Home / Transcripts / Radware Ltd. (RDWR) · February 20, 2020

Radware Ltd. (RDWR) Earnings Call Transcript

February 20, 2020

NASDAQ US Information Technology Software investor_day 211 min

Earnings Call Speaker Segments

Anat Earon-Heilborn executive
#1

Good morning, everyone. Could you please take your seats. Thank you. Good morning, everyone. Thank you for joining us today to Radware's investor meeting. Our schedule for today, we're going to start with the presentation from Roy Zisapel, our CEO; followed by David Aviv, our CTO. Then we're going to break for about 15 minutes. And after the break, we will hear Raffi Kesten, our Chief Business Officer; and Doron Abramovitch, our CFO. Then we will have a Q&A panel, also joined by Anna Convery, our CMO, who's sitting right there. Please take a moment to read the safe harbor statement. And also, I would like to remind everyone that this session is being recorded. It's on live webcast, and it's also going to be available in replay on our website. Thank you all for coming here today. And Roy Zisapel, please come over.

Roy Zisapel executive
#2

Okay. Good morning, everyone. I'm going to cover several topics today. I'll start with the -- some key highlights as we see them from 2019. I would then explain our strategy and how is it evolving. I would like to spend some time on the topic of subscriptions, what subscriptions do we have, how does it look, and then to summarize. So first on 2019. Overall, we're quite pleased with the year. We've done 8% revenue growth. It's completely in line. Doron will show it with the model we gave 3 (sic) [ 2 ] years back, in 2018. So we are on that model. And I think the model also shows very strong leverage. That translated to over 50% growth year-over-year. Then I touched on subscription. Subscription is now over 30% of our booking. It's ahead of our plan. We were actually -- thought it will happen only this year. We finished it already in '19. And that's the main driver behind the growth of our total deferred that's up 10%, again, to a record $185 million. From a strategic point of view, there are several things we're looking at. There's our -- there's KPIs for the business. We did a record number of deals over $1 million with our customers. And $1 million, you can pick up any number, but what it signals to us that there was a strategic investment in the Radware portfolio from these larger enterprises or carriers. We are at a record level of that. And also Cisco, which I know we have a common ongoing interest in that, I think it's the first year, '19, that we really saw a strong pickup. Raffi will speak about it more in his presentation. But we grew 2x -- over 2x in '19 over '18, and we think we have very good momentum. So overall, in the core -- on the core items that we are tracking, we think we had a very, very decent year. So now let's go to our strategy. We will continue to execute the same strategy like we had in the last several years, and it's centered around 4 areas. First, we continue to focus on the data center because we think there's a lot going on there. Within that, cloud and security. Everything we do -- even when you ask me about our ADC business, everything that we do, we look at the prism: what does it mean for cloud? And hence, our announcement from yesterday about Alteon Cloud Control. It's taking Alteon to those cloud environments, private and public. And David Aviv will talk about that. And security, so our Kubernetes WAF announcement from, I don't know, 2.5 months ago or 3 months ago, is squarely in that. So everything we do, we look through those prisms of cloud and security. And all our investments in the portfolio, in tuck-in acquisitions we do, in field investments are with this prism in mind. The third point is the OEM and the global system integrators that we use to get more access to the very large customers. So we know we are limited in size. We are making, and Raffi will talk about it, major investments in the field organization for this year and for the years to come. But we are also making large investments in leveraging the power of others that are selling to the very large enterprises in order to accelerate sales cycle and to be present in these games. And last, but not least, M&A. We did an anti-bot acquisition last year in '19. We continue to be very active and looking for opportunities. Some are on the technology, some are on the business side. But as always, I can guarantee you that it will be something that when you look on it, you would think it makes business sense, you understand we can get the return on it and that it fits our culture and our size. So let's deep -- go deeper a bit into the strategy. And let's start with the data center, with point #1. And I wanted to share with you -- I thought, how can I give you a sense of what's going on really in the cybersecurity space as we see it? You all the time hear about attacks and attacks and this and that, but it's very hard to understand what's really going on. And the 3 numbers I have here are numbers only from our cloud platforms. So I'm going to show you a number of attacks, but not all the attacks that we're seeing with all our thousands of our appliances installed in the large carriers and enterprise. Only on customers that are now in production, live on our cloud platforms, what have we seen? And look at the numbers, and then I think when we'll talk about our approach, some of the stuff would be very, very clear to you. So let's start in the middle. In December alone, we blocked 134,000 denial of service attacks on the customers we protect in cloud. So divided by, I don't know, 31, we are talking 5,000 attacks a day. You cannot throw people at the problem. You need algorithms. And David Aviv is going to show you the strength and the power -- and that's our claim to fame. If you think what's unique, what's the competitive edge of Radware, one of the key points are those algorithms from behavioral algorithms to fuzzy logic, to machine learning, to deep, to shallow, supervised, nonsupervised, we have the complete stack and we fit different algorithms to different problems. That's our claim to fame. Then look at the right side, web application attacks. We blocked 73 million. Now when I say block in web application firewalling, you should think about an online bank. You should think about an airline online ticketing. And when I say block, it means we thought that the session is malicious, and we dropped it. If we do a mistake in dropping, legit traffic, there's a customer complaint on the other end. So when I'm saying I'm blocking 73 million, we need to be very, very accurate because in these numbers, you can create huge damage for the enterprises. So huge amount of malicious activity with very, very strong accuracy. And I think Raffi will show you some of the examples of our new wins in the cloud DDoS, cloud WAF because of these technological benefits. And last, but not least, on the right side, you can see large attacks. We put 10 gig. Why did we put a volumetric attack over 10-gig? Because for the most common enterprise around the world, U.S. included, if they get a 10-gig attack on their data center, they're down because the pipes are full. It doesn't even matter whether they can block it on their end or not. The pipes get full, traffic jam, no one can come in. So except for the very, very few large ones that may be a bigger connectivity than that, everyone else would be down. Without a service like ours, you can see also hundreds of attacks. So huge amount of activity. All those numbers are growing significantly. So cyber is increasing, we see day in, day out in our platforms. That is also bolstering the advancements of our TAM. So you see DDoS protection, it's said to be -- and you can see at the bottom where we took each number from: Gartner, IDC, Forrester, et cetera, roughly a $1.5 billion market growing high teens. ADC it's a $3 billion market. Some of it is done by the cloud providers like AWS, Azure and so on. That's not accessible to us. In the market that's accessible to us, there's a tradeoff between declining appliances. You see here 6% increase in virtual, or in software around 19%. Let's call it, from what we see in the market, it's flat to down single digit, the whole market. The web application firewall market, the web security, close to $1 billion, growing 10%. And the anti-bot market -- here, this is a fresh market. Some numbers are saying 100, some numbers have said 300, but it's a very fast-growing market, in any case. So this is our TAM. And we feel that within this TAM, we can get to double-digit growth. And in Raffi's presentation and so on, we'll show you what we are doing to accelerate growth beyond the current level. But all in all, a very good TAM for us, not so many competitors, very strategic to our customers, growing in importance and growing in dollars. So that's the current state. Then we're seeing several changes or advancements that -- you can look at the risk, we're looking at the opportunity behind them. So the first one is, many of our customers, here, you see 40%, are already multiple cloud environments, and many are over 3 -- in over 3 public clouds. I'm long enough in this industry, some of the marketing slide, you look on it, you say, it's a bit over the top this statistic, like who would run -- why would they run in 3 public clouds? Why won't they take only 1 and centralize everything there? So I want to tell you about Radware, okay? We're 1,200 people -- 1,100 people. Yes, we are advanced in technology and so on, but that's our size. We are, in Radware, running today in 4 different production clouds. We have in AWS some assets. For example, our Cloud Workload Protect (sic) [ Cloud Workload Protection ] product, the portal for the cloud WAF. We have assets in Azure. Some of our data nodes for cloud WAF are based on Azure and SoftLayer of IBM. We're running in Google. Our cloud DDoS portal, our anti-bot back-end and front-end, they're running on Google. So in Radware, I'm not talking about R&D development, R&D experimenting, I'm not even talking about IT backup that we do in Google Cloud. I'm talking like our core production. Customers are running today on 4 different cloud providers. So that's true for Rad. And go 3 years ago, there was nothing. In Doron's expense report, he didn't pay anything to those cloud providers. Now this is a huge line item for him. So we're seeing it also across all our customers. What does it mean? More entry points, more heterogeneous environment, very hard to secure, very hard to rely, let's say, on AWS and/or Azure and/or GCP for your security needs because what are you going to do the rest of the data centers you have. Not to mention your legacy data center. So if in the past, we were really focused on the enterprise data center, now in almost all of the target customers, the large customers we're targeting, just the private cloud, meaning new environments they're building in their data center using the new cloud technologies. And here, names like OpenStack, VMware, that would be the names of the environments we will work with and then, of course, the public cloud, AWS, Azure and so on. And workloads would move. They would move from the legacy to the public cloud, from public to the private, from private to legacy. There's movement in multiple directions. And it's clear that from a security point of view, the hacker can come in now in many more places. Not only that they can come in, in many more places, the public cloud environment is a very standard environment, meaning if I wanted to know how should I get to the Bank of America storage, I don't know in their, whatever, Raleigh Data Center, it's hard. I need to dig. I need to understand how they're getting inside those legacy data centers with all their mainframes, to their back-end storage and how do you go A and B. If I want to go on Capital One on their AWS and understand how to get to the storage, that's easy. It's AWS. They have an S3 bucket. I open the Internet, I type in API for S3, and I see everything with examples, with code examples, with tutorials. I, as a hacker, I have the same level of knowledge as the chief architect of Capital One or Bank of America regarding storage access on their AWS. So from a hacker point of view, moving to the cloud is heaven. Standard API well debugged, meaning I'm not going to get stuck because someone did not debug the API well. I go to the API, I'll get the data, and I'll get it exactly like I want to do. And that means that their understanding of our environment is way, way better than in the past. They don't need all those social engineering inside their corporation. They have everything in their hands. That's a major risk for security. We see that as a major opportunity for Radware. And then we'll show you in David's presentation some of the new solutions that are targeting you. So that's on the on the data center infrastructure, move to public, move to private cloud, all those movements. There's also changes on the application infrastructure. When I started Radware, everyone that talked to me about mainframes I could say, "He's older. He knows mainframes." Now I'm talking 3-tier architecture, client service, 3-tier -- everyone knows I'm old. I'm getting old because now it's microservices, it's Kubernetes world. We're breaking the application into those small little services that are working like in a mesh together. Again, 60% of organizations run microservices. That might look to you, again, very high, given, I don't know, your knowledge of your own IT system. Let me tell you about Radware. If I look on our production products, more and more of them are based already on this architecture. So definitely, the Alteon Cloud Control that we announced yesterday, full. All the infrastructure is Kubernetes. The Kubernetes WAF, we announced 3 months ago, of course, full. The cloud WAF portal, the cloud DDoS portal, the defense flow for automation of the attack landscape, all of these are fully Kubernetes-based. So all the products that we are shipping now, everything that we developed has moved to this new architecture. And knowing that, I can tell you while there's huge benefits for the architecture, there's also huge security risks. Where are you going to place, in those hundreds and thousands of elements, your security infrastructure, your security appliances? There's no place to place them. Those are up and down, up and down. They're running around. Each one communicates with everyone else. There's no physical place to place the security gateway that we know from the regular world. Again, huge challenge, huge opportunity. A lot of it is APIs, a lot machine-to-machine communication, not only user to machine, we see that as another major opportunity for the future. So that's why we like the data center: very critical, a lot is going on and we can excel based on our technological innovation. So then let's go into what we do in terms of solution to those cloud and security. So basically, if you think about Radware, and today I'm going to speak about the public cloud. But until today, we had 5 sales plays what we do. The bottom are the service providers, the blue. We have 2 plays: protecting their infrastructure against attacks -- and I think Raffi will give you an example of [ an SD-WAN ] doing that -- and assisting them