F5, Inc. (FFIV) Earnings Call Transcript
March 8, 2023
Earnings Call Speaker Segments
All right. As we get everybody up on stage, I'll read a sort of disclosure. For important disclosures, please see the Morgan Stanley research disclosures website at morganstanley.com/researchdisclosures. If you have any questions, please reach out to your Morgan Stanley sales representative. Welcome, everybody. I'm Meta Marshall. I cover the networking space here at Morgan Stanley. We're delighted to have F5 Networks here with us today, Frank Pelzer, CFO; and Kara Sprague, EVP and GM of App Delivery and Enterprise. My record of nailing last names is continuing.
So all right, over the past few years, F5, it's had a bit of a renaissance, not only from -- internally within the portfolio. But also just as ADCs went from being viewed as mature to kind of being viewed as a very relevant market. So what -- maybe just like remind investors like what has kind of caused this resurgence of the core ADC?
So before I respond, I need to get our safe harbor on record. So please note our discussion today may contain forward-looking statements, which involve uncertainties and risks. Our actual results may differ materially from those expressed or implied by these statements, and please see our SEC filings for information on these risks. So great question. And yes, it's true that ADC is only a piece of what F5 does today. Over the last several years, we've expanded significantly into security, predominantly application security. So we now have a broad portfolio that includes things like web app and API protection. That includes WAF, API security, denial of service, anti-bot. We also have SSL termination, traffic break inspect as well as identity aware proxy solutions for customers. So it's a quite broad set of security capabilities. And our security business has now surpassed $1 billion annually. And so it's been a big push, and that's now about 1/3 of our total revenue. So you asked specifically about ADC and what's driving the resurgence in ADC. I think the important thing for folks to understand why is ADC seeing this kind of renaissance is to understand what is an ADC and what does it do? The best analogy that I have come up with in my 5 years at F5 is ADC is the beating heart of an application infrastructure for companies. It basically drives traffic. It filters traffic. It steers that traffic to where it needs to go. And it also transforms that traffic if it needs to. So if you think about any application and average person has 50 to 70 web apps sitting on their phone, you're interacting with mobile applications and your browser every day. Those all have some sort of ADC technology that are sitting behind them.
Got it. Okay. I'm always 1 to love the analogy, so I like that. We'll definitely turn back to the security business as we go throughout. I think another impressive thing that you guys have done over the last 5 years is just positioning for new and existing workloads because people would have thought kind of the ADCs as more relevant to kind of premise data centers. Where do you think customers are in figuring out what their end state is going to be with these workloads and kind of application framework? And -- or does -- I know you don't necessarily -- you're agnostic to what decision they make, but just where are you seeing them in this kind of decision framework?
So okay, as you might expect, customers are existing along the spectrum. You've got some customers that even today remain strongly convicted that their future is 100% public cloud. And you've still got those customers that you meet with that are talking to you about how they're starting to dip their toes into the water of public cloud and meaning they haven't even removed anything. So a big, big spectrum. What I have seen as a major shift, however, in the composition of those customer attitudes in the last 18 months is the majority of our customers who 5 years ago were telling us public cloud is where we're going. You guys are a data center dinosaur you're going extend and public cloud is going to eat your lunch, are now saying our future is hybrid and multi-cloud. We see a persistent need for investment in some of our on-prem infrastructure. We have workloads that we believe are better served on-prem, that are lower cost on-prem or for whatever the reason, we want to keep on-prem. We are adopting our average -- customers are adopting about 2.8 public clouds. And so they're deploying applications in those multiple public cloud environments. They're increasingly deploying applications in edge environments. And so that's the big change that we're seeing. And that change is not just something that we're hearing in our sales conversations or that our channel partners reiterate with us. You see this also in the data points. So we're seeing quarter-over-quarter growth numbers coming down in public cloud, which indicates that there's a bit of a stabilization going on in the market. You're seeing increasing anecdotes and reports from individuals and companies that are repatriating workloads and have extensive cost models about why they see on-prem as a less costly solution for them than running workloads in a public cloud. And then the third area I would point to is you see increasing investment from organizations and large enterprises and SRE practices, which enable their on-prem operations to run as smooth and as agilely as a public cloud might.
Got it. I mean understanding that we're moving to this multi-cloud future and kind of this hybrid opportunity. So what can F5 do to kind of take advantage of that? Is it, okay, this is -- now that you've given me this hard example. It's like is this Azure GCP and this is AWS and you're just kind of adding more limbs to kind of the beating heartbeat? Or what can you guys do to kind of help people along with this hybrid journey?
