Palo Alto Networks, Inc. (PANW)
NASDAQ: PANW · Real-Time Price · USD
373.80
-0.14 (-0.04%)
Sep 15, 2026, 9:42 AM EDT - Market open
← View all transcripts

Analyst Day 2015

Mar 30, 2015

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Greetings everyone. Welcome to Palo Alto Networks Investor Track at Ignite 2015, which is our annual user conference. I'm amazed. I was joking with somebody, you get RSVPs and we had a great RSVP, but frequently there's a very large portion of the audience that doesn't come, so I'm thrilled to see the turnout here. We know that this is a big time commitment for all of you, that you all came in on a plane, and our objective here is to make this experience as meaningful as possible. Thank you very much. For those of you who are listening on the webcast, if you're interested in the agenda, it is posted online. For those of you in the room, several of you have asked me about the Wi-Fi password, it's Ignite 2015 with a capital I, and hopefully that'll help you. Although no surfing.

We'll be very upset if you don't pay attention. No, just kidding. With that, head of investor relations always gets stuck with this extremely exciting slide. The good news is they're not going to make me read the safe harbor, but there you have it. For those of you who are here, at the conclusion of the formal presentations, we invite you to join the executive management team for drinks for a little while, and then we hope that you can enjoy the balance of the user conference. Tomorrow morning, the keynotes start at 9:00 A.M. and go, and then in the afternoon there are technical sessions and all kinds of things. We welcome you talking to our customers and partners and finding out a little bit more about us in depth. With that, I will turn it over to Mark, but first we have-

Speaker 18

We're currently serving over 19,000 enterprises, and at the same time, we're selling more stuff to those enterprises. They realize the value of the platforms. They're using our technology. What they're seeing is, for the very first time, they're getting just a visibility of what's happening on the network. From that, they can get control over that. It's really an enabling technology.

My pleasure. I'm excited to introduce the new PA-7050, the fastest next-gen firewall that we've ever produced. In fact, it's the fastest next-generation firewall on the market.

100% channel-centric, and we will remain that way.

We're very excited to announce 6.1. It's our latest release for PAN-OS. We've packed this release with 30 new capabilities.

I think in the case of Palo Alto Traps, the answer is clear. The effectiveness of the security solution on the endpoint has proven itself.

Personal data on your iPhone may be up for grabs.

Security researchers at Palo Alto Networks have uncovered new malware targeting both Apple computers and iPhones.

The malicious software is called Wire Lurker.

Something like 350,000 users may so far have been affected.

Four leading companies, Fortinet, Symantec, McAfee, Palo Alto Networks, all very much involved in the battle for cybersecurity. If we can share threat intelligence information that we would usually consider competitive and proprietary for our companies, that's going to be to the good of all of our customers.

The president urged companies to share information.

To fight the growing threat of international hackers.

The Cyber Threat Alliance, which includes companies like Palo Alto Networks and Symantec, are going to work with us to share more information under this new executive order.

One of the really big emerging companies in Silicon Valley that is so crucial in the world of cybersecurity is Palo Alto Networks.

Cybersecurity will be a huge issue in the year to come.

Speaker 17

Please welcome Chairman, President, and CEO of Palo Alto Networks, Mark McLaughlin.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

Thank you. Thanks so much for being here for the Analyst Day for Ignite. This is our third annual conference that we've had for our users, and it's been a resounding success for us. We hope you'll partake not only in today, but you can stay for the entirety of Ignite, and I would encourage you to do so. When we started it three years ago, we thought we'd have a couple hundred people here. We ended up with 1,000. Last year, we had just about 2,000, and this year we have over 3,000. It's growing very quickly in popularity as our customer base continues to grow. If you have the chance to stay through at least tomorrow, you can mingle with everybody and get a chance to see what we're talking to customers about, more importantly, what they're talking to each other about.

We also, through the course of the day, we're going to do a few presentations for you. We have a cocktail hour this evening when it's done, like Kelsey said. There's a lot of Palo Alto executives here, all in the back there, but we have John Spiliotis, who runs North America, Chad, who runs business development. We have our head of HR, Wendy, our general counsel. You don't want to talk to him. We've got, let's see. I thought I saw Christian Hentschel here, who runs EMEA for us. Uri and Nati, who are the founders of Cyvera, are here with us again this year, are back there, too. Raj is back there. He was the former CEO of-- Oh, jeez. Now I'm blanking. Morta Security. Yes, I'm sorry about that. My names mixed up here, but so Raj is with us as well.

Anyway, please take the opportunity to mingle with the executives during the course of the day. Rick Howard, our chief security officer, is back there as well. Lots of folks here. You're welcome to talk to all of them. Okay? What I wanted to do today from an agenda perspective was go through what's happening at a high level from a cybersecurity perspective in the market. I think there's kind of two things happening there, and I'll address them. The reason I wanted to do that was there's stuff that's happening for security-wise that's very important, and I think from an investor perspective, there's a concern of, are we in a bubble from a security perspective as well? I think those are two separate but related topics. I'll address a little bit about that.

We're going to hear from Nir Zuk, who is our CTO and founder. You're all pretty familiar with Nir, I think. About Palo Alto Networks' platform approach and why it's winning, and why we would expect that to win in the future in the context of what's happening in the security space. Lee Klarich, who runs products, will talk with us about the platform and what we're doing with that. We'll hear from Mark Anderson, who runs all of sales and customer support on a view from the field, what's happening when we are out talking to customers and we're trying to sell this concept, and more importantly, the actual platform itself. We're delighted to have with us some of the leaders of some of our largest distribution partners who are in the back of the room with us today.

They'll come up in a little while with Mark, and we'll have a panel discussion with them. You'll be able to ask them some questions as well as to what Palo Alto Networks is doing from a go-to-market perspective and why it's important for them. Last but not least, of course, we'll hear from Steffan, our CFO, who will go through the business model, which is fairly unique, product SaaS business model, and then update you on some of the key financial metrics as well. Okay. I think everybody's pretty familiar with Palo Alto Networks, but for those who are not, just at a glance, quickly, what do we think we have here from a company perspective? We think it's pretty unique. We think it's unique because we have a true platform.

We'll talk about what that actually means, a true platform at a time when it really matters, when security is very important, and it's going to last for a long time. Because of that, we're seeing this quickly become a reference architecture for the future for enterprises. That's measured in a lot of ways, but we have very rapid customer adoption, and we're capturing market share very quickly. Importantly, because of the time we live in and this platform technology we've brought to market and what we're doing with it, we think we can continue to capture significant market share, and we think we can capture more market share than anybody's ever held in this market before. We'll talk a little bit about that as well.

That platform produces this hybrid model we talked about, which is generating very high revenue growth, and a lot of it's recurring in nature. You can see that when Steffan gets into the deferred cash flow. It's a very nice model with a high cash flow generation, and very importantly, increasing leverage at scale. We've been increasing leverage to the model consistently. We think we will consistently continue to increase leverage into the future, particularly as we continue to scale the business, which is actually pretty sizable, and we'll talk through that right now. This is how we think about the company, primarily from an investor perspective. Obviously, from a customer perspective, you'll hear more about that in a second. Just at a glance, this is how we think about things.

As an executive management team and as a board, to attain our position in the market we have today and to continue to grow our position in the market, this is how we think about things. There are things that really matter to us, we think about those. One is the timing that we live in. Timing is important, right, when you're trying to bring things to the market. The second is what is the problem that's trying to be solved in the first place? The philosophy about what the problem is and how to solve the problem is very critical on what you ultimately build to solve that problem. The third is consistency. Even if you build something to solve the problem, it has to be highly consistent for enterprises everywhere, because where it's inconsistent will create an issue from a security perspective.

The next is the platforms. We're using that word all the time. Lots of companies use that. We think we have a real platform, a unique definition around what that is, and you'll hear a lot about that from Nir. Platforms matter, like they win. When they win and they win in large market segments, that gives you a chance to capture a lot of market share. We think that matters a lot. Then you can have a fantastic idea, fantastic technology, and a great time in history and just screw it up on execution. We know that execution matters, particularly when you're operating at scale. We really care about that. The last thing is results, like the way we can judge whether our philosophy and our platform and our execution are working is what do the results look like, right?

We'll spend some time from a result perspective because we watch those very closely. If I start at the highest level, the time we live in, right? Some of this sounds pretty obvious, this is why security is getting so much attention. The time we live in is one in which everything that matters to us is completely digital now. It's the digital age, right? Money, it's very rare to touch real money anymore. It's either on a credit card, most of your money's in a bank account that you look at with bits and bytes, and you just hope that it's there the next time you look at it, right?

Access, your identity, healthcare systems, things that get you services, the ability to get basic services like utility and water, those things are highly controlled through SCADA systems these days from a digital perspective, you just trust that it's going to work. Safety, next time you get on a plane, you're hoping that the air traffic control guys are doing their jobs, right? A lot of that is computers, right? We live in this highly digital age where things that we used to touch a lot physically, we don't anymore, which means we just trust that they exist, and we trust that they're going to work when you need them to work, which is great because there's a lot of leverage in that. The problem is that the trust in that is quickly eroding. We see all these breaches and headlines and these attacks.

What's really happening, why is this really hitting a nerve is because the undercurrent is this is attacking the very trust on which the digital age is built in the first place, right? If you felt like tomorrow when you checked your bank account that it may or may not be there, right, you would go take all your money out today, right? If you felt like you couldn't get access to certain systems tomorrow, you'd be really worried about that, like from a healthcare perspective, are you going to get on the plane or not, right? What's at risk for all of us right now in the face of all these breaches is it's going right to the heart of the digital society of blowing up the trust. If that trust goes away, it's chaos. Just total chaos, right?

That's why security is such a big deal and why we're hearing about it all the time left and right, because it really matters, because it's right at the very heart of all of our systems today. We're seeing this at the highest levels in government You saw the little clip there from President Obama. That was about two months ago. He came to Silicon Valley and did a cybersecurity summit. It's the first presidential summit that's not been held in Washington, D.C. in 50 years. He came to the heart of Silicon Valley, the heart of technology in the United States, to talk about cybersecurity and intersection with privacy. When he showed up, he showed up with an executive order. The executive order did certain things relative to cybersecurity. Right now in our legislature, there's tons of bills. See what happens, right?

Tons of bills working their way through there to get done. That's because the government recognizes this trust issue, that if the trust erodes in all these systems, we're in a world of hurt. That's why we're seeing such attention to this at the highest levels in the government, and that's on a worldwide basis. We're seeing that in the military. Traditionally, in the military, for the very longest times, when you thought about theaters of war, it was land and sea. It was only in the early 1900s that the whole aviation came around, where you got air on top of that. That took until about 1950, by the way, to be its own theater from a warfare perspective in the United States. Now it's land, sea, and air. Now there's a new one. This is the patch of the US Cyber Command.

Cyber is its own theater of war now. There's land, sea, air, and cyber. I was just at West Point, my alma mater, a little while ago, the Army stood up a cyber branch. Just like there's infantry and field artillery and aviation, now there's one called cyber. Cadets are graduating in May into the branch of cyber. They're going to wear this patch. Things are changing very dramatically in the military as well, all again because this is so important to what's underlying society today. We absolutely see it in business. This is in the boardroom context globally, not just the United States, globally. When I travel around, I talk to boards of directors, which I do quite often, and senior executives in companies. Cyber is one of the top three items being discussed in a boardroom today. Lots of top-down here. Why?

Because of recognition that the security is so important for these companies, for their reputation, for their business models, maybe even for their very existence, depending on how vulnerable they are from an external perspective on how they deal with their customers. It's a super top-of-mind issue, and it's not going to go away. Security has become, I've been using a term with some of you, if you like it or not, I don't know, but doing fabric. It is woven into major technical decisions now, all of them. It's woven into major business decisions. It's woven into national security and diplomacy. As a result, it's pervasive. It's important, it's pervasive, and it's long-lasting. To the point I mentioned a little earlier about where are we from a security perspective, I don't know about winners and losers in the market.

We'll sort all that out, and we think we're definitely a winner in that market. Security is going to be around a long time. This isn't going away anytime soon. All this anxiety here about the spending that's going on a result of this is not going away. Because, back to what I said, this goes right to the heart of the trust on what our society is built upon. The idea that this is going to get fixed quickly or that it's going to just abate over time, like, "Yeah, we used to worry about that. We don't worry about that anymore," I don't think that's the case whatsoever. I think it's going to be with us for quite some time, and that creates opportunities for folks who can do something about it. The second thing I said that matter is ideas.

The reason for that is what you think the problem is and how you intend to solve the problem is going to dictate almost entirely what do you do about it. How do you think you're going to fix it, and what are you going to build in order to get things done? We think that ideas matter a lot in this, and we think we're kind of against the grain on this, by the way, because we're very prevention-oriented as a company, and I want to explain why that is. It's because behind all these headlines that we're reading about, it's a battle, but it's a math battle. What's happening is the cost of compute power is going down. It keeps going down. That's not going to stop either. It's going to keep going down. That's a good thing generally for productivity purposes.

In cybersecurity, what that means is the cost of compute goes down, that the ability for a bad guy to launch an attack and launch a successful attack just gets easier and easier and easier. They can launch more and more attacks, and more and more of them become successful, and this is what the curve looks like. As long as the curve looks like this, it's going to be easier for those guys to do those things. With that in mind, what we think is if you want to ensure failure in this battle that's going on, then stick with that dynamic. Keep that curve just the way it is. In the face of an attack and breaches, do more of the same. Stack up legacy technology, which I think is fairly obvious now, failing left and right.

Three years ago, we'd go in a customer and say, "Your legacy technology is not going to protect you," and we'd get a lot of pushback on that. We'd have to prove it to them by running AVRs and things, and we're very successful in doing that. You go in today and say, "Your legacy technology is probably not protecting you in the face of these attacks," people are much more open to that. Because as you're reading about in the papers left and right, Mark's going to talk to you, and Anderson's going to talk to you about what are the commonalities in these attacks? What are people doing in those networks, and how do we take advantage of those commonalities to sell the Palo Alto solution? If you want to ensure failure, keep doing more of that.

Keep stacking up that legacy technology because when you do that, the next thing you're going to have to do is keep adding more people. None of that stuff works together, and it just puts more and more burden on the humans, which is the least leverageable resource that anybody has in this battle. You're going to end up with this conga line, just keeps getting bigger, more people to operate them and try to catch the stuff that falls through the cracks. What do you do with the 2,000 alerts I got today? That's a problem. What we have to do is turn the cost curve on its head. This is the answer. We think the answer. Change the dynamic of what's happening out there.

What we mean by that is we have to make it such that the cost of a successful attack keeps going up and up and up, ideally to the point where nobody wants there to be successful attacks, but there will be. Ideally to the point where if somebody is able to launch a successful attack, it works once. It works one time, one place, and it doesn't work anywhere else anymore. If that's the case, then we've completely reversed the dynamic here. Today, the bad guys take a piece of malware, they use it here, there, and everywhere, again and again and again and again across the world, willy-nilly, and it works in a lot of places, so it's cost-effective for them to do that.

They take a variant of the malware, and they try it again, and it works again in a lot of places, so it's cost-effective to do that. If you can change the dynamic, which is it doesn't work, it works maybe once. Then you have to start all over from scratch. You have to write brand-new malware. That's not easy. That's expensive, and that will change the curve on the ability to actually get successful attacks launched. The only way to do that, we think, is leverage. You have to get leverage into the system. Lots of ways to get leverage into the system, so I'll talk about a few of them. The one that's most important, we believe from a technology solution perspective, is prevention. Now, nobody's going to prevent everything.

Palo Alto never goes in and tells a customer, "We're going to prevent everything." That's not reasonable. What we do believe, we're telling customers, and they believe it, and they buy it, is that it is very possible to do a very high degree of prevention. The way you do a very high degree of prevention is you have a very good prevention capability at every single point where an attack has to be successful in its lifecycle for the attack to be successful. There's a misnomer or a misunderstanding in cybersecurity that all the attacker has to do is get in. That's not a successful attack. What the attacker has to do is get in and do a lot of other stuff to be successful, and Lee will walk you through what that looks like.

The idea here is to get a prevention capability every single place where the attack has to be successful, and it's a good capability, and you make it better and better and better. All those capabilities are native to each other. They work tightly integrated together. They're completely native to each other, so that it's highly automated. You get highly automated prevention at every one of those points. Then in addition to that, it's shared. You're in an ecosystem, which we have, a very fast-growing ecosystem of customers, where when we do prevent something, everybody gets that right away. It's shared. The next thing that comes over your network is not an unknown attack, it's a known attack, and we could just stop it right there. That's leverage.

We think that getting prevention in a highly native, automated capability like we have from a platform perspective puts leverage into the system, and it changes the math. Even if you do that, then I said consistency matters as well. You have to do it everywhere, and you'll hear Nir talk about this quite a bit. You have to do exactly the same thing with the same capabilities in the data center and at the perimeter and at the branch office and on the mobile devices. Then you have to do it whether I'm operating on-prem or in the public cloud or in a private cloud or a public cloud, it doesn't matter. No matter where you are and how you're deploying, you have to have 100% consistency from a security perspective because the place where you're inconsistent, that's where you're going to have a problem.

