Welcome everyone to our fourth quarter and full-year 2020 financial results video conference. At this time, all participants are in listen-only mode during the formal presentation, which will be followed by a question-and-answer session. Joining me remotely today on the call are Gil Shwed, Founder and CEO, along with our CFO and COO, Tal Payne. As a reminder, the video conference is live on our website and recorded for replay. To access the live conference and replay information, please visit the company's website at checkpoint.com. For your convenience, the replay will be available on our website. If you'd like to reach us after the call, please contact investor relations by email at kip@checkpoint.com. Before we begin with management's presentation, I'd like to highlight the following.
During the course of this presentation, Check Point's representatives may make certain forward-looking statements. These forward-looking statements, within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934, include but are not limited to statements related to Check Point's expectations regarding business, financial performance and customers, t he introduction of new products, programs, success of those products and programs, t he environment for security threats and trends in the market, our strategy, focus areas and demand for solutions, the impact of COVID-19 on our business, including our product development, sales, marketing efforts, and our financial conditions and results of operations, the impact of COVID-19 on our customer suppliers, business partners and the macroeconomic environment as a whole, our business and financial outlook, including our guidance for Q1 and full-year 2021.
These statements pertain to future events, they are subject to risk and uncertainty. Actual results could differ materially from Check Point's current expectations and belief. Factors that could cause or contribute to such differences are contained in Check Point's earnings release issued on February 3rd, 2021, which is available on our website, and other factors and risks, including those discussed in Check Point's latest annual report on Form 20-F, filed with the SEC. Check Point assumes no obligation to update information concerning its expectations or belief, except as required by law. In our press release, which has been posted on our website, we present GAAP and non-GAAP results, along with the reconciliation of such results, as well as the reasons for our presentation of non-GAAP information. Now, it's my pleasure to turn the call over to Tal Payne for a review of our financial results.
Great, Kip. Thank you. Good morning or good afternoon to everyone joining us on the call today. I'm pleased to begin the review of the fourth quarter and the full-year. Revenues for the fourth quarter increased by 4% year-over-year, reaching $564 million. Our non-GAAP EPS grew by 7% to $2.17, both above the midpoint of our guidance. Before I proceed further into the numbers, let me remind you that our GAAP financial results include stock-based compensation charges, amortization of acquired intangible assets, and acquisition-related expenses, as well as the related tax effect. Keep in mind, as applicable, non-GAAP information is presented excluding these items. Now, let's take a look at the financial highlights for the quarter. Revenues for the quarter reached $564 million, $14 million above the midpoint of our guidance. Products and security subscription revenues were $340 million, a 6% increase year-over-year.
Our subscription revenues continue to be strong, with 10% growth year-over-year, reaching $118 million. Software update and maintenance revenues increased to $224 million. We've seen strength in our strategic areas. Our CloudGuard family had great results with a high double-digit growth. Infinity continued the momentum with significant transactions in different verticals and impressive growth in the business we do with these customers. During the year, we launched the vast majority of our Quantum Appliances series. The family was well-received in the market, we finished the year with over 90% transition. Deferred revenues reached $1.482 billion, a growth of $95 million, 7% growth year-over-year. Short-term deferred revenues increased by 10%. Revenue distribution by geography for the quarter was as follows: 43% of revenues came from Americas, 45% of revenues came from Europe, Middle East, and Africa, and the remaining 12% came from Asia-Pacific.
We delivered strong gross profit of 89% and non-GAAP operating margin of 51%, similar to last year. Our financial income for the quarter was $14 million. As a reminder, interest rates in the U.S. sharply dropped earlier this year, hence the reduction in the financial income versus last year. Naturally, this reduction is also part of the cash flow. Effective non-GAAP tax rates for the quarter was 0% as we expected. This quarter, similar to last year, our tax expenses include tax benefits from lapse of statutes of limitation on certain provisions. GAAP net income was $271 million, at $1.95 per diluted share. Non-GAAP net income was $301 million, or $2.17 per diluted share, an increase of 7% from fourth quarter of 2019, and $0.08 above the mid of our guidance. The accelerated growth is related to the continued reduction in our diluted outstanding shares.
Our cash balances as of December 31st reached $4 billion, again. Operating cash flow for the quarter increased by 19% to $293 million, with strong collection from customers. As a reminder, we hedge our balance sheet against currency fluctuation. The hedge affect our cash flow with a minimal effect on the P&L as intended. During the quarter, the dollar weakened against the Israeli shekel, resulting in a hedge income of $26 million in our cash flow compared to $2 million last year. In addition, during the fourth quarter of last year, we completed the acquisition of Protego and Cymplify. Net of hedge and acquisition related costs, our operating cash flow increased by 4% year-over-year. During the quarter, we continued the purchase of our shares. We purchased 2.7 million shares for $323 million at an average price of $119.
