Akamai Technologies, Inc. (AKAM)
NASDAQ: AKAM · Real-Time Price · USD
110.25
-0.50 (-0.45%)
Sep 10, 2026, 11:17 AM EDT - Market open
← View all transcripts

Analyst Day 2018

Jun 26, 2018

Operator

Ladies and gentlemen, please welcome Akamai Head of Investor Relations, Tom Barth.

Tom Barth
Head of Investor Relations, Akamai Technologies

Good morning. Good morning. On behalf of the Akamai executives and our over 7,000 employees around the world, I want to welcome you to our 2018 Analyst Day. I think we're very pleased today to have our executives sort of walk through about the current and future opportunities here at Akamai and how we are well-positioned to take advantage of them. You'll also see that we have two breaks after the second and fourth presenter. After this morning's session, we will bring up all our executives on the stage for a question and answer period. I ask that you hold your questions until then. You did see some signage about there is some power strips on the right side of your chair, and you can also see where the Akamai Wi-Fi is. The password was Akamai.

After lunch, for those industry analysts that are joining us here live today, we'll also have breakouts up on the third floor, and we'll talk more about that agenda during the breakout sessions. It's not an investor presentation without some safe harbor language, and you'll be happy to know I don't plan to read all this, I'd like to just remind you that today's presentations and webcast do include forward-looking statements, and these prospects that constitute forward-looking statements for purposes of the safe harbor provision under the Private Securities Litigation Reform Act of 1995. Actual results may differ material from those indicated in these forward-looking statements and as a result of various important factors on the slide before you, as well in our Form 10-Ks and 10-Qs.

In addition, any forward-looking statements represent our views only as of today, June 26th, 2018, and should not be relied upon as representing our views of any subsequent date. While we may elect to update forward-looking statements at some point in the future, we specifically disclaim any obligation to do so. Lastly, as noted in the final paragraph, the non-GAAP financial reconciliations can be found on akamai.com in the investor relations website. Enough of the formality, let's get things rolling. Again, thank you for joining us today.

Speaker 17

Tomorrow. It means the next day for all of us, but for some of us, it's more than just the day after today. Tomorrow is where today ends and imagination begins. Tomorrow goes beyond the horizon of what is possible and what will be. Whether you're already on digital's cutting edge or just taking your first transformative steps, your tomorrow always demands more. More actionable insights, better access to new markets, faster ways of reaching customers, killer apps that transform your industry. No matter what your tomorrow looks like, you'll be building it on one very simple thing, connections. Connections to your customers and employees, to your apps and data, to your cloud and between clouds, to the Internet of Things, to things you haven't even imagined yet. Your ability to shape your tomorrow depends on connections. Our singular focus is helping you create those connections.

With scale and resiliency second to none, Akamai is everywhere your customers are on the internet, ready to help you deliver flawless digital experiences anywhere and anytime, to keep you secure and protected, to be the heart and backbone of your digital business. Leading businesses across the globe trust Akamai's people and technology to help them deliver today while shaping what's yet to come. Working together, we can all connect to the things that truly matter.

Operator

Please welcome Akamai CEO and co-founder, Dr. Tom Leighton.

Tom Leighton
CEO and Co-Founder, Akamai Technologies

Thanks very much, thank you all for joining us today. As you know, the focus of our Analyst Day is to do a deeper dive into the company and talk about the longer term trends that we're seeing and the investments that we're making for the future. That said, Q2 is almost done, and I know that many of you are wondering how things went. We thought it would be helpful to provide a quick update on where we are. We're going to spend the rest of the day explaining why we are so excited about the future. As you probably saw from the press release we issued this morning, revenue and earnings for Q2 are tracking to the middle of the guidance range that we gave in April when measured using the foreign exchange rates that were in effect then.

As you know, the dollar has strengthened quite a bit since then, that's going to cause a $3 million hit on the top line and a $0.01 hit on the bottom line. The net is that we're revising our guidance, as shown here in the right-most column. Of course, a bunch can happen during the last week of a quarter, especially with the World Cup going on, which drives a bunch of traffic. I think we think this guidance should be pretty close to where we wind up. For the full year, we're tracking towards or above the high end of the guidance ranges that we gave in April, as measured in the currency from April. The impact of the strengthened dollar is pretty significant, with a $17 million hit on the top line and a $0.05 hit on the bottom line.

This results in the full year guidance shown in the right-hand column. You can notice that we're raising the guidance on earnings per share for the full year, despite the foreign exchange headwinds. Basically what's going on is we've got a $0.05 hit because of the strengthening dollar, but a $0.10 growth because of the great work we're doing on improving margins and controlling costs. The net is that we're taking up guidance on the bottom line for the year by $0.05. At the midpoint of this guidance range, at three and a quarter dollars, we would be up 20% year-over-year in constant currency. We'd be up 24% year-over-year as reported. That's a significant increase.

Our work on improving margins isn't done, and we're working hard to develop a plan that'll get us to 30% operating margins by 2020 while continuing to invest in innovation and growth. Jim is going to talk a lot more about this during his presentation later today. I want to be clear that we are very serious about continued margin expansion at Akamai. Okay. For the rest of the morning, I'm going to talk about the major drivers of our business going forward. You all are quite familiar with the first three shown here, since they're responsible for most all of our revenue and growth today. I'm going to spend most of my time this morning talking about these areas, media, performance, and web security.

I'm going to say a few words about three new areas where we see a significant opportunity for future growth. For the last couple of years, we've been investing in our platform to support a zero trust architecture for enterprise security, for Internet of Things applications for major enterprises, and for blockchain transactions. We're not generating meaningful revenue in these areas yet, we do hope that they'll start to make a real difference for us in the next couple of years. All right, let me get started by talking about our media business. When it comes to media, the biggest driver of revenue is traffic, and the biggest driver of traffic is online video. OTT is still in its early days, I think now most major broadcasters and media experts believe that the majority of viewing will someday take place online.

Many now believe that almost all video watching will eventually move over the top. In fact, I was in Europe a few weeks ago and talked to one of the largest broadcasters in Europe. They told me that they do long-range planning, and in their long-range plans, that they are planning to stop using satellite altogether within 10 to 15 years, which I thought was pretty surprising, that really going all the way. Moving over the top is not as easy as it sometimes might seem. It might seem like, oh, the video just comes from the cloud. Not that easy. You have to worry a lot about quality, scale, and cost, especially if you're trying to do live events or linear streaming. A few years ago, viewers might have tolerated a lower quality picture or maybe the occasional rebuffer. Those days are long gone.

That viewers are paying for OTT, it needs to be better than classical TV. It's got to have a high quality picture and uninterrupted viewing. It needs to start up instantly with low latency on any device, anywhere. To make matters even more difficult, today's online broadcasters also have to worry about the cost and capacity challenges with streaming over the internet. This was never a problem with a traditional broadcast model, since once you paid for the satellite, once you got the signal there, you're done. You didn't have to worry about how many people watched, since it didn't cost you anything more every time somebody turned on a TV. You didn't have to worry about flash crowds or congestion on the internet. Today, the more successful you are with OTT, the more you have to worry.

Based on the traffic growth that we're seeing, many of our customers are becoming very successful online. Actually, it was 10 years ago, in 2008, when traffic on the Akamai platform first reached a terabit per second. This seemed like a really big deal, and we were pretty excited back then. A terabit a second. To put that in context, how much is a terabit a second? Well, it equates, if you thought about it in terms of video, that equates to 1 million people watching a video streamed at a megabit per second. Just multiply that and you get a terabit a second. A megabit a second is not enough. It's about half enough just to do standard def, the old thing, standard def TV. All right? A terabit a second is 1 million people not getting standard def TV.

A lot has changed, obviously, since 2008. Just last week, we delivered 15 terabits a second just for the World Cup. We've had many days now where we've delivered 60 terabits a second on the platform overall. Last year was the first time we hit 60 terabits per second. It's pretty routine. Pretty much any day where there's a bunch of World Cup or a big software release, we're over that threshold. How much is 60 terabits a second, if you think about it in terms of OTT? Well, that would be enough to have 15 million viewers. I let you decide, is that a big number or a small number? Really, it's a small number. Watching at 4 megabits a second. All right, what's 4 megabits a second?

That's enough to do low-end DVD quality, better than standard def, just getting into DVD range, nowhere near HD, Blu-ray, or anything else. The question always on our minds, and I think maybe your minds, is where we're heading from here. Already 2.5 billion people have watched a video online at some point. Suppose we get to the point where 2.5 billion people, who are reasonably well connected, watch video every night during their local prime time. Suppose they watched it at 10 Mbps. 10 Mbps is the typical encode rate for high-quality video that broadcasters use today. It is still well below 4K, which at the low end of 4K is 16 Mbps. Doesn't get anything close to 8K, which we'll be doing for the next Olympics.

Doesn't get anything close to augmented reality or virtual reality, which we're already doing for some broadcasters in major events. In fact, in Europe a couple of weeks ago, I talked to one of the major broadcasters there, and we are now streaming UHD for them at 35 Mbps. That's the upper end of where folks are today. Suppose you just did it at 10 Mbps, sort of a sweet spot today for broadcasters, and you had 2.5 billion people watching over the top in the evenings. Let's do that math. 2.5 billion people watching in their local prime times at 10 Mbps, 25,000 Tbps. Even if you only had a tenth of this usage, it's still a mind-boggling number.

It's thousands of Tbps, and this is the reason why online broadcasters are so concerned about the capacity of the internet and the cost of streaming over the top, because every person that watches adds some cost, and as they watch at higher quality, that's a higher bit rate, adds cost. This is a big challenge, and it's something that Akamai has been putting a lot of effort into addressing. To really understand what's going on, I think it helps to look at the high-level architecture of the internet. One common misconception is that the last mile is a bottleneck in the internet. That is true in some countries, especially less developed countries. It's true for cellular. For a lot of people in a lot of the world, it is not the bottleneck.

In fact, if you do the math, you find that there is a lot of capacity in the last mile. By the last mile, I mean the connections in the homes and offices, schools. There's no exact numbers here. This could easily be off by a factor of two, but roughly, you've got hundreds of millions, almost a billion lines, last mile lines into a home somewhere, an office somewhere, a school, a dorm, whatever. Today, in the developed world, the typical connectivity in the last mile is 40 Mbps. It varies wildly. My guess is that all of you have more than that. There are some cities now where the typical connection is 1 Gbps. In fact, many cities in Europe and Asia are now when you get new connectivity is 1 Gbps.

You do that math, multiply that's 36,000 terabits a second. That is plenty to deliver decent quality, good quality video to a couple of billion people. All right. Plenty of capacity in the last mile in a lot of the world. The problem is at the core of the internet, where you have the cloud data centers that serve up the video, at least in the traditional model, and the major backbone providers in the core of the internet that deliver video from the major cloud data centers across hundreds, or in some cases, thousands of miles into the local neighborhoods. If you do the math here and you look at what's the capacity of the core of what we think of as the cloud, you can do it a couple of ways. You could either do it based on the data centers.

I think it probably is more helpful to do it in terms of the big transit providers. There are not 100 tier 1 networks in the world. There's a few dozen big core transit providers, and they do not have close to five terabits per second of core backbone capacity. All right. Even if we allow room for growth, you'll have less than 100 tier 1 Transit networks with far less than five terabits a second of core capacity. Being generous in doing the math, we find that there's hundreds of terabits per second of capacity in the core. Take the ratio of the capacity at the last mile and divide it by the capacity in the core, and you see you got a pretty big imbalance. All right.

That's a problem because as people get connected, they expect to use that connectivity in the home. They expect to start watching high quality of video. If you try to deliver that video from the cloud data centers or by the big tier 1 providers, you run out of capacity. That results in congestion. That means poor video quality. You can't get the 10 megabit per second stream. You can't even get an uninterrupted picture in a lot of places. Sometimes you'll see that congestion in the data centers, things fall over there. More often, you'll see the congestion hit in a choke point that's a peering point as you get close to the data centers, as the traffic coalesces going into the data center. We're already seeing this happen in many countries around the world.

It happens with some carriers in the U.S. It's going to get worse as the last mile gets better. As the last mile gets better, it puts more load on the core infrastructure and the expectation for what the internet should be able to provide gets bigger. It's weird. The more money you spend on the last mile, actually, the worse things get. The issue is actually really noticeable now during the World Cup. We're doing a lot of broadcast. In fact, most of the broadcasts for that in the countries around the world, Adam will talk about it later.

There's already been two instances of a major provider having a big challenge, because they deliver from the core of the internet, including one of the world's largest cloud providers, so the requests come in, and you get a congestion in a peering point, now you can't get from the cloud data center to the end users. Of course, then you have your failure at the worst possible time, exactly when folks are trying to watch the game. This is where Akamai makes a huge difference, and it's why we put our servers in thousands of locations at the edge of the internet. We put them at the edge because that's where the people are and that's where the capacity is, so viewers can get the stream, and you don't have to worry about the congestion.

The congestion is all in the cloud data centers and the peering points in the core. By delivering the viewer out from the edge, we have access to all that capacity, and now we can give the viewers a great experience, which is what's happening for the majority of viewers around the world watching the World Cup as Akamai delivers it. Going forward, as Akamai client software is used, we can achieve even greater scale, even better picture quality, and reduce cost at the same time by leveraging the power and the colo and the CPU that lives in people's homes and offices and on their devices. That's because our client software can draw the content from multiple sources, including other nearby users. We always choose the best source of the content in terms of quality and cost.

I think at the AR section this afternoon in media, we might even show a demonstration of the new client software. Next I'd like to talk about application performance. When it comes to performance, it has to be fast today. We are just not patient anymore when it comes to the web. If it doesn't show up right away, we will go elsewhere. Several years ago, there was something called the four second rule, which meant that a page had to load under four seconds or you were in trouble. That morphed into the two second rule. Everyone just wants it instantly, and interestingly, even on a mobile device and even in a congested cellular network. This is really hard to achieve, especially when it comes to mobile devices on congested cellular networks.

In fact, it's getting even harder to achieve today since users are demanding richer experiences. This means heavier pages with more pictures, more interactivity that requires large JavaScript files, third-party content, numerous API calls. All these things slow down sites and applications. Normally with tech, things are always getting faster, better, and cheaper over time. With the web, it's getting harder just to stay level, never mind making instant response times. That's a problem because performance really matters to business. The performance of your sites and apps matters to brand, search rankings, conversion rates, revenue, and ultimately customer satisfaction and loyalty. Simply put, performance is vital to just about everything that a business does online. The good news is that when you improve the performance of an application or a website, the returns can be really dramatic.

They integrated our Ion solution to make their mobile apps much faster. You see they got a speed-up here of 36%. When they did that, they got a 27% increase in their conversion rate, and that caused a 10% improvement in revenue. 10% for a company that size is an enormous improvement in revenue, the vast majority of which they attributed to Akamai. That's huge. There are zillions of case studies like this now. What really matters to our customers, of course, is the gain they can get for their website and their business when they improve the performance. We can now help them figure this out with our new Digital Performance Management solutions.

This is an example of what it looks like, and I think Rick and Craig are actually going to show it to you, interact with it later today. Today, we can go into our customers and show them a histogram of how their site's performing for their real users as they go through the site. We can show them that, wow, the users getting your site faster are buying more, or they're doing better in terms of the business metrics for the site, whatever those may be. Then we can also focus them and tell them which part of the site is the most important because some parts of the site actually don't impact the business metrics. Others do. So we say, "Look, put your energy here to this portion of the site.

By the way, we've got some great solutions that will speed that up. When we integrate those solutions, here how much more money you're going to make, here's how much money you're going to save. Here's how much we're going to improve your business." That way, they can justify going forward. They make the case, and after it's all done, we show them what really happened to prove that it really worked. This is a great tool we have now, and we'll see it in action later today. All right. I'm going to change gears now and talk about the third major area for us today with our existing business. In a lot of ways, it's the most challenging, and this is, of course, security. Security is our fastest-growing business by far. In fact, in a few years, it could be our largest business.

Pretty much everything today depends on the internet, and unfortunately, that means that pretty much everything is vulnerable. The scale and the damage being caused by data breaches today is enormous. When it comes to cyber attacks, everything is being attacked. Just when you think, boy, it can't get worse, it does, and you see the next headline. These are just some of the headlines from the past few months. It's mind-boggling what's going on. You see this, and you got to ask, why is this happening? Why didn't these companies, some big-name brands here, why didn't they defend themselves? I don't think it's because the execs that worked at these companies were stupid or careless. Probably quite the opposite. I think it's partly because we're up against some very large and very well-funded adversaries.

I'm not talking about the prototypical teenager trying to impress his or her friends in a garage somewhere. We're up against major governments, major organized crime, and political hacktivism on a very large scale. Each of these entities has their own objectives, but all of them have very large resources at their disposal. They are all highly motivated and very capable. Another major challenge is that on the internet, it is a lot harder to defend than it is to attack. All it takes is for there to be a slight hole in the defenses, an unpatched application, an employee who clicks on the wrong link, a device that didn't get properly secured, and the attacker will use massive bot armies to find the way in and exploit it, then you wind up with one of those headlines. This is a really hard problem.

Even the protocols that we rely on for security, remember the famous Heartbleed incident? Even our core security protocols have vulnerabilities that exist for years sometimes before they get figured out. No matter how much training a company does, some senior exec with permissions will click on the wrong link. Here's an example of a phishing attack sent to the CEO. Looks like it comes from the chief security officer. Looks like an Akamai domain. With my eyesight, that looks like Akamai. It's actually Akarnei. It's so easy to click on that, then you're dead. We actually own that domain now. Then to make matters worse, you got the Internet of Things. Billions, tens of billions of devices are getting connected, a lot of them have no security.

If they do have security, they have a password that's known to everybody and you can't change it. Just way too easy to compromise these devices, these devices are powerful. Today, they got a state-of-the-art CPU, a full communication stack, and access to massive bandwidth at the edge. That's incredibly powerful, the adversaries can exploit it, the bad guys. You know that same capacity we talked about at the last mile, the imbalance between big capacity out here and little capacity in the core, relatively speaking, the bad guys are using that to mount denial-of-service attacks. They take over the devices out here that have access to a ton of capacity, flood the cloud data center and the peering points with traffic, they get swamped. All right? That's a major challenge point or vulnerability for the Internet with IoT today that we're dealing with.

We're already seeing attacks with a scale of greater than a terabit a second. Just to put that into context, a terabit a second is enough to wipe out pretty much any cloud data center, pretty much any ISP, the connections for most countries at a terabit a second. As we talked about, the amount of capacity out at the edge, you can measure in tens of thousands of terabits per second. You've got billions of devices out there that aren't adequately secured. You get all excited and you see headlines when you're seeing attacks at a terabit a second, but there's no reason we won't be seeing attacks at tens of terabits, hundreds of terabits a second, or more in the future. All right? That's a pretty scary concept, I think, going forward.

This means we're already at the point where the traditional data center defenses just aren't enough. There's just no way to provision the capacity you need for a DDoS attack at any scale today, and even if you could provision it, you couldn't afford it. Maybe a few giant players could, but it just doesn't make sense. This is just the tip of the iceberg. The only way to defend yourself against large-scale attacks today, and this is only going to get more true in the future, is to defend at the edge of the Internet where the capacity is, and that's what Akamai does. That's, again, why our servers are located at the edge of the Internet, because that's where the bots are, and that's where all the capacity is.

Today, our servers act like a defensive shield against the attackers, and not only for DDoS attacks, but also application layer attacks. We place our Kona Site Defender application firewall software out at the edge of the Internet. All right. When the attackers come, we absorb that attack right where they are, at the edge, so that bad traffic doesn't get anywhere near the core data center. Because if the attack traffic gets close to your data center, you're in trouble. If the attack is at any scale, no matter what you've got, you're dead. No carrier can withstand it. No data center can withstand it today. This, I think, is one reason why, I think it just came out yesterday, that Forrester named Akamai as the leader in application firewall technology. Okay.

Being at the edge is important because more and more the traffic is coming from bots and compromised machines. It's important that we handle not just DDoS of traffic, but application layer traffic. A lot of people don't realize it, but for many of our customers, the majority of their web traffic today is not from humans. It's from bots. It's from machines. People right away think when they think bot that it's bad. A lot of times that's true, but actually there's many types of bots. There's some good bots, there's a lot of bad bots, and there's some bots in between. These are just some of the examples of the many types of bots out there. People don't think about this either, but how you respond to a request really should depend on the type of bot.