What we defined or what I just talked about is a platform, and we believe we have the platform that does this. It has capabilities at every single step of the attack lifecycle. Those things have been natively integrated together. We constantly improve them. They give highly automated prevention outcomes that goes faster and faster, and we share that across our customer base, which is growing at very dramatic rates. We put leverage into the system to change the dynamics of what the fundamentals are of what's going on in the cybersecurity battle. Like any good platform, you'd want this to be extensible. We've proven over time that it is extensible. Actually, we're always doing three things with the platform. The first is we're extending its capabilities, depending on what the situation requires.

We've done that with threat prevention, with URL filtering, with GlobalProtect, with WildFire, now with Traps, and you'll hear Lee talk about additional extensions. The second thing is we continually enhance every portion of this because we can't sit still. We have a great prevention capability. We have to make it better and better and better and better, and Lee will talk about how we continue to do that as well. We want the ecosystem to be bigger and bigger and bigger, which means we're going to have lots of customers in here. We're going to share all that information. In addition to that, we're going to have great technology partners to help us in that as well. We'll talk through that as well. We know that platforms win.

We think by analogy, when you think about companies that have successfully come into large markets and done what I just talked about, different dynamics. Put a platform in place that really works like these kind of companies. What has happened, they've been able to capture very significant market share. For us, that matters a lot because we're in a very large addressable market opportunity with low market share today, although we're capturing at very rapid rates. Because we think of this time being so important and long-lasting, like I talked about, security's not going away, and we think we have this platform I just described to you, we believe that we can capture not only rapid market share, but we think we can capture more market share than anybody's ever had in this industry before because it's been a very fragmented market.

All those legacy point solutions I talked about, all trying to do one thing or two things and not doing them well at all, let alone doing them together. Platforms win, and they win in a major way from a market share perspective, and we're confident that we're going to be able to capture a lot of market share here. We can see that playing out. You'll see lots of metrics today from Mark Anderson and Steffan, but the one obvious one is just the customer count. We've got almost 23,000 customers today. We've been adding over 1,000 net new customers a quarter for 13 quarters in a row. It just continues to feed upon itself in a great way. Obviously, this is good for business, when you see these kind of numbers.

When you think about it as security professionals, like Nir thinks about it, and Lee thinks about it, and Uri and Nati, and all of our really smart technical people, the reason they love this chart is not because it's good for business. They love this chart because of all of the threat intelligence it brings. When I said it's really important to have the extensibility enhancements and share it. How do you get that prevention to be done really fast on a broader and broader basis, is you try to see everything you can on a global basis, in every single vertical, and bring it to bear for everybody. I don't have to scale out my own network, which is a completely futile attempt to keep up with cybersecurity. I cannot do that. There's no way for one company to keep up with this.

When you can bring the ecosystem to bear, now we have a chance. When they see this chart, they get very excited about it because this is the sharing pool of threat intelligence that's out there. That's why we like to see these numbers continue to go up and to the right. I also said it could be a great time in history, you can have a fantastic idea and a great technology and just blow it. We know that execution matters, which is not an easy feat for us. We're operating at over $1 billion right now on run rate and growing at very high rates. We're adding 200-plus employees into the company every quarter. We have customer support that has to keep up. Our customer stat scores you'll hear about are the highest in the industry.

These are not easy things to do. We care a lot about execution, and we think about it a lot. We invest aggressively, and we'll continue to do that across the company, and face this opportunity to make sure that we get execution right, which means scaling well, because we want to make sure that we capture as much of this opportunity as we can, as fast as we can, but we keep it over time as well, because we know that happy customers buy a lot from us, and you'll see some of that from the cohorts analysis. The last thing I talk about was results. Results matter, right? How do you keep score of whether we're more right than more wrong on this philosophy and platform? One obvious way is look at the market.

What I did here is I just grabbed Juniper, us, Fortinet, Check Point, and Cisco, and all I did was I took the last 12 months trailing revenue and added them up. Because some of us are on fiscal years. Other ones are on calendar years. Just to give a sense of size. This is just the last 12 months of trailing revenue, added them up. As you can see from this chart, Palo Alto is the fourth, and just about any second now, about to be the third largest provider in this market. We're a pretty big size company. This is revenue, and obviously sales are much ahead of this. This is revenue, so we're a pretty big provider. Our ideas are working in the market.

Way more important than the size, I mean, size matters, but more important than size is growth rates. This is the growth rate over that period of time for all these companies. You can see, our ideas and our platform, it's working out in the market. Our growth rates are showing that the market is coming very rapidly to Palo Alto Networks. The most interesting thing about this chart when I looked at it before was it looks to me like we're on a fast trajectory to be number one, just mathematically, when you take a look at this, given our size today and the relative growth rates. We're playing for the marbles here. We intend to be the biggest provider here. Size is great. There's lots of ways to measure success.

Back to what I said before is we think we've got the opportunity, because of the time we live in and the platform approach that I think is obviously working in the market, to capture more market share than anybody's ever had here before. Our size and growth rates would suggest that we're on a fast trajectory to be the number one provider here over time. That's what we're playing for. We're very focused on that. Back where I started. At a glance, we think we've got a great time to be Palo Alto Networks. It's not fleeting. Security's not going away. The anxiety about security, I don't mean that in a good way, but if you're a provider, the bad news is the good news. This is going up, and it's going to be around a long time.

We think we've got a time in which a platform that fundamentally changes the math, it changes the dynamics of what's happening in the market, is absolutely critical, and we believe we've got that platform. It's a great business model as well. High revenue growth, hybrid SaaS model, generating lots of deferred, lots of cash flow, and increasing the leverage at times. We are at a time in this market opportunity, not only are we growing really well, but we're increasing the bottom line as well too, because we think that's ultimately what companies are supposed to do. We definitely want to prove that out from a model perspective. I'll wrap up with that. Thank you very much again for your interest, for being here. We really appreciate it.

I know it's a lot to get people to come on planes and do something like this, so we use your time very efficiently. Make sure you stay for all of Ignite if you possibly can. We will end today with Q&A. If you hold your questions, we won't do them after every one just to break up the flow, but we'll definitely get to Q&A at the end of the day and reserve time for that. With that, let me introduce Nir, who I think you all know is our CTO and founder. Thanks.

Nir Zuk
CTO and Founder, Palo Alto Networks

Hey. Thank you, Mark. As Mark said in the introduction, what I want to talk about is the platform, and what is the platform, why you need the platform to secure networks, and why is the platform going to win. To start with, imagine this scenario. Imagine the Secretary of Homeland Security coming out with a statement basically saying, "We have determined that we cannot stop the terrorists. They are going to succeed, and therefore, we're going to shift all our budget into crime scene cleanup." This is what's going to happen in the streets of America if that happens. Government, go do your job. Your job is to protect us, not to clean up our malls after someone did something there. This is kind of what we're seeing in the industry today.

What we're seeing is firewall vendors Firewall helper vendors coming out and saying, "We've lost to the bad guys. They've won. You should focus on detecting the attacks as quickly as you can and then remediating from them." That's what we're seeing. The question is, why? Why is that what we're seeing from our competitors? Why are our competitors trying to convince the market that you can't stop attacks, all you can do is detect them, we're going to give you the best detection. We're going to use big data to detect your attacks, we're going to provide you incident response services to clean it up. I really think it depends who you are. Look, everybody can detect attacks, okay? Some vendors detect attacks better than others, but let's assume that everybody can detect attacks, which is probably the case.

The biggest question is, what are you going to do when you detect an attack? It really depends on who you are, right? Starting here from the right, if you are in the CSI business, meaning you wait for someone to call 911 and report that there is a body, your job is to come in and figure out who attacked you and why you're being attacked, what is it that they stole from you, that's what you're going to do, right?

You're going to wait for one of your customers to find out or to receive a call from the credit card company, credit card issuer, the credit card issuer is going to tell them, "Look, we've seen hundreds of thousands of people that shopped with you having their credit card number compromised, you are the common denominator to all of them, maybe someone stole credit card numbers from you." There, you're going to call CSI, you all know who CSI in our business is. You're going to call CSI, they're going to come in and say, "Oh yeah, they stole credit card numbers from you, $70 million of them," it's kind of too late. If that's who you are, that's the best you can do.

You can be like Inspector Clouseau over there from "The Pink Panther," who sometimes is really, really, really lucky at stopping the bad guys, that's if you're in the right place at the right time, right? If you have an IPS, for example, the IPS somehow had a signature for an attack because the attacker decided to use an exploit that everybody knows about, sometimes you'll get really, really lucky, you'll be able to stop the attack, usually not. Usually, you'll have to call CSI to come in and clean up the scene for you. You can also try to be Jack Bauer, right? You can try and go and stop each and every attack before it happens and do whatever it takes. You can use traditional and non-traditional methods to go and stop the attack, actually stop them.

I'm not saying that we can stop all attacks. I don't think we can stop all attacks. I don't think the Department of Homeland Security can stop all attacks. What I think we can do, and Mark talked about it, is we can make it so expensive to attack by stopping the vast majority of attacks, that it won't make financial sense for the attacker to attack you, okay. This is really our goal. Our goal is to increase the price of an attack to a point where it just doesn't make sense to attack. The only way to do that is to be Jack Bauer, right, is to go and stop the attacks, whatever it takes, before the attack happens. The question is, why isn't anyone there? Why isn't anyone talking about it?

Why are we seeing our competitors coming out and saying, "No, you can't do it. All you can do is detect and remediate, detect and clean up. Sometimes we'll be lucky." I think that the answer to that is that in order to stop attacks, you have to be in the position to stop an attack, right. You have to be able to stop attacks, right. David Caruso from "CSI: Miami" is not in a position to stop attacks. He's always being called after the attack has already happened. Jack Bauer is in a position to stop attack. In our world, in order to stop an attack, first you have to be everywhere, okay. Sometimes the attack will happen, or you'll be able to detect the attack, or you'll be able to prevent the attack at the perimeter.

Sometimes you'll be able to do it at the data center for north to south traffic. Sometimes you'll be able to do it in the data center for east to west traffic. Sometimes the place to detect the attack and to stop it will be in the branch office. By the way, you don't detect and prevent attack at the same places. Sometimes you'll detect it in one place, by the time you've detected it, some time has passed, and you have to stop it somewhere else where the attacker is right now. Sometimes the right place to detect attack or to prevent the attack is on the endpoint, and sometimes it's in a virtual data center, and sometimes it's on Amazon, and sometimes it's in a SaaS application the attacker was going after.

The bottom line is you have to be everywhere in order to stop the attack. If you aren't anywhere, you won't be able to detect all attacks, and certainly, you won't be able to stop all attacks. You have to be everywhere, and you have to be there all the time, which means you have to be the firewall, and you have to be the endpoint. The only network device that is everywhere, meaning in all these different places that I talked about, and is in a position to stop attacks, is the firewall. Other things are either not in a position to stop attack because they just listen to the network, they're not running in line, or they aren't anywhere, or the most common case is they are both. There are devices that listen to the traffic, and they are just in few select locations.

They're not everywhere that you need to be. Of course, you need to be on the endpoint because that's where the attacks actually happen, and some of the steps of the attack, Lee will talk about it later, happen on the endpoint. If you want to stop an attack, and by the time you know about the attack, the attack happens to be on the endpoint, you have to be on the endpoint to stop it, which I think really explains why many of the competitors out there aren't even saying that you can stop attacks. The reason they don't talk about stopping attacks is because they know that they're not in a position to stop attacks. The world really is broken down to three different companies, okay? There are the firewall helpers. Their job is to sit behind the firewall and help the firewall do its job.

Every few year, we have a new firewall helper that everybody here likes, and likes to buy, likes to cover, likes to recommend the stock, and so on. Then a few years later, they disappear, right? In the mid '90s, it was ISS, IDS s oftware, right? Everybody loved ISS. Their stock were flying high, they disappeared, right? Then it was URL filtering, right? Websense. Then it was proxies, Blue Coat, now it's APTs, right? The reason these companies come and the reason these companies go is because all they can do is sit behind the firewall and help it detecting attacks. They can't stop attacks. Because they cannot stop attacks and because ultimately what the customer wants is to stop attacks, they don't want CSI to come in and clean up the attack.

They want Jack Bauer to go and stop attacks for them, those companies disappear. Unfortunately for these companies is that they were dealt a really, really bad hand because they don't have a firewall. That's the best they can do. That's why the CEO of APT companies would come out and say, "You cannot stop attacks, sorry. All you can do is detect them, and then you can call the Ghostbusters or CSI to come in and clean up the attack." That's the hand that they were dealt, okay? That's what they're going to preach. That doesn't help anyone, okay? Detecting the attack after the fact and bringing in CSI to clean up the scene doesn't help anyone, which is why we think that, like history shows, those kind of companies will come and will go. What about the traditional firewall vendors, right?

The Check Points of the world. What about the UTM vendors, the application, excuse me, the UTM vendors, the blade vendors, there are different names for that. The problem that they have is that they have lemons, okay? Those lemons can't make lemonade because what they did is they took a bunch of different components, usually from different places, and stuck them together in a box on top of a firewall. Again, some call it UTM, some call it a blade architecture, hardware blades, software blades, software UTM modules, hardware UTM modules. The common thing to all of these is that these are separate products that were stuck together or were crammed together into a single device. I'll show you now why they can't stop attacks. They can barely detect them, and they cannot stop them. The reasons for that, let's look at one example, okay?

All the UTM blade vendors claim that they have a sandbox today, and they do. They have zero market share, but they have a sandbox. The reason they have a zero market share is not because the sandbox doesn't work, it's because it's useless. The reason it's useless is because it's UTM, or it's a blade architecture. Let's say that your sandbox has just detected a piece of malware trying to go through the network. You might think that this is where your problem ends, "Hey, I just detected the malware." No, this is where your problem actually begins. The reason this is the moment your problem actually starts is because of what you need to do when that malware came in. Usually, at the time you see the log that tells you that the malware just came in, it's too late.

Let's say that it's not too late. Let's say that the attack is still going on, and you have an opportunity to stop it. Now, the malware is already in. You can't stop it there. There is another phase the attack is currently running, and you're a firewall, right? I mean, you're a UTM, you're a firewall, you are everywhere. You have an opportunity to stop it. What you need to do at that point is to take that piece of malware you just found and create prevention mechanisms from it, right? You need to take the piece of malware and create anti-malware signature from it and distribute those signatures to all your network and all your endpoints.

You want to take that piece of malware, look for the command and control connection or the probing connection that the malware generates when it's trying to connect back to the bad guy, and distribute those command and control signatures to your IPSs. You want to take this malware, look at all the domains that the malware is trying to resolve to figure out where the bad guy is, and send those domains to your firewall so that your firewalls can block these domains, and your firewall can block any attempt to resolve these domains. In many cases, in almost all cases, the malware will be using HTTPS to communicate with the bad guy, to download more pieces of the malware, what we call droppers.

Since HTTPS is involved, URLs are involved, you want to take those URLs that are involved and add them to your URL filtering solution. Well, if you're a blade vendor or if you're a UTM vendor, you can't do it because your anti-malware comes from maybe Kaspersky, and your URL filtering comes from Websense. Your IPS is something that you bought a long, long time ago, and nobody knows how it works, and your firewall is completely separate from it, and domains, you don't deal with domains. You leave that to some other vendor, you can't do it. Your customers end up having to do it manually.

Your customers have to take the malware and do it manually, which takes many, many hours, if not days, for each malware, which means that your customers need to hire armies of security experts and run them all the time. It just doesn't work, so nobody does that, okay? A UTM vendor can't do anything about it. They have lemons. They have a bunch of different products from different vendors that they just crammed together into a single box. How can they do that? They can't. They can't stop the attack. Even though they know about the attack, they just found a piece of malware, they're in the right position to stop it, they don't have this thing that allows them to take the malware and reprogram the infrastructure to stop the malware. They can't do it. That's what platforms are supposed to do, okay?

When you have a platform, a platform can take a piece of something new you just discovered somewhere. I gave you an example of a sandbox discovering a new piece of malware. It can be a URL filtering solution discovering a new website that's infected. It can be many different things, but a platform allows you, once you discover something bad, to immediately take it and convert it into prevention mechanisms, and distribute those prevention mechanisms to all your endpoints and all your networks in order to stop the attack while it's happening, okay? That's what platforms do. How do they do it? That's the third approach. That's the Palo Alto Networks approach. How do you do this? There are really five steps that the platform has to take in order to stop attacks.

The first thing that the platform does, That's probably the only common thing here that other vendors do as well, is to stop known threats. We've been stopping known threats forever. All our competitors have been focused on stopping known threats forever. If you know about it, you should stop it. Okay? Now comes the unique part to Palo Alto Networks, the part that I just haven't seen anywhere else. That part talks about the next step is collect information from both the network and the endpoint into a central location, we call it a threat intelligence cloud, so that there you can find new attacks. What information do we collect? As much as we can, as much as our customers are willing to send to us. Today, they're sending to us all the files on the network. We call that WildFire.

They send all the URLs that their end users are accessing. We call that PAN-DB or our URL filtering service. We ask our customers to send DNS information to us, every release of our product, we have more and more things that we're asking our customers to send to us. They send it from the endpoint, they send it from the network, all to a central location where that information can be processed. That's really step number 3, I'm going to talk more about step number 3 later. Step number 3 is this magic thing that takes this information and somehow, in all that information, detects things that you've never seen before. It sounds weird. How do you take information, and in that information, you detect attacks that you've never heard about before? I'll show you how. There are multiple ways of doing it.