As you took the analogy somewhere I hadn't done before. So I'm not sure -- I'll have to think more about that one before I commit to that.
Right.
But if you use a beating heart example right? What do you do when you have to replace a heart, right? You make sure that the traffic is still flowing through something. So you redirect it through something alongside, but it's a very costly, very expensive procedure. And a lot of people aren't jumping whole hog to replace their hearts. It's a good analogy for how sticky and how critical this technology is in a customer's application environment, and why there is such an extensive need for customers to have deep trust of the vendors that supply them with these capabilities. And so that's why we see our expansion of our opportunity set. We moved into modern apps a few years ago with the acquisition of NGINX. We've extended our security portfolio to include more things with the acquisitions of Shape Security and Threat Stack. And we've also added additional capabilities in cloud delivery in the CDN through the Volterra acquisition and Lilac Cloud. As we've expanded all of that, our addressable market and our TAM has expanded beyond what is the narrow focus of software and hardware-based ADC which is just a few billion dollars. We now see an addressable market that's tens of billions of dollars across all of that. And we have retained the customer trust and reliance on us. They know that we are the place to go to secure and deliver applications.
All right. So we'll step away from the heart analogy. But the -- I mean, I guess, the question really is you can address all of the different types of workloads and you can address the kind of security use case. But is there still a pain point that your customer has as they move to this kind of multi-cloud universe that you can help address?
Absolutely. Okay. So let's think about what customers are doing today or what they have been doing over the last 5 years when they declared they're all in on public cloud. Many of them had on-prem data centers. Many of them have a half-baked or half-done process to migrate into some sort of private cloud environment. So they still have some legacy stuff, some private cloud. And then they started throwing a bunch of workloads into a public cloud, usually the easiest workloads to move and migrate. Then their developers got wind that they could use public cloud and said, "Hey, I want this other one over here, and I want this other one over here." And so now you see most organizations when you ask them, okay, where are your applications. They've got their on-prem traditional stuff. They've got a private cloud going on. They've got some sort of colocation facility. They've got multiple public clouds and they've got edge. And what they've done because in 1 regime or another, they were going all in on one of these solutions as they've siloed the operations for each of those. And that includes siloing their policy, including, for example, something as simple as the signatures that they apply to the web app firewall in the applications in that environment. Now along comes something like a Log4j, right? It happened earlier this year and you asked customers how did you deal with it? What they had to go custom lock down every single door in every single environment. That costs a lot of time. It was very difficult because they don't have transferable skill sets across all of these different operating environments, and it creates vulnerability for the organization. So I hope that's a useful example of why this kind of fragmentation and inconsistency in siloing is creating vulnerability and cost and complexity. And so what we suggest customers do, now that we're at this point where they're taking a step back and considering how do I rationalize my public cloud spend, think about how do you rationalize your public cloud and operational spend across all of these environments, invest in a single set of capabilities, invest in a single set of policies and deploy those things with consistency across all of your applications and APIs regardless of what environment they're running in. And that's what F5 does.
Yes. Got it. Maybe for you, Frank, a part of these broader architectural changes we're seeing has caused your software growth to kind of be an area of strength over the past couple of years. But there's been a lot of volatility on a kind of quarter-on-quarter basis. Given the full portfolio is being used across these broader implementations, like is there services almost done sometimes of focusing just on the software number? Or just how do you judge how to kind of express to investors the health of the business?
No, it's a great question, Meta. And I think let's go back in time. So when I joined the business in 2018, we had just had our Analyst Investor Day a month before, we split out for the first time that software and hardware from the product portfolio. And I think we were right around high single digits, low double digits in terms of the percentage of our product revenue coming from software. At the time, I think there was a lot of discussion around F5 is will we be a going entity, your hardware company in a software world, it should decline. It's just how steep is it going to get to 0 at some point. As more workloads move over to the cloud and will you be relevant. And so we needed to set up some metrics and some benchmarks that we reported to. We gave people a time frame of Horizon 1 and Horizon 2, which was from FY '19 to the year that we just had in FY '22. And we said, "Hey, these are the aspects of what we want to see, 20% software growth, exiting Horizon 1 around 25% and then doubling that by the time we get to Horizon 2." We actually updated that in November of 2020. And part of that transformation effort that digital transformation that everybody has been experiencing did lead to a lot of growth in software, maybe even more than we expected, and we exited last year at 51% of our revenue coming from software. So for the last 4 or 5 years, as a measure for our transformation, we thought it was really important and a very important disclosure. We're certainly not done with that transformation effort. We want to continue to grow, but I think it's probably less important for the investors to focus only on that software growth since we've got a much broader portfolio since part of our value proposition is to meet customers where they are, whether it is software, hardware, whether it's perpetual or subscription or utility-based pricing that's wherever they are and want to consume, we want to be able to provide that for them. So as the portfolio has broadened, as the consumption opportunities have broadened, we think it's probably more critical today to look at our EPS growth in the double digits that we have -- we made commitments to. The Rule of 40 is our North Star to try to find that balance between growth and margin on an overall basis. And then the cash that's being generated by the business ultimately is the measure of the stock.