Now, let's take a look at the financial results for the full-year. Our revenues for the year is $2.065 billion , an increase of 4% year-over-year, $50 million above the midpoint of our original guidance at the beginning of the year. Subscription revenues continue to be the main growth drivers with Infinity and CloudGuard solution leading the growth. Infinity deals continue to gain momentums, crossing the $100 million booking bar. Annual contract value of Infinity customers show a significant growth of tens or even hundreds of percentage as customers adopt the full Infinity threat protection solution. This is great news. CloudGuard solution already reached more than 3,000 customers. Both CloudGuard IaaS and CloudGuard SaaS are growing fast with a strong double digit.
Non-GAAP operating margin for the year were a strong 50% as we had higher level of revenues on the one hand, and about $40 million less expenses as a result of COVID-19 impact on the other hand. During the year, the dollar weakened against many currencies around the world. The effect on our results in 2020 was minimal, as we recovered effectively by our hedge.
The dollar continued to weaken after the year-end, as you could all see. Based on the current rates, the effect is expected to be an increase of our operating expenses for next year of about $25 million. Our financial income in 2020 reduced to $67 million from $81 million last year as a result of the reduction in the yield on our portfolio as we discussed. We expect again to see the continued drop of $1 million-$2 million a quarter with a total financial income for this year 2021 of $42 million.
Effective non-GAAP tax rate for the year was 13%, in line with our expectation. For 2021, assuming no regulatory changes, we expect the tax rate for the year to be similar, 12%-13%. Quarterly tax rate for next year, from Q1 to Q3, 17%, same like this year, and around 0% around Q4 as a result of the lapse of statute of limitation that's also expected to happen in Q4 next year. GAAP net income for the year was $847 million or $5.96 per diluted share. Non-GAAP net income for the year was $963 million or $6.78 per diluted share. The EPS was $0.13 above the high end of the original guidance for the year and is reflecting an increase of 11%. Cash flow from operation increased by 4% to $1.152 billion.
During the year, the company repurchased approximately 11.4 million shares at the cost of $1.3 billion at an average price of $114. For 2021, based on the current buyback rates and the current share price, we expect our average diluted number of shares to be around 136 million shares for the year, starting at 138 million in Q1 and moving down to 134 million by Q4. Now I'll turn the call over to Gil for his comments.
Thank you, Tal. Happy belated New Year to all of you joining us on the call today. I hope that you and your family are safe and healthy. I'm glad to report the results for 2020. What a year it was. As you've heard from Tal, we delivered good numbers for the fourth quarter and for the entire year. More important is what we achieved throughout the year. Despite the pandemic, we launched an entirely new product line for our core network security business, the Quantum family, and the results were quite positive, from negative product growth in 2019 to positive one in 2020. Our cloud business delivered double-digit growth in 2020, a trend that intensified in the second half of the year.
Our Infinity solution that delivered the industry-only preventative architecture for cybersecurity across the entire spectrum of attack vectors, network, cloud, and endpoint, more than doubled its number of customers and contract value. We've augmented all our products families with plenty of technologies, serverless protection for cloud, IoT and autonomous threat prevention on the network, EDR capabilities for the endpoint, and our new Infinity SOC security research and management tool, just to name a few key technologies that are now part of our products in Infinity architecture. The importance of cyber and the internet has risen significantly over the last year. The network became the lifeline of our lives and businesses, and I believe I've said it before, but our industry can be proud. We kept the world running. The world faced big increases in traffic, and with that, it also faced a huge increase in cyberattack.
I can go on and on and describe our achievement in 2020, I'd like to focus more on talking about the state of cybersecurity and our plans for 2021. I've been speaking about the fifth generation, or Gen V cyberattacks for the past couple of years. 2020 demonstrated that it is not a theory or a projection, the Gen V attacks are here, sophisticated multi-vector attack that are polymorphing, disguise themselves very well, start the attack in one place, and end it two steps later, deep in the enterprise. This was the hallmark of many of the attacks in 2020, including the Emotet bot, that was one of the most popular launchpad for attacks last year. The Emotet network was taken down in a sophisticated operation involving the law enforcement agencies from eight countries.
Great achievement for cyber law enforcement, also an important signal for all of us. Emotet has been active since 2014. We saw it in one out of five enterprises in the world. We can't allow attacks to go on for seven years. We have to defend against it ourselves, which we do. Check Point advanced threat prevention uniquely designed to prevent these attacks on patient zero, even when the malware is polymorphic and appears differently on each attack. In the middle of 2020, we coined the term cyber pandemic, which was underscored by the World Economic Forum, emphasizing the world is indeed facing a cyber pandemic. In December 2020, the SUNBURST attack demonstrated the impact that a Gen V cyber pandemic can cause, an attack that was seen in over 18,000 organization, including the top U.S. government agencies and the world's largest companies.
