be the #1 SD-WAN provider. John, do you want to talk a little bit more and give a little more context of who's buying it, how they're buying it?
John Maddison
executiveYes. I think one of the themes that I'm seeing is some people are forgetting that the digital experience requires a really highly secure, fast network. We're not moving everything to the cloud and you're not just sitting at home. There's something in-between core network, which is extremely important to give you that digital experience. And so we saw SD-WAN as being the foundation. I hear SASE a lot and I'll ask customers. Every single one has a different vision of what it is, what it means and when it's going to come. Definitely, I see more people say it's more of a framework versus a product. I think the majority, depending on the definition of SASE, majority of the revenue today is either SD-WAN or secure gateway as a service. This firewall as a service doesn't make any sense to me in terms of the numbers people are talking. CASB, yes, but it's becoming -- I mean becoming a feature. And then Zero Trust, which I think will be its own market, its own right. So the foundation, if you believe the definition of SASE, is SD-WAN.
Ittai Kidron
analystRight. Absolutely. Got it.
John Maddison
executiveSo you go from SD-WAN, the WAN edge. You go back towards a LAN edge. You go to the 5G edge. You go to the cloud edge. It sits right in the middle. That's why it's absolutely critical that we are #1 in SD-WAN, and that's what we're pushing very hard for.
Ittai Kidron
analystGot it. That's great. Keith, just from a -- to make sure I understand the characterization. When you talk about SD-WAN being 14%, is that -- is it of billings or of ARR, remind me?
Keith Jensen
executiveIt's a billing number, 14% billings.
Ittai Kidron
analystBillings? And that would be included within what you'd call FortiGate, yes?
Keith Jensen
executiveIt's like any -- part of it is, yes, but not all of it.
Ittai Kidron
analystNot all of it?
Keith Jensen
executiveSo with SD-WAN -- and SD-WAN solution will attach, of course, services just like a traditional firewall sale, security updates we call FortiGuard for the care and support product. And you can get into secure SD-WAN solutions that will include access points and switches and things like that. And you also see an SD-WAN sale like a FortiGate sale. They'll buy products out of the platform so you can call the manager, the analyzer and things like that.
Ittai Kidron
analystGot it.
John Maddison
executiveIt was interesting last year that a lot of people were saying because of COVID and work from home that maybe SD-WAN slows down because the branch offices are not -- it grew 40% in the marketplace.
Ittai Kidron
analystInteresting. Interesting. But I kind of wonder why, right? I mean -- John, I mean those branch offices are still largely empty. So is this just future proofing and companies taking advantage, frankly, of the fact that people are not there to do this?
John Maddison
executiveDifferent verticals. It became absolutely critical for retail to have that connectivity for online orders. And so just -- it moves around. And so now we're seeing people build out some more branches, et cetera. But back then, it was just retail, making sure they had absolute connectivity.
Ittai Kidron
analystGot it. Got it. Okay. Keith, going back to your answer on how the SD-WAN, I guess, billings are kind of split between FortiGate and non-FortiGate. I guess I was trying to think about how does the FortiGate growth look like without SD-WAN. Is there a way to think about that?
Keith Jensen
executiveIt's certainly something that we track about -- we track internally. We don't comment about it specifically. I would say that it bounces around some quarters. The SD-WAN use case is greater than the other use cases. In the second quarter, it was quite the opposite. The other use cases were much larger than the SD-WAN. SD-WAN itself grew very, very nicely in the quarter. But the rest of the platform and suite of products just grew fantastically during the quarter.
Ittai Kidron
analystGot it. Okay. And then, John, drilling again into the SD-WAN, what is it exactly that you are selling? Is this a software? Is this an appliance that's -- a router that sits in the branch? Help me understand what is this that you're actually selling here?
John Maddison
executiveYes, all of those things. It's -- SD-WAN is application routing, which replaces the traditional IP routing. So that's the first most basic application. And you buy it so you have higher availability. But eventually, really, you're buying it to make sure you're routing applications correctly long term. There's some other -- but for us, that mainly is our entry-level FortiGates, which are built on our SoC4, which is an ARM-based system on a chip. I don't know if you noticed that over the last 2 years, just about everyone is switching to ARM because of the power consumption, the performance.
Ittai Kidron
analystRight.
