Fortinet, Inc. (FTNT) Earnings Call Transcript & Summary

August 11, 2021

NASDAQ US Information Technology Software conference_presentation 30 min

Earnings Call Speaker Segments

Michael Turits

analyst
#1

Everybody, good afternoon. I'm Michael Turits, senior enterprise software analyst here at KeyBanc. Welcome, once again, to our technology leadership forum, formerly or informally known as Virtual Vail. And we are very happy to have Fortinet in a fireside chat this afternoon. We have Co-Founder, Chairman and CEO, Ken Xie; CFO, Keith Jensen; and Peter Salkowski from IR is here. So I think we're going to do the safe harbor, and then we'll move on.

Keith Jensen

executive
#2

Thank you, Michael. Peter, you might want to advance that slide because it's not showing. Very good. I would just call everybody's attention to our safe harbor statement and of today's discussion is cover by the safe harbor statement. And with that, back to you, Michael. Thank you.

Michael Turits

analyst
#3

Good. All right. Well, I'll start with the macro question. So I never liked there's a lack of [indiscernible] security. But it does seem as if things are particularly urgent, if you will, at the moment. What are you guys seeing? And I'll address my questions to both Ken and Keith, of course, determine as you like, in terms of security demand might be differential right now?

Ken Xie

executive
#4

Yes. Thank you, Michael. I think right now, we see kind of a -- compared to 1 year ago, a lot of company rushed to supporting work remotely. Now they're taking the time and rebuild a new architecture to rather more supportive working from home more permanently and also try to make the whole infrastructure more secure, including the remote access, the Zero Trust access, including the make -- all this work from home and also internal segmentation -- internal segmentation and also supporting the secure SD-WAN, secure 5G. And it's a probable last for few years with this new refreshed infrastructure supporting the whole infrastructure security. And we see -- and also that's also opened a lot of greenfield beyond the traditional network security, endpoint security and try to -- and also making the whole security working together is very, very important.

Michael Turits

analyst
#5

So if you had to distinguish between -- well, first of all, and I want to come back to the more general macro picture. But I think you drew a distinction I've been thinking a lot about, which is what's the difference to what people were buying in terms of security products call it, May, June of last year from what they're buying right now. You mentioned architectural change. Was that true then a year ago? Or what was the difference?

Ken Xie

executive
#6

Yes. A year ago, it's more like this like a catch-up rush buy, whatever's supporting the people working remotely, like upgrade their gateway or increased license for VPN access, all these kind of things. Now they also found out how to expand security beyond the traditional what they have, whether the border network security and expanding into some whether the mobile device expand into all these kind of WAN access, especially when the 4G and also supporting all these permanent work from our home, which is more using the Zero Trust access, since they have no traditional VPN. At the same time, with the ransomware may start -- become bigger news over this year, within the company, internal segmentation, how to secure -- I mean between different departments or secure a server, and also internal like WiFi, mobile access and now all the security starting to kind of get a very, very important. And also at the same time, we see -- we're also setting more partner with some service provider and try to make the network security more combined together with secure-driven networking and also making different part of security, like endpoint working with network, with e-mail, with WAN, with all these other different device. And also, we -- last quarter, we also see pretty strong growth in the traditionally pretty low percentage security segment like certain utility, energy, some other ones. So we see beyond the top 5 vertical, we see the other vertical grow like 75% year-over-year, which is a pretty, pretty huge ramp up.

Michael Turits

analyst
#7

Yes. There's a lot of really interesting stuff in there, Ken. And this is some of the stuff that you talked about on the earnings call. So maybe I'd like to talk about a couple of them. Let's start with what you finished on, which is this point that you made about the nontraditional vertical segments spending more. I mean, I think, we can see lots of different times, you talked about what vertical spend, what percentage of their IT budget on security, and it probably starts with financials and health care and government, fairly high, and we end up maybe with sort of the retail and manufacturing lower. So when did you start to see that? And what's driving it? And how much of a boost do you think that could be to demand for -- into your revenue growth?

Ken Xie

executive
#8

Yes. I see that -- probably Keith also can help add in more and better, like when there's like a SolarWinds kind of cyber attack, end of last year, they do drive some kind of supply chain security, but they are not demand some product secure services right away. They're more planning on a long time, they need to have the supply chain security. But once the ransomware starting to hit and especially taking some utility companies [indiscernible], we see a pretty quick ramp up pretty much right away. A lot of this kind of energy, utilities, some another company, they started to see the importance of internal segmentation, internal security. And that's driving the demand environment quickly go up. That will be on the traditional -- the top 5 vertical we keep talking about, the government, the finance service, the telecom service provider and the retail, education. So there's some other areas which have been hit by the ransomware. They do see a very important of how to make the internal security, I mean, internal segmentation, all these kind of things -- and also their access setting that kind of quite a lot of interest. Probably Keith can cover some vertical quite better with the data.

