Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary
September 14, 2020
Earnings Call Speaker Segments
Patrick Edwin Colville
analystHello, everyone. I appreciate you joining us today for this session with Palo Alto Networks and the CEO, Nikesh Arora. So I am Patrick Colville, a senior analyst at DB covering the cybersecurity and infrastructure software space. The format of this session is going to be a video fireside chat with a listener Q&A. There's a chat box where you can ask questions. The questions are anonymous. We're not going to mention your name or company affiliation. So let's kick off with introductions. We got Nikesh Arora, CEO of Palo Alto Networks with us. As everyone knows, Palo Alto Networks is the largest information security vendor and a firm that has got a reputation for driving innovation in the space. Nikesh, thank you for joining us.
Nikesh Arora
executiveThank you for having me, Patrick.
Patrick Edwin Colville
analystWell, given time constraints, I'm going to jump straight into questions. And I think, I guess, the elephant in the room right now is COVID-19. And so a trend everyone's familiar with, cybersecurity risks facing the enterprise are only increasing. But how is the coronavirus pandemic affected that trend?
Nikesh Arora
executiveYes. Thanks, Patrick. Look, I think it has -- it's -- there's been puts and takes. I think we all saw a heightened interest in remote secure work the moment pandemic hit because you have to go set up your business to allow for 100% of your employees to be able to access stuff remotely. Not just that, you have to make sure they're going to access everything. So typically, a company would schedule 5%, 10%, 15% capacity. And you didn't deal with the most complex apps because you can always come to the office and use them. Now you got to make sure everything is accessible from everywhere. So we have seen both the capacity ask from people, but now that's translating into an architectural ask. People are saying, okay, my old model may not be the long-term model, and I might need to go to a different architecture if this thing is going to persist for a year, 1.5 years. And you're saying that, right? Banks are going 1 week on, 1 week off, people are going 2, 3 days a week. So you need full capability at home. So I think that's kind of accelerated some trends. I think the cloud computing trend is accelerating. I think people are sitting there and saying, where -- how quickly can I migrate off my infrastructure because everybody's been talking about the cloud and say, okay, let's use this opportunity to move our stuff to the cloud and be more robust and sort of more secure. And kind of like they don't want to manage too many moving parts. So you're saying let's do that cloud transformation conversation as opposed to build out more data center capacity, which is more complex in a COVID environment. So you're seeing cloud transformations. You're seeing remote secure work conversations. In some cases, people who are further along their cloud journey, you're beginning to hear them talk about SD-WAN and security in the same breath, saying, how can I get my traffic route? And how can I get it to be secure? So I think that's on the upside. I think there is a general concern that hardware is harder, no pun intended, to deploy in this environment. And you're seeing that in large enterprise hardware businesses, they're pointing downwards because that's all they do. And you'll see that, I think that trend will continue over the next 6 to 12 months. Their hardware is going to get harder just because it's a complex deployment, and it's harder to upgrade and hard to deploy. So I think you're going to see that on the other side. Now outside of that, I think it's just -- the question is, net-net, how many of the customers out there are seeing a positive or neutral impact in COVID? How many are seeing a marginal down impact? And how many are seeing a harsh impact on their own P&Ls, which is causing some degree of consternation or caution in the way people spend money? And I think that's more of a macroeconomic event as opposed to a company-specific event from an enterprise company perspective.
Patrick Edwin Colville
analystAnd I guess, I mean, talking company-specific for you guys, in your results, I mean it seems like COVID's been a pretty major tailwind for Prisma Access adoption. So it would be good to talk about what this tool offers for customers. And then as a CEO of Palo Alto Networks, why you think Prisma Cloud should be a tool that your customers adopt or amass.
Nikesh Arora
executiveYes. Look, I think Prisma Access 2 years ago, it's just about global protect cloud services and is a very lumpy revenue stream for us. A building stream for us. And I think 2 years ago, probably we were lucky to see a $10 million quarter. And this past quarter, we saw 90 -- obviously, it has CloudGenix and there's a little bit of CloudGenix in it, but there's $91 million. That was -- I think it's all been built in the last 18 months. We've paid off a lot of technical debt, hire a lot of engineers, ordered the entire platform to Google Cloud and our larger customers deploying 220,000 concurrent users if they want at any point in time. So it has stood the test of scale. It has stood the test of security, and we're seeing a lot more conversation. In Q3 in COVID, we gave a bunch of free trials and we saw significant numbers that convert in Q4. So we've seen the COVID impact in that number as well. And I looked at these scanners' number, just very impressed they did $195 million. We did $91 million. 2 years ago, we were not in pitching distance or whatever favorite sport analogies. So I'm really excited about the product capabilities we've built. I think the combination of that with CloudGenix is going to position it as a SASE product, which is a must-have product category -- I think where in the future as people do more cloud transformation. So yes. So we're really excited about it. Also it's kind of a substitution product, but you have a choice. If you want to get more remote access to your employees, you can put more firewalls in a data center and run more VPNs, which is older tech. I think in the future, you want to split the traffic, take cloud traffic to the cloud and data center traffic to the data center that requires a solution like that. So I think this product category and the product itself has legs, and we will see more of it in the next few years.