If it's a search bot, you want to respond quickly and with the right terms embedded in the page so you get a good search ranking. If it's a partner bot, well, you might have some idea of the partners and who should get priority. If it's a price-scraping bot, you might want to give it the wrong content. Sometimes you see with the aggregators, if you're looking to buy something and you go to a site that lists 10 vendors with a product. They rank them by price. You ever notice how some of the prices of one vendor are a penny less than the other guy? Well, because they've gotten a bot to go scrape the prices of the other guy and then automatically make their price be a penny less, so they show up on top and you're more likely to buy for them.

That's happening to lots of commerce companies. Maybe what you want to do is detect, oh, that it's a price scraper bot and maybe one hired by my competitor. I'm going to give it the wrong price. You give it the answer, just with a different price in it. Or maybe you don't want them to know you got a sale going on. What we'll do is, in real time, provide a page with different pricing because we know what the entity is coming to the site. Finally, you got the most nastiest bots of all are the hacker bots. These are bots that are trying to take over an account. They've stolen your password on another site, and they will try it on 10,000 sites because probably you've used that password on a bunch of the other sites you go to.

They find that, they get a hit, and then they sell that information to organized crime, which then takes over your account. Very, very hard to detect these bots today, and they're run by organized crime, which makes a lot of money doing it. To combat all this, we have the Akamai Bot Manager product, this has been our most successful new product in memory, in a long, long time. What it does is it provides a response in real time to any request based on the type of bot, which we can detect in real time. We leverage massive amounts of internet and transaction data to figure out what the entity is coming to the site and what it's trying to do. We use machine learning to protect against evolving bots, because all the sophisticated bots adapt very quickly to what we're doing.

Also increasingly now, we're putting effort into identifying what's human. We started by identifying what a bot is and the different types of bots, now because the bots are so sophisticated, we need to identify that it's a human. Someday even, which human, based on, in part, how you hold your device, how you move your mouse, how you tap on the screen. When you tap, does the device move in a certain way if you're holding it? Using this information based on recording this for billions of transactions, we can tell in real time, is it a human logging in or is it a bot? Let me show you now how that works with a demonstration. I'm going to do it on my phone.

Because it's a demonstration, what I got to do is tether my phone now to the screen that you're going to see here for the demonstration. Let me do that. We're going to go to the mobile. Let's see. Set it up here. This happens without your knowing it, my guess is on all your devices. That's because probably all of you are a customer at a bank that we're doing this service for, or you're buying something online for a company that we're doing this for. This is happening when you are already on your device. Watch as I move my device, how I hold it. We're actually recording all that information, how you move it around. If I set it down on the desk here.

Now you can see I set it down. If I rotate it, catches that. All right. Now in addition, as I do things like make my screen bigger here or minimize it or move around on the screen, it's going to record that on the touch. Now I'm going to log in. Username, Tom. Password, Tom. My CISO doesn't like that. All right. I type the log in. Okay, now what happened behind the scenes is this is what I just did. All right? I minimized it, moved around a little bit. The bots are good enough now they're trying to fake that. All right? They might do something like that. You can see as a human those are different. Our machine learning also sees they're different. Here's my key presses.

All right, you see I logged in with Tom, the three clicks, then I did my password with Tom there, the three clicks. Here's what a bot might send. A sophisticated bot might do this. Might send. You can see the difference. We are telling in real time, after analyzing these signatures of humans on zillions of signatures and knowing which ones ended up being bots and which ones ended up being human, we now, learning based on that, can tell in real time when you're going to your bank account or buying something online or going to one of the sites that has bought this service, that it's a human and not a bot. Someday we hope to know is it you or not, but we're not to that state yet. Okay, let's go back to the slides.

This is a new capability, but already we've got a lot of customers using it, starting with the banks, because the banks are the biggest targets for account takeover. This is a story from one of the world's largest banks, they've now been using this Bot Manager service for over six months. Before Bot Manager, they were losing 8,000 accounts per month due to these hacker bots that would come in, they'd steal a password or guess it, get logged in, see that it worked, sell it to organized crime, then organized crime empties the bank account. The bank was losing tens of millions of dollars a year, of course, the usual brand damage when you got to go to 8,000 customers and say, "Hey, your account's been hacked." They turned on this Bot Manager service, it wiped out the account fraud.

They're down to one or two accounts per month now. Not 1 or 2,000, one or two accounts per month that they lose. Huge change. Big deal. Very happy customer, obviously. Here's another example, this is from a commerce site. In this case, the commerce site sells apparel, sometimes their apparel is very popular, they'll have a special release, people want to buy it, they do it online. What happens is organizations get bot armies to go and buy out the entire inventory so they can resell it at a higher price on the gray market later. Now, obviously, the apparel company doesn't want this to happen. They want to sell the inventory to real people. They use our Bot Manager service to detect is it a human coming in or a bot?

In this case, the bots were 99% plus of the traffic coming in at 800,000 transactions per minute. All right. We filter out all those and only let the humans in to buy the merchandise. We see this also for ticket sales. Maybe there's a popular concert or a sporting event, or actually, we saw it with a very popular play on Broadway, where without Bot Manager, all the tickets get bought by the scalpers who employ bots to buy them. With Bot Manager, we can stop that, and the humans get to buy the tickets. Here's another one that's interesting. We see this across the airline industry, especially in APJ, interestingly enough.

The way it works today, when you go online and you get a quote or book a seat on an airline, when you first do the query, the airline has to go to a reservation system. That costs them a lot of money. Whether or not you end up buying the seat, they spend a big chunk. Their biggest cost is the reservation engine. What their experience is that bots come, often from their competitors, especially in Asia. The bots want to see what the pricing is. The bots sometimes want to book up all the seats, and that way the competitor has seats available at, you know, a lower price, or at least they're available. This is the way they compete with major airlines in APJ.

By using Bot Manager, they were able to cut their costs by a factor of five. What we do there is when the bot comes, we give a cached price. We don't go to the reservation engine. If they want, we'll give them a higher price. It won't be the right one, but it'll be a high price because it's the bot coming from the competitor. It's just amazing difference it's made to their businesses. Okay. That's our business, the three areas of major areas of our business today. There is a lot of growth in the future for those businesses, especially in security, which as you know, is growing like mad.

What I want to do for the rest of my talk this morning is talk about three new very disruptive areas that Akamai is helping to enable, which could have a big impact on our revenue over the next five years. I'm going to talk about Zero Trust for enterprise security, IoT, which is now in beta, and blockchain, which we're just in the very early days with. Starting with Zero Trust. Most data breaches today are triggered by insiders. They're triggered from inside the corporate perimeter. Sometimes, not usually, it's a malicious employee that is doing something bad. Usually, it's just an unwitting employee that clicked on that wrong link, went to the wrong website, might even be a legitimate website, but somehow got infected, got malware, then came back inside the perimeter, connected, and spread the infection.

The idea of the perimeter defense is sort of like the moat around the castle. The riches, your data, your apps, are on the inside with the people you trust. The bad guys are on the outside, and the perimeter is supposed to keep them out there. Doesn't really work very well anymore. The first challenge you've got is today you've now got remote employees. You've got contractors. You've got to give them access to some of your internal applications. You buy a company, you got to somehow integrate them to your existing systems. You end up poking holes in your firewall to let these parties in. You ship them a device. It's expensive. It's not very secure. About a year ago, we introduced a new capability called Enterprise Application Access.

The way it works is we will authenticate these third parties much better than you're likely to do on your own, and allow them to have access to only the apps they are supposed to have access to without poking a hole in your firewall. This makes it be cheaper and a lot more secure. Today, the challenge is, once that employee gets access to the wrong thing or gets inside with some malware, the time it takes to spread and cause damage is measured in hours. The time it takes to catch is measured in many months, and that's a big problem for the data breaches. You see that happening in this graphic here. The employee goes out somewhere on the internet, gets infected. Within hours, the employee has spread that infection to sensitive apps and data on the inside, and the data's gone.

All right. This is why Forrester recently said that the idea of a corporate perimeter becomes quaint, and even dangerous in today's world. That's because the corporate perimeter is giving you a false sense of security. This is the way that pretty much everybody does it today. In reality, you can't trust anyone anymore, not even your most trusted employees. We truly live in a world of zero trust, or should think of it that way. You need to protect your internal apps the same way that you protect your external-facing apps, just as if you didn't have a perimeter or a firewall. For your external apps, you do all sorts of things to protect them because you know they're going to get attacked from the outside.

You have authentication, you have web app firewall, you have DDoS protection, you have bot protection, you have all the things that we provide with Kona at Akamai. You need to do all that for your internal apps. Your employees are still going to get infected. When they do, and they try to access your internal apps, because you don't trust them, you're going to block them. You're going to catch and stop the spread of the infection, you're going to detect they're infected, and you're going to let the CISO know so you can go clean it up. That means you're not going to lose your data. We support this capability today. It's early days still. We have our first set of customers using the technology, and they're seeing some amazing results. This is data from one of the world's largest airlines.

Within the first week of turning on this capability, which is Enterprise Application Access with Kona Site Defender to protect the internal apps, in the first week, we caught dozens of inside devices, insiders, trying to attack their internal apps, and they had no idea. First, we stop the attacks from happening, and second, they now know they got to go clean up those devices. Defense in depth is still important. I'm not standing here telling you get rid of your firewalls or your perimeter defenses. Someday, I think we'll get to that point. Today, no, you still want to have that, but you do need to have a zero trust mentality and architecture and support for that. I think it's also important to do everything you can to protect your employees and devices as they interact with the outside world.

We also have capabilities to help with this. In particular, Enterprise Threat Protector, which again is a relatively new service in the last year, and that provides protection by using recursive DNS, which we provide as a service for the enterprise, and secure web gateway capabilities to do the best we can for your employees as they go to the outside world to make sure they don't get infected, and also if they have been infected, to catch and stop the spread of your sensitive data getting released. We have a lot of customers using this today, and already we've had several customers use this to find that internal devices were infected, in particular, the HVAC system. All right?

People don't often think about the air conditioning system being connected to the corporate internet, but of course it is because somebody wants to control the HVAC system remotely, set the temperature in the remote stores or branch offices. It got connected. You don't think about it, but today, your HVAC system is part of the Internet of Things. It has probably a very capable CPU and a full communication stack. It probably doesn't have very good security. The bad guys have figured this out. They get inside, they get malware on your HVAC system. From there, they go collect your internal corporate data and they exfiltrate it.

We catch it because usually those devices have to do a DNS lookup to reach the botnet to send out the data, because the botnets have to move around, the HVAC system has to query DNS to find out where the botnet is to send it the data. We know because of all the data we have, massive amounts of data on the internet, often where those botnets are as they're moving around. As we handle the DNS lookup, we can say, "Wait a minute. The HVAC system just tried to connect to a botnet known for data exfiltration. That's not good." The HVAC system shouldn't be going out there at all, much less to a botnet. We block it, and then we notify the CISO, "Hey, you got to go fix your HVAC system." Already we've seen this happen in several accounts.

Here's where the Nominum acquisition comes in. With Nominum, we are now providing the DNS lookups to a huge fraction of the internet. Many of the world's major carriers, we're now providing the recursive DNS lookups. This gives us access to a massive amount of data. We're seeing 5 million new domains every day, many of which are malicious. They're the botnets as they're moving around, and we block 1 million of them every day. We get fantastic amounts of data, which is great for our security products. Also great for mapping, as Bobby will talk about later, to help with our video flows on the internet. It also gives us an access to the carrier sales forces and the carrier as a partner and a channel for our security services to reach small and medium businesses.

What I'd like to do now is show you an ad that Telstra runs in Australia, this is describing the capability to provide security services for small and medium businesses and homes, in fact, to help homeowners from being infected. It's all running on Akamai technology. If we could roll that video, please.

Speaker 17

There we go. Look right here in the eyepiece. Wow. It's a place where children learn. It's where people connect. Is this your first dance class? You want to help mama pack? Okay. Where futures are planned. It's your new Telstra bundle on our fast and reliable network, and it's safer. Telstra Broadband Protect automatically helps protect every device in your home from online threats. Telstra Broadband Protect puts you in control of your family's time online. Okay, honey, it's time for your homework

Such as limiting access to certain sites during homework time so that parents are more confident with what their children are doing online. Putting protection for all your devices at your fingertips with Telstra Home Dashboard. You can be confident that if you accidentally stumble upon a malicious link, you're more secure. You can trust that Telstra Home Internet Bundle, including Telstra Broadband Protect, works continuously to give you a fast, reliable, and safer online experience. Telstra. Thrive on.

Tom Leighton
CEO and Co-Founder, Akamai Technologies

Yeah, you don't think about it as you're using it. Probably many of you are using something similar, and there's a very good chance, as it is the case here with Telstra, that's us doing that. It's important for us because in part, we get all that data, which helps make our services like Enterprise Threat Protector so powerful and so much better than the competition, which doesn't have access to all that data. Okay, the next area I want to talk about is the Internet of Things. There has been a ton of buzz about IoT, but we've only seen the tip of the iceberg when it comes to real applications. There are billions of people and tens of billions of devices and countless petabytes of data and information that are getting connected, and instantaneous and intelligent access is the expectation.

There's some pretty big challenges. Scale, performance, security, talked a lot about that, and cost are all challenges to really large-scale applications with the Internet of Things. Of course, these are the areas where Akamai has a lot of experience. Over the last couple of years, we have built an IoT edge cloud platform. This is a global edge platform for real-time data management, processing, and control at scale with security and the power to do compute at the edge. In particular, it supports MQTT and the IoT protocols, which are not all HTTP. Has container support at the edge, so business logic can reside at the edge. Bidirectional security for IoT devices, by this I mean we want to protect the devices from getting infected, and a lot of them already are.

The ones that are, we want to block them from doing bad things on the internet. Low latency is critical for a lot of IoT applications. Of course, you need massive scale, where again, this is where Akamai has a lot of expertise. We're already in beta with the IoT platform. The two early use cases are for automotive. There's 70 million connected cars. All the new cars are connected. In fact, a typical new car will have 70 different functions in the car that's trying to maintain a real-time data feed back and forth with the manufacturer. For them, logging, alerting, and command and control is really important, especially in real time, and especially as we try to do more autonomous driving. You really want to have instantaneous back-and-forth connectivity there. The other early application area is with gaming.

There's 130 million consoles out there where one of our large customers would like to maintain constant connectivity. They're interested in real-time groupings of players for the game, so so-and-so can play with their friend, so-and-so can send an alert to their friend's device to wake up to say, "Hey, I'd like to play." Again, you got the same desires for logging, alerting, and command and control in real time. We've got a breakout session later today on IoT devoted to this. Ash Kulkarni will be speaking, and you can learn a whole lot more about our IoT efforts if you'd like to attend that. The final area I'd like to talk about today is blockchain.

A lot of buzz about blockchain, and sometimes when people hear that word, they think about cryptocurrencies like Bitcoin, and there's a bit of a bubble and a lot of hype out there with cryptocurrencies. In fact, blockchain is a serious technology with far wider applications than just cryptocurrencies. It's going to be useful for financial transactions, cashless transformations, privacy and identity applications. Pretty much wherever you want to have a record or a ledger that something happened. Blockchain has some pretty serious challenges to its adoption. Again, it's things like scale, performance, trust, and cost. Part of it is because blockchain typically today is based on this notion of proof of work. You got to do a ton of work to update the ledger, and that means you can't scale it. It's not cost-effective by the very definition.

These are areas where we've got a lot of experience. As with IoT, we've been putting a lot of work into this over the last couple of years and developed a blockchain platform using a little bit different technology, so we're not wasting a lot of work to update the ledger. That makes it be a lot faster and more scalable, and also we can make it be trusted. This is just a comparison of what we can achieve with this platform. Traditional approaches being a few updates per second, maybe some of them maybe getting to a thousands per second. We can do millions. End-to-end latency, typically with blockchain, takes minutes or hours. We can do an end-to-end latency of 2 seconds. You swipe the card and to have it be securely transacted with everything done, 2 seconds.

The cost goes way down, and this is critical to really do blockchain at scale, down from tens of cents per transaction to a tiny fraction of a penny. The first application which we're working on is with a payment network with Mitsubishi Bank in Japan. The new network is targeted to provide a comprehensive set of financial services, including support for credit card and debit processing, pay per use, micropayments, and other IoT-enabled payment transactions. The goal, and Mitsubishi's motivation here, was to provide huge cost efficiencies and security enhancements to get digital payments at a much higher scale. The legacy system there is slow and expensive, and we're working together with them to change that.

For those of you who stay this afternoon, we've got a special breakout session on IoT and what we're doing, to be run by Andy Champagne, who's the CTO for Akamai Labs, and he's been spearheading the technology development on our blockchain platform. Almost done. One of the really nice things is that everything I've talked about today, all 6 categories, all the solutions run on a single platform. That platform is incredibly well-situated to provide great performance, great security, scalability, great reliability, and cost. This is the Akamai Edge platform. It is unique in the world today. It's the largest and most trusted cloud delivery platform. We have over 240,000 servers, and what's even more important is that they're inside, not peering, inside 1,700 partner networks in nearly 4,000 locations around the world in 133 countries.

We're carrying a ton of transactions and traffic, over 40 million hits per second, 2 trillion a day. I think that number's probably out of date now. Typical day is 50 terabits, some days 60 terabits per second. Great penetration into the world's major enterprises. All the major retailers, the biggest retailers use us. The biggest carriers are partners and using us. All top 25 U.S. banks, I think 22 out of the top 25 in Europe use us. Pervasive use by major enterprises today on the platform. Next, to talk more about the platform because it is so important. It is what enables us to do all the things that I talked about and to do it in ways that other folks can't.

Bobby Blumofe is now going to come up on stage, talk about the platform, why it is hard to replicate, and what's going on in the internet. Thank you all very much.

Robert Blumofe
EVP, Platform and General Manager, Enterprise Division, Akamai Technologies

Thanks, Tom. Okay. What I want to do now is go a little bit deeper on the Akamai platform, explain why it is that we deploy at the edge, the advantages that we get from building out our platform at the edge. In fact, I will be talking a bit about the advantages that the entire web ecosystem gets from the fact that we are deployed at the edge. I will also speak about why it is that it's so hard for others to replicate that architecture. To understand our unique approach, our edge architecture, it's helpful to start from the traditional architecture. Let me start by showing you the traditional way in which an enterprise would deploy their applications, and that begins with a data center. The servers go in data centers, and of course, today, when I say data center, it's probably a cloud data center.

You have your servers in the cloud data center. You would then have a first-mile connection to one or a small handful of networks that we call transit networks. The transit networks will then connect to the ISPs. The ISPs then connect over a last-mile connection to their subscribers, the end users in their homes, on their mobile devices, in their enterprises. I have simplified this diagram in a number of ways. One important way is that I have shown only one transit network between the data center and the ISP. Typically, there would be multiple. Typically, one transit network might connect to another transit network and so on before you actually get to the ISP, which then connects to the end user.

The transit network performs a very important function in this ecosystem because it is the transit network that creates the connection to all the ISPs, because there is thousands of them. There are thousands and thousands of ISPs out there, and it is impossible for most enterprises, certainly, to connect directly to all those ISPs. It is the transit networks that make that possible. The transit networks provide that sort of intermediary function that allow enterprises to get connected to all the ISPs. In fact, that is kind of the definition of a transit network. The definition is basically that the transit networks, either directly or indirectly, connect to all the ISPs so that you don't have to do it yourself. Okay? Now, this architecture works. It is simple, it does have some problems.

To begin with, the data centers and the end users are typically far away, because we're talking about only a small number of data centers, a small number of transit networks. You're inherently going to be somewhat far away from your customers, the people that you care about. Now, it's also the case that the traffic, as it routes from your data center to your customer, is probably not going to take an optimal route. Well, for sure, it's not going to take an optimal route. In fact, the routes can be oftentimes quite convoluted, and that may surprise you at first, but if you think about it shouldn't be that surprising, because the vast majority of networks out there have never heard of you. They have no idea who you are. They've never heard of you. They have no contractual relationship with you.

Why should they bother to route traffic in a way that is at all optimal for you, high-performing in any way, shape, or form? They are going to route traffic purely based on what matters to them, which generally means trying to minimize their cost. Okay? You get bad routes. That happens. Now, the other thing that's worth pointing out is that this model is also not so good for the ISPs because the traffic, as it routes from the data center to the end user, has to route over the peering link, and that's the link between the ISP and the transit network, then across the ISP's backbone before it finally gets to the end user. That's where there's cost. In many cases, the ISPs actually have to pay the transit networks. You see that all over the internet.

ISPs pay the transit networks for that backbone and for that peering connection. Even if they don't, it's a cost. It's an enormous cost for a network to maintain peering capacity and backbone capacity. As traffic grows, they have to grow those capacities, therefore, their costs increase dramatically, but of course, their revenue doesn't increase. For that reason, the ISPs generally restrict the capacity, especially on their peering links. They do this very intentionally. They make sure that they only have so much capacity on their peering links, partially to save money, and partially to the extent possible to force the larger enterprises to create direct connection and bypass the transit networks. For that reason, you get congestion on the peering links, and that creates a whole new performance problem.