John Maddison
executiveThis is our fourth generation. And we'll continue building those out because we can get much better performance. So there's a hardware component, there's a software component and then there's a security component. And then there's an orchestration and management component. All of those things come together to give you an SD-WAN solution.
Ittai Kidron
analystGot it. And if I deploy this -- if I think about the traditional branch architecture, with the Cisco ISR, that's what's going to get kicked out. Is that the right way to think about this?
Keith Jensen
executiveYes.
Ittai Kidron
analystAll right. Very good. Okay. If I remember correctly, they, gosh, nominated a good 80%, 85% of the branch footprint with that device. So there's a massive footprint there for -- up for replacement, I guess, the displacement?
John Maddison
executiveStill is. I mean I think that's why I think Cisco bought -- spent a lot of money on company internal development. I mean they have 3, 4 solutions, I think they still do. But in the end, what customers are looking for is an integrated solution. So the next evolution for us is SD branch, with ads in the WiFi, the switching, eventually the Zero Trust, the 5G. And that's when it becomes a much larger platform but built on the foundation of the WAN-Edge or SD-WAN.
Ittai Kidron
analystGot it. Interesting. If we talk about things from a customer perspective, is there any common denominator for the customers on SD-WAN? Size? Region? Are they buying this as a stand-alone capability or part -- as a whole platform? Help me think about that.
John Maddison
executiveYes. I mean some separated out because there's still this kind of siloed mentality in many larger customers that networking is here and security is over here. It's all separated out. Service providers kind of have the same still, but I think they're eventually coming to the realization that these edges, WAN edge, LAN edge, 5G edge, cloud edge, has to have security, enterprise security on it. You can't just put an edge in there and say, "Oh, don't forget about security." So the -- this is actually -- SD-WAN is one of the applications which really brings the security and the networking teams together.
Ittai Kidron
analystGot it. Got it. That makes sense. You've touched actually, I think, in one very interesting point, which is the blending of security and networking, right? And I always remember -- because John Chambers, right, he was famous in saying that if you have 16 security vendors, you don't have security. And I guess Cisco and you guys, Fortinet, are probably one -- the only ones that can claim that's trailing both sides of the equation, right? The networking side of the equation, the security. How important do you think that's going to be going forward? What is the advantage it really gives you, I guess, other security vendors that are perhaps not as close to that networking layer as one perhaps should be?
John Maddison
executiveWell, obviously, we're not going to say it's critical. But I think it gives you a lot of -- there's a lot of security vendors who do detection, "I found something." Well, okay...
Ittai Kidron
analystVery simple.
John Maddison
executiveNow from an end point vendor, maybe I can do something because I'm an agent on there. But there's a lot of people with detection either in the cloud or on the network. The real benefit of being able to fit in the network and behave like a networking device is to be able to prevent things and stop things. And then after that, you've got to be able to then integrate multiple components together. And so I think if you look in history, there's a lot of cybersecurity vendors. The end point vendors -- between 2000, 2010, the end point vendors trying to bring together everything together in an end point platform. Between 2010 and 2020, the networks -- networking vendors try to bring things together in a network platform. I think recently, these cloud platforms -- we believe, long term, a platform has to include end point, network and application or cloud to truly be able to provide the use cases end-to-end. Now if you just have an end point platform or you just have a networking platform or you just have an application platform, it's not enough.
Ittai Kidron
analystRight. Interesting. All right. Keith, let me ask you about -- I want to kind of go back to the drivers of growth and try to kind of break it down between new customers, expanding customers, land, expand. I want to understand if you're -- help me understand how much of the growth is coming from increasing the number of customers versus getting more dollars and more footprint from your existing ones. Help me think about the puts and takes of that.
Keith Jensen
executiveYes. I think like with any -- most tech companies, the vast, vast majority of your revenue and new billings are from existing customers. And for us, we have 500,000 customers. So it's going to be a fairly large number each quarter. But the new logos are key to the growth that comes from future quarters. And we have a very strong new logo quarter. We haven't given specific numbers historically, but we have provided information to allow people to think around the order of magnitude, about 5,000 new customers in the quarter in the logos. The second quarter, this quarter was -- this year was very strong. It was a 50% growth year-over-year. So you need the new ones to feed the growth engine for the future years. But given our size of our footprint with our customer base, the installed base is always going to be dominant in terms of the mix of revenues.
