Fortinet, Inc. (FTNT)
NASDAQ: FTNT · Real-Time Price · USD
178.76
+2.80 (1.59%)
At close: Sep 30, 2026, 4:00 PM EDT
177.74
-1.02 (-0.57%)
Pre-market: Oct 1, 2026, 7:55 AM EDT
← View all transcripts

Investor & Analyst Day 2020

Nov 18, 2019

Peter Salkowski
VP of Investor Relations, Fortinet

Quiet, it's like church all of a sudden. Scary. Hope you enjoyed the video there. I did notice, I think one of the slides wasn't completely up to date, as the stock has moved a lot since I made that slide. Anyway, quick logistics so we're all on the same page before I bring up the speakers. Just want to let you know the timing. We'll start now. At about 11:15, we'll do a Q&A session after Ken and John speak. For about 15 minutes, we're going to try to do a brief one there, and then we'll do a 30-minute Q&A at the end, after Keith's presentation. Couple of logistics things. If that wall does come down, which we talked about doing, there will be a door open to get to the restrooms, which are right behind us.

Secondly, we're going to do a lunch in this room, starting at 1:00. It'll be a box lunch, we'll just have it in the back. We will also be handing out gifts as you leave. If you do depart, please grab the Fortinet swag, as we like to call it, on your way out. Obligatory safe harbor statement. I'd like to remind everyone that we are making forward-looking statements today during the presentation. These forward-looking statements are subject to risks and uncertainties that could cause actual results to differ materially from those projected in these statements.

Please refer to our SEC filings, and particularly the risk factors in our most recent Form 10-K and Form 10-Q, and to other reports that we may file from time to time with the SEC for additional information on factors that may cause actual results to differ materially from our recent or current expectations. All forward-looking statements are our opinions only as of the date of this presentation today, and we undertake no obligation and specifically disclaim any obligation to update forward-looking statements. That was for my legal group, who's in the back somewhere. Also of note, logistically, these slides will be posted after the presentation this afternoon. You don't need to take pictures and try to memorize everything that we show today, because they will be posted immediately following the presentation. With that, I'd like to invite up Ken Xie, Founder and CEO of Fortinet.

By the way, if you weren't aware, we did celebrate our 10-year anniversary this morning as a publicly traded company by opening the bell on the Nasdaq. Today is the actual anniversary date. Ken.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Thank you, Peter, and welcome. Thank you for joining us. I will go through the industry overview and company vision quick with John together, and then we'll do a quick Q&A. First, a lot of talking about what's the refresh, what's happening in the industry. You see network security in over 90% deployed in the hardware base, which they need to install the whatever software or the server into a system. After five, six, seven years, that will be too slow or old and need to be refreshed. The last time refresh happened about six, seven years ago, starting 2012, 2013.

That's where the first generation network security firewall, which is traditional connection-based, whether the NAT or whatever, is being replaced by we call the second generation, next generation firewall or UTM, which can look inside connection, look inside the content, detect the intrusion, detect the virus, the web content. That's where today probably most firewall deployed in a border already been the second generation firewall, compared to my previous company, NetScreen, which almost 20 years ago is a first generation firewall, VPN, which are connection based. Today, also we're starting facing similar issue after six, seven years. This firewall still got at the border. They're starting get slower and old, need to be replaced. What happened this time is different than the last few times refresh.

The reason, really, there's a lot of mobile device, lot application move to the cloud, and also some other, like IoT, some other things happening in the industry. This time, the border's still there, but got weakened. A lot of security issue come from inside the company. Majority actually come from inside the company now. A lot of data go to the cloud, go to the IoT device. This time, the traditional border security having the last two generation still there, but they are not increased a lot. That's where you see if the company still using the traditional way to develop the firewall or network security device. Their growth rather flat. They are not seeing much growth.

Overall market still grow over 10%, because they starting expanding inside the company through the internal segmentation, or we call Security-driven Networking. They also starting expanding to the WAN, like SD-WAN. Actually, 10 years ago, we also developed the Wi-Fi security, which FortiGate also is a Wi-Fi controller. 10 years ago, probably internal Wi-Fi, they all view internal, inside the company like still very secure. That thing did not quite take off like today, SD-WAN. SD-WAN more expand to the WAN side, which need more, 80% need more security. That's what happened in this time, the third generation refresh, little bit different than the last few generation refresh. It's really expanding beyond the border now. The border security is still there. That's where some old company enterprise firewall, and they still kind of replace the border.

The whole traditional border firewall is not decreased but also will not increase. Internal security growing a lot, internal segmentation, including the Wi-Fi, and also go to the WAN, SD-WAN, and also the cloud side, IoT security also expanding a lot. That's what we call the infrastructure security or Security-driven Networking. This is Gartner size. Look in the last 40, 50 years. Initially, you can see the server PC that eat up the mainframe terminal. The cloud and the mobile starting eat up the traditional server and PC. Going forward, maybe still a few years away, or five, 10 years later, by Gartner they see the edge and immersive, whatever the wearable or the meta will be starting eat up the mobile and also the cloud. That's where the long-term trend happen in the industry.

We have the technology, we can embed a lot of security, whether inside the edge or inside the immersive technology, and then that's keeping driving the whole industry. That's where we develop a lot of technology today, try to feed the future trend of the security space. Fortinet is the only company we can cover both edge and cloud. Later, Patrice might well present some of strategy product related to the cloud, related to the edge. By the next 2 years, 40% enterprise will start deploy the edge security because most of data generate on the edge. Edge also has some advantage, latency advantage, the bandwidth advantage, and the cost advantage, compared to the cloud. Also, I always say cloud good for certain things. Like they're good on the management side, they're good on some detection, which not quite need a real time.

The edge, more good on the prevention. The prevention device, just like most network security device, is inline device, need prevention, need to stop the intrusion, stop the virus, stop the bad web content, bad traffic, need to process the data in real time. The latency requirement, the bandwidth cost requirement, and also need to be very close to the data. That's where more fitting of the edge. That's where the company strategy we have from our beginning, try to more combine the security networking together. That's where the total addressable market for us is keeping expanding. The traditional network security is still there. We grow faster than the market. The market grow about 10%, including the internal segmentation, including sometime expand the WAN to the other area. Then on the other side, the cloud also grow very fast.

There's other we call the secure infrastructure. That's also keeping expanding. Like I said, SD-WAN, the 5G, a lot of new network function, they need security because the traditional network function, you call it a 5G or whatever, they only care the connectivity and speed. Anything beyond connectivity, speed need to be handled by security. Like what's the content, what's the application, what's the user behind, what's the device behind, what's the region country behind? All has to handled by security. That's where we see the infrastructure security get more and more important because you need beyond connectivity and speed. That's how security give a bigger percentage of the total IT spending. Especially when the 5G IoT taking off. We all prepare the technology and develop the product for all this going forward.

Fabric, you can see in company growth, Fabric grow faster, much faster, almost double the growth rate compared to the network security growth. That's where because the trend in the companies, they need a consolidation. Too many product from too many different company, they're now working together, difficult to manage. Management costs very high. Also they cannot automate if they not integrate. That's where you need to be integrate, you need to be automate. That's where for us, we develop most of Fabric product in-house. That's very different than most of our competitor. They come from acquisition by acquisition. That's what make the integration both on the product, on the team, more difficult. We also do some acquisition, but for our acquisition, they probably need to be first become a FortiFabric partner. We want to make sure the technology, the product, can working together.

Most of our acquisition also in the product technology stage, not quite when they already expanding the market stage. That's want to make sure integration automation will be working after the acquisition, completing the whole Fabric picture. I think few months ago, we announced SoC4. It's a fourth generation system on a chip, which can go to the SMB device, go to the edge, and also go to the, we call the FortiGate 60F. You can see we starting also introducing earnings call, we call the Security Compute Rating. Security Compute Rating is really at a certain price or price range, like example is about $1,000. What's the industry average computing security power you can get, including go to the cloud, including go to the appliance, including whatever? We compare all the competitor, all the cloud or on-premise solution, compare to ours.

What's industry average for around 1,000 price, or could be like a 3,000 or could be 10,000 or 100,000. That's where each one they have a different price range. Then compare to the product, what's our Security Compute Rating advantage? That's where you can see the rating here from 4x to 47x. The chip we introduced here, they have multi-core CPU. They custom design a lot of security function inside. That's what make it performance much better, much hugely computing power compared to a general purpose CPU. General purpose CPU, they are not designed to run a lot of security function.

They're not designed to run a lot of networking function. That's where this SoC chip is so powerful, give us quite an additional computing power room to keep adding network security function like SD-WAN, like we already have the Wi-Fi, like the 5G going forward. Keeping adding additional security function, also go deeper in security function. Because in security space, every year there's a new function, new feature requirement. At the same time, if you can integrate more function into a single device, because this device deploy in line, the less, the faster processing, and that's give you better control, better cost and performance advantage. That's where it is so important you can leverage hardware to keeping the performance, the function better, faster, because security need much more computing power than the networking.

On average, security need about 50 to 100 time computing power to process the same traffic. Also security need to be in line to stop the bad traffic. That's where most of the time security become a slow device and also most expensive device on infrastructure. This technology actually we started from day one and also including my previous company, they enhance the function a lot, easily add a new function. At the same time, they improve the performance, lower the cost. The best way to measure, use the Security Compute Rating. We spend almost five years developing this new one we call the Network Processor 7. That's the first time we introduce. Compared to the NP6, which we introduced almost five years ago, the product like 1500D, 3700D, this one is about five times faster.

The interface go for the 100 gig, and the packets per second processing power equivalent to the 200 Meg. You can see a lot of new functions and also a much faster processing power compared to the last generation network security processor. In the next few months, we're going to introduce some more products with leverage this new chip. This chip more go to the middle and the high-end, and also can go to inside the cloud, inside the data center. We call the hyperscale. Handle all this kind of east-west traffic, compared to most border security. The cloud security is a north-south traffic. Because you need a speed, internal networking speed tend to be 10 to 100 times faster compared to one connection. Without fast processing power, you cannot secure the internal, whether segmentation or inside the data center.

This chip gave us the capability to handle a new market inside the company, inside the data center, secure all the other things. That's really take about almost five years to develop. It's the best technology today in the industry. They also gave us additional computing power. We do use whatever the latest commercial available CPU chip, but this is very unique. We're the only company design the chip in this level, can process network speed faster, can process function much faster than the regular CPU in the industry. Here are some summary comparison to the regular CPU. You can see this CPU actually cost almost $3,000. Then compared to the new NP7, then compared to the last generation NP6, and also the SoC4. We also have, we call the CP9. It's another content processor, more process SoC.

Another one had been released two years ago. It's a much faster, much better Security Compute Rating power compared to any other industrial competitor. That's what keep us keeping gaining the market share, keeping growth faster, because this technology is very, very unique and has much faster computing power, better computing power than any other competitor have today. They use the regular CPU, which we also use, but on the side, we also have this accelerator. Just like the GPU, the TPU can handle different functions. This is a technology we call SPU, security process unit, will give us huge advantage and also can easily add a networking function, add additional security function, and still much faster than any other competitor. That's why so far, we don't see any competitor can do the SD-WAN, Secure SD-WAN. They cannot do the Wi-Fi with security integrate together.

Far, we have not seen them go to the 5G with security and also so much security function. That's where you can see the testing evaluation. When customer engage in the evaluation testing, we always win. That's where the power behind this platform, this technology help us. Also making ASIC for us, that it more make business sense because the economy of scale also working. Today, we have almost 30% the total unit deployed or unit shipped in the industry. For the ASIC chip, because the very high cost take a long, like a big investment to produce the chip. Per chip cost will get lower if you have the quantity. We believe in the next few years, we can have more than half majority of the total industry unit shipment. That's where leverage our chip technology.

Our ASIC chip cost will get lower. Will helping our margin and also other competitor more difficult to get in the space because they don't have the quantity, they don't have the economy of scale working for them. For us, we spend in the last 20 years, spent billions of dollar in this technology, we're starting to benefit a lot, including going forward, IoT security, embedded security into different infrastructure, can be networking, can be storage, can be like a connected cars and other IoT smart city. This will also benefit us in the long term because we starting to have the quantity, the economy of scale also starting more working for us now. When we engage a customer testing evaluation, we always win, because so far, we believe we have the best technology. You can see this from the independent industry testing certification.

Sometimes a lot of people joke that we spend more money on the test evaluation certification than the marketing, it's a part of marketing, general %. We still want to be leading the technology, keep up with innovation. Let's go to the number of pattern we have. More than 3x than any of our close competitors. We want to keep the innovation. We do develop a lot of technology, a lot of product, more broad solution, most in-house developed compared to our competitor. That's what more like I said, in our own space there. The company, we still want to keeping the long-term investment, the long-term focus, into this network security industry, develop a lot of technology will benefit the customer, benefit all the industry in the next 5-10 years.

We talk about merger acquisition, probably Keith or whatever can spend more time there for our capital strategy. We are, want to make sure the acquisition we make can fit into the Fabric. They can work in together. If they can integrate together, they can automate together. That's the strategy. A lot of acquisition more in the product stage. That's where there's a lot of startup, they can spend like easily $20 million, $30 million to develop the product. In security industry, because, most enterprise customer, they're still not quite a testing evaluation of product yet. That's where if you want to go to market for this industry, you can easily need to spend over $100 million to go to the market.

That's where quite a lot of startup company, they develop product, where the investor, the team not feel comfortable to spend additional $100 million to go to market. That's the best stage for us to acquire some of the company. SD-WAN, this data come from Gartner. You can see how quickly it's growing for us. This is compared to Q1 to Q2, is quarter-over-quarter, like more than double. That's the market share we have because we're the only one can combine security with SD-WAN together into a single FortiGate box. By Gartner also, some other IDC data that show over 80% SD-WAN need security. None of our competitor have the computing power capability to embed security inside SD-WAN or combined together. We can easily add SD-WAN, like we add Wi-Fi, we add some other security functions.

Still have a lot of computing power for the future growth, for the future function going forward. With that, let me pass to John, and we'll give some detail of the product. Thank you.

John Maddison
CMO and EVP of Products, Fortinet

Thanks, Ken. This mic's a bit high. Put it down a bit. I'm John Maddison. I've been at Fortinet about eight years, and probably seven and a half of those years were focused on the product side, meeting with customers and strategy there. In the last six months, I took over the CMO role as well. As Ken said, I don't think we've got any issue with our products. For sure, our products are the best out there, network security-wise. I think right now, a lot of people know Fortinet, but they need to know what we stand for. Right now, we're actually the third-largest cybersecurity company out there. We'll focus in 2020 on making sure our customers and our potential customers know who we are in more detail.

My title of the slide said Digital Innovation, I think everyone here has an example of digital innovation, it's not just one industry, it's all industries. Whether you think about retail, manufacturing, transport, education, every single industry is being impacted by digital innovation. It's very disruptive. Very disruptive indeed. You just have to look at the Amazon model to some of the retail stores, although I think some of those retail stores are coming back by using digital innovation. Disruption also causes increased risk. From our perspective, it's causing cybersecurity risk. Four main reasons. One is, what used to be a fairly conservative attack surface, which we now call the digital attack surface, is very much expanded, creating edges in your network, in your compute, in your users, in your devices. Secondly, the cyber threats have not gone away. Breaches are expanding.

We saw our first cloud breach, major cloud breach this year. Ransomware's not gone away. You can see it in the U.S. in local authorities, for example. Cybercriminals are still out there and expanding. I've spoken to a lot of customers who are just fed up of buying one more security point product. Too many point products, it's too complex, the ecosystem. They can't fit it all together. They can't build workflows across there. Finally, something that's not going away is regulatory and compliance. We're based in California. There's a recent California Consumer Privacy Act that came into play. There's global, there's regional, there's industry-wide, there's government compliance, which will always be there. Let me start with the first one, the digital attack surface. Obviously, you want to make sure all your devices and users can get to the right compute and applications.

