Welcome to Qualys' 2016 Analyst and Investors Day. I'm Joo Mi Kim, VP of FP&A and Investor Relations at Qualys. Today, we have a series of presentations from the Qualys executive team and Mark Butler, Chief Information Security Officer at Fiserv. We also have some exciting product demos by Sumedh that we think you'll find very interesting. Before we get started, I'd like to point you to our safe harbor in our management presentation, given that we expect to make forward-looking statements during the event. Our risk factors can be found in our Q3 press release as well as our latest SEC filings. Our non-GAAP to GAAP reconciliations can also be found in our press release as well as in the appendix of this presentation. At the conclusion of this event, a replay of the webcast, along with management presentations, will be made available on our IR website.
With that, I'd like to introduce you to Philippe Courtot, our Chairman and CEO.
I should have the lapel. Thank you very much, Joo Mi, and good morning, and thank you for attending our Investor Day in New York. This morning, I would like to discuss with you about the consolidation of the cybersecurity industry that we see coming, discuss about the key drivers, and then discussing with you why we believe that Qualys is very well-positioned to be a consolidator of that industry. Also, discuss with you about where we are going to focus in 2017. In fact, there are multiple drivers at play. We all know that attacks are not going to subside anytime soon. Today, we are fighting essentially the bad guys with a multitude of solutions, point solutions, that are costly to deploy, difficult to deploy, expensive to maintain. They don't speak with each other. We are here at a disadvantage.
At the same time, the companies are faced also with the necessity to retool their computing infrastructure to leverage, of course, these new cloud technologies. For them, it's a huge challenge, because on one hand, you have to continue securing this old infrastructure with, again, tools which are very expensive to deploy and maintain. Then you have also now to secure as well. While you move into this new environment, you have to secure also as well that environment. That, of course, is a huge challenge because you need the resources. It's very expensive. Now you pay twice. It's a huge effort and a huge challenge, and we see that with all of our customers.
In addition to that now, the regulatory environment is putting a lot of pressures on large corporations because, we see that in Europe, and it's coming as well into the U.S., where the regulators now want to make the company responsible for the security and the privacy of the data that they collect from their customers. In fact, even in Europe today, there's regulation that will impose fines if they cannot demonstrate that they have done everything they could to ensure the security and the privacy of the data of their customers. We see today a fledgling cybersecurity industry, insurance industry coming, which, of course, is going to also look for metrics about how we can ensure that before I can insure you that you have taken enough of the steps so you will minimize the risk of being breached.
All in all, it means that there is absolutely a need to find ways of doing these, securing that computing environment in a much more cost-effective way. In fact, in the presentation of Mark Butler, you will see the challenges that I've just described that every large company has today. The average Fortune 1,000 today has about 30, 35 security and compliance solutions that they have each of them have their own infrastructure. They require specialists to operate them. They, again, don't speak with each other, you have to make the effort of integrating the data from one and the other so you can have a better view of your security and compliance posture. What I would like to discuss now is how well we think we believe that Qualys is positioned.
First of all, we build an impressive customer base, which since the very early days understood that the cloud-based architecture was presenting a significant advantage. We started with VM, as you may recall, and our big advantage was that we could deploy much more easily. Deploying the Vulnerability Management solution, which essentially was scanning your internet-facing devices. We were doing that from the cloud, which is very logical. Then through appliances that we were FedExing to you, so we could look at your inside of the network and bring all that information. We had, in fact, because of that, we have taken a significant share of the very high-end of the marketplace with more than 60% of the Forbes Global 100 because of the deployability that the cloud-based solution offer us.
Of course, this customer base that we know today have that issue, and they are absolutely looking at us to deliver more application in the same way. That's what you're going to see in the demonstration, all the new services that we're bringing together, essentially consolidating a significant number of application all delivered from the same platform. We have built a very highly scalable go-to-market model that Amer Deeba will essentially give you more details on, as you will see a combination of market segmentation. We now serve out of the same code base, the enterprise, the SME, the SMB, but also build a significant ecosystem with a lot of partners from the MSSPs to consulting organizations to traditional enterprise consulting organizations. We have built a true cloud platform, which is extensible. Sumedh is going to give you the view of what makes that platform so powerful.
In fact, we've built a significant barrier to entry. It took us a long time to build all these capabilities, where essentially today we can scan every IP on the planet, every website on the planet. We do about 3 billion scans a year today, and of course, we could do significantly more. Also, as most of you are familiar, have extended the capabilities of that platform with this groundbreaking agent technology, which allows us now to enter also not only make the vulnerability management application and the policy compliance application more real-time, more effective, more continuous. It's also now, it's a new platform that, as you will see in the demos and in the presentation of Sumedh, also enable us to bring additional solutions together. Sumedh will also tell you about that additional technology that we're bringing, which is the passive scanning, essentially the network analysis.
If you look at what Qualys does, today we have two main engines. One is the scanning capabilities. I used to say like the Klingon on the Enterprise, the scanning, the universe here. Then the second technology, which is this Cloud Agent technology, bringing in real-time continuous information back. Now we're adding the third technology, which is analyzing what's coming in and out of devices and what's happening in the network, bringing all that into a powerful back end where we can, of course, correlate information, analyze, and have a much better view and much more continuous view of the security and compliance posture of your entire computing infrastructure, whether it's on-premise, whether it's on endpoints, and whether it's on cloud environment. This is what Qualys has done very uniquely.
Because of that platform, also, we've been able to release significant numbers of new services in 2016, and Sumedh will tell you more specifically about all the new services that we're about to release in 2017. We added, about a few months ago, Elasticsearch capabilities, which allows us now to view and search in seconds across all that information that we collect, giving the ability to provide companies with that two-second visibility on their global IT assets. Again, Sumedh will give you a live demo of those capabilities. We have, in fact, built an impressive engineering capabilities. First is, of course, the platform in itself. It took us a long time to get there, but again, it's a huge barrier to entry that we have created for ourselves. Also the unique organizational structure that we have established.
When we embarked about five, six years ago now to rearchitect our first platform because we realized that, of course, the technology has changed, so we injected a lot of new things into the platform. We embarked into the major architecture expansion. What we realized is that the cloud was very different. The beauty of the cloud is that you can deliver instantly your services or your solution globally. So we realized that, in fact, we needed to put together into under one roof all the components that are needed to ensure that we can build, QA, deliver, support our solutions. Under one roof, under Sumedh, we put essentially engineering, QA, ops, DevOps, customer support, and product management under one roof because all these pieces have to work 24 by seven together.
What we did is we cloned that structure in Pune, in India, which allows us, of course, now to have the full 24 by 7 coverage, but also allowed us to attract, in fact, the top talent in India. India has become a significant element of our ability to continue improving our solutions as well as delivering new services. We have now today 200 people in Pune, India. We have added about 100 this in 2016, of course, we are continuing investing there. We went to India not for the cost. Many company goes to India for the cost. We went for the talent. Then as Jack Welch said many years ago, "And then we discovered the cost." Engineers in Pune, India cost us $25,000 a year as opposed to $200,000 in California.
Significant advantage We'll also build over time, excuse me, a global presence. We have essentially 25 companies registered in the world where, of course, we pay taxes, where we have local teams. That, in a way, give us significant opportunity to increase our sales productivity. Why? Because today we do much bigger deals in the U.S., which represent about either 75% of our revenues. Today, we have a huge potential of increasing our sales as we deliver more services, already have built the infrastructure. Of course, this is significant productivity gain that we're expecting to see in the future from our presence abroad. In the U.S., the increase in productivity is the fact that we do more and more bigger and bigger deals. I think Melissa will give you some data about how we see the dollar per customers increasing significantly in the U.S.
Finally, we have also built a model which is extremely profitable. In fact, Melissa will go through the specifics of what makes our model so naturally profitable, as well as she will give you some metrics about how to look at the model that we have been building over time, and how is that model shaping up. Now what do we want to achieve in 2017? Essentially, we want to focus on three things. One is that we're continuing investing for growth. This year has been a year where we invested almost in every segment of Qualys, in sales, in marketing, in engineering. We want to continue that because we believe we have a huge opportunity to seize as we are delivering more services. We're going to pick up naturally more momentum.
Having more services to offer makes us, of course, much easier to get new customers. Of course, it makes us significantly more sticky with our existing customers. We now want to also look to, we've been doing everything organically, essentially since the very beginning, for a very simple reason is that as we were re-architecting our backend, acquiring companies and having to integrate now their technology would have been far too much. We're very prudent in that sense and say we need to get our architecture right, build the right foundations, then we will be capable of acquiring companies. Today, as I've mentioned quite a few times on the earning calls, we're ready for that, except that we need to find the right companies, we're very careful and making sure that we're just not looking at a company just to get top-line growth.
