Synopsys, Inc. (SNPS) Earnings Call Transcript & Summary
October 4, 2022
Earnings Call Speaker Segments
Lisa Ewbank
executiveGood morning, everyone. I'm Lisa Ewbank, Vice President of Investor Relations. Welcome to our inaugural Synopsys spotlight for investors. Today focused on the Software Integrity Group. It's designed to provide a little bit more information and perspective than is doable in a brief conversation, and we hope you find it valuable. Jason Schmitt, GM of the Software Integrity Group, will take us through some market and customer dynamics, our solutions portfolio and go-to-market efforts, followed by a Q&A session. Before we start, a couple of housekeeping items, there is an ask a question box at the bottom of the webcast window. Please feel free to submit your questions at any time. Also note our safe harbor statement. We will discuss forward-looking statements during the webcast. And while they represent our best current judgment, our actual results are subject to many risks and uncertainties. Please review our most recent SEC reports, for a full description of factors that could cause results to differ materially from what we expect. With that, I'll turn it over to Jason.
Jason Schmitt
executiveThank you, Lisa, and thank you, everyone, for joining and giving us the opportunity to dive deeper into the Software Integrity Group. I'll start off with a snapshot about exactly who we are and what we do and then address many of the things that Lisa talked about in terms of market opportunity and how we're uniquely configured to address it. So starting off with a snapshot on what is software integrity? So from our perspective, there is an important baseline to understand that software is everywhere. You hear about it quite often. And what we are in software integrity are a set of solutions that basically enable organizations to manage the security, quality, compliance and reliability of any type of software at the speed of their business. So there's a lot that goes into that. But what you have to consider that we serve organizations of all types of software from embedded systems, including semis and systems all the way to enterprise IT use cases across many industry verticals from financials to automotive. So what you see is product security use cases all the way to the software that's running the businesses that you all are a part of in a sense. So that Software Integrity element of what we do is about securing and creating reliable software at the speed of the business of all types. For that business today, that rolls up to $449 million trailing 12-month revenue at the close of our third quarter. So that gives you a perspective that you're familiar with the size of the business within Synopsys. Of course, later, I'll talk about where that fits in the market. So a little bit more about what the Software Integrity Group is. And that's the collection of solutions that address that security and reliability of software, as I said. But first, to kind of set up an industry product baseline and the way that all of our customers go after solving the software security challenges. So at the most fundamental level, all software is built in the same way from design through operations with a series of processes, whether this is iterative or waterfall or any sort of approach, any type of software is ultimately coded and tested before it's deployed. So the application security testing market, as it's defined by independent technology industry analysts really apply some categorization of the techniques and practices that are commonly used, and you see them here to address solving software security challenges at various parts of the software development life cycle. And so what that means is there's a series of point tools that are often applied and then a solution set of services that come from the perspective of everything from management consulting style services for program strategy, development, all the way to implementation services and services to actually automate and run this security activity on the -- on behalf of customers and organizations. And so as a baseline, that's how the industry addresses it with tools, processes and services. The way the Software Integrity Group's portfolio is aligned, it's essentially taking the broadest portfolio of software security tools that addresses each of these categories of security testing and security remediation and applying automation to it so that our customers can do it at scale but also doing it in such a way that we address all key personas throughout the challenges of securing software in this way. I'll go in more into what that means in a little bit. But the key is it's a much bigger challenge than just handing tools to people to run to do testing. And so what we've also done is augment the software tools that we've had for quite a while with a fast-growing set of SaaS offerings. So Software-as-a-Service that's designed to create lower time to value, much lower total cost of ownership and much lower expertise required of the average customer in able to -- in order to be able to operationalize these solutions. So our SaaS offerings are capturing a part of the market that's fast growth and maybe what you might call the later adopter stage of the market. And then we wrap all of that with the foundation of strategic consulting that is leading in the industry in terms of setting the stage for how strategy is developed around building trust and software all the way to teaching organizations to operationalize this themselves and implement these solutions for them. But from a business outcomes perspective, these are the things that we think of as the problems that we saw. So we don't seek to just try to sell tools. We try to work with customers strategically from a holistic solution to software risk