In addition to the latency problems because of the bad routing, you now have a packet loss problem because of the restricted capacity on the peering links. The Akamai approach basically addresses all of these problems. We, instead of having our servers in these small number of data centers, deploy our servers at the edge, effectively bypassing all those problems in the middle, serving content right near the end users and over optimal routes. This improves performance, that's better for the application owners, that's better for the users, and it's also better for the ISPs because we have now taken all that traffic off of their peering links and off of their backbones, saving them an enormous amount of money. To boot, we're of course improving the performance for their subscribers. They've got happier subscribers, happier network engineers, because they've saved a whole lot of money.

Another thing that Tom touched on is the capacity issue. I get this question all the time in my role. People ask me, "Well, what is the capacity of the internet?" The answer is that it depends, and it depends a lot. In fact, Tom showed you two orders of magnitude difference between the center of the internet and the edge of the internet. That's the right answer. The right answer is that the capacity of the internet depends on where you measure it. If you measure it in the center near those cloud data centers, you get a pretty modest number. In fact, a concerningly small number.

As you get toward the edge, as you get near the end users, you get to the last mile connections to the edge of the internet, the capacity grows exponentially in the ballpark of two orders of magnitude more capacity as you get out to the edge. That, of course, is important not only for media traffic, but also for protection. Tom did talk a bit about how we use that capability to provide DDoS protection, and let me show you that in one more way and maybe in a little bit more detail. I'll again do what I did before, which is contrast our approach to DDoS protection against the traditional approach. The traditional approach, of course, is to employ devices, appliances, or software in your cloud data centers that are typically some form of firewall.

I've drawn a firewall right at the data center. That is the typical model. This model is not going to work at the scale of DDoS attacks that we've seen now for many years. The reason is because the attackers can congest links and backbones far upstream of your data center. In this example that I've drawn, you see a set of bots who are performing the attack, and these bots happen to be on a single ISP, and they have congested the peering link between that ISP and the transit provider, effectively knocking that ISP offline. Now for you, the owner of this application, all of your legitimate customers who are at that ISP, subscribers of that ISP, can no longer reach your website. This example can be repeated at many different scales.

In fact, it could be repeated quite easily at the country scale. I could change this picture and instead of the label ISP, I could put the label of a country in that location. The picture would be the same. The attackers have now knocked an entire country offline. All of your customers in that country can no longer reach your website. At a slightly larger scale, I can now repeat this example. In this picture now, the attackers have congested the link, your first-mile link between you and your transit network. Now they've completely knocked you offline. In this picture, you're completely offline. Your entire world, all your subscribers, all your customers all around the world can no longer reach your website. There's nothing you can do about it.

There's no addition of firewall capabilities inside your data center that you could employ that would fix this problem for you. The only way to address this problem at the scale that we've seen really for years now, and certainly at the scale that we are going to see, is the edge, because that's where the capacity is. By blocking the attack at the edge near the source of the attack, near the attackers, as opposed to near the destination of the attack, that's the only way that you can really address these problems at scale. Akamai, our servers have built-in firewall capabilities right at the edge, right near the source of the attack.

We block the attack there before the traffic can ever get onto the backbones, before the traffic can get onto the peering links, and before it can get anywhere near its destination, anywhere near our customers. These problems that I've just shown you, these problems of lack of capacity in the peering links, lack of capacity in the backbones, the ability for attackers to take out these links, these problems have only gotten worse over time. I've been at Akamai for a long time, and I've been watching this over many years, and progressively, year after year, these problems, and this may be counterintuitive, by the way, these problems have only gotten worse. Certainly over the past few years, we've seen them get actually considerably worse, and there's no reason to expect that to change.

That may surprise you, again, if you think about it, you realize the reason for this problem has nothing to do with technology. You can't expect some new technical breakthrough to fix this problem. It's not a technical problem. It's inherent in the business structure of the Internet, the Internet as a network of networks, all of whom have to cooperate as well as compete with each other. This problem, as I said, just gets worse. I've explained Akamai at the edge, the advantage that we get from being at the edge, really the benefits that the entire ecosystem gets from Akamai being at the edge. Now let me transition into a discussion of why it is that this is so hard for others to replicate.

On this slide I've listed six areas of challenge from an engineering and development point of view that basically create difficulties for others to do this. The other way you can read this list, by the way, is this is a list of things that we have invested in substantially over the past 20 years, building up these capabilities to make it possible for us to be at the edge. Again, that's a barrier for others. Let me start with deep network relationships. Tom showed you some of these numbers. The Akamai platform today, 1,700+ networks, 130+ countries, almost 4,000 locations. The point here is that you cannot get to the edge of the Internet without numbers that are in this ballpark. You can't do this with tens of networks or even hundreds of networks. You can't do this with a few tens of countries.

You can't do this with a few tens or hundreds of locations. You need to have numbers in this range before you can have the kinds of capacity and capabilities that we have at the edge. Creating these network relationships is an enormous investment. That's what we've been doing for the last 20 years. The next point I want to make is about cost, because if you're going to be at the edge, if you're going to do this at scale, obviously cost matters quite a bit. Creating a cost-effective edge infrastructure is another enormous investment. Let me spend a little bit of time explaining our cost structure, and I'm going to talk in particular, of course, about our network costs, which are in the form of capital expense and COGS.

In this slide, I'm showing you the last 10 years or so of traffic, and you can see the enormous traffic growth. You can see two of the big drivers of cost, which are energy and servers, and you can see that we've effectively decoupled the cost metrics from the traffic metric. We've been able to do that through this enormous investment in cost optimization. To explain that, I want to show you how it is that traffic drives the various forms of cost. Server CapEx, colocation, which is a form of COGS, energy, which is COGS, and bandwidth, which is COGS. Starting from traffic, of course, to deliver traffic, you have to buy servers. Servers cost capital. Of course, servers have to be placed into racks. Racks have to be purchased. That's colocation. Servers also need energy. You have to buy that energy.

That's also COGS. Traffic has to be delivered through ports. These are the pipes that you obtain through networks. To deliver traffic, you have to purchase ports, and that drives bandwidth COGS. The point of this slide is to understand that all these are areas that you have to invest in if you really want to drive down cost. You can't ignore any part of that graph if you want to really invest and drive down cost. I'm going to explain that in a little bit more detail now by going through some of those lines and giving you some idea of what the types of things that you have to do are to manage cost on that line. Starting with servers. If you want to minimize the number of servers you buy, you need to optimize your hardware and software.

Of course, as you buy servers, there's an opportunity to manage cost in how you manage your purchasing of servers. Next, putting servers in racks. That's an optimization problem. It's actually a very interesting mathematical optimization problem. How do you pack servers into racks into an optimal way to buy the fewest number of racks? Then, of course, you want to manage your colo vendors. There's energy. How do you deliver your traffic, your capabilities at the minimum amount of energy? Optimize energy consumption. Then, of course, you can manage the way you purchase your energy. Next, traffic. This is another fascinating mathematical optimization problem to try and pack your traffic into the minimum number of ports and then purchase those ports at the optimal configuration. Look at all those green boxes.

Each of those is an area where we have invested over the last 20 years to drive down cost. If you're serious about cost optimization, you need to get into all those areas. What I want to do now is give you a little bit more insight into one of those areas, and that's hardware and software optimization. Starting with hardware. We're at a scale now where we look at all of our servers, and we produce a custom server configuration, and it encompasses a whole bunch of different areas from chassis design, power supply, the configuration of the storage, the mix of the different types of storage devices, the controllers. In this example, I'm just showing you one particular part of the hardware, and that's the motherboard. We remove components that we don't need.

We use different types of components depending on what our specific use case is. We've actually taken some components that are normally not part of a motherboard, and we've integrated them onto the motherboard to, again, drive down cost. This can result in up to 3% capital savings per server, and that's just for the motherboard. That's just the motherboard part of it. Add it up across everything that we do, substantial savings. Again, when you think about the scale that we're operating on, that creates the ROI. Again, this is very hard for a smaller scale player to do because it is a significant investment, and you're only going to get a return on that investment at scale. Software optimization is somewhat similar. In fact, software optimization has many more dimensions to it, really.

This is a list of some of the areas where we work to optimize the software. I'm not going to go into each of the items on this list, but I want to show you the first two, kernel optimizations and software-defined networking. Starting with kernel optimizations, we use an operating system that is derived from Linux, and we have customized the kernel of that operating system with 78 Akamai-specific patches that cover a number of different areas like storage systems, file systems, the network communication protocols, memory systems, and so on. Again, my point is not to get into each of these areas, but by creating this custom kernel and creating these capabilities built into the kernel, we take down costs substantially.

One of the ones that I will highlight here just to give you some flavor of what each of these is, if you look about the middle of the list toward the bottom, connection tarpitting. You may wonder what that is. Connection tarpitting is the following. The idea is that when you're under attack, you respond to the attackers, but if you respond too quickly to the attackers, it actually makes it easy for them to amp up their attack because they get a response quickly, they generate another attack back to you. It makes their attack actually efficient. Responding quickly makes their attack more efficient. The name of the game here when you're dealing with attackers is you want to make them inefficient. You want to make them consume as much resource on their end per unit of attack.

By doing this thing that we call connection tarpitting, which basically is slowing them down. It allows us to respond to the attacker slowly. It may seem counterintuitive that you'd want to respond slowly, by responding slowly, you make them use up lots more resources on their end for every unit of attack that they generate on our end. By building this into the kernel, we're able to do this at very small amounts of resource on our end, that's the name of the game. We use very small amounts of resources; they use very large amounts of resources. All right. I mentioned software-defined networking. Not going to spend a lot of time on this. Simple idea. As you scale, locations get larger and larger. Obviously, we have lots of locations, but that doesn't mean that the locations themselves are all very small.

These locations do have to get large, as they get large, you hit scaling barriers and cost barriers when you use the traditional approach of using a router. Again, our competitors are just going to buy a big router. Routers, not only are they expensive, but they actually have scaling limitations. What we've done is replace the router with custom software and commodity switches. That means that we can now scale simply by adding more and more switches. We don't need bigger and bigger routers. We just need more and more of these commodity switches, that creates reliability benefits, scaling benefits, and enormous cost benefits. Next point, request routing, failover, and load balancing. This is a system at Akamai that we call Mapper.

Those capabilities are done by the system that we call Mapper, it is a rather remarkable invention that, in fact, actually goes back a long ways. We've been developing our mapping capabilities for many years, it's a unique capability at Akamai that its job is to direct end users in real time. Every end user who makes a request to an Akamai customer, the Mapper system sends that user to the Akamai server that is at that moment in time best able to serve that end user. From a performance point of view, from a reliability point of view, all those factors are taken into account. Mapper also, by the way, takes into account cost, it actually is part of our cost optimization engine.

Mapper is unique, to just give you some flavor of how it's unique, let me contrast it with the more traditional way of directing users to servers, which is a technique called Anycast. Anycast is based on using the internet routing protocol, which is called the Border Gateway Protocol, BGP. Anycast just uses BGP, the Border Gateway Protocol. The issue is if you ever are bored and you want to spend some time on this, read the BGP protocol spec, one of the things you'll discover is that there is nothing in BGP that says anything about load balancing or performance. It's just not there. Again, if you think about what it's intended to do, it's really to run the business of the internet, not the performance of the internet. It wouldn't surprise you that those things are missing.

Yes, if you use Anycast, there's nothing there that provides for load balancing. You can very easily get into a situation where your users are all being sent to one of your cloud data centers, your other one is completely underutilized. This is an enormous problem if you think about how you're going to build up the capacity in your data centers. No ability to manage load balancing. There's also no ability to really control performance. We frequently see with Anycast end users, for example, in this picture, you see an end user in Philadelphia being directed to servers in Singapore. This kind of thing happens. With Anycast, this kind of thing is going to happen because, again, there's nothing built into these protocols that say anything meaningful about route optimization or locality. In contrast, our Mapper system is designed to solve exactly this problem.

It is designed to load balance, it's designed to maintain locality. Locality, by the way, is another factor that comes right back to our ISP relationships because there's nothing that an ISP engineer cares more about than locality. Localizing traffic is everything to an engineer at an ISP because that's how they manage their networks. Our Mapper system is able to do that. Tom, by the way, talked a little bit about the Nominum acquisition, talked about some of the benefits that we get from a data point of view. We also get this incredible benefit from Nominum in that because Nominum is the recursive DNS for all of these ISPs, we get additional localization information that allows us now to localize traffic even more than we ever were.

By the way, this localization information isn't information that you could even use if you were doing Anycast. It just would be pointless. Because of our approach, we can take advantage of all that data, localize even more. That helps our ISP partners as well as, of course, our customers. Okay, let me move on to the last couple of points, and I'm pretty much at the end. If you want to manage a system at this scale, you need automated global system management. There's really nothing you're going to buy off the shelf that's going to work at this scale. If you want to build a system that is going to support multiple customers, you need to deal with this issue of multi-tenancy. This is surprisingly difficult.

Many traditional software vendors who have been in the on-prem business and trying to move to cloud, this is one of the biggest challenges they're having. Because the typical approach, by the way, which is to use something like a hypervisor and use virtual machines or containers, doesn't provide enough isolation. Customers need to be completely isolated from each other in one of these systems. Then finally, multi-product. Tom talked a lot about the capabilities, this afternoon, you're going to hear a lot more about the many different products. Behind each of those products is a wealth of capabilities. Our edge servers support all of these capabilities and more. My point here is that it's, one, a lot of capabilities. Two, these are capabilities that our customers really care about.

They need the vast majority of these capabilities to really deliver their web applications with performance, reliability, and so on. In contrast to our competitors, the competitors that we deal with or that our customers will deal with really only have one or a handful of these capabilities. Therefore, an enterprise is going to have to cobble together six, seven, eight separate vendors to cover all these capabilities. With Akamai, they get it in one. To conclude, our edge platform is highly scalable, provides an enormous competitive advantage that allows us to drive down costs, and creates product capabilities that are unequaled by far anywhere else in the ecosystem. That is it, and I think, am I at the end of this morning session?

Tom Barth
Head of Investor Relations, Akamai Technologies

You are, Bobby.

Robert Blumofe
EVP, Platform and General Manager, Enterprise Division, Akamai Technologies

Damn.

Tom Barth
Head of Investor Relations, Akamai Technologies

Thank you very much. Thank you. I appreciate that. We are going to take a 10-minute break. We'll let you know when to come back. Thank you, Bobby. Around the corner near the registration desk, and we'll see you in about 10 minutes. Thank you very much.

Operator

Please take your seats. The program will begin momentarily. Please welcome Akamai's Media Division General Manager, Adam Karon.

Adam Karon
EVP and General Manager, Media and Carrier Division, Akamai Technologies

Thank you. I am really excited to be here today to talk about Akamai's media and carrier division. I am more excited to be here to talk to you about the actions that we have been taking over the past year and some of the successes we had as a result of those actions. Before I get to that, I thought it would be good to baseline us in what the media division does and what we are responsible for. Starting with what we are responsible for, we are responsible for carriers, the giant cloud platforms, and customers across media segments that Akamai serves. Verticals such as OTT, gaming, software publishing, advertising, and social platforms, like I mentioned, those cloud platforms and, of course, our carrier partners.

Our business is driven primarily by traffic from large content distributors, but additionally, it is driven by products that our web division creates, such as security and performance, that helps us drive depth and stickiness in our customer base. Let us talk about that customer base. We have deep penetration in all the segments that we serve. In broadcast OTT, we have 47 of the top 50 U.S. television networks. On the OTT pure play side, five of the top six virtual MVPDs. Social media publishing, seven of the top 20 global social media platforms, 21 of the top 25 global newspapers, all of the top 50 carriers that Tom and Robert talked about that are required for us to get deep into networks. On the gaming side, 21 of the top 25 global gaming companies. On the sporting side, all of the major U.S. sporting leagues.

This list is exceptional, but there is tremendous opportunity for us to expand our base, but also go deeper inside those customers and get more share. More than 70% of our revenue comes from products like streaming, large file delivery, and carrier products that we develop inside the division itself. The remainder, as I mentioned before, come from products like performance, security, and services and support that we sell to those same customers. On the revenue mix side, we are continuing to diversify. Over the last five years, the diversification away from the cloud platforms has continued. We are down from 27% of our revenue in 2012, down to 13%. Those giant cloud platforms, some of them are still important customers, but this diversification away from them means they have less impact on our revenue growth in the future.

The video segment has grown significantly, up from 41% in 2012 to 55% today of the traffic that we deliver inside the division. On the revenue mix side, in terms of international mix, our revenue is growing at a healthy 12% internationally, driven heavily by APJ, and it now represents 40% of the divisional revenue. We have got a good mix between U.S. and international today. All right. I have baselined you and our customers a little bit and what we sell and a little bit about our revenue mix. Tom talked about it earlier in the beginning of the day, which is that traffic drives the media and carrier division revenue and success. I want to talk to you a little bit about the growth drivers for that traffic, and first, video, where we are seeing that continued trend of broadcast television moving online.

Whether it's live or VOD, viewers of that content want to watch what they want, when they want, wherever they want. That's bringing more viewers, longer watch time, and higher bit rates to that traffic, and that traffic's increasing rapidly. Tom showed that great chart, at the beginning, showing how that traffic's increasing. On the gaming side, that's also driving dramatic traffic, and we're seeing four key trends in the gaming industry today. The first one is free games. I have kids, and they play Minecraft or Roblox, Fortnite, and one of the things that reduces the barrier for them to try out these games is that they're free to download and start to play. Unfortunately, for my credit card anyway, that they have in-app purchases, and my kids spend a ton of money on them.

That low barrier of entry to play the games means more people downloading the game, less barrier to try the game, more people playing, which leads to multiplayer gaming. These games are not like when I was a kid where I played by myself. This is where they can play with their friends. They can talk with their friends with the same games I just mentioned. More people are using them, playing together, leading to longer engagement time. The move to digital continues. I was surprised to see that 50% of console games are still distributed by disc, so there's still a long way to go to move those online for digital downloads. Of course, multi-platform experiences. All those same games I just talked about, people want to play them on their phone, their tablet, their console, and their PC.

All of this creating more gamers, more games online, and of course, bigger game files, and that, just like in video, leads to more traffic. If I haven't mentioned it already a couple of times, traffic is the growth driver for the Media & Carrier Division. Let's talk a little bit about the competitive landscape. We have three primary types of competition. One is the traditional CDN. The second is those giant cloud platforms, and while some of them are still very good customers, some of them do have competitive CDN offerings. Of course, the do-it-yourself approach. We don't take any of the competition lightly, but at the same time, we have excellent competitive advantages in the market that allow us to win.

First one, it's better video quality, higher bit rates, providing HD 4K viewership so that experience are even better when you're viewing them online. We have seamless viewing, which is really lower rebuffering. You know when you're watching television, a movie, and it just pauses in that really terrible moment right before something great happens, and you've got to watch and wait for it to reload? Akamai's technology strives to create the lowest rebuffering in the industry. Next, lower latency for live video, and this is especially crucial for news or live sporting events, where even just a few seconds of delay can really ruin an experience. You know what it's like when you're watching a World Cup event on your iPad, and somebody in the next room watching on TV screams, "Goal," and you haven't gotten to the goal yet. It's a pretty depressing experience.

Akamai produces technology that drives that latency down. Faster game downloads, global reach, wherever you want to deliver those games or that video, we can reach it. Scale for unpredictable events. If you don't know how big your event's going to be and you know you want to be able to scale it large, you need a company like Akamai that can scale to whatever size you get to. Neutral. Whereas some giant cloud platforms may compete with a content provider in the market, Akamai's neutral place providing a service to those same customers provides a competitive advantage for us in the market. Lastly, it's services support, because at Akamai, we believe it's really the combination of people and technology together that really drives success for our customers.

We have 2,000 people located globally close to our customers to help them bring more and more content online and drive traffic. All right. That's why we win. Let me talk to you a little bit about a few of the wins that we've had. Let's start with gaming first. I talked about Fortnite just for a quick second before, this is really a true phenomenon, right? 125 million players worldwide, 40 million monthly plays, and a huge competitive takeaway for Akamai from a giant cloud platform that had this customer at first. The customer moved to Akamai, not just because of our scale and global reach, although that's really important when you have a game of this size and this magnitude and you need to get it to all the users who want to play it.