Patrick Edwin Colville
analystI mean your point there about the kind of can [indiscernible]
Nikesh Arora
executive[indiscernible] question, sorry.
Patrick Edwin Colville
analystNo, no. So go for it?
Nikesh Arora
executiveNo, no. You said, tell us why people should buy Palo Alto Networks because you can't take a Deutsche Bank trading application and work it from home using a proxy. You need a firewall.
Patrick Edwin Colville
analystSure. Okay. But so you made a point about cannibalization, which is actually, I guess, fairly interesting. It's -- I mean how -- everyone's investors, everyone likes a bit in numbers, you used to be an investor yourself. So how can we quantify this cannibalization, Prisma Access versus on-prem?
Nikesh Arora
executiveYes. I think, Patrick, what I do internally is I look at the 3 form factors of firewall we sell. We sell hardware. We sell virtual firewalls. We sell Prisma Access. If you add up the billings for all 3, if that number's growing in double digits, I'm happy. Now remember, my firewall has a 6-year life. My VMs are typically 3-year contracts. My Prisma Access are 3-year contracts. So I'm adding 3-year subscribed revenue -- billings and 6-year end-of-life product into one number. It's still going to grow that in high double digits or mid- to high double digits. I think we're taking share of the market. Now there are people out there who's selling hardware, and tracking that and saying that's growing at double -- they're taking share, but a lot of people are -- not a lot, many people we know in the firewall business are low single digits. So I think that people with the high double digits are taking share. We're taking share in hardware and software form factors. Some of these are taking share and hardware form factors and I said hardware gets harder. So I think software wins in the long term. With that, software is the world.
Patrick Edwin Colville
analystYes, exactly. And I guess, in that space, in the software space, you mentioned Zscaler. They've got a great product. You guys -- the number's looking pretty favorable as well. So just talk us through Prisma versus Zscaler? And I guess how you guys win?
Nikesh Arora
executiveI'd say -- I don't think -- this is not the Internet. This is not a zero-sum game. I'm perfectly happy with 40% market share in any category. I'm perfectly happy with that. And if the numbers keep growing the way they are, we will have transitioned the hardware business into a robust hardware and software business. Couple that with everything else we do, I think we're in a good place. I think they have a solution which works in a certain set of customers. We have a solution that works with a certain set of customers. We have 1,500 customers who deploy our firewalls in the Global 2000. We didn't have a product for them 2 years ago, which did a software [ as all ] for remote secure access. So now we have a solution, and they have a consistent management pain that allows them to do what they do in the data center with our software delivered firewall on the cloud and VM. So we have a large installed base to go target our solutions. So I think there's enough room for us to peacefully coexist. It's just that they won't be able to run away.
Patrick Edwin Colville
analystOkay. So for the investors listening, I want to make this interactive as possible. So any questions, please use the chat box or e-mail me, I'm on patrick.colville, which is C-O-L-V-I-L-L-E @db.com, patrick.colville@db.com or use the chatbox. So Nikesh, as it come in from an investor. Q4 was a pretty impressive billing sprint, no doubt. Question from investors, was the Q4 benefited from a pull forward from the first quarter because the first quarter implies a fairly steep seasonal decline? So just any color and context around that would be great.
Nikesh Arora
executiveYes. Truly, mathematically, the bigger Q4 is the lower Q1 looks relative to that. So yes, we had a big Q4. So by definition, Q1 looks a little less interesting than Q4. And there was -- Patrick, it's interesting, in my 2.5 years as CEO, we saw this is nearest to perfect execution we saw in Q4 that we've seen in the company. Very few deals slipped out of Q4. Normally, you see a reasonable number of slip in the following quarter. So there was ample deals that got done. There was a bunch of pull forward. So you did see a great set of numbers in Q4. So some of it is pulled forward. Some of it is customers looking for more certainly signing ELAs sooner than they probably needed to. So yes, so there's some of that that's coming in a comparison. But the other part of the year is we still continue to be watching the market to see that we still see some macroeconomic wins to some of our customers. There is a spectrum. Some customers are getting tailwinds because of what's going on in the market. Some customers are marginally on the upside. Some customers' tech is the only thing working, so they're trying to invest in tech but they're price conscious. Some customers are seeing no demand, so they're revenues are hurting, they're pushing back on everything that they're spending. So we have the same spectrum of customers out there. So we're just cautious of the ones who may not be able to play in the current environment and go with being continued or sustained for longer, causes us to watch on the margin, what's happening on that customer base.
