Good afternoon, everyone. Hopefully, you're settled. I'll kick this off very briefly. I have all the legal language, the faster we go through that, the better. No insult to the lawyers in the back corner of the room. Welcome. I'm Kelsey. I run investor relations for Palo Alto Networks, we're thrilled that you came. We know this takes a lot of time investment. Many of you have flown long distances, we appreciate your time and your interest in the company. This is the investor track for Ignite. Mark will give you some high sort of overview of what we invite you to do this week. Following our formal presentations, we'll be hosting a cocktail party, which will include demos. It'll give you a chance to actually touch and feel and check out the technology.
This is all of the cautionary statements that said everything we say after this, you can't pay attention to. We're done. I'm going to turn it over to the team. Thank you very much for coming.
That mindset needs to be. What we sort of think about at Palo Alto Networks is to really move to more of a prevention mindset.
You can't just bolt on different threat preventions. You have to do it holistically. It bought a company called CirroSecure, which works on cloud security, bolstering the subscription base, recurring revenue stream. Ooh, I love that.
Their latest security service called Aperture. How to safely enable SaaS applications that are increasingly prevalent on their network. The PA-7080, the latest addition to our next-generation firewall product line.
Here at the launch of our book, "Navigating the Digital Age," our partnership with the New York Stock Exchange.
Every meeting with your executive committee, every meeting with your board, cybersecurity is on the agenda. Dabbling in this space is not the way to go.
The Scarlet Mimic adversary is targeting those government organizations to access the information they have.
Dubbed Operation Lotus Blossom, the campaign has been ongoing since 2012.
The new strain of malware called YiSpecter spreads via a malicious code inserted into web pages.
You don't know what the bad guys are coming up with next, and that's why the relationship with Palo Alto Networks , they certainly have their eyes on the ground and what's going on.
We want to continue to deliver prevention capabilities in the platform to make sure that we're staying ahead and prevent these attacks.
Please welcome Mark McLaughlin, Chairman, President, and CEO.
Thanks a lot. I'm going to echo Kelsey's comment. Thank you very much for taking so much time with us, particularly coming to Vegas. We know this is a flight for most of you. The reason we do the investor track here is because we are at Ignite, and we hope you get a chance to spend some time tomorrow as well. We're going to have over 3,000 of our users here, up almost 1,000 from last year. Just a sense of what's going on with Palo Alto Networks, how people are using the technology, and the level of excitement around it as well. That's why we do it here, and we really appreciate you taking the time to be with us. Today, you're going to hear a lot from us today.
We'll try to be very efficient with your time, and we want to be very respectful of your time. This is what the general agenda is going to look like for the investor track this afternoon. After myself, our CTO and founder, Nir Zuk, who I think most of you know, is going to talk about our platform. You're going to hear a lot about the platform. I know that you hear a lot from us about that. You hear a lot from other companies, we really want to dive into that day just to a good degree. Lee Klarich, who runs all products for us, will also talk about the platform. He's going to talk about the roadmap. He's going to talk about things that we will be talking to our customers about over the next two days as well, that they'll be very excited about.
Mark Anderson, who's our EVP for worldwide operations, is going to talk about what the view from the field looks like and how it is that we have and will continue to execute at scale and use that as a competitive advantage for us. We're delighted as well to be able to have some of our partners here who are actually in the room with us right now as well. Mark will run a partner panel, where you get a chance to ask them some questions yourself as Mark will. René Bonvanie, our Chief Marketing Officer, is going to give you some sense of how we continue to drive demand generation and also drive thought leadership in the market, which is important for us from a selling perspective, of course.
Last but not least, Steffan Tomlinson, our CFO, will give some financial updates. We'll talk about the model. Afterwards, these folks will join me on stage, and we'll have a good amount of time for Q&A. We have a break as well. After the Q&A, we'll have a cocktail hour, and we will stay long into that. Happy to answer as many questions as you can. I also wanted to note, in addition to the folks here on the agenda, we have a very full complement of executives from Palo Alto Networks. We stuck them all the way in the back in the corner to give you guys the best view.
We have our head of HR, we have our chief security officer, we have the person who runs EMEA, we have the person who runs APAC, we have the person who runs what we call cybersecurity solutions, so he's in charge of Aperture and AutoFocus and Traps. They're all back there in the corner. They will be here at the break and also through the cocktail hour this evening. Feel free to get some time with them. What I wanted to start off this morning was, if I only had one elevator ride with you, and I know you're busy, and you'll be multitasking through this, I'm sure not my part, but for the afternoon. If I could only give you one slide, this would be it.
This is how we would encourage folks to think about Palo Alto Networks from an investor perspective, which is we really believe that we've attained a leadership status. We continue to grow that in the digital age. I'll do a little bit of a setup on that in a minute. The reason I mention the digital age, because that's the age we live in, and I get the question a lot about security demand and spend, and understanding, I think, where we are in this time in history is important to answer that question. The second thing is, we truly believe that we have a unique platform in delivering against what has to happen in the digital age from a security perspective. Everybody uses the platform word a lot.
We're going to peel the onion a couple, three times for you as to what a real platform looks like and why we believe we're the only ones in the market who have one. In addition to that, with our really large and growing competitive advantage on our go-to-market excellence, which Mark Anderson will talk about, and René will talk about, we've been rapidly capturing market share in a market that's really big and continues to grow over time. I think it's going to continue to grow for quite some time into the future. We have a model that is driving really high revenue growth, but underneath that, really significant free cash flow and increasing margins over time. Steffan will spend some time with you on what we think that looks like going into the future.
When we're talking inside the company and talking with the board of directors, we really parse the company on the five things that we think really matter for us. The rest of the presentations this afternoon will also follow along to fill in some of these things that I have listed here, which, the first thing we think that really matters is philosophy, which means what are you trying to do in the first place? Because if you don't know what you're trying to do, the chances of getting it done are pretty low, right? The philosophy you start with as a security company really matters over time, because if you start with the wrong one, you're compounding an error.
If you start with the right one, you've got a much better chance to be able to add to that into the future in a way that works for customers. The second thing is frameworks, what I mean by that is how do you think about how you implement the philosophy? We think frameworks matter, we're doing a lot of work with partners around this as well, about what is the proper framework for a customer to think about in security to get outcomes that matter for them. Those outcomes have to be delivered then. The third thing that matters, we think, is do you have a platform that can deliver the outcomes that are dictated by the framework within that philosophy? Platforms really, really matter, and I think that's one of the keys to our success today.
On top of that, you could have all that wonderfulness and slip on many banana peels from an execution perspective. Really being disciplined on execution, particularly with high velocity at scale, that matters a lot. Of course, at the end of the day, we all want to keep score. We do, you do. Results matter. We watch that very, very closely, of course, and we know that the investors do. Let me I'll go through these kind of quickly, and again, people will fill in through the day on this. Kind of the setup, which really goes to security, where are we? When I get the question, like, "What's the demand for security today, and what's it going to be in the future?" My answer to that is, what time is it in history?
The time that we're living in today is absolutely the digital age. Everything is, almost, right, is digital and becoming more and more digital into the future. That means that all the things that we rely on as consumers, as businesses, and as those things merge over time, are more and more bits and bytes really. There's massive productivity enhancements for that. This age is being more and more called the fourth Industrial Revolution. They compare it to productivity gains that have occurred over history. The difference on this one, because it's digital, is compression, the time compression rates. In the last 30 or 40 years, the amount of productivity enhancement we've garnered as a society, because of the digital aspects of what we're doing, is far outstrips anything that has come before, certainly the Industrial Revolution.
Really importantly, the expectations for productivity into the future are enormous. Like, we have to get it right to support the growth that we all want to see in society. I mean, these are what world leaders are talking about and academics are talking about when thinking about the digital age. There's huge productivity gains that occur. The problem is, as we know, is that the very things about the digital age that can drive productivity are security concerns. That's the flip side of the coin. I started using these words about two years ago in my role as the chairman of the NSTAC, actually with the President, and it kind of resonated, which was security, I think, more and more is a fabric item of society in the digital age. What we mean by that is it's often a mistake is made.
I go to talk to boards, particularly with non-technical people, they think it's technical. They think it's about technology, right? Of course, it is, meaning you have to use technology and people and training and processes to deliver on security. Security itself has far transcended technology. It is something that is woven, and this is why I came up with fabric. It's woven through certainly every major IT decision a company's going to make, whether it has anything to do with security or not. Somebody's going to say, "How do we secure that?" Right? Or, "What are we going to do about that?" In the national sphere, many decisions being made around that from a statecraft perspective. When you have something that's a fabric, it's hard to get in there and parse it out, right?
If you have the wrong thing in there, the only way that we get it out is to tear it, right? If we are tearing the fabric of the digital age because we got it wrong from a security perspective, that's a real problem for us. This is really apparent to folks. We saw 2015 was one of the years with the highest number of reported breaches. There was a lot of talk about whether breach has gone up, breach has gone down. I'm pretty sure they're going to do nothing but continue to rise over time. I think we're in good company with that thought. You saw President Obama come out not too long ago, request a $14 billion increase in cybersecurity spend, just to give you some sense of how our own government thinks about their own posture, right?
The day after President Obama asked for this 40% increase from Congress for spend, the Director of National Intelligence, James Clapper, came out and said, "Cyber is the number 1 threat to the U.S." He did not say nuclear, he did not say chemical, he did not say kinetic terrorist attack. He said, "Cybersecurity is the number 1 threat to the U.S. from a national security perspective today and into the future." Around the world, other countries are, I think, rapidly catching up to the U.S. about these expectations. Recently, the EU said that they will have laws in effect and in short order, where it will require companies to report breaches. I think that's fairly common to the U.S. for publicly traded companies. It is not the case yet in the EU.
It is not the case yet for all the major countries in APAC, but all of them have laws that are coming online. I think we're going to see a lot more reported breaches on a global basis than we have in the future, simply just because of reporting requirements, because we know they're happening for sure. It's getting more complex. Security is not a static thing whatsoever. It's dynamic. We know that if you've been following the space, we know that for sure. Some of the complexity that I think is going to drive security demand into the future are the three things I've noted here. The first is that with the declining cost of compute power and it going down more and more over time, the compute power is, in essence, limitless, right?
When that happens, the bad guys get to use more compute power for less cost to drive more attacks. The second thing is the digital assets protecting the physical assets are very real. I mean, the problems are very real. When we usually think about cybersecurity, it's about protecting intellectual property and PII, and those things are absolutely important. If you paid attention to the Iranian folks who were indicted a couple of weeks ago by the U.S. government for attacks against major U.S. banks, one of the portions of the indictment was taking over the control systems for a dam north of New York City. Right now, they didn't do anything with it, but they demonstrated that they could.
The mix from IT to OT and SCADA and ICT is very concerning and very compelling, and that's going to drive a lot of security needs into the future. The third is cloud and massively aggregating data and IoT, making it more readily available in a lot of places, drives great productivity. If you're a bad guy, you're looking at that saying, "Thank you for putting all the data in one place. I appreciate that, and thank you very much for giving me lots more ways to get at it with IoT." There's going to be a lot of complexity in the future or needs to overcome this complexity from a security perspective.
That's kind of the big-picture setup right before I get to the five things that matter very quickly on the decisions that get made today are going to matter for a long time into the future for society about whether we get the productivity gains that we have to get in the digital age. Which takes me to my first thing that matters, philosophy, right? If we're not thinking about it the right way, we're unlikely to end up in the right place. The philosophy that Palo Alto Networks has been driving for a decade since we opened the doors is one of a prevention orientation. I want to be clear about that. Not anybody stops 100%. Nobody stops 100% of attacks, right? A prevention orientation to say, "You have to try.
You have to drive this industry to do more and more prevention, because if we don't, we're upside down on a simple math problem." The math problem is that as long as the cost of compute power goes down as it has, then the number of attacks and successful attacks is going to go up. I think that's been well demonstrated over the past decade. If we don't change this, if we can't flip this on its head to dramatically increase the cost of a successful attack, we have a mathematical problem. What we have to do is increase the cost of the successful attack, because if we can do that, theoretically, or more than theoretically, we should be able to drive down the number of successful attacks, not the number of attacks. Nobody is going to drive down the number of attacks.
Not us, not anybody else. What we're trying to do is drive down the number of successful attacks, right? Therein lies the difference, because from a framework perspective, the framework that people have been operating under for a very long time is based on outcomes. The framework that we've been operating under has been one that's been very detection-oriented, using legacy technologies, usually delivered in point products. The outcome of that has been reactive and manual. If you have a highly automated adversary using compute power to their advantage, and more and more our outcomes are reactive and manual in nature, we are mathematically upside down in a way that we'll never recover from the longer this continues.
What has to happen is a real paradigm shift on these frameworks to one that is a prevention-oriented outcome that we're looking for using next-generation technology delivered in a true platform or true platforms, because the outcome then can be proactive and highly automated, and that's where we have to get to, right? Fighting highly automated adversaries with highly automated capabilities and not being in reactive manual mode. Just again, it's just simple math. Let me give you a quick primer on what's a true platform, because that's super important to the success of Palo Alto Networks. Lots of other people say a platform as well. I'm going to give you just a few viewpoints of what the characteristics of a true platform will be. Nir's going to talk about the technical requirements of what a true platform is.
Lee's going to talk about how a true platform actually works, right? The characteristics of a real platform, first, would be that if you're trying to do prevention and get inside the attack lifecycle to stop everything that the attack has to do correctly, which is what we're trying to do with capabilities that are designed to do that, and that they all are built together to work together. It means they have to be native to the platform. It's not something you cobble together. If you do that, you're going to have superior security defined as higher prevention rates, number one. Number two, a real platform is extensible.
It's able to roll with the punches from what the new threats are or where your data may be in a way that is really flexible and really extensible, meaning you don't have to do massive hardware redesign, you don't have to burn ASICs, you don't have to do massive software rewrites. You can easily, relatively easily, create capabilities that are native, again, to each other to take care of whatever the next threat is or to make sure you're covering data wherever it is. The third, it has to be highly automated. We mean by that is those native capabilities. When one of them does something right, it needs to be able to reprogram the other ones so that they all have the same base of knowledge in your own network. That's getting leverage in your own network. Highly automated capabilities on your own network.
The fourth point would be to get serious leverage outside of your network. When it does something right or you did something right for somebody else, everybody is in your ecosystem, which ideally would be big and quickly growing. Everybody gets it in a highly automated fashion because that's how we get leverage against an automated adversary. The last thing, it has to be entirely consistent. What I mean by that is when it's doing these things, it has to do it exactly the same way wherever your data is. Because if you're doing it differently, you've created an inconsistency, and inconsistencies are not the friend of security. It has to be the same whether you're on an endpoint, in the data center, on the perimeter, in AWS, in NSX, in Dropbox, it doesn't matter.
It has to do the same thing everywhere in a highly consistent fashion. Again, we'll drill into that as well. What are some of the business implications? The competitive moat gets bigger, some of you here has noted. Even more importantly, what do customers think about that? If you have a real platform, the competitive moat around that is already large because you started with the right philosophy. You started to build it the right way from the beginning, and as you continue to extend it and make it more flexible, the moat gets bigger and its competition continues to be on the wrong philosophy with the wrong framework, with approximations of platforms, that's actually helpful. It makes the moat bigger over time because it really highlights the differences between those approaches and a real platform.
The second thing is, Steffan will get into this, we've noted before, is the services. You can deliver services then off a real platform, subscription services off a real platform. As you do that, they would continue to grow in importance over time because that's the way the customers want to consume them. Right? What customers would like to do is be able to consume things in a services mode instead of a lot of point solutions, as long as they're truly delivered in a platform with those kind of capabilities I described. The third thing is a real platform is positioned for whatever's coming down the path. It doesn't mean you have all the answers for whatever's coming, it's the flexibility that allows you to address things as they come down the path. What's coming down the path that's important? IoT is important.
The SCADA, IT to OT things are important. The cloud is important. Endpoints are important. Having a real platform says, "I'm in position to be able to take care of whatever the issues are that arise from all these complexities that are going to continue to drive security in the future." From a business perspective, whether it's security or not, historically, in cases where you have fragmented markets, real platforms have had the ability to capture historic market share. We think, we've got about 9% market share today. We have a long way to go on market share. With a real platform, we think we have a chance to capture historic market share gains as we progress down the path. That's important because it's a big market.
We've got about an $18 billion market we're playing in today, growing to about $22 billion in the next few years. There's a lot at stake from a market perspective, and we intend to capture more than our fair share of that market as we go into the future. The next thing, so I talked about philosophy matters, I talked about frameworks matter, I talked about platforms matter. The next thing that really matters, and we pay a lot of attention to, is execution. Execution for us has been this challenge, right? There's opportunity that I'm showing here, which is not a really pretty picture. Basically, we're saying, "Hey, we're operating at a pretty big scale." We've been doing that for a very long time at really fast velocity. It's hard enough to run a company at scale of $1 billion, $2 billion.
