Greetings, welcome to the Check Point Software third quarter 2018 earnings conference call. At this time, all participants are in a listen-only mode. A brief question and answer session will follow the formal presentation. If anyone should require operator assistance during the conference, please press star zero on your telephone keypad. As a reminder, this conference is being recorded. It is now my pleasure to introduce your host, Kip Meintzer, Head of Global Investor Relations. Thank you. You may begin.
Thank you. I'd like to thank all of you for joining us today to discuss Check Point's third quarter 2018 financial results. Joining me today as always on the call are Gil Shwed, founder and CEO, along with our CFO, COO, Tal Payne. As a reminder, this call is webcast live on our website and is recorded for replay. To access the live webcast and replay information, please visit the company's website at checkpoint.com. For your convenience, the conference call replay will be made available through October 31st. If you'd like to reach us after the call, please contact investor relations by email at kip@checkpoint.com. Before we begin with management's presentation, I'd like to highlight the following. During the course of this presentation, Check Point representatives may make certain forward-looking statements.
These forward-looking statements within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934 include, but are not limited to, statements related to Check Point's expectations regarding business, financial performance and customers, the introduction of new products and programs, and the success of those products and programs, the environment for security threats and trends in the market, our strategy and focus areas, demand for our solutions, our expectations regarding the acquisition of Dome9 and its impact on our business and financial outlook, our business and financial outlook, including our guidance for Q4 2018. Because these statements pertain to future events, they are subject to various risks and uncertainties. Actual results could differ materially from Check Point's current expectations and beliefs.
Factors that could cause or contribute to such differences are contained in Check Point's earnings press release issued today, October 24, 2018, which is available on our website, and other factors and risks, including those discussed in Check Point's annual report on Form 20-F for the year ended December 31, 2017, which is on file with the Securities and Exchange Commission. Check Point assumes no obligation to update information concerning its expectations or beliefs, except as required by law. In our press release, which has been posted on our website, we present GAAP and non-GAAP results, along with the reconciliation of such results, as well as the reasons for our presentation of non-GAAP information. Now it's my pleasure to turn the call over to Tal Payne for a review of the financial results.
Thank you, Kip. Good morning and good afternoon to everyone joining us on the call today. I'm pleased to begin the review of the third quarter. Revenues for the third quarter increased by 4% year-over-year to $471 million, and our non-GAAP EPS grew by 6% to $1.38, both towards the high end of our guidance. Before I proceed further into the numbers, let me remind you that our GAAP financial results include stock-based compensation charges, amortization of acquired intangible assets, and acquisition-related expenses, as well as the related tax effects. Keep in mind that as applicable, non-GAAP information is presented excluding these items. Let's take a look at the financial highlights for the quarter. Product and security subscription revenues were $257 million. Our security subscription revenues continue to be strong with 13% growth year-over-year, reaching $136 million.
Our software update and maintenance revenues increased to $213 million, representing 4% growth year-over-year. Deferred revenues as of September 30, 2018, reached $1,148 million, a growth of $112 million or 11% over September 30, 2017. Revenue distribution by geography for the quarter was as follows: 47% of revenues came from Americas, 37% of revenues came from Europe, and the remaining 16% came from Asia Pacific, Japan, Middle East, and Africa region. From a deal size perspective, this quarter we had 58 customers with transactions over $1 million. This quarter, similar to last quarter, the total value of these transactions increased significantly. Non-GAAP operating margin for the quarter was 53%, similar to the previous quarter. We continue to invest in our sales force and marketing efforts. The full effect of these will be reflected naturally in the next quarters. Effective non-GAAP tax rates for this quarter was around 18%.
Our Q4 tax rate is expected to be lower at 10%-12%, related mainly to expiration of tax provisions at the end of the year. GAAP net income for the third quarter of 2018 was $198 million, or $1.25 per diluted share, an increase of 7% from the third quarter of 2017. Non-GAAP net income for the quarter was $219 million, or $1.38 per diluted share, an increase of 6% from the third quarter of 2017, and towards the top end of our guidance. As the share price increased significantly during the quarter, the number of options included in the diluted outstanding shares increased. Our cash balance continued to increase, reaching $4,072 million as of September 30. Operating cash flow was $249 million. Collection from customers continues to be strong. Our cash payments increased in line with our continued investment in sales and marketing.
In July 2018, we approved an increase of our buyback program to $2 billion. With quarterly amount that may vary but will not exceed $325 million. During the quarter, we purchased 2.6 million shares for $300 million at an average price of $113. Let's turn the call over for Gil for his comments.