because what we often say is now software risk is business risk. And so what that means is they're not looking for just testing tools, they have needs to secure the software development life cycle when they're building software themselves. They have a need to put governance and risk management around their adoption of open source because open source is a key innovation driver, and we want to create the ability to capture value from that and not let security issues get in the way. Then there are key issues that our customers run into in modern software around cloud transformation, whether it's lifting and shifting old applications or net new cloud native development, these are the types of things that our solutions are designed to solve so that the business outcomes are enabled rather than slowed down by security programs. And then we apply this to the complexity of software supply chain and embedded systems. So software is embedded in everything that we're using today, of course, to have this conversation. And there's a lot of rigor that has to go into how these things are constructed all the way from the hardware layer to the software richness of the screens we're looking at. And then finally, there's a unique business within our consulting group around M&A due diligence, which is essentially what we call our Black Duck audits business, which is really any M&A transaction for any business that has software, not just technology businesses, we do fast turn software due diligence to give the acquirer an understanding of the risk and the software from quality problems, reliability, security or licenses. So that's the full scope of the solution set that we apply to solving those business challenges. So that gives you an idea of who we are. And now I'll kind of take a step back in the market landscape as we see it and why it's a very lucrative opportunity for us to continue to find solid growth. From the market perspective, I no longer have to start these kinds of presentations, convincing anyone that the security threat is real. I think it's headline news practically every day. But what we focus in on is that the new security reality is that software is the #1 attack factor. And what that means is in the successful breaches that you see in the news or feel in the financial repercussions from companies that you watch. Software is the #1 attack vector in the sense that software vulnerabilities are exploited. You see in this Forrester survey software vulnerabilities and web application exploits are the #1 and #3 mechanism for attackers to gain entry into a system or compromise a technology system to get into a business. And then supply chain third-party breaches are just another variant of that same thing. So these have become even within some of the other types of things that you're very familiar with, like fishing and malware and things like that, they're all exploiting software vulnerabilities in order to capture this sort of attack. And then from another very reliable data source in terms of roll-up aggregation of all the breaches that happen every year from Verizon, you might be familiar with the state of breach investigations report. Again and again, they see web applications as the #1 attack vector in breaches. And this isn't just saying this is the most popular attack vector in terms of what everyone is trying. It's solidly more than 40% of all breaches are coming in through the web application layer, which is purely software vulnerabilities that are being exploited in order to do that. But in the face of that being the #1 attack vector, we also see that software complexity is continuing to grow almost unbounded. And the reason that is the case is because software is driving businesses through transformations and innovation that is unheard of in history in terms of what technology is creating, but the reason software is growing more complex is because the sources of software are becoming more complex, more numerous and more opaque. And so recent attacks of software-based systems that you are likely aware of like SolarWinds as a supply chain breach, Log4j as an open source component that really brought boardroom and White House level awareness to the challenge of the software security or the software supply chain because open source software is literally everywhere. And it's not always used wisely. As I said, it's a key contributor to the innovation and the fast delivery of software systems that is really bootstrapped by the adoption of very powerful open-source software. But we see again and again that as you see some statistics about how often code bases that we see are powered by open source software. So we see 98% of software through all the audits that we do contain open source software. And many of them, as you see 85% contain very, very old open source code. And so while we're adopting it for the richness that it brings and the speed of delivery that enables businesses to adopt the problem is only getting worse because it's getting so pervasive. So with the fact that open source is everywhere, it's really something that has to be solved and it's become a much more top-of-mind issue for all businesses and especially the security teams within them. But then another thing that we see is back to that point I made, there's a lot of tools that can be applied to solving these problems, but they address really just a piece of the problem. But organizationally, there's also conflicting priorities and ownership for who actually owns the security of the software that runs a business. And it depends on what type of business it is. But when it comes down to it, the security team is responsible for proving that the software that a product company delivers is safe and secure and that an IT organization is safe to keep the customer data, the crown jewels