It's really hard to get it right when you have the velocity growth rates that we have because there's lots of banana peels to slip on all over the place. We spend a lot of time thinking about that, and we'll talk a little bit at length through René and Mark about how we do that, just from a go-to-market perspective on things like our thought and brand leadership, which is like a flywheel for us. The more we're known, the better known we are, the easier it is to get meetings, to get meetings at the right level, and hopefully to sell things at the end of the day.
Our demand generation, René is running a machine based on a lot of science, is close to $2 billion of demand generation a quarter right now to support the kind of growth that we have, and have been able to continue to seamlessly grow that over time. The third Mark Anderson will talk about is what does it take from a focus and discipline perspective to go understand what the market opportunities are and continually segment the market in such a way that we can give the maximum focus and attention to customers in each part of that segment, so that they're very happy with the engagement from Palo Alto, and we're happy with the results of being able to engage with them like that. The next is partner relevance. In our business, we're almost 100% fulfilled through partners. Partners are a part of our business.
We treat them that way. We feel like we're in business with them. Give you a lot of data points about how we do that. Most importantly, we want to be and we need to be relevant with them. If we're relevant to their businesses, then they'll be relevant to us. They will invest in us. They will invest in training and people and all the things that go with success. We care a lot about that. Of course, we care about our customers being delighted. We use that word delight. Brett Eldridge, who's back there, who runs all customer support, that's his mission, is delight our customers. Mostly because we want the customers to be happy, right? Makes sense from a prevention perspective.
We also know that happy customers tend to come back and buy more from us as they understand and fill out that prevention story. We definitely want our customers to be delighted with us. Last thing I said that matters is the results. We keep score like you do at the end of the day. Just quick snapshot from a results perspective. What I just took here was, I just took our last 4 quarters, so Q2 backwards by 4 quarters, right? Added it all up from revenue perspective. I did the same thing for some of our competitors in the market. I took the closest quarter for them from our Q2 and added them all up backwards. Just got to get a sense of the scale Palo Alto's operating at right now.
More importantly, the growth rates relative to our largest competitors who are underperforming the market, right? The rate at which we are over-performing the market and over-performing this competition. Their numbers up here Also give them the benefit of acquisitions. The Fortinet with Meru, for example, probably even more telling. Cisco has done 6 acquisitions in the security space over the last 3 years for a total of about $4 billion, right? Yet, they get these kind of results. I only mention that because I think it really matters about real platforms. If you're trying to approximate a platform to do the things I'm talking about, and you think you're going to buy them and put them together, this is what you get, right? We're very focused on a different approach. I will leave you where I started.
At a glance, I'm not going to go through all these again, we think we've got a very special company here at Palo Alto Networks, doing something important at a time when it matters for our customers, we really care what our customers think about that. That's why we do Ignite. That's why, if you hang around tomorrow and the next day, you'll see very little people talking on stage. You'll see tons of breakout sessions, lots of labs. You'll see us enabling our customers to get together and talk to each other so we can get their feedback, and we can help them solve really hard problems in security. Thanks again for taking the time to be with us today. We appreciate that. I'd like to follow up or have Nir Zuk, our CTO and founder, follow me. Thank you.
Thank you. Okay. Thank you, everyone. Thank you for being here. What I'd like to cover now, as Mark said in his introduction, is to talk about some of the technical aspects of the platform, and specifically explain why you even need a platform in order to deal with data breaches. Talk about how the platform works. Just one slide. Lee's going to cover in much more depth. Talk about what are the technical requirements from a platform, and show you what different vendors in the space have in terms of the different pieces that are required in order to build a platform, okay? To do that, I have to cover a few subjects or go through some explanation about some areas that will help me explain the things I want to explain.
The first thing I want to do is I want to show you a breakdown of the market, which is relatively unique and is based on the attack vector that the bad guy is taking. There are other parts of the cybersecurity market that are not depicted here. These are the ones that, at least to me, are the most important. There are really three main attack vectors that bad guys take today. The first one you can see at the top is going directly at the external-facing application at an external data center. Those are usually protected mostly with WAF, with web application firewalls, and with DDoS prevention devices.
There is the market that we're playing in, that's the market where the attack vector is the bad guy taking over an end-user machine, sometimes an unmanned machine, like an ATM or a point-of-sale system and so on. From there, jumping to the data center, doing whatever they want to do. Sometimes they want to modify the data, encrypt the data, delete the data, most often take the data out. That's the market we're playing in, right? Our job is to prevent these kind of attacks. As you probably know, we don't have the different market sizes here. This is by far the largest part of the cybersecurity market. Messaging security, which is an area that we don't play in, is sometimes considered part of that because it's part of that attack vector, right?
Very often, attackers will use email or instant messenger or other messaging applications in order to deliver something to an end user, take over the end-user machine, from there, jump to the data center and do whatever bad thing they want to do. Last, down there, we have the market where the attack vector is usually stealing credentials, right? This is what the IAM, the Identity and Access Management vendors are trying to deal with. The bad guy is stealing credentials and using those credentials for remote access through VPN or other services, and sometimes accessing applications using stolen credentials as well. If all those fail, we have the incident response market where if a data breach is successful, they come in and they try to figure out what happened, clean up, and see what you do next.
Again, we're playing where that big blue oval is. Everything I'm going to say from now on is really going to be focused on that area, on that market, okay. Excuse me. If you look at that market, if you look at, again, preventing that attack vector, traditionally, the industry has been focused on dealing with known attacks. Meaning, if you look at the typical vendors out there, the different solutions that are listed there in those boxes and others that aren't listed here, they try to stop known attacks. Meaning, if you know in advance, if they know in advance something about the malware that the bad guy is going to use, they know something about the command and control infrastructure that the bad guy will be deploying in order to control that malware.
If they know in advance something about the vulnerability that the bad guy is going to exploit in order to gain access to an end-user machine, there are many other things like that, they will do their best to stop the attack. That if they can see the traffic, if they're in the right place at the right time, Lee will cover that a little bit more. This works great, except that most of the attacks that customers care about today, what we call the targeted attacks, the attacks where the bad guy takes the time and money to create an attack that's never been seen before, are irrelevant here. I will say something a little bit more explicit. Take all the IPSs in the world, ours included. Put them as a standalone IPS, not as part of the platform.
Put them in any infrastructure that was breached in the last three years that made it to The Wall Street Journal in a bad way. What percentage do you think you're going to save? The answer is zero. There is no IPS in the world that would have saved anyone from being breached with a targeted attack over the last three years. The same is true for antivirus. The same is true for URL filtering being used as security, not as an HR service. The same is true for the proxy. The same is true for the stateful inspection firewall, except of cases where it was just an open port that shouldn't have been open.
These products would not have saved anyone from being breached with a targeted attack in the last three years, because they only deal with known attacks. Those targeted attacks are almost always an attack that's never been seen before. This is why we've seen a cottage industry being created around the detection of unknown attacks. You know about sandboxing companies. If you've been to RSA, you probably saw about 3 billion big data and machine learning companies dealing with security. There are companies using DNS traffic or DNS information, URL information, and so on to detect attacks that's never been seen before. The way these companies expect you, the customer, to work is they'll detect the attack for you, they'll tell you about it, and you are going to respond to it as quickly as possible, then remediate. Right. Detect, respond, remediate.
The challenge with that is that it's easy to do when there are very few attacks. The bad guys are not stupid, and because they have unlimited compute and unlimited bandwidth available to them, thanks to Amazon Web Services and other services like that, they will never try to just attack you with one attack. They have learned, and we've seen it in real-world attacks, to either completely hide underneath the radar or, more often, overwhelm your infrastructure for detecting unknown attacks with thousands and thousands and thousands of attacks. The thing is that the difference for them between you having to deal with one attack and you having to deal with 10,000 attacks is almost zero.
The difference for you, as a defender, between dealing with one attack and dealing with 10,000 attacks is either you hire 10,000 security experts that you'll never find and don't have budget for, or you spend three months, six months, nine months investigating a data breach, which is usually what happens. Like Mark said, what we believe is security has to be automated. The idea is that, and as an engineer, I just don't think there's any other way, and I'm surprised that many others think there's another way. The idea is that if you can detect an attack, if software can detect something, software should be able to stop it. Humans don't need to be involved in that situation. People have to go and hunt for attacks that software cannot detect. If software can detect it, software needs to be able to stop it.
This is easier said than done, and whenever we talk about it, then this is the reaction of the industry. We've been talking about the need to stop these attacks for the last many years, and the response from the industry has been, "You can't do it. There is no way to prevent attack. What you have to do is to embrace for them, understand that they're going to happen. You're going to lose to the bad guys. Just recover as quickly as possible." We don't believe that. We have been working really hard to convince the market that this is not true. We've been working really hard to show customers that this is not true and show them how they can prevent those targeted attacks. The result of that is that now the competitors are now following us.
This is our slide. At least slide taken from our book from five years ago. At least the marketing of our competitors is now following us. You need to do prevention. All of the sudden, prevention is possible. It's not that simple. The same way you cannot take a 20 years old product, put the words next generation in front of it, and make it a next generation product like we've proven again and again with our financial results versus theirs. You can't just UTM your way into prevention. You can't take a 20 years old product, put a bunch of blades on it, whether UTM blades or software blades or whatever blades different vendors have on top of their product, and all of the sudden prevent attacks. It's much more complicated than that. Okay?
The biggest challenge, Lee's going to talk, I think, about it a little bit more, the biggest challenge in stopping attacks is that unlike the attack that you know about, that you can stop like this, we can stop an attack at 100 gigabit per second in less than a millisecond if we know about it in advance. It takes a few minutes, sometimes more than that, to detect an unknown attack. Since you can't delay everything for a few minutes, the business has to keep going. At the time you know about the attack, meaning at the time you turn that unknown into known, the attack is already going on.
What you have to do then is you have to take the information you just have in your hands and reprogram the entire infrastructure, not just where the attack was found, but of your entire customer base. You have to reprogram everything to stop the attack. You have to reprogram all the networks and all the endpoints to stop that attack at wherever the attack is now and at whatever phase the attack is. For that, you need a platform. This is at a high level from a technical perspective, what a platform needs to do. It needs to be able to take unknown attacks, very quickly determine that they are, know about the unknown attack, making them known, and then very quickly go and reprogram the entire infrastructure of everyone to stop the attack. That's the only way to prevent data breaches.
To do that, there are six things at least that you need to do from a technical perspective, and I'm going to cover them one by one very quickly right now. The first thing is you have to be at the right place at the right time. Now, with an attack that you know about in advance, you know where the attack is going to be. You know where it's going to come from. You know how it's going to look. You know where you can stop it. You can just wait for it there. With an unknown attack, you don't. You don't know where the attack is going to come from. You don't know where is going to be the best place to detect it.
You don't know at the time you detect it, where the attack is going to be, which is where is the right place to stop it, which means that you have to be everywhere. You have to be on the main internet connection, you have to be in the branch office, you have to be in the corporate data center, whether it's virtualized or not. You have to be in the public data center. You have to be in SaaS, you have to look at mobile traffic. You have to be everywhere, which means you have to be the firewall. The only network security device that is everywhere in the infrastructure is the firewall.
Everything else that is being sold today in the market is not deployed throughout the entire infrastructure, usually doesn't see all the traffic, usually only dedicated for two or for one application like email or web, and in many cases, not even in line and position to stop the attack. If you don't have a firewall, you are not going to prevent data breaches. You're not going to stop the unknown attack. Maybe if you see the traffic, you can stop a known attack. Nobody cares. You are not going to stop a data breach if you don't have a firewall. Okay. We just took out 1,995 vendors out of the list of those that can stop a data breach. Okay. We're left with the firewall vendors, we'll talk about them next.
You also need to see the traffic. For that you need to have a next generation firewall. We will talk about it more. You also need to be on the endpoint. That's where the attacks are happening. In many cases or in some cases, the endpoint is the best place to detect the attack. In some cases, the endpoint is the best place to stop the attack. You need to be there. Okay. That's the first requirement from the platform. You have to be a firewall. You have to be on the endpoint. The second requirement is you need to be best of breed. Okay. You're not going to replace an IPS and a content filter and URL filter and an APT solution and so on if you are not best of breed. Okay.
It doesn't matter how good you are at stopping data breaches, you also need to be able to stop the old stuff. You need to be best of breed. If you look at reality, when we, Palo Alto Networks, compete, for example, on an APT deal, right, an advanced persistent threat deal, the only other vendor that shows up is FireEye. You never see the other firewall vendors or other standalone vendors even trying to compete on an APT deal. Why? Because they don't waste their time on something they know they're not going to win. I don't recall a single case where the competition was not, or was, someone other than FireEye when it was an APT deal. When we compete on a URL filtering deal, these guys don't show up either, and neither does FireEye.
It's Websense and Blue Coat that show up for the deal, right. When we compete on an IPS deal, Cisco shows up with Sourcefire, not with their firewall or the IPS inside the firewall. They talk about it all the time, but they show up with a standalone Sourcefire appliance. Maybe McAfee shows up with their IPS and that's it. You never see Check Point and Juniper and Fortinet. They don't even try to compete on an IPS deal in an enterprise because they know they have no chance of winning, because they don't have a best of breed solution. The way to test whether they have best of breed is looking at the results. They don't compete on these deals. They don't win those deals.
They don't have best of breed, which means they cannot be a platform because nobody's going to replace a fine working IPS with an IPS that's not best of breed, even if it gives them additional functionality on the breach prevention side. Okay. The next thing is you need to have a single path architecture. This idea of creating a new module every time you need to detect something new and ending up with 25 software blades running on poor Intel Core doesn't work both from performance perspective. Okay. You need to be able to run fast at the same speed no matter what you're trying to look for. For that, you need a single path architecture. You can't have, again, 25. You can even have 3 UTM modules or application module or whatever they call them.
The next thing, Mark said this requirement, is the ability to adapt to new attacks. When there is a new attack and something new has to be detected, you can't wait for your vendor to come up with a new module, a new UTM module, a new blade to support that. Sometimes they even need a new ASIC in order to do it, which is a 3-year process, and then go through the one to two years process that it takes to upgrade all the software in a very large enterprise in order to bring it to the latest version. You can't wait two years to deal with this new attack. If you have a single path engine, and the single path engine can be configured to look and stop any kind of attack, there's no upgrade required, just a new service.
Either a new service or part of an existing service will deliver it, you need to do that. There's just no way to do it without a single path architecture. Okay. The next thing that you need is to be able to control the security capabilities. As I said, the way the platform needs to work is you detect a new attack that you've never seen before, and you immediately reprogram the entire infrastructure, all the networks, and all the endpoints to stop it. To do that, you need to have control over these security capabilities. If you OEM your antivirus from a Russian company or a Chinese company, if you OEM your URL filtering from another company, if your IPS was acquired not too long ago, and it's completely separate from your firewall, you don't have this kind of control. Okay.
You either need many, many remote controls or in many cases, it's not even your control because it's someone else that's doing the work for you. You need to own these capabilities, and they need to be native, integrated into a single path engine such that you can control them and you can update them very quickly once you need to, when you find a new attack that you've never seen before. The next thing is that when you do that, as I said, you need to run everywhere. You have to secure everything everywhere, which specifically more and more means that you need to go virtual. Lee will talk about it more.
Securing AWS, Azure, and internal virtualized data center has to be part of the platform, which means that you need to be supporting virtual environments, which means that if ASICs are your competitive advantage, you're kind of screwed because there are no ASICs in the virtual world, right? All you have is a bunch of Intel cores. If you rely on ASICs for your competitive advantage, guess what? You're not in that market. If you rely on the fact that you're the networking vendor in order to sell security, meaning your message and the reason people buy you is because you're the networking vendor and they want to buy the security from the networking vendor because security is part of the network, guess what? You're not the networking vendor in AWS. It's Amazon.
You're not the networking vendor in Azure. You're probably not even the networking vendor in the private cloud. It's NSX. Okay. You have to be not relying on things that don't exist in the virtual world if you want to play in the virtual world. Since the virtual world and the physical world have to be secured the same way as part of the same platform, guess what? The last thing is that, Lee will talk about it more, as you've seen on the previous slide, there are different techniques today for detecting unknown attacks. If you walk the floor of RSA, you probably saw between 100 and 300 companies doing different things with big data analysis and analytics and sandboxing and all this other stuff to detect unknown attacks. There is no winner here.
You have to do all of them because nothing is perfect. Okay. The only way to detect the right number of unknown attacks with the right level of false positives, Lee's going to talk about it, is to have many different detection capabilities. They all have to be brought into the platform. Having a standalone sandbox or a standalone something else that only detects attacks, only doesn't prevent them, and only in one way is not going to cut it anymore. Okay. They all have to be brought into the platform. Again, Lee will talk more about it in his presentation. The next thing I want to do is to map those six requirements, technical requirements that I have for a true breach prevention platform into vendors. Who has what? Okay. Of course, we have everything except [inaudible] stateful inspection firewall. You would expect less, right.