Thank you, Tal, and hello everyone joining us today. In the first quarter, we continued to see results that are better than our projections. Overall, this is the second quarter we've seen improved trend in execution by our sales force. We continue to focus on further improvements to the sales organization and will continue to invest as we move forward. At the end of July, we made an important change in the leadership of our sales organization and appointed Dan Yerushalmi to be Chief Customer Officer. Dan has been not only a tremendous sales leader in his past, but also a CIO of a major bank in his last position, making his experience very relevant to C-level interaction. We continue to execute on our major initiatives, primarily around the Infinity Architecture.
A recurring trend in the feedback we hear from our customers is that Infinity represents a truly differentiated approach to security. Infinity accomplishes this by consolidating security and providing a universal platform encompassing the network, mobile, and across the cloud with a focus on the prevention of cyber attacks rather than merely detecting them after the fact. The pipeline for Infinity deals continues to build. During the quarter, we closed some nice deals in a variety of industries, from mid-size law firms and non-profit organizations, all the way up to some of the world's largest financial institutions. We've continued to build the breadth and depth of the Infinity platform. This quarter, we expanded our mobile security offerings, introducing advanced threat prevention capabilities to mobile devices with the launch of SandBlast Mobile 3.0.
This makes our product unique by preventing mobile phishing attack on all apps, prevents browsing to malicious sites, and blocks infected devices from leaking sensitive data to botnets or accessing corporate data. On the cloud front, we just went GA last quarter and launched our CloudGuard SaaS security solution to address security needs of Software as a Service cloud application, such as Office 365, Salesforce, and ServiceNow. With an entire industry of solution for SaaS security called CASB, where the focus is mainly on detecting the use of such cloud application and a little bit on user identification. CloudGuard SaaS is much more than a CASB. It focuses on actually preventing malicious access, blocking malicious content within SaaS application, while also providing transparent and reliable user identification. We already have more than 100 enterprises that have begun to utilize CloudGuard SaaS.
Today, we announced the further expansion of our cloud security offering with the acquisition of Dome9. The acquisition bolsters our Infinity platform by expanding the breadth of our cloud security offering. One of the key challenges in public cloud environment is to ensure the enforcement of corporate security policies across all elements of the cloud infrastructure. Dome9 addresses exactly that challenge. It enforces the corporate security policies and manages all cloud assets accordingly. It makes certain that all cloud servers are protected. It verifies that cloud apps have the right security setting and manage the native cloud security features of AWS, Azure, and the Google Cloud. It does so while providing compliance with security best practices and company-specific guidelines. These technologies also provide a broader market potential for us.
With the ability to address non-Check Point environments by leveraging these technologies as a cloud service without the need for any on-premise software or hardware. Dome9 aligns with our strategy to drive prevention and protection across the network, mobile, and cloud environment. Check Point is known for management capabilities, and Dome9 enable us to extend our superior management capabilities further into a cloud-centric environment. The combination of Dome9 together with our CloudGuard SaaS and SandBlast product families will enable us to expand our cloud security capabilities and provide multiple layers of security to cloud environment. This will be accomplished with further automation and scaling tools that are critical in the cloud. We evaluated many other technologies in this space and found Dome9 to be the most comprehensive.
The one that delivers on the Check Point principles on enforcing security and providing true threat prevention rather than just detection and reporting, like many of the other products we evaluated. The acquisition closed today. While we don't disclose the full terms of the transaction, the main effect you're going to see in our financial results in the next quarter will be in cash consideration of approximately $175 million, that will be part of our Q4 cash flow. It will not have material effect on revenues and will reduce our non-GAAP EPS by approximately $0.02-$0.04 a quarter, and our GAAP EPS by approximately $0.07. We would like to share our fourth quarter projection. Overall, the third quarter produced good results.
I do believe that our growth potential is higher than what we have seen in the past few quarters, and we will continue to work on making that happen. You know my regular caveat, the future is always hard to predict. There may be an upside and obviously the potential for a downside. With that in mind, here are the fourth quarter projection that include the effect of the acquisition. We expect revenues between $500 million and $528 million. Non-GAAP EPS in the range of $1.56 to $1.67. GAAP EPS is expected to be approximately $0.20 lower than that. I'd like to open the call for your insightful question and feedback on our strategy. Thank you.
