Good afternoon. Thank you all for joining us. We really appreciate it. It's always nice to see a full room. Thank you very much, and thanks to those of you on the webcast for joining us as well. Unlike an earnings conference call, I'm not planning on reading all of the fine print to you all. I've checked the box, and I can now go to the much more important part of things. This is a high-level agenda of what we're going to accomplish this afternoon. A lot of you have asked us why do this at our user conference, and quite frankly, it's a perfect place for you to actually see the excitement about what's going on with us. A lot of you ask us difficult questions, things like, "I hear other companies saying X, Y, and Z.
I hear you saying something else." We really encourage you to go talk to our customers, talk to our partners, and ask them the hard questions, because they're really the best ones to speak about the value proposition and the vision, and what it's like doing business with us. That's the point. One note to all of you should have received an agenda book with all of your information relevant to the track. If you don't have one, we'll have some in the back. Times and locations are located in that. There's been one small change. Right after this, we're going to go into a cocktail reception where you'll have the opportunity to spend some more time with our executives. We have changed that location. It's going to be some place called the Chelsea Mezzanine, and we will have people stationed to help you find that venue.
To that end, if you don't get a chance to ask your question in this forum, we will be here, and we would be happy to field any questions during that cocktail hour after we're finished. The other point to make is tonight, you're invited to the Ignition Chamber, which is also known as our exhibition hall. That's really where we're going to kick off the customer portion and the partner portion of this event, and we'd love for you to come and see what's going on up there. That starts at 6:00, and it is going to be on the fourth floor. We're going to actually get started with a little video, and then Mark will come up and kick off. Thank you for joining us.
Fiscal 2014 so far has just been a great year for the company.
In-line earnings better than expected revenues surged 48.7% year-over-year.
Your stock has certainly performed well. It's up better than 60% in a rather short period of time.
Bad guys breaking into your system, Palo Alto's got a solution.
Replace the old systems, the legacy systems, with just one new solution, the next-generation firewall, and we really gained in performance as well as in efficiency.
We don't know what the next 12 months holds, so we need partners who can be flexible enough and change quickly enough to grow with us. I feel that Palo Alto Networks is one of those partners.
We've moved into our new campus. We've launched new innovative services, like the new version of WildFire.
Our 3,000-plus WildFire customers are now also sending to the cloud PDF documents, Office documents, Java files, and of course, Android APKs.
It gives us a very immediate notification that something has happened, that malicious or potentially malicious software has come down to a very specific endpoint, and it gives us a starting point to go look.
We're really excited about the launch of the PA-7050, which is the world's fastest next-generation firewall. So far, it's been great, and we're really looking forward to the future. Good afternoon, everybody. Thanks for being here. It's great to see all of you here. I really appreciate you taking the time, especially to come to Las Vegas. I know it's a bit of a trip for folks from the East Coast to join us for our Ignite user conference. This is actually the second one that we've done. Our very first user conference was last year, what we wanted to do last year, and it was very successful, was to get together our users in order to talk with them, but more importantly, just enable them to talk to each other about things that they need or things that they see in the market.
We took all that feedback back to the company and did stuff with that, it was so successful last year that we were going to keep it going. Last year, we had about 850 folks at the user conference. This year, we're looking at just shy of 1,900. If you have the opportunity to stay over the next two days, you'll be sitting with close to 2,000 of our customers and partners in the main ballroom, which we encourage you to do, like Kelsey said. We're really just enabling these folks to get together, they're wide open to speak to if you want to spend the time, or I shouldn't say that, they'll let you know if they want to talk to you, but they're available if you want to spend the time with them. That's really why we wanted to have you here.
Last year, we couldn't do that because just from a timing perspective, we were in a closed window. The ability to do something like this tacked onto it was limited, so a little better prior planning this year on our side. That's what this is about for this week. What I wanted to do, what we want to do this afternoon, since we have the opportunity to speak with you, is get you updated on some of the things that are going on in the company, then most importantly, answer any questions that you have, take the chance to get everybody at the same time to do that. I have with me today a lot of the senior executive staff from the company, some of you who you'll hear from.
We've got Mark Anderson, who runs worldwide operations down there at the end of the table, Steffan Tomlinson, our CFO, who I'm sure most of you know, René, our chief marketing officer. Of course, we have Nir Zuk, our founder and CTO. Lee Klarich, who runs all of products, is with us as well. Sitting next to him, if you raise your hand, is Chad Kinzelberg. You may not met Chad, runs, strategy and business development for us. He was on point for both Cyvera and the Morta acquisitions and was also the guy who made VMware a reality for us from a relationship perspective. If you have interest in that, he's the guy to talk with. We also have with us, Uri and Nati, down at the end of the second table there. If you raise your hand, guys.
These are the two co-founders of Cyvera, who flew over from Israel last night, to be here with us today. We'll get a little bit of stage time with them, and they'll be with us all through tonight at the cocktail hour as well. Feel free to introduce yourself or ask questions. We also have way in the corner back there, Raj Shah. Raise your hand, Raj. Raj is the former CEO of Morta Security, who we brought into the family in January, who's with us as well and will also be with us through this afternoon and the cocktail hour. Please avail yourself of the opportunity to speak to anybody on the staff you like.
The other thing we're really delighted about this afternoon too, is we have some of our best partners from a distribution standpoint with us, who will get introduced in a little while, but they're sitting down here too. We're going to do a bit of a panel with them, and open it up for any questions you may have, too, so you can talk to some of the folks who are actually out in the field every day, working with not only our technology but other people's technology too. What I'll do for the next, about 20 minutes or so, is I just want to give you a high level of what we're thinking about as a company, where we're going, and then we'll try to keep this as interactive as we can.
We'll take time during each of the shorter presentations for some Q&A, and at the very end, Steffan and I will field questions along with the rest of the team for a while before we break for the cocktail hour. When we think about Palo Alto Networks as a really unique and compelling company, we think it's got a number of attributes for it. The first is that we're operating in a very large addressable market that's growing. That's true for, I'll call it enterprise network security, and it's also even more so true now with the expansion into the enterprise endpoint security market as well. Large and growing addressable market opportunity, for a use case, which could be simply stated as cybersecurity, which is a very high level, high visibility issue in all enterprises today.
We're offering a strategic solution in order to address that concern or problem for customers. We're doing that uniquely, we believe, with a true platform approach, meaning it's not a product that does many things or cobbling together disparate pieces of technology, but a very ground-up platform approach, and that's going to be important for us in the future, as we roll out particularly things like Cyvera and Cyvera as well, and we'll talk about that. In this platform, and I'll give you a visual in a second of 3 points of a triangle, every one of them is next-generation technology. I think you're very familiar with our next-generation firewall technology. In Cyvera, we found the next generation of endpoint technology, and we're wrapping those things together with our Threat Cloud technology as well, also, we consider very disruptive.
We'll talk through why we think that's the case. What that's resulting with for our customers is, first and foremost, superior security. It's better security. They're also getting fantastic total cost of ownership. We'll see this run through some of the numbers when we hear from Steffan about lifetime value, and things like that. What our customers have found working with us and continue to find is actually the more they work with us, the better the security they get and the less operational burden they have over time. Those two things are very important. Superior security and superior TCO, I think, are the winning formula. That's what we've been doing, and that's what we're going to continue to do in the future.
This has resulted for us in a very compelling business model, I think, somewhat unique again, in that we have a hybrid product SaaS business model, and you can see that playing through in our subscription services as well as product. We've been able for over a number of years now to demonstrate the results of this with very high revenue growth, high billings growth, and a lot of the benefits that come from a hybrid SaaS model from that, and we'll get into some more detail and update you on what that looks like. I want to step back for a second and say, what's the strategic evolution of Palo Alto Networks? What does 2014 mean? Why Morta? Why Cyvera? What are we doing with WildFire, things along those lines.
If I go all the way back to 2008, which is when we introduced our first technology, went to market with it, which is the next-generation firewall, which is the mainstay of one of those three points of the triangle. It was thought of as a next-generation firewall company. It was in an addressable market opportunity at that time of about $4 billion for a piece of technology that's very critical for all enterprises, where we did something very disruptive as opposed to what everybody else was doing in that market. The customer needs at that time were really, the customers were saying, "I'm being invaded by all these third-party applications and traffic on my network, and it's creating a real problem for me." The core value proposition for our company at that time was application visibility and control. The technology is very different.
A lot of customers actually didn't know what to do with it other than when they tested it, they said, "Wow, I get to see things on my network that I never saw before." A lot of times people were installing us to provide application visibility, and they started to grow into control after, like, what could you do with that visibility at a time when it really mattered? If I go back to 2010, what has occurred since we first launched the product, was people are starting to realize what that next-generation firewall could actually do. It's a lot more than a firewall.
All the technology and use cases for that existed already, there was an acceptance from a customer perspective of what the needs were, which were really about, we have all these macro trends driving applications and threat onto the network, that that next-gen firewall could actually do something about it, in addition to providing just the visibility. This is what the world looks like today. Sorry, I think this realization came about five years ago, it's really what the world looks like today, which is all these big-time IT macro trends that are driving an immense amount of productivity for companies. At the same time, they create the perfect storm for the bad guys. You have all these third-party applications coming on the network, all the bad guys know the best way to get on your network is through an application.
You're no longer controlling your applications. If they can get in there, if they can get on your network, you multiply that by whatever, because you have all these mobile computing devices, even more points of entry. You have a complete blurring of the line between what's work and what's home. These applications are not even just corporate applications anymore. Just to make it more difficult, you put everything up in the cloud, it's not even your own network, right? All of these things are really important, together, from a security perspective, this is why security is so hot, right? Why it's so important. Why is everybody talking about advanced threats and cybersecurity? It's because a culmination or combination of all these things has created the perfect storm for the bad guys.
From a core value proposition for us, the recognition or realization from our customers was that they could actually make those applications on the network safe. The first thing is they could easily see them for the first time, they could actually control them, the ones that they wanted, they could make them safe. Everybody else in the market's value proposition was, "We'll prevent the application. We'll stop it. We'll block it," right? That binary approach called let it in or block it just doesn't work for enterprises, because in a lot of cases, they want the applications on the network, they want them to be safe. Even if they don't want them on the network, the chances today of stopping them in the first place go down because the bad guys are getting smarter and smarter.
With that backdrop bringing us up to the present, we believe now that we're serving an even broader market, which is the enterprise security market. It's not just the network, enterprise network security market. With the addition of Cyvera, which is something we've been thinking about for the better part of two years, which is the entry into the enterprise endpoint network, we're now playing in a broader market, which is the enterprise network, which is the combination of those two things. Why is that the case? Why now? Why does it make sense? Everybody's heard about advanced persistent threats until they're blue in the face, right? The breakdown of what an advanced persistent threat means is that the threat itself is incredibly sophisticated. It's very focused and targeted, usually on an individual in a company, in order to get some specific information in the company.
It's the sophistication of the people who are trying to do it has gone up dramatically. Those are the three things. That's what APT means. Those three things together have created a scenario where, from an enterprise perspective, the concept of security is totally strategic. It could be the loss of your whole business. It could be the loss of your reputation. I saw something after Target got attacked in January, said like 54% of the foot traffic in their physical stores dropped off. It's a staggering amount of stuff because of what occurred there. The idea of security as being really, really strategic to enterprises and organizations, I think is for sure. I think that has definitely arrived. The second thing that's arrived, or is coming, is how do they think about that as companies?
I think I use the word holistic here, and I mean that in the sense of when we talk to senior security professionals, and there's going to be 2,000 of them in the room tomorrow. Senior security professionals, they're thinking about their enterprise less and less called, "I'm the network guy. I'm the endpoint guy, and I'm the desktop guy," particularly the higher level in the organizations.
They're thinking holistically about security, saying, "I have to protect the entity, and I'm looking for approaches that allow us to actually protect the entity, ideally in a preventative manner." This is a big reason why when we want to expand into the enterprise market from it, but we've moved into the endpoint space because I think the walls are breaking down very quickly about buying centers inside an enterprise that you're just thinking strategically and holistically called, "I just got to protect this thing." The other thing that has been evolving very quickly is the actual technology itself. By this, I mean really cloud technology, which we've been utilizing since the beginning of the company, for threat prevention.
We did it for WildFire, now we're going to tie together the Cyvera technology as well, which is starting to use the cloud a long time ago, we've developed the methods and mechanisms to use the infinite compute power that's available out there in a very high-speed manner in order to do things at the network, which we've proven for some time, and now we're going to do it at the endpoint as well and use it as the brain, for lack of a better term, to tie those things together from a securities perspective. We think the time is right for us to expand into the enterprise security market, not just the network security market, for all these reasons. We're very confident that we're right about this and that the time will prove us right in the next couple of years.
All that tied together is an approach for us that's prevention first. I wanted to highlight this a little bit because I think there's a couple things about Palo Alto Networks that they're just fundamentally different than what everybody else in this market is doing. Start with philosophical and then go to technology. The philosophical approach is from the beginning, we've believed in prevention, not just detection and fix. Almost everybody in this market today is very focused on detection and fix. What bad thing has happened to my network? The assumption that it's there, can I detect it? Can I fix it and remediate it afterwards? There's nothing wrong with that, right? Because if something bad was going to be in your network, you'd certainly want to be able to do that.
We've taken an approach over time that, wouldn't it just be better to stop it, right? Now, nobody's going to stop everything from getting on your network. We're not saying that we can do that. We do believe that the idea that you can do high-speed prevention, that exists. That's what we've been doing with WildFire for some time now on the network side. As you'll hear from some of my colleagues here, the Cyvera technology is all about prevention, as opposed to just detection. It's about stopping things before they occur in the first place. If you could do prevention, right, as well as detection capability as well, but prevention first, you get to a core value proposition. In 2014, as a company, we think this is our core value proposition for our customers, and we've been talking with them a lot.
This is an enterprise-wide security platform that's going to safely enable all applications that you want on your network through granular use control. It detects all known threats and can stop them, and it can prevent unknown threats in a faster and faster cycle. That's going to be for all users on any devices across your entire network all the time, whether it's physical or whether it's virtual. This is what, when we go out and talk to people, this is what we say, right? It resonates really well because it really means at the bottom here, where I put, which is if you could do that, you would have superior security, meaning better and better prevention capabilities, which is better security.
You would do that ideally with ever-increasing superior total cost of ownership, and specifically what I mean by that is the continued reduction in operational burden on customers for security. One of the things for sure, if you hang around for my keynote tomorrow, that you'll hear me say is customers, they don't even know how to keep score anymore, right? On the security battle about put more technology, put more technology, put more technology. I don't know if I'm winning or I'm losing. Everybody has to spend on security. Like, they have to do that because it's such a strategic imperative for them. There's going to be some point where companies don't have all the money in the world, right?
They have to make hard decisions about what they want to do, and we think a platform approach with this value proposition is a winning formula for those folks over time. I think we've shown this for sure in the next-gen firewall plus the other things around the firewall we've done in enterprise network security, but you just can't do prevention, right, with legacy technology. Stateful inspection technology, which we've talked about a lot, is just an approximation in the first place to even do detection, let alone prevention. Legacy technology doesn't get you there. Legacy technology in the endpoints don't get you prevention either. No amount of consolidation of legacy technology is going to get you there either.
I think that's been fairly well proven by us for the last few years, and it's just going to accelerate, meaning the recognition of that, we think, is going to accelerate over time. I just came across this the other day, this quote up here. This is a McKinsey report that was developed from the most recent Davos Forum, and just a few months ago. They basically went around and talked to a lot of leading companies over there, and this is what they said about security, right? Which is that the traditional approaches are increasingly ineffective, right? They look to be ineffective, and it looks like all they're doing for us is they're passive measures to let us know what happened already, right? Which is usually bad stuff.
Then you got to get into the position and say, "What are you going to do about all that bad stuff?" That's what the industry's been providing. Let me tell you what bad thing has happened, and let me charge you a lot of money to try to go fix that. To get to prevention, we think you have to have a platform approach, next-generation platform approach, that really at the end of the day is doing highly integrated and highly automated security processing so that you have to do less, right? I'll give you a specific example. For detection capabilities, if you have a lot of detection capabilities in your network, generally what happens is if they can detect something bad in the first place, you get an alert, right?
You get an email, you get a text, you get something on your management system, but you get an alert. Basically, it says, "Something bad happened. Good luck," right? Then it's up to you as the customer to figure out what, if anything, you can do to try to stop it, isolate it, fix it. All those things become the customer problem. We think highly integrated, highly automated security in a platform approach is the outcome, and that's what we've built here. It starts with the next-gen firewall, which you guys are all, I think, very familiar with. Basically, this is the device because it's the firewall, right? You have to be the firewall to do this. It's a security device that inspects all the traffic, all the time, in and out of your network, right? It can do that.
