Palo Alto Networks, Inc. (PANW)
NASDAQ: PANW · Real-Time Price · USD
374.50
+0.56 (0.15%)
Sep 15, 2026, 9:43 AM EDT - Market open
← View all transcripts

Investor Day 2017

Sep 27, 2017

Lee Klarich
Head of Product Management, Palo Alto Networks

Please welcome Kelsey Turcotte.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Good morning, everyone. Thank you very much for joining us. We really appreciate it. In order for you to have the opportunity to review the very small language behind me, I'm going to let you read while I give you a little bit of background. First of all, welcome to Investor Day 2017. We really appreciate this opportunity to spend this morning with you. Mark will have the opportunity to go over the agenda. I'm just going to give you a few little factoids. There will be a break in the middle of the presentation. Please take advantage of the beverages and food on either side. Logistically speaking, for those of you who need the restroom, they're half a level down, and the team outside in the lobby can help you.

I think I've spent enough time on the legal, and we're going to show you a little video and then get things rolling.

Speaker 18

Security has become a colossal topic in society. Security's role has shifted away from being considered a business inhibitor to becoming an amazing business enabler, but only if it stays ahead of the technology and advances made by cybersecurity attackers and villains. Here it comes. Whoa.

Whoa!

With the 8.0 release, which is the biggest release in the history of the company, we've done some really amazing things.

Rene Bonvanie
CMO, Palo Alto Networks

This is beautiful, you guys. I have to tell you, this is the front. The back is not as interesting.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

I'm very proud to be the one that everybody's looking up to, I mean, as a company, and I think we've given them a lot to look up to today, but this is just the beginning of 2017.

Rene Bonvanie
CMO, Palo Alto Networks

Wonderful.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

2017 is going to be a very, very big year for us, and you're going to see a lot of new innovation and major changes to the way you do cybersecurity coming out this year.

Lee Klarich
Head of Product Management, Palo Alto Networks

Third-party partners that are part of the application framework, we think that this is phenomenally powerful.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

To navigate in the digital age. This is kind of a how-to guide for senior executive boards of directors, government officials, on how to think about cybersecurity in a non-technical fashion.

Speaker 18

Palo Alto Networks, PANW.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

We've been acquiring customers at a very rapid rate and then growing them after acquiring them from the wallet share expansion.

Speaker 18

There's a new badge in town, and Girl Scouts as young as five are hitting the computers to earn them. Girl Scouts of USA teamed up with Palo Alto Networks.

Girl Scouts can now earn a badge for cybersecurity. That explains why there's a mysterious $7,000 charge on your credit card for Thin Mints. We had no idea.

Lee Klarich
Head of Product Management, Palo Alto Networks

Please welcome Mark McLaughlin.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Morning, everybody. Thank you. Appreciate that. Thanks so much for taking the time to be with us today. We know your time is super valuable, and we hope to be as efficient and productive today as possible. We know there are a number of things on your mind in security, in our business, and we're going to do as much as we can today to hope to answer all those questions. To help me do that today, I have a whole bunch of people from Palo Alto Networks here with me, and I'll go over the agenda. There's lots of other folks from Palo Alto Networks here as well, who will be at the breaks and at the lunch session and manning the demo booth. You can see them with their color of their badge, which is blue. Please feel free to interact with the team here.

They'd be super happy to talk with you and answer any questions that you have. From an agenda perspective on what we're going to do today, I'd like to kick it off to talk about what's been happening in security, and I think of those in terms of evolutions, and I'll describe that in just a few minutes' time. I'm going to talk about the platform advantage we have, the distinct, highly competitive platform advantage we have in serving those security evolutions, how we continue to disrupt the security market, how we have done that in the past and continue to do that today and intend to do that into the future, and how with that distinct platform through these evolutions, we're solving the customer's most important needs.

Then, of course, we'll discuss how we do that from a financial framework perspective, and we intentionally left an ample amount of time at the end for questions and answers as well because I know you have things on your mind we'd like to talk through. Let me just start off at a very high level for a minute on just how we view the company at a glance. We think Palo Alto Networks is the primary winner in security now, and it's going to continue to be the primary winner in security into the future because we see ourselves as having a company that is serving a very large and continually growing total addressable market with a unique platform that has significant technical advantages, not only today but into the future. It's very resilient that way.

That's been able to acquire outsized market share gains, and we intend to keep doing that into the future with super happy customers, world-class customer satisfaction, and all inside a framework where we're committed to deliver growth and profitability along the way as we continue to scale the company. Now, the setup for doing all that, of course, is we're in the digital age. We all know that. We know that digital is so important for society and for all the productivity that underlies the digital age. The people really have to trust that. We know, we don't have to go into a lot of detail on this, that that trust continues to erode over time. We can see it all over the place, in financials, in media, in healthcare, now even in elections, just to name a few areas where we continue to see that trust erode.

Into that breach steps Palo Alto Networks about 10 years ago with this mission statement, which is to protect our way of life in the digital age by preventing successful cyber attacks. That's a mission statement we've had for a very long time and a mission that we'll continue to have for a very long time because it's important. It's meaningful today, it will be meaningful in the future, and it gets people really jazzed, and that's why we get some of the best talent in the world to join the company because they know they're doing something important, not only today but in the future for society.

With that mission statement in mind, we've been able to serve a very large and growing total addressable market, currently at about $19 billion, expected to grow to about $24 billion in 2020. We'll dissect that during the course of the day for you a little bit more. A large and growing addressable market opportunity with that mission to do something very important in the digital age with security. With all the anxiety and security that we see in the past, every day today, and we expect in the future, it's been a healthy market in security, and I don't see any reason why that should change as security gets more important and more complicated on how people digest it over time, something that we're trying to fix. It should drive a healthy market, from a customer perspective, on trying to solve these problems.

Let me talk about the problems. I'm just going to mention the two biggest ones in security at any time that we've been looking at security in these evolutions over a decade back or a decade forward. The first problem is that how do you do increasingly better and better and more automated prevention, very important, when the adversary has increasingly automated themselves, very sophisticated, simply because the cost of compute power keeps going down. The adversary takes advantage of that. They're doing a lot more, a lot faster, a lot cheaper, and a lot more sophisticated, and they are extremely automated. Right? The first problem is how do you do increasingly better prevention against an increasingly automated adversary?

The second thing is, how would you do that with a completely broken consumption model in security where everything is very disparate, there's 2,000 vendors, it's very complex, and there's tons of innovation happening, which is good, but how do you actually consume that innovation in a way where the consumption itself doesn't cripple you from an operational perspective? Highly automated prevention and consumed in a way that doesn't kill you, right? If you're the person who has to operate these things, right? That's what we've been up to. As a company, what we keep doing is deliver highly automated, orchestrated, leveraged prevention capabilities, which we make better and better and better. We've done that in the past. We're going to keep doing that in the future.

Doing that in a way where the consumption model is continuously disrupted, it becomes easier to consume the innovation without swamping the environments or requiring yet more and more people to run more and more stuff. Those are the two main issues people are dealing with and the two things that have to be solved if you want to be successful in security. That's led, over time, to the drive for platforms. Everybody talks about platforms. It's important, it's true. Platforms actually matter. They're bringing automated prevention and better and better consumption models to the market, right? In those platforms, the architecture really matters. It's super important about how do you think about these things, and how do you build them, because that's actually how you deliver automation and orchestration and leverage, and how you dramatically change the consumption model in the process.

You don't slap stuff together. Right? The architecture is super important. We believe we have the winning architecture. It is purpose-built from the ground up, starting 10 years ago, and we continue that today in how we think about that. We really care about the architecture, not losing our way or losing our sight on how that has to work in order to be successful for customers in the future. With those things in mind about what are the problems we're trying to solve, we'd say that security has moved in evolutions over the last 10 years, and I would expect them to continue to do so into the future. Each one of these evolutions is very important in and of itself, and I'll describe them to you, but each one's very important in and of itself. Each one is self-reinforcing for the next one.

We would also posit we invented each one of these evolutions and were the leaders in each one of these evolutions, which provides us a very significant competitive advantage, technically and in the market, because they are self-reinforcing. I'd like to describe them to you quickly. I'll do that technically. Then I'd like to come back to them actually from a business perspective, is what it means for our business today and into the future. In order to understand those three evolutions, we have to go back to the beginning in time, if you will, from a security perspective, and understand one basic point in security, and that's the difference between an attack and a successful attack. The difference between an attack and a successful attack is a successful attack actually has to do a number of things right. Right?

If you're a security practitioner, the parlance on that would be there's this thing called the lifecycle of attack or the kill chain of attack, right? The attack has to do all these things correctly in order to be a successful attack, as opposed to just an attack. Right? For a very long time, it's been a very good idea, which is how can you interdict the attack everywhere where it has to do something right, as fast as possible, at any point you can, in order to get to the end before it gets to the end and prevent it from happening? Or if you couldn't prevent it from happening, understand it super fast and to distribute that new knowledge as fast as possible everywhere, so while there might be patient zero, there's not an infection everywhere. Right?

That's been a basic idea in security for a long time, and it's a very good idea. It's a philosophy that has a lot of legs to it, right? The problem is that in doing that from a prevention perspective, it really got delivered over time as many, many disparate things, point solutions. There's still a proclivity in the market to do that. The problem with that was back to the two things I said, there's no automation in that. Over time, the consumption model actually gets worse. It gets more complex, which is counterproductive to doing security from an elegant perspective, which is what is needed in the market today. That led to the first evolution Which we invented about 10 years ago, right?

Which is at the network security level, just the network I'm talking about now, for network security back when perimeters were very contained and everybody understood that, right? It was all nice and neat. That was where we proved that all the attack interdiction best-of-breed capabilities that had been in the market and are very important from their capability perspective, but were delivered as disconnected point solutions, could actually be natively performed and delivered in a single platform, mostly from the cloud, which would bring lots of automation, lots of orchestration, and lots of leverage the bigger and bigger the customer base got over time, and would significantly improve the consumption model. Better prevention and a way different consumption model, where, in essence, we subsumed entire industries into the platform at the network security level to drive the first evolution to get better prevention and different consumption.

About four years ago, we introduced the second evolution in security, which really is defined by consistency. If you could do security the way I described, you could do high degrees of automated, orchestrated leverage prevention, where you get better and better and better. We believed four years ago, and we're surer of it now, that you have to consistently apply that wherever data is going to be residing or computed or moving. If I simplify that and said, "That might be in your network sometimes it might be on endpoint, on IoT devices, sometimes it might be in the cloud." Cloud may mean AWS, it may mean Google, it may mean Azure, it may mean your own hybrid environment. It may mean a third-party SaaS application. The point is, data's going to move, right?

The consistent application of those highly automated, orchestrated leverage prevention to be delivered exactly the same way wherever the data is, we think is increasingly important in the second evolution because customers understand that if it's inconsistent, that's complexity, right? We spent 10 years of time with the customers on the first evolution of saying, "Complexity is not your friend." Right? I think many of them understand it now, even though a lot of them are just working through that today. They don't want to drive the inconsistency of security posture and outcomes wherever data may be as it moves to endpoints and cloud, because that's just more complexity. Don't replicate that network problem again horizontally with more complexity. Let's have a consistent approach to prevention. Of course, along the way, we'd assume that your consumption model would also get better as well.

It'd be more simple over time. That's the second evolution we invented about four years ago and brought to the market. It's doing well. I'll talk to you a little bit more about that in a second. That's been the setup for evolution three, which we brought to the market recently at our Ignite user conference. We call it the application framework.

The third evolution takes the massive number of our security capabilities that have been deployed in a network and growing very quickly in endpoints and growing very quickly in the cloud environments, and the petabytes of telemetry that that's been producing over time and growing at exponential rates because the customer rate of adoption is growing so quickly, puts them in our data lake, applies very sophisticated analytics and machine learning as we've done historically with many of our capabilities like WildFire, and Nir will talk more about this later on, applies it to the data to do predictive and proactive analytics to give highly sophisticated, preventative, and proactive security answers. Answers, in this case, again, is prevention, right? It allows algorithms to be run against that huge dataset with the answers from the algorithms automatically enforced on everything that has been deployed. Okay.

An important point back to prevention and disruption of the consumption model so that you don't have to deploy more stuff, right. Now, that is a big deal to get that right because it brings highly automated prevention in workflows, whether it's our capabilities or some third-party capabilities, and in a way which completely disrupts the consumption model for the positive, which is be very different in the next decade than it has been in the past decade about how do I get all this innovation and security, right. Really kind of harmonizing a dissonance problem in consumption, which is there has to be tons of innovation in security because the adversary's moving so fast. No one company is going to be able to innovate and invent all the innovations that are required for security. We certainly don't think we can do that.

No security company has ever proven they can do that. No security company has bought many companies and cobbled them together to ever do that in any successful fashion. So how do you harmonize that dissonance, which is there are going to be a lot of security companies because they're doing highly innovative things, but how do I actually use that to get automated prevention and consume it in a way where that next vendor I bring on board doesn't kill me from a complexity cost people perspective, right. We've been laying the groundwork for the application framework for a number of years now, and we've done a number of things to prove this so that we would have the confidence to stand up at Ignite and launch it and bring it out to the world.

Let me go through a number of the things that we've done from a proof perspective. First thing is we did was we did a couple applications, right. The first application that we put into the application framework is called MineMeld, which is a free open source application we developed. We gave it away to the community. We have over 1,200 customers using it today, growing quickly with over 150 sources of data. What MineMeld is it can aggregate and normalize lots and lots and lots of threat intelligence streams automatically. It normalizes it automatically and then can feed it into the data lake so it can be ingested very simply automatically from a machine language perspective. A great source of threat intelligence coming from our customers, where the customers are curating that community now.

Which is important when you're trying to develop a software developer community. The second one was AutoFocus, where we said, let's write an application into the data lake with the idea that we can take the data, the threat intelligence data, and make it very valuable, primarily for SOC analysts, so that they could be more productive, because we have to get people out of the equation, make them more productive. Can we do that, and is it valuable enough that we can actually monetize it? Can we monetize an application through this framework? We'll do one ourselves. We intend to do a lot more. The answer to that is yes. I'll get into that a little bit more in a second.

The third thing we did was with our LightCyber acquisition, which is one of only a few acquisitions, as you know, that we've done over 11 years of time. On the architecture, we believe that for it all to be automated and all to be leveraged and all orchestrated, we usually have a better chance of doing that when we're building it ourselves. Not because we're arrogant, but because we know it works together. One of the few acquisitions we did was a small company called LightCyber, which is a behavior analytics company, and they have a great algorithm to do behavior analytics. Like many of the innovators in security, these small companies, if you want to use it as a customer, they would sell you hardware.

I need to get the visibility and the data for my algorithm to work on, and I need to enforce the answer. Please deploy me everywhere. We wanted to prove a point, which is, could you take a really great behavior analytics algorithm engine, take it out of the hardware, write it as an application through the framework so that the algorithm can be applied to everything that's already been deployed, whether it's hardware or software agents or in the cloud? The answer to that is yes. That was an important proof point for us as well.

The last thing we did was we said, in order for the application framework to be as best as it can be, and the applications running on it to be as great as they can be, it really matters to have a lot of data and the right data. Nir will talk about what we mean by that in a second. Today, it's pretty cost prohibitive for customers to log a lot of data, just the way the market is and the architecture. Our very smart engineers invented something called the Logging Service, which we just released, which is a way for customers to log massive amounts of data in a very cost-effective manner.

They're going to be incented to log a lot of data so that you can have the applications with the algorithms run against the biggest data set possible to make them better and better and better over time. The application framework, the third evolution, we think, has positive impacts for our business. I'll describe those as push and pull. From a push perspective, increases our addressable market opportunity, which I'll describe in just a second. We are going to develop our own apps, and we're going to sell them to people like we've done with AutoFocus and LightCyber coming through the application framework. We will monetize third-party applications from other providers through the framework because they're accessing our customer base with our data to enforce the answers across our infrastructure. That's our push aspect of increasing the business from the application framework.

The pull aspect is probably best described with this note I have from a Global 1000 CIO after I spent time briefing him on what the application framework is. This shows a sense of what we're trying to solve for customers with automated prevention and consistency. If you could consume a lot of innovation in a very simple way without having the umpteenth vendor where you have to find them, test them, buy them, run them, deploy them, maintain them, hire the people to do all those things, it's actually a really big deal if you can have these automated work streams in a very simple way. This customer has gave me this feedback. I didn't ask for it. Sent me a note the next day after hearing it. Clearly thought about it overnight and said all these things.

The pull aspect from our business, though, is the important point which I highlighted at the end, which is if we can eliminate those hurdles, that makes you the preferred source for everything. What's everything? It's the network, it's the cloud, it's the endpoint. It's where you enforce all these decisions. We expect over time, if we get the application framework right, which we will, that it would pull through other things that we already have in the market from a services and hardware perspective, so that people can get the most value from the applications running on top of the application framework.

