Good day, welcome to the Palo Alto Networks special investor update conference call. Today's conference is being recorded. At this time, I would now like to turn this conference over to Jeffrey True. You may begin, sir.
Good morning, thank you for joining us on short notice. As you've seen, this morning we announced the proposed acquisition of Demisto. Joining us today to discuss the transaction are Nikesh Arora, Chairman and CEO of Palo Alto Networks, and Lee Klarich, Chief Product Officer. Please note that we are still in our quiet period and will be reporting our fiscal second quarter results on Tuesday, February 26th. We will not be commenting on our fiscal second quarter results or fiscal third quarter guidance during today's call. We'd like to remind you that during the course of this conference call, management will make forward-looking statements, including statements regarding our competitive positions and the demand and market opportunity for our products and subscriptions, including our beliefs about the anticipated benefits of the proposed acquisition of Demisto and our continued execution and focus on providing new products to our customers.
All statements other than historical facts, including the statements regarding the expected benefits of the proposed transaction, are forward-looking statements. These statements are based on management's current expectations, assumptions, estimates, and beliefs. While we believe these expectations, assumptions, estimates, and beliefs are reasonable, such forward-looking statements are only predictions and are subject to a number of risks and uncertainties, which are beyond our control and which could cause actual results to differ materially from those anticipated by these statements. These forward-looking statements apply as of today, and you should not rely on them as representing our views in the future. With that, I'll turn the call over to Nikesh.
Thank you, Jeff, thank you, everyone, for joining us today. Since I joined Palo Alto Networks seven months ago, you've heard me say that digital transformation is altering the way customers evaluate their security needs. We at Palo Alto Networks continue to make progress on our strategy in support of our customers across three dimensions. One, securing their enterprise by delivering more and more highly effective security in their on-premise infrastructure while taking away unnecessary complexity and breaking down existing silos. Our announcement last week of launching DNS as a service, as a subscription that you can trigger off our firewall, is another example of this continued innovation. Secondly, enabling our customers' journey to the cloud by delivering the broadest set of security capabilities across all clouds and cloud configurations.
Third, helping them secure their digital future by deploying advanced AI and machine learning in our Application Framework and constantly delivering new technologies in the areas of security, analytics, and automation. We're delighted to announce the acceleration of our Application Framework strategy this morning with the proposed acquisition of Demisto. A few weeks ago, I was talking with a customer debating how many security vendors do they have deployed. We agreed that it was likely a large and undesirable number. She was kind enough to email me later and share that the actual number was 35. We cannot solve security by deploying more and more solutions that alert us to potential issues. We need solutions. Demisto is a leader in the evolving space called SOAR.
With Demisto, we add more security, analytics, and automation technologies to our platform and can strengthen the security outcomes that we deliver to our 60,000 customers and more. We believe that Demisto's multi-vendor orchestration capabilities and unique analytics and playbooks will help our customers further automate a significant part of their security operations and allow them to turn their attention to solving unique and complex threats. Founded in 2015, Demisto has established itself as a leader in a large and growing market with an offering that uniquely serves security operations teams that are sorely in need of solutions. This is validated by the 150 customers they serve worldwide, which spans more than 10 industry verticals. A quarter of these customers are from the Fortune 500 and include large organizations in healthcare, high-tech, and financial services.
Demisto is changing the way incident response teams use automation to manage and stop attacks today. They've amassed one of the largest incident response communities in the industry, with approximately over 5,000 members. Their platforms and over 200 integrations with companies such as Microsoft, Amazon, Splunk, Slack, and others are the top reasons why some security teams have chosen Demisto. With Demisto, we believe we are accelerating our ability to capture the $5 billion addressable market we have associated with the Application Framework. Demisto's proven technology success, coupled with the benefit of Palo Alto Networks' large and growing customer base, well-established sales organization, and deep partner relationships, will allow us to provide a more comprehensive set of solutions to our customers. As you all have read, the agreed-upon purchase price is $560 million, subject to customary closing adjustments.