Patrick Edwin Colville
analystOkay. I mean, you touched on this earlier, about the demand for appliance-based firewall. So I guess reading between the lines of your commentary, it doesn't seem like it's the focus. But can we just talk about the appliance firewalls and the metrics to help investors kind of quantify this around either deal sizes, churn rates, closing? Anything that's COVID-19 might have changed that you think is worth probably flagging?
Nikesh Arora
executiveYes. Patrick, I will answer that question, but I will also make a plea to all the investors is this is a very backward-looking conversation. The hardware conversation. I don't mean that the [indiscernible] sense or I do not mean to question the intelligence of the question. But if you look at our business, we have a firewall business, which has approximately $1 billion of product in its billings, a significant $3-plus billion for what remain $2.7 billion of subscription billing. We just connected to hardware but also connect to an extra base of security. And then we have $928 million in next-gen security billing. What's happening is that our product proportion of our total billings has declined rapidly this year relative to the overall purely mathematically by product being flat and everything else going in [ 90-point ] on range. If that trend continues, product continues to become a smaller and smaller part of our overall billings, the quality of that revenue becomes more and more -- billings and revenue becomes more and more SaaS-like in the future. So if you should play the movie over the next 2, 3 years, you will see that product is less interesting about networks, software becomes very, very interesting about the network. If you noticed we started showing ARR metrics. We're beginning to look at deployment rates, net retention rates internally to make sure we understand how to create that flywheel that SaaS companies have. And if you look at this year, I think it was a pivotal moment, $928 million of the billings has shown approximately less than $100 million -- or around $100 million of revenue this year, $300-plus million of revenue will unfold into our P&L next year from our $928 million next-generation security billing. If we continue to grow NGS next year in the $1 billion-plus category next year, you will see that impact also roll into our numbers. Now it has 2 interesting impacts. One is trust by revenue growth for the company in a more sustainable, more predictable fashion because tremendous amount of revenue falls off our deferred revenue into our P&L. And the second part is what people need to just pay a little bit of attention to is on operating margins, we are guiding them to flat because we have a lot of upfront calls on NGS. We have sales commissions that will all kick in. We have deployment costs, which will kick in the cloud hosting costs for proof-of-concept, which are onetime amortized by us or written off by us, and that [indiscernible] which all hit gross margin. So in 2.5 years, you should see some degree of gross margin improvement in our NGS business. From cloud hosting efficiencies and deployment costs normalizing relative to the overall number. And secondly, you should see operating margin expansion because my quality of my year 2 in year revenue is way higher operating margin year 1. So you are going to see the SaaS benefits of Palo Alto Networks in 18 to 24 month time frame, at which point in time the product conversation becomes more. Product is interesting right now because it has disproportionate impact on our P&L from the revenue impact of it. Now having made that plea, I will answer your question. So I'm not playing for nothing. Sorry, [indiscernible] the [indiscernible] product. Look, product -- there are 2 things going on, specific product-wise. One, when a customer walks up to me and says, "I'd like to have remote access for all my customers. I also follow all the firewalls in the data center, can you give me more firewall?" I say, have you tried Prisma Access? Do that because I can give you a software capacity in the cloud, and you can dynamically adjust the capacity base for number of users. So when we get out of COVID, you don't have to be using that anymore. And we aren't [ coordinating ] with everyone, and you don't have to go to 50 different locations that deploy Palo every year because you're driving your traffic from the cloud into your data center for more use cases. So I am preferencing a software solve versus hardware and certain situations, right? So part of it is like I say, you use the word cannibalistic, and that's on purpose because I would rather have higher quality software revenue. And by the way, it's a better outcome for the customer. The cost of ownership is lower, the deployment costs are lower and their upgrade costs are lower. So that's a good outcome for the customer, and it's competitive. As a better advantage. I can do that and many people can't So that's kind of one impact of it. The second impact is a hardware's life cycles are 6-month cell life cycle. And I think in the last 6 months and everybody be being home, COVID, people not being in their offices, logistics, deployment. I think hardware is hard in this time. And I'm just being cautious to make sure that, that impact doesn't hit us and people get surprised and say, oh my God, yes, we get it is [indiscernible], we get it's hard to deploy, but you never realized that. So that's the second part. And the third part to be honest, II think this is more my gut than what data and hard data [indiscernible] all the time. I think the cloud transformation conversations have accelerated in the last 3, 4 months. People are beginning to see, can they move to cloud quicker. And that typically means that people pause data center spend and start from migrating to cloud, start talking about moving to cloud workloads. So I might see more VMs get spun up in the short term because people want their excess capacity in the short term, but they are eventually trying to move to the cloud. Some of them will end up in hybrid situations. All these things call for more software form factor deployment, which is the right answer from a technological infrastructure perspective. So I'm just being cautious. And I'm telling my team, make sure you give me double-digit firewalls to platform growth because that means you're playing in the software space, you're playing in Prisma Access place, I'm less posted about product, but the street seems to be more customer product.