If I step away from this technically for a second and look at the business, what we've been doing over time is through these evolutions, they've all been growth drivers for our business, where we keep layering in the way to bring these innovations to market to solve these problems of automated prevention and disrupting the consumption model. Each one of them leads to bigger and bigger opportunity sets. Very important technically, each one of them is self-reinforcing, where the next one builds on the previous one and builds on the previous one, which continues to give you an architectural advantage over time.

If you look at this from a market perspective of what the opportunity is, if I dissect that other TAM I showed you a little earlier, the first evolution was really directed towards network security, where the addressable market opportunity there is large and growing, and our capabilities can service everything in this addressable market opportunity as we have been doing for some time. The second evolution on the consistency portion moved us also into the endpoint, not because we're trying to get addressable market opportunity. That's great, of course, but because it's a necessity to provide the consistency of security for wherever data may be, and endpoints is a place where they are. Some things in security can be done better on endpoints than in network, and some things in security can be done better on the network than the endpoints.

If they actually understand each other seamlessly, that's better for sure, and definitely gets better if it's in the cloud as well, that there's a seamless understanding and capability set. We increased our TAM by about $5 billion in the second evolution by moving into the endpoint space. The third evolution increases the TAM further by about $5 billion as well, because now we can address additional security things that are happening in the market, and we expect will happen in the market later on, either directly by ourselves and writing applications to the framework or by monetizing third-party applications. Nir, when he talks about this in a little more technical detail, will give you some sense of what all those use cases are or look like to help us drive this increased TAM opportunity through the third evolution in the application framework.

Of course, all of this only matters and all this starts with customers, right? What do we have to do is we have to acquire customers. We want to get as many enterprise customers as we can. We've been very good at that. Then we want to increase our share of wallet with them over time by selling them more and more of these capabilities as they understand and accept the evolutions, where we're very often the teacher, is the way things should be done over time. They continue to understand these evolutions and adopt them as things that will matter to do automated prevention in a better consumption model. We've done very well in both regards of landing and expanding into the customer base.

New customer growth, as you can see, is very high, about 42,500 customers now, and continue to add lots of customers, thousands of customers every quarter. We know a number of things about the customers which are really happy then, if you're trying to increase your wallet share. The first is they buy a lot. Mark will go through LTV expansion with you, give some updates around what that looks like, but the customers continue to buy a lot of stuff. They're very happy. Mark will give you some sense of NPS scores, customer sat, and feedback from the customers, where they are telling us, "Hey, we think you guys are doing the right things." They're very loyal. Our retention rate for our customer base is very high.

We'll go through some of the statistics around what that actually looks like from the renewals and attach rate, and things along those lines. A large customer base that's growing quickly, where our goal is to then get as much wallet share as we can from those customers for their security postures, right, that they're going to have, and where we are helping them work through the architectural decisions about what those should look like in these three evolutions. What are they buying from us, right? Well, they buy hardware, of course. We've sold hardware to them. We've sold a lot of hardware to them. If you look here, this is showing the total value of the hardware we've sold since 2009. It's about $2.8 billion, right? That's what we've sold out the door since 2000. Customer retention is very high, they like us, right?

They continue to use us. It's given a lot of long-term customers to sell new services to. It's given us a great stream of maintenance revenue, and it's given us a significant refresh opportunity with this kind of installed base from a hardware perspective, which we've done well on in the past and we expect to do well on into the future because our customers really like us, right? In addition to the hardware buying, what we sold, I want to give you a sense of why do people buy hardware? What drives those decisions as to hardware buying, right? Over our years of experience, I kind of just boil it down to three things here. The first is it's cyclical. For whatever reason, it's cyclical, right?

We've seen buying patterns like this over a long period of time, from a hardware perspective, which I think has occurred because of two other things. One is the timing aspect of customers making architectural decisions about how they're going to architect their environments and what the impact that's going to look like to them, what they need and want in order to secure those environments. Then a third thing is continued innovation in use cases, which change in hardware all the time, right? A use case today, if you're out talking to customers and trying to sell them some hardware today that they care a lot about, for example, is like, can you do SSL decryption on the fly at a price performance that's acceptable to me, right?

The answer for us, of course, is yes on that, as it's been yes on all the other use cases historically, and that's one of the reasons why we keep rolling out new hardware devices. We've done a very large launch, as you saw, that we can always address every use case. Maybe it's a branch office use case, maybe it's a data center use case. Maybe it's the SSL decrypt use case. Being able to address every use case in a highly innovative way for the customers. Now, in thinking about those buying cycles and how these decisions work over time, I also want to just double-click on hardware for a second as to what is the growth of the hardware market.

The reason I want to just take a minute on this was because it's not unusual when people talk about this market to conflate two things which are not the same. The first is the growth of hardware in the market, and the second is total enterprise security revenue, like what's everybody selling, right? I see these numbers get mixed up quite often. I think one of the reasons for that is there's no third-party data that speaks specifically to the product side as to what it looks like. You'll see things that add in maintenance and support and some services on top. You'll see total revenue and security, some of which is hardware and support and maintenance. Here's how I think about this, which is I just go to the top players in the industry.

I take their publicly reported numbers for anybody who actually talks about the product, right, nothing else, actually talks about the product, then add them all up, right? Over time, you can see a number of things here. The first is that in the last reported quarter for all these players combined, there was a total of $562 million sold in product, right? Think of that as hardware, so product perspective. The growth in that's about 3.7% year-over-year. In that quarter, which is our fourth quarter as well, we sold $212 million of it, so we captured a large share of it, biggest share, and grew at about over 11%, right? Let's go back further and say, okay, rolling 6 quarters backwards and take a look. There's $3.2 billion, roughly, of product sold by these vendors in the market.

That grew about 3% year-over-year. Again, in those cases, we sold over $1 billion of what was up for grabs, if you will, with about a 12% growth rate, far in excess to the market and the competition. If we go back even further through these cycles, these buying cycles. If you go back a rolling 8 quarters, there's been about $4.3 billion sold by these vendors. It's about a 7.4% growth rate, and we sold close to $1.4 billion of it. Again, the largest from a share perspective and also growing well in excess of the market and the competition. Of course, you'll note Cisco's not on this chart. The reason Cisco's not on this chart is Cisco doesn't report this pure number. They roll in everything that they have into a security number.

If I put them on the chart without being able to dissect the hardware portion of this and just gave them credit for everything that they have, we would've seen in the last quarter they just reported that all of their security revenue, which includes all of their hardware, all of their services, everything they bought with over $4 billion of acquisitions in the last 4 years, they publicly reported and threw it all in there, it's 3% growth. To me, that would indicate probably their hardware business is going backwards, but I don't know because they don't report that. That's why they're not on this chart.

I just want to give a sense of the difference between total revenue in the market, which I'll come to, and what the hardware market looks like, and why and how buying decisions are made over time, because I thought that might be helpful. Let me back up for a second, come up. I got a lot of customers. We're increasing customers at a rapid rate. We've sold those customers a lot of hardware. In addition to that, we've also sold them a lot of subscription services over time. Some of those are attached to the hardware, some of those are not attached to the hardware. We have more and more of them that are not, of course, but they all matter in subscription services.

We're doing that because we're increasing our attach rates, we're increasing our penetration rates, and Mark will talk to you about what those look like. We keep launching new services as well. In fiscal 2017, our billings for subscription services, as you can see, was $867 million, growing about 30% year-over-year. Let me get a little more granular inside the subscription services bucket as well and some of the newer stuff that we've done. I'll talk specifically on Evolution 2 in the endpoint and in the cloud, where we've been growing well for over the last three or four years or so, when we brought that consistency definition into the market as something important in the second evolution that's contributing more and more to our business. As you can see from a customer perspective, customer count's growing well.

We ended fiscal 2017 with over 1,400 Traps customers. We also ended in our cloud business, which is our VM-Series plus Aperture to solve cloud security problems, over 3,500 customers as well. In addition to the customer count, we ended our fourth quarter in 2017 on a billings run rate of over $140 million of cloud and endpoint combined. That's about equally split between the two of those things. The growth rate on that is about 90%. A very fast-growing business contributing a decent size and growing amount into our billings for non-Traps subscription services. If I jump ahead for a second, the third evolution, which is already beginning to deliver for us, and we think this will be a driver for us into the future as well.

If we look at that application framework and the way it's going to work with our applications through the [audio distortion] and monetizing third-party applications through the [audio distortion] , we have one example of an application that we wrote to prove a point earlier I said about how do you actually make threat intelligence valuable and can you monetize that? That's AutoFocus. That's one application in the application framework where today we have over 300 customers using it, so customer count's growing nicely there for just this one application. We ended Q4 2017 on a billings run rate for that one application of over $15 million with a growth rate of over 85% for that one application.

If we think about the application framework and in the future of how many applications will run through there, some of which will be ours, like LightCyber, coming shortly, plus many, many, many, many, many third-party applications. We'll get into who's writing applications for us right now and our ability, which we think we will be able to do over time, to monetize off third-party applications in addition to ourselves. We expect that to drive some significant growth for us over time into that subscription services bucket as well, as our mix of our business continues to go in that direction because we're driving it there through these evolutions. If I come back up for a second, say, back to these evolutions, we've been the inventors of these major evolutions over time. That's been increasing our market opportunity consistently over time.

We've been delivering new capabilities to continually capture more and more of that market share into our large and growing installed customer base. We're going to keep doing that into the future. We think that we're doing that really well because we're really the only true platform in the market that actually does highly automated, orchestrated leverage prevention with the continually disruptive consumption models. We can see that into the results. Here I will flip gears from what I was showing you on the product side and say on total revenue. All this goes into total revenue and other companies report their total revenue for security. We can see that in our fourth quarter, we delivered a lot of revenue at very high growth rates relative to the market and all of the competition. We've been able to do this.

We're growing faster than the market and the competition at significant scale consistently now, and we expect to be able to do so into the future. We're doing that inside our growth and profitability framework, where we have our innovation and disruption. That's what we're doing with this framework. Developing in this framework, which we've discussed before and which we're committed to and we're executing against it, we balance a number of factors. On the top line, we have to balance what do we bring to market? How do we train and send our people in the field? How do we develop the channel? How do we do our technology integrations, which ones with which technology partners? How do we market all these evolutions and educate the market on what is actually in security and how security should be done over time?

On the bottom line, we have to look at things like, how do we prioritize these investments? How do we drive continued leverage in sales and marketing? How do we hire and train hundreds of employees to support the growth in a high-quality manner? How do we get the customer support organization and mechanisms to keep our customers so very happy, with customer sat and NPS scores that are off the charts, among other things as well? Which is why we developed the framework in the first place, to give us that ability, so that we can balance these decisions over a long period of time. Right? Steffan will talk a little bit more about this. There's only one change to this we wanted to highlight here, which is on the free cash flow margins. Used to be 25%-30%, but not bounded on the top end.

Because as the business moves more into subscription services, we don't expect that to be the case. Steffan will get into some more detail around that. We're committed to this growth and profitability framework, been delivering against it for a while, and we expect to be able to continue to deliver it against the future as we march the market through these evolutions as the leader. Allow us to say that I think we have been, and we will continue to be, the most disruptive force in security. This is something I use with our team internally all the time. We have been the most disruptive force in security.

We believe we are the most disruptive force in security, and we're going to continue to do that because we have the only real platform that actually delivers on the challenges of increasing automation to do increasing prevention and increasingly easier consumption models. I'll end where I sort of started, which is at a glance. What does all that mean? We think we've got a great company here, one that is serving a very large and growing addressable market over time, with very significant competitive technical differentiation that is getting reinforced through the evolutions. You can't have evolution three if you didn't do two, and you don't get two if you didn't do one. Right? That competitive differentiation keeps growing over time, technically, as well as our abilities in the market. We've been driving outsized market share gains.

We expect to continue to do that in the future with a very large and happy customer base that we're able to sell more and more things into as we develop these capabilities. Doing that continuously in a framework that delivers both growth on the top line and profitability on the bottom line. With that, I'm going to thank you for giving me some time, and I'm going to turn it over now to Lee to give you some sense of how do we do all that stuff from an evolution perspective. Thank you.

Lee Klarich
Head of Product Management, Palo Alto Networks

Thank you, Mark. Good morning. Mark did a great job of talking through the three security evolutions and why they're so important. It's interesting, we initiated that first evolution over 10 years ago with the introduction of the world's first next generation firewall. Since that time, we've completely transformed the network security market. Along the way, we figured out how important it was to be able to provide consistent security everywhere that applications, users, and data need to be secured, and that became the foundation of the second evolution and the focus on endpoint and cloud. More recently, we realized just how fundamentally broken the consumption model is of new security services and have embarked upon the third security evolution. Only with our unique approach to the next gen platform is this even possible, are we able to enable and drive these security evolutions.

I thought it'd be valuable if today I spent some time describing both what that approach is and what we're doing to drive continuous innovation and focus in the platform to drive these evolutions forward. To set some context, to be really good at security, and our definition being [audio distortion] successful cyber attacks, there's a few things that have to be done and have to be done very well. You have to start with visibility because you can't secure what you don't see. Based on that visibility, you have to then reduce the attack surface down to something that can actually be secured, and you do this through control mechanisms. That sets up the ability to then prevent everything that we already know to be bad and malicious, which then is the foundation of detecting and ideally preventing attacks we've never seen before.

Very importantly, these four core elements build on each other, meaning you can't do anything if you don't start with visibility. Then you have to reduce the attack surface, because without that, you're not going to be able to prevent what is already known. If you don't do that, you don't set yourselves up for the ability to then detect new attacks and prevent them. So these are self-reinforcing, highly integrated when done correctly. At the same time, there's a lot of capabilities are required in each of these four elements. If you just look at visibility, you have to understand all applications, all users, all devices, encrypted traffic, SaaS, and endpoint, and cloud, and mobile, and all of that is just to get visibility, and all really important. The number of capabilities only grows over time. It doesn't shrink.

More and more, we identify the next capability we have to deliver and then the next capability. Perhaps most importantly, because security is so important, each of these capabilities have to be really, really good. Because of that, there's this misconception that you need to deliver point products for each of these capabilities. At least this is what the market would lead everyone to believe. If you want to be really good at one thing, just do one thing. It doesn't work that way, though. Let me give you an example. Imagine if you wanted to be really good at preventing known malware. That was going to be the one thing that you do with a point product. This is not a made-up example. There are companies out there that this is their primary focus in life.

If you weren't also the absolute best at understanding applications, users, devices, endpoints, cloud, mobile, et cetera, you wouldn't be able to prevent very much malware because you wouldn't be in the right places with the right level of visibility. Even worse, if you weren't also the absolute best at detecting new attacks, you wouldn't know about very much known malware. Let's illustrate this with recent examples, say WannaCry or Petya. The way this should work is a set of detection capabilities for detecting new attacks we've never seen before ideally would detect that new malware outbreak as soon as it happens, patient zero, automatically create protection mechanisms that could then automatically be applied to everywhere that security has to happen. If you don't automate that entire process, it takes hours, if not days, to do, which simply doesn't work.

To add a level of difficulty to this, you have to do it everywhere. You have to do it everywhere that applications, users, and data exist and have to be secured. This is getting harder. More and more applications are being consumed as SaaS. More and more applications are being deployed in the cloud. Increasingly, users spend time off the network, working from home, hotels, airplanes, branch offices. Where this has to take place is ever-increasing. The legacy approach of every time there's a new capability that's needed, there's a new product that's acquired or OEMed or just delivered on its own, clearly doesn't work. This is what you would have to deploy in one location. Imagine replicating this everywhere the security has to be performed. It simply doesn't work.

Which is why we've taken a very unique approach to building the next-gen security platform. This approach starts with the idea that every one of these capabilities has to be natively integrated together in order to get the leverage. It needs to be automated such that everything that one part of the platform learns immediately is shared with every other aspect of the platform. It has to be prevention-focused, because in an automated world where adversaries are increasingly sophisticated and automating their attacks, prevention is required. Manual detection response simply cannot scale. It has to be consistently applied because attacks will find their way to the least secured part of the infrastructure. Very importantly, it needs to be flexible and extensible. Increasingly, it needs to enable a completely different consumption model. That is our approach to the next-gen security platform.

We have to translate that then into a set of products and services that our customers can deploy and consume. This is how we do it. The way to think about this is very simple. You have to be in all of the right locations where security has to actually be enforced, where applications, users, and data exist. This means the network, the endpoint, and the cloud. Those locations then need to be tightly integrated with a set of cloud-delivered security capabilities. Because increasingly, more and more of security is dependent on analytics and machine learning and having the ability to iterate quickly and change and transform and respond to new attacks and new techniques, which the cloud is uniquely capable of providing.

It requires data from these different locations, it requires the ability to then automatically reprogram these points of enforcement for better and better security. Importantly, each of these core components has to actually be really good on their own and then made better through the integration with the other capabilities and the cloud. I'd like to talk through how each of these core components keeps getting better and better and then how we connect them together. I'll start with the network. In network security, we've been an innovator and a leader from the very beginning. Starting with the very first release of our next-gen firewall, it delivered a number of industry-first, unique to Palo Alto Networks capabilities that started the transformation of the network security industry. Over the last 10 years, we have delivered innovation after innovation after innovation.