Okay, making sure that all users, before they get on the network, have a trust level, whether they're known, unknown, or trusted. Very important going forward, as a lot of these devices are always headless and you can't get agents on there, and they're part of the IoT and OT infrastructure. Then, of course, there's compute. Everyone talks about the cloud. The cloud is many different things. It's multiple public clouds. There's multiple SaaS clouds. It's edge compute. It's hyperscale going forward. A lot of companies have call centers, and of course, edge compute going forward as well. What's really important is you've got to connect all those devices to all those applications and compute. People forget they need a very secure and fast network.

Otherwise, all they build out inside the cloud, all they build out inside their factories and campuses are for nothing if you haven't got a very fast, very reliable network. I was talking to a customer about six months ago. They've got about 4,000 sites around the world. They were getting an average 120 outages each week on the network. This affected their business greatly. You've got to make sure the network And by the way, the campus and the branch and the factory are not moving into the cloud, nor is the network. The cloud's very important, but so is the network, and so is the infrastructure that onboards your devices and users. The other piece is the cyber threat landscape. I'm not going to go through this in a lot of detail.

If you go back a while from 2000 to 2010, the biggest thing that was changing was the attack vectors, email, network, Code Red, Nimda, web drive-by downloads. The threat landscape was changing very rapidly every year, and that's why you had a lot of different point solutions from a cybersecurity perspective. Now, what's happened in the last five to six years is the infrastructure is changing even more rapidly. Not so much creating new threat vectors, but as I said before, creating new edges, new ways in. You can see now that breaches are $5 billion-$6 billion-plus compared to in the millions or tens of millions five years ago. Not only breaches, ransomware will reach over 1 billion attacks in 2019. A very different approach. What's ransomware trying to do?

It's trying to hold your infrastructure or destroy your infrastructure and then allow you to operate it once you've paid that ransomware. It's not only breaches, it's also ransomware. Look at the numbers for ransomware and breaches still going up. That threat has not gone away whatsoever. For us, we absolutely think that the cybersecurity platform will enable companies' digital transformation and digital innovation. It's absolutely essential to allow those companies to move forward with their innovation. We feel there's four main components of a platform going forward. First of all, at the core, what we call Security-driven Networking, you need a very fast network to enable all your devices and users to connect to your applications and compute and data. Securely and accelerating the user experience or even the device experience in some ways.

We want to make sure that every device and user is securely attached to the network. Of course, we want to make sure you have that dynamic cloud security, making sure that all your compute and applications and data are safe in whatever cloud that you're using. Once we've done all that, we want to apply the most advanced AI-based or machine learning-based threat intelligence to any part of that network. Ken talked about this, it's what we call our Fabric, our Fabric platform. We believe it's the broadest cybersecurity platform out there. We can cover everything from IoT to OT to endpoint, to secure access through Wi-Fi and switching, to core network security, to application security, to cloud security. The full length segmented all the way from IoT devices all the way into the compute.

Again, we believe this is the broadest cybersecurity platform, and this reduces risk for customers because they get that visibility of everything on the network. Also, we believe it's the most integrated, and again, Ken touched on this. We do some acquisitions, but not big acquisitions, because it's very hard to integrate mature products from other companies into your platform. We do a lot of organic development. Again, we believe we're the most integrated platform out there. This absolutely reduces cost in terms of having to buy point products for every single attack vector or every different infrastructure component inside your network. Most importantly, and probably the conversation I have most with customers, is automation. I want to build workflows to enable my infrastructure to be dynamically operated. When I find something, I want to be able to automate the response very quickly.

We believe our Fabric is a complete differentiator out there in terms of how broad it is, in terms of how integrated it is, and in terms of how we can automate workflows across everything. What does that mean in terms of products? We have quite a few products. For those of you familiar with Fortinet, we have a very simple naming system. It's the Forti-whatever it does. Okay? Everyone can follow that. Even our sales team can follow that process. There's a few salespeople in here. I definitely haven't got a spare six hours to go through every product here. Rest assured, I'm not going through every product here in a lot of detail. I'm going to focus a bit more on the network security piece component here.

You can see we go all the way from our FortiNAC solution, authenticator, and token to authenticate everything going on to the network. Our endpoint, we made a recent acquisition on the EDR, in EDR space to increase that capability. Our secure access through FortiAP and FortiSwitch, our core product, where all the controllers are around FortiGate. We've actually been working very hard on our cloud portfolio around FortiGate VM, virtualization, cloud workload protection, application protection through WAF and FortiMail, analytics, and then of course, probably one of the biggest differentiators for us is a single console across all of those products. A single point of visibility, a single point of policy. Again, that's extremely hard to build if you do that with different vendors and try and mash it together.

Running across all of this is FortiGuard Services, which allows you to apply that AI-based threat intelligence at any point. Interestingly enough, we try and provide all of these products with different consumption models as well. Obviously, we're very well known for our appliances because we build some of our own SPUs and ASICs inside there. We also make available as many products as possible through virtual machine, through cloud. We've actually rolled out a lot of SaaS delivery services in the last 12 months. Obviously, some of their agents and software, but you'll see us roll out things like container security going forward. Definitely the consumption model will change depending on where the application is or depending what the customer wants to focus on in terms of deployment. Very important to us is our FortiGuard Labs, which is our threat intelligence.

Given that we have almost 5 million firewalls deployed, that's a huge footprint in terms of visibility. It gives us a huge advantage over our competition because we can just see more of what's going on across the world. Not only network security and firewalls, but also WAFs, FortiMail, clients, enterprises, and we continue to roll this out. We bring all of that information into our AI-based and machine learning cloud, process it, and send it back out so those sensors then become protective nodes going forward. This is a huge operation, almost 10 billion+ events on a daily basis get processed through our FortiGuard labs. Ken showed this slide as well. This is what we think the total addressable market is for Fortinet's current products and solutions. Obviously, the core of that is network security, about $24 billion.

Secure infrastructure, which includes access points and switching, secure access to the network, endpoint and IoT, and OT security, of course, cloud. About a $60 billion TAM by 2023. Let me zoom in to the network security marketplace. Obviously, this is our core marketplace in terms of products and billings and revenue. You can see network security is absolutely dominated by network firewall. If you look at the current situation, almost two-thirds of revenue is network firewall. The second largest marketplace is a web gateway, sometimes called secure web gateway. Right now it's IPS, secure SD-WAN. As you go forward, you can see actually network firewall remains the predominant market inside network security. These, by the way, are coming from Gartner. You can look this up. They have individual reports for every one of these marketplaces.

IPS declines a bit, mainly because of the movement into cloud, data center movement into the cloud. Web gateway is still very important as it secures users and their access to the traffic. SD-WAN increases as well. Moving from $18 billion market to a $24 billion-$25 billion marketplace by 2023, about an 8% growth. What's also interesting, let's just zoom down in more detail into the network security marketplace, into the firewall marketplace. Here right now, again, according to Gartner, about 5% of all firewalls are virtualized. In their mind, this is going to move to about 15% by 2023. Going from 90%-80%, about a 10% decline in hardware, but that's just the percentage. The overall marketplace for security appliances will still increase and still be large.

There's something else called firewall as a service, not quite sure what the market is for that, ranging between 1%-2%, but still very tiny. Network security use cases. Network firewall to manage all your risks. We're going to talk a bit about the hyperscale firewall. This is a marketplace that's not served right now. Technology cannot serve this marketplace. Secure SD-WAN, which has absolutely exploded for us in terms of marketplace and secure web gateway. We continue to see new use cases for network firewall, not just firewall, but IPS, next-gen firewall, internal segmentation is still a very important application and use case as those edges appear inside the network and the network expands. There's something else which is very important, that's SSL inspection. Almost 80%-85% of the traffic's encrypted now.

A lot of companies don't open up and look at this encrypted traffic because of the performance issues, and I'll talk a bit about that. Most of you should be familiar with the Gartner Magic Quadrant. Anybody not familiar with the Gartner Magic Quadrant? Don't be embarrassed, you can admit it. It's fine. This is what Gartner used to define, obviously, and categorize the different vendors. This one's about two weeks old. It came out about a couple of weeks ago. Excuse me, this glass is slipping down the table here. You can see there's definitely two leaders in this marketplace, in our opinion. In fact, whenever we're in deals, we usually see two leaders bidding for new deals. We continue to kind of make that difference in terms of separating us from maybe Cisco and Check Point, but definitely doing extremely well.

This is actually the 10th time. I know Ken said the third time. Now the UTM Magic Quadrant is being incorporated inside here. Now this is actually, if you include UTM and network firewall, enterprise firewall, this is the 10th time we've been inside there. From a network firewall perspective, as I said, two main consumption models. One is the appliance and one is virtual machine. We've seen virtual machine take hold maybe in the East-West SDN environment. We've also seen it obviously in the cloud. We still, a lot of people deploy those appliances, especially against the internet, where it needs to be hardened against the internet. We see a lot of people making sure that they have high performance, but a hardened machine against the internet. This is the analogy we use for something we call our security processing units, the SPUs.

There's something else in the industry called the GPUs, obviously, this is for gaming. What it does is just offload the CPU from a lot of those computes to render the graphics. A medium level, a low entry CPU plus a GPU will easily outperform a very high-end CPU. This is the same concept we have for our network security appliances. Obviously we still use CPUs. We still need to add new features. We still need to make sure we can support cloud and software, et cetera. We offload the CPU, two main CPUs we have, one is the network processor, which offloads all the network processing, all the firewalling, the NATing, policy, et cetera. We also have another SPU which is on the content side called the content processor, Content Processor 9.

This provides all our deep security processing as well as, for example, SSL inspection. How do we scale our systems? Well, our entry-level systems start with one of them, and then as we scale up in the marketplace, we just add more network processors. In fact, we add more CPUs and more content processors. We have one firewall, for example, today that runs at one terabits per second. That's pretty fast. If you look, Ken had this slide for our entry-level systems. This is one of our mid-range systems. You can see again, there's such a huge advantage. We refer to this as the Security Compute Rating by taking an industry average across different vendors in the marketplace, coming up with an average, comparing it with our system, and then giving you a Security Compute Rating. Again, this is ranging from four to 12x faster.

That's huge when you're putting in your network and making sure it works at those sort of speeds. We believe we have a huge advantage now, but we believe going forward, we'll have an even bigger advantage. I talked a bit about SSL inspection. This is a very important area because most customers have it switched off because of the poor performance of their network security firewalls. Most customers are looking at making sure they can turn that on going forward because guess what? The bad guys absolutely know that's turned off, and all their attacks are going through that encrypted channel. This is actually a report done by NSS Labs, probably one of the most independent test houses out there. This was actually a 2018 test for next-gen firewall, and as a part of that, they switch on this encrypted test.

Where they encrypt, for example, I think the IPS traffic here. Every vendor's going to get some degradation. We get about 18% here, so we go from about 6.1 down to 5.8 gigs. Just look at some of the other vendors here. Again, these are not our results. These are NSS Labs. It's independent testing. They've almost got 80% degradation. Your 10 gig firewall goes down to 1.5 gig firewall. These are this year's results. Not much change. I think Cisco's got slightly better there. We actually got slightly better. Our FortiGate 500, for example, still maintains about 5.8 gigs. Palo Alto PA-5220 is about 2 gigs. Also remember that our 500 is about $10,000 and the Palo Alto is about $50,000. It's not even just the performance, it's the price as well.

This is why we're taking market share in network security. As you follow the progress of network firewalls, more and more use cases are added on. If you go back in history here, Ken will say the history should go back a bit further, from when he was building at Stanford University's firewalls. Let's start in 2000, where you had mainly firewalling. Pretty quickly, it came along to add VPN inside there. As we went forward, because of some of the attacks, the network attacks, network worms, you started adding IPS inside there. UTM came along, and we started adding in next-gen firewalls so you could see the applications. Around 2010, 2012, you had to support IPv6. As you went forward, SDN, segmentation's a big application. As I said, SSL inspection is very important.

We've also seen now that putting SD-WAN inside the firewall is also extremely important. Each time you add these applications, you put more pressure on the CPU and the processing capability there. That's why as we go through this history, what Fortinet has done is looked at these different applications that are coming along and make sure we offload that going forward. A lot of our SPU technology has been put in place to make sure we can keep adding new applications to our network security firewalls. What's coming next, in our opinion, is hyperscale firewalling. What is hyperscale? To us, it's a completely new marketplace, a new set of applications that even some of our systems can't get to today just because of the performance and criteria. Here's some examples, and there are others that's come along as well. Something called elephant flows.

These are big research centers that have to get big chunks of data to different research centers around the U.S., around the world. Most firewalls today just give up at 10 gig. They can't process it anymore. Firewalls are not even in the path some of these research centers because they can't cope. Second one coming along, edge compute. Edge compute, 40% of enterprises by 2024 or 2023. Gaming and e-commerce sites that spin up hundreds of thousands of users within seconds. Massive attacks, DDoS attacks, we're seeing them still on the application level. Ultra-high definition streaming, 8K TV. The next Olympics will be broadcast in 8K, for example, in Tokyo. 5G networks. Core segmentation. Firewalls, you can't put today's firewalls in the core of your network. They're just not fast enough. They can't cope.

They can't deal with some of the segmentation that you need to do today. Finally, large inter-data center, large connectivity to the cloud. To do these things, you need a totally different type of capability. For example, on elephant flows, you need 100G at least interfaces to provide those flows. Ultra-low microsecond latency for edge compute. Millions of connections per second. We're not talking 100,000 here, we're talking two to three to four million connections per second to cope with these very large sites. DDoS built into the hardware. Software just won't work with the volume and the scale of DDoS attacks. 200 gigabits per second of throughput and ultra-low jitter for streaming of high definition TV, carrier grade NAT, accelerated VXLAN. Sorry, VXLAN is a bit of one of those terms. It's a technology used in the core of your network from a switching and tagging perspective.

75 gigabits of IPsec connectivity. It's what we call our NP7, our hyperscale SPU. We're introducing it now in Q1. We'll introduce some of the first products. Right now it's just the chip, obviously. You can't send the chip to the customer and connect it. You need Ethernet ports and systems and software, et cetera. As Ken said, we've been working on this for about five years, and we'll roll out systems in Q1. This will absolutely open up a new marketplace for us in what we call the hyperscale. Again, here's some of the comparisons of NP6 to NP7. Most is a 3X to 5X comparison in terms of performance, but it absolutely opens up a lot of new applications for us in terms of network security, and we'll provide more detail on how big we think this is going forward in 2020.

Don't forget virtual machines. As I said, our FortiGate virtual machine, APIs and software, works the same. We have a lot of customers rolling out our FortiGate virtual machine in SDN, in NFV for service providers, in cloud, for example. We're very flexible. We're still trying to accelerate it. We're still trying to make sure we can scale it horizontally or vertically, with different flexible licensing models. We're still investing heavily in virtual machine as well as our hardware. Now, the next big area, which has already been very successful for us, is Secure SD-WAN. Secure SD-WAN, we think, is extremely important. Again, here's the Gartner Magic Quadrant from last year. I believe the 2019 Gartner Magic Quadrant, what they call WAN Edge, is coming out any second now or any day now.

It's late by a few weeks, you'll see the new one coming out. Definitely take a look at that. Obviously, I can't say a thing about it. I can't even hint in the tone of my voice or anything, what's going to happen in that. Definitely, otherwise Gartner will be after me, but definitely take a look at the new one that should be coming out any day now. To us, SD-WAN technology is not just having multiple connections to your branch and making it more secure. SD-WAN path control technology, which is the upgrade from routing technology, can be used anywhere in your network. It can be used in your core network, it can be used to connect campuses, it can be used to connect your data centers to the cloud. Don't think of SD-WAN technology as just branch office technology.

We also think because that's the edge, you need to make sure that edge not only has that secure technology, but also has the security stack as well at that edge, not somewhere else, but at that edge. It provides obviously different transport components. It allows you to connect internally, but most importantly going forward, SD-WAN will be your on-ramp into the clouds. It's the base technology. A sophisticated SD-WAN, once you add on the SD-WAN on-ramp capability, becomes absolutely critical technology. By the way, as we go forward, there's a lot of people positioning what they call, Gartner call this the SASE, it's a great name, for cloud security. What's also happening is that a lot of the telcos, a lot of the ISPs, a lot of the big major cloud vendors want to be that first on-ramp capability.