SUNBURST started with an attack vector that is almost impossible to detect, embedded into the SolarWinds software, but once executed, it's made its way into multiple systems in the network and presented major challenges to cloud environments that were the most vulnerable to the SUNBURST attack, a true Gen V attack. These nightmare and worst case scenarios of executive and CISOs have now become a terrible reality. Most leaders in 2020 characterized last year as one stuck in survival mode. Everyone needed to operate in environments they've never experienced, faced level of uncertainty the world has never seen before, and challenges the world has never faced in this modern era. Looking at the state of cybersecurity, it is time to move from survival mode into revival mode. It's a new world, and we have the opportunity to protect it.
We're starting 2021 with a strong, focused, and ambitious strategy to make our customers secure in this new era of Gen V cyberattack. A strategy that relies on the technologies we've developed over many years, a strategy that will make achieving the required level of security much simpler than ever before. We have over 80 products and technologies today. In 2021, we are going to provide them under three key families with unified management and control tool for the entire environment. Let me describe briefly these three families. First, let me start with the newest family to our portfolio. Work from anywhere has become the new norm. Over 70% of businesses believe that it will become a major part of operations post-corona. CISOs have prioritized securing the work from anywhere as a top priority for the next two years, a very new phenomena in cyber.
We're going to tackle this challenge head-on and provide the best solution for that secure connectivity from anywhere and secure work environment on any device, company managed, personal, and mobile. It involves unifying over seven different security categories, from endpoint to clientless remote access. We believe no single vendor except Check Point has all these technologies today. It presents a great opportunity for us and for our customers. The second pillar will be a continued focus on cloud security. We intend to continue and are driving to make the CloudGuard family the most comprehensive cloud security solution in the industry. In 2021, we are going to augment it with the next generation of web application firewall, one that is powered by what we call contextual AI, where the system deployment and learning phase can be reduced from 48 days on legacy systems to 48 hours with our automated technology.
Our new application security capabilities will secure multiple cloud workloads, APIs, web application, as well as hosted and on-premise web servers, a $1.5 billion market potential that will augment our total addressable market just within the cloud security space. The third pillar is our Quantum family, a comprehensive set of solutions for network security. In 2021, our Quantum family will include all network security technologies for all sizes of networks, from nano security on IoT devices to terabit security on major networks. Today, we introduced the Quantum Spark appliances, creating a full set of solutions for branch offices and small businesses. This family will utilize an intuitive web-based installation and management, a mobile app for monitoring that will make enterprise security simple and achievable for all.
Quantum Spark joins the other Quantum models and technologies, making it what we believe to be the most comprehensive network security solution in the industry. Our three pillars are going to be quite simple, securing the users wherever they are, CloudGuard for the cloud, and Quantum for the network. Simple, isn't it? One more thing, these three families are going to enjoy a single management suite. The new suite will be called Infinity Vision. It includes the ability to manage the entire portfolio with a single portal. Some users will prefer to run parts of it on-premise, but the fully enabled cloud-based management is going to be provided. Infinity Vision will also include our SOC and XDR tools. Many of them will be delivered in 2021 and will provide sophisticated intelligence tools.
All are going to enjoy unified policies, monitoring tools, and most important, the ThreatCloud service, which will relay the attack information across the world and across all attack vectors and turn security information into actionable prevention. Overall, I believe that the revolution of our product portfolio is going to provide the world what it needs, unified, strong cybersecurity. On the business front, we're going to augment this technology and innovation with increased investment in our sales and R&D organization. We started the year with our sales kickoff meetings. For the first time, we held them virtually. We received excellent scores from employees and partners on the event, and more important, on the clarity of the vision and the market fit of the solutions. Today, we're finishing the last event.
We started two weeks ago with our APAC sales kickoff, continued with the American sales kickoff. Just now finishing our European sales kickoff meeting. At the end of the month, we're going to hold our first virtual Check Point Experience customer conference. We expect record attendance at the coming CPX. I believe that we're entering a new world in 2021, a world that presents new cyber challenges and new opportunities for everyone. New opportunities for the way we work, the way we live. Opportunities to secure this world. This is a good transition to our 2021 projection. As you know, my regular caveat, it's hard to predict the future, especially with the challenges we're implementing to our technology, business. The pandemic around the world.
The level of uncertainty in our world remains high, but I will do my best to share with you our guiding principle, bear in mind that many things can change. With that in mind, our revenues for 2021 are expected to be in the range of $2.08 billion-$2.18 billion for the entire year. As for earnings, in 2021, we plan to invest more in our business. I believe that the new opportunities ahead of us warrant more investment than what we did last year. Keep in mind that the level of expenses in 2020 was extraordinarily low as a result of the cancellation of almost all physical activities. This had a positive impact on our earnings in 2020 of approximately $0.25. We expect partial return of these expenses in 2021.