in building a business. Some of the known -- very well-known DDoS services in the industry are based on our products, meaning they buy from us the products, they deploy it as a service, and they sell an MSSP. That's what we mean when we say, build the business, build the DDoS protection business, a web security business and so on. Those are the sales plays we have on the enterprise -- on the carriers. On the enterprise, we had the application delivery; the data center protection, which is practically DDoS plus, but hybrid, both devices on-prem and the cloud in conjunction. And here, we have the who's who, names as references. You name it. The top SaaS providers, whoever you thought about, is our customer. The top online, 12 out of the top 20 banks, very, very strong showing here. And by the way also all our OEMs have started from -- they started here. Then we expanded them, but they started here on our capability here and are growing -- very strongly growing application protection practice. Web application firewalling, bot management, Kubernetes WAF, Cloud Workload Protection and so on. Beyond those 5 sales plays -- and that's how we go to market, meaning we go to an enterprise, we will choose one of those 3 in order to penetrate for each one. There's the personas. We're going after the application security guy, the network security guy, the application owner, et cetera. We have our offering, our competitive advantages. And as a company, we feel very, very good on the plays we are from a solution, competitive position against the different players. Those different competitors in each one of those sales plays. What I want to tell you about now is about a new sales play that we've added to the public cloud, meaning we want to be extremely relevant to the public cloud, to companies that are either what we call cloud native or born in the cloud, meaning they don't have IT, they don't have a data center. All they have is AWS or Azure presence. So how are we critical and relevant to them? That's one. And second, to companies that are now in hybrid, some in public cloud, some in regular data centers. And our solution, that's heavily relying now on some of our new announcements that we've made, looks like this. So first, from the outside, we can protect against any attack to their public cloud data center. Whether it's web security, bot or DDoS, we will block it with our cloud services, as you know them today. What's the new and exciting additions is what we do inside the virtual private cloud. So think about it like the new on-prem. They don't have an on-prem appliance. They're in the cloud. But this is what they install inside their premise. And there's 3 things here, not one. And I'll start with the Alteon Cloud Control. So we can solve the load balancing and security. Very importantly, security application, security needs by deploying that on Azure, AWS, OpenStack and physical appliances. What's unique about that is that it has complete auto discovery of the environment. So if I mean AWS or Azure, a server went up, it will automatically join that load-balancing cluster. You need more capacity. The Alteon by itself will scale out -- scale in and scale out. You want to look on how the application is doing across all your environments. There is a single pane of glass with an application view that capture together all your different environments heavily on API integration to the DevOps and so on. We think that's going to be very -- playing very, very strong with our existing ADC customers as they move to the cloud and will allow us also to penetrate customers that are in the cloud and interested in a highly secure environment where the local, the Azure, the AWS offerings are simply not enough. So that's one. The second, if they're on Kubernetes. And many today of the workloads running Kubernetes are actually running in the cloud. AWS has a Kubernetes offering, Google has GCP. Of course, that's Kubernetes offering. SoftLayer has a big Kubernetes offering that is getting stronger, even with the Red Hat acquisition. Azure has a Kubernetes offering. If the customer runs Kubernetes, we have a unique solution to protect these clusters with our Kubernetes WAF. So we can do web security, completely native to Kubernetes, again, solving displacement issue. Where do you place security? So we are becoming part of the service mesh almost. We're embedded into this Kubernetes cluster in a very distributed manner, very unique, but very friendly, I would say, natively to the developer. And last, but not least, with our Cloud Workload Protect (sic) [ Cloud Workload Protection ] that sits on top of the AWS or Azure APIs, we are continuously hardening the environment, detecting attacks and blocking them on the fly, things they cannot see or cannot do without us in such a dynamic environment. So today, if you have an application in the public cloud, we are coming with a full stack of protection from the external DDoS, web security, anti-bot, to the internal Kubernetes protection, to overlooking all your account in the public cloud and hardening it and looking at your privileges and tightening them and detecting attacks. Unique. You can throw at me -- I invite you to throw at me any company you want. They don't have that breadth for the -- of security capabilities for the public cloud. Now not only that we are after breadth, we're also after integration. So all those products, for example, all our cloud capabilities are fully integrated. It's one common portal. It's one common dashboard of all the attacks. It's one emergency response team that deals with your escalations. It's one customer success manager that deals with your relationship. In security, you need something that will play like a team. It's not enough, 11 good football players. Many tried it and failed. You need a team. And that's the meaning of the team, this integration, the playing together, the exchange of information, understanding each other without a lot of -- that's what we deliver here on security on top of the very strong unique offering that we can deal one by one. And when we add that to the complete picture, I want to explain to you why is this team so important, why it's getting harder and harder to buy best-of-breeds. Although I can tell you, you take DDoS alone, cloud WAF alone, anti-bot alone, not to mention our new offerings like Kubernetes WAF or Cloud Workload Protect (sic) [ Cloud Workload Protection ], in each one we excel by itself. But for the next wave, I'm telling you it's not enough because that's what it takes. So what I'm -- what we try to put on the board is what it takes today to block and attack. And I made it very, very simple. I didn't even go to the complexities of running this application in the public cloud with all the APIs and with all the privileges and so on. I did like a very, very simple, reduced case in complexity. So if I have my application on the right side, what you see at the bottom is all the tools I need in order to block today a cyber-attack. Now if I don't have one of those tools, let's say, I don't have the anti-bot, so all the web scraping, denial of inventory, all those attacks, I cannot block with all the rest of the tools. If I'm missing the WAF, the brute force, the cross-site scraping, the application misuse, I will not be able to do, and so on. So for each one, you can see the class. Now everyone wants to speak about viruses. The family of viruses, you will not be able to protect against. It's very, very hard for an organization to buy budget-wise, to deploy and even much, much more difficult from operation and expensive to operate all those tools. The applications are changing. It's a very dynamic world today. As they change, you need to adjust all your security policy, all your security plan to it. Who's going to do it? And who's going to do it 24/7? And who's going to do it in Christmas Eve? And like how do you make sure that all those tools are really, really working together? That's where we come to play. We have a fully integrated offering. We run it for the customers if they choose to. If not, they can operate it, and we can just supervise it and offer consulting services on top. We take care of the integration between the components, we advance the architecture and we make sure they don't need to buy 8 different separate tools, but they're actually buying 1 attack mitigation solution from us. We believe that's a very, very strong competitive advantage we have in the market beyond all the individual advantages that we have. Taking it all together, that's our view, is that when you talk about data center and application security for legacy data centers, for private cloud, for public cloud, as I've mentioned, just now we have the broadest. We cover the biggest amount of types of attacks and the deepest. Each of our offering, based on our algorithms, is very unique. We are not running heuristics. We are running real algorithms. You're -- David comes after me, challenging on every algorithm, on every capability we have. You will see how deep they are. And that gets us, in our opinion, a sustained competitive advantage in this industry. That -- I think last year, and we'll talk about it, we've also expanded with some of the new families of algorithms we launched. So now let's move to the market. And as I said, beyond the investments that Raffi will cover, that we are making -- and we are making big investments this year in the sales organization, and that's why the leverage on the EPS is not as probably some of you wanted to see. And we acknowledge that. We understand that. But we think there's huge leverage in our model like you've seen in the past 2 years, and Doron will cover. And we think it's the right time to invest. We have all it takes to invest. And it's time to go for accelerated growth. Some of this investment is going through those unique channels. And we have the OEM partner channel, namely Cisco, Check Point, Nokia. We have the global system integrators. We're talking here on companies like Accenture, like Atos, like Tata Consulting Services (sic) [ Tata Consultancy Services ] and so on. And we have the cloud service providers, cloud and hosting providers. What's common to all of these is the large customer, they have very, very tight relationship with them. And our approach is to leverage that relationship. For example, is Cisco the dominant player in security or Check Point; if it's a carrier, is it Cisco, is it Nokia? Think about a carrier, how many of the carriers around the world? Cisco is not an incumbent, and Nokia is not an incumbent, meaning they don't do any business with either Cisco or Nokia. If they do with one of them, we should be able to get a good seat at the table when they are discussing their security needs. Think about large enterprises. Think about a large enterprise that doesn't use Cisco, doesn't use Check Point, doesn't do business with Tata, Wipro, HCL, Atos, Cognizant, Infosys at all. If they do, we should have executed properly -- maybe not everything in 2020, executed properly a seat at the table. So that's the GSIs, that's Cisco. From our point of view to the Global 2000s, which we think with each one of them, we can do $1 million of business, give or take a year, maybe not every year, but on average $1 million. When we execute properly this go to market, and Raffi will get you updates where we are in each plays and how we are progressing, we think we can get to that opportunity, a seat at the table, in each one of these. And that's why we're investing. We think the time is now. The time is right. We've built the bridges. We've invested a lot in getting them there. Now we need to take it to the next level. That also -- all your questions, that might happen. Okay, this company is bigger than you, 5x, and this company is 7x and what are you going to do about it? Well, we're bringing our big brothers with us. So we come with Cisco. We come with Checkpoint. We come with Nokia. We come with Tata. We're changing that philosophy considerably when we're acting like that. Okay. Based on our last conference call, investor conference call and some of the feedback we got, we wanted to give more visibility into subscription. And Doron has it in his presentation, that extra visibility, but I want to start talking about it and give you some more indications to where we are. So first, I already mentioned subscription is already over 30% of our booking, and that drives the growth of the total deferred. This is our, today, subscription offering, and we continue to build. As you can see, you see here what is new for 2020 and what is 2019. You can see we continue to add more and more subscriptions. Now some of them granted is a move from product that we used to sell as perpetual to subscription, some of it. For example, the management [ T-Systems ], we used to sell perpetual. We're now selling them as subscriptions. But many are product add-ons. Last year, we talked about the ERT Active Attackers Feed. We're now adding the bot manager as a subscription on top. The Alteon Elastic License data transition from Alteon to a product. ERT Silver and Gold, those are add-ons to a product sale. And of course, we have the new cloud subscriptions. We're adding new cloud offerings that are not -- generally, they're not replacing something we had. But from the get-go, they are being sold as subscription. The fact that we accelerate -- so here, you can see what was the percentage of booking coming from subscription. And you can see in '19, we accelerated greatly, beyond even our plans. Now it's true that subscription, when we move faster into subscription, there is a headwind to revenues over the short term, of course. You start to defer. So you see the total deferred going up. Revenues, maybe you get a hit, but we think it's very -- from all our information, from all the data we have, from our renewal rate, from our cross-selling in subscription, it's a very, very positive trend for Radware. We're getting better visibility, much bigger lifetime value, and we really like this acceleration to subscription, which we think will continue. Doron will talk about it in more details. So to summarize, I think we're playing in a very, very good market, growing market, strategic market. The attacks are getting more sophisticated. The damage is getting bigger. And we are uniquely positioned through a very broad and deep offering to help the top customers. And I can tell you that in this year, I saw an evolution in what Radware does and the discussions we have with really the leading carriers of the world, the leading enterprises, about all the next strategic challenges that they face as they move to Kubernetes, to 5G, to data centers. We're getting deeper, and we're seeing bigger projects and bigger opportunities. They are not immediate. They are not Q1. Don't ask me, okay, how we translate to Q1. You don't talk about the carrier security for 5G for Q1. But those are significant opportunities and strategic position for Radware. I think we're very well positioned from our ability to access the market with the OEMs, and specifically Cisco, and with the global system integrators. And I think we're doing very well on our transition to subscription even ahead of our plans. So thanks a lot, and I'll let David cover more the technology and the advancements we're doing there.