Thank you. If you would like to ask a question, please press star one on your telephone keypad. A confirmation tone will indicate your line is in the question queue. You may press star two if you would like to remove your question from the queue. For participants using speaker equipment, it may be necessary to pick up your handset before pressing the star keys. Please ask one question and then re-queue in for additional questions. Our first question is from Brad Zelnick with Credit Suisse. Please proceed with your question.
Thanks very much, Brad Zelnick, Credit Suisse. Congratulations, guys, on a nice quarter. It's good to see billings growth back in the business and returning to market levels, and congrats on Dome9. Gil, on Dome9, can you just talk a bit about why now and as you think about integrating the offering into your management console, do you envision that this is going to be something seamless a year from now that we won't even notice was a separate entity, and what does that take? Then I've got a follow-up for Tal. Thanks.
First, I think now is a very good time to invest in the cloud, use of cloud application is getting higher and higher. I don't know if it's getting to mainstream, definitely almost every enterprise in the world is expanding to the cloud, when they do that, they also tighten up security, I think security is becoming more important to them. We've been working and looking at Dome9 for a long time, this is not something that happened overnight, that's something that we've been doing for quite a long time. I think the Dome9 capabilities are far better than anything else in the marketplace. We're the only company in the space to have active protection, network security, threat detection, and better capabilities in compliance in multi-cloud environment than everything else we've seen. We are very happy to be working with them.
We've passed on several other companies that we look a long time, I think we're very fortunate that we've been able to pull this deal through. Hopefully we will be able to integrate it quite quickly. All the Dome9 employees are now part of Check Point. The deal is closed, we are ready to act right now, it will probably take us a couple of months to integrate all the different departments and all the employees and provide the true Infinity cyber protection for Gen V attacks and strengthening the cloud, which I think is more and more important.
Thanks, Gil. Just, Tal, in following up on the financial impact, I trust it's all subscription revenue. Can you just confirm for us, were these annual subscriptions paid in advance? Does it flow through to the balance sheet or just directly to the income statement on a consumption basis? Is it fair to say that the business was doing roughly $25 million run rate? Anything else that you can tell us to appreciate the impact would be great.
No, the run rate is not 25, it's less than 10. Just to clarify, that's why we said it's immaterial, so you won't see an impact that is relevant from the revenue perspective in our size of company. That's one comment. The effect that we talked about is relevant mainly as a result of expenses. We continue to invest in the company as well. It's a very exciting area. That's why the numbers, the range that we talked about is $0.02-$0.04 on a non-GAAP and about $0.07 on the GAAP.
Got it. The $0.02-$0.04, that's helpful. Tal, $0.02-$0.04, I mean, were they burning that much cash, or do you intend to invest that much more in integrating the business?
No, they have over 100 employees. They are spending cash, and it's an area that we would probably plan to expand as well.
Awesome. Thanks so much for taking my questions.
Our next question is from Michael Turits with Raymond James. Please proceed.
First, Gil and Tal, can you talk about Dan Yerushalmi and what any changes might be in the strategic direction for what he'll be doing around sales, how you'll be improving, and again, obviously, how that's changed. Then I'll just throw out my second question, too. There are a lot of things taking place at a macro level in the world, obviously. To any extent, you feel like you can look out to 2019, talk about how tariffs might impact you and any impact that other macro trends might have on security spending right now. Dan, and then macro.
Okay. First, in terms of the sales strategy, I think our sales strategy is the right strategy, and our strategy is not something that we change very often. I think the main challenges that we have, or the main opportunities that we have, depending how you want to look at it, is execution. We are focused on new customers. We are focused on broader sale of our Infinity Architecture, getting higher level in the C-level in the organization. Dan is putting a lot of emphasis on better working with our partners to bring the products to market. I think all these things that have been part of our strategy will continue, and hopefully, we will do them in a better way. I don't think that there is a huge change in strategy. I hope that there's going to be a change in the execution of the strategy.
Second part?
The second part was relating to macro changes. In what area? Can you repeat the question?
We just had bad semiconductor report tonight. People are concerned about tariffs. In general macro concern about next year and potential impact on tariffs. How do you think that, if it does impact you guys specifically, and anything you could say about the impact on the security market?
When you talk about tariffs, it's nothing that we expect that will affect us. In the macroeconomics, I would just say the general changes that you're familiar with the tax regulations in Europe and the tax regulation in the U.S., we're still waiting for the regulation to come out during Q4. Based on that, we will see what do we believe is the effect on us.
Okay, guys. Thank you very much.
Our next question is from John DiFucci with Jefferies. Please proceed with your question.