In addition to that, detects all the known threats, so it can safely enable the applications on your network, and then it blocks the known threats. It takes unknown threats and sends them off to our cloud, which I'll talk about in just a second. Our newest addition to this would be our next-generation endpoint technology, and the reason I say it's next generation is, and there's the education about this from a customer perspective, is very similar to the next-generation firewall. In the endpoint market today, everything in the endpoint market today is around malware detection and forensic capability. It's that detect and fix mentality. What Cyvera has done uniquely, as far as we can tell, is the only company that's figured out actually how to prevent the exploit in the first place. That's why we think we have liberty with this next-generation endpoint technology.
What that does is it's inspecting all the processes and files across all of your endpoints, and it's actually using the underlying exploit technique itself in order to block or stop or prevent or misdirect, or there's lots of things you can do with it. Basically, the answer is it just doesn't get there in the first place. With our cloud, what we're doing is we're saying that we can take the information from the network. Now we'll get it from the endpoint as well. We can send it up to the cloud. We can quickly analyze it, we can correlate it, and based on what we see in the cloud, we are then able to push to the network, which we've been doing, think of the cloud areas for WildFire, as an example.
We can push down to the network from unknown threat perspective, the signature back to say, "Well, now it's not unknown anymore. Now it's known." Now you can block it or stop it once we know what it is. We're going to do that with the endpoint as well and tie those things together, just like this diagram shows. It's this platform approach that is prevention as the answer. From a customer perspective, sort of what does that look like? If you're going to be an enterprise security company, you have to be able to take care of your customers across the entire enterprise. That means you got to take care of them in the data center, you got to take care of them at the perimeter, you have to take care of them at the branch office.
You've heard us say that before, and now more and more, we think that's going to include the endpoint too. That's just going to be a requirement. It's not so much a move by an attractive adjacency. That's not why we're in this market. We think that is going to become a necessity, a reality for anybody in this market has to do this. The endpoint is in that viewpoint of what the network location is. You have to be able to do it with a family of appliances that can serve the proper throughput needed every one of those places, all with the next-generation technology, which is why we just introduced the PA-7050, which is a data center use case. More and more so, you have to be able to do it completely virtually.
Not just on a physical basis, that's why we've had the VM-Series for a while and why VMware was so interested to work with us and vice versa with the NSX platform, which we'll talk some more about as well. We provide those things on a platform basis with subscription services. Like I said, that allows us to have a hybrid business model of product and SaaS, which has some great financial benefits for us, and then for all use cases. Again, we are unique, I think, in the ability to go into any enterprise, no matter what their use case is.
When they think about security, whatever the use case is, we can answer that use case for them and with the same platform expand over time, and you can see that from our lifetime value, which we'll dig into a little bit later with some more detail than you've seen before. The lifetime value of being able to do that, and more and more so, particularly in the larger customers, of selling the use case just called cybersecurity. When I said it was strategic and holistic, a lot more of our conversation these days are not based on the traditional buying cycle called, "I'm in the market for IPS. Can you help me with that?" "I'm in the market for a firewall. Can you help me with that?" The more and more they're based on, "I've got to solve this security issue across my entire company.
Can you help me with that?" I'll call that use case cybersecurity, and the answer is, "Yeah, we can definitely do that." All based on top of our proprietary PAN operating system, which we rev once a year with lots of features and functionality to power this whole thing from a platform perspective. You get this great security, and you get this total cost of ownership benefit. I just grabbed four quotes from customers. We have literally thousands of these, of very happy customers who are working with us primarily because of the next-generation nature and flavor of the security platform. But this ever-decreasing operational burden thing's a big deal, and I think it's going to become a bigger deal over time.
This is the kind of things they say when they work with Palo Alto Networks, which is, "I'm in a better spot than I was before, and it's actually costing me less to be there." That's a very compelling value proposition, and one we're going to keep driving over time with this platform approach. It matters because we're in a huge market. The market opportunity for us is the network security market now plus the enterprise endpoint security market, which is by a lot of estimates in just a few years' time, is a $20 billion market opportunity. It'll take us time, obviously, to address the enterprise endpoint side. $5 billion is a big number, but we'll have to work our way into that.
Also customers, this viewpoint about them thinking about just the enterprise as opposed to different buying centers, that's going to take some time to work itself out as well. It gives us even a bigger opportunity than one we've been in before, and kind of no matter how you slice and dice the numbers from where we are from a revenue basis as a company, we're in single digits in a total addressable market opportunity, where we think the ability to double, triple, and even more from our market share is entirely possible for us in a very acceptable period of time, because the customers really like the security, and they really like the total cost of ownership. We've demonstrated this over time, the ability to do this. Our model is very simple, PAN and expand. We can address any enterprise security need for folks.
We have been able to put a lot of customers into the funnel, if you will, at the top of this land strategy. We have over 16,000 enterprise customers today. We've been adding over 1,000 a quarter for nine quarters in a row. We would expect that we would continue to have rapid customer acquisition. It's a big world. There are a lot of enterprises out there. We are under-distributed in a lot of cases around the world today, particularly outside the U.S., meaning just brand recognition, feet on the street, the ability to touch customers in the first place. We think we have a great opportunity to continue to put a lot of customers into the top of the funnel, which is critically important because of the next point, which is once we get them, we've demonstrated the ability to expand them.
The one I threw up here was a 2009 cohort, the reason we use 2009, which came to market in 2008. That cohort is actually higher than this one, but it's such a small base, I'm not sure it really matters. The 2009 cohort is currently at over six times their initial purchase and lifetime value with us, and that continues to grow. As Steffan will get into some detail, the cohorts are following suit with that. That's resulted in very rapid revenue growth for a company that I would say is at scale. We're operating well north of $500,000 in revenue run rate today.
That implies a substantially larger bookings number in order to do that, given the flow down model that we have today and still growing, as you can see, at 48% year-over-year revenue growth for the first half of this year. Earlier, I sort of started with this view at a glance, but we can really simplify this in just three things for Palo Alto Networks. The first is our philosophical approach that then leads into technology, is a prevention approach. It's very different than what everybody else is doing in this market today. The idea of being able to stop things as fast as you can or as quickly as you can if they're happening is very compelling with customers. You can't do that without a next-generation platform underneath it.
Next generation of the three components I showed you, and definitely from an integrated perspective of the delivery of that cybersecurity solution for folks with a platform view. That results in the superior security with ever-decreasing operational burden over time. We think these are the three things that are defining for the company, and these are the three things that'd be more and more defining for our industry. Whether you can actually stack up to these three things is something that's going to play itself out, we think, in relatively short order in a matter of years in this business. We don't think everybody else stacks up. We think we're going to be continuing to grow pretty quickly with that. That's going to wrap it up for myself.
I'm going to do some Q&A at the end with Steffan, I don't want to take this time right now. One of the really important things for us, or probably the most important thing for the company, is we're a technology company. We're very technology-driven. We have fantastic go-to-market capabilities and motions and teams. We really start and end each day with technology, what's the customer going to want and what's the customer going to need. That's the reason why we did a couple of these acquisitions, because we found fantastic technology in Morta, we found fantastic technology in Cyvera, and we're building fantastic technology.
I thought it'd kind of be helpful if we heard from Nir for a little bit, who's our CTO and founder, who had a vision eight or nine years ago, and we're really working rapidly into the fulfillment of that vision. I'd like to introduce Nir. Thanks.
Okay. Thank you, Mark. Thank you, everyone, for coming here. I'm Nir, I'm founder and Chief Technology Officer of Palo Alto Networks, and I want to spend the next 25 minutes talking about what are the requirements from the next-generation security platform. Meaning, what do you need to have, what we believe you need to have in order to be a next-generation security platform provider, okay? I'll try to speak less than 25 minutes so you can also ask a few questions at the end. Mark showed you the platform. The platform has three components. It has a network component, it has a host component, and it has a cloud component, and we started building that platform eight years ago. One interesting thing about building a platform is that you cannot decide one day that you are a platform and then become a platform.
Meaning, if you haven't built it as a platform from the beginning, it's not going to be a platform. You cannot take a point product and make it a platform, and I think we've proven that. We've proven that our competitors, which have taken their existing products and kept trying to retrofit it again and again and again by adding this blade and that blade and this function and that function, are still only growing 2% year-over-year. Okay? We're growing 50%. We're growing faster than them even in absolute dollars. There's a good reason for that. It's that you cannot retrofit what you have to become a platform. Okay? You have to start from the beginning, and you need to have a platform mindset in order to build a platform. What does it mean to have a platform mindset?
It means to have a very long vision of where you want to be and build towards that. You start small, and you start with one component and one function, but you build it in such a way that it can become a platform, and it can encompass everything that you want it to encompass. Okay? We started building the network component, the next-generation firewall, about eight years ago, just over eight years ago. We started building the cloud just over eight years ago. Back then, the conventional wisdom was that to be best of breed on the network side, you need to be individual component provider, meaning you have to be a standalone IPS, you have to be a standalone firewall, you have to be a standalone this and a standalone that.
Also, the conventional wisdom for taking malware and understanding it and making your network or even your host being able to detect and stop it was that you need to have 600 people in the Philippines sitting down and doing it for you. We changed both. Okay? We created the network component of the platform to be able to do many different things in what we call the single-pass engine, which we'll talk about a little bit later. We also created the cloud-based component that can take malware and automatically convert it into whatever the network needs in order to block it the next time it comes in. We've been doing it for a long time now. Since then, we've been adding more and more functions to the network and more and more functions to the cloud.
We did it in a way that didn't change performance or functionality for our customers, which shows that it's a true platform, right? That's one thing that a true platform needs to provide, which is the ability to do more and more and more and more, and consolidate more and more and more functions without reducing existing functionality and without reducing performance. One of the first things, like Mark said, when we started building the platform, we decided that we're going to be a prevention platform, meaning we decided that it's going to be hard. We had to fight for that against very strong competitors. Our philosophy was we are going to prevent attacks.
We didn't want the customer to wake up in the morning and see that 70 million credit card numbers were stolen and then have to call prevention professional services guy, IR, and incident response guys to come and investigate it for 2 months to tell them how they got screwed. We wanted to make sure they didn't get screwed in the first place. Okay. That's our philosophy, and that's going to continue to be our philosophy. There is a real argument in the industry between those that think that you need to prevent things and those that think that you need to detect them and then have people come in and tell you how you got screwed. I guess both approaches are valid because customers are paying money for both, and we strongly believe in ours.
The second thing that we decided from the beginning with our platform is that we're going to safely enable applications. We are going to go to the CIO and tell them that we're here to protect them against the bad nations and the bad actors and the bad criminal organizations and all those that are trying to attack them. We're here to enable the safe use of applications. We are here to make sure that you can use not just email and web browsing. We're here to make sure that you can use SaaS applications like salesforce.com. We are here to make sure that you can use box.net, and we are here to make sure that you can use SharePoint and you can use Office 365. I mean, back then, there wasn't Office 365, but Gmail and Google Docs and applications like that.
We're here to make sure that they're being used in a safe way, which means that whatever our competitors do for web and email and for files, we need to do for everything, okay. We're still the only ones that do that. When you talk to our competitors, they'll be very happy to sell you an application blade that's going to block SharePoint for you. They cannot scan SharePoint for viruses. They cannot scan SharePoint for export of vulnerabilities. They cannot take SharePoint documents and run them through their sandbox. They'll be very happy to block it for you. Our approach has always been, and it's going to continue to be, that the platform and all the different components of the platform need to work across all applications. That's what we mean by safe application enablement.
Our job is to make sure that enterprises can use applications in a safe way. That's what we're selling them. Okay. Now, focusing on the network component, our philosophy is that the network component needs to run everywhere. All enterprise traffic needs to be inspected at the network level. That includes internet traffic, that includes data center traffic, both internal data center, which is a very big market, external-facing data center market, which is a pretty small market, branch office traffic, cloud traffic, if you host your applications in the cloud, of course, traffic coming out of mobile devices. All that traffic has to be inspected and has to be inspected in the same way. This is another philosophical difference between us and our competitors.
Our competitors believe that, for example, on the internet gateway, you need to inspect traffic in a different way than you inspect it in a branch office and in a different way than you inspect it in the data center. We think that it has to be the same. For example, some of our competitors, actually, most of our firewall competitors, if not all of them, will tell you that, yeah, in the internet gateway, you need this Palo Alto thing of safe application enablement, but why would you need it in the data center? It's clear why they're saying it. They're saying it because they can't even run at the gigabit speed when they turn on all the different functions that we do on the internet gateway. In reality, the enterprises today cannot treat their internal network differently than they treat the Internet.
They've got to assume, they are assuming, that's what they're telling us. They're assuming that the bad guys are already on their network, that some of their endpoints have already been taken over by the bad guys, and they need to protect their own data centers, their own crown jewels, their own applications, from their own user network, the same way they protect their user network from the Internet. The bad guys are already on their network. Our competitors are insisting again and again, "No, you don't need to do that. The bad guys are not on your network. You can put the regular stateful inspection firewall in there. No, you don't need the IPS. You don't need to look at all applications. You don't need to look for command and control connections. You don't need to look for malware in the data center.
You don't need all that. Just put a regular firewall. It's going to be fine because your network is clean." Our approach is very different. Then there's always the question of, do you really need to be the firewall everywhere? Meaning, or is there room for 2 devices or 3 devices or 4 or 5 devices? In some places, it might make not an economical sense, but it might work if you put multiple devices, like maybe the internet gateway. I don't think so because we believe that everything needs to work together for superior security, and we can talk a little bit about that in a second. Yeah, theoretically, you can put 5 devices in Internet connection, but in the data center, you can't. In the data center, your firewall connects to multiple networks inside a data center.
You have different physical networks or different virtual networks inside a data center. The firewall has many physical links coming out of it. If you want to be the IPS, for example, and you don't want to be part of the firewall, then you're going to have to put an IPS on each and every of these physical links, if you want to do prevention. If you want to do detection, that's fine. You can take a single IPS, which is really an IDS and like an octopus, send your arms to different networks and monitor them. If you want to be in line and you want to prevent stuff, you have to sit on all those links. Does it make sense to put a firewall and then 10 IPSs behind it? Nobody does that.
If you want to do prevention, you have to be the firewall. Only the firewall can do prevention. This is why some of our competitors insist that you don't need to do prevention, that you need to do detection and then call IR, incident response people, when you find something. Because they're not the firewall, what can they do about it? Okay. What do you need to do at each of these locations? Malware is trying to get in, you need to look for that malware. How do you do that? Traditionally, you do it with sandboxing, and the proxy does it traditionally. You have to replace them if you want to be a next-generation firewall, which is part of a next-generation security platform. You want to look for command and control connections.
If the malware is already on the network, you want to look for that malware communicating with the bad guy. They do it over something we call command and control connections, that's traditionally done by the IPS. Every network location has to do that. You need to look at DNS traffic. One of the Achilles' heels of malware is trying to resolve the domain names of where the bad guy is, because they don't use fixed IP addresses. Those can be blocked easily. Looking for that traditionally can only be done by the firewall, because the firewall is the only device that sees all the DNS traffic. You want to look for URLs.
You want to make sure that users are not going to URLs of websites that are known to be hosting malware, or that there is no communication with well-known command and control infrastructure that are based on URLs, on HTTP, which is the vast majority of them. For that, you need to be the URL filter. You have to do all those different things at each network location, at the data center, at the internet gateway, at the branch office, for mobile traffic, and at the virtual data center, at the cloud-based data center, if you want to be a next-generation security platform. You have to do all those things. There's only one proven way of doing all those things at each and every of these locations, that proven way is the single-pass engine.
All our competitors, which started with one-point product, usually a firewall, sometimes a different product, then started adding blades on top of it, have been proving again and again that it doesn't work. It doesn't work. When we go to an IPS deal, they don't show up. The only people that show up in IPS deals are the standalone IPS people. The firewall people that have an IPS blade, a UTM blade that does IPS, they never show up. They know they cannot win against a standalone IPS solution. We can. We win. We have proof of that. When we go after APT deals, only the APT guys show up. The firewall guys, they don't show up. When we go after content filtering deals, only the content filtering deal guys show up. The traditional firewalls that added all these different blades, they don't show up.
This consolidation approach, this let's take different components and put them together on the same platform, they don't work. They also don't work in the other direction. We've seen blade providers like an IPS provider or an APT provider now adding more and blades to their solution, right? An APT provider adding IPS, or an IPS provider adding APTs or anti-malware, it doesn't work either. The approach of taking a blade and adding blades or taking a firewall and adding blades, those approaches have been proven again and again not to work. The only approach in the market that works is this, okay? That conclusion is that you have to start building your platform as a platform from scratch. It has to scale.