Patrick Edwin Colville
analystGot it. Okay. Yes, I mean, that's a very comprehensive answer. And I guess -- so your guidance was for flat to slightly down product growth. And so is the way that -- I don't want to butcher your words, but that product is Palo Alto's legacy. The future is software and cloud delivered. And so that's kind of flat to slightly down is not really what you should focus on. We should focus on the, I guess, software-delivered form factors, Prisma Access, et cetera, because that's kind of really where the pack is going for Palo Alto, and that's kind of where you want to take them.
Nikesh Arora
executiveI think I'll take that one step up, and I'd say the industry is migrating from a -- needs to migrate from a hardware to software platform solution. And as long as the industry is growing at about 2% to 5% on the firewall side between hardware and software. And as long as I am growing twice or 3x that rate, I'm taking share in the long term. And if you focus on meeting share and the firewall capability out there, I'll be happy if 3 years now with more firewalls platform share than less. And if that means that I'm more biased towards wanting software share than just hardware share.
Patrick Edwin Colville
analystGot it. Okay. I mean on the kind of software/hardware kind of space. I mean CloudGenix, that was a big acquisition you guys did at the beginning of the coronavirus crisis. I mean, what's the feedback been there? SD-WAN is obviously one of the kind of hottest areas in cybersecurity. So just I'd love to talk about the early product feedback in SD-WAN and how that's changing as a result of COVID.
Nikesh Arora
executiveYes. I'll tell you long term, and all these acquisitions we've made, we've made with the point of view of TAM, where the puck is going and where we believe the customer needs are going to be. If you look at what's happening, 2, 3 years ago, when we went to the market, and I joined Palo Alto, we're talking about cloud transformation, people moving to the cloud. So still talking about moving into one cloud. They go to GCP, Azure. What's happened the last 2.5 years is that now suddenly, you're seeing a wave towards multi-cloud. We got 1,800 customers in Prisma Cloud, most of them are multi-cloud customers. They're not just on one platform because typically you end up using AWS, GCB Azure tools if you're just on one platform, but then you're on multiple platforms, and on prem, you start using that. So you're seeing that shift has happened towards multi-cloud. I'll give you a case in point ourselves. When I came 2 years ago, we had our own data centers, and we did everything on our data centers. And that's like, if you want to do a cloud-hosted service like Prisma Access, we should put on GCP or Azure or AWS, we evaluated in GCP. It still took us 12 to 18 months back there to get on to GCP and move 70% of our infrastructure there. So every cloud deal you hear about today whether it is Adobe or Walmart, they're still in the early innings of their journey. They're going to take 2, 3 years to get most of their applications in the cloud. But let's assume that 2 to 3 years from now and some different people on different cohorts. When that move happens, 20%, 30%, 40% of traffic's in the cloud, it will make no sense for me to take all my traffic back to my data center because I have to go to the cloud, half my traffic has to go to the cloud. At that point in time, you got to get rid of expensive MPLS and go with SD-WAN. That it's important for SD-WAN to be secured. So I think the puck is going to secure SD-WAN, secure box or secure edge, which means you need both security and networking in a single product. So we're really going to security. We're leveraging a lot of Google networking underneath it, and we're going to leverage the SD-WAN capability of CloudGenix. That's how we'll deliver a SASE solution to our customers. So tomorrow, when a large retailer says, wait a minute, half my traffic is going all the way into the cloud. Why do I have expensive MPLS lines going to my data center, which are large cable lines going in there, let's rip that out. And you'll see, they'll see 50% cost savings ripping out MPLS, putting SD-WAN in. So this is a category that pays for itself over time. So I think it's still the early innings of SD-WAN. But over time, you need SD-WAN and security to be best-of-breed and be able to combine to be able to win those deals.
Patrick Edwin Colville
analystAnd would have cloud units bring that you guys didn't have stand alone? You guys have a phenomenal R&D team. And so what are these -- do this kind of scale up bring that you guys didn't?