On top of that, just like Tal said, the dollar is weakened and has a big effect on us, as more than 50% of our expenses are not in U.S. dollar. About $0.16 impact as of today. Interest have gone down, which reduced our interest income, also about $0.16 impact. The total impact of these three factors is approximately $0.52. We are starting 2021 with - $0.52 to our annual EPS, mostly, by the way, in the latter part of the year. Based on these assumptions, our non-GAAP earnings per share is expected to be in the range of $6.45-$6.85. GAAP EPS is expected to be approximately $0.90 lower.
For the first quarter, we expect revenues in the range of $485 million-$515 million, and non-GAAP EPS in the range of $1.45-$1.55. GAAP EPS is expected to be approximately $0.22 less for the first quarter. Thank you for being with us today, and we'd love to hear your questions.
Thank you, Gil. Before we begin with the Q&A session, due to time constraints and in consideration of other participants, please limit yourself to one question. If you run into technical difficulty, please type your question into the chat. Our first question today is going to come from Adam Tindle from Raymond James, followed by Fatima Boolani from UBS Equities. Adam?
Thanks, Kip. I just wanted to start with the near-term and long-term repercussions of SUNBURST, maybe Tal could start on the near term. Could you maybe talk about the cadence of Q4? Did you see any acceleration in conjunction with this? Looks like you're guiding revenue above seasonal in Q1 based on what I can tell from the quick math here. Just wondering if maybe there's some bursting that you're seeing to give you confidence in that above seasonal. Then maybe Gil can tackle the long term. Just speak to the repercussions for security architecture changes, does this open opportunity for M&A for Check Point, or do you think you can attack it with your existing portfolio? Thank you.
Gil, unmute please.
Tal, go ahead.
Yeah, I wouldn't say I saw something specific relating to that. Q1 guidance, a lot of it is mathematical in the sense that some of it's coming from the deferred revenue, we know already how much we have in hand, both in the subscription and in the support. The product is the area where you have the range, where it can be higher or lower, it depends on what will show up in the product revenue. It's not relating really to any increased demand or decreased demand we see in the market. We expect it to be in line with our expectations.
Again, for the strategic impact for that, first, I think it highlighted the fact that these attacks, sophisticated, disguised them very well. True Gen V attack, like we're describing, this is real, this is something we have to face. Is it going to have a direct impact on our revenues? I hope it will because I think we're the only ones that can actually address that. Companies were frozen with what should we do? Companies invested tons of energy just investigating what happened six months before, trying to realize if they were attacked. By the way, I think it's very hard to know. SUNBURST was an attack that most companies cannot know if they were affected by it. It got in, did what it did, and in many organizations, it just deleted itself and left almost no traces.
Again, I think the secret against that is not to know that you were hacked, and your secrets were stolen six months ago. The key is to prevent it and make sure that whatever gets inside doesn't proliferate, doesn't cause damage. That's all about prevention. I think we're doing that. We're doing that quite effectively, and I think we can face these attacks. I think our challenge remains to show customers the huge difference in deploying our technology and deploying our solution compared to everything else that they know in the marketplace.
Okay, maybe I'll repeat the guidance since I'm not sure everyone heard it. For the first quarter, $485 million-$515 million. Non-GAAP EPS in the range of $1.45-$1.55. GAAP EPS $0.22 below. For the year, $2.08 billion-$2.18 billion . The EPS, non-GAAP, $6.45-$6.85. GAAP EPS expected to be $0.90 lower.
Thank you, Tal.
The high end of revenue guidance, $515, not $550?
$485 million-$515 million, yeah.
I heard $550. Okay, that's helpful. Thank you.
Sure.
All right. Our next question is going to come from Fatima Boolani, followed by Brad Zelnick at Credit Suisse.
Good morning. Thank you for taking the questions. Gil, maybe to start with you very quickly. You were very explicit that 2021 is going to be characterized by investments in R&D and sales and marketing. As I think about the new product families, and the vision you have around your new product families, can you talk to us around how that's going to impact your go-to market efforts, specifically around any changes to incentives, compensation structures to your direct sales force, and how this is going to move down the pipe with some of your channel partners as you build and continue to build your channel partner relationships? I have a quick follow-up for Tal, please.
Sure. First, in terms of our go-to market, I think the general structure remains the same, and we have a big and good sales organization that doesn't need major changes, needs some small ones. We do have two overlays, one that will focus on the CloudGuard technology and another overlay that supports the sales with regards to the new user-centric security. We haven't formally launched the name for that, but you'll see that in a couple of weeks. I think that's going to be a very focused approach. Now, if before, again, if I'm a sales guy, or if I'm a customer and I need a solution, Check Point probably has that solution amongst the 280 different technologies. Now it's extremely simple. If you want cloud, CloudGuard is the solution. If you want something about remote connectivity end user, Harmony is the solution.