Keith Jensen

executive
#9

Yes. And I think that you and Michael pretty much covered it very, very well, and I'll give a little more color. Those top 5 verticals, for us, have almost religiously been 65%, 66% of our business. And then the others that we just -- that Ken mentioned a few -- a moment ago, utilities, manufacturing, transportation, et cetera, host is made up about 35% of it. And we saw a very -- we saw a significant shift, if you will, in the mix. And it wasn't because the top 5 stopped growing, it still grew very nicely. It was just that 75% growth from that other number. And I think we saw -- we conjecture that it's related to ransomware and the fact that it's become such a hot topic of conversation, unfortunately, perhaps somewhat pervasive. Pervasive meaning it's hitting all verticals, all industries. It's hitting companies of all sizes. It's hitting all geographies. When we look at our internal metrics and we can see the mix and what was happening, say, in the mid enterprise and the SMB part of the business in the first quarter, and what was happening internationally, it wasn't just the verticals, but those key metrics seem to all point to the same story line, which is there's clearly a response now to the bad actors. Michael, as you alluded to, there are some technology leaders or security leaders, financial services makes sense, retailers because of their credit card treasure trove, if you will, and governments and telcos, et cetera, have always, I think, been perhaps a little bit more advanced in terms of their spending. And now you're seeing these other industries come online and come on pretty significantly. I suspect also that those other industries perhaps don't have budgets that are as robust as maybe some of the big boys. And so when we bring a costs and performance advantage to the table, through our channel partners, I think that we saw that resonate very effectively in the quarter.

Michael Turits

analyst
#10

Once again, a lot of interesting stuff there. One of the questions that I think is most relevant for investors is this. So if these other verticals are starting to spend more, is that sort of just kind of a knee-jerk reaction and you get that spend this year because there's ransomware? Or is that something that's part of a multiyear spend cycle for them? And that plays into this question, look, you're going to -- you just guided to mid-20s revenue and billings growth. It was 20% last year, which wasn't bad in COVID, 20% the year before. So you, as well as some other sectors that I follow, are in this enviable position from a stock perspective of having accelerated growth. So when we look at this question of new verticals coming in, is this going to contribute to sustain higher growth than we've seen in the past, this is a multiyear cycle that we're seeing here for these companies?

Ken Xie

executive
#11

I think compared to last time, the hyper growth period, maybe the 2013, '14, which we kind of more using refresh is really using the next-gen firewall UTM replace the traditional firewall. This time, we see it's expand beyond the firewall. Go to the WAN side, like SD-WAN security, 5G security and because more devices being connected and also go internal beyond the Internet connection or the border, go inside the company, like a different department or the server even within the data center, which also need more high-speed network security, which we have some advantage with ASIC chip, which is kind of traditionally is really the networking side, which is internal networks tend to be 10 or 100x faster than the Internet connection. So that's where we see kind of more whole infrastructure security to be addressed. Yes, at the same time, also a different part that we're working together, right, network security with endpoint with some other like different e-mail web security or some other net or some box and all this, the management. So it's kind of -- but that's also the fabric we found a continued keeping growth probably almost double compared to the traditional -- compared to the FortiGate. So that's where the fabric part, non-FortiGate grow almost double the rate compared to FortiGate growth, which just mean multiple product working together, integrate together.

Michael Turits

analyst
#12

Yes. I think you make a very important point for us, Ken, by specifying that these new initiatives by companies that are not necessarily at verticals, not as sophisticated in terms of their internal security resources, will look to a Fortinet who has that fabric and who has that -- who has all that integrated, whether it's on the OS or different parts of the fabric. So it makes a lot of sense. I want to drill down on a couple of other things that you mentioned. When you called it Zero Trust, but I think what you're talking about is what someone referred to when we talk about the SASE space. Now I think in terms of SASE, probably most people thought initially a Zscaler and probably initially at Palo, but I think that there's more and more presence in terms of your messaging and in terms of the channel and in terms of customer viewpoint of Fortinet on the SASE side. You've taken a slightly different strategy there. So can you tell us how much that's really starting to have an impact on your business and how your approach is differentiated?