David Aviv executive
#3

Hi, everyone. Good morning. Glad to see many familiar faces. Anyway, I will take you to the ride from what we call from transition to transformation. I think that Roy made already a lot of the introduction that is going in that space. And from transition, we mean moving the customers, doing some baby steps in the multiple dimensions, moving aggressively to a new business model, a new technology model. Now the issue with -- obviously, with transformation, transformation redefines the rules. So it shapes differently the way what our customers wants to do. It shapes the way we provide our solution. So I will take you through a short ride on the strategy that shapes our solution and the way we redefine the rules for ourselves as well. So that obviously creates an inflection point in time. And the inflection is really now. I think you have been -- you saw from Roy many of those indications. And I would like to look at that in 3 different angles. The most important thing here and the key takeaway is that our customers simply change the way they consume and they pay for services. So the consumption, the payment is different, which means the solution that we should provide should be transformed as well. So you can see when we talk on gravity centers, definitely the move from the chain, from premise-based solution, adding SaaS to the portfolio, moving to a cloud-naive solution -- cloud-naive, I mean, lift and shift. I'm taking -- lifting what I'm doing, shifting to the public cloud, using IaaS, and hoping for the good. When it works, customers now understand the power of the cloud native, namely using cloud-native analytics tools, cloud-native storage tools, et cetera, integrating them into the new way of building application. And they need it very simply in that competitive environment, accelerate applications, accelerate the go-to-market, accelerating my -- as a business competitive advantage, my web appearance, et cetera. So we are moving to the way we are redefining the application build-out. So in order to do any transformation, you need to have power tools to do that transformation. One of them is the cloud, obviously. And the second one, I think that Roy pointed out, is that -- is using microservices, being able to really accelerate the deployment of application. From our point of view, it changes also the point -- the balance point between the networking guys, the DevOps guys that are starting to own some of those deployment, owning those deployments. So with that -- and by the way, it's so relevant because it's considered, Kubernetes, et cetera, as a cloud in a cloud, which means you're building an application cluster using Kubernetes, it's a micro cloud. Now you can run that micro cloud in your laptop. You can run it in the cloud. You can run it in VMware. You can run it everywhere. So it gives a way to those developers to build and consolidate the application build-out. So that's definitely a big shift that we are seeing. And the third shift is the network itself. The network itself is being redefined mainly because the 5G and the edge cloud impact. It's a huge impact where we understand that the network economics for the large service providers breaks those kind of massive scale. And the reason is that the focal point is moving from core centric to edge centric. We're seeing the implication of that. So the main takeaway here, from this one, from that inflection, we see cloud centric, application centric, edge centric. Everything is starting to be aligned for that. So let's move the map and look at the new attack surfaces. I mean if there are so many changes, definitely, the attack surface is being changed as well. So let's map the attack surfaces accordingly. So obviously, when we talked on gravity changes on the cloud native, we are going to be introduced with a generation of cloud-native attacks. And once again, as Roy pointed out, it's a very simple fact that all the public cloud APIs are publicly published, so the DevOps knows them, the application developer knows them and the attacker knows them. Gives them an advantage over those what we have implemented in the private. So for every API, there is a provision model, a role model, et cetera. So we start seeing excessive permission attacks. We are talking now on a different landscape. It's not anymore on inspecting traffic and applying algorithms to detect anomalies in traffic. Now we are looking at the API invocation level, and we're trying to detect anomalies at the API invocation level. It's a completely different paradigm. And by the way, not many companies crossed, up to now moving aggressively from the traffic network to API, cloud-native paradigm. So in that sense, exposing resources, my resources in the cloud gives the attacker visibility on what I'm doing and letting him in a very easy way to plan campaigns against me. And many, many, many of those campaigns were advocated by the way that crafting by spearfishing, social engineering, getting credentials and using that credentials to use fake identities in order to do the excessive permissions, run on behalf of me, take over resources, many, many kinds of attacks that are happening. So that's the cloud. When we move to the application-centric level, well, we have similar things. Now we are talking on application assets, data specifically. So we are talking on encrypted floods, let's say, encrypted HTTP, SSL floods. We'll see a little bit, 2 slides from here, that the most important fact that this is providing an attacker an excellent aggressive attack tool against application clusters. Credential stuffing or any other mean for data leakage, being able as the way we did at the cloud level, at the API level, to be able to exploit by [ any mean ] credentials to the application itself and one account takeover in order to leak data, steal sensitive information, et cetera. And obviously, the API exposure. All of the microservices are about API communication, web API communication. So everything is going to be automated addressed by API, API gateways, B2B, B2C. Every communication is going to be run by that. So that's a major way, a major concern that has to be protected as well. The last, but not least, is the network edge. The network edge is the interesting point because the way the 5G is now built is completely different than the current LTE 4G, 4.5G, et cetera. It's like the 5 -- the fifth generation of the fighter, the [ self ] fighter against the 4.5 and 4 fighters. It's a different beast. In the sense, it's a distributed environment, completely distributed environment, many breakout points, everywhere. Every network today has limited peering and breakout points. With 5G, everything is open, SD-WAN, cloud-native from any to any communication, creates a huge headache for the network providers because we are now -- we need to protect and look at not 1 tera traffic, 100-tera traffic. So how do you do this? It's a challenge and better -- because everything is connected to everything, think of industrial IoT, commercial IoT, workers that run in public cloud. It's a big challenge. So we do see new generation of attacks at that level: carpet bombing, starvation of every stateful device on a network range running on all the IPs of vertical and horizontal simply using amplification, TCP-based amplification attacks, starving everything, burst attacks, IoT bot-nets. All the good flavors that you can think exists. So what I'm trying to map is there are many challenges, which are different from each other that needs to be addressed by different technologies, by different algorithms at every layer, the network edge, the application-centric one and the cloud native. Doing that, our strategic approach to those evolving threat landscape is actually built upon 3 pillars: deep, broad and innovate. Deep means we start -- we continue to leverage and expand our competitive edge at algorithm level, to add more and more stuff for the behavioral algorithms, data lake analysis, AI, AI technologies, deep learning technologies in order to be able to address all those kind of threat vectors that I've explained and Roy explained before. Broad, a very broad portfolio and delivery, covering from the perimeter, whatever perimeter, network perimeter, data center perimeter or edge, to the cloud native. We'll come to that in a second. And innovation. Take all those and push it to the new frontier. The 5G and edge frontier has different challenges. You cannot simply take -- do a shift and lift of virtual appliance and hope that it will work for 5G. It won't. Same thing that you would do to -- you would like to do a shift and lift to Kubernetes or to cloud native. This is a new paradigm. It's not only a technology product, it's a consumption product. Say, the way it's consumed by DevOps by application guys, which is completely different the way we used to work at the different perimeters with the network teams. That means other different product and once again, I stress the product that not many companies still crossed yet. So let me take you to the way we shape our solutions. So what we are seeing here is the way that we classified as protection the perimeter and protection in the cloud or external and internal, the way we'd like to look at it. At a perimeter, you have 3 delivery modes: the premise, the cloud and the hybrid. And this is our claim to fame for many years, the DDoS, the WAF and what we have added this year to the portfolio, the Bot Manager, to provide a complete holistic stuff that can be provided, consumed in different way by customers, and we continue to drive our capabilities there. As I said, dealing with encrypted attacks, another thing that you will see in a second, we'll have some kind of deep diving into that. With that, we are taking and expanding our solution portfolio, understanding that customers will need a much broader stack, much deeper stack as well that goes -- moves into the application-centric environment. And for that, the way we'd look -- we look at it, more and more customers are deploying that in containers. So we have built a Kubernetes, WAF or a built-in Kubernetes, built-in solution that is a citizen -- is a native citizen of the Kubernetes ecosystem. Native citizen means it runs within the Kubernetes pipeline automatically, natively, no exception, same tools. So it means when a customer deploys an application in a very easy way, he will deploy our protection the same easy way. And the next frontier is the public cloud, where we have launched our Cloud Workload Protection. Once again, a native citizen of the cloud -- in public cloud. That product looks for anomalies in API invocations in the cloud telling the operator, are there some anomalies that can imply for attacks running here, penetration and many other -- many other factors that we are providing solution for. So looking at that, you can see the completeness of our solution. So with that, we provide to the customer a deep, a broad, a rich, a comprehensive and a very competitive solution. Let's look a little bit deeper into our comprehensive integrated solution. So those are typically data centers that are deployed either in the private, in the public or the emerging edge cloud, edge compute, edge cloud with the 5G networks. So up to now, as you all know, we provided protection at the perimeter, and you can see the different stacks. At the perimeter, you can see the private cloud being able to provide a solution in either by SaaS, either hybrid, either on-prem, whatever format you would like. You can see as well that we have extended that offering to the public cloud, namely running the solution in a PoP, as a PoP, natively integrated in the public cloud, in AWS in Azure and GCP will follow. So now we can provide a very holistic way to customer to protect the perimeter anywhere. And obviously with the 5G, it's a different edge issue over there. As we said, the service providers are moving because of the scale issue to a new model of deployment. Distributed, disaggregated model is another model of an edge fabric defense. So being able to add what we call protection in the cloud, provide you protection for all deployment models, namely virtual machines, container and cloud native. Our ACCs, acronym for Alteon Cloud Control, provide you the ability to harmonize any workload that runs in any virtual machine in any cloud anywhere automatically. That's auto discovery, aligns automatically the security policy and integrates to the cloud ecosystem, can run it everywhere. If you move to run containers, we have the KWAF, the Kubernetes WAF, which is once again integrated within the Kubernetes pipeline environment, harmonizing Kubernetes clusters anywhere, can run a cluster in the public cloud, a cluster in the private, a cluster in the edge cloud, runs harmonized. And the Cloud Workload Protection, that takes care on understanding on the cloud posture. Well, I have a cloud posture, namely I have different API invocation that run because of my deployment. Well, I need to look at it. Someone is hacking. Someone is snipping. Someone is trying to steal data. That product gives the answer for that. So when we look on the entire landscape, we start to navigate. We look on that. We have now a solution for the north-south at the infrastructure level. We continue to innovate there. We [ avert ] to the perimeter, to the edge application at the north-south, namely the WAF at the edge and the Bot Manager in the edge. So are able now to protect against different web breaches at the edge, different bot activities at the edge. This is the north-south space. And you can see this is, by the colors, purple is the infrastructure. This one, the reddish is the application. And the third tier is the cloud native. When we move now to the new stack -- the new stacks, you can see that they are moving into the east-west, so-called east-west, but there are many differences. North-south, much more stable, owned by our traditional NetOps guys. East-west much more noisy environment, dynamic applications spinning up, spinning down, everything moves, owned by DevOps. It's a paradigm change not only from the technology point of view, from the consumption, the way you build the product, how you plan them, who are they going to serve, what kind of visibility are you going to provide. Everything has to be taken in consideration is a change. That's why it's not a lift and shift approach. Lift and shift cannot succeed here. You need to have a different mindset. And what we are doing now is extending the north-south to support the new 5G environment. So now if an enterprise runs workloads, public, edge cloud, it runs IoT devices running in an edge cloud in service provider, runs workload, analytic workloads in AWS and writes its own data centers, we are able to harmonize the entire north-south. And we are going to harmonize as well all the cloud, all the east-west activity, providing once again -- and this is what I mean -- a deep, broad and innovative approach, comprehensive and a very, very competitive approach in this one. Last but not least, the other layer of the Cloud Workload Protection adds the cloud native. That's the blue one on top of the stack. So you can see now that we have stacks, very deep stacks across every domain, very broad across domain. We are going to harmonize, more and more invest in harmonization between the stacks, deeper insights. Now you can see the way you can share insights between different stacks. I can learn many things that no way that I can see the north-south in order to provide insight to the north-south to block activities. There's no way that the north-south, that kind of resolution to understand and you can do it across things. So we are just in the beginning of a new capability and revolution in security that we are going to provide because you can see the way the market is evolving, the way the customers are consuming the services and they are willing to pay. And we are actually addressing it. That's part of the -- I would say, the investment that we are accelerating now in order to be able to be ready for the upcoming years on that. Just to give you an example, some of the attacks, some of the innovation that we brought to the market just lately seeing based on the attacks in the recent 12 months, carpet bombing, encrypted attacks. I would like to stress the encrypted attacks because this changes the way the edge is working. Usually, we are doing a lot of asset sale decryption at the edge. But some butterfly change in [ industry ], making different changes in North America, not the corona. I'm thinking literally when you look on Kubernetes, the application clusters are building a way that all the secrets are kept in the cluster. I mean you can expose some of the secret. They don't want because there are different teams. Everyone runs his own to run very fast. SSL is going to be terminated here at that level. And if any many -- as much as many firewalls doing deep DPI, without DPI on the edge, you don't have the budget literally, CapEx, OpEx and latency-wise to do decrypt, encrypt, decrypt, encrypt. Has to be done here. That's why the encrypted attack, the way to detect applications flat within encrypted tunnels without the necessity to decrypt is critical because this is a common tool for attackers to run after all stateful devices in the application cluster and simply kill those kind of clusters in a very easy way. So this is, I would say, another way to look the way the insights and the ecosystem now that is built between east-west component and north-south components influences the solution and the entire stack. Once again, data leakage, some new innovation at the north-south application tier, account takeover, credential stuffing is very common to fake identities in order to be able to make you severe damage by stealing sensitive information. Other, as we said, the ability now and the application layer to add the OWASP, open web application protection, top 10, let's say, at the Kubernetes level, so we can now look in each and every east-west intra-cluster transaction and understand if it contains some malicious information between a database cluster and an application cluster, let's say. And last but not least, an example in the Cloud Workload Protection where we add a lot of AI-based technology, artificial-based technology in order to track abnormal excessive permission activity by API invocation that indicate if someone is starting to mess with the behavior, the way a specific role is utilizing his permission because there's a chance that if he deviates in those kind of abnormal activity, it means that someone has already taken his credentials. So these are examples of attacks, common attacks that you are used to deal with at the [ NetFlow ] layer, new application level attacks at the Kubernetes network and very new attack surfaces at the cloud native effect to address the transformation at the cloud level, at the application level, at the edge level, all those 3 levels. So in that sense, that is increasing our addressable markets because now you have the born in the cloud market, the full stack supporting the born in the cloud. Have a full menu not only, a, a SaaS can integrate a dip as deep as you run. Classical enterprise or those which are reborn in the cloud, they're born and they're reborn in the cloud by using their premises as they're using now more and more cloud native services. And the third addressable market is obviously with the 5G, the service providers. It's a very full-blown addressable market, but those stacks in the integration -- and the integration of them. So a very sure tool on the investments, the investments we are doing to support the growth. And I would like to show in 2 layers, in the way we provide very deep insights, namely behavioral network algorithms, the way we move into from the network to support application defense. And after that, into the right to the cloud native protections. You can see all over self-learning algorithms that support network attacks, application attacks, cloud native attacks. In the cloud native, you can see complete -- 3 areas that we are dealing with, mainly compliance and response, prevention like permission, excessive permissions and detection algorithms. So the support, the prevention phase and the detection phase if someone has already penetrated and is doing his lateral movement inside. So you can see here the strength. And you know, if you look at it and you look on the traditional competition, traditional competition didn't reach to that level yet at all. You know our traditional competition. Here, we have new competitors obviously, but the benefit that we have is the broadness of our delivery and the stacks. And the broadness, you can see the delivery from obviously the appliances, through virtual appliances, through containers, through our SaaS, Security-as-a-Service (sic) [ Software-as-a-Service ], and through delivery in the public cloud. So now you know and the way we can craft different solutions for different challenges that we have from our customers, you saw it in stacks, obviously on top of it, you have the control automation, the big data analytics, and you can see here that it's there. GEL, the elastic license, is now providing you a very flexible way to provide licenses based on many factors, bandwidth consumption, other consumption. You can play it across any cloud. Alteon Cloud Control is a excellent example. So we have controller for delivery, controller for security, harmonized by the GEL. And obviously, our cloud factory analytics sector, which are the -- what we call it, those are analytics factory, which are actually using different algorithms, different capabilities in order to support and push down profiles, ACLs, many, many activity -- many mitigation, many mitigation ways to the data plan, obviously supporting also the threat intelligence activity and many, many activities. Here is a huge cyber fusion factory. We have our -- the threats and the honeypots and third-party feeds. Everything is fused together with our customer insight. And we are building insights for different category of solutions. It's really a powerful solution. So to sum up, it's really -- we believe that we are expanding our competitive advantage and once again, by being very deep, very broad, very rich, very comprehensive and with a very big competitive advantage. And you can see based on the, I would say, based on the investment that we have done in the last 3 years that you will see and we will see probably the beginning of '20 -- the year 2020, some of the fruit, bearing the fruits of those investments. And definitely, it will accelerate that kind of solutions and numbers in '21 and '22. Thank you very much.

Anat Earon-Heilborn executive
#4

Okay. So there will be a break for 15 minutes -- 14 minutes. Let's start again at 9:55. [Break]

Anat Earon-Heilborn executive
#5

Could everybody please take your seats? And Raffi? Thank you. So Raffi Kesten, our Chief Business Officer.