I'll show you at least four of the ways that we're using for that. Once you detect the attacks, once you detect those attacks that you've never seen before, you just detected a new attack, a new threat. What you want to do with it is to convert it to all those different prevention mechanisms I talked about before and very quickly distribute them, not just to the customer where the information that led you to discovering the attack came from, but to your entire customer base. You want to disseminate those prevention mechanisms to everyone, to your entire customer base. Then the next step is to stop this attack that was unknown until a few minutes ago. Now it's a known attack. It might be in a different phase.

You might have discovered it in phase number 3 of the attack. Now the attack is in phase number 7. Lee Klarich will talk after me about those different phases. Since you're the firewall and you're the endpoint and you're sitting everywhere, and you have all these different prevention mechanisms, and you pre-reprogram them, you have a good chance of stopping the attack at phase number 7 or 8 or 9. If the attack is at phase number 7, in my example. This is really something that's unique to Palo Alto Networks. You can't get that in UTM. You cannot get it in a blade architecture. You can't get it, of course, if you're a firewall helper.

To do this, you have to be the firewall, you have to be the endpoint, you have to be deployed everywhere, and you need to have full control of your entire technology. You need to have what we call the single-pass engine. You need a single engine that you can reprogram with all those different things, so you don't have to wait for Kaspersky or Websense or any of your partners to reprogram their prevention mechanisms in order for you to be able to stop them. You need to do what Palo Alto Networks has been doing for the last nine years, been selling for the last seven and a half years in order to do that. Nobody does that. Nobody has the technology to do it.

They're all stuck with an old firewall and a bunch of blades sitting on top of the firewall that don't even talk to each other. That's why we're winning. That's why we're winning in the market, and that's why platforms win in the market. The next thing I want to do in the last eight minutes I've left is to talk about step number 3, which is how do you detect things that you haven't seen before? How do you know that something that came in that you have no information about is bad? Well, there are multiple ways of doing it. On the left, URL filtering, for example, is a good way to do it.

If you provide the URL filtering service to your customers, that means that every time an end user at any of these customers visits a website that you've never seen before, the firewall has to query the cloud and say, "I've never seen this URL before. What is it?" You do it usually for HR reasons. The answer that you're expecting is, it's pornographic content, it's banking, it's healthcare, it's gambling, it's weapons related, then you make an HR decision whether to allow it or not. I don't allow my employees to go to pornographic websites, to weapons, and gambling-related websites. I allow them to go to financial services and healthcare. As a side effect of knowing about all these previously unknown websites, is that you can have automated processes go and visit that website and check whether it's good or bad. How do you do it?

With a sandbox, with other ways. The bottom line is, whenever a new website pops up and any of our end users, any of the end users of any of our customers that are using our URL filtering service go there, we know very quickly whether that website is good or bad. If it's bad, we'll immediately reprogram all the networks and all the endpoints of all our customers that subscribe to these services in order to stop a potential attack that might come from that website. We'll even, of course, program them to block any access to that website if that access hasn't happened yet. The second way in the cloud to detect attacks that you've never known about before is sandboxing. Not going to get too much into it. In the sandbox, you take whatever it is, a document, an executable, you open it.

If it does something bad, then it's bad. If it doesn't do anything bad, then it's probably good. The third approach in the cloud is by collecting domain names from our customers. We can correlate those domain names that we've never seen before to domain names that we've seen before that we know are bad. We see where they point to, when they were created, and other things, we can very quickly determine they are malware domains, even though we've never seen them before. There are other things that we do in the cloud that are similar to these in order to use the information we collect from our entire customer base to detect things we haven't known about before.

Again, the important thing that is unique to Palo Alto Networks is that extremely quickly, that information turns into prevention mechanisms that are distributed to all our customers, to all their networks and all their endpoints, such that if an attack is going on right now, we can stop it at whatever phase it is at this moment. Lee will talk after me about an exciting new thing that we're doing, which is very big for us. That thing has to do with. Okay, he'll explain to you what the direct customer benefit of the thing is. I don't want to expose too much. Given that, remember, our goal is to make attacks expensive. Again, our goal is not to stop attacks. If someone is very persistent, they'll eventually find a way to attack, okay? That's a given.

The question is how much money they'll have to spend on the way, and if the amount of money they have to spend on the way is so high that it makes the attack economically unreasonable, they'll just move somewhere else, right? We think that one of the effective ways to do it has to do with the fact that attackers are lazy. Bad guys, in general, are lazy, right? I mean, the reason people become criminals is because they're lazy. If they weren't lazy, they would doing what we're doing, which is work. Because they're lazy, they're criminals. They're trying to find shortcuts to attack you. The nice thing about it is that what they tend to do because they're lazy, at least in our world, in our cybersecurity world, is to take something that was done before and modify it a little bit.

Meaning it's extremely rare that an adversary would be developing a new piece of malware from scratch, deploying a new command & control infrastructure from scratch, and doing everything from scratch. Number one, they're lazy, and number two, it's extremely expensive to do that. What they do is they buy toolkits on the internet, either the internet or the dark net, for developing malware, for developing exploits. They take a piece of malware that was used in the past, that they modified, either used by them or used by someone else. They modify or they use something that's already existing. If we can get them to a point where they have to develop everything from scratch with each and every attack, and remember, they need many attacks in order to be successful against a specific target, then we win. The question is, how do we do that, okay?

How do we force them to do everything again from scratch every time they want to attack someone? The answer is, I hate the term big data, but we'll use the term big data here. The answer is big data. Big data is something that's been used too much. Everybody that has a huge database claims that they're doing big data. That's not big data. In reality, big data is not having huge database. In reality, big data is about having a lot of information about what's good and what's bad, and determining, giving something new, whether it's good or bad based on that information. Right? Your car manufacturers are doing it today. Your car manufacturers are collecting a lot of information about your cars. It's easy for them to collect information about problems, right?

If you drive your car into a dealer and you say, "My engine blew up," then they can read all the sensor information, all the log, and send it to the car manufacturer, and the car manufacturer can see, okay, this is what happened before the engine blew up. That's useful, but it's much more useful if the car manufacturer also get a lot of information of what happens when the engine doesn't blow up. That gives them more information about what is it that was leading to the engine blowing up. We're using it in cancer research today, right? What they do is they take genome sequence of sick people, they take the genome sequence of healthy people, and they find genes or whatever that is causing this disease.

They don't know how the gene is causing the disease, they know that if they see it in a lot of sick people and they don't see it in any healthy people, then it might be a gene that first we can use to identify the propensity for having the disease. Number two, maybe through gene therapy, we can cure the disease, okay? The same thing can be done in security. If we collect enough good things and we collect enough bad things, I believe that given a new thing, we can very quickly tell whether it's something that we've seen in the past. Meaning whether whatever it is based on something that was done in the past.

If we can do that, we can force the bad guys to develop a new thing, something new from scratch every time they go to attack us, because if they're going to reuse something that was used in the past, we'll know about it immediately. To do that, as I explained, you have to collect not just the bad things, which a lot of vendors out there collect, right? I mean, if you're an APT vendor today, your customers will be sending you all the bad stuff they find on the networks. It's as important to collect all the good things on their network, the known malware, so you can very quickly compare the known malware to the malware, given a new thing, and know whether it's an attack or not.

Lee will talk more about it in his segment, and much more about it, I think, during the Ignite conference. If we do that, I'll reuse the slide that Mark was using, we can get to a point where we can drive the cost of a successful attack high and drive the number of successful attacks down. To do that, you need to be a platform, okay? You need to do the things I talked about before. You need to be the firewall, because you have to be everywhere on a network. You need to be the endpoint. You need to have the single-pass engine. You need to control all the aspects of your technology, so that if you detect something bad with one technology, you can reprogram the entire network and the entire endpoint, the entire set of endpoints, to stop that thing.

That's a true platform. I don't know about any other company that has that. I truly believe that there is an opportunity for someone in our space to take a market share that you've never seen before anyone taking in this industry, of course, for that, you need to have a platform. If you can show customers that you can stop attacks, you can make it so expensive to attack them, as Mark said, we certainly intend to do that. Thank you very much. Next will be Lee, our Vice President of Product Management.

Speaker 17

Thank you.

Nir Zuk
CTO and Founder, Palo Alto Networks

Who is going to tell you what we actually do.

Lee Klarich
Senior VP of Product Management, Palo Alto Networks

All right. Yes, I always have the pleasure of following Nir and getting to explain the things that he says. Today is no different. In fact, every day of my life is spent doing this. You heard both Mark and Nir talk about prevention, which obviously we believe very much in as a company and from a product team perspective is what we wake up every day thinking about how we get better and better at that. You heard Nir explain why a platform is required to do that.

What I would like to do today is to basically go 1 level deeper and describe a little bit more about how we do that at all stages of the platform, talk about some of the unique ways in which we approach this, and along the way, do what Mark was talking about of getting to give you a preview of a new service that we're announcing to our customers this week at Ignite, talking about how we are constantly raising the bar in our prevention capabilities, and finally, talk about how we're expanding the ecosystem. All right? To get started, I want to just give you just a quick refresher on something we've talked to you about before, which is the attack life cycle.

I'm not going to go through all the details of this, it is important as a backdrop for understanding our approach. At a high level, there's a couple of important points that I want to make about the attack life cycle itself. The first thing is, an attacker doesn't just have to do one thing successfully in order to carry out a successful attack. The attacker has to carry out a number of steps. What I've shown here is eight different steps, although sometimes it might be more or less. Typically, it's a significant number of steps, all of which have to be successful for the overall attack to be successful. The second key thing to understand about this attack life cycle is that the attacker does have some flexibility as to how they combine things together.

They don't necessarily have to go through steps one through eight in order. They can do them in slightly different orders in some cases. In some cases, they'll actually repeat steps multiple times in order to avoid another step. Well, why are those two things so important? The first thing is it tells us that we have to do prevention at all stages of the attack. Why? Because if we only focused on one, the attacker's going to find a way to combine other steps to get around that one prevention technique, and you will not be able to prevent those attacks. First and foremost, you have to be doing prevention everywhere. The second thing it tells us is there's a very interesting compounding benefit of doing prevention at every step.

What I mean by that, imagine if at step one, we could prevent 90% of exploits. 90%. Stop 90, 10 go through from a percentage perspective. That wouldn't be great, actually. That's a lot of attacks that are getting through. Well, what if in the second step we could do 90% prevention as well? Well, because of the compounding, the benefit of doing 90% twice means you actually get to stop about 99% of the attacks. Imagine you keep doing that across this entire attack life cycle. The compounding effect is amazing at raising the prevention rates. If we can do prevention everywhere we make the prevention better, that is the prevention opportunity that the attack life cycle gives us. Okay? What does that mean? Well, we built a platform for all stages of the attack life cycle, quite simply.

What do we do with that platform? First and foremost, we do prevention. Everything we do focuses on how we not only detect, but we prevent everything that we can. This is across the different three elements of the platform, but even within features of a element of the platform, we're constantly focused on how we can do prevention. Second, we've come to understand that tightly integrating these different functions together is one of the best ways to raise that prevention capability. As Nir talked about with WildFire doesn't just make us better at malware prevention. WildFire makes us better at URL filtering. It makes us better at IPS. It makes us better at blocking known bad domains. It makes the rest of the platform smarter as well. We're constantly looking at how we can integrate and automate these capabilities together.

Lastly, we built the platform to apply to all applications, all users, all devices, all the time. The reason this is so important is because attackers will find the weakest entry point into a network. They're not going to attack the hardest point. They're going to attack the weakest point. If the platform doesn't apply to every stage of the attack life cycle, the attacker will find those weak spots, and they will take advantage of it. Okay. Now what I'd like to do is walk through each of these three aspects of our platform, go into a little more detail about what we do and why it's unique, and along the way, as I said, share with you new services, improvements to existing services, and extending the ecosystem. Let's start at the top. Let's start with the Threat Intelligence Cloud.

Quite simply, what this does is it ingests information as much as possible. We use this information to discover new threats, then as rapidly as possible, we disseminate that information back down to both the network and the endpoint to do prevention. In its simplest form, that is what the Threat Intelligence Cloud does. This is one of the areas where we've shown great execution at being able to extend the capabilities of the platform in a highly automated, integrated way. One of the great examples of how we've done this is WildFire. WildFire launched a little over three years ago and went from basically no customers using it to today, 5,000+ customers using WildFire. What it basically does is it is the service that collects as much information as we can. It started with executables.

We added a bunch of other file types. We've added URLs to it. There's a whole bunch of analysis in the cloud itself in order to do what Nir described as, if it does something bad, it's bad. It's a little more complicated than that or sophisticated than that, but that's basically what it does. When it finds something bad, it quickly reprograms that infrastructure, both the network security and endpoint security infrastructure. That's what WildFire does. Aside from the business success with WildFire, from my perspective, even more importantly is the success of WildFire in terms of its technical capabilities. If I was standing here last year, I would have been talking about how great WildFire was scaling because we were able to see roughly 250,000-300,000 unique samples every day that we were analyzing inside of WildFire.

Which at the time actually seemed really great. Guess what? Over the last year, the processing capacity of WildFire and the amount of information we see every week has grown 1,500%. Last week, we analyzed well more than 20 million unique samples within WildFire. Unique, no duplication. Out of that, we discovered well more than 200,000 new unique pieces of malware. Of that, the majority of it, when we discovered it, nobody else had seen before. We were the first. We actually tracked that last metric over time, and we find that even after a week, most of the malware is still only discovered by us. WildFire is able to process a massive amount of information, find new targeted, unique threats that no one else has seen.

From the customer perspective of this, imagine trying to be an end user building out capacity to process 20 million samples every week. Imagine you somehow figured out how to get there, and you're looking at this curve thinking about what investment you need to make for the next year. It's not possible. We can do it because we're aggregating across the entire customer community. We can do it, and we can plan out for the next year, the next two years, the capacity we're going to need to be able to continue to process everything that we see from our customers very rapidly, find the threats, and disseminate the information to then prevent them and reprogram the infrastructure. We can do it because we're doing it for our entire customer base. In addition to that, there's another benefit that's probably even more important to our customers.

It's the network effect. Every time we add a new customer to WildFire, everybody else benefits. We don't just reprogram the infrastructure of the customer that sent us the malicious file to begin with, we reprogram everybody's infrastructure. I tell customers, "Whatever you send us, you're going to benefit from the 4,999 other customers using WildFire today, and they're going to benefit from you." Every time we add more customers, it adds to that ecosystem, it adds to the network effect. This is WildFire. One of the interesting things that WildFire has given us is a massive amount of data, as you can see. We asked ourselves the question, can we use this data to do something other than what WildFire was initially intended to do? Can we use this data to find the most important threats, the targeted threats, the advanced attacks?

Let me give you an example of what I mean by that. This is a real example. The only thing I've changed is the name of the companies. Company A is made up, obviously. Everything else actually is true here. Company A represents a fairly large enterprise in the U.S. that was somewhat recently breached very publicly, very bad. We were able to get a copy of a piece of malware that used in that attack. We weren't on the network, but we traded and shared and things like that. We got a copy of it. We ran it in WildFire. WildFire did exactly what we would expect it to do. It identified it as malware.

What you see in the little dots there, these are just a handful of what is actually a pretty long list of what we call artifacts. Artifacts are the things that we see when we run a file in WildFire. We analyze, we collect everything that's unique about that, and we store it. This is just a sample of what we would see. This particular piece of malware is basically a fake VPN client. Somebody tricked the user into downloading it, thinking it was a real VPN client. It actually was a piece of malware, compromised the machine. The attacker had control of the machine. They used that compromise to then move laterally within the environment to steal a whole bunch of data. That's basically how this attack works, and that adversary down there did a lot of damage with this.

Interestingly enough, when we were looking at that, we were also looking at a different company, different industry, different piece of malware, slightly different set of information when we ran that particular piece of malware. Do you spot the commonality? Both of these files, when you run them, create this installer.exe in the temp folder, and specifically temp MicroVPN installer.exe. You may wonder, was that interesting? Turns out this is actually highly unique. Across the hundreds of millions of good and bad files that we've ever seen, that is unique. How do we know it? We know it because we store 30 billion artifacts like these from all the files we've ever analyzed. We know whether they're associated with good or bad files, and we can very quickly correlate this information.

We went out and talked to our customers about this and said, "Imagine we could do this." Every single one said, "That would be fantastic." You know what we can do with this information? We know a lot about company A and the breach that happened. Because of the association, we now know a whole bunch about company B that we otherwise wouldn't have known. The malware in company B by itself is malware, but when we can tie it back to the malware used in the company A breach, all of a sudden we know a whole lot of information about the adversary, what they're after, how bad they are, how sophisticated they are. All of our customers said, "That would be really great. Can you automate that?" Right? Imagine trying to do this manually. That's what we did.

This week at Ignite, we're announcing a new service called AutoFocus. This service will take all of the information we have through WildFire, through our URL filtering PAN-DB service, through our threat prevention service, through feeds that we get from other sources, combine that into one location, do all the correlation, automate a lot of the processes that you just saw me walk through manually there in order to find the targeted and unique events that are happening on our customer networks, in order to prioritize the stuff that really matters separate from all of the noise. While we do that, there's actually interesting side benefits to this. We also get to provide our customers with context around these interesting indicators of compromise. Very quickly, indicators of compromise are typically IP addresses, URLs.