Ken Xie

executive
#13

Yes, we see a little bit too different market, different product compared to Zero Trust and also SASE and some of the overlap. So definitely, the Zero Trust is really replacing -- is better security compared to the traditional VPN, which basically open up the network, when we remotely access from VPN. But with the Zero Trust, you open up certain applications, a certain segment or part of the network, give people access on a certain device level. So that's where we see is coming more kind of a concern within the traditional VPN being replaced by the Zero Trust right now, especially working remotely from home. On the other part, the SASE is a little bit more service kind of model. Some of them have forward traffic to the part to be processed, which also including certain networking function like a SD-WAN or some other CASB and also a part of it is also related to Zero Trust, which we do believe the new track strategy we have, you can talk about in the last few years, WAN strategy working with a service provider because a lot of carrier service provider, they do on the Internet infrastructure, they have a lot of -- whether the properties center themselves compared to the SASE vendor, you mentioned. On the other side, they also kind of -- actually, they have a little bit healthy business model because they own the infrastructure pretty much not additional cost for them from the infrastructure side and compared to a lot of SASE providers have to add a lot of cost. Even for Fortinet, we do have a kind of own, kind of a SASE structure. Like that's also one of the reason last quarter, the service revenue margin grew by 2.2%. Basically, we have to invest in some of that. But on the other side, we feel it's more important or probably even better business model working with a carrier service provider, help them to build a SASE service, which they are more closer to the customer has an infrastructure and also have a pretty big team may not be quite a security already that's traditionally sometimes SASE provider, but they have a pretty good customer relation there. And that's where we have -- we still track working with service provider carrier and also build some ourselves for the customer, which they don't have a service provider behind them.

Michael Turits

analyst
#14

And then, Ken, you mentioned internal security microsegmentation. And then I think you also mentioned, at one point, your work in -- there was more demand around the operational technology side, OT. So what does this actually mean in terms of what you're selling? When you do microsegmentation, what products are you selling more of? And the same thing with OT, is it just the same or smaller boxes because it's addressing segments or remote sites. What's the driver?

Ken Xie

executive
#15

Yes, let me first go to OT side. OT in a lot of -- they call the recognized environment or even some outdoor have supporting that kind of platform and also a lot of device connect remotely, so you do have a pretty solid path to supporting that. And then in the company side, the internal segmentation, you can look at the percentage security on the IT infrastructure spending there. Like when I started Fortinet 21 years ago, it's maybe 1% or 2% of infrastructure IT spending go to security. Now probably in the U.S., about 10% now. So that's what we're using because secure-driven networking because the networking whether has a 5G or some other is still more about connectivity and speed. You can now go to 500-gig, 400-gig, 2 terabit. But that's all they connect, everything is treated the same. But when you're using secure-driven networking or even some kind of [indiscernible] SD-WAN based on different applications, different content, different user, different device and different -- even different location have different policy, different way to handle the traffic, allow the traffic or block the traffic. So that's where we see this kind of inside the company, just connect everything equally, everything just open up, it's no longer enough. So the internal segmentation, like a different department, they may have a different application, or different company to be treated differently. And also based on the user device levels, the same channel, even location, you remotely access from different location, how to treat this with different policy. So that's where we see the secure-driven network in all the security total IT spending get a higher, higher percentage. I feel there's still a lot of room to be improving, maybe from 10% today, we'll keep going up 20%, 30%, 40%. That eventually may change in the whole Internet. Our whole networking is not just connectivity and speed, it's no longer enough. When you connect things, you probably also need to look at the content application, user device or even location behind that. So that's what we see, which is all handled by the security, but also security need a huge computing power at the process beyond this traditional switch and routing, which is just kind of everything in the same level, but security has to look in the content, look in all this high-layer traffic data to make decision, what kind of networking needed.

Michael Turits

analyst
#16

Keith, one of the things that you had mentioned in the last couple of quarters has been that with COVID, there's been less displacement, less people going into data centers and actually replacing one provider with another. Let's hope that we would back to the office, call it back to the status there, if you will, that may hopefully, fingers crossed, that's actually taking place. Is that now, assuming we keep in that direction, is that going to be a trend that's an opportunity for you to start doing more displacement?

Keith Jensen

executive
#17

Yes, I think so. And just to [indiscernible] out the answer a little bit. I think, clearly, we saw in 2020 with COVID that the priorities that CIOs and CISOs have, VPs of networking, it was not about going through and refreshing their firewalls, right? They were going to swap the assets. There was some competitive displacement activity, I think, in 2020. It was nothing like we had seen in prior years. That activity has certainly come back online now. We've gotten into 2021. And we do -- we look for those opportunities where perhaps our competitors is going through a renewal cycle or a refresh cycle, is -- and if there's an RFP that's going to be placed or an RFP that we can encourage, we like those opportunities for us to come in and treat the displacement opportunity. That motion, if you will, throughout this year to this point, has been, I think, significantly more active than it was in 2020.