Fortinet will provide SD-WAN plus the cloud on-ramp into whatever cloud it may be. We're not going to say you have to go to this cloud to do your security. We're going to give you flexibility to go to any cloud, even our own cloud, to do security going forward. What is SD-WAN? We get this question a lot. We believe SD-WAN or Secure SD-WAN, is more broad than just a WAN edge controller. Yes, it's very important. Where did this marketplace really start? It started in routing, where the routing used to do hub and spoke and get everything back to the data center. People wanted more flexibility, so they brought out something called the SD-WAN controller. As I said, as you do that, what's very important is you secure that.

As you break out into local internet access, you need to make sure you have that next-gen firewall capability. For us, we run it about 10X faster than our competitors on a SoC4. We do put it on virtual as well. You need to make sure you have that orchestration system, because that's going to be key in providing your cloud on-ramp API connectivity going forward. What we've also seen is a lot of customers when they see this, because we've got an in-built unified AP switch and NAT controller inside our FortiGate, expand that all the way to the edge, to the device edge and user edge. A lot of the deals we've done for SD-WAN add in what we call our SD-Branch. It adds in Wi-Fi access, it adds in ethernet access, it adds in network access control and IoT security.

As I said, as we go forward, we've already announced two cloud on-ramp capabilities with Azure a couple of weeks ago with their vWAN. We already have AWS Transit Gateway. Each one of our clouds we'll build a separate cloud on-ramp for to make sure you have the most optimized traffic path, QoS path into those clouds for whatever application it may be. Fortinet so far in SD-WAN has been very successful in the enterprise space, winning a lot of large enterprise deals. We talked about on our analyst call last time about the number of enterprise, very large enterprise deals we've won. One space where we still need to work on is service provider, because SD-WAN to service providers is just as important because it's taking away MPLS revenue. About 50% of the marketplace we think is enterprise, 50% is service provider.

You'll see us start to announce, and the first one we announced this morning, new SD-WAN deals for service providers going forward. Sometimes you refer to this as network-based SD-WAN. We're starting to make inroads into the service provider marketplace. We've already been successful enterprise, and Orange is one of the first big announcements. We announced some other service providers earlier in the year. We announced this morning that Orange will be using our technology. Orange, by the way, is one of the biggest, most global network service providers in the world, will be using our SD-WAN technology to power their offering to their customers going forward. We also announced SoftBank this morning, same. They're going to be using, in fact, they already are using our SD-WAN technology to provide their customers with the best WAN edge capabilities across their global network.

These are two examples we announced today. More to come for sure. In terms of cloud, definitely cloud is very important to us. We have public cloud infrastructure. There's also private cloud and SDN. We also have worked very heavily on our SaaS offerings. Remember what I said about this is that applications, when they move somewhere else, you really need to move where the security control points are. If your email has moved to the cloud or some of your applications have moved to the cloud, you really need to move that email security and that WAF, as a web application firewall, which protects your applications into the cloud as well. What better than moving them onto a SaaS platform that's on that cloud itself? SaaS today is lots of different data centers people have built.

Long-term going forward, we believe our SaaS offerings built natively on AWS and Azure and Google going forward is the best way to protect those applications which sit inside those clouds. Zero trust network access, absolutely becoming more important as more IoT devices are out there, as more OT infrastructure is put in place and IP enabled. Obviously, endpoint is the second largest security marketplace, very important indeed. Our network access control is doing extremely well in the marketplace. It's very unique. It's API based. Also we can roll out identity on top of that. Making sure you have zero trust for anything coming onto the network, making sure you provide that application control in terms of making sure it's authorized to get on your network, making sure it's got the right agents on there, making sure you can see it, is extremely important.

Today, our third announcement, quite a few announcements today, the PR team were busy, is with Siemens. Operational technology is already extremely important, but to be able to provide that security, you need to know those OT systems. Every single vendor out there, large OT vendor, has proprietary systems. So unless you partner very closely with them to understand their systems, to understand their protocols, you can't really provide true security. This is, again, one of our first announcements around operational technology partnerships, which are extremely important for that marketplace going forward. AI threat intelligence. If you go 10 years ago, most threat intelligence was really focused on protection, making sure you protect against known threats. I would say customers have spent absolutely more money these days on detection or unknown threats.

We've actually implemented a lot of machine learning inside our systems to make sure we can scale with the size of the threats, and then, of course, once you find something, you need to respond in an automated way. Again, all part of our Security Fabric. Probably one of the most difficult developments, yes, we develop our SPUs and ASICs and appliances and software here, but what the industry has struggled with the most, and it's not just cybersecurity, it's infrastructure, it's endpoint, it's cloud, is bringing a unified management center together. We call it our Fabric Management Center. You can bring up our Fabric Management Center. You can see all of our products that I talked about today and earlier in that visibility view, in the topology view. It's very hard to do. We can see how they're connected. We can implement workflows across every one.

For example, if an endpoint finds something bad, we can tell the switch to take it off the network. That's just a simple case of building workflow, which is absolutely impossible when you've got 10 to 20 vendors inside your infrastructure. Having said all of that, it's very important that we have an open Fabric, that we have partners that can connect into our Fabric, and we have systems that we can connect into as well. We call that our open Fabric ecosystem. We have 4 types of different integrations. We have Fabric connectors where we build into the orchestration systems of companies, because those orchestration systems are extremely important. They know where all the infrastructure is. Examples would be Cisco or VMware or AWS. All the big orchestration systems know exactly where the infrastructure is.

We don't want to be the orchestration system, but we want to know where the infrastructure is. We provide deep connectivity. We build it ourselves, deep connector into these orchestration systems. We have about 135 partners who have built our API, providing specific applications. We have a very active DevOps environment, which usually become connectors long term. Since we've added components to our Fabric, such as NAC, we've also expanded, for example, our NAC system supports over 60 different vendors, including all our competitors' switches and APs, for example, to make sure we have a completely open ecosystem. I don't expect you to remember all of these vendors in 10 minutes. This is just a sample of them.

Obviously, in the market today with a Fabric and an ecosystem that goes so far, there's a bit of competition going on. In the end, it's the customer's choice. If they have certain vendors they really want to keep inside their infrastructure or they want to use going forward, we're absolutely okay with that as long as it fits inside our Fabric integration. Finishing up. Again, I can't possibly go through all the opportunities and markets or all the different products and solutions. I've summarized here what I think are some of the growth drivers for Fortinet going forward. Obviously, network security. We're growing much faster than the average rate of 8%, that's for sure. We're still taking market share in network firewalls, in segmentation. SD-WAN was a completely new market to us three years ago.

You can see we're already third in Gartner's market share after only a year. Hyperscale. We don't really know how big this may be. We think it's big. Hyper means big, I think. I think that's going to be huge next year and making sure we can go where no firewall has gone before, into the center, into the core, looking at applications, et cetera, which firewalls, again, could not cope with in current technology. As I said, we just acquired an EDR company to bolster our endpoint solution. IoT security is also doing very well for us with our NAC solution, OT, our hybrid cloud, edge compute starting to roll out, that needs a completely different architecture, SaaS delivery, and across all of that, we can sell our advanced AI-based threat intelligence across every single part of that Fabric to make sure it's secure.

I'm going to stop there. Thank you.

Peter Salkowski
VP of Investor Relations, Fortinet

Thank you, John. Right away, she's quick. We're going to turn to Q&A. Fatima is reading the screens quickly. I'm going to invite Ken up to join John up on stage to take questions on their presentations before we move forward. We're running a little ahead of schedule, which is shocking because I didn't know how long John was actually going to speak because you never know with John. We'll take questions for the next 15 or so minutes, and we'll see how it goes. Yeah, please do wait for the mic. I will run around.

Fatima Boolani
Analyst, UBS

Good morning. Fatima Boolani from UBS. Thank you for taking the questions. John, a question for you. You made a very specific point around security controls moving to where the applications have the most gravity, so in the instance of emails and other applications moving, having native security controls in the cloud becomes all that much more important. Kind of a two-part question for you. From a competitive standpoint, how does Fortinet interface with cloud native capabilities, so from the likes of AWS and Azure? Secondarily, as a company with certainly more of an hardware engineering culture, how does that change the R&D calculus for Fortinet going forward as you think about that?

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Yes. Go ahead.

John Maddison
CMO and EVP of Products, Fortinet

I think by 2022, 75% of email will go through Google or Microsoft. That's the gravity of going towards that. Those email applications are moving there, what you have to do is make sure you re-engineer. We have, obviously, an email security appliance, those exchange servers are not there anymore in the data center. This is the reason, a lot of data center applications have moved into the cloud. They're either through SaaS or through native public cloud. For us, we just need to engineer the security and move that into the cloud. What the difference is, it's not just having a virtual machine email security running in the cloud. You need to connect to their APIs. Cloud API security is very important, the API gives you visibility.

In fact, long term, a lot of those applications may not even look at the traffic through traditional traffic paths, they'll look through it through APIs. We re-engineer those, as I said, for appliances, for virtual machines, and for cloud, and for API going forward. It's very important. What's still very important is that you have a total solution. If I've got an end user somewhere, and we know, for example, that they've had a phishing attack, and we can see it through the API in Office 365, then we can apply some security policy back onto the campus to make sure that it doesn't spread across. It's not just that point product instance on its own, it's the total Fabric solution across everywhere that's very important. You're right, we have to re-engineer it differently in the cloud versus the network versus the campus.

I always have a problem with two-part questions because once I've answered the first part, I've totally forgotten what the second part is.

Fatima Boolani
Analyst, UBS

I agree that the cloud-native capabilities are potentially just.

John Maddison
CMO and EVP of Products, Fortinet

This has always been the case for the big platform vendors. Before Fortinet, I worked at Trend Micro, and back in 2005 at least, they were saying Microsoft is going to come and take everyone's lunch. It's kind of happening now a bit, I think. You can see Microsoft now is by far the leader in the Magic Quadrant. Not that everything should be guided by the Magic Quadrant, of course. It's always going to be there. You have to make sure sometimes you'll use their capabilities and build on top of it. Sometimes you always have to find added value, though. For us today, for example, our sandboxing technology, where we do file, is more advanced, we think, than Microsoft.

Again, the biggest advantage is the workflow once we've found something to go back into the campus on the network and provide some mitigation of that threat upfront or afterwards.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

I mention, even we develop the hardware dedicated chip, but we do have a more software engineer than hardware engineer. That tend to be working together much better compared we have to using commercial hardware. We do use commercial hardware whenever possible, but the dedicated hardware actually helping the performance, helping the function a lot.

John Maddison
CMO and EVP of Products, Fortinet

Yeah.

Sterling Auty
Analyst, JPMorgan

Sterling Auty with JPMorgan. Sterling Auty with JPMorgan. John, I actually want to touch upon very early in presentation, you actually mentioned marketing and your CMO title, and you talked a little bit about maybe 2020 being more brand marketing. I wonder if you could just go into how much of your marketing resources were dedicated in 2019 to top of funnel pipeline generation versus brand, and how that might change in 2020?

John Maddison
CMO and EVP of Products, Fortinet

Yeah, good question. I think, last two years at least for sure, we've been very focused at getting a seat at the table. We weren't at the table a lot of the times. Definitely a lot of ABM programs, for example. Definitely a lot of events on the road and making sure we get access to the highest levels and getting access to those customers. I think in 2020, we're going to change that slightly in trying to create a bit more of a brand guidance. We've done some surveys so far, and as I said, most people know us. They've heard of us. They kind of think maybe at least that we're a firewall vendor, but they don't realize, A, the scope of the company, the size of the company. They don't realize how broad we are in terms of products.

We're not as well known, I would say, in the Fortune 50 or Fortune 100 in terms of CIOs and CSOs. We're really focused on that. You won't be seeing advertising billboards all over the place. You'll see some very focused branding to make sure people understand who we are.

Melissa Franchi
Analyst, Morgan Stanley

Thank you. Melissa Franchi from Morgan Stanley. Ken, we've talked a lot about SD-WAN becoming a key point of differentiation for you all. I want to ask about the competitive environment in that market. You have Palo Alto that just recently announced capabilities, which is obviously a validation of your market strategy, but also represents a new competitive threat. Can you just talk about how you sustain differentiation moving forward when you have new entrants in the market?

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Yeah. Actually, we started to develop SD-WAN for the FortiOS 5.4, which we released almost four years ago. Also leverage hardware ASIC. We have much better performance compared to competitor, which they just get into the space. From early testing, they're still way behind, probably even not quite match with three, four years ago function there. I do believe now SD-WANs become more important, especially Secure SD-WAN, and so will be huge growing market. Also, we'll have room for more player, but we are gaining market share very quick. Also, we have a unique advantage compared to any other competitor, especially SD-WAN combined with security need a lot of computing power.

Whether the vendor come from security or come from network side, which they don't have the actual power to add additional function, that's the biggest struggle they're facing because in the networking side, performance also important and more easy to test in a network function compared to a security function. Customer can more clearly see the advantage from SD-WAN, who is better with security and who is not because network function is more easy to test.

John Maddison
CMO and EVP of Products, Fortinet

Thank you. I'll just add to that. You can announce it, that's great. I think there, in terms of SD-WAN functionality control, it's difficult to build. That's why no one's really done it on the security side except us. To build an enterprise SD-WAN control is not easy. It's taken us four years to get where we are, where we compete head-to-head against networking vendors who don't have any security whatsoever. I think, I don't want to speak on Palo Alto's behalf, but I will. I think they're long-term more focused on Zscaler, because their service is a Zscaler plus SD-WAN. The reason they want to do that is because, as Ken says, their appliances can't compute the security and SD-WAN capabilities, so let's just shift it all to the cloud.

I think long-term, people will want a choice on which clouds they go to and which security they go to. That's why we keep saying, put that security at the edge straight away.

Michael Turits
Analyst, Raymond James

Hi, guys. Michael Turits from Raymond James. Actually, that's exactly where I'd like to start off, where you finished. Both Palo and Zscaler providing security, let's call it, broadly speaking, from the cloud. It sounds like you're working to partner more with the carriers and others to create access to the cloud. Can you just clarify that strategy and whether or not you need to be in a true security from the cloud position?

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Yeah, that's our strategy. A few years ago, when Zscaler launched whatever the service, we feel the service provider, some cloud provider, has the best position infrastructure, also even the team can do the similar service. So that's our position from our beginning in the last few years. Also you can see today we announced some of the carrier service provider also starting working with us closely launching a similar service. We do feel, because sometime, like John mentioned, who get touch of the first touch of whatever the traffic to the cloud, it's very important for a lot of service provider, cloud providers will be pretty hot competing space and also need a lot of infrastructure investment, data center, all these kind of things. Whoever can have data center close to customer, they have latency, they have a cost advantage.

Also need a huge investment. That's where the carrier service provider, cloud provider, they probably already have some infrastructure compared to some other network security vendor. They have to build something there. Also whether they are renting the data center. That's where you can look at the economy behind whether they can be profit or when you forward the data from the customer premise to their data center or POP, sometime also unencrypt and also not secure, and also there's some other regulation requirement whether they can afford or not. Like for us, when we do the R&D, we never let any data out of our R&D center there. That's where there's a lot of issue, lot of debate in the space. We do believe stay with the service provider is the best strategy, so we're supporting them. They also understand better in the space.

Keith Bachman
Analyst, Bank of Montreal

Hi, Ken and John, over here. Keith Bachman from Bank of Montreal. I wanted to stay on the SD-WAN space if I could. Every system you ship out has SD-WAN functionality, and customers can use it, or they don't need to use it, and you don't get paid incremental dollars. My question is, how do you have good data surrounding what the impact SD-WAN is on your largest customers? I'm guessing that your sales force gives you very direct feedback about who saw it as a key deployment feature or enabling a win for Fortinet. If you think more broadly or how would you want us to think about over the next 12 to 18 months, if you provide this functionality and users don't have to pay for it, how do you think about what it's enabling for a growth rate?