of the business safe. And so given that it's the #1 attack surface for cyber criminals, the security team is really paying much more attention to it than they were even 5 or 10 years ago. But they often are at odds with the sources of software. So security teams don't create the software and they don't buy the software, but they're responsible for its security. Yet the development side of this has a very critical role to play. But the conflicting priority here is development teams are measured by their velocity. In other words, how quickly can they release the functionality that they're paid to deliver? And is it meeting the functional requirements of the business. And is it powering that differentiation and edge in the market that businesses are looking for. So their #1 priority in development is not security, it's to get the code out that solves the business problem that they're trying to do. So developers will reject tools or processes that slow them down. And then in the face of that, the business risk is yet another constituency that really has to be managed here because, as I said, software risk is now business risk. It's not something that's just relegated to a risk line item within the overall cybersecurity view of the board. It's something that can have existential, reputational and financial impact on the business, given that it's such a lucrative attack vector. And so when a business risk is trying to reconcile the priorities across the common practices that are used to try to solve these problems. You really have a complex challenge. What that translates into in terms of market opportunity for us -- as you see, the serviceable market from our view, is in the ballpark of $2.5 billion to $3 billion this year. And although this is still a very fragmented evolving market, we see consistent growth at around 15% every year. And so that serviceable market has expanded within that overall TAM through not only just the overall market growth, but the ability for us to continue to address natural unserviced areas of the market with some of the solutions that I talked about that are designed more for the lower-skilled sort of organizations that have a lot to lose, but not a lot of security talent. And so the growth drivers that impact that and drive us at that rate or one of the major drivers is just the growth of software. So the pure growth in the baseline of how much software is produced and the cloud transformation that's driving a lot of that development is a key driver within this market. but also those complexities that I talked about, the risk of breach, the pervasiveness of open source and then the complexity of trying to manage software from all these different sources are what's making this a more and more top of mind challenge for board level views of risk but also IT and security budgets and how they apply it to solve these problems. Now with that market opportunity and the glimpse into what our Software Integrity business is about. Let's talk about the vision for how we're addressing this. At the vision level, what we're about is building trust and software. And what that means is it's not a very simple thing to say we just want to remove all security risk from software because it's not that simple. But in terms of building trust, we focus on something that is an aspirational attribute of software that has gone through a process where people, tools and the processes are aligned with that goal of really looking at all sources of software, whether organizations are developing it themselves, outsourcing it to someone else, downloading and adopting open source or even buying and procuring third-party components from another vendor. The scope of what we have to look at is all those sources of software and then give our customers a unified policy view for how to manage it according to the needs of their business, visibility and transparency into how all of the security risk is emerging from the collection and evolution of that software. And ultimately, how do you prioritize all the efforts around eliminating or mitigating the risk that comes from that. And so with that cohesive integrated platform, we take this complete security assurance view for all sources of software, and we believe that's the only way that you can instill trust in the software that's running a business. Now on the other side of that, we think about the customer demand drivers. In other words, what are the issues that our customers are facing in light of that comprehensive view of end-to-end software security assurance. And that's looking at the business initiatives that are driving what they're trying to do to remain on the leading edge or stay competitive. So I mentioned cloud transformation that has a profound impact on how security teams and development teams think about creating trustworthy software and how do they do that in a systematic and consistent way. And then the software supply chain notion of we're not just developing all of our own software. Most organizations are getting it from many, many places without having a real reliable view of how secure is the software coming from all of these different sources. And so that's something where the visibility and transparency across all software is super important for our customers to have that ability to understand can they trust their software that runs the business. So that's the view of -- from a vision perspective for how do we bring solutions to market to solve these problems from the business standpoint of let's reduce the business risk that comes from our necessary dependence on software. So we'll look at the overall portfolio of solutions that we bring to that. So I'll start with -- I mentioned earlier, we're essentially a collection of solutions that are made up of software, SaaS and services. So