It has to be able to run at tens of gigabits per second in the data center. It has to be small enough to run at the branch office. It has to become virtual, and it has to do all kind of things and across all applications for you to be able to call yourself an enterprise security platform. Okay? Now that we talked about network, let's talk a little bit about the cloud, okay? In the cloud, actually, one second, one more thing about this slide. This slide talks about prevention. This slide talks about who can do prevention, how fast can they do it, meaning can they do it fast enough to be in the data center, and can they do prevention at all, and across what can they do the prevention?
Let's talk about cloud for a second, about the cloud component of the next generation enterprise security platform. What do you need to do in order to be a cloud provider, in order to be a next generation security cloud provider in the cloud, in the next generation Threat Cloud? The role of the cloud is simple. The cloud collects information from the network, and now from the host as well, takes that information, crunches it, finds bad things, comes up with signatures to detect those bad things, very quickly turns around and sends them back to all these different devices, both network-based and host-based, for detection. Okay? On the network side, the cloud would be collecting applications like executables or Android applications. It would be collecting documents like Office, PDFs.
It will be collecting access to URLs to check whether they're good or bad, DNS traffic to see if the DNS traffic is going to domains that are well known to be malicious, and so on. On the network side, you'll be collecting applications, executables, Android applications, iOS applications, and others. You'll be looking at access to operating system functions, crunching all that information, coming up with signatures, and sending them back to both the network and the endpoint for enforcement, for prevention. If you look across the industry, different vendors can do different pieces of it. There's only one approach that's been proven to be able to collect all that information. Today, we do it within 30 minutes, come up with signatures, and send them to all our customers for prevention. Okay? That's the only approach that's been working in the market.
Last, I want to talk about the endpoint. First, why do you need an endpoint? Why do you need endpoint security? Why isn't network plus cloud enough? The answer is that you cannot see everything on the network. Sometimes bad things get on the network, not even through the network, like through USB keys and others. There are attacks that cannot be detected on the network. The most sophisticated attacks can, in some cases, only be detected on the endpoint. Is the endpoint enough? No, because some attacks cannot be detected on the endpoint. Some attacks can only be detected by the network, especially if those attacks affect things that you cannot run endpoint security on them, like POS, point of sale systems, routers, switches, printers, multifunction devices, and others. Okay. There are really two high-level ways of getting on an endpoint.
The first way of getting on an endpoint is by getting the user to install something. Getting the user to download an application and install it because they like it. It can be Angry Birds that takes all your email and sends it somewhere. It can be some movie player for Windows that the user installs because they want to see a new kind of movie, and that movie player is actually a piece of malware. It can be a USB stick that you throw in the parking lot and hope that one of the employees will pick it up, stick it into a laptop to see who it belongs to, and you know what happens next. That's the first way of getting on an end user machine, is by getting them to install something. How do you detect that?
Traditionally, you do it with antivirus, with a traditional antivirus. You do it with sandboxing, taking executables and sandboxing them. You do it with what's called IOC-based. This is like next generation AV, indicator of compromise base detection, and you can do it with whitelisting. Whitelisting says what you can run, so if you haven't seen it before, you can't run it. The other way of getting on user endpoints, which is the three other bullet points that you see here on the slide, is really what the more sophisticated attacks use, which is exploiting vulnerability. You find a problem, we will talk about it a little bit more.
You find a problem with some application running on the end user machine, you exploit it, then you get to run something on the end user machine, and by that, you get the malware without user intervention, meaning the user didn't even know that it happened. Or maybe they know that something is wrong, they don't know that malware got installed. There are really three different cases there. The first case is when you exploit a known vulnerability, something that as a vendor you know about, and/or a malware that is known or at least from a known family is installed on the end user machine. This is a simple case. This is more true for the widespread attacks, in those cases, you can detect them using traditional network IPS, host IPS, again, IOC, next generation AV base detection, and whitelisting. Okay.
The more sophisticated attacks exploit unknown vulnerabilities. They use malware that you've never seen before. They use both completely new vulnerabilities that nobody knows about. They use a piece of malware that's very different than anything you've seen before. In that case, the only traditional technology that works is whitelisting. Okay. Because that malware that you see there is still not something that was approved by the enterprise to run. Therefore, the whitelisting service can block it from running. The most sophisticated attacks, these are the real dangerous, targeted, sophisticated attacks, are those that don't even involve malware. In those cases, the bad guy exploits a vulnerability on the end user machine. They run something inside memory, and that's it. Nothing ever gets installed on the hard drive. Nothing ever touches the OS. There's really no way to detect it like that.
We've been looking at the markets, as Mark said, for the last two years. We've tested every solution on the market. Anything you can think about, any startup that has endpoint security that is talking to you, we tested their solution. One company stood apart from everyone else. The reason they stood apart from everyone else is because of their ability to do all those different things. They can do it in a way that doesn't change the way end users work, unlike whitelisting and microVMs and all the other approaches, which might work for some of these cases, but really change the way end users work. The Cyvera approach doesn't change the way the end user works. You just install it on the machine, the user keeps doing what they did before. It just works.
More importantly is this last row over there. The most sophisticated attacks, which don't even involve malware, they exploit vulnerabilities and use in-memory programs. They never make it to disk. They can bypass everything else on the market. The only solution we saw on the market that can stop them was Cyvera. It's extremely difficult to do that. When we talk to our internal people, which are not dumb either, we have a very good security team, they just said, "Look, we don't know how to do it." Okay. "We don't know how to do what Cyvera does," which is detect the most sophisticated attacks on the endpoint. Okay. The next thing I want to do is to talk about what Cyvera does.
Yeah. We have Uri and Nati joining us today.
yeah, it's probably better if Uri and Nati were here. A little bit jet lagged. It's now midnight in Israel. Okay. Uri, Nati, can you maybe introduce yourself?
I'm Uri Alter.
I'm Nati Davidi. I'm co-founder of Cyvera.
Okay. I think it works now. Move forward a little bit. Yeah. It works? Okay. Both co-founders of Cyvera, why don't you tell us what's so special about Cyvera? What is it that you do?
Thank you, Nir. In order to explain why Cyvera is substantially different than any other endpoint security solution, we'll start by having a look on that pretty simplified flow of targeted attack. Whether the attacker is aiming, gaining access to critical infrastructure and disrupt it or to gain access to sensitive data assets, he will always start by looking for vulnerability in the organization system. He will look for a way to utilize this vulnerability to practically exploit this vulnerability, which is not simple thing at all. After finding a way to do it, he will inject a malware to the endpoint, to the server, to the whatever system in the organization, just to initiate the attack. Now, in terms of numbers, there are probably 1,000, you can see the number on the screen, 1,000 new vulnerabilities per year on any operating system.
When it comes to the malware, the left stage of the initiation of the attack, there are hundreds of thousand new malwares a year, practically millions of them, millions of variants per year. It's very, very hard, of course, to know about all of them. When it comes to the exploitation, to the way of utilizing the vulnerabilities of the system, there is a very small group of techniques that are utilized by the attacker for a decade and a half now. This group is something that if one can deal with, he'll be able to practically deal with all the vulnerabilities and all the malwares without prior knowledge. It sounds almost obvious, and the reason that no one did it until now, it's just because it's very, very hard.
It require, sorry, knowledge, not only in security, but also in operating system and hardware and the way CPUs are working. Again, if one have the ability to deal with that, he can prevent attack without having prior knowledge on the malware, without having prior knowledge on the vulnerability itself, and it will prevent the attack before the malware is running, meaning it will prevent the attack rather than trying to detect it after the damage already was initiated. Let's have, again, the look on the same flow, and this time, in terms of the existing solution. When it comes to the first stage of vulnerabilities, there are some host-based security solution trying to provide virtual patching, automated patching, trying to deal with these vulnerabilities, but they will cover probably only the known vulnerabilities.
More than that, there's a lot of production implications of using these solutions. When it comes to malware, again, and it's also already an old news, it's very hard to deal with the unknown malware. It's very hard to avoid the fact that the attackers can easily reverse engineer the system in order to bypass the security solution. For those of you who are going to stay here, we will show a lot of demos in the upcoming days. Again, basing on signature and prior knowledge won't help you in preventing the attack, but only maybe to detect it. That's the reason Cyvera went with exploit techniques prevention. There is no off-the-shelf solution today for that specific layer. Again, because it's very hard to deal with that.
Cyvera is the only product that have the ability to deal with the exploitation of vulnerabilities, with the way the attacker utilize the vulnerabilities, and therefore, have the ability to deal with all the malwares and vulnerabilities on the endpoint with a minimum CPU and IO resources. That's at a glance, a description of Cyvera, and I hope it creates a value.
When I met Uri and Nati about a year ago for the first time, one of their investors is a military buddy of mine, and he brought him for a meeting. I think we made it to click because what I saw back then is that they're trying to do in the endpoint security market was exactly what I tried to do in the network security market eight years ago, which is go after big incumbent vendors that have been using old technologies that just don't work anymore, and doing it in a very disruptive, in a way that is very simple to explain. Right? On the network side, you just do everything across all applications with a single pass engine. What's the problem? What they're saying is, "Well, don't look for the vulnerabilities. There are too many of them.
Look for the ways the vulnerabilities are being exploited." Both sound easy, both work, and both are extremely difficult to execute. That's why I like them. Uri, why did you guys decide to join us?
First of all, I think that, as Nati said, what we're doing is substantially different. We got a very strong feedback from customers understanding the need for something which is substantially different, and they really appreciate what we're doing and got it. Now, we understood that if we want to solve the problem, the big problem, we have to do it on a multilayer solution. We looked for partners or partnerships. Once we dig in, we found that Palo Alto Networks, everything that just happened, everything that happened from the beginning of the panel until now, is the same philosophy like ours. It made sense for us to dig in, and we digged in, we saw that the technology is a perfect fit.
More than that, again, the culture, understanding that what we have to do is something substantially different, not the next generation of a very small leap, but a big leap. Joining Palo Alto Networks, doing that together, where they already did it on the network level, and now doing that on an endpoint level, combining that together and producing a totally new security solution for enterprises, we thought that that makes a perfect fit. That's why we chose that after a lot of consideration. It made perfect sense for us.
Okay. Thank you, Uri. Thank you, Nati.
Thank you very much.
Uri and Nati will be around here today during cocktail hour and in the next few days. If you have any questions, of course, you can ask them. To summarize, the next-generation security platform has three components. We believe we have the best one on the network side. We've proven it again and again with our growth rates and with market share taking from the incumbents. We think we have the best cloud. I think we've proven that again and again. We have the only cloud that's able to generate signatures that go within 30 minutes and actually help the end user to prevent bad things getting through the network. We've been doing it for many years now.
I think that now with the acquisition of Cyvera, we have by far the best next-generation endpoint security technology, and this is something we still need to prove to you, but we will. We're about a minute over time. Do we have time for a few questions or? Please.
This is going to be webcast-
Okay
I need to give you a mic. The other thing is if you're all taking pictures of the slides and keep emailing me, they will all be posted as soon as we're done. Don't stress. It's all good. Here you go.
Hi, Nir. A question on Cyvera. Does somebody need to coexist with WildFire to be effective, or can you have Cyvera deployed on the endpoint and not have WildFire on the network?
WildFire is a sandboxing technology that looks at incoming files, executables, documents, and other things, and tries to make a decision whether they're good or bad. It works for the most part. Sandboxing technology, as good as it gets, cannot detect everything, and you need multiple layers. Cyvera is a technology that can detect exploits. They cannot detect an executable getting on an endpoint. That's something that the sandbox can do. If an exploit on the endpoint tries to happen, to be exploited, for example, an exploit in Adobe Acrobat or in some Microsoft Office or another application, they can detect that very well, they complement each other. Okay? You cannot use one really without the other, meaning there's no 100% in any of them, and together, they provide very good protection.
I guess just to follow up on that point.
You're on.
Am I on? Okay, yeah. Just to follow up on that point, if this is one piece of functionality on the endpoint, are there other pieces of functionality on the endpoint that you need to have a broader kind of protection layer?
The answer to that is that if you only have an endpoint solution that is completely separate from the network solution and from the cloud, then yes, you need to have other components on the endpoint. I think that if you combine your endpoint solution with the right network solution where they can share information and each can complement each other by looking at the things that they are good at looking for, then you don't need much more. You need a little bit more, and we do plan to offer that more as part of the endpoint client. Yes.
Nir, just to point, you talked about exploits, and then you talked about memory as opposed to vulnerability. Can you just clarify that with regard to Cyvera? Do they do the block the in-memory?
When you exploit a vulnerability, you also need to run something after that, okay? Usually, what is an exploit? An exploit is a small piece of code that the bad guy gets to run on the endpoint as part of the exploit. You exploit a vulnerability, and you get to run a small piece of code. Usually, that small piece of code does one thing, which is go out to the internet, download the actual malware, install the actual malware, and then run it, okay? That gives you an opportunity to detect that malware, for example, using whitelisting services and other things, which again, they put a lot of burden on the end user, but they can detect it. With Cyvera is the only solution on the market that detects the exploit itself. It doesn't detect the malware the exploit brings in.
It detects the exploit itself, even if that exploit exploits a vulnerability that's never been seen before. The way they do it is by looking at the tools that the bad guy needs to use. There's no other way for them. They need to use it in order to perform the exploit, okay? It doesn't matter if a malware actually gets downloaded and installed, or this piece of code that the bad guy gets to run as part of the exploit was big enough to perform what they wanted to perform, Cyvera will detect it. Actually, Cyvera, another thing I really liked about the Cyvera solution is that they can detect failed exploits. Even if the bad guy, which happens a lot, they try to exploit a vulnerability, and they fail, and then they'll try another one, and they'll fail.
Even if they try to exploit a vulnerability and that exploitation fails, they still need to use the tools. They still use the tools to perform that exploitation, and the Cyvera tool can detect it. It's the only tool we've seen that can detect all exploits, including the failed ones.
We have time for probably one more question. You want to take it from over there?
Hi, Nir. I watched some of the videos on Cyvera's website, and the implication was in some of them that you could actually run systems unpatched because of the technology that Cyvera has. This seems like an incredibly valuable technology. Why were you able to buy it? Why isn't an operating system company interested in this? I guess a follow-on question, do you have to instrument the operating system to get this to work? Do you have to instrument the software application to get it to work?
I don't want to get into too many technical details about how Cyvera works, but you instrument things that are at very low level, sometimes even below the operating system, like memory access and things like that, as well as some operating system-related things. In terms of working on unpatched systems, so essentially, when Microsoft comes out with a patch, what they really do is they fix a vulnerability, right? There is a vulnerability in Microsoft, they come out with a patch to fix it. You don't need that with Cyvera. Cyvera is running on the box. There's just no way to exploit that vulnerability, and that's a very powerful thing. Your question was why an operating system company wouldn't buy it.
Well, maybe if they were interested in that company.
I don't know if they were interested or not, as I think Uri said, they wanted to come to Palo Alto Networks, I don't know. I don't know if they had an offer from an operating system company or not, it certainly makes sense that an operating system that cares about its customers, and maybe that's where the issue is, would be doing that. Yes.
Can you just real fast talk about signatures from this? There's a lot of signature-less. What does that all mean?
Signatures and signature-less.
Yeah.
Yeah. A lot of talk about that in the industry. Mark, I think this is again, a detection versus prevention argument. It is true that, number 1, signatures have bad reputation. The reason signatures have bad reputation is because, according to our statistics, 40% of the malware we're going to detect today using WildFire, and Lee will tell you how many pieces of malware we're going to detect statistically today with WildFire. 40% of the malware we're going to detect today with WildFire, will not be detected by any of the major AV vendors a week from now. Even a week from now, they will not have signatures to detect 40% of what we detect today. Signatures certainly have bad reputation. On the other hand, to do prevention, signatures is the only mechanism that works.
You cannot do prevention without signatures, because signatures are the only mechanism known to us and to the industry and to everyone that can run at 10 gigabit per second with sub-millisecond latency. Prevention requires high speed, low latency, real-time, in order to work. The only way to do prevention is signatures. The question is, how do you bridge the two? How do you bridge the fact that signatures are generally bad and the fact that you need to run signatures at least for detection? The answer is, Excuse me, for prevention. The answer is, you use other things for detection. You use sandboxes for detection, and we have a completely customized virtual machine that we developed ourselves to do sandboxing. You can use DNS-based tricks that we're doing. You can combine it with some of your URL filtering technology, which we're doing.
You can collect a lot of information from your customers into a very, very big Hadoop database and run a bunch of processes on it that are designed to detect even more bad things. You can do a lot of things to detect bad things, but they take time. It takes about five, six minutes to run something in a sandbox before you know if it's good or bad. You cannot do that in real-time. Once you do that and once you know it's bad, you can turn around, generate a signature very quickly, such that the next time, you can prevent it. Okay? I think that the argument, again, on signature and signature-less is in detection and prevention argument. Yes, the best way to do detection is not to use signatures, and we don't use signatures for detection.