Raphael Kesten executive
#6

So good morning and welcome. I'm really happy to be here with you. For me, it's the first time, so welcome again. After listening to Roy and David, they basically covered the company vision, the technological vision, I will cover the execution angle, and basically, I will cover the field perspective. A bit about myself as a short introduction. I joined Radware a bit more than 6 months ago, and my experience is basically from the international high-tech market. I used to work for Intel here in America and in Israel. Then I moved to work for Indigo, an Israeli company that was acquired, very successful one and acquired later on by HP. And my last job that I did for many years was the COO of NDS that later on in 2012 was acquired by Cisco, was quite a significant Israeli exit. What I did at NDS, I was the Chief Operating Officer, basically focusing on sales, customer success, delivery, support. But I think that to put everything on one word is, basically, I was responsible for the execution of the company. And in 2012, '13, when we were acquired by Cisco, we reached and we crossed the $1.3 billion of revenue and quite a successful and profitable business. What is my role here? My role in Radware is a Chief Business Officer. In every company, titles are different. I'm focusing on sales. I'm head of sales for all the 3 basically regions, running engineering, sales engineering and running professional services. My job, my goal, my objective and the thing that I'm doing from morning until night in Israel and traveling a lot is basically to accelerate and focus on growth. I did an in-depth search before I joined, and my observation before and after I joined, logos that we have are outstanding. And I'm still talking about outstanding logos that, unfortunately, we cannot kind of disclose openly that compared to the logos that I was very proud with in my previous job, I was amazed, outstanding logos in the financial services, retail, carriers, pharmaceutical and more, and I'll bring few examples later on. This is an outstanding situation. And I want to say that although we are only accelerating the OEMs and the GSIs now, most of this deal, if not all, and the logos that I'm very proud and I'm sure that the people that brought these logos to Radware are proud with, were done by a direct sales, and this is still without an in-depth involvement by the GSI, the OEMs, all the external forces. Many areas of excellence that we just have to replicate by good day-to-day execution, broad portfolio. We heard it from Roy. We heard it from David with many products that meets current and future customer needs. And at the time that I'm joining the company, the 2 main activities with the OEMs and SI or system integration, worldwide, Indians, et cetera, and I'll cover it later, are kind of accelerating, relationships are improving. And I think that in one word, I will say that it's not that they are attractive to us. I think that what we achieved in the long process from starting these projects until today, we are being -- and we are attractive to them as well. I think that's the transition that we had and we faced in the last few years, and it's true for the Cisco as an OEM, and it's true for the GSIs. What are the main focus area? And I'll try to be very simple, very sharp and very clear. This is a message that all our sales engineers and sales reps are getting from their management, from me, from Roy on a daily basis, basically, focusing on the inside in the sales organization. Remember, most of our booking is coming from the -- it's still coming from the inside, so we cannot ignore it. So when we are talking about OEM, GSI, GSI and OEM, we must not forget that still the vast majority of the revenue and the booking are coming from our direct and great people. Focus on the access to the market and the GSI and OEMs and focus on the obvious, which is customer satisfaction that will renew their contract and we will be successful in lending and expanding them. Focusing on the inside. Focusing on the inside. Basically, we have a structure that is working properly and nicely. We are investing a lot and invested a lot in H2 of 2019 in people, and I'll be very -- and I'll bring you a few kind of deal about it. U.S. sales force grew and still growing by much more than 25%. Why? Because we see the potential here in America to adapt and to get more people that will simply bring us more business. We invested a lot in resources to grow the market, to support the OEMs and the new product introduction. Few examples to that. The Cisco journey and the GSI journey basically started in -- the Cisco journey started by us working here in the U.S. But when we moved last year to a faster relationship and better relationship with Cisco and we started to see the growing business, we started to invest in people not only in the U.S., in the regions, basically to support the local growth, something that we have not done before because, guys, it takes time -- and I'll cover it later on -- to grow a business with such a conglomerate like Cisco or like Tech Mahindra or like HCL or whatever. We focus on operational excellence, and we focus on the people because I think that you got from both Roy and David, the description of all the products, and I'm talking about new products and even products that we introduced 2 or 3 years ago that are coming to the field, and we need the field to be ready and to be able and to be capable to launch it, to sell it and to successfully sustain it. It's not an easy task. In terms of the market access and then I'll bring example from the GSIs and the OEMs. As Roy pointed out, we have the ability to access all the big 2,000 companies. Again, we have done it in the past and the logos that we have today, 90% of them or more are not from the Cisco or from the other OEMs or not from the GSI. We did it with our 10 fingers in the past. But one, it took longer, and I'll bring example later on. It was much harder to win, and in addition, there are many companies today or many potential customers that without your connections to those player, you will have no chance to win. And I'm not talking about defense, Pentagon or whatever, that it's hard to come as a company like us without the umbrella of the -- those big players. And I'm talking about even main or major potential customer that they adopted the outsourcing kind of mentality. And basically, they will even force you if you know them or you create relationship with them. They will tell you go and bid with others. Today -- and that's what we are focusing on every person. Each and every salesperson has a Cisco and GSI plan that basically he is monitored and he is doing his best to win and he is basically measured upon. Those external forces, the GSI and the OEMs are huge and great generator for new logos and significant deals, and I'll talk about it later on. And as I said before, we moved -- it took us quite a long time to bring the Cisco to kind of maturity level, and I'll say -- and I'll bring example later on. It is a complicated challenge. It's a top-down first that you need to go to the leaders, but then without focusing in the region and on the bottom -- and the bottom up, you'll have difficulties to win the deals. Cisco. This is really a great example that I'm very proud of what Radware did in the last few years in this direction. Yes, it took us time. But when I'm looking backward, even as an outsider, when I looked at it, I saw that the channel and the journey was long. To reach a moment that you are an attractive supplier and partner to Cisco, that it simply takes time and effort. And after you pass the first phase, then you need to develop your infrastructure to put your partner and to put your product. And product is kind of a growing thing and dynamic thing. And after you do that, then you start to train the field, your people and the Cisco people in the field. Guys, all these activities, top-down infrastructure and educating the field, it takes time and it takes a lot of time. I'm proud to say that, in most of the cases, it is behind us. And it's behind us. We can see here even the booking results from '18 to '19 that it grew by 2x, and the target for 2020 is again growing by 2x to a target that Roy and Doron committed 3 years ago or 2 years ago that -- to reach tens of millions of dollars on an annual basis. This is not here only for the slide. These are the quota that people will be measured upon and people will be paid for. And it's quite a significant number, especially when you still keep the 2x when the numbers are growing. I'm very confident that we will achieve it. I'll show you later on the result from Q4 that are giving me that confidence and giving us the confidence that we will be able to do it. We are working quite hard on it. We created Cisco forum and Cisco X and Cisco Y, and the people, the language in Radware changed. It's not only a company that we are pushing toward a direct sales. It's a company that also using other sources to reach the outcome that we want. We see an increasing number of global opportunities in the CRM. We are tracking it on a daily basis. We are participating in a very strategic Cisco project, and I'll give you an example in a case study in a second. And all Radware sites are active. Guys, it's not trivial. It's not trivial. It was not trivial in the Cisco side. Look what happened to John Maynard that sent an e-mail to all the security sales organization internally at Cisco and basically said, "Guys, work with Radware, and you'll be able to achieve great result to support us in integrating our product but also for you to make your quota." To get this e-mail, took us years. Still, it's not enough because we really need the support from their guys in the field and not less important, to get the support from our guys in the field. So all Radware regions are active, means weekly meetings with the Cisco account people, for example, and it's almost the same but in a lower level with the other, with Nokia and with Check Point that we are investing less, still investing a lot. And as a case study, we won, but let's be honest. We were brought to the deal by Cisco. Without it -- it's in Asia, a major carrier in Asia. Without Cisco, we wouldn't have the access to this account. And it's true in the other example that I'll bring later on when I'll talk about the GSI and others. This is a major carrier in Asia that is running fast, and for Cisco, it's one of the most, if not, the most service provider, prestigious project that they run. The exposure is to Chuck Robbins and to others. They're trying to do their best with an effort to win it. And even now that we have 6 months in the project, I think that Cisco is starting to talk to us about more 5G or carrier new-generation projects. As you can see here, we have here the full software-based application delivery and also security, so both Alteon and WAF and with our subscription, with our vision portal that we do. Very successful so far, very challenging project for Cisco but for us as well, major project that we are all involved on a daily basis with an effort be successful in it. Moving from Cisco to the GSI. Again, journey that we started few years ago, but similarly to the -- what we were facing with Cisco, it takes time to reach the moment that we become attractive to those conglomerates. We are talking here about the American GSIs. We are talking about the Indians, the Tata, the Wipro, the HCL, et cetera, and we are talking about the European. I'll bring one example later on about the wins. But again, why it's attractive for us, I think that we all understand. It's a faster time to market. They have a very wide, broad kind of coverage. It's much more scalable. We cannot build our future only on our kind of direct activity. But why it is starting to be attractive for them and they're bringing us to business? One, because the trend of moving toward security is kind of accelerating. Second, their move to the cloud and even to the public cloud is a bit of a threat to them because of the outsourcing model, et cetera, and they really see us as a supporter in those 2 directions of moving to the cloud and moving even deeper in security. One case study, it's a major pharmaceutical case study in Europe, a win from Q4 2019. It's a multiyear contract, multimillion-dollar contract for cloud DDoS and cloud WAF. Look at the size of the project, size of the project, 20 data center, 700 protected networks and 3,000 application that we are protecting. So look at the size. Deployment is basically global, project started and managed in Europe, but the implementation will be everywhere, and it will cover North America, Europe of course, Asia Pacific and Lat Am. One major achievement that I really like to highlight is the fact that we are replacing multiple incumbent cloud security providers. And something that is common to this activity and this win and the previous win that I talked about before on the carriers that we won with Cisco or Cisco won and brought us is very short cycle time. Usually, big project like that takes 9 to 12 months or even 18 months. I think that, here, the overall process from putting the opportunity in the CRM until winning it took us much less than 6. That's one of the advantage that you have a player like GSI, like a huge conglomerate that is running $200 million, $300 million or more in the same account. They have the ability to change things. One thing that I would like to bring as an example that cover both the Cisco, the GSI and the direct in one example is we have a project that we are still bidding. Chances to win, I even do not want to mention here. We started it as a direct -- it's a carrier -- major carrier in Asia. Started it as a direct and then Cisco approached us, so we are offering it with Cisco. Tech Mahindra wanted to bid with us, so we are bidding it with Tech Mahindra. And then Nokia found themselves outside of the camp, so we are bidding it with Nokia as well. So basically, direct Tech Mahindra, Cisco and Nokia. I think that so far, it can be exploded because of how we are going to manage it properly and high integrity, et cetera. Yes, we do it and we do it properly. One of the deal, we'll win. Yes, we are facing a competitor that in addition to the 4 that we are competing with. A great example of, again, the message that I tried to say before that we are attractive to those big player, one for defense -- as a defensive mode for them but also as a -- as a source for revenue. Moving to the obvious one and this leverage customer base potential. We must continue, and I have to say that retention rate is good or even excellent. And we have to continue, and this is for the third point that I wanted to focus on. We invested a lot in major accounts because we found out in 2018 and 2019 that the request and the demand and the patient that those major accounts, especially in the carrier front, they want the solution and they want the bug fixed in a day. They cannot wait. And when you do not support them well, you are at risk. I must say that last year, for sure, the last 6 months, we see a major improvement in terms of relationship, customer satisfaction and -- et cetera. One thing that Roy covered before is the number of deals that are above $1 million. 2019 was a high record with more than 32 deals that were above $1 million. And for that, you have, one, to support them well; second, to make sure that you are onboarding them well and supporting them well even during the sales. One example that I want to cover is the top-tier #1 carrier in the U.S. that we are, again, an example of the logos and the brands that we are supporting and we have. So basically, in terms of products, we have the defense process, the mitigation and also the portal. But I think that the most important thing here is that we continue to support and to satisfy the customer. And again, I'm talking about a top-tier U.S. carrier, and it helped us a lot in addition to the innovation and the 5G new architecture that David covered before. The fact that we are perceived as a good supplier, we are perceived as a good potential supplier to their next-generation network. And before my summary, the question is that I'm asking myself, why I'm optimistic? Or why am I confident about the future next year and the year after, that Doron will cover later on. First of all, I think that the focus that we put, the internal organization, the external sources and in the customer, guys, it's really the basic. I'm not inventing anything. This is a basic -- that our job is to execute and to continue to execute well. But in addition to that, Q4 '19 was a record quarter in the cloud business, and we grew more than 2x Q4 '19 divided by Q4 '18, and over 40% of the new cloud business comes from new logos. So as I've said before, cloud, GSI and OEM are a significant source and a safe source to get new logos, and the company is measured by the creation of new logos. But not only that, in terms of key trends and momentum, we see -- and we talked before about 32 deals that were larger than $1 million, GSI quarter-over-quarter grew by 2x, and Cisco, year-over-year, and I'll explain why it's year-over-year, suddenly grew by more than 2x. The reason that I put here year-over-year because quarter 4 '18 was very low. So I did not want to put here 10x or 5x or 7x. I wanted to put something that is logical, does make sense and understood. And to summarize. Again, the same thing, focus on the sales organization. Remember, most of the new revenue and booking is still coming from this organization, and we continue to invest, and we continue to hire people, and we continue to train people that are working on the direct and people that are supporting the missions of the GSI in all 3 regions and the Cisco in all the 3 regions. Focusing on the market access, GSI and OEMs and bringing the innovative technology that we covered before, bot management, CWP, 5G and basically moving to the public cloud is a key element that will drive our revenue in the next few years. And again, without focusing on the customer and maintain them satisfied, we will have difficulties. And so far, the situation is great in terms of customer satisfaction and in terms of very relatively low attrition. So this is what I had. So thank you very much for listening.