I'll go to each one in turn. So starting with our software portfolio. This is a suite of tools and capabilities that start with the ability to test software at various points of its development and enable developers and security teams to remediate security problems as early in the software life cycle as possible. And so what that looks like is in each of these solutions, Code Sight is built for developers so that they can do this as they code. So literally, spellcheck like feedback as their coding on both code level issues as well as open source issues. Our Coverity suite of static analysis solutions is really about source code review of any type of source code from embedded systems to enterprise IT so that teams can find as early as possible in the process where they have code level security or quality issues, even reliability performance issues can be identified that way. Then Black Duck is our software products that address the open source challenge. How do you put in place governance testing and remediation at scale around the adoption of open source. So that's the key enabler for people to really lean into open source as a creator for innovation and doing it in a secure way. Then we have a software product called Seeker, which is about really doing transparent interactive testing while applications are in development. So this really goes to the web application challenge that I talked about and how do you find security issues as it's being developed in testing environments and even in production environments. Defensics is then now yet another testing technology, which is applied to any sort of system that implements a protocol for exchanging information. So from telecom to networking to any sort of hardware embedded devices that has an interface, Defensics is used and as a market leader for testing those interfaces so that communications are secured. Then Intelligent Orchestration and Code Dx. These give us the opportunity to then apply automation across all this testing in an intelligent way that can be policy and AI-driven and then Code Dx is our way of aggregating this information across thousands and thousands of applications and give with some intelligence and normalization and machine learning, essentially prioritize the risk from all these software products that are discovered across thousands of applications in the average customer. So that's the foundation of the software products in the portfolio. The next level down is, as I mentioned before, some fast-growing SaaS applications that we've developed each on those core technologies, but delivering it in an integrated SaaS platform. So many of the capabilities that I talked about above in software, that same technology is leveraged in this Polaris Software Integrity SaaS Platform that enables us to be consumed on a much faster, easier way to adopt, but also gives you a comprehensive view given that it's a SaaS platform, providing insight for managing the risk in the software supply chain. So it's not just about scaling out testing, it's about creating the insight around bringing this together. But what this also gives us the opportunity to do with our SaaS platform as well as Code Dx. We have opened up our ecosystem so that we can apply this intelligence policy and visibility to any application security testing product, not just those from Synopsys. So that's what we believe is the first of its kind in our market to really be able to give a consolidated comprehensive management of any testing products, whether they're from Synopsys or not because the fact is there's lots of disparate software within most organizations and that insight and visibility across that entire portfolio is necessary. And so pulling in that information with pre-integrations to any sort of security testing tool is what that creates. And all of that's built on the foundation of expert consulting around building AppSec programs, strategy and implementation services and the ability to actually operate these programs on behalf of customers. So that makes up the services component, which is really about codifying the expertise that we have and having done thousands of these programs and implement these products in an equal number of customers in order to solve those challenges that we talked about. So now with that portfolio view, let me turn to the go-to-market strategy. Many of you are familiar with transformation. We've taken the software integrity business through over the last 2 years or so. And a major part of that has been a 3-pronged go-to-market strategy, which is designed to take the strength of that very comprehensive portfolio and bring it to market in a, let's say, a consistently executed and scalable way. So number one, there is build a global scalable and leveraged, and I'll come to what that means, go-to-market engine, so that we can address all of the different constituencies, developers, security teams, the DevOps groups that sit between them often so that we have the ability through a single sales organization and go-to-market engine to bring all those products and services to these buyers through a single distribution engine in a sense. And that's more from the selling and marketing side. But what we also do is lead with that strategic consulting when we can because that proves to deepen our relationship with the customer, starting with a trusted adviser relationship that's even agnostic to product and tools adoption and look at how can we take that customer from where they are to where they want to be and then drive them through that journey based on a very methodical process for based on having done this hundreds and hundreds of times with a proven record of not only leading our customers through these journeys, but when we do it and start that way, it improves retention, it improves product