Many of these innovations are actually still unique to Palo Alto Networks, completely. Others are still very unique in how we do them in very important ways. As you can see, we continue to deliver these new innovations, and with the release of 8.0 last February, we had one of our biggest releases in the history of the company, continuing to drive this innovation forward. I'd like to share with you three really important innovations we delivered recently, starting with hardware. Hardware is still actually very important. Bandwidth requirements continue to go up. New use cases are driving increasing bandwidth. More and more traffic is encrypted with SSL and needs to be decrypted in order to be secured.

All of that is driving load and capacity requirements into the network. With these next-gen firewalls, this new hardware that we released, we really pushed the envelope on all the different hardware technologies that we bring together and integrate into these different platforms in order to drive orders of magnitude improvement in performance, in capacity, with a focus not just on total bandwidth, but also a focus on SSL decryption as one of the key use cases that we're seeing more and more of our customers adopt and understand the need for. 8.0 was a very big release from a software perspective as well. In fact, our customers have embraced it, with over 20% of them now running 8.0.

One of the key security capabilities we added as part of this release was a focus on how we can leverage our location in the network as an identity enforcement point. This is really important because when you look at how attacks have evolved over the years, identity and specifically credential theft and then the reuse of stolen credentials to log into sensitive systems and steal data has become more and more prevalent. We can help prevent that. We start with a number of new innovations that focus on how we prevent credential theft in the first place. First, leveraging machine learning tied into our URL Filtering capabilities. Second, with the ability to actually inspect traffic and prevent enterprise credentials from passing through the network out to the internet, where they're not supposed to go. Very innovative, very unique to Palo Alto Networks.

At the same time, we always have to assume that we're never going to be perfect. I'd like to believe we're perfect, but we always have to assume that we're not. What happens if credentials are stolen? Well, interestingly enough, this is something that everybody in the security world actually knows what to do about this. It's called multi-factor authentication. Do not allow a username and password to ever be enough to log into an important system with important data on it. Have one-time passwords, swipe the phone, tokens. There's lots of different technologies for this. The problem is, for a lot of applications, it's very difficult to integrate multi-factor authentication into the application. I've talked to customers that say they have projects that span months, even years, to do this for a single application, and most enterprises have hundreds, if not thousands, of applications.

We did something very interesting, and we turned the next-gen firewall into an identity enforcement point, where we integrate once with the identity infrastructure and then reuse that integration for all of the applications that we're protecting, whether those applications are sitting on-premise or in the cloud. Customer feedback on this has been tremendous. Third, I want to talk about the GlobalProtect cloud service, which we announced recently and actually just made available this week, so we're very excited about that. I want to set a little bit of context for this new service. Many, many years ago, we recognized that more and more users are spending a lot of time off the network, and they were accessing more and more applications that were also not on the enterprise network. They were deployed in the public cloud and SaaS and other things like that.

As that happened, more and more enterprise traffic moved off the traditional network. Okay? When we looked at that, obviously, it has implications relative to how you secure the application. I'll come to that later. How do you secure all these users when they're spending more and more time off the network? The answer was GlobalProtect. We introduced GlobalProtect over six years ago, and since that time, our customers have been adopting GlobalProtect. Initially, people weren't quite sure just how important this was going to be. More recently, it's become very apparent to our customer base how important it is to secure these users, regardless of where they're located, whether they're on the physical network or off the physical network. As a result of that, we've seen a lot of success with GlobalProtect. Today, we're serving over 5,700 customers with GlobalProtect.

Maybe even more exciting is that in just the last quarter, we added over 700 new customers to GlobalProtect, our largest quarter ever. Our customers are really understanding the importance and the value of this important service. Many of them have been telling us, "This is great, but I would like to be able to consume this as a service as opposed to having to deploy it and operate it myself." That was the impetus behind the GlobalProtect cloud service. Same security capabilities as GlobalProtect, and we continue to offer GlobalProtect for customers who want to deploy and manage it themselves. For those that don't, we now offer it as a service, one that we operate on their behalf. This will give our customers even more deployment options for GlobalProtect, more flexibility, and more ways to take advantage of this very important component of the platform.

Switching gears to endpoint. This is another market, very much like the stateful inspection firewall market was over 10 years ago. This is another market that has been ripe for disruption, largely based on the fact that the legacy vendors in this space all started with a very simple, yet now clearly faulty assumption, that for every piece of malware, you can write a signature. In reality, this was true at one point in time. It's just not true anymore is the problem. Let's dissect this just a little bit. If you think about how attacks happen on the endpoint, certainly there's still a lot of commodity malware out there, and you can approach this from many different ways, but you need to be able to stop traditional malware. The reality, though, is malware has evolved significantly.

It is increasingly polymorphic, changes rapidly, in many cases automatically. It's increasingly targeted, meaning you're not going to see it show up millions of times around the world. Frequently, it's delivered in new formats, not just executable application for Windows, showing up in the form of malware and macros and scripts and DLLs and other kinds of formats. This is largely what the next-gen endpoint vendors have really focused on is how do we deal with this adapting malware on the endpoint? It is really important, and in fact, it's something that we focus a lot on. I'll show you that in a second. It's not the only thing that you need to do on the endpoint. Increasingly, attackers are leveraging vulnerabilities found in operating systems in common applications to change the delivery mechanism of malware.

In some cases, they've found ways to not even use malware to carry out an attack on an endpoint. Attackers actually get to pick and choose these different techniques in order to be successful with their attack. You have to be really good at covering every path an attacker might take. That is why our approach to this is very unique. We start by focusing on malware, not just the traditional malware, commodity malware, the polymorphic and targeted and new forms of malware with multi-method prevention for different kinds of capabilities that are necessary brought to bear. Some of these are very specific to the endpoint, but some of these leverage the full power of the platform and what we learn from the network, what we learn from the cloud, and what we learn when our cloud-delivered services like WildFire.

We complement that with multiple methods of prevention for vulnerability exploits. Here we take a very unique approach. We focus on the techniques that attackers use, which do not change very frequently. It's very hard to do, but they don't change frequently, which allows us to get ahead of the attackers. It allows us to not only prevent vulnerability exploits that we know about, it allows us to prevent attacks we've never seen before because we take the tools away from the attacker that they would otherwise be dependent upon. Then we continue to iterate and execute on this strategy. Around this time last year, we introduced Traps 3.4, a very important release in our focus on endpoint security. Because with this release, it was the first point where we could really stand in front of customers and say, "We can replace your legacy AV.

While providing all of these new great capabilities, we can also replace the legacy capabilities you have as well." This is important because customers don't want to keep adding to the endpoint. They want to be able to replace something when something new and better comes in. This spring, we released 4.0. A lot of important capabilities, probably most notable was the inclusion of macOS support. This allows us to secure more and more of the endpoints on enterprise. Most recently, just a week or two ago, we introduced Traps 4.1.

A number of new and very important security capabilities, extending support with some new exploit techniques that focus on the kernel, new ransomware behavior modules that enhance our already really great prevention capabilities for ransomware, and support for DLLs, which I don't blame you if you don't understand what that is, but it's a new way of delivering malware that we can now prevent as well. Through this iteration and execution on the endpoint, this is what has allowed us to really drive the customer adoption forward. As Mark said earlier, we now are proud to serve over 1,400 customers with Traps and growing at a very rapid rate. Now we switch to cloud. First, a little context of what's happening. Many years ago, you rewind the clock far enough, this is what a typical enterprise network looked like. Applications were deployed in the data center.

Users worked in the campus environment on-premise, most of the traffic went from users to applications and back and forth, there was a little bit of traffic that connected out to the internet. Fast-forward to today, more and more applications are deployed in the cloud. More and more applications are consumed as SaaS applications. This drives a couple of really important trends. First, you'll notice that the amount of bandwidth has both increased, but it's also shifted. I mentioned before the importance of the new hardware platforms. This is one of the key reasons for that, as the shift to the cloud actually drives increased bandwidth load across the infrastructure. In addition to that, the vast majority of it is encrypted with SSL that needs to be decrypted and secured. That connects the dots back to the new hardware models and why they're so important.

At the same time, what you'll notice is applications are now showing up in lots of different places, which drives the need for consistent security. There is no one cloud. There are many clouds, customers use many clouds to get a diversity of capability and a diversity of location and uniqueness that they need. What this has resulted in from a cloud security perspective, starting with public and private cloud, is our approach. Our approach starts with consistent security. You have the same bad guys going after the same applications for the same reason. You need to have the same security. That needs to be applied everywhere. To do that requires that we support a diversity of clouds, different private cloud environments, different public cloud environments, all with consistent security.

You can't just do security in one place, you can't do security different in every different cloud environment. It's operationally impossible, it's not very good from a security perspective. Third, you have to support the way the clouds scale. Yes, things still scale vertically, meaning when you need more performance, you get something bigger. More and more in the cloud, you scale horizontally. When you need more capacity, you scale up. When you need less capacity, you scale back down. This is natively built into our VM-Series for the cloud. Lastly, in all of these environments, everything's automated, because that's how you get a lot of the value of the cloud. To perform security in these environments requires a very tight integration with the automation tools and orchestration capabilities that exist there.

They're different in different cloud environments, which goes back to the diversity of cloud support as well. We've enabled this, in fact, we enabled this from way back when we first built the Next-Gen Firewall, by making sure that everything we did was always extensible through APIs. As we approach the cloud, we're able to take those APIs and extend them into the cloud infrastructure as well. That has enabled us to have a very different approach to securing the cloud. Where many of our competitors have de-featured and de-everythinged their product in order to get it to fit into a software form factor that can run in the cloud, we've kept all of the same security capabilities, we've extended the integration points, the networking and APIs, to be cloud specific.

Now, there is a different form of cloud for our customers, which is SaaS. SaaS is different in that SaaS you consume as an application as opposed to deploying your applications into the cloud. In SaaS, it's important to understand that there are different ways in which these SaaS applications are consumed and used. There's sanctioned SaaS. These are applications that the enterprise, the CIO, and the IT department, they specifically go out and contract with these vendors to have an enterprise contract with them. These are typically things like Salesforce and Office 365 and things like that. With these sanctioned SaaS applications, you clearly want to enable them, you need to make sure they're used safely. You have tolerated SaaS. The easiest way to think about this is a business partner's SaaS application. Not yours, but theirs.

You have users that need to be able to use them and access them, because you don't actually own that application, you do have some limitations in terms of what you're able to do. You have to be very thoughtful and focused on how you securely enable these applications to be used. Third, you have unsanctioned. Unsanctioned has come in many different forms. It used to be called consumerization of IT, once that term went away, it became shadow IT. Now it's just unsanctioned. Generally speaking, these are all high risk. These are users deciding that they want to go do something, usually without any regard for what the implications on the enterprise security posture actually is. The approach that you have to take to how you secure these different SaaS applications needs to be multifaceted.

For us, this starts with Aperture. Aperture is how we tie into the sanctioned SaaS applications at a very deep and granular level to understand how the application's being used, what data is there, how that data is being shared, whether the data is safe, whether it's sensitive, whether it should be shared at all. At the same time, though, we integrate that into the rest of our platform, because how we then deal with tolerated and unsanctioned SaaS applications is through a combination of our Next-Gen Firewall plus GlobalProtect to make sure we have consistent and complete visibility and control over all SaaS applications that are being used.

This is yet another example where the power of the platform can deliver a complete solution as opposed to point products trying to solve individual challenges and never actually tying it back together as a complete solution. Through this approach to cloud, this has driven our success. As Mark pointed out earlier, over 3,500 customers are using us to secure their cloud applications and growing very quickly. Many of you have asked for more information about these cloud customers, let me give you a couple of very interesting facts. First, what we know about our customers that buy us to secure their cloud applications, they grow faster than the rest of the customer base. Over two times faster, in fact.

What this means is, when we have an opportunity to get one of our customers onto the cloud and help secure that journey for them, they are a better customer. They will buy more, and they will buy faster. Second, we've also seen that cloud is a very important and useful opportunity to land new customers to the Palo Alto Networks platform, where then, of course, we get to expand into the rest of the capabilities that we have. We've seen of these 3,500 customers, over 1,000 of them came to us to secure the cloud as the first thing they ever did with Palo Alto Networks. In the overall strategy of land and expand, the cloud becomes a great opportunity for us to land new customers and expand, and we've seen that when we can do this, they grow faster.

All of that comes together as how we're really focused on innovating and executing for network security, how we're doing this on endpoint security, how we're doing this in the cloud. Very importantly, all of this then is made better and integrated together through a set of cloud-delivered security services. In a second, Nir is going to talk through what we're doing to transform this new set of cloud-delivered security services. I thought it'd be helpful to first set some context for that and talk about one of our really important security services that we deliver from the cloud and show you the journey that it's been on. I'm going to use WildFire to talk about this. WildFire first came out a bit over five years ago, and this is what it looked like when we first came out with it.

Our firewalls at the time, our hardware firewalls, could send Windows executable files up into the cloud to be analyzed. When they got to the cloud, we could perform what we call dynamic analysis. This means you actually execute it, you see what it does. If it does something bad, it's malware, we could create signatures. We could do this automatically and deliver those automated protections to our customers every 24 hours. In fact, this was really great functionality for our customers, even when it was first released. Over the ensuing five years, we have made WildFire great. To start, we've expanded it such that our endpoints, our cloud partners, can all send data up into the cloud to be analyzed. The kinds of data has extended significantly.

Lots and lots of different kinds of files and other kinds of data can now be sent to the cloud for analysis. What we do with it when it arrives in the WildFire cloud has also extended significantly. Static analysis and machine learning, bare metal analysis, lots of different capabilities can now be brought to bear on everything that is sent to the cloud in order to make sure we have really accurate results of both what is bad but also what's good. The number of protections that we can deliver when we find something malicious has also extended. In addition to preventing malware, we can block at a URL level, DNS level, command and control level, and all of these protections are automated.

What originally was about 1,000 protections per day is now over 230,000 protections in a typical day are delivered to our customers, and they're delivered every five minutes. What this means is that from anywhere in the world, one of our customers sends us something that we detect as malicious, within five minutes, we are protecting our entire customer base. That's happening 230,000 times a day across the network, across the endpoint, across the cloud, across our key partnerships as well. Not only has this driven amazing customer growth with over 19,000 of our customers using WildFire today, but it's delivered an amazing amount of data that we're able to leverage as well. Since the inception of WildFire, we have collected and analyzed over 3.1 billion unique files.

For every single one of these files that we've analyzed, we produce a set of artifacts or attributes about that analysis. We have produced well over a trillion of these artifacts that we fully understand, both in the context of what we analyzed, as well in the context of everything else that we've analyzed. Every time a new file comes into WildFire to be analyzed, we can immediately compare it to everything else we've ever seen. The power of that has delivered over 350 million protections to our customers since this service was first introduced.

WildFire has obviously, on its own, has been an amazing service, but it also does a lot to set ourselves up for the third evolution, both in terms of the years of learning that we have gleaned from how to do this and how to do this successfully and how to expand over time, but also just the sheer amount of data that it has provided to enable the next set of applications. With that, I'd like to invite Nir up on stage to talk through that. Thank you.

Nir Zuk
Founder and CTO, Palo Alto Networks

Okay, good morning, everyone. Thank you, Lee. Thank you, Mark. I'd like to pick up where Lee has ended his presentation and spend the next 25 minutes or so talking about our third evolution. Specifically, why do we need a third evolution? Why is now the right time for the third evolution? Most importantly, why is Palo Alto Networks going to be the one that leads the third evolution? I want the conclusion that we all reach at the end of this presentation to be that Palo Alto Networks is not only the best positioned, but probably the only company that is positioned to deliver on this third evolution due to our market position, due to our architecture, and due to the data that we have collected, analyzed over the last 10 years. Okay? Why do you need a third evolution?

If you look at a typical Security Operations Center, SOC analyst, you peek behind their back and look at what they do as their daily job, they have consoles in front of them. They have data. They go in and they search through the data. They look for attacks. Maybe they get events that support attacks. They investigate the attacks. They come up with conclusions, with decisions. They come up with mitigation to these attacks, they take those, and they reprogram different things in their infrastructure to stop the attacks. On the other end, we have an adversary that's growing in size, right? More and more cybercriminals are entering the cybercrime circles every day. We're seeing more and more automation, which increases the volume of attacks, and we're seeing more and more sophistication.

While cybercriminals are increasing exponentially the amount of data that they produce, and poor the analyst, the poor analyst is still doing everything manually, and there is a big disconnect over there. That disconnect is forcing us to lead the industry, and we've been doing that for many years, like you've heard from Mark and Lee, to automate as many cybersecurity processes as possible, right? Automate the process of analyzing the data, coming up with conclusions, coming up with decisions, coming up with mitigations, and taking those mitigations and distributing to the infrastructure for prevention. Automate that entire process. That's called analytics, right? We've been doing that for many, many years.