We have agreed to pay a portion of that purchase price in shares of Palo Alto Networks common stock. While shareholders might be concerned about the dilution associated with issuing more shares, I am pleased to report that during our fiscal Q2 2019, we completed our $1 billion share repurchase program authorized by our board of directors. During the quarter, we repurchased the final $330 million at an average price of $177.62 per share, thus offsetting the vast majority of dilution expected with this transaction. Demisto adds to a series of investments we've made in the last 12 months designed to strengthen our ability to offer integration, not consolidation, to our customers.
At this point, I am comfortable that we have all the elements across our three pillars to forge ahead in our plans to provide industry-leading solutions to our customers across their traditional infrastructure, help them secure their journey to the cloud, and also change the paradigm of how security is offered with a more data-centric approach that relies on industry-leading AI and machine learning. Demisto has an ambitious plan for 2019. To facilitate and support it, we will have Demisto operate as a separate speed boat under the leadership of Slavik Markovich, their CEO. At the same time, Slavik will work closely with Lee, Nir, and me to continue the integration they have with our Application Framework. Before taking a few questions, I'd like to say that we're very excited to welcome the Demisto team to Palo Alto Networks.
We took a hard look at the market, and we strongly believe that Demisto has the best technology, talent, as well as a shared vision for what we can do together to improve the effectiveness of security teams, and will provide meaningful returns for our shareholders over time. This is the future. With that, I'll be happy to take your questions.
Thank you very much. Ladies and gentlemen, at this time, we would like to open the floor for questions. If you would like to ask a question, please press star one on your telephone keypad now. If you are using a speakerphone, please make sure your mute function is turned off to allow your signal to reach our equipment. Once again, to ask a question, please press star one on your telephone keypad now. Again, that is star one to ask a question. Our first question will come from Kirk Materne, Evercore.
Hi. Thanks for taking the question. I was wondering, could you give us a sense for how you intend to modify your go-to-market efforts to support Demisto?
Good morning, Kirk. Thanks for your question. Kirk, part of the interesting conversations we've been having with many of our customers, as I highlighted in my prepared remarks, is that customers feel that they're getting a lot more alerts, a lot more alerts are getting spun out by the variety of solutions they're deploying in their SOC. They have been asking us, is there a way for them to solve this problem? That sort of triggered and inspired us to go looking in the market to see who had a good handle on this issue and was providing an industry-leading solution. That's how we uncovered Demisto, spent a lot of time with them, and understood actually what they're offering is what the customer is asking for.
We hope to be able to empower our sales teams around the world who are constantly having conversations with CIOs and CSOs on their security strategies and what they would need for the future. We have been talking about our Application Framework for a while and how that is going to integrate data from everywhere and provide the ability to run analytics on top of that. Demisto is a perfect use case, where they're already integrated through our Application Framework and a large consumer of that data. We hope to be able to provide that solution to our expanded sales force around the world.
Just as a follow-up to that, do you expect this to be sold through the channel as well?
Yes, of course. Demisto is sold by the channel today, and we anticipate that not to change.
Great. Thanks very much.
Thank you. Our next question will come from Keith Weiss, Morgan Stanley.
Hi, this is Hamza Fodderwala in for Keith Weiss. Just a couple of quick questions on my end. Can you maybe give us a little bit more detail as to where exactly this extends the Application Framework, whether there's any existing whether there's any overlap with existing functionality? Could we, as a follow-up, get a split between the cash and stock that's going to be offered for this transaction? That's it for me.