They also came to us because we drove a five times reduction in error rates, allowing those downloads to get better and more seamlessly to their customers. That's really what they need to have happen, right? They need all of those consumers to get the game so they can buy more of those in-app purchases. This is a big win in terms of seeing the growth in gaming, but also a big competitive takeaway from one of those three competitive types that I talked about in the previous slide. All right. Next, let me talk about Hotstar. Hotstar is one of our exclusive partners in India, and we had a great success with them during the IPL tournament this year. It's 45 days, 60 live matches, and over 38 billion minutes streamed.

Hotstar had one of the record-breaking totals for concurrent viewers at 10.39 million concurrent viewers. It's a record from a sporting event perspective. Amazingly enough, 97% of those viewers watched the event on a mobile device. The event also showcased something else that we see happening in the market, which is the events themselves are growing dramatically every year. In this case, it was four times larger than the IPL tournament in terms of online viewing than the year before. Akamai's ability to scale with an unpredictable event, even in a tough infrastructure like they have in India, really was showcased for the event. Another area for this was a new component that Hotstar launched during this game.

They launched a game that you could play side by side in the video where you could, in essence, bet on what was going to happen, the next play, the next run, whatever it might be. To do something like that when you're using online video, you need to have extremely low latency, because how bad would it be if I could watch on television and see what happened, what the next play was, and then be able to kind of bet in the game app before it ever showed up on my live video? It'd be a terrible experience. Hotstar and Akamai partnered together to drive that latency down low using our Media Services Live technology, and we produced an amazing engagement between the game and the live event online, leading to longer viewing time, driving ad revenue, and ultimately subscriber retention.

It was a great success for them, and I think you'll see them use that more in events going forward. The last thing was another unique thing we did with Hotstar during this event. We talked with them well before the event, and one of the ideas in a market like India, where there's hundreds of millions of users who can't necessarily, from an economic perspective, reach connectivity because they can't pay for data access. We created a proof of concept with Hotstar, and we deployed Akamai servers in train stations in India to allow users who might not necessarily want to pay for that data access to access over free Wi-Fi Hotstar's application and watch that video inside the train stations. It was a proof of concept.

It wasn't large yet, but what we wanted to see was with that barrier of consumption driving down, would that really drive up consumption? What we saw is that is the case. Inside the train stations, people were accessing over this free Wi-Fi to watch the games, pay for the application even, but they might not have done that if they had to pay for cellular data access. We'll be working in emerging markets like India to see if that technology really can drive the next 50 or 100 million users online, because markets like India have tremendous potential for traffic growth. Last win, I'd be remiss if I don't mention the World Cup, and Tom briefly touched on it in the beginning, but we've already seen traffic at the World Cup exceed for one single game, 15.5 terabits a second.

I imagine today, I think it's one of the later games today, and we're going to see traffic probably exceed that today. We service this for 55 broadcasters in over 100 countries, and 33 of those customers are using the technology I just talked about for the IPL, where we drive down latency and drive up quality, and that's our Media Services Live technology. Similarly with the IPL, we saw a four times increase in the event size from the year before. I have a kind of quote up here, which is by the 10th day of this event, we had already streamed the volume of traffic that we did for the Brazil World Cup just four years ago. A great example here of just tremendous growth in online viewership for this type of event. This also led to a couple of great competitive stories.

There's two specific ones that happened during the World Cup just so far in just the few days we've had with the World Cup. The first one involved one of the giant cloud platforms, it really accentuates how difficult and complicated it is to produce a live event like this in a globally distributed way. This particular customer was using a giant cloud platform to try to attempt to do this, it didn't work for them. That customer, mid-event, had to switch over from the giant cloud platform, move all of their content and live streams onto Akamai to continue to stream and produce that content and keep subscribers on their network.

The second good example was somebody in another competitive area, so I talked about the three areas, and this one was in the do it yourself area, who also thought before the event, "Great, it's really easy to do this. We're just going to do it ourself." Again, very complicated. People think it's easy, but it's not. They attempted to do it, and their platform didn't scale, didn't perform, didn't provide quality, and really toppled over. They also came to Akamai to come to the rescue, and we switched over their live streams onto the Akamai platform, now providing an amazing result for their customers.

The World Cup is a good example of not only the size of this type of event and what's happening online in terms of traffic, but it's also a good example from an Akamai perspective of why Akamai wins in the market against the competition. In terms of growth, a lot of people say that in the end, this market is really going to be ruled by two or three people in the end. I think the evidence is quite the contrary so far. We've seen new entrants, changing dynamics every day, new services being offered from Disney pulling their licensing agreement, from Netflix to launch their own OTT service next year, or Perform Group launching their DAZN service, which not only is going to be launched in EMEA but is launched globally.

Of course, what I just talked about with Hotstar, tremendous growth available in India. There's just so many opportunities for expansion and new services in the OTT market that we're going to see traffic continue to increase between video and, of course, gaming. To attack all those opportunities, you really have to have the best products and services available, and we feel we do. We have first along the top is our delivery platform, and central to there is our Adaptive Media Delivery, which really focuses on the video use case. It includes optimizations like looking ahead in a video and getting the next segment of content even before the playback device asks for it. We have our Download Delivery product, which specializes in use cases around gaming and software downloads.

It has specialized services such as whether the download's in foreground or background or even altering performance of the download based on the customer's needs. It may throttle the download. We have our MCDN and LCDN solutions, which really package up our Adaptive Media Delivery and Download Delivery products into nice little neat packages for our carrier partners to then deploy on their own networks. Again, we have the MCDN version, which is where we manage it for them, and we have our LCDN service, which is where they can deploy it themselves and manage it. Supporting our delivery products, we have our origin services. First, NetStorage, which is a globally distributed storage platform that includes sophisticated rules for replicating content for availability and performance.

I've talked a little bit about it, we have our Media Services Live product, which ingests live streams, and it enables unique features to drive that low latency down very low and ability for us to stream content at extremely high quality on a global basis. Like I said, at MSL, you can see it live today if you look at almost any of the World Cup distributors streaming the World Cup now. It's 33 of the 50 that we service. Cloud Wrapper is another important product we have. As our customers move some of their workflow to the cloud, it's important that we have a product that can help them support their workflows in that public cloud architecture, and I'm going to talk a little bit more about that in just a second. The final area is visibility and data.

It's really important as customers move their content to the cloud, that their end users get a TV-like experience. Visibility and data around what their end user is experiencing is critical and crucial to them, and it is today, and it will be as we go into the future. Media Analytics provides real-time data on what their viewers are seeing and experiencing, whether it's rebuffers, throughput. Our BOSS and Box service go even one step further and take the disparate components of their media workflow, provide a single integrated view so they can see what's happening online, and then we couple that with professionals that help manage, monitor, and support our customers as they bring more and more of that content online. I said I was going to go a tiny bit deeper into Cloud Wrapper.

Akamai's highly distributed network provides a significant advantage for a centralized platform, providing them performance, scale, reliability, of course, security. Our media customers, like I said, are building more complicated workflows, and they need to put some of those components of that workflow, they want to put it online in a public cloud. Last year, we launched our Cloud Wrapper solution that allows us to securely connect our customers with cloud storage or cloud compute. This year, we're launching another version of that product, which greatly enhances the amount of offload our customers get. That is important for two reasons. First, performance. We want to drive that offload down and get that content all the way to the edge next to the user so they get high quality.

The reason the customers are coming to us for this is because those public clouds charge significant egress fees to them. As the data leaves their platform, as it leaves that central area and going out to the edge, those clouds charge for that. Our customers want that charge down as low as possible. We're working closely with them to build a product that reduces that variable cost they have when they need the content to leave the central area of that diagram there and get out to the edge. That's critical for us, and it's an example of innovation that we're working on with our customers to help them have the flexibility to leverage whatever architecture they want while also leveraging the power, the scale, the performance, and the security of the Akamai platform.

At the beginning I said I was going to talk to you about the actions that we've taken and some of the results we've had. I've given you the high level overview of the division, the products we have, the customers we serve, some of the revenue diversification we have. Now I really want to talk to you about the action that we took starting last year. I'm going to cover it in three areas. First, how we optimized our go-to-market. Next, around our R&D optimization, the last one, Bobby touched on a lot of this, which is lowering cost while growing capacity. First, let me talk about the optimization on the go-to-market side. The first thing we did was take a look at our customer base and we enhanced the segmentation that we're doing.

You've heard Tom and Jim during earnings calls talk about our top 250 customers, that's really where we pivoted the entire division around saying, "That's the majority of our revenue." It's 70% of the revenue in the division. It's a large majority of the traffic. We're going to pivot around those customers because that's where the growth is. We refocused our marketing investment around an account-based marketing program that would go deep in those big customers. Many of them are very big. They have many buyers. We want to touch every one of the buyers with our marketing programs. We created creative and flexible contracts that are driven specifically with our customers to allow us to capture all the traffic share they might have available.

We used our new data-driven operations analysis to paint white space targets for our sales force to ensure that while we're in there capturing that share, that we capture everything else that they might have to offer, whether it's performance, security, or services and support. Lastly, we revamped our compensation model around our sales force to really focus them around the things I just touched on, so that they're focused on capturing share and attacking all of that white space, selling the breadth of the portfolio into their accounts. Focus on the R&D. We looked at our portfolio and we said, "Which products aren't really around the core?" The core is delivery. We exited peripheral products, focused on improving quality and visibility, and as I talked about, as our customers move their content online, visibility and quality is critical.

Folks want TV-like experience online. Some of them want better than that online. The quality and visibility capabilities we provide are crucial to our customers. We ensure that all the innovation that we're doing is, again, focused on the core, on delivery with products like Media Services Live, producing low latency, high bit rates, more engagement. Last, all the disruptive technology that we're innovating around is also geared around that core, delivery. Things like Cloud Wrapper that I just talked about with increased offload for public clouds. Peer Assisted Delivery, I think Tom mentioned that as well in his speech. Multicast, LTB, those disruptive technology, again, all geared towards the core, delivery. All right. Last, lowering cost while growing capacity, really scaling.

We knew that as we took some of these actions, we were going to bring a dramatic amount of traffic onto the network because we had faith in what we were going to execute on was going to lead to results. We did that. We doubled our capacity while lowering CapEx as a percentage of revenue. We increased our cash gross margin in the division, increased our free cash flow, all while still investing in developments around hardware and software optimizations that Bobby talked about so we could continue on the same trajectory into the future. All of these are great things, but they're really only great if they manifest themselves in, first, in traffic growth for us, but also in revenue growth, right? The question is, did it work? I guess I wouldn't be standing up here if it didn't work.

Let's take a look. The Cisco VNI report says that the internet's growing at around 24% year-over-year. You see we came in around Q2 of 2017 to take action. The orange line is total Akamai traffic, so that includes those six internet giants, and you see that line's slightly depressed. In Q2, the internet giants growth rate was depressing the line lower than the 24%. As we move forward in the future and we took actions, you see us bringing all that traffic back onto the Akamai platform, and you see the growth beginning to take off Q2 to Q3 all the way through Q1 of this year. Even when you normalize out those giants, you also see the same effect.

You see that Akamai always has been growing faster than the Cisco VNI report's 24%, but you see the growth happening right after we begin to take those actions heading into Q3, and again, kind of following out through the end of last year. Great actions with traffic growth and we're really happy to see that coming to fruition. Again, traffic growth is great, but it has to manifest itself in revenue growth. You heard from Tom and Jim in multiple earning calls that we thought that our actions would first manifest themselves in this growth, and then about 6-9 months later, we would see that come to fruition in revenue growth. Let's look at revenue growth, and we see just that, right?

In Q2, you kind of see us bottoming out in terms of revenue year-over-year growth down there at Q3 2017, you see following the traffic, that revenue beginning to accelerate up into the low single digits heading into Q1 2018. We were really happy to see that the actions that we took led to these specific results and helped the broader company in its growth rate in 2018. All right, Akamai's been delivering the world's biggest events, the most important events for about the last 20 years now. We've seen traffic continue to grow, and you kind of see that along the curve there, over the years. Whether it's expansion of OTT or the expansion of gaming, it's tremendous amount of growth.

You can see the peak traffic that we did this year at 64 terabits for the IPL where we had that 10 million concurrent viewers dwarfs what we saw in 2008 with the elections at one terabit. Even just four years ago, I think it's up there, yep, the FIFA World Cup from Brazil, seven terabits, right? We had an event the other day at 15 terabits. You just see this tremendous growth, which is leading to tremendous opportunity for us as we lead into the future, and this market is exploding. Whether it's online video or online gaming. Okay. To wrap up, we're really focused on delivering that unmatched quality, reliability, and scale, because that's what leads to our customer success. If our customers are successful, we're going to be successful. We're going to focus on our sales productivity.

We're going to maximize traffic share, because as we've mentioned a few times today, traffic growth is what drives divisional growth. We're going to continue optimizing our cost, whether it's around how we deploy our network, build our products, or manage our sales force. Of course, we're going to continue on our path of driving operational excellence within every facet of the division through a data-driven approach that we believe is the foundation of the success that I've just shown and the foundation of the success we're going to show into the future. With that, I want to thank you, and I want to invite up my partner, friend, our President and GM of the Web Division, Rick McConnell.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Thank you. Thanks, Adam. Good morning, and welcome. It is my pleasure to be with you today to talk to you about our Web Division, give you an update on our overall business. Let me begin, as Adam did, with the notion of the customers that we sell to, in particular, we target all those segments and verticals that are not covered by the Media and Carrier Division. Adam covers our media customers, large media customers, the giants, our publishing companies, gaming and so forth. We tend to cover other segments. For example, our key verticals, as you can see here, around commerce, financial services, travel, hoteling, public sector, so on. We also cover a myriad of other industries such as automotive, business services, and so on. Adam's business is primarily driven by traffic, as he talked through it.

Our business is primarily driven by bookings. We actually get commitments from our customers around the amount of money that they will spend on our services, typically around performance and security on a monthly basis. In terms of the largest of the customers, because we tend to focus on those customers that really care a lot about their overall internet strategy. As you can see, we've had very strong penetration into the top end of the pyramid here for this customer base. So all 20, for example, of the top global e-commerce customers, more than 90 of the top 100 commerce ones in the U.S. Vast majority of the world's financial institutions, largest financial institutions, more than, 14 out of 15 cabinet-level agencies of the U.S. government, all branches of the U.S. military, and the top global airlines and hotels.

In fact, more than about 85% or so of our revenue in the Web Division is driven by the performance and security products that we create and develop within the organization. One other aspect that I'd share with you is we are at approximately 300 customers now, 300 out of the Web Division that are spending more than $1 million per month with us. Some well more than that. Approximately 300 a million-dollar-a-month customers. That continues to grow and continues to demonstrate our penetration into very large customer internet strategies. Having said that, we are far from fully penetrated. We see that we've got a lot of white space and a lot of opportunity here to really go continue to drive ongoing growth out of these segments. The mix of our business is also shifting in a couple of ways.

For example, we see very strong growth in financial services as well as travel. Tom talked earlier about things like Bot Manager, security, and these kinds of solutions that are in fact driving substantial growth. By contrast, commerce, which is under some amount of pressure from Amazon, is still growing quite nicely for us, but growing less rapidly than, say, financial services. The result of that is our mix of revenue in the Web Division is shifting slightly towards some of these verticals that are growing more rapidly. In terms of geo revenue mix, our international business continues to grow quite nicely, greater than 20% for both EMEA and APJ. The result of that is that the international mix of our business continues to grow as well.

As you can see, we're now at about 35% overall of Web Division coming from international sources in terms of revenue. Let me switch gears. What I want to do is spend a good portion of time talking about the growth drivers of our overall business in the Web Division. This is really key to understand the investments that we're making really across the board in driving ongoing growth of this business. I'll cover the six that you see there. Let me start with security. Tom talked about it earlier, but this security business seven years ago was low single digits of millions of dollars of revenue. Today, this business for Akamai is greater than a $600 million run rate.

It has enabled us to become the leading cloud provider for DDoS and web application firewall solutions. It has enabled us to grow this security business within the Web Division by more than 30% in 2017, and it now comprises more than 30% of our Web Division revenue. One other point of note, though, is that only 46% of our customers in the Web Division actually spend money with us on security. Why is that important? Well, it is simply that there is still a lot of white space left to go, even just in our installed base, before we even get to the notion of new customer expansion. Our churn rate also is very low overall across our business.

It's quite rare that we lose any measurable amount of revenue to competitors, which is something that we don't take for granted for even a moment, but we like to see. Turns out that for customers who have a security and performance product, that churn is 40% lower than it is across the Web Division overall. When we have multiple products being deployed, we do even better than we do on our standard basis with respect to churn. The other point is simply that security represents now about two-thirds of our overall bookings. Remember that I talked about the revenue of the business overall in web being driven primarily by bookings. Those bookings increasingly are driven by security. Let me go to the second growth driver, which we see as pricing and packaging.

One of the core themes of this session as I go through it, and you'll see as we get to the technology showcase that Craig's going to come up and do for us in a moment here, is the breadth of our portfolio. The breadth of our portfolio has never been more extensive, and it is adding true significant and extensible value to our customers as a result. It is this sort of multi-product edge that gives us great value in some of these solutions, whether they're Image Manager or Bot Manager. I'm going to say more about new products in just a moment, but putting these solutions together into a consumable form for our customers really adds significant value. One of the things we've done is we have put together a bundle that enables our customers to more simply buy performance and security from us.

They don't have to just buy a performance product. They start with performance, and later they evaluate security. Instead, we're simplifying the onboarding action, where they could pick a security product and then pick a performance product, deploy them in one line item, and purchase them as a bundle. This makes it easier for our customers to deploy Akamai. A second example of what we're doing in pricing and packaging is more at the high end of the pyramid, if you will, around Enterprise License Agreements. Our largest customers want it to be easier to deploy the entire Akamai platform, the entire Akamai portfolio and Web. What we have done is we've facilitated these Enterprise License Agreements so that a customer can get access to the entire Akamai portfolio for as many properties as they want, as many websites, as many mobile applications, mobile sites, and so on.

This simplifies their utilization and gives them more capability to figure out when and how they're going to use the Akamai platform for their purposes. These ELAs importantly often result in what can be tens of millions of dollars of revenue to Akamai and to the web division over the course of, say, a 3-year contract span. The third growth driver I wanted to talk about, which I alluded to, is around new products. This has been a tour de force, if you will, of the expansion of our portfolio, which has really been led by Ash Kulkarni, who runs our products organization for web. He's done a terrific job along with his team in really bringing the breadth of our portfolio to bear to provide more value to our customers.

In fact, these products include many of the ones that Tom talked about earlier, Image Manager, Bot Manager, our API Gateway, Web Application Protector, our mPulse solution, CloudTest. Quite an extensive expansion of our products over time. What we see with these new products is that in 2016, we delivered just $10 million of revenue from these sources. We are now just in the web division alone at greater than a $100 million run rate out of these products less than a couple of years later. The result of this new product expansion in the portfolio and the execution of that portfolio expansion has resulted in true and substantial growth for the web business. One aspect that is also, I think, notable is that despite the substantial growth in new products, for example, Image Manager and Bot Manager both have fewer than 300 customers each.

Against our entire portfolio of customers in the web division, we still have a lot of opportunity still with these products to penetrate additional customers with these solutions that are generating such revenue growth for us. In fact, it's generating out of these new products about 50% of the web division bookings. Let me go on to the fourth growth driver, and that's around mobile apps. Not surprisingly, you may find yourself on your smartphone through the course of today and really every day sitting on a mobile app or spending more time on a mobile app, whether it's checking into your airline flight or buying something online or whatever it might be.

The interesting aspect of the mobile app is that the constraints around mobile apps in terms of performance can be different, in fact, are largely different than the constraints we see of downloading a website to a laptop over a Wi-Fi connection. What are those constraints? The constraints often instead of occurring in the core of the internet will occur in the last mile from the tower to your mobile device. The creators of these mobile apps can often be different groups within organizations than the website, and the buyer for our technology can often even be a different buyer. The technologies that we use to accelerate mobile apps are different as well. We leverage a lot of the same componentry. We leverage all the same platform, but there are incremental components we can provide to accelerate and manage mobile applications.

They also use substantial use of APIs. Tom Leighton alluded to it earlier, these mobile applications utilize APIs to call back to an origin server, for example, to download content. We can accelerate and also protect those APIs. We have delivered a series of technologies, for example, a mobile SDK, to provide an application developer to pre-position content. That can make it faster coming down from the tower to the device to have it already on the device when that application calls for it. We have provided an API Gateway. This allows for the pushing of the API management to the edge of the Akamai platform. By pushing it to the edge, we are reducing the number of calls required to the origin server infrastructure of the customer. We can allow for the facilitation of delivery of that content more rapidly.