What's the difference you think you can make in that regard, and how do you measure it? When, for instance, when you say Gartner's going to provide, or IDC, market share number, I'm curious how they gather their information on that market share. It seems like it's a huge opportunity, but I'm just trying to drill a little bit lower in how do you think about it internally in terms of metrics, and how should we think about it when we think about your total growth rate? Thank you.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Yeah. I think that the way we measure later, I think as Keith, Patrice, and Matt will present, that's where sales finance, they have a very good way to measure. We have a very good tool right now. Also, has a lot of a very good use case right now. We maybe after their presentation, we can do the QA in the end. I hope it's okay.

Keith Bachman
Analyst, Bank of Montreal

Okay.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Thank you.

John Maddison
CMO and EVP of Products, Fortinet

In terms of what it means for us is we are still very strong in what we call the UTM marketplace, which is more of a retail distributed. This is allowing us now to go into enterprises, into branch offices. Those are marketplaces we couldn't go before. When we get in there with our SD-WAN solution, they also switch on our next-gen firewall. To us, it's incremental marketplace we couldn't get into. Long-term, we're also rolling out in orchestration type services, which will be charged for as well.

Keith Bachman
Analyst, Bank of Montreal

Okay.

John Maddison
CMO and EVP of Products, Fortinet

Obviously our competition are a bit annoyed today that it's free of charge inside our operating system. Long-term, we'll add some enhanced features which allow us to charge for it as well.

Keith Bachman
Analyst, Bank of Montreal

Thank you.

Brad Zelnick
Analyst, Credit Suisse

Great. Hi, Brad Zelnick with Credit Suisse. Thanks so much for the presentations. Excuse me. Very informative. I wanted to go back to that slide talking about the mix of virtual form factor versus hardware and the small sliver of Firewall as a Service. If you were to reflect back to when you introduced the virtual product, I think it's a few years ago or so now, I'd be curious to know, how has adoption been relative to what you would have expected? Even more interestingly, looking forward, if we think about where that goes, I mean, this is only a Gartner forecast. Who knows what the adoption patterns might be, but can you talk a bit about the impact that it has to your business, and why you feel that Fortinet is well-positioned to succeed regardless of what that mix looks like?

John Maddison
CMO and EVP of Products, Fortinet

Yeah. We treat it as the same in some ways. As I said, the operating system works the same on both. We make it the same, we make all the features the same, make the APIs the same, so the customer can choose in the end. What I've seen basically is that anything that's facing the internet that needs to be high-performance and hardened, they go with the appliance. Where's virtual machine done well? Obviously, in the data center, east-west, in SDN. Obviously, you can't take your appliance in your hand and take it into the cloud. That's all virtualized there. We've seen resistance. Even this kind of universal CPE concept that people are trying to roll out, has not done that well at all. We still see anything that's facing the internet to be very appliance focused.

I think Gartner's forecast, it's probably reasonably accurate. I don't know. We've seen it tracking in the last couple of years to what they've said. Again, we want to be flexible, that if you really want to go virtualized. Obviously, the benefits of virtualization is you've got more flexibility, and you can bring it up and down wherever you want. Right now, we're at 10x in terms of network speed and about 3x in terms of next-gen firewall speed. That network speed will be 50x next year for us. That's our balance of performance versus flexibility, versus hardening, versus licensing. We want to be able to provide both, depending on where the customer goes.

Brian Essex
Analyst, Goldman Sachs

Hi, good morning. Brian Essex from Goldman Sachs. Thank you for taking the question. I was wondering if you could touch a little bit on NP7 hyperscale. If you could maybe give us a little bit of insight in terms of where are we in the stages of that. Is it just in the pre-planning stages? Do you have involvement with partners and potential customers involved in that roadmap? How do we think about the discipline in terms of how are you going to invest in that platform versus what the opportunity might be going forward? Do you have visibility into any kind of a pipeline yet, or is it still very early stages?

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Yeah. The NP7 chip we announced actually has been come back in the summer, it's been testing for a few months. We feel more confidence about the progress and also both on the product technology, all these things. We do have a very good market share, almost dominant in the care service provider, which they need a lot of high performance data center technology to secure their all kind of huge data or huge traffic there. Also, we do have a lot of other bigger customer, which also using to secure inside segmentation, all the security there. We do working with them, and like I said, we do develop a lot of technology, including going forward with 5G, some other like SD-WAN, SDN, some other things with customer together. I think it's in the testing stage, I say.

Once we announce the product in the next few months. Every quarter, we do announce one or two new products, so that's where we'll give some more detail. Right now, it's still a little bit early, but we are confident about the chip level. We're using the chip to build a new system, a couple, two, three system every quarter to announce it. Thank you.

John Maddison
CMO and EVP of Products, Fortinet

I would say, as Ken says, we've got to rip the system out, yeah. Think about that NP7, that's one chip. We scale multiple chips across there. I think my simplest example is research centers, when they're trying to send maybe a 50 GB flow between research centers. Today's firewalls can't deal with that. In fact, they have software built in to bypass it. Most firewalls just bypass it. We'll start training our sales force across those, what we call hyperscale applications going forward in Q1, and start working with some of those big customers, to see if those use cases will work for them.

Peter Salkowski
VP of Investor Relations, Fortinet

I have a question from email from an analyst who isn't here today, couldn't make it. John, I think this kind of goes back to what you were just talking about on hyperscale. The question is, sounds like the strategy is to be at the core of the hyperscale network. Does that mean you need to win those entities as an appliance customer, i.e., AWS needs to put the service provider SP-based appliances in their network?

John Maddison
CMO and EVP of Products, Fortinet

I think initially, it's going to be more for some of the applications which are more focused on data and transfer of data or some e-commerce sites. I think it's going to be hard on the AWS side initially. There's going to be some long conversations. There's a lot more hyperscalers out there than you can imagine. Some of these universities are building $1 billion data centers to transfer data. I was in Europe recently at the World Economic Forum, and there was a big debate on how we get this data safely across different educational institutions. I wouldn't say AWS is our prime target, to be honest. There's lots of different applications out there, which need this type of functionality that you just can't do today. It's just impossible to put a firewall in the middle of it.

Ken Talanian
Analyst, Evercore ISI

Hi, Ken Talanian, Evercore ISI. I just want to talk about the OT opportunity. I saw the Siemens announcement. I thought that was interesting. Two-part question. One, you've had ruggedized appliances for some time, but is there any other product initiatives as part of that? Second, are Siemens sales reps compensated differently than a traditional channel partner as part of that agreement? Does it look more like what we've seen with the traditional two-tiered distribution? Thank you.

John Maddison
CMO and EVP of Products, Fortinet

Yeah. For the OT stuff, definitely a big market opportunity as a lot of those companies are bringing together their physical and their virtual worlds. I don't think it's a point solution that's going to work for them. Definitely, we have ruggedized devices, but that's only a very small part of it. Another part of it is recognize the applications through our FortiGuard Labs Lab service. We've had real trouble in getting some of those samples so we know what it is. You can say, "Oh, it's some sort of device," but you need to know what it is to give it a trust level. Is it something you don't even know about or whatever? For us, it's making sure we can work with Siemens across all their infrastructure gear so we can make sure we can tag it and identify it going forward.

OT is going all the way from wherever the factory is, through the campus, through the network. It could be Edge Compute, it could be data. Again, the end-to-end solution is very important, not just a specific point solution that can identify something. For us, working with Siemens is really our Fabric approach all the way from the device, all the way into the compute. As for the business relationship, I think we're still working on some of those deals. We can come back to you on that.

Taz Koujalgi
Analyst, Guggenheim Partners

Hi, it's Taz Koujalgi from Guggenheim Partners. Can you comment on the ASP trends in the last couple of quarters? Have you seen growth in SD-WAN? Has the average ASP of the appliance changed a lot, given the SD-WAN growth?

John Maddison
CMO and EVP of Products, Fortinet

Well, I think we should be charging a lot more actually, to be honest with you. The ASP price, some of our competitors are probably 5x, 6x in terms of their prices. We think there is a lot of room to actually increase the ASP. We're extremely competitive, whether it's just basic SD-WAN functionality or whether it's a full Secure SD-WAN, or whether it includes that orchestration component as well. Anyway, we see as kind of opt for that sort of pricing.

Taz Koujalgi
Analyst, Guggenheim Partners

When you compare your own ASP, say, from a year ago, has the ASP now gone up with the increased, I guess, blend of SD-WAN?

John Maddison
CMO and EVP of Products, Fortinet

Initially, it's more a question of taking market, gaining market share in branch offices which we weren't in before. Initially, it's a land grab right now. It's like any marketplace that's happening. SD-WAN, okay, it's three or four years old in some ways, but there's still a lot of greenfield opportunity out there need to go after. Right now, our goal is to make sure we win as much SD-WAN business as possible and then build on services on top of that going forward.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

I think, I do believe our ASP go up, and Keith will have some presentation, give the detail, and also, the sales and also partner also be able to sell multiple product also better. That's also tend to help in ASP. That's also one of the reason our gross margin, our operation margin also go up. We'll have some detailed data we'll present by Keith, so we have our Q&A in the end.

John Maddison
CMO and EVP of Products, Fortinet

I think the one thing I mentioned before was SD-Branch. Definitely the big upsell and cross-sell for us is not just SD-WAN or Secure SD-WAN, it's the SD-Branch sale right on top of that, which is Wi-Fi and access points and NAC, for example.

Peter Salkowski
VP of Investor Relations, Fortinet

I don't want to steal all of Keith's fun in his presentation. We knew SD-WAN was going to be a question that we would get. We've been getting it a lot lately. There's definitely some statistics that Keith will share in his presentation. It's about 11:25. I didn't build a break in because we only had three hours. If you do need to use the restrooms, they are out that door on the left. Please just get up and help yourself to the area. We're going to take one more question, and then I think we're going to start again with the presentations and bring up Patrice, who is our Head of Worldwide Sales, followed by Matt Clay and Keith Jensen as well this afternoon. One more question, then we'll move on.

Sterling Auty
Analyst, JPMorgan

Sterling Auty from JPMorgan. I just want to sneak one follow-up. Ken, I want to make sure that I understand this correctly. If I think about SD-WAN, I think of it traditionally as MPLS replacement, so branch office to headquarter. When I see some of the charts that you have up there from Gartner IDC, you have SD-WAN broken out separate from web gateway. I think about that local internet breakout and that internet traffic as traditionally being a web gateway portion, so a la Zscaler.

Are you at a point right now with Secure SD-WAN that you can apply all the same policy to internet-facing traffic that you would normally get in an internet breakout going through somebody's security cloud like a Zscaler, or is that an opportunity for you to develop additional services and revenue opportunities moving forward on top of what you're doing with SD-WAN today?

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Yes, we definitely handle much more than the web traffic. That's why the SD-WAN, they can base on application, based on different type of traffic, have different security policy or networking policy. Our customer base for SD-WAN is much broader than the WAF. At the same time, they're also not just the traditional replace traditional MPLS. There's a lot of a case, whether the enterprise branch office or retail, which they traditionally using some other 4G or some other connection or some other like a lease line connect, like some different kind of connection there, which using SD-WAN can lower the cost a lot, at the same time, can be more secure, can be more like responsive what application need in real time. That's where we see a lot of use case, and I think it's because we have more than 5 million deployment.

Actually, we just see so many customers starting interest to using even some other device already deployed is starting using SD-WAN as some additional service. That's where some is new sales, some is using existing box to enable some function. That also will help in and also give us a kind of a more like a stickiness or whatever, more stay close in with the customer. We see it's a very good function helping grow the business and also enable bigger deal and also better service and helping more margin.

John Maddison
CMO and EVP of Products, Fortinet

Thank you. Again, I would say that our goal is definitely to win that SD-WAN controller footprint. We believe you need to protect into the LAN, so you're going to need security services for that. At the bare minimum, you're going to need firewall and VPN services. We can add secure gateway if you want that right there. We can add SASE . We can add a whole level of services. We have a lot of customers who have Zscaler as well inside there. For us, it's winning that controller piece to make sure we can secure the LAN and the WAN and the edge there going forward, and then we'll support different cloud on-ramps going forward.

Peter Salkowski
VP of Investor Relations, Fortinet

Okay. On that note, who's got the clicker? I need the clicker. All good. Next presentation will be actually two folks. Patrice Perche from-- actually based in Europe, of all great places. Our Senior Executive Vice President of Worldwide Sales will present, and then we'll have Matt Pley, our VP of Cloud and Service Providers, come up and talk about some of our cloud strategies, followed by Keith on the CFO slides, which is the only reason you're all here. We all know that. We'll end with another Q&A at the end, about 12:30. Again, if you do need to use the restrooms, that door sticks, I'm going to try to get it to stay open. With that, Patrice.

Patrice Perche
Senior EVP of Global Sales, Fortinet

Yeah. Thank you, Peter. Now Peter, do we need to wait before starting or?

Peter Salkowski
VP of Investor Relations, Fortinet

No, go ahead.

Patrice Perche
Senior EVP of Global Sales, Fortinet

Okay. I'm Patrice Perche. I'm leading the global sales. I've been 15 years in the company. Ken asking me to build international business, which we've been very successful. We are number one, so much bigger than our two direct competitor, both on revenue and unit ship. We acquired many country, almost over 20% market share. Four years ago, Ken asking me to, of course, look about how we can transform the North American market to capture, in fact, the bigger market size here. With all what we have seen in term of product, I think the company has the best product and the more, I'll say, broadest offering on the market. In my experience, it's not, in fact, the technology that potentially avoid us to penetrate, in fact, the wider market, especially the enterprise market.

We have been proving that's happening, we are acquiring the biggest, in fact, enterprise customer outside North America. You have seen that, of course, there is a lot of opportunity that with the innovation that we bring, can accelerate, in fact, the growth. We are growing above almost three times the market growth. You have seen our Q3 result and since 2019, very strong, I will say, result. Let me share what has been driving, in fact, this great result and looking how we can even grow faster in the near future. The product offering, as I was mentioning, is quite unique, and we are unique on the market as we are able to address the three market segments. We are not just only playing on the enterprise segment. We are able to play on SMB market, enterprise, very large enterprise, and service provider.

We have been very strong, especially on North America, on serving the mid-market, especially service provider, going up. Of course, outside U.S., we have been very strong, delivering, in fact, all the three market segment. That of course offer us a very large opportunity, much wider than our direct competitor, that are mostly playing on the enterprise segment. It's all about sales execution. The go to market when you address the three market segment are slightly different. When you're entering on the mid and the low-end part of market, it's mostly a sales and a channel motion, and it's of course rely a lot on the partner. I will come back on this aspect. When you address the enterprise or the service provider space, we're talking about direct touch engagements. That's what we have built, in fact, during the last two years.

That's starting to generate a very strong result across the board, but more specifically North America. Knowing that we are going very deeper on this segmentation per segment, but inside the enterprise segment, we are also going on the verticalization. We are going much deeper on FSI, healthcare, government. We have been building inside our sales organization, the motion that address a true value proposition for each of the segment. That's what make a significant difference on generating, in fact, constant result and growth. I will highlight that as you know that the service provider space has been a bit soft. We have been growing very nicely in North America, and that's been mostly driven by enterprise growth. It's really starting to generate, in fact, the result of this sales strategy.

My goal is, of course, to fuel the engine, so hire more people and be able to align the people, the right people for each market segment. You will learn that we have a significant wide space opportunity. As we have been able to grow very nicely on this enterprise segment on site, as I mentioned. North America, that's where we are now getting back and capturing, in fact, a much wider portion. I will say, even if some of our competitor has been maybe strong on capturing the core business or the We are getting back with the edge, and this SD-WAN opportunity to also open the door to enter on this enterprise edge segment.

It's a strong, I will say, vector to penetrate the enterprise while, of course, leveraging our platform and the value of the platform. When I met CISO across the world, they're all concerned about what cybersecurity can provide as a business outcome. They want to see us helping them to go on this digital transformation journey. It's all about unlocking, I would say, the digital innovation. Cybersecurity has been the biggest challenge. The second point is all about how cybersecurity can--. They know they need to increase their security posture, but they can't spend more. How we can also provide cost saving, and there is multiple area where we can provide cost saving.