Let's pick on the next vendor on the list, which is Check Point. I'll explain why I have the check marks and the X marks over there. Check Point has a stateful inspection firewall. They don't have a next-generation firewall. I mean, they took a stateful inspection firewall, they added the word next-generation in front of its name. That's not a next-generation firewall, and I think we've proven that in the market, okay. If you don't believe that anymore, I don't know what else we can do to convince you that they don't have one. The next thing is single-pass architecture. They don't have it. They have, I don't know, 20, 30, I don't know how many blades they have today. Each one of them is a separate engine. A separate engine running separately from all the others. That's not a single-pass architecture.
Not going to cut it with a platform, okay? It's not going to run fast enough. It's not going to be modular enough. In terms of capabilities, they don't have best-of-breed capabilities. They never show up for IPS deals. They never show up for APT deals. They never show up for URL filtering deals, proxy deals, and so on. All they do is they show up for firewall deals, which proves that they don't have best-of-breed capabilities. The proof is in the pudding, not in what they say. They just don't do that. They don't show up to these deals, meaning they don't have best of breed. That's, by the way, true for the other vendors as well. I'm just picking on them now. In terms of being able to control their technology, many of their blades are OEMs.
Their AV blade is OEM, their URL filtering blade is OEM. They probably have other blades that are OEMs. They don't have control over it. How they're going to reprogram it within a few minutes of seeing an attack, they're not. Okay? Check Point is one of the few vendors that doesn't rely on networking and ASICs and other things. Yes, they're ready for the virtual world. Too bad for them, they don't have the other stuff. In terms of using multiple attack detections, as far as I know, they only use, whatever they call it, SandBlast or something like that to detect attacks. I haven't seen any customers using it, but at least they have the technology on paper. They don't have anything else. Okay? There's one platform in the market, and that platform belongs to a company that's growing so much faster than everyone else.
That's the reason for that. Okay? The last thing I just want to quickly go over is to talk about how customers see. We are seeing more and more customers now buying architectures. Okay? Customers used to look to buy firewalls and IPSs and URL filters and endpoint and AV and all these other technologies. That's not true anymore. More and more customers are thinking about an architecture and about an outcome. The outcome is I want to stop data breaches. Right? The traditional outcome is I want a new firewall. I'm not kidding you. That's what customers were thinking about. I need a new firewall. I need a new IPS. Now it's about, I need to stop data breaches. How am I going to do it? Well, I believe Palo Alto Networks, I believe that it's going to be a platform.
Here are the requirements from the platform. Here's how we're going to do it. Palo Alto Networks does a few things very, very well, or many things very, very well. There are things that Palo Alto Networks doesn't do. We don't do WAF and DDoS. We don't partner with WAF and DDoS vendors because there's nothing that we do that can make them better. There's nothing that they do that can make us better. We don't do that. In the case of messaging security, there is information that messaging security vendors have that can make our platform better. There are things that we have that can make their messaging security better, which is why recently we partnered with Proofpoint. It provides much better value for the customer because now they can protect email as well as the rest of the traffic in the same way, okay?
If you look at incident response vendors, more specifically about vendors that are focused on breach investigation or forensic analysis, we have a lot of information that's very useful for them. We have very strong relationship with vendors like Splunk and Tanium because we have information that we can provide to them that make them much better. We partner with them. Good for the customer, it's good for us. If you look at identity and access management, identity and access management is becoming more and more important part of preventing attacks because in many cases, it's stolen credentials that are being used. More importantly, we are becoming a more and more important identity and access management enforcement point. Right? They do the identity management, we do the enforcement. We need to work with everyone. Okay?
We need to work with the traditional ones, the IBMs and the CAs of the world. We need to work with the new ones, the Oktas, the Pings, the Centrify, and so on. We work with everyone, and bring them into our platform in such a way. I think that what you're going to see, our philosophy just in general is really following what customers are asking us to do, which is to focus on the things that make the platform better. If something can make the platform better or the platform can make something else better, we'll find a way to do that at the right time. If it doesn't, we stay away from it. There's no reason for us to do that. We'll let others do that. They can do it better than us. That's all I have. Thank you very much.
Next, we have Lee Klarich, who's going to tell you about the products that do all the different things that we talked about.
Great. I am the Lee that is going to tell you everything in more detail, as Nir pointed out along the way. In addition to that, I'm going to try to actually pick up where Nir left off and try to go from the approach, the philosophy, the architecture of the platform and translate that into products and product capabilities. Along the way, share with you some of the really exciting things that we're announcing this week here at our Ignite user conference. When I think about that translation of platform to product, that's what I mean when I say product execution. For any high-tech company, product execution obviously is going to matter. I think in particular as a security company, it really matters.
Even the slightest difference in capability can really translate into whether or not one of our end customers is protected or not protected, and that difference is, as we all know, very meaningful. To set some context for this, I thought it would be helpful to share with you how we think about this concept of prevention and what it takes to actually do prevention. At the simplest level, this is what you would have to do to be successful at preventing attacks. You would start by having complete visibility because if you don't have visibility, you can't secure what you can't see, quite simply. From there, you would reduce the surface area of attack. Let's face it, security is hard enough without trying to secure things that aren't actually necessary for the business to operate.
From there, you would prevent all bad things you already know about, then you would prevent any new unknown attacks you haven't seen before. Sounds pretty simple. It may not be that simple, but conceptually, if you could do this, you would be great at preventing attacks. To do these different elements actually requires a lot of different capabilities, and each capability that's required in and of itself is fairly complex, hard to do, requires a lot of technology, requires a lot of know-how and expertise. It requires continual innovation and focus. You can see there's a lot of different things, and this is not even an exhaustive list of all the capabilities you would have to have. Because of that, the industry has historically approached this with the idea of building a new product for every capability that's needed.
20 years ago, this list was really short, as the years have gone by, the number of capabilities required continues to increase. As it keeps increasing, the number of different products keeps increasing, and this goes on and on. There's lots and lots of problems with this. Let me start there. There's three that are really sort of top of mind from my perspective. The first is, for an enterprise, a large enterprise, to adopt a new product in an infrastructure is actually really hard. It takes them a long time. It's hard to figure out how to fit it in, which one's the best, how is it going to tie into operationally, and all the things required just to operationalize it and deploy that new thing. Very difficult. It takes a lot of time.
If you need a new capability and the response is a new product that has to be built and selected and deployed, it takes a long time for an enterprise to be able to respond with the capability they need. Second, most of these products are not designed to be part of the infrastructure, because of that, they're designed to hang off of span ports and taps and things like that to provide detection, not prevention. Third, there's no integration. There's no sharing. There's no leverage between these different capabilities. This is possibly the most important point. Let me show you just a couple of quick examples. Imagine if you're trying to detect and block bad domains on a network. Relatively simple and straightforward as a technology, most heavily dependent on knowing about all the bad domains.
One of the key ways in which you can find out about new bad domains is by doing dynamic and static analysis of new files. The problem is, if you're the product that does bad domain prevention, you're not the product that's doing the sandboxing for the dynamic and static analysis of new things, you get no leverage from that. In addition, you can't apply that to all traffic because you're also not the thing that's actually scanning all of the applications. Let's look at malware. You want to prevent malware. You have to know about the malware, you have the same problem of not being the engine that's detecting new threats. You have the same problem of not being able to apply your preventions to all applications.
You have additional problems of not being able to apply this to encrypted traffic, which increasingly is the majority of enterprises' traffic, with SSL taking over from traditional web browsing. Besides all of that, you have these bad applications like Tor and these encrypted tunneling and Ultrasurf and a bunch of other things that are ultimately designed to bypass you. If you don't have any way of reducing that surface area of attack. You have no hope. I can give you example after example after example of these different problems when you approach each capability as if you need a new product to do it. For us, from day one, we reimagined how you would approach this. Sort of very fundamental to this was this idea that these different elements that are required to accomplish true prevention have to be natively integrated.
They're all gaining leverage and context and information from each other, constantly making each different element smarter in a highly automated way. When you think about what the platform does, ultimately, this is what it's designed to do. Everything's integrated together. We're able to take that and consistently apply it everywhere in the enterprise. It's designed to be very flexible so we can extend it with new capabilities as new requirements come along. We automate everything, and with everything we do, we're always thinking about how we can turn detection into prevention. I have this conversation with my team probably on a daily basis. We're talking about some new capability, I say, "Okay, great. Now how do we use that to prevent an attack, not just detect it to kick off the manual remediation process," as Nir was talking about.
With that as the context then, there are a few very important sort of security transformations that are taking place, and have been taking place, and will continue to take place. Really big transformations obviously take time to play out. I want to talk through each of these. The first is this idea of having complete visibility and being everywhere you need to be in order to provide security. There's a lot of activity going on, whether it's things like IoT and SCADA systems or cloud, whether it's public cloud, private cloud, this movement of, and changing of the enterprise network, and what it takes to be in all the right places to secure it is a very important transformation to us. Quite frankly, it becomes an opportunity for us to extend our footprint and the value we can provide to our customers.
Second is, as the attackers evolve and become more sophisticated, what it takes to actually provide real security has to evolve as well. There's a lot of things we've been doing and continue to do to accelerate our ability to detect and prevent even the most advanced attacks. Lastly, how we extend from a network security standpoint to the endpoint is very important. It's very important because the endpoint provides a unique opportunity to prevent certain types of threats that the network is not necessarily the most well-suited for, just like the network is very well suited for things that the endpoint isn't as well suited for. I'll talk through how our thinking around endpoint security continues to evolve and what we're focused on. I want to start with a very important trend around the movement of applications.
This gets back again to you have to be everywhere the applications are in order to be able to secure them, and you have to be able to provide consistent security as well. If we start by kind of rewinding the clock back several years, every enterprise had this very traditional data center architecture. It tended to be a bunch of physical servers. It was very static, it was hard to change. You put high scale firewalls in front of it to protect it. In fact, this actually is still going on. To a large extent, that architecture is giving way to private cloud. Now, it's important to understand with private cloud, it is still the enterprise's infrastructure. They still have all of the same security requirements that they used to have in terms of protecting that infrastructure at the north-south boundary.
Only in addition to that, because private cloud is highly dynamic and automated, and changing very rapidly, there are additional requirements to secure traffic within the private cloud infrastructure. You'll often hear of this referred to as micro-segmentation, and this is securing between applications, between tiers of applications. This is why we took everything we do and virtualized it in the VM-Series. This is why we took that and integrated it with VMware's NSX, which is the primary orchestration platform that drives all these public cloud architectures. This has been something we've really helped our customers embrace the change to private cloud because we can help them do it in a safe way.
At the same time that that's happening, more and more enterprises are looking to be able to move some of their applications up into public cloud infrastructure, whether that's Amazon AWS, Microsoft Azure, IBM SoftLayer, and others. The idea is to get some of the benefits of just the sort of pay as you grow dynamic, spin up, spin down, move globally kind of benefits of the cloud. In some cases, saving money in the process. In these environments, though, the public cloud providers only take responsibility to secure their infrastructure. They are not taking any responsibility to secure the applications and data that enterprises are deploying into those environments.
For that reason, we took the VM-Series, and we packaged it up in such a way that it can run in these public cloud infrastructure environments so that our customers can have that same consistent security there. This week, we'll be announcing that we're extending support to include Microsoft Azure in addition to AWS, which we've had now for a bit over a year. In addition to that, there is the transformation of applications to SaaS consumption, where instead of the enterprise owning and deploying the application themselves. They're letting somebody else do that, but it's still their data. It's their data running within the application, and they're consuming it. It's for this reason that we acquired CirroSecure almost a year ago and came out with Aperture a little over 6 months ago.
All of this is designed to be able to extend our security capabilities into SaaS environments in a consistent way to secure the use of these enterprise managed applications, whether it's Box or Dropbox or salesforce.com. Most recently this week, we'll be announcing support for Office 365 as well. Ultimately what I'm basically painting for you is this picture that the enterprise application landscape, while changing, ultimately it's extending. It's extending from traditional data center into private cloud. It's extending up into public cloud and SaaS. As all of this movement happens, what we're hearing from our customers is they need the ability to have consistent security regardless of where their applications move to, regardless of how they consume their applications. That's what we're providing to them.
As I said before, the providers of this infrastructure, whether it's public cloud or SaaS, they're not taking responsibility for this. That's why it's so important for us to do this right. Lastly on this topic, I just want to update you with what we're seeing from our customers. Many of you are asking us and me, like, how does this transformation kind of play out? What I can tell you is sort of our observations so far. Our observations are we're seeing very healthy adoption of the VM-Series. Well over 1,000 of our customers have purchased VM-Series from us and are using it. This is probably one of the better metrics to think about relative to private cloud adoption.
In addition to that, even though it's relatively new for us, we're seeing hundreds of our customers adopt us to secure their public cloud applications and infrastructure. At the same time that this is happening, we're seeing continued growth in our data center business. This time last year, it was about 35% of our overall business, and now it's over 40% of our business. What we're observing from our customers is healthy adoption growth across all these different areas. Okay. Switching gears to Threat Prevention and the Threat Intelligence Cloud, we've talked a lot about why this is so important. Within the Threat Intelligence Cloud are a number of capabilities. This is where a lot of our security services are delivered. Within that, we talk a lot about WildFire as sort of one of the core capabilities that we provide from this infrastructure.
I want to start just by giving you an update. If we were here 2 years ago, I would've been actually thinking we were doing a great job in the scale of WildFire, and it would've been that little tiny blip down there. In the last 2 years, we've grown WildFire usage by about 50x. Last month, we processed over 100 million unique files in WildFire. In addition to that, we processed more than 250 million unique URLs. The scale of WildFire is just amazing. This is important because WildFire has this great community effect or network effect where if any one of our customers anywhere in the world submits something to WildFire that we're able to detect as being malicious, we can then reprogram the infrastructure of every other customer to be protected from that.
Everybody is benefiting from everybody else in this architecture, which means that this really matters. The more capacity and scale we can bring to bear with WildFire, the better the capability is over time. To support that, over the last 12 months, we've been running a project, and I'll preface this by saying this is probably not the sexiest, most interesting thing on the surface I'm going to tell you about, but it's actually really important. We've rebuilt the entire back end infrastructure of WildFire in order to be able to continue to scale to any capacity that we can foresee in the future, and to do so in a very global way, because our customer base is very global as well. That project completed a few months ago, and it was very important to set us up for continued success.
In addition to that, we've expanded the operating systems we support. We started with Windows, of course, the biggest attack vector. We extended that to Android support a couple of years ago because we started to see a lot more attacks against mobile devices. This week, we'll be announcing support for Mac OS X. As a Mac user, I'll tell you, I like to believe that Macs are impervious to all threats, but it's not quite true. In fact, during the beta of OS X support in WildFire, we actually detected and were able to successfully prevent a new ransomware campaign that was targeting Macs. It was the first time we've seen a fully productized ransomware campaign for Mac OS.
We were able to detect it early enough in its cycle and then get it taken down from the App Store and get it removed from the applications it had infected before it had ever spread to anybody. It's just an amazing example of good technology and being able to prevent attacks by detecting them early enough in the attack life cycle. In addition to that, we've been very focused on how we continue to make WildFire better and better at prevention. In 2011, when WildFire first launched, we were at basically industry norms from a speed perspective, from when we detected something to when we had prevention, and that's supposed to be a 24-hour clock, in case you're wondering. It took about 24 hours. Industry standard. We thought it was great.
We started observing what actually happened. We noticed that most malware spread very quickly within the first 24 hours. We said, "All right. Well, we've got to get faster." In 2012, we brought it down to 60 minutes. In 2014, we brought it down to 15 minutes. This week, we'll be announcing that we've brought it down to every five minutes, we're able to release new prevention capabilities, both for the malware as well as the other attack vectors that are subsequent to the initial infection. Basically just squeezing that time from detection anywhere in the world to prevention for all of our customers. One more thing on WildFire, and I have to set this up a little bit. Everybody understands a seesaw? This is my attempt to draw a seesaw.
From a security perspective, we're constantly dealing with how do we get really good coverage and ideally how we get really good accuracy for that coverage. The problem is, it kind of goes like this. You bring the coverage up and your accuracy goes down. When your accuracy goes down, you have false positives. The problem with false positives is that nobody wants to deploy you in prevention mode because they're afraid you're going to block something good. You try to raise your accuracy up and your coverage goes down. Now you can prevent, but you don't get to prevent very much. This is what happens over and over again. Nir and I were talking about this, I don't know, two or three years ago, and we said, "Well, this is stupid.