Hamza, I'm going to give you a quick overview and then have Lee jump in on any potential overlaps. As I said, Demisto is a multi-vendor automation and orchestration tool. As you know, Application Framework has been purely focused on Palo Alto Networks data so far. From that context, this adds and extends our capabilities to be able to provide the analytics and solutions across multiple vendors, not just our own data. To that extent, it is non-overlapping. There are some analytical capabilities that we have already in the Application Framework, which are also part of our Demisto. Part of our whole philosophy on the Application Framework is to allow the customers to choose the best of breed they'd like to deploy while retaining a consistent integrated platform underlying the data. They have their transferability and visibility across various solutions.
Lee, did you want to jump into that?
Demisto is already a partner in the Application Framework, by nature, that is already very complementary to the core capabilities we have. For example, integrating with AutoFocus for intelligence data, leveraging the rich data that our sensors provide into the Application Framework, providing SOC analysts the automation capabilities for dealing with alerts and responding to them. Nice complementary aspects with little overlap with what we already have.
Hamza, to your second question, unfortunately, I'm going to give you a non-answer, but I think part of the opportunity the shareholders and management wanted was to be able to participate in the continued success of Palo Alto Networks, hence they wanted a significant part of the consideration in stock. The final numbers of amount of stock and cash will be determined at close, we're unable to provide that information at this time.
Got it. That's it from me. Thank you.
Thank you. Our next question will come from Fatima Boolani, UBS.
Good morning. Thank you for taking the questions. I just wanted to drill into the rationale behind the build versus buy route you took for Demisto. As you've mentioned, Demisto has been part of the Application Framework for several months now. I really just wanted to better understand sort of why acquire Demisto's intellectual property versus go out and take a more organic R&D stance and a quick follow-up as well.
That's a good question, Fatima, I think the rationale is, I think as you look at the continued attention to security across the enterprise, the continued need for security as you start making cloud transitions, there's a lot of pressure on the SOC. There's a lot of alerts going to the SOC. There's a lot of piece parts being deployed in the SOC, and we felt that there is a need for SOC management and integration being provided to SOC. We did not feel we could do that from a slow roll in terms of an organic evolutionary approach. We felt that we needed a backbone to be able to create that integration, that automation, using all the data that you can deploy in the Application Framework. Hence, we went down the acquisition path. Lee, did you want to add?
He did. That's a great answer. I'm always happy when our head of product tells me I've given a good answer.
Fair enough. Just actually on that point, one of the attractive elements of Demisto as an independent company, was its ability to play nice with others and potentially some of your competitors. Maybe a two-part question. How do you expect, having acquired Demisto or in the process of acquiring Demisto, how should we expect this to impact Demisto's technical and commercial relationships with third-party vendors who could happen to be your competitors? Secondarily, what implications should this have on the monetization model for Demisto as we think forward? Thank you.
I think the reason Demisto has been successful is that it provides a multi-vendor cross-enterprise view of security and allows you to automate irrespective of the vendors that you have deployed in infrastructure. I don't think in our lifetimes we're going to end up in a situation where every vendor only has Palo Alto Networks or any one vendor from that perspective. A multi-vendor approach to solving the customer's problem is not just essential, it's mandatory. From that perspective, we're not going to interfere with what has made Demisto successful so far. We expect that we need to be focused from a customer's perspective on a solution that works for them. Hence, Demisto is a company run almost independently with Slavik leading the charge, working with Lee, Nir, and I to keep driving that capability because that's not a motion that we do at Palo Alto Networks.
Definitely you have a good point, we intend to stick to the notion of keeping them as a multi-vendor, unbiased solution. In terms of monetization, I think Demisto brings a tremendous amount of value to the SOC, part of their opportunity is to be able to become the backbone of the SOC in the future. We believe the more problems you solve for the customer in the SOC, which is where customers are deploying a lot more spend because they're trying to remediate and automate and solve all the security alerts they get. We believe the more value you add there, the more likely you're going to get compensated for it.
That's very helpful. Thank you so much, Nikesh.
Thank you. Our next question will come from Gur Talpaz, Stifel.