Looking at companies which either will allow us to accelerate some of the existing development that we're currently undertaking, or that would essentially bring us faster into adjacent markets. Their technology needs to be also capable of being injected into our backend. As we speak today, as I used to say, we're kissing a lot of frogs in hope to find the princess. We are very actively now looking at making some small acquisition, technology-centric, which again, will either allow us to accelerate some of the undergoing developments or bring us faster into adjacent markets. The second focus is that today we have the opportunity now that we've built, as you will see from the demonstration of Sumedh, a significant and very powerful solution. This is the time for us to elevate our messaging.
We always have been careful to this, to our Qualys, of not claiming things until we really have them. Some other companies take on a different approach. We're being seen and we're seen much more as a vulnerability management company, which has done a very good job there. Today, we're significantly more than that. As I mentioned to you, we believe that we are going to become an important actor in the much needed consolidation of the cybersecurity industry. One of the things, of course, that we are going to do is to now reach out to the CIO. Historically, we've been selling bottom-up. We started to sell to the techies, to the white hats, and then moving up the food chain. We're selling now more and more to the CIO, to the CISO.
Now today we have the goods, and you will see that very clearly in the demonstrations of in the live demos that Sumedh will give us. We have now the ability to go and sell to the CIO. Essentially, this is what I can go and tell any CIO today on the planet. Today, Qualys can provide you with a 2-second visibility across all of your global IT assets, whether they are on-premise, on endpoint, or in the cloud. Again, you will see that from the demo of Sumedh. Across millions of IT assets, we can add attribute to those assets, the business owner, the technical owner, the criticality, what the asset is. Then we can synchronize also that with your CMDB. We have done already the synchronization with the ServiceNow CMDB and starting to have some customers doing that.
We are with a few large companies today, building that ability to provide them with a full, continuous, global view of the inventory, which today, no company in the world really has been able to do. The second thing from there. We can now provide you with a continuous view of the security and compliance posture of those assets. Soon, early next year, we're going to be able to also provide you with an indication of which assets are already compromised, or those that we believe have indicates that they probably are as well. Finally, and as importantly, of course, we can reduce drastically your spend. Why? Because we consolidate today 10 enterprise security and compliance solutions, which again, all require their own infrastructure, their own people to manage them.
That to integrate the data between those applications, you need to go and take the data and put that into a Splunk or into anything else, or create that integration yourself. You will see, for example, with ThreatPROTECT, that Qualys offers you natively integration of threat information with the vulnerability information so we can help you prioritize. That today requires, of course, if you're a Qualys user or a vulnerability management user, for you to take the data out of our application and essentially use another, either put that into Splunk and put the threat data, do yourself all that correlation. Well, now today, Qualys can offer that to you natively. Just through that very simple process, we eliminate a lot of cost.
One of the beauty of our cloud-based architecture is that everything that Qualys does is centrally managed, self updating, and this is how we can eliminate significant cost. With that, thank you. I would like now to introduce Sumedh, our Chief Product Officer, which is going to show to you essentially what I've just told you. Thank you very much.
Good morning, everyone. I'm Sumedh Thakar, I'm the Chief Product Officer for Qualys. As Philippe said, I'm responsible for all product related functions, engineering, product management, customer support, infrastructure ops, essentially anything that's needed to keep the product up and running and innovating on the product. I'm going to talk a little bit about what we have done in 2016 on the platform, then give a couple live demos on functionality that we already have released recently as well as a couple of the upcoming new products that we are working on around file integrity monitoring, indicator of compromise detection from malware. Then give a bit of a roadmap update on when we will be delivering these services. Kind of elaborating on what Philippe said, our customers today are, everybody's global.
Even a small company today like Qualys, as you saw, has multiple locations, even with 600 employees. Everybody kind of needs to have a view of the global visibility in sort of this perimeter -less world. Today, our customers look at infrastructure. They have their on-prem infrastructure that they are working on, have been working on for a while. Obviously, endpoints are increasing. A lot of people don't give desktops, laptops are going out of the enterprise all the time. Traditional enterprise solutions don't work that well on that. Then there's a definite move towards cloud in pretty much every customer. They are moving a bunch of their applications to the cloud. You have all these interconnected systems that are heterogeneous, and they have to be looked at by the security team and the IT team all at the same time.
It's not a 1-flip switch that moves them from the existing infrastructure to the cloud infrastructure. A lot of times they will have all of these infrastructure connected, the risk, as they're looking at from a security perspective, is also connected. You have your application, maybe your payment processing for our customers is hosted inside their on-prem environment. Maybe the front end of that is being hosted in AWS or Azure. You have laptops for employees that have privileged access that are out there at coffee shops. Any 1 of them getting compromised can basically lead to a compromise of the overall system. The way customers have been looking at this is they tend to get different solutions. Maybe they'll get CloudPassage in the cloud and Tanium on the laptops and then some other solutions on their on-prem.
That really creates issues for them to get the single pane of glass visibility across all of this infrastructure at the same time. Which means, as Philippe said, they need to pull that data out into other solutions like Splunk and try to build it themselves, which of course, incurs a lot of cost. That need for single pane of glass is certainly there. The way we have been developing our platform is making sure that we can provide the single pane of glass view with sensors and connectors that are throughout all of the infrastructure that they today have to manage. We have done a lot of work in creating multiple different sensors. Whether it's on-prem, physical environment, physical servers, whether it's virtual environment, with virtual, we have 11 different hypervisors that we support. We have cloud certified AMIs in Amazon, Azure.
We have the Cloud Agents now that go on all three infrastructure. We're also pretty close to coming up with a sensor for Docker and container-based security as well. Of course, we're releasing our passive scanning sensor, which gives the visibility on the network side, as well as our API. With this approach, we, instead of having individual instances of the solution being deployed in AWS, in Azure, on-prem, and they don't talk to each other, customers get the single pane of glass view. We take a combined approach with agent-based technology, agentless technology as well as the passive scanning technology. All of that, pulling that information, putting it into the back end, and that's really where we do a lot of the analysis.
There are solutions out there which are being leveraged to ask queries off of the devices, like Tanium, where you go in and you ask a query that gives a point-in-time response. Our approach and architecture from a cloud-oriented architecture perspective is very different. We collect information from the devices. We put that up into our platform. We have done a lot of work on the platform side with new back end, with Elasticsearch, with Kafka, a lot of these improvements and new back ends that we have put in place. The idea is that as the sensor picks up a change on the device or on the network, it sends that up to the platform. Based on what the customer has subscribed to, we will run the different engines that analyze that change on the platform side.
This keeps the sensors very lightweight. We have the ability to say one registry key was changed on the device. Does that mean it's a vulnerability? Does that mean it's a compliance issue? Does that mean it is actually part of an indicator of compromise? We can do that analysis on the platform side without the customers having to take that hit on their devices. This also consolidates the number of sensors. In a traditional environment, you will have a different sensor for looking at a file for vulnerability. You will have a different agent for file integrity. You will have a different agent for indicator of compromise detection. Now we are able to consolidate all of that with a single agent, one sensor that is looking at the changes. All the analysis is being done on the platform side.
Now we can give different views, as I will show in my presentation. We can get different views of that same change based on which group inside the organization is looking at that. As I mentioned, because of the sensors, the distributed sensors that can go globally, we have multiple customers today that have 200, 300 appliances. These sensors, as Philippe Courtot mentioned, we have over 1 million agents that have been purchased already by our customers, all of them putting information up into the platform. We have our analytics engine, we have our API. That is enabling us to provide multiple different solutions off of the same platform. As I will show in the demonstration, that one change in the file can now. Today we are looking at that for vulnerability and compliance.
We can also now look at that from a file integrity monitoring perspective. For customers, what does that mean with this platform? Instead of them deploying individual sensors and agents, of course also the management consoles of each of these solutions in each of these infrastructure, an additional system to try to pull the data from each of them and making it work on the Qualys platform, they get all of that already built into the platform. All of those applications are off of that same platform. Not only can they reduce the amount of cost that they have to do by putting infrastructure, putting more servers for each of these solutions, the management console, the agent, but the information coming into the platform is already correlated.
When there is a file integrity alert, you're going to look at the asset. You already see all the information regarding the asset inventory of that asset, the vulnerability posture of that asset, the compliance issues with that asset, all in one place already pre-built, so they don't need to pull this data out in other systems. The platform already does about 3 billion scans every year. We are processing trillions and trillions of data points. We've also done a lot of work on taking the platform and making that available as a private cloud option as well. Which means that in highly regulated environments, customers that need to have that information on their premises, not necessarily have to put that information out in our data center, have that option. It's the exact same code base.
It's deployed in the customer environment, but Qualys will remotely manage it for them. We have hardware virtualized. We have that in AWS now that our platform also is FedRAMP certified. We just recently became FedRAMP certified. We can now put this platform in GovCloud or SIs who actually are already working with the federal government. It gives us multiple options for creating sovereign clouds. Today we already have 30 of these platforms deployed globally, managed by Qualys. It allows us to go in countries where a partner can deploy the Qualys platform, provide multi-tenant services to the customers in that particular country, because they may be okay with the cloud, but just not the data going out of their country.