We use many other things, including customized sandboxes and other things for detection. For prevention, the only thing you can do is to use signatures. Unlike the AV vendors, we come up with signatures within 30 minutes after we see the bad thing, or less, in any of our customer networks. When we see something bad on a customer network, we'll know about it very quickly using our cloud-based technology, and within 30 minutes, all our customers that subscribe to the WildFire service will be protected against that thing. With the only way to protect against bad things, which is signatures.
Great. Thank you. Again, we can spend more time with Nir after. Appreciate that.
Thank you, Mark.
With the addition of Cyvera to the mix too, I think you'll see us looking different as a company too as we go to market. I was going to ask René if he would just join me for a quick 10 minutes up here to talk about a few things about how does Palo Alto look today, and what it's going to look like in the future, from a go-to-market perspective. We just kind of make ourselves comfortable, I guess.
Yep.
Okay. Maybe just start off, like, how are customers using us in their networks today? How has that evolved over time? What have you seen?
I've been with the company. I'm in my sixth year. I can tell you when we started the company and started selling, we were used as a helper, right? People came to us and said, "You can help me solve one thing." Six years later, we have become not only a piece of the infrastructure. In other words, we have become, I think well over three-quarters at the time, the primary firewall in all those implementations. In addition, we're doing a lot of other things in addition to firewalling. The use case that we have seen evolve is doing multiple security functions, right? In multiple spots on the network. One of the key things that we track is the adoption of our technology, not just on the perimeter, but also in the data center, as well as in branches.
Today, about half our business is on the perimeter. 35% of our business is in the data center, either a core data or corporate data center, an internet-facing data center, or a cloud data center, and 15% of our business is in branches.
What's the velocity of those look like?
The data center is rapidly taking this share. The credibility we had to have to do that really came when we introduced the PA-5000 series. With the launch of the PA-7050, there are additional use cases that we can fulfill, because it's the only next-generation firewall that can run at 100 gig plus and do all the security functions. This has been a crusade almost that we had to do for years because there was a firm belief that you had to have more security functions on the perimeter. As it turns out, the data center is just as vulnerable and just as prone to attacks as the perimeter. Therefore, it isn't good enough to run 40 gigs or 80 gigs of simple traffic control on the data center. You have to have a next-generation firewall in the data center.
With this sort of platform approach, We call this the Holy Trinity, by the way, the aspect. If you're a customer on the receiving end of Palo Alto Networks.
Yeah
From a marketing standpoint.
Yeah
Starting Monday after.
Yes
Whenever the deal closes. What are you going to hear?
For the last 5 years, the story has been one of enablement versus prevention. We have said, we are all about application enablement, making it safe to use those applications. We are against preventing applications in the first place. Because the traditional answer has always been to make applications safe, you have to prevent them. Interestingly enough, we're doing almost like a 180 here on the malware. We're going to say, well, prevention is the Holy Grail for malware and for attacks, because it is actually crucially important that prevention becomes the leading story versus the approach of detection and remediation. This is not going to be trivial because the market has been conditioned, just like it was 5 years ago, to not believe that it could be done.
In a lot of ways, my job for the last 5 years has been as an evangelist, saying that it is actually possible to make application safety use. The fact that even today, we shield the baby with the iPad, we still have to explain to the market why it is critically important that enabling an application and making it safe is different from blocking it altogether. What customers are going to see is a value proposition that is both extremely focused on the applications being the good guys, the malware being the bad guys, and while we enable those applications, we can prevent everything that is bad. That will be seen in a massive rollout throughout our own organization as well as our channel organization in the days to come, in fact, starting tomorrow.
I'll do it tomorrow when we have 2,000 of our best customers here in Las Vegas to start going down that path.
Last question. There's been other network companies over time that have, I think, from it said, "Hey, there's an attractive adjacency aspect of the endpoint," and that hasn't really worked out for them. Why do you think that's the case, and how do you rate us?
Yeah. We thought about this long and hard. Five years ago, when we started to really seriously market the next-generation firewall, everybody said, "Well, why would you? Nobody cares about firewalls." It was a market that almost didn't grow, and there had been almost no innovation. Why do you even care? Well, because we're very, very different. Today, it feels exactly like that again in the endpoint market. We've seen years and years and years of the same technology. We've seen traditional network-based vendors buy some of the technology or take it out of open source and do something with it in the belief that by doing the same thing over and over again, it would somehow be different. It wasn't. This approach is as disruptively different from the traditional endpoint vendors as this.
Now, there is something else, though, because the technology is only one part of this. The other part that we were very concerned about is: has their buying motion changed? In other words, traditionally, when we came to market, the guy who took care of the firewall was typically a networking guy. What we were able to do with the next-generation firewall was transcend the two worlds of network and security. We could bring those two worlds together and have a conversation about security in the firewall and making it safe to use applications and all these use cases. That was a transcending conversation because the use case was that all these applications came onto the network. All these mobile devices came onto the network. All of a sudden, the tribal differences between the networking guys and the security guys went away.
Well, today, we believe that those tribal differences between the networking guys, the security guys, and the endpoint guys will go away because the pressure is so much on the security of these organizations that if you solve it in different ways, you still do not coordinate. The conversation about securing enterprises is no longer a bottom-up approach where the networking guys get to decide one thing and the security guys something else, and the endpoint guys do something completely different. That is the case, and we clearly have to take care of the operational implications of doing business, but the decisions are no longer made there. The decisions are made top-down by folks who, from a political perspective or from a policy perspective, make those decisions and transcend the tribal wars that you typically see in organizations. Again, that is a firm belief that we have.
When we were in consideration for the acquisition of Cyvera, and when we talked to our larger end customers, they all were very appreciative of somebody coming in who can do this. Not through consolidation necessarily, but by bringing the security functions of these different things together.
Great. Well, throw it open for some questions for René or myself if anybody has any questions.
Rob.
Yeah, Rob in the back there.
Hi, René. Just a couple of questions. Maybe give some perspective in general on increasing customer acquisition costs that we're seeing in security, as a lot of companies are running at pretty significant negative margins from the sales and marketing perspective. Number two, from a marketing perspective, how you cut through the marketplace, especially since you mentioned that the buying motion has changed and it's becoming more political.
I am pleasantly surprised when some of the other parties in the market say that they don't spend enough on sales and marketing, clearly marketing, because it would somehow imply that we're doing something that is very easy to replicate. Marketing is not something that you can just solve by doing it with money. Throwing money at marketing is not necessarily the right thing. In a lot of ways, we care about one thing. We care first and foremost about the story that we tell. It is exceedingly important that you tell a story that is differentiated. The fact that everybody now says they have a next-generation firewall doesn't mean that they have a next-generation firewall. It means they're following our marketing. The fact that they come up with an idea that just by spending more on advertising, that is going to help, I don't think that's true.
The one thing that we have done very consistently is stick to the story because it's still differentiated, regardless of what people say. The way we do this is we measure marketing spend incredibly well. Between Mark Anderson and I, we run a very lean machine and a very oiled machine when it comes to demand generation. Because at the end of the day, that's what matters. With our channel partners, having a complete closed loop on the generation of opportunity is much more important to me than having billboards at airports and all that kind of stuff. That's not the kind of marketing we profess. We are extremely focused on digging up opportunity and going after it, and sticking with that story that has helped us sell well.
Back row. More questions. Right behind you there.
Jayson.
Yeah, we'll go to Jayson. Okay. Sorry.
Sorry, which one?
We'll get you both. Go ahead.
Yeah, we'll get you. Go ahead, Jason.
Thanks. Sorry. Jayson Noland with Baird. René, could you talk about the go-to-market, how it's morphed over the years-
Yeah
how you expect it to change? There's a WildFire overlay, there's going to be a Cyvera overlay.
Yeah.
How that would impact the channel.
Yeah. Jayson, we have been 100% channel since day one, we have never polluted that model. We haven't taken deals direct. Our go-to-market model, you should always think of as a high-touch sales force who educates customers, who helps with the implementation, who helps with the consideration. Our deals, our transactions are done with our channel. The beautiful thing, the leverage that we start to see in our business, is that our channel is stepping up. You'll hear from some of the channel partners how we have grown within their organization. Regardless of how we build our own specialization in the sales force to go have cybersecurity conversations or infrastructure conversations, it is always with a channel partner in tow, and that is sacred. That will never change.
I'm giving Kelsey a heart attack, last question.
Just to follow up on this significant market for next-generation firewalls, which I've heard about for at least five years, haven't seen too many that work. One of the first people that swore they had the best product that was just outstanding was Sourcefire. They claimed that they competitively killed you and many others. You really never know because who knows what goes on at Cisco.
I think we sum that up, yeah. We actually know the answer to that, but go ahead.
I just want to know, Cisco has this big market share, and I'm aware kind of the reason. How many times do you replace a Sourcefire from Cisco?
Sure
did they ever really have that platform that they've showed at prior meetings?
Yeah. One of our biggest Sourcefire replacements actually sits in the room here, and he can identify himself to you after the meeting. Let me put it this way. From a next-generation firewall perspective, we have never run into Sourcefire in the bake-off or in deals. That is a myth. What Cisco bought was an incredibly good standalone IPS product.
Which is the attempt to aggregate traditional legacy technology to solve the problems. Thanks, René.
Thank you very much.
Appreciate that. We talked a bit about the division, the platform, bringing together. What I want to do next, and then we'll take a quick break after that, is ask Lee Klarich to come up. He's the guy who actually has to build everything and make it work. Maybe we could talk a little bit, maybe, about what you're doing from a platform perspective. You're just powering through. There we go.
Thank you, Mark. I don't get to be comfortable? Well, thank you very much. As Mark said, I have the enviable job of trying to turn what Nir so eloquently described in the requirements into something that actually works and can be deployed on enterprise networks around the world. It all sounds really easy, but in fact, of course, it actually is fairly challenging to turn that into something that really is integrated natively, that does what it's supposed to do, and as a platform, not as individual pieces and all of that, right? What I'd like to do is really sort of talk to two things today.
One is just talk to the pieces of the platform and give you an update on where we are with that and some of the most recent things we've done that really show our ability to continue to execute on all of those areas. Two, give you a little view into what makes it a platform in terms of how we integrate those three pieces together, and how each of the three pieces makes the others more intelligent and better. This is the picture, you're going to get sick of it probably by the end of today, of what the platform looks like. The three pieces, starting with the network security piece with the next-gen firewalls. As Nir said, this is very much where we started.
Over eight years later, I think probably the most interesting thing to me is we're still finding very compelling ways to innovate in this area of the product line. I'll walk you through a few of those today. Second is how that ties into the cloud and how we can leverage cloud to make everything else more intelligent. This is actually something we started from the very beginning thinking about and using. Of course, many of you recognize this primarily, or associate it primarily with WildFire, but there's actually other aspects of this
I'll give you an update of where we are with that. Lastly, on the endpoint, which I think is certainly one of the things that everybody's very interested in hearing about, how we turn those requirements into actual product that Cyvera has already developed, as well as how we take that forward. On the network security side, about every year we have a major new release. We also typically have a mid-year minor release as well, and each of these really move the needle forward on what the network security element of the platform is capable of doing. Most recently in January, we launched 6.0, which when we went back and looked at how much was actually done in that release, over 70 features were implemented in 6.0 across PAN-OS and Panorama.
Many of these very innovative new capabilities that no one else has on the market today. Of course, this is also the release where the PA-7050 was released, and just to put this in perspective, a fully loaded 7050 has 12 times the processing power of our previously highest-end platform, the 5060. 12 times. By the way, the 5060 was already faster than anything else on the market when you actually turned everything on. Why this is so important is in data center environments where there's a lot more consolidation happening, performance requirements are going up, clearly important there. Service provider space, of course, and even on the internet gateways, we're seeing large enterprises have faster and faster requirements there. Lastly, just recently we announced the integration with VMware's NSX platform. NSX is the platform they recently rolled out for software-defined data centers.
This is basically the orchestration tools and all of the other capabilities for bringing other technologies into that environment, automated, et cetera. Just about a month ago, we launched our integration into that, which is highly unique and actually expansive in terms of what we're able to do in the data center. Okay? When you think about the data center, the PA-7050, the 5060, the 5000 Series, a lot of what that's doing is looking at traffic coming in and out of the data center and trying to secure that, which is an incredibly important thing to do. What the VM-Series does with the NSX integration is it looks for traffic that is moving between applications within that data center. The jargon would be east-west traffic, for obvious reasons.
Where that's important is as these environments become highly dynamic, more and more of the applications are able to communicate with other applications directly without going back through a central control point. That's where the extension into the VMware environment really makes a lot of sense for us. Given how important that is, I just want to walk through quickly how that works. Many years ago, even before we get to this slide, many years ago, the way the data centers were deployed is every application was deployed on a separate physical server. Every server had a wire that came into it. That wire would route itself to some physical separation to make sure that one application couldn't talk to another unless a policy allowed it. Along came virtualization. With virtualization, you put multiple applications on the same physical server.
Because of security concerns, all those applications couldn't talk to each other. They were basically put onto the network and routed back to that same central control point as they always were before. Over the last couple of years, what you've been hearing is under typically the umbrella term called SDN, but the term we prefer, software-defined data center, is what you're seeing are all these enterprises saying, "Well, why do I have to send all the traffic back onto the network when its destination is to a VM that's sitting on the same server? Why can't they just communicate?" Along with that, come all these ideas of, why can't I just automate that? Why can't it just be dynamic? Why can't it be self-service? All of these concepts roll up under software-defined data centers.
The virtualization companies, VMware and others, they can do this. There's basically no enterprise that actually uses these capabilities because up until now, there's been no way to secure a highly dynamic software-defined data center. Let me walk through what we're now able to do because we can now actually safely enable all of the things you see here. The first is in order to be deployed into this environment, you can't be disruptive. What we've found and what we've been able to deliver through the VMware integration is a way of transparently being integrated onto the hypervisor, in such a way that you don't have to change the physical networking or the virtual networking in order to provide the security capability. Okay?
When we talk about the security capabilities, we're talking about all of the same things that we do on all of the other platforms. We didn't dumb it down in order to get it to fit into the virtual environment. We found a way to do all of the same safe application enablement functionality and threat prevention in a virtual form factor. That is the first thing you have to do to secure these environments. The second is to be fully what everybody wants these to be, virtual machines can be turned up, they can be turned off, they can be moved in seconds. How do you keep up with that? It is not possible to have operators changing policy real-time every time a new VM has to be turned on or moved around.
What we found a way to do is we found a way to abstract that sort of physical layer change, which is happening all the time- abstracted into we call context, or more specifically dynamic address groups. What this does is it basically allows you to specify in a security policy your SharePoint VMs. Okay? Very simply, here's all my SharePoint VMs based on attribute. Every time a virtualization operator wants to clone those virtual machines to expand capacity, this is a process that happens all the time and takes seconds, they can do that. Those new virtual machines automatically get added to the same policy without any human intervention because this context understands, oh, these are just more virtual machines that look like the other ones that are defined by this policy.
Every time there's one of these changes, the policy dynamically adapts to it without requiring human intervention. Third, we tie into the automation. With the NSX management platform, we can actually now have our technology, our solution, automatically deployed down to every physical host in a virtualized environment. As part of that provisioning, all of the necessary initial networking and initial management configuration can be done such that the VM-Series then automatically connects back to Panorama to download the rest of its security configuration, and everything stays in sync from that point forward. What this allows you to do, just to put it in simple terms, would be a virtualized data center with 1,000 servers, each server running maybe 10 VMs, 10,000 VMs. The deployment of all of the VM-Series, 1,000 VM-Series, one per physical host, can simply happen automatically through the NSX manager.
We're basically leveraging the automation tools that are there from VMware, tying it into both the VM-Series as well as Panorama for automating all the things that have to take place. This solution is so unique that two things happened. One, we were announced as the VMware partner of the year for the work we did jointly with them on this. Two, as we announced recently, we actually are doing a joint go-to-market with them on this as the only partner that they're doing that joint go-to-market with because, one, it's so unique, two, it's so important to enterprises for taking advantage of all the virtualization capabilities that they want to. Okay? Switch gears to the cloud for a second. Just to level set on the WildFire cloud. It's interesting the number of sort of questions we get relative to this.
First of all, to understand, this is an incredibly scalable environment. I'm going to show you on the next slide some recent statistics that really sort of drive this point home. The use of a cloud-based architecture was done very specifically to enable the scale that we believed was required to deal with the amount of threats we're seeing. Second, everything about it is highly customized, tuned, hardened. In fact, every month we are actively making changes to this environment to stay ahead of the attackers and adapt to new ways in which attackers behave and new malware that we see. The fact that it's in the cloud allows us to do all of those things without impacting our customers and without asking them to have to go do all of these changes themselves. We're able to do it all proactively for them.