Yes. I have a question for Gil and a follow-up for Tal. Gil, for Dome9, I'm just trying to, in my mind anyway, figure out now what you have versus what you might need. I read something that Dome9 even has some identity technology. Is there anything here that, in the cloud area that you don't have, that you'd have to partner with others or that you wouldn't go into? Normally, you haven't gone into the identity space either.
I think we're not going to be a provider of pure identity software. We're going to connect that identity into making sure systems are locked. That's what we've been doing. By the way, we've started that also in CloudGuard SaaS, our solution for SaaS. We will be having a little bit more of that in Dome9. That's not our focus. There are going to be more areas in the cloud that we will get into. The cloud is a very broad environment, there is much more layers and specific areas which we can secure in both of our Gen V and next year, our sixth generation of security will also focus on that. Dome9 is not just a feature.
Dome9, I think is a platform that's very strategic to us because it does know how to manage security and enforce security in very large and very complicated and very heterogeneous cloud environments. That's critical because the cloud is not one entity that's simple to manage. Actually, if you look at the AWS cloud, there's probably around 300 different services. When you activate any service, you want to make sure that automatically the security is applied to that service. Otherwise, that service becomes unintentionally the backdoor to the company, to the enterprise data. I think that's part of what Dome9 has, a lot of automation to automatically set security policies on all the clouds, automatic detection when things go wrong, and automatic remediation, which is even more important.
Think about that, if some operator tries to do some maintenance to, let's say, a storage server on the cloud, they leave something open, they go home. Tomorrow morning, you might get an alert that you left your data open, but that's too late. During the night, somebody might have sucked all your database. Somebody that's using Dome9, for example, automatically, these permissions will be reset to the locked permissions. Whether you see the alert or not, it should be in a good state. This is one example of what Dome9 can do that nobody else in that industry is doing right now.
Okay. Thank you. Tal, the results were better than we had been looking for anyway. The subscription growth actually accelerated a little bit, about the same growth. The product numbers are still coming down year-over-year. I'm just curious, is that more to do with sort of a transition to, within the sales to sort of push more the platform sales, the Infinity Total Protection type sales, like the selling motion? Is it just customers are buying more subscription at this point, and ITP is exciting, but it's still really early?
That's our saying, general, when you look long term, it's obvious that the industry is an industry is moving to providing new product as a subscription. All the relevant product that we present, basically since 2010, is subscription mode, all the additional layers. Cloud is subscription. Dome9 is subscription. It's clear that the new area, mobile, is subscription and so on. Most of the new things are subscription. Having said that, product can and should be positive, that's why we're talking about continued improvement on the execution of the field.
Okay. We should hope or expect to start to see product, not only beat numbers, but actually turn positive at some point.
That's our goal, definitely.
Okay. Great. Thank you very much.
Our next question is from Andrew Nowinski with Piper Jaffray. Please proceed.
All right. Thank you, and congrats on another good quarter. Maybe just starting with the Americas. Growth was strong, I think up 8% this quarter, which I think you hinted at last quarter as well. Is that a reflection of share gains, or is that a seasonal contribution from the Fed, U.S. Fed, or just an overall improvement in the market that drove that growth?
Remember that revenues and bookings are not always in the same timing, right? Revenues are a recognition over a period, it's not necessarily you have accounting movement, VSOE, and so on. In general, you're right. You see in the America, positive, and Europe positive, EMEA had a few large deals in the previous quarter in terms of revenue recognition, you see it actually in, I think in a small negative. It's not necessarily a mirror of the bookings.
I would say that I think we did have some slightly better metrics in the U.S., and I'm very happy about that because we are focused on gaining share, on doing more things in the U.S., but we are far from over. I think our potential and what we can and should do in the U.S. should be much better than what we are doing, and there is still a long road until I'll be here and say, "We are getting everything that we need to from the U.S.
Very good. Just one quick question. Your long-term deferred looks like it went up a little bit this quarter, and your duration also went up. Is that just a factor, or is that attributable to the Infinity sales plan as more customers move to that sales model?
Not necessarily. Of course, Infinity has been affecting the long term, but it's still not a big number that will affect it in that way. Remember, the long term can be just an effect of a support or subscription contract that's signed for over a year, and then the over a year portion, in case it was invoiced, then you see it in the deferred long term. Also short term was very healthy with a growth, if I recall, of about 9% year-over-year. That was quite healthy as well. Remember also that some of the bookings you don't even see because it's accumulated un-invoiced, because some of the long-term deals, you issue an invoice only once a year, and that portion is not reflected in the deferred revenue.
Okay, got it. Keep up the good work.