SD-WAN is a perfect example where instead of spending a lot of money on WAN and MPLS, you can of course invest on more, let's say, advanced technology that can secure your data and your networks. This verticalization and of course segmentation is critical. That has been really the pillar of our sales strategy since now three years. Takes time to build the motion. What I'm pleased to say is that we are able to hire the best people in the service team. Fortinet now, especially in North America, we are known as a very strong player. We are onboarding a lot of our strong talent. It's capacity, which of course has been driving a lot, and who Ken has been sharing this for many, I will say, presentations.

It's really generating, in fact, and we continue to fuel the engine by increasing, in fact, our direct touch team and with the right people. Then, of course, as you can see, it's about how we drive, in fact, the pipeline role. We are, of course, able to capture new opportunity, especially in fact gaining a white space or new customer. We definitely, as I was mentioning, growing three times the market. We are, of course, replacing legacy vendor. We are acquiring net new customer every week, every day. That's part of the strategy, why we will have also a strong reserve of growth by expanding our product for customer that already acquire Fortinet and are expanding with the platform. Let me go to the pipeline growth and where is the pipeline going.

You can see here in this chart that we have been able to grow very nicely, in fact, our pipeline, thanks to the marketing effort. I know that companies pursue us more as an engineering company, but we making a lot of effort and spending on generating, in fact, the right branding and the right communication to the market. It's also directly fueled by the investment we did. Over half of this growth in term of the pipeline come from our direct touch team. It's the direct seller that engaging visiting customer, expanding, in fact, our presence and building the pipeline. About 30% is coming from our channel, which you see now winning a lot of projects.

They also, thanks to the dealer registration portal that we build in place, are able to generate also pipeline generation at about 20% of our investment done on BDR and BDS, which of course drive also additional, in fact, opportunity for us. Of course, we have, as John was presenting and Ken, we have multiple opportunity. The Fabric platform is really embraced by most of the enterprise, mid-enterprise. We see, in fact, very big project where we are selling up to 10 different product. Why? Because that provide the simplification that they require, the automation at a better coverage. When you go up on the market, it's made a bit more latency in term of this and the changing and going for one main provider on cybersecurity. They are more using and transforming their infrastructure by use case.

That's typically the different use case where we are leveraging on the enterprise to penetrate the enterprise, where we see clearly that this message about cost reduction, business outcome has resonated very well and becoming, in fact, very mature even on the enterprise level. The go-to-market strategy has been very stable from the beginning. We decided to go through partners. We have an indirect sales strategy. Why? We invest heavily. Most of the investment on term head count is for the direct touch people. We engage directly with end user, but we leverage, in fact, our entire channel ecosystem to go and penetrate the market. The service and the telcos service provider space, as was we mentioned, it was two great announcement. We use them to leverage both mid-market, small market, and even going more on the enterprise market.

On the cloud, we have now a very large, in fact, partnership with all the public cloud provider. Again, these cloud provider are able to address different market segment where we already play. It's an expansion of, I'll say, channel community. The rest, of course, reside among very strong dynamics in term of the existing strong key cybersecurity specialist, a size and large company that help to bring this. We definitely continue to maintain this strategy, which is really paying off. The challenge we see is that I was mentioning some of the, I will say, SD-WAN or maybe cloud vendor security that try to go to the partner, to the service provider. What we see, the service provider is losing, in fact, their, I will say, control to people like Zscaler or the other one. They see that they have lessened value. Why?

What they're asking us? They ask us to help build the same motion. Our strategy is to build based on our technology, in fact, to leverage the service provider data center around the world to push the same technology to the customer. That's what resonated very well because at the end of the day, they have their business to grow and their MPLS is going out. If they lose the control from the cybersecurity, they will have a very challenging situation. I can tell you that why it was easy for the service provider to click and use some of those providers, they are changing and shifting. We are there to provide infrastructure to deliver similar services to the end user. Of course, where we have our largest, I would say, growth opportunity, it's on the Global 2000 very large customers.

Again, here we have very great, in fact, strategy on moving up the market. You will see very nice results and nice announcements that are coming on this space. Overall, I'll say we are able to maintain very high growth. Enterprise segment, that's where, in fact, we are fueling, in fact, the acceleration of the growth above the 20%. Talking about white space, of course, you can maybe see, are we limited? You understand that, yes, we have three major opportunities to drive the market. When you look only on the Enterprise segment, why we are hiring a lot of people, and we have been able to, of course, continue to increase the capacity. We also try to reduce the number of accounts they manage. It's about sales discipline and be able to have much more focus per account.

We bring more people on board, we start reducing the number of accounts that the reps are managing, both on a major account manager with target enterprise, but also on the mid-market with name account manager. You see here that we have a significant opportunity, almost like two-thirds of the pipeline, that can continue to, in fact, be addressing this approach. What can we do, of course, to continue to fuel the engine? It's about capacity and, of course, as you hire new people, cost. It's how we can get those new reps on board more productive and very fast. We did invest this year, in fact, heavily on system and tools. We were using our CRM, which is Salesforce. We have been acquiring a new module, it's called CPQ from Salesforce, which allow us to do quote to cash.

We continue to invest on system, as you know, we have a significant sales population to increase the productivity and increase, in fact, the ability to generate revenue on the very short timeframe. We also have a lot of data. We have more than 5 million appliances and over 700,000 customers worldwide. The data are stored in a system. What we do with the MDM, we are now consolidating all the data, be able to leverage our salespeople to upsell with the right visibility about what is the current customer inventory in term of product. That's another level of growth for the future. Sales enablement, part of course, the sales strategy to increase productivity is critical.

We have also built with the sales training team, a lot of value leveraging our NSE Academy to train our own people, but as well training on the sales approach to pitch them how to address this different segment depending on the role they have on the company. We're also leveraging a lot of new tools to generate customer intelligence, to be more efficient and addressing and targeting the customer that are ready, in fact, for those transformation. Also the marketing, we are building a very strong lead, I would say, demand generation team by sales rep, BDR. We continue to fuel this aspect as well to help driving the pipeline, as I was mentioning earlier. It's contributed already by 20% growth, so it's an important motion. Again, I was mentioning about the channel.

I will say our channel strategy has been very strong, and I think we have been considered as a trusted partner from day one. That's what I think make Fortinet successful. You can see here that we have very different profile, and we are about to launch, in fact, early next year, we announced already accelerating 2019, kind of revamping all the program to make sure that all the different category of partner can fit and benefit from the business development, in fact, this program. As you can see, we have a lot of accolades and great reward and award from the market in terms of our channel strategy.

I can just confirm that we are very cautious about our channel because that's been driving our business, and we are moving with an advanced, in fact, channel program that will even accelerate, in fact, the collaboration with our partner. The Fabric really resonate across the board, as we was mentioning earlier. This chart show you, in fact, how our sales rep are able to sell. As you see, almost two-thirds of our sales population, including the new hire that we hired this year, have been able to sell more than five products of the Fabric. The Fabric is really now in the real motion inside our sales organization. That, of course, drive the value of expanding, in fact, the wallet, expanding the share that we can get from the customer, and of course, increasing the value per deal.

Of course, delivering business outcome for our customer. What we'll do for 2020 as we continue to move forward, I don't think there is no rocket science here. We are very constant on trying to continue to execute well. You have seen result has been there. We will continue to hire and fuel the engine by sales hiring, looking about where we have white space, how we can quickly put more people on board, getting the best people on market. The goal is to move up also potentially from 3-3.5 times pipeline, so in quarter pipe. You see my previous slide where we measure every quarter the pipeline and how we grow. This sales discipline has really landed to a great, in fact, acceleration of the pipeline.

It also give us, in fact, I would say, a longer term visibility on how we can generate, and I'm sure I will reassure investor about how we control the growth. Of course, focus will be about productivity, as I was mentioning. Getting those people on board quick, making sure they have the right tools we can automate. We continue to invest. There's new tools coming on early January, that also should help to better control, in fact, this big engine that we have on the sales side. We, of course, on the sales strategy and product, we continue to sell the platform. The platform resonate, that will be the key focus for 2020. I know that many question sit about you are more like an appliance or hardwares company. As Ken was mentioning, of FortiWeb, it's very strong.

The engineering team delivering the software is maybe the biggest aspect as well, and not necessarily very well known outside, but I can tell you that drive, in fact, a lot of value with our customer. Today we have the broadest cloud offering, private and public cloud offering. We are able to provide one single pane of glass leveraging, in fact, the different scenario to cover the cloud, the core, the edge, and data center. That's what customer asking for. I know that there's of course, many questions. I'll ask Matt to come on board, to share more about the cloud strategy, so you can understand that we are very strong here and we are getting share as well here.

It's not that if the market is moving out of the, I would say, the appliance, there will be disruption. Our vision is that we will be a hybrid and, of course, a much more complex environment to secure, and cloud is important and cloud is strategic. Let me introduce Matt Clay. Thank you.

Matt Clay
VP of Cloud and Service Providers, Fortinet

Thank you, Patrice. Good morning. Still morning, I guess. Some of you were at our Cloud Analyst Day back in August, I already heard a few questions about cloud, which is fantastic. Sorry, I'll get close to the mic. I think there is a lot of confusion around cloud, or at least questions around cloud. What does cloud mean to you, and how do you use it? How do you adopt it? I think we're here to solve some of that. The opening slide that I had back in August was: how do you set the market for cloud? How should we think about cloud, and how are businesses or enterprises adopting cloud? I think the first part of this, when looking at how do you get to the cloud, what is the experience while using cloud?

Such a big part of, I think, how clouds are used, when you say cloud, is that public cloud, is that private cloud? Are those clouds talking together? That connectivity is such an important element to the user experience. Then you layer on top of that, you layer on dynamic cloud, which we call dynamic cloud, which is workloads moving back and forth through public cloud and private cloud. You see, I think the market data for supporting that is, on average, most people use one and a half clouds, which I'm not really sure how they got to that statistic, but in any event. One and a half public clouds is typically what customers use, and because of that, they're also obviously using private cloud on top of that. Then the cloud really is broad.

The landscape is pretty vast, and I think there was a question about the native integrations with cloud, and I'll talk about that in a second, but it is a good point. I think we talked about, Brad, I think we talked about one time some of the product offerings they have, and how do we integrate with those product offerings. The cloud creates just a unique attack surface. It's not because cloud is bad, it's just because cloud is used differently from usually ingress, egress coming off an enterprise. I think we all know this, but there's a shortage of people in the industry, and so that compounds all of these things in making cloud work effectively, and that's what Fortinet's here to solve. This is a very busy slide, so I'll try to talk through this as best I can.

Really, the solve for us is Secure SD-WAN to on-ramp to the cloud. That's such an important element, how to use and get to cloud. John, to your point, what you said earlier, I think a lot of people think of SD-WAN as a branch to campus or hub and spoke, if you will, back to it. What we're seeing is actually private cloud to public cloud use. That's a big element of why people connect, I think those two elements together. We believe that the SD-WAN on-ramp, the cloud on-ramp, will serve as a big competitive advantage for us. Dynamic multi-cloud. Private, public SaaS, so delivering from the public cloud or down at native services. The cloud-native services for us is that when we talked about our SaaS WAF, as an example, that's built in AWS.

I think you had a question about some of the native integrations, GuardDuty or Macie and those kinds of integrations in AWS. Well, our solutions absolutely plug into there, what we call through a connector. For those automation stitches, we call that a stitch for the automation through the API call into those native integrations. When using some of the services, either native or built natively into the cloud for us as a SaaS offering, those are absolutely paramount to how to work with these environments. Of course, CASB on top of that. Then, how we're looking at the attack surface is really offering multiple products together via the Fabric.

Really taking not only just the FortiGate itself, but then using WAF, using sandbox, some of those native integrations alongside of our products is very important and key and paramount. Single pane of glass, how do you see and view all of this together, is the biggest, I think, challenge that you'll see in public cloud. Having a unified security posture is the key element. There was a slide that I showed back in August, which essentially showing the broader picture of your environment from a topology view and viewpoint. It's really not about where you're using or how you're using it and what form factor, it's about how the security enforcement takes place. Then, I just put down a couple of use cases, at least from a customer standpoint.

I did want to provide how cloud expands our market opportunity pretty uniquely, I think, in the market. We do a number of things when we market to cloud, and one of the key, I think, parts of cloud is the web app firewall. Web app firewall for us is, you can use it natively or you can use it SaaS-based in cloud. What we do is we fuel that engine by marketing to the impression. You'll see 14 million impressions is what we get from the advertisement of cloud. Of those, 45,000 visitors come to our website, and then of those 45,000 turn into trials, 3,500 of those turn into trials, which then equals about 1,400 new customers. If you do that, it's about 60% conversion of trials for us.

On top of that, as an example, 75% of those also have hardware for us. This serves as a very big opportunity for us because it brings brand awareness, but it also brings the ability to stitch together multiple products together, in public cloud. With that, I'd like to invite up Keith Jensen, our CFO.

Keith Jensen
CFO, Fortinet

Good morning, thank you for joining our Analyst Day and our 10-year anniversary celebration. As Matt Pley noted, I'm Keith Jensen, the CFO of Fortinet. I've been with Fortinet for about five years. A little legalese stuff to follow up on Peter's safe harbor language. Keep that in mind as I go through my presentation. Before I start, I'd like to share that references to 2019 full-year results are based upon our midpoint of our guidance that we gave on October 31st, unless we say otherwise. Of course, financial amounts that we provide today are non-GAAP, except for revenue, unless we note otherwise. Okay. During the course of the presentation, I'll share some key concepts and metrics that are designed to show the consistency, the visibility, and the predictability of our business model.

That together with our diversification, enables us to grow faster than the market, increase our profitability, and execute consistently. I'll frame up the presentation by starting with revenue and margins, then I'll move on to billings. I'll go a little bit deeper on a couple of areas like Fabric and SD-WAN that have been talked about, perhaps a little bit on some metrics as well, and wrap up with cash flow, some discussion about capital, and then, of course, the model. I'm going to guess red is backwards.

Matt Clay
VP of Cloud and Service Providers, Fortinet

First and green and then the white.

Keith Jensen
CFO, Fortinet

That green button. Do you know there's two green buttons on here?

Matt Clay
VP of Cloud and Service Providers, Fortinet

Big one.

Keith Jensen
CFO, Fortinet

Thank you. This is well-rehearsed, if anybody's wondering. Okay. The chart on the left tracks our annual revenue growth. It highlights our combined compounded annual growth rate for the last three years or our CAGR, which has been 19%, and that's well above market average growth rates, as you know. Product and service CAGRs during that same period of time were 13% and 23% respectively. These growth rates are driving the mix shift that you see in services. We're seeing a shift from product revenue to the more predictable, higher margin service revenue, specifically 57 points to 63% of our revenue over a three-year period of time. Roughly two points per year in movement. As we talk, 63% of our revenue right now comes from service revenue. Okay. A total of 95% of that service revenue comes from two security offerings, FortiCare and FortiGuard.

We typically attach these two security offerings to each of our appliance sales. As you'll see later on, we often attach them also to our Fabric product and software solutions. FortiGuard is now the fastest-growing of the two. It represents about 55% of that service. If I talk a little bit more about the growth drivers on those two service offerings, I would share with you that we've seen FortiGuard and FortiCare move from single individual security sales to bundles of security. Specifically, FortiGuard now represents about 85% of the mix in bundles. That's up 15% in just over three years. In FortiCare support, we've talked before about the continuing mix shift from eight by five to 24 by seven. That mix shift has continued, and we expect it to continue. Currently, 24 by seven represents 56% of the mix, 44% is eight by five.