That's what it does. From a scale perspective, I want to give you an idea of on a typical day what we see in WildFire. Today, probably, we're in the midst of seeing about 280,000 unique files. All the duplication has been removed. These are unique files that are going to be uploaded from over 3,000 customers from around the world. Just to translate that translates down to three files every second are going to be submitted up to the cloud for analysis. From those files, we'll see typically about 30,000 of them will be new malware that hasn't been seen before. As Nir said, of those, about 70% will not be detected by the leading host antivirus companies at the time that we detect it, and most of them will still be undetected a week later.
From a scale perspective, over the last four months since 6.0 launched and the new file types were released and everything else, we've seen a quadrupling of the number of files submitted to the cloud. During that quadrupling of files that we receive, our ability to process these files in less than six minutes has never been compromised. What this means is we can scale the cloud as much as we need to, and we can do it real-time, all of which is completely transparent to our customers. They simply keep sending more and more files to us, and we continue to build out the processing power to scale with it. Incredibly powerful. This is something you cannot do by deploying appliances on-prem.
If you wanted to scale that times four, you'd be deploying four times as many hardware platforms as you did before and then trying to figure out how to load balance files across them, which simply wouldn't work. Okay? The last piece of the platform is the endpoint. I want to try to walk through how a targeted attack actually works to try to give you a sense of what exactly it is that Cyvera does that's so unique. Just about every endpoint looks like this. There's an operating system, and there's a number of applications running on top of it. In addition to that, every single one of those operating systems and applications has bugs. Or from an attacker perspective, vulnerabilities that can be taken advantage of.
As an attacker, or for a target attack anyway, the first thing you're going to do is you're going to either take advantage of a known vulnerability or you're going to discover a new vulnerability that nobody else knows about. This alone doesn't actually do anything. You have to actually be able to take advantage of the vulnerability. You have to be able to exploit the vulnerability. In order to do that, there is a handful, less than 20, exploit techniques that an attacker has at their disposal to leverage that vulnerability. Without these techniques, the vulnerability doesn't do anything. All of that is to deliver the malicious file or the malicious payload that the attacker then uses to carry out their attack. As Nir and Nati were saying, there's literally thousands of new vulnerabilities every year. There are millions of new malware every year.
The exploits, there's less than 20, and new exploit techniques are found on the average of zero to four every year. Okay? Cyvera's approach to this is disable the exploit techniques, disable the toolkit that the attacker has to use in order to carry out their attack. If you take the toolkit away, there's no attack. That's what they do. Again, the reason why this works is because there's only 20 or so of these common exploit techniques, and the attacker has to use at least one, often multiple of these techniques in order to carry out their attack. Again, you take away the exploit techniques, you take away the attacker's ability to actually do something bad. Okay?
This is actually quite hard to do, but we'll leave that for a different session to go into all the details exactly why, technically speaking, this is so hard to do, other than to say no one else can do it. If it was easy, somebody else would have done this. Like next-gen firewalls. If it was easy, somebody else would have built one over the last eight years. Okay? Leveraging that as a starting point of exploit prevention, how do we build this out, as Nir was talking about, into the more complete endpoint security solution? The first piece will be extending this out for malware prevention. This will be tied tightly to the WildFire cloud, tying endpoint to cloud in order to be able to deal with the malware problem. We'll do that in a next-generation way.
We'll do it in a way that is highly unique and highly leveraged with the rest of the platform. The other aspect of this, which is already in the Cyvera product, but it's something that will continue to be built out, is the forensics capability. The forensics capability is very important because what it allows us to do is anytime we learn about something on the endpoint, it allows us to share that with the cloud, which means the rest of our security researchers, and allows us to share it, from a signature perspective, with the rest of our customer base. Speaking of sharing, how do we take the three pieces and combine them together into an integrated platform? First, information sharing.
This is a very important step and something that we've done, I think, very good job of scaling out, as you saw with the numbers before, of being able to share unknowns and information associated with those unknowns with our cloud environment. This is something that we will continue to build out in order to get more and more information consolidated into a single place where our threat researchers can start to correlate and understand even more about the advanced attacks. The second component of this is very rapidly sharing everything that we learn, turning it into actionable signatures that are then distributed as quickly as possible, today less than 30 minutes, down to all of the network devices and all of the endpoints around the world. Detection in one corner of the world leads to prevention across the entire customer base.
That is something we're doing today, but extending that to endpoint is obviously going to be something that will happen very rapidly. Lastly, there are a number of things that can be shared from endpoint to network and vice versa for real-time sort of operational support. For example, if WildFire detects something on the network, being able to immediately share that with the endpoint to turn detection into, number one, prevention, but two, understanding more about what that looked like when it was actually run on an endpoint as opposed to what it looked like when it was run in a sandbox. We see ways of integrating all three points of the platform together, and these are all things that are either working today or will work in the very near future. Okay. With that, we'd like to open up for some questions.
Hi, Sterling Auty from JPMorgan. With 30,000 new malware a day, and you're talking about signatures, is there a theoretical limit? Do you eventually run into the same signature burden that traditional AV vendors ran into?
Good question. Certainly so far we haven't run into that, and the 30,000 we find with WildFire plus the 50 plus thousand that we receive from other sources combined together, and so far there's been no issue with being able to turn those into signatures, one, very quickly, but two, from a capacity perspective. The way the single-pass engine works is it's hardware-based, which allows us to do things at incredibly high speeds, even as capacity and number of signatures increase.
Thank you. Keith Weiss from Morgan Stanley. As the guy who has to put all these technologies together, how do you ensure that when you buy Morta and when you buy Cyvera, it doesn't become what Mark was warning us against, with being that consolidated solution, that bolt-on solution that's just a component of a bunch of acquired parts?
That's a great question. I think we, as a company, as a product organization, this is one of the reasons why in a lot of cases, we focus a lot on organic growth, is to make sure that everything we do is very tightly integrated, and we don't end up with the bolted-on different pieces. With Morta, one of the things we're able to do is, one, bring in some really smart people that understand the attack life cycle very well. Our starting point is going to be integrating some of their ideas as new capabilities into the product natively, as opposed to trying to bolt new technology in.
In the case of Cyvera, what it allows us to do is actually extend our platform in a very unique way that makes a lot of sense, and is not bolted-on, but rather ahead of time knowing how are we going to tie these pieces together once we have all of them. That's really the answer. Outside of that, it'll just be very careful attention from Nir, from me, and from the rest of the organization to make sure that when we do these things, we do them in highly integrated ways, not bolted-on ways.
Probably have time for one more question.
Sure.
If we have one. Scared you all away.
Thanks, Kelsey. Lee, Nir mentioned doing some other things on the endpoint besides the exploit prevention that Cyvera is doing now. A, I wasn't sure if when you just talked about the actual prevention of the malware, if that was what you were talking about or what those other things might be and how much of an overlap that might be, those other things might have with traditional malware prevention.
Near term, absolutely, the taking what Cyvera has done with exploit prevention and extending that to malware prevention is a very obvious and important next step on the endpoint. That absolutely would be one of the top priorities over the next few months. The other is doing that in a way that is unique and differentiated by tying it back into the cloud, and leveraging all of the goodness that WildFire has built up, and being able to share that back to network security as well. That's where a lot of the focus will be on near term in terms of how do we extend the core capability to include some of these other requirements. Forensics is the other area.
Again, this is very helpful for a number of reasons, including being able to gather information, including information that you're only going to see where the end user actually interacted with the malware. Being able to gather that as forensics that can also be set up to the cloud for better threat intelligence gathering and better response. Okay? Great.
Okay. I think we're going to take about a five-minute break. There is water out and there are snacks out in the hall. That's it. Tick-tock. We'll be back soon. Lee, Nir mentioned doing some other things on the endpoint besides the exploit prevention that Cyvera is doing now. A, I wasn't sure if when you just talked about the actual prevention of the malware, if that was what you were talking about or what those other things might be and how much of an overlap that might be, those other things might have with traditional malware prevention.
Yeah. Near term, absolutely, the taking what Cyvera has done with exploit prevention and extending that to malware prevention is a very obvious and important next step on the endpoint. That absolutely would be one of the top priorities over the next few months. The other is doing that in a way that is unique and differentiated by tying it back into the cloud, and leveraging all of the goodness that WildFire has built up, and being able to share that back to network security as well. That's where a lot of the focus will be on near term in terms of how do we extend the core capability to include some of these other requirements. Forensics is the other area.
Again, this is very helpful for a number of reasons, including being able to gather information, including information that you're only going to see where the end user actually interacted with the malware. Being able to gather that as forensics that can also be set up to the cloud for better threat intelligence gathering and better response. Okay? Great.
Okay. I think we're going to take about a five-minute break. There is water out and there are snacks out in the hall. That's it. Tick-tock. We'll be back soon. How you doing? I am the money guy. How are you?
Okay, guys. Whoa. Okay, that's loud. Sorry to do this, but the good news is that the next time you get to do this, you'll all have a cocktail in your hand, which might make it a little more enjoyable. Would love to get going. The balance of this afternoon is actually going to be a presentation by Mark Anderson, and then we're very privileged to have three of our partners will do a panel, and we'll close with Stefan. Mark, take it away.
It's bad enough that Stefan and Mark don't let me out of my cage very much to talk to you guys, that to hide me from the tools that are going to help me communicate with you, I think that's going too far. Well, good afternoon. My name's Mark Anderson, folks. Really happy to talk with you this afternoon about the reality of what happens in the street with all these amazing things that Nir and Lee Klarich talk about. What happens in the street really, I think matters to you guys the most because it allows the team that I work on to drive revenue. You guys have very high expectations from us from a revenue growth standpoint.
Mark and I designed this team when I joined, just short of two years ago, worldwide field operations with that in mind, because we do have a massive market that we're going after. We needed to have alignment between the two teams that I primarily manage, the pre-sales team, so it's the men and women that design the solutions, that interact with customers, that go out and sell and close the POs and ring the bell when we get the order. With the post-sales team, the global customer support organization that picks up the phone when problems happen. The men and women that go out and do the professional services that teach our customers how to deploy and consume our solutions faster. It's one unified organization with a common goal, and that's driving customer satisfaction. Because what do happy customers do? Okay.
I get a lot better response when I'm talking to my team, but I'm going to give you guys a hall pass. All right. Of course, happy customers buy more. Let's talk about the go-to-market. Now, you heard a word of this land, expand, extend. Steffan's going to talk a lot more about the real economic value that's derived from this very simple go-to-market. We have to keep it simple, land, expand, and extend, because it's a massive market, and it's all about taking share, and taking share really fast. What do I mean by land?
To me, land means when one of René's geniuses in marketing puts on one of their 500 events that they do a quarter, they talk to all kinds of people that are interested in our solutions, that are tired with the firewall cartel telling them that a daisy chain of old technology is better than what they can get from this new company called Palo Alto Networks. Those leads end up on an inside salesperson's desk. That inside salesperson really sets up a call or sets up an appointment, we go in and talk about our solutions. We send typically an SE, technical sales engineer, and an account manager. We have beside us an enabled and motivated partner, we tell the story, like Nir talked about before. We tell the story of what is pretty disruptive technology differentiation.
Inevitably, they believe us or they don't believe us. Either way, we have to prove it out by doing a technical proof of concept. When we do that technical proof of concept, for me, it's one of the most gratifying moments of being a sales guy. It's sitting in front of a CISO or a senior executive that's really proud of their infrastructure, that thinks it's impenetrable because they've got defense in depth circa 1999, with a conga line of devices that are very hard to manage. We tell the story, and we prove that story out. We get a PO 85-plus% of the time. We typically start in a small quarter case, maybe a lab, maybe it's an EBC deployment, we prove ourselves out in their environment.
We apply our sales focus to expand that relationship, to sell into some of the dozen use cases that you heard Lee and René talk about earlier today. Landing, expanding, and extending. Extending is really just adding more functionality onto the platforms that we've already sold. We sell a customer a firewall implementation because that's the problem they're trying to solve today. They like the fact that we can solve that problem with a platform that has got future scalability, not only in terms of the traffic that's going to grow for them, but also the problems that we can help them solve on this platform as they decommission old IPSs or old web gateways or old firewall devices, or excuse me, FireEye devices.
It's a really fun environment to be in because when you've got this technology leadership and you're a sales guy, you walk into an account, your chest puffed out, you feel confident because you know you've got the men and women back in Santa Clara supporting you with some very differentiated technology. The growth that's required from you guys is really being driven by this very simple go-to-market. Of course, we're going to be hiring salespeople. I stood up in New York talking to you guys a little less than a year ago, I talked about investing in building out our go-to-market capability. At that time, we had about 443 salespeople, SEs, channel account managers from around the world on the team. By the end of this fiscal year, by the end of July, we'll have almost 900 people.
These are people that we're taking a look at geographies in pretty much every corner of the world that we're allowed to sell technology to and building coverage. We're working with the best channel partners in those areas to build a go-to-market strategy together and go out and try to find opportunities to have that conversation with customers, prove that technology out with those customers, and make it happen. I talked last year about investing in capacity, certainly from a field perspective. Really important for us to understand the capacity that we're building out in the channel. As you heard before from René, 100% of our business goes through the channel, very much a channel-focused company. We needed to get better at teaching our channel how to tell the story, how to solve these problems. It's really the combination of the two.
The field sales team, though, from my perspective, I'm going to talk about this proven model for productivity. This is the third go-around I've had here. I worked at Cisco in the '90s, as some of you know, worked at F5 for eight years up until a few years ago. This strategy is time-tested. It really is. It's building out a coverage model to be able to extract bookings from customers. It starts with the quarterback of the team, and that's the major account manager, global account manager, or the regional sales manager, RSM, that covers a geographic territory. That salesperson, man or woman, has a dedicated SE all around the world. Everywhere, they've got at least one dedicated sales engineer. The SE is the lifeblood, I think, of our organization. I think it's the most important job in the sales organization.
It's a technical sale, you need to appeal to people on a technical basis to prove that this is a better way, this is a better mousetrap. We also have an inside sales team that sits in call centers in Santa Clara, in Plano, Texas, out in Singapore, where we just opened up our new office last week, in Japan and also in Amsterdam, where our international headquarters is based. These inside sales folks, they do a number of functions for this team. They set up appointments from the marketing events that René does. They do the renewals for the account team because they're better and more efficient at being able to leverage the tools that we provided for them to do those renewals.
They move sales opportunities from market-qualified leads to the point where it needs to be put in the hands of a partner salesperson or a partner SE or one of our account teams. This is a really focused team environment where there is a huddle. There is a huddle between the quarterback and the rest of the team, and they talk about strategy and how to prosecute their territory, whether their territory is two accounts or whether their territory is one-sixteenth of Chicago. It's a territory, we expect productivity out of this. One of the things that I've learned over the years is really to build a model like this that maximizes productivity, you have to have the resources, the tools, and the process to make it happen. That's where the channel team comes in. We didn't have a channel team two years ago.
We had a few folks that worked with channel partners. A few months ago, I hired a worldwide leader, Ron Myers, who's here today. In fact, Ron, this morning, and I hosted our first-ever Global Distribution Council to bring our global distributors together to talk about what's important for us as we build out this business in the next five years and how we can be the best partners for them. This channel team has really gone up from hardly anyone to now dozens of people around the world that are teaching our partners, first of all, how to be efficient in doing business with us, but also how to tell the story and why they should invest in resources for their business to focus on Palo Alto Networks solutions. Around everybody is the sales operations team.
They instrument the tools, the processes that we have within sales so that we're compliant and we can certify our quarterly results to you all. They're designing ways to help managers be more effective in managing the personalities, I guess, is a good way to put it, that some salespeople have. Are they good forecasters? Are they bad forecasters? We have to be good at predicting our business right down to the territory level. Every week on a Friday afternoon or a Monday morning, an account manager sits with his manager and talks about their commit, their commit for the week, how they did against their commit for last week in a 13-week quarter, how they're doing for the month that we're in, and how do they feel about the quarter that they've given us a forecast on at the beginning of that fiscal quarter.
We apply the same discipline to our partnerships. When I sit down with folks at Accuvant, at Dan Burns' company, we talk about what's their commit for the quarter, what are they going to deliver for us, and we look at the pipeline of opportunities that we have, and we agree on a number, and we go out and prosecute that number with them, like we do with our partners all around the world. Finally, we've got Brett Eldridge and his team, Global Customer Support, that provide the services to help make these customers happy. It's a fairly simple model.
Applying that, going from a couple of hundred people to 443 people to approximately 900 people, it's a simple process. The devil is in the details, I think having the experience that not only I have, but the team of people that we're teaching and we're putting around us, is making the growth a reality. I mention customer satisfaction because it's really important. Obviously, you got to have happy customers. We started benchmarking ourselves against other people in our space a few years ago and measuring the customer satisfaction. As a small company, it's hard to really invest in this, I got to hand it to McLaughlin when he started. He opened up the wallets for global customer support.