Doron Abramovitch executive
#7

So I will start with a few slides on 2019 performance, and then I will go to 2020 and the outlook for the long term, as we call it, the long-term model. So overall, I think that you already got from Raffi and Roy that we really feel comfortable and happy with most of the performance, a lot of records that we achieved this year, starting with the revenue growth, 8% versus 2019 reached $252 million, a record deal for us. The subscription that now is above 30%, actually 31% subscription out of the total booking, which is, as you heard, it's a bit more than we expected. We planned for 25%. I will refer to it later when I will talk about the subscription. And this one led to a record $185 million. Total deferred revenues, up 10% versus last year, we added approximately $20 million only in the fourth quarter. So overall, we are very happy with this one. Let me remind you that a good indication for us, and it's something very stable, we see it in the last 3, 4 years, that as long as the total deferred revenues growth is higher than the revenues growth, it's indicating that we have a very healthy business, and we made this one as well this year. In other parameters, our growth drivers lead us to a 12th consecutive quarter that we are growing. We'll see later some slides. The model is quite predictable what the subscription is growing. It allows us to feel comfortable with what we are projecting. We will see it later in the long-term model. And of course, strong margins and cash flow record for this one as well. I will review this slide and at the end of the day, we are very happy and proud with the consistent execution, which is in line with our long-term model. We will see it later. A few slides about the revenues. On the left side, you see the enterprise versus the service providers. In Roy's presentations, you heard that the vast majority of the options and the potential growth come from the enterprise. And this is something that we are focusing, but we are not neglecting the service providers. As for the service providers, we grew this year by approximately 10%. It's still a stable one, $80 million, almost out of our business. And while in 2017, it was 34%, 35% of our business, now it's tend to be 31% because the enterprise is doing well. The CAGR between '17 and '19 is 12%. And again, remember what Roy said that we invest a lot on data price. So it's a good indication for this one as well. In terms of regions, so we are growing 4% year-over-year in the U.S. to a record revenues of $106 million. Raffi mentioned this point that we will invest a lot, and we added people in the U.S., 25% in order for us to grow because 4% is not good for us in terms of the growth. In Asia Pacific, to a record $70 million, and even the slip or the flat EMEA for $75 million. In the call last week, Roy mentioned that this year, EMEA business was best ever and a record in terms of the booking. So we are very optimistic for this one as well. As for the break between the quarters, so 2 things that I mentioned that, one is the consecutive -- 12th consecutive quarter that we are growing, and you can see very clear in this slide, but also something that I mentioned in the call last week, overall, our business is, as I said, predictable. The first quarter is the lowest within the year. And then we are going a bit, the second one, the third one, and the fourth is the highest one and then going down a bit because of the services that we are providing in the last quarter. So this is a trend that you saw in 2017 and in 2018. But what happened in Q1 2019 that we pulled a couple of million from Q2 because of revenue recognition. So there was some anomaly and I explained in the call, that this is the reason why our 2020 Q1 guidance is a bit lower, but it will be, at the end of the year, it will be flattened. As for the operating leverage. So we see that the operating income is growing from less than 2% in 2017 to a bit more than 13% in 2019, which comes from a few aspects. First, of course, it's a top line story. We are growing our business approximately $20 million a year. So this is 1 aspect. The second one is that we are continuing to improve our gross margin. Although the shift to the cloud that is in a way challenging because of the different profitability, we still maintain, and we plan for 2020 to be in the same level even higher. And the last thing is that we are quite disciplined in terms of the OpEx. Roy mentioned that we will add more resources, and you will see it later, but the $176 million, if you can see the break, the $176 million for 2019, so we keep the G&A and the R&D, the additional R&D is the acquisition that we did, so quite flat. And unfortunately, given the sales and marketing in the last 3 years, it's quite stable, not something that we wanted, and I want to break it a bit for you. What we see here in this slide, on the left side, you can see the first line is the OpEx guidance q-by-q. This is the numbers that we are providing every call. So you can see Q1, Q2, 3 and 4 and you can also see the actual, it's the second line. And you see that in a way, we are below. And every quarter, I'm explaining that we are quite disciplined, but we want to do more, and we try to recruit. And you see in the third line, the open position. Now the fourth quarter, in a way, is something that we are targeting in a company that we have more than 1,100 people, 20, 30 open positions is quite good because this is attrition replacement and stuff like this. So Q4 was in line with our expectation. And you can also see something that roughly indicated in his presentation that the North America and EMEA sales, at the beginning of the year, we suffered from lack of resources. And at the end of the year, we feel very comfortable. And it's impacted also the EPS. So we beat q-by-q the EPS, but it was from the reason that we didn't really fill some of the lines. And you can see on the right side, kind of a pro forma that we did. The diluted EPS that we ended 2019 was $0.84. It should have been $0.65, maybe $0.70, and I didn't -- I put the tax and other issue here. So this is what we see. And this is why the OpEx was a bit lower than we planned for this year, and it was supposed to be not $176 million, but a bit more than $180 million. And going to my guidance for Q1 2020 when we guided less than $0.18. Now you also see it clear, the main reason for it. Going to our cash position. Continuous strong cash generation. We had a record quarter. Generated a lot in the fourth quarter that led us to a record here of $53 million. In the last 5 years, we did some approximately 50% of that, something like $100 million buyback, and the rest, you can also see between CapEx and acquisitions. Here, we see the CapEx. The main reason for the approximately $8 million to $10 million in the last few years in the CapEx is our investment in cloud facilities, which led us to a record $428 million cash. Now as for the use of the cash. We have 2, and you know it already, 2 ways for these deals. You see on the right side, the Cisco acquisition that we spent some money at the beginning of the year. And also the second one, is the buyback. And I want to give some color about this one. So you see here in 2019, we did $24.5 million, which is part of the $40 million plan that the Board approved us to do. And the plan is supposed to be until the end of April, so we have some time, and we mentioned it to utilize the rest of the $15 million. And what you see here that if we will continue to have this plan I still don't know what the Board will decide. But the $40 million in 2021 and 2022 together with the cashless plan that we adopted in 2019, you can see that in my eyes, in 2022, and this is the right 2 bars, will be more than $50 million, $55 million. I call both of them buyback. But of course, it helps us to use the cash, but also to decrease the dilution. In the next few slides, I want to give some color on the subscription. We have some strong model that allows us to feel very comfortable. I give 2 examples. First, is the high-growth subscription model. You see some of -- in Roy's presentation, one slide that indicated most of the subscription, the new services. This one is an example, is from 2018, the ERT active attacker. And what you see here is small, we call it a small initiative, but you see the contribution. It's 50% more than we expected. 3x versus the previous year, and this is one of the smallest examples that we have. It's not the cloud leaders that is contributing a lot, but we have a lot of like this. And again, when Roy presented the portfolio of the services of the subscription, you can assume that we plan to duplicate this one. Another example is the Alteon secure subscription, which is kind of a cross-selling. This is something that we are selling a bundled service of subscription for the security for a cloud -- for ADC customers and with that, we help to increase the potential. And you see here an example with 2x. So this is the model that we have. Now going to some of the numbers that are part of this. So let's start with the 63% of 2019 recurring revenue. First, in terms of dollars, we grew from $150 million approximately to $160 million. And the reason that we declined a bit, 1%, is because of the nature of the other businesses. I said that the subscription is growing nice. And you can see here in the red bars that we overachieved the plan for the subscription as out of the total booking. So you can assume that we did very well, but because of the split and the mix of the other services, kind of, the mainly the support in terms of the percentage, we do -- we went down a bit. As for 2020, it will be more than 35%, the total subscription out of our bookings. It will lead us to more than 65% in terms of our recurring revenues. And again, some of it is just it's a math -- it's a math of the services that we also add to this parameter. Now on the left side, you see the -- what we saw in the previous slide, the growth of the subscription booking out of the total booking, which is the red, and this is the 30%. On the right side, we see the revenues that are generating from this. You see that we have a CAGR of 44%, which is nice, but it's -- from my point of view, it's very -- now it's strong. You see that in 2019, we managed to get 22% of our revenues come from this part of our business, and it's very strong. Another nice thing to see that in 2019, we did more than 30%, 31%. So you see the gap right now that between the 22%, which lead us to a 2020 number that will probably be more than $75 million, a growth of 40% -- more than 40% between 2019 and 2020. And this is, again, you can see just from these 2 bars that right now, we did very well in the subscription. Roy mentioned the revenue recognition that sometimes call for challenges, but here, we will benefit from it in 2020, and you see it on the right side. And we forecast that 2020 will be more than 25% in terms of the revenues and more than 35% in terms of the booking. So we can expect that 2021, we will have same trend as well in terms of the revenue -- revenues that we are generating from the subscription, and it's very nice, very powerful. Going back to my first comment on the $185 million. And with that, I will conclude this part of the subscription analysis. Again, in the last 4 years, we feel very comfortable with the trends. We know that we want to do better. We need to do better. But overall, we are very happy with the model that we are running and with the parameters, total deferred revenues CAGR is 15%, the revenues in 9%, again, in line with what we expect. And the $185 million record, total deferred revenues, allows us to feel very comfortable with 2020 performance. As for the outlook. So I will start with 1 slide that we presented 2 years ago, in February 2018, and that we indicated the 3-year model. This is what we plan for 2020. And to put it in a different way to view. So on the right side, these are the numbers that you saw in the previous slide. And on the left side is the 2019 actual, which is part of the process and part of the numbers. So in all of the parameters that we mentioned, we are ahead or in line with the plan. You can see that the subscription, we are more than 31%. A few slides before, I already mentioned, in 2020 target is to be more than 35% in terms of the booking. Profitability is very nice. We will meet the revenues, the $270 million, we mentioned it. And as for the operating margin, again, Roy mentioned that we want to accelerate some of the investment, and you heard David Aviv as well. So maybe it will be a bit less, but overall, we feel very comfortable with what we planned and going to 2020 from our point of view. So this is -- you saw it in Raffi's presentation and also gathering some of the [ views in ] Roy's comments. So we will invest in sales force. We'll continue to invest, something that we already started. And you saw the other slide about the OpEx of Q4. This should be, in a way, the run rate. We will see in the next couple of slides, the numbers themselves, continue to invest in the partnerships in terms of OpEx, but also we expect to generate revenues. Raffi mentioned, the Cisco 2x, and we are on our way to get the tens of millions. And the increasing term is something that we took into consideration. So overall, this is the 2020 guidance that we shared last week, added some of the headcount that will be approximately -- we will add 50 to 60 employees. I think that all of them will be in the field and in the product delivery. We don't intend to add people in the G&A and not in the R&D. And we will lead us to a flat diluted EPS, but I think that I conveyed some message about the fact that we still see a growing profitability. Take into account that 2019 was some anomaly, and we saw it a bit different this $0.84. As for 2022, as a long-term model, so we do see that in 20 -- we plan for 2022 to get a double-digit growth of 10%. That will lead us to approximately $325 million in 2022. Gross margin will grow a bit. We do plan to add people. And again, we assume that most of them -- of the additional to be 1,250 headcount will be in the field because we want to continue to invest in this area. Profitability is the outcome, and we do plan for the EPS to be 1 point to a dollar coming from the $0.84 that we plan for 2020. And the only -- in a different way to see it and the only addition on this one is the 35% subscription to be part of our revenues. As I said in the other slide, today, it's 22%. So we plan to continue to generate revenues and the model to continue to be very strong and to impact our financials. And that's my part.

Anat Earon-Heilborn executive
#8

Okay. So let's start the Q&A session.

Anat Earon-Heilborn executive
#9

Could all the speakers come here please?

Unknown Attendee attendee
#10

Well, so let me just start off with the obvious question on the slide on Cisco, and it says tens of millions of dollars that sets us up through '19 to '20 by 2x. If I just simply do the math on that, that's almost half your growth rate forecast for the year. So can you reconcile whether that tens of millions that you mentioned, I think, several years ago was still the aspiration? Or whether they're -- can you be more specific what you meant by that?

Roy Zisapel executive
#11

So I think you asked me, if I'm not mistaken, was it a year ago, like, what do we imagine Cisco can be and so on, and whether it -- so I told you, we expect tens of millions. After this year, this year meaning '19, is at reach. What Raffi mentioned, for 2020, we target to reach it. So we've done significant progress this year, which is accelerated because if you follow our comments on every quarter, and I'm saying record booking, record booking, and we expect record booking for the next quarter. So it goes up sequentially, very strong. We are getting into the -- what we thought we will get, and we plan to achieve it in 2020, tens of millions.

Unknown Attendee attendee
#12

So that's a guide, you think you'll hit tens of millions of revenues from Cisco channel in 2020?

Roy Zisapel executive
#13

Yes.

Unknown Attendee attendee
#14

Okay, perfect. That's what I wanted to clarify.

Doron Abramovitch executive
#15

Yes and then just to emphasize it's bookings. So I assume that when you refer to the growth, it's a multi -- and I try to -- when I gave the example of the carrier, stuff like this, it's a multi-element that we're taking into account. So when these guys will give the tens of million to convert into revenue, it takes some time. So this is part of the $270 million that we guided.

Roy Zisapel executive
#16

But we are in the environment that we wanted to start where we wanted to be.

Unknown Attendee attendee
#17

Okay. If I could ask a second question on a different subject. More broadly, you've announced a major platform coming into this meeting. What's the time line for, a, the investments to support that growth; and b, when do you think it starts to metastasize into the revenues to deliver an acceleration in growth rates? Is that in the '21, '22, '23 time frame? Or is it a 6- to 12-month sales cycle? What does the cycle time look like?

Roy Zisapel executive
#18

Yes. So I've mentioned the whole public cloud initiative. It's in the beginning. The R&D investments are funded already and will continue. And the sales investment, I think, what Raffi mentioned in his presentation, he pointed to investment in specific products, go-to-market, it's targeting exactly that. So we're just -- some we hired in Q4 '19, some we're hiring now, some we will hire, things will ramp, but that's part of the investments we're making. And growth rates, probably 9 to 12 months from the beginning. That's the start of the revenue pickup. Initially, it's not going to be meaningful, but we believe it's the next growth drivers, #1. #2, it's part of the complete stack. So yes, maybe Kubernetes WAF in this quarter is not going to be big. But I already know on a major, major account, we could not penetrate until now that we are landing through that. So maybe the big money will do in DDoS or in ADC, but the way in and getting the DevOps buying and getting the conviction is on the KWAF. So we're looking on those products also as a hunting or landing versus the big money on the expansions.

Yi Fu Lee analyst
#19

This is Yi in for Shaul, with Oppenheimer. Just going back to the geographic regions. I think in last quarter, you reported that, EMEA, there was some softness. I was wondering if you guys could comment on do you know when that region, EMEA is going to normalize? And then also on APAC, it grew very healthy in 2019. Are there any, I guess, preliminary issues, slowdown, you're seeing with the current situation, with the virus situation going on? And then I just have another quick follow-up.

Raphael Kesten executive
#20

Regarding the corona, I think that we covered it in the call, and it does not seem that it has, at the current moment, any major effect on us. As a matter of fact, we are, myself and other in daily contact with the guys in China. And by the way, I don't want to be as optimistic as they, but they're saying, yes, they're working from home, an email that we got today even. They're working from home, but at the current moment, they are not even reducing the target and it seems okay, and they're all healthy. So that's regarding the corona. In terms of the other markets. I think that I put in my presentation, a comment that we have outstanding in very successful regions. And we have others that we still need to focus with an effort to make them even healthier. The reason for the weakness that we talked in the past, was more like kind of a Brexit, in England and whatever issues. But at the same time, we have to focus more on that, but with no doubt in terms of hiring the right amount of people to support it. Including overlay that will support them with the channels and with Cisco, et cetera. We are basically done. So we have hope that 2020 in terms of more kind of an even spread between region, I think that we'll have a much more uniform situation.

Yi Fu Lee analyst
#21

And just one quick follow-up. Going back to Alex's earlier question about the OEMs. I was wondering if you could comment on the Check Point as well as the Nokia relationship. I know Cisco is very big. And obviously, you hit it already. I was wondering if like whether these Check Point, Nokia as well as other relationships are in the pipe?