How do you think about this in relation to what Splunk is doing with Phantom out there? Meaning we've typically seen SOAR bolt alongside the SIEM. How do you think about the relative advantages you may have with Demisto now building on the App Framework versus perhaps what others are doing out there with their efforts in SOAR?
I'm going to let Lee answer that one because I know you will ask me a follow-up technical question and try and take me out. Lee, take this guy down.
That was not my intention.
We've seen in the sort of the SOC market overall is first the desire to collect lots of logs and data and alerts. That has produced both the benefit of having access to lots of data, but the challenge of being overwhelmed with too many alerts that can be dealt with. Out of that, the SOAR market has emerged as a way of helping SOCs deal with this overwhelming number of alerts that are coming in through the use of analytics and automation. With Demisto, we see an opportunity to extend our focus and belief around the use of automation as a very critical component of security and leverage on top of the Application Framework allows us to integrate it with the data and the sensors that we have.
Now, as you're aware, Splunk recently extended with the acquisition of Phantom, which is also in the SOAR space. There will be a certain amount of overlap there. We continue to be close partners with Splunk, because it's one of the tools that we see our customers using.
That's helpful, Lee. Maybe just a quick follow-up. As far as the internal application of Demisto, can you see this enhancing what you're doing organically now with Panorama? Meaning could this be sort of a Panorama on steroids as far as orchestrating your first-party tools as well? Thank you.
Yeah. When we talk about automation, there's actually many different forms of automation. Some of the automation that we do is sort of very native and intrinsic to how we integrate different services together. We do a lot of that in the back-end infrastructure as we're building solutions. Second is how we automate the integration with different data sources in order to use context in setting policies, one of the key ways in which Panorama provides automation. Third is the automation when we see an event, and we want to take action, and that's largely the kind of automation that Demisto will provide. While it's complementary, the kinds of automation that Demisto provides and PAN provides are different. We'll leverage them together, we'll integrate them together, but I don't see one replacing the other.
That's helpful. Thanks, Lee, and congrats, Nikesh.
Thanks, Cole.
Thank you. Our next question will come from Gabriela Borges, Goldman Sachs.
Great. Good morning. Thank you for taking my question. Nikesh, I was hoping you could speak to a little bit of what the potential limiting factors could be to adoption. Specifically, how difficult is Demisto to deploy today, and how do customers get comfortable with some of the automation algorithms without accidentally breaking a piece of the business? Thanks.
That's a good question, Gabriela. I think part of the challenge that we've also discovered in this process is as the industry deploys more and more complicated solutions, that's not just restricted to SOAR. I think if you look at EDR, if you look at SOAR, the degree of sophistication that we're deploying in the AI, in the ML, the automation, it becomes harder and harder for SOC analysts to be able to go and figure out what's going on with 35 different vendors deployed in there, and everyone's spinning out a different way of analyzing the data. I think your point is well taken. We are working really hard with some of the cybersecurity MSSP partners and some of the partners who are deploying more resources to put on customer site because we want to make sure that people are well-trained to be able to deploy these tools.
Over time, my anticipation is that these tools will get more and more automated because that's the only way to make them simpler. I think in the short term, the only way to deploy these and for our customers to get the full value of this, we have to have some sort of a managed part of the service to get mass adoption.
That's helpful. Thank you. The follow-up is, what can you disclose at this point about revenue or growth rates? To the extent there's not a lot of information that you can disclose, maybe just talk to us about the puts and takes that the team thought about when considering valuation. Thank you.
I think I'm going to save that question for next week when we do our earnings call. We should be able to talk to you about that with more comfort. There's a reason our General Counsel opened this call. He's watching me very carefully, sitting across the table.
That's fair enough. Thank you.
I'll answer that question next week for you, Gabriela.
Understood. Thank you.
Thank you. Our next question will come from Karl Keirstead, Deutsche Bank.
