Fortinet, Inc. (FTNT) Earnings Call Transcript
March 2, 2021
Earnings Call Speaker Segments
Good afternoon and good morning. This is Keith Weiss, Morgan Stanley's U.S. software equity research analyst, coming at you from Day 2 at our TMT conference. And, and really pleased to have with us this morning from -- wait, this afternoon from Fortinet, both Ken Xie, Founder and CEO; as well as Keith Jensen, the CFO over at Fortinet. Before we get started, I have a brief disclosure and I think the other Keith has a brief disclosure as well. From the Morgan Stanley side, please see our website at www.morganstanley.com/researchdisclosures for important research disclosures. And Keith, I believe you have a safe harbor you'd like to read.
Certainly, thank you, Keith. I'd like to remind everyone that we may make forward-looking statements during today's fireside chat. These forward-looking statements are subject to risks and uncertainties that could cause actual results to differ materially from those projected in these statements. Please refer to our SEC filings, in particular the Risk Factors in our most recent Form 10-K and Form 10-Q and to other reports that we may file from time to time with the SEC for additional information on factors that may cause actual results to differ materially from our current expectations. All forward-looking statements reflect our opinions only as of the date of this presentation, and we undertake no obligation to specifically disclaim any obligation to update forward forward-looking statements. Back to you, Pete. Keith.
Outstanding. Thank you. So thank you, gentlemen, for joining us this afternoon. A really interesting time to be talking about security, really interesting time to be talking about Fortinet more broadly in that security landscape. But I wanted to start out on sort of the macro picture, the security demand environment. From our perspective, coming out of calendar '20, we were coming into a better year of security spending even before SolarWinds hit, just predicated on what we're seeing in terms of work from home or distributed computing environment, those changing architectures, necessitating. People think about their security architectures in a new way was in our survey work and in our conversations rising the priority of security. And then you have SolarWinds come in on top of that to really heighten the threat environment. So maybe to phrase that in the form of a question, what are you guys seeing in terms of the overall spending environment on security coming out of calendar '20 into calendar '21? And two, how does SolarWinds kind of change that equation if it changes that at all?
Yes,. Keith, totally agree with you. We do see is that 2021 will be a stronger, better year compared to 2020 because, like I said, a lot of our companies, service provider, they leverage the new technology or whatever the new architecture needed to supporting work from home to leverage the SD-WAN 5G and some other zero trust network access and like SASE, all these things and both cloud and endpoint networking. So they do need to kind of upgrade or kind of adopt some of the new architecture. Compared to last year, they are probably more high on what they already have and the existing vendor maybe just add additional service instead of keeping buy some new products. So you can see most of the security vendor, the product revenue are pretty flat. And we are lucky we keep gaining the product revenue. But this year, we do see even stronger demand in both on the new architecture, the new product and also agree with you, the SolarWind is really helping that. But I do see SolarWind probably a little bit more long term, maybe towards the end of the year or next year and because it really related to the third-party supply chain security, maybe eventually can drive some new industry standard like from government, how they deal with like a healthcare standard, how -- the food supply chain standard, but that may take like a couple 2, 3 years to come. But long term, it's definitely helping drive the overall infrastructure security and raise the secured awareness in the short term. But is -- but even without SolarWind, we see it's a very strong year this year.
Got it. Got it. Shifting the conversation towards -- more towards Fortinet. I think one of the really -- one of the most interesting aspects of the story over the past couple of years is what has traditionally been a network security story and Fortinet came public and really came to its current size, on the back of consolidating that core network security space on the back of your next-generation firewall appliances. But now there's a networking component of the equation as well. SD-WAN is a big part of the story. Can you talk to us about why it's important that Fortinet brings both sides of the equation together for the end customer?. What is it important that you have both network security and the underlying networking capability that, that's going to secure?