They're things that the FBI issues and says, "If you see this IP address, it's bad." They don't tell you anything else. Imagine we could provide our customers with, oh, that indicator of compromise is associated with this adversary. We typically see it in these verticals. We typically see it with these other things as well that you might want to look for, right? Build the context around these other pieces of information, and that would include incidents as well, providing the context to understand how all of this works. This is AutoFocus. Just to show you this in a little more detail, let me walk through just a very quick demo so you can kind of get a feel for what the customer's going to see. This is a sample. This is actually the malware used in the Target breach.

What you'll see is when I click on the connection activity, the first thing that is highly unique about this particular piece of malware is that it connects to private IP addresses. Private IP addresses are addresses that you can't get to across the internet. Why is that interesting? It means the attacker was already in the network, and this malware was designed to connect to a server that they already knew where it was and what IP address it had. In addition to the private IP addresses they connected to, we noticed a very unique service activity, process creation, that if you look very closely, has only been seen in two pieces of malware and has never been seen in any good file that we've ever analyzed, meaning it's highly unique to this particular attack.

What we're able to do with that is we're able to create tags of that information, and those tags are then used to identify any other piece of malware or file that carries that same process activity. Anytime we see another piece of malware that has that same process, we can immediately correlate it back to the Target breach and know that it's related to whoever launched that attack. Just to contrast that, commodity malware is also interesting to be able to identify and segment off and say, "That's commodity. I know what to do with it." In this particular demo, we'll search for the Kelihos malware, which is a very prevalent malware family, as you'll see in a second. It's tagged, which makes it easy to find, pulls up the samples, and you can already see 1.9 million samples.

These are unique samples, by the way, that's how many different variants of this single piece of malware exist in the world. If you look at the statistics, the thing that's really obvious about this is it's everywhere. It's everywhere from a time perspective. It's everywhere from an industry perspective. It's everywhere from a global perspective, as you'll see in the map in a second. That basically gives you the two ends of the spectrum. What we're able to do with this platform, as I mentioned before, though, is everything that I just talked about can be uniquely tagged by our threat researchers, by our Unit 42 organization, but also our customers can do the same thing.

Very much like WildFire, there is a community and network effect that we will be able to build around this service where our customers, their security intelligence operators, will be able to actually come in and add to the intelligence we have within this platform and share it with our other customers. Because of that, and very much like WildFire, we will initiate this access to the service as a community access, meaning we'll open it up for free to our customers for a period of time in building that initial network effect. Then from there, we will move to a new service we'll be selling this fall. Okay. Fantastic. That's the new extension to the security platform, the new service offering. I now want to talk about how we've continued to focus on enhancing the prevention capabilities in the platform.

For this, I'll talk about what we're doing from an advanced endpoint protection with Traps. Traps is obviously critical because several of the attack lifecycle steps happen on the endpoint itself, so endpoint security is very important. Second, it's primarily important because we've built new technologies that really focus on new ways of doing prevention, not the old stuff that clearly doesn't work, and of course, tightly integrated with a threat intelligence cloud. To talk about Traps, I want to take a quick step back because I often get questions, what's an exploit and what's malware? This is my attempt to simplify it down to the core of it. An exploit is basically the use of software vulnerabilities to run the attacker's code. Usually, the attacker's code in these cases is relatively small, designed to perform just a few tasks.

Often, the task is connect to the attacker and give the attacker full control. As an example, probably the most recognized exploit used in a breach is the RSA attack. That exploit was delivered as part of an Excel file. When the user opened up the Excel file, it looked like a normal Excel file. What they didn't realize was in the background, the exploit was compromising the machine and giving the attacker full control of their machine, which was then used to move laterally within the environment, get source code, exfiltrate it. That's an exploit. Exploits can be delivered typically in files or over the web. Malware is a little bit different. It's basically the full application, does lots of bad things, whatever the attacker's programmed the malware to be able to do. Malware is what we hear more about.

It's more prevalent from a volume perspective, and it's like the example I showed you with Target. Malware, actually, multiple pieces of malware were used to carry out the Target breach. Why is this important? It's important because the legacy approach to endpoint security, pretty much 100% of the legacy approach has been focused on 50% of the problem. It's been focused on malware prevention, not the exploit prevention. Even the 50% that it focuses on, it's not very good. I don't have to tell you that because the vendors that actually are in that space have told you that publicly. A year ago, one of the major vendors in this space said that they thought they could prevent 40% of malware. I actually think they might have been being generous, but it's okay. 40% is not good. There has to be something better, and that's Traps.

First of all, we focus on both exploits and malware. Both are important, not just one. As you know, with exploits, we focus on blocking the exploit techniques, which allows us to prevent even attacks we have no prior knowledge of. Malware has primarily been WildFire integration, which is a great way to prevent malware and to find new malware that we haven't seen before. This week, we're sharing with our customers the latest Traps release, where we're extending both of these capabilities. Exploit prevention is we're adding three new exploit prevention modules. These modules are designed to prevent techniques that we are starting to see in development that we think somewhere down the road, attackers will actually start to weaponize, so we're building the techniques in advance of these techniques actually being used in the wild.

Exactly as we told you we'd be doing when we first brought the product to market. On the malware side, we're enhancing the WildFire integration to better handle unknown applications, in addition to known bad and known good. We're adding execution restrictions, which allow us to only allow files to be run from known good locations, signed applications as well, basically reducing the surface area of attack. Finally, we're adding the first of behavior-based detection and prevention mechanisms on the malware side. Think of it like the exploit techniques on the exploit side, but for malware. We're adding the first of these modules that focus on the actual techniques without regard to the actual file itself. Building up and enhancing the prevention capabilities, and finally, extending the ecosystem around this platform.

The ecosystem is very important because it helps our customers leverage the full power of the platform and tie it into other tools that they have. We have this with partners like Splunk and Aruba, extending that ecosystem simply makes our platform more permeable and spread across their network more easily. I'll talk about that in the context of the next-gen firewall. First, I want to reiterate something, a couple of very important points about the next-gen firewall. First, to actually do security, you have to do security, which sounds like a really obvious statement. It may be surprising to you that many of the network security products, particularly firewalls, actually don't have core competency in security. Nir talked about this, actually. Many of the security techniques are outsourced. They're OEM'd, but they're not core competency.

Second, in addition to doing the things of preventing known attacks, detecting unknown, and that loop that Nir talked about, the first thing you actually have to do is you have to reduce the surface area of attack. This is really important, and it's a concept lost on a lot of people. The reason it's important is because if you don't do this, the attacker can evade steps 2 and 3 very easily. If you allow me to run Tor across your network, I can do anything I want to because Tor uses proprietary encryption. Do you allow me to run UltraSurf? Same thing. Do you allow me to run encrypted BitTorrent? Same thing. There's a set of applications that are just bad, that use proprietary encryption to bypass all of the normal network security capabilities.

The first thing you have to do from a security perspective is you have to reduce the surface area of attack. You have to limit what applications your users are allowed to use to just those applications the business actually needs. Once you do that, you then obviously have to safely enable them, and part of that for things like SSL and SSH includes decrypting them, which is something that Palo Alto Networks was really the first network security vendor to do. This is important because when you decrypt SSL, you then apply all of the same network security functions to that traffic that you apply to anything that's not encrypted. That has to be done. If you want to have any hope of doing decent prevention from a network security perspective, you have to do that. These are all hard security tasks to do.

Second thing you have to do is you have to do it in the firewall. You have to do it in the firewall for two very simple reasons. You have to do it in the firewall because prevention has to be in line. There is no form of prevention that's not done in line. Second, it has to be the firewall because the firewall is the only device that is deployed pervasively throughout the infrastructure, at the data center, at the internet gateway, at the branch office, in front of cloud applications. The combination is what's really important here. The combination is what a next-gen firewall has to be able to do. I want to focus on the last aspect because it's very important. This idea that the next-gen firewall has to apply to all traffic. There's a couple of trends that are very important.

First is cloud computing or virtualization. As applications have moved from static servers to dynamic virtualized servers within the private cloud, as they then move up into the public cloud as well, in some cases, move into SaaS environments, the common thing about that is the application is moving. In order to provide the same network security capabilities to those applications, you have to move with it. From a private cloud perspective, that's why the NSX integration with VMware is so important. It's how we move to the east-west visibility and security within that data center. It's why our integration with Amazon and other public cloud providers is so important, because when the application moves up into the cloud, the same consistent security has to move with it.

When the application moves into a SaaS offering, we have to apply the same security capabilities to that traffic as well. Similarly, from a mobility perspective, you have applications moving off the network, but you have users moving off the network too. Users taking laptops and traveling. All of you are either on a laptop or a mobile device right now. In either case, you're not actually on your corporate network receiving your normal corporate network security capabilities, but you should be. The same network security functionality should apply to all users on all devices all the time, because otherwise, you lose several of those steps in the attack life cycle where you have a prevention opportunity. The network security has to follow the user. This is why GlobalProtect is so important. This is why granular application segmentation on mobile devices is so important.

This is why it's so important to secure Android devices from the malware that exists out there that we're seeing every day of every week. It's in this last point where we have a new technical integration partnership where we're extending the ecosystem with AirWatch. AirWatch is the leader in enterprise mobility management. Over 15,000 customers use them to manage their mobile devices. We have great mobile security capabilities that need to be applied to all of these mobile devices. The technical integration that we'll have with them will allow us to leverage their management capabilities with our security capabilities to extend the security, the full power of our platform to these devices. They'll be able to manage their GlobalProtect app. They'll be able to share context from these mobile devices with us. We have more intelligent security policies applied to mobile devices.

Lastly, they'll be able to integrate directly into WildFire to detect and prevent new Android and mobile malware. This is a technical partnership that we'll be introducing to our customers this week that we expect to be available in our products the late summer timeframe. Okay. As I look ahead, there's a couple of very important things. First, the right platform, the right foundation. This is important because it allows us to build up new capabilities. It allows us to enhance the prevention capabilities we have. It allows us to extend through the ecosystem partners. I believe we have a proven record of being able to execute on that very successfully in all areas. I'll remind you that we actually have a very strong pipeline of new capabilities that we're coming out with.

I shared with you the things that we're introducing to our customers this week, the pipeline for this year has never been stronger for new innovations, products, and software releases. With that, I'd like to say thank you, and we have a 10-minute break.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Yeah.

Lee Klarich
Senior VP of Product Management, Palo Alto Networks

Okay.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Please feel free. There are drinks and snacks out in the hallway. If you'll take about 10 minutes, we'll come in, and we'll resume the program. Thanks.

Lee Klarich
Senior VP of Product Management, Palo Alto Networks

Thank you.

[Break]

Speaker 17

Hold on. Hold on.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Is the microphone on?

Speaker 17

It's not on. Just the switch on the bottom. I don't know how that happened.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Here, stay. Sorry.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Hi there. Oh, much better. Okay. Thank you very much for coming back so quickly. We appreciate it. It's my pleasure to introduce Mark Anderson, our Senior Vice President in charge of sales and operations. Mark, take it away.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Thank you, Kelsey. Worldwide field operations team. Just for those of you who don't know, field operations at Palo Alto Networks is a combination of the worldwide field team, okay? The over 1,000 today men and women around the world that call on customers and support them, and the global customer support team, which is now 300 men and women around the world that man our five corporate

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Your mic doesn't work. Yeah, try that. There's Mark Anderson.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Sweet. Hey, hold on.

I think I Yeah. There you go. Okay. Jeez. All right. Let's see. I know some Irish tunes. Okay. Without question, I couldn't agree more with the characterization that Mark gave about this being the right time in history for our platform. We're definitely seeing that play out every day, and what I'm hoping to share with you today is what we're doing to take advantage of this incredible opportunity that we have in the marketplace. We saw this exact picture from Mark. We know for sure the breaches have been massive out there in the last year since I talked to you. Without question, we know that the legacy technology just isn't working, and the consequences, the public shame and humiliation that's coming from failure to protect your assets, your customer information, your intellectual property, has never been higher.

Without question, we're seeing that from time and time again. Even when President Obama came out to Silicon Valley to confer with CEOs of companies like American Express, Kaiser, PG&E on a panel. Oh, yes, and my boss, Mark McLaughlin, on that panel. Without a doubt, as a company, we've never been more relevant, and we're really working hard in the field to leverage that relevance to our partners and to our customers. We're seeing CISOs get more and more power out there. When I joined Palo Alto Networks three years ago, CISOs were off in a little department, usually in a different office, somewhere off-campus, doing their own thing. I see one of my friend CISOs back there. He might be a little bit different. We saw CISOs didn't have budget, and often they had a hard time imposing their will on the architecture.

Today, that's very different. CISOs have budget. They have money. They have teams. They're relevant. They're not only reporting to the audit committees, they're actually reporting to the boards themselves every quarter. The smart CISOs that we're seeing out there are imposing centralized architecture designs, and that, I'll tell you, is very good for Palo Alto Networks and our platform. If you're a point product, a box-selling company in that conga line of firewall helpers, that's bad news for you. For sure, this has been a massive driver from boards that we're seeing every day. Boards are imposing their will on executive leadership, and it's really playing out in terms of this do different leave behind architecture that follows the incident response teams that go in. They hang around for a couple of months, make a few $100,000 in services.

We're more and more becoming part of the leave behind architecture, that reference architecture that stays, that our sales teams are being trained on every day on how to build and grow and develop those relationships. Out there, we see three common traits, basic traits of every single breach that we're involved in. Number one, it's typically a port-based stateful inspection firewall that it happens upon. These things are either open or closed, and usually they're open. Number two, they're surrounded by firewall helpers. As Mark said, the conga line of devices like IDSs, IPSs, proxies, web gateways, even sandbox point devices out there don't just do it. They are disconnected. They're a massive pain in the ass to manage. They're expensive and complex. Number three, this just overwhelms the security teams. They're often understaffed anyway to begin with, and as I mentioned, it's very complex to manage.

You're managing your teams that need to be trained on three or four different command lines or user interfaces, three or four different maintenance contracts that you have to think of and manage renewals on. It's a mess, and obviously, it's contributing to the breaches that are happening out there. We're winning our outside share of these new customers. We're expanding our existing customers because we are the platform. We are that leave-behind reference architecture that can not only detect known and unknown things but can prevent them, as you've heard my esteemed colleagues mention earlier today. I can tell you that our partners around the world, our customers are obviously grooving off of this.

You're going to hear some data from myself and from Steffan on cohort information that really is proving this out more than just the revenues that you guys see and that we report every quarter. What we're doing about it is we're building, I think over the last three years, a go-to-market machine, and I really want to level set with you to understand what I mean by that. Think of the core of this team as quota-carrying heads. These are the men and women that are major account managers, global account managers, RSMs. Major account managers, global account managers, they manage a list of accounts, generally not more than 10 to 15 accounts, pretty much anywhere in the world. RSMs have the geography in a particular area, not including those global accounts.

For each one of these quota-carrying heads, we dedicate at the very least one systems engineer or sales engineer. You can see the ratio that we have here is actually 1.2 SEs to every quota-carrying head. That's because we've got specialists around the world that focus on malware, focus on endpoint technology. They're really the subject matter experts in the field that help our field sales teams close big deals. They transfer knowledge to these field sales teams, and they get involved in some of our biggest and most strategic customers. This is the sales team that we call the sales team, the account manager, and the SE. Oftentimes when I'm traveling in the field, I'll be in the passenger seat, and behind me in the back seat, of course, is always the SE.

Sales guy's always driving, typically a type A, and they're sitting there arguing about directions, just like my wife and I do, like an old married couple. Think of that sales team as an old married couple. Supporting that sales team is inside, typically centralized in one of our major offices in Plano, Texas, Santa Clara, California, in Amsterdam for the EMEA team, and Singapore and Tokyo for Asia-Pac, is as a ratio to that quota-carrying head, 6/10 of an inside salesperson. We don't just have inside salespeople that do everything. We've actually decided to specialize different functions that an inside salesperson can do. This 6/10 of a head is a bit misleading because it's actually several different functions. We have inside salespeople that are experts at taking a marketing opportunity from a partner, from René's magnificent marketing machine, and turning that into an appointment.

We've got inside sales reps that focus on renewals. Their job is to renew at least 100% of that quarter's available to renew for their territory. We've got inside sales SEs. We've got inside sales channel business managers. We have CSRs, inside sales reps that actually have their own quota and drive their own productivity. Except for the CSR, all of these inside sales reps are dedicated to make that core team more productive, just like the rest of the company is. Ron Myers, I hired him a year and a half ago. I'll talk a bit about channels in a bit, but we have, again, as a ratio from that one quota-carrying head, we've got about a third of a channel team member.

These men and women around the world, they focus on treating our channel partners like customers, making sure that they're compliant, making sure that they're enabled and trained and certified to be able to be as effective and productive and efficient as possible for our team. They work together with our sales team members to manage pipeline. They work together to drive events. This is a very symbiotic relationship with this core sales team. Behind all of us in sales, for sure, is the kind of engine room of this go-to-market machine, the sales operations team. They're the ones that are putting the nuts and bolts together to devise automated planning tools like territory plans, account plans that we can share with executives when we're going on sales calls, that we can strategize with our colleagues around the sales organization. We can share best practices.