Ittai Kidron
analystGot it. Is there a way to think about attach rates? Meaning -- so I understand that, clearly, a lot of the focus is -- a lot of the growth comes from existing customers expanding footprints. But how much -- how do I get my hands around how much of the growth is driven by expansion of the portfolio, meaning buying more and more different products rather than the same thing, just more of them?
Keith Jensen
executiveYes. I think internally, we track metrics by size of customer, if you will, the small businesses, the mid- and the large in terms of what their buying patterns are and how long it takes them to buy the third product and the fifth product and so forth. But they're not numbers that we necessarily talk about openly in terms of that penetration rate. We do, however, believe that the penetration opportunity for us, we're proving it is real, but it's still very significant in front of us.
Ittai Kidron
analystGot it. When you talk about your $1 million customers, maybe perhaps if you focus on that type of cohort, is there an average product count that you should think about when you think about that cohort?
Keith Jensen
executiveNo, I think you've got to look at it. When you start peeling back the onion, you start to see the MSSPs and the telcos, for example, have very large attach rates of additional products, which kind of makes sense when you think about a service provider or an MSSP. They're looking to gain that management cost advantage. And so if they are buying from a single -- if they're consolidating vendor purchases, they're taking costs out of their organization. As you move through the mid-enterprise is probably another place that you see a very rich mix of attach rates.
Ittai Kidron
analystGot it. Interesting. How much of your revenue is driven from MSPs?
Keith Jensen
executiveIt's ranged anywhere -- we break it out, we call service providers, which includes both selling into the telcos and selling to the MSSPs. That ranges in a given quarter from high-teens to low 20% of our business.
Ittai Kidron
analystGot it. Interesting. It would make sense for them, I guess, to consolidate it. It saves them a lot of OpEx, I guess, getting on one -- to have a console to run multiple products make sense. Maybe we can talk about the cloud and the opportunity of the cloud and talk about the ways you're evolving in the market between corporate or private data center deployments and campus deployments versus cloud deployments and migration to cloud? How are you guys positioned here?
John Maddison
executiveYes. So I'm assuming you're talking about security for the cloud?
Ittai Kidron
analystYes.
John Maddison
executiveYou also have a security from the cloud portfolio. Just -- I always try and clarify that. For the cloud, we're seeing that application journey, as we call it, that still continues from data centers to the cloud, although we have many customers who just can't move applications or refuse to move applications. So we're still seeing a very hybrid world for a long time. It's interesting that we did think initially that the applications -- that customers would try and move applications across multiple clouds to get the best costs because sometimes cost is an issue with cloud. That's not happening. Once you decide on that cloud, you decide on that application for that cloud. We're starting to see some edge compute. When I say edge compute, building compute, so applications are now going from the cloud and moving off on to get closer to the applications themselves. So yes, we just see a very hybrid world. And so being able to support all the major cloud vendors or the data center, edge compute is very important. And the consistency of policy across those clouds and the consistency of protection and the consistency of operations is very important to customers. So it's a very, very fragmented environment. You've got the cloud vendors themselves. You've got quite a few -- it's easier just to spin something up in the cloud and say you've got security. So it's fragmented, but I don't think there's that many that work across all the applications like the workload protection or WAF or -- it goes on than across all different clouds. So to us, it's very hybrid, and multi-cloud is the key strategy there for us.
Ittai Kidron
analystGot it. Okay. And if we talk about security from the cloud, how would I think about that for you guys?
John Maddison
executiveYes. Well, I think there's 2 different types of versions. There's one which is very traffic-oriented. So you've got e-mail security. You've got web security, which you talked about earlier on. And so those are taking direct traffic. You then got what I call management as a service. So you're providing management services. And we've got quite a few of those. Even for a hardware, we have management services. And then you've got cloud capabilities like our EDR solution. The analysis, the AI is going on in the cloud. And so that's the only way you can do that because you've got big data in there and you can provide those. So I think there's different types of cloud delivery services ranging from, I would say, simplistic management all the way into AI that's being applied to that end point because you need to provide that EDR functionality and post-detection-type capabilities.
Ittai Kidron
analystGot it. Interesting. Keith, I know security from the cloud, SASE is early for you guys. How long before it's 25% of revenue? Do you want to put a bet here?