Actually , from Day 1, when they started Fortinet, and it seemed like my previous company has said, NetScreen, we always want to see how the next-generation or next version of Internet may change it because so far, the Internet is more about connectivity and speed whether you go to the 5G or some other IPv6, whatever, it always bring more connectivity, more speed. And also, you can see there's a big gap between how the security, network for security and the traditional routing switching because the security they need on edge, maybe like 50 to 100 computing power to process the same data, same throughput compared to routing switching. So there's of a big gap as a security's relatively slow and kind of more expensive, more difficult to manage. So that's what we can see how we can bring like close our gap and make it kind of a security more faster and also like how we deal with SD-WAN and some other like Wifi. And going forward, 5G, really we call secure-driven networking, basically, it's really kind of applied somewhat high level, whether from application layer, the content layer, the user device layer towards the network side and make it working together, so that's where we see. It's very important to combine these 2 together and not just the SD-WAN, we did a few years ago. But also, like -- probably like 10, 12 years ago, we also combine our WiFi security with -- WiFi and security together and, going forward, 5G. And on the other side, security now need to deal with much broader, bigger infrastructure, not just the network side, but also involving the cloud endpoint with that 5G IoT security. So that's why I try to see how there's bigger infrastructure we call the fabric, Fortinet fabric, make it all kind of more -- covered broad tech service and more integrated together, especially in the OS level, in the ASIC level to improving the performance and to make sure different product functions working together and, at the same time, to automate. So that's where it's kind of a cover more broad, automate and integrate solution for the whole infrastructure.
Got it. Got it. Can you talk to us a little bit about the 5G part of the equation. You talked about that being a big opportunity for forint for a lot of investors, it's not clear how sort of the 2 come together. We think about you guys as very much a sort of an Internet protocol protection, right? On that core network side of the equation, where does 5G come into the Fortinet purview?
The 5G, we do see later this year, next year was, we're starting to ramp up pretty quickly because it's a more connected device, probably like 10x more than 10x compared to the other technology connecting all the devices together. And also, it's more addressed infrastructure and government and the business is more involved compared to whether 3G to 4G is still more like a personal mobile phone. And once you connect the device, you really address all these security because a lot of industry, whether smart city or utility or some other part of health care, once this device is being connected, you really need to have visibility. You need how to manage it, how to may be secure the data, the information there, which just really need security from almost from Day 1. So that's where we see it's a huge opportunity. And also, we have pretty good -- like the government and service provider is 2 big sector for us, and they're both heavily involved in 5G, both building the infrastructure and also quickly like ramp-up application in there. So we do see there's a huge opportunity going forward. And also, we're working very closely with our service provider with some government to make sure that the 5G infrastructure is secure from Day 1.
Got it. That makes a ton of sense. Keith, and maybe to bring you into the conversation, SD-WAN billings had a outstanding year ending calendar '20. I think you guys talked about it doubling on a year-to-year basis. Do you -- is there any impact of kind of the work-from-home dynamic going on in there? Was that a positive impact, and can we sustain that pace of growth in SD-WAN as we had head into calendar '21?
Yes. I think the -- in terms of SD-WAN what we saw in 2020, I don't know that I would say that was a work-from-home application directly. If you look back at the performance and the billings numbers, I go back to a couple of years, we said -- can say the target actually of 5% of billings, and we got to that. And then he said 10%, and now he's got us working towards 15% of billings. Ultimately, the goal is to be #1 in this particular market in a market that's expected to grow 40% over the next several years. Now as you look forward and, I think, as work-from-home environment has become maybe a little more robust and rigorous in some of their security applications, we are looking at some opportunities now of deploying the SD-WAN functionality in the home. But I think at this point, I'll probably just pause on going to too deep on that until we get a little further down the path on it.