Raphael Kesten executive
#22

And so first of all, our investment in the Check Point arena is lower than the investment that we are doing in Cisco. That's the reason that we all kind of try to focus on the tens of millions that, Alex, you asked before. But nevertheless, we continue to focus on Check Point. We see quite a few interesting deals ahead of us. We are still talking about a few million dollars a year. It seems that in a few regions that we see that there is kind of an open discussion and really support from the Check Point guys in those specific regions. That we are doing quite well. We just -- most of us return from New Orleans from a big event that Check Point had there. And most of our regional directors of Radware attended it with an effort to improve the relationship with the support of marketing, et cetera. So again, it's behind Cisco, by plan, the investment is much lower, but we are still investing marketing people that are driving it, and we are pushing the organization because it can be a good additional revenue for Radware. And Nokia, listen, I think that Nokia is kind of -- if I rank all the 3, rank -- Nokia is in the third place at the current moment. We truly believe that there is a good potential. I talked about the Asia Pacific deal that we are bidding with them right now. But with no doubt, yes, the order is still Cisco, Check Point, Nokia.

Unknown Attendee attendee
#23

I have a question about how your costs are ramping as your bookings are ramping. Are you still incentivizing your sales force to do more subscriptions? Are they getting a higher commission on that? And are you incurring more costs upfront with the deferred booking?

Raphael Kesten executive
#24

This is a challenge. First of all, I think that the incentive program that we have kind of dynamically changing. And we try to motivate and to give the right incentives to the people that will drive the company goals accordingly. So your specific question about cloud or subscription, so the answer is yes. If I'm in RSM and making a deal that is cloud deal or subscription deal or et cetera, I'll get a bit more than a standard deal, and that's the way that we are kind of motivating the organization to drive the things that are critical for us. By the way, another thing maybe not open to the public. We do similar things, maybe in a different order to drive the Cisco, especially at the beginning to ignite this system, because you have to understand that without it, the people that are doing direct deal, they will -- can prefer direct deal because the total revenue is lower -- is higher, so, et cetera. So you have to motivate them with -- until they get the message. They are becoming mature and they understand that even if they will get less per deal, the chance is, one, they will get bigger deals; second, they will get more deals. I think that in Cisco, we are reaching this moment that the sales organization is driving it properly. Yes, we give a bit of a higher incentive, but, I think, that we'll do it until they will be mature and understand that it's better for them, it's better for the company to work with the local guys.

Doron Abramovitch executive
#25

And obviously, the expenses are already part of what you see here in the financials. And in 2020, if Raffi's plans will be -- we will meet them, and I'm sure that we will, so we already took them into account this extras and all these accelerations, yes, we plan to pay more because of these initiatives that Raffi just mentioned.

Unknown Attendee attendee
#26

Right. So another way of looking at it is if we look at the next year, as you're still trying to get ignition of the sales force, your OpEx is actually overstating what run rate would be for commissions or selling?

Doron Abramovitch executive
#27

Obviously, yes. But remember that we pay commissions based on collections and revenue. So even, and I assume that we will generate a lot of good things. Still, the expenses are...

Unknown Attendee attendee
#28

Based on revenues. Okay.

Unknown Attendee attendee
#29

Could we talk a little bit about the competitive landscape? And to what extent you're competing with, say, the Akamais and the cloud players and the fast leaders of the world as they move into the security? And conversely, if you could talk about them as customers because, obviously, you've got a very good penetration in the SaaS vertical. And obviously, that's part of that. So maybe you start off with how much of your revenues are attached to that vertical that's SaaS companies, the sales forces or whoever as well as the Akamais and CDNs and the like?

Roy Zisapel executive
#30

Yes. So the CDNs that -- so for obvious reasons, I don't want to mention specific names, but some of the audience already did the research and know where, where we are and who we are serving exactly. So first, they're a very good customer of ours, and we are proud to be behind. They're very successful services. We're seeing now more traction in general with the CDNs, especially on the -- also on the web security business, on the anti-bot business and so on, and, of course, predominantly in the DDoS. So they're very good customers, some of them use our technology for their own service, some are refilling ours. In terms of competition, in general, in the market, regardless of whether they are our customers or not. So I'm putting that aside. When we go to a cloud DDoS or a cloud WAF deal, we will generally see Akamai and, to some extent, Imperva. We will not see Cloudflare unless it's a very price-sensitive deal so far. And I don't recall we saw Fastly at all competing with us on a deal. So it's really about Akamai and Imperva Incapsula in terms of competition on the cloud deals with the customers. We feel very good about our competitor. So for those that we supply the technology, it's clear that we feel very good because generally, there will be several generations after us. So they need to let the equipment run. They need to take the ROI. We have no problem to equip all our centers with our latest and greatest. Given that we are at 83% gross margin, you can understand the delta of our cost structure versus their cost structure in that business. So in terms of people that are buying from us and basing the service, we have a very, very strong competitive advantage, let's say, they're running the equipment 3 to 5 years. So take 3 presentations of David with all the algorithms or the new types of attacks, that's our advantage. That's our delta. We generally will not be that direct with the customer saying, because they're also our customer. But it's evident that we have a very good advantage. And we have a name for providing really top security.

Unknown Attendee attendee
#31

If you were to add up all of the SaaS companies, the Salesforce, the service networks and the like as a vertical and throw in the CDNs as a vertical, what percentage of your revenue is that? And is it growing faster than the corporation as a whole.

Roy Zisapel executive
#32

So we don't break it. We will not break it. We feel that today, we gave a lot of information. But it is growing very fast, faster than the overall. And we're, I think, gaining share. If we look on our SaaS name list, we're definitely very, very well represented there. And it comes back to very specific technology advantage. The more the customer is dependent on the security for their business, SaaS is a great example. The business is online. They cannot afford any downtime. So security is paramount. They cannot go down. Financial services, also a similar vertical for us. All of them are dependent on security, they will go very deep on the technology and the evaluation and our ability to win these situations is very, very high, #1. #2, we have specific advantages that David mentioned, like encrypted attacks. If you talk about SaaS providers, they have thousands or tens of thousands of customers, all running encrypted traffic, all having their own keys because they don't want to share any information. You need to do encrypted attack protection at scale. We're the only one in the market for that. So when we go down to this, it's a killer. We can talk about all the rest. But here, the competitive landscape on the SaaS market I think ends and then it really relates to our access to the customers. Do we have the conversation? Are we at the table? If we are, our win rate would be very high.

Unknown Attendee attendee
#33

Two very quick last ones. You put up a growth rate on the ADC market of 6% on one of your slides, that seems like an increase. Is there a reason why you've increased your expectation for the ADC market growth rate? You've been talking about it flat before. And then second, can you talk a little bit about F5's acquisition of NGINX and Shape and how you see those?

Roy Zisapel executive
#34

So on the ADC overall, we put 6%. It's not our expectation for ourselves. It's like Gartner and IDC, they include in that, the business that the cloud providers, AWS and Azure are doing in the cloud load balancing. That's not available as is to the vendors. So when we talk about ourselves, we take that piece of the market out. And we focus only on the appliance and the software. And over there, appliance is declining, software is rising. And I said, overall, flat to single-digit maybe declines. Now the other question you had was on NGINX and Shape. I don't feel -- I don't want to say, general comments on a respectable competitor of ours. So far, we don't see that affecting our business. Meaning, I don't want to be a commentator on their behalf. But in the places we play, ADC with a focus on security and with Alteon Cloud Control and our abilities, we don't see the relevance of the NGINX acquisition. And our play with the broad and deep security play, we don't see Shape as changing significantly our game plan, our strategic relationships, our way to market. They are probably a very good anti-bot for the high end financial government sector, but we are running a different play with our security offerings. So we feel very good about our position. We still see, as I've mentioned, in some markets, other competitors as more visible at least now for us.

Unknown Attendee attendee
#35

Roy, you have a lot of cash on the balance sheet, and you've expressed your wish to do some M&A. And I think most shareholders here have expressed their wishes for you to buy back shares. Can you sort of parse out how you view -- how much cash would you use for M&A and what type of companies you're looking for, given your strategy?

Roy Zisapel executive
#36

Yes. So no, we would like to think about M&A, not by the -- what we pay, but what's the impact. So I think, for example, take the anti-bot acquisition we've done beginning of '19, we could have paid more. I'm sure they would have liked it, the other side. I don't think it changes the nature of what we buy. So those 2 types of acquisition we look. Technology tuck-ins, I think $20 million, $30 million, $40 million -- $20 million to $30 million, that's the range that we would look at. And then business acquisitions, companies with customers to allow us reach and scale. We're very interested in that. Those might be bigger in the spend, but what's important for us is really the ability to return it. Meaning, how can we generate then scale in cash generation and so on. We think the -- overall, we are, as you saw in Doron's presentation, we are increasing our commitment to the buybacks. I think we are very committed to finish this last 12 months based on the Board $40 million. On top of that, as Doron showed, we have the cashless exercise. So 2020 probably will be high 40s, even if the Board will not increase the next plan. And 2021 will be above $50 million. Again, or being equal. Obviously, we are looking whether it makes sense to look again at allocations, et cetera. But first, I want to assure you that we are executing on the plans that we do have, and I think it will be seen when we will report in April.

Unknown Attendee attendee
#37

When looking at business acquisitions, acquiring customers that way, I imagine you're hoping to pay a lower multiple for that type of business in your referred technology business?

Roy Zisapel executive
#38

Of course, because the technology businesses generally don't have a lot of revenues versus the -- unfortunately, versus the price.

Unknown Attendee attendee
#39

What are some of the other elements within a business that you are looking for? And typically, when you find businesses that would be the right size for you to buy with customers. There's always something going wrong and what are things that you don't want to acquire? Sometimes you acquire bad things not just good things.

Roy Zisapel executive
#40

Generally, I think, we were very clear on our strategy, like, where we are heading, like the data center, cloud and security and so on. We talked that we want to strengthen North America. So all these are factors when we look on the potential targets. And very importantly, you know that we have a very good integration plan, that we have a very solid execution plan that we can really make out the investment. Overall, we feel we had a good -- overall, we had, in the past, very good experience with acquisitions. We've done several already, not all of them were successful, but a very high percentage of them were successful. It added talent to us. Some of the business acquisitions did very well in terms of scaling the company and driving customers. So we are very, very interested in that. And again, also from management point of view, we think we have the infrastructure now of management to execute. For example, Raffi joining definitely frees me. He is also on the only thing, you saw the structure. So I think we have also the capacity and the management capability to take on an acquisition.

Unknown Attendee attendee
#41

Great. I think you definitely have the balance sheet to do that as well as I think your company is probably is one of the most undervalued assets on the market. So you should take advantage of that, too.

Roy Zisapel executive
#42

Okay.

Unknown Attendee attendee
#43

I want to touch on the revenue visibility. When you project out internally, can you talk about the assumptions you use around -- on subscriptions or around retention rate, contract duration, time from booking to realization? And then separately, could you comment on the trajectory of the support business in light of all the growth in subscription?

Roy Zisapel executive
#44

Okay. Okay. So on -- in general, we don't break retention rates and churn rates, et cetera. But I think Raffi mentioned, we were very happy with the low churn rate we have today on the cloud business. In general, when we do a subscription deal, which is product attached, then the revenue recognition will go based on the contract length. It will be spread evenly 2 years, 3 years, 1 year, depending what was this -- what was the length of the subscription that was booked. If it's a cloud subscription, we are trying to onboard them as soon as possible. So we're trying to onboard them within -- between, I would say, a day to a couple of weeks. Of course, if it's a very, very large customer, like Raffi mentioned, I don't know, 700 networks, 3,000 applications, there's a buildup and a plan with them. But once they're onboarded, once they're on, the clock starts to tick. I mean, from that point, it's according to this length of the agreement, pro rata.

Doron Abramovitch executive
#45

As for the support, you can see on this slide that in 2015, the vast majority of our recurring revenue derived from the services. But as long as we continue, and you see the subscription growth and impact, so yes, there are some fluctuations. And I gave an example in 2019 that services contributed a bit less, so this is why we declined. But as long as we will continue with the subscription, the impact of the services will go a bit down. But you can see, approximately 40%, I assumed a bit less, derived in 2015 from this part, and it's quite stable until 2020 in a way.

Unknown Attendee attendee
#46

Doron, maybe sticking with the financials from your side. I think in the past, you mentioned that the cloud business, the more you sell the cloud, the margins are a little bit slightly lower than the legacy stuff. Can you reconcile like the guidance just plotted that the gross margin as well as the operating margin, it seems like a little bit higher? And as you sell more cloud, how can you still get -- gain more operating leverage as you sell more cloud, considering the margin on the cloud stuff is a little bit lower?

Doron Abramovitch executive
#47

Yes. So this is why, again, when I'm saying that we're quite happy in 2019 because in the way, you're right, and I mentioned it that there is a -- tend to decline a bit. And I also mentioned that we invest a lot in infrastructure, so it also gets some impact. On the other side, we have a lot of other aspects, inventory and other products that we are selling, and we are quite efficient over there. So the fact that we are declining in a way on one parameter, which is the cloud subscription, but we are benefiting from the others is just an indication of the great operational leverage that we manage to do. We still see this trend. We will continue in 2022, and I mentioned that 2022 as well to -- in a way to decline a bit, but although we are getting more revenues from the subscription, we still plan to be above 83% because of the efficiency, because of the scale. We don't plan to invest that much and to spend in a level of $50 million that we have brought in our subscription. Next year, it will be $75 million, and we plan for it to be more than $100 million. Of course, it will minimize a bit the impact. But the trends are that.

Unknown Attendee attendee
#48

That makes sense, Doron. So as the efficiency. And then my last question is really on the subscription. Your guidance is 35% of total revenue. I was wondering, concerned the mix between products as well as the SaaS subscription. I know some clients are more legacy clients, where they prefer the old method. In terms of when does that number top out, what do you think is the number of subscription mix that is a good number to top out?

Doron Abramovitch executive
#49

No, we don't break it. Sorry, but we don't break it. We consider it as a whole, and I gave 2 examples in the presentation about a product and cloud. Overall, right now, we feel very comfortable with this metric. When time comes, we will probably break it, but no.

Unknown Attendee attendee
#50

Doron, I was wondering if you could go over a couple of numbers. First, are you providing RPO yet? Or are we waiting for the 10th, the 20th for that?

Doron Abramovitch executive
#51

No.