Our next question is from Daniel Ives with Wedbush Securities. Please proceed with your question.
Yeah. Hey, how are you? Congrats again. Can you maybe just talk about Infinity, just in terms of what you're seeing in the field, in terms of how maybe the conversations are changing from kicking the tires to actually deal flow? I'll just stop there and then a follow-up question.
I think first, Infinity does raise the conversation to not just product transaction, but how people actually think about security architecture. In my mind, by the way, that's one of the key elements in building today's cybersecurity, because it's not refreshing that product or adding another product. It's the overall thinking about how to prevent threats. That gives us much better opportunity to present our vision and to challenge our customers, and they challenge us about actually delivering that. I think Infinity so far is generating a very nice pipeline. We're still closing only a small number of deals because it takes a very long time for a company to make a decision about a long-term commitment and about change of an architecture. We are seeing that change is starting to happen, and as I've mentioned, it goes from mid-size.
Last quarter, we even had some small size. This quarter, it's more mid-size, going all the way to very large corporations that are willing to subscribe to that and see the potential in that. I think long term, it should have a very good effect, both on our, what we call Infinity sales, Infinity Total Protection, but also on the general dialogue and opening doors with customers that might lead to other product deals that extend our footprint within a customer environment.
Okay. Just lastly, how do you view the cloud opportunity? You're a veteran of security, and you've seen all different phases and facets. How would you compare this maybe over the last decade versus other opportunities that some bore fruit, others didn't, in terms of this cloud and how real this opportunity is and how Check Point's positioned? Thanks.
I think first, predicting the future is always challenging, but I do think that the cloud is more real than other things we've seen, simply because enterprises are. We see that unlike many trends in IT, that some happened, some didn't happen, some remained very small. The cloud is already substantial. Every company in the world is expressing interest in moving systems to the cloud. There is a new generation of companies that's called born in the cloud, that only have cloud environments, and I think all these are potential. What will happen in 5, 10 years, it's really hard to predict. It's really hard to predict if cloud sales will be a small percentage of the market, but still relevant, or the majority of the market. I think we'll know that in 10 years. For us, meanwhile, I think it's a quite substantial opportunity to get into.
Thanks.
Our next question is from Ken Talanian with Evercore ISI. Please proceed.
Hi, thanks for taking the question. I was wondering if you could give us a sense for how the deferred growth was driven between either subscription or maintenance. Just trying to get a sense for what's driving that uptick.
Naturally, the deferred revenue, most of it's relating to, as you said, subscription and support. I would say both been healthy and pretty much in line with what you see in the P&L. We had a very good booking in subscription as well. I would say nothing abnormal. They both grew, and they grew nicely. Naturally, when you talk about double-digit growth, subscription is the only one that can do that. Support is typically single digit, low single digit. You can see it in the P&L, since it's a renewal of your install base support. Majority of the growth is driven by subscription.
Great. I guess around the Infinity deals, could you give us a sense for the kind of uplift you might be seeing in some of the initial deals versus the prior run rate for some of these customers?
I think it's anything from 30%-200%, depending on the customer and depending on how big they were and how much they are getting into that in the future. I think that's the range that we've seen. It's a wide range, in general, it's a quite substantial increase per customer.
Remember, it depends on what the customer had to start with, right? If it's a new customer, obviously all of it is an uplift. If it's a customer that had only, let's say, firewall, and now we added the entire family, it will be a very significant increase. If we already had before, let's say, NGTX and threat prevention and threat extraction, then the lift will be smaller.
Great. Thank you very much.
Our next question is from Gabriela Borges with Goldman Sachs. Please proceed.
Thanks for taking my question. Tal, you commented last quarter on off-balance sheet bookings activity being particularly strong. I know it's not something that you regularly comment on, I wanted to ask the follow-up, which is, how did that bookings activity compare this quarter versus last quarter for deals that may not necessarily show up in the balance sheet?
Again, we don't report it. Just so it doesn't look like I'm avoiding, I can tell you it's increased this quarter as well, but it's not an indication that I'm going to give, just because remember, it can be very lumpy and depends on large transactions that are coming in that can be multi-year. If you look at the deferred revenues, you can see the growth there. I think it's a reflection of the run rate, which is better than just the fluctuations in the booking.
That's helpful. A question for Gil, if I may. Earlier comment on how it does take time to close Infinity Total Protection deals because it requires a change of architecture of the customer. For your customers that are coming back to you and saying, "Thanks for presenting. It's really interesting, but we're not interested right now. We're going to buy on the old model," what are the reasons that they give you for that?