Got it. That was a great little teaser. So I want to shift attention to the core firewall business. And I would say this is probably the primary bear case for investors, not just on Fortinet, but on the space. There's definitely a, what I would call an exaggerated perception, that as we shift more and more workloads to the cloud, as we make more use of public cloud applications, whether it's SaaS or Infrastructure-as-a-Service, the necessity for firewalling goes away over time. But contrary to that, you guys have been seeing strong growth in your firewall business. That was above-market growth rates. So both in terms of the short term and the longer term, how do you think about the health and durability of growth of core firewalls in the near term? And is that going to be able to sustain over the next 3, 5 years? There's still a position in corporate security architectures for core -- like a hardware-based firewall.
I think the traditional firewall space we don't see as the business is going down, probably even keeping growing, just they're not enough to cover the whole infrastructure because infrastructure security, attack service is expanding beyond that traditional firewall can cover. And like whether the mobile, work from home or some other part of internal segmentation and the zero trust network access, they do need some other technology to working together with the traditional firewall. And they need to expand to the one side like SD-WAN or 5G, which traditional firewall will not cover. They also need to go to the internal, go to the land side, whether the internal segmentation, the WiFi security and also work from mobile device internal segment and zero trust network access and also with service providers, SASE, different application. So that's where we need to be keeping expanding beyond the traditional deployment, which is only secured border, and if it's going inside, need to go outside and also need to be like a dynamic and cover the cloud endpoint, the mobile, some other part of it. So that's where the -- how we see it basically, how to make the whole infrastructure working together, secure together. And instead of -- in the past, probably the networking side not working much with endpoint, not working much with some other different applications or different cloud part, but now has to be all considered together as an integrated solution and automated solution. So that were we see the trends going on right now.
Got it. Got it. So there's a lot of newer cloud-based vendors who are out there talking about ripping out firewalls and ripping out edge appliances and moving all that capability to the cloud. But it seems like your perspective is, it's much more likely that enterprises expand their security architecture. They evolve it to start protecting these new threat vectors, these new technologies that they're adopting like a 5G, and it's more of an evolution versus a revolution of ripping and replacing. Is that the right way to think about it?
Yes, it's more like add on top additional beyond the traditional firewall. Traditional firewall is still there. I don't think they've been kind of replace up in -- kind of reduce the spending there. So that, you can see our few vendor, they keep growing in the traditional -- some of them maybe see some market share because they cannot keep up. Because traditional network firewall, whatever, they still need to keep up the new function requirement, keep up the speed requirement like the network still almost double every 2 years, so they will keep up on this. On the other side, they do need to cover more broadly infrastructure and expanding beyond the traditional border security. And so that's the part if they cannot keep up, then they starting losing some market share. But on the other side, secured -- every year, there's new things come up usually the quickest response really come from some new vendors with some point solution, whether it covers certain application of certain vertical space or some big enterprise. So that's where they really quickly respond. But on the long-term wise, you also need to working together with other part of infrastructure, other function on a separate security. So we have all the integration. So that's where sometimes you can use acquisition to quickly cover some of the function. But long term, the integration seems very important. Without the integration, it's very difficult to keep in growth because also that the separate product, all this different kind of a point solution, they add a lot of management costs. Most enterprise service provider has some difficult time to address all these added additional costs of the management.
Got it. And I think we've talked about this a lot over the years. Is that sort of pendulum between investor breeds and suites within security, there's a lot of parts of suites that make sense. You want to integrate the data that's coming from all the different parts of your architecture, you want to be able to coordinate the action amongst the various components of the security architecture. And to your point, it's just easier to manage, and you really take away some of the risks of trying to manage multiple products. But you still see a lot of best-of-breed buying take place in the security sector. When when we ask resellers, they say, listen, this is still very much a best-of-breed type category. Where do you think like -- is there -- is it different parts of the market? Is this like the suites win in the SMB part of the marketplace and its heart of the enterprise? Is it just a matter of time until everybody figures out that suites are the way to go? How should we think about that pendulum, that sort of -- that push towards a more consolidated solution and how that actually transpires over the next couple of years?