Today, we have over 200 people in many of those same call centers that I mentioned to you earlier that are picking up the phones in the markets, using local telephone numbers, and delivering very high-quality support to our customers and to our partners. Almost every day when I'm out in the field, I get somebody that just comes up to me and says that we do a great job. We're better than the people that we compete against, or the HP or the IBM of the world that are much larger companies. From the very beginning, this business was built to scale. It's a massive market. We all know that. When Nir designed the company thinking of the cloud first, he designed the company with much, much greater targets in sight.
Certainly, I would hope that you would feel that that's indicative of the changes that we've made. A year ago or so, I stood up here and talked to you about quite a large number of changes that we've made in the field, geographic leadership, right up to the theaters, we've made some changes. I'll tell you today that the majority of those changes are done. The framework is built out. Theater leaders in each geographic theater, there's regional leaders that in some cases are vertically specialized, that are managing teams or hiring teams. We built this team with a lot of people that I've worked with in my past, people that I know and trust that can do the job, people that know what's going to be around the next corner, the billion-dollar corner, or the $2 billion corner.
These are people that I feel really comfortable with in scaling to this size and beyond. By no stretch is $1 billion the target for us. We're really focused on market share. I feel that just in the last two quarters, having grown from, I think it's 4.3% market share, according to Forrester, to 5.2% market share. Now I want 50% market share. Nir, I know, wants 50% market share. Steffan would be happy with 40% market share. We're going after it, and we're following time-tested go-to-market models that I think will get us there, and I feel very confident about that. Really super excited to be on the verge of closing this acquisition with Cyvera.
I can tell you that the team members that I've talked to, once it became public, were just blown away with the connection opportunity that we have to expand our platform to the real estate where the majority of the bad things are detonated. I think there's a real sense of excitement about what this means to expanding the story that we get to tell. I also am going to be spending pretty much all week here, and probably 50% of my time is going to be dealing with either the Cyvera team themselves, customers of ours that have approached me to ask for some introductions to Nati and Uri, or just dealing with the influx of questions. Just today, as I was trying to eat my lunch, a lot of the questions around the analyst table were about Cyvera and the market that you have.
I think the same guy asked the question, why didn't Microsoft buy them? They didn't buy them because they don't have Nir working at Microsoft. I'm saying that in a joking gesture, but I truly mean it. Once the deal is complete, I think you'll see us hit the ground running and how we're going to organize to go out and prosecute this market. We have a team of really good network folks, really good security folks. We don't have a lot of endpoint specialists, so we're going to build out a subject matter expert team globally to go after this market. I expect that in the next few quarters, that we'll be hiring dozens of people, get a really good, aggressive start at it, and cover it from a single person that's going to report to me.
We'll announce this at the end of this week. This person's going to manage this team. They're going to have the same ownership and accountability that every field sales team member has at Palo Alto Networks. There'll be a lot of systems engineers that will be working with customers to teach them how to leverage this very disruptive platform. Super excited about the combination of these two companies. I agree wholeheartedly with Nati when he talked about the culture parallels that exist between the two companies. It's going to be a tremendous opportunity for us. For me, as I look at the expectations that we have, what my board plan is, what I know you guys expect from us on a quarterly basis, I realized pretty quickly a few years ago that we had to build out capacity in our market.
Not, like I said earlier, just in hiring salespeople and SEs to cover the geography, but really to leverage the world-class NextWave partner program that the company already had. We've made some really important innovations in that in the last year, really very much committed to that brand and to the programs that you'll hear from three partners that will be up on the stage with me in a few minutes, I think has been very effective. When we inserted in this space seven or eight years ago, only the smallest regional partners would do business with us. We weren't big enough. We had a funny founder that would get up on stage and wave his arms around a lot. We just had, at that point, some future-leaning thoughts from partners.
You look at companies that did embrace that technology, companies like an Accuvant that started only probably four or five years earlier than we did in 2002. That business has grown to be a half a billion-dollar business. At the time when we started doing business with them, Dan's company was a small regional VAR based out of Denver. Today they do over half a billion dollars. They're, without question, our biggest partner in the world, to put it in terms of perspective of scale. I think of those salespeople on Dan's team as extensions of our salespeople, and that gives us capacity. All of our partners aren't growing as fast as Dan's business is. Some of them are doubling or tripling each year, but still, that doesn't give us enough capacity.
We really have to build out this capacity, and we can't just do it with people and with partnerships. We've got to do it with tools. Tools that are going to drive efficiency so that we can automate the coding process, do all the nuts and bolts things that have to happen behind the scenes to make doing business with Palo Alto Networks as easy or easier than doing business with a Cisco or a. I won't say Check Point because then Nir will kill me if I do. Doing business with a much bigger company.
Without question, we've had to focus on finding global distribution partners, companies like Westcon and Arrow, that have global footprints that can help us not only deal with our global customers that want to buy in multiple theaters, but really allow us to be more consistent in how we apply these programs and these tools out so that the customers have a pretty consistent touch no matter where you are in the world. Really very important for us. I think the next time you hear from me, you'll hear some real results with numbers about the benefits to our business, our shareholders, and to our customers with these global distribution partners. At the end of the day, it is about channel capacity.
It's about us figuring out that the sales capability and capacity that exists when you add all of our partners together is greater than the number that you guys expect us to do every quarter. To do that, we've really had to step into a new model for partners. A model that doesn't alienate or move us away from the Accuvants of the world. Quite the opposite. We're still applying more resource and more focus with Accuvant and a lot of our legacy partners than we ever have. We also have invested a ton of focus in global models, global FIs, like Dimension Data or global FIs like I talked about last year on stage, with NTT Com Communications, formerly known as Integralis.
Simon Church is going to be up here with me in a few minutes, that was a big bet for us, and it was an even bigger bet for Simon, as I'm sure he'll tell you, because he had legacy business partners that were generating a lot of money for his business on a quarterly basis with renewals and whatnot. Also business partnerships that can build out managed services solutions. Today, from Telstra, from NTT Communications, from AT&T and Verizon, you can buy a managed service solution that runs on Palo Alto infrastructure. We've worked with these vendors. We've convinced them of the value of a next-generation enterprise architecture, and they've trusted us enough to build a solution and a service to sell to their customers for it. We think this will be a bigger and bigger opportunity for us as we go forward.
Big partnerships, global partnerships equal scale and capacity, and that's clearly what we're after. We'll talk about three quick deals here. Going over the first one, this is one that if you were here last year, you may have seen up on the screen. I was really excited at the time because it was a large media company in the U.K. that was building out a new go-to-market solution away from the traditional broadcast solution that they had to people's televisions, to computers, to mobile devices. This is a new revenue stream for this company, and they needed to build out a new data center to deliver on it. They had to choose a partner that was a next-generation provider that could deal with the proliferation of the very devices that they're streaming their content to now and secure that content from any bad people.
This company last year spent $2.9 million with us in this project. We included professional services to make sure that they implemented it correctly. We've got a resident engineer there to make sure that everything runs smoothly. We've got dedicated support teams and premium support to make sure that when the phone rings, we know the name of this company and what their design looks like. The reason I'm putting it up here today is because it really exemplifies the land and expand strategy of our go-to-market. Just in the last four quarters, we've almost doubled the LTV that we've done with them.
The lifetime value of total billings or bookings that we do with the customer is an important measurement because it shows us how successful our go-to-market strategy is of narrowing the focus of field salespeople and partners in every geography down to a smaller list of accounts or a smaller piece of geography, so that the touch that they get from us and our partners allows us to be much more successful. In this case, it certainly was the case. Just in one year, we went from zero to $2.9 million. One year later, we go from $2.9 million to, what is that up to, $5.7 million. Is that right, Steffan? $5.7 million. We're still scratching the surface with this company. This is a huge U.K.-based media company. Second account is a high-tech manufacturer right here in the U.S.
The use case was, I wanted to put this up here because it really tells a very good story of us competing head-to-head against FireEye in the market. FireEye does have a good point solution. They clearly have taken advantage by scaring the shit out of people all around the world about the bad world that we live in. We're out there competing against them with, I think, a more elegant solution, and a platform that extends pretty soon all the way to the endpoints. It was a head-to-head competition. Frankly, we were feature deficient before we introduced PAN-OS 6.0. Once we delivered this version of code, the customer returned the FireEye gear to its rightful place back at FireEye and cut us a PO for $1.4 million. This was an existing customer, but this is a great example of what sales focus does.
Us salespeople, we're pretty simple beings. We're very programmable. When you put a comp plan in front of an account manager or an SE that motivates them to continue to sell to these customers that have shown us that they believe in our story and believe in our solution, you'll get your return from that. Clearly, that's what's happened here. Again, at this account here, we are still just scratching the surface. There's an entire Cisco environment to go after that the team is going after right now. I think Dan's team is as well. Finally, this is a great deal, a large military deployment right here in the U.S. It was a significant deal. It was an 8-figure deal for us.
The team worked really hard, really over the period of about a year, was able to prove to this account, in their quest to safely enable applications for greater than 1 million men and women in this branch of the military. They needed to have scale, they needed to have manageability for the applications that were the most used by the men and women, and they needed to have a partner like Palo Alto Networks. It was a much greater than $10 million deal, leveraging all the technologies that we had today: threat prevention, URL filtering, and of course, they engaged us for professional services and premium support. This is just the first phase of this deployment.
We expect this deployment to, with the right amount of focus and certainly the right amount of execution after the sale, to be a gift that keeps on giving as we continue to earn this business. Really just in closing, this to me looks like a marketing slick that our competitors would use. They'd use a slick that talks about speeds and feeds. To me, what I see here is a connected suite of products, physical and virtual, working together as a platform in a way that solves problems for our customers that need to be solved today because of the way the world has become. It's filled with apps running on personally owned iPads and iPhones that run on corporate networks that represent a great opportunity for the bad guys in the world to do something bad.
To be able to deal with this, the new reality that we live in, you have to have an orchestrated, a connected, and a coordinated platform to be able to meet with the audit committee, or as I understand now, about 50% of the publicly traded companies in the Fortune 1000 in the U.S. have got security and safety committees, where the CISO sits in front of the board and explains to them what the heck happened. I know, I don't like to see my customers on CNBC talking about a massive breach and $100 million worth, or 100 million customers with information stolen. I certainly don't want to see that. We get the opportunity to sell this platform with some pretty amazing partners. You heard Lee talk about VMware. Let me tell you, the response in the field with that partnership with VMware is very impressive.
One of the questions I had at lunch was, how quickly are people moving to embrace this new technology because there's decades of people getting trained on Check Point's management platform, blah, blah, blah. At the end of the day, bad things are happening on those networks, and those customers are designing solutions with VMware to virtualize their data centers. These are the biggest accounts that are doing this, the largest banks, the largest data center users out there. When we pick up the phone today from a marketing program or just to try to get an appointment, one of the things that will get us an appointment with these large accounts that don't do business with us today is talking about our relationship with VMware. We have partnerships with Citrix in the field, where we work together to sell the NetScaler solutions.
Our partnerships with Aruba and the ClearPass integration that we've done has been really impressive, and I expect more and more contribution to the top line and, of course, the bottom line by integrating these partnerships with this amazing lineup of solutions. I know that our partners are excited about that as well. Just in closing, I'd like to say thank you, guys, for your support and for your attention. We're building this business for long-term scale. Customers are really embracing the concept of a platform that's coordinated and automated. To really drive this home, I thought it would be appropriate to bring up three of our partners up onto the stage just to have a pretty informal panel to talk about what we're seeing out there. If I can, invite Simon Church up to the stage. Simon, come on up.
Simon gets to be comfortable. Cheers, man. Yeah. Simon is the CEO of NTT Com Security, formerly Integralis. Simon, thank you so much for joining us here today. Maybe have Dan Burns from Accuvant come up. Dan Burns co-founded Accuvant. Today, he's the CEO, and I can't say enough about this great American story of a business that's being built, and Dan, thank you for your partnership and for coming up today. Dan is a humble guy. He's not going to brag about growing his business to half a billion dollars in a very short amount of time, but he's done it, from my perspective, by being a great partner. At F5, we were a partner from Dan almost from day one and delivering great service to make his customers happy. I really appreciate that. Finally, let's have Bill Corbin up from Westcon.
Bill is EVP of some fancy title. What is it? Technology Alliances.
Yeah, all that.
He's like chief cook and bottle washer. Guys, thank you very much. As you know, Westcon is one of our global distributors. I would say that we've got the biggest bet with you guys globally.
Yes, we do.
Maybe if you don't mind, Bill, we'll start with you. Let's just talk about the security landscape that we see out there. Everybody opens the papers and reads the bad things that we're hearing that's happening from China, from Russia. Just from an industry standpoint, what do you see out there that kind of gets you up in the morning?
I guess the threats are a good thing for business. We're seeing the security business as super robust right now. Everything that's going on within the security arena is bringing opportunity to companies like Palo Alto and Westcon, Accuvant, and NTT. We're seeing that change is a good thing, to be honest. The change that our partners are going through and the change in the way that the end users are acquiring security technology is driving us to behave differently and to evolve our own business to support them.
When you say evolve your business, maybe talk about some of the things that you do for us that will enlighten this crowd.
We do just about everything for you guys, Mark. Like Mark said, we're distributors, we're in the middle of the supply chain. We provide training, certification for all the partner base, obviously logistical services around the world. We operate in over 80 countries, we can deliver products and solutions seamlessly across borders and do local transactions in local currency. We do just about everything.
Today, as an example, if we do a deal with Accuvant or NTT Com Security for that matter, that deal needs to be fulfilled in India, in Singapore, in London, U.K., in Paris, France, and in New York, we would work with those resellers or systems integrators, the business would all be done through
Through Westcon
through Westcon. Yeah.
Yeah. We can take a single PO, we can land the solutions and the technology in any country around the world, make that recoverable if possible, depending on if it is a country that we actually operate in, we're in most of the countries at this point in time. What we try and do is take what you guys do with the end users and make it seamless and easy to deliver technology to your customers around the world.
You do a great job of that. Thank you.
Customer.
Thanks, Bill. From a landscape standpoint, Simon, how about yourself? What are you seeing out there?
We're definitely seeing, what we provide is solutions. We marry managed services with great technologies such as Palo Alto Networks technology, and a sort of full service consulting portfolio. Everything from ex-CISOs of Fortune 500 companies through to offensive security guys, deployment guys, audit remediation guys. The big thing that we've seen is the shift in the industry from being less of a traditional perimeter-based security business to a more threat-based business. We've certainly seen a massive uptick in business in the last 18 months or so in working with large multinationals in, I say, rewiring the way in which they deal with the security landscape and the risk landscape. That's what I would say the main area that we've seen. You comprise mobile, BYOD, the shift to cloud, virtualization, all those new areas to interact with those organizations.
Our ethos really is working on the basis that you have been breached, whether you've been breached or not. You work on that basis. Take a very much a risk-based approach.
You've got assets in every corner of the world as well under the NTT umbrella.
Absolutely.
That's a great global view. Dan, the landscape has changed a lot since 2002 when you started with a three-legged dog and a blind rat, I think.
That's generous.
What are you seeing these days? It does feel to me like things are changing faster than they ever have before.
Yeah.
Just in terms of the compute landscape and the endpoint landscape for sure.
When we started the company in 2002, what we saw was a really fragmented market, meaning just from a partnership perspective or a security consulting perspective, there were a lot of pockets of small players here and there. I had always sold to the enterprise clients. When I sat down with CSOs or CISOs, what they told me was they needed a company with the depth, breadth, and wherewithal to do it all. That's what we really founded the company on, was bringing all of that talent and that intelligence to the forefront as quickly as possible and building a national organization that could match up with the likes of the largest organizations out there.
I think, probably echoing some of the things that Simon and Bill have already said, what we're seeing out there is being a Chief Information Security Officer is probably the most difficult job in the world. I really believe that, I think I read somewhere that the average tenure of a CISO is about 12 months.
Right.
Not a fun situation to be in. What's going on out there is it's just getting more and more complex, right? As a CISO, you've got to worry about dozens and dozens of regulations and standards, right? You've got to know those. You've got to understand those. You've got to make sure you're abiding by those, number one. Number two, the threats and vulnerabilities increasing dramatically. Every single year, they're piling on top of each other. Number three, you've got all of these new little niche players coming up saying, "We've got the silver bullet for you," right? What we're seeing is our clients saying, "Hey, please help us demystify this really, really complex situation." We see more and more people not trying to go it alone anymore, but reaching out to companies like us to help solve the problems.