This really is enabling more of those partners, customers to deploy the same platform and all of the same services inside their premises, managed by Qualys as well. We've also done a lot of work this year to create a smaller version of the platform. For banks in these different countries where they may not have as many number of IPs, we have customers today that are scanning anywhere between one to two million devices on a daily basis. With the platform, we manage huge scale. There are also customers who are looking at 30,000, 40,000 devices only right now. For them, this solution, which is a single U, where we are leveraging container technology to deploy the same features, same functionality now inside of their environment, even for a smaller item, much lower cost to them.
However, still managed by Qualys is another innovation that we have done this year, which is now enabling us to go into the markets in Asia and these countries where they do need to have, because of regulation, the information stored in their environment, but they don't have that many number of devices as well. One of the foundational changes we have done on the platform side is the Cloud Agent. It's a very innovative agent that we worked on, and we have filed patents for that. It's a very lightweight agent. It goes on your on-prem and servers for the customers. It goes into dynamic cloud environments as well as endpoints. Because of its nature, and being lightweight today, it is very scalable. We have over a million of these already purchased by our customers. The really significant advantage of that is that we provide this agent.
If you think of what Philippe was talking about, giving our customers the ability to have that global view of all of their assets, we give this agent for free to all our customers, so they can deploy as many agents as they would like. That free agent gives free asset inventory information up to date, near real time, which brings a significant value to the customer. If they want to go in and search for their assets in the platform, they can do that very easily.
From that point on, when they decide that they want to do a vulnerability assessment or compliance or file integrity monitoring or any of these additional solutions, they can just go in and now they can actually leverage the licensing model, and they can actually purchase those to get some of those agents or a bunch of those agents working on for leveraging those modules as well. The reason why this agent is different, it is a delta-based approach, so we do not actually run the analysis on the endpoint. We actually collect information about that device and what is changing on that device and send that information up to the platform. That makes it extremely lightweight, very low impact to the CPU and the network, and all of the information is stored on the platform side.
That is where all the heavy lifting happens, which is very different than the other agents. Today, that agent provides our customers with the ability to instantly query information as I will demo. You can go and say, "Show me all devices that are a particular manufacturer, show me all devices that have this particular OS or this service running on it, or a particular version of the software running on it." Typical asset inventory challenges that customers struggle with because their CMDBs are not up to date. We provide that functionality with this agent. That same agent is providing also that real-time asset inventory with the query capability. We are doing vulnerability management with that agent today, as well as the policy compliance, configuration compliance functionality.
Coming up, as you will see, early next year, is also going to be file integrity monitoring with that same agent, indicator of compromise detection. A big one that we are going to do next year is also the ability for that same agent to also deploy the patch. Today, a lot of our customers with Qualys, they get the view of their entire patching environment or what they need to patch across all of their infrastructure in one view. Across 2 million devices, they will see exactly how many devices. In one single interface, they can see that how many of their 2 million devices need a particular patch. When they have to go and deploy those patches, they have to work with 10 IT teams, 25 different solutions based on which operating system it is.
The patching is very costly and takes a lot of time. Now by providing with that same agent, the ability to, in the same interface where we show them that these patches are missing, to just say, "Okay, now go ahead and deploy this patch across these 10 global locations" is going to be something significant, and that will really eliminate a lot of costs for our customers in deploying the patch management capability as well. Quick note on the passive sensor. As we talk about putting an agent on the devices that the customers know about, having the appliance to scan actively networks. The third component of this is the ability to have a passive sensor.
We can actually look at all the traffic in the various environment networks that the customers have so we can pick up the activity on the network, new devices coming onto the network, devices communicating on the network. Now when they look at that interface, that single pane of glass view, they can see exactly how many live devices are communicating, are alive on the network. Out of them, how many of them have been actually scanned already by the Qualys VM solution, how many of them already have the agent, and then how many of them they don't know what that thing is. It's there, it's communicating. Now we provide that visibility, so customers get value out of that.
Of course, it also encourages them to now be able to bring those additional devices as part of their scanning program, as part of their indicator of compromise program or their file integrity program as well. In 2016, we have done a lot of work. As Philippe said, we have a 200-person strong team, in Pune, in India. We have about the same number of developers in the U.S. as well across different teams. We have been able to deliver quite a bit through the year. We delivered AssetView and ThreatPROTECT, which I'm going to demo. We went GA with our Linux and Mac agent.
We created a ServiceNow CMDB synchronization because as our database is up to date in near real time about what software is installed on those devices, what hardware is there, what's the disk space availability, that information needs to be synced into ServiceNow. A lot of customers are using the ServiceNow CMDB. We have a connector in the ServiceNow app store that they can just leverage that connector and keep their information synchronized between the two different solutions. We have a TA for Splunk customers who want to pull this information into Splunk can now actually do that with a TA that is provided by Qualys. We talked about the smaller version of the private cloud platform that we provided. It was a huge effort to get FedRAMP certification and we achieved that, now we're looking forward quite a bit to working with federal customers.
Updated our web application scanning capabilities to address newer single page applications, AJAX applications. That's been quite a big feature that our customers have been waiting for. Another thing that we released, I think, which is quite strategic, is the Azure agent. The interesting thing about this is, this is one of those, when we talk about security needs to be built into the fabric of the infrastructure, this is a great example of that. Now Azure customers who have their Azure Security Center from Azure can directly, without having to download or without having to go through multiple steps of deploying, go in and click, with a single click, deploy the Qualys agent on all of the VMs that they're running on Azure. That information then automatically is processed by the Qualys platform and synchronized back into Azure Security Center.
Now customers who are leveraging this new infrastructure, with a single click can get that functionality, it also provides the information with the cloud-to-cloud integration back into Azure so that they can actually put remediation policies around that with the Azure Security Center. They can say, if Qualys reports that there are X number of vulnerabilities, those vulnerabilities are synchronized back there, and if I see any issue on one of these VMs, which maybe has a publicly exploitable vulnerability, that needs to be quarantined, put it in a different security group, whatever it is. Making it extremely seamless and making it very easy in sort of deploying entire solutions as their own VMs into these platforms, like Azure and Amazon, not only do we have our presence there, but we are integrating very well in a true cloud-to-cloud integration, which is really the future.
We also released a new capability around Security Assessment Questionnaire, which is a new module our customers can buy. It provides them the ability to collect non-technical information as well. Now they can actually create questionnaires. A lot of them need to work with external vendors. They need to ask them questions, have them answer questions, upload evidence about security measures that they're doing. Now, on that same platform, with all of the scanning that they do with the agents, with all the security and compliance-related checks they do, they also now get the ability to purchase from Qualys this capability where they can now send out questionnaires to internal stakeholders, to their vendors, have them review those, upload evidence, and then provide a way to track all of that in a single place. I'm going to give a quick demo of the capabilities around AssetView, ThreatPROTECT.
Hopefully you can see that. Our customers are logging into Qualys now. They used to have vulnerability management as the solution that they purchased. Now when they log in, they get to look at and switch between and buy off of the same platform multiple different solutions that allow them to fulfill different compliance and security needs off of the same single platform. Today, if you look at the various things that are already available, all the way from web application scanning, ThreatPROTECT, AssetView compliance, PCI, all of that off of a single platform. AssetView is the new module that we have put in place that allows our customers to get that instant visibility, ability to search across multiple different assets very quickly. It really is where we have put all our Elasticsearch clusters. We are indexing about 5 billion data points for our customers today.
Those are 5 billion data points that they don't have to spend money to index on their side. We are doing that already off of the platform. This is enabling them to do multiple different things. It will really reduce the number of FTs required to get information out, to get solutions, or widgets and applications right out of the box on the platform. Simple use cases, like I talked about earlier, they can just go in here across their global assets, a few million assets, they can go in here and say, "Show me all devices where the manufacturer is Lenovo." Out of the 2,000 devices we talked about, 690 devices are Lenovo. Filter quickly further to, say, only in a particular location, only the ones that are in our India office. There's 127. Very fast, less than two-second visibility.
You don't have to actually send out queries to these devices and wait for them to respond, and only the ones that are alive will be responding in our model. The data is constantly kept up to date on the platform side. We're able to go in and do the searches very fast. You can look at that information quickly, group by, say, the manufacturer, the model number. We can very quickly tell our customers across their entire infrastructure how many assets for which particular model or which particular model is in the environment, how many of them are there. It's all drill down. Customers can do simple security use cases, which actually is a very important use case. We see a lot of customers buying Tanium specifically for that.
It's just the ability to go and say, "Show me all devices." CIO somebody, CISO somebody says, "I found out that a particular version of Adobe is being actively attacked. How many devices do I have in my environment that have that particular version?" They can just come in here and say. For software name, let's say AIR and the version of the software. 172 devices exactly in my environment have this particular version of Adobe software installed. Now very quickly they can go in here, they can download this. Very soon we'll be allowing them a way to create a connector to send this information to ServiceNow so they can create tickets.