Nikesh Arora
executiveTwo things. What happens is that, first of all, if you deploy an SD-WAN, there are components in SD-WAN and there's an architecture of SD-WAN. The components are our firewalls. Our firewalls can do SD-WAN capabilities, so can other people's firewalls. And Palo Alto firewalls [ can do ] SD-WAN capability, you can put them into an SD-WAN architecture and be able to use them because you need to talk to both sides. Point A needs to talk to point B to figure out what's the least cost routing for getting the traffic there as fast as you can. So our firewalls have that capability. Our controllers have that capability, and you can put our firewalls into SD-WAN architecture. The question is, can you use me as a management control pain to manage that SD-WAN architecture? We didn't have that. That's what CloudGenix did. And it's based on -- they actually deployed on the cloud. They actually use some very interesting AI, where they actually don't have to talk to both ends. They can based on AI, they can figure out the lease cost routing. And give you a cloud-delivered SD-WAN pain. Couple that with the cloud-delivered capability of Prisma Access, we can merge those 2 into 1 cloud ping and say now you can SD-WAN metrics and security at the same time because there's a lot of interplay between networking and security, right? If you want to go from point A to point B this way as opposed to this way, that's SD-WAN telling you do that, you want to make sure you're security in lockstep with your packets moving across your network.
Patrick Edwin Colville
analystSo to paraphrase it back, it's more the management [ plane ] and I guess the networking components that they brought to the table and is kind of really, I guess, thawed out the product set?
Nikesh Arora
executiveWell, they've been -- they've been at it for 7 or 8 years, right? So they've developed expertise in the whole networking piece. And yes, I've got a great R&D team, but my R&D team, 90% of the time is focused on security and on networking. So I needed the networking [ comp as well ], which is what they bring, and we bring the security competence. And because they've run longer than as a Prisma Access only around 18 months, they have a lot of customers they bring, which we can go down pitch Prisma Access to and vice versa.
Patrick Edwin Colville
analystYes. I mean, I guess in your 2.5 years as CEO, there's -- you've done a number of kind of tuck-in acquisitions. That's been something that we've seen, it's been a strategy of yours. I mean thinking about the product portfolio, thinking about the cybersecurity landscape. And where do you feel that there could be areas that there might be need for Palo Alto to address any holes or [indiscernible]
Nikesh Arora
executiveIn the last 2.5 years, we've looked at every part of the security market and seen which part is there value for us to play in and which part is there no value for us to play in, right? And do we play organically or do we play with M&A? So I'd say cloud security was a blue ocean. There is not many players out there. We made 4 acquisitions. We've integrated 3, we'll integrate the fourth from next month. And we win 7 or 8 out of 10 deals. That was an opportunity. We looked at it, we grabbed it with Prisma Cloud. We think that's we're in a good space, and everybody is now going to trying to play catch-up. So I see, I hear every day that some CASB vendor is building CWPP and CSPM. I hear that McAfee is building that capability. I heard that [indiscernible] is building cloud security. CrowdStrike's building cloud security. So everybody's figured out there's a market there, they're chasing it from their vantage point where we spent the time and effort. We think we're 18 months ahead of most people in the cloud security space with the integrations we've done. And that was blue ocean. There was a category where remote secure access, as you saw, which one company was running away with it, and we basically intercepted. We started Prisma Access with about 200 engineers on the project, with [ GCP ] back plane, and we deployed our go-to-market teams against it. So we felt -- now we are -- maybe we want to do 1 or 3 in that space or reckoning that everyone have to get away from VPNs over time. So VPNs are going to go away, and this is going to be the new way of accessing remote branches and remote security. So those areas, we did what we needed to do. On the firewall side, we don't do much acquisitions. We fell to one area of IoT security where we took a differentiated approach and we said, look, we're just going to make it easy to deploy from the firewall, so you don't have to go put another appliance in there. And that's kind of our subscription strategy in firewalls. We did that. And the other category we have built over time is the XDR category where we compete with CrowdStrike, which, again, there was CrowdStrike [ Silence ], Carbon Black, and Cybereason. I don't know over [ Silence ], I think it's somewhere out there for the refractory. Don't see the much Carbon Blacks or VMware, CrowdStrike. CrowdStrike [ ported relished ] [indiscernible] seen. We are #14 on a list of 10 end point vendors. Now we're in the top 3 where we get consideration forever because we beat some of the competitors in the [indiscernible]. So we've built capability in end point because we believe that's an area, which is a must have. We've built capability in data analytics, ML and AI, which I think is the frontier -- next frontier, so I was [indiscernible]. And if you think about it, that's where you will see us focus more and more to make sure we get more and more of a robust capability in ML and AI because I think that's the frontier or that's what allows to do instant remediation. Today, cybersecurity still takes 50 to 60 days to solve a breach. I think that's too long. I think by that company, it's going to be shut down. And the financial service institution has been breached over 3 days. I think the SEC will ask them to shut down. So you can afford keep opening up your infrastructure to customers, to vendors, to third parties to go to public cloud. You can't afford off-line security.