We need to find a better way to do this." We said, "Let's go break the seesaw. Let's go make it so that we have really great coverage and really great accuracy at the same time." We said, "How would we do that? We can't keep doing the same thing that everybody else keeps doing because it's not working. How do we do this?" What we figured out is the way to accomplish this is with multiple techniques, ideally non-overlapping, where for each one, we're going to try to be really good at it, but we're going to focus on making sure the accuracy is really high. We're going to drive the detection rates as high as we can, but knowing that for any one technology, we're not going to get it to where we want it to be.
We're going to combine that with others. When it's non-overlapping, each one benefits from the other and can accomplish things the other one's not specifically suited for. With WildFire, we start off with dynamic analysis. We try to get really good at this. We think we did, and we continue to work on this. Over the last 12 months, we've been extending that with static analysis and machine learning from the big data we get out of AutoFocus. We've been building up these different capabilities in order to make everything better. The net result of all of that is we've been able to break that traditional trade-off.
Based on our analysis of what we're now processing over the last couple of months, we're able to achieve coverage that is approaching that ultimate goal of know about everything bad, while accuracy is approaching that same level. Really driving false positives out of the tool while driving coverage up at the same time. Ultimately, the result of all of this and why it really matters is with these levels of accuracy, it gives our customers confidence to turn on the automated prevention. When they do that, they're turning on really great coverage and prevention capabilities. WildFire, as all of you know, it's in the middle of a lot of different things we do. It's making the firewall smarter, Traps smarter on the endpoint, Aperture smarter for SaaS security.
It's the basis of all the data that's being fed into AutoFocus from a threat intelligence and analytics perspective. It's also the place where we're extending out to a number of very important partnerships. We've taken it recently, we've extended it out to Proofpoint, so we can extend our security into their email platform. We've extended out to Tanium and Splunk, so we can extend it out to, as Nir was saying, the incident response tools and analytics tools and others, tools like that. We're just going to keep doing this because we think that while WildFire makes everything we do better, we think for our customers' benefit, we can make other tools better as well. Okay. Last piece, advanced endpoint protection. I mentioned before that there are certain things that the endpoint is uniquely positioned to be able to do.
For this reason, this was very important to the overall platform and efficacy of the platform. The endpoint landscape, for those of you who've sort of paid attention to it, is actually kind of convoluted. There's lots of stuff. A typical enterprise endpoint has lots of different agents running on it. Some of these are very security-focused, some are management-focused, some are DLP-focused, et cetera. With all of these agents, system load typically kind of grinds the endpoint down to run a lot slower. Users get angry. In the process of all of this, you don't even get very good efficacy. It might be okay if you actually had a really good outcome, but you don't. It's not very effective from a security perspective.
As we've approached this, the way we think about it is Traps, first and foremost, needs to be very good at security. It needs to be very good at being able to prevent targeted advanced attacks. That's ultimately the primary value we want to provide. We think we're doing a very good job of that, both from exploit prevention perspective, as well as malware prevention. In addition to that, though, because of that problem I just mentioned, we're more and more focused on how we, at the same time, can replace the legacy junk that's sitting on the endpoint. Can we replace the legacy antivirus? Can we replace the legacy host IPS? Because that would be a good thing, to be able to reduce the footprint while providing the real thing, which is number one.
And over time, expanding operating system and refining the product so that we can then be pervasively deployed across all endpoints. That is our focus. That is what we are trying to do. When you go back to that same picture, the blue is what we are ultimately trying to replace and replace with a single Traps agent. At the same time of providing very unique and incremental value, we will reduce the overall load and footprint on the machine, providing better security, better total cost of ownership, and better user experience. Okay? With that being said, we are seeing very good traction amongst our customers with Traps. We are very pleased with the adoption rates.
This is still a relatively new product, but at this point, we have well over 300 enterprise customers using Traps, many of which are using it across tens of thousands of endpoints in their infrastructure. It is very good to see. We are here to Ignite. I feel compelled to tell you we are announcing a lot of new product capabilities here, a big new release with PAN-OS and Panorama 7.0, over 50 new features. We have many WildFire and AutoFocus enhancements coming, some of which I described to you today, but others of which will be announced this week. Cloud expansion into Azure, which we are very excited about in terms of extending the cloud, infrastructure we can secure, extending Aperture to include Office 365, just expanding the number of applications we can secure there. There is actually a lot of GlobalProtect enhancements as well.
Nearly 15 different features are enhancing GlobalProtect as it becomes a bigger and bigger piece of the overall platform and how we accomplish security. With that, I would like to say thank you and bring Mark Anderson up.
Hey, good afternoon, folks. I am going to talk about things I am very familiar with, execution and scale. Certainly going to talk about how we are winning with platforms, maybe not quite as passionately as Nir talks about them, but definitely more passionately than Steffan will talk about it. We really are affecting some major business outcomes with our customers with this concept of prevention that our platforms can deliver. What we are doing in response to this is we are continuing to build out what I think is a world-class execution machine and continuing to deliver these outcomes that are making our customers happier than they have ever been and prone to buy more from us. What I said last year on the stage here was I talked about how our relevance had continued to get better, and holy mackerel, in the last year, it really has snowballed.
We've seen a 250% increase in the members of the Cyber Threat Alliance, something that's very good for the industry. It's a nonprofit consortium. We've seen over 100 campaigns solved by Unit 42. Lee just mentioned one of them, but almost every week they're coming up with actionable threat intelligence and research that they're doing from their basement offices and their dungeons and caves. Boy, we ever really got a lot more relevant in social media. You're going to hear René talk about our cyber notoriety has really gone through the roof. What that's doing is it's causing us to invest real dollars with our partners, driving 70% more marketing events. We'll do 7,000 events around the world this year. At each of these events, we're looking at existing partners, targets, getting them together, looking to build significant pipeline, it's definitely working.
Back home in our HQ in Santa Clara, we've actually had to expand the size of our EBC because we've doubled the number of customers that are coming to our EBC, we're getting senior executives, CEOs, CIOs, CSOs, CFOs are coming to visit us to listen to what we have to say about our platforms and that preventative architecture that we can deliver. Finally, at the end of the day, what I really care about is the pipeline that René's magical marketing team is helping us deliver. Our field teams, our partners are creating real, actionable, significant pipeline, 80% more this year than ever. I would like to sort of take the gauntlet and say that we definitely have become the one and only thought leader out there in security. It feels like that every day. I hear that from customers every day.
Certainly is playing out with customers where we've added almost 2,000 customers a quarter for the last six quarters, over 1,000 customers a quarter since we became public almost four years ago. Really seeing major traction there. In response, as I said, we're building out this incredible team. When I joined four years ago, we had 226 people on the worldwide sales team back in 2012. Today, we've got well over 1,800 people. Just to put it into context, from a salesperson's perspective, when we build out the team to that selfish salesperson that I used to be, it means my territory is getting smaller. For Palo Alto Networks, it means we're building tools, we're dedicating resources to that quota-carrying head so that they can be more productive.
When we split a territory, within three or four quarters, that territory is doing twice as much as it was before. We're doing that all around the world. As an example, in the state of California in 2012, we had four sales teams doing a little more than $1 million a quarter. Today, we've got 32 sales teams. It's actually four different districts, each with a district sales manager. I can't tell you how much we're doing because Steffan would shoot me, but it's many, many times more than $1 million a quarter, it's a significant part of our business. In Germany, same thing. We had four sales teams back in 2012.
Today, we've got 18 sales teams calling on enterprise customers, calling on service providers, calling on government, producing on average, like I said before, close to $1 million a quarter around the world, well over $1 million a quarter in the Americas right here. Finally in Australia, when I joined, we had four sales teams there, three in Australia, one in New Zealand, doing way less than $1 million a quarter. Today, we've got 21 sales teams out there, it's a great business for us. Really happy customers, much more safe customers. You can see from the total addressable market numbers we have up here on the slide, that we still have so much more to go. Even with 1,800 people, we still have a long way to go. Less than 10% market share in the Americas.
Less than 5% market share in EMEA and Asia Pac. We are thoughtfully continuing to invest in building out this coverage, working closely with partners to go after customers, not only grow our existing customer base, as you heard Mark talk about, but continue to add new customers that will become the gifts that keep on giving. I'm not going to go into detail here because I did last year, our go-to-market machine really hasn't changed. We continue to have a philosophy of dedicating an SE to an account manager. It is a technical sale. They work together. They don't necessarily always do four-legged sales calls, but they work with our partners and our customers and are driving those outcomes. We're continuing to build a machine behind that quota-carrying team to make them more productive. More investments in inside sales.
We've got an amazing science-driven team around the world now that helps support our outside sales team members. We're continuing to invest. Now we have close to 100 people in the worldwide channels organization that are treating our partners as customers, you'll hear me talk a lot more about that in a few slides. I'm really proud of the machine we have. I think it's very scalable. Again, I'm not going to go into detail here, we have added a couple of new segments here to our go-to-market plan. We're still focusing very aggressively on major accounts and global accounts. We've got sales teams that have a heavy direct touch there. We work with large global systems integrators, like you're going to hear from PwC later at the panel that I'll be moderating, working with large service providers.
You're going to hear from Telstra talk about managed services that we're driving with them. These major customers are flocking to Palo Alto Networks, we're doing a very good job of helping make them more secure. We continue to focus on named accounts, typically in a territory that has about 80 accounts in it with an outside sales team supported, again, by these back-office resources. We created a new tier called commercial, this is primarily an inside sales-led channel that goes after our medium-sized customers, many of whom definitely, or all of whom definitely need world-class security. We really haven't paid much attention to them in the last four years, we're really going after this tier now.
It's definitely a channel-led tier. Our inside sales teams are working with outside sales teams from our partners and taking business there that's purely incremental for us. I'll talk about service provider in a bit, but we're actually creating a brand-new tier going after service providers. It's an important market for us today, less than 7% of our business, depending on the quarter, but I think it has a very bright future. You guys have seen this slide since our IPO roadshow, talking about how that intense focused coverage is delivering great productivity for Palo Alto Networks, delivering new outcomes for customers. You can see in the last year, the ticket to get into the top 25 customers has gone from $7.4 million to $11.4 million, a massive increase just in one year just to get into the top 25.
The multiple of the initial purchase to their lifetime value has gone from 32.2x the initial purchase to almost 41x the initial purchase. Quick trivia question for you here. Does anybody remember what the ticket to get into our top 25 customers was on our IPO roadshow? Get a car? No. $2 million to get in to be the 25th largest customer we had back in 2012. We've really come a long way, and I'm sorry nobody gets the car. We'll have to save that for next year. Talking about the service providers, these are the markets that we're going to go after. These are the businesses, the customers that we're going to target to go after this massive spending service provider market. Certainly going after fixed telco. These are businesses that spend a lot of money delivering wireline services to us today.
Mobile operators, for sure, are looking for differentiated services to deliver to their customers more and more focused on user experience, more and more requiring application security, user security. Same thing with cable operators. That's where I get my internet service from at the house that I'm never at. Web scale and cloud. We had the folks from Amazon Web Services in yesterday for my weekend direct report team. It's amazing what they're doing. You heard Lee talk about our focus there. We definitely need to learn how to sell to these giant web scale companies, and we are going to do that. We're going to get design wins with the team that we've hired to go after them. Same thing with SaaS and hosting. salesforce.com, LinkedIn, these are very different customers.
They're not enterprise mindset, they're more of a production networking kind of a mindset. We're hiring people. I hired Scott Stevens to run this business at the beginning of the fiscal year. Definitely a person that has a really good legacy in service provider space, and our mission is to make all of these logos here customers in the near future. In the past, we've called on service providers mostly as an enterprise customer. Their IT organizations are quite familiar with our solutions. Many of them have become among our biggest customers. The big spending dollars that we can go after, we've just ignored. The production networks for mobile operators selling Gi firewalls, selling infrastructure that goes into their core networks to deliver the services that I spoke about.
If you talk to Lee and you look at the next major releases of our products, you're going to see services and features here that are very applicable to what they need and what they want, and we're working very closely with them to make sure we're aligned with that. Same thing with managed service providers. The more I travel outside of the U.S., and even within the U.S., the more I hear from customers that they want big providers to take some of these services over for them, right? It's a different mindset for us to sell into, so we're building out a team. It's going to focus on using Palo Alto Networks infrastructure to turn on services for these big MSSPs out there. This, again, will not only be a very important channel for us in the future, but will be a very big market for us.
I want to talk about our comp plan. I think we've got a great comp plan. It's definitely a world-class design. I played a small role in it. We've got a great team in our sales operations team that have gone after this. It's really based on a simple philosophy of paying for performance. When you're building the platforms that we are, that are changing the dynamics and being the thought leader in security, it's definitely fun to win with a better platform. We give really aggressive quotas to teams. I think it's enterprise, world-class quality quotas. We tend to focus their greatest payouts are on product plus initial, so P plus I. The bigger rates that they make are on products that are going to affect our in-quarter revenue. We don't pay most reps for renewals. We have an amazing inside sales-led renewals motion.
We do pay for multi-year, but it's a much smaller rate. I think it's a very well-aligned comp plan. It's really driving the right behavior. It's certainly a big part, I think, of our success in driving these never-before-seen rates of growth and security. I'm really proud of the team. I think it's a world-class implementation. Because our productivity has just never been higher, annualized, you take a look at how even with the changes that we've made by dividing and conquering the territories that we're splitting, going from 200 and something to 1,800 people around the world in just four years, we're still driving increased productivity. That tells me we still have so much more to go. Less than 10% market share in this massive total addressable market.
We're going to continue to thoughtfully invest in areas, countries, cities, right here in the U.S. of A., where we can continue to drive productivity up and to the right. We're very thoughtful about it. We leverage data science like my brother from another mother, René, does in marketing, and we're very focused on continuing to do this. This is only with 55% of our team members that are fully ramped. Again, we're hiring good quality people. We've never seen better inbound candidates, and we're focused on driving that productivity on a continual basis. I want to talk about enablement for a little while. We just hired a woman to run worldwide enablement for us, I know this is a busy slide, but if you think about the people that need training or enablement, think about customers.
They need to learn how to be able to configure and manage and consume our technology. I think about partners, the account managers, the SEs that need to learn how to sell and position Palo Alto Networks infrastructure. I think about our TAC engineers, the world-class team that Brett manages of hundreds of people around the world that provide support, but also we get support delivered by our partner TAC engineers. We need to build programs and solutions to train all of them. We've done a great job on this, building a framework to be able to deliver the right kind of training, either free or delivered through partners, in a way that I don't think anybody in our industry has ever done. The outcomes for the people are accreditations and certifications that they can use to get raises in their jobs.
They can use to make more money working in a community that craves trained and enabled security professionals. For us, the outcomes are very simple. Our technology gets consumed faster. We get a much broader reach with thousands of people that are enabled every year, drinking the Kool-Aid of Palo Alto Networks. At the end of the day, our customers get better security, and that's ultimately what's most important to us. We're going to continue to invest more and more in this. If you're a partner account manager or a sales rep, we had 548 of them attend our sales kickoff last year. We opened up all of our internal sales training to our partner account managers and engineers. They sit in the audiences every month.
I talk to roughly 100 people at our new hire, including many partners that are digesting the same curriculum as our very own salespeople and SEs get. Very open like we are with you in this community. We're very open in terms of training our partners to make sure that they can go out there and become extensions of our very own sales force. For the result with the customers, like Mark said, for our customers, with customer satisfaction standpoint, it's just never been better. I mean, close to nine out of 10, the customer satisfaction range is absolutely world-class. I've never worked at a company that's focused on delighting our customers.
If you look at our net promoter score for our global support, in a range of negative 100 to positive 100, where 50 is considered world-class for an NPS score, we've got 75.3, which is a 7.3% increase over last year. It's a big focus. We're investing, I think, smart dollars in getting better at this, and the outcomes for us are happy customers buy more. I want to talk about our commitment to the partner community and really the evolution, the journey that we've been on. If you look back at 2009, our revenues were $13 million or so. You fast-forward to today, you saw that at the end of Q2, we printed the billings line close to a half a billion dollars a quarter, a $2 billion run rate. That's a tremendous transformation. We could never have done this without our partnerships.
But on the distribution side, we started with many country-based distributors that were difficult to manage. The current state is we've got much fewer large global distributors, companies like Exclusive Networks in Europe, companies like Arrow and Westcon that have become great, very efficient distributors for us. On the reseller side, the only people that would pick up the phone 7 years ago to listen to someone from Palo Alto Networks were the mom-and-pop security-focused resellers that were very regional. Of course, the great scale didn't exist with them, but in the last year, we had over 500 of our partners grew their business by more than 100%. Clearly, even those mom-and-pops are getting bigger, the current state today is a really nice range of regional, national, and global resellers, global systems integrators.