Eleven and a half years ago, when we started developing our product, we decided that unlike anyone else in the industry, we're not going to offshore hundreds and hundreds of engineers to somewhere in Asia, so that they can look at files, analyze them manually, and come up with signatures. We completely automated the process of taking malware, reverse engineering it, coming up with mitigations, coming up with signatures, and distributing those signatures to our customers. We replaced hundreds of people with analytics. That was 11 and a half years ago. You just heard Lee talking about how six years ago, when the market was deploying sandboxes in order to generate even more work for those poor analysts in the SOCs, we decided to completely automate that process.

We decided to use analytics to take the sandbox, take the output of the sandbox, investigate it automatically, come up with mitigations automatically, and distribute those mitigations automatically to our customers for prevention. We've been using analytics in order to make our customers' lives better, in order to make them more secure over the last 10, 11 years, and I don't know of any other vendor in the industry that's even remotely close to what we're doing with a single analytics process. We have many of them today. Over the years, we found ourselves using more and more a very specific type of analytics. There are multiple types of analytics. You need all of them. We use all of them, but there is a very specific type that we found ourselves using more and more, and that type of analytics is called machine learning.

Everyone in the world is now talking about machine learning and how machine learning is going to fix all the problems in cybersecurity, and the engineer inside me gets really upset when I see companies talk about machine learning without really even knowing what it is and without doing the right things that need to be done for machine learning. I hate it, especially when they put the word AI in front of it, because AI is a specific type of thing that almost nobody is doing for cybersecurity because We can talk about it another time. You just can't do that. It's too much. I only have a few minutes to talk about it.

I think it's worthwhile spending the next three minutes talking about machine learning, what machine learning is, such that we can set the stage to be able to understand what machine learning is, and then be able to really determine if someone is doing machine learning or not. Maybe before that, today, we have, at Palo Alto Networks, we use about 100 machine learning classification models in order to secure our customers. That number is growing very fast. We have a very impressive team of cybersecurity, machine learning, data scientists, both in Santa Clara, California, and in Tel Aviv, and we're expanding that team constantly. Right? Let's talk about what machine learning is. Let's say you want to build a self-driving car. Right? You can use a traditional approach of building software or having an engineer sit down and say, "Write a bunch of rules." Right?

If you see a green light, you go. If you see a red light, you stop. If you see a yellow light, you look for police, and you make your decisions based on that. The list is so long that a human is probably not going to be able to enumerate all the use cases and all the different cases that software that's driving a car will encounter. We need something else. What we need is a way of creating the rules under which the car is driving in a more automated way. What do you do? You take a bunch of cars, you put a lot of sensors on them, you put humans in them, and let them drive around the town.

It happens to be the town I live in. I see them all the time. Those cars keep recording everything that they see, keep recording the action of the driver at the same time. There is a lot of data there. You take all that data. You let machines figure out from the data of what we've seen and what was the human reaction, what are the rules for driving, right? You take that. You let the car try to drive itself. You see when the driver is touching it. You reinforce your learning. You get more data and more data. You make your self-driving better and better and better. This is machine learning.

Machine learning is about letting software figure out by itself what are the rules under which it needs to perform or operate rather than a human putting in those rules? That's very useful in situations where you need to distinguish or you want to distinguish between good and bad. Right? If you have a lot of information about the good and a lot of information about bad, good files, bad files, good URLs, bad URLs, domains, IP addresses, network activity, endpoint activity, cloud activity, whatever it is, if you have enough information about what's good and enough information what's bad, and you're pretty certain that the good is good and the bad is bad, you can theoretically and practically teach machines how to distinguish between good and bad. Okay? How does the process work? This is very, very generalized and simplistic case.

Don't try to take that and have a meaningful conversation with a machine learning expert. In general, you start with a very high-quality data set of what's good and what's bad. There are other things it can do as well. You have data scientists extracting important information out of the data. That huge amount of data usually has very specific data points that are important for this specific machine learning that they are trying to build. The data scientist chooses the right machine learning algorithm, there are many dozens of them that you need to choose from, runs all the data through it, and create what we call a machine learning predictive model. Right? This is a model.

It's kind of a pre-wired brain, a brain that was wired based on all this data, all the features that were extracted from the data, that is now able, given data coming in from a customer side, to distinguish between good and bad. You take the data, you distinguish good and bad. If it's good, you do whatever you do with good stuff. If it's bad, you do whatever you do with bad things. You take all the data that you collect and use that to reinforce the machine learning. You keep that data. You make your machine learning models better and better and better. This is what machine learning is about. Okay? What are the challenges in machine learning today? The first challenge is that machine learning needs a lot of data.

If you have 10 pieces of malware and 10 pieces of benign files, or 10 good domains and good domain names, 10 is not going to get you anywhere. You need millions. You need tens of millions. You need hundreds of millions, depending on your machine learning model. You need hundreds of millions of data points, okay? We're living in a world where customers have to make very tough decisions every day as to which data they collect and retain, and which data they decide not to retain, because the cost models of retaining security-related data today is outrageous. It's completely out of whack. Most of our customers, most of the customers that we talk to, end up only recording, only logging into their event logging infrastructure, the things that they already know are bad.

When the firewall stops something, or the IPS stops something, or the EDR stops something, or whatever, they log it. That's useful information, but not for machine learning. If you already know it's bad, you don't need machine learning to tell you that it's bad. You need the good. You need everything. Cost models today are very prohibitive for that. The second thing is that all these systems that customers use today to log all this information were designed for an analyst that sits in front of the screen and looks for stuff. We call it direct search. That's the opposite of what machine learning needs.

Machine learning needs data that is stored all together in one place, to process that in what we call batch processing, right, or MapReduce, where you go into the data and break it into small pieces, you use a lot of processing in order to process those pieces of data, you aggregate them. It needs inline processing. It needs to take the data coming in from customer side, every time something comes in, you have to compare that piece of data to all the hundreds and thousands of machine learning models that you have to figure out if it's good or bad. That's completely different than what customers use today. The architectures that they use today to store the data, whether it's commercial or an open source tool, they just use the wrong architectures.

On top of that, if you compare the infrastructure that's required today for security analysts to do simple searches, and the infrastructure that's required to drive analytics in general and machine learning specifically, the amount of infrastructure that you need is multiple orders of magnitude higher than what customers are using today. Machine learning needs a lot of data, very specific data structures, huge infrastructures, customers don't have that today. The second thing that you need is high-quality data, right? If the driver in the self-driving car is going to pass a red light or 5% of the time, guess what? The machine is going to learn that 5% of the time, it's okay to pass a red light. You need very high-quality data.

If the hundreds of millions of good things and hundreds of millions of bad things have 5% noise in them, you're going to end up with a machine learning model that has more than 10% inaccuracies in it. How do you get very high-quality data? Well, you can't use machine learning because there's a chicken, egg problem there. You need other techniques, the other techniques that we've been using and developing for the last ten years in order to come up with high-quality data, and you need to have a very big customer base that has been sending you all that data over the last ten years in order to have that. You can't wake up one morning and say, "I'm a machine learning company today." Where do you get the data? Okay? That's why I just don't believe a lot of these startups that are saying that.

It takes a long time to do that. The other thing is that if you look at customers today, customers don't have data lakes. They have data puddles, right? I met one of the largest utilities in the country last week, and they feel very proud about how very close they're going to have a petabyte of data. The ability to capture a petabyte of data, which is probably for them, two days' worth of data, into their data lake. That's not a data lake. You want to do machine learning, you better have tens and hundreds of petabytes and exabytes. Okay? Otherwise, you don't have enough data in order to do machine learning. You're not going to be accurate enough. You're not going to have the right machine learning models coming out at the other end of it.

The last thing that's important is that it's very hard to find cybersecurity experts. It's very hard to find machine learning experts or data scientists, and it's extremely hard to find the unicorns that you need, which are data scientists that understand cybersecurity. You won't find those. You'll find cybersecurity experts that have turned into data scientists as well. We have them. We hire them. We train them. We made an acquisition of a company called LightCyber, and they brought a lot of them into the organization as well. You need unicorns. Very hard to find. Okay? Now that we understand the challenge with machine learning, there are two other challenges.

If you are three smart engineers who just graduated from a good university, and you have this great machine learning-based, algorithm for cybersecurity that you want to bring to the market, today, you need a complete product around it. Okay? Whether it's a network product or an endpoint product or a cloud product, you need to build a complete product around it. You go and you raise $10 million, and you build a product, and you go out to the market, whether it's an endpoint product or a behavioral analytics product or a UBA product or EDR product or whatever product it is. You come out to the market, and all of a sudden, you find out that there are 100 other companies that are doing exactly the same thing as you are, just with a different machine learning algorithm.

You go and you raise hundreds of millions of dollars, or at least $100 million at some outrageous valuation, to then go into the market and try to convince them that you have the right solution. Okay? That's not scalable. We have to change that. We have to enable very small teams of engineers to come out to the market with machine learning-based detection and prevention or other kind of analytics without going through that process. Then on the consumption side, you've heard the challenges before, but there is another challenge, which is a lot of these technologies are junk, but very few of them are good. Today, as a customer, you have this long line of vendors in front of your door trying to sell you the technology, and maybe you'll find three or four good endpoint machine learning-based algorithms.

You find a few good ones for EDR, and you find a good one for this and good one for that. You can only choose one because it's so difficult to deploy it today, it's so difficult to consume it today, that you have to limit yourself to one. You want to use all of them. How do you use multiple machine learning algorithms from different vendors, from different innovators at the same time? When I look at all these challenges, the fact that the world is not ready for analytics and specifically for machine learning, when I look at an industry that just can't bring innovation out anymore because of the cost associated with it, and I look at a customer base that cannot consume the innovation because of this long line that they have to deal with, I see an opportunity for disruption. Okay?

I see an opportunity for Palo Alto Networks to disrupt the market for the third time and bring the third evolution into the market and drive the third evolution into the market. What do we do? We created the applications framework, and we created the logging service, which go together. We created an architecture that turns all the very high-quality sensors that we have there, network, endpoint, cloud, into data producers. We collect all of that into the right architecture, I'll talk about it in a second, in a very cost-effective way.

Then we run our own applications, and we let third party run their applications, whatever kind of applications these are, whatever type of analytics they're doing, and if they're doing machine learning, whatever type of machine learning they want to do, display results to users, but most importantly, make decisions and drive those decisions back into the infrastructure for automated prevention. Okay? Let's click into some of these components, starting with the log service. There is a test after this about all these different components. No, I'm kidding. This is what you need to do in order to do machine learning. If you don't have that, you're not doing machine learning. Okay? Our logging service takes what customers do today, which is in purple there.

They do direct search, either with Elasticsearch or some commercial tool over a very limited amount of data, and extends that to all the right technologies that process the data and also extends that with practically unlimited amount of data can be stored. You want batch processing? We use HDFS, Hadoop for that. You want direct search? No problem. We have that. Things are not showing up well there. Sorry. It's hidden somewhere there. Just with the wrong colors. You need inline processing? We have Hadoop, and we have Spark for that. We have HBase. We have SQL. We have all the different components that you need, and all of that for a fraction of the cost that you pay today for whatever is there in purple.

Today, for whatever there in purple, again, something for an analyst to go and do direct search, you'll be lucky to pay a few tens of thousands of dollars a year per terabyte. Usually, you'll pay closer to $100,000 a year, if not hundreds of thousands of dollars a year per terabyte. Our pricing, $2,000 a year. We created an architecture that allows us to charge customers $2,000 a year per terabyte, not because we want to lower the price that they pay, because we want them to use the same amount of budget that they have. Actually, they'll need new budget because we're not going to replace what they have today, but we want them to use a reasonable amount of money to log everything.

We don't want customers to be in a position where they have to choose what to log into and what not to log. We need all the data if you want us to do machine learning for you. We put it into the right infrastructure, into the right architecture. Not into a subset of it, which is well done today, but into the right things that need to be done. We have the data sitting in the right architecture, at the right size, at the right volume. The second thing we need to remember is high-quality data. How do you do that? You spend 10 years building it. You saw Lee talking about very specific type of data, the data that comes out of WildFire. WildFire is only one thing of the things that we're doing.

We've been doing threat prevention and URL Filtering. We're looking at DNS, URLs, files, command and control, network traffic, endpoint activity, cloud activity. We have a lot of data that we've gathered over the years, but more importantly, we have created processes to very accurately classify that data. We have the right data, and we're very unique at having the right data that can drive the training of machine learning models so that we can deliver to the market in a very high-quality way. Okay? That's the second thing that we have. We have all of it in one big data lake. We don't have data puddles. We have huge infrastructure that's been collecting all the data forever.

It's now significantly expanded in order to collect all the additional data that we're going to get from customers through the logging service and all the data, whatever type of data it is, no matter if we collected it 10 years ago or we collected it yesterday, it all goes into one extremely large data lake. Okay. No more data puddles on customer premises. Just doesn't work. It has to be a huge lake in the cloud. Okay. Now that we have all of that, we can let our own engineers, we can ourselves, run applications on top of that data, analytics application, including machine learning-based applications, and we can let third party run applications on top of it. What kind of applications? Many different ones. Here are just a few types of applications. We already are selling one application. We're selling a threat intelligence application called AutoFocus.

We announced a behavioral analytics application, that's going to be available around the end of the year. That's called LightCyber. Well, it doesn't have an official name yet, but it's coming from LightCyber. We are working on more applications today. We are working on a good number of applications that are going to turn into a good number of services that our customers are going to be able to buy from us. More importantly, we have more than 30 partners, some startups, some large, some customers of ours, some partners, some competitors, that have already announced that they are going to build applications into the applications framework and deliver their functionality to our customers through the application framework while we monetize that. Okay.

I see a future where I want to get to a point in the industry, in the future, without a timeframe, where everything that organization consume when it comes to cybersecurity is consumed from the cloud. Most of it will come from either us or our partners through the app framework and the logging service. Some of it might be coming through other mechanisms, but all of that will be running on top of just a few things that float in the infrastructure. Our next generation firewalls, our endpoint security solutions, and our cloud security solutions. Okay. I think it's very clear what's the benefit for a vendor in delivering their services through the applications framework. You get immediate access to a lot of customers. You get immediate access to data that doesn't exist anywhere else in the world, and not just in quantity, but also in quality.

You're able to deliver those services without building a lot of code. You just take what's unique for you, the algorithm that's unique for you, or the machine learning model that's unique for you. You build it into the applications framework, and all of a sudden, all of Palo Alto Networks customers can consume it. Very clear what's the benefits to these vendors and others. What is the benefit to customers? If you're a customer, why would you use that? I want to give you an example. Let's say that you decide to use a behavioral analytics solution, whether it's ours, LightCyber, or a competing behavioral analytics service that's going to be delivered through here or it's delivered in other cases. Here's the way you work with it today.

The behavioral analytics solution that you decided to use is going to tell you about something weird that happened in your infrastructure. You have to take that information. You have to compare it to all your threat intelligence feeds. You have to make decisions. You have to score the risk of it to figure out what is the risk of what you just found and compare it to your risk tolerance. If it's high enough, you want to take that information and convert it into actions that you then take care of the infrastructure. All of that is a person moving from one application to another, looking at the alerts, looking at the threat intelligence feed, comparing them, then looking at their risking system, taking it into the risking system, taking it into the system that's going to then orchestrate and distribute that into the infrastructure.

Then you need to take the data and generate a report for your manager to show, here's what I've done. Here is what happened. Here is how I mitigated the attack. That takes hours, if not days or weeks. As a customer, you can buy those applications inside the applications framework. You can, again, buy LightCyber or can buy competing application inside the application framework. We're not going to make the life of our competitors more difficult than us in delivering applications. We don't care. We monetize it anyway. You use that application. The application comes up with the alert, automatically sends alerts to a threat intelligence application that's going to mine many threat intelligence feeds and figure out whether that threat is relevant to you.

All of that goes into a system that scores the alert or the event and gives it a risk number and checks whether the risk number matches your risk profile in connectivity versus security. If needed, it goes into an orchestration tool that takes that information and distributes that information back in the infrastructure for prevention. Then automatically, that information goes into your application that's responsible for reporting. A report is generated and sent to your manager, wherever it needs to be sent. All of that automatically within seconds, without a human touch. This is the future. We believe we're going to drive that future because we are uniquely positioned when it comes to access to network-based information, endpoint-based information, and cloud-based information. We have a unique architecture. Nobody has that. Nobody gets close to that.

Everything that's being used today has been geared towards an analyst, not machine learning and, in general, analytics. No correlation is not analytics. It's two queries that you combine. We have the right data in the right context, data that took 10 years to build and will take anyone else in the world at least 10 years to build, if they can even do that. We're going to use all of that to bring to the market more and more and more Palo Alto Networks applications sold as a service to our customer base. We're going to monetize many more applications that are going to be brought to the market by third parties. Many of these have already been announced and many more, I'm sure, are in the works. Thank you very much for listening.

Operator

Ladies and gentlemen, we will now take a 10-minute break.