Unknown Attendee attendee
#52

Second, if I -- can you help me understand, the bookings in the fourth quarter seem truly enormous given, I forget the number, $55 million, $60 million of deferred that was netted out from the balance sheet? So the question is, how do I understand that number, first, from a cash perspective? So you build that $60 million. It comes in. So should we look at the normalized cash of the company at the 4 50 or 4 60 level, not at the 4 25 level? And then second, how should I understand those bookings in terms of an ARR? If you're doing 2-year contracts on average, does that mean that whatever the ending ARR was at the end of the year that produced the $55 million, really, the $75 million is already in the bag?

Doron Abramovitch executive
#53

Yes. So first, the $55 million. It was the back end of the quarter. It was a very good one, but we gave a few parameters. I think all of them are extremely well. This one, just from my point of view as the CFO, it's technicality, and we have a lot of discussions about this. Not a lot of companies break this one. We break it from a different reason. But the $55 million came at the end of the quarter. We didn't invoice from various reasons, we did it at the beginning of the quarter. I think that I also already mentioned it last week that we collected most of it. So yes, my CEO is expecting Q1 to be a very good cash flow because of this great quarter, $55 million and our collection capabilities. As for the ARR, it comes with the subscription. You're right. We didn't really change any of the KPIs fundamentally in the last 3 years. So we do expect this in same duration, nothing changed, and we expect the ARR to grow. So if I gave the $55 million growing to more than $75 million, in terms of our subscription, so probably they are -- will follow as well. But since we don't break it right now, you can assume that it will go. The subscription is good enough.

Unknown Attendee attendee
#54

Can you remind me what duration has been over the last few years?

Doron Abramovitch executive
#55

In our total deferred revenues, the average duration is 1.8, 1.9 years, going up and down, depends on a certain deal. And you can see it also in our 60% to 65% of our total deferred revenues. So it's the same. We don't really change -- good for us, but we don't really change it in the last 3 years.

Unknown Attendee attendee
#56

So that means that typically, year-end ARR is above revenue. So year-end ARR would be above $55 million, plus we have these bookings of at least $20 million to $25 million. So we're really thinking of ARR close to $80 million.

Doron Abramovitch executive
#57

Since I don't disclose it, I cannot even try to answer and to get back from this question, no.

Roy Zisapel executive
#58

Sure. But Jonathan, in essence, you're right. Obviously, you see that the booking is higher than the revenue. We said that we booked over 30% from subscription. The average contract length does not change materially. So it means that eventually, that's the growth rate of the revenues as well, and we already broke 2019. You add up the revenue growth, and you reach roughly. We are -- we feel very good about the subscription revenue guidance we gave. One comment on our end. If you look on the -- I don't know if we can put those -- the subscription revenue graph on the -- put aside our other business and the fact we're generating $50 million, $60 million from operating cash flow quite consistently, in the past 2 years, you look on a business that does this subscription in cloud security with this growth rate. We're planning for growth rate in 2020 not to decrease, if you see our guide. We feel very good about that piece of the business. We think we're building something very strong there. We continue to invest in people, in CapEx, and we're going to invest also in sales there, but we think such a business is, by itself, is a very, very good indication for what we can achieve in Radware.

Unknown Attendee attendee
#59

Right. I agree with that. Why not put more money into that? Why not like, really press that if that's where the growth is coming from.

Roy Zisapel executive
#60

So we're trying to balance -- when we put more money, sometimes the market doesn't like it when -- so we need to balance between the different views. We think we took a balanced approach in our -- I don't think we're underinvesting. I think also that if the current wave of investments that Raffi's doing in the field will show good results, there's room for invest more. If we see everything is tracking well, we will not be shy.

Unknown Attendee attendee
#61

I think the market will reward growth faster than earnings, double-digit growth. Just to make sure people really understand.

Roy Zisapel executive
#62

We -- we are very, very -- you heard Raffi. He's very focused on that.

Raphael Kesten executive
#63

Robert, I had a comment that I had about the gross margin as well, I don't think that we will suffer when, and we will have this growth in the cloud, we are ready with the infrastructure. So it -- continue to what Roy said, it's not that we are missing in a way. And the gross margin right now, we have all the capabilities to support this growth in scrubbing centers, the people, stuff like this. So we are in the -- balance is not only thinking about the financials. Balance is also part of the people that you saw the increase. We added approximately 200 people within 2 years. Some of it is acquisitions, some of it is the sales, but significant part is the cloud people. So I think -- I hope that the VP that manage the clouds agree with me that they have everything that is needed.

Unknown Attendee attendee
#64

You have market-leading product offering strategy, and you're no longer the second in the market with this. So you're not trying to improve [indiscernible] marketing, do you need to sort of do the premarketing like -- that's like [indiscernible]?

Raphael Kesten executive
#65

Yes. I think we're doing -- we're trying to do that.

Roy Zisapel executive
#66

Jonathan?

Unknown Attendee attendee
#67

For customers who are around subscription, can you comment on the direction of retention?

Roy Zisapel executive
#68

The direction, meaning where the...

Unknown Attendee attendee
#69

The retention rate or the organic...

Roy Zisapel executive
#70

They're high, they're high. I want them to stay where they are. That would be a very, very good execution. Given the -- we have a very high growth, we didn't show you, we're showing you only the subscriptions. We have very, very high growth in number of customers in cloud. We have very, very high growth in the amount of data centers we build, bandwidth we take. For example, we're adding, I think, a couple of terabits this quarter in North America, just because of contracts we won in Q4, and we really need to build up more for that. So the -- a lot of the pressure in the execution is doing all those builds and all this new customer onboarding. And if we'll achieve that, while maintaining our high -- I think there is a very high churn rate -- very high retention rate, I think that would be very good.

Unknown Attendee attendee
#71

Just secondly, regarding support revenues. Is that converting to subscription revenue?

Raphael Kesten executive
#72

The support? No, it's different. We have three parameters. No.

Unknown Attendee attendee
#73

To Rob's point, more growth is always welcome. But even under the current set of circumstances, the financial profile is uniquely attractive with high single-digit top line growth, strong cash flow, plus 80% gross margin, plus 60% recurring revenue and 1/3 is for the business in subscription. It seems like the company is not getting rewarded by that from the market, with peers having much higher multiples. And the question is why is the valuation so cheap, given how, right now, things are very attractive at the company? And what can the company do to help close the gap in terms of valuation?

Roy Zisapel executive
#74

Yes. So I don't want to say my opinion on the share price. There are so many smart people here with so much experience, and I think your job is to take advantage of such situations if that's the case. Regarding us, we are doing several things. We're trying to market more on the IR side to tell the story, to model. We're trying to accelerate our growth rate internally, because this double-digit growth rate is probably more meaning than the 1%, 2% financial or mathematical -- and we think we should be there regardless because the markets allow our position allow, we want to take advantage of that. So we do that internally. And we are planning to use the cash allocation also, maybe to do some actions about that. So we're looking on multiple dimension. Obviously, we're not super happy. We think we are just looking, as I said, on the subscription business, and on a stand-alone basis, I think the anomaly is there. But we should do our work, focus on the markets, focus on the customers, get the growth. I'm sure -- I'm doing it for 20 years in NASDAQ. So there are anomalies, but overall, the market, over time, over a long -- over time, finds the right balance. And as long as we do right and we continue to execute, we'll find that balance. And we are not, as you understand, we're talking 20 years. This level of commitment, we are not short term here. So it will find the balance. And hopefully, the ones that find the good opportunity, we'll take advantage of that, make money. It's very good.

Unknown Attendee attendee
#75

So just quickly on the GSIs and CSPs. It's obviously taking a while to get those ramped up and starting to generate some revenue growth. What further headwinds do you see in that area? And how are you investing to negate those?

Raphael Kesten executive
#76

So I think that I've said it before, we are investing a lot. With no doubt the GSI today is, let's say, a year or 2 years behind the progress that we achieved with Cisco because -- mainly because of the effort that we put in but not much more than the 1 or the 2 years. So we are investing a lot, as I said. We did move, and we brought people to the regions because until a year ago or whatever, we managed it mainly from -- with the Indians kind of GSI from India. Not that it was not enough, but that was a step that we did at that time, while basically doing what I've said that we did with Cisco, creating the product, creating the training, creating the part numbers, et cetera. This is behind us. We hired the people in the region that are starting, one, to be measured according to the opportunities that they bring to the RSM, to the salespeople. And we start to see again, and I saw it, that the pipeline of the opportunity level in the CRM from the GSI is growing. I have to say I will predict, in 5 years, maybe the situation between the Cisco and the GSI can change. Both will be much higher than today if I predict it well. But because the GSI is not 1 player like Cisco, and we are talking about 10-plus Indians, the American, the Atos in Europe, et cetera, there is a good chance that this focus will need even more than the Cisco as 1 company bringing to us. That's the reason that we are not kind of betting on 1 player, which is Cisco. And with the other OEMs but on the GSI as well, it's a major focus for us. We have quite a few deals that are progressing with them, deals that we couldn't win before. And I see really kind of nice progress again, I'm very honest here, a year behind, let's say, the progress that we have made with Cisco, because that's the way that we led it.

Unknown Attendee attendee
#77

It seems like there's the next big move for enterprise applications of cloud is sort of a big opportunity for the company. To what extent do the cloud platforms become major partners for you to attack those born-in-cloud applications or new ways of doing business, versus maybe Cisco's more of a data center-focus or the -- or is it more the GSIs that are more important in that environment?

David Aviv executive
#78

Yes. For the cloud or cloud-making-whatever business, so there is the born in the cloud, which is all the carriers still is some kind of an embryonic stage. The cloud, et cetera, even though it's a very large market. So we do over the 2 real opportunities from our point. They're really born in the cloud, which is nondata center-related. Everything is only public cloud-focused. And the other side, which is a greater opportunity probably over time, will be the reborn in the cloud. Those which are classical data center, understanding the advantages of building hybrid way to run in the cloud. So 2020, we think it will be the inflection point, from our point of view, of revenues, starting to see revenue based on our investment. And definitely I think we'll see the -- and the much larger ones starting taking off in '21, '22.

Unknown Attendee attendee
#79

And how do you change your sales organization or your go-to-market for those opportunities?

Raphael Kesten executive
#80

To support this change, I think that we are -- one, a lot of training and a lot of training, I mean. Second, the new hires that we bring, and as I showed before, in the U.S., we are kind of increasing the head count by at least 25%. So the criteria for the newcomers is different. It's more development DevOps than people that did mainly hardware and networking. So I think that, that thing, plus the usual X percent of attrition or retention of people that basically replace them with people that are more educated to the new world.

Unknown Attendee attendee
#81

And when do you start marketing that?

Anna Convery-Pelletier executive
#82

I already have. We -- just to give a little bit of an insight into the -- actually it's nice to have a female voice here for once. So just to give a little bit of insight into what we're doing marketing wise. The whole move towards cloud, public cloud is already out there with regards to the positioning from the Radware marketing perspective. When Roy illustrated the go to market, and you saw that go-to-market, that was twofold. One, it was to simplify our positioning in the market, so that you could see where we played and whom we mattered to. And the second thing was to actually make it easier internally for Radware to understand how to pivot as a company, to add the whole cloud go-to-market. That was to do with the environment. It's to do with the personas whom we play with. It's also to do with who we should now be partnering with in the marketplace. So your earlier question, do we work with the providers? Do we work with the GSIs? We work with all of the above. And as you go through this year, last year, when I was presenting, I was talking about the doubling down on our marketing with Cisco. You see that coming through. We also started to really work hard with the GSIs. You see that coming through. And now you see us working hard with the various main providers in the marketplace. And the last thing I'd say in terms of the go-to-market for the cloud is it is a different type of marketing, more community-based, a lot more conversational, a lot more of a profile that is different to the traditional enterprise marketing. And so we've moved towards that. You'll see presence in many of the marketplaces in those communities of the Radware products. And you also see us bringing talent into the company that can help us speak better in that area as well. So that work has already started, and it'll continue.

Unknown Attendee attendee
#83

Great. Also great to hear a non-Israeli voice over there.

Unknown Attendee attendee
#84

I was wondering if we could look at some of the newer products that seem to have very big opportunities all by themselves. And maybe you could talk about the competitive state of play. Anti-bot, you bought a tiny company a year ago, but it looks like Akamai seems to be doing $100 million a year, up 30% in that space. So maybe you could talk about that product and that opportunity. And what are the small niche products that seem to have a similar wide-open opportunity?

Roy Zisapel executive
#85

Yes. So anti-bot, for us, was a very good, I think, acquisition. It's now fully integrated in our cloud portfolio. And we're seeing very, very good take-up rate for cloud WAF customers to add anti-bot. So I think our sales team picked it up very, very quickly. The value proposition, the people we sell to is quite similar. And I think in most cases, it actually doubles the size of the initial WAF opportunity. So they'll pay $1 for WAF and $1 for anti-bot. In some segments, airlines, hospitality and so on, even anti-bot is even more important for the business than the WAF. You should think about anti-bot almost on the verge of a business sale, not only a security sale, because it aligns very much with the brand, with the marketing expenses, the business expenses. There's a lot of business implications to that. So we think anti-bot will play very well for us. It's already there. We're very happy with that piece.

Unknown Attendee attendee
#86

Can you discuss [indiscernible] competitors?