Got it. I mean part of some of that software volatility has just been that you guys have traditionally employed kind of an ELA type of agreement for a lot of your software products. Why has this been kind of the approach taken and why keep that versus kind of more subscription that could be -- bring a little less volatility to that line?
Yes. It's really kind of the way customers want to consume. And so despite the visibility that maybe we see as a business, investors could see. It's really the way that our customers wanted to set up those agreements. And we initially started talking about them in terms of ELA, but I think ELA has adopted a philosophy in the market of an all-you-can-eat type consumption model, which is not the way actually our agreements work. And so we've changed the name of that to a flexible consumption program and really talked about it that way for the last couple of years, where customers basically sign up for a commitment in usage and can vary that between the products that are part of that agreement. But there's a true-up feature for Schedule B and a true forward for our Schedule A, which is the vast majority of our contracts. And so it does give customers a budget certainty within their model to say this is what I'm going to spend this year and they're locked into it. Now we'll measure that at the end of the year and true forward to a new rate of consumption, and then they can budget that. So it gives them a lot of certainty as to what their budget is going to be for the year. And it also gives them flexibility to consume products in the way they want within that construct. And so it's been really a way that customers want to consume our products. It may be a little less straightforward in terms of revenue recognition for everybody else and a little more volatility. But we're making that trade to allow customers to consume it the way they want. I mean we offer that, but we also offer perpetual and we offer SaaS-based solutions for a number of our products. We've got a very broad mix within our revenue recognition.
Got it. I think people can understand the competitive landscape when it comes to the ADC market and kind of the more traditional market. Just as you broaden out into security, edge, a lot of different areas like -- where do you -- or what are you running most as kind of an alternative solution?
In the security side, and I'll focus mostly on our web app and API production offerings, the players that we would run into more often is Akamai, Imperva, Cloudflare. And the reason why we win in scenarios against those players is we have best-in-class security efficacy. So it's about different customers measure that in different ways. It could be about reducing the number of false positives, capturing the more complex bot opportunities, but our technology captures all of this. And then the second thing that we differentiate on is what Frank was just describing, which is this choice that we offer to customers in terms of extreme flexibility and deployment options as well as consumption options, Whereas those players are all cloud-based subscription only, we can extend for customers across their on-prem and public cloud deployments. We can offer them hardware, packaged software, SaaS and managed services. We can offer perpetual if they need that.
Got it. We spoke kind of kicked off starting about the core ADC market and just kind of the resurgence that, that market has seen. You've noted that there's kind of been share gain opportunities as maybe the competitive landscape has become a little less focused. Is there a way to think about how you extend the growth period we've seen kind of on the hardware side or just what growth opportunity you see within that market that's maybe just not pure market growth?
So in terms of share gain opportunities, we're seeing that on both the hardware side and the software side. And we are seeing that for a couple of reasons. One, our continued investment in innovation in our systems business. We are in the middle of right now a refresh cycle in our appliances. So we have come out with our Series appliance line. They've been out for about 15 months now. We also have a refresh opportunity for the chassis form factor that we have, that's called VELOS it is replacing VIPRION. And in both VELOS and rSeries there's significant amount of innovation that we're bringing to market that is very compelling for customers because, frankly, there hasn't been a lot of innovation coming from other competitors. A couple of things I would point to is that these systems are now much more highly automatable. So fleet management is much more simplified. There's a compelling TCO argument for just that. In addition to the fact that they are multi-tenant. And so they can host multiple tenants. And then on the software side, our reasons for share gain there is because of this proposition of saying, look, if you want to deploy our hardware on-prem and get hardware acceleration for critical workloads there, but then have consistency in your policy and deployments in other places, that's what you get by deploying our software either on-prem or in public cloud, and that's what you get by using our SaaS and managed services capabilities.