Michael Turits

analyst
#18

So that -- and that's an opportunity for you, which probably didn't have nearly as much in that last cycle that Ken was talking about, call it, 2014, 2015. And one of the reasons -- I mean, I think about that because I think at that time, perception certainly amongst customers in the channel was that you were less of an enterprise player, which is -- which I always thought was odd because I'd talk about you in the field and [indiscernible] Fortinet, they're not really in the enterprise. And I'm like, what do you mean? They got this and they got that. They got great boxes and a fantastic technology. Well, that's not it. That's not -- that is not an enterprise player. And so suddenly, now you are. And so I guess, yes, of course, the fabric is there. You're much broader than you were. But what's different? And what's really done the trick in terms of going to market, creating a perception that you can target the enterprise, work with the enterprise, work with the enterprise channel. It's really been a big change in your perception.

Keith Jensen

executive
#19

Yes. And I'll jump in because Ken want to be humble and I'll have to say it for him. I think the products have always been...

Michael Turits

analyst
#20

Ken's always humble.

Keith Jensen

executive
#21

I think the products have always been suited for the enterprise. If you look at the business and the percentage mix, even in if you go back to 2014, '15 and the footprint that we have with the telcos, those are large appliances or chassis that we call them. So it wasn't a function of the product. I do think, and you made reference to it, Michael, that the go-to-market is different. Now in between those, that period of time when we talked about 5 or 6 years ago, we should probably not lose sight of the fact that Gartner has been kind enough to put us in the enterprise Magic Quadrant with firewalls and leadership position. And that's kind of a calling card, right, to get in there. So you needed that, and I think that's helped. At the same time, I think the -- our motion with the channel partners and perhaps some of the channel partners that we use, and I'm not talking about the distributors so much as [ I had ] the resellers now, has continued to evolve because it is a dual track motion when you get into enterprise. You need to be close with the resellers and you need to have your own direct sales force. And I think that's the third leg of the table of building out our own direct sales force. So we get more at that, and we don't simply miss out on deals. I think all those things have happened over the last several years.

Michael Turits

analyst
#22

I want to ask a couple more financial questions, but I do want to talk -- we've talked a lot about network security, what you're able to do around things like SASE, around like things like VPN, SD-WAN, microsegmentation. But when we specifically talking about security for the cloud, Ken, what's -- how much of a player should I think of you there? I mean there's amazing strength across number of security in the ASIC, do you have that capability to really be a player when we're talking about securing virtual cloud, software-based workloads?

Ken Xie

executive
#23

Yes, we have quite a broad and also a very strong product offering in the cloud compute match with any other competitor. Just we are not just promoting cloud only compared to a lot of other -- compare to few other competitor, which they probably only have the cloud solution. So for us, cloud is a part of our infrastructure, so we also feel long-term edge compared to the cloud, also have some advantage going forward. But on the other side, we see this whole infrastructure security is more important, which cloud is a part of it, and also the edge computing, security and also some other OT, IoT security. And also like within the compass within the enterprise company side, I also need to address security. Even the cloud also, within the cloud data center, how to handle east-west traffic security also kind of important, which we feel is a high-speed ASIC have some advantage. It's not just because they can process data faster, but also the huge computing power enable it to add additional function easily. So that's where every time we announce a product, we're using what we call secure computing rating to give the indicator like to handle the same function and the same cost compared to the industry average of products on how this have advantage easily affect 10x better performance for the same cost function compared to the industry average. And at the same time, that's -- we also enable much more function in the same OS level. So that's a feel with this cloud is very important, but the solution probably not just not cloud only has to be beyond the cloud, including some other part of infrastructure.

Michael Turits

analyst
#24

Thanks, Ken. Keith, at the last Analyst Day, you gave a long-term framework where you get to calendar '23 to $5 billion in [ revs ] and some $5 billion billings for billing and leasing. That was then implied about it from 2020 about a 17% CAGR. You just guided to 26% billings growth. So how can I put this properly?

Keith Jensen

executive
#25

How far off was I, 4 months ago?

Michael Turits

analyst
#26

Well, [indiscernible] on the err on that side of things, but I guess do those targets still apply?