The Bot Manager SDK is something that Tom Leighton showed you all earlier, which is this notion of the neuromuscular movements of your phone or of a mouse click or keyboard presses, so that we can assess more readily whether or not it is a bot or a human, especially with regard to these mobile devices. Finally, Kona Site Defender enables us to then protect those APIs just as we protect content. We see the mobile space has a significant opportunity for ongoing growth as we capture more and more of the mobile application traffic. The fifth growth driver is around new customers. We have invested quite significantly over the last 6 months in our new customer game plan and our new customer acceleration. In fact, I've put up here some of the areas in which we're investing.

We've invested in more than 25 global sales development reps, we're continuing to add more. These sales development reps are targeted at lead generation and lead qualification, they will evaluate leads coming in, accelerate them through the process toward opportunities, then manage them onto the sales group as a whole. We have added more field hunters to go after the larger segment of customers and had inside sales reps to go after the, say, mid-market range of customers. We've added another 25-plus inside sales reps around the globe. We have increased our digital marketing spend as well to increase that lead flow, we have provided better integration and work and rebates with our channel partners to also provide incremental lead flow where we're only accelerating those rebates in the case where channel partners bring us new customers.

The result of all this is that we've actually already seen over the last 6 months' time an increase of about 20% in the number of new customers we're closing year-over-year. I actually think we can do a lot better in this area, we are not stopping here. We want to accelerate the number of new customers being onboarded, we want to do it through some of these investments that we're driving here. We're going to continue to make these investments as we go. Finally is the area of emerging areas overall. Tom Leighton talked about each of these in terms of zero trust, IoT, and blockchain. The way that I see it, zero trust enables us to address a strong market in Web Division customers for enterprise security.

Essentially doing for employees what we have been doing over time for our customers' outbound content and traffic by providing that layer of protection and access that really enables us to embrace the zero trust capabilities. There's very strong demand for this, early demand, I would say, out of our web division customers. In the area of IoT, we are already providing capabilities around over-the-air traffic to automotive. Our EdgeConnect product now enables this bi-directional traffic flow. This will be coming out of beta into production in the balance of this year, that's going to enable us to provide this ongoing communication with devices and providing that content back to manufacturers that they can then utilize to assess how that device is performing or any number of other things that they may learn from the information coming out of that device.

Then blockchain, of course, we believe represents a material opportunity for us as well, initially in the area of payment processing. One can imagine many utilizations for blockchain technology as we look forward. We've only just begun. These areas overall represent a substantial opportunity for future growth. What you can imagine is that we've got the core of the portfolio with solutions in performance like Ion, with solutions in security such as Kona Site Defender. We've added to that an array of new products that are rapidly growing, such as Image Manager and Bot Manager and mPulse. Then to that, we are now extending into the future with yet additional opportunities that we believe all represent substantial market capabilities in the areas of zero trust, IoT, and blockchain. Overall, the six growth drivers, again, just to summarize quickly.

Strong growth in security that we continue to invest in and drive. Pricing and packaging to facilitate the onboarding of existing as well as new customers with performance and security and additional solutions, including ELAs as well at the high end. The notion of new products driving a substantial growth opportunity. Mobile as a new targeted and addressable market where we still believe there's a lot of opportunity for expansion. New customers where we're accelerating our investment in new customer acquisition. In emerging areas as we look to the future for zero trust, IoT and blockchain. I wanted to transition to products. Before I do that, as you might imagine, many of those growth drivers included this notion of go-to-market. What are we doing in go-to-market? I wanted to introduce to you our newest executive, Scott Lovett, who I worked with for seven years at Cisco.

I've seen his ability to contribute in the go-to-market area firsthand. Scott came most recently from McAfee, where he was EVP of Global Sales, then before that, from Cisco, where he was responsible for global security sales. The result of this is that we've got a new executive added to our team with tremendous potential in terms of execution of our go-to-market strategy, but also with great security background. Scott's up front, Scott, may I ask you to stand up and just wave to people? Nicely done. Good. We practiced that, just so you know. Scott is just fabulous to have on board, and I wanted to introduce him to you as our newest executive, at the breaks, you might be able to say hello. Welcome, Scott.

I'm going to go into the product section, as Adam did, to talk a little bit about our portfolio so that you understand it, and then I'm going to have Craig Adams come up, who is our head of Web Performance Product Management, to give you a technology showcase to really try to drive this home, because the core theme, being the breadth of the portfolio, is really invaluable in our overall story here. To start, we look at it across really three dimensions, this notion of performance management, application optimization, and edge computing. In the three boxes that are shaded in white, this is really, if you will, the core, the flagship area of the portfolio where we'd love every customer to have these products deployed.

Namely, in the case of Ion for application optimization and website optimization, as well as Image Manager to reduce the overall payload of images being delivered out of any one customer's origin. I'll talk more about Image Manager in a moment. mPulse provides the analytical framework, I'll talk about that as well. To that, we've got a number of other capabilities. For example, CloudTest that allows for substantial testing at scale. For example, before e-commerce selling season in November, December, you want to test your origin at scale to see the impact of load on your overall infrastructure and applications. CloudTest enables that.

CloudTest is also used in many of the media cases that Adam would have talked about to test large video load, for example, as well, and what happens on the internet when you're going to have a lot of traffic coming to your site to initiate that video stream. Cloudlets or container services are in edge computing. What this does is essentially enables tuning of websites and performance capabilities at the edge. For example, one of our Cloudlets is visitor prioritization. What visitor prioritization does is it enables our customers to tune for certain kinds of customers faster response times in the case of large load. Many different Cloudlets that we provide to allow for customization of the environment that we're allowing our customers to deliver.

One other point that I wanted to make is that DevOps, as you might imagine, is becoming more and more critical every single day. DevOps is essentially this notion of programmatically engaging with or managing the Akamai platform by our customers. It's sort of a strong desire for our customers to use our portal less and less. Not because they don't like the portal so much as they want to do it in an automated fashion. They want to integrate Akamai into their workflow, their workflow of creation of websites, creation of mobile applications, adjusting and updating content for those applications, delivering a global purge, for example, of all of their content on the Akamai platform in under 5 seconds so that then that content can be repopulated with the new content that's coming out of their infrastructure as quickly as possible.

The creation of a new configuration or a new property, a new website, all done automatically by integrating with us through a DevOps framework. We actually did a DevOps tour recently. It was 25 cities. It was far oversubscribed around the globe, and more than 2,000 people, developers at our customers, attended this DevOps world tour, which was just fantastic from our point of view because it really expressed very strong desire, demand, and engagement for interacting with and engaging in our platform in this way. Let me next talk about Image Manager, just a little bit more detail as a setup to Craig here. Image Manager essentially is a solution that instead of having customers process all their images in the core, allows us to move that image processing or really rather allows them to move the image processing to the edge of Akamai.

Why would they want to do this? Turns out that we would want to distribute images of varying sizes, resolution, different crops perhaps, down to a mobile device based on the network characteristics, based upon the device itself. Is it an iOS device? Is it an Android device? Is it a website? Is it over Wi-Fi? Is it over a cabled connection, and so on. The result of this is that instead of having to manage tens of variants, maybe even more than 100 variants of an image in an origin infrastructure, and for an end user to come to the edge of our network only not to find the correct image at the edge of the network so that we have to go to origin to pull that correct image. Instead, we can do all that management and manipulation at the edge.

The result of this is substantial performance increase through the reduction of the image carry or payload from the origin to us, and then optimization of the image size down to the end user. As you can see here, it results oftentimes in 10X improvement in the download time for images. What's even more interesting is that we're about to add video to that as well. This would be video snippets, so very short clips, but the ability to manage and push those video clips to the edge as well. Image & Video Manager is really important extension of our Ion framework. mPulse is a solution that we bought in an acquisition of SOASTA about a year ago, and it is a very, very valuable platform for analytics.

What it does is it basically provides linkage from the performance characteristics of a website or mobile application back to the business analytics or business ramifications. For example, and Tom showed some of this earlier, we're going to show you a little bit more of this in a moment, this notion that a second improvement in website download or delivery can result in increases in conversion rate and from there increases in overall revenue. It is that combination of evaluating using non-sampled data. Unsampled data globally of specifically what's happening by region, by device, by network condition, by download and page load time, what is happening to your business. By being able to isolate that, you can get great value out of that. Let me move on to security with a similar sort of story.

In this area, you see the three categories as well, enterprise security, DDoS mitigation, and application security. In this case, you see that the white boxes here are oriented around, again, the flagship products that we would love to see deployed at a vast majority of customers. Kona Site Defender is really our flagship solution that covers all three of these areas. It improves enterprise security by protecting those applications in the cloud. It improves or delivers DDoS mitigation by addressing those terabit-per-second-plus attacks that are occurring, whether in the network layer or in layer 7 at the application layer. Of course, application security by allowing Akamai to do TLS or SSL termination, we actually can inspect traffic coming to our customers and process it accordingly to assess whether or not that is valid or hostile traffic.

Web Application Protector is a solution that we've come up with as a simpler form of Kona Site Defender targeted to mid-market, deployable more rapidly, not all the features and functionality, but very well tuned to the mid-market. The API Gateway, which is something I'll talk more about, allows for management and authentication of APIs at the edge. Bot Manager, which we've already said a lot about, to protect and manage overall bot solutions. Prolexic, which essentially uses BGP as a protocol to provide routing into the Prolexic scrubbing centers to manage data center traffic. One of the aspects of Prolexic, which is given the size of the attacks, we just in fact over the last quarter have doubled the overall capacity and number of locations of our Prolexic framework and platform globally. This has essentially enabled us to take on larger attacks.

In the area of the enterprise security, as I mentioned earlier, Enterprise Application Access, just providing controlled access for only those authenticated to a particular application and Enterprise Threat Protector that uses recursive DNS to evaluate whether or not we should allow an end user to go to a particular website. Both of those components essentially fit within the zero trust architecture that we talked about before. Bot Manager Premier is something that Tom talked about earlier, but I cannot stress enough the value to customers that we've seen so far out of the delivery of Bot Manager Premier for fraud prevention. It allows these customers to assess whether or not logins are valid or invalid based upon whether or not it is bot or human traffic, and whether or not we perceive, based upon the technology that we've created, this to be malicious traffic or valid traffic.

By using that, we can assess these behavioral anomalies in order to provide significant reduction in overall fraud and really to enable this credential abuse, credential stuffing problem to be largely mitigated by our customers. We've seen it, as Tom mentioned, in airlines. We've seen it in retail by being able to do a better job of managing inventory flows of new inventory or special releases out to customers. We've seen it in large financial services in institutions where we've substantially reduced fraud of credential abuse from invalid logins. We've added the Bot Manager SDK now to do an even better job of assessing mobile devices.

This is really a key area of investment, fastest-growing product that we've released in some time, as I said earlier, really still a very limited penetration in the scope of a few hundred customers and yet driving a substantial amount of revenue growth for us in the web division. The API Gateway. I talked a lot about mobile earlier. This notion of an API Gateway and APIs needing to be authenticated at the edge is really essential in a mobile app world. What we've done is we allow for API calls to occur on the edge of the Akamai platform. By doing so, we manage and mitigate and evaluate the authentication of those APIs at the edge.

We can provide quota management capabilities to assess how many of those APIs can be made and whether or not, based upon those quotas, we think that that API traffic is valid or not. This API Gateway is a new solution. We just launched it this quarter, at the beginning of this quarter. We've already seen a good interest. We had a strong beta program for it, and we're optimistic going forward. With that, what I wanted to do next was transition to a bit of a technology showcase because I've covered a lot of ground with a lot of products. We've got Image Manager and Bot Manager, API Gateway, mPulse, and so forth.

What we thought we would do is show it to you live and to give you a sense of sort of the day in the life of several customers as we might look at how and why they would deploy the solutions. To help me do that, I'm going to bring Craig Adams up to the stage, who is our Vice President of Web Performance Products. Craig, take it away.

Craig Adams
VP of Web Performance Products, Akamai Technologies

Hey, thanks, Rick.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Thanks very much.

Craig Adams
VP of Web Performance Products, Akamai Technologies

All right. The session we're going to walk through is really two parts. The first part, which I hope you take away, is how we're going to market with our customers. You've already heard a lot about each individual product and capability. This is how does it sync together so that when we're not talking about point solutions, we're genuinely listening to the business opportunity our customer has and presenting back a platform in aggregate. This platform approach, to be very clear, is one of our strategic differentiators. It's how we have such a high rate of both retaining our existing customer base as well as growing it. The second, though, we've talked a lot about the products, but I want to show you the customer's view of them. With that, let me dive in and first tee up what you're going to see in the demonstration today.

There's over seven different products. Rick did a fantastic job of talking about each of these. Let me do it quickly. mPulse gives our customers insight and particularly breaks down data silos in their organizations. Ion does all of the caching. It does pretty sophisticated things like pushing things to an end user before they notice it. The mobile app SDK, really important. This is where we give software to app developers that they're able to integrate into their native apps, and we're able to do unique things by actually having a presence on the device itself. You've now got Image Manager, which from a customer's view, they're focused on their brand and audience engagement. That's frankly images and video. How do they manage that while still having a fast, reliable site? Talk about APIs. It's powering, frankly, every modern app, much of the modern web.

How do you do the things you need to do with APIs, which is authenticating them at the edge, increasing origin scale and performance? The threat landscape and Kona, it's been talked much about. You got to protect those APIs, too. We also do that. Finally, of course, Bot Manager. Now, for the demo, we use the case of a mobile application because there's so much innovation of our customers happening inside of mobile, and frankly, it represents a great opportunity for us to expand inside further. With that, let me pull up the first part of the demonstration onto the screen behind me. This is one of our customers, a EMEA-based global telecommunications customer. Let me first describe what you're seeing in front. On the top, you can see the key metrics I care about as a native app owner.

I care about the number of installs. It's one of the key metrics everyone focuses on, is they're trying to guide their customer base into the most sticky way of communicating. Of course, I need to be able to see my error rate over time. I see performance, and performance is different in a native app world than it is in a web world. In a website, you have this notion of an HTML page. It downloads objects. That's your page speed time. In the app world, there's no page. You originally have typically a JSON call for an object and then a bunch of embedded things inside of it. That's the difference between request time, which is the first request that you see, and the screen load time, which is how long does it take my screen to paint, what our customers really care about.

We provide all of that insight. One other significant difference in the app world is that compared to a modern website, I have different versions of my app in the wild at any time. In my website, even if I'm personalizing my content to each end user, it's the same software stack. In an app world, it's radically different. I produce new versions of my app for different platforms, but it's up to you, the consumer, of when you actually download my latest version. I need to have performance and app insight across all of my individual applications. In this example, we can see the app versions that start with a 3 represent this customer's Akamized versions of their app. The app versions that start with a 2, the bottom 3, represent the non-Akamized version.

Each time I'm creating a new software update, I have the ability to see what's happening with the application I've just released in real time basis. In addition to seeing what's happened when I've released, I always want to compare different app versions against each other. In this case, I pulled up a chart where the green bar that you see here represents the Akamized versions. The red bar represents the non-Akamized versions. 2 things you'll obviously notice. The first is it's faster. We kind of expect that. The second is it's less peaky. Let me talk a little bit why this is happening in the background. The first thing, of course, is we're caching and accelerating with Ion.

All of the things, I'm preventing it from going to an origin through the congestion points that Bobby articulated, offloading at the edge, and if it's dynamic content, I'm routing around content congestion. The mobile app SDK, which we talked about earlier, having software on the device allows us to have device-specific information for optimizations. Just to give 2 snapshots into it, allows us to do a lot of things on protocols. If we can tell that a device has a slow connection, we can change our protocol, or vice versa, it's coming in the fast connection. It also helps us merge the different caches that exist on a device, decreasing the number of requests that go back to the end user. All this, by the way, differentiated to Akamai, unique to what we have on the platform.

As an app owner, I can see that this is better, I have lots of tensions in my organization between new functionality I want to release, I need to try to quantify this in some way. Let me go to one of the other things that mPulse does, which helps break down data silos in an organization, and this is really important. No customer is lacking data. They have tons of data. The challenge they have is their data doesn't speak to each other. Typically, there's data silos that exist. I have my business data in one system, I have my technical data in another, and good luck if you're trying to connect the two. This is one of the unique things that mPulse does, is it allows me to see my business and technical data intertwined.

Let me describe what you're seeing on the screen first. At the top, I can see my conversion data on the app, my revenue over a time period, and I see my performance data. The middle is where we start to see the intersection of data that I typically wouldn't have. Across the bar, I see the load time of the application itself, so how it's performing. How tall the bar is represents the number of users in that session. I can see the majority of my users are kind of between this one and a half to seven-second blob. I can also see, though, the green line represents my conversion rate. If I go up to two seconds, I can see that my conversion rate is somewhere around 6%. I can see at seven seconds, my conversion rate is roughly 1.5%.

Key point is this is not model data. This is actually my end users and how they're behaving on my site. Akamai is giving me the ability to connect my data in ways I haven't before. Of course, let me go back to the example earlier where I take session load time. One of the other things it allows you to do is essentially show that what happens if you increase performance by a certain amount. In this case, I tried to model it roughly the second performance delta we had. In this case, it means an incremental $30 million a month from mining data.

Through mPulse, we're able to help our customers break down the data silos that exist for the app owner, help them track the different versions of their app happening in real time, and also quantify the impact that performance is having on their business. Let me transition to another example of an app. This is a case where Hilton contacted us regarding performance of a new version of their iOS app. Excuse me, all is a bold statement. The majority of hotel applications out there have pictures in them because if it's a new hotel to you typically want to see it and interact with it in a certain way. As Hilton was introducing a new version of their app, they were noticing iOS version, they were noticing performance being really slow.

Through mPulse, we were able to tell that the primary opportunity was the size of the images downloading. Even though we're caching at the edge, there's still just big things that we're trying to send down the pipe. This is where Image Manager comes in. Rick described how Image Manager works. Let me show you the result for Hilton. First, you can see the original object size was 245k, 246. The whole image you see here is the original image, so this is not impacted by Image Manager in any way. You probably already skipped ahead and noticed that we reduced the number of bits going down by 76%. Pretty significant. This is just one of the images on the screen.

The key thing that's unique to what Akamai does is we're able to reduce the size of the image without it being noticeable to the human eye on a device. Anyone can do dumb compression, but that has an impact to brand. As I scroll across, even on this giant screen, you'll see that the Akamized image through Image Manager will replace the origin. As I drag it across, you're not going to see any difference of image quality anywhere here on the screen, but I've significantly reduced the number of bytes going down to that end user. This impact, to be able to reduce bytes going down, has a dramatic impact over cellular connections. It all happens automatically. There's no complex configuration that you need to do. You turn it on, it gets delivered. Let me pause.

I'm going quickly for time, but as an app owner, I was able to get insight to break down my data silos. I'm able to cache and accelerate with Ion. I have software on the device that gives me incremental protocol and cache optimizations. I have Image Manager, which is automatically adapting my images. Apps are all based on APIs, much like most of the modern web is today. In order to effectively handle APIs, you have to speak APIs. For those that aren't familiar, there's different languages associated with APIs. Customers literally name them. They have different accesses that they give to different people. I may have a public API I give to the world. I may have a private API that I only give to these individuals, and these individuals may have five API hits, that ability to authenticate them at the edge.

Let's go to the type of functionality we enable our customers around APIs. First, you have to have a good, easy way to define your APIs. Of course, as Rick said with our focus on DevOps, you can automatically import things if you wished. Showing you an API call will, I assure you, would be even less interesting than this screen. You have the ability to also go through and configure it directly, and you can see in this individual API, I've configured it that, hey, I'm going to allow get request, I'm going to allow post request, but I'm not allowing these other types of methods to the API call. Immediately, when Akamai sees something, for example, a put request on this API, we know that that's not valid traffic, and we're able to offload and handle that at the edge.

In addition to, of course, handling it at the edge, I now can determine which of my end users can access this particular content. One of the common choke points of API infrastructures is this authentication to ensure that this person can access it. This is unique functionality we have at Akamai and helps our mobile app and our web customers significantly. Once I've defined the API, you've got to be able to protect it as well, and this is where our Kona comes in. What I'm now showing you on the screen is an example of one of my individual APIs that I have enabled and how easy it is to turn on some of my configurations. In this case, I've checkmarked application layer controls. This helps prevent against malicious payload like SQL injection.

I've also turned on network layer, which enables IP and geo-blocking from OFAC countries as an example. Rate controls, in case someone's trying to send too many requests to my site. You can also see, though, that I chose not to put on slow post protection, intentionally unselected to show you the flexibility that customers can turn on. Behind this, once I turn it on, you have the Kona rule engine automatically learning what's happening across our platform and constantly updating the policies that exist. You have the ability to have an easy-on experience, or of course, you can more tailor the rules that you have. Let me give just another customer example, this time a customer from New Zealand, and it was just over a one-week time period, in the month of June.