I think the new things always come up with a point solution first. You can look at whether the intrusion like 20, 15 years ago, intrusion detection prevention of a separate box, then eventually mostly integrated into the firewall, next-gen firewall. And then the same box, the same thing, 10 years ago, first come up a separate box now mostly also part of the gateway solution, suite solution now. The same thing for zero trust and for the SASE. So we are the first vendor announced that integrated OS level, zero trust network and SASE in OS instead of have a separate point of service solution. Because in the network security, it's pretty interesting. You need to have this box in the middle to stop the bad traffic, right? And so the less in the middle, the better. And also, you also need to process the traffic in real-time to handle very quickly. So the more, the deeper you can cover, the better. So that's where the point solution always very quickly address certain applications or certain attacks, certain vertical surface. But in the end, you also need the other part of infrastructure, the other function working together because the traditional part of some function of some other legacy parts never goes away. And then the new things keep come up every day, every year. And so that's where -- it's always kind of the balance about. There's always a new -- make a new challenge, new solution to meet with the point solution. And with the company, they have a more budget, sometime they need to cover threat of security quickly. That's where they adopt that point solution, first. And then in the end, they also need to consider the whole infrastructure to manage together with service providers and the other part, then gradually move to the integrated solution to the suite solution. So that seemed to happen in the last 20, 30 years I worked in the industry. It's always kind of -- this is evolving, and there's certain balance about it. That's why there's so many new security companies come up, but also very few keep growing, especially the organic growth because it's key part of innovation and the same time to address this kind of an integration issue, the performance issue, the cost issue.
Got it. Got it. I want to change gears a little bit and move to the non-FortiGate part of the solution portfolio, the fabric and the cloud solutions. And Keith, correct me if I'm wrong, I think you've talked about that, fabric and cloud being about $725 million run rate business today. You targeted that getting to be $1 billion business when you're exiting 2021. Can you talk about, one, what's in the portfolio, what and makes up fabric and cloud? And two, what are the big growth drivers? Where are you going to get that extra basically $250 million over the next year out of that solution portfolio?
Yes. I think the -- we're very, very pleased with the growth that we've seen there in that segment of our business. The 3-year CAGR on that has been about 35%. So as long as we continue to execute, I think we're going to do very well there. And I'd like to be able to say, follow this one individual product, if you will, but out of a solution set that probably spans 20 products, maybe just a tad bit more than that, they are all adding meaningfully to the platform strategy. I don't know that I could really point to a single product that's driving it. I think the acceptance of the platform strategy is actually broader than I would have initially expected. I think like other people, it resonates with me when we talk about SMBs, that are very cost-focused, are very frugal, if you will. They may not have the resources, et cetera, and they're trying to manage their entire security landscape. But it's also, as Ken has noted, it's very applicable to the service providers. They have the same challenges they're trying to control costs as well. And as you move into some of the larger enterprises that maybe don't have the same affluent budgets that we see every day, I think there's significant success there with the platform as well. So I really -- it hasn't been ruled out from any segment of our business.
Got it. And digging into sort of the cloud component, in particular, can you talk to us a little bit about the strategy around cloud workload security and container security, both from the perspective of sort of how you differentiate in the marketplace because it does seem like it's a pretty crowded market. There's a lot of vendors that are rolling out solutions right now. I think a lot of -- or overall, lack of clarity in the marketplace on how they differentiate. How does Fortinet look to create a differentiated solution in that part of the market?
Yes. I think, first, we see cloud as an important part of the whole infrastructure. And that's also, like I mentioned in the earnings call, in the 2025, the total -- we have total addressable market is about $94 billion, cloud, about $10 billion, and the network security, maybe $47 billion. But on the other side, we do see cloud is more like some point solution, you can -- where is other infrastructure can deploy very quickly, can come up very quickly. But then the other part, you also need working with a different part of the infrastructure, a different function. So that's why even for the cloud, we also want to make sure for the cloud solution, they can also integrate together, automate together different functions there. So that's real importance of whether zero trust or SASE integrated OS, you can deploy using the platform the customer like either the software version, the cloud version, clients' version to give them flexibility but make sure, always, different part of working together is also very, very important because it even takes a little bit more effort, longer time to integrate. But in the end, the customers do want to have a different kind of function or working together different part of infrastructure to secure together.