Thank you. Hey, Nikesh. Congrats on the deal. Nikesh, there's been some news around lately about changes that Palo Alto Networks has been making to its channel model, where you've moved to more of a deal referral model for certain products. I'm just curious, will this fall into the category that would be more of a deal referral model, and would you mind just commenting on those channel shifts? Thank you.
The only change we've made in our channel program is only around RedLock, where we're seeing there is a natural go-to-market motion with the cloud provider. When a cloud provider, whether it's AWS, Azure, or GCP, signs up for a program with a customer, they take them direct. What we've noticed that we have to attach our sale of RedLock to that sale. Hence, we've made a change on adaptation to our channel model specifically for that product category because we need to make sure the channel gets compensated, yet we need to be able to follow the motion of the cloud providers out there. Outside of that, we haven't made any other changes with respect to referrals.
Demisto is a channel play, it's a partner play, it's an MSSP play. We anticipate to get more engaged and involved with our MSSP partners and SIs to be able to make this sale happen in the market.
Got it. Okay. That's very helpful. We'll talk to you next week.
Look forward to it.
Thank you. Our next question comes from Andrew Nowinski, Piper Jaffray.
Hey, good morning. It's actually James Fish on for Andy. Congrats on the announcement here. Most of my questions have been asked, but I'm just curious how we should think about the mix of on-premise versus cloud deployments now at Demisto and if there's going to be any needed changes to the Demisto sales team in terms of just compensation to get them on the Palo Alto comp plan. Thanks.
Well, as of now, Demisto has, as I said, ambitious plan for 2019. Part of the attractiveness for us to work with them is they have a well-developed go-to-market motion and a good sales team in the field. We anticipate helping them from our broader sales team and getting them leads and getting them to customers. We don't intend to change much of their structure and process and plan in the short term. You should not see any change in the market as regards Demisto. I think the big opportunity is to go out there and expose the capabilities to more and more customers, which our sales teams can help create the opportunities and open doors and create the leverage.
I think in the short to medium term, you should see no plans, and any changes that we make is only after we spend a lot of time with management, which thinking about future integration, et cetera, which is still early to call.
Got it. Then on-premise versus cloud deployment mix?
Look, I think what's interesting is that Demisto has followed the model which the customer has. The customers are slowly going from an on-prem only situation to a hybrid situation or to a cloud-only situation. In a way, Demisto has followed the customer in terms of where they wanted to keep their data. As you know, SOARs or Demisto relies on where customers store their data. That is a key determinant as to where they get deployed. As of now, we anticipate making no changes to their current model that they have in place.
Got it. Thanks, guys. Congrats.
Thank you.
Thank you. Our next question will come from Michael Turits, Raymond James.
Just to make it clear, I've jumped on late, just make it clear, you're not giving any financial impact information at this time, waiting till next week. Is that right?
Yes, Michael, you got that right.
Okay. You've talked about SOC a lot, and people ask you about SOC, but can you describe how this fits in with your strategy and thought process around SIEM long term?
Let Lee answer that one.
Good question, Michael. The SIEM and SIEMs have been around for a long time, as you know, the primary purpose of having a SIEM is to collect all the security alerts and provide SOC analysts the opportunity to investigate those alerts and figure out what response is necessary. What we have seen in this market is a few important aspects. One, the data feeding into the data store is very important, with our sensors, next-gen firewalls and the network Traps and the endpoint, RedLock over the cloud service Aperture in the cloud. We have some of the best sensors in the world for not only preventing attacks but also collecting data. Those are collecting data into the Application Framework, where we make it available to our own apps as well as third-party apps.
The second piece is being able to analyze that data and analyze the alerts and figure out which alerts are important and need to take action on. In that area, with the acquisition of LightCyber a couple of years ago and the release of Magnifier about a year ago, we have some of the best AI ML capabilities for analyzing that data and detecting some of the most sophisticated attacks. The third piece is how we then respond to those alerts. With the Demisto acquisition, it will give us both the analytics and the automation capabilities for taking action. Ideally, as Nikesh talked about, a highly automated action so that we can get SOC analysts back to doing the harder tasks as opposed to the menial tasks over and over and over again.