That will work both in positioning it, in getting the technologies in it, by the way, also in the ability to sell it because some of these solutions are going to be much simpler to purchase, like one price for the entire suite and not having to deal with tons of different SKUs and sizing for the different elements. Of course, if you need a network solution, it's part of the Quantum family that still remains. By the way, has a huge potential in it for the main market. I think from a go-to market, this is a very good strategy. Add to that Infinity, that enables customer to get the full architecture. Again, Infinity is still small but is growing fast. Again, I think Tal mentioned, double the number of customers, double the contract value last year.
I mean, it's hitting on all the right things. Still a way to go, still a few years before all these three components will become a huge part of the business. I think we're now seeing that I mean, when we analyze our internal measures and everything in 2020 and in 2021, we're going to be very important for the growth. If they will be successful, we will see their impact on the overall business. I think overall it has good impact. I think everything that I've said now is not just for our sales force, it's for the partners, it's for everyone.
If you're a partner, you have a cloud issue, you don't know all the different few hundred vendors, dozens of solution, CloudGuard is a good solution. Quantum is a good solution. I mean, for connectivity and end user, good family for that. I think it will make things much simpler for everyone. For the again, I got feedback from customers that say, "Now, it's simple for me. Now I understand that I need that solution."
Tal, just very quickly for you, how should we see these efforts consolidating around these three product families show up in the financials? If you can give us just some finer points on how the revenue segmentation, and growth trends within the revenue segmentation should trend over 2021.
Shouldn't really change. Remember, things happen not the next day, right? The same thing, when you talk about the appliances, you're going to see it in the product line. When you talk about the subscription, it doesn't matter if it's a subscription that relates to the remote access or if it's subscription that relates to NGTP or NGFW or SandBlast. All of them are subscriptions, all of them will be in the subscription line, support is support.
Infinity is the only one, not the only one, the major one, that when you do a transaction of Infinity, it actually splits between the entire lines, some of it going to product, some of it going to support, some of it to subscription. A major part of it, probably more than 50%, going to the subscription line because it encapsulates everything that Check Point has to offer, hence majority of it going to subscription line.
Appreciate it, thank you so much.
Thank you, Fatima. Our next question comes from Brad Zelnick at Credit Suisse, followed by Sterling Auty at JP Morgan. Please try to keep to the one question at a time, going forward. Thank you.
Great. Thank you so much, Kip. Nice to see everybody, and congrats on a really strong Q4. Gil, as we think about SUNBURST and the future of other supply chain attacks, at the end of the day, don't they all rely on lateral movement across the network? If so, do you think this accelerates a broader shift to zero trust security models? Can you maybe speak about not only how Check Point succeeds in a zero trust world, but also the extent to which it might be a headwind to the core business?
I think first, you're absolutely right. These attacks underscore the importance of network segmentation, of zero trust, of all the network security capabilities that in the end are the main capabilities to stop an attack. We are in a world that things can get in some way. What we need to do is to stop them and contain them that they are there. Network security is the most effective one. We can't get to every workload in the world and every application in the world. We are trying, by the way.
We have plenty of technology and plenty of market space to secure many workloads, and we are doing that. At the end of the day, the main one is these network security capabilities that see the attack and stop it right there and contain it. I think that should provide us with an opportunity and more opportunity to our network security portfolio.
Okay, thank you. That's it for me.
All right, our next question is with Sterling Auty at JP Morgan, followed by Joel Fishbein from Truist Securities.
Yeah, thanks. Hi, guys. I wanted to return back to the go-to-market discussion. I'm wondering, the success that you've seen in the Americas channel, in particular in 2020, was there anything that you did differently or any learnings that you can now take and apply to both Europe and Asia?
I think we've seen good traction and good cooperation with channels in America, but I think it's the other way around. Asia, especially Europe, are working better with the channel, and I think in America, we can learn from the cooperation that we have in Europe. I think it's now unified under our head of worldwide channels, Frank, that you may have seen some exposure to him. I think we are trying to learn. Again, first, every region and every place can learn from others. I think Europe is the place where we have the best cooperation with the channel, the best joint go-to-market. There is a lot of cooperation that we can do, and do much more in the U.S. in getting to new customers, and so on. I think it's a little bit more challenging, actually, in the U.S. than in other places.
Thank you.
Our next call is going to be with Philip Winslow from Wells Fargo, followed by Ben Bollin at Cleveland Research.
Great, r hanks for taking my question. A question for Gil. When you compare SUNBURST to, let's say, prior attacks like NotPetya, some of the things we saw at Target years ago, what do you think the implications, or what's different this time, in your mind, versus those prior attacks that similarly were widespread or, in some cases, very focused on specific companies? What's different this time, what do you think the ramifications are?
I think first, with each attack, you learn new techniques, and the level of creativity that the attackers have is unbelievable, I'm saying it all the time. I'm meeting with our researchers and seeing the vulnerabilities that they find in applications, in infrastructure, in everything. It is truly unbelievable. Maybe one day we should do a seminar for you guys to show you some of what the researchers find. I meet with them every week or two, and every time, I'm getting shocked from the level of vulnerabilities that they find and the attacks that are being found. I think what's unique about SUNBURST is the fact that it was super professional. It hide itself very, very well. It was really hard to detect that.