sale into those organizations and post-sale customer success. So the depth of relationship that comes with that strategic consulting leads to many great things downstream on the product side. Now to the leverage part. A big focus for us over the last 2 years has been driving incremental growth and expansion into new geographies through a channel program that's really about partnering meaningfully with systems integrators and value-added resellers. So together with that scaled out go-to-market engine, the partner capability allows us to really add reach and incremental growth on top of it in places where we can basically enter new markets, new verticals faster win more often without having to hire teams and ramp them up. So that partnering has had a profound impact on the growth trajectory over the last 2 years, and we expect to see a lot more of that. So what I can give you a glimpse up here is just as an example, what the partner business is allowing us to do to expand reach. So this is really just a view of new logos in the business through partners over the last -- throughout FY '22. So it's allowed us to enter double-digit new countries without hiring sales team, working through partners that have trusted relationships leads to more multiproduct sales and higher win rates. And so we're seeing the fruits of a commitment to selling through partners and really making that a partner-first mentality. So now I'll close this last section on giving some external validation, both from market analysts as well as customer success stories that gives you a perspective on what others think about everything that I've talked about. So I'll start with Gartner. I assume most of you are familiar with Gartner as leading technology analyst, they for many years, have had a Magic Quadrant dedicated to the application security testing space. Synopsys has been named a leader for 6 straight -- not 6 straight years, 6 straight iterations of this, which roughly translates to years and has been the most top right for 4 years in a row. And if you're unfamiliar with the Gartner MQ, it really signifies their view of the ability to execute on one axis and the completeness of vision on the other. So how well do they do in the market and serving customers and how well do they do in terms of bringing innovation to market and really pushing the envelope on what's possible. And so you see that validation there is really important for us from an execution validation. But they also create something called critical capabilities in many of the IT markets that they cover. Critical capabilities assesses in our case, 5 different categories at the technology or product level to really give another view of the portfolio. And for the first time ever, Synopsys has been named #1 in all 5 categories. So these are things like DevSecOps and mobile and client testing and enterprise and continuous testing. So you see validation both on execution portfolio, vision as well as the technology itself. Now finally, what does that translate to into customer success with us because that's the ultimate measure. And what I can give you a couple of examples here of how the breadth of the portfolio really signifies how we can solve not only a lot of challenges within each customer we engage with, but across a lot of different types of businesses. So here in the first example is Calix, which is a solution provider to telecoms. This is something where they have a lot of communication software and tools around and services around creating basically telco networks through service providers. And so they use each of the testing technologies that I talked about earlier to really, at every stage of the life cycle as well as in their customer implementations, secure the software, but ultimately, their measure of success with us is it enables them to deploy software faster. So it's not just about making it more secure. That's absolutely a goal. But when we can consolidate the visibility across all these different types of software that they have, then it allows them ultimately to move faster. And that creates competitive differentiation for them as a business. And that's when we know that we've won. The next one to talk about is Nuance, a voice many of you might have interacted with it and not even known it, it's a leading provider of voice solutions both in software form as well as in many, many embedded devices. And they chose us with the notion that they were aggressively adopting open source but also subject to a lot of compliance and regulations to show that they are producing secure software. And so this is a partnership that has allowed us to create trust on behalf of Nuance to their customers by showing that they're a trusted adopter of open source and that the software that they are developing and deploying to their end customers has rigor around the adoption of those technologies. So that gives you a sense of the breadth of the customers and the types of use cases we can solve. Now in summary, we -- I want to reiterate the view that we've given before of we see consistent 15% to 20% growth objective in this business as well as a path to $1 billion and beyond within the software integrity category. And we do that based on that strong portfolio, which is made up of organic innovation M&A that creates some expansionary ability to address more of the market and the SaaS transformation that really enables us to go after a different category of customer than we traditionally have. And with the strength of that go-to-market engine and the customer base across embedded systems and enterprise has a diversity that allows us to have a pretty strong platform to continue to bring new capabilities to market. with that solid foundation. So with that, I'll close and turn it back over to Lisa, so we can get to the Q&A.