Got it. Got it. I want to shift gears again here and talk about to investments and pace of investments. I think in your most recent conference call, you guys mentioned shifting the focus, if anything, more towards growth as we enter calendar '21, take advantage of the good spending environment out there, take advantage of the broadening product portfolio as well as for FortiOS 7.0, which you guys just rolled out, can you talk to a little bit about sort of where those investments are going to be made on a go-forward basis? Where is the opportunity to sort of build out go-to-market, R&Ds, the channel, all of the above. Can you give us a little bit of color on that investment profile?
Yes, I can cover some and then Keith will help. And like I said, it's really, really -- this year will be the stronger year compared to last year. And there are a lot of new infrastructure, new architecture being developed. We see very strong pipeline. And at the same time, the internal product is also very good timing, whether the FortiOS 7.0 or Forti -- basic MP7, which also take a few years to develop, starting kind of -- position very nicely. And at the same time, we also -- like last year, we offered free training to our internal sales force to partner for the customer. We see the trend interest up like 5 to 10x. That's also helping seeding -- helping training the channel, the partner, the customer, like to make sure different part of the infrastructure are working together kind of the whole infrastructure securities -- all this is helping drive the growth opportunity going forward in the next couple of years. So we do it. And also, we started to have more investment in the sales/marketing side. That's also set up the potential of positive growth. That's probably key in to help cover...
I think we've been talking for several years about this notion of balanced growth and profitability, profitability, and we've put some numbers around that. And we've been very successful in terms of executing at it. At our Analyst Day in November 2019, we. I talked about growth in excess of 15% and operating margins that operate -- that averaged 25% or more. Obviously, we did well beyond that in 2020, even in a pandemic year with a recession. And as we come into 2021, leading up to Ken's point, within that framework, there's years that we probably balance a little bit more towards margins, and maybe other years, we balance it a little bit more towards growth. Given the tailwinds that we see in the market, how well the market is balancing back, even the macro indicators in terms of what GDP is expected to do and stimulus, et cetera, we just think this makes a lot of logical -- a lot of sense that this is a year that we want to really to focus on the growth opportunity within that framework. And specifically, I think you've touched upon you and Ken, some of the key areas. First and foremost is probably go-to-market right next to R&D and continued innovation. On the go-to-market, it really is, particularly as we move deeper into the enterprise and expand into that area of the market, it's about adding more and more salespeople and getting more and more coverage. The metric we've shared previously 3 years ago in the U.S., our reps were probably covering 65 accounts on average. If you fast forward today, within that framework that we talked about in hiring, that number today is less than 25. And we'll continue to move in that direction as we continue to make the investments that are needed as a part of penetrating the enterprise accounts.
Got it. One area of go-to-market investment that I wanted to drill down into in particular, over the past couple of years, you guys have made a lot of investments in channel partners. Channel has always been a big part of the Fortinet story. But I got to say, in our channel work, when we talk to VARs all the time, it seems to be resonating. Something really clicked, I would say, in calendar '20, the feedback about the partner program, the feedback of that Fortinet getting much better. Anything in particular that you put into place in calendar year '20 that incented that? Or is that just kind of the marketplace catching up to your investments? And anything incremental in calendar '21 when it comes to the channel partners, in particular?