Yeah. Are you a bank or an IT company? Are you a petrochemical company or an IT company? Especially with that rapid changing environment where expertise is so difficult to obtain and retain, there is an arms race out there of retention of expertise, and if we can mutually provide cool environments for our guys to work at, and we suffer positive attrition with our consulting services, for example.
Well, you guys really earn the title of value-added partners too, in your respective domains for sure. What about just the industry trends? We're hearing a lot, you heard a lot today about virtualization, software-defined networking, these sort of bigger trends towards cloud, Amazon Web Services is now everywhere. How do you guys think that affects your businesses, and what do you see just in the security market as it relates to your businesses in the next few years as a result?
If I can sort of jump into that one, because obviously my parent or my major investor, NTT Communications, part of the NTT group, the largest ICT company on the planet, acquired us or majority shareholding in us originally to help them secure their cloud network and data center infrastructure. The ethos there is that irrespective of what their sales guys and their consultants sell to the clients, it has security embedded. I would say sort of two sides, but it's make sure the security is embedded, or if you don't know security is embedded, then also ensure that you know what assets you've got out there in your cloud and virtualized environment.
Yeah. Dan, how about from your perspective?
Yeah, absolutely. A couple of things. I'll try to save a couple for you, Phil. It's always tough going last.
Yeah.
What we're seeing is finally a shift to companies, enterprises actually looking for managed security services in a big way. 10 years ago, that was a very difficult thing to sell. Nobody wanted to give up their security. Five years ago, you started to see some clients make shifts to outsourcing and managed security service providers. Today, I think it's one of the fastest-growing sectors in security, period. I think it is. The numbers are there. You can read it. It's a big part of our business. We'll be expanding globally from that perspective. Back to the point, it's getting more and more complex. You've got to outsource. You've got to find a good managed security service provider, number one. The other thing, all you have to do is go to RSA, and you can see what's going on.
Yeah.
It's amazing what's going on. A lot of clients are really talking about understanding who the adversaries are, right? Counterintelligence, right? Who is it that's coming after us? What kind of industries are they going after? What kind of code are they writing? How are they doing the attacks so that they can recognize this in advance. It's one thing to really understand the threats and vulnerabilities. It's another thing to really understand the adversaries. We see a lot of that going on out there. I think back to the point that I think Palo Alto was making earlier, it's not a matter of not having enough stovepipes. We've got too many, right? As an enterprise-
Yeah
we've got stovepipes coming in everywhere. It's about consolidating all of those stovepipes and really understanding what's there. Secure data analytics is a huge-
thing today.
Yeah. Absolutely. Phil.
I'll echo what both these gentlemen said, and again, it comes back to something I said earlier, which is the consumption models around security. Where we sit in the supply chain, how do we supply security in that consumption model to make it easier for you guys to do business, to make it easier for the enterprise customers to adopt an MSP model.
That's what we're seeing.
I'd say that's been a massive shift in the industry to that. The shift from CapEx to OpEx.
Yeah. Huge.
Certainly, we've been through that over the last three years, shifting what was traditionally very much a VAR, resale-centric business based on spiky CapEx to OpEx. Having gone through that, dare I say, valley of death, without having NTT sitting behind us, it would've been a really scary experience, and certainly there's a lot of vendors that are sitting out there in the marketplace that are hardwired to Wall Street expectations, and it's going to be pretty sporting for them to make that shift over the next few years. That's, again, another reason why they like doing business with Palo Alto, is you've got those models in place already.
Yeah. Well, it speaks to the bravery that you showed 18 months ago when we sat in the lobby of that hotel in Heathrow and talked about how to convince Integralis to move away from some of your legacy vendors towards the Palo Alto Networks platform. I think making that shift for whether it's distributors, whether it's systems integrators or resellers, it's very dependent on the partners that you choose for the future, isn't it?
Yeah.
Yes.
Let's bring it back to the partnership because everyone that knows me knows that it always has to come back to me.
It's all about you, huh?
Let's talk about your relationship with Palo Alto Networks and kind of what you see there and maybe some of the things that you'd like to share with this group. Simon, how's your business been since you-
Our business, from doing it properly, I would say we played for six months previous with the conversation we had at Heathrow, and we tested. What we tend to do is have sort of two levels of partnership. We have our mainstream partners, which is like a handful plus three or four, and then we have an incubator set, and we effectively ride maturity curves, and if we can overlay those maturity curves, it means we always get in the sweet spot. We played for about six months to nine months with you guys, and then we went mainstream full bore, and we've seen our business triple in a year.
Wow.
By far, the highest growth business. I think that's a combination of reasons. Yes, it's sort of traditional resale, but we're into selling solutions to our clients, not just reselling technology. We want to really associate NTT brand name with a solution for X and for Y and for Z here or Zed, or however I can.
It's also the consulting services associated with managed services. We announced our managed service security service relationship with you guys a month or so ago. Prior to that, we've actually been running for quite some time an application profiling service as a managed service, whereby all those devices that are sitting out there now that are running multiple applications, we can do profiling on those and allowing organizations to run those applications while ensuring that they're safe. That respect and the flexibility of enabling us to do that has been very, very cool. I would say also, it's a very rapidly changing marketplace. A team that gets it, a team that understands that this is a true partnership, not an organization, dare I say, that demands certain numbers and certain programs must be deployed as opposed to the things are changing quite rapidly. Having that agility.
There's also a bunch of what I call if-only guys here. They've done it before, and when they've gone, they come here and say, "Well, if only we'd done it this way last time. If only we'd done it this way last time." We've got a bunch of if-only guys here, which again, is very, very cool for us because I think that marries incredibly closely to what we've tried to build in our organization. The marriage is a good one. I'm very, very pleased.
Great. Thanks. Bill, as you start to turn on our distribution business in more and more countries now every quarter, how do you feel about the relationship?
I know we feel really good about the relationship. A year ago, we sat here, and we were transacting in three countries.
Yeah.
That was Australia, the U.S., and Canada. Today we're in the Middle East, Africa, Latin America, Europe, and all throughout Asia Pac and North America. We're very encouraged. We're very engaged down to the country level, and partnering on enablement programs and getting the Palo Alto story out. Our business, if I combined it all, and we were lucky to be on board early with Palo Alto in North America, but if I combine it all, we're at a 75-plus % run rate year-over-year-
That's awesome
growth. It's very, very healthy.
When I interviewed with Nir, he told me the secret to getting more partnerships was to tell these VARs and these SIs that they're going to lose to Palo Alto Networks anyway. You should tell them before they lose too much business to I can't do the accent quite right, but before they do too much business, tell them that they should do business with us. I think that's proven out really with certainly NTT Com Security as well as Westcon because you did have legacy relationships, and still do have legacy relationships
Sure
out there with the firewall cartel. How do you feel the next six to 12 months? I know we've got really high hopes for this relationship. How do you feel the next six to 12 months will be?
I think it's going to be a bit of a bumpy road, to be honest, because we do have legacy relationships in the firewall cartel. I think it'll be a bit challenging, but nothing we can't manage through. We really are looking at Palo Alto as the growth engine in the firewall business for us.
That's terrific
That's where we're betting our money.
Love to hear that. Dan, how about yourself? It's been a long relationship relative to the youth of your company.
Definitely. I've known Nir and some folks here and for you for a long time. That always makes it easier. Obviously, when you guys started Palo Alto, it was an automatic yes, let's get this going, because I knew what you were building, and I knew it was going to be very, very powerful. The channel is really all about reciprocation.
It really is. To make it successful, it's got to be equal on both sides. I can truly say that with Palo Alto, we bring about 50% of the deals, and you reciprocate 50% of the deals, or vice versa. That's a sign of a very, very healthy partnership or marriage. That's always been wonderful. The margins have always been kind of in the top quarter of our partner list. You're always right in there.
Careful. Steffan's in the room.
Still not good enough. Those are kind of the primary success factors. That's always been very, very wonderful. You're solving problems that our clients are asking about.
Yeah.
I couldn't be happier about it. I know you've added a lot of people over the years, and we've seen that out there in the field, where we're just matching up our teams with your teams going out there after enterprise clients, and you guys are throwing more resources at it. You get more face time with companies like Accuvant and NTT. You're going to get more business.
Yeah, for sure. Those people are pretty coin operated, aren't they? I think when they get the validation in the field, and they look across at their Accuvant colleagues, seeing them throw business on the table, leveraging the relationships that you have in 50% of the Fortune 1000, we want to do the same thing because we know and we trust that your team can take the ball down the field all the way.
Yeah
score the touchdown. I think it's a really mutually beneficial relationship in all three cases.
Yeah.
I really appreciate you guys being partners, first and foremost. I know our customers do as well, and really appreciate what you do every day for us at Palo Alto Networks, and I'm very optimistic about the future for our relationships.
As are we.
Are we.
Thank you very much.
Thank you. Appreciate it.
Thanks.
Last talk we're going to have is with Steffan, who's going to translate all this wonderfulness into some financial detail for us. Last, Steffan. Oh, there he is.
No. All right, perfect. You've heard about the power of the platform today. What I'm going to channel for the rest of the discussion today is really about the power of the model. It's really the model that provides the underpinning around our financial performance, our go-to market, our investment thesis. When you look at the foundational elements of what we've built here, we've been always a disruptor in the enterprise network security business. With the acquisition of Cyvera and our plans, which you heard from Mark and Nir and Lee, et cetera, we are going to be a continuing disruptor in the overall security landscape. With that as the backdrop, we're also going to be looking at capturing market share and doing it in a profitable manner. I'd first like to level set.
You've seen some of these numbers, but I wanted to bring it together for you. Our current total addressable market is roughly $12 billion, scaling to $14.6 billion. We have about 5% market share. Post the acquisition of Cyvera, we're going to be playing in about a $20 billion market. The reason why we've been able to grow a lot faster than the market, et cetera, is it starts with the differentiated technology. We have a proven, unique and disruptive platform. It's extensible, we have the versatility, unlike any other company, to have an integrated approach where we sell a platform to any enterprise network security need. With Cyvera, we're extending that to the endpoints. We've had tremendous traction with acquiring customers. We have over 16,000 customers lifetime to date.
Our revenue model, which is another aspect around the power of the model, it's recurring subscription business and a hybrid SaaS model. It's powered by the platform, this hybrid SaaS model component is one of the key and integral parts of the story, which I'll be getting into a little bit later. Our revenue growth since we started shipping in FY 2008 through FY 2013, has grown 30 times faster than the market. Everyone here is, I'm sure, a student of human nature. Customers would not be taking out the existing incumbent vendor if it wasn't doing the job. The nature of the threat landscape that Nir and Mark and Lee went over has completely altered the playing field, it's created a disruption, it's created an opportunity for our company. Additionally, we've been able to do this in a profitable manner.
The gross margins on our product and our offering, total gross margins as of last quarter were 75% on a non-GAAP basis, we're at 9% non-GAAP operating margins. We're able to generate these types of margins because of the extensible platform that we have. In this hybrid SaaS model, it's been, again, a key generator of free cash flow. Over the past three and a half years, we've generated over $230 million of free cash flow with an average of 22% free cash flow margin. Not many companies who demonstrate this type of top-line growth, market share growth, can have this type of financial foundation. Let's look at the trended revenues from inception to date. We've grown 166% on a compound annual growth standpoint, we've been growing much faster than the rate of the market.
Our model is powered by landing new customers, once we get those customers, we're very interested in expanding the opportunity within that customer base. Oftentimes, we're deployed in a very small portion of the network in a pilot, it could be for a firewall project. It could be for an IDS, IPS project, filtering APT malware. We have the versatility of the platform to go after any enterprise network security need. As Mark mentioned, we have this land, expand, and extend model. The other leg of the story, which is crucial to our business, is retain. We've been able to retain our customers because of the great technology that the team has put together, the overall go-to market, which Mark Anderson talked about when we have post-sale support, the customer satisfaction levels, those are key indicators of the health of the business.
This revenue growth has been driven across a wide range of verticals. What you see here is the lifetime purchase order value of the company. There isn't one vertical on here that accounts for more than 13% of total share. You can see that every vertical needs enterprise network security. What we're able to do is we are able to have our platform be ubiquitous across all verticals. Let's take a look at what's fueling the engine of growth. We've talked about landing and the importance of landing. You can see from the trending here, we have over 16,000 cumulative end customers. Over the past 9 quarters, we've added over 1,000 new end customers per quarter. We estimate that we're less than 10% penetrated within our existing install base. The opportunity is large.
In how you see the landing part of the equation translate into the expand and retain part of the equation, over the last 6 quarters, about two-thirds of our business has come from existing customers. You have this phenomenon happening where we're adding a lot of new customers to the top of the funnel, and they're coming back and buying more. As a CFO, candidly, I'm agnostic about the initial purchase order as long as it's from the type of customer that has a long tail of repeat buying opportunity. Let's talk about repeat buying and the expansion opportunity because it is a key part of the story. It's so important that I'm going to give you three examples. The first is our lifetime value analysis of the top 25 customers. Many of you have seen this chart before.
This gives a little bit more granularity in terms of trending than you may have seen before. To level set, in order to be included on the top 25, the minimum entry point for inclusion as of last quarter was $4.6 million in lifetime value. You can see the nice trend increase over the past prior quarters. The other element to the chart is the lifetime value, which as of last quarter was 21 times. That means they've spent 21 times more in lifetime value than their initial purchase. Even in this slice of customers, we feel like we have a lot more wood to chop in those accounts. We're not done yet, and we expect to see these continue to grow.
The next slice of data that we'll take a look at is we're going to widen the aperture, we'll take a look at the cohorts. This cohort analysis is, again, lifetime value by cohort, it starts with the most recent vintage first, which is 2013. Our 2013 cohort has spent 1.3 times more than their initial purchase. You can see as we get farther out from 2013, the trending goes up. Our 2009 cohort has spent 6.3 times more in lifetime value than their initial purchase. If we do some simple math and we take our existing 16,000 customers and apply the LTV analysis, the patterns that we've seen, we estimate that there's over $2.5 billion worth of lifetime value eligible for us to go after in our existing install base if we do not add one more customer.
We feel like the extensibility of the platform, because it can solve any need, provides great footing for us going forward. Commonly, I would get questions around, well, what's the profile of the repeat purchasing? The next example is to dive deeper into the 2009 cohort. What you see here is in 2009, the initial purchase split amongst product subscription and support, you can see the ratios. Since that initial purchase, the expansion part of the opportunity has come in three forms, and you can see the build of the graph here, where we have product subscription and maintenance and support. Pretty powerful. The part of the story which is as important and powerful is the retain part of the business, or what I call renewals. You look at the green bar chart here.
We've been able to renew the subscriptions at a very high rate, and we also have support renewals. When you combine them all together, the repeat purchases of 5.3x that of the initial is a very compelling story around this engine that we're building, and this engine has a lot of benefits down the road, which I'll get to in terms of being able to generate free cash flow and free cash flow margin and the profitability of the story. Now I want to pivot. We just covered a little bit of the power of the model from a sales standpoint. Let's take a look at the power of the model from the recurring revenue and hybrid SaaS approach that the company has taken. For those of you who are unfamiliar with the story, we have four subscription services: threat prevention, filtering, WildFire, and GlobalProtect.
Each subscription is 20% of the appliance list price per year. Customers opt in for this. The genius that Nir embedded in the operating system, and which our engineering team and product management continue to proliferate, is that all these subscriptions are actually running natively on the operating system, and we're simply unlocking the value via a license key. The concept of churning on a subscription actually doesn't degrade performance, and it becomes a very elegant way to have expansion sales within the customer base. One of the metrics that we use to track the success of our subscriptions is we look at the number of subscriptions shipped per devices shipped in the quarter. As of last quarter, the attach rate was 1.9, and that was up from the prior period of 1.7. It was up from a prior period of 1.6.
One of the reasons around the catalyst of growth for subscriptions is we are choosing to monetize and bring to market value-added subscriptions that companies will want to buy. One of the biggest areas of growth for us is WildFire. WildFire, because of its unique integrated capability with our platform is a differentiator to the other folks who are in the APT and malware space. We can do both detection and prevention at the point of the firewall, and I'm happy to say that, at that 1.9 metric, the highest growth was WildFire between the 1.7 and the 1.9, but all three other subscription services increased in that time period. The power of the model is working.
The other leg of the model is the renewals business, we're able to have greater than 90% renewal rates in our subscriptions business and close to 100% renewal rate in our support business. With the recurring revenue and hybrid SaaS model as the setup, Cyvera is going to add another subscription offering to the mix. It's going to be different than Threat and URL and WildFire and GlobalProtect because this is going to be based off of an annual subscription based off of endpoints. Remember what I told you about the power of the model from a land and expand standpoint? We have 16,000 customers, 3,000 of whom are running WildFire. We have a significant cross-sell and upsell opportunity into our existing install base for Cyvera. That's not even capturing the prospective new customers that Cyvera is going to bring to the table.