Lisa Ewbank
executiveGreat. Thank you, Jason. That was a really great overview. Let's just continue the slides, and we'll hop into Q&A. [Operator Instructions] So I'll pause just a moment. Our first question, Jason, is, are there any gaps you think you need to address for a complete security platform?
Jason Schmitt
executiveGreat question. So I don't see or look at anything in terms of gaps within our portfolio. But our perspective really is the modern software development constantly changes and evolves. And I mentioned multiple times, cloud transformation is a real accelerant for how software itself has changed. And so what we focus a lot on is not gaps in the approaches that we have, because we feel very strong conviction around the coverage and comprehensiveness of where we are. But we do have to constantly evolve our solutions to stay abreast of how the cutting-edge technology companies as well as any business relying on software is adopting new technologies. So a lot of what we have to do is to stay on the cutting edge of modern software development and the use of cloud and the technologies that are related to it, so that we stay in front of our customers instead of kind of reacting to what it is they're needing to do.
Lisa Ewbank
executiveOkay. Our next question is you -- looks like you increased the TAM by $500 million from $2 billion to $2.5 billion to $2.5 billion to $3 billion. Is this driven by underlying market growth? And if so, how -- or has White Hat expanded the TAM?
Jason Schmitt
executiveI would say it's all of the above. So at the foundational level, that consistent 15% growth, which has been pretty steady for a number of years, represents a good part of that expansion but also White Hat for us represents the ability, as I said, through our SaaS solutions that we continue to bring to market. The ability for us to essentially address parts of the market that we didn't have appropriate fit product for in the past. So it's a combination of underlying market growth plus we're addressing more of the market. And that goes for some of the others in the market as well as software is evolving, as I said. So that allows us to reach more of those customers within the overall TAM.
Lisa Ewbank
executiveOkay. Great. Our next question, what synergies do you see between Software Integrity and the Semiconductor & Systems segment? Are there any sales or product synergies?
Jason Schmitt
executiveSynergies at the -- I'll go back in time a little bit when we start with the very inception of the Software Integrity Group comes from a conviction that software continues to be and will always be a growing part of any system design. And so what that means is software becomes more and more important for all Synopsys customers. And what's important for software customers is a software trustworthy and reliable. So at that foundational level, we within Software Integrity see tremendous synergy and being able to bring these solutions directly to a customer base that values Synopsys as an innovation leader over a very long period of time and also to be able to plug in early into the life cycle of any system design gives us tremendous leverage. And then in terms of technology synergy, we have a lot of benefits that are growing within our Software Integrity Group for technologies from the system in the semiconductor or heritage of the company that allows us to do innovative things within software security that we wouldn't be able to do otherwise. So on both counts, technology as well as being able to have access to and the reputation and success with so many embedded systems customers really helps us.
Lisa Ewbank
executiveOkay. Our next question, what is the mix of end markets served by software integrity. For example, financial services, travel, retail, technology, et cetera? And how has that evolved?
Jason Schmitt
executiveSo down at the individual vertical level, it's hard to break it down to that granular of a level here. But what I can say is if I just kind of lump markets served into embedded systems and enterprise, an enterprise could be anything non-embedded. Over time, the embedded area for us has been a very, very strong foundation. We're well penetrated, but still growing within the embedded segments. And that's everything from semis to automotives to aviation, anything embedded. But where we see even faster growth is in the enterprise side. So that's inclusive of everything we talked about from financials, which are a significant driver for us, both on the services and software side. But historically, 5-plus years ago, that wasn't the case as well as some other areas. Enterprise represents the faster growth. And also the -- it's hard to size, but the larger overall market opportunity is there. So a lot of the solution development and the evolution of our portfolio has been to capitalize on that strength in embedded while capturing the growth on the enterprise side.
Lisa Ewbank
executiveOkay. Our next question. What percent of the business is SaaS versus on-prem today? And how do you see that mix evolving over time?