Okay. That's helpful. If I get a follow-up. Nikesh, this is something you and I have spoken about before, but since you've come on, you've talked about this becoming a more data-focused company over time. Its roots as a next-gen firewall company are really in network functionality, let's say. What does Demisto contribute to what may be an ongoing effort to build more IP around data science and analytics to make this a more data-focused company?
Well, thanks for that question. I think if you think about the future of security, I think we've said that in many different ways. Nir said it, Lee said it, I've said it. I think today's approach over time is going to get antiquated. The notion of deploying a solution and infrastructure, popping up an alert, having a SOC analyst stare at it and try and remediate it over 50 or 150 days, by the time the bad actors have come in and taken what they wanted to take and left your infrastructure, perhaps who's sitting in there, is going to make it antiquated. They're deploying a lot more compute, a lot more techniques to go find that 1% of your infrastructure that is not secured.
From that perspective, you have to believe that things are going to get by the inline sensors that you have in the infrastructure. The question is, can you take a look at it the other side, see what comes out, be able to figure it out on the fly, automate it, and remediate it before bad things happen? That requires a degree of machine learning, a degree of AI that is not deployed in the industry today.
I believe the SOAR is a first step towards aggregating all the events at one end, automating as much as you can automate over time, learning what is a false alert, being able to really sift it down and reduce the signal-to-noise ratio, really sift it down to events and have smart analysts be able to take a look at it and remediate it much faster, eventually getting it to real time. I think this is the first step in our ability to aggregate multi-vendor data, start looking at automation, which is going to be manual. If you look at what happens in AI today around the world, there's a lot of data tagging, there's a lot of manual sort of processing going on through each system. I think SOAR is our first step to create learning systems for security in the future.
I think that's why this is so critical for us from a building the future perspective.
Thanks very much, guys.
Thank you. Our next question will come from Matt Hedberg, RBC Capital Markets.
Bergstrom for Matt Hedberg, thanks for taking my question here. Automation, obviously, it's a key part of the technology here. There's been a lot of talk around automation on the call. Could you talk a little bit about the importance of the automation of the security processes, particularly given a shortage of security personnel?
Absolutely. Maybe it'd be helpful to give you an example. One of the common forms of alerts coming into SOCs everywhere is every time an employee thinks that they might have received a phishing email. This happens hundreds to thousands of times a day. If you think about this in a traditional SOC with highly manual workflows, every single one of those probably gets handed off to a SOC analyst who then has to try to find additional data, find the original email, figure out if it was really a phishing email or not, possibly reach out to the employee and get confirmation, and then some disposition of that, either to say it's a false positive, false negative, or maybe the user is compromised and you have to now deal with cleaning up the user's machine.
Think about that just as one kind of alert that could happen hundreds or thousands of times a day. You realize just how much value there would be if you can automate part of that process or even all of that process. That's one example of many that Demisto has built these automated playbooks that can be customized for different customer environments, to be able to take that sort of very manual task that SOC analysts perform and automate it.
Great. Thanks. Maybe one more. Just curious if the deal was a competitive process. The company was in the press last year as a target from some larger technology companies. Thanks.
I can't tell you what I don't know.
Thank you.
Thank you. Our next question will come from Sterling Auty, JP Morgan.
Hey, guys. This is actually Ugam Kamat on for Sterling. In your prepared remarks, you mentioned that they have 150 customers, any particular color that you can throw on what is the overlap of the Demisto customers with Palo Alto's existing customers, and what are the common themes between those 150 customers?
You have to imagine at this point, with over 60,000 customers, Palo Alto Networks, that there's going to be a lot of overlap. In this case, we both target enterprise customers, and many of their 150-plus customers are in the Fortune 500. Now what comprises that customer base at Demisto, the main theme is enterprise customers with SOCs, obviously, because this is a tool and product that is targeted towards the SOC. Often, it's more forward-looking and forward-leaning customers that are looking to find ways to improve the function of the SOC through better technology.