Cyvera is going to be a great door opener for Mark Anderson's team to go out and get more prospects in the door. Of course, Cyvera expands the TAM by $4 billion. How does this model focus and help with the free cash flow story? It begins with billings and deferred revenue growth. From a billing standpoint, over the past three and a half years, you can see the progression, very nice, healthy progression on a year-over-year basis amongst all three categories, product, subscription, and support. The byproduct of billings, because we have a SaaS model, hybrid SaaS model, is that deferred revenue has been growing, and you can see the mix between short-term and long-term. One of the very nice aspects of the business that we've seen is the average contract length has been increasing, which tells us a lot of things.
The first is people want to standardize on us, they're willing to go do a three or five-year subscription. The type of margins that come with multi-year subscriptions and support, very healthy. You can see a very nice buildup of deferred revenue. Right now, our deferred revenue balance is over $320 million on the books, and that gives us visibility into future revenue streams. One question that we often get is, product revenue is not growing as fast as some would like. Posting 30-plus% product revenue growth on a year-over-year basis is something that we're very much focused on. I would like to show you an alternative view of how we look at it internally as practitioners of the business. When we look at the health of the business, we look at product and subscription billings together.
A new subscription sale is equivalent to a new product sale, we have chosen to monetize the subscriptions in a SaaS business, in a SaaS model. The growth is increasingly coming from subscription services, we're looking at bringing more subscription offerings to the market. Cyvera is just one of a number that we're contemplating. When you look at the subscription and product billings together, that does give an alternative view on the health of the overall business. How does the hybrid SaaS model factor into what I think is probably the most meaningful metric of profitability for our business model? It's free cash flow. Over the past three and a half years, as I said before, we generated $230 million worth of free cash flow while posting industry-leading growth rates.
Free cash flow margins naturally will be above operating margin because of the ratable revenue recognition that we have of our revenues. There's obviously a differential there, and we think that free cash flow is an important leg of the story that folks should focus on. Candidly, it gives us the firepower to make the incremental investments like we're going to be making in Cyvera as we expand sales and marketing, as we look to invest in engineering. It's this model that is powering the overall business. Now, this final leg of the presentation, I'm going to walk you through some of the planning assumptions and our target model. What we told you on our Q4 earnings call from a planning standpoint was, CapEx was going to be $45 million-$50 million for the year. We're on track for that.
A non-GAAP tax rate, 38%-40%, on track for that. Share count dilution, it's approximately 1% per quarter. We're on track for that. Once we close Cyvera, there will be incremental dilution, and part of that's going to be dependent upon the stock price. It's probably going to be around 1.2 million-1.4 million shares. Let's look at Cyvera for a moment. It expands our TAM by $4 billion, like we talked about. The revenue and gross margin model, the revenue is going to be a subscription offering, so it'll be a recurring revenue stream. The gross margins for the Cyvera business should approach software-type gross margins, which will be a positive tailwind for us, so they should approach over 90% once we get to scale.
The impact of our revenue model is that billings and free cash flow will naturally ramp ahead of revenue and operating margin. In the timings of billings and revenue, we anticipate them building in the second half of FY 2015 with meaningful contribution to our business in FY 2016. From an investment standpoint, you may or may not know, Cyvera was a Series B round company. They raised about $11 million of venture capital, and nearly all that money was going towards building a world-class R&D team. When you look at how we're treating the Cyvera transaction, it's almost like where you have to inject late-stage venture money into that business to make sure it's successful. We have outlined an investment plan of $1.5 million in OpEx, $3.5 million and $25 million for Q3 2014, Q4 2014, and FY 2015.
The areas of investment are going to be in R&D because we're going to continue to extend our lead and build out a great Israeli-based, Tel Aviv-based organization. We're also funding a specialized sales team and marketing and support in order to make sure that we are successfully resourcing a great company that we acquired. From a free cash flow standpoint, we anticipate we'll be projected breakeven and cash flow positive in the first half of FY 2016. With all that said, I'm pleased to report that we're not changing the timing of our target model. Remember, I purposely don't call this a long-term target model. This is a mid-term target model. What you can see is we've made some adjustments to the components of our target model.
To level set, folks, at the time of the IPO, we said that we would be able to achieve 22%-25% non-GAAP operating margins exiting Q4 FY 2016. The timing is the same and the net result is the same, the component parts have changed a little bit. Why have they changed? We've been consistently above our target model in gross margin. The original target was 70%-73%. Now we're at 73%-76%. This reflects the increasing contribution from subscriptions, the hybrid SaaS model, and the fact that we're going to be selling a lot more appliances into the data center. Think the 7050 fully loaded. Those are very nice margins. R&D, we're currently below the target model.
With the acquisition of Cyvera, we're going to be continuing to invest not only in the next-gen firewall platform, but with Cyvera, we're going to be investing in the endpoints and also the Threat Cloud. We think it's going to be 13%-15%, so there's no change. Sales and Marketing is being bumped up from 30%-33% to 33%-36% in this time period, mainly because we're making a lot of investments, not only in Mark's go-to-market organization for the core business, but we're building out a specialized sales force for Cyvera. G&A, no change from 5%-6%, we're going to get there through improved efficiencies and economies of scale. Wrapping it up, we feel like 22%-25% is achievable exiting Q4 FY 2016, like we said before. With that, I'll bring Mark up so we could do some Q&A.
If I take time with just Steffan and I, then you do general questions or from Steffan's presentation, then we can, you see the team is here as well. Take about 10 minutes for that.
In the day, it's Brent Thill from UBS.
Okay.
Maybe you can just talk a little bit about the pipeline for the 7050. For Steffan in Europe, your numbers have been great in not nitpicking, but when you look at the actual growth rate in EMEA versus the rest of the world, you're under pacing in EMEA. Is there anything that you see that is prohibiting that growth competitively or go to market? Can you just talk through your aspirations in the EMEA region?
I think 7050, that'd be good, yeah.
Sure. The pipeline for the 7050 is called tracking to plan. What we typically do with any new product introduction, we make sure that our field sales organizations are prized before we introduce something. We have a lot of POCs gone right now. The 7050 will have application and applicability in the data center, the high-end data center. We have lots of customers who are trialing it right now. We've started to ship to customers, we have real shipments that are going out in the quarter, which is good. We expect it to be a meaningful contributor over the next, call it two, three quarters, it'll start ramping up. We should see a broad-based adoption of the 7050.
Yeah. There's a lot of POCs gone right now. I believe we sold units in the quarter and a lot of POCs gone right now as well. On your question of EMEA, I think two things on that. One is that's been a harder market than the rest of the world for quite some time just because of the macro stuff, even though it's still growing at really nice rates on a year-over-year basis for us, it's trailing the rest of the geographies for us. The second thing is, from a distribution standpoint, that's an area of the world, particularly for Check Point, that they're very entrenched with the channel over there. Quite candidly, they threaten them.
If they sell Palo Alto, they're going to go away. As you heard from our valued partners here, not for these guys in particular, but just general matter, just mathematically, that just doesn't work out anymore. Lots of partners we talked to a couple of years ago said, "Hey, bring me a new opportunity. I'll sell, but I can't touch my existing base." With our growth rates, you're just realizing that they're definitely losing business, just somebody else is fulfilling it. They're fulfilling Palo. I see that changing in Europe soon, where a couple of those stones are going to come out of the dam, and it's going to open up just from a reseller perspective for us as well. I think that's a big next 12-18 months for us. We'll tell that story.
Next question.
Hi, Aaron Schwartz from Jefferies. You talked about the cloud as one of the likes of the platform here, it sounds like a lot of what you're talking about is delivering or using the scalability of the cloud to deliver back to the on-prem platform which you sold. If we look at the security space, there's another approach of displacing legacy vendors that's actually delivering more product from a cloud perspective. How far down the road do you go there over time? Then you also talk about your partnerships with SIs and how much will they take on in selling your product in that cloud-based approach over the next couple of years?
Yeah, there's a lot of things going on there. One is just the power of the cloud in the first place, right? Is massive infinite compute power. From the beginning of recognizing that that was going to be important for us in constructing that platform so that we take advantage of all those things. It's working. It's definitely, you can some of the speeds and feeds that Nir gave you. Just the difference of what we can do in the cloud versus on-prem technology is, they're just worlds apart, like factors apart. We have lots of data to show that as we run tests against these different kinds of systems. That's important, and it'll be more important for us in the future as when we bring endpoints in, because we can do the same with the endpoints cloud processing up there as well.
From an SI perspective and folks like that, they understand that. What we're seeing from systems integrators, some large companies, NTT being a perfect example, of folks who are saying that their customers are coming to them saying, "You have expertise, you have the technology, from a network perspective, and we'd really like to shift some money from the CapEx to OpEx expense." Can you, not just outsource the network, but can you, on a managed service basis, run portions of our network? When you do it, you have to provide, at least in our world, security that is top-notch, next-generation security. That's a growth area for us.
We've seen some of our systems integrators who are, in this case, service providers, spinning up services using our technology that they're in turn selling to enterprises, not small businesses, but enterprises on a recurring revenue basis. Everybody wins in that model. I see that building over time a lot more on a global basis. Kelsey's texting. She's texting. I'm thinking, "Sterling.
Sterling Auty with JPMorgan. Steffan, you mentioned the $2.5 billion TAM if you never brought on another customer. Does that include Cyvera? One follow-up question.
That excludes Cyvera. That doesn't include any contribution from them.
Mark, on the go-to-market with Cyvera, you talked about the overlay, even talked about it in the acquisition call. Curious, when you made the comments earlier about talking at the senior security, we know that traditionally endpoint has been purchased by a different part of the organization. What's going to be the main focus of how you're going to try to penetrate those accounts? Is it going to be a dual track approach where you're talking senior and that traditional endpoint buyer, or is it going to focus on one versus the other?
We're going to do two things at the same time. The first thing is we're going to build a team that would be primarily SE-based versus salespeople-based, because it's a technology sale, it's next-generation, all the things we've experienced with the next-gen firewall, to go in and talk to the endpoint person because even if we do the second thing, which is sort of get the air cover at the CISO level or CPO level called security for the whole enterprise holistically, and you really need the platform and you need this stuff. Somebody at the end of the day in an office with no windows in the basement has actually got to make it work. We have to cover both of those. And we'll do that with our major accounts team and global accounts team, and we're going to focus primarily first there.
We've got 16,000 customers in the company, 3,000+ of them are using some version of WildFire. Over 1,400+ are using paid for versions of WildFire. That's where we're going to start, 1,400 that are using the platform with WildFire, because that's two legs of the stool. We're going to go right in there and say, "Here's the third one." When we have that conversation, we already have account managers who have captured mind share from the cybersecurity perspective. Now we need to bring somebody else in to say, "Here's how to complete the triangle with the endpoint." You have to know how the endpoint works. You put it on there, it's not going to break anything. All those things are actually very important to get that person to sign off on the purchase.
Thanks. Rob Bovo with Millennium. Thanks, Mark. Just a quick one on the WildFire success. Where you're seeing the uptake, and you talked about the
Increasing attach rates to your embedded product base. Are you being invited into installed customers for bake-offs that are specifically attacking the APT opportunity, given that FireEye has raised the visibility of it with the marketing message? Is that how you're seeing that success? If not, how are you cross-selling that to justify that momentum? Thanks.
We're really seeing three things going on there. It's great. The visibility from this whole APT thing is great. We love that, right? The fact that people are finding budgets. There's a lot of marketing that's being done for our benefit. What we're seeing there is three things. First is, when we're bringing in 1,000 new customers every quarter, the ability on the acquisition of the new customer to sell WildFire in that initial purchase is really high.
We do really well there because a lot of those customers, they don't have an answer to that yet, right? They're being sold to. When they're already deciding to purchase the Palo Alto Networks device, that one point of the triangle, to talk to them about WildFire and APT, which they're hearing left and right and all over the place and say, "Oh, I can get that too?" It's actually relatively, from a value perspective, is a lot more value for a lot less price. I'll take that. That's the first thing. The second thing is, in our existing base of customers, for people who just don't have a solution yet at all. They're hearing about it all the time as well. We're already there. We get to go back and say, "Hey, that thing you heard about?
You already own the baseline you need in order to have the best, most sophisticated technology. It's not just protection, it's prevention. We have that opportunity too. The third thing is we do have folks in our customer base, particularly in larger organizations, that they own FireEye already, right? They made those purchases a number of years ago, or whatever the timeframe is. We get to go into them and say, "We know you have that, right? You're already running our firewall inside your company. Here's WildFire. If you want to do a compare, head-to-head compare on this thing, this is how it works. It's technically superior. It does prevention, not just detection. It's 20% of the list prices of all the devices you've already deployed.
If you want to rip the devices out of there, just like you love with us with IPS, and just like you liked with filtering, all these things, here you can do it again and get superior security with superior TCO. All three of those things are working for us at this time. Rob.
Hi, guys. Rob Owens from Pac Crest. On the product and subscription billing slide, Steffan, that you showed, how much is the extension duration that you talked about influencing that growth rate?
It definitely has a factor in that, because anytime you do anything more than a year, you're increasing the billings. It's hard to put a percentage on it, but I can tell you directionally, from a couple of years ago, our average contract lengths were, call it a year. As of last quarter, they were about one and a half, one and three-quarter years. They've been trending up over time. That will have a beneficial impact on the gross billings that are happening. That's why you see growth in deferred revenue and the long-term component also going up.
Second is, when we look at the upward guidance or the upward revision guidance for the gross margin, how should we think about that? Can you give us colors? Is this a function of higher-end boxes, cost efficiencies, or a mix shift to more services in the add-on and extensibility of the platform?
Well, it's really a combination of all those three. We are relentlessly focused on driving cost of goods sold down on our platform. We have gross margin targets and COGS reduction targets on a quarterly basis, so we're very much focused on that. From a mix standpoint, as we get more traction with the 7050 getting into the higher-end data centers, those will have higher gross margins over time as those 7050s get built out. Certainly from a subscription standpoint, the higher the attach rate of the subscription that we have, that is almost pure 100% gross margin. That mix shift, all those three things that you just said, will all play a part in expanding the gross margins.
Hey. Walter Pritchard from Citi. Just a question on the product side with Cyvera. I think when you first came up with the PAN firewall, it was eye-opening to so many customers. You showed them things they didn't know. They almost had to buy the product to be a steward of their company. Can you talk through sort of what you can do in this area to sort of open people's eyes to what they have, what your product will do, and therefore the hole that it fills?
Yeah.
Stefan, just for you on the numbers, can you give us a sense of. I know you're not selling it at the percentage of the box because Cyvera is maybe agent-based or what have you, but how should we think about deal sizes or if a customer sort of a multiplier, something would help us quantify. We get the TAM, but something that helps us quantify it on a customer basis.
Yeah. Thanks, Walter. I think with Cyvera, we're going to run a playbook, right, that we've been running with the next-gen firewall for a while, which is just prove it, right? On the next-gen firewall, we do those AV application visibility reports, and we just side-by-side it, and if people test it's truly black and white. We're going to run the same kind of playbook on the endpoint with the Cyvera technology. It's starting with the baseline of the Cyvera technology, when it's tested, which we've done, would have stopped every exploit since 2009, right? Because it's going at that exploited technique aspect of that. We can show that from a testing perspective, and then we can talk to customers and say, "All the malware exploits that you saw on your network, pick a date.
If you're keeping track of them, this is what would not have occurred if you had been running this technology." Go ahead and test it on your network, and we'll run some of those exploits by you in a lab environment, and you'll see that it just stops them. We'll run the same proof is in the pudding playbook with that, and we think that'll be successful.
On the subscription side of the house, it will be a subscription per endpoint. We haven't divulged what that pricing's going to be yet, partly because the deal hasn't officially closed. We're looking at different models. There certainly is a cross-sell and upsell opportunity within our existing install base. The quantification of that is really ultimately going to be based off of how many endpoints is the technology going to be deployed on. I would just say stay tuned. As we close the transaction, and most likely on our upcoming earnings call, we'll give a little bit more clarity relative to the size of the near-term opportunity on that front.
Yeah. We probably have time for one more. One more? Okay, yeah. Thanks. Sorry. No? No takers? Okay.
One clarification question for Steffan. Your prior financial target is for exiting fiscal year 2016. May I verify the timeline target for the revised financial model?
Yeah. The timing hasn't changed at all. What we had said was exiting Q4 FY 2016, we'd be at 22%-25% non-GAAP operating margin target, nothing's changed. Even with all the investments we're making in the short term with Cyvera, with the TAM expansion, et cetera, we still feel confident that we can get to 22%-25% exiting Q4 FY 2016. No change. Okay. Great. We're going to have to wrap up because I know we're running over time. I want to thank everybody for attending. For the folks in the webcast, this is going to end that portion, if you would. Thank you.