Their first reaction when they saw this is, "I can't believe the number of different attacks over a one-week time period that you're protecting me against." Kona is able to not only protect against the attacks, enable the configuration flexibility our customers need. Frankly, it also shows you what's happening, which is why Rick mentioned earlier when our customers buy plural products, they're so much stickier, and also why we're focusing so much on go-to-market simplification to enable that multiple go-to product sale. One other unique thing to Akamai is you can see, for example, that, yes, I've configured rules. Akamai is also going to alert me if we see what we call a traffic anomaly, which is something that occurs that's outside of the rules that you've configured. In this case, the customer has turned it on alert mode for many of those rules.

We not only protect at the edge, but we're giving information to their security teams of things that they should research further as an opportunity for them to continue to tune and optimize their firewall. Following Tom, I'm no fool that I can't beat Tom on a Bot Manager demo. What I'm actually going to do, though, is show another customer example of how bots had a real-world impact on their site and how Akamai was able to help. What you're seeing on the screen behind me is an example from a customer in the travel industry, that you can see there was an individual bot. You can see a particular country that it's coming from. Essentially, Bot Manager was able to protect against all of these specific type of reservation attempts that it had.

What it also did, though, is it gave the customer unique insight of which credentials had been compromised. Not only did Bot Manager prevent against the credential abuse, it actually alerted me as a customer that I need to go reset these credentials. In the case of this customer, that was over 200 credentials for their customers that they had an opportunity to notify. In addition to fraud protection, we're helping the customers have bigger insight for their applications, making them more secure in aggregate. We went through all seven of these really quickly. While the example was focused on a mobile app, every single thing we went through is just as applicable to mobile web. All the technologies also apply.

If I'm an app owner at a customer and I want each of these pieces of functionality, there's nothing here as an app owner I don't want. I would have to piece together different vendors to try to apply, and even then they wouldn't connect and I wouldn't have half of the differentiating functionality we have. This aggregate portfolio approach to go to market is why we're so excited about our ability to both retain as well as grow and capture the white space in our customers. With that, let me turn it over back to Rick.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

All right. Thank you. Thanks, Craig. When I first told Craig I'd like him to demo the entire portfolio that we have of new products, I think he had a big gulp, but nicely done. Thanks very much. Hopefully you get a sense from that showcase just how important the breadth of this portfolio really is to our customers. It's no longer just about simple performance or delivery. It really is about image management and bot management, API management, and so forth. It has become really, really essential as we look into the value that we're delivering to our customers. I'm almost done. Just a couple of slides to go, I did want to talk about the competitive landscape first and then the market size, and then we'll wrap up. The competitive landscape is one in which we love to compete.

I love to compete personally, whether it's on a bicycle or in a running race or whatever, we compete. We compete ethically, we compete hard. We compete to win. We like to make sure that we are continually developing the solutions that meet our customers' needs, that delight them about using our portfolio and engaging with us. In the web performance area, we see various different competitors. For example, cloud service providers. We see web performance startups and traditional CDNs. The way that we compete against all of them essentially is through global reliability, scale, and performance. Reliability, scale, performance just are themes, whether it's on the web security side or web performance side, that are just really, really essential to our mechanisms and ability to compete effectively over time against all categories here.

You might imagine that cloud service providers, for example, have very rudimentary offerings. We also provide a much broader array of portfolio there as well we do with web performance startups that are primarily focused on delivery or performance acceleration. To whom we can sell security, Image Manager, Bot Manager, other capabilities that solve these problems and needs of our customers well beyond just simple performance. It is really the breadth of this portfolio, plus the size, girth, capabilities of our platform that provide the differentiation needed for us to win. The other aspect I touched upon earlier was DevOps. DevOps really is becoming a crucial mechanism for us to integrate, for us to interoperate with the overall workflow application infrastructures of our customers. That has also provided some differentiation relative to many of these different competitors.

Now, in the area of web security, we add to that this notion of massive scale delivering data that is invaluable in threat protection. Not only do we have the global reliability, the scale, the ability to handle zero-day attacks, but we also have been able, through these sort of 2 trillion-3 trillion transactions that occur on our network every single day, couple billion per minute, that is an enormous wealth of big data. That big data then goes into our algorithms and our threat research to analyze where these attacks are coming from. By being able to do that, we believe that we do better than anybody in our industry at handling these so-called zero-day attacks, basically protecting even the first customer that would get attacked.

In the event that we haven't seen a particular attack before, or we haven't calculated it through our network, our security operation centers that we have around the globe will then be able to rapidly see an attack, propagate a rule set to our entire platform, then to protect all of the other customers. The benefit is that one customer's attack can become the rest of our customers' protection. This wealth of data and threat protection and analytics becomes invaluable in constructing the best security platform that we can provide for our customers. This, of course, we're very proud of the Forrester Web Application Firewall Wave report that just came out, that Tom talked about earlier, as we believe that really is representative of what we've been investing in these past seven or so years in security to compete effectively.

When you put together the notion of performance and security, we think that we have a collective competitive platform to win. The other aspect of the overall market is that as we look at the buildup, it really comes from all three components, performance, security, and these emerging areas. They really all build into the notion of what we believe and perceive as a billions of dollar market opportunity for us yet to come. That we've expanded this both organically as well as through acquisition as we've looked at it. The result of this addressable market is that we expect to be able to continue to grow our Web Division in the low double digits to mid-teens growth rates as we look to the future. Let me wrap up then.

It is really about. Hopefully one theme that will stick with you coming out of this Web division session is that the breadth of the portfolio matters. Matters to our customers by delivering substantial value to them, and of course, matters to us by being able to be a fuel to revenue growth, as well as increased switching barriers against those customers potentially leaving the platform later on. It's really that customer value that we seek. The second component is really around the go-to-market and the go-to-market strategies. Great to have Scott on board, as well, the notion that this go-to-market strategy must be consistent with that portfolio.

Whether it is to new customers or existing customers, we want to take this portfolio and make sure that we get it deployed broadly for our customers, and we're making the go-to-market investments in expansion, both of new customers, as well in deployment to the installed base of this portfolio to make that happen. The market trends that I talked about are really the market trends that are fueling those six key growth drivers we talked about earlier, which really are the sources of growth for our Web division broadly. Finally, we really are quite dedicated and focused to operational excellence. It is this notion that our operational focus will enable us to continue to grow this business in the future and to build more and more value for our customers that really fuels us on an ongoing and daily basis.

With that, Tom, I think we're going to go to break. I want to thank you very much. That's our Web Division, and we'll be back after the break with Jim. Thanks so much.

Tom Barth
Head of Investor Relations, Akamai Technologies

Thank you, Rick. We'll take a five-minute quick bio break, we'll be right back for the financial overview. Thank you. We'll come back, we'll make a quick announcement. Okay? Five minutes.

Operator

Please take your seats. The program will begin momentarily. Please welcome Akamai's Chief Financial Officer, James Benson.

James Benson
CFO, Akamai Technologies

Well, good morning. Actually, good afternoon, I think for some of the folks that are on the webcast. Quite a few folks in the room, quite a few folks on the webcast. I really want to thank you for coming. I really want to thank you for your interest in Akamai. It's very important to us. What we did for you this year was we made sure that there was no snow. For those that came last year, we had a little bit of a snow incident, I figured June would probably be a time that we wouldn't get snow. We covered a lot today. I got about 45 minutes, hang in here. We covered some familiar themes that we've talked about every year, there's a reason for that: consistency.

What you've heard is very consistent with what we've talked about since I've been here talking about these analyst days. The market trends around over-the-top, mobile, cybersecurity, bots. Tom talked about, Rick, Internet of Things, enterprise security, blockchain, again, a theme of differentiation and expansion of the Akamai platform. Hopefully, you have a theme here of innovation is alive and well in the company, heritage of innovation, we have multiple growth levers for the business. I'm going to wrap up the morning, which is actually almost afternoon now, with a brief Q2 and 2018 update. Tom covered it, I just want to make sure that I clarify a few things for folks on the guidance update that we issued with the press release this morning.

I'm going to do a bit of a level set around the journey that we've been on the last five or six years, a reminder of what we've done, some of the decisions that we made, traction we've made in some areas, the opportunity ahead. I'm going to double-click quickly into the divisions, which is really the enabler to growth. As you know, we changed the organizational structure of the company a couple of years ago to move to divisions. These divisions are really the execution arm for the company. I'm going to end with a looking forward, talk about the priorities of the company, where we're going. I have a lot to cover. Fasten your seat belts because we're going to go fast. Let's just start with guidance.

This event, as Tom mentioned, is really about the future, about where we're going and the path forward. It is almost the end of June, we really felt that a brief update was in order, and really in the spirit of transparency and openness, which is really the culture that we have at Akamai. This chart is what we guided for the quarter on April 30th: $658 million-$670 million in revenue and $0.79-$0.83 of earnings. Again, guiding for another strong quarter on the top and the bottom line. Foreign exchange, as we mentioned, had an impact of $3 million on the top line. Literally, if you drew a chart from 4/30 to today, straight down as far as the dollar strengthening against pretty much all major currencies.

A pretty significant headwind from a foreign exchange perspective on both the top line and the bottom line. If you just flexed our guidance for the impact of foreign exchange, it would go down $3 million on the low end, it would go down $3 million on the high end, and then about $0.01 on earnings. We're two months into the quarter. We have two months of actuals. We basically have three months worth of traffic for our media business. We have a pretty good read on where the quarter is tracking. The quarter is tracking very well and roughly at the midpoint of our guidance, excluding the impact of foreign exchange. You'll see here that we narrowed the range, and we narrowed it because we have much better visibility into where the quarter is tracking. As Tom mentioned, there's a few events.

Obviously, the World Cup is a big one that we've had very good traffic here over the first few matches, we'll see how things transpire here over the next week. Narrowed the range in the top line pretty much at the midpoint of where we guided ex FX. We did increase, or we are trending a little bit more towards on the margin side, closer to the 26% side of margins, and then again, $0.79-$0.81, call it $0.80 at the midpoint. Another quarter of strong growth and margin expansion. For the full year, again, the same thing. Full year impact is $17 million in the top line. The reason it's much more for the full year, you say, why is it three in Q2 and it's much more for the full year?

It's because really you got to take where the foreign exchange rates are now and use the current spot rates to project what Q3 is going to be and project what Q4 is going to be. The impact of foreign exchange is much bigger for the full year, $17 million on the top line and $0.05 on EPS. Again, if you flex it for foreign exchange, no other changes with the operational performance of the business, you'd move it down $17 million on the top line and $0.05. As Tom mentioned, we've actually increased slightly the revenue guidance ex foreign exchange. We actually think we're tracking more towards the higher end of the range. We do know that obviously, there's some seasonality that takes place, in particular our fourth quarter, we've bounded this.

I'd say we're tracking more towards the higher end of this range, and we've increased margins. The work we've done on margin expansion that started in Q4 of last year continued into Q1, continues into Q2. We're quite bullish that we're tracking more to 25%-26% on operating margins versus what we guided in April of 2025. As Tom mentioned, you're actually seeing we're increasing earnings for the year about $0.05. As reported, actually $0.10 i f you adjust for foreign exchange. We feel very good about where the business is at. We feel very good about the traction that we're making.

I know obviously, some of the folks in the room and on the phone build their models, and they say, "Well, it's good that you give me full year guidance, but can you give me a little bit of color, Jim, on Q3 versus Q4?" We're going to cover that a lot more in our earnings call. The color that I'd give you is that seasonally, Q2 to Q3, our media business is relatively sequentially flat. Now, media business is excluding our carrier business, which includes some licensed customers, and we don't expect as much licensed business in Q3 of this year that we had Q3 of last year. Just some color for Q2 to Q3 is we'll probably be modestly up sequentially from Q2 to Q3, and call it margins will be roughly flat to what they are in Q2, wherever we land in Q2.

In Q4, you'll see a seasonal uptick, as we always do because of the holiday season, with the commerce season and a lot more that happens in the media landscape in the fourth quarter. You're going to see a step up from Q3 to Q4 in revenues, and you're going to see a step up in operating margins from Q3 to Q4 with the revenue increase. You'll also see that on the earnings front. That's enough about guidance. Kind of check the box that we felt that an update was in order. Now let me switch gears and talk a little bit about the financial reflection. Really what I want to get across in this presentation is the purposeful decisions that we've made over the past few years as a company.

I want to cover a little bit the proof points of the progress that we've made and why we're optimistic about the future. If you weren't optimistic after hearing Tom and others, there's just a lot going on in the company, a lot of really good and exciting things. We've been delivering against what we said we would. Really, we're focused on driving long-term shareholder value through strategic repositioning of the Akamai portfolio. We've really set the company up well to now be in a position where we're going to talk about future margin improvement. Let me start with Akamai's financial priorities. These priorities have been in place for a while. They're not new themes. There's been a very strong focus by the company over the last several years to accelerate revenue growth. We've also talked about investing in innovation for long-term growth.

We've talked about delivering strong operating margins. We've not talked about expanding operating margins. That's an important distinction. We've been talking about delivering strong operating margins. Actually, we have a very enviable operating model and financial model for the company. As we've been going through the last few years, we've been investing more in innovation while we were managing through the impact of a reduction in revenue from some of our large internet giants. Those were very purposeful decisions that we thought were smart for the business. We didn't want to constrain investment. We signaled this over the past few years that margins would dip.

Certainly, we've signaled that we would also be in a position that once we were able to get to a level of scale in some of these new businesses, that you'd begin to see margin expansion, and we'll talk about that a little bit later. We've done a good job as a company always being focused on being disciplined in our approach to capital allocation, and again, very much a managing for the long-term orientation. How have we done? This is a chart for revenue, EBITDA, and non-GAAP earnings. We've had strong growth over a multiple year lens. Growth has slowed a little bit over the last several years, largely because of these internet giants that we'll cover a bit that we're recovering from a growth rate perspective already. Strong top line growth 13%.

As we've been investing more heavily in the business, EBITDA margins haven't grown quite as fast from 2012 to 2017, but still grew 9%. 2017 obviously is impacted by two acquisitions that we did, our SOASTA acquisition and to a lesser extent, our Nominum acquisition, but certainly an impact nonetheless. The same is true on earnings, 10% growth in earnings over this period. Again, you kind of step back and you think about Akamai as a company. We created a category called the CDN category. It didn't exist before Akamai. We're now a leader in new categories and in new areas. Obviously, Rick talked about, and Tom talked about earlier, the fact that we just got recently recognized by Forrester as a leader or the leader in Web Application Firewall. That's in addition to being recognized in Gartner's Magic Quadrant last fall for the same thing.

You can certainly see that what the company's been able to do is put innovation to use, leveraging our platform for multiple use cases. I think now is at a point that we're poised to benefit from a lot of these investments. If you look at this is the exact same chart. This is a chart that is basically a trailing 12 months by quarter. Basically Q2 2017 to Q1 of 2018. Again, revenue, EBITDA and EPS. We've made very good financial and operational progress across the business. The actions that we've taken have already shown up in the P&L. You can certainly see that we're starting to see an acceleration in revenue growth. We're starting to see margin expansion on both the EBITDA line and the operating margin line, and we're starting to see good growth on the bottom line from an earnings perspective.

We feel very good about where the business is. We've been focused on driving operating efficiencies, scaling the M&A that we said we would when we acquired those two companies last year and showing acceleration in the business. We've continued to see very strong growth rates outside of the internet giants. The internet giants obviously were growing very rapidly for the company from 2012 to 2015. They began to serve more of their own traffic, and we've seen a dip. Obviously, the dip was more notable in 2016. It's moderated a bit from 2016 to 2017. If you look at the businesses, or the business outside of the internet giants, you've seen very strong mid-teens growth with very strong growth in both divisions. We feel good about the work that's been done, and the pace of innovation, and I'll cover that a little bit more.

We talked a little bit today, this is kind of I think a good maybe a pictorial of expanding the portfolio into brand new categories. This visual is you have the Akamai platform on the bottom, obviously you have the categories that we've been in. Obviously, we started in media. We went into web performance, most recently into web security. We have aspirations, obviously, to do more in the enterprise security space, or we call it the zero trust architecture. We talked briefly about IoT and blockchain, all riding on the same 1 platform. Security to the right, obviously, is our most recent example. 5 years ago, we were barely in the security business. Our business was, you can see here $25 million. We exited our 1st quarter of 2018 with a $600 million annual revenue run rate with the business growing 30%.

This is a subscription model. Those growth rates are quite impressive. While the revenue for enterprise security and IoT and blockchain are really early days for those areas, those are really the next waves that we're investing in. You want to invest now in areas that are going to be future growth engines for the company. We've also extended the portfolio, not just in brand new categories like security, but even in existing categories that we've already been in. We've extended the portfolio more deeply. This happens to be some new products that we've released over the last 18 months in each 1 of our divisions. Rick McConnell talked a lot about them, in particular in the Web Division with Bot Manager, Image Manager, Digital Performance Management. Some of this has been done through M&A, some of this has been done organically.

Again, all natural adjacencies to our core performance acceleration and security businesses. You certainly see here from this chart that these businesses now exiting Q1 have over $140 million run rate. Rick McConnell mentioned $100 million because $100 million is just from his products alone in his division. It's $140 million if you look at all the products across all these areas. You look at that, to put that in perspective, that number, $140 million, is the size of most of our competitors. This is what we've been able to do in 18 months with announcing new products just on the Akamai platform. A lot of growth levers now for the company, both expansion of the portfolio into new categories and an extension into new areas. We've done this by leveraging what is a very strong cash flow and balance sheet for the company.

The chart to the left is our cash flow and kind of a sources and uses. The cash flow, mid-teens. It dipped a little bit in 2017 with the absorption of some acquisitions and some investments that we made. Over this time period, the bars next to that are basically what we've spent in M&A and what we've spent in buyback. We've had a pretty balanced approach to capital allocation. We've strategically deployed more than 100% of our free cash flow. It's actually 134% over the last six years. Over $1 billion in M&A to fortify and extend the portfolio. We've reduced our share count, which is obviously the chart to the right going down by over 5%.

We talked this year about the fact that we're going to spend another $750 million in buybacks in 2018, which is really a statement about our confidence in the business, to be able to put that amount of firepower to buyback for the company. Thereafter, we'll probably spend more of what we've done, which is offsetting dilution, maybe a little bit less than 50% of our free cash flow in buyback. We took on some debt about a month ago. We took on a convert to add more firepower for the company. We expect to continue to be acquisitive as a company. We expect to put the cash to use in the best areas. We took on a $1 billion convert at very favorable terms. We also took on a revolver, which effectively is just a capacity to access more funds of $500 million as well.

A lot of this was done through some early refinancing our existing debt, which comes due in Q1 of 2019. Again, I'll remind you, all very purposeful, and focused on driving long-term shareholder value. When you look at this, well, how have we done against this? This revenue diversification strategy has really positioned the company well. This chart shows you where we were in 2012 by solution area, where we were by kind of geography and where we were from a customer perspective. You can certainly see that much more of the business was dominated by media in 2012. Over 40%, it's now less than 30%. Security is now nearly a quarter of our revenue. Offerings are much more extensive. We're much more diversified, and these new areas that we've extended into are much more stable.

You look at the geography mix, 27% of our revenue was outside the U.S. We now have 37% of our revenue outside the U.S. Again, go-to-market expansion investments that we made, really in areas we thought were pretty greenfield for the company. The last one obviously is by kind of customer mix, call it the giants. They represented a large percentage, 16% of the company's revenues in 2012, less than 7% when we exited Q1. Much more balanced and lower-risk revenue mix now than what we had just five years ago. Obviously, not only do you get more diversification, but you also create a larger opportunity when you extend into new areas. We outlined a few areas. Adam talked a little bit about it. Rick talked a little bit about it. It's very difficult to come up with total addressable markets.

We do the best we can. As you can imagine, as a company, that we have a buildup of this against all these areas, which by our estimate is well over $16 billion of market for us to go after. We are certainly not market opportunity constrained at all. We have a lot of growth vectors for the company to go after and many strong long-term secular tailwinds as a company. The other thing to talk about is not only is the portfolio broader and with the broader portfolio, you obviously get the benefits of having a larger market opportunity, but it also makes us much more strategic to our customers. It's hard to argue the quality of the logos. Think about the stats that Adam showed and that Rick showed. These aren't just logos because they do a little bit of business with Akamai.

These customers, these big customers, we are mission-critical to their environment. The chart to the left is how many customers did we have in 2012 that spent $1 million a year with us? How many of those customers do we now in 2017 spend $1 million a year or more? It's more than doubled from 2012 to 2017. Rick mentioned that 300 of those customers were in the Web Division. I think the slip he had was he said $1 million a month. His quota has just gone up because it is not $1 million a month. I told him at a break that I will give him 2 years to get to that level. It's 300 customers in Rick's division at $1 million a year.