Roy Zisapel executive
#87

I think we have a very competitive offering. It's -- we chose ShieldSquare because of several factors. First is the fact that they had strong algorithms, including machine learning, doing the anti-bot. We liked it a lot. It's -- it was a very good match to what David mentioned on algorithmic first approach, and it was quite unique versus what we saw from other players in the market. #2, we liked it because it was, from the get-go, very cloud-oriented. Unlike some of the anti-bot players that rely on proxies sitting on on-prem and so on, they had many, many integration possibilities, from the application server, to the web server, to the load balancer and to cloud-only. So we think technology-wise, we're very happy with that. We continue to invest in that team. It's nothing more there to say, and it plays very well. When I said we need Akamai and Imperva, mainly on those deals, so Akamai had a Bot Manager, and Imperva bought like 6 months or 8 months after us. So it tells you that this is really the battle that goes on. And we feel we did well from technology, costs, ROI, integration, time to market. We like our choice there very much. Going to the other products, cloud workload protection. It's a market like Gartner defined cloud, cloud posture, security management. They have this big name for that. At a high level, Palo Alto did a couple of acquisitions in that space. Check Point did an acquisition. Not exactly what we do, but generally, in that space. So people are starting to pay attention to that field. We think we have a -- I think it's one of our deepest products in terms of the use of machine learning, how advanced it is. We have clear advantages there, I think, in detection and hardening. And we think it's the very, very beginning of a very, very big market. Everyone that would build their application in the cloud and run mission-critical applications, will need a solution like that to harden the environment because the environment is open to everyone and known to everyone. How do you harden? And how do you detect attacks? It's not going to happen through your firewall or IPS. Palo Alto recognize that. Checkpoint recognize that. We recognize that. And we think we're well positioned technologically there. Yes, the -- those are good competitors to have, right? They have a lot of muscle. But again, we have also some partners here, both on the GSI and the OEM, and we think we have a very good product. The Kubernetes WAF, if I need to speak it by itself, we don't know of any direct competitor that does web security for Kubernetes. Again, very early. We see the, as I said, the initial wins, the -- in very interesting accounts. But I think -- and I can continue to talk, Alteon Cloud Control and so on. The power is in each one individually is to lend. But the real power is in the complete stack because, okay, Akamai, yes, they have the anti-bot. But if the customer sits in AWS to the FCWP, if the application runs in Kubernetes, do they have Kubernetes WAF or not? So when we are coming to someone who runs an application today, and I'm saying, "Okay, what -- is it Kubernetes? Yes. Okay. What are you going to do to protect the web security there? And what are you -- on the East West? And what are you going to do on the North South? And what are you going to do in DDoS? And did you think about automatic attacks that we call it anti-bot, but this is more like a Gartner and a vendor view?" The customer has an application, and is it protected from all dimensions. And it doesn't make sense for him to buy 1 solution for CWP, another solution for anti-bot, a third solution for KWAF, a fourth solution for DDoS, and try to operate it by themselves. It's just not going to work well and definitely not within a budget. We come with a complete offer, and that offer will become more and more integrated, more and more, what David mentioned, on those cloud analytics that feed all. So I think we are -- we will generate more and more competitive advantages that will be very, very hard to achieve with multiple vendors type of solutions. So beyond the importance of each one and each one opening us, we think, a very interesting market, we think there's a very big power in the complete approach that we try to present in David's presentation.

Unknown Attendee attendee
#88

So to what extent is there a possibility of the cloud vendors bringing that sort of functionality in-house? And what prevents them from doing that, and that being competitive, other than just not being able to work on somebody else's cloud?

Roy Zisapel executive
#89

Yes. So I think, first of all, they can do many things. They've proven it. But I think there's a very significant difference between ADC and security. In ADC, the ADC goes with a specific application. And as long as it serves that application, you're fine. So if the public cloud has it, that's good. In security, you need something across all your applications. And some of them will be in a specific public cloud. Some will be in other public clouds. Some will be in your private, we're talking large enterprise. How are you going to have a consistent policy? How are you going -- if you have an event, let's say, and your AWS WAF discovered it, what are you going to do in Azure? What are you going to do your private data center? How would you even know what to do? Okay, I see this event cross-site scripting 543 session blocked. Okay, what do I do now? Am I at risk? Is it critical? Isn't it critical? Can it happen in the other environments? We're coming with a completely different approach. Doesn't matter where you see it. Doesn't matter how your applications will be moving also. Forget today, tomorrow, in a year, in 2 years, in 3 years, you are protected constantly across all threats in all environments. And that's a very, very strong value proposition that I don't see a specific public cloud able to mitigate.

David Aviv executive
#90

Just to add something. Actually, our approach is to partner with those kind of security controls. Public cloud security controls. So we are taking them as feed, additional feed for our -- some malicious indicators so we can import those kind of feeds, train our engines with those feeds. Besides the feeds that we are collecting, measuring and sequencing, simply, we look at it as additional dimension of getting information from the public cloud.

Unknown Attendee attendee
#91

And you can get that from all the players?

David Aviv executive
#92

From all the players, exactly, because the feed from Azure, GCP, AWS, everyone will have a different focus. If you're running in 365, natively, Azure will provide you a much better, completely coverage rather than you take it from other. But -- so individually, from each cloud, we collect the relevant feed, feed it as external feed into our system, to our engines, to simply empower our detection mechanisms.

Unknown Attendee attendee
#93

So regarding the 5G opportunity. When do you see this starting to contribute materially to growth? And also, what do you see your road map looking like to really capture that opportunity?

Roy Zisapel executive
#94

So we think it's 2, 3 years out. I don't want to [ assume ]. We are engaged. We mentioned some large account with Cisco. Some are based on our own relationship. We are engaging some very large opportunities. So can we be positively surprised? Yes. Yes, we can. But realistically, looking at what happens in the world and the pace of deployment, let's say, in North America, in the major European countries, I think it's 2, 3 years out.

Unknown Attendee attendee
#95

So the acquisition that F5 did of NGINX was all about bringing the coder community into their fold, clearly, you guys have a different approach to that. Can you talk about how you're pricing on capacity utilization versus -- so it looks somewhat free to the coders and how you reach those coders. Maybe you can talk about the penetration there, whether you're using GitHub or whatever to get in front of them. Because, obviously, the world, the power is shifting out of the net ops teams and in IT management to the DevOps and coding side. How do you participate?

Roy Zisapel executive
#96

Okay. So we have a multi-dimension answer here. So I'll cover the GEL, the Global Elastic License and what it means. David, maybe you will cover the Kubernetes WAF and how that ties to developers and to DevOps. And Anna, maybe you'll take the marketing side and so on. So there's multi-dimension to this question. So first, what we're doing in the ADC space, we came with what we call Global Elastic License, meaning no longer you pay for a spare appliance or physical device, but you tell us what will be the global capacity that you would need for these services, ADC and WAF, across all your organization. Public cloud, private cloud today, tomorrow. Let's say, you say, "I'll need roughly 100 gig," we will charge you annually subscription for this 100 gig. If you go to 200, you'll pay -- you'll increase your spend with us. Now with -- in this 100 gig, it's all you can eat. You can do whatever you want. You can have as many instances of our technology as you wish. So for example, your DevOps guys and development guys, it's very beneficial that they would run with the same environment like the production environment, because then all the testing stimulation, the agility of the life cycle of pushing from development to staging to production, all of that is greatly accelerated. When we charge based on total bandwidth, given the fact that in the development labs, there's very, very little bandwidth consumed, it's basically free of charge for the development. There's no -- the marginal cost is 0.

Unknown Attendee attendee
#97

So it looks open source.

Roy Zisapel executive
#98

So it's like the model of the open source but with full backing of a vendor in terms of support, in terms of security, patching, in terms of the cleaners of the code and so on for them. And it gives the IT environment, at the same time, all the capabilities of a full-fledged product with all the proven experience. We see very nice take-up by our customers. It's almost like that the IT now called NetOps, SecOps, whatever, those guys, with the DevOps, can come to an agreement. Because the DevOps have the freedom to spin up and down, move to cloud, from cloud, whatever instance they want, and they don't need IT permission to do that. It's under the same global pool, but they're free to whatever they want. And at the same time, IT enjoys the product that they can operate, know how to operate, et cetera. So we think that's a very good solution for our customers. In parallel to that, I want David to answer some solutions that we're doing specifically for the DevOps environment like the Kubernetes WAF.

David Aviv executive
#99

Okay. So Kubernetes, for example. It's a good example because the design and the solution itself is taking to -- in the design that has to be a Kubernetes native citizen, which means it needs to please 2 communities: the DevOps and, and the devs tech -- DevTechOps. Sometimes they are the same thing, sometimes not. So meaning that for the DevOps team, because it's a Kubernetes native citizen, it's being deployed natively as a side car, as a security side car, utilizing envoy. Very simple, same deployment, by the way, 1 line of code, and that could consolidate on the console. The way you launch a container, an application container, you launch and you decide, "Okay, with this application container, I'm launching a security container." This is #1. So, pleasing the DevOps. Now coming clearly the DevTechOps, different thing. Here, we -- I think we have a very unique capability in the market because we use an air-tight technology, which means 95% or more of the solution needs a security engine out there in the cloud to do the security calculations. And basically, what they are doing in the cluster is effectively collecting telemetry to feed it. We run a self-learning engine, which means in the cluster, doesn't the intelligent -- security intelligence doesn't leave the cluster, air-tight solution. I mean we still send off cluster information to do some high-level analytics, but this is very unique. Think of a government-sensitive application that you need. And doesn't matter. You will encrypt it. You will send either GDPR, all kind. It's done in the cluster itself, self-learning algorithm. Once again, you can afford it. Only if you have positive -- very powerful, positive self-learning technologies. So if you take those 2 things, being able to please the DevOps, being able to please the DevTechOps, I think we have built a very native solution for that kind of environment. And that gives you an example of the shift that we have done from being able to address the natural guys, the IT tradition. Not to say that we don't provide them today's solution. But I think we cross the chasm in the fact that we are now building hybrids sometimes, not in the sense of being able to deploy premise in cloud, but now up centric, negative centric, whatever you would call it.

Anna Convery-Pelletier executive
#100

So from a marketing perspective, it falls into 3 areas, as I look at it. The first area, and this goes back again to a little bit of the insight I gave into our go-to-market last year, is we have an approach of we do account-based marketing, we do partner marketing, et cetera. And as part of that, you have a framework of the personas you go after. So the DevOps, DevTechOps, they are all part of our personas. So when we do qualification and scoring of our demand generation and our activity in the field, that has been part of that process and has been now for over a year. Step #1. So first of all, we know that they're there. We know that we're marketing to them, and we know that we are putting the marketing behind it to communicate with them. The second part of it is internal readiness. It's where we go to another part of my responsibility, which is making the field knowledgeable and enabled, as to whom they're talking to and what products are relevant to them and how they should position. So we have, over this past year as well, had active, focused training and enablement sessions for the field on addressing these personas, the DevOps, DevTechOps, et cetera. As we launch the products that David just talked about, we also internally have education, especially when we bring new titles, maybe new to some of our folks into the fold. We have special education on how do these folks look at the products, what matters to them, how do they engage and how do they react to what's going on. That's the second part of what's important in the go-to-market. The third part is a continuing piece of exercise is, we also now, as part of our expansion in the market, have to go to where the DevOps, the DevTechOps want to find their information, want to engage in organizations. And I'll tell you, there's a very healthy piece of information I can see coming through in the activity is, in our traditional marketing, we see our conversations expanding within opportunities to include DevOps and DevTechOps personas. And then I also see that there are net new opportunities coming in from us right now, reaching out to this community as they start to talk to us. Because, as Roy said, we have a great balance to appeal to both of those. Those are the 3 areas. And that, too, is -- has been ongoing for quite some time now.

Unknown Attendee attendee
#101

One more question, if I could. Could you talk about FedRAMP and what you're doing in the government vertical? I haven't heard anything on that front.

Roy Zisapel executive
#102

Yes. Currently, we're not active. Our activity is through the OEMs and the GSIs. So we do win, but then that's news to us because for the last 10 years, I didn't think we try to sell to the federal community. But obviously, having Cisco, people like CGI or other global system integrators that are very relevant to that environment, we're starting to see wins there. So -- but we did not certify our cloud or cloud data centers as federal. We let partners deal with building such offerings.

Unknown Attendee attendee
#103

In the past, if you look at the ADC market way back when F5 put iRules in their ADC, and they built a moat around what they didn't know, it was really hard to penetrate that market. How does this market play out now and reaching the DevOps and getting at the ground level with programmers? And are they putting codes within their Kubernetes or within their micro programs, and do you have to be there first to win the market? Or what's -- how can it move from 1 vendor to another vendor? And how difficult is that going forward?

Roy Zisapel executive
#104

Yes. So I'll let also David complement that. But our approach here is not to take the proprietary routes, meaning the iRule was a proprietary solution locking. I think the whole concept of DevOps, whether in the end it's true or not, like cloud, it doesn't matter in reality if it's really open or not. The DevOps guys, they want to feel that it's an open environment, that it's like an open-source environment, that it's part of the global distribution, standard distribution and they are not locked in, that they potentially -- maybe it's very costly, maybe it's almost impossible. But potentially, they can change. So what we've done in Kubernetes WAF, in cloud workload protect, in all of that, we are not adding proprietary code. We're actually being, what we call, a native citizen to the distribution. So take Kubernetes. They have a proxy there that's called Envoy that can do load balancing and so on. We are not targeting Alteon to replace Envoy. So we're not saying NGINX will replace Envoy. We said no. Envoy is the standard. We will work with Envoy or we will build on top of Envoy the capabilities, so we behave natively, and it's very easy for them to deploy us. They don't need to do anything to deploy us, and it runs fully integrated with all the other tools of that ecosystem. Same we did with CWP. We are not putting code on each and every workload. We're actually reading all the information we need from the cloud APIs. So as little touch and as little, I would say, code lock in as possible, but at the same time, bring the value from this very clean integration, very easy deployment and focus on the value that we would have been doing.

Unknown Attendee attendee
#105

Is that different than what NGINX or other people are doing?

Roy Zisapel executive
#106

Yes. Very much so. So I think the game, I don't know, maybe there's much more knowledge on F5 game plan here. But they want to see NGINX as the proxy in Kubernetes or NGINX Plus or whatever it would be. We are looking on a different approach.

Anat Earon-Heilborn executive
#107

Okay. Then, thank you very much for coming.

Roy Zisapel executive
#108

Thank you very much for the very communicative Q&A session. Thanks a lot.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Radware Ltd. transcript - plus 252,000+ transcripts from 12,000+ companies, speaker segments and full-text search - through the EarningsAPI REST API or hosted MCP server.

Get an API key View API docs →

For developers and AI pipelines

Programmatic access to Radware Ltd. earnings transcripts and 252,000+ others is available through the EarningsAPI REST API and the hosted MCP server. Quarterly plans from $105 - full transcripts, speaker segments, full-text search, and the /api/v1/transcripts/recent polling endpoint for ETL pipelines.