I think, by the way, that we will never know the extent of the damage and the information that was stolen because we really saw that it got in, took a lot of stuff, and in some organizations, it stayed in. Many organizations, it simply erased itself and left almost no traces. With our researchers and all our incident response team, all the team that we have of very good security professionals, helped many customers, analyzed many environments, and almost left no traces. On the other hand, by the way, took something that was an internal attack. It actually started from within the core network of the company with SolarWinds and so on, and took Active Directory certificates and took cloud certificates and used them to penetrate the cloud from the outside.
The cloud actually, in many cases, remained vulnerable because, by the way, the cloud, in many cases, is not shielded as well with gateways and firewall like the core of the network, like the data center inside the network. SolarWinds, to that extent, SUNBURST will remain an attack that I think we'll hear a lot more about it in the future as more and more research will get published. So far, I think the world, not Check Point, the world in general doesn't know enough about that and who's behind it and what we've done, and I think that's the unique part. It was an attack that seems like a state-sponsored with all that sophistication, and especially with the fact that they left no traces and no information was leaked or disclosed, but found itself into the wrong hands, for sure.
I think we all would want to hear from your researchers on a webinar. I like that idea.
We'll schedule that.
All right. Thank you, Philip. Our next question is coming from Ben Bollin, followed by Shaul Eyal of Oppenheimer.
Good afternoon, good morning. Thank you for taking the question. Could you tell us a little bit about maybe the mix of revenue and/or billings attributable to cloud and SaaS subscriptions, in Q4 or for the year, and how this has developed over time? Then, as you get more of that revenue mix over time, take us through the impact on support and maintenance revenue. Thank you.
I'm not sure I understand what you mean when you say the mix. Can you elaborate a bit?
If you look at Infinity Dome9, could you take us through how much revenue you're generating from those products and how that's developed and then where that's going?
Okay. It's still not very big, but I'll just give you a sense. Cloud, when you say Dome9, it's part of the CloudGuard solution. You have mainly CloudGuard IaaS, which is Dome9 and our IaaS solution, and you have a CloudGuard SaaS. When I call it all together, the CloudGuard, it's over 10% of the subscription line already. It's already quite material, but not material enough to pull on the number up enough. That's a good trend because if it's growing in a double digit and a fast double digit, it's over 50% growth, then over time it will become bigger and bigger, and we will see that pulling all the numbers up. Cloud is a great success. Majority of it, if not all of it, is in the subscription line.
I think very small portion might be in product, but I think majority by far is in the subscription. When you talk about Infinity, it's smaller, maybe about half, just for a high-level size in the revenues already, which means already also becoming a significant low tens of millions in the revenues. It's no longer $1 million , $2 million , $3 million, it's already getting to a few low tens of millions. That's again, growing also quite fast. I gave an example that when we signed an Infinity Total Protection transaction, the annual contract value of the customer can grow in tens of percent or it can grow in hundreds of percent, depends what was his starting point. If he had very few solutions of Check Point and now he gets everything, it can grow in hundreds of percent.
If it already was a customer that was very well covered, then it can grow maybe in tens of percent. That's a wonderful opportunity. That dollars are showing up in three different lines because remember, it provide to the customer everything we have. He gets in that bucket, product, a budget for the year. He gets all the subscription solutions of Check Point, and he gets the support for the appliances. That actually appears in all of the lines, although still majority of it, probably over 50%, is in the subscription line.
Thanks, Ben. Our next question is from Shaul Eyal at Oppenheimer. Followed by Gray Powell at BTIG.
Thank you. Hi, good afternoon, guys. Gil, quick question on your threat intelligence capabilities. Are these homegrown solutions or are you partnering with some other companies, maybe some emerging startups, in Israel, outside of Israel? Just curious how do you approach threat intelligence?
First, in intelligence, you need to collect it from many sources, and that's something we learned. Our threat intelligence technology is our own. We have amazing capabilities for research, we are also cooperating and subscribing to many other services. I mean, some of it is cooperation, which is quite good. We're even, by the way, part of an organization that shares threat intelligence with our competitors, CTA, which is an organization that's an industry-wide organization between us and our direct competitors. We are subscribing to many other threat feeds from other companies, we are cooperating with few startups that are providing threat intelligence, even though I'm not sure that we have a direct link or a direct subscription to their feed. Still, the majority of the technology or most of our findings there is our own technology.