This slide tells us several things about our business model. The first thing you'll note is our two-year CAGRs are fairly consistent across geographies. We see APAC at 17%, the EMEAs and the Americas at 19%. We talked in our third quarter earnings call that we had some work to do with APAC related to hiring, and as Patrice talked about increasing capacity, and that work has started, and I'm pleased with the results. The second aspect of this is that it highlights that we are somewhat unusual for a U.S. tech company, and that the majority of our business is international, it's not in the U.S. With that, it sets up a discussion for us about the opportunity that we see in the Americas. We note that 42% of the business is in the Americas, but keep in mind, that includes Latin America, the U.S., and Canada.

If you tease out just the U.S. subset of that, the U.S. is less than one-third of our worldwide revenue. With that in mind, that's why we view it as an opportunity for growth, Patrice talked a moment ago about the enterprise opportunity in the U.S. Okay, staying with the income statement and just going through margins quickly. The chart on the left tracks our three-year trend in gross margin. The very simple explanation for that is that's that mix shift we just talked about of moving from product to services and the move up that we're seeing in our gross margins. The chart on the right tracks both non-GAAP and GAAP operating margins. Our non-GAAP operating margin is expected with this year to be 920 basis points in total growth over that period of time.

One of the drivers for this, of course, is the gross margin, but it's also the CAGR in revenue that we talked about a moment ago at 19%. If you look at our revenue growth and our CAGR growth, if you take revenue growth and add to that the operating margin number, if you will, and you apply the rule of 40, what's interesting to note is for eight of the last 10 years, we've ticked above that milestone for the rule of 40. The second line provides the operating margin on a GAAP basis. Unlike some of our cybersecurity peers, Fortinet has been GAAP profitable and has been GAAP profitable for every year as a public company. Let's pivot to billings. This chart provides the breakdown between FortiGate and non-FortiGate.

As you can see that FortiGate represents, or firewalls, about 75% of our billings, and the CAGR for FortiGates is about 17% for the three-year period end of this year. Non-FortiGate, which includes Fabric and Cloud, represents 25% of billings. We expect Fabric and Cloud portion of that to have a CAGR by the end of this year of 35% for that three-year period. Non-FortiGate also includes other. Other is that little purple part at the very, very top. It includes things like professional services, training, and non-FortiGate or non-Fabric products, such as phones and cameras and legacy access points. The other portion of our business does not contribute meaningfully, if at all, to our growth rate. Okay, let's look a little bit deeper in what we call non-FortiGate.

This segment, we've taken out the cats and dogs that are in other, and you can see the mix between Fabric and Cloud and the dollar amounts involved. Combined, Fabric and Cloud will grow probably a little bit over 31% this year. We expect billings for the entire year for Fabric and Cloud to be $525 million. Okay, we're going to get really detailed, and this is designed to answer the question of what's what. People understand what's in Fabric and what's in non-Fabric. If you look at the two main headings, you can see FortiGate and non-FortiGate, and right below that, you see the subheadings for groups of products and solutions that are included in each. Below those subheadings, you see the actual product that's in each of those groups.

As John mentioned earlier, our marketing convention is for the sake of salespeople and finance people, Forti whatever it does. It also tells you what FortiCare and FortiGuard security subscriptions attach to those products. If you take as an example, underneath FortiAnalyzer or underneath solutions, you see FortiAnalyzer, very top line. You can see that that particular solution is included in the Fabric group of products. You can also see that it's part of non-FortiGate. If you look across a FortiAnalyzer, you can see that it's available in a hardware form factor. It's also available in a virtual form factor, and you can also acquire it through the cloud providers on a pay-as-you-go basis. If you continue on, you can see that it actually comes with FortiGuard and FortiCare as well. It's a bit of a reference sheet.

I want to make sure that you have an example and an understanding of it, and we'll post it to help people understand the business a little bit more. I also want to call out the far left-hand side, and there you see our 3 segments of firewalls: entry point, mid-range, and high-end. You'll also note the numbers in parentheses. Those are the number of models of firewalls that we provide. That's about 90 different firewalls. I think some of our competitors are about 15 firewalls. I want to offer a couple of points about these 90 different firewall models that we provide. First, they're designed to address a wide range of use cases, from large data center applications, branch, campus, and edge applications.

The second part of this is that we upgrade and replace our own products, as you heard earlier today about some new chips that are coming out very frequently. This internal refresh process is continual, and typically, when a new product comes out, you will not notice a spike in revenue for an individual period. It is a continual process. One element that's improved to the consistency in our financial performance is the diversity of our business, whether that's by customer segments, whether that's by geographies, or whether that's by industries. There's three pie charts here, and I'll start in the middle. That middle pie chart talks about each of these are billings for the first nine months of this year. What you see in the first pie chart is that the larger economies dominate the percentage of billings that we have.

Specifically, six countries, those larger economies, represented 51% of our billings in the first nine months. What's interesting about Fortinet is that 49%, the remaining portion of that, came from countries with smaller billings. Specifically, no one country of those 80 had more than 3% of our total billings. Very diversified. Part of that is it helps us mitigate when something pops up in a certain country, whether it's a geopolitical event or something else. We often get questions about what's happening in a specific economy, with that diversification, you get a sense of why one individual company doesn't necessarily cause us concern when we're setting our guidance. Okay? Moving to the left, you can see the mix of our customers, right? 34% is SMB. We add to that 24% for mid-enterprise and 43% for enterprise. I apologize, that doesn't total 100%. We'll fix that later on. Okay.

Keep in mind that 43%, it also includes the telcos. Over the past two years, we've seen each of those segments outgrow the market. With telco included in the enterprise segment, in terms of measuring our actual market growth in the enterprise segment, if I move the telco group out, you'd actually see that, yes, that segment would be a little bit smaller, but the move-up market that I track would be even larger. Moving to the right-hand side is our billings by geography. Typically, just about every quarter that we've looked at this, about two-thirds of our billings come from our five largest verticals. That really hasn't changed.

What we have seen is that while we continue to dominate in carrier, or pardon me, be a leader in carrier and managed service providers, we have seen more diversification now in our verticals. That diversification is really coming from outside growth in other verticals such as financial services, local governments, state governments, and international governments. A lot to digest there, I know. All right. Staying with our billings, let us review some of the key metrics that we have that have led to our more consistent and predictable growth and margin improvement. We framed each of these metrics, establishing a baseline, and then measuring our actual results within a band of ±2 points of that baseline. In the case of contract term in the bottom, ±2 months.

The first thing that jumps out at you is if you look from Q3 2017 onward on each of those metrics, we've stayed inside the band. We've been extremely consistent for about two years on each of these metrics. Let's go around the horn a little bit and talk about each of them specifically. On the top left, we have renewals. This sets as a baseline our average renewal rate for three years, and then establishes guardrails that are plus and minus 2% of that renewal rate. Having now explained it a bit, you can see that for over two years, the renewal rate has remained very consistent. We've stayed inside the guardrails. Moving clockwise to the top right-hand corner, we use a similar concept here, but in this case, it's our three-year discount average.

Again, I've established a baseline, put two guardrails, one +2 points, one -2 points, so you can see how we're comparing on our discounting period-over-period and the consistency of it. One twist here, when that particular dotted line moves down, that's a good thing in this chart. Less discounting. Moving down to the bottom right-hand corner. This chart illustrates the predictability of our service revenue. It tracks the percentage of service revenue each quarter that was recognized from deferred revenue as of the beginning of that quarter. We've talked publicly that it's at least 90% every quarter. Remember, we're shifting more and more of the revenues to higher margin, more predictable service revenue. In terms of predictability, you can see each quarter we start off, and I'm setting guidance, I know where 91% of my service revenue is coming from.

It's coming from my balance sheet. Lastly, back over to the lower left-hand corner. In this chart, we're showing our average contract term or trend. You can see that for a period of about 18 months in 2016 to 2018, our contract term moved up about four months, from 21 months to 25 months. That's a 20% increase. For the benefit of all the salespeople who have joined us from my N.Y. office, I keep track of this because I judge the quality of your billings. I judge that same quality, use discounting in the same way. Between discounting and contract term, I have a pretty good idea of the quality of the billings that we're seeing each and every quarter. I mentioned earlier that we've been in the rule of 40 club for eight of the last 10 years.

The last time we were not was 2017. It's interesting when you look at 2017 on this particular chart, you see that 2017 was a period of volatile discounting, higher renewals, and increasing contract terms. Okay, is my ASP going up? Yes. That was the question. ASPs can go up for a lot of different reasons. Distributors can order in larger quantities. We can change the price list and so forth. Yes, ASP is going up. What I have for you here. I got to get on the right page, I apologize. What we've done on the left-hand chart is track deals over $500,000 and deals over a million dollars. The million-dollar deals are in the dark blue. Keep in mind, we've also talked that no one deal since Q1 of 2017 has represented more than 2% of any quarter's billings.

I have a lot of million-dollar deals, but they're not mega-million-dollar deals. The chart on the right represents the dollar value that we receive from the million-dollar deals. You can see that for the first 9 months of this year, the total is $268 million, which is up about 34% year-over-year. Yes, we do see our newest firewall use case, Secure SD-WAN, providing a tailwind to these metrics. I say the newest firewall metric, and I'll pause here to emphasize 2 points and follow on comments that have been made earlier this morning about the history of the FortiGate Firewall. First, the FortiGate Firewall has shown to be the cornerstone for consolidating security functionality over an extended period of time. Second, with the ASIC compute power, this means expanding capacity. Expanding capacity means adding more functionality. Most recently, SSL encryption, de-encryption, and Secure SD-WAN.

Now for the star of the show. IDC has been very kind to us recently, talking about our Secure SD-WAN solution. In the second quarter, they noted that our market share had basically moved in one year period from zero to 11%. They commented that our Secure SD-WAN billings were about $45 million in the second quarter of 2019. They've also pointed out that we're the only firewall vendor that has Secure SD-WAN functionality built into the application. Secure SD-WAN has been a feature in our operating system for a few years now, and it's really come to life as companies have recently focused on securing the edge, minimizing the number of applications that they have to manage, and reducing their MPLS and other transportation costs. The chart on the left provides year-over-year billings for the third quarter. It also breaks it down into product and service mix.

The product is the light blue bar, and the services are the dark blue bar. When you look at our largest deals represented here, those deals over $250,000, the mix between product and services runs 35%, thereabouts, for product and 65% for services. A few things to note then, as we've commented before, we do not charge separately for a Secure SD-WAN. It is built into the operating system. It is part of a firewall sale. That product and service mix I just gave to you is very similar to other product and service mixes for all of our other use cases. In terms of revenue recognition, it's just like everything else, product upfront, services over time. Now more detail about Secure SD-WAN.

There's a series of pie charts that are based upon our billings for the first nine months of this year. It'll give you a sense of some of the characteristics on the customers that are requiring Secure SD-WAN. I'll offer probably a point on each of these. First, the pie chart on the left provides the firewall mix. Again, as part of a firewall. You can see that 25% of it is high-end, but the majority is mid-range at 44%. In terms of geographies, as you typically see with a newer technology sale, it's dominated first in the Americas and in the European continents with APAC to follow. That's the purpose of the second pie chart. The third pie chart tells you what type of customer we classify them as, small business, medium-sized, or large enterprise. Yes, it is obviously a larger enterprise sale.

Yes, again, it is opening the door and creating opportunities for us inside organizations that we currently or previously were not a part of. John and I are going to have a debate afterwards about how to measure Fabric partners. He's in the hundreds. I'm not quite there yet. This is a subset of our Fabric partners. I measure that at 74 currently, and we're growing those at about 50% per year. We'll probably retire this metric, but I want to make the point while we're here about the importance of our Fabric partners. The Fabric Partner Program enables other security vendors to integrate their technology into ours and provide greater automation and centralized management. No matter how John and I count them, that's the purpose.

Strong billings, deferred revenue growth, profitability, and better inventory management have all contributed to a significant step up in our free cash flow margin. Specifically, we've gone from 24% in 2016 to year to date this year at 39%. We expect deferred revenue, one of the largest drivers to our free cash flow, it'll surpass $2 billion this year, and it will grow over 20%. I think we've made the point today that this strategy is consistent with our belief that it's critical that the Fabric platform remain tightly integrated to the product suite.

It's no surprise then to see that we spent about $850 million in R&D since 2015, or that we have over 600 patents outstanding, and that our M&As have been largely described as tuck-ins. When you look at our tuck-in M&As, we've used about $100 million since 2015 to acquire technologies like SIEM, Endpoint, NAC, and others. In terms of returning capital to our shareholders, starting in 2017 through the end of the third quarter of 2019, we returned about $773 million of capital through share repurchases to our shareholders, and that's about 40% of our adjusted free cash flow during that period of time. Ken wants me to make sure I make this point very clear. Last week, our board of directors approved an additional $1 billion for share repurchases, bringing the remaining total that's authorized to $1.6 billion.

The board also extended the expiration date to February of 2021. No changes to guidance for Q4 or for the full year. This is a legacy slide that helps with some of the modeling of 2019, if you're looking at it for any reason. One item to note, though, is that I have added to this slide a first look at total CapEx for the year 2020 at the bottom. The second building of our campus is scheduled to be completed in the fourth quarter of 2020. We expect to move in partially in October, and again to the rest of the company in November. As such, we expect elevated total CapEx in 2020. A few years ago, we described a balanced operating framework that we wanted to operate in. That included increasing revenue faster than the market and increasing our profitability.

The table on the left grades our performance on that first element, revenue growth faster than the market. We expect to organically grow, the cybersecurity outgrow the market by more than 7% on average from 2017 to 2019. The chart on the right evaluates our performance on the second element of that framework, increasing profitability. Here you can see the expected margin improvement over the three-year period of time, taking us to 24.3%. Clearly, we're pretty pleased with our execution. All right. With that in mind, let's talk about what we see for the next three years. As I tee this up, I'll say including the 2019 guidance we noted earlier, again, that rule of 40 tests, you take the sum of revenue growth and the sum of margin, eight of the last 10 years we've been in the rule of 40.

With that in mind, our expectations for the next three years, we expect billings and revenue growth to be at least 15% in each of those three years. It's organic growth, and yes, it's higher than the current Street estimates for each of the next three years. We expect our non-GAAP operating margin to average at least 25% over the next three years. We will provide more detailed guidance for 2020 in our fourth quarter earnings call in early February. In the interim, I'll offer just a little bit of commentary about setting these expectations in our modeling. Multiple factors were considered when we determined our expectations, including market growth rates and our ability to continue to outgrow the market.

When looking at market growth rates, we also consider that IT budgets will continue to grow, but the security portion of that budget will grow faster than IT budgets as companies continue to prioritize their security spending. When looking at our ability to outgrow the market, we consider our ASIC advantage. We believe we'll continue to have a lower total cost of ownership, and that the ASIC security compute advantage will continue to provide an advantage to us. We believe we'll continue to add new firewall use cases as we have done with Secure SD-WAN. We expect revenues from our existing Fabric product suite to continue to grow, and we expect to add new products to the Fabric suite. We plan to continue to increase sales capacity in consideration of our pipeline growth and our revenue growth.

As a result, these models indicate that we will continue to achieve the rule of 40 in each of the next three years. All right. The next slide just kind of summarizes the drivers for our business, and I'm going to leave it up while I invite Ken, Patrice, Matt, John, and the rest back up for questions. Okay?

Peter Salkowski
VP of Investor Relations, Fortinet

Okay, as I said earlier, the goal is to end at about 1:00. We're at 12:21 at this point, so we've got about 40 minutes for questions. I'm sure you guys can fill it. If not, we'll finish early. We will start taking questions of the panel. Again, guys on the podium, please do use the microphone so they can hear it on the webcast. For those that have questions, please wait for the microphone. As a reminder, the slides should be up momentarily.

Sterling Auty
Analyst, JPMorgan

Hi, Sterling Auty with JPMorgan. Just on that three-year guidance, I think the one that immediately jumps out to a lot of us is the operating margin. If you're 24.3% in 2019, you're talking about greater than or equal to 25% for the three years. How should we think about that? How much is the greater than versus the equal, and where are those investments going to go?