Got it. I mean, having looked at F5 for a long time, we started to kind of get into this refresh cycle story, you just talked about iSeries, rSeries. You also talked about VELOS, VIPRION. Just how is this refresh cycle may be different than kind of refresh cycles of all?
Okay. So this is the first time we've done a refresh cycle for our chassis. So the last refresh was some decade-plus ago. And in terms of rSeries for the appliances, the last refresh we did was in the 2016, 2017 period. So quite a lot has changed. I'll name 4 things. So one, our overall product business has now surpassed 50% software. And so when you look at what -- or try to estimate what would be the kind of financial impact of a refresh cycle and how it shows up in our metrics, it's much more muted now because it represents, at this point, a minority of the product business. Second difference is that the rSeries introduction came at the same time as we were seeing unprecedented disruptions in our supply chain. And so we've been navigating a number of component shortages that impact -- some of them impact the iSeries of the previous line as well as others impact the rSeries. And so that is inserting a new freshness in the refresh process. There's -- I talked about there's innovation. Historically, our appliance refreshes have been very focused on just improved price for performance. But with rSeries, we're introducing some fundamentally new value propositions. I talked about the automatability, I talked about multi-tenancy. And then the fourth thing I would highlight is that in this refresh cycle, our primary competitor in the hardware ADC space has been taken private and is showing signs that they're reducing investment and support for perpetual models and for the hardware business. And so there's a different competitive dynamic out there.
Got it. I'm going to pretend that I haven't been here for the past 2 cycles. All right. So have some of the -- you just mentioned supply chain challenge. Just have some of the supply chain challenges push customers towards virtual solutions? Or is it really just still a -- that has nothing to do with the decision process. It's really how their cloud transitions are going.
Yes, I think, I mean the natural way to say is it would be if hardware isn't available, let me just pick the software solution. The reality is there's a lot of application infrastructure that needs to change in order to do that. And the work and the planning required, the execution of that is actually longer than the supply chain, even in the worst of times, the supply chain environment. So I think it certainly probably sparked the idea of we need to invest more time in thinking about this in case there's another situation like this. But for people who are starting from a standing stop that now I can just automatically flip the switch, and pick up a virtual edition, it isn't likely to happen that way. We haven't seen it happen that way. For people who are starting down that path, maybe they were far enough down where they couldn't make that change, but it really wasn't a meaningful driver for our software business in the last couple of years.
Got it.
And just to put some numbers on that, the worst of the supply chain situation, the lead times on our products for the worst case got into the 26 to 28 week period, which as Frank is saying, if you're a company and you've been investing in hardware, you're going to need more than 6 months in order to rethink your application and solution topology in a way that would make sense for deploying these technologies in a virtual form factor. You can't just replace one for one.
Got it. I mean you started off talking about 1/3 of revenue kind of comes from your security-based portfolio today. You have a unique position in the traffic flow and Layer 4 to 7 visibility, security seems like a natural area where you can kind of add to that portfolio. Just I think today, investors normally I think of your security portfolio as just WAF. Just how broad is that portfolio today? And where can you kind of continue to take that?
Yes, the portfolio is much broader than just WAF. So we have a best-in-class web app firewall that does get a lot of attention because it is ranked among the top in the industry. In addition to that, we have API security that is related to the WAF, but there are different capabilities required for that around API discovery and other types of threats about attack APIs. We -- with the Shape acquisition, we brought in a very, very powerful machine learning-based capability and anti-bot. It's really more of a traffic profiling capability. So it's able to detect, is this a human interacting with me or is this a bot? So it passes the Turing test. And then second thing I can do is, is it good traffic or bad traffic like? Are they trying to do something malicious? And so really, really powerful for profiling traffic and determining do you block it, do you redirect it somewhere else? In addition to that, we have something called SSL termination, which is traffic break and inspect. So we have customers, for example, that they are unencrypting every single packet that comes into and out of their DMZ in order to inspect that for malicious stuff, do other transformations on it and then pass it along on its way. We have identity and access solutions, which enable customers to basically say, only individuals with these access rights have access to this application. And so that's like -- that's what we call an identity aware proxy solution. And then on the service provider side, we offer Layer 4 firewalls, which include Layer 4 DOS, anti-denial of service as well as CGNAT type capabilities.