We have, by the way, plenty of sensors around the world that find plenty of things. That's the nice thing about it. For example, when we analyze files that are being sent all around the world and when we find a malicious file, immediately the file signature or the file characteristics that arise from that is added to the ThreatCloud for all customers, and that happens in real time. If I find one file in my mailbox, suddenly millions of Check Point customers are being protected in the same second. Not only that, by the way, it's not just knowing that this specific file is insecure. By the way, this is the unique thing about ThreatCloud. In our solution, one endpoint will find the signature, the same endpoints, other endpoints might stop that file.
Here, the file won't be downloaded on the web, the file won't pass through the network. We will have the ability to identify that everywhere. On top of that, we will extract from these files many other what's called IoCs. For example, if that malware communicates with a command and control server somewhere over the internet, we can take down that command and control or stop the communication to that command and control for all customers worldwide. I think that's the unique thing about our ThreatCloud and what's behind a lot of our threat intelligence.
Thank you.
Thank you, Shaul. Our next question is going to come from Gray Powell at BTIG, followed by Rob Owens of Piper Sandler.
Okay, great. Thanks for taking the question. This might sound like I'm getting a little bit into the weeds here, I'm actually looking for more of a high-level answer. If I just kind of run through the numbers, if I take current billings and I back out product revenue as sort of a proxy for annual subscription or annual recurring billings, the growth there really accelerated nicely in Q4, it was actually the best performance we've seen from Check Point in about three years. Can you just talk about the drivers there, either in terms of attached subscription or on the cloud side, just the overall sustainability of that trend?
Are you basically calculating your implied booking?
Yes.
Okay, just wanted to make sure I understand. You're right, the implied booking was high. I think in the short term, it was 10%, and the total implied was about 8%, so it's very high. We did have very good booking. We did have a very good implied booking. We had a good quarter. You know that because we're transitioning into cloud, into Infinity, then it takes time to see that translating into the P&L and into the revenues. Probably number one reason is that fact. We got a lot of Infinity and cloud transaction subscription in general. I gave a hint about the Infinity over $100 million booking. It's quite significant. Hopefully it will continue this trend of these drivers. If you remember, we defined the growth when we talked about what we need to do in order to grow over time.
We said it will take a while. The three main pillars are cloud, Infinity, and now we're talking also about remote access. Hopefully, that will start next year with the new plan that Gil presented. This is in line with our efforts to focus on those growth areas.
Got it. Okay, thank you very much.
Thank you. Kip?
We got Rob.
Sorry, we'll go to Rob Owens of Piper Sandler next, followed by Michael Turits at KeyBanc. Sorry, guys.
That's all right. Thank you, guys. As we contemplate kind of this shift towards more the remote user and potentially more user-centric models, does this potentially change the pricing dynamic for Check Point moving forward and then have TAM implications moving forward? Thanks.
I think we definitely grow the addressable market. I specifically didn't talk about that threat size because all the sizes about remote access and endpoint security are giant markets. I'm not attempting to take on all these markets and replace all these solutions there. We are focusing on the new world of connecting the mobile workforce, of connecting work from everywhere, work from anywhere, any way we want to call it, and securing that. Again, I think it's many, many different categories, and I think what we've found when we analyze the market trend is, A, this market that wasn't the top priority for customers shifted from mid or low priority into the top priority on customer mindset, and we have all the technologies. It's unbelievable.
I mean, when we looked at our portfolio, we found out that we have, let's say, more than a dozen solution that address all the elements. Now we need to take them, put them together. There's still work that we need to do. I'm not trying to say that it's trivial, it's not. I think what we have, what no other company Just remember, by the way, we completed another acquisition in that field in, I think it was September or October, the acquisition of Odo Security.
We were very, very active on that, and now it all came together and say, no, it doesn't need to be a dozen different solution, one point solution for every one point problem, but a unified one. I think it can change the whole thing, the pricing dynamics, the simplicity, everything around that, because we will make it very, very simple to acquire and to implement and mainly to get the security level.
Thank you.
Thanks, Rob. Appreciate it. Our next caller is Michael Turits with KeyBanc, followed by Saket Kalia from Barclays.
Thanks, Kip. Congrats Tal, Gil, and everybody. I just want to ask about product, which as you pointed out, was really strong, this year in turning, coming back to a positive. Was there a lag in people's abilities to refresh firewalls last year, and does that start to come back? If so, why wouldn't that provide a little bit more visibility into Q1, and potential for upside to revenue given the strong billings this quarter?
First, in terms of the product business, in many cases, we supply the products right away. Actually, where we have the deferred revenues and the predictability is more on all the other subscription-line products, we are usually very fast to supply them, even within the last few days of the quarter. As for last year, on one hand, we saw some increased demand for capacity. For example, in April and March, we saw companies pushing, for these specific customers, big orders to increase capacity on the network. On the other end, customers generally last year tried to avoid getting into the data center because we were all working from home, and we didn't want to touch anything physical unless it's absolutely necessary. I think last year was characterized by somewhat of a slowdown of everything that's physical.