Speaker 18

Day in, day out. That same old blues follows me about. The same old pounding in my heart whenever I think of you. Baby, I think of you. Day in and day out, day out. Day in.

Operator

Ladies and gentlemen, our presentation will resume in five minutes.

Speaker 18

How my days begin When I awake, I get up with a jingle. One possibility in view. That possibility of maybe seeing you. Come rain, come shine. I meet you after me, the day is fine. I kiss your lips and the pounding becomes an ocean roar. A thousand drums. Can't you see it's love? Can there be any doubt? When everything is in its place. Come rain, come shine. I meet you after me, the day is so fine. I kiss your lips and the pounding becomes an ocean roar. A thousand drums. Can't you see it's love? Can there be any doubt? When everything is in its-

Operator

Ladies and gentlemen, please take your seats. Our presentation is about to begin

Speaker 18

Can't you see it's love? Can there be any doubt? When everything is in its place.

Operator

Please take your seats. Our presentation is about to begin. Please welcome Mark Anderson.

Mark Anderson
President, Palo Alto Networks

Morning. Thank you. I hope this morning we've made it crystal clear to everybody here in the room that our innovation engine at Palo Alto Networks has never been stronger, and the need for what we do in a highly integrated way has never been greater from our customer bases or around the world. With the 24-hour news culture, as well as the proliferation of disconnected legacy point products that are out there, our prevention-oriented architecture is winning in governments, it's winning in enterprises in a very high rate, and I'm going to talk a lot about that in detail. Connecting with customers every day, and the themes, things that I'm hearing from customers give me a pretty broad perspective, and I'm going to share some new data with you today that demonstrates the value of this innovation is going to only get stronger as time goes on.

Our ability to be able to leverage this power of innovation, to be able to continue to drive improvements in productivity and enablement in our field and partner ecosystems, is going to continue to drive massive differentiation between us and what everybody else is doing. Around the world, hearing the exact same thing from customers. They need better security. They need more efficient consumption model. We've seen this slide now three times, but to me it really feels like it's been broken for a very long time. We know the consequences for failure have never been greater. Obviously, the breaches aren't slowing down. The scale actually seems to be increasing. Despite what you hear from the marketing departments of some of the other people in our industry who claim to have glued together architecture from acquisitions or umbrellas or fabrics, they're really just not cutting it.

Fighting highly automated adversaries, as we've heard, and the huge amount of data crunching that's required to be able to be effective in this space is not going to be enabled by a conga line of different and disconnected devices. Our three evolutions of technology tie things in a very nice, tight, integrated way, and an architecture that is being recognized by customers, recognized by the governments that I talk to around the world, and it's driving better security outcomes everywhere. The platform is winning, and it's a comprehensive platform. We see long-term customers extending beyond the network security platform that we evolved, from moving from the data center to our endpoint solutions, to our cloud solutions. I'm going to give you some specific examples of that later on.

Others, like Lee said, are attracted to us based on the innovation we've applied in the cloud or on the endpoint, with over 1,000 customers coming to us first in cloud. We get the chance to expand that relationship, as we've very much focused on that. As we expand these customer relationships, I want to make sure you understand the barriers to entry for our competitors as we deepen relationships with customers get very significant. The choice for Palo Alto Networks becomes self-reinforcing. The common thread that runs across all of our entire customer base is that they buy and they keep on buying to drive those outcomes. The platform is really delivering on what they're telling us that they need from a partner.

We win because we really are delivering that better security, and they're choosing Palo Alto Networks because we're solving these compounding issues that they're finding in security, and these are compounding issues that really are existing because of the waves of innovation that are hitting the entire IT supply chain. Our platform helps reduce the number of discrete vendors that people have to deal with. Reduces big-time operational complexity. As a result, it reduces the number of people that they have to hire to manage this estate. We demonstrate this with tools in front of our customers every day with provable high rates of return, provable ways to reduce their operational costs. Just a few weeks ago, I was in Spain, spent some time with the team down there in Barcelona and met with a number of customers.

I got to tell you, the vendor fatigue that I hear from customers is very high. Clearly, in the northern part of Spain, the economy is improving pretty dramatically. They're starting to spend, but they're buckling under the complexity of the legacy point products that they have, and our brand in Spain has never been stronger. They can't hire enough qualified people, even if they could afford them. This is a big problem I hear about worldwide. Today, there's roughly 1 million open cyber positions around the world, and recent cyber job reports talks about by 2021, there'll be 3 million open cyber positions in the world. Clearly, automation is very important in this dynamic, and our adversary, as we've said, is highly automated. We've got to be able to respond to them, and Palo Alto Networks is doing so in kind with customers.

Customers are agreeing, and they're voting with their wallets. It's why we're seeing this really record customer adoption. You saw in Q4, we added a record number, close to 3,000 customers. Almost every single one of these 42,500 customers that we have today, they've displaced multiple point products from our competitors with our platform. Let's take a little bit deeper look at these customers. Who are they from a vertical standpoint? Take a vertical cut of the data. This data is based on lifetime purchase order value for each vertical. We've got tremendous vertical diversity. It's one of the things I love about this company, is everybody needs better security. We've got some of the largest spending verticals that we still have a tremendous amount of room for expansion in.

All customers are struggling with the same issues, complexity of managing the estate and lack of skilled personnel. As we focus our subject matter experts that we've built out over the years into the bigger spending verticals, like service provider, like financial services, like SCADA, ICS entities, they're turning to Palo Alto Networks as their subject matter expert, thought leader for security for help. I think we'll continue to be able to expand not only these larger spending verticals, but continuing to focus with our partners and our diversified sales team, to cover all of these different verticals and capturing more wallet share. Where are they? Well, really, as we talked about in the Q4 earnings call, we saw a record revenue growth, or certainly great revenue growth, out of EMEA and Asia Pac and Japan.

This cut of data is talking really about the 8,500 customers that we brought in FY 2017 and the customer acquisition by geo. You can see the investments that we've made in Asia Pac, Japan, and EMEA are paying off, with customer acquisition growth growing by 27% and 30%, respectively. I think about the IT cultures that I visit around the world. Clearly, these cultures vary. Some are very forward-leaning, like the Americas here. Some are a little slower to adopt new technology. What struck me in recent travels, you look at EMEA as an example, some of the compelling events coming in May 2018, GDPR, General Data Protection Regulation, and the NIS Directive. Legislation that are imposing a sense of urgency on these customers, and we're getting meetings to talk about what our view is of the definition of state-of-the-art technology.

More and more, they're turning to us to help them in this journey because we're Palo Alto Networks, the brand reputation that we've evolved over there is pretty spectacular. I think this legislation, and others like it in places like Australia or Canada or the U.K., is very good for Palo Alto Networks. As one of the two non-Americans on the executive team, I get a chance to spend time not only with customers internationally, but also with governments. Government entities like NATO, national police agencies, security organizations, as well as Ministry of Interior, Ministry of Defense from most of the countries across Europe.

Now, in this last couple of years, more than ever, they want to turn to Palo Alto Networks to ask for advice on how to interpret this legislation and how to federate it into their countries, respectively, different forms of certifications and whatnot, we're there at the table with them. They're also becoming customers. We're invited to the dance just generally more than we ever have been before, and it's especially the case with our biggest customers, our Global 2000 customers. I want to break this down for you. I stood up here a few years ago and talked about betting big on major accounts and building organizations to go after dedicated teams, to go after major accounts, and specifically this index, Global 2000, the Forbes Global 2000 Index, in every geographic theater.

As you can see in the past three years, that focus has really paid off. Going from a little less than 50% in FY 2015 to 63% penetration of the Global 2000 by the end of FY 2017, the investments are working. Many of these customers have gone all in with us. I'll give you an example specifically later, and that's fantastic. They'll use us to protect their perimeters, their data centers, their endpoints, their journey to the cloud. These are very big, complex customers, many of them having subsidiaries and dealing with ultimately thousands of vendors. Many of these accounts, we still have ample opportunity to expand. I'll give you a sense of wallet share in a few.

The 37% of the G 2000 that are not Palo Alto Networks customers today, we're getting meetings there, we're talking about this journey, we've never been stronger at being able to do that than we are today. With the brand we've built, along with the motivated sales teams, the motivated partners that we have, we're all focused on landing and expanding, in all of these accounts. As far as wallet share goes, even with the accounts that we have penetrated, the 63%, we still believe that on average, we still only have 10%-15% of the wallet share within their security spend.

There's enormous upside in the accounts that we've already broken into, and that's why we're focusing on driving an improvement in that wallet share, helping them with new use cases, new locations, new customer sites, and leveraging some of the new and exciting services that we've recently announced. I'm going to zoom back out to our 42,500 customer population. You can see for Evolution 1 that our attach rate in Q4 was 2.9. This is new data for you. Last year, bless you. Last year, we mentioned we attached a 2.66 subscriptions on average for every device sold. This really proves that we're continuing to penetrate and leverage the power of the platform for our network security offerings. When we land a brand new customer, we land with the platform. We don't just try to sell a firewall or a web gateway or an IPS device.

We're replacing multiple products as we land with customers today, and it's clearly supported by the numbers. For all existing customers, we're selling new use cases, looking to expand their estate. Example is, someone that's committed to us for firewall and IPS, if their web gateways come up, the easy thing to do with the kind of coverage that we continue to focus on them is to just turn on URL Filtering if they haven't purchased that initially. Just look at the WildFire adoption, it's pretty incredible. This is a product, remember, that we announced about five years ago, and customers continue to unplug their standalone APT devices and turn to WildFire for better, more orchestrated, more integrated security verdicts that we can provide with the platform.

If we pull back out to Evolution 2 and 3, important additions to our plan like Aperture, AutoFocus, our VM-Series. They're all represented here in the cloud category for 2 and 3 for just an exceptional year for Traps. We grew our customer count by over 3X. The prevention part of endpoint, being an integrated part of the architecture, really resonating with customers. Same thing with cloud, more than double. These numbers are starting to get very big and material for us. We know that our customers are moving workloads to SaaS environments. They're moving them to public cloud data centers. They want to be able, as Mark said, to enable consistent security policy.

Every single customer I talk to, whether it's at an EBC or whether it's during my travels, I always ask what their plans are with regards to cloud, and we're seeing almost 100% customers are thinking about it, they're testing it, or they're deploying it in different stages. More and more, they're turning to Palo Alto Networks as the thought leader in security to help them on this journey. The other thing I thought, if you got a chance to attend Ignite or download any of the presentations, up on the main stage, I had Ann Johnson with me, the head of cyber at Microsoft. She talked about Palo Alto Networks being the number one ISV for Microsoft Azure. We're working very closely with Microsoft's teams. Same with Dave McCann, he was up on the stage with me, runs engineering for AWS.

Talked about the engineering integration that we've worked so closely with on AWS to be able to enable these AWS deployments for customers work and drive that consistent level of policy enforcement. I really want to make this crystal clear. I think you think about this from any of our field salespeople, our existing partners, they really view cloud as being additive to us and to our mission. We're not only adding value to the existing customers, but as Lee said, it's an attractive entry point for us. Buying cloud Traps as a first product purchase, we're leveraging the brand that we built and the ability that we've been able to take to customers, land with the product, and then continue to expand there.

If we want to talk about wallet share expansion here from a different viewpoint, this shows each cohort's expansion multiple of LTV against the initial buy. As you can see, every cohort continues to expand year-over-year. Look how interesting this gets for the fiscal years 2012, 2013, 2014, and beyond. The number of customers that we added in those cohorts are actually becoming substantial, in the thousands. In a little while, you're going to hear Rene and Naveen. Rene, our amazing Chief Marketing Officer, Naveen, our Chief Information Officer. They're going to talk about how we're arming our sales teams and our partners with data science and specific tools to be able to go after these cohorts and move them to new products and services in a very scientific way. Teams around the world, they've got a lot more to sell.

Logging service, GlobalProtect cloud service. They've got new products to sell. They got a lot more arrows in their quiver, and we're laser-focused on our existing estate to continue to focus on growing more wallet share. The power of the LTV here is really substantial with this land and expand model that we have. I know all of you are familiar with this. In the past, we've used the 2009 cohort to kind of demonstrate the journey that we take with our customers. This year, I want to shift it to the 2012 cohort. That's the year of our IPO. I think it's a better illustration of our business. You look, again, the cohorts, as you move after 2012, they continue to expand very nicely. By the end of last year, the products and subscriptions growth from that 2012 cohort, 5x.

Even the renewals has grown 2x. This is even without a major refresh cycle, and that's certainly coming up with the new products we announced six months ago. Thousands of Palo Alto Networks personnel out there in the field, tens of thousands of partners are focusing on the opportunity at hand, which is to go after this existing estate and help their customers on their digital transformation journey, to really protect their way of life in this digital age. It's clearly yielding results. I want to give you a little more granular look at our top 25 customers. This is a very familiar slide. We talk about this every quarter, but I want to deconstruct it for you to kind of by pulling data out to illustrate the significant opportunity that we have with our largest customers.

Just as a reminder, top 25 slide represents our biggest 25 customers at a point in time. This list can change from quarter to quarter because we're seeing large customers make seven and eight-figure buys that buy their way into this top 25. This looks at it at the end of last fiscal year. The initial purchases for these prospective customers are represented by the green boxes. You're going to see a remarkable pattern emerging from this data when you think about the thought leadership we have in our industry and the focused sales coverage that we're applying to these customers. The blue boxes show subsequent purchase orders in subsequent quarters. It's a sea of blue, right? Repeat orders are the norm. New business is being contracted with us at an increasing frequency. We're not just selling them more stuff.

We're really helping them expand their scale, cover their attack surface. We're working with global organizations and helping them reduce complexity and drive efficiencies, and this is just a remarkable phenomenon. Bigger customers pushing for consolidation faster, looking for more automation, as we heard. You can just see the consistency of this vend. It's almost every single quarter. Let me overlay how this consistency looks with regards to multi-year agreements that we've done. The orange boxes are quarters where customers first made a multi-year purchase commitment to Palo Alto Networks. Clearly, major account teams don't just go away. They're proactively positioning and winning additional business because of the growing faith and trust that these customers are giving Palo Alto Networks because we're helping them eliminate pain points. In fact, almost every single one of these top 25 customers have purchased another multi-year purchase in their journey.

Different locations, different solutions, different services. We have dozens of use cases to sell, a whole now broad array of products, physical and virtualized to sell. Our teams and partners are trained to go after these like rabid dogs, to help customers get to a much better place. The ticket to get into this club grows every quarter as well. We announced on Q4 earnings call that the ticket to get in was close to $22 million, up from $14 million in Q4 2016. Can anybody guess what the ticket was in the first quarter of our IPO? The ticket to get in to the top 25 club. I've got a free portfolio for you if you can guess the right answer. Yes?

Speaker 16

$2 million.

Mark Anderson
President, Palo Alto Networks

Yes. Roughly $2 million. Good. Give that man another portfolio, please. Actually, $1.8 million. Really, a compelling story here of growth and focus and, frankly, thought leadership and technology. Lifetime value, year-over-year, we see this, the multiple going up. We've mentioned again, it grew from 52x in FY 2016 to the end of FY 2017, 97x that initial buy. I'm going to share some new information with you because you continue to ask us for more information about a broader cut of our customers. Let's talk about that beyond the top 25 customers. Our top 100 customers. LTV expansion is 75x. That's pretty compelling. I was expecting some jaws to drop and some gasps. If you zoom back a little farther, the top 500 customers, the lifetime multiple is still 25x. Truly partnering with these customers in their journey.

I talked a bit about digital transformation. It's the buzzword that we hear from pretty much every customer today. You can't embark on a journey of digital transformation without thinking about security from day one. They've got to look at their legacy security estate to embark on this transformation. When they're doing that, they're thinking about Palo Alto Networks. I'll show you by double-clicking on one customer in the top 25, in particular, to show you their journey, just to give you some even more data. Just picked a particular customer here in the middle of the top 25. This is a large professional services company. Started with us innocently enough back in Q4 of 2010. Made a small pair of firewall purchases in one of their locations, bought threat prevention and URL Filtering.

Back then, the legacy estate owners, Cisco, Check Point, Websense, and Symantec barely even noticed that we were there. Fast-forward three quarters later, they felt comfortable enough with the leveraging of App-ID and User-ID, the visibility that we were giving them to their customer and application behavior, they decided to displace some of this legacy estate in more sites. As you can see, every quarter or two, they went about deploying our network security offerings and displacing these vendors pretty aggressively, adding both new products and more subscriptions. We get to the end of FY 2013, the year we productize WildFire. They slid us into the network right beside FireEye. A few quarters later, they felt comfortable enough with the capabilities of now this extended platform that was being deployed in more and more of their global sites to turn WildFire on globally and kick out FireEye.

By the end of FY 2014, they started buying from us every single quarter, new sites and new use cases. FY 2015, they had our devices deployed in almost every single site. Our sales and partner team introduced GlobalProtect as their Juniper Networks SSL VPN started to experience some scaling problems. They turned on the first few sites, same thing, getting comfortable with us. Now we've become their global standard. We're a trusted partner of this account. Within a few quarters, they pushed Juniper Networks out of the way and had GlobalProtect deployed globally. As you know, with GlobalProtect, we can enforce consistent policy for customers' users that are off network, and they love that capability.