Keith Jensen
CFO, Fortinet

Well, first of all, Sterling, you told me you were leaving early today, so we made sure you got a chance to ask your question, so you can leave now. I think that, again, I purposely framed it up by showing the operating margin improvement with a slide preceding it. I believe that we feel very good our ability to continue to improve margins while continuing to grow the company. I think the next logical step, we've gone through, I think a very nice quarter in the third quarter. We raised our guidance for the third quarter. We provided the long-term model now, which I think represents an increase, and I think the next time to really talk more in depth would be in our guidance that we provide in the first quarter of 2019.

Keith Bachman
Analyst, Bank of Montreal

Hi, Keith Bachman from Bank of Montreal. I'm always comforted by the fact that I don't think you'll forget my name. I had two questions. One is the follow-up, though, that I asked previously. I appreciate you indicated that the SD-WAN billings have grown 5x, I come back to how do you know? Again, I assume the largest customers you probably have pretty good feedback, the breadth, including channel partners, as you deliver more, how do you know? I have a follow-up question.

Keith Jensen
CFO, Fortinet

Yeah. I think what we don't know is if a customer has an existing firewall on-prem, and they're going to convert that to Secure SD-WAN, we don't have visibility to that, right? What you're seeing in terms of this growth and what Gartner is talking about in terms of our percentage of the market share, that's excluding whatever may be happening behind the scenes inside of an organization. This is just the purely additive part of the business that I'm getting paid for.

Keith Bachman
Analyst, Bank of Montreal

Right. It could be larger.

Keith Jensen
CFO, Fortinet

Yes. I would expect that it is, but I don't have visibility to it.

Keith Bachman
Analyst, Bank of Montreal

Okay. Thank you. My follow-up question is just talking a little bit about Fabric and how should we think about that in terms of customer segmentation. In other words, for email or SIEM or those kind of areas, is that more of an SMB solution? Because I was impressed by when you talked about the number of sales reps and the wins they were having. If you could just help us.

Keith Jensen
CFO, Fortinet

Yeah

Keith Bachman
Analyst, Bank of Montreal

think about enterprise versus SMB in terms of the adoption of Fabric and where you're actually gaining traction. Thank you.

Keith Jensen
CFO, Fortinet

I may ask Patrice a little bit to comment in terms of where he's seeing the sales. Before I do, I'll offer one anecdote that we were out visiting with customers in the Pacific Northwest recently and some very large organizations up there, obviously. There was really within that very large company set, a polarization. I had certain CISOs tell me flat out, "We are a best-of-breed shop. We don't care about platform products. We don't want to talk about it." I had other CISOs from equally large companies say exactly the opposite in terms of the enterprise. Do you want to talk about it, Patrice?

Patrice Perche
Senior EVP of Global Sales, Fortinet

We do see a strong adoption about the platform, with Fabric sitting on six, seven different product, to the enterprise segment. They may be moving a bit faster. Why? Mostly because there is a scale shortage worldwide, they need to automate, and also we drive a lot of the cost benefit. When talking about the enterprise, we mentioned about the branch and the next generation edge branch, where we're sitting here, we're not just selling Fortinet. We are replacing Cisco AP, we are replacing switches from Juniper. We expanding, in fact, the branch. Those customer are looking, I'm talking about very large customer, large bank, large financial. They are looking, in fact, to automate the branch with zero touch deployment and everything which is managed.

That's part of the Fabric expansion that we see and driving a lot of, I will say, revenue. Last, to maybe answer about, do we have our customer using existing Fortinet to do this SD-WAN? If you have seen the chart from Keith, you see that the model that we're selling is more and more mid and high-end. The need to manage those different device inside the edge is quite important. They need also to refresh the hardware. I think we mostly see, in fact, new business coming on this SD-WAN.

Gregg Moskowitz
Analyst, Mizuho

Hi, it's Gregg Moskowitz from Mizuho. Keith, on that SD-WAN pipeline chart that you showed, I think you made a mistake. The Y-axis actually was not included.

Keith Jensen
CFO, Fortinet

Oh, I apologize.

Gregg Moskowitz
Analyst, Mizuho

Two questions for you. First, in terms of the billings and revenue CAGR over that medium-term basis, over 15%, as you said, it is north of where the street is at this point. At the same time, you have a competitor who very recently talked about a 20% billings revenue CAGR over that same time period. You have a lot of tailwinds associated with your business, not the least of which is SD-WAN. I guess the question is, are there any perhaps offsetting headwinds that you think about that might take that average growth rate down to mid-teens as opposed to higher over the next few years? Or is that just some function of conservatism? A second quick question, just a clarification on the CapEx for 2020.

How much of that $210 million-$230 million is related to the HQ as opposed to being maintenance CapEx?

Keith Jensen
CFO, Fortinet

I'm going to take the second question first, then hopefully forget the first one because that's what John said I could do. I think the building will run about $150 million, and you can probably put about $60 million of run rate on top of that and then give me a few extra bucks as we continue to expand the organization. What was the first question? Growth. Look, I think without going into specifics of what we got into very specific modeling when we built the model, I don't think this is the appropriate place to have that conversation. Without tying any of my commentary to the specific %, I would say I feel very good about the team's ability to execute going forward. When people ask me what do I worry about, what keeps me up at night, it's a black swan event.

It's not something that I'm seeing from competitors or something else. It's something that I just don't anticipate that's extremely unusual.

Matt Clay
VP of Cloud and Service Providers, Fortinet

Want to add one thing on that?

Peter Salkowski
VP of Investor Relations, Fortinet

I think that's good.

Matt Clay
VP of Cloud and Service Providers, Fortinet

Yeah.

Peter Salkowski
VP of Investor Relations, Fortinet

I'll let the other guys answer that. Thank you.

I think one of the things that Keith pointed out in his presentation was that our guidance for revenue growth for the next three years at 15% plus is all organic. There are no acquisitions built into that guidance, as opposed to maybe somebody else's guidance.

Saket Kalia
Analyst, Barclays

Thanks. Thanks, guys. Saket Kalia from Barclays. Thanks for taking the question. Maybe a two-parter on the same topic here. Keith, can you just talk about what your assumptions are around public cloud as part of the midterm model? I think it's about $124 million in billings as part of the non-FortiGate. That's the portion that I'm specifically referring to. Perhaps what the profile of those billings will be, meaning pay-as-you-go versus fixed subscription. That's the first question, essentially on pricing around that. Secondly, maybe for you, Patrice, just as you're out there with customers, how is that preference for pricing evolving as more customers adopt virtual firewall? Will the market gravitate towards one or the other? That's the second question.

Keith Jensen
CFO, Fortinet

Yeah, I think in terms of, perhaps not answering, Saket, your question all that directly. Part of the analysis we're going through in building the model is looking at what growth rate assumptions are for the different TAMs that we talked about. I think obviously given the history of the company and the product suite that we have, we can look at the standalone firewall market, if you want to call it that. We know what that percentage is. We feel very good about our ability to grow at that rate and above. We can have a discussion with Gartner about whether or not SD-WAN actually belongs in a separate Magic Quadrant or a separate TAM or not, but I think we have pretty good visibility in terms of what our expectations are for Secure SD-WAN.

When we look at cloud, I think we also, again, I know what my cloud growth has been. I know what the market growth rates are expected to be, I can layer some of that into it. Yes, there's a lot of what-if analysis that go into that, a lot of Monte Carlo type work, if you will. I think we're in a comfortable spot knowing what the market's going to grow at and what our expectations are.

Patrice Perche
Senior EVP of Global Sales, Fortinet

Sorry. To answer to your question about the cloud, we do see, of course, demand about VM. You see the large enterprise, of course, are now embracing about the cloud and moving workload to the cloud. They still have quite an extensive, in fact, infrastructure or whatever on the core data center and the edge. If you look from the mix about, we'll say, when we re-embrace the on-prem, I would say, at extra fast and providing the Fabric, we are about 10% of the VM and the rest is more appliance-based. It's really about depending on the use case. If the performance is required, they may go with better, I would say, ROI on using the appliance. If it's more like VM, that's maybe also a bit more agile and all the automation that's already in.

It's really the different use case may land to different choice, but we see, of course, adoption on VM, and we call BYOL, so bring your license, perpetual license on this one. The on-demand is more like if you look from the large enterprise, they may have project where people are starting evaluating and using, in fact, those public cloud provider. That's where they consume, in fact, on-demand security. It's not necessary long-term investment. At some point, they look about the overall cost, may go for a perpetual license or I will say that overall, the shift about the cloud is a bit less than expected, because there was a lot of noise on here. Maybe behind the scene is the cost of this, because to deliver the same performance, to deliver the same value, you need to invest a lot on, I would say, generic computing.

That's what may be driving a bit the challenge. The perception about the cloud, which is secure, it's also a big challenge, because the people feel that, okay, because they go with the public cloud provider, they have the right security, they may have the right infrastructure to do HA and high availability, but not securing the cloud. All this aspect, in fact, is, I would say, slowing down this exchange. We do see, in fact, a very hybrid environment.

Peter Salkowski
VP of Investor Relations, Fortinet

Thank you.

Matt Clay
VP of Cloud and Service Providers, Fortinet

I'm just going to add one point to that. In public cloud, you can do for enterprises, you can do what they call private offer. Private offer is not show up to marketplace and buy, but rather work together in tandem with the cloud provider itself. Additionally, what we're layering on top of that is going to market with our channel providers or channel partners, I should say, on a program called CPPO. It really accelerates the adoption and a broader message with it can be hardware and software together, it can be private, and it could also be public altogether. It's a pretty unique offer, and we're kind of first in from that perspective.

Saket Kalia
Analyst, Barclays

I had a question for Keith and a question for Patrice. Keith, I'll start with you. I think about the discounting slide or the chart on the discounting rate that you put up, and then I also think about the mix shift you've seen on the FortiCare side. That's naturally giving you a pricing uplift. On the FortiGuard side, as you consolidate a lot of this functionality, as you talk about lowering the TCO to the customer, it seems like there's a disparity between what you are charging on the bundles today versus your theoretical ability, given the consolidation and the automation and all these other benefits that you're providing. I wanted to understand to what extent pricing power is contemplated in your forecast going forward, i.e. outright pricing increases, because I don't think you've done that in a while.

Keith Jensen
CFO, Fortinet

We do not, in terms of the modeling, I do not ascribe anything specific to increases in pricing.

Saket Kalia
Analyst, Barclays

A question for Patrice. As you move into more networking-oriented conversations for the SD-WAN use case, that puts you in front of a fundamentally different buyer and a procurement decision maker. What implications does that have for you for the type of sales capacity that you're bringing online? Is that profile very different from the direct sales hire that you maybe hired two years ago?

Patrice Perche
Senior EVP of Global Sales, Fortinet

Yeah, it's a good point. Especially the SD-WAN, so which started almost three years ago. It was more like a networking discussion, so not with the network, I will say, networking people within the enterprise. On the large enterprise, we definitely have these two different groups, the security CSO groups, and then the networking. I will say that we definitely see a lot of conversion. Very large bank are starting to, in fact, consolidate this aspect, having network security tracked approach. What we have done is we have been, of course, training our salespeople very specifically to start engaging with the networking who are within the enterprise. That's what's lended to this discussion, because otherwise, if you stay with the security buyer, you may be stuck because a lot of the issue reside on the networking side.

The announcement we just released today with Orange, one of the largest European, in fact, player in this space, is with the networking side, the people selling WAN, selling the, in fact, the connectivity. It's not the cyber defense, which are different business unit. We do have a lot of engagement with them as well, just to show you that you're right, you need to address a bit this market. We see a conversion between the two roles, the sales motion has been, and the sales team has been trained to address, in fact, the two market. Of course, we discover a lot of legacy, Juniper routing, old, very long product that have been there at the branch. There is definitely a discussion about refreshing the branch at this entire, in fact, environment.

Michael Turits
Analyst, Raymond James

Hi. Michael Turits from Raymond James. Keith, back to margins. The guide one way or another, no matter how you take that 25%, definitely contemplates less annual increase or expansion than we had in the prior one, 50-100. How should we think of that? Is it just that you were starting off a lower base a few years ago, you're getting closer to long-term margins, or is it a different philosophy relative to balancing growth and margins at this point?

Keith Jensen
CFO, Fortinet

Yeah. I don't think it's a different philosophy in terms of balancing revenue margins. I think it is just we're starting from a different starting point than we were two or three years ago when we sort of let out the framework. I think this notion of balanced revenue growth together with increasing profitability has benefited the company very, very nicely for the last several years. I would expect that we're going to continue in that direction. I think that's why in the commentary about what went into the guidance, I made a reference to increasing sales capacity in consideration of, first, the pipeline growth, but also the revenue growth. I'm alluding to that there.

Michael Turits
Analyst, Raymond James

Just a quick addendum to that. Anything you can help us out with relative to expansion and cash flow from ops margins? Should they be at the same pace as?

Keith Jensen
CFO, Fortinet

Yeah, I think, we did a very good job a couple of years ago in terms of changing the inventory turns and management. Drew did a very good job with that. If you look at the large drivers, profitability and margins, of course, will be a large part of it. Billings growth will be a large part of it and the inventory management. We're not anticipating any dramatic changes in our business. We're not expecting to change contract terms or things like that. Obviously, you saw the slide up there. If you go to a shorter duration, it does have an impact on free cash flow, but we're not seeing that from our customers. We're not being pushed in that direction. I think we feel good about it.

I do think the SD-WAN solution tends, because it's an enterprise sale, to tick up just a little bit longer, in terms of contract terms. You get a little bit of a lift there, but we're not really seeing anything else other than that.

Peter Salkowski
VP of Investor Relations, Fortinet

One quick public service announcement. If you are leaving or as you do leave, please make sure you grab one of the Forti bags with a Forti hat. As you register, it is a Forti hat, it says Forti hat. Over on the left, by the windows, if you pre-registered, you registered for a jacket and a size, they are arranged by size. Please grab one on your way out. More importantly, we have Forti cupcakes to celebrate our 10-year anniversary as a publicly traded company, and box lunches are out, so please do grab them. We have this room for a little while afterwards, so you can stay here if you'd like to have lunch, and mill around a little bit. Some of my management team's got to travel, so they may be departing on me.

We'll wrap up in a little bit. I forgot who I was going to next, though. Hang on.

We'll go with you, and I'll figure it out.

All right, great.

Brian Essex
Analyst, Goldman Sachs

All right. Hi, it's Brian Essex from Goldman Sachs. Thanks for taking the question. Real easy one for you, Keith. Cash on the balance sheet's now 11% of market cap, and I heard you highlight the share re-purchase authorization. Is there a level where you think you might get kind of I guess maybe if you could frame out how you think about capital efficiency, and is there a level where cash might get to a point where you might be more creative, or how do we think about, and I've gotten a lot of questions from investors recently, just kind of setting the baseline of how you think about deploying cash and capital.

Keith Jensen
CFO, Fortinet

Well, as Peter reminds me, prior performance is not an indicator of future performance, right? I think, again, we've been very committed to the tuck-in strategy and to the notion that the Fabric and the FortiGates have to be tightly integrated. The types of acquisitions that we've done, whether it was the SIEM acquisition or it's the NAC acquisition, or even enSilo most recently, typically, to emphasize that point, we're in the market typically at $20 million-$40 million, and they may have 30 or 40 engineers. These are companies that we feel very good about, that we can integrate them very, very quickly. Typically, we have some sort of prior relationship with them. enSilo was a FortiFabric partner. Bradford was a Fabric partner. AccelOps was probably a Fabric partner. I think we're trying to de-risk it in that regard.