Like I said, whether the channel or the service provider, it's a very important part of the cybersecurity and because they are -- in the long term, why they also will have a bigger, bigger percentage of the total cybersecure business there. So we do want to keep investing in the channel there. And also like last year, the training, we see tremendous success. And also, the other part of we see the SMB and even certain retail branch office approach is really let a lot of our service providers to help the customer manage some of that. It's a huge opportunity because like SMB is only 5% to 10% in SMB right now has some kind of cybersecurity coverage there. So there's a huge potential going forward, and also, work from home is another big driver. Whether it becomes a home branch or have the home -- have the branch office standard, both networking for security, for the quality of service, it's also very, very important. And so and we do see quite some opportunity keep working with channel, channel partner and also service provider to offer all these services together.
Got it. And then digging into margins, Keith. In calendar '20, there was -- while it was a difficult year in terms of overall macro, given that you have so much revenue that our subscription revenues amortized off the balance sheet, there was some very idiosyncratic areas of savings like T&E, none of us were traveling. We're already doing the same type of in-person marketing we're doing. Is there anything we should be aware of just in terms of flowback? Like sort of expenses that weren't there last year because of the crisis, now as we start to emerge out of the crisis, they could potentially be coming back that we should be aware of?
I think most of us are talking about T&E savings, right? And we've tried to quantify that. Probably about 150 basis points of savings on the T&E line in 2020. And as we look at our modeling for 2021, we do not expect that same level of savings. We do expect some savings in 2021. But in a simple math, I would just draw a straight line and kind of make it linear through the year, that's our best guess in terms of how much travel savings and how much is going to come back online. I think the other story in terms of 2020 was gross margin. Gross margin did exceeding well as -- including the product component. Over the last 3 years, product gross margins moved from 58% to 62%. And yes, it's only 1/3 of our business, and services are the other 2/3. But I think we got a nice little lift from the gross margin line of the business as well as that T&E savings that we talked about.
Got it. And then if we think about the business from a free cash flow margin perspective, free cash flow margins are slightly above 40% in 2020. That kind of shortcuts the balance sheet, if you will, sort of the balance sheet to income statement and translation, if you will. Does should investors think about that is nearing a peak in terms of what type of efficiency you can see out of Fortinet or do you think free cash flow margins might actually have room to move higher from here?
Yes. We shy away from providing guidance on free cash flow and by extension, free cash flow margin. But I think the 2020 was a good year for us for some of the tailwinds we just talked about. The margins were strong. The billings' number was strong. On the flip side, we did leverage our balance sheet, which is very strong in terms of providing financing, particularly in Latin America to some of our customers there. You saw the DSO number move up. We did try and mitigate the supply chain risk, if you will, with carrying higher inventory balances. So like any year, there's puts and calls. I think if you step back and look at it over the next several years, continue -- the company will continue to execute. The company will continue to grow, and we'll see how that plays out for us.
Got it. So that takes us to end of our time frame. But Ken, maybe one final question for you. As we think about calendar '21, a lot on your plate in terms of new product initiatives rolling out, what's the one thing you're most excited about? What's the one product initiative that you think has the best ability to drive incremental growth as we go into the year ahead?
Definitely, the new OS, the new ASIC will help support the new infrastructure spending there, whether the SD-WAN, 5G and work from home is pretty exciting there. And we do see it's a very good year going forward this year and next year.
Outstanding, we'll keep an eye on that. Ken, Keith, thank you so much for joining us. As always, a really interesting conversation getting to dive deep into the security landscape, dive deep into the Fortinet story. And I hope to have you guys got back here next year and, hopefully, in person at the Morgan Stanley TMT conference. So thank you for joining us.
Thank you.
Thank you, Keith.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Fortinet, Inc. transcript - plus 251,000+ transcripts from 12,000+ companies, speaker segments and full-text search - through the EarningsAPI REST API or hosted MCP server.
Get an API key View API docs →For developers and AI pipelines
Programmatic access to Fortinet, Inc. earnings transcripts and 251,000+ others is available through the
EarningsAPI REST API and the hosted MCP server.
Quarterly plans from $105 - full transcripts, speaker segments, full-text search,
and the /api/v1/transcripts/recent polling endpoint for ETL pipelines.