It's really important for large distributed customers, especially in the professional services space, but I'd say every large distributed business in the Global 2000 is going to use GlobalProtect, and especially with the growth that we talked about earlier. At this point, it's becoming very difficult to penetrate this account with the proliferation of Palo Alto Networks. Now with their global standard, they start to build out hybrid data centers with VMware. They deploy our VM-Series to enforce consistent policy there. Again, these VM licenses clearly additive to the spend. By the beginning of FY 2017, with their entire global enterprise uploading files to WildFire from all devices, physical, virtual, on-prem, off-prem, they really saw the value of AutoFocus and made the investment there. It helped their SOC engineers hunt for threats. That was very valuable to them.

Later in FY 2017, as they started to move workloads to SaaS and more incremental workloads to public cloud, they added more VMs and finally added Aperture, beating out the startup CASB vendor that really had a difficult time coming in to be one of the non-Palo Alto Networks standard solutions there. We beat them out on features and capabilities, especially with the backdrop of the platform. As you can see, this customer's consistent buying is now every single quarter. Last year, at the end of the year, they did a huge Traps deal with us, eventually getting rid of Symantec as their core antivirus solution and extending our platform to the very location that many of these attacks are being launched to the endpoint. Bless you.

I think this point, they've rationalized so many vendors, purchased every single product that we sell, and along the way, you can see we're adding products and subscriptions almost every single quarter. Their lifetime spend with us today is well into the tens of millions of dollars. But more importantly, we're driving airtight security for this important customer, way better security outcomes everywhere in their estate, and that's what we care about the most. But we've also displaced so much cost and complexity out of their environment. Internally, we're viewed as the poster child for ROI for information services. It's a really good customer story. It's taken place over close to 10, excuse me, 7 years, and it's going to continue to grow, because now we have new stuff to sell them. All this, it's not happening by accident.

It's happening because our customers, as Mark said, are really happy. Our subscription rate's at 90%, renewal rate's around 100%. I think it's world-class, and I think it's a big driver of top and bottom-line growth for Palo Alto Networks, but also for our partners. They're very much attracted to this. You look at our Net Promoter Score over the last six months, 71.6. Remember, this is a range that goes from -100 through positive 100. This is world-class, we think, in our industry. Last year, we were also recognized by the TSIA and J.D. Power for our outstanding customer support and outstanding experience that we deliver to customers. We've got hundreds of amazing support teams around the world driving this. But it's not just people, it's business process, very agile business process that Matthew Taylor has driven in that organization.

It's tools, next generation, world-class tools that we're using to be as quick and responsive and effective as possible. Listen, our company, the support organization, the rest of the company, we're not distracted by selling switches or routers or video teleconference or Wi-Fi devices. We sell security. We support our customers with regards to security, and we're very much focused on driving customer success across the board. Talk a little bit about our channel partners. We've got 4,420 out there, with a portfolio of services that continues to grow, which is why they love us. Spent a lot of time with partners in Spain last week, and boy, the reception for the logging service, GlobalProtect cloud service, and the application framework was unbelievably positive. We're always looking to surgically add new partners. We're not out there just trying to cover the world with tens of thousands of partners.

We're looking for ones that are going to help solve our customers' problems. I think we saw a nice uptick year-over-year for that. More importantly for our partners, 661 of them last year doubled their business with Palo Alto Networks. That is incredibly important to them, given the dynamics of the world that we live in. Really what this means is the ones that are growing at this rate and at high rates are really leaning in with Palo Alto Networks. They're making investments, they're training their people, they're hiring and building out teams to cover Palo Alto Networks' customers. They're even buying demo gear to expand the footprint, the sales footprint that we have for our sales team.

They're doing this because we're providing the top-line growth at scale in our industry that nobody else is doing. That's leading to very attractive bottom-line outcomes for them. Continue to be very attractive to them. Ron Myers done a great job of building out this business. Partners continue to become more and more productive and carry the ball farther and farther down the field. This is part of a multi-year focus that we've had. Last year, just as an example, we trained over 8,000 partners around the world. These are partner reps, partner SEs. We had 1,000 that came to our sales kickoff in August. Hundreds of them came to our annual SE Tech Summit. Every month, we do new hire for the dozens of people that we onboard each month. We bring partners to that.

They're getting the exact same curriculum that our sales teams are. Exact same curriculum. Sitting there shoulder to shoulder with our people, learning how to articulate the business value that our platforms deliver for customers. They're really an extension of our sales force. That's why last year, over 1,000 more customers were sourced by our partners, going up from 3,500 to 4,500. This is a significant value creation that we have there. On the Traps side, we now have 130 certified Traps partners. This is up from 50 year-over-year. Just to make this clear, you got to spend a lot of money and a lot of time to become Traps certified for Palo Alto Networks. It's not an easy endeavor. You got to make a sizable commitment to training. My perspective here is success begets success.

As our endpoint customers and the endpoint revenue that we're getting and sharing with our partners continues to become a more meaningful and more material number, we're going to continue to snowball and grow this. As we go through FY 2018, I expect this number to go up dramatically as I do, clearly, with our revenues in Traps. Finally, really a new category for us, maybe a new category for you. This is Born in the Cloud Partners, the BICs. We hired Dean Darwin a little less than a year ago to build out a global focus on public cloud. He went about and signed up nine, and these are nine of the biggest Born in the Cloud Partners. This is an emerging channel that's ramping very fast. Right now, there's another 30 BICs that are in the process of becoming certified.

Really, they're coming to Palo Alto Networks not just because of our brand and reputation, but because of the subject matter expert team that Dean has built out around the world. Public cloud security specialists that we have now in every geographic region that are overlaying our core sales teams to be able to go in to customers and help customers on that journey. I'm spending a lot of time with our biggest, longest-term partners, and I'm probing on what they're doing, to react to this really existential reality that's happening in their world as the stack of value for delivering an IT service to a customer gets compressed by the likes of Amazon and others, by the likes of our application framework, for that matter. We're challenging our existing partners to develop these capabilities, and they're responding very well.

They're building out their own public cloud practices. They're buying Born in the Cloud Partners, and we're going to work with them together to help them on this journey, and we think it'll be great for both of us. On the strategic technology partner side, these continue to be a cornerstone of our open approach. We're not focused on building marketing relationships that we can broadcast, but really ones that are R&D led and that are highly integrated and coordinated in our field sales organization. Partnerships that our customers lead us into really help them reduce the cost of integration and implementation so that they don't have to do it, and they can leverage the automation that we can provide.

Market-leading partners like Proofpoint for email security, VMware for private cloud, obviously AWS and Azure for public cloud, identity companies like Centrify and Okta to help prevent credential theft, as Lee walked you through, and really Arista for next-generation networking. I'm also really proud of our partnership with Splunk. We got compelling integration as they build out a next-generation SIEM. We continue with Splunk to be the number 1 independent downloaded app in their marketplace. These partnerships are mutually beneficial, obviously, but more importantly, they're driving better outcomes for customers. Really to close things out, going to get back to some of the questions that have been asked over the last few quarters, just on the execution side of things. We're deeply focused on field execution. Want to give you a few quick updates.

As we said, we're in the bottom of the fifth inning, well into the run it phase. This is the relationship building side of things where we're trying to maximize the alignment that we put in place a few quarters ago. Firmly believe we have the right solution. Our employees, more importantly, believe that our partners and our customers seem to agree with us. As the president, I'm laser focused on the two key elements of this, attrition and productivity. On the attrition side of things, it's improved. It's where we expect it to be and well below industry average. Very much focused on this in the hierarchy of sales leadership around the world. On productivity side, by the end of Q4, over 60% of our sales teams were ramped and fully productive. This is the highest that it's ever been. This is new data, right?

I expect that this will continue to grow in FY 2018. It will grow mathematically as we focus on attrition and driving productivity. We're focused on improving that productivity in a number of different ways. Sales enablement is a really important one. Adding productivity enhancing tools, driving better efficiencies, will clearly drive higher productivity. The woman that runs worldwide enablement, Liane Hornsey, now reports directly to me. It's a major time focus from my standpoint. Excitingly also at SKO, we announced some new world-class organically built tools that leverage machine learning and artificial intelligence. This is going to ensure our reps are taking a very scientific approach and have the best possible chance for success. It's something that our CMO, my brother from another mother, Rene Bonvanie, and our CIO, Naveen Zutshi, have been working really hard on for a while.

I'm going to let them get into the details and invite them up onto the stage. Naveen, Rene, please come on up.

Rene Bonvanie
CMO, Palo Alto Networks

Thanks, Mark. Mark promised me he wouldn't say AI. After what Nir said about AI, of course. Much like what Nir said before about the power of machine learning and the power of data, I've had the privilege of having been with the company for quite a while and having the opportunity to set up an infrastructure that was capable of collecting the data that we have gathered over time about how our customers, our channel, our sales reps, our marketing efforts all come together.

We're talking about millions and millions and millions of data points that we have collected over time in a single data infrastructure, very much like the data lake that Nir described we build for our products using the same types of tools and technologies that Nir mentioned to build what is ultimately a highly targeted system to help our sales reps, our channel partners, our distribution channels, to go after the right opportunities with the right knowledge. That kind of machine learning is non-trivial, and we believe is a distinctive competitive advantage for the company. Now, the context in which we have done this didn't happen overnight, of course. It took us 10 years to collect this data and build and refine the algorithms. Clearly, in the last 6 months, there's been lots of emphasis after our Q2 announcements.

We started to train this machine even more so on making sure that we could align the machine learning outcomes to the priorities that we had set in our go-to-market planning, but as a result of the first half performance. It is based on investments and technologies that we've had for a long time. The reason I'm doing this with Naveen is typically what you hear is the CIO and the CMO can never be friends because somehow, they're at odds. Not so here. We have built a lot of this together. Naveen has been with us for quite a while now. It turns out that if you build a great relationship based on fantastic tools, such as Salesforce.com and SAP that we use, and Hadoop and those kinds of technologies, you can build amazing things.

The machine has been very specifically trained to do a variety of things. A few use cases for which we have developed very specific and very precise algorithms is for opportunity scoring, and we'll show what that means. Where do we get our sales reps aligned behind the opportunities that are there in the market? Lead scoring. Where do we train our partners what to go after? Account scoring. What is the opportunity for expansion in those accounts, and where do we point the machine, the investments, to go after? Competitive risk factors in deals or in existing accounts. A lot is said about somehow a threat after the first half performance that all of a sudden, the competition said, "Well, listen. Palo Alto Networks has some volatility." We wanted to make sure that we understood that volatility and could arm our sales reps, our channel partners, with the right tools. Also very much account churn risk. We now start to get into the very early innings of a refresh cycle, but where do we want to point the machine? Where do we see that appear first? It can be random. The machine has been trained, and we now see very high accuracy in the recommendations, well over 90%, which is where these technologies should be.

Palo Alto Networks has some volatility." We wanted to make sure that we understood that volatility and could arm our sales reps, our channel partners, with the right tools. Also very much account churn risk. We now start to get into the very early innings of a refresh cycle, but where do we want to point the machine? Where do we see that appear first? It can be random. The machine has been trained, and we now see very high accuracy in the recommendations, well over 90%, which is where these technologies should be.

The first we want to talk about is opportunity management, because this is important specifically because of the work we did in North America after the first half, where we reset the clock on territory management and on account management, where we wanted to make sure that we were closer to the opportunities. Naveen, why don't you explain what this screen is about? By the way, what you're looking at is a salesforce.com implementation, one of our core technologies, a technology called Lightning in Salesforce. Why don't you tell us what is going on here?

Naveen Zutshi
CIO, Palo Alto Networks

Good morning first. Good morning, everyone. Rene, as you mentioned, I think this notion of co-creating with business is really taking hold at Palo Alto Networks, and it's great to work with sales, marketing, and other leaders and teams to actually build solutions together. As we looked at sales productivity, one of the areas that we are focused on is how do we improve sales productivity in general, but more specifically, how we give time back to our sales reps so that they can spend time with our customers. That's a critical factor for us because we know that when they are talking to our customers, our customers are successful in preventing cyber attacks, and we are providing better tools to our customers to do that.

What we did in Salesforce specifically is simplify account opportunity creation, contacts and lead creation, put rigor and discipline around sales stages, and by sales stage, add specific processes that make it really important and critical, on what stages they need to work through and run through each stage specifically. We also made the resources available in one place for our sales reps. Whether these are TCO analysis, whether that is evaluations they want to do for a customer, whether there's a POC request that they have that they want to evaluate with a customer, we made it really easy for our sales reps to accomplish that through the Salesforce tool.

Rene Bonvanie
CMO, Palo Alto Networks

Every one of these opportunities is scored. It's also presented to the sales reps in such a way that they can work their way down from the highest possible score to the lowest possible score, and then align the resources that we have so that they can spend more time selling and less time searching or researching these opportunities and these accounts. This is very specifically developed for upsell because as you know, lifetime value expansion is lifeblood for the company. The other tool that we built was the ability, and we're using a technology called Wave, which is part of Einstein Analytics within Salesforce. This is a completely different way, a new way that we build in Salesforce, that we are giving back to Salesforce as a methodology, to score the propensity of accounts to expand in certain parts of our business.

For example, it allows a rep to better look at his or her territory and say, "Well, in my territory, what can I do in terms of upsell and what can I do in terms of cross-sell? What can I use in these accounts? an intersection of different technologies, Very specifically, what is my action that I'm going to take there? What should I do to introduce Traps to a VM-Series customer? What should I do to introduce hardware to a VM-Series first customer? What are those actions, right? Typically that is not take them out to lunch. That is not the first action. It typically is much more technical, it is much more evaluation driven. It is very important that we test the tools and the effectiveness.

There is a very important feedback loop in all these tools that helps us also refine the machine and the machine learning so that the outcomes keep on becoming better and better. The next thing is an idea about refresh as a alternative to renewal.

Naveen Zutshi
CIO, Palo Alto Networks

Right.

Rene Bonvanie
CMO, Palo Alto Networks

We applied some very specific technology here in terms of scoring, also in terms of scenario building. You want to talk about that?

Naveen Zutshi
CIO, Palo Alto Networks

Yeah. I think with the amazing new products that we just rolled out six months ago, as an example, the refresh cycles coming for our customers, we are surfacing for our account managers at account level as well as at the opportunity level, the ability for them to refresh instead of renew. We are also giving them what if scenario generators where they can do scenario planning for their customers in terms of TCO calculation, looking at price performance ratios between what is the existing install base compared to the new install base, do that in a dynamic and a real-time manner so that they can have those valuable conversations with the customers. More importantly, they can generate opportunities automatically from that into their Salesforce accounts.

All with the intention of really improving, one, the visibility and tracking our refresh opportunities within our expand business, and two, being more effective in selling to the refresh install base for a renewal install base, as well.

Rene Bonvanie
CMO, Palo Alto Networks

I want to make one comment here. The data you're looking at, by the way, is entirely fake. Don't think that we're showing you opportunities in our install base. This is a disclaimer of what the data says. The systems are entirely real, the data is not. What is important to note here as well is that the scenario building, again, is presented through machine learning. In other words, the rep doesn't have to come up with these things. They don't have to understand these different scenarios. The scenarios will be generated based on machine learning, and then the rep can decide together with our channel partner and the customer, which of these scenarios works best. It isn't just how much more money can we gain from these opportunities, also, what is in it for the customer in terms of a return on investment or TCO?

All of these things are combined, and this helps our sales reps spend a lot more time on the sales process, a lot less time on configuration, on emailing, on quoting, because we want folks in the field with the best tools possible and with the most competitive information out there. Now, all of this was great. Naveen one day walks into my office and says, "I think we can do even better. Why don't we allow our sales rep to crush it?" Because as you know, reps love to do 100%, but they love to do 150%, even more. Naveen came up with this idea of a quota crusher. Why don't you tell us a little bit about the quota crusher?

Naveen Zutshi
CIO, Palo Alto Networks

Yeah. I think, the basic premise is the following. I've been supporting sales teams now for a while, and as you think about the sales teams, you want to make sure that they have a leg up in their territory to manage their book of business. They have better visibility, and with the notion of machine learning, surface opportunities and accounts that they ordinarily would not have scoured themselves. What we did with this notion of quota crusher is, okay, how do you achieve quota and how do you actually beat quota? You look at the new logo business, you look at the expand business, and you look at your refresh business. In each three areas, we can actually apply statistical analysis, we can apply machine learning, and we can apply other algorithms to actually surface better opportunities and accounts for the sales reps.

With that, we can also have a feedback mechanism, which is both qualitative and quantitative, where over time, those machine learning algorithms can improve. As an example, in the new logo business, you can show the total addressable market in that account, and then you can show what percentage of that addressable market is accessible to our sales reps in a given quarter in a given fiscal year. More importantly, over time, you can actually demonstrate, okay, based on are those quality opportunities that we are surfacing, sales reps can tell us that. More importantly, we can also look at forecasted amount versus actuals, and we can modify the algorithms over time to improve the feedback mechanism that's going back to the algorithms itself.