You can certainly see great progress on selling the portfolio, which gets to the chart to the right. The chart to the right is the adoption of products by these million-dollar customers. The purplish kind of a pie there or donut, 26% of our customers in 2012 bought 5 or more of our offerings. You look at it now, 76% of our customers buy 5 or more of our offerings. Again, this revenue diversification strategy has made us much stickier with customers. Certainly, our retention rates reflect that. Actually, one thing I should go back to, just a reminder on that, 25% of those customers that now spend $1 million were not even on the Akamai platform in 2012. You say, well, are we fully penetrated? Absolutely not.

The good news is we have 62% of the Fortune 500 and call it half of the Global 1000. There's still a significant opportunity to expand the amount of customers that we reach. For the customers that we already have, as happy as I am with the penetration of the products, there's a lot more opportunity to go deeper with the customers that we have. 38% of our customers still only buy 1 product, 40% buy security. Of that 40%, it's not a large percentage that buy more than 1 of our security products. As Rick mentioned earlier that it's a pretty low percentage of our customers that buy some of the new offerings that we just announced in the last 18 months. There's a significant opportunity for further growth of the company going forward.

When you think about that, again, purposeful decisions, pivoting as a company, progress that we've made, and a lot of opportunity ahead. I'm going to segue quick into the divisions. I'm going to go very quick here because I think that this was covered mostly by Adam and Rick, but we get requests for these events that people like to see maybe in one place. I tried to include some of the relevant statistics on the divisions in my section as well. Again, the division profile is we're more weighted towards Web, about 53% of our revenue, 47% within Media. The verticals that they cover, Adam talked about this primarily being in Media OTT, gaming, and software, and obviously the carriers. Rick talked about the big verticals within the Web Division, primarily being commerce, financial services, travel, and hospitality.

Drivers, if you didn't get the point, media is about traffic. It's about getting the right customers and maximizing traffic share. It is much less a customer acquisition story. It's about getting the right customers on the platform and ensuring that Akamai is the platform of choice and that we maximize traffic share. Obviously, in the Web business, much more of a transaction booking business. You want to drive sales transactions, you want to drive more velocity from a sales perspective. That is much more of a SaaS-like subscription model, certainly not as intensive on the traffic side as the media business. The areas that we're innovating in very heavily, very focused in media on video delivery and carrier, Rick talked about the areas that we're innovating within Web.

Media division, again, this just gives you a visual, because we don't always share this with folks quarterly, but you get a view of the Media and Carrier Division. Certainly, the pie to the top left gives you a view of most of the revenue is in media and performance. Performance obviously is low-end Web performance solutions that these are media customers that tend to use our low-end Web performance solutions, somewhat like a media product. Most of the revenue that we sell obviously is kind of traffic-oriented products, but very good progress on security. Certainly, you'll see when I talk about Rick's percentage of security is much higher, but there's significant opportunity to sell security as well within the media division. Obviously the customer mix, Adam talked about this, the focus on the top 250 customers between the giants and the remaining top 250.

They're over 80% of the revenue within the Media and Carrier Division. Adam talked about the revenue trends and the work that we did to re-accelerate revenue in the division over the last few quarters, and you're starting to see that it's manifesting itself in the results. Traffic acceleration for three straight quarters, the strategy around top 250 paying off, and really a laser focus on R&D innovation being on quality, cost, and scale, and de-emphasizing areas like the media workflow. Financial model. I've talked about these financial models in the past, and they've been very product-oriented because that's really what the company really looked at primarily several years ago. From a division perspective, this is the P&L profile of the Media and Carrier Division. We are a one-segment reporting company. We don't manage the business by division P&L, at least yet. We may someday.

We make an effort every year to try to allocate the cost of the company to the divisions. This is a pretty good estimate of what the financial profile of the Media Division looks like. Not surprisingly, it looks very similar to the media product P&Ls that I used to share, which is, call it high 60s cash gross margins, low 30s EBITDA, and call it teens, mid-teens operating margins. This business is a little bit more CapEx intensive just given the nature of its business being very heavily focused on traffic. Then I've given you kind of a target model around what we're striving for in these businesses.

We might be able to eke out a little bit more on the cash gross margin side from some of the work that Robert talked about, but we're pretty close to where we think we should be here, maybe a little bit more. We think there's some work to do on the OpEx side. Some of the areas that Adam talked about will help. There's also some areas of the company infrastructure, scaling that better will obviously benefit itself into the media and carrier division P&L. Web, again, same chart. Obviously, Rick's division much more focused on high-end web performance products and security. 31% of Rick's portfolio revenue is in security and growing very rapidly. Then on the adoption side, you can certainly see more of Rick's customers. This is not million-dollar customers. This is all customers.

You can certainly see here that the purple donut, again, being customers that buy five or more of our products growing significantly from 2012 to 2017, again, revenue trends being in, call it, the mid-teens. They slowed a little bit. Obviously, the size of this business is harder to grow at those levels when the business gets bigger. Our goal is to try to maintain double-digit, to call it, to low- to mid-teens growth in this division. Again, this division is all about the portfolio. What we've introduced, they made great traction around penetrating multiple products with customers. You can certainly see that. That's what's fueled growth in this business. We've made some go-to-market changes that Rick talked about to try to do better on new logo generation. We've done well in that area, but that admittedly is an area we think we can improve on.

Then Rick talked about the addition of a new leader with Scott Lovett joining us really to drive some go-to-market enhancements, and I'll talk about that a little bit more when we talk about the financial model as we go forward. From a financial model perspective, again, this P&L looks very similar to what we used to talk about with performance and security solutions, because that's effectively what these customers buy. A very different financial model, mid-80s cash gross margins, kind of low 40s EBITDA, low 30s operating margins, again, with a desire to drive scale to be able to kind of maybe inch up gross margins just a little bit to mid-80s and to get EBITDA from the kind of low 40s to kind of the mid to high 40s, and obviously operating margins from the low 30s to the high 30s.

This isn't all going to come from activities within the Web Division. This is going to come from company infrastructure costs that go down that obviously the benefit of that is when you allocate those costs into the divisions, you'll see it show up there. The areas that they're focusing on are go-to-market productivity, M&A scaling, obviously the most notable being SOASTA, and then a continued effort around ongoing R&D prioritization and reprioritization. Let me switch gears a little bit and talk about going forward for the company. This is the same exact chart that I showed previously, which is the Akamai financial priorities. Financial models are about decisions that you make and timing.

Decisions and timing for the company over the last few years have been to invest in the business to basically fuel the innovation that we've been able to pull together as a company. We actually think now is the time is right to balance both innovation, and we think we have enough scale in our R&D areas that we can now drive optimization. The change now, I'd say nothing else has changed as far as the priorities of the company other than we are going to strive to drive further optimization and expand operating margins as a company, and we're going to try to do this without sacrificing growth for the business. I'm going to talk a little bit more about that. When you look at this is a chart of EBITDA, non-GAAP operating margins and EPS.

The bar to kind of the far left is the quarters, in the middle or kind of to the far right is the years. You can certainly see on the EBITDA line, op margin line and EPS line from Q4 to Q1 to what we just guided for Q2, margin expansion every quarter, both in EBITDA and operating margins. For the year, expecting EBITDA margins to improve from 37% to 39% and for operating margins to improve from kind of 24% to 25% to 26%. Good expansion on operating margins from some of the work that we've already done.

We did take some actions in the fourth quarter and the first quarter of 2018 as part of some of the efforts around operational efficiency and areas that we weren't getting the return on that we did make some difficult decisions and resulted in a RIF for the company. You're seeing that manifest itself in the P&L. It's not just about that. There's other actions that we've taken, whether they be facility consolidations and some other areas that is fueling kind of this growth and improvement in margins in the near term. Certainly on the EPS side, again, EPS growing nicely with a plan for EPS to grow at the midpoint of our guidance, 20% in constant currency. We're committed to sustainable, profitable growth. We're making progress, and we're focused on both innovation and driving efficiencies. Here's the model. We've talked about 30%.

This gives you a configuration of where we are in 2017 or where we were, because we obviously haven't closed 2018. I could have put 2018 on here, but I just figured 2017 is an actual. Where are we trying to get to in 2020? How do we get there? I'm going to talk a little bit about each one of these areas. Obviously, these are not contemplating M&A. M&A would maybe move your timeline out a little bit around when you get to 30%. We've always had a plan that we thought we could get back to high 20s, and we're striving for 30%, and I'm going to tell you what I think we can do to try to get there. Let me start with cash gross margins. There's two areas.

One is the area that Bobby talked about, which is around network costs. We've done a fantastic job on driving network costs over the last several years. Actually, since I've been here. I think it's just a heritage in the company. We actually think there's more work that we can do there in the areas that Bobby outlined. I think across kind of these network, I'll talk about services, maybe we can drive between 100 and 200 basis points of improvement from where we are in 2017. We were at 77% margins before 2017, so we think we can get back to 77%, maybe even as high as 78%. On the services side, again, we have 2,000 professional services employees in the company. We actually think we can drive some utilization improvements in that area, potentially some increased offshoring or nearshoring in different areas of the U.S.

Where we can, driving service delivery automation for things that today a human has to focus on. That's 100 to 200 basis points. R&D, you'll see here not a big number. It's 7% now, I'm saying it's probably going to be about 7% in 2020, there's a reason for that. We're not looking for a lot of scale in R&D. This is an innovation company. We don't want to constrain innovation. A lot of this is about reprioritizing existing resources into the highest ROI areas. This is not about reducing. Obviously, if there's things we can do around utilizing lower cost centers of excellence, we'll try to do that. If there's things we can do around improved project management tools and tracking, those are things we will do, this is not an area that we really think that there's a lot of scale on.

Now, obviously, if we find some, we'll go work it, not an area that is of huge focus around scaling for the company. Sales and marketing. This is an area that is maybe we could get 100 to 200 basis points of improvement in. Again, we don't want to jeopardize growth. There are some areas around, I'll call it go-to-market modernization. There's a reason why we brought Scott in. Scott brings a particular skill in this area. I think there's things we can do around increasing productivity from our sales organization. If you can increase productivity, you can actually increase velocity means more sales transactions, which means you get more sales efficiency, which means we move faster, which means you can get more productivity per rep.

It's probably less a cost play and more an ability to drive more productivity per rep, which obviously will show up in better spend to revenue ratios for our go-to-market spend. I've outlined a few other areas around looking at our coverage model, looking at our specialist models, getting better channel leverage, and looking at our sales support area and seeing how we can streamline that. I actually think that this is another area that we can drive some improvement in. The next area is G&A. G&A is probably the biggest area we think we can drive some improvement in, and we're targeting about 200 to 300 basis points here. Obviously, we've talked in the past that we include some things in G&A that some of our peers do not. We've talked about what they are, and I would say that that's pretty clear.

Nonetheless, we still think we can actually drive improvement in this area, probably 200 to 300 basis points. The areas we're going after are around shared services. That'd be finance, HR, legal, IT. Can we get some global business services streamlining out of those functions? Improved automation. Obviously, I lead the finance organization for the company. There's still a fair amount of our back office activities, in particular around contract processing, that are done. They're done in a low-cost center, but they're very manual, there's some work we need to do around increased automation to drive scale. Maybe more leveraging of low-cost centers. Third-party spend is an area we're focusing on. Not just getting better rates from folks, but also from driving reduced demand for third-party spend in particular.

The last area being facilities consolidation and making sure that we're maximizing our facility footprint as a company. Depreciation, again, probably not looking for huge scale there. Depreciation is obviously on the network side. Capitalized software is another area, maybe just getting some better engineer productivity in that area, and obviously, I talked about facilities being consolidating our footprint in those areas. Obviously, this is a model that says, let's try to get to 30% in 2020. Obviously, it's a target. I think it's important to remind folks that it's not going to be a linear progression of we were at 24% operating margins in 2017, going to maybe 25%-26%. This is not going to be linear, and I would say 2019 will probably be a transition year for the company. There are some things in 2019.

We will make progress every year, I'll say that upfront. There will be progress made on margin improvement every year. I think in 2019, it'll be a little bit more moderate, and it'll be a little bit more moderate for a couple reasons. One, there are some spend headwinds that we have. The company's building a new headquarters, and we will see the manifestation of that in the back half of 2019. The other area is there's some improvements we think we can make around IT automation, and we're going to try to make some investments in IT enablement to enable this to occur. If you look at it from a trajectory perspective, probably not the same level of improvement from 2018 to 2019, but certainly committed to strive to find a path back to 30% by 2020.

I'd say just some other financial modeling assumptions for the investor community is that our CapEx as a percent of revenue is probably going to be in the 15%-16% of revenue. I had some investors that asked, "Boy, you have a lot on CapEx." You got to double-click on that, and half of our CapEx is capitalized software. Our R&D at 7% of revenue looks low. It's actually more like 14% of our revenue is on R&D, because you got to take what we capitalize, including what we include in OpEx. That's roughly half of our CapEx. Network CapEx today is around 8%, we think we can drive some efficiency in network CapEx.

On the facility front, call it roughly 2% as a target, with 2019 being a year where we're going to make an investment because of the headquarter build-out. On the tax rate, call it roughly 20%. It depends upon our international revenue mix. Obviously, the U.S. tax rate is lower now, it's probably not going to move a lot. Probably best case, 19%-20%, but call it 20%. Let me just end with just a reminder, then we'll go to Q&A, that these bullet points, I think, speak for themselves, that innovation across the company is really, really strong. The portfolio is broader and deeper than it's ever been. There are multiple growth levers for the company in very large and emerging markets.

These investments are driven by secular trends, areas that we're in a kind of a rapidly evolving cloud ecosystem. We've talked about the fact we're committed to drive margin expansion while not sacrificing growth. The focus is going to be to improve productivity, try to increase agility, and try to move faster. Those are the things that will actually help the company move faster. We're going to continue to take the approach of managing for the long term while delivering in the near term. We believe that execution against the plans we've talked about are going to deliver a very compelling investment proposition for investors. With that, I think we are going to move to Q&A, we're going to bring some chairs up. Just give us a moment, and we'll get set.

Tom Barth
Head of Investor Relations, Akamai Technologies

That's right. Thank you, Jim. Again, we're going to have a question and answer period. Following this, we will have a lunch breakout for those that would like to stay. If they need to run, feel free. For those industry analysts, we are pushing back those breakout sessions specifically for you, 30 minutes, and those are up on the third floor. If you have any questions, I know both Stephanie and Bob are running around, and you can ask them. Now, we do have two individuals-

James Benson
CFO, Akamai Technologies

I was going to say, Adam and Rick, you get to come up here as well. Maybe even Scott. We'll have Scott come up.

Tom Barth
Head of Investor Relations, Akamai Technologies

We do have two individuals with microphones. I do ask that if you have a question to raise your hand, and we will move around the room with that. I think, Ellie, there's a person here.

James Benson
CFO, Akamai Technologies

Yeah. Come on up. Pull up a chair.

Tom Barth
Head of Investor Relations, Akamai Technologies

Okay.

James Benson
CFO, Akamai Technologies

No, you go ahead, Scott. I'll stand.

Tom Barth
Head of Investor Relations, Akamai Technologies

The first question is over with Noel. Gentlemen, as soon as you.

James Benson
CFO, Akamai Technologies

Is Ed McGowan out here too? Our sales leader for media.

Tom Barth
Head of Investor Relations, Akamai Technologies

He's here. Yeah.

James Benson
CFO, Akamai Technologies

There he is. Is he hiding?

Tom Barth
Head of Investor Relations, Akamai Technologies

He's right there.

James Benson
CFO, Akamai Technologies

Come on up, Ed. You don't get to shy away.

Tom Barth
Head of Investor Relations, Akamai Technologies

We may not have enough chairs at the moment, but we'll stand. The first question is there. I think.

Michael Turits
Analyst, Raymond James

Hey, guys.

Tom Barth
Head of Investor Relations, Akamai Technologies

Oh, Michael Turits. Thank you.

Michael Turits
Analyst, Raymond James

How are you?

Tom Barth
Head of Investor Relations, Akamai Technologies

Good.

Michael Turits
Analyst, Raymond James

Great. As you said, no snow. Everything's gone smoothly. Much appreciate the day today. Michael Turits from Raymond James. Two questions on security. First on the product side, and then sort of on a financial and operational side. On the security, I think it might've been Rick that was talking about the amount of capacity that you're building out at the edge for security. I'm wondering, what are some of the more traditional product categories that you could potentially put at the edge? Specifically, I think about firewall capability that could be at the edge, secure web gateway capability at the edge, and obviously there's a company right now that's having an analyst day or an event in Las Vegas that's had a lot of visibility in that area.

I was wondering what your thoughts are in terms of building those more traditional large market product categories into the edge, secure web gateway and firewall, and then I have a financial and operational question.

James Benson
CFO, Akamai Technologies

I think it's yours. You guys?

Tom Barth
Head of Investor Relations, Akamai Technologies

Yeah.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Yeah. Well, let me start, maybe Bobby can add to it on the enterprise side. There was a slide that Bobby had about all of what we're doing at the edge, it was three columns and had lots of capabilities, we do a lot on our edge servers, it's specific to the architecture that we've designed to allow as much of that processing to happen at the edge as possible. We will continue to do that, continue to add more capabilities to the edge. What we're now doing is we do obviously DDoS protection there. We do Web Application Firewall protection there. We do all of our layer seven work there, SQL injections and other kinds of attack vectors that we see. We manage all of those at the edge. All of that we'll continue to expand upon at the edge.

Now as we're adding the enterprise portfolio with Zero Trust there as well to push all of that to the edge also.

Robert Blumofe
EVP, Platform and General Manager, Enterprise Division, Akamai Technologies

Yeah, with Enterprise Threat Protector and Enterprise Application Access, we are adding a number of new capabilities at the edge. Those include things like authentication and authorization, identity, malware detection, malware filtering. The list kind of goes on from there. All those are edge capabilities.

Michael Turits
Analyst, Raymond James

Just to be specific in the question, do you intend to enter the secure web gateway and branch office remote firewall market using your network?

James Benson
CFO, Akamai Technologies

Yeah. Enterprise Threat Protector has a number of capabilities that are oftentimes associated with a secure web gateway, as edge capabilities, if you will. We don't necessarily say we're directly entering the secure web gateway market, but Enterprise Threat Protector has secure web gateway capabilities in it, like malware detection, like URL filtering and so on.

Michael Turits
Analyst, Raymond James

Okay. The operational question, I guess partially I see Scott's up there also, but what do you think you need to do in terms of incremental investment in security? Not just around the R&D side, but perhaps around the go-to-market side because you're in two specific markets, but really broadening there. Do you need to do anything in terms of sales force, sales management, marketing expertise in order to get into those broader security markets?

Scott Lovett
SVP, Global Web Sales, Akamai Technologies

I think we'll continue to expand the sales specialist category of resources that we've got out there, allowing deep technical investment and resources as well. Customers specifically on the security side are looking for kind of a trusted advisor status from us. I see more in-depth technical resources that we're adding in that group, and I think that'll continue as we move forward.

Tom Barth
Head of Investor Relations, Akamai Technologies

Will, questions over here. Will?

Speaker 16

Great. Thanks. I guess two questions. First, Jim, on the financial guidance, you raised full year guidance slightly on the revenue side, despite, I guess, Q2 being at the midpoint on a constant currency basis. I'd be curious what the confidence in the drivers is there, what the key elements of that are. The second part of that, where's the margin upside coming from relative to prior expectations in the second half? Then my second question, for Tom Leighton or whoever wants to take it, is on Bot Manager. A fair amount of discussion today about the opportunity there. How do we think about the size of that opportunity? Is that something that's similar to DDoS, your web application firewall product, and what's kind of the timeframe to get there?

James Benson
CFO, Akamai Technologies

Okay. I'll take the first one. Obviously for 2018, you're right, we did increase the guidance slightly, I mentioned, I actually think we had it in the press release that, as you can imagine, we have not historically provided full year guidance. This is the first year we've done it in quite some time. Obviously, you are a bit more cautious when you are early in the year. I'd say that's what our guide was initially for the full year, which was kind of some caution. We're tracking very well to where we thought for Q2, call it the midpoint. That's roughly where we peg. Obviously there's quarters you do better than that. We've had some where that's been the case recently, but we've looked at the business. We actually think that the business is strong kind of exiting Q2.