Patrick Edwin Colville
analystGot it. And I guess, I mean, in the AI, ML, the space that connects cells in is when you're doing a lot of log management and log crunching. So is what you're referring to, that kind of SIM saw security operations type area, that's kind of where the -- you're seeing most kind of, I guess, interesting developments?
Nikesh Arora
executiveYes. I think it's more than that. Patrick, to be honest, I think it was the last generation was log ingestion and SIM. And I think that's, again, it's very off-line. Like log-in just as dump a lot of security data and then everybody has apps on how to curate the data. It actually doesn't do much online remediation. There's no like cross-correlation happening online. So there's a bunch of companies that do data ingestion and data dumps. Then there's a bunch of companies that take that data and put all alerts into a billable screen and say, no, data customer put some rules in to tell me what is more important. Well, if I've got to tell you what's more important as a customer, what's your value add as a security company? Give me all your data? Write your own rules? What is that, a UI? That's what next generation -- that's on the premise. So what we've done is saying, we're not going to take data dumps. In XDR, we take all the data from an end point, we cross-correlate that with -- with firewall data and say, "Hey, this alert is on the end point and the firewall, it's the same thing. We're cross-correlating, reducing that by 50x. So we're actually adding value by reducing it then, we're running behavior analytics against that stuff to tell you what's most important. You just ingested identity data and start telling you, "Hey, we can cross-correlate those identities too." So what we're doing is we're building a single normalized data lake against one set of source of truth. So the only way you do ML and AI is, you have to anchor on some source of truth. If you don't anchor on the source of truth you can't do AI. That's where the big difference is. We don't ingest everyone's data. We ingest what we believe is good quality data. So if you want AI, ML solution, you have to take XDR from us. Without it, we can't do AI, ML for you. And then if you take XDR, we can keep [indiscernible] more and more data in enterprise against it, which we are building more and more capability. Once you can do that, we can tell you, don't bother about these 5,000 words. They're silly because they've been cross-correlated to do the same thing. There's just different ways of looking at that thing. Today, what customers do, they'll take constructs from one place, Palo Alto firewalls another place, Prisma Access, there's no correlation on [ keep ] data pieces. If I take my XDR and Palo Alto Prisma Access and firewalls, I can cross-correlate and reduce the number of alerts by 50x. That makes the life of a stock analyst a lot easier. In our own stock, they've gone from 50,000 alerts to 500 events that our teams look at. So you've got to get to some degree of elimination of [indiscernible] in the cyber industry.
Patrick Edwin Colville
analystAnd so -- and I mean in XDR, I guess, the acquisition of the Crypsis Group was something that you guys made in your results last month. I mean, just talk us through, for those who don't know about the deal, what they are, what they bring? And then I guess why you needed to do it? What was the kind of reason to pull the trigger?
Nikesh Arora
executiveYes. It's interesting, Patrick, one of the things as we analyze the competition, as we analyze the market, realize that there are SI channels. You can go to Accenture, Deloitte, you can go sell with them. There are SP telcos who will sell with you. But these are all peacetime efforts, right? A word time effort is when somebody has an incident who responds. That's when they needed the most. So they will typically call Mandiant. They will typically call CrowdStrike. Nowadays, they'll typically call Crypsis. And CrowdStrike will lead back CrowdStrike. They've announced the earnings that they [ won ] is to $3.77 of the product lead behind our incident response. FireEye still manages -- Mandiant still manages to get behind FireEye products, I don't know why, but that's fine. And we're sitting there saying, we've got a great product, but we don't even see these 1,500 incidents that breaches that happen because we don't know when it's happened. Only tells you when they're being breached or been breached. So this way, now we have insight into 1,500 breaches where Crypsis goes in to solve the customer's problem, and we can help with our tools and hopefully, that if we can get anywhere close to CrowdStrike, leave behind I'd say, nice jump on our XDR business, which is 6 months old. So yes, I'm -- Crypsis is actually well-run business. Their gross margin is not quite like software gross margin or [indiscernible] gross margin, but they're not bad. And if I can couple that with a product lead behind, I think that's a huge opportunity for us. And we didn't pay -- we paid services company type multiples. So it's not a SaaS company multiples. If we paid to acquire the business. I think they were just -- they fit perfectly into our Cortex strategy of being in -- giving us the heft on the IR piece, which some of the competition has which we don't.
Patrick Edwin Colville
analystAnd then what's the time line for integration for this vision to become a reality? I mean, are we talking September 2021.
Nikesh Arora
executiveCrypsis does not need integration. They have a product called Hadron which is 10 people. We should be able to integrate that in 3 to 4 months into XDR. But they don't stop them from doing their day job and going in and telling people, hey, we're part of Palo Alto Networks. And if you think the product, we know a product that you can use. They're not using our product to remediate a breach. They're just going in with their own product called Hadron. They'll do the remediation and they'll -- if interested there to bring our Cortex sales team and give us a lead.