Keith Jensen
executiveWell, if you're going to ask for guidance and numbers, I'm going to hand it back over to John and let him talk to you about that. I think he's actually, John, just trying to hear more about what the journey is like for us on SASE, so I'll let you take that.
John Maddison
executiveSo again, the SASE -- towards the SASE component is the secure gateway plus some features like CASB. We've started to build that out a while ago. We did an acquisition a year ago with some key technology. Our strategy from acquisition is not necessarily to buy the leading solution with all the customers and all the revenue. It's to make sure we buy technology that we can integrate quickly into our overall solution set. So we have all the components. We're building it out. We have customers on board. I think from our perspective, regardless of the overall percentage that it's just -- it's a piece of the overall solution. It's not the end goal for us. It's a component of that kind of fabric solution for us that started SD-WAN and goes to the cloud edge, which is where SASE predominantly is. It goes to 5G. It goes to the LAN edge. It's an element. And so for us, SASE or SaaS, it is a SaaS, as I said, we have 15 to 20 different SaaS services offerings. We have a specific SaaS offering, SASE offering, as you call it, which really should be called secure gateway as a service.
Ittai Kidron
analystRight -- Got it. Okay. Well, then let's bring down the SASE element. You mentioned a few parts that need to go in here, the secure web gateway, the CASB, the Zero Trust, of course, the SD-WAN, right, as the foundational element of the architecture. In your perspective, is there a better starting point for -- if one is to build such an architecture, is there a better place to start from in order to be successful in it?
John Maddison
executiveWe think personally the most -- the best place to start would be with service provider partners because they have the network already and the capabilities because otherwise, it becomes a very, very expensive proposition for anybody to build out. So that's one of our primary motives is to kind of arm and supply the service providers who are, surprise, surprise, starting to work out that the SASE events are actually service providers and can compete against them at some point. And so they should maybe realize that a while ago, but that's happening. And so -- but to provide that, a SASE offering or even any offering, to be honest, a lot of S's in there, you need to kind of sometimes build it yourself a bit to look at how to supply somebody else. So our goal is a dual strategy of building it ourselves as well as supplying to many of the service providers who already have our secure SD-WAN. And this is a component you add on.
Ittai Kidron
analystGot it. So it sounds like this is going to be an umbrella term that lumps in it revenue from multiple different products, some of which fully integrated, sold together or sold independently, all depending on the situation?
John Maddison
executiveYes, but I think some of them are -- I think Zero Trust is not just a feature. I think CASB is a feature. Gateway is a product in its own right, SD-WAN. I think Zero Trust firewall as a service, I don't know, I can't even understand what that market is, to be honest. No one has told me how much revenue is in there. But Zero Trust, you need that end point component. You need a proxy, which can be in the cloud through SASE, can be in the data center, will eventually be on the campus and replace ACL-type stuff in the campus. You need that identity engine. You need that policy engine. Eventually, you need to integrate in DDR. And you've got 5 or 6 products. When I speak to customers, they've got 5 or 6 different vendors. Now making 2 vendors, cyber security vendors work together, is hard enough. Making 5 or 6 is impossible. So that's -- the trust journey is going to be very important, but it won't be 5 or 6 vendors. It will be 2 to 3 vendors at the most that work together.
Ittai Kidron
analystOkay. Well, then let's go back to a comment you made at the beginning, where you say customers want to consolidate the number of security vendors that they have. If you think about the path by which this would happen, are there natural paths of consolidation, product- or vertical-wise, that you think make more sense early on in the process versus later on? Because we're not going to get to SASE everything from a single vendor anytime soon, it sounds like. But what would be the first, more logical first steps of consolidation in this path?
John Maddison
executiveYes. That's a good question. And that used -- if you had asked that question 5 years ago, some of the vendors would say by vendor. "I'm this vendor. Trust me. I'll build the thing for you." Well, that hasn't worked. That's for sure. I think there's 2 modes which are -- enterprises are looking at. I think the very large enterprises, they're looking at function. So let me build an end point platform. Let me build a networking platform. Let me build a cloud or application security platform. They still find it hard because I still find customers who have got 8 different agents on there even though they're building an end point platform. And then I think going forward, the more forward-thinking enterprises will go by use case. I'll pick out a use case. It's digital security or it's my Zero Trust use case. And then I'll decide in 5 years' time who my platform vendors are going to be, maybe 1 or 2. And then I'm going to go from here. And I'm going to gradually work towards that use case that the platform is with. So even if you have a platform, you still need to work with the infrastructure. You can't just be an island. You've got to be able to interwork and connect. And the reason why we build a platform is automation, to make sure that you can automate policy and you can automate the exchange and the transfer of threat intelligence. But you still have to be able to do that externally. And the industry, as we know, is not the best there.