I don't know if that's the typical discussion with you. The typical discussion, for us, one of the challenges, is actually how to go higher in the organization and to present to people that see the broader picture in that regard. That's the opportunity with Infinity. I don't see many places that customers say, "We're not interested." They might say, "This is a project for next year. We are right now not evaluating big changes, but this is good." In general, almost everything that I heard with customer was either, yes, we are getting on, let's start the process or continue the process or let's evaluate and let's see how it would make sense to us. I think the real challenge for us is simply presenting it to enough customers.
When I'm presenting, the feedback that I'm getting from customers that say, "This is revolutionary." This is all, by the way, feedback that I got from a group of customers that spent a week with us here last week, a customer delegation like that. Their feedback was, "It's fresh, it's new. Nobody else is doing that. The focus on prevention is unique to you." This is all good feedback. Unfortunately, it's from a very small list of customers that we're actually presenting it. That's why I'm saying that in terms of our execution, we need to learn how to take it to more places, then we need to translate that interest level and that acknowledgment on the strategy to actual deals.
That's very helpful. Thank you.
Our next question is from Walter Pritchard with Citi. Please proceed.
Hi, thanks. Question for Gil. Just on product revenue, I'm wondering if there's areas of the world or territories within the world that are doing consistently better than the down eight or six that you've had the last couple of quarters. I'm wondering what might be different about those areas as leading indicators of how your product revenue could get better as we look into future quarters.
First, I think it's very non-uniform. We have areas in the world or countries that are performing quite well for, if I take eight quarters, the six out of eight, they show great metrics, and they might have one quarter that's lagging behind and vice versa. It's not that results are uniform. As I said, when I look at some of these territories, the main element is field execution, is focusing on new deals and on new customers. I think that's one of the things we need to expand and do better in our culture, is how to approach more new customers and not just base our relationship about the existing customers with the existing relations with the existing customers.
As a follow-up to that, just from a feet on the street perspective, if I look at sort of where your peers are spending, it just seems like spending quite a bit more from a sales and marketing perspective. I'm wondering, is there a notion that just more feet need to go on the street, or is it an efficiency or retargeting the folks that you already have in the organization? Thanks.
I think it's both. I always believe that the way to work is work efficiently and work smart, if you build the right engine, it will have amazing results. My focus is on that. Still, I think we're going to add more feet in the street because there is more potential, because that will allow us to access more opportunities and more segments. We will do both, and I think we'll keep doing that in a responsible manner.
Great. Thank you.
Our next question is from Philip Winslow with Wells Fargo. Please proceed.
Hey. Thanks for taking my question. Just wanted to get some color on the pricing environment that you're seeing. During the second half here, anything that you note change-wise, whether it be just from competitors on, let's call it the base product, or maybe the added subscriptions, just general color on competitive environment and pricing.
I think the environment is quite competitive. There is price pressure. We have few competitors that their focus is on low price, and when they come to a deal, the prices are going down. We have others that are focusing on other attributes. The market remains competitive. I haven't seen that it became more competitive in the last quarter, to put it in that perspective. Tal, anything?
Yeah, no. Typically, when you're in a transaction that is large and many competition, that you see many competitors and a large bid, then you see more competition, naturally. Remember that product discounts different from subscription, different from support, it can vary, depends also on the mix on a specific order.
Got it. Then just one follow-up for Gil from a previous question about the cloud. If you believe that the world is going to be hybrid going forward, and that you're going to see workloads both on-premise and in the cloud, could you talk about just from a, I call it a policy and management, and sort of like the operation side of security, what you guys discussed about sort of having a single pane across both cloud and on-premise versus, let's say, using Check Point on-premise and then, let's say, just a native product and call it a cloud vendor and having to maintain two policies. What is your thought process? What are you hearing from customers on that?
Absolutely. That's an excellent question. First, I think customers are more and more aware. Took two, three years back, their whole security thinking was very siloed. Customers more and more understand that the role of the CISO needs to be on overall security policy management, on overall security policy enforcement, and that's a new trend. Again, new, which happened in the last maybe one or two years, but something that is changing in the world. In terms of managing the cloud, you're absolutely right. There is a hybrid environment almost everywhere. Today, we do have that advantage that from our SmartCenter console, we can manage our CloudGuard IaaS and have uniform management of whether your instance is a physical appliance or a virtual security gateway in the cloud. Dome9 addresses exactly that.