You're going to hear from James Shira, the global CISO for PwC later on today. You're going to hear from Mike Conley at Forsythe, an incredible business that we've grown dramatically with. We're really focused on these target partners and making them better and stronger, training them on how to sell our solutions, and helping their businesses grow while we help our customers and ourselves get to a better place. On the deployment side, you've heard from Lee's presentation and from Nir's vision, we're not just selling products that sit in our customers' environments anymore, so we need to be mindful as we build out partnerships, that we might be selling license keys. We might be selling software that resides on somebody else's servers, we're very focused on that. Finally, I think we've become so much more relevant to this partner community.
We had one CAM in Europe, one CAM in the U.S. in 2009, today, as I said, we've got close to 100 people around the world under Ron Myers , really focused on delivering training to these partners just like their customers. We have channel business managers, we have inside channel business managers for the emerging size partners, we've got dedicated systems integrator managers that manage a practice around the world. Continuing to focus on this because it's a big game-changer for us and very psyched about the job that we're doing. I just put up these logos here. We have arrangements with all of them. You're going to hear from Juhi at IBM on our panel. Still very focused on executing with everybody on this list, service providers, large global systems integrators.
In the last year, our relevance to this community has, like I said, snowballed dramatically. We're responding by dedicated resources, by building out service creation teams to help them build managed services, we think our business here still has a very long way to go. I want to talk about some of the pain points that we're solving with customers. I've got five very quick examples here. I had to sanitize them. Our chief counsel made me do that. Just this last week, I was in this unnamed city visiting this healthcare company based in the U.S. If you think about the healthcare and the healthcare insurance market, it's just been a systematic target for the bad guys out there. These guys responded to that vertical being dramatically breached by implementing a zero trust architecture.
We did an eight-figure deal with really selling everything that we provide to these customers, all of our subscriptions, our biggest chassis devices, our biggest appliance devices, as well as some VM versions as they're deploying right now. This is a tremendous opportunity where I think we've only got 20% of the opportunity there penetrated, so we've got a long way to go at this account. Over in Europe, a huge energy services provider, same thing. This company itself was breached in 2004. Because they had a multilayer, very complex point product approach to security that they called defense in-depth, I think they were in deep shit, to be honest with you, but they got breached and we don't follow these customers around with our hands out for POs, but we're there with our engineers offering assistance.
In this case, we were able to completely retrofit their corporate network security. Again, selling the biggest chassis that we have, selling all of the subscriptions that we make available, and we continue to have eight figures of opportunity even after having them spend a lot of money on Palo Alto Networks. Large city government, one of the largest cities in the world, a very politically charged environment, disconnected legacy point products, different groups politically fighting within to get control of the security landscape. They needed to deliver a next-gen emergency services call center. They brought in Palo Alto Networks. Not only did we deliver the gear and design that provided the winning solution, but they ended up hiring four of our resident engineers.
We're seeing this more and more as a best practice for our bigger customers, where they want a Palo Alto Networks badged employee to be on-site or a valued partner's resident full-time engineer on-site to be able to be there to transfer skills and help them do the migration faster than they would otherwise do. Like usual, we competed against the cartel of legacy providers, Cisco, McAfee, longtime vendors in this city that had a very strong political hold, and we kicked their butts. I think there's still a lot more opportunity here, like we feel there is in many of our customers, and we've got a focused and dedicated team to go after it. Another healthcare provider, this is actually a hospital chain that they were onset with CryptoWall in 2013 and 2014.
We were brought in on the network side a year and a half ago to help remediate that situation and build out a new architecture that could protect against it in the future. We were brought back in to sell them 35,000 endpoints with Traps. We competed against McAfee. It was a McAfee renewal. They actually used the money from the McAfee renewal for AV to pay for the Trap solution, and then they went to Microsoft with Microsoft Security Essentials and were able to use their free antivirus solution because they had an ELA with Microsoft. We're seeing more and more customers look at doing this. Again, we've got plenty of expansion opportunity here because certainly no hospitals are a target for the criminals. Finally, a global services tier-one bank. This is really a next-generation opportunity. We worked with VMware, and actually EMC was the integrator.
It's a huge data center of virtualization and perimeter refresh. They were taking legacy data center architecture, completely refitting it with an NSX build-out in this amazing bank. We sold them really big physical devices. We sold them tens of thousands of virtual for thousands of nodes of our VM-Series. It was a real, very highly publicized rip and replace from a longtime reputational account with Check Point. This is one of their big data centers that they've done. We've had continued opportunity here. This is, again, one of the world's largest banks. I could tell you many, many more, but I think you're going to hear the same pain points being resolved. You're going to hear the same theme that platforms are winning, platforms sell, customers looking for more of a preventative-minded architecture.
Palo Alto Networks is really the only one that they can turn to for that. I'd like to say that the sales team that I manage, the global customer support team that I manage, I think we all have the same philosophy that even though the change is pretty constant here at Palo Alto Networks, we all feel, certainly I do feel that this is the opportunity of my lifetime. We get to do things that are very different than we do at other technology companies. It's fun to win with sheet metal and software, but when you get to win with security solutions that change the outcomes at customers, if you're selling to the government, I've had government officials tell me that we're helping save lives. If you're selling to large enterprises that have been breached, that you're helping turn those companies and turn their reputations around.
Even the most selfish of salespeople out there have that kind of running through them every day, realizing that what we do really makes a difference. I think that drives us all to work a little harder and work a little more efficiently and continue to make the world a better place. I certainly know it helps me feel great when I wake up in the morning. With that, I'd like to thank you again for your time. I'm going to push you out for, Kelsey, how long of a break? A 10-minute break. That's not nine minutes. 10 minutes is how long you get. I'll see you back at 10 minutes to 4:00 for the partner panel. Cheers.
Hello. We're going to get started again. This is our partner panel. We're going to talk up here amongst ourselves for about 20 minutes then open it up towards the back half for questions from you all. With that, I will turn it over to Mark.
All right. Thanks, Kelsey. Do we have chocolate bars out there? I didn't even get to go because I was assaulted as I was leaving. All right. Thank you folks. Thank you guys for coming back from the break in a good solid 10 minutes. I'd like to welcome you for the partner panel portion of our talk. I'd like to really just go down the line and maybe get our partners to introduce themselves and their companies. Juhi, why don't you start?
Hi, everyone. Nice to meet all of you. My name is Juhi McClelland. I work for IBM. I've been there for about 16 years, so feel old now and entrenched. Because IBM is so big, and most of you know it, I would just say that I come from IBM Global Technology Services, we're the group that does system integration and services integration.
Great. Well, thanks for being here.
My pleasure.
James Shira, everybody. James is really the only security practitioner on our panel today. James was a CISO customer of ours a couple of years ago, but you've migrated to PwC. Tell us about that.
Yep. I've been with PwC for about 11 months. I'm the global partner and a global CISO here. I've been in security for about 15 years.
15 years, you don't look a day over 25. All right, Craig Joyce. Craig?
Hey, you guys. I'm with Telstra. I've been with Telstra for just over two years now. For those of you who don't know who Telstra is, it's the largest telco in Australia. Revenue's around $26 billion, I think, thereabouts. We have a presence in about 22 different countries and a pretty big footprint within the Asian region.
Great. Thanks for joining us, Craig. Mike Conley from Forsythe.
Hi, my name is Mike Conley. I'm the Executive Vice President of Forsythe Hosting Solutions. Been there about 23 years. Forsythe started off as a leasing company, but we are a large hosting service reseller, managed security service, and consulting firm today. Mostly based in the U.S., with services also in Canada.
Great. I guess my first question for the panel, James, if you don't mind, I'll start with you. Why Palo Alto Networks as a partner? You may have heard this morning we announced a pervasive partnership with PwC, that's starting in the U.S., and I believe will roll out globally with success in time. James, tell us why Palo Alto Networks, and again, why at this point in time?
Sure. I think it has a lot to do with how customers integrate security, and I think it was well covered earlier, but to recap, customers look at security from the endpoint point of view. They look at it from the firewall point of view, and increasingly, there's other elements like Threat intelligence, et cetera. We like to partner with organizations that provide customers with a platform.
That definitely makes a big difference. Maybe I'll move on to you, Craig. We heard that service provider is becoming a bigger part of what we do. Telstra's an amazing company, having been down under many times and met with many of your colleagues. Tell us about this relationship with Palo Alto Networks and the timing of it.
Well, I think it's been a longstanding relationship. We've been a partner since 2012. We were the first diamond partner in the APAC region. We obviously have been seriously committed. I think the appeal for us, though, is really around getting to our customers, where they might have had a whole bunch of technology that was deployed, and it might have been designed that way for the last sort of 10 years. Looking at how we can actually provide some sensible new ways of actually rationalizing it.
Solidifying.
Renewing that infrastructure. Giving a huge uplift in terms of their security capability to actually support the demands of their businesses.
Mike, Forsythe is normally associated with data centers and hosting. It's a relatively young relationship that you have with us. Maybe talk about why us.
Yeah. Forsythe is a $1.3 billion integrator, as I mentioned. Security is $300 million of what we do. We have been, for all our existence, focused on best of breed. In the managed security services and in the cloud hosting business, it is wickedly important because the nature of our customers, being the Fortune 100 and 200, that we eat what we kill. What that means is we are integrating best of breed inside of our own facility. Our customers buy a result. They come to us and say, "Mike, we want you to secure the platform." To us, you can only secure what you can measure. I know earlier a comment was made that you can secure everything that you see. I would tell you that we have to secure what we see and what we can measure, because the skill set out there is waning.
Customers come to us and say, "Look, you take care of the problem. We own the resolve, but we need you to secure it." We are very passionate that if we can't measure it, we can't improve it. If we can't be very firm with our customers that a single platform is the easiest way to stay secure, then that's very bad for them and us. All of our data centers, all of our hosting services are built on the back of Palo Alto, not just the hundreds of millions of dollars that we resell in product. We're also a very big customer.
Yeah. We really work very well with the Forsythe people. I'll add, I know we definitely go in and leverage your relationships as well as our relationships, and there's a very good symbiotic relationship going between field sales teams on Mike's team and on my team.
It's really important. It's really important because as all these customers go through this big evolution, many of them, we talk all about security in the cloud and the edge. Everyone forgets that that legacy application still maintains the majority of our clients' IT budgets. If they have to go to microservices and move all of that, they are looking for solid partnerships. We are the same way. Very few things operate inside every line of a contract. Palo Alto's been fantastic to work with because they understand that when you build that relationship, you are buying yourself comfort for when things go wrong. They always go wrong in large transactions. That customer is going to give you that room to keep going and innovating. It's wickedly important.
Juhi, I mentioned James was the sole practitioner. You're probably the least security-minded person here, but IBM's a massive company. Why have you chosen to engage with Palo Alto Networks now?
We've been working with Palo Alto opportunistically. We had a bunch of clients who had talked about it. We love it when they're exploring the market. That was kind of how we got started about 12-18 months ago. I would say a couple of things. One is, I think the philosophy of Palo Alto being trust oriented aligns very well with what people expect from IBM, right? When we're redesigning their data center or their infrastructure, trust is a given. We need to make sure that we deliver on that. Secondly, much of our business, we have many people, but they're all cloud, and analytics, and cognitive experts. Having a platform from you that we can plug into our infrastructure for our clients or our client's infrastructure was very critical for us.
I also do value this. It's kind of an implied benefit. You guys are really serious about education and a go-to-market model that enables your partners to be successful. To us, at IBM, that was very attractive to have a partner that cares about education, educating your clients and your partners alike. It's very symbiotic and very good so far.
Yeah, for sure. Some of the big markets where IBM is very relevant in, not coincidentally, K-12 is a massive market for IBM. I know we've had some great-
Yeah
joint success around the world-
Right
going after that market.
I would say that also, looking at your presentation, and you had all these dots around the world, most of our clients are global.
Yeah.
They start in one country. I'm very excited that you have so many clients that might be penetrated in a country or a department, working with us, we could potentially grow this in their entire business or another part of the world. I think that's also a synergy between our two groups.
Yeah, for sure. Thanks, Juhi. James, let me take it back to you. I mean, PwC is a trusted advisor at the board level for some of the world's largest companies and governments. The concept of prevention versus just detection and manual remediation, we talked a lot about that this morning. Give us your perspective, really, from the partners that are dealing with those large governments and customers, and how you think that's going to play out with those big customers.
Well, I think in general, it's important to understand the shift that was alluded to earlier in the comments from Mark and others. There is a shift. I think in general, there's two camps. There's either organizations that pursue a prevention strategy, or there's organizations that continue to kind of ride on the older paradigm of reacting and dealing with things when they happen. You can't put everybody into necessarily one bucket, in general, I think what we see is that the more institutions rely on trust and branding, the more they have to be pulled towards prevention. The other piece is that they need solutions that natively allow them to work towards that premise.
Yeah.
The average CISO, I think, has somewhere north of 50 different security products in his or her environment, especially if they're talking Fortune 500. Orchestrating all of that is a significant challenge, going on a prevention path.
Yeah, for sure. Maybe Craig, I'll ask you about the kinds of managed services that we've seen service providers deliver to their customers in the past have been mostly network-based. Maybe you can tell us a little bit about what security means to Telstra, and then what specifically you're delivering to the customers in ANZ as well as across Asia Pac.
Sure. Security really is a pivotal part of our portfolio. We're trying to build security into every product we release, not just the stuff that's security specific, but into mobility, into cloud, all those sorts of platforms. There will be a security segment that sticks through it. In terms of some of the things we're trying to do, though, to actually shift the needle a little bit is, we've made a significant investment in a platform we've called Symphony, which is our SDN network. You would've potentially seen some announcements in the last week or so about that actually going live for the first time for some customers. That gives us the ability to spin up a virtual CPE pretty much anywhere within our network, and in our customer's premise. Potentially also do service chain stitching to actually bring them all together as well.
Now, Palo Alto, during the ideation process, was the first vendor we actually thought, "This is great use case here for this." It really allows our customers now to go to a single portal. They can quickly log in with their credentials, and in a few clicks they can actually spin up a Palo Alto firewall on their MPLS network and actually have it stitched into the network fabric in real time. I think that's a really powerful thing that gives our customers a lot of visibility into what's going on in their infrastructure, but takes away the complexity of having to worry about where they host this stuff and dealing with the team.
Yeah, especially at Asia Pac, I find that the security practitioners that exist in market are few and far between. I think a lot of big companies are going to look more and more to providers like yours.
Yeah, definitely. I think the other thing that Palo Alto has been really good with is helping us establish a security academy within Australia. There's 30 or 40 graduates we're taking through in the first cycle, and it's really around trying to fill the bottom of the funnel, not the top, and actually making sure we can actually grow out the capability domestically, but then potentially into Asia as well. Your organization's been great as a key sponsor of that.
Yeah, for sure. Mike, one of the things that Forsythe is famous for is having a meat-eating sales organization that is maniacally looking for more and more growth. Talk about us in that context, if you will.
Well, although he's joking, it's true. We started off really as a reseller. We're moving best-of-breed products, not just Palo Alto. What we stress to our customers is that in the security world, stop buying all these endpoint products. It does not make you more secure. You can have the greatest endpoint products and what, there's 700 new ones coming out of the Valley every year. Everybody's got a different cure on how to solve this security problem. At the end of the day, back to the passion of the statement is that if you can't measure it, you can't secure it. That is core for these customers. We stress on them, beat up your partners. Beat up hard on your key partners that understand it's a platform.
When you have a platform, you can now secure it because, A, you get to see more and measure more, B, you get to hone your internal skill set, and C, you get to work with core providers like you folks and us, PwC, and IBM, that have a commonality of what happens when breaches occur. Palo Alto gives you that platform. For us, in translating that into real numbers, year-over-year, we have grown more than 300% with Palo Alto of my $300 million in security of my $1.2 billion. It's not like I grew from $0 to $3. These are substantial numbers. Again, it's around the passion of stop going out and buying all this endpoint. Those that have the manageable, measurable platforms are going to win this game, and they're going to make you more secure. Go push on them, and they'll innovate.
Amen.
Amen.
Amen.
Made us good money.
Juhi, I've heard Ginni Rometty talk about security really being one of four focus areas for IBM. How do you see building a partnership with Palo Alto Networks, sort of helping become part of your ecosystem play out tactically as we roll this out around the world?
Yeah. First of all, we have an IBM security division that carries the security mission, right? That's one linkage point between us. I also think that the group that I come from, Global Technology Services, we're 40% of IBM's revenue, and there clearly our alignment around the data center transformation as well as endpoint management with you guys is a very strong linkage. We have to deliver and grow.
Yeah.
It's a very good technical linkage. We also have a very large number of outsource clients that outsource their complete IT to us.
Yeah.
Many times they, I think the point that Mike was making, they don't care what's protecting their infrastructure as long as it's protected. I think that's another area. Then the last area I'll mention is IBM has a very strong Internet of Things strategy.
Yeah.
Looking at some of the new things that you all are bringing to market, again, we have a framework. It's software and services oriented, and if we can match it with some of your product and assets, and have a solid subscription and support kind of a model, I think those could be some really good ways for us to find some early wins and then scale.