Jason Schmitt
executiveSo we don't break out the products that way. But what I can tell you is the SaaS services for us really hit the market, I would say, 3-ish years ago, and are by far the bigger contributor to our growth now as we expand into those other markets, which you might call a mid-market or Global 1000 or below. So without saying exactly the split, it's definitely the fastest growth, and we expect to continue to see that as more and more -- not our software customers are not converting to SaaS. It's more going after greenfield market opportunity for us as the portfolio has expanded.
Lisa Ewbank
executiveOkay. It looks like we've got several questions about competition. One, where does Synopsys compete with competitors like Snyk, which has really high growth? Who do you see as the most -- see the most frequently from a competitive perspective and -- I'll stop with those 2 and then go with the next.
Jason Schmitt
executiveOkay. Who do we see most frequently that is a bit of a fragmented answer because it's a bit of a fragmented market. Most of the competition we see most often are narrow tool providers within each of those application security testing approaches that I talked about. So within each one of those categories, if we engage a customer on the basis of a project just around that particular type of testing tool, there's a number of usual suspects within each one of those but not a lot of consistency across them. There are a few that have successfully consolidated across all those. But within static analysis and open source, there are some consistent players that we see there. But what we end up doing there is competing with them on the basis of up-leveling the conversation to a much more comprehensive customer view that leads to advantage of our portfolio. So that often plays to our strength when we see those competitors that engage in that way from the tool upwards. To your question about Snyk, we see Snyk in organizations where there's a belief that developers will solve this problem on their own. And then we can solve security challenges by convincing development to wholly own the problem. What that means is that it can be a seductive early entrant into doing application security to think that, that will scale and solve the challenge ultimately. But when you consider all the sources of software, the complexity of what it takes to solve these challenges at any sort of scale you're confined in what you can expect the developers to do without proper governance and visibility across the whole security program. So that's how we see them engaging in a different way. And in a sense, participating in some growth around development, that's not really even within the application security testing market. So kind of a fair accounting of what they do is a bit different than an apples-to-apples comparison to AppSec testing. It's much more of a developer tooling platform.
Lisa Ewbank
executiveAnd what about the larger players like Microsoft, GitHub type player? Do you see risk in your business that they will try to enter your area of expertise? Or how do you see them in this landscape?
Jason Schmitt
executiveSo a lot of those folks that you mentioned, Microsoft being a great example, GitHub, GitLab and even really each of the major cloud providers, Slack, Google or Amazon, what they all do in a sense is create a vertically integrated kind of software development to operations platform. But what each of them does is, in some cases, they offer tooling capability to add value to their individual platform, but they necessarily have to remain an open ecosystem because no one completely vertically integrates their entire software pipeline all the way to cloud with a single provider because that's very risky, even though that can be a very full featured, economically effective approach, many industries even mandate a multi-cloud approach, which also means multiple vendors for your developer tooling. So that market in and of itself is very fragmented. I would see that as more of a threat if we weren't open to the fact and aware of the fact that the heterogeneous nature of that environment necessitates a solution set that can work across all of those platforms. So from that perspective, just like the cloud market is often a multi-cloud solution. We see that the developer tooling and death pipeline is also a multi-vendor approach that most people take. And that means they need a partner that can see and manage risk across multiple platforms, whereas the security tools from each one of those are just a piece of the puzzle for them.
Lisa Ewbank
executiveThank you for those competitive insights very helpful. Can you talk about the key steps towards margin expansion? And what do you see as a reasonable long-term operating margin?
Jason Schmitt
executiveSo a lot of what I talked about in the go-to-market strategy as well as the portfolio really hits to the key drivers for margin expansion for us. On the portfolio side, a lot of our focus in growing the software business, which is, as you would expect, higher margin than other sorts of businesses and also growing the services line item is allowing us to really transform the profitability of the overall portfolio more towards higher-margin software and SaaS. So when our services engagements lead to software sales, or services engagements lead to SaaS applications, kind of automating the challenge that the customer has. That's a part of the portfolio margin expansion. Then within our go-to-market, each of those 3 areas I talked about are key vectors in the margin expansion as well, building a scalable go-to-market engine isn't just scale in the terms of just grow it horizontally, but consistent execution globally leads to efficiencies. And then a key driver there is our partner model. So we've been able to continue to grow our indirect sales through partners quite well. And that overall, each of those areas of the go-to-market transformation allows us to have lower and lower cost of sales over time. So as we evolve the portfolio, get more efficient in the go-to-market than we naturally kind of capture growth while also expanding margins.