If you look at where the growth rates of the business are in the first half and you look at the projections that I provided for the full year, we're trending more towards as a business to growth rates are, call it, in the 7%-9% range. We actually felt that that was probably something that should be reflected in our guide on the top line. That's roughly speaking why we increased modestly the guide ex-FX on revenue. On margin and earnings, again, we've made traction in Q1. We did a little bit better than we thought. That was reflected in our Q1 results. We're tracking a little bit better here for Q2 and the actions that we're taking here, you're going to start to see them manifest themselves again in Q3 and Q4. Q3 may be more modestly.

The company does have some compensation increases where our annual salary increases take place in the third quarter. You won't see the margin expansion in the third quarter that we saw from Q1 to Q2, but you will see it Q3 to Q4, again, from a lot of the efforts that we've talked about. One thing I didn't mention that I probably should have, which is we have engaged an outside third party to help us as we're looking at areas of margin expansion for the business. We want to take a very measured approach from a company perspective that this is not a company that's in any level of financial distress. The financial model of the company is very strong.

The decisions we want to make around improving margins, we want to make sure that they're smart decisions and that they're structural decisions and that they're well-timed decisions. Some of that is factored into our guidance, some investments that we're going to make. The areas that we've talked about, whether they be facility consolidation, more constrained headcount investment, because I think we've built out and fortified in many areas already, are going to start to manifest themselves in the P&L with the revenue projections that I outlined. You just do the math on it and you're kind of in the 25%-26% range for operating margins for the full year. Certainly on the tax rate front, the tax rate front depends upon what our international mix is.

We're doing a little bit better outside the U.S. as far as our business than in the U.S. as far as growing faster. I think that you'll probably see a little bit of favorability in the tax rate as well.

Tom Barth
Head of Investor Relations, Akamai Technologies

Great. Rick, do you want to take the Bot Manager market question?

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Sure. Bot Manager, as you surmise, we're very excited about the solution, and we see enormous growth potential. We're doing many $ tens of millions of dollars per year. Got that right, Jim. $ tens of millions of dollars per year on Bot-

James Benson
CFO, Akamai Technologies

Your quarter is still going up

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Bot Manager already, and we're doing this with 250 to 300 or so customers. We've got a lot of penetration left in the installed base to continue to grow that, and bots are just becoming more and more pervasive and more and more difficult and challenging to manage for our customers. If you put all that together, we think that there's a really sizable market in bot management left to come, and we have only really just begun. I think the potential is enormous.

Tom Barth
Head of Investor Relations, Akamai Technologies

I think it's Greg over there, and then Mike's over here. Yeah. Go ahead.

Jeff Kvaal
Analyst, Nomura Instinet

Hi, it's Jeff Kvaal from Nomura Instinet. I'd like to delve back into security for a second. Can you

Give us a sense of where you feel that the growth is coming from. Is this because you think many customers are investing more in cloud security than they were before? Is this a share shift from on-prem? I'm not sure that the overall market necessarily is growing as fast as you all are. My second question is really much more simple, I think. That is, could you give us an update, please, on where you are with those web scale customers, and how solid as a percentage of sales they are at the moment?

Tom Leighton
CEO and Co-Founder, Akamai Technologies

Yeah. In the security market, we are growing a lot faster than the competition. We are uniquely able to stop the large DDoS attacks. We have very unique capabilities with Bot Manager and Application Firewall with Kona Site Defender. You saw the announcement yesterday as the market leader in that capability. Exciting capabilities and unique capabilities at the same time you see the threat levels rising. I think that's fueling really dramatic growth of our security business overall. I missed the second question.

Jeff Kvaal
Analyst, Nomura Instinet

Just to put a finer point on that security question, do you feel like you are gaining share at the expense of some competitors in that particular market?

Tom Leighton
CEO and Co-Founder, Akamai Technologies

Well, we're certainly gaining share. We're certainly growing at a far faster rate than you see a lot of other folks talking about, and we have unique capabilities that are really needed by the marketplace.

Jeff Kvaal
Analyst, Nomura Instinet

Okay.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Yeah, I would just add to that it's moving to the cloud, because that is pushing the ability to secure our customers' architectures further away from their origin infrastructure. Absolutely, I would say we're taking share from the CPE providers of security. You want to?

Scott Lovett
SVP, Global Web Sales, Akamai Technologies

Yeah, I was just going to say, as the newest guy standing up here on the stage and coming from the security market, I think what you're starting to see is customers consolidate spend in certain categories, and I think cloud has become probably the most prevalent. I think the days of CSOs having 85 discrete security vendors and buying best of breed have kind of passed by the wayside. They're now looking in key areas, on the endpoints, whatever they may be, mobile or desktop, in the traditional network, and I think that's changing in relevance. Cloud has jumped up significantly, and I think it makes us uniquely positioned to play there and fulfill that void.

Jeff Kvaal
Analyst, Nomura Instinet

Secondly was web scale. Sorry.

James Benson
CFO, Akamai Technologies

Okay, thank you. Samit?

Speaker 16

Yes, thank you. Jim, I'm going to borrow a term that you've used. Double-clicking. Can you talk about the second quarter guidance and, because if I take Rick's word that Web should grow low double digits implies that the Media division grew about 6%-6.5% in the second quarter, versus what you've been saying is that as volumes pick up, revenue acceleration should be expected going through the year. That's my first question. Second is, can you talk about the competition in the performance business? Obviously, it's your largest business, but at least from my perspective, we don't have much visibility into that. And how SOASTA is helping you kind of counter some of these competitive threats?

James Benson
CFO, Akamai Technologies

I'll take on Q2, we didn't guide necessarily by product area, but we grew about 9% in Q1. Our guide at the midpoint for Q2 was call it 8%. We're kind of tracking to that. I think your configuration is about right, call it mid-single digits in Media and Carrier and low double digits in the Web Division, and that's where the business is tracking for Q2.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

In terms of competition on the performance side, I went through the 3 categories. You have the large CSPs, you have the traditional CDNs and the web performance startups. As I think Jim mentioned, you see that just the growth in our new product area over the last couple of years is on the order of the size of some of the web startups, and we compete very successfully with the cloud service providers. In fact, many of the cloud service providers are our customers as well for certain parts of their portfolio and solutions. We compete based upon reliability, performance, and scale, and we compete based on the breadth of the portfolio because once you get on net, it is really incumbent on us to deliver comprehensive performance and security solutions to those customers. It's not just about performance anymore, I guess, is the key point.

It really is about security as well as a broader portfolio.

James Benson
CFO, Akamai Technologies

Probably worth you talking about kind of some of the bundles that we're doing, Rick. You talked a little bit about that.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Yeah, it's pretty rare these days that new customers are buying just a single product from us. We send out new product announcements, as you might imagine, internally for private consumption inside the company. When we see those, it's how many products did they buy? The result of that is that these customers have been demanding a broader-based solution set from us.

Tom Leighton
CEO and Co-Founder, Akamai Technologies

I think to your point about SOASTA, it does help us sell performance products and differentiate from the competition because it shows that we're faster, among other things. Shows the value of our products.

James Benson
CFO, Akamai Technologies

Keith?

Keith Weiss
Analyst, Morgan Stanley

Excellent. Keith Weiss from Morgan Stanley. Thank you guys for hosting this, thank you for these super comfy chairs. They're probably the most comfortable analyst day I've ever been to.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

With power.

Keith Weiss
Analyst, Morgan Stanley

Tom, I had a question for you on your presentation, I think what you were doing is kind of laying out sort of the overall advantage that Akamai has in this marketplace and kind of the advantage of what you guys have built out. I feel like I kind of missed the punchline a little bit in terms of when you're talking about scale, when you're talking about the scale on the edge, I think it was like 35 terabits per second in terms of what's on the edge, in the core there's 550, there's a mismatch there that they just don't have the capacity to handle 35,000 terabites per second. You guys have 60 terabites per second. How does that 60 fill in the gap where 500 couldn't?

Tom Leighton
CEO and Co-Founder, Akamai Technologies

Yeah, no, that's a great point. We're not at 500 today. We're nowhere near close to it. I said there's Take 100 tier 1 networks, actually maybe a couple dozen. Take the capacity in the backbones, five terabits a second. Nowhere near that today. I think over time it can grow there. In fact, you see this, as Adam pointed out, during the World Cup, there's a country, two countries. Actually, both countries are on the order of a few hundred gigabits per second, in both cases, a major carrier went down, couldn't do it. The prime minister tweeted about it because it was such a big deal in that country. The other country, the world's probably biggest cloud platform fell over, couldn't handle it. Even today we're seeing the core get squeezed. You see it in attacks.

If Akamai's not in front of it, the attacks today at only a terabit a second wipe out any cloud data center, any cloud company. In fact, the giant platform companies which have all this core infrastructure, they turn to Akamai to secure and defend their key websites. The point of that slide is that today and going forward, there is a mismatch between the potential demand and capacity at the edge and the capabilities in the core, and that mismatch lives and gets worse into the future. Even today, there's nowhere near 500 terabits a second. Today, in the core, things are falling over even before you get to a terabit a second in terms of what they can do.

Keith Weiss
Analyst, Morgan Stanley

Right. That mismatch also appears in terms of what your capacity is and what that edge is. It's just an order of magnitude different of 35,000 versus 60 terabits that you have. How do you fill in that gap? Because it's not going to be going from 200,000 servers to 120 million servers.

Tom Leighton
CEO and Co-Founder, Akamai Technologies

Yeah. Today we're delivering at over 60 terabits a second on a lot of days now. Our capacity is far bigger than that, and we're growing our capacity. In fact, as Adam mentioned, I think in the last 12 to 18 months, we've doubled our capacity on the edge of the internet, and we will keep doing that with our existing model going forward for several years, and that'll take us to hundreds, probably 1,000 terabits per second. We also talked about the importance of having our client's software on the devices. For many reasons, one of them is to help with capacity and reducing cost. I think as you get to many thousands of terabits per second of demand at the edge, that's where having the client side delivery helps offload the Akamai platform.

You can take advantage of the colo in the home, the power in the home, and the bandwidth that's available there to augment the edge capacity that we have today and will continue to grow.

Keith Weiss
Analyst, Morgan Stanley

Got it. One last one, if I could squeeze it in. You mentioned the media executive, the broadcaster you talked to was talking about they're going to be off satellites within 10 to 15 years, but also the scalability issue that they have in pricing. They now have to pay for that increased pricing. How does that broadcaster, how does he rationalize the move to OTT when it sounds like he's going to have to spend more to reach his end customer? What's the ROI rationalization that they're running?

Tom Leighton
CEO and Co-Founder, Akamai Technologies

That's another great question. The broadcasters are going there because the consumer demands it. You're absolutely right. They much prefer the satellite cost model. It's expensive to get the first signal up there, but then the marginal cost is zero for every TV that's turned on or as you do something improving the quality. With the internet, much more complicated, and that's another reason why we're putting so much investment into reducing the cost of delivering video. Every year, the cost for every bit we deliver per bit comes down substantially, and we're investing a lot to make that happen so that we can continue to enable the world's major broadcasters and content owners to put more content online.

At the end of the day, the traffic goes way up. Adam showed you a chart where basically we're double internet now in terms of the growth rate. At the same time, the cost is coming down. It's the product that we need to get right to drive revenue growth. As Adam showed you, we're now doing that in the media division. We want to do that even better. Of course, profitability, really important. Margin expansion important. That means driving down our costs even more. We've had a really good track record of doing that. You can see that in the gross margins of the business over the years, how well they've done, a lot of work internally to improve gross margins as Jim mentioned.

James Benson
CFO, Akamai Technologies

We do have a time for a couple more. We're going to go over there first. Is that Brandon?

Brandon Nispel
Analyst, KeyBanc Capital Markets

Yep.

James Benson
CFO, Akamai Technologies

Yeah.

Brandon Nispel
Analyst, KeyBanc Capital Markets

Brandon Nispel with KeyBanc Capital Markets. Three questions. Tom, could you maybe comment on Microsoft's acquisition of GitHub and what that could mean for their own CDN and the functionality that they're trying to build in their cloud platform? A housekeeping for Jim. Does the EPS guidance for the year now include your share repurchase program that you guys have in place? Then maybe one for Robert, maybe Tom. Can you help us understand what the cloud service providers, the cloud titans, if you will, do to handle their own congestion issues at the core of their network? Because it does seem like they're building out more edge facilities overall. Thanks.

Tom Leighton
CEO and Co-Founder, Akamai Technologies

Okay. Yeah, first with the acquisition, I think totally neutral to us. We have great relationships with both companies, so I don't see there being any issue in terms of the GitHub acquisition.

James Benson
CFO, Akamai Technologies

On the EPS guidance, yes, we did factor in that we're going to spend $750. Obviously, the share count will go down between now and the end of the year. It is factored into the full year guidance. Bobby?

Robert Blumofe
EVP, Platform and General Manager, Enterprise Division, Akamai Technologies

On the cloud service providers, I think they continue to expand their infrastructure and grow into more locations. Obviously, they're orders of magnitude-

Fewer locations than we're in, That does create some limitations. Many of their customers would use the cloud service for, say, storage and compute, turn to us then for the scalability that they need to reach their users at the scale and the protection levels that they need.

James Benson
CFO, Akamai Technologies

In fact, a lot of them themselves do exactly that. They'll use their internal services for storage and compute. They'll use us to accelerate their apps to protect their applications.

Adam Karon
EVP and General Manager, Media and Carrier Division, Akamai Technologies

That's exactly the Cloud Wrapper solution that I described during my presentation, where we wrap around those central compute and storage platforms to distribute that content out to the edge so that those cloud providers don't need to have that distributed infrastructure. We take care of that.

Robert Blumofe
EVP, Platform and General Manager, Enterprise Division, Akamai Technologies

Colby?

Speaker 16

Great. Bobby, maybe for you just to start, you guys talk about the 3,900 locations that you have. As you add more services that you're offering on those edge deployments, how easy or accessible is it to get more servers into those locations? Of those 3,900, is there a way to segment that 100 or 1,000 are running an overwhelming majority of where your content is actually being distributed from? Again, how easy is it actually to add the capacity in those particular ISP locations that you might need? Then just two very quick housekeeping items. The $750 million buyback, you were constrained in the first quarter. I think you were constrained again in the second quarter because of the debt financing you were doing. How comfortable are you that you could actually get that done in 2018?

Also, you guys talked a lot about the growth opportunity for web. I think you said low double digits to mid-teens. I don't recall, and I could have just simply forgotten what your expectations are longer term for the media business in terms of growth rate on the top line.

Robert Blumofe
EVP, Platform and General Manager, Enterprise Division, Akamai Technologies

When it comes to adding capacity, we don't always have to add it in terms of more servers linearly in every single location. It depends on the size of the location, how much traffic is growing in that area, what part of the web it's serving. We get a lot of capacity adds simply through things like software innovation. We get capacity increases without necessarily having to add hardware. We just make the software more efficient, for example. It's just a matter, in some cases, of a conversation with that ISP of adding some pipe, not adding servers, which is easier to do, of course, than adding servers, because adding servers means more co-location space, and that's generally the most constrained resource that they have in their networks.

It varies by location, but I think it's important to recognize that capacity adds don't always mean a linear amount of server adds.

James Benson
CFO, Akamai Technologies

On the buyback, I'm very confident we can spend the $750. We'll spend more this quarter. You're right, we were constrained because of going through the convert. We did buy back some shares concurrent with the convert, and we've been buying back since then. Very confident we'll spend $750 by the end of the year. I'll have Adam comment a little bit about media, that we probably didn't talk about media as far as a near-term growth business, because the media business inherently has variability. We're going through what is a recovery in the media business with what we're doing around traffic share. I'd say our aspiration is to get back to double-digit growth in the media business. That is more of a long-term aspiration.

That is not a this quarter, that is not a this year phenomenon, but that is certainly the aspiration that we want. We want the media business back to double-digit growth, and then the web business to be in the low double-digit to teens growth.

Adam Karon
EVP and General Manager, Media and Carrier Division, Akamai Technologies

I don't think I have anything to add to that. Yeah.

Tom Barth
Head of Investor Relations, Akamai Technologies

There are questions in the back, then Siti, did you have a question? Okay. I think that'll probably be it unless there's any other questions.

Melinda-Carol Ballou
Application Development and Quality Management Research Director, IDC

Okay. Melinda-Carol Ballou from IDC. I want to congratulate you on the ways in which you've been leveraging your acquisitions. Threaded throughout the discussion this morning, it was clear that there's significant impact around that. I'm curious about two things. One is the relationship between security, quality, and performance for DevOps, and the opportunities that you have there to pull those pieces together. I've been personally seeing some better coordination between the CSOs and the quality folks. That'd be one question. Then a second, as a citizen and as an analyst, I'm curious about Bot Manager impacting potentially the elections, what kind of inquiry you've been getting from state, local, federal governments, because personally, I'd like to see that be a little more controlled in the future, as I expect most would in this audience. Those two questions. Thanks.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Sure. For security and DevOps, it's interesting because we first started our foray into DevOps around performance, not security. Josh Yowell runs product management for our security organization. We had this debate about a year and a half ago as to how critical DevOps was for security. As we worked with various different CSOs, we found that it's critically important. We are working on delivering, and in fact, delivering on API solutions for customers in both the performance portfolio as well as the security portfolio, and we're investing in them equally. That's that. In terms of elections, I can't speak to any one customer engaging in bot management utilization for elections. Be happy to take that offline and talk more to you about specifically what you mean there.

Suffice it to say that we have solutions that can manage bots of all sorts, malicious to non-malicious, and state and local governments are customers of ours as well.

Melinda-Carol Ballou
Application Development and Quality Management Research Director, IDC

Well, I think you have an opportunity to coordinate the security and the quality together with performance. There may be some bundling options for that too. We can talk offline. Thanks.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Fair enough. Thank you.

Tom Barth
Head of Investor Relations, Akamai Technologies

Our final question, Siti?

Siti Panigrahi
Analyst, Wells Fargo

Yeah. Siti Panigrahi from Wells Fargo. You talked about traffic growth on your Akamai platform. Just wondering what sort of benefit you'd get on your web performance and security. I understand that you don't price it by traffic volume, but is there any kind of indirect benefit you'll see on that part of the division? Also on the acquisition side, you have been very aggressive last few years, but last acquisition was in November. Just wondering, as you look forward to your new product initiative, what's your strategy between new organic development versus M&A as you focus on the margin expansion?

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Right. Sorry, go back to the first question, as I was thinking about the second one.

Siti Panigrahi
Analyst, Wells Fargo

About the traffic-

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Traffic and performance and security. First and foremost, as I said, we drive revenue in the performance and security areas primarily by bookings as you noted, but secondarily by traffic. There is absolutely a traffic component, which is why you see, for example, in Q4, a tick up in the Web Division revenue, typically from Q3 based upon the commerce selling season. That is largely traffic-based, traffic-driven. I would say it's primarily driven by bookings and commits from our customers, secondarily from traffic, which is a core component as well. That's the answer.

Siti Panigrahi
Analyst, Wells Fargo

What percentage of that business influenced by traffic?

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

I don't know, Jim, how you would answer that, vast majority is through bookings, much lower percentage by traffic.

James Benson
CFO, Akamai Technologies

Yes.

Rick McConnell
President and General Manager, Web Division, Akamai Technologies

Traffic is an important aspect.

James Benson
CFO, Akamai Technologies

Traffic obviously has a heavier element for the web business in the fourth quarter with the commerce business, because obviously seasonally you're going to have more traffic in that quarter just because seasonally commerce is faster. Your question around kind of our M&A strategy, our M&A strategy has been pretty consistent that we'll continue to do. We've had a variety. We've done technology tuck-ins. Call it technology tuck-ins, will have no impact on the financial model that I talked about because you'll just absorb them. If there are product adjacencies, which we've done, which have been most recently SOASTA and Nominum, if we do something like that, obviously, it's very unlikely you're going to find a target that has the financial model that Akamai does.

It'll probably be near term dilutive, we will make sure if it's near term dilutive, that it's long term accretive, all it might do is just move out our horizon, so maybe you don't get to 30 in 2020, maybe you get to 30 in 2021. We'll certainly signal that if that's the case. I will tell you that we are active in the market as far as shoppers, we are very disciplined buyers, so we take a very value-enhancing approach to M&A, we're not obviously ready to announce anything here. I think it's fair to say the reason we took on some debt, as a company, is we expect to be more acquisitive in the future, as we have in the past. We'll make sure that it's for the right benefits for the business long term.

Tom Barth
Head of Investor Relations, Akamai Technologies

With that, I want to thank the executives and their teams for all their efforts in putting together a great day. I want to thank all of you for coming to join us. The executives will be mingling through lunch if you have some additional questions, we look forward to any feedback. You'll see a feedback form on your little desk there. We'd be appreciative of any time you would spend on any feedback, we look forward to any questions you have in the future. Thank you very much and have a safe trip home.

James Benson
CFO, Akamai Technologies

Thank you.