Dome9 is exactly getting to the point of how do I manage multi-cloud. Our motivation here is to incorporate that into the Infinity Architecture and give the customer a single pane of glass. It's not just a single pane of glass, it's really the uniform thinking about I can know what's in the cloud is very important, to know what are your assets, to know what is changing, to automatically provision thing, and most importantly, to enforce that policy everywhere. I think that's exactly the value of Dome9, and that's why we liked them, and that's why it's worth for us doing that kind of deal.
Great. Thanks, guys.
Our next question is from Sterling Auty with J.P. Morgan. Please proceed.
Thanks. Hi, guys. Clear you saw a really good step-up in execution in North America, but it's actually the first quarter that Europe has slowed down underneath the growth of North America. Anything in particular that maybe caused some deceleration in Europe?
I think Tal indicated already that the revenues and the business trend that we're seeing underneath don't always correlate, and Europe is actually doing quite fine, and we're pretty happy with the performance of Europe at this point.
Okay. Gil, one trend that we're obviously seeing is the number of vendors in security plays into EDR, the endpoint detection response, and use of machine language to ingest a lot of data and go out and either threat seek, threat hunt to protect their customers. I'm curious that now you're making with the Dome9 investment, is this another area that you think you're going to need to have a presence in, either through organic development or through acquisition?
First, I think that we do have some presence in that. Our SandBlast Agent for the endpoint does have many of these capabilities and does have amazing capabilities of EDR. I think that the strategy on that looking forward is quite challenging, not because there's no technologies around and not because we don't have good capabilities. Actually, there was just a test now, when we rated very, very high, far better than many vendors, both traditional vendors and new vendors, in terms of our endpoint security capabilities, and especially these new ones. We got, I don't remember what was the score, but again, it was one of the highest in the industry. The challenge for me strategically, I'll share it openly, the endpoint market itself is very fragmented. There are very large, well-established vendors.
There are many tiny startups, there are even companies now in the middle, in the $hundreds of millions of revenues that are mid-size companies but are quite sizable in the high tech world. The question is how to play in that game. Can any vendor just have an endpoint that's good and get a real important market share in that? I think I do have few ideas. I won't share all the idea. I'll share the challenge and the strategic thinking. In terms of ideas, yes, we have a product, and I think it's a great product. We can also acquire more technologies, and there are a few interesting technology that I've seen around. It's really unclear to me what's the right play in that market and what's the right way to provide that overall security.
Currently, I must say we're the only vendor that has everything connected. The cloud, the endpoint, the mobile, the data center, the network, all connected in one platform. We do have it now, and we do have customers that are using it.
Thank you, Gil.
Our next question is from Jonathan Ho with William Blair. Please proceed.
Hi. Good morning. I just wanted to maybe start out with the sales and marketing investments that you talked about. Can you maybe give us a sense of magnitude and maybe where you're making those investments, in terms of what the sales force is asking for?
I think the investments are quite uniform and around the world. Let's take an example. This quarter, we had 20 local conferences, which we call CPX. We have three big CPXs, regional, in Europe, in the Americas, and in Asia. At the beginning of the year, we call it CPX 360. We roll it into a local program of local conferences. This quarter, we had 20 of them in cities all around the world. This quarter was actually more focused on North America. Again, we had a huge one in Singapore, and actually just this week, we had a big one in Russia. It is all over, and I think the potential is all over. In terms of sales investment, again, the potential is all over the world.
There is a big potential, again, in the U.S. I don't think that I can say that there is one area that is more important than the other. In marketing expenses, there are spend on everything, on trade shows, on conference and so on. In sales, the biggest investment is simply headcount. That's the number one driving, and that's, by the way, most of the spend that we have on sales and marketing.
Got it. Just as a follow-up, can you talk a little bit about whether you're seeing an impact from SSL traffic increases, either drive people to purchase larger boxes or potentially on installed base renewals, drive any type of upsell?
Okay. That's an excellent one. I think technically SSL is a very challenging thing because more traffic is moving to SSL and we need to inspect it, and that requires much more horsepower. Yes, we are seeing more demand for more performance and more computing power. By the way, we came last quarter with a new model called the 23900, a high-end model, and that's exactly its positioning. With more SSL traffic, you need more power to do more threat prevention. Actually, it's going quite well in that regard. I do believe, by the way, that the biggest differentiator is not just speeds. Our SSL, our new capabilities in our latest version of our R80.20 on SSL are far better than the competition. Everybody is claiming to have SSL inspection.