I think we're very, very committed to it. The second part of your comment is, okay, the buildup of cash, and I think that I would not say that any one quarter we're going to set out milestones or guardrails, to use a term from before, in terms of how much cash we'll deploy each quarter to buy back stock. But when you look at us over an extended period of time, and be able to say that over 40% of our adjusted free cash flow has been returned back to the shareholders in the form of buybacks, I think we feel very, very comfortable about that strategy. Ken, do you want to say anything about

Dan Ives
Analyst, Wedbush Securities

Yeah. Dan Ives, Wedbush. Ken, specifically a question for you on 5G. Where do you think Fortinet plays on 5G in terms of sort of next leg of growth? Seems to me like pretty well positioned there. I'm just interested to get your thoughts.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Our engineer already working on all this technology solution. It's depend on how quickly this business may ramp up. Probably can different country region may ramp up differently. With our experience, like from 10 years ago, integrate Wi-Fi into FortiGate. 10 years ago, where our size too small, impact will be small, or the market will be not quite mature enough within the enterprise. They do deploy a lot of Wi-Fi, the security Wi-Fi is not that high percentage. Now we see the trends starting come up, also starting like 4 or 5 years ago, the SD-WAN development. Also, we do have a SDM development also in the past, also that market also not quite take off.

We do have the 5G keeping developed and also working closely with all the carrier service provider, but also will be depend on how quick it ramp up. Some country outside U.S. probably starting ramp up that's maybe quicker sooner. That's also kind of match our other strategy, like from IoT, some other edge computing. We do believe we're leading this space, and we have very good opportunity once the whole business ramp up. Thank you.

Keith Jensen
CFO, Fortinet

I can vouch for the cupcakes.

Patrice Perche
Senior EVP of Global Sales, Fortinet

Sorry, Peter. Just to add on the 5G, because I think it's an important topic. The typical use case of mobile security, which is currently 4G and 5G, we talk about Gi firewall, CG NAT, SGi gateway. We have of course in the past doing pretty strong, in fact, solution providing to the customer. We have both the solution available on virtual appliance and a physical appliance. 5G real protocol, the change will make complete game change is not yet set. They still discuss about to find this, the protocol, and I think all the party agree. When we talk about 5G today, it's mostly in fact leveraging the 4G technology and I think a bit higher speed, in fact, on the antenna. It's not necessary yet leveraging the full power of the 5G.

We have a very strong collaboration with those very, of course, key integrator and provider of the 5G technology, such as Ericsson. We recently signed it also early this year, an agreement with them. We are co-working deeply with them to make sure that the security is tightly integrated on the 5G. We, I can say that there was a question about NP7 use case. We have already use case as we have been putting in fact, the CG NAT and all these Gi firewall function in the ASICs. Which will deliver, in fact, the performance that those mobile provider is asking for. That's one of the future use case of the 5G. There's much more to come on this 5G.

Although the sales part has been, I will say, pausing in term of investment, there was a lot of investment about the infrastructure, but they are now in the next, in fact, two, three years, they have to invest seriously about the infrastructure and the security.

John Maddison
CMO and EVP of Products, Fortinet

Yeah, I was speaking in Geneva this week about 5G. Think about 5G, one of the big differentiations from 4G is just the number of devices connected. Instead of hundreds and thousands, it could be millions. Think about the bandwidth for high-speed video, and think about the latency for edge applications. Those are all the attributes of our NP7, and that's why we built it.

Peter Salkowski
VP of Investor Relations, Fortinet

Okay, again, I can vouch for the cupcakes. They're delicious. If you did arrive late, or did not, or I might have missed you on the registration, there are extra jackets and hats and things, so please, do get one as well.

Speaker 21

Happy 10 years. This is Yi in for Shaul Eyal with Oppenheimer. I just have two quick question, one for Keith and one for Ken. Keith, Thank you for the slide with the guardrails on the discount as well as the long-term contract. Can you give us a little bit more color on what drove the outperformance in the less discounting as well as the longer duration of the contract? Is it because of newer innovation? What's the driving factor behind that?

Keith Jensen
CFO, Fortinet

Thank you. I think we talked publicly, if you will, almost two years ago, that a couple of things that Patrice and I were going to spend time with from that point forward was looking at contract duration and discounting. We do spend a lot of time talking about it and messaging it and reporting on it internally. I thank Patrice and his team for doing a very good job with it. Well, I guess I would offer on discounting.

When you come into a bake-off, and if you already have the lower TCO, you already have the cost advantage that comes with the ASIC chip, we do try and spend some time making sure our salespeople understanding that going deeper and deeper on discounting is probably not something that we would think you would normally have to do because you're already in a winning position there. It's really probably more about selling the value at that point in time than there is in discounting.

Speaker 21

That's all.

Keith Jensen
CFO, Fortinet

Patrice, do you want to talk about it? Oh, I'm sorry, you were-

Patrice Perche
Senior EVP of Global Sales, Fortinet

It's also, as they say, our engagement more earlier with the account. You're not like coming late on a project where often it's about price discussion. We drive really value, we sell the value as we're engaging more upfront with the customer, so in time of the project.

Speaker 21

That's it. Thanks, Keith. Thank you, Patrice. Ken, just more general question? In terms of the IT spending environment, we see some noise in the Western Europe, politically, as well as certain parts of Asia. Can you give us a little bit more color on a general IT spending environment? Has that impacted any of the region? With the understanding Fortinet is very well diversified.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

For some traditional firewall vendor space, sometimes they do get more pressure, like in certain country, Europe, the spending take longer time, slow down. For us, we also open up a lot of new opportunity, like all the SD-WAN, like some other IoT security, some other more broad cloud offering. We can see a lot of SD-WAN also helping the enterprise, most of the company enterprise, lower their cost. The trend also, the NOC and SOC starting combine the network operation center and security operation center, starting more combine, whether in enterprise, in the service provider. The trend actually helping us. That's why we're keeping gaining market share, grow faster than the market. You can see 2018, the market grow like 12%, 2019 probably estimate about 9%, do slow down a little bit. For us, we don't see a slowdown.

Because by the technology advantage or for the new trend much better. We have quite strong R&D both on the culture, on the team, on the product side, also will help us to lead in the trend. Because security and networking, they're starting, like security expanding to inside the company, inside data center, and also expand to the WAN side and not just traditional border security. That's most our competitors still stay there. The move to the cloud also kind of tricky. We have quite some presentation, quite some discussion with both cloud providers, service providers, and customer. We also want to make sure, so we have a good position and also more long-term invest growth in this space.

Keith Jensen
CFO, Fortinet

Yeah. Thank you.

Taz Koujalgi
Analyst, Guggenheim Partners

Hey, guys. It's Taz Koujalgi from Guggenheim Partners. Can you guys comment on the refresh cycle of your appliances and has that helped any growth in 2018 or 2019? Across the board, 2014 and 2015 were good growth years for security. Has that helped at all in driving your growth in 2018 and 2019? I know, Keith, on the earnings call, you de-emphasized the refresh impact on your growth. Can you give more color on that?

Keith Jensen
CFO, Fortinet

I think whether you look at an internal refresh cycle or external refresh cycle, tried to cover that off in today's presentation by noting that when you have 90 firewalls, you can do some quick math and assume they have a life of, say, five years, that tells you that you're revving a lot of firewalls every year, right? It's unlikely that any one firewall is going to do something dramatic into our revenue stream. From an internal refresh cycle, it's just steady state. We use the description of it's like painting the Golden Gate Bridge. You start at one end, you go to the end, you finish. One of my competitors stole that from us, so we have to find another explanation for it. That's really what's going on there.

In terms of the external product refresh cycle, if you want to look at it that way, I said the impact to us is muted, and I would offer two comments about that. One is I can look at what I would call is my internal renewal opportunity at the start of every year. If you go back and, say, 2014, how much did I expect to renew throughout 2014, and look at 2015 and 2016 in the same way, that metric is very linear. If I had a refresh cycle that was happening internally, I would expect to see a spike. If I sold a bunch of stuff in 2014 or 2015, it would age out, in 2018, it would come up for renewal. It simply doesn't exist.

I think more importantly is that keep in mind, we really probably were not viewed as being in the enterprise market space during that last refresh. Those large legacy enterprise customers that may be going through a refresh cycle currently with a legacy firewall incumbent, is creating an opportunity for Patrice and his team to come in and compete during a very high price renewal conversation, if you will.

Ken Talanian
Analyst, Evercore ISI

Why would you still say refresh in a big market? I agree that you were not in enterprise back then.

Keith Jensen
CFO, Fortinet

Yeah, I think when you have 400,000 customers, you get the law of big numbers, and it's difficult to see that there was a spike. Was revenue growth in 2018 strong? Yes. Particularly in the U.S., keep in mind, we had tax reform, capital was available. The carriers had a very good year in 2018. I don't know that I would really ascribe that to a product refresh cycle, if you will.

Mandeep Singh
Analyst, Bloomberg Intelligence

Mandeep Singh, Bloomberg Intelligence. I just wanted to hone in on the point about partnering with cloud vendors and service providers. Is identity management one of the solutions that you would be looking to add just to kind of complete the platform, or is there anything else you want to highlight around integrating with cloud and service providers? Thank you.

John Maddison
CMO and EVP of Products, Fortinet

Yeah, good question. Our zero trust network access consists of endpoint security, it consists of identity, and it consists of NAC. We think all three of those components are important. If you haven't got any one against it, you need to use one of them. Making sure every user, you have that identification coming on. If you've got a client in there, that's great. If you can't see it at all, then maybe use the APIs on the NAC. We feel like identity, NAC, and endpoint security, all three components are needed. In terms of partnering, we also make our products also multi-tenant and API-driven. Any one of our MSSPs or service provider customers or even cloud customers can use that. Obviously, there's standards like SAML right now, which are going about, which will also help as well.

Definitely identity is a component of our Fabric going forward.

Peter Salkowski
VP of Investor Relations, Fortinet

Public service announcement number three. I don't know if you've noticed Ken's tie. It is a Forti. I point that out only because John's not wearing a tie. Ken.

Oh.

Oh, sorry.

Ken Talanian
Analyst, Evercore ISI

Hi, Ken Talanian, Evercore ISI. Keith, one for you. Just as we think about the midterm targets, do you expect any meaningful change in headcount growth relative to what we've seen in the past few years?

Keith Jensen
CFO, Fortinet

Ken wants me to hire more people in finance, if I'm not mistaken. Oh. Well, perhaps not. No, I don't expect. Other than that, no changes.

Ken Talanian
Analyst, Evercore ISI

I guess, just a quick follow-up, do you have any changes in expectations around free cash flow conversion relative to the next three years?

Keith Jensen
CFO, Fortinet

No. I think really, if you go back to what are the drivers for our free cash flow again, net income, billings, inventory management. We're not expecting anything significantly different in inventory management, and we're not expecting anything significantly different in contract terms.

Ken Talanian
Analyst, Evercore ISI

Great. Thank you.

Peter Salkowski
VP of Investor Relations, Fortinet

Is that already on?

Melissa Franchi
Analyst, Morgan Stanley

Thank you. Melissa Franchi, Morgan Stanley again. Keith, you mentioned that new appliances generally don't tend to drive an uplift in revenue because it's just a regular cadence of releases. Given the new chipset that's coming out, it does seem like it's a material change in the performance, and it's enabling new use cases. With the new appliances on the NP7, do you still think that's the case, that you won't see increased activity around those new appliances?

Keith Jensen
CFO, Fortinet

I don't think I said we wouldn't see an increase. I said I don't think we see a spike, if you will. I wouldn't say that just because we're rolling out, say, we rolled out the 1100 or the 2200 or something like that, the next quarter there's going to be a dramatic spike in revenue. Typically, what you're seeing is that we're refreshing our own product line. Using the 1100 as an example, that E product replaced a D product. The D product's going down, the E product is going up. I'm going to hand it off to Ken and John if they want to talk a little about NP7, because there is a process of, one, announcing the chip, and then getting the chips into the product.

In terms of actually modeling that to be dramatically different, I don't think that the advantage that we have conceptually with NP7 is significantly different than we had prior generations of the chips.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

Yeah. I think NP7 definitely will open up some new market opportunity, which we are starting working with some customer right now. At the same time, they do refresh the current product, but will take some time, usually like two, three years to gradually refresh, just like in the previous generation. We have three chip. We do have SoC, now is SoC4. We have a CP content processor, now it's Content Processor 9. The content come out probably one and a half years ago, now the NP seventh generation. We do believe each generation they can improve in performance as 3 to 5x, and it's about same cost. That's where, but we have a many products.

Each quarter we may refresh a few of it, and then gradually kind of. Even with current product, they still have a huge computing power, which not even quite utilized. That's where we can easily add wider security function or networking function, and it's still much better than competitors. That's where we believe there's a technology that we use in a Security Compute Rating, which can see the difference compare ours, compared other competitors.

Peter Salkowski
VP of Investor Relations, Fortinet

Okay.

John Maddison
CMO and EVP of Products, Fortinet

Just to add some more on that. We definitely think NP7 opens up some new markets, but it'll take some time because customers in the past have not thought about putting network security there because it's not possible. It's also very important to understand that NP7 will run on our FortiOS operating system, so it'll be consistent. We can apply NP7 not only to hyperscale, but also to existing applications. Customers are protected because their existing platforms and new platforms and NP7 platforms will run on FortiOS, so you've got the same applications and APIs there.

Dan Bartus
Analyst, Bank of America

Thanks. Dan Bartus, Bank of America. Quick one for John or Ken. Just curious, what % of the firewall market today do you think is influenced by SD-WAN? What do you see that going to over the next one to two years, say? Then for Keith, with such a big innovation like SD-WAN added, and you have many other services including FortiCare, why not start to break out more of these services as upsell and change strategy going forward? Thanks.

Ken Xie
Founder, Chairman of the Board, and CEO, Fortinet

I think probably there's a market data. SD-WAN probably will go to $4 or $5 billion in the next three, four years. I see the more bigger market, more important is really internal security, like internal segmentation and all this local LAN security, including the Wi-Fi segment, more importantly, to be secured. That market probably even much bigger, a few times larger than go to the WAN side. Traditionally, network security can only sit in the border, that's what between the WAN and the LAN, local area networking or the wide area networking. Now we can expand into the WAN and also the internal security, because most intrusion attack today come from internal, whether because more agent-based attack or some your mobile device or some other being infected.

That's where, but internal is very difficult to secure because speed tend to be 10 to 100 times faster than the WAN connection. That's where the NP7 will help a lot. The internal security is huge because if we talk to pretty much all the enterprise, and they need to have internal security, but with current technology, it's pretty much impossible because speed and cost is really the limitation. We see this is probably even much bigger than the SD-WAN opportunity going forward, and we do have a lot of customer interest into, and even the service provider interest in security within data center hyperscale. That's the one we believe this will enable a lot of new upmarket.

John Maddison
CMO and EVP of Products, Fortinet

On the security part of SD-WAN, it started off as networking technology. All of a sudden, you open to local internet access and you create an edge. You need security. What we saw initially was all the networking teams making independent decisions about their SD-WAN technology. These days, the CISO's involved and the security team because of that security aspect. In fact, Gartner was saying that, if you look at their report, 80% of SD-WAN decisions will include security by 2022. I think it started small. It's increasing. I think it'll increase greatly as we go forward.

Keith Jensen
CFO, Fortinet

Don't go far, John. You may want to explain the pricing methodology on FortiGuard here in a second. There's two different business models. We understand that you can sell the services separately, and we do sometimes. Our approach is to sell it as a bundle. There is the constant tension of keeping the price points high for the bundle by having a richness in the offering of the bundles. Sometimes you see us adding things into it. There are other services that we do also sell separately. They're just not large enough to tease out and have a part of this conversation.

Peter Salkowski
VP of Investor Relations, Fortinet

Anything to add?

John Maddison
CMO and EVP of Products, Fortinet

Yeah. I would say I'm definitely seeing for SD-WAN, for example, they want two or three specific services. For other customers in the mid-market, they'll say, I'll have unified protection or enterprise protection that covers everything. It really depends on the customer, the use case, and the application. We're definitely seeing a growth in actually specific, à la carte FortiGuard services and bundles as well.

Peter Salkowski
VP of Investor Relations, Fortinet

With that, I want to thank you all for coming today. I want to first of all, most importantly, thank my management team for all their time and effort in putting in this Analyst Day and making it a great event. If you could all give them up. Thank you. Now it's time to eat cake, or cupcakes in this case. Thank you very much. Have a good day. We'll end the webcast at this point, and let's have lunch. Have a good day. Take care. Bye-bye.