Despite that, I think we turned from negative into positive, which means that it has potential. My belief, by the way, is that the market for network security and gateways and firewall has a huge potential. That's the main point, the most effective point to block this new cyber pandemic attacks. We really need that.
Thanks, Michael. Our next question is going to come from Saket Kalia from Barclays, followed by our last question from Brian Essex of Goldman Sachs. Go ahead, Saket.
Hey, great. Can you hear me okay, Kip?
Yes.
Okay, excellent. Thanks for taking my question here, guys, and fitting me in. Tal, maybe the question is for you. There was a nice little hint that you provided just on ITP bookings, I think, crossing $100 million this year. The question is, can you just talk about how big they were last year? Also touch on what's prompting customers to opt for ITP when buying network security versus buying that under sort of the traditional pricing model. Does that make sense?
Yeah, can you hear me?
Yeah.
Yeah, the first question I got, it grew significantly, over 100%. I don't remember the exact number, but it was a significant growth. The second part of the question, what was that?
The second question is, what do you think is prompting customers to go for ITP pricing versus buying firewall sort of in the traditional model?
I think first it starts before the pricing, it first starts with the need. When the customers understand what was Gil relating to, that as the world becomes complex and many customers need to adopt more and more solutions, it becomes very complicated to implement separate, disparate solutions for many different vendors in many different places with different management capabilities and so on. It first comes with the need of increasing your security while trying to keep it, maybe I would say, as simple as you can in a complicated world. The pricing is complementary to that, where it says you don't need now to negotiate with us 20 or 50 or 60 different features pricing, one of them based on user, one of them based on gateway, one of them based on throughput, 1% of the enterprise install base, and so on.
Here, you get one simple pricing. Tell me how many users you have, your price will be x numbers of dollars multiplied. Very simple, and you can basically go and install in your pace, hopefully fast, everything you need in the organization. I would think as a CTO, as a CSO, and as a CFO, everybody will prefer that, both from financial perspective and from simplicity perspective.
Very helpful, thanks.
Thanks, Saket. Our last question is coming from Brian Essex from Goldman Sachs. Let's see if he's. There he is.
All right, thank you for fitting me in. I really appreciate it. Gil, I just have a question for you. I wanted to hit on the competitive dynamics you're seeing in the market, particularly given the product cycles that you've had. You have R80, now R81, you've got Maestro, Quantum, Infinity. How much of that growth is in the install base, and where do you see share coming from? Is this a dynamic where we have just an installed base of existing customers that you can help them migrate to the next generation of threat prevention?
Do you see meaningful uptick from incremental customers on the platform, and where might those be coming from? Are we seeing, for example, shared ownership from larger legacy vendors like a Cisco or Juniper, or are these kind of head-to-head competitive new wins in the next-gen market? Just love a little bit of color, kind of around the competitive dynamics.
Sure. First, my priority has been for the last few years about getting new customers. Now, still the majority of our business, the vast majority, is coming from our installed base, both because these are the people that we switch, these are the people that like us. Also, we have a lot of enterprises that maybe, by the way, small customers now and are growing and becoming more major. Still, we have amazing set of competitive wins, and that's not just, by the way, against the older vendors in the marketplace, that's also against some of the other vendors in our marketplace. We have a lot of nice wins, a lot of competitive wins when the customers actually evaluate the product, actually see that they come up with a lot of technologies and being innovative and being cool, but at the end, they don't prevent the attacks.
Look at their instruction manual. They'll tell you, if you got infected by a threat, we will give you an alert after it happened, after it's in, and we recommend that you disconnect the network. That's taken from the instruction manual of our top competitor. By the way, some of it, by the way, is how the world understands the solution. Most of the solutions today in the marketplace are not deployed with the full threat prevention capabilities on and with the full prevention on. Which means that if we go to a customer and implement a product the right way, the product brings 10 times more value. It also, by the way, may be a little bit more complicated, may be a little bit more challenging to operate because it does the work. We replaced competitive product in some customers.
The customer complained that it was complicated, that it wasn't as fast. We looked what they've done with the competitive product, and they've basically done nothing. It's like going to a hospital with a serious heart condition. In one place, you're being operated and get all the treatment. In the other end, we give you an aspirin and hope that it helps. In many cases, when people use our competitors' products, they don't use them to the extent they even need to use them.
Not just the capabilities, it's how we use them. I think overall, we've seen all of that. We had a very, very nice competitive wins in the last quarter. Some of the biggest names, by the way, we've seen it in healthcare, we've seen it in hospital, we've seen it with companies that manufacture the COVID-19 vaccines. We've seen very nice competitive wins when we took over competitors and replaced them with solutions that actually provide prevention.
All right, that's super helpful. Thank you.
Thanks, Brian. Thank you all for joining us today. That's going to conclude our call. We'll look forward to speaking to you throughout the quarter. With that, I'll allow you guys to disconnect, and have a great day. Bye-bye.
Thank you very much.
Thank you, guys.