We will show soon how we are doing the checks in a much more rigid way and in a way that doesn't let anything go unlocked, when if you're a malware developer, you can easily develop an SSL malware that will bypass other companies' SSL simply because they say, "Yes, we have SSL." It's easy to bypass for SSL security. These are things that we'll actually discussed in the last few weeks here internally, that we can show the value of what we do. By the way, I'm amazed at every technology review that I'm doing to our people, that they're working on the right stuff, we are providing the right security, and sometimes I'm simply puzzled to see that a lot of the competition is very negligent on the level of security that they provide, and SSL was a perfect example from last week.
Thank you.
Our next question is from Erik Suppiger with JMP Securities. Please proceed.
Yeah. Two questions on Dome9. First off, I think Dome9 was used in a lot of environments where they were not using a third-party firewall, be it Check Point or anybody else. Is the strategy here to get into environments that are not using firewalls, or is the strategy to leverage Dome9 to bring Check Point into those environments, and integrate Check Point into the broader security profile? Secondly, do you have any incentives to keep the management of Dome9, as part of the terms of the agreement?
I'll start with the second one. It's easy, yes. I think, by the way, in all the recent acquisition that we've done, we've put incentives for management to stay, and as far as I can say, they did stay. Unlike what we see in the industry and what I've seen in our historical past many years ago, here in the last few acquisitions that we've done, the management stayed three, four years, and it's working well. That's for the second part. For the first part, I think you're right about the need for Dome9. I think that we are able to get into environments that haven't been using advanced security like, our CloudGuard IaaS or other gateways. Dome9 clearly lets us get into that environment and provide your management. If you're not a Check Point customer, the value is there.
If you're a Check Point customer, it's easy to see why you have tools to manage your network security. Right now, you need to have similar tools for the cloud. Dome9 should be an easy decision to expand your control. Once you have that, it's very easy to see with the visibility tools that here I'm using, let's say, level 1 security, I want to go to level 5. We can provide also the level 5 or the Gen V security with our advanced threat capabilities. I think we need to start from securing the environment when the cloud is getting, and it is out of control in most enterprises today.
Very good. Thank you.
Our next question is from Fatima Boolani. Please proceed with your question.
Good morning. Thank you for taking the questions. Tal, maybe to start with you, I wanted to follow up on your comments around product growth and your confidence that going forward, this could and should stabilize and in fact, grow. Beyond focusing your execution and continuing to improve your execution, are there fundamental aspects that you see that maybe we don't, that is underpinning your confidence, in the form of maybe better appliance shipments than we can see or a better refresh opportunity within your install base that we could see? A follow-up for Gil, if I may.
Yeah. Actually, I didn't say that, just to clarify. I said that when you look in the long run, the more technologies you have that are subscription and virtual and cloud and mobile, actually you will see less product. I think in the long term, there is a trend that is clear that everything, or majority, is moving to subscription. Even when you look at Infinity, the more people will buy Infinity, the more portion of the deal is going to subscription and support, and less on the product, because the entire bundle has much more layers of service-orientated portions versus the appliance and the product. Long term, I actually think it's not.
I was talking in the short term that once we continue and see the improvements and you can start to see the improvement on the execution, I want to see also a growth in the product. Long run, I don't know whether the industry will go there.
All right. Fair enough. Gil, just as a segue, just off that point, as Check Point endeavors to become essentially a security-as-a-service provider, with Infinity Total Protection, what implications does that have, from how you manage and build out your infrastructure? Because the onus of SLAs and delivery of the security service would be from you instead of the appliance that the customer would have to buy to enjoy the security subscription.
Some of the things we're doing and some of the future architectures that we'll be speaking about will be like that, where we provide more and more cloud services. We have been doing that for quite a few years on several areas, and we will expand that, like our sandboxing and threat emulation is done mostly on our cloud, and we've been doing it quite effectively. I think that's an area that we're building and growing and learning, and so far, it's working well. I believe that we are serving almost 7,000 customers today with security capabilities that we supply from the cloud. Today, it's in hybrid environment. Eventually, some of this might become not hybrid, but full cloud. For the foreseeable future, it will all be in a hybrid environment in that regard.
That's very helpful. Thank you.
Ladies and gentlemen, we have reached the end of our question and answer session. I would like to turn the floor back over to management for closing comments.
Thank you guys for joining us today. We'll be looking forward to seeing you during the quarter. Also, if you'd like to have a call back today, pop me an email and we'll get you in the queue. Thanks, and have a great day. Bye-bye.
Ladies and gentlemen, thank you for your participation. This does conclude today's teleconference. You may disconnect your lines and have a wonderful day.