Patrick Edwin Colville
analystGot it. Now could we switch gear to public cloud? Because you briefly touched on it earlier, but I think it's critical to double-click here. Pretty sure no one will disagree that this coronavirus has proven that the public cloud delivery model works great in the enterprise. And the likely outcome is 2020 to 2025, there's going to be an acceleration in public cloud adoption. And just trying to think Palo Alto's positioning in that new paradigm, I think probably the biggest question really I get from investors is the dynamics between independent software vendors and cloud service providers. There's this kind of frenemy relationship that's why -- if I'm a CSO, do I need to layer on Palo on top of my GCP, AWS or [indiscernible] environment?
Nikesh Arora
executiveI'll give you a very simple answer. There's 1,800 customers who felt it important to layer on Palo Alto networks. 2 years ago, you can ask me that question. 1,800, we cover 43% of the Fortune 100. Why? Because everybody has multiple cloud providers. You can go deploy containers with Microsoft, with Azure -- sorry, with Azure, with GCP, with AWS and with VMware. Now which container security product you're going to use? You can use a Microsoft product. Well, it kind of doesn't work in integration with the AWS and GCP. Which one are you going to use? So typically, moment customers ends up on multiple platforms, we're kind of like we're neutral because we don't have a cloud platform so we have to make it work with everything. So we can do a [ teaser ] platform. We can work from various security [indiscernible] security between platforms. We can now take serverless and make it with one agent with container and serverless. We have the same agent that will work with segmentation with Aporeto. With the same agent that's going to work with our WAF perhaps. So we have 1 agent across 7 -- 5 modules, and we have 7 modules that work together. So even if you were trying to replicate what we do, you have to self integrate these 3 modules from AWS and 2 modules from GCP and 3 from Azure. So if you want customers to spend their life trying to integrate across 7 different security stalls across 3 different clouds, they can. But it's way more efficient for them to use our product. And our products have APIs into the native products of cloud providers. It's not like what we generate our own data. We're taking their data from the AWS, GCP, Azure. We're just launching a product called IAM, identity access management, to the cloud. So if you have a developer, he's developed on AWS, on GCP and Azure, as a manager, CIO, your choice is to give them rights for each platform in each of the native tools. Or we can give that involve to IAM, and we will just, through APIS, deploy that capability across all cloud and make you consider. That's kind of like Okta, right? That's what we do, which is doing it to the cloud use case is connection to workloads and security. So you can see where only [ 100 million ] exposure. So the reason we get in is because of the fact that customers are multi-cloud. The hardest customers for us is going to say, I'm only going to one cloud and not going anywhere. So there are customers out there like that, but less and less.
Patrick Edwin Colville
analystAnd I guess, when does this hit numbers because we can point to a number of kind of fairly big companies in the end point space, in the SASE space. In the public cloud security space, there are any kind of companies with significant revenue streams, which suggests to us that a market is still fairly nascent. So when does this translate into hitting the P&L and looking kind of interesting? And I guess why now?
Nikesh Arora
executiveWell, I'll tell you why, because 2 things. One is, we've all been hearing about the public cloud. If you go ask your own companies, whichever companies or your customers and say, what percent of your public cloud transformation is done? And I'll wager you that the average answer you're going to get is 15% to 20%, right? Walmart's not done. Adobe's not done. Palo Alto's not done. We're in only 60% rate. But we move fast us because we have products that need it. So you go around the 2,000 -- Global 2000, 90-plus percent of those are legacy businesses, not 10%. It's like, yes, Airbnb is done. Lyft is done and Uber is done and DoorDash is done. Those guys are done, and that's where they started. But most traditional guys are not done. So as you see more important workloads move to the cloud, people get more conscious about security. They're not conscious you don't have your most critical application. Most critical applications are running in your data center. DB has a -- you should go to a CIO and ask him how much of mission-critical stuff is in the cloud. I'd wager a guess that he'd say none. So do you need to secure that stuff? Probably not. You put your trading system in the cloud, you better secure the d*** thing. You put a customer account, they're not even secure. So the reason it's now is because people are starting to move mission-critical applications on the cloud. When they do, they want to make sure that their stuff doesn't get breached. You've seen Capital One, Target, all these guys move stuff on the cloud because they had -- and they used some of them will use open source security solutions, which is a bad idea, do not use things that people contribute to for security, generally speaking, that's not a good idea. It's like going and buying a lot that was made in a nation-state, which doesn't really put the key strike. So don't do that. So from that perspective, now because people are beginning to think about moving mission-critical workloads into the cloud. Now because you're seeing the migrations begin to pick up. So I think we confuse ourselves. You can see the big cloud deals, they take 3 to 5 years to deploy. [indiscernible] so there of scale, yes. Like we -- as I said, we've been in 7 out of 8 deals, we lose to people who are on a single cloud. So we lose to people who are looking for a point solution where they've gone and done a deal with somebody and negotiated a really good price for one piece.