Keith Jensen

executive
#27

I think when we went out the first week of March, we did not yet -- we felt good about the first quarter, where we had not closed the first quarter by any stretch of the imagination. And we certainly didn't have the second quarter in the books. I would step back a couple of months earlier and say we felt good about 2021 coming into the year for a number of reasons, GDP swings and products and sales capacity, et cetera. I think we've probably gotten everything we expected and then some out of the year at this point. Ken made mentioned of the ransomware earlier, I think that's also providing a push. And I do think that to build out that concept is a little bit more security, fortunately or unfortunately, is one of those things that once you start purchasing security, you don't stop purchasing security, right? It just kind of builds on itself over time. And that's why I think we have a longer-term view to it. Yes, I think it's a little bit early, but we have to get through 2021 here and continue with this high level of execution that we've had in the first half of the year and then perhaps look at an opportunity as part of the planning process for 2022 in terms of not providing guidance for 2022, but is that the logical opportunity to reaffirm our prior midterm targets or make an adjustment to that one way or the other. But coming off a quarter where we have 35% billings growth and 30% revenue growth and 25% operating margin, yes, we feel very good about the execution level and what we're doing.

Michael Turits

analyst
#28

Just continuing in terms of the long-term view, I mean you've talked from a profitability perspective, you talked about being a Rule of 40 company, but more near-term favoring growth over profitability. Can you just give us as much color as you can on what you mean by that? And if you are prioritizing investments where they'll be.

Keith Jensen

executive
#29

Yes. I think we've talked for several years about 25% operating margins, whether we want to average that for a period of time or set that as a floor for a period of time. We saw some overperformance last year. We had some [ audit piece ] going on with travel budgets and marketing budgets and things like that. And we also have different revenue mix last year. Services were very -- were a higher mix than they're showing to be this year in product. So I think we've performed very well. This quarter, coming back to 25% operating margin, I think we did that in the face of still some headwinds. FX was a significant headwind for us. As a reminder, we bill everything in U.S. dollars, but we pay in local currency around the world. So when the dollar slips, that's a headwind for us as well as the travel and marketing coming back online. So to put up the numbers that we did and still be at 25% operating margin, I think we're very, very pleased with that. And why it's relevant is I don't expect to have FX headwind in future quarters like I did in the second quarter all along. And so I think there's certainly opportunity for us to continue to reinvest back in the business and still be talking about that 25% operating margin target. It is a business or an industry that is, as Ken has talked about, very fragmented. So we look at that. We look at the fact that we're in a business model that generates 80% gross margin or almost 80% gross margin. And we think we have superior products. And so the thing you would normally do in that situation is you would invest in your go-to-market strategy because you see the opportunity to continue to take market share. As we go through the planning process that we're just starting now for 2022, we'll see how this plays out and whether or not we make the statement at the beginning of next year that we expect 2020 -- 2022 to be the end of the year to be [indiscernible] growth that we've set for the next several quarters. And what I just gave you, I think we feel good about how we're executing and how we're going about things.

Michael Turits

analyst
#30

And do you -- should I think of that 25% as an average? Or is there flexibility to go above or below it?

Keith Jensen

executive
#31

Well, I don't know that I'll hit it perfectly every quarter. How's that? But I would like to be able to look over a 3-year period of time and say, yes, we were at 25% operating margin. And if I'm not, it's because my top line growth has far exceeded expectations anybody has.

Michael Turits

analyst
#32

And then lastly, CapEx did go up. I mean you are expanding, you're growing faster than expected. You talked about real estate investment. Just anything you can tell us about why that's the right thing to do right now? And then once we get beyond this real estate pickup, what the normalized levels of CapEx could be?

Keith Jensen

executive
#33

Yes. I mean we -- I guess it's a bullish sign of how we feel about the business when we make that statement coming off the last 2 quarters that we have, and there's another element of capacity here with this physical capacity for your employees, right? And we have historically performed as you would expect a long-term investment to perform where we have the opportunity to take down our office space and own that office space. We think the long-term ROI on that is very attractive. I don't think that's changed in terms of our thinking. What has changed perhaps you're looking at those -- the growth numbers that we've put up recently and started looking about capacity and say, where do we need capacity, how much capacity do we need over the next 3, 5, even 7 years as we look out. And perhaps this is not a bad time to be looking at commercial real estate assets for a number of reasons. Vacancy rates in certain cities, for example, in certain locations, maybe a little bit lower than they have been historically. There's still uncertainty around return to office. You have questions about interest rates and inflation and so forth. So we think it's a logical time to kind of do a little self-assessment of what we want our real estate strategy to be.

Michael Turits

analyst
#34

Well, I think we're out of time. Thank you very much. It's been a pleasure having you guys. Ken, thanks, Keith and Peter, thank you guys very much. Really appreciate it.

Keith Jensen

executive
#35

Thank you.

Ken Xie

executive
#36

Thank you, Michael. Thank you.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Fortinet, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Fortinet, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.