Yep, totally agree. Well, terrific. Thank you.
Yeah. Thanks.
I think one thing that I mentioned earlier in my talk, we've built, I think, this execution machine out there in our field sales organization now, 1,800 subject matter experts strong, really covering all through Australia, all through Forsythe's business, most corners of the world that PwC and IBM sell into. I think we actually bring a lot to the partnership as subject matter experts in the field because we do sell everything we sell through partners. These are the prototypes of our partnerships for the future, and I really appreciate you all taking the time to do this. I'm going to unleash you to the hounds here and ask if there's any questions from the audience. Of course, Sterling is the first guy with a question. Question from Sterling at JPM.
Curious for those on the hosting side, when you're looking at the virtual implementations, one of the things that we're trying to wrap our heads around is when you have to protect using virtual firewalls versus physical appliances, what's kind of the ratio? In other words, how many virtual instances do you need to replace a physical firewall appliance? If there's any way that you've looked at it in your business, that would be great.
I think it's an interesting one. The legacy way of actually doing things with great big firewalls and sticking them in front of everything in your data center environment makes sense when you own the data center. When you start actually looking at cloud providers and actually trying to put virtual instances in there, your architecture's probably going to shift a little bit. It might actually be smaller, containable security domains, where you try and restrict the blast radius if something goes wrong. When you're actually doing and segmenting things down and actually having smaller virtual appliances, it doesn't really actually cause you much in the way of pain around that. In terms of price, performance, really if it's designed appropriately, you shouldn't actually see any impact to it. Yep. Question over here. Do we have a mic?
Hi, Michael Turits from Raymond James. This is for Craig again, at Telstra. Historically, we've thought of Palo Alto as being a bit more enterprise-focused than some other vendors, especially the ones that have done network, more focused on the service provider market and telecom market. Are there ways in which Palo Alto has changed in terms of their product set? They've rolled out the 7000 series. Has it become more appropriate, or is it the network that's changing, getting more software-oriented?
I think it's a little bit of both. In terms of the big boxes at the service provider level, which we can then segment up and use for customers, they make great sense in a hosting environment. From the start, the Palo Alto devices have had great API integration. They've been built to do software-defined networking. We're trying to leverage that as much as we possibly can at the moment, and it gives them a real head start against a lot of the competition, where they're trying to bolt this functionality in after the fact.
Yep. Question?
Excellent. Thank you guys for joining us. This is very useful. Maybe a question for Ms. McClelland about working with someone like Palo Alto Networks when IBM does have a pretty broad portfolio of security solutions as well. How does that work out? Does it limit the ability of you to really push the Palo Alto Networks platform story if IBM's kind of pushing a platform intelligence story of their own, or could the two really coexist?
Good question. I'll give you an honest answer. I think a very big chunk of our business, like I mentioned earlier, is outsourced to IBM, right? In that scenario, IBM gets to make the decision on what's the right solution for our customers. I think given that much of our practitioners are focused around data center, and systems, and storage, and networking, Palo Alto has been very attractive to all our project executives because it's a plug-and-play kind of a module. I'll call it plug-and-play. I hope I'm not saying anything offensive, but it's more integrated. I think that's been very attractive. Then frankly, on the other side, we're seeing a lot more pull in the market for Palo Alto. There are clients who want to have a say and opinion in what they want, which nowadays more and more clients do. Why not?
We think of this as a very strategic partnership for us. It doesn't mean we won't work with other partners, but we definitely see this as very strategic. Did that answer your question? Okay. Thank you.
All right, great. Time for one more question. Yep, in the back.
Hi.
Josh
James. James, in both this role that you're in now and your previous role, you've obviously dealt with a lot of different vendors, and you've all talked about Palo Alto sort of pulling ahead. Who's sort of falling behind from your perspective, in terms of who you've worked with over the years?
I'm going to punt a little. I would say, no, in fairness to others, I'm going to punt a little. I will tell you a little bit about what I think the Palo difference is and where I think others are struggling. I do think there's significant, to state the obvious to a smart group, pattern and opportunity for consolidation in security. I think the smart vendors are anticipating that and really have a crisp vision around product roadmap and feature and integration, rather than maybe just growth purely through acquisition. We all know that in software companies, it's very challenging post-acquisition to figure out which features live, which die, and there's a whole DNA aspect to that that goes down.
I think the good to great security companies have a vision for that that starts before they think about the feature or even the acquisition. It's actually the vision for the business. I think those are the companies that I tend to like to work with.
All right. Well, I'd like to thank our panel members for joining us today. Thank you, Juhi.
Thank you.
Yeah. James, as well. Yeah, appreciate it.
Thank you.
Yeah. Keep going.
Thank you.
All right. I'd like to welcome up my brother from another mother, René Bonvanie, our Chief Marketing Officer.
You ready? Good. You had it. Now I have two. Good. First of all, thank you very much for making it out to Las Vegas. I know you all love the place as much as I do. I get to put on this show, and you have to sit through it. It's also good to see a lot of you back. We've been at this thing for quite a number of years. I always enjoy this part of the four-day journey that is called Ignite a lot, to spend some time with you and in the end, answer some questions. I want to do two things.
I want to talk about what it takes to drive a machine where we acquire that many customers, where we grow our business that fast, and how we apply science, data, and relentless focus and alignment with our sales teams, with our channel partners, with our hosting partners to get to these results. This is non-trivial. This doesn't happen a lot in the industry when you grow that fast, and you do it at that scale. That's the first part. The second part is, now what does that mean from a customer's adoption perspective? We would like to share a number of these parameters that we hold very dearly and track very closely to, and what does it take to improve on these metrics? You saw Mark, for example, talk about lifetime value expansion with our top 25. What do we have to do to get there?
Is it just sitting back and waiting for these things to happen, or is it a lot of hard work? Of course, it's going to be the latter. I'm going to tee some things up, how to think about how our customers use our products. Because I know you guys are dying to know what we are going to say about what people use, subscriptions, and so forth. I will tease you. Steffan will follow me. He will tell you even more detail about what we're going to do. That's going to be the presentation. I want to start with story. Some people would like you to believe that this prevention thing, this enablement thing, was their story. For those of you who have tracked this very closely, this is what it looked like seven years ago.
This was a snapshot of our website seven years ago. I remember putting those pictures up on the website, and that's what it looked like. Two very important words. Identifying and controlling applications and preventing threats. This prevention story is the DNA of the company. It is not a marketing slogan. It is not something that you can just repeat. It doesn't work that way. It has to be in your technology. It has to be in the DNA of everything you do. Over time, more and more of your customers will follow this. This is a steady pattern. We said next-generation firewall. Other people say those things, too. We say prevention. Other people say these things, too, in their marketing. Their products haven't changed, their technology hasn't changed, but they've adopted these words.
They're saying platform, just like we have said for the last years. We have used that term not to say a collection of things, but to say something that is natively integrated and automated and has complete control over everything. These are very, very important principles in how we tell the story. Others would like you to believe they have this, too, and they call that marketing. This is not about marketing, because at the end of the day, the proof is in the pudding. When we put this to the test, which is what every one of our customers does, it doesn't matter what my website looks like.
It doesn't matter what the brochures look like, because in the end, the customers will test the product in the lab. That then yields the success rates when we do this. This then yields into the growth that you see relative to our competitors. It's important, though, that we keep reminding the industry of what makes us different. To do that, thought leadership is very important. You have to get to the table. You cannot just put a website up or launch your reps into the market and say, "Good luck, have at it." It is a lot about how do we get at the table and how do we get there with conviction? What is it that makes us different from everybody else?
What we cannot be is a company, and this is again, a choice, that just benefits or profits or that leverage from breaches. That is not our business. Our business is not to say, "Ha ha, told you. Something went wrong. They should have used our technology." That is not who we are. Who we are is very thoughtful, very deliberate about using technology and the way that the technology works as a way to help people prepare and put a prevention platform in place rather than wait for something to go wrong. To do that, we have a very big voice out there. Millions of people come to our blog to read about things we know. The blog is not about, oh, Trump got hacked again, or the Trump hotels got hacked again today.
Which is, by the way, the news, but that's not what we would put on our website or on the blog. Our story is about how to apply technology to do certain things. Everywhere this is true. We help through a partnership with the NYSE to educate directors and officers of public companies on how to think about cybersecurity. In fact, Mark used the example of the EU formalizing laws for disclosure. Within weeks, we had an edition ready of that handbook for European companies so that we can have a conversation with those executives about what it takes to do this. That's part of the fabric that we have to put in so that the market understands what the role of security is and what the role of Palo Alto Networks is to help people get to that prevention posture that we believe everybody should have.
You're seeing it today at Ignite. Well over 3,000 people that show up here. You're seeing it in our user community. 7,500 people have now in the last year joined our user group community. We have 122 chapters around the world where people gather on a very regular basis to share best practices in how they use our technology to put prevention in place, to put a platform architecture in their organizations. We also have a very big voice in understanding and disclosing things that happen in the industry. We find things, we discuss things, we do very responsible disclosure with the vendors involved, and we then describe to the market how these new techniques are working. It makes a lot of difference. It makes a lot of difference when you do this because customers are really better off.
In all of these cases, we're not just publishing or going to these publications with a story. We're actually going to them with a resolution. There is already something done in our technology to help people protect themselves against what we found. That is the responsible way of doing it. It's very easy to latch on to things that are wrong, not what we do. In this case, there are big differences that we make. For example, when we started to find the first new malware on iOS, where non-jailbroken iOS machines, that was shocking news. The good thing is, when we announced that find, we also had protection in place for our customers by the moment that it was announced.
The difference was that one of our largest customers here in the U.S. saw that the part of the network they had already protected with Palo Alto Networks, within minutes, was in great shape because it was protected. The part that wasn't had to be brought down for a number of days, no longer allowing any iOS devices on that network, and there were many, until they found a way to deal with it in the legacy technology. It's not just about making lots of noise, it's also then bringing the solution to these enterprises. All of that is great. Lots and lots of stories, lots and lots of people clicking on your website, reading your blogs. At the end, that counts for nothing unless there is pipeline, that it helps Mark's organization to go and close deals.
Between Mark and myself, we've been at this at a relentless rate. As you can see, I've been doing this for quite a while at the company, and we always hark back to the 2009 timeframe when the company was very small, as you know. This is the machine that we built, a very predictable machine of demand generation, pipeline creation, where we build a big head of steam for the sales teams to go close in terms of business. More and more of this pipeline is done in conjunction with our resellers, with our services partners, with our hosting partners. This is a great leading indicator of how we are going to land this quarter and the next three quarters. This is part of the instrumentation. This has all been instrumented even before we had customers.
We laid out all of the structure underneath in such a way that we could deliver on the expectations of growth. We didn't have to find this out midway, that we didn't have an infrastructure. We invested very heavily in technology, in data sciences, in big data to make this happen. We built a very predictable machine when it comes to pipeline and the alignment to our billings and our business growth. You got to scale. Because it's one thing, as Mark said, to do this at scale, but now the velocity in this. Because running a $1 billion or $2 billion, if you grow 5%, is a very different story than running a $2 billion billings run rate when you grow north of 60%. I don't think there's many CMOs in the world or heads of sales that have ever enjoyed that.
When I say enjoy, I really mean it. There's nothing better than to have the velocity at that scale. It also means you have to keep everybody very busy. Mark Anderson already said 1,700 events on a quarterly basis. These are just numbers for one single quarter. This is one quarter of activity, and we measure everything. I hear these stories all the time. We put more money into marketing, or we're kind of behind on Palo Alto Networks in marketing, as if money can buy you this. This is years and years of fine-tuning a very well-oiled machine that has been together for many years get to this scale. By the way, not just a marketing machine, but a machine that spans everything, from product to product management to everything. This is not just about marketing or just about aligning sales and marketing.
This is about the company being focused on this. When I said we measure everything, I measure every minute we spend with our prospects, and I know exactly what we spend it on, and therefore, I can be highly predictive in knowing how many minutes I have to spend with them so I can move them to becoming an opportunity. That science is very unique in the market. We do it for everything. We grow these numbers as fast as we put the business in. Yeah, do I have to generate more leads? Of course. I also have to make sure that those leads grow in value to the company. The growth is not just can I get more people to show up?
It's can I get people to show up that have more money in their pocket than the guys who came in last year? That's the beauty about scaling. When we do all of that right, what does it mean for customers? What kind of customers are we now attracting, and what does it mean? At the scale that we run with 30,000-plus end customers, we have two opportunities. One is to get more from them, and the other one is to add more to that number. Those, as you probably understand, are different dynamics. For me to acquire a new customer is different than for me to acquire a dollar extra from an existing customer. We're doing both. Let me be very clear, both are extremely strong growth drivers for the company.
What we know is that our customers are adopting us because we are a preventative platform. We don't have to go argue use case for use case. We have to win the business, of course, when we introduce new technologies, such as Traps or Aperture or AutoFocus, but when you already have a seat at a table, that's a great position to start with. Yes, acquiring more customers is great because it gives us a long runway on expansion. I'll get back to that in a second. We also know that customers in certain strata are incredibly profitable and incredibly strong when it comes to security. Two teams or two groups that we have called out in the past is the Global 2000. These are the 2,000 biggest security spenders in the world, where we now have 53% of those organizations. Last year, that was 47%.
Half of those people that have already adopted us as their firewall and many other use cases, also use us for WildFire and APT. You can imagine, these are very demanding companies. Because it's not good enough to show up with a product. You have to be best of breed. What Lee and Nir said, to do this, you have to win the POC, even though they love the idea of platform and they love the idea of prevention, and they all do, you still have to win the bake-off. It's not a free ride. Even though we've had these customers for some time, we still have to go back and win those deals. The same is true for Fortune 100. That number, of course, was lower last year. It was around 80.
Here, even a higher percentage of these folks use WildFire because they even more so need the best APT part of a platform. They don't buy standalone. Standalone is very 2000s. That's not what people are buying. People want to buy this as platform. Something I'm very proud of here, because we measure everything, is the NPS in this group. These are the toughest buyers, the toughest organizations in the world when it comes to vendor management. If others were as honest as we are in revealing their NPS to you, whether that is Oracle or EMC or Cisco, they would dream of a number like this. This is an amazing number when it comes to net promoter score in the biggest companies in the world. Our business continues to be highly diversified. No concentration.
I didn't put any last year numbers on this thing because it fundamentally hasn't changed. Our go-to-market strategy has not changed, with one exception, which is over the course of the last year, different teams, including my team, Lee's team, Mark's team, have hired practitioners from these industries into our organizations, and that is to even better serve the needs of these folks. Because we know that the requirements on financial services companies or public sector, or education or high tech or energy are different. The folks on our teams are folks that come out of that business, that understand how to implement architectural changes, including the change in risk management in these organizations. Our data center business has done very well. When you become a platform, you become more and more relevant.
The myth or the story that is oftentimes said is, "Yeah, we're a great platform for doing application inspection on the perimeter." Not true. Of course, we do that. Let there be no mistake, we do a really good job at that. The relevance of a platform can be measured in clearly how many things are being used in the platform, but also where is it being deployed. Having now more than 40% of our business after Q2 come out of that data center part of the business is important and relevant. WildFire, clearly a well-performing product, the number 1 APT product in the world, again, specifically in those higher-end organizations. Much higher adoption rate there than across the board, which is good. Good. Something new. This, you've never seen this. We've alluded to this, I use the word, the penetration.
Penetration rate is a metric that we believe is much more relevant at the scale that we run for the things that our platform performs. This is when the cameras come out because this is new stuff. Thank you, Keith and Ruth. Yes. When we start to think about our business of what would be a better way to describe how our technology is being adopted, we believe that penetration rate is a better metric. Steffan will put a finer point on this. If you think about the evolution of this, people adopt it as a platform. This is what a platform vendor should show. Great adoption across the board of the different subscriptions. Some of these are much newer. For example, Traps and VM-Series are relatively new. URL Filtering, Threat Prevention, much more mature.
This is what a platform vendor should show you. All of the rhetoric aside, this is the proof. That is one way to illustrate that. Steffan will make the next step because I'm sure you guys are dying to hear about attach rates and that's the next one. Good. One more thing, device refresh. I've been asked this question many times. How do you think about this? As many of you have speculated, device refreshes occur somewhere, in the security business, occur somewhere between four and seven years. I challenge ourselves to understand what is going on here, I want to put one data point in your head. I want to go back to that 2009 cohort, the cohort that we always reference to as representative of our first year of being in serious business, those customers.
What have they done with their devices? I'm going to put a number on top of this that shows you that by now, because they are probably in the middle of this cycle, at the apex, what they do, and they have refreshed about 65% of their devices, which is what you would expect. It's smack in the middle. Here's the good news. They've refreshed their devices with more valuable, more expensive devices that from a subscription perspective, also have more expensive subscriptions attached with them. This is great because not only have these people maintained their relationship with us, as you will see in a second, they've also grown their total business with us, but the devices that they refreshed were refreshed to bigger devices with more, not of course, but in dollars, higher subscription billings back to us.
That's a data point, and we, in the future, may decide to update more of this behavior. Good. Finally, the point I made. The 2009 cohort has shown that this is not just about maintaining the number of devices and refreshing them after four to seven years. It's also about expanding the use of our technology over and over and over again. That's it. A journey that these customers make, where over time they not only wait for things to occur, they force their hand. They make us more and more relevant. They add new things that attach, things that don't attach. Because we see this dynamic now where attached and non-attached is both showing very well, we will introduce a new way to think about this. Penetration rate is a very important way to think about our business going forward.
The final conclusion on this. If we were to perform the way that the 2009 cohort performed over time with us, we believe that there is an opportunity to expand the lifetime value in our install base another $8 billion. If we continue to delight our customers, to work really well with our partners, to continue to innovate in our platform as we do, then there is an amazing amount of opportunity ahead of us in that install base. Put on top of that, a lot of work that we're putting into acquiring more relevant customers in more parts of the world. I think you see how proud we all are of being at Palo Alto Networks today. With that, I'd like to move the show over to Steffan. Thank you very much.
Thank you, René. Appreciate it. Thanks again for joining us today. You've heard about the vision, the product, the great go-to-market capabilities that we have, and the great marketing machine that we've built. These are all dynamics that set us up very well for sustaining growth and increasing profitability. We look at growth and profitability in a framework, and that framework consists of different stages of growth. We're clearly in high growth mode right now, and we anticipate being in high growth mode for years to come. Growing at greater than 30% is something that we feel is very achievable. In many ways, it feels like we're just beginning. We have a very large market opportunity in front of us, $18.2 billion today, growing to $22 billion by 2019. We have approximately 9% market share.
The previous high watermark for market share has been greater than 30%, and our goal, and plans call us for achieving greater than 30% market share as quickly as possible. A significant market share opportunity doesn't necessarily translate into success. You need to have the right platform. The platform that we offer that you've heard about earlier today, it provides the superior security protection for both network and endpoint. We tie it together with a threat intelligence cloud. This is our unfair advantage. When you couple the platform offering with the great go-to-market capabilities, and we have this land, expand, and retain model, it's driving outsized growth. You look at the billings and revenue growth rates, they're very high. Our revenue CAGR since we've gone public is 54%. That's seven times greater than the rate of the market growth.
A couple of our larger competitors aren't able to actually even achieve market growth. We are differentiating on a number of fronts. As many of you who are familiar with the story understand, it's not just about top-line growth. We're committed to growth and profitability. We've consistently said that this isn't a trade-off. It's a balancing act. Since 2012, while posting industry-leading top-line growth, we've been expanding operating margins and free cash flow. Let's take a look at the trends in the business. When you look at billings and revenue over a multi-year period, one thing jumps out. At scale, we're actually accelerating growth. Take a look at billings for the full year of fiscal 2015 and for the first half of 2016. Both billings and revenue growth have accelerated on a period-over-period basis.
What's driving that growth, in part, is due to our existing customers buying more of our platform, and existing customers make up about two-thirds to three-quarters of our business every quarter. The remaining balance come from new customers that we're adopting in the quarter. The geographic strength of revenues continues to be very strong. The Americas theater, which is our largest theater, and for the first half of 2016 accounts for about 70% of the business, grew 58% on a period-over-period basis. EMEA and APAC also have very strong growth numbers. EMEA clocking in at about 39% year-over-year and APAC clocking in about 57%. Each of these theaters provide great promise for future growth. The visibility and predictability of our business has increased, and it's being driven in large part by the platform adoption that we've alluded to. Products, subscriptions, support, it's all been great.
What you're seeing here is deferred revenue. We have $929 million of deferred revenue on the balance sheet. That's grown 74% year-over-year. The healthy growth in the subscriptions and support business, coupled with a very strong renewals business and the fact that we're selling higher unit ASPs that some of the subscriptions are attaching to, are some of the growth drivers of this deferred revenue. The result is better predictability and visibility in the business. You can also see contract lengths have been operating at a relatively stable range. Over a pretty long period, it's ranged from 1.8 to 2.1 years. 2.1 being the latest quarter that we just posted. These top-line trends have influenced our profitability profile. We've made a conscious decision to grow operating margin and free cash flow.
If you look at the first half of 2016 versus the first half of 2015, operating margin has grown over 500 basis points on a year-over-year basis. Free cash flow is 700 basis points. The power of the hybrid SaaS model that we have is playing out in both the top-line growth and the bottom line. Again, it's not growth or profitability, it's growth and profitability. The people who are responsible for executing the business are our employees. At the end of the first half of fiscal 2016, we have 3,343 employees. About half of those, call it roughly 55%, are in sales and marketing, and the balance are in cost of sales, R&D, and G&A. Proportionately, these metrics haven't changed on a period-over-period basis, and it reflects the investments we're making in the business.
We're investing across all elements of the business, proportionally, we're putting more in sales and marketing, mainly because we have low market share, a differentiated platform, and sales productivity is increasing. This is a time to put our foot on the accelerator to continue to drive growth and take market share. Let's talk about some of the growth drivers in the business. Where you can really see the power of the platform taking hold is in the composition of our billings. Since FY 2012, you can see very strong growth across each of the core elements of the platform. Product growth has grown over 43% CAGR. Subscriptions and support have grown even faster than that. In fact, if you take a look at fiscal year 2016 in the first half, our subscriptions and support business, which we call services, is operating on north of a billion-dollar run rate.
The platform story doesn't work unless you have a great innovation engine, and that innovation engine has to be spitting out brand-new products, which we call new product introduction. Over a multi-year period, we've been adding more elements to the platform. As an example, in the next-generation firewall part of this slide here, you can see that Product billings has grown 44% on a year-over-year basis for the first half of 2016. That's driven in large part by the new products we've brought to market. The mid-range PA-3000, our 7050 and 7080 data center type chassis. That has helped expand our wallet share within our customer base. We've also added four new subscription services recently, Aperture, AutoFocus, Traps, and our VM-Series. We are also getting great traction from our existing subscription services, WildFire, Threat Prevention, URL Filtering, and GlobalProtect.
This platform is responsible for the growth that we've seen. There are other growth drivers in the business. With the robust services offerings that we have, which comprise both subscriptions and support, any business that has that type of profile needs to be looking with a very critical eye at support renewal rates and subscription renewal rates. I'm pleased to report that we have very high renewal rates across the board. For subscriptions, they're at about 90%. Support's approximately 100%. These are extremely high, and they're very stable. In fact, they haven't changed on a year-over-year basis. Our renewals business is the gift that keeps on giving. It's a driver of growth and operating margin expansion.
The other element of the renewals business is it has a compounding effect, and as you'll see in later slides, when I show you about the LTV impact of the renewals business, it becomes very apparent how critical of a component this is to our future growth. With the services business taking up more of a proportion of the total business, you can really see this play out over a multi-year period. From FY 2012 to FY 2015, in those three years, as more elements of our platform are being adopted and more subscriptions are being adopted in the high renewal rates, you've seen a services billings mix shift over that time period, where it's taking about a 12-point share of that mix. Many of you who follow us, listened to our last earnings call.
For the first half of 2016, the services mix component was 63% versus 58% for the first half of 2015. That mix shift is becoming even more pronounced over time, and that's all goodness. The reason why that's goodness, if you think about the impact that it has on margins on a longer term basis. Let's start with gross margins. Over that same three-year period, you've seen a 500-basis point pickup in gross margins, which is largely driven by the adoption of more subscription services. Subscription services have software-type gross margins. This is a tailwind for the business going forward. The mix shift for services does have an impact on our operating margins.
As I mentioned on our Q2 earnings call, because of the nature of services billings, when services billings are billed, it goes into deferred revenue, and it gets recognized ratably over the life of the contract. Commissions expense gets incurred in period. There is a natural timing mismatch. There's a near-term depressive effect on operating margins, and you can see it play out on this chart. Longer term, as more of that revenue comes off the balance sheet, that will be accretive to operating margins. One thing to point out, we are looking at doing an amortization project of commissions related to any services revenue that comes in. We're currently doing an evaluation of that, and the soonest that we could adopt that would be beginning FY 2017, which would take care of the timing mismatch. Stay tuned on that front.
We'll probably address that in our Q4 earnings call. One of the most important things we think about in terms of running the business is the dollar contribution from our install base and new customers, and we like to refer to that as share of wallet. Historically, we've shown the subscriptions attach rate as an indicator of share of wallet. You can see that over a period of time, from Q4 2013 to Q2 2016, the subscriptions attach rate has increased very healthily. As of this latest quarter, Q2, it's at 2.3. There are some limitations to the subscription attach rate. First of all, we have eight subscription services. Only four of them attach to a device. The ones that attach to the device, I'm sure you're all familiar with, but I'll click off, just for completeness. Threat Prevention, URL Filtering, GlobalProtect, and WildFire.
These attach to the devices. What the attach rate also does not address is the dollar contribution. The dynamic we’ve seen in the business, coming out with our mid-range PA-3000 and our higher-end chassis, the PA-7050 and the PA-7080 products, the dollar contribution when those subscriptions attach becomes very high. There is a limitation with the attach rate here. We also have four subscription services that have no concept of an attach rate. Traps, VM, Aperture, and AutoFocus. Given the fact that we’re looking at wallet share as a more meaningful indicator of the business, we’re going to be sunsetting the attach rate metric at the end of our fiscal year. We’re going to be focusing on penetration rate and LTV.
When you combine penetration rate with LTV, you will get a better sense of the traction we’re getting in the business in the wallet share. The penetration rate slide, which you’ve seen before, and I’ll briefly go over, shows a number of things. First off, our Threat Prevention and filtering services have a very high penetration rate. Threat Prevention is at 88%, and URL Filtering is at 72%. The stability of the penetration rate is key, mainly because the metric is a customer penetration rate. We’ve added over 7,500 customers since the last fiscal Q2 of 2015. We’re able to monetize those new customers by having them buy at the same rate as the prior customers, the same rate of Threat Prevention and filtering.
When you look at the earlier or less seasoned subscription services out there, like WildFire, GlobalProtect, VM, and Traps, they have lower penetration rates, but you’ve seen them increase over time. We think that there is a very significant upsell and cross-sell opportunity of those subscription services into the install base of our accounts. WildFire, as an example, a year ago was at 23% penetration rate. That’s ticked up 10 points. Over time, we think that WildFire can be between Threat Prevention and filtering from a longer-term model standpoint. GlobalProtect, you’re going to hear a lot more about this going forward. We’ve made some great innovations on that, and there should be an upward bias, too, to that penetration rate. Our VM-Series, you guys know the story frontwards and to backwards around the movement of workloads to the cloud, and the other dynamics that Lee discussed. We think that there’s going to be an upward bias there as well.
With Traps, we’re just getting started. We have about north of 300 customers. We have close to over 30,000 more customers that we can be selling Traps into, plus all the new customers that we’re going to be acquiring. Coupling penetration rate with LTV gives you another insight into the power of the model. Oops. When you look at LTV, we start with the 2009 cohort. You saw this slide before, but without any of the numbers. Our 2009 cohort has spent 11.8 times more in lifetime value than their initial buy. The cohort math, the way that it works, we look at it from a land and expand standpoint and a renewal standpoint.
In that land and expand bucket, which accounts for a little bit over 8 times, that is benefiting from us selling more higher-end products and appliances, more subscriptions, and more support. For the 2009 cohort, it's also benefiting from a refresh cycle of the original units that they bought. The power of those four dynamics is playing out. Then you can see the compounding effect of our support and subscription renewals business in the 2009 cohort. This is becoming a very important part of our business, and in conjunction with the land and expand, we feel like we're very well set up to continue to monetize each cohort. Taking a look at each cohort, another powerful story emerges. Each cohort, the growth continues to accelerate and increase on a year-over-year basis.
You can see the 2009 cohort is 11.8 versus 8.6 that we showed last year. The later cohorts, the 2010 is at 9.3, the 2011's at 5.6, so on and so forth. The robust nature of platform adoption is playing out in the cohorts, and when you do all of that cohort math, as you've seen before, and you use 2009 cohort as the anchor cohort, and you assume that the later cohorts buy to the same level of the 2009 cohorts, which when we do our own modeling, that's what the trend looks like, there's at least $8 billion worth of unlocked value opportunity within our install base that we can go and monetize. With that as the backdrop, I want to now transition to some planning and modeling points.
From a capital allocation standpoint, we have a number of near-term investment areas that we'd like to share with you all today, and the first starts with our innovation engine. With research and development, we're planning to extend our capabilities for next-generation firewall, cloud, and endpoint capabilities. We're looking to continue to build out our threat intelligence services, which is a great competitive weapon for us. In sales and marketing, we're looking to expand our share, ramp endpoint capabilities. We're also looking to scale through partners and enablement. We're definitely focused on increasing our world-class customer support. From a G&A standpoint, we're looking at investing in cloud and infrastructure, and data center expansion to support the growing subscriptions business that we have.
As we shared with you about a year ago, we have a new headquarters facility that's coming online in FY 2017 to support the overall employee growth. From a multi-year planning standpoint, there are five categories I'd like to cover with you today. Seasonality. What we've said historically is our Q2 and Q4 should be the strongest sequential quarters. When you look at the profile of our business, especially on a billings basis, we're north of $1.8 billion run rate of billings. At some point, and it's been hard to call, but at some point, we will have a more typical Q4 to Q1 revenue and operating margin pattern. When that happens is unclear, but at some point, that will happen. Our non-GAAP tax rate, starting in FY 2017, is going to be improved from 38% to 31%, which will structurally translate into a non-GAAP EPS pickup.
Our cash taxes are forecasted to be between $10 million-$25 million per year. We don't anticipate being a significant cash taxpayer for at least five years. From a CapEx standpoint, we have what I would call a normal run rate for the business on a go-forward basis, which will be approximately 5%-7% of revenues. In FY 2017, we're going to have about $100 million more of CapEx in the business related to the new headquarters facility. That's more of a one-time item. From a stock-based compensation expense standpoint, we're going to remain competitive for the size of the company that we are and the growth rates that we're posting. I'd like to wrap up with our framework for growth and profitability, which is applicable for FY 2017 and beyond.
I'd first like to start by stating that relative to our earnings call that we had in Q2, there's no change to the balance of FY 2016. We believe that we'll have approximately 40% free cash flow margin for Q3 and Q4, and an 18%-19% non-GAAP operating margin exiting Q4 2016. As it relates to the longer-term health of the business and where we are today, we are squarely in high-growth mode. As I said before, we anticipate being in high-growth mode for years to come. In high-growth mode, we're looking at free cash flow margins of 35%-45%. We've been operating at the midpoint to the high-end of that range, and we would naturally be in this range for sure.
With FY 2017 coming on board, we'll probably be at the midpoint to the lower end of that range just for that year due to the CapEx build for FY 2017. Still, this business is throwing off a lot of great free cash flow. Operating margins, we're anticipating expanding on an annual basis, 100-200 basis points per year. At this point in the company's life cycle, given the fact that we have 9% market share in a TAM that's growing to $22 billion, with increasing sales productivity in a differentiated platform, we're not striving to maximize profitability right now. We are striving to balance growth and profitability. Longer term, in the distant future, when our growth rate declines a little bit, but it's still greater than the market, we envision our free cash flow margin to be 25%-30%, and operating margins greater than 30%.
With that concludes my part of the presentation. I'd like to invite the executive team up on stage, and we'd be happy to answer any questions. Thank you very much.
Yeah. I'll field the questions, since I'm right by the chairs.
I think you're bringing up one more chair.
Oh, for Palihapitiya. Bring up one more chair.
Okay. All right, great. We'll kick off Q&A for anybody who's got a question. We have a mic runner right here. Thanks. Start right back there.
Oh, yeah.
Hi, thanks.
There we go.
Hi, Saket Kalia from Barclays. Thanks very much for all the detail, especially on the penetration rates. I wanted to zero in on WildFire a little bit more because the 10-point increase is very impressive. Two questions. First is a little bit more talk about the partnerships, whether it's Proofpoint, whether it's Splunk, whether it's Tanium. How important are those partnerships to improving that penetration rate? Is the first question. Secondly, maybe more for Steffan. You were nice enough to show us the renewal rates on maintenance versus subscription. A little bit of a lower renewal rate on subscription. Could you maybe rank order some of the subscriptions that maybe have higher renewal rates versus lower? Thanks.
Lee, do you want to cover that one?
Sure. Yeah, I think the partnerships are important. Mostly in the sense that wherever we can find a good opportunity to partner with other technologies that serve our customers better, we want to go do that. We're trying to provide the best solutions to our customers. The ones we talked about today are some of those key partnerships. With Proofpoint from making email more secure, Tanium and Splunk in terms of response and incident response and forensics and things like that. We think those are very important. In a lot of ways, I think it helps in the sense that picture I drew where WildFire's sort of in the middle of a lot of different things.
Absolutely that comes back around and helps with the growth of WildFire as more and more of our customers view it as the center of programming of a lot of different things, including our own products.
Yeah, just before Steffan jumps in, I just note as well that while it's important that's about threat intelligence, and we have an insatiable desire for the intelligence, those relationships are relatively recent. When you look at the growth in WildFire, that wasn't driven by partnerships, it's just driven by the efficacy of WildFire.
First off, we're extremely proud of our 90% renewal rate. It's one of the best in class that's out there. There are some instances where a customer will trial a subscription service, use it for a year or two, and not renew. We haven't really broken it out from a subscription basis of what the renewal rates per subscription are. I will tell you that writ large, our customers are renewing at a very high rate, and they're renewing most of the subscriptions. Perhaps in the early days, GlobalProtect maybe didn't have a renewal rate that was as high as it was in the past, but we're seeing that trend reverse.
Okay.
Mark, for you, also Nir. Nir talked about identity and access management being sort of on the periphery, and you're partnering with everyone there, or at least agnostic in that space. Then in the CASB space with Aperture, you and I had talked about this before, and it not really being a space and being built into the product. Is that how you feel about the CASB space now, and are you seeing pretty good adoption there? Then I would love to hear if identity and access management could be core to what you guys are doing longer term from a platform perspective.
Sure. I'll start off and then throw it over to Nir. I think on the CASB side, that's the kind of thing where when I was talking about frameworks and then platforms, and the consistency is you have to do security where the need is, and then you have to do it where the data is. A lot of times, Palo Alto's not going to come to customers and talk about topology of networks. We're going to talk about security and where's your data, and who knows where it's going to be in five years, right? The platform has to be flexible enough to get you there. From the CASB perspective, I think that's one of those examples to say, "Hey, look, some of your data is in third-party SaaS applications.
It's just not going to traverse the network, so we better be able to do our thing there." That's why we're in that space today. There are companies there who are trying to give just visibility into that, which I think are rightfully features of what a real platform would do. That's how we think about that. That's in our market today. I'll let Nir speak to.
On the IAM side, there are synergies between the two markets, we're suddenly becoming more and more enforcement for identity. It's just that there are many identity vendors out there, some legacy, some new ones, there's no clear leader, we need to work with all of them. We also think that there will be some new leaders in that space, for example, Microsoft, we'll certainly need to work with them as well.
Thanks.
Thanks. Just a question on endpoint, probably for Lee or for Mark, then a question for Mark on M&A. On the penetration, I'm not asking, I guess, for you to predict where does penetration go on the endpoint side, but does that need to be 30%, 40%, 50%, 60% of your customers yet? Does that have to be a big number in terms of penetration over time for you to have the platform complete and include that important component? Then I guess I just had a philosophical question on M&A, both as well related to the platform, which is, does having to develop a lot of this stuff yourself or keeping the platform pure keep you from doing large deals, billion-dollar deal, buying a big revenue stream, buying a public company, for example, in security?
Sure. I think on the first question, I don't know if Nir or Lee can jump into this on the endpoint side. As Nir was saying, when we went through what are requirements of platforms like, you got to be in a position to play the position. In order to actually do prevention, you definitely have to be the firewall, more and more we think that it's super helpful to also be the endpoint just because attacks are happening there as well. If you can do prevention both with the networking and the firewall and with endpoints, it's just better. We're committed to that, right? We're trying to convince customers of that as well. I think they understand that in the standalone space called endpoint security about they already have it right now. They want to do a better job of prevention.
It's really the intersection of bringing that into a real platform that should have juice for us, to say, "Look, we're very unique on that. We're doing something special on the endpoint, but we're the only ones who actually have incorporated that into the entire platform." We would expect as a result of that that business would grow nicely for us over time because people just would understand that. On the M&A side. The way we think about M&A is the platform view, right? If we think about not a topography thing, where's data and what are the threats and what the threat landscape looks like, that has driven all of our roadmap for a 10-year period of time. There was never. You know, we're not quick on the trigger from an M&A perspective, right?
That's primarily because we're not trying to roll up the security industry. We're not trying to do everything for everybody. I think without exception, every company that's ever tried to do that has failed in doing that, right? One of the things that we hear from our customers on this point is they appreciate our focus of trying to do things that we can do extraordinarily well for them. When we try to do something in addition, it's easy to understand why. Like for example, with the CASB space, as to why that feature should be part of the platform. This can change over time, meaning depending on whatever we're talking about in the future, can change on what could be parts of this platform.
Some of those things might be more impactful, right, as for what the threat landscape looks like or the kind of threat intelligence that we may need, or where is data these days. Usually, our go-to motion first is to build something because of this native capability that's highly automated. The next go-to is partnering, right, as we've seen. Then in a few cases, we've purchased our way into either a new market like endpoints or into new where data repositories are, like CASB.
Is there a question?
Yeah.
Thank you. Jason with Baird. I wanted to comment on Threat Prevention. At first, at almost 9 out of your 10 customers, the network effect of threat intelligence is powerful, of course. Where are you today versus your competitors? I'm asking in what you see, how much do you see in your ability to update? You said it's at 5 minutes now. Where is that relative to your largest competitors?
Let me set that up, and I'll hand it off to Nir Zuk. The 5-minute updating is actually related to all this stuff working together, but primarily WildFire is the brains of the platform, right? When we say if we have seen what is an unknown threat and then turned it into a known threat and done something about it, we can update the ecosystem in about five minutes, right? That's what that statement is. WildFire is the thing that does that, but it's all the capabilities working together that lets us unwind an unknown threat and turn it into a known threat. That's what we mean by the statement.
In terms of speed, industry standard is still roughly every 24 hours. In some cases, in emergencies, you see eight-hour updates and four-hour updates and things like that. For the most part, nothing is approaching the five-minute update speed. It's also important to note what it is that we're able to update. We're updating for malware signatures themselves, being able to detect and prevent that malware from ever happening again. We're also updating URLs and DNS and command and control, which is very important because that allows us to not only prevent the malware, but to prevent later stages of the attack. Even in the cases where the malware was first seen somewhere, it was detected, we then have the ability to prevent the later stages of that attack and, of course, provide that protection to everybody else.
The content of the updates is very unique to us, and the speed of updates is unique as well.
Okay. Thank you.
Just to make it clear, Threat Prevention is more about replacing a traditional IPS and anti-malware gateways for detecting known attacks that everybody knows about and you need to go and stop. As you mentioned, the presentation rate is close to 90%, which means that close to 90% of our customers are using us as an IPS. Where is that compared to the competition? I mentioned in my presentation, we only see Cisco and McAfee today competing on IPS business. We don't see Check Point, we don't see Juniper, and we don't see Fortinet competing on IPS business. I don't recall a single deal where we competed against them. I mean, I'm sure they are. They don't get to our level, but I just don't recall a single deal where we competed against them as an IPS.
Yes.
Thank you. Just a quick follow-up, if I may, on share by geo. You showed the U.S. as 9% and major geos, EMEA, Asia, at 4% or 5%. Not surprising for a high-growth, U.S.-based company. Should that narrow over time, or is there some type of headwind for a U.S.-based company selling network security products?
I think we can capture a lot of market share in all of the theaters. I think as you correctly note, a company that starts in the United States and then over time works its way internationally, it's not surprising that these other countries would take a while to catch up. On top of that, we've just had this fantastic growth in North America. I remember I joined the company five years ago. I told the executive team, "Hey, we're going to shoot for 50/50, right? It's a big world out there." That was a metric that if we had managed to, I'd shoot myself in the head today, right? Just because America continues to grow at scale at such enormous rates, it's hard to catch up to that when it's that size and it's growing that fast. Any questions?
Questions.
Yep. Okay, in the back. Yep.
Hi. Asima Bhallani from UBS. Thanks for taking the questions. Just two questions on go-to-market for Mark. Specifically on the product side for Traps, what needs to happen from the go-to-market perspective to really open up the floodgates to get that number from 300 to theoretically 30,000?
Okay.
Yeah. You can ask another question. I think right now we have an overlay team that covers the global sales team that are subject matter experts, both salespeople and sales engineers for Traps. Their job is to work on large opportunities at those 300 and many more prospective customers, also transfer skills to the field sales team, because really, Traps is an extension of our platform and it's a big part of the platform sell that our core sales team sells with partners every day around the world. I think functionally, what we're doing is very different than what everybody else is doing. Getting better at explaining that and then proving that in the wild, I think is something we will continue to get better at. I don't know, Lee, if you have anything to add.
We're good.
No, just a quick follow-up. You had mentioned that about 55% of the sales force is fully ramped, I can appreciate there's been a ton of hiring happening in the last couple of years that potentially has depressed that number. Is there an aspirational target that you're trying to hit, 60%-75% in a particular timeframe? If you can help us think about that as to how that should play out.
Yeah. I tend not to think aspirationally about that because we are adding dozens and dozens of sales team members every month into the sales organization and working really hard to train and enable them. I think one of the factors that we have working in our favor is that our sales attrition is very low. I think it's a market low. Now's probably not a good time to have Palo Alto Networks come off of your resume, I would submit. It's something that we certainly focus on. I think it's a culture around creating a winning environment and a positive environment for people to feel comfortable working in and be successful at. I would see it moving up marginally over time.
Question here.
Thanks. Karl Keirstead at Deutsche Bank. My first question to maybe Mark and Mark, one of my takes from this event last year is all the love that you guys were showing to the big distributors. You had Westcon and Dimension Data, et cetera. With the passage of a year, can you give us an update on how that's played out? If you can be specific, what portion of your sales are being driven by those partners, and where was it a year ago? My follow-up is to Steffan, just to clarify on your operating margin guide of +100-200 basis points, assuming your growth stays above 30%. I presume that's not assuming any change to the accounting methodology for the sales commission.
Is it true that if you do make a change, you might get a step-up in fiscal 2017, after which you would be on a +100 to +200, or put it another way, it would be +100 to +200 apples to apples? If you understand what I mean. Thanks.
Yeah. I'll start off, Mark, and maybe you can finish up. I think, Karl, if you think about what I've talked about over the last three years, I've always tried to talk aspirationally about where I think our partner ecosystem is going to go. Three years ago, I yearned for a day when we would have fewer, bigger global distributors, and last year I came up here with Dolph from Westcon and dropped the mic on that because I think we really have. We've narrowed our distributors to Arrow, Westcon, and primarily in EMEA, Exclusive Networks. They transact the majority at the distribution layer, the vast majority of the business that we transact. Dimension Data is not so much a distributor. They're like a global systems integrator.
I brought them up last year because it was a new relationship, and we've rolled out nationally across the U.S. and internationally across the world, and we're doing very well with them. I think they are turning on their managed service called Uptime with us all around the world, and we're engaging with their field sales reps like we are with many of our large resellers around there, and frankly, like we will and are starting to with some of the big resellers and GSIs who are up here on the stage this year.
One question from Allison. Oh, hold on.
Yeah.
For the second part of the question, we're still estimating what the full-year impact would be for a commissions change, because remember, the commissions amortization would only be hitting the services portion of the business. Currently, the 100 to 200 basis point annual operating margin improvement is inclusive of any accounting change we would make. If it turns out that the commissions amortization project has a massive benefit to us, then we would possibly relook at that as a transitional year for FY 2017. At current rate and speed, the 100 to 200 basis points annual improvement is inclusive of any accounting change. We have time for two more.
Hey, guys. John Lucia from JMP. It seems like there is an increased focus on subscriptions at the company. I think a lot of your growth in recent quarters has come from subscriptions sold to the install base. My question is on new customers. If you look over the last year, how has billings growth for new customers trended? Looking forward, how do you keep your sales force focused on new customer growth when they have the subscriptions to sell on the install base? Maybe it's more low-hanging fruit there.
Sure. I'll take the first, Mark. When you have the platform play and you're trying to really get the point across for prevention for customers, we're going to tell that story whether you are a brand new customer or whether you're an existing customer, right? It really falls out between the teams who are attacking a new customer opportunity, telling the entire platform story, and trying to find the intersection point where we can earn some trust from the prospect to get started and earn some of their business, versus an account manager sort of role, which is, you're an existing customer, and we know exactly what you're using our technology for.
Over time, we're going to have a very good understanding of what your network looks like and what the best opportunity is we can talk to you about how to extend the prevention capabilities inside of there. The result of that is they're both strong. We're getting good penetration rates both in the new and existing customer base. Mark, I'll let you take us from here.
Yeah. I think if you think about the typical sales territory, most of them have existing customers and prospective customers. There's probably a good balance of focus from a typical named account sales team that might have 80 accounts in their patch, probably 20 of them are customers. They're focused on growing those, of course, as Mark just mentioned. The other 60, they're looking to break in, and they're looking for ways to come in and prove the outcomes that we can deliver to our customers. From a motivation standpoint, I think our comp plan has done a great job motivating people to sell product. Our sales management infrastructure has done a good job of reminding our sales teams that I know you get paid the majority of your comp on selling product plus initial, let's not pass the gas pump.
Let's make sure if the customer's willing to commit for three to five years, let's drive that sale. I think our numbers sort of prove out that we're doing well in both.
Okay. We got time for one more. Keith?
Keith.
Excellent. Thank you for the day. I was hoping to dig into two of the opportunities that Mark brought up earlier. One was IoT. A lot of talk about IoT. It's going to be billions of devices. Not a lot of specificity on how that actually translates into market.
Yeah.
How should we think about Palo Alto's opportunity there? Is it all those industrial control or firewalls that they actually have in place that you guys are going to start going into that market? Where does that relationship with Honeywell fit into the whole thing? If you could give me more specificity on how you actually monetize IoT. The other question is more competitive around cloud. One of the questions I get most from investors is, why doesn't AWS do it? They own the network, they run the network, why wouldn't they protect their own network? Maybe it's a question for Nir, of why AWS and Azure don't turn out to be more of a competitor versus a new platform for you guys to secure.
Sure. Good question. I'll let Lee take IoT.
Sure
Nir can take the cloud one.
In some ways, IoT has sort of been going on for a while in terms of the things have been proliferating, but the idea of actually needing to secure this infrastructure is relatively new. Ultimately, it's going to come down to a number of different locations where security is really important. One of those is securing the infrastructure that all of the things generally connect into, which increasingly is cellular mobile infrastructure for a lot of these things, right? Whether you think of automobiles, whether you think of smaller devices and whatnot, even increasingly like oil wells and pumps. A lot of them connect into the internet through cellular connections, some of them through wireless connections. The first opportunity from a security perspective is that first hop that they connect to and providing security from there.
The second piece is they almost all connect into some backend infrastructure that is controlling them, and these are largely data centers, next generation data centers, private cloud data centers. They're connecting back into some infrastructure that's providing a lot of the control systems for running them. There's definitely an opportunity there to secure both the connections as well as that infrastructure that they're connecting back into. Of course, you can even extend that out to SCADA and industrial control system environments and whatnot that are also involved in a lot of those. Again, there's opportunities to secure that infrastructure and provide the security capabilities we have. Multifaceted in terms of what the opportunity is and where we need to be in order to provide the security.
I'll put one just example on that. Some of our larger customers in the utility space where we are already providing security for their networks, like the corporate IT sort of thing. Those conversations we're having now are them saying our non-corporate side, but the SCADA side is in the Stone Ages, literally, from a security perspective. That is a huge concern of theirs now. Now they're looking to say, "What can we bring over from best practices of what we've done onto the SCADA side of these things?" Because they're really archaic.
The same is true for car manufacturers. Many of them are our customers, and they use us both to secure their own IT environments as well as data centers where they run applications that connect to the cars. We also think that long-term, like Lee said, service providers, specifically cellular service providers, are a great target for securing IoTs. We think that unfortunately, IoTs will not be secured by software running on the IoT itself, even though it might be, in some cases, the right or the best thing to do. It's just not very practical.
Regarding your competitive question about AWS getting into security business, we believe that security, again, has to be uniform, and you cannot secure your AWS implementation differently than you secure your Azure implementation, differently than you secure your own data centers, secure your users' traffic, your branch office, your many internet connections. I'm not sure AWS or Amazon will get into the business of being a full-blown security vendor securing everything across the entire infrastructure. Therefore, most enterprises will continue to buy from a dedicated security vendor such as ours. Such as us.
Great. We're going to have to end there. I know we're over time, so thanks for sticking with us. Thank you everybody for being on the panel here. That is going to end the webcast portion. We will post the slides for everything that you saw today, so folks who are not physically in the room will be able to get that. We'll end the webcast portion of the session now.
Great. Thanks.
Great. With that