Got you. Can you give us any color on what contract structure does Demisto follow?
I'm not sure I understand the question. What kind of contract structure?
Contract structure in the sense that whether they sell one-year contract, three-year contract, build up front or build in the add years, something like that.
No, not at this time.
Okay. Thank you.
Thank you. Our next question will come from Shebly Seyrafi , SBN Securities.
Thank you. Can you talk about who you guys see as the key competitors to Demisto? Gartner talked about Expel, Canon, Response, Splunk bought Phantom. Just talk about who you see as the closest competitors to Demisto and what key advantages Demisto has over the competition.
In this space, there are a number of competitors, obviously, I think in a lot of ways, the biggest competitor is actually just, what do you call it, the momentum of customers with trying to focus on their manual processes. We saw this, anytime there's a need for a market shift, the inertia of keeping things the same is actually often the biggest challenge that needs to be overcome. In the SOAR space with Demisto, our focus will be on helping customers understand that there is a better approach, a way to leverage automation to improve the efficiency and the capabilities of the SOC analyst. As we noted earlier in the call, there are companies out there like Phantom.
There's other companies in this emerging space that are trying to approach us from different angles, some more from the automation space, some more from the analytics space. What we really liked about Demisto is that they've focused on that combination of analytics and automation in order to provide for better outcomes for the customer.
Okay. Nikesh, I think you communicated last year, or you hinted, that the company's likely not going to make, at least near term, any big splashy kind of deals. This is not, I would guess, splashy, but it's $500 million+. What's your posture on future M&A?
Look, as I said in my prepared remarks, I feel very comfortable that with the acquisition to Demisto, we have the key ingredients in place to drive the 3 pillars of our strategy. As of now, it's heads down and execute on our vision across all 3 different pillars. We're very excited. Last week, we announced our biggest release from an OS perspective for our firewalls. We announced our fifth subscription. We haven't launched a subscription in a while. Our strategy on the firewall side is now to keep deploying more and more capability on the firewall
Once you've already deployed us in an infrastructure, there shouldn't be need for you to bring more appliances into infrastructure, which is the theme of integration I talked about in my first ever call about this topic. I think we are driving towards more and more integration across all 3 pillars, so all 3 categories. We felt that rather than go ahead and build automation capabilities from an organic perspective, I think as Gabriela asked, we felt the need to accelerate that opportunity, and hence we looked hard and thought hard about Demisto. We haven't done this lightly. We've spent a lot of time and effort thinking about it. We intend to spend a lot of time and effort resources building this. As of now, I don't see anything in the near future that we're missing from a portfolio perspective.
As I've said before, I don't feel the need to go out and buy market share in any particular product category because that does not fit into the theme of integration. I think from now, we're happy and good.
Thank you. Our next question will come from Dylan Reider, Cleveland Research.
Cole. Just curious if you guys could provide an update on the Evident.io RedLock and Secdo integration within the broader portfolio. Where do we stand now? Are those integrations complete? Thank you.
Yeah, absolutely. Very pleased with the progress that we've made on the Evident.io RedLock integration. We're now substantially integrated between those two into a single product with all of the capabilities of both offered to our customers. Very happy and pleased with the progress there. Regarding Secdo, we had previously stated that in early calendar 2019, we would be coming out with XDR, which is a largely based upon the technology that Secdo had developed, and we are very close to announcing and making that available.
Thank you. Just want to follow up. Could you provide any color around how many employees Demisto has currently?
150 between Israel and here.
Perfect. Thank you.
Thank you. Our next question will come from John DiFucci , Jefferies.