Okay. Got it. Frank, maybe turning to kind of the operating profile of the business. You guys had probably one of the leading operating profiles kind of across tech 5 years ago, and has come down a fair amount as you've just invested in acquisitions, doubled down to sell those efforts, particularly as we go into a tougher macro period. Just how do you think about working to optimize the structure of the company for this environment and still invest in kind of the growth opportunities laid out?
Absolutely, absolutely. So I think the biggest -- again, let's go back in time. When we take a look at the change of what was an 85%, 86% gross margin to where it is today and maybe a 36% to 38% operating margin where it is today. The first hit was to the operating margin. It was because of the dilutive acquisitions that we did to that, but it was incredibly important for us to add those capabilities because of probably the lack of investment that we had, had for the past 10 years. We just didn't have time to do all of that organically. And so needed to acquire. And largely, with the first 3 acquisitions, we really built up the reach and the world that we serve for application services through those engines through Shape and through Volterra. We've tacked on a few other since, but nothing is meaningful to the architectural capabilities that we have today in relation to those. But we have certainly seen operational leverage improvements from that 2021 time frame to where we are today on the OpEx side. Now take a look back 5 quarters ago and what happened on the gross margin side of the picture was very much supply chain related. And where we had been getting by through a challenging supply chain, but there's still broker market opportunities that we're starting to take a little bit of a hit to the gross margin profile on our system side froze up completely about a year ago, where there was no broker market. We were unable to ship that impacted our revenue, and we still had a certain amount of cost components in there that then started to bring down the systems. A quarter or 2 later, the broker market starts to open up a bit, but at prices that were hugely inflated from the expectations that we had going into any given year. We were able to get some critical components faster than a 52- to 60-week lead time, but it required expedite fees. All of that is still working through the components that go into the box that we are making today and shipping out today. As we get through the end of this year, that will probably start to normalize as well. And so through both gross margin improvements on the system side, continued gross margin improvements on the software side because the economies of scale of SaaS business, they continue to grow and get better. And then operating leverage that we will continue to find in the business by looking at overlap in the product areas, by looking at efficiencies in sales and marketing and G&A. All of those are reasons why we believe we will get to that Rule of 40 and balance out that growth with the operating margins regardless of the environment that we sit in.
Got it. And maybe just the last question as we wrap up. It's certainly been the topic of the conference is AI. And just what are you doing within your own portfolio to kind of bring more automation, more intelligence, kind of to your product portfolio and just simplifying kind of customer networks or just capitalizing on it within F5?
Yes. I would describe this in 3 areas. So one is just using AI across F5 functionally in terms of exploring opportunities. There's obvious applications for generative AI and providing customer support. There's applications in the marketing domain around content generation and basically helping simplify content generation for our team members there. As well as in the engineering side, increasing applications for using generative AI to build at least a first copy of the code that they would use, and we are exploring all of those paths operationally. The second place I would point to is in the products themselves. So we have been, for a long time, been using machine learning and advanced analytics techniques to do some of the sophisticated traffic profiling that we do. And we're also looking at extensions of that kind of technology to drive more insight and more automation based on that insight, which starts getting into the realm of what we've talked about with our Adaptive Applications vision, which is enabling applications to be much more responsive and adaptive to their environments that don't require as much manual intervention. That will be very reliant on those kinds of AI-based and machine learning techniques. And then the last thing I'd say with regard to AI is I think we're seeing evidence in the market so far. We talked about it being the topic to user, but there's evidence that this is going to drive a huge renaissance and a resurgence in application growth and application and API growth. And then hopefully, if you take one thing away from this fireside chat is that F5's business is inextricably tied to the growth and explosion of apps and APIs. And so we see that as a net good for us.
Got it. All right. Well, perfect. With that, we're out of time. So Frank, Kara, thank you so much for being here today.
Thanks.
Thank you.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete F5, Inc. transcript - plus 251,000+ transcripts from 12,000+ companies, speaker segments and full-text search - through the EarningsAPI REST API or hosted MCP server.
Get an API key View API docs →For developers and AI pipelines
Programmatic access to F5, Inc. earnings transcripts and 251,000+ others is available through the
EarningsAPI REST API and the hosted MCP server.
Quarterly plans from $105 - full transcripts, speaker segments, full-text search,
and the /api/v1/transcripts/recent polling endpoint for ETL pipelines.