This notion of providing a tool that actually makes their life easier, at the same time, makes them more effective in going and addressing our customer needs is what we are after.

Rene Bonvanie
CMO, Palo Alto Networks

Yep. Nir mentioned that in our platform, we make use of 100 plus algorithms. In this single screen, you see about 30 algorithms at work that we use for this specific use case that have to do with the understanding of the market, understanding of wallet size, understanding of addressable market, understanding of competitive products, understanding of the customer lifetime value, understanding of their buying pattern, understanding of their interaction history with the company, understanding of many of these things. These are all specific modules that we then combine. You see a little doctor up there, it's our deal doctor. He recommends to a rep what needs to be done, or he prescribes to a rep what needs to be done or suggests what needs to be done. These are all the fine-tuning that we do on this.

Now, we had a challenge with this because, again, we don't want our reps to go into systems and spend lots of time at home or in the office. We want them on the road. The final thing we did is we made it entirely mobile. We build a complete mobile security infrastructure for these guys that is entirely portable, gets this on their phones, on their iPads, in front of them, so they can do this right in front of the customer, right there where they need to be. This is all homegrown. We did not rely on some third party. This is our intelligence brought in our technology by our sales reps, and our channel partners, right where the opportunity is. That is an amazing collaboration that Naveen and I have had for which I want to thank you once again. Okay.

Naveen Zutshi
CIO, Palo Alto Networks

Thank you so much.

Rene Bonvanie
CMO, Palo Alto Networks

Thank you. Thank you very much. It is my honor now to invite Steffan Tomlinson on the stage. Thank you, thank you.

Steffan Tomlinson
CFO, Palo Alto Networks

All right. Welcome. You've heard a lot of great things today from my colleagues. What I'm going to walk through today, and later on, I'm going to invite Kathy Bonanno, our Senior Vice President of Finance, to come up and talk about modeling points. What I'm going to talk about is a little bit about the financial strategy of the company. Our philosophy and mindset, as Mark mentioned, has always been balancing market share capture with growth and profitability. I'm going to start with market share. First, you've seen the slide before, we play in a very large market, $19 billion market, growing to $24 billion and ultimately over $30 billion by 2020 with the expansion of the evolutions that we talked about.

One point that Mark mentioned that I just want to reemphasize because there's some confusion on the street about market growth rates. When you look at CAGRs and you understand how the markets are growing, it's a total revenue number, which is hardware, software, and maintenance. One of the reasons why we have such a large market to play in is security remains top of mind to customers and partners across the world. Now, it's great to have a large market, but you need to have the right architecture and framework in order to capture that market share. You've seen this before. This is our updated version of our framework. We continue to make investments in the innovation engine and introduce the right technology at the right time.

Each evolution, which we covered today, has tapped into the needs of our customer base and therefore expands the market opportunity for us. With our framework, we enable customers to actually have automated and consistent security wherever they are. Because it's a true platform, it automatically improves the level of security and sophistication that we can use to attack threats. As a result of having the right platform at the right time, it's led to outsized market share gains. In the inset graph, you can see the TAM. What I'm focusing on right now is network security. In the first evolution of the company, we've been disruptive to enable customers to use an automated and integrated approach to security. Customers are actually able to decommission hardware appliances from legacy vendors that were sitting behind the firewall and use our network SaaS subscription services.

By replacing hardware with software, we're actually leading and accelerating how customers consume technology in the security space. In a relatively short period of time, we've gained a market share of 14%, surpassing Check Point, and we have Cisco in our sights. Cisco is just a waypoint on our journey to capture outsized market share growth. When you broaden out the market and you look at the total market, including endpoint and other functionality, our market share has risen to approximately 9%. There's still a large market in network security, and relative to network security, the market expansion opportunity in front of us is even greater for cloud endpoint in the application framework. We view market share capture in the context of our growth and profitability framework, which I want to cover. This framework governs how we run the business.

It enables us to balance different priorities within a framework. With the right framework in place, we're able to deliver industry-leading growth and profitability and free cash flow margin. The security market is dynamic, and when new opportunities and initiatives arise, they're vetted through this framework. The ranges in each category give us the latitude to make the trade-offs to run the business. Mark mentioned this earlier, and I just want to underscore one change that we've made to the framework. In the long-term category, previously the range for free cash flow margin was range-bound between 25% and 30%. The change that we've made is now free cash flow margin is unbounded above 25%. The reason for this change is you've heard about the three evolutions. We are driving the business to be more SaaS-based.

The consumption models are changing, as the profile of the business change, we look at running the models, we look at the free cash flow margin potential of the company, which is why free cash flow margin is now unbounded, just as operating margin is unbounded above 30%. We're very much interested in increasing the leverage of the business over time. Now let's take a look at top-line growth. The starting point for top-line growth is new customer acquisition. We proudly serve greater than 42,000 customers, and we added a record number of new customers in FY 2017, increasing the base by 25%. The flywheel of new customer acquisition is being driven by the integrated and automated platform that we have, which delivers better security at a lower total cost of ownership, and it's coupled with a very strong go-to-market machine.

You've heard us reference our land and expand sales strategy. The land component is important, and it's critical, what's even more important as part of the equation is the expand opportunity. You've seen a number of data points in this presentation and in other presentations around the concept of lifetime value and cohort analysis, which clearly demonstrates how we've expanded within our install base. A new data point, which we'd like to point out, which is comparative in nature, demonstrates our true platform, and ultimately, true platforms win. We've spent a lot of time with the investment community, I fully sympathize and empathize that a lot of companies and securities sound alike. The data sheets sound alike, the presentations sound alike.

When you look at our true platform, and you look at it on a revenue per customer basis, once we land a customer, we're able to expand by selling other parts of our platform, and our revenue per customer on average is 5.6x times the size of the competition. There's no better data point than that in terms of underscoring how true platforms win. This land and expand sales strategy has culminated in market-leading growth. Since our IPO, we've grown close to 7x the rate of the market growth, which is another data point around how true platforms win. Our top-line revenue growth is also put through our financial model, and we call it our hybrid SaaS financial model. This SaaS financial model is a key element in the overall financial strategy of the company.

With more of our business being consumed in a SaaS and recurring manner, the visibility of the business is increasing. As of the end of 2017, we have about 45% visibility into our FY 2018 revenue, which is based off of FactSet consensus, that percentage number. The visibility is being driven by strong billings growth. In FY 2017, it was approximately 20%. Steady contract duration. In FY 2017, it was approximately three years. In FY 2018, we're expecting it to be stable, and that's for new business. That's led to strong deferred revenue growth. We have $1.8 billion worth of deferred revenue on the balance sheet, in FY 2017, that grew 43% year-over-year. Visibility is improving, and that's being driven by how we're selling our products and subscription services. Top-line is just one part of the equation.

We've been very much committed to driving growth and profitability, as measuring points, we look at operating income on a non-GAAP basis and free cash flow margin. When you take a snapshot in time, and then you look at the trended analysis, we started at FY 2012, our operating margin was roughly 7% and free cash flow margin was 24%. Through this time period through 2017, our operating margin and free cash flow margin have increased, with operating margin at 20% and free cash flow margin at 40%. There are very few companies that are able to grow the top line, take the market share that we've done, and expand profitability, and that has been a hallmark of the company.

It's been underscored by Mark McLaughlin in terms of the growth and profitability framework, we feel very proud of what we've accomplished to date, we feel like we're just getting going. When you look at other forms of profitability, like GAAP profitability, that's something that we're also focused on, In addition to non-GAAP and operating margin, non-GAAP operating margin and free cash flow, the biggest recurring difference between non-GAAP profitability and GAAP profitability is our stock-based compensation expense. We're committed to reducing the share-based compensation expense, the main input of that is our burn rate. To level set folks, between FY 2014 and FY 2017, our burn rate declined by about 12% per year. SBC as a percentage of revenue declined approximately 200 points year-over-year in FY 2017.

As we look towards FY 2018, we're looking to decline SBC as a percentage of revenue by at least 200 basis points. To wrap things up before I give it over to Kathy, I'd like to spend a moment on our capital allocation strategy. Given the amount of cash flow generation the company generates, we have three priorities, it starts with investing in the business. The second is M&A, the third is return of excess cash. Priorities, of course, change over time with the evolution of the company at different stages of the company. Right now, our priority is to invest in the business. However, we've also demonstrated the capacity of doing M&A and also returning excess cash to shareholders.

While these priorities govern our annual planning process and our strategic approach to the business, we've been able to basically demonstrate we can do all three and do it in a high-quality manner. With that, I'd like to hand it over to Kathy Bonanno, our Senior Vice President of Finance, to cover some modeling points, then I'm going to come back up on stage to wrap things up from a finance standpoint. Kathy?

Kathy Bonanno
SVP of Finance, Palo Alto Networks

Good morning, everyone. Thank you, Steffan. I want to provide you with some modeling points today, which will hopefully help you as you put pencil to paper and project our business going forward. I want to start with the growth and profitability framework. You've seen this several times today already. Steffan and Mark both commented on it, both reiterated our commitment to operating within this framework, the only difference on this slide is that you'll see our FY 2018 guidance here. As you can see, for FY 2018, we are in growth mode. I want to peel the onion back a little bit and talk about our top line, in particular, talk about revenue mix.

As you've heard today from a number of people, our innovative approach to delivering security with a platform approach has meant that more and more of our security offerings are delivered as subscription services. Mark talked to you about the breadth of the subscription offerings that we have today, and with the application framework, the number of subscriptions will just continue to grow over time. Steffan touched on the recurring nature of revenue that is associated with those subscription offerings. It's the combination of both more and more subscriptions that we're offering to our customers and what is now a very large and growing subscriptions recurring revenue stream that has driven this shift in the mix of our revenue towards subscription services. In FY 2017, 60% of our revenue was in the form of subscriptions and support. We expect in FY 2018 that that will continue to be the case.

We'll see a greater shift happening in FY 2018, with 65% projected to be in the form of subscriptions and support in FY 2018. Another trend that we've seen in revenue, as we have grown, is that seasonality patterns have become more and more apparent in our business, both in terms of revenue and operating margin, which you see here, and operating margin, of course, being very tied to revenue performance. Q2 and Q4 are our strongest fiscal quarters in terms of sequential growth. Q2 is strong for us because the calendar year-end falls in that quarter, and as many of you I'm sure know, there's a lot of budget flush buying that happens at the end of a calendar year, and that boosts our second quarter results.

Fourth quarter is driven, like many large enterprise companies experience, by sales behavior, which I'm sure Mark Anderson can attest to, as the sales team push and strive to hit their numbers and move into accelerating territory. That drives our Q4 higher. We've seen these patterns for some time now, and we expect in FY 2018 that we will continue to see the same seasonality pattern. I'd like to touch on gross margins for a moment. The shift into subscriptions that I was talking about earlier have impacted our gross margins over time as well. Because subscription services have higher gross margins, the more and more subscriptions become a portion of our revenue, our gross margins have been averaging up over time.

We have a targeted gross margin range of 75%-78%, and as you can see from the slide, we've been operating at the high end of that range for some time. We will fluctuate within that range depending on our investment levels, and for product gross margins, they can vary depending on our product release cycles. You saw in the second half of last year, our last fiscal year, we had the largest new product introduction in our company's history, and that did put some pressure on our product gross margins. We continue to operate within this range, and we plan to operate within this range in FY 2018 as well. I'd like to look beyond FY 2018 at a few modeling points around taxes and CapEx. For our non-GAAP tax rate today, our rate is 31%.

There's a lot of discussion about tax code changes both in the U.S. and elsewhere, but barring any significant change to tax laws, we expect to remain at a 31% non-GAAP tax rate for at least the next couple of years. In terms of cash taxes, which may be of interest to you as you think about free cash flow, we are today a very low cash taxpayer, and we expect, because of our significant NOL balance, over $1 billion in NOLs on our books, that we will continue to be a very low cash taxpayer for the next several years. For CapEx, we have a targeted range of 5%-7% of revenue. That's been the case for many years in the past, and I would expect that to be the case into the future.

For fiscal 2018, we've guided to $100 million of CapEx, with $10 million of that associated with building out our headquarter facility in Santa Clara. In addition to spending on building out facilities, which we need in support of our employee growth around the globe, we also spend capital on DevOps, building out the application framework that you've heard so much about today, as well as building out the IT infrastructure that's needed in support of our growth. Finally, in terms of modeling points, I just want to touch briefly on ASC 606, the new revenue recognition standard. As you may have read in our 10K filing, we plan to adopt the new standard at the beginning of our fiscal 2019. We are still analyzing the impact of the new standard on us.

As you can see, if you look at the first and the third rows in this table, the vast majority of our revenue, in terms of hardware and subscriptions, will continue to be recognized tomorrow as they are today. However, there are definitely some finer points in the new revenue recognition standard which we are analyzing, and once we have completed our analysis, we'll be sharing results with you at that time. With that, I'd like to turn it back over to Steffan.

Steffan Tomlinson
CFO, Palo Alto Networks

Great. I'd like to just take 30 seconds as a point of reflection on my tenure at Palo Alto Networks. The company's business model is dynamic and it's durable, and the progress the company's made financially and driven by the team, with the power of the hybrid SaaS model, has been really extraordinary. We've grown our customer base by over 30,000. We've increased operating margin by over 13 points. We've generated over $1.8 billion of free cash flow during my tenure. Again, it's all about the team and the team results. It's been a privilege and it is a privilege to work with all of my colleagues at Palo Alto Networks and our customers in the Wall Street community as well.

Our team at Palo Alto Networks is dedicated to fulfilling the mission that Mark mentioned around protecting our way of life in the digital age, and it's been an extremely rewarding experience. With that, I'd like to turn this over to Mark for final and closing remarks.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Thanks, Steffan. As I mentioned earlier, that concludes the presentations for us today. We certainly want to leave some time at the end for Q&A. I have the executive team here with me, and we're happy to take questions that you may have. If you want to fire them at me, I'll moderate that for you. We got mic runners, too, and we webcast, if you could just take a second, here comes the mic so people can hear the question, that would be great. Yeah, we hear you.

Speaker 15

Okay.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Hey, Jason.

Speaker 15

Mark, thanks. Hi, Steffan, good luck with the next step. I wanted to ask on the data lake, that's a relatively new topic for Palo Alto, in quantity of data are a big deal. How do you monetize this? Would it be done directly, or would it be done through products across the portfolio?

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Well, a couple points on that. One is, we have been monetizing it indirectly for quite some time through services that we bring to market. You heard both Nir and Lee talk about how we've used the data and the analytics to do things with threat prevention, with WildFire specifically, which has been a giant analytics capability for us, which is a service to do sandboxing, but it's all being driven by the data behind it, right? We've monetized data for quite some time in the form of services. The next monetization around that would be to use the data lake to develop our own applications on, like AutoFocus, like LightCyber. In addition to that is to have third parties that are algorithmically driven, right? Where their value prop to the customer is saying, "I have an algorithm to do something like behavior analytics," right?

That algorithm is literally academic if it doesn't have data to operate on. The more data it has, the better its chances is to operate. It's also, not academic's the right word, but it's more useful if you can enforce the answer, right? The second level of monetization for that data, now that it's so large, is to say, "Well, we can write our own algorithmic apps on top of that and monetize third-party apps as well on top of that." We're not monetizing the data directly and selling data to people, right? What we're doing is allowing people to access the data, because the more data you have, and if it's the right data, algorithms get better and better on massive sets of data. Does that make sense? It's monetized, but it's indirect through whatever the applications are that feed on the data lake.

Speaker 15

Okay. Just to clarify, the third party's paying for access to the data, and then are you receiving data from the third party also to populate the data lake?

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Sure.

Speaker 15

I'll stop there.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yeah. The third party would access the data in order for the algorithm to run on top of that, and those algorithms are also producing results as well, which in turn feeds data. Right? That's one of the reasons why when I said, hey, we were trying to prove things out for ourselves over the last couple of years, when we built the MineMeld tool, which is a threat intelligence aggregation and translation tool. It was one of the things we wanted to show, was to say, that is getting data from over 1,200 of our customers now, growing very quickly from hundreds of data sources that they're curating for us, right? And it's feeding into the data lake their data, that they're providing for indicator of compromise.

Speaker 16

Hey, Mark.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yeah.

Speaker 16

A couple times, people brought up the whole thought process around the refresh cycle.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yes.

Speaker 16

Love to get your thoughts on how that's going to work its way through the system, where we are with that right now, and how you think about monetizing that.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yeah, sure. From the refresh, we've shown customer cohorts over time, right? You can see them getting bigger and bigger over time. The cut I showed you today was to take a look at the dollars that we've collected over time and hardware into that estate, if you will, right, around that. In both of those views, of taking a look at that, we know a few things. We know that the opportunity set gets larger and larger over time, just because you can see how the value of hardware that's been installed has grown over time.