Patrick Edwin Colville
analystGot it. Okay. So if I was to paraphrase that back, it's that mission-critical workloads are not yet running in the cloud for the bulk of enterprises. And when they do, that's typically when you get the attach of security, if I understood you correctly. And I guess -- so the way I should think about it as an investor is that kind of that goodness is still to come. That we know that at the moment, it's about building footprint, but the revenue impact is kind of in the out years.
Nikesh Arora
executiveLook, it's a good number for us from where we acquired all these companies, they barely had any revenue or any billings, and we are beginning to see it become more and more interesting in our numbers. But yes. I think what will be interesting is 3, 4 years from now, you'll turn around and look and say, wow, that's amazing. Your thousands of customers in cloud security and their workloads continue to increase so renewals will get more and more interesting because don't forget we sell into it, but -- and I honestly ask all of you to go back to your own organizations and ask them how many workloads have you moved to the cloud because the financial services industries is notorious for not having moved yet. And you'll realize, if you believe 30%, 50% of those are going to end up in the cloud 4 to 5 years from now, they're very security conscious, you'll find that there's a natural tailwind associated with cloud security, which will effectively become more and more real as more and more step moves.
Patrick Edwin Colville
analystSo again -- I mean, interesting because your point earlier was in firewall, we're moving from a world of appliance-based firewall to kind of SASE and, I guess, cloud-based firewall and that we're in a bit of a pocket of air as the subscription revenue, I guess, makes up for the shift from product. And so your point here is in the kind of, I guess, the public card security space, that's to ramp. I mean -- so I don't want to give you -- put you in a spot and make you kind of give long-term guidance. But I guess, is the way that one can think about it is that we're in the transition phase now, and a lot of these kind of engines are firing, but the financial impact is going to come in a bit?
Nikesh Arora
executiveI don't think that's fair. I mean, I think like we grew billings at 32% this year, so that's financial impact. I think we billed $928 million of next-generation security this year that grew at 105%. So I hope that's financial impact. I think that shift you're seeing is that the $928 million of billings, [ insure ] of $928 million of revenues because that was hardware firewalls, it would not be in a transition, we do $1 billion more of revenue. But if you look at my deferred revenue spiking because all that stuff is getting ware into the balance sheet and over time is going to unfold into my P&L. So I think -- we think if you have a leading indicator, it's got building. Leading indicators got deferred revenue. And that's what happens when you do a hardware and software transformation and beat not growing the billings at 32%.
Patrick Edwin Colville
analystAnd I guess my final question is about on the cost side. That you're in all these areas. You're in firewall, you're in EDR, you're in cloud-based security.
Nikesh Arora
executiveYes.
Patrick Edwin Colville
analystSo is -- you guided for flat margin year-on-year. Is the thinking behind that, that you basically you need to compete again the best-of-breed vendors on those spaces and that you're optimizing for the top line?
Nikesh Arora
executiveYes, partly that, Patrick. And partly, I think it's the transition impact, right? So the more I shift from hardware to software, the more my billings keep rising, but my revenue is for a later period in time. But my costs are still real right now. So what happens is, my costs are all upfront. So if you take a look at typical SaaS company in the first 2, 3 years of their type of growth years, you will find there's margin compression and that margin expansion happens after 2, 2.5 years, when you begin to see that revenue falling off the deferred revenue line and showing up on your revenue line and your revenue growth rate continues to stay solid for a long number of years or many number of years long as you're growing your billing. So I think we're in that phase. We've had 1 year of hyper growth in our billings. Hopefully, we continue this for a year or 2 more, and you'll start to see that revenue unfold on to our P&L, and you'll start to see our margins expanding by themselves. But for now, you're seeing us load up front end for sales cost, deployment costs, cloud hosting costs, which also will scale over time. So you're seeing the margin compression gross margins and operating margins, which if we separated the 2 P&Ls for FMAP and for NGS, you will see them mirroring what you would expect a steady hardware business versus a SaaS business too if you put them together.
Patrick Edwin Colville
analystGot it. Well, a lot going on. Still fascinating times at Palo Alto Networks. Thank you so much, Nikesh Arora, CEO. I really appreciate the time. Have a great rest of the day, and we'll keep following the company closely.
Nikesh Arora
executiveIt's time for you crack that ball of [ kianpi ] given where you are. Thanks.
Patrick Edwin Colville
analystCheers. All the best. Bye-bye.
Nikesh Arora
executiveBye-bye.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Palo Alto Networks, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.