Thank you. Nikesh, my question's in regards to the orchestration part of Demisto. You say you want to keep it as a multi-vendor, unbiased solution across all security products and vendors, your purchase of it, in a way, negates its truly neutral status, which is an important characteristic for something like this. I guess this is I think Fatima was trying to get to this. I don't know. In other words, since it's owned by you now, how are you going to ensure that competitors continue to seamlessly integrate with Demisto? I can see how this helps you to further integrate your own platform, your products across that platform, I could also see how competitors aren't gonna be so forthcoming in integrating, helping you manage their products.
Just two comments, and I'll let Lee jump in. I think first and foremost, it's important to realize that whether it's Demisto or take Phantom, for example. Phantom relies on other data stores other than Splunk to be able to provide the sort of capabilities. They still integrate with ArcSight, LogRhythm, QRadar, et cetera, which are effectively competitors to Splunk. Similarly, Demisto integrates across multiple data stores. There is no special integration that SOARs enjoy with any of the cybersecurity vendors. They have to get the customer's permission to be able to integrate, and they use open APIs and protocols to be able to integrate across the board.
From that perspective, I don't feel that any particular competitor or partner out in the industry is going to stop us from being able to do the things that Demisto needs to do because it's both in their best interest and the customer's best interest for this to continue. There are many people who you would call competitors who are integrating into our Application Framework platform, not something that we ask them to do. They volunteer to come and participate with us and provide their capabilities and solutions to the Application Framework. I don't particularly see it as an issue. Maybe Lee, you do, or you have something else you want to add?
The integrations between Demisto and all different security companies and third parties are based on a set of standards and APIs. These standards and APIs are readily available to anybody. Just like we've been able to do this with the Application Framework, they've extended this to hundreds of third parties in terms of the data they can collect, as well as the APIs they can use for integrating for response action. I don't see any reason why we can't technically continue to have these integrations and extend these integrations. On top of that, the value of the platform is based on, we will continue to push and focus on being able to embrace these kind of third-party integrations, to continue to extend the value of the platform.
everything you need is available through open APIs today?
Yes, APIs and standards. log standards, log format standards, sysl og formats, and things like that for data collection as well.
I think it's important to understand that the customer has a big say in this as well, because the customer wants the benefit and visibility across all their security vendors. Typically, you cannot go deploy a SOAR without getting a customer to buy-in and then signing up to be able to integrate with what's on their prem and on their infrastructure.
Understood. Okay. Thank you.
Thank you very much. Our last question will come from Walter Pritchard, Citi.
Hi. Maybe this is premature, but a question for Lee. I'm wondering on the product side, one thing I think the SIEMs and the SOARs have been very complicated to install, and you look at customer counts in these areas have been pretty low. I'm wondering, given you have a very large customer base, larger than any of the kind of modern security companies here, how do you make this really lightweight between Application Framework, your cloud SIEM and SOAR, make it easy to take the customers who have found these technologies too complex? Is there something you can do from a product or deployment perspective that might be different than what's been done in the past?
Yeah, I think there's a couple of things that we will be focused on. One is very similar to what we've done across the rest of the platform. We will be very focused on continuous improvement and how we can make it simpler and simpler for customers to consume and use this. The Application Framework is designed to be able to enable and simplify the consumption of security applications, and we'll leverage that over time as well. The second aspect is through partnerships. We have a great set of system integration and MSSP partners, many of which we believe will be very interested in partnering with us with Demisto as a key component of their service offerings, which of course, from a customer perspective then makes it even easier for them to consume the benefits of Demisto and the rest of what we do.
Got it. Thank you.
Well, if there are no more questions, I really want to thank all of you for joining us. I can't reiterate how excited we are about this acquisition and how we believe this is going to become a significant part of us being able to build the future of security with a lot more AI, a lot more ML, a lot more automation. With that, I want to thank you, and I look forward to talking to all of you next week.
Thank you very much. Ladies and gentlemen, at this time, this now concludes our conference. You may disconnect your phone lines and have a great rest of the week. Thank you.