We know a number of things about our customers' reaction to us with the retention being high and the penetration being high and the attach being high and all these other so-called data points that are around the idea that customers are very happy, and they like Palo Alto Networks and tend to stick with us for a long time. If we look backwards and say, hey, from a 2012 or 2013 kind of view of those customers and what has occurred refresh-wise, we've done very well in there. We've also done extraordinarily well in expansion in there, right? Sorting through what are people doing with the various devices and use cases, it's harder over time as the cohorts get bigger because they continue to expand so aggressively as well.

We know that they continue to spend a lot of money with us, and the retention is really high, right? We know that the refresh has been positive up at that point. When we look and say bigger cohorts over time, we would expect that to continue to do well for us over time. Now, just one point that did come up on the call as I said, hey, in 2018, we didn't think that was going to be the primary driver of our hardware growth. The primary drivers, we think, are going to be the fact that we've got the best platform. We introduced new hardware. We're sorting through the execution things that we suffered last year, which we're fixing, right? We think those will be the primary drivers of the growth in hardware.

Of course, the refresh is going to be part of that, I don't think it's the primary part of that. You can just see the values growing over time past, like, 2013 as to when those may occur. We're positive on that for sure. Yeah. Who's got the mic there? Oh, sorry. Okay.

Speaker 16

Right here.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Sorry, I can't see anything.

Speaker 16

I'm trying to understand the company in kind of traditional ways and understand the growth drivers for the next few years. If you go back the last five years and you try to think about growth drivers, you can put it in three buckets, kind of the market grew and accelerated, you've taken share, and the attach rate of new products went up, either standalone platforms or attached products. If you think about these three buckets, the market may slow because we went through major cycle. Market share gains may slow because Cisco recovered and Juniper is making efforts. The attach rate got really high with some of your products. When you think about this kind of framework, what do you think about the growth going forward?

Should we still think in terms of these three drivers, or should we think about something else that may drive up revenues that is not related to what I discussed?

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yes, that's a great question. I would add a fourth into there, of course, which would be new services as well, right? Because the attach rates, as you heard, went up. Those are services attached to devices. We have a whole slew of things that are not attached and that are growing well for us, plus a few things we just announced literally this week from a new service perspective. Let me add a fourth category, if you will, to yours. On the second category, what I'll call the competitive landscape as well, we continue to displace the competition at very, very high rates, right? I've heard that Juniper's making efforts. Frankly, Juniper is almost nonexistent as a security player these days in network security. That's just a numerical statement.

The idea that Cisco's gotten more and more competitive relative to us, I don't see a lot to support that statement when you just look at the relative growth rates of the company. Now we have to prove that every day of the week, right? That's my competitive juices coming out. We have to prove that every day of the week, but I would say in those buckets you just laid out there, we continue to beat the competition at very, very healthy rates in taking their market share, the portions that they have, from those in any market environment, back to your first point. I would add the fourth one as well, which is the new services.

Speaker 16

How long does it take the new initiatives to kick in, the things that Nir spoke about?

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

It'll take time, right? That's why we speak of these things in evolutions. If we looked in evolution one from things we created that became network SaaS services over, look at WildFire for example, or the other network SaaS services over a multi-year period, they grew into nice businesses for us. In the second evolution, you can see that our endpoint capabilities and cloud capabilities are getting to be more significant contributors to the new subscriptions billings, as I showed you earlier. In evolution three, it's just starting off. We've got one of our own applications there, LightCyber, coming soon, and we would expect those 30-plus application developers plus many more over time to drive increased revenue growth from the third evolution. As far as that being significant, I don't know yet.

We have a lot to prove out there in the application framework and the business model, but it looks very promising. Who's got the mic? Okay.

Matt Hedberg
Analyst, RBC Capital Markets

Hey, Mark. Matt Hedberg, RBC.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Hey, Matt.

Matt Hedberg
Analyst, RBC Capital Markets

Splunk is a great partner of yours.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

It is.

Matt Hedberg
Analyst, RBC Capital Markets

I'm curious, a little bit more detail on your new cloud log management system. Is that eventually going to become a little bit more competitive with their offerings? Or maybe just a little bit of-

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yeah

Matt Hedberg
Analyst, RBC Capital Markets

differentiation on how the two are positioned.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yeah, I don't think so. Splunk is a very good partner of ours and has been for a long time. We expect that to be the case. Nir made a very important point about data lakes and this, I'll call it, a separation of data where it is, right? From a use case perspective, where Splunk has done a very nice job and continues to do a nice job of saying, "Wherever your data may be, we can ingest that data into multiple use cases for analytics," right? Our logging service is focused on logging information from Palo Alto Networks capabilities, right? It's taking information off anything you deploy from Palo Alto Networks into a Palo Alto Networks data lake in order to run our applications and the third-party applications on top of that.

That's a different statement than saying you take information from many, many sources into multiple data repositories and run analytics on top of this, some for security, some that are outside security. In Splunk's world, they have many use cases that they operate under. Does that make sense? Next.

Saket Kalia
Analyst, UBS

Hi, Mark. Saket Kalia from UBS.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Hi.

Saket Kalia
Analyst, UBS

Thanks for taking the questions.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Sure.

Saket Kalia
Analyst, UBS

Just thinking about the addressable market slide that you put up, if I look at the composite areas that you're playing in, one aspect or area or vector that's specifically missing is email security. I'm wondering your thought process around why not think about getting into that arena so the network portfolio of protection is more filled out.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Somewhere along the presentations, I can't remember if it was Lee or Nir specifically, said something important about how we think about what we're doing as a company, which is try to be very focused, okay? Security moves real fast, right? In order to be really good at things for customers, we believe you have to be focused on things you can do extraordinarily well, right? We said we cannot do everything in security, just as a general matter. Nobody's ever done that, right? That's one of the reasons why the application framework is so compelling is you don't have to innovate everything. You can bring all the innovation to market through a different framework, right? As we look at areas in security where things are important, like location's important, email's an important location, right? Everybody uses email.

It's got a ton of data in there, right? It's an important location. When we look at that market and say, "Can Palo Alto Networks organically bring something to that market that other people haven't done yet?" We looked at it and said, "We don't think we can do that right." If somebody's doing a great job in that market, then let them do it. We should partner with them. In this case, our partnership, which we've talked about many times, is with Proofpoint, who we think is doing the best job in next generation email security. What did we do with them? We tried to make it better for the customers and feed the data lake. Right?

Our relationship with Proofpoint, which is good and many years in the making now, is that their version of WildFire, which they call TAP, and WildFire are integrated together, where the data is moving back and forth. If a Proofpoint customer sends an attachment to the Proofpoint cloud to be dissected, it also then goes to WildFire to be WildFired. Why do they do that? Because WildFire is a massively bigger data set, right? Proofpoint gets a better answer, if you will, by having that question WildFired in addition to what they're going to do for it. Why do we do that? Because we get all the data, right?

If it's maybe not obvious from everything we've said so far, we have an insatiable appetite for data from all sources, and email is an important source, and that's how we're getting lots of really good threat intelligence data from email is through that partnership. We think that works. It works for them, it works for us. Next question.

Operator

Is it Mike?

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yes. Is it on? Okay.

Keith Bachman
Analyst, Bank of Montreal

Hi.

Yeah.

Yeah. Thanks very much. It's Keith Bachman from Bank of Montreal.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Hi, Keith.

Keith Bachman
Analyst, Bank of Montreal

I had two questions. On one of your slides when you started out, you indicated that hardware growth over the last six quarters was about 3% for the industry. Palo Alto was above that. As you think about the industry dynamics that you laid out on the slide, what does that look like over the next two years? For the industry, is that still a positive number? Is it low single digits?

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Did you say product or partner?

Keith Bachman
Analyst, Bank of Montreal

I said hardware.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Okay, sorry. Yeah.

Keith Bachman
Analyst, Bank of Montreal

Hardware. Sorry.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Okay.

Keith Bachman
Analyst, Bank of Montreal

I had a little trouble turning on the mic.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

That's okay.

Keith Bachman
Analyst, Bank of Montreal

The hardware growth has been 3% over the last six quarters.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yep, got it.

Keith Bachman
Analyst, Bank of Montreal

Is that still a positive number over the next two years? Then I have a follow-up.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Well, the point I was trying to make on that is, it's hard to tell, right? Which is what is going to happen with hardware over time. That's why I went back to sort of what have we seen over many years of time, right? Whether these buying cycles, if you map hardware sales in a 10-year period of time, you see kind of a cyclical nature like this. We know people, which we mentioned a year ago, are saying, "Hey, I really need to think about these things when I make decisions about machine learning," right? Or the cloud or the impact of those kind of things as I architect my environments over a long-term basis. Plus, I have additional use cases now, like, hey, that visibility point Lee mentioned is super important. You can't secure anything you don't see.

If 35-plus% of my traffic is now SSL encrypted and I can't do something about that's a problem, right? All these things kind of go into the mix to say how much hardware are people going to buy in any given time. The answer is for us to sit back here and say, as one player in the market, we don't know that over a multi-year period. What we do know is in those buying decisions over a long period of time, we do really well, right? That's the reason I wanted to show you the more product or hardware-specific thing, is to say we've outperformed the market growth, and we've outperformed the competition's growth. Back to the gentleman's question over there, specific to hardware.

In the short term and the midterm and the long term, we would expect to be able to do that in the future. We don't think hardware's going away. People are buying a lot of hardware. We said we're going to sell $750 million-ish in this coming year at least, right? What we wouldn't be able to tell, as one vendor in a market on a multi-year basis, is what the hardware growth rate's going to look like on a multi-year basis. I don't know. What we do know is that people are using a lot of it. They're definitely in hybrid architectures, right? We expect that to continue for a long time.

As long as we're doing our jobs as we have, that we would expect to capture more than our fair share, a lot more than our fair share of whatever that spend would be. Which means we've got to execute.

Keith Bachman
Analyst, Bank of Montreal

Fair enough. My second question relates to, you've talked about analytics and data lakes being one of your value propositions going forward. In order for that to come to fruition and you presumably to take more share of wallet from your customers, who do you think is at risk? In other words, where are you going to take share from in this process, or is this new dollar spendings? Thank you.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yeah, sure. We think in order to continue to acquire market share, that means, well, first we have to acquire market share in the sense of get more customers, right? Just get them in the first place and sell them more stuff. We're going to keep doing what we have done. Get as many customers as we can, and we're going to sell them as much stuff as we can, right? Then we broke it into those, I broke the evolution into the TAMs to say if what their interest is and their needs is today is network security or internet. We have a meeting with them, and the meeting is about firewalls, right? The meeting is about IPS capabilities, or the meeting is about malware advanced. Customers think that way, and that's how they talk.

We say, "Great, we've got something to sell you on that. We're going to try to sell you in the context evolution for the next thing I want to sell you is something in your hybrid journey to the cloud or in an endpoint or whatever the case may be." We're going to keep doing more of that. As far as the winners and the losers in this market, over time, I think we continue to acquire more market share in the network security market. We're small but growing rapidly in the endpoint security market. I think we're doing more than our fair share in cloud security market.

We just open up an entire vector, if you will, to take market share in things that we don't do today yet, but in Evolution 3, as Nir had that whole list of the use cases of applications where people actually buy point products today for those things. Either do that ourselves through the application framework or monetize a third party through the application framework because they're doing a great job on something that we're not doing ourselves. That's what we have to keep doing into the future to do that. I think, and I made a comment on the break, somebody asked me a question, is that with this application framework in mind, we think we're the winners in this. We think it has to happen.

If you looked out over a few years' time, three to five years' time, and said in the security market, there's going to be lots and lots and lots of security companies. There always are. Right? Why are there 2,000 companies at RSA every year? The answer is because security needs tons of innovation. The adversary is moving very quickly. You can't run 2,000 vendors, right? That's the problem that has to be solved.

More and more, because of the second evolution of consistency, I hear customers saying, and I think this is going to happen, we think we're going to win all this, is to say, if you looked at a few years of how many companies will be able to make a credible claim that I'll call that second evolution of consistency, to say, "I can give you the exact same security in your network that you're going to get on your endpoint, that you're going to get on IT devices, that you're going to get in cloud, exactly the same." When I do that, I won't crater your network because a firewall is a networking device and a security device. That's why there's so few firewall vendors in the world. It's not a security thing. It's about being able to do great security and operate, not crater your network.

I'm not going to blue screen your endpoints. That's an operating statement, operational statement. I'm not going to lose the connections to the cloud or not be able to sync data. That's an operational statement. How many companies are going to be able to make that operational statement with security on top of it in a few years' time to say, "I can do all that for you globally, highly availability for giant enterprises around the world?" Less than five. There's still going to be 2,000 security companies. How do they get to the market? That's increasingly a problem for customers and for them. Next question. John? I think you're on.

Speaker 17

Thank you, Mark. Just wanted to ask about the application framework. Maybe can you talk a little bit about sort of the type of revenue model that you guys are expecting and maybe the type of margins that we could see from this type of business? There seems to be the data lake component, which seems a little bit more storage-oriented, but just wanted to see what the overall model looked like.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Yeah, sure. The monetization model for the application framework would be, as I mentioned a little earlier, to say two direct angles and one indirect angle. The direct angle would be we write applications, we serve them through the application framework like MineMeld, which we don't monetize. That's about giving threat intelligence. Like AutoFocus, which we do, like LightCyber, which we will shortly. One, we write applications ourselves, and we monetize it through the application framework. The second way is third parties will want to be in the application framework. Why?

They have access to tens and tens and growing thousands of customers to put their algorithm on a set of data that is massively bigger than anything they're ever going to see themselves, and to have their answers enforced in our infrastructure that's already been deployed, so they don't have to go stand in line at a CIO to get their stuff tested, run, deployed, and all those things. We should get paid for that. We expect to on a rev share basis. We'll work all that out. We need to do that. That's the second model. The third would be indirect, which is why I showed you the email, not that one email makes the case, but I hear this all the time. I showed you that one of customers saying the application framework's very compelling.

If you get it right, I'm going to want to deploy you everywhere because that's actually how I get the most value out of all the applications is I get to enforce the answers everywhere. The pull-through impact of saying, "I want you all over my network, I want you all over my endpoints, I want you all over the cloud," is another aspect of that we think would grow over time. Did you have a second part to that?

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Margin.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

Oh, I'm sorry. Margin structure, right. As a general matter, we believe, and it's been the case for us, that if we're delivering something as software, it's higher margins. The application framework, as far as what's coming through the top, are software applications. We would expect those to have software-type margins if they're ours. If they're not ours, we're a distribution channel in there, very low friction distribution channel in there, so the margins for that should be very high because we didn't even write the application. We're just monetizing the fact that you're using it through our framework. Last thing on the logging services. Well, logging services is about creating the capability so that customers will log as much data as they want to. We have to sort that out at scale over time with the infrastructure we built.

That's actually about getting them to log the data. We're going to make money on that. That's not a software kind of model. We actually have to run a big infrastructure for that. That's a building block point in order to make the application framework, which are very high-margin things, from an application perspective, more useful for folks.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

I want to quickly say we have time for one more question, which is over here. For those of you in the room, please do not pack up. We have an extra special little piece of information for you in terms of some customers that'll come up as soon as we're finished with the Q&A. We'll take one more question.

Michael Turits
Analyst, Raymond James

Hey, Mark. Michael Turits from Raymond James. I have a growth and profitability framework question. If you look at the Street's numbers for they drop below the 20% level, and yet the free cash flow margins are still up in the 30s. Two related questions. How long do you guys think that 20% plus growth might actually be sustainable? If not, if the Street's right, what are the puts and takes in maybe getting higher than the framework margins on free cash flow, which is what the expectation is.

Mark McLaughlin
Chairman and CEO, Palo Alto Networks

This is why we have a framework over a multi-year basis. In the top line of the drivers in the top line, we have a lot of top-line drivers. What we haven't done and I'm not going to do is go out beyond 2018. We gave you what our guide is from a 2018 perspective. We have a lot of drivers of growth, and the ones that are in the market and baking already are doing very well, and we have more to come. We haven't gone out beyond 2018. From a free cash flow perspective, given the model, which is hybrid in nature, we collect all the cash up front for all of the things that we sell today. We expect to be able to continue to do that into the future.

We generate a lot of cash flow off of that, from a free cash flow perspective, the main impact of that on a long-term basis would be taxes, not the model itself. You've heard us, Kathy just say for quite some time, we expect to be a low cash taxpayer. One is we re-strap up profitability, we've got a lot of NOLs to burn through at that point as well after we achieve that. That would be the main driver for free cash flow. Steffan, anything else to add to that? Did I get it right? Okay, I'm good. He's giving me a thumbs up. All right. I'm sorry. That went by real fast. Sorry. I'm here. Steffan's here. Whole management team is here.

After we finish up in the hall and in the demo stations, if you haven't seen them, we'll be here for as long as you like to answer any questions that you have. With that, we're going to end the webcast portion.