Ittai Kidron
analystGot it. So it sounds like you're counting on the market to ultimately, over time, evolve towards you. Meaning the enterprises that are forward thinking will say, "I want to pick the vendor right here right now that might not check all the boxes but I have a very high degree of confidence that X years down the road will be incredibly able to fill this in a robust kind of a way that I can right here right now start building and grow along with that vendor."
John Maddison
executiveExactly. And it's not -- so you're not saying, "Let's go from 30 vendors to 1." They're not going to do that. 30 vendors to 7 platforms or 5 to 7 -- 5 to 6 to 7 platforms, but those platforms need to work together.
Ittai Kidron
analystGot it. Okay. Very good. Keith, let's talk about -- clearly, there's been a lot of focus on the FortiGate side. But let's talk about the non-FortiGate side. Can you kind of peel the onion on this a little bit and remind us what's included in this part of your business?
Keith Jensen
executiveYes. The core -- one of our core technologies, we probably will evaluate 3 different products in that group, whether a sandbox or a SIM or DDR, it's our manager, it's our analyzer product or what have you. It also includes switches. And it also includes access points on an area that we call secure access. We continue to try and look for a way -- or a product that, so far, outperforms everything else that we should call attention to it, but it really hasn't been that way. It's been -- I think Ken used the term session for a rising tide lifting all boats. And those growth numbers across that suite of products individually have been spectacular. I'm very, very happy with it.
Ittai Kidron
analystGot it. Interesting. In what way are these solutions tied to FortiOS and the FortiGate architecture then?
Keith Jensen
executiveI will hand that back to John.
Ittai Kidron
analystJohn?
John Maddison
executiveYes. So as part of our fabric technology, the key is allowing policy from -- a policy from a central location to be spread across the attack surface, whether it be end point, network or application and then when you find something building that automation. So if my end point finds something, do I want to put a policy in place on my SD-WAN to not allow that end user to go to the data center or cloud? So the key is building automation, but these products need to talk to you. That's why when you go and acquire mature, sometimes market-leading products, it's almost impossible to integrate it. It's a different code. It's different management systems. It's a different AP. I mean it's just -- so our road maps have 2 pieces to it. One is to build it as a stand-alone product to be able to compete in the marketplace that may sound right, SD-WAN is a good example, but also to integrate into our platform so that it can take policy and it can take automation scripting, et cetera, to apply that automation when you found something. So all of those products we talked -- Keith talked about, whether it be end point or whether it be our WAF in the cloud or whether it be our switching and WiFi, they all talk to the OS. And the OS talks to it and can exchange that policy in that [indiscernible]. But what's more -- most important is as we start to evolve use cases like Zero Trust, or identity-based segmentation east-west, you can then build that use case across the platform and the fabric, not just in that one-point solution so that we can tell switch ports or we can tell WiFi, we can tell the WAF to block -- it's the ability to talk as though it's the same product through that FortiOS, which is our huge differentiator because, yes, we've done acquisitions. But really, most of our development is organic, as you know. But when you do it that way, you allow everything to talk to each other. That's the key.
Ittai Kidron
analystGot it. Interesting. So how much of -- right now of your non-FortiGate business is sold stand-alone versus part of FortiGate solution?
John Maddison
executiveThat's a good question. I wouldn't be able to give you a percentage in any way. I do know it happens and...
Keith Jensen
executiveIt does. I would probably jump in to think about the business. Certainly, FortiGate is the cornerstone, right, the firewall. And that's -- the vast majority of the time, that's the first sale. And then the add-on sales are typically from the suite of products that are in the platform or the non-Fortigate as we call them. As John alluded to, do we see customers actually enter our business, if you will, for the first time, not coming through the firewall chat? Yes, it does, but it's not a significant occurrence.
Ittai Kidron
analystInteresting. And do you view that as an opportunity? Or you always envision that the bulk of non-FortiGate revenue will be an upsell to a FortiGate customer?