From the point that they are being asked or told that we need to find this specific information, it's a matter of couple of seconds when they come into the platform to get this particular view without them having to create connectors and pull this data out in different environments. Of course, we also have the use of. For example, here, the other thing that we do a lot is also the ability to consolidate various pieces of information. You will see more with the new things that we are doing, how we are giving customers that global view, exactly telling them who's the logged in user on that particular asset. You can see that logged in user, IPv4, IPv6 addresses, information about the location of that particular asset. Where did we see the asset? A minute ago we saw this asset in San Mateo.
We bring them all the information about time zones, model, manufacturer, all running services. You want to find out all devices that have a HTTPD service running on them. Everything that I'm showing here in this screen is searchable, they can go and search that. We're bringing all information about user accounts on each system. Again, we're talking about customers, how easy it is for customers who have millions of systems. They can do this in a matter of couple of seconds. Somebody comes and says this particular user name has been compromised. How many devices are at risk? How many devices have a user account for this user on them? They can come in here, type that particular username, and within a couple seconds, we're going to give them that visibility so they can actually make that actionable. We're bringing all network information as they have multiple adapters.
Today, a lot of customers struggle with devices with multiple adapters. They only see an IP address on the network. They don't know exactly which device that belongs to. They may be the same device with multiple interfaces. They can bring all of that together because we are collecting all this information. Everything about open ports, installed software versions. Multiple use cases, just want to know how many Word licenses do I have purchased versus how many of them are actually being deployed or I have in my environment. You can come in here and get that information. As you notice so far, I haven't even talked about vulnerabilities. We additionally also provide the vulnerability view, of course, what vulnerabilities are on this particular device, which vulnerabilities do I need to fix first, how many of them are active.
Quickly change that view to going between 30, 60, 90 days. As you will see in the upcoming release, we're bringing even more capability around that. Now when customers need to go and find out on a particular device what's going on, a lot of that information is already being provided to them out of the box in the Qualys platform. Simple use cases like I want to find out where are all my Google related vulnerabilities. They can come in here and say, for that particular CVE, show me all the devices. I have 200 devices. I can quickly look at that by, for example, operating system.
Now not only do I know that there are 92 devices on the Windows 7 operating system, but I can also go down all the way to see that there's a Hitachi storage array controller that has that particular vulnerability. There's the [net screens ] that have that particular vulnerability. This is possible only because we have taken that approach of bringing agent-based and agentless information together in one place. If this was only agent based, then you cannot get information about network devices, databases, things like that. If it's only databases and network devices, you cannot get this view of real time on these assets. As you can see, we're providing this view really snappy, quick, out of the box, and we've done a lot of updates on the platform to be able to provide this kind of functionality.
We see a lot of customers doing simple use cases like, I want to know which of my machines are pointing to a DNS server that is compromised. All they have to come in here and say DNS IP address, let's say we take the example of this. Now we're going to show them exactly 338 devices in this environment have that particular DNS server on one of the interfaces. These are the ones that maybe they need to look at quickly. All this information is available even if the device is offline, because just before the device went offline, it has uploaded its delta changes to the platform, and as soon as the device comes back online, it's going to update that information up into the platform.
Another part that we provide our customers an easy way to create applications, so they can create multiple different applications, which is a collection of dashboards, widgets that they can track different things, maybe asset only. Creating widgets, we have made it extremely easy, very much like how you can do this on Splunk without actually having to pull that information out. We provide a bunch of out of the box widgets already related to asset threat, and they can share widgets amongst themselves. It's very easy to, for example, say I want to track all my OpenSSL related issues. All they have to go here and say, show me all devices that have an OpenSSL related vulnerability. It's going to be 334. I say compare with my overall number of devices. I have 16.15%.
Now for a better comparison, I'm going to say I only want to look at the ones that actually are SSL related. What does that tell the customers very quickly, of all the devices that have an SSL related vulnerability, what percentage are related to OpenSSL? Now they can say, if I patch OpenSSL in my environment, what's the bang for the buck that I'm getting? That's exactly 48.4%. If they go and focus on patching OpenSSL, they're going to get this particular thing. They can create tracking capability, give this access to a lot of their internal stakeholders. You can say when everything is good for this particular widget, it's always going to be green. Any time that I see that percentage is above 15, which is the minimum acceptable percentage, I can say that particular color is going to turn orange.
Just like that, very quickly in a matter of few seconds, they are able to compare anything against anything and create a very, very customizable widget off of the platform. Not only that, what we have done, and this is really significant, is taken this capability of AssetView, which we have rolled out to all our customers globally. All our customers have AssetView. We don't charge additional for AssetView if they have vulnerability management already purchased from us. That has enabled us to bring a new solution to market that our customers purchase from us, which is ThreatPROTECT, is the ability for us to leverage this Elasticsearch.
This was done just in a matter of few months by a couple of developers because the platform already has so many of these components that we were able to create a new solution, which is revenue generating for us with just a few engineers in a matter of few months, to give customers that ability to say, "That's fine, I have all these vulnerabilities, but what is exactly going out there in the wild? What is being attacked? What is it that I need to focus on?
What do I need to prioritize?" Now they get to see this view, and not only do they get to see all the information that our research teams do in terms of the research, how exactly it manifests itself and all of these things, but it also gives them the ability to, which is probably more important, is to basically be able to say how many devices exactly are impacted in my environment. By clicking on that, they will know exactly the 65 devices in their environment that are impacted by this new attack that is currently attacking Silverlight from Microsoft in the last 24 hours, or there is an exploit kit called Angler or Neutrino and a particular vulnerability is now exploitable in one of those that we've noticed in the last few hours.
It gives them that ability to actually go ahead and prioritize their fixes so they can now focus on saying within five seconds of our research team adding that capability or that intelligence in the platform, we make it actionable for all our customers because they can now go into their accounts and see that information with the exact number of assets that are impacted. This is not a threat feed that gets sent you an email that you cannot really do anything about it. This is very actionable and this is something that our customers can purchase. Again, another derivative on top of the vulnerability management solution. We also provide enhanced capabilities on top of this with Continuous Monitoring, the ability for our customers to actually make this even more actionable by being alerted proactively.
Another thing where we do a lot of the processing of the deltas, and we create alerts for our customers on many different things, not just related to vulnerability management. Customers who want to put a simple rule that say, "I only buy certificates from VeriSign in my environment. If I ever see a certificate that is not from VeriSign in a given data center, it's a security issue, compliance issue." They want to be alerted. They don't want to have to go and dig this information every time. It's as simple as them coming here, creating a drag and drop rule that basically says anytime a new certificate is detected in the environment and if that certificate issued by does not contain VeriSign, they click finish.
They have a rule that actually will send them email alerts or alerts into their incident response system so that they can actually proactively start getting alerted on that. We have customers now who are getting better with their vulnerability management program now purchased up to this particular solution so they can do in addition to just looking at vulnerability. As you saw in this example, has nothing to do with vulnerability management. Because of the sensors, the scanners, the agent as well as the upcoming passive scanner, we'll be able to feed all these systems so it gets better and better for them to be able to get that particular view. Another thing that now I would like to demo is some of the new things that are upcoming over the next few months in the changes that we have made.
I showed earlier, of course we're going to have this global view as we talked about on a map exactly the assets where they are. You can click on that. As I showed earlier, that AssetView is becoming that one place when they come to find out any information that they need about that particular asset. Now, with some of the enhancements that we're putting in place, our customers will see even more information as they get more solutions from Qualys, as they purchase more solutions from us, they can see even more consolidated information in a single place for that given asset. When there is an incident response, like I said, you find that a particular device got a malware alert.
You want to go and find out what's the history of this device, what is installed on it, who's logged in user, all of that information. Now not only do they have the vulnerability view that I talked about, now they also get the ThreatPROTECT view. They purchase ThreatPROTECT. Now they know very quickly exactly on that particular asset how many vulnerabilities do they have or how many issues do they have that may not even be vulnerabilities that actually may lead to high data loss or high lateral movement. What are the issues on that particular device that have a publicly available exploit that they can look at. We go even a step further to show them that view of saying the patch summary information. For some reason it's not working As always, it's a QA platform, something has to go wrong.
The patch summary here is going to show them exactly how many patches need to be deployed to fix how many vulnerabilities. A lot of time people want to prioritize and say, "If I apply these three patches, that's going to fix 300 vulnerabilities." They get to see that particular view in this particular way. If they have purchased a compliance solution from Qualys, not only will they know the security issues, they also get to know, how am I doing against the compliance mandate that I have? What CIS benchmark, NERC CIP, HIPAA, whatever different benchmarks that I'm tracking against, how many controls am I failing against? You may have a control for encryption, for example. Say I have 42 encryption-related controls that are failing on this particular device.