There's tools to automate commission accounting. Believe me, when you're a sales rep, knowing if you do this deal, I'll make this much money is really important to you. These are things that three years ago, I came here, we were a small company focused on driving R&D and building an early sales team out. All these things were done manually. The sales ops team, I'm very proud of them. They've done a very nice job. Then, of course, behind all of this is our global customer support and engineering team, 300 men and women around the world in those five support centers that really have become a competitive advantage, and I'm going to talk more about them in a bit. Let me double-click on the sales team coverage and show you how we're tiering out the market, starting from the top.

We've got 50 global accounts around the world. We've built comp plans to make sure that the team in Hong Kong isn't going to argue with the team in London or the team in New York about a major bank that's based in all three of those geographies. We've got tools to help them share best practices and collaborate and communicate with one another so that it's one team facing the customer. We're acting and fighting higher than our typical weight. As a superset to those global accounts, we've got 2,000 major accounts. Major account manager teams cover these 2,000 major accounts around the world. The productivity that these teams contribute to us, I think is world-class. A typical major account manager or global account manager is doing, when they're fully ramped in the U.S., upwards of $5 million a year. Right?

In EMEA, it's obviously a little bit less than that. In Asia Pac and Japan, slightly less than EMEA. We know that when a rep starts to do a lot more than this, it's time to split their territory, and I'll show you how we do that in a little bit. Below the major accounts, we have what we call named accounts, and we've identified that there's 20,000 of those around the world, again, in all four geographic theaters. As opposed to the touch that's required for the global and major accounts, which is typically high sales touch, working with large systems integrators, global distributors, very much a field-driven model. The touch for these medium-size accounts is a little lighter.

It's definitely with a sales rep, but they're working hand-in-hand with partners to outsource many of the tasks necessary in the life cycle of an opportunity at these accounts. These aren't small accounts by any stretch. These could be accounts like universities, often are found in these named account territories. Universities are one of our bigger verticals. We do seven-figure deals every quarter around the world with universities, not just in the U.S. I see John Spiliotis nodding over there. He loves universities because we crush it at universities. If my two daughters are any indication of what might come out of a university from users using applications wrongly, then I think it's a great use case for universities. We certainly also call state and local government another great vertical for us in this named account territory.

We're really just in the last year or so, really starting to think a lot more about vertical alignment in these tiers as well. In the majors, it's BFSI, it's service provider, a major increasing and ramping focus. It's U.S. federal. Energy is a great vertical for us as well, especially with a lot of the SCADA deployments there. Thinking horizontally and vertically in these is really important. It's something that we do every day. Finally, at the bottom, we've got 150,000 commercial customers out there that we approach with a very different go-to-market model. That's typically inside sales-led. It's typically partner-led, where the cost of sale is significantly lower, and therefore we can pass margin on to partners, but we can certainly get better and better leverage as we prosecute this tier. I think it's a targeted coverage model.

It's thoughtfully rolled out and delivered as we add the kinds of sales resources that we're adding every quarter. We're trying to do this in a very thoughtful way, and I think it is ripe for repetition, and it helps us really to predict what these teams can do because we are building out this team pretty dramatically, as I mentioned. Those of you that knew me before I came here, three years ago, the team that I inherited, sales and marketing, was about 300 people around the world at the beginning of FY 2012. Today, we will finish FY 2015 in the 1,500 men and women in sales and marketing, in that range, a little bit less. That growth comes from literally taking a sales territory that, think of that, the core, the nucleus of that chart I showed before, and splitting that sales territory when it gets too big.

We take an account manager that has 20 accounts, we split that territory into two 10-account territories, and we do that everywhere. We're doing that in Poland right now. We've done that many times in the U.K. When I think of opportunities where we've thoughtfully split territories and we've generated tremendous productivity. I was in Australia about a month ago. Mark was there the week after. Nir was in Australia two weeks before. That'll just give you a highlight to the fact that this team is very switched on. When I joined, we had three teams doing less than $1 million a quarter. Now in Q2 of FY 2014, that business has grown tenfold. The team is at 42 people, I think, is where we are right now.

We hired a new leadership about a year and a half ago, aggressively hired some of the smartest, best, impressive people in that market, and we're just getting going. The week that I was there, I had an event in Brisbane one day, an event in Melbourne the next day, an event in Sydney on a Thursday, lunch events with 30 to 40 customers, dinner events with 40 to 50 customers. I put on five pounds, it was great to see these very switched on customers, very interested in what we have to say at Palo Alto Networks, where we're taking our business and what we're doing, and building a more and more relevant relationship with that team. Same thing two weeks earlier, I was in the Middle East, in the United Arab Emirates, Abu Dhabi, and Dubai.

That team there two years ago didn't even have an entity, so we weren't really selling. We were selling anecdotally through local partners. The team today, just in the UAE, is eight people, and we're doing about $8 million a quarter. Very switched on people. A few ex-Cisco people, a couple of ex-Juniper people, really smart, and I would put them up, sales skill-wise, against almost any team in the world. In terms of getting me in front of CEOs, CFOs, CISOs, CIOs, every meeting I had, I found customers that were willing to listen to what they can do to have the best security. They're willing to pay premium prices for the premium solutions out there, and they love the platform story. I guess my favorite leverage story has got to come from our home base in Northern California.

Three years ago, we had three sales teams doing about $800,000, $900,000 a quarter, just getting going in the Bay Area, the cradle of innovation for technology. I remember talking to the team back then, kind of waving my arms and saying, "Here's what the future looks like. Here's what we're going to apply. We're going to apply this go-to-market model. We're going to divide territories." I could see the reps thinking, "Oh my God, my territory is going to get smaller.

My territory is going to get smaller." One guy, who's actually one of our best reps today, came and talked to me afterwards and he goes, "Dude, I've only got 75 accounts, and I'm getting every opportunity in every one of those accounts." I said, "Listen, if we do our job well, and we thoughtfully split these territories, you'll make more money and the company will benefit from the productivity that more teams can apply to this geography." Well, that same team in Q4 of 2014 with 11 teams did $14 million of productivity just in one quarter. That guy, I won't mention his name because he's one of my favorite reps and he's still doing a great job for us, has four accounts now. He's complaining because he has too many accounts, so we'll probably take him down to one or two.

He was at the end of the first half, so two quarters into our fiscal year, he was already in the $12 million range for the year. This is what having the best platform out there does for you. You hire smart people, you put them in territories, you give them opportunities, and I can tell you that we're attracting by far the best people we ever have. It's never been difficult, frankly, because I think people in this industry get what we're doing. Just a great example is a guy that I've known for a long time is sitting in the back of the room, Ross Pellizzari. Ross, wave that big meaty hand of yours. There you go. Ross Pellizzari, this is a guy that I knew him back even before Cisco days, but he ran channels for Canada at Cisco.

He ran service provider for Cisco after that. His last job was the president of Avaya Canada, running a multi-hundred million dollar organization, almost 1,000 people. He came and joined us to be a director of our enterprise business in Eastern Canada. I'm super excited about what Ross is going to bring to this team, but that's just an indication of the quality of the people that are coming here, like Mark McLaughlin. Actually I did four and three years ago to take jobs at a smaller company because of where this company is going, and we all absolutely feel that every day. It's playing out in fully ramped quota reps. For the first time in Q2 of FY 2015, we had 55%, so more than 50% of our reps were on fully ramped quotas. That's up pretty substantially from Q2 FY 2014, when it was only 42%.

This really plays into the leverage, right? We're hiring people that have a longer career aspiration. They're not startup junkies like they may have been 5 or 6 years ago. These are people that are coming to a destination that they want to call home for a long time. At the same time, I think the cycle of change that frankly this leadership team has imposed on the team in the early days, it's really slowed down. We're seeing fantastic voluntary attrition numbers at record low levels, right? At the same time, the team is still very much focused on managing bottom performers out. We feel there's a lot more leverage to be gained by more productive reps here. At the same time, we're still aggressively investing.

This isn't a metric that is the be all and end all for us. I think it's very important. Of course, it's without question playing out with customers. When you have teams that are now focused on fewer and fewer customers, you are going to get customer growth when they're focused on targets, and you're going to get product growth. Our teams with these fewer and fewer customers can go deeper and wider in these accounts. Let me tell you what I mean by deeper. This is the cohort slide, same format that we put up in the pre-IPO roadshow, right? This is our top 25 customers. Just as a refresher, the gold box is the quarter in which they made their initial purchase with Palo Alto Networks.

The blue box is each subsequent quarter in which they made another purchase with a repeat purchase with Palo Alto Networks. You can notice there's a lot more blue boxes up there than there are white boxes, which are quarters where they didn't buy. I think that's because, again, it's a great platform. It sells into many use cases in an enterprise. We're growing in relevance as a company. The focus that we're applying on these enterprise customers, especially the large ones, is really playing out. Look at the buy-in and how the buy-in has changed just in the last year. A year ago, to get into the top 25, you had to have a lifetime value or a sum of all the products and services that we've sold you as a customer of $4.6 million. One year later, it's up over 60% to $7.4 million.

That's an impressive ticket for the top 25. This grows for sure every quarter. The multiple of that initial buy to the lifetime value has grown pretty dramatically as well. Again, this is a sum. It's grown from 21.3x to 32.2x. That LTV has grown over 50% as a multiple, which is, I think, very impressive. I know Steffan's going to talk a lot more about this in his talk. We look at these cohorts all the time. These cohorts, every year, they grow every single quarter in- quarter out, just the 2009 cohort, as an example, is already today for all of our customers, large and small, regardless of vertical, 8.6 times that initial buy that this cohort has. This is all being done when we really haven't had a product refresh to go in and churn this customer base with.

Most of these purchases, all of these statistically purchases are incremental purchases. Again, shows to the power of the platform. The unlocked value in this base of cohorts is much greater than $5 billion. Yeah, we're definitely focused on getting new customers. We're going to do that every quarter. I think at some point we'll probably stop talking about it, acquiring 1,000 customers a quarter because it just happens now, with the effort that we're putting forth to do this. We're really also very much focused on getting the unlocked value out of these customers by driving that expansion mindset with that more and more focused sales team. I think these numbers are impressive. A big reason why this is happening, without question, is our customers are very happy, and happy customers tend to buy more, right?

The team that Brett Eldridge has built out in global customer support has just done an incredible job. It's not just the people. Oftentimes people think, well, we've hired 300 people. It's more than that. It's the culture that exists around customer satisfaction and success. It's the business tools that we're using, the business process that we're imposing on this team, and the results are unbelievable. Almost 9 out of 10 for a customer satisfaction score. To put it in perspective, at Cisco and F5 in the 90s and in the last decade at F5, we worked our butts off to get it into the high eights, right? That took a long time to grow it up to 8.7, 8.8. This is world-class. Same thing with Net Promoter.

In our industry, a Net Promoter Score, or the score that reflects the customer's willingness to recommend you to a friend or a colleague, in this industry, 50 is considered fantastic. Our Net Promoter Score is off the charts for our industry. I'm really proud of that team and what they're doing for us. Believe me, in the field, we feel that every day that they're behind us and helping us. Traps, by the way, the cohort numbers I just showed you don't include Traps, right? The sales team is absolutely excited about extending this platform to the very real estate, as Nir put it, where these breaches are taking place, right? We're really excited about being able to extend our sale.

The guys in APAC and Japan that don't have subject matter experts yet, these guys are chomping at the bit to get at this technology. The team that I've built out in the last 6 months, the subject matter expert overlay team, primarily is in the U.S., Canada, and EMEA. We made that decision for a number of reasons, but for sure, we wanted to make those initial implementations go very well. We've got great support resources in those geographies. We can be sure that the early successes that we would be having selling this solution would go very well, and the company would learn more and more about how to make them go even better. Just like Palo Alto Networks did in the early days. You heard Mark McLaughlin talk on the last couple of earnings call. We have had commercial success here.

We had dozens of customers that deployed the technology. In Q1, we had our first-ever $six-figure deal. Q2 last quarter, we closed a $seven-figure deal, and I had the good fortune of being involved in that sale. It was with a large healthcare system in the U.S. This is a customer that was just beset with CryptoLocker ransomware about a year and a half ago, that they were almost grinding to a halt. They really couldn't provide services to their patients and to their employees. They came to Palo Alto Networks because their board imposed its will on them. Go do something different, replace this legacy technology, and do it now. Palo Alto Networks showed up with a great partner. We demonstrated our platform, we installed the platform, and we helped rid them of their major issues.

As soon as we came out with Traps, they actually approached us and said, "Hey, our McAfee subscription is terminating in this timeframe," was in the last couple of months. "What about Traps?" We went in, installed Traps. The demos went really well, and we were able to close a $seven-figure deal, tens of thousands of endpoints at this customer, and they're deploying it right now. This is something that we're all very excited about and something that I think is going to be a big add to our business in the coming years. I talked a lot about the business partnerships that we have in previous years. We're going to have a great panel after I talk. Our regional partners, our national partners, the partners that helped us get to where we were, say, two, three years ago, still very important to us, without question.

These partners, many geographies, they're still growing 100% year-over-year, every year. For sure, I look at the prototype partners like Accuvant. Accuvant started in the early 2000s, couple of people and a three-legged dog, and now 15 or what is it? 13 years later, they're a $billion and a half business with 1,500 people. I wish all of our partners could grow the way Accuvant has, but they don't, and they can't. Maybe some others in other geographies will. To be able to get the capacity, the scale that we need to grow our business the way we are, $hundreds of millions incrementally every fiscal year, we need to find and develop broader partnerships. Partnerships like Dimension Data. Matt Gyde, who's head of security, is going to join us on stage here in a bit. Dimension Data has been really impressive.

At F5, it took us two, three years to break into Dimension Data before we were relevant enough to them to get them off the Cisco heroin. Right, Matt? They took about a year to vet us, and then within a year and a half, they became our largest reseller at F5. Still to this day, I think they're among the top. I'm really excited about what Dimension Data is going to bring to us as a partner. Matt's going to talk a bit more about that on the panel. Same thing with large telcos. Not only are they big customers that we're selling our solutions into from a customer relationship standpoint, but they're also important partners, not only reselling our technology, but selling managed services that use our technology to share with their customers. Verizon, AT&T, NTT in Japan, BT in EMEA.

Really important. We're dedicating resources to make these partnerships successful, and they're scaling very impressively. Finally, from a global distribution standpoint, on the stage at this event last year, we announced a global partnership with Westcon. I can tell you how fantastic it is. You're probably not going to believe me because I'm a sales guy. Dolph Westerbos, the Chief Executive Officer of Westcon Group, is going to be up here talking specifically about the success of that partnership. It's been fantastic for us. It's been a massive expansion geographically. Number of partners and revenues have been terrific from that distribution agreement and arrangement. Just double-clicking a bit on partner coverage. One of Ron's first official duties was he realized that we were getting 80% of our productivity out of about 20% of our partners.

His decision was, we're going to keep investing aggressively in hiring channel business managers around the world, but focus them exclusively on our focus partners, those partners that are doing the vast majority of our revenues, right? That group as a business last year grew 100% year-over-year. Tremendously good decision. Thank you for that, Ron. With that group, when we roll out new solutions, like a year or so ago, this big data center implementation with 7050s, when we bring out Traps, and we tap the shoulders of these focus partners, we can very quickly mobilize, certify, train them on both technically and from a sales standpoint and get them productive out on the street spreading the gospel for Palo Alto Networks. I want to talk a bit about sales enablement. This is something that's near and dear to my heart.

We're growing very fast. I realize that over time, as a percentage of the base of the ads that we're adding each quarter, the hires that we're making today are a smaller percentage growth of that base. We're still hiring a lot of salespeople, but as a percentage of the base, that percentage is declining because we want to get more and more leverage out of that base. We made the decision at the end of last year to train our channel partners side by side with our salespeople. Just as an example, we have Power Base Camp, our new hire training. 11 months of the year, we run a Power Base Camp, typically 40-50 new hires in each class.

20% of that class is now partners, account managers, and SEs from our partners that sit in the same room, learn the same curriculum, hear the project-based methodology of teaching them how to make these things stick so that they can represent Palo Alto Networks out in the field right beside with our partners. Same thing at our SE Tech Summit. A few weeks ago in Denver, the 400 SEs from around the world go for this annual training. We had 50 partners, mostly American SEs, that came and got training, again, shoulder to shoulder with our employees, getting the exact same roadmap, message from Lee, and the exact same training curriculum, same certifications. Finally, at our sales kickoff event this upcoming August, there'll be, like I mentioned earlier, about 1,500 men and women from sales and marketing in attendance.

We're going to have 500 partners, mostly SEs and account managers, again, shoulder to shoulder in the auditorium, learning about Palo Alto Networks for that week, going to the same breakout sessions, learning how to sell our solutions better so that over time, we'll get more and more leverage from this field of engineers and salespeople. I'm really stoked about that. I think we have the best partner program in the world that René brought when he came here five years ago. The next wave, we're going to continue to enhance it with enhanced deal registration, pay-for-performance attributes. Finally, we're really trying to become easier and easier to do business with as a company with our partners.

We've launched a major IT initiative that should kick off this month, actually, I guess month of April, where we're putting the ability for our partners to do pricing and quoting with the CPQ implementation, configure pricing and quoting. It's a big bet for IT. It's an expensive investment, but it's one where we feel that the productivity and efficiency of our partners will greatly benefit us in the long run. Just finally, I'd like to talk a bit about what it feels like to be a sales rep at Palo Alto Networks. We do feel when you hear about the power that this platform is having on our customers, we get to sell something that's really important. We get to sell security to help make our customers more secure, to defend them from things that our competitors can't defend them from.

When you hear about the investments that we're making in threat intelligence, Rick Howard and his team of Unit 42, uncovering major threats that are out there, we're going to continue to invest massively in that. Finally, when you hear about the Cyber Threat Alliance, this consortium of previously thought of as competitors that are sharing threat intelligence for the greater good, we do feel at this company that we have a mission that's one of a higher order. I tell you, it's a privilege to be here. I think when people talk about the company, you'll see the same switched-on attitude that they have every day. That absolutely rubs off on customers, absolutely rubs off on partners, and heck, it sounds like it actually absolutely rubs off on investors as well.

Just in closing, really want to let you know that we're very much focused on growth and profitability, because it's a massive and growing opportunity in this market. Number two, we're relentless about how we're pursuing this in every corner of the world. Not just focused in one geography versus another. Number three, without question, we're leveraging proven and repeatable go-to-market model that we think in the long run will have outsized gains and will have increasing leverage. Finally, this only happens because our customers choose to do business with us. The people that represent Palo Alto Networks, the Lees, the Nirs, the Marks of the world, our salespeople in every corner of the world that are driving this attitude, this mission of a higher order. It's happening because our customers are happy, and we're making them successful.

I'd like to thank you very much for your time, now I would like to call up my partners to come up and have a little panel up here to talk about partner stuff. There's some pictures. Hey, Dan.

Dolph Westerbos
CEO, Westcon Group

How are you?

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Good, man. How are you? Hey, Matt. How's it going, bud?

Matthew Gyde
Group Executive, Security, Dimension Data

Dolph, good to see you.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

All right. Thanks. My friends up here, we've got Matthew Gyde, who runs the security business unit from Dimension Data. Hey, Matt.

Matthew Gyde
Group Executive, Security, Dimension Data

Thank you, Mark.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

We've got Dolph Westerbos, the CEO of the Westcon Group. Down there, way down there, we've got Dan Burns, the CEO of-

Dan Burns
CEO, Accuvant

Acufish

Fishubond or Acufish, or what's it called? Accuvant, right?

Dolph Westerbos
CEO, Westcon Group

The name's coming. Yeah.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Thank you guys so much for joining us. Please grab a seat. We've heard a lot, and I think I appreciate you guys sitting in for most of the afternoon here. One of the things we talked about was this sense that security is becoming mega important. Just in the market. I'd love to get your thoughts on that and what that means for your company. Why don't we start with you, Matt?

Matthew Gyde
Group Executive, Security, Dimension Data

For sure, Mark. I think from Dimension Data's point of view, there's several ways we could look at that. The first way internally, within the Dimension Data business, the security business is growing rapidly. It's recognized by executives within the organization. I think there's that angle. Also when we're talking to clients, it's not necessarily talking to the security officer anymore in our client base. I think that's exciting because we're having to change the way we talk to our clients about security. We're talking to CFOs, for instance. We're talking to the data center guys. We're talking to their guys that are talking about moving to the cloud and things like that. Every conversation includes security, I think, in the IT world right now. There's a great story we've got.

We were in visiting a client in a data center in Australia, as we were walking out, the security guy introduced us to the data center guy. He said, "Wow, some guys from security, that's fantastic. I've got a $10 million budget that I haven't spent for the last five years because nobody from security would talk to me." To me, that's the importance of security and having those broad-based discussions right across organizations.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah, fantastic. Dolf, how about yourself?

Dolph Westerbos
CEO, Westcon Group

Well, clearly, we've heard it this afternoon already from Mark and everybody else, the relevance and the importance of security has continued to increase. We're hearing it from our customers, and if you look at how IT is becoming more complex, it's getting more distributed. Certainly endpoints, but cloud is becoming much more real in many areas, and that means the need for security as part of the fabric, and I think I heard the word fabric here earlier today, becomes really important. Clearly with the high-profile examples that happened last year, the need for more sophistication around security is really important. More than a third of our business is purely security. What we do at Westcon Group, we do run a $2.5 billion security business.

We represent just about all the major solutions and vendors out there in the market, and that business is doing really well for us. I think that's a good point.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah, for sure. Dan, you've built a whole company around security.

Dolph Westerbos
CEO, Westcon Group

Yeah

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

I'm sure I'm not telling you anything that you're hearing. From your perspective, what are you seeing?

Dan Burns
CEO, Accuvant

Yeah, I'll just reinforce pretty much what's already said, and I think everybody sees it and understands it. It's pretty obvious. It's not a trend, that's for sure. It's ongoing. This is an issue we're all going to be trying to solve for many years to come. When we look at security and the complexity therein, it's truly obvious, and I like to simplify it by saying, there's hundreds of millions of threats and vulnerabilities out there. By the way, let me back up for a second. The Chief Information Security Officer, it's the hardest job in the world. There's no question about it, and I think the average tenure for a Chief Information Security Officer is about one year, so put yourself in that situation. It's difficult, and here's why. Because you have these hundreds of millions of threats and vulnerabilities.

Every single day, you're trying to protect your environment against that. Add on top of that, you've got dozens and dozens of regulations and standards, whether it's SOX, whether it's GLBA, HIPAA, the list goes on and on, and they keep coming. Then on top of that, you've got to figure out what technology and what partner is going to help solve your problem. It keeps getting more and more complicated. Yep, it's not a trend. That's why we're here, and happy to be a part of this.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Let me ask a self-question of you, Dan.

Dan Burns
CEO, Accuvant

Yeah.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

How has Palo Alto Networks' relevance changed for you?

Dan Burns
CEO, Accuvant

It's been a great partnership. I think, first, there's so many things I can say about it. We've grown the business with you 50%, 60%, 70-plus% year-over-year. I think last year we grew at over 60%.

We've got the combination of Accuvant and FishNet coming together. There's so many opportunities out there for us to continue to grow the partnership. When I talk to my guys, the field people, and everybody, and I ask, "What's the major difference here?" The first thing they see is Palo Alto clearly views the channel as a commitment, a channel by commitment. Other partners out there that we've worked with over the years, we call it a kind of channel by convenience, which is a totally different story. You guys are committed to the channel. We see it. We have relationships at our level with you, Mark, and Nir and Brett, and the list goes on and on, all the way through the field organization. We're just committed to each other's success. Global distribution is also a big thing that our clients are asking about.

With your global expansion and eventually our global expansion and the partnership with Westcon, we'll be able to get a little wider and deeper as well.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah, for sure. How about you, Dolf? You're new to the position, right? About a year and a half ago or so?

Dolph Westerbos
CEO, Westcon Group

Yep.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

I remember first talking to your predecessor about global distribution. I think Mark held him down, and I kept smacking him until he said maybe. Thankfully, you came on board and had the cojones to make this decision. Let's talk about that and what it's meant to you.

Dolph Westerbos
CEO, Westcon Group

It's been like Dan said. It's been a great relationship and great results this past year. We just closed our fiscal year, we grew together our business 120-plus%. We're now doing well over $300 million of business together, really appreciate it. It's great to be here with two of my most important customers as well.

Dan Burns
CEO, Accuvant

Yeah.

Dolph Westerbos
CEO, Westcon Group

It feels like a really good network. Look how relevant you have become for us. You made us wear suits in Las Vegas.

Dan Burns
CEO, Accuvant

Yes. Actually had to go

Dolph Westerbos
CEO, Westcon Group

That doesn't happen very often.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Well, they're required at the high roller tables as well, which I'm sure you guys will be at.

Dolph Westerbos
CEO, Westcon Group

No, seriously, we're hearing the same relevancy coming from our customers. Palo Alto is becoming more relevant, not just for us, but also for our customers. Clearly, you have a great product. We heard a lot about that this afternoon from a number of your colleagues. It's not just about a great product, in my humble view. It's also about combining a great product with a great go-to-market approach and a great go-to-market strategy. I think that is what you have. You have both of these pillars here, and you've got a very deep channel DNA, and that's from the top down, exactly like Dan said. It's from Mark, you, Mark, from Ron, the regional leads, John here, Christian in Europe, Armando in Australia, indeed a very good hire. It's just really nice to see that.

People feel like when you partner with Palo Alto, it's a win-win, and that gives me trust to make a significant amount of investments into our business together. It's not a convenience relationship. It's a win-win relationship.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah, for sure. Matt, this is a relatively new relationship for you. What the hell were you waiting for, mate?

Matthew Gyde
Group Executive, Security, Dimension Data

The setup you did in the practice was a lot better than that, I think so. DD was later to the party, I guess. We've sort of been partners, signed global contracts about 18 months ago. For us, it's a little bit of a different story. Dimension Data is a global company. We're physically present in 62 countries right now, with a reach into an additional 110 or something like that. Quite large. 20% of my business in the security space comes from the North American market. Many North American companies think that's kind of where the world ends, at the borders of California and New York. In fact, it's a lot bigger, and we operate 80% of our business outside. It's critical for us that we get a few elements right before we dive into a partnership.

If you go to our website and have a look on the website, we really only advertise five partners, Palo Alto being one now, and that's because we've got to stand up a global services organization to support the implementation of Palo Alto, to do the consulting around that. We've got a service called Uptime, which adds extended SLAs to the platforms that we sell. Doing that across 28,000 people in 58 countries, it takes a bit of time, even for us. It wasn't a 30-day, let's sign this up. The other thing we look at is the volume of business you're doing globally, but then also outside of North America. That becomes critical because we've got aspirations to own 10%-20% of that revenue. If you're a $100 million company, it costs me a lot of money to stand that up.

I can only be between $10 million and $20 million revenue, kind of the mathematics doesn't stack up. It's absolutely getting all those components right. I think the final piece was when Ron came on board. We were engaged before that, but when Ron came on and brought that world-class channel program to the table, that just changed things for us and enabled us to get to where we're going. We always, at Dimension Data, like to say, if there's a channel program that you think we fit in, we're obviously not important to you. We've found that whilst we do fit into the channel program, there's also certain things outside that we actively do together, which is great for my business, great for our clients.

I think that partnership, it's not a vendor or manufacturer and an SI in this case, it's a partnership. We saw that with a client in Australia, what, about six months ago, where Mark got directly involved with that. There was a few problems with the implementation. It was mainly the user problem rather than installation or product. Mark personally called the guy a couple of times, I believe, and really pushed that deal across the line. That's now leading to a second, much, much bigger deal with that client. I think from that point of view, it took us a bit of time, but I think we've absolutely made the right decision at the right time for Dimension Data, for us all to be successful.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Great. Cheers, man. Thanks. Appreciate it. Dan, I think the group of people here probably want to hear most about how the knitting together of these two amazing companies, FishNet Security and Accuvant, is going. I'd love to get your views on that.

Dan Burns
CEO, Accuvant

Put me on the spot, Mark. Thank you. It's going really well. I appreciate the question. It's going tremendously well. When you look at that deal that we did together, clearly it was a kind of a merger opportunity. We had two companies, like in size, $750 million on one side, $750 million on the other side. Combine the two, you got a $1.5 billion company with 1,500 employees and 60 offices across the U.S. and Canada. Like-minded, very like-minded, where we all came from the security fabric and DNA, out there trying to solve the same problem. While at one point we were probably relatively fierce competitors, you put like-minded people together in the same room, and magic tends to happen. It did. It's been a wonderful marriage of two of the leaders in the industry. We're having a ton of fun.

Sales is absolutely fully integrated. Consulting is fully integrated. We're rocking and rolling. Things are going well.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

It was pretty stunning to learn how little overlap there was in terms of customers and field sales coverage, which is always important in these kinds of mergers.

Dan Burns
CEO, Accuvant

Yeah. There's 10,000 clients between the two organizations with 3% client overlap, which tells you a couple of things. The market is massive, and the upside is huge, and the white space is massive as well. There's still plenty of problems for us to go out there and solve.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah. Well, great. We're looking forward to doing that-

Dan Burns
CEO, Accuvant

Well, yeah.

hand-in-hand.

Together.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yep. Dolph, this global relationship that we have, maybe you can give us some specifics about the geographic expansion that we've experienced, because for us, it was for sure meaningful, but you're experts at rolling this out.

Dolph Westerbos
CEO, Westcon Group

Well, we made this decision about a year ago. For us, it was a bit of a bet. Like you said, you need to be big enough, relevant enough, and we said, "This felt right." This felt right from a culture, right from a partner point of view. We made the bet together. You made significant investments. We made significant investments. We took some risks. You made some trade-offs. You started to rationalize your channel platform. Rather than just going an all-out approach, you actually went with let's pick a few very focused partners, that allowed us to make significant investments. I think this past year has been brilliant. We now do business together in about 50 countries. A year ago, that was well under 30. Two years ago, that was five.

Yeah.

Just to give you a sense of how these kind of partnerships can really accelerate, I think, very rapidly, your profile and our profile around the globe. This year, we'll be doing a lot of expansion in Asia Pacific. Four new countries next month in Asia. The rest of Asia later this year. Also next month, a bunch of countries in our fastest-growing region, which is Africa and the Middle East. We were a big part of your tremendous story in the Middle East, and we feel very proud of that. Now to expand that throughout Africa will be very exciting.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah.

Dolph Westerbos
CEO, Westcon Group

Just in addition, I just want to say, it's not easy for us to bring up another vendor, another partner. Just like you said, it's a lot of work. We have to invest a lot. We have to learn your processes. We have to learn your customers, and your markets, and your solutions. It's not easy. You want to do it with somebody who's interested in your success as well, and that's what it feels like here. We're in a tough space, so when our salespeople are under pressure, who do they want to gravitate to? They want to gravitate to a partner that they feel's got your interests at heart as well, right? I think I'm starting to see that more and more and more. Every one of our regions last year, we grew well over 100% across the globe.

That's been very rewarding to see, I look forward to the next road.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

That's amazing to hear you say that. Thank you very much for that. We've got some time for Q&A, if there's anybody in the audience that wants to ask Matt or Dolph or Dan or all three of them any questions. A question from Joel down here.

Speaker 16

Obviously, a tremendous amount of confusion, lots of different products being thrown at your customers. How do you see Palo Alto positioned as a potential consolidator in that market? Obviously, they've come up with endpoint, they've got the network-

Dan Burns
CEO, Accuvant

Yep

Speaker 16

they've got the threat protection in the air. At the same point, a lot of your customers, the big ones, have 10, 15, 20, 30 vendors.

Dan Burns
CEO, Accuvant

Yeah

security vendors. How do you guys see that playing out over the next five years?

Yeah, may I have first shot at it?

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah. You can go first.

Dan Burns
CEO, Accuvant

For us, I think most of our clients are sick and tired of vendor sprawl. I mean, not just security, across the board. They're looking for that platform, as was talked about a lot earlier, That's absolutely the conversation we're having with many of our clients is that single platform that they can deliver on. Where it becomes really interesting is when that buy, We're going to start seeing it very soon, the buy moves from a pure CapEx, here's a box deployed in my own data center, to a bit of that with a bit of CapEx, with a bit of utility, and maybe some of it based in the cloud.

As that happens, as that trend really starts to take off, I think as the security industry continues to consolidate, the clients are going to pick a platform, That's going to be the winner. As was mentioned earlier, I look at it, Palo Alto is really the only company that we're working with today that talks this platform. The other partners are trying to get there and trying to have that conversation, They get a little bit confused about what a platform is. For me and for Dimension Data, I think it's critical that we start getting Palo Alto integrated into our cloud platform. We've got 24 sites around the world where we operate clouds, et cetera.

We're going through that process now of getting that integrated so the client consumption model can be what they want rather than what I want and what the market may want. It really becomes customer, well, for us, client, but client-driven. Yeah. Well said. I think it's interesting. I'll use just a use case real quick. I was at a Global 5 not too long ago, Talking to their chief information security officer, He said, "Hey, Dan, here's the deal. Edict from our CEO is to minimize number of vendors." He said, "Guess how many security vendors I have?" I said, "I don't know." He said, "89." 89. This is just an excellent opportunity for scaling that down, right?

The more vendors, the more cost, the more management, the more partners, the more care and feeding, all of that kind of stuff. Palo Alto is, I love the slide, the client lifecycle slide, showing the add-on sales opportunity. For us, that's critical, right? Once you're in a client, you want to continue maintaining that relationship, having that opportunity to add additional sales on again and again and again. This is one of those rare situations where we see that, right? We see and we live that slide every single day where maybe the use case may start with a client that has something out there. You implement Palo Alto, maybe in transparent mode right behind the other firewall. They start to get confident. They start to bring it in line. They build that confidence. They start to deploy it across the network.

They add the modules, whether it's URL, anti-malware, IPS, the list goes on and on. As they continue to develop and add solutions to the platform, we're going to continue to be able to solve problems through a larger partner as opposed to a lot of different partners.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah. Well said. Good question, Joel. Thanks. Yep, Michael.

Michael Turits
Analyst, Raymond James

Hey, guys. Thanks very much. Obviously, last year was a great year for spending and security. As we move into at least what's year two of what's called accelerated security spend, is there any change in what you see as the priorities for customers? Are there new product areas that they're shifting to? Any change?

Matthew Gyde
Group Executive, Security, Dimension Data

Can I get this?

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Sure. Go ahead.

Matthew Gyde
Group Executive, Security, Dimension Data

Okay. For us, we're seeing that it's more of a consumption model discussion for us. They want to consolidate technologies. They want to slim it down. They want to make it more manageable. I saw a great graphic a few months ago where it was, they're looking to cut costs out of their business, and I think at this particular time, there was something like 30,000, this is just numbers, I'm not going to get them right, but 30,000 security jobs being advertised in the industry, and there was only something like 12,000 people coming out of university. The demand versus supply just wasn't working. They're looking to consolidate. The fewer platforms you have there, I think the better it's going to be for our clients.

Dolph Westerbos
CEO, Westcon Group

Just to echo that as well, it's really now about consumption.

Dan Burns
CEO, Accuvant

Yeah.

People are looking for different ways to consume it and pay for it, pay on an incidence basis, pay on consumption, those kind of solutions. Yeah.

Yeah, definitely. I would say based on that, I think you guys are spot on. We're seeing a pretty nice spike in managed security service demand based on the consumption issue, right? How do we continue to build and hire great intelligence security minds? In most cases, you got to eventually outsource quite a bit of that, and that's where the future is going, right? It's somebody managing these great technologies and these platforms for clients so that they can continue to focus on their core business and what they do. I think we're going to continue to see that. I think on top of that, behavioral analytics in general. We heard Nir talk about, I guess, security big data. That will continue to be a big trend. How do you take all this data, right?

You've got pipes and pipes of information and data coming in from a security perspective. How do you take that data, crunch it, correlate it, and produce something meaningful and actionable that you can do something with?

Dolph Westerbos
CEO, Westcon Group

That's where the promise, I think, of this AutoFocus offer that Lee talked about earlier, I think comes in really nicely, because customers are indeed looking for that managed service around it and being able to leverage the data that exists already. They don't want to set it up themselves. Sounded really interesting listening to Lee today, definitely interested in learning more about it, but that is the kind of stuff that we're hearing our customers are asking for.

Matthew Gyde
Group Executive, Security, Dimension Data

That added layer of intelligence for their clients.

Dolph Westerbos
CEO, Westcon Group

Yeah.

Matthew Gyde
Group Executive, Security, Dimension Data

That's really, I think that's starting to drive a lot of our conversations, is intelligence, turning the data into information and then providing intelligence out of that.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Hopefully you heard loud and clear from me, Michael, that we feel very confident about our ability not only to continue to take share from these box pushers competitors, but also to continue to grow our base.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

We have time for one more question.

Speaker 15

Thanks. Maybe just back on the consolidation theme. As more standalone appliances move to one consolidated platform, what happens to individual markets like IPS and Secure Web Gateway? How does that impact just the overall network security market? Thanks.

Matthew Gyde
Group Executive, Security, Dimension Data

I'll let one of you two get this. That was a tough one.

Dan Burns
CEO, Accuvant

I'm happy to take a shot at it. I think IPS is going to be relevant. It's still relevant, will continue to be relevant for a while, no question about it. All the things that we talk about today, whether it's anti-malware, malware detection, threat intelligence, all of those things are very, very pertinent. What's different with Palo Alto is the holistic approach and their ability to do a majority of this. I think there's certainly clients that. I want to make sure I'm answering your question through this long response. There's certainly clients that they've got maybe a little bit more of a kind of niche-centric focus. They'll use just an IPS vendor or antivirus vendor or something like that because they haven't seen the opportunity here that a Palo Alto really brings to the table. It's a massive market, though, and it's growing, right?

What is it, $78 billion global market today, growing at 78% annually. I think there's a lot of problems to solve out there. I don't know if I answered your question.

Dolph Westerbos
CEO, Westcon Group

Likewise, I don't think I can comment to each of the elements of the security portfolio. I just want to echo what you're saying, Dan. We're supporting about 5,000 security customers and customers like ADI DATA or Accuvant. We sell only about just over 10% today, actually work with us and you together. Just think of that as an enormous opportunity. We're not even covering the whole world yet. Just, I'm sure there's going to be lots of shifting parts in the landscape. I think you're well-positioned. I think you picked the right partners. I say that very selfishly. I do. I think there is just a tremendous amount of opportunity still ahead, and customers want to do business with you. This kind of culture, this DNA, it's not just extending to partners, it's extending to customers.

I think that's what we want. We want a vendor partner that is as motivated to support and be interested in our customers as you guys are, not everybody is like that, but you guys are, and that helps us.

Matthew Gyde
Group Executive, Security, Dimension Data

Maybe if I just have one quick shot at answering that question as well. I think the couple areas you're talking about, IPS and web gateways, that becomes very highly commoditized very quickly. I think we're starting to see a lot of that move from a premise to a cloud. Clients are starting to look for a, let's call it a clean pipe delivery, so they'll clean the traffic before it comes into their network, remove that. However, they're still legislated that they must have an IPS, they must have an antivirus, and they must have a web gateway. I do think you'll start to see a lot of that move off-prem. It won't be in their data centers anymore, and it'll be a clean pipe feed coming through.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

All right, gents. Thank you guys very much. Really appreciate the time.

Matthew Gyde
Group Executive, Security, Dimension Data

Thank you

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

appreciate the partnership.

Dolph Westerbos
CEO, Westcon Group

Thanks, Mark.

Thanks, guys. Thanks. All right, I'm going to hand the microphone or hopefully the lapel over to my colleague, Steffan Tomlinson, our CFO. Oh, here you go.

Steffan Tomlinson
CFO, Palo Alto Networks

Okay. Thanks.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

How about this, too? I'll hand that to you.

Steffan Tomlinson
CFO, Palo Alto Networks

That's even better. All right. Good afternoon. Is my mic on? Good. All right. You've heard today about and the platform and the importance of that. You've also heard around our go-to-market model and the great sales execution, you've also heard from our partners. What I'm going to do today is cover off how this all gets translated into the business model and the financials. When you take a look at our company, there are multiple growth drivers, and those growth drivers show up in our revenue growth. You take a look at the past seven full years of shipping, our compound annual growth rate of 140% is 25 times that of the industry growth rate. Pretty staggering. That's due to primarily the platform. It starts with the platform, we quickly translate into going to market.

You've heard us reference our land, expand, and retain sales strategy. These are key elements around how our business model gets built. Even with these growth rates being what they are, we feel like we've only just begun. You take a look at the market. We're playing in a $15 billion enterprise market today. We have 8% market share in enterprise network security and 0% market share in endpoint. That $15 billion market is growing to close to $20 billion over the next several years, that is a massive opportunity for us. You're going to be seeing us playing our hand around capturing more market share. When you look at where the market share is coming from and where the growth is coming from, we're highly diversified across all verticals. In fact, every major vertical in the world needs enterprise security.

When you look at the profile of our own customer base, we have very limited concentration. In fact, the biggest vertical that we have is high tech at 14% of sales on a lifetime to date basis. This diversity is actually a great thing. It provides us incremental opportunity for further expansion in those verticals. As our marketing department with René at the helm and our customer success organization that we're going to be building out, we're going to be coming up with programs that are targeted specifically for verticals, we think this is going to be a great opportunity for future growth. Additionally, you look at the great geographic distribution of our revenues. Every theater here is posting best-in-class growth, starting with APAC at 36% year-over-year, EMEA, 46% year-over-year, and Americas growing at 58% year-over-year.

It's almost counterintuitive. You have to ask the question, why is our largest and most mature market growing the fastest? The reason why that's the case is we've been fine-tuning and honing our major account sales strategy and our go-to-market model. We've taken it to a place now where we're ready to take this across the globe. Why that's important, especially for EMEA and for APAC, is when you do the screen on where the Global 2000 customers reside, over half are international. Our major account sales strategy will be a key element for us to attack more of the markets and expand geographically. Now let's talk about the primary driver of this growth, and it does start with the unique platform offering.

Many of you are familiar with the story, but for those of you who aren't, we sell a family of products and subscriptions that satisfy most use cases for enterprise network security. We've recently come out with our Traps product, which covers endpoint. Tying network security and endpoint security together is key. We also have new features and functionality that we're coming out with. Lee mentioned that we have AutoFocus coming into the mix. That's a new subscription service that will be incremental growth opportunity for us. Each element of this platform is both an entry point to a new customer and it's an expansion opportunity for existing customers. The versatility of the platform is one of the biggest assets the company has, and how this versatility plays out is in our land and expand strategy. You take a look at the customer additions.

Over the last 12 quarters, we've added well north of 1,000 customers per quarter. Once we acquire a customer, the versatility of the platform, the fact that we can sell to now any enterprise security need, shows up in the expansion business. Over the reporting period that I'm showing up here, you can see that the majority of our business every quarter comes from expansion. Now, interestingly enough, if you train your eyes to the bottom of the graph, the contribution from new business is actually increasing slightly, and that's actually a great data point. There are a few things that are going on there that's driving this. The first is we're selling higher unit ASPs to start with. With the PA-7050 coming into the mix, which is our chassis-based product, and our ability to get more into the data center, we're selling more.

Additionally, we have higher attach rates. Higher subscription attach rates are also driving this. Lastly, the sheer number of new customer adds per quarter is also a positive development, which is why you see the contribution from the new customers growing. Very much the land and expand sales strategy is a key component of the model. If we take a look at this strategy and how it plays out by cohort, last year when I was up here, we gave you insight into how each of the cohorts trended on a lifetime value to date basis. This is what I showed last year. At the end of fiscal year 2013, you can see that the earlier the vintage of cohort, the greater the LTV metric, and you can see that in 2009, that LTV metric was 6.3. 2010, hit that five handle on it.

Where we are today, we have massive growth across all cohorts. In fact, you can see the progression where the 2010 cohort eclipsed where 2009 was a year before. This gives you a further proof point of the land and expand power of the model. The other element that is new this year that we're sharing with you is to give you a sense of the size and scale of each cohort. Across the board, on the bottom, you can see the approximate customer counts, and the great news about this is enterprises refresh their technology typically on a four to five-year cycle. We've seen just the early green shoots of refresh hitting the books, but we're at the very early stages. I would call it in the top half of the first inning.

We have a big refresh cycle coming up in our own install base, which is yet another growth driver for the business. We've talked a lot about land and expand. What I want to give you a little bit more insight into is why customers expand. Using the 2009 cohort as an example, this is the progression of how customers in that cohort ended up expanding with us. In their initial year, what the use case typically was a limited use case selling a few appliances at the perimeter for a segment of the perimeter, and we're probably selling one or two subscription services to begin with. Over time, as our model gets more mature and proven, we start to take more share of the perimeter, and maybe we're selling more subscription services.

As we come out with new product introductions, like back in the day when we came out with the PA-5000 Series and later on with the PA-7050, we're getting deeper into the data center. We're selling more products and subscriptions as well. With the advent of WildFire to sell the APT and malware solution, that's yet another data point to go into the customer and sell. We're not even talking about Traps or AutoFocus yet. Those will be incremental growth drivers for that cohort expansion. The other thing that you see here is the power of the subscriptions model and the services model. I want to spend a little bit of time walking you through some metrics around the power of our hybrid SaaS model.

There are a number of metrics that we talk about on a semi-annual basis, and this is an opportunity to refresh those. In our platform for next-generation firewall, we have four subscription services, threat prevention, filtering, WildFire, and GlobalProtect. You can see that as of Q2 2015, the attach rate, number of subscriptions per devices shipped in the quarter was 2.2. The composition of how each of those subscriptions plays out, typically threat prevention is greater than 80%, filtering is greater than 60%, WildFire is approaching 50%, which is, by the way, it's our fastest-growing subscription, and we see no reason why WildFire can't be in the same zip code of threat prevention and filtering, and then GlobalProtect is the balance. The subscriptions per device increase is a testament to our field sales acumen around selling the value proposition and selling the power of the platform.

Every time we sell a subscription service, or I should say most times, we are typically displacing a physical device of another vendor in the network. You heard from our panel up here that there's one extreme example where a customer had 89 security vendors in the mix. The fact that we're selling a platform is an ability for us to consolidate and provide a more elegant solution. That elegance of solution and the power of the platform starts with our product management and engineering teams, and we have the best in class in the business. One final point on the subscriptions per device metric that I just want to highlight to you. Over time, this metric actually becomes less meaningful because it's an in-quarter snapshot. One of the things that we're going to be migrating to down the road is talking about penetration rates.

That will be something down the road that we'll introduce. Another key element of this hybrid SaaS model is the contract duration. We sell subscription services and maintenance, and we sell one, three, and five-year tranches. We've seen what I would call a picture of stability around contract duration, although we have seen, I'll call it a very modest uptick. The fact that we're seeing a very modest uptick is actually good news because we are being designed into the fabric of the network for a longer period of time. It's also good from a financial standpoint as well. Our renewal rates for subscriptions are very high, greater than 90%, and for support, it's close to 100%. Another element on the slide that I'd like to highlight is we have two other subscription services that aren't attached to the device, AutoFocus and Traps.

These will be funneled into our services revenue stream down the road, and that's going to be a positive note for our business model. How that hybrid SaaS model plays into billings and deferred revenue, and then you add the power of the platform, it's very powerful. At the end of the first half of fiscal FY 2015, we're north of a billion-dollar billings revenue company on a run rate basis. When you look at the componentry of the billings, you can see our products in the dark blue, subscriptions, and support. One thing to note is we're running a $300 million on an annual run rate business for SaaS, and it's the fastest-growing part of our business. Last quarter, our subscriptions grew north of 70% year-over-year. How the billings increases visibility is through deferred revenue.

With the majority of our billings coming from our services, deferred revenue has been increasing, and we have over half a billion dollars of deferred revenue on the balance sheet, and that helps with the future visibility of revenues and profits. Now, speaking of profits, Palo Alto Networks has really never debated growth or profitability. We're balancing growth and profitability, and that is a hallmark of how we're trying to run the business. The two metrics that we like to focus on, non-GAAP operating income and free cash flow. For the first half of fiscal year FY 2015, non-GAAP operating income was $47 million, grew 112% year-over-year. Adjusted free cash flow was $152 million, growing over 170% year-over-year. These are proof points that our capital allocation strategy, where we're making our bets financially are paying off.

What's typical in this industry is you see companies with very high growth rates and negative free cash flows. We try to build a franchise and an enterprise that's very much focused on delivering best-in-class top-line growth and profitability. In the context of balancing growth and profitability, the areas of focus of where we're allocating our capital over the near term, we wanted to give you folks insight into. From an R&D standpoint, we're going to be putting more dollars into the business to extend our lead in the next-gen firewall, cloud, and endpoint capabilities. We're going to continue to build out our threat intelligence services, which is both people and systems. From a sales and marketing standpoint, we're going to grow to expand share, and we're ramping our endpoint go-to-market capabilities in a big way.

We're going to be scaling through investment in partners and enablement, as well as building a world-class customer support organization. I know Mark Anderson flashed up the customer sat scores. I can't tell you how great of a business that we're building in customer support. It is a differentiator for us. On the G&A side of the house, and infrastructure, we're going to invest in cloud and data center expansion to support that $300 million in growing SaaS business. We're going to be building out facilities to accommodate new employee headcount growth. Speaking of headcount, we wanted to give you a snapshot of where the heads are in the organization and give a year-over-year comparison. You can see support and operations, 333 people as of Q2 2015. Sales and marketing personnel are at 1,155. G&A is at 227, and R&D is at 368.

The year-over-year growth in R&D on a percentage basis is the biggest, and that's in part because we did a great acquisition with Cyvera, and lots of those folks were engineers, and that's added on a year-over-year basis. This gives you a sense of where the employees are located, and you can also see where we're making the most investments. Sales and marketing and R&D are certainly the areas where we're making the most. Let's talk about the target model. I want to give you a little context about the model, and I'll start with the headline. We remain committed to the target model and the timing of the target model.

The context is we came up with this target model at the time of our IPO, and candidly, we didn't think, and candidly, we're pleasantly surprised that we're growing at the rates we're growing at this size and scale. It's very rare when you get to a billion-dollar billings run rate where you're seeing accelerating growth. Additionally, between the time of the IPO and today, we made a meaningful acquisition in Cyvera, and we were able to absorb, in this fiscal year, an incremental $25 million of OpEx investment, and we're not changing the timeframe. What we've done here is we've fine-tuned the model. By fine-tuning the model, we've increased our gross margin target from 73%-76%, to 75%-78%. We're doing that because we're getting a broader adoption and bigger contribution from our services and SaaS business.

We're also going to be making investments to help build the infrastructure out. From an R&D standpoint, we're not making a change to the target, but we are very much keen on increasing our technological lead. We're going to continue to invest there. Sales and marketing, we're bringing up a touch. We're bringing it up to 35%-38%, from 33%-36%. How we are going to get there from here is we're going to be expanding within our existing customers. You've seen that proof point. The expansion sales typically come at a lower cost of sales and marketing. We're going to have a higher percentage of ramp salespeople. Higher percentage of ramp people are doing more dollars per person. We'll have higher sales coming from renewals, and we'll have improved leverage from the channel and lower cost sales regions.

Over the longer term, we certainly think we can get sales and marketing lower than 35%-38%. However, the time to do that is not now. With 8% market share in network security and 0% market share in endpoint security, and the growth rates that we're posting, getting more incremental leverage out of sales and marketing will come, but it would be cutting off our nose to spite our face to try to do it sooner. We'd be giving up a large market opportunity. G&A, we're not making any changes to at 5%-6%. Again, the overall operating margin target of 22%-25% remains intact by exiting Q4 of 2016. At some point down the road, as we get closer to the target model, we'll look at what the long-term target model is.

We've purposely never called this the long-term target model because we want to get there first, we've had a playbook of making the investments and seeing it pay off, and we're marching towards this. There are a few other modeling points I want to highlight for you. The first is free cash flow margins should be north of 30% at the target model. CapEx for this fiscal year is no change. What we talked about on the earnings call was CapEx was going to be $45 million-$50 million this year. While we haven't done all of our planning for FY 2016 yet, we're looking at CapEx to probably be in the range of 5%-6% of revenues for FY 2016. Our tax rate, our non-GAAP tax rate is static at 38%. We don't anticipate changing that in the near future.

Our cash tax rate's going to remain to be very low. That covers the modeling points here. Then to summarize, we feel like we have multiple growth drivers in the business and lots of proof points that the model is working. We have a proven hybrid SaaS revenue model that's a key differentiator for us. Today, we're generating strong free cash flows, in the future, we're going to be increasing operating leverage. With that concludes my section of the presentation. What I'd like to do is invite the other members of the senior team to come up for Q&A. Thank you very much. Appreciate it. Thank you.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

While we get things started, Karl's eager to join the dialogue. I'm coming. There you go.

Karl Keirstead
Analyst, Deutsche Bank

Steffan, Karl Keirstead at Deutsche Bank. Thanks for hosting everybody. This has been really great. My question is on the guide for free cash flow margins. I think when you say over 30, that's basically reaffirming what you've said before, which is that the free cash flow margin should run 5 to 8 percentage points above your non-GAAP operating margin numbers. In the last couple of quarters, they've run more like 25% above, and it makes that 5%, 8% look a little conservative. Maybe you could help us with how we might model free cash flow margins between now and then, because that 30 looks a little conservative to me. Thank you.

Steffan Tomlinson
CFO, Palo Alto Networks

As we get more of our revenues off the balance sheet, we've already collected that cash. Okay? The other thing is, over the longer term, we will be paying more cash tax, which is something that's not in operating margin, right? You will see a convergence, and that's why we feel like the 5 to 8 percentage point rule of thumb above the top end of our model is reasonable. That's why we say it's going to be north of 30%. In the near term, between now and Q4 2016, I anticipate there being, again, this very large delta.

As a data point, what we've told folks is, as an interim milestone, that we'd be in the low teens non-GAAP operating margin exiting Q4 of this year, and then get to 22%-25% of Q4 next year. There will continue to be a sizable gap between today and Q4 2016, but I see that gap narrowing as we are getting more of the revenue off of the balance sheet. Yep. Kelsey?

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

Faster.

Brent Thill
Analyst, UBS

Hi, it's Brent Thill with UBS. Steffan, just on AutoFocus, can you talk a little bit about the monetization and how you expect to price? Then, for Mark, just on Traps, can you just bring us up to date in terms of what's happening with the enablement of the field, the reseller community, kind of where you're at in the reference-ability and live projects going out would be helpful. Thank you.

Steffan Tomlinson
CFO, Palo Alto Networks

Yep, sure.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

Okay. I'll take one.

Steffan Tomlinson
CFO, Palo Alto Networks

Yeah.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

On AutoFocus, our intent there is that this will be a service, a new service for us. It'll feel like the service revenue collected up front, recognized over time. It will not have an attach rate concept, though, because it doesn't attach to a device. It'll be more like Traps in that sense and less like the WildFire, for example. We'll start selling this in the fall. We would expect that the price points around this would be that we'll charge tens of thousands of dollars per year for usage of this and in enterprises. It'll depend on how many operators are in the enterprise who use a tool like this, a service tool like this. We'll get a better sense of this as we go through the Community Access Program as well, as far as what the uptake and adoption rate of this would be.

We think it's a tool that'd be useful for the whole customer base. Larger customers run teams that have security teams who can use something like this. Smaller companies may not, but that's where partners can come into play to provide it as a service for them.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Other question was about Traps.

Steffan Tomlinson
CFO, Palo Alto Networks

Brent, on the Traps build-out, we're slightly ahead of our hiring plan right now for Traps teams in the Americas and EMEA. A big part of what they do is they enable the focus partners that we've chosen to resell Traps. These focus partners, in many cases, are like Accuvant, that are existing security partners. In some cases, they're actually focused endpoint partners that we've found and are starting to do business with. In terms of the POCs, we've got lots and lots of POCs out there. I don't think we comment on the exact number. A ton in the U.S. and a significant amount in the EMEA theater. We even got customers in APAC and Japan. We actually have one partner in Japan already spun up, even though we don't have the resource on board there yet.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

It's ahead of, I guess, my internal expectations, and it's going to continue to ramp this year. We'll hire people in APAC, probably in Australia, maybe in Singapore as well this quarter. We'll hire some in Japan in the next 15-90 days.

Jayson Noland
Analyst, Baird

Jayson Noland with Baird. Thanks, Kelsey. Question on what Nir referred to as Ghostbusters to start. One of your competitors has a post-breach services business that sometimes competes with the channel. With some of your partners here, I'd love to see where Unit 42 could be someday. Is it services? Is it more marketing? I know it's the meaning of life, but what else could it be? Steffan, you referenced products by industry. Could those be items that are sold as modules, or are they just enhancements of what you have today?

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

Yeah. I could take the first question. This is one of the reasons why I talk about ideas and philosophy matter. We're very prevention-oriented. We're very technology-oriented, right? Now, in order to get the job done, you have to have people, process, and technology. We're very focused on the technology aspects and getting leverage from that in order to do the most prevention as possible. It doesn't mean that there's not a business out there for incident response or remediation. It means we're not in it, right? Our job, our goal, is not to make that stuff go away, because it won't. You'd be wise to be prepared for that. Our job is to make it occur less, right? It's a very big market, and people will fit into that market. We're not in that business.

You're not going to see us get into that business. Unit 42 for us is a group of really, really smart folks from a threat intelligence perspective, that their primary task is to make our technology smarter. That's what they do mostly for a living. The second thing they're doing in doing that, they're finding stuff out there that's of interest to the customer community. You've seen us do that with WireLurker and CoolReaper and some of those things that are out there. That's great. That gets notoriety for Palo Alto Networks and the team on being some of the smartest guys in a room around this. We don't monetize Unit 42. We don't intend to monetize Unit 42.

We absolutely intend to monetize the intelligence that's coming out of that, as you've seen with AutoFocus as a perfect example of that, and things that are going into the platform. Their job is to make the platform better and better.

Steffan Tomlinson
CFO, Palo Alto Networks

The second part of your question, what I was referencing is more industry-related solution selling, not specific new products or subscriptions specific to an industry, but it's best practices. You can imagine across the 22,500 customers that we have, we have some of the biggest logos in each of those verticals. There's a lot of commonality around network topology and infrastructure. When we have great customer wins and use cases, we're going to start to package that more to have more of a vertical and industry marketing focus. No new products per se, but it's an ability to go deeper into those verticals themselves because we'll have best practices and solutions guides.

Sterling Auty
Analyst, J.P. Morgan

Sterling Auty from J.P. Morgan. Steffan, you mentioned entering in kind of the refresh cycle. What I'd be curious about is maybe some of the early data points that you've seen. What's an average refresh? Is it four to five years? What's the trigger? Is it when the depreciation comes off the books? What triggers the refresh to happen? When you look at those early cohorts, how do we think about the number of devices in some of those customers?

Steffan Tomlinson
CFO, Palo Alto Networks

The first part of the question, there's certainly the depreciation element around it, which when a unit comes off depreciation cycle, that could be a catalyst. The real catalyst is when we come out with new operating systems that have great, robust features and functionalities, and usually we have 60 to 70 new features per new OS. When you have older hardware, we're selling the PA-2000, the PA-4000. As an example, if you're running 5.0 code or lower, you wouldn't have the benefit of having WildFire running as an example. The catalyst is really the new features and functionality around that refresh discussion starting to happen. The size, again, we're real early days. Oftentimes in the earliest purchases, it started out with a handful of appliances. Maybe they've bought a dozen or so. Typically those are PA-2000 and PA-4000 units.

The natural upgrade would be to the 3000 or the 5000. There's even the opportunity for an upsell to occur, because if they're refreshing those at the perimeter, we could be going into the data center with our 7050. Not only is there the refresh cycle for the original units, you have multiple new use cases, you add on Traps and AutoFocus, there would be an ability to upsell more.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

Can I comment on that also?

Steffan Tomlinson
CFO, Palo Alto Networks

Sure.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

I don't know. Can you hear me? Generally in our industry, for many, many years, it's not just Palo Alto Networks, the main reason for an upgrade was fees and speeds. The thing is that if you look at the price of security, it goes up significantly as you go up in speed. Meaning to go from 100 meg solution to a gigabit solution to a 10 gig solution to 100 gig solution, the increase is very, very steep. Customers tend usually to buy what they need right now, meaning if you need five gig firewall today, you will buy five gig. You're not going to buy 100 gig. It so happens to be that network throughputs are growing very, very, very fast, especially in the data center, and that drives a lot of refresh.

Just the need to increase the speed because you didn't buy the PA-7050 when you should have.

Speaker 15

A question for each Mark. Mark, you first, just with Traps, can you talk about your expectations for selling it to customers? Are you expecting that to be largely sold through the endpoint groups in the enterprise, or do you expect that to be mostly bundled in as packaging with your platform sales?

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Largely sold through the endpoint resellers, you mean? Or endpoint solutions-

Speaker 15

Well, you mentioned that you're going through the resellers with a lot of your trials, so I'm wondering if you expect that to be your primary channel to the enterprise, or if it's going to be packaged in more with-

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

It's going to be packaged in more with our core go-to-market motion. I think the major account managers, global account managers have already started to engage the subject matter expert teams that we have And presenting them to their customers as experts and earning opportunities to do proof of concepts and ultimately sales. Same thing's happening in the commercial business as well. From a partner standpoint, I think the real partner leverage will play out much more over time when the partners have had enough success and soak time with some of these projects.

Speaker 15

Okay. Mark, just in terms of the east-west firewalling, if we rewind 12 plus months ago, we heard a lot about WildFire, a lot about east-west firewalling, a lot about the PA-7050. We've seen two of those three probably exceed our expectations, at least. Can you talk about the partnership with VMware?

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

Yes, sure I will. Just one more point on the Traps thing, too. What Mark's team knows how to do is they know how to sell the platform. Of course, we're going to talk about Traps to solve a specific problem on the endpoint. When we tell that story as part of the platform with the attack lifecycle and the prevention, that's where it really gets juice. That's whether you're talking about NSX or whether you're talking about AutoFocus. It doesn't matter, whatever you're talking about, it's just an entry point. The NSX relationship is going very well for us. If we back away just for a second on what the problem is of going into the private cloud environments and having to protect east-west traffic, that's a use case that didn't exist a while ago, and now it does.

What we get from that relationship with VMware is two things. The first is mind share, meaning that we've leaned very forward into this go to the cloud, and what that means from a consistency of security. We did it with VMware because they have such market share in that case. As an attention-getter for us, as a meeting-getter for us, as a follow-up to meeting getter for us, I would put that close to 100%. Personally, I talk to customers all the time. I don't think I've had a conversation, unless they just say, "We can't stand VMware." Even then, we can move the conversation somewhere else that benefits us. Very high attention-getter for us. Then follow-through is good as well.

I think VMware said recently they have last time they reported, I guess it's getting close to the end of the quarter for them, but they had 400 customers already. When we look at that base and say, "That's great," on the four-legged sales calls, which we're doing a lot with these guys, we're running over 300 POCs. We've closed multiple deals already with this. One that closed last quarter was a Fortune 100 company that was a small customer of Palo Alto Networks at the perimeter already. In a four-legged sales call where they're buying NSX, we closed a multi-million dollar deal in association with that purchase that they made. That got us to the table. We were able to talk about the data center and virtualization of the data center and what the security needs.

We had VMware sitting next to us saying, "Yeah, that's the right answer." I think that over time it's working, and I think over time, this could grow into something pretty meaningful for us. We do have a condition precedent of you got to buy NSX. We're hopefully a big tail on that dog. It seems to be going pretty well.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Yeah, Nick, VMware themselves will tell you that the number one use case that they're selling NSX successfully is micro-segmentation. That's a security use case, that's right in our sweet spot. We're very much aligned with them in the field as well.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

Yeah.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Actually, I think we've run out of time.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

I think we got one more.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

Okay. Darn it.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

You guys took a break. You were longer on your break than you were supposed to.

Kelsey Turcotte
VP of Investor Relations, Palo Alto Networks

I'm going to throw it up in the air, and one of you is going to catch it.

Speaker 15

You have to stay two more minutes. No, I'm just kidding. Excellent. Thank you for squeezing me in. One question for Lee. Just want to make sure there's a reason he's standing up there.

Mark Anderson
Senior VP of Worldwide Field Operations, Palo Alto Networks

Eye candy.

Speaker 15

Drilling down on AutoFocus, it seems like you're trying to solve the signal through the noise problem. The question is, what's different with this product versus what people get with WildFire, and what would be the difference in the use case here versus your partnership with Splunk, where they're trying to sort of pull that information and get the signal out of the noise? Then one for Mr. McLaughlin. We've heard a lot about the value of the intelligence that's being pulled out of all these systems and sharing the intelligence amongst the parts, you guys are also doing agreements where you're sharing information with other security vendors. We're hearing about President Obama trying to legislate sharing of information. Does that at all devalue sort of the security intelligence that you guys come about with?

Lee Klarich
Senior VP of Product Management, Palo Alto Networks

I think with AutoFocus, there's actually a few use cases. The one that I really focused on today was sort of that finding the needle in the haystack use case of through all the different things we see, what are the things that should be most prioritized? What are the targeted unique attacks? That's based on WildFire data, WildFire is just trying to find good versus bad. AutoFocus is then focused on how do I prioritize and sort through the bad to really pull out the things that should receive the most attention. They work sort of hand-in-hand to a large extent. Now, how that varies from, say, Splunk, I think Splunk is more focused on the WildFire side as well. How do they take a WildFire log and just go confirm that the malware was successful or not?

Again, they're also not focused on what AutoFocus is able to do in terms of really pinpoint those unique targeted attacks. There's actually a couple other aspects to AutoFocus as well. I talked about context, which is very important. When you have a piece of information, how do you get as much information around it as possible? Because that makes the information more actionable. There's one that Nir kind of alluded to that I didn't talk about, which is just the internal use of AutoFocus within our threat intelligence teams, Unit 42, in order to be able to use it as a tool to create new detection mechanisms that otherwise don't exist. There's a number of really amazing things that we believe AutoFocus is going to be able to do as we build it out, expand it, and get the community going.

Mark McLaughlin
Chairman, President, and CEO, Palo Alto Networks

Yeah, on Gary's question on the sharing, again, not to repeat the whole philosophy ideas matter, it really matters about what we're trying to get done. If you really believe in prevention like we believe in prevention, you're really trying to get highly automated prevention dispersed as fast as possible to everybody, you have to share intelligence, right? If that's your mindset, it sort of frees you up in a way. I can tell you, I've had this idea of the Cyber Threat Alliance for a while. It was sort of like a security ISAC. You go out to pitch that to other security CEOs, the first answer is, "Are you out of your mind?" Right? That's the proprietary crown jewels. It's our stuff is so much better than your stuff. It's as special.

Your response to that, which is taking hold, is the security industry is changing, and it's changing this way, which is, it's not about what you see, it's about what you do with what you see, right? It is to the platform. If you had the information, what would you do with it in order to help you as a customer? I think that's changing pretty quickly in the customer community. They're not going to tolerate this anymore. Customers are not going to tolerate Tom, Dick, Harry, Suzy, and Jane come along saying, "I see a little bit more in D.C., so buy all of our stuff." We're very confident in that. We're trying to get ahead of that. We're saying, "You know what? We see fantastic stuff." Lee showed you a chart of unique samples in WildFire.

We'll hold our uniqueness, from a threat intelligence up to anybody. We're way more interested in what we can do with that, and we're willing to share now because we think the platform can actually deliver the high prevention outcomes. You're seeing that all over the place, not only for us trying to do that with our own ecosystem. We're trying to do that with the CTA to get the community to work together. You're seeing a lot of stuff in the government about threat intelligence sharing as well. On that last point, and then we're going to end, but at the lunch table, a lot of people were asking me, like, what's happening in Washington, D.C. with this threat intelligence sharing and all these bills and stuff. That's it. That's the point, right?

The reason that everybody's focused so much on sharing threat intelligence is to do what we're talking about. The sooner you can get that information and data in a highly automated way, the sooner you can make it such the attack is only going to work one time. Like, that's the end game. I wanted to highlight, Ryan Gillis is in the back room there. Stand up there, Ryan. Ryan just joined us from the White House, and Ryan's our first ever and new head of government affairs for Palo Alto Networks. When you saw Barack Obama in a little clip said Palo Alto Networks, Ryan did that, right? We expect to have a lot of relevance in this whole conversation as we go forward. We're going to have to end there. We're out of time. Thank you very much for being with us.

This is going to end the webcast portion of this.