Keith Jensen
executiveWell, we certainly don't disqualify anybody from being a customer because they don't want to buy FortiGate first. We're happy to suit their needs.
Ittai Kidron
analystHow do you -- it's more like what's the mandate for the salespeople? Go and find new customers? Or use the Rolodex of FortiGate to make the upsell?
Keith Jensen
executiveThere's not a -- we don't distinguish between the 2, right? I've seen corner cases where somebody has done a very good job of selling the 4G phone as an entry point into a customer, I guess a very large networking company down the street. So if they're successful at it, I think that's fantastic.
John Maddison
executiveYes. I always -- whenever I do my executive briefings or with the sales team, I always tell them, "It's always going to be some way you can get into that account with our broad portfolio." But as Keith suggests, the core of FortiOS sits on FortiGate and not a FortiGate appliance. It could be -- eventually, it's a SASE component, but that provides a lot of ways you can go towards the LAN or the WAN or the cloud or data center. But to me, there's always an opportunity inside an account given our portfolio breadth.
Ittai Kidron
analystGot it. Okay. Let's talk quickly about competition, more specifically Palo Alto or Check Point and Cisco kind of the big ones there. Help me think about some of the differences. They have growth, but they're not anywhere close to your growth. So help me think about what sets you apart here. And what do you think is your ability to sustain this advantage relative to them in the marketplace?
John Maddison
executiveYes. That's a long answer, I must assure you.
Ittai Kidron
analystGive us the 2-minute version answer.
John Maddison
executiveThe 2-minute version is we have the technology across the end point, network and cloud. It allows us to build out use cases in the platform. I think some of our competitors want to go to the cloud. Some of them want to stay at home and not go out. Some of them have decided they want to be a services company. And our strategy has been consistent for the last, how many odd years, and we'll keep building against it. We'll keep adding functionality both individually and as a platform. And definitely, I think that's where the market is going.
Ittai Kidron
analystExcellent. Keith, maybe last one for you because we're starting to run out of time here. How do you think about the balance of margin and growth going forward? You are now hitting growth rates which are quite phenomenal. Aren't you tempted just a little bit to say, "You know what, guys? Let's throw another couple of margin points in there and see if we can reach 50% growth next quarter"?
Keith Jensen
executiveYou sound like my CEO.
Ittai Kidron
analystIt sounds like you have very aggressive battles there over the budget.
Keith Jensen
executiveYes. We try -- he and I try to stay in our swim lanes and represent our constituents. How's that? Look, I think I would probably frame it a little bit and say -- I'll give you a couple of metrics to give you an insight about how we run the business. So one is this Rule of 40 that we measure based on revenue and operating margin. 11 out of 13 years that Ken, the CEO, has managed the company to be at the Rule of 40 or above. 20% revenue growth, in 10 out of the last 13 years, we've had 20% revenue growth. I think the other comment I would add to that metric is that it's a business model that comes pretty darn close to 80% gross margin. For a "hardware company," that's pretty spectacular. But it also affords you, to get back to the question, the opportunity to leverage that growth with your sales and marketing dollars, right, together with your R&D spending and where you invest it. So it's very nice to have that particular business model and be able to manage it in that fashion. We have said that our metrics and our midterm targets that for the next 3 years, we want to average at least 25% operating margin. And we thought we'd be a $5 billion company in 2023 in the billings line. Those metrics are all very achievable from what we've seen in the first half of this year. 35% growth in the first quarter on the billings line and 25% operating margin, those are pretty spectacular numbers. To be able to hold the line of that margin growth -- margin number at the same time, we've got that kind of growth. I think we're very pleased with the execution by the team.
Ittai Kidron
analystOkay. Very good. And then last one for you. I'm going to ask you a Freud-type like of a question. What would you rather have? One more point of growth or one more point of margin?
Keith Jensen
executiveIn our business model, I don't know they're mutually exclusive. How's that?
Ittai Kidron
analystVery good. Excellent. I tried. Very good. Guys, really appreciate it. Keith, John, I appreciate your time. I know you're very busy, and I appreciate you spending the time with me here today. This was great. Keep it up, and looking forward to catching up again soon in person. Thanks again for your time.
Keith Jensen
executiveThank you very much.
Ittai Kidron
analystThanks. Bye-bye.
Keith Jensen
executiveBye.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Fortinet, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Fortinet, Inc. earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.