Lisa Ewbank
executiveAnd we have another financial-related question. Software Integrity growth really slowed in early fiscal '21 and have significantly reaccelerated through this year. Can you talk through what some of the issues were and what you've done to improve and reaccelerate growth?
Jason Schmitt
executiveSure. I'm at risk of repeating myself, I'll come back to really the 3 things that we have been focused on transforming since then. And those are indicative of the things that might not have been working before. But we'll focus on what we've done to rectify that. Portfolio is one. So having a much more comprehensive portfolio that is laser-focused on customer value and customer outcomes rather than just producing technology, but putting it into an integrated platform that allows customers to get synergistic value by adopting multiple of our products. So making it easier for customers to choose our portfolio on that basis has been a big contributor. And then simple go-to-market execution has been a major part of that in the sense that really focusing on that scalable engine on a global basis with consistent execution and partner first. That's enabled us to really scale much more effectively and reach new markets, as I said. And finally, that real advantage we have with that strong services business that allows us to engage and lead with that and not be afraid to engage with customers in that manner, knowing that the long-term value of that customer is higher. Those 3 points of emphasis, portfolio execution and services is what has allowed us to reaccelerate the growth.
Lisa Ewbank
executiveWe are at our theoretical end, but it looks like we have a couple more questions, so let's just move forward with those. A couple of questions related to your international expansion. Can you comment on your investments in the international expansion? And in terms of your indirect channel, what partners are you having the most success with?
Jason Schmitt
executiveSo what I can say in our international expansion is we've actually been able to grow in each of our international territories and the way that we think about it EMEA and a couple of Asian sub-territories. We've been able to grow our business in all of those sub territories without substantially growing the team on a go-to-market basis. And the way that we've been able to do that is those 2 things I talked about, a globally consistent model for our sales and go-to-market distribution engine and relying more and more on partners. So I would say 2 years ago, we were actually below market norms in those international markets in terms of how frequently were we selling through partners. And so what you have to do is take a global but local approach to partnering in international markets so that there are some global systems integrators that can give us reach in multiple geographies. But for the most part, regional players and regional partners, both SIs and value-added resellers within each of the territories we operate in allow us to be very selective and strategic about who those partners are so that they're high value for us, and we can dedicate the time necessary to make them successful with us.
Lisa Ewbank
executiveOkay. And we have one final question. AI and machine learning, the big topics in software, and you touched on AI a bit. What do AI and machine learning mean to you? How do you guys think about incorporating those AI and ML within your platform?
Jason Schmitt
executiveThat's a great question. One attribute of what happens in software development, that's very interesting to apply AI to which we do is, when you test let's say, 100 million lines of code with complex security testing tools, you can produce a lot of information. And often, it's more information than an organization can act on when they're just getting started. So we bring to bear intelligence to help automate the triage and prioritization of that information. So it's a classic use case for machine learning, where what our tools basically do is label data, whether it's -- label source code, whether it's secure or not. But when you do that, at massive scale, humans can't consume it and make the right judgment calls. So we can apply fairly simple ML in the right places within that pipeline. And then it makes the overall return on investment and speed of delivery of these tools that much better. But then there's also other use cases where we're actively working to apply more advanced AI and kind of decision-making, insight analytics and kind of prioritization of security problems. So it's squarely within the challenge of finding the signal from the noise of all the software development that's happening.
Lisa Ewbank
executiveOkay. Thank you, Jason, for taking the time today and walking through the group, some really good information about markets and portfolio and go-to-market. And we want to thank everyone who participated in the event today. If you have any follow-up questions, please feel free to reach out to the Investor Relations team, and we hope to do this again in the future and that you all have a great week.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Synopsys, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Synopsys, Inc. earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.