Now you can come in here, the customers can come in here, they can actually look at that very quickly. Within a couple of clicks, they can see all the details of that particular information saying which exact controls are not working and why are they not working, what's the evidence around that as well. Let's see if this loads in a little bit. As I'm going to also quickly give a demo of the new upcoming solutions around indicator of compromise detection, around file integrity monitoring. Customers who are purchasing that from Qualys will also get, in this single view, the ability to see what kind of malware-related alerts are being generated on that system as well. They don't have to go to 10 different solutions to try to consolidate that. Here you can see in this example, you have Zbot that's shown up.
We show exactly the information on why this particular indicator of compromise has been triggered. What hashes did we find for those files? What are the locations? Maybe there's a network connection that that particular device made to unknown bad IP address, or an activity, a suspicious IP address. We bring all of that information together and show them which of their malware indicators maybe have been remediated, which are the new ones that are coming up. The same we do for file integrity monitoring, again, in that same view. They can create triggers, alerts on events that they don't want to see, certain folders or configuration files that should not be updated, certain directories where no files should be written in a production environment. We bring all of this information. It's all drilled down, and I'll show a little bit more in details of that as well.
Now, early next year when we have this release, now customers, in addition to all the different solutions, will also be able to see file integrity monitoring and indicator of compromise detection capability. From file integrity monitoring perspective, this is the new things that we're going to show today, and these are coming up over the next Q1, Q2 timeframe. We'll have this out in beta, and then we'll be going G as well. The idea here is that this is typically what customers buy a completely separate solution for, very expensive solutions like Tripwire, that they deploy on their systems separately from what they do for compliance, what they do for vulnerability management. They have to have their own agent, they have to have its own console so that it can show this particular view.
Now it's all combined with the same agent, with the same console. They can bring all of this information from that same device up into the platform. They see this view of all the changes that are happening on the system. They can go into the events. They can see all the various events that we are generating. Let me take an example. In this case, say from looking from September 1st. We bring all the events that are being triggered on the various files based on the various profiles that they have created. We provide out-of-the-box profiles like HIPAA or like PCI, so they don't really have to go too much into the details of that. When they click on it, we bring all of that information. Let me see, I can search for a particular file.
Here in this case, I look for a particular file. What host was it on? When I look at the details, it's going to show me all the information about who modified, what was modified, and it will also show me exactly what was modified on that particular device, all in the cloud platform. If you look at the indicator of compromise solution, again, with something we're going to have a beta of in Q1. Again, this particular solution provides the customers the ability to, what typical traditional solutions like CrowdStrike or some of these may offer is the ability to say, show me the hashes. Given a hash, you can investigate a particular system or systems across your environment. You can do that with that.
Because we are proactively collecting information on our side, we can also show customers things that are suspicious, not always something that they have to go and look for hashes by looking at threat intelligence. Things like processes running from recycle bin. We are collecting this information so we can proactively show it to them, saying, "These are the ones that you need to focus on." Because maybe that's not a normal activity. It may not be a confirmed activity that it's a malware, but again, they get that particular view off of the same platform. Anything where maybe their antivirus is disabled or out of date, something that's running without a disk image. Sometimes malware installs itself, deletes its own file. If you see a process. We are collecting and bringing all this information together.
We're also doing something very unique with our team in India, which is doing a lot of research around this, is there is thousands and thousands of malware signatures generated every single day because of the variance. What we focus on is we analyze the malware, and we actually look at the characteristics based on a family. A lot of times, just like regular developers, malware developers are also lazy. They take the same code and they modify it a little bit, and put it out there. The good news is that a lot of the characteristics, even the hash, does not match. Our research teams are generating IoCs that are based on the family. We can say, look, typically, a malware of this family is going to show these eight indicators.
If we see five of those or six of those, it's a very good possibility that you have an unknown malware that's a variation that still doesn't have a signature. We're also providing that very unique capability around that as well. Of course, we can show all the infected hosts by location, by particular system, things like that, when they go into investigation. I have this example here that I have pulled up. FBI puts out these pieces of information around when some new software is being leveraged out there that is malware. They give these hashes. Of course, the solution can come in here, and you can basically go to the Events section and just say, hash dot There you go. We found a couple files.
Again, because we already have this information with our new agent, we are actually able to collect the information on the hashes up front in the platform. We're able to go and find this information very quickly. Again, we can go look into the details, which show all the information around that. Again, that file integrity solution is something that is providing that kind of a capability, again, off of the same platform, so customers can look at the various infections. Again, once a customer gets the agent, for the free agent or the vulnerability or the compliance, trying all these other solutions is extremely easy. They don't need to go and deploy anything. They don't need to deploy a new console. They don't need to go deploy a new sensor.
They can just select a bunch of hosts, they can actually go ahead and I'll show that component as well. Customers that have the Cloud Agent, for them, it's extremely easy to do a trial. We can enable a trial for them to go in there. All they have to go and, say, create a new activation key, for example, and say, any agents that are registering with this particular activation key, what modules are licensed for that? All they have to come in here and say, "Yes, these agents, I want them for FIM, for IoC." It's that simple compared to even if you want to do a POC of one of these solutions, you have to spend months getting infrastructure in there, procure, deploy, and that's how easy we make it on the platform to be able to do this.
Another key change we're releasing as well is, we are also now providing a very important capability around the ability to create trends across the various parameters that they are looking to track. Coming in the next month or so, we are going to release the ability for our customers to trend on the pieces of information that they are tracking out of the box. Typically, creating trending information means that they have to set up their own data clusters, their own Splunk instances, their own Elasticsearch instances to do an ETL process to pull this data, which needs developers, which needs machines.
We now provide this information out of the box, so when they click on that, they can clearly see the trend of what we are tracking on how the particular issue may be, which is being exploited out in the wild, maybe SSL certs, maybe configuration issues. Things that have nothing to do with vulnerability management can be tracked in here completely out of the box just by checking a little checkbox saying, "Track this particular widget." Another thing that we have also done is quite a bit of work around I'm going to try to demo the new changes that we have done around the web application scanner. The Web Application Firewall, we're releasing our new Web Application Firewall end of this year, early next year as well, and that has some significant changes.
It really brings the ability to do virtual patching together with the scanner. Today we have customers that are scanning hundreds of applications with the scanning solution, but they don't have the resources or the ability to deploy expensive firewalls in front of them, or developers take a long time to fix that. Now in here, they have the ability to come in and do virtual patching very easily directly from the scanner. They can actually go in and say, if they go into the web application scanner, as they have findings that our scanners are finding for them, we now make it extremely easy and very unique that nobody else is really doing, is the ability for them to go and say, 'Let me see if I can find the next vulnerability.' To say, 'Install a patch.' Let me make that example. Let's see if I have that.
Here we will show right here in there that this particular vulnerability is, for example, patched by the virtual patch. All they have to do is right click here, say install the particular patch. For some reason, I don't see the example that I had in here. When they go back into the Web Application Firewall, now they can actually see all the events that are coming up from, you can do multiple things based on the specific page, the specific parameter, or just things around a particular country, or location or IP address. For example, let's say we want to go and allow them the ability to create a new key. Some rule. How easy is it for them on the platform to create these conditions?
All they have to say when the client IP address, for example, is coming from a particular country that is in the list of, say, Ukraine. What is the action you want to say? The action will be, let's say we want to drop the particular packets. That's it. Within a couple seconds, they're able to create a rule very quickly about a parameter, about a particular location, many different things, headers. This is how we are, again, making it extremely easy for them to be very nimble and fast with their security and compliance, so they can come in a single platform and do all of this together in one particular place. A little bit over my time, but going back to the presentation.
A couple quick things I want to talk about, just essentially talking about the enhancements that we are going to do. Q4 2016, we are relaunching our WAF solution with all of the new updates. Q1 of next year, we're planning to have betas of the file integrity monitoring solution, indicator of compromise solution. We are also coming up with a new solution for SSL certificate audit. This is something that customers today have to buy and deploy Venafi, which requires scanning or an agent which Qualys already has. We can now provide the global inventory of all the digital certificates and also create alerts on that. In Q2, we'll also have the betas for patch deployment as well as the passive network analyzer. In Q3, we are looking at another very unique solution, which we call the CloudView 360.
Is going beyond just virtual machines, collect information, leveraging the APIs that cloud providers provide, like Azure or Amazon, and bring all that information into the Qualys platform. Across multiple clouds, VPCs, they can actually see how the resources are behaving, what are the groups that are well-defined, what are the groups that are not well-defined. The unique advantage would be that these are the things that companies like Evident.io offer, but the unique advantage will be that we also have the information on the actual VMs because of the agent being there, which can now fit into this particular view and make it even more actionable for them. From a product perspective, from a platform perspective, we are really focused on building a platform, which is a single platform that is providing multiple different solutions to our customers.
We already provide a bunch of solutions, and we will be providing a few more as we talked about, and more are to come later in the next year as well. Okay. Thank you very much. Joo Mi?
Thanks, Sumedh. Right now, we'll take 15-minute break. If everyone can return to their seats by 10:25, that'd be great. Thank you.
Hi, we're ready to get started. If you can please take your seats.
Okay. Good morning. My name is Amer Deeba. I'm the Chief Commercial Officer for Qualys, and I'm going to quickly go over our go-to-market strategy and execution and how we sell our services on a worldwide basis. Our platform that Sumedh and Philippe had talked to you about allows us to enable our customers with a cost-effective service across all market segments. The way we approach our market is through these four different categories, starting with the enterprise, 5,000 employees and more, the small medium enterprise of between 250 and 5,000, the SMB, which is below 250, and the consultants. What's unique also about our offering is that we package the platform separately for these different categories.
The product comes packaged for the enterprise with enterprise features, enterprise capabilities, different than the SMB market and different also than the consultants, which we recently upgraded and provided a lot newer capabilities and then better packaging and pricing so we can be very competitive in that marketplace. All these packages, basically, we take them to our customers through either direct model or through our channel partners. You see the split right now between direct and indirect is approximately 60%-40%. This is based on 2015 revenues. We're maintaining approximately the same numbers in 2016. The difference really, the volume is coming more and more through the channel, but we're doing much larger direct deals. That's why you see the difference right now around 60-40.
On this partners list, there's a couple of new logos here that are quite important also, and I'm going to talk about them individually. NTT Security, we signed them recently, as well as with the Hewlett Packard Enterprise, which we announced last week, their managed services, converting their offering and moving it completely to our platform. Our partners, we divide them into four main categories, the managed service providers and the telcos, the outsourcing providers or mainly delivered from their remote locations, either in India, on various parts of the world. The value-added resellers, which also we'll go into detail into that, and the consultants and auditors. Really, the platform is a highly attractive model for our partners, simply because the way we deliver the services and the recurring revenues we allow customers to make that on an ongoing basis.
Starting with the managed service providers, as you can see from the Magic Quadrant, we cover pretty much 80% of them, and the rest are going to come soon, hopefully. We allow these partners immediately to provide a recurring revenue model into their managed services, fully integrated into their offering. Our VM services, policy compliance, web application scanning, the agents, all of that fits into their model, and they deliver it automatically as part of their managed services offering with zero CapEx, and enables them to do these higher recurring margins, not just on an ongoing basis, and to provide value-added services on top of that. As I said, NTT is new here on the list, and HP is new. We continue to expand that market for us.
The global outsourcing providers, this is also becoming a very strategic channel for us simply because of their outreach and the ability of the large contracts they do with their customers and security is a bolt-on into it. Our services fit into that automatically. We uniquely support their business model with zero CapEx capabilities. We give them the high margins recurring services. And we work very well with their environments across public cloud, private clouds, co-located data centers, and they can access the service and provide services to their customers remotely, which fits perfectly into what they're trying to do. We have all the leading outsourcing providers as partners with us. Some, they deliver, they resell the services fully integrated with their offering, or they bundle other services around it. End customers. End customers, of course.
The value-added service resellers, this is basic, particularly are very helpful for us in the SMB market space, and internationally. They're typically small consulting houses or security firms that are moving into managed services and want to do more with our platform. We also give them high margins recurring revenue stream with zero CapEx. We have over 600 of them worldwide, and we have very good relationship with a lot of them, Optiv here in the U.S., SkyPoint, and some are also in the federal space. They're a big channel for us. Moving into the consultants and auditors, we have a very unique offering for the consultants. Most of them leverage the platform to provide pen testing services and consulting services to their clients.
We help them go into their client base and provide these services either through, it could be interconnected systems to the internet or in some cases really air-gapped environments, and we support both of them for them. But what's unique for us with the consulting market is they help us build mind share. They go into their customer sites, they provide the engagement, they do it, and sometimes they leave the product behind. If the customer wants, come back and they can purchase the product directly from us or through some of these consulting partners who are also value-added resellers. We have over 1,600 consultants worldwide, and it's a growing business for us. We recently expanded our offerings so we can be more cost-effective for them and give them better capabilities to perform these engagements for their customers.
The way we market the product is really the try and buy model. Across the board, any of these Qualys services that Sumedh had showed you earlier, you can sign up online, you can try them yourself before you purchase. We give you a number of avenues and free, what we call freemiums or free tools that will allow you to access them very quickly through our website or from our partners. AssetView is the latest addition to this set of free services. Anyone can, no matter how big your network is, you can download AssetView and have it for free. FreeScan is one of also the highly rated free tools on the internet for running a free scan in your environment that it would really allow you to test drive our entire suite from all the product tools that we have there.
SSL Labs, if you haven't used it, you should try it. It's really becoming the authority on the internet for testing SSL and TLS. All these capabilities, you can try them as a freemium, or you can also try them as a free trial through our platform. From there, we convert the customer from a freemium to a free trial, and then they become a customer. All our partners have access to these free tools so they can run their own marketing campaigns and then generate leads for their sales teams. I'd like to cover just a few customer case studies to show you how the platform is used and really our competitive advantage. Starting with a leading software company, one of the largest, one of the top 10 in the world.
They just had a bunch of legacy tools, all built-in, homemade, lots of people trying to put it together to make it work. Very complicated, heterogeneous environment that they needed to secure on an ongoing basis. They started a pilot with us in 2004 on their publicly facing internet systems. They moved into the internal scanning starting 2009. As of last year, we have basically three PCPs on the platform. They're doing over 2 million IPs on vulnerability management using the regular scanning and the Cloud Agent. They're scanning using WAF for over 2,000 apps and policy compliance. Huge scale, we're the only solution that can work at that level and work at that scale. The next one is a leading U.S. healthcare organization. Same day, we helped them build a successful vulnerability management and web application scanning program.
They were all before doing it using consultants, very costly and expensive and not continuous. They started with a small deployment in 2010 and expanded both on VM, on web application scanning, and now they want to deploy it into all their retail stores and provide that visibility to the board. We see more and more of that through our customer base. Of course, lots of excitement about the Cloud Agent, and they all want to try that also for their policy compliance pilot. From a managed service provider's perspective, this is one of our largest MSSPs that uses the platform. They had built their own solution using a competing product. It was costly, expensive. They couldn't maintain it and run it and operate it themselves. They transitioned to us in 2011.
We really enabled them to transition their entire customer base over to us. They launched new services with very little investment on their end using the VM product, policy, PCI, policy compliance, and web application scanning. They refocused all their energy, all their tools on reselling the product, integrating it into their MSS, offering it, and providing it to their customers rather than building it themselves. Now they're looking to deliver the new services, including the agent, the Cloud Agent, ThreatPROTECT, and our SAQ. The last case study is a very recent MSSP we recently signed. They had an outdated program for VM and PCI and policy compliance offering. They were using a competing product too. They transitioned to us. We enabled them to move their entire customer base over.
We're training them, getting their sales force up to speed, then helping them refocus their resources on reselling both VM and policy compliance services fully integrated into their managed services offerings. With that, thank you for your time, now I defer to Melissa. Thank you.
Thank you, Amer. You heard from Philippe, Sumedh, and Amer how we are uniquely positioned to capitalize on the move to the cloud as well as the trend to consolidate. What I'd like to cover is a quick overview of Qualys, the multiple drivers of revenue growth, the highly profitable implications of our operational model, as well as new metrics to highlight these. What I want for you to take away is that we see a real opportunity to accelerate growth, enhance our leadership in cloud security, and expand margins in the future. For those of you who are new to our company, we offer our solutions through a SaaS subscription model. We bill our customers up front for their annual subscriptions, which is very attractive from a working capital perspective.
We have a few customers with multi-year contracts, so our effective average contract length is a bit more than a year. As Philippe discussed, we have a large global customer base with no customer concentration risk. When you aggregate known, approximately 14% of our customers are from large enterprises, 50% of the Fortune 100, 41% of the Fortune 500, 33% of the Fortune 1000. However, because our enterprise customers do larger deals, conversely, they represent a larger share of our revenues, representing approximately 73% of revenues in the year-to-date period. Amer spoke to you about our go-to-market, having a roughly 60%-40% mix of direct to indirect is another factor that balances our business and provides us with sales leverage. We compete in a large and growing market.
We estimate our total addressable market at $3.6 billion, growing to $6 billion over the next few years and 11% compound annual growth rate. However, on a historical basis, our revenues have grown 22% over the last few years and in the year-to-date period. Our growth is organic as the company has not made acquisitions. The reason for our strong organic growth is that the company has innovated both around vulnerability management solutions and other security and compliance solutions. When I joined in May, I heard questions about vulnerability management market growth and our ability to sustain our growth rates. What I've unpacked for you on slide 64 is that one reason we have outperformed the market is the additional vulnerability management related solutions we've rolled out.
You can see here that the core vulnerability management solution, which used to be 83% of revenues three years ago, is only 74% year-to-date. On slide 65, we show the revenue growth of vulnerability management together with its newer related solutions, Continuous Monitoring, AssetView, ThreatPROTECT, and the Cloud Agent, and our other security and compliance solutions together, which are about 50/50 policy compliance and web application security. This is the segmentation we plan on using going forward. It includes all products grouped together in a manner that we believe most closely resembles our business, with scanners allocated across revenues. Both these groups have continued to outperform their markets. Revenue from vulnerability management solutions grew 20% in the year-to-date period, and other security and compliance solutions grew 27% year-to-date versus IDC's estimated market growth in 2016 of 13%.
Our strong revenue growth has been driven by new customers and, to a greater degree, expansion within existing customers, which is a key element of our strategy. You can see that since 2012, our revenue growth has accelerated at a faster pace than our customer count. This is due to the powerful upsell opportunities we have with our customers. We get many of our customers young, and we grow them. In fact, our net dollar expansion rates have been consistently over 100%. We expect the increased breadth of our solutions to increase our ability to win new customers and displace others because they provide meaningful savings by reducing infrastructure, operational, and maintenance costs. We're proud of the large customer base that we have built. When you compare it to the potential universe of customers, we see a significant opportunity for increased share.
Our estimate is that we have only 3% of global enterprises and 1% of global SMEs and SMBs. We also see the opportunity for additional revenues in our existing customer base. Even within our existing customers, we are not fully penetrated in terms of number of critical IPs that could be scanned. You can see on slide 70 that there's also meaningful opportunity for further penetration of our current solutions, with only 29% of our customers having web application scanning subscriptions and only 8% with policy compliance. We see the opportunity for both our vulnerability management and policy compliance solution revenues to grow with the adoption of Cloud Agent. For greenfield opportunities like the endpoint, all the revenues will be additive, and for traditional deployments, we generate an approximately 20% uplift to the underlying vulnerability management or policy compliance subscription.
We're seeing good momentum with 1.3 million paid agents over the last 12 months, but we see that as more of an indicator of a demand rather than a driver of significant near-term revenues, given that it's early in terms of greenfield deployments. We also have the opportunity to accelerate the growth rate of our web application security revenues with the release of our web application firewall that Sumedh talked about, which provides our customers a remediation tool. Slide 71 shows the customers with the most spend on new services, and I'd like to point out two things. One is you'll see that spend is higher with existing customers than newer ones, which as I said, we get our customers young and we grow them. Also, with our new customers, most of the newer services spend is going towards the Cloud Agent.
The power of our platform model, which drives upsells, can be seen in further detail on the next few slides. We've shared that the percent of enterprise customers who have bought three or more solutions has risen to 23%, up from 18% a year ago. We focus on enterprise customers because while we sell our platform cost effectively to both small customers of 50 employees as well as large enterprises, we expect to see additional solution uptake more pronounced in our large enterprise customer base. This additional solution uptake drives meaningfully higher spend. For the year-to-date period, the average spend of an enterprise customer with three or more solutions was 82% higher than customers with two products and over three times that of customers with one product. It's also driving increasingly larger deals.
Since 2012, we've seen a 22% compound annual growth rate in terms of the number of customers with deals larger than $100,000, and the underlying revenues of those customers has more than doubled. We expect this to only increase with our new solutions. While we haven't finalized pricing of all of our new solutions, we believe that today, for a customer who spends a dollar on VM, the dollar opportunity inclusive of all of our upcoming solutions is more than five times that. The reality is our customers spend thousands of dollars on vulnerability management with us, so the opportunity is multiples of that. The benefit to our customers is greater security in a scalable, cost-effective manner, and to us, additional revenues and stickiness with our customers. Our ability to land and expand is one contributor to why we enjoy industry-leading margins.
Our operational model, whose foundation is an organically developed platform, has significant efficiencies in R&D and sales and marketing. On the sales and marketing front, as Amer discussed, our cloud platform enables prospects to try and buy, generating sales at a lower cost than on-premise software companies. We have a unique sales force based on technical account managers, who we call TAMs at Qualys, who we partner with our new business reps. These TAMs stay with the client post-transaction to provide continuity to the customer. They manage all renewals and upsells, so you can imagine that the incremental cost of additional revenue, Chas, is very little. We get these TAMs from our customer base, and they're successful because they know our market, they know our product, and they know the challenges in deploying different solutions.
They make more money working for us, we benefit because they're less expensive than a traditional enterprise software sales force. Adding to this, our channel partners drive thousands of customers to us without much overhead. These factors create significant sales leverage with our 2015 revenue per sales and marketing head over $1 million as compared to a median of approximately $540,000 for comparable security and SaaS peers. On the R&D front, Qualys has created an extremely efficient architecture. We have one code base, which we use for all of our customer segments, from SMB to the enterprise. We have reusable modules, which easily enables us to add products quickly. Philippe also discussed we have built a large operation in Pune, India, with at the end of Q3, 44% of our R&D customer operations or customer support and operations employees based there.
Philippe also mentioned we actually went in search of great talent, but we happened to find great cost, too, which is a key element of our model. By having a strong operation there, we can innovate 24 by seven, which accelerates our ability to develop solutions for our customers. These drivers are why we've been able to increase margins so significantly. You can see that the company's EBITDA margins increased from 15% in 2012 to 34% in 2015, a 60% compound annual growth rate, and operating cash flow margins from 24% in 2012 to 40% in 2015, a 40% compound annual growth rate. Let me share now a few thoughts on our outlook. We are reaffirming the Q4 2016 and full year 2016 guidance that we provided on our earnings call a few weeks ago.
We have guided to revenues in the range of $51.9 million-$52.9 million for Q4. We currently expect that our year-over-year revenue growth rate in the fourth quarter will be understated by about 50 basis points because the negative impact of FX is expected to outweigh the positive impact from the MSSP contract. Our current deferred revenues are impacted negatively both by FX as well as by the MSSP contract. We expect that impacted our Q4 current deferred revenue growth rate to be between 500 and 600 basis points. Our full year 2016 revenue guidance is in the range of $197.6 million-$198.6 million. Q4 GAAP EPS guidance is in the range of $0.06-$0.08 per diluted share and $0.16-$0.18 for non-GAAP EPS per diluted share. We expect our expenses to sequentially increase in Q4 as we are investing for the rollout of the additional solutions.
Full year GAAP EPS guidance is in the range of $0.41-$0.42 per diluted share and non-GAAP EPS in the range of $0.79-$0.80. Regarding our 2017 outlook, we will provide more specific thoughts on guidance, as we always have, after we report Q4 earnings. Directionally speaking, though, I'd like to highlight that we currently expect our year-over-year revenue growth rate in 2017 to be understated by approximately 300 basis points based on our current FX forecast, as well as from the absence of a one-time bump in revenues in 2016 from the MSSP contract. We're excited about the upcoming solutions, but given our ratable revenue recognition model, we do not expect them to have a material impact on 2017 revenues. We believe that we'll see increasing adoption over the course of the year, leading to an uptick in bookings in the second half.
We see a real opportunity to sustain and even accelerate our revenue growth rate over the next few years, especially given the Trojan horse nature of the Cloud Agent. Let me caution you that the growth may not be linear as the pace of adoption of new solutions is not easily predictable. Given the opportunity we see for these new solutions, 2017 will be another investment year to ensure scale and capacity to support our growth. We anticipate purchasing more servers and storage for the platform, as well as hiring across all functions, although the majority of hiring will be in R&D. In terms of what that means for margins, it's too early to provide direction. We're in the midst of our budgeting process, which we approach with a view towards balancing growth and profitability, and it's also dependent on our 2017 revenue expectations.
It's important that you know that our company philosophy has been to not spend ahead of growth. However, we see a real opportunity to accelerate growth, enhance our leadership model, and expand our margins in the future. We believe continued innovation is the engine that drives greater customer adoption. Rather than present a five-year model, I'd like to underscore our view of the leverage in our operational model by reminding you what Qualys has already achieved. In 2013, Qualys crossed the $100 million revenue mark, and thereafter, the incremental expenses associated with generating incremental revenue significantly declined from 78% to 19% over the next two years. When our new solutions scale, we believe we have the opportunity to see additional margin expansion since our cost associated with additional revenues at scale is rather low.
This is the scalability of our unique platform model and why we enjoy industry-leading margins as compared to both SaaS and security peers. In summary, we believe Qualys is a unique investment opportunity because of our competitive positioning in cloud security, our multiple drivers of revenue growth, and our scalable operational model. By virtue of our integrated platform and its evolving breadth, we believe we can offer our customers greater visibility, security, and compliance at a much lower cost than on-premise solutions. You don't have to just take my word for it. We have Mark Butler here to give you a customer perspective. Mark Butler is Chief Information Security Officer at Fiserv. Mark has over 25 years of technology experience managing enterprise information security functions, delivering security consulting services, and enabling security solutions at a number of companies, including Fiserv, H&R Block, IOActive, and Depth Security.
As a CISO, Mark focuses on establishing the right financial investment to provide the needed visibility to take risk-informed actions to protect the business. Mark supports and actively partners with executive management, IT, risk, business leadership, and legal counsel to provide security visibility into ongoing and new business opportunities. Here's Mark.
All right. Thank you so much. Everybody hear me? All right. Thank you. I'm going to give you a little bit of history. If you've been around the security industry, if you've been involved in the security industry, if you're obviously looking at investing in the security industry, the security industry is obviously the best place to be for lots of different reasons. The historical approach that most enterprises, most environments have taken have been go choose the best product you can find for a particular purpose and choose that one. Right? There's been this best of breed strategy to choose the best product for the best point solution and deploy it, and there's been a heavy investment over time in best of breed products, point solutions. Let's go find the best product for a particular use case, a particular opportunity.
There's been a defense in depth design, defense in depth architectures. The defense in depth concept is if an attacker gets through one layer, they will likely not get through a second or a third or a fourth or a fifth, et cetera. Defense in depth has been the architectural design paradigm. The marketing engines and the product teams, et cetera, in the security industry want you to think that their product is as close to the silver bullet as possible, they are the one solution that you need and the one solution that you must have. There's been a blend of people, process, technology to pull off investments, capabilities, solutions, in a particular environment to deal with the risks of that environment.
This is all historical approaches of companies, enterprises looking at how do we deal with information security, how do we deal with our risks, how do we manage our environment, right? These are all the historical approaches. Where has this approach taken us, what was the outcome of this approach? There's been too many best-of-breed solutions, too many by the fact that we've had very high quality, we've had very focused and very targeted solutions to meet a very particular use case. While they may meet that use case and may meet that requirement, they're not integrated, the integration story is very important. Fiserv has 36 security vendors, that could be 50 plus if we hadn't have managed it proactively.
When you look at the number of security vendors we have, the number of security solutions we have, the scale, the complexity, the data management, the work that a security analyst has to do to figure out what is going on in our environment across network, endpoint, identity management, analyzing traffic, looking at threats, et cetera, is a daunting task. From a management structure and a vision and a strategy standpoint, the integration piece is a byproduct. The lack of integration is a byproduct of these best-of-breed solutions that are not talking to each other. They're not integrated on the back end, the data isn't converged. That's a big point here. No silver bullet solution actually does exist. That's something that marketing engines like you to try to reach and attain, there is not one master solution for every particular use case.
We have disparate people, process, and technology integration. This is the result of the historical approach that enterprises have taken, that the information security marketplace has kind of modeled their products and selling around. This is a reality that every enterprise deals with. What I'm seeing in the security industry landscape is there's more and more specialized vendors coming out, popping up, being established, there's reasons there's very specific niche vendors. There's a reason that they're created, there's a reason that they're invested in, there's a reason that they're putting a niche product out there is because there is a need for it. There's a lack of orchestration. There's a lack of integration across the solutions. The data is the most important element of any solution. The data represents identities. The data represents assets. The data represents traffic.
The data represents a potential valid transaction or a potential breach. The data integration on the back end is a huge piece that most organizations underestimate until they try to deal with the volume of data, they try to deal with the analyst view of the data, and they try to take timely responses and timely action based on that data. What you'll see in the industry, and Qualys is a great example of this, of heavy investment in integration, heavy investment in APIs, heavy investment in the ability for the solutions to talk not only to other components of Qualys' solution, but outside, right? When Qualys talks to ServiceNow for ticketing or Qualys can pull in additional threat feeds from additional vendors, right?
That integration piece is critical because every time there's an integration, there's one less manual step that a human analyst or person has to do and possibly could miss something from a process standpoint. A little bit about Fiserv. Fiserv processes transactions. We provide solutions to financial services industry, regional banks, large banks, credit unions, broker-dealers, et cetera. From a Qualys standpoint, we do not have the biggest environment out there, but we do have a substantial environment. We scan about 200,000 IPs. That's production assets, certification environment assets, any type of assets that deal with transaction, money movement, settlement, ACH, person to person, et cetera. We have 140 on-premise scanners. That's a large footprint. We have 42 data centers. We will be getting that down to a single-digit number of data centers over time. From a footprint standpoint, that's what we have.
The way we cover our environment is we scan an entire network range. Whatever assets are on that range, we scan the range. If one day there's 100 web servers and the next day there's 150, it doesn't matter. We cover them all. We use authentication as well to make sure that we're logging into the box, we're getting authenticated traffic back from the host, and we're getting additional quality of data from a vulnerability standpoint. We file 42 PCI reports on compliance. If you're familiar with the PCI ROC, we file 42 of those annually. That's a huge effort. Qualys is a great foundational piece for us to not only say, what kind of vulnerabilities do we have? What are the highest risk vulnerabilities? What business unit do those assets belong to? Which PCI ROC do they relate to? Where's my last quarterly scan?
Have I addressed issues out of my last quarterly scan? Is that scan attested? Right? There's a huge support ecosystem that Qualys provides to us just related to our PCI ROC filings. This third bullet item, private cloud. Fiserv is a service provider to financial institutions. We leverage the public cloud for very specific use cases from a corporate standpoint. We do not leverage the public cloud for transactional environments. We build our own private cloud for that. This is something we're working with Qualys on heavily is the paradigm of a highly virtualized data center is a dramatically different operating environment than a traditional data center. The new generation of data centers are fully virtualized from the network all the way up to the applications, and there's a different way to look at vulnerabilities.
There's a different way to look at assets, hosts, virtual machines, traffic management, et cetera. This is what is typically a greenfield opportunity from a build-out standpoint. It's a different way to look at risks. It's a different way to look at traffic analysis. It's a different way to look at host-level scanning vulnerabilities, et cetera. This is actually a very exciting area. It's something that we will continue to heavily invest in. The opportunity is the traditional approach of putting all of your controls, all of your agents, all of your configuration monitoring on a server, which relates to a physical asset, all of that's virtualized.
There's going to be efficiency gains based on how we look at that traffic, how we analyze it, how we risk vet it from a container, a compartment, et cetera, standpoint, which is a group of elastic services which are running within a defined set of boundaries. From an investment standpoint, we use policy compliance, we use vulnerability scanning. We're going to be piloting the file integrity monitoring product, which is coming out. We've deployed the agent, we are very excited about the ThreatPROTECT capability. ThreatPROTECT allows you to say, okay, if I have 100,000 vulnerabilities in my environment, these are the 10 that I really care about. Go take care of these 10, then we'll figure out what the next 10 is.
There's a huge fatigue factor in vulnerability scanning, vulnerability reporting, vulnerability routing of all those tickets, all that work stream, all the downstream work efforts, how do you prioritize what should you really care about and what do you have to fix? ThreatPROTECT is something that we looked at internally to say, how could we do a custom scoring model? We figured out that we could build a custom scoring model, we would have to defend it to auditors, we would have to maintain it, we would have to tweak it, we'd have to adjust it, et cetera. What ThreatPROTECT gives us is an industry-referenced model to say, are these vulnerabilities easily exploitable? Are they remotely accessible? Are there active exploits occurring, right? It gives us that third-party, external, objective view to help us prioritize the 10 vulnerabilities versus the 100,000.
Fiserv's security strategy. If I go talk to a business leader, I'm going to say, I want to obviously optimize my spend. That's a given, right? My financial investment needs to make sense. It needs to be justified. It needs to be the least amount for the given capability I'm trying to realize. Risk visibility is a key priority. Then data analytics. If you look on the left, you'll see goals, on the right, you'll see outcomes. Obviously we want to realize value from our investments. We want to prevent risks. In the security industry, you'll see a lot of pendulum swings between detect, respond, prevent, right? Prevent what you can. If you can't prevent it, detect it. If you detect it, respond as quickly as possible. Then there's the simplification of our environment.
With 36+ security vendors, we're trying to get down to a manageable number, which reduces the number of vendors we manage, reduce the number of interactions we have to do from a supplier risk assessment standpoint. We want to collapse our data sets on the back end. We want to integrate with our SIEM solutions, with Splunk, with Palo Alto Networks. With pick another vendor, right? The integration strategy, the integration story is huge because every single vendor we have has a different portal, a different management dashboard, a different report engine, et cetera. These are our high-level security strategy goals and outcomes. From a business standpoint, what I get asked about on a regular basis is, are we spending money in the right areas? Are we spending money in the right way? Are we addressing our risks from an adequacy standpoint?
What we've done is we've looked at 11 core domains, and there's different ways to look at this. You can have 5 domains, 20 domains, et cetera. We chose 11. What it gives us is a model to say, okay, let's say somebody in a business unit wants Tanium, for example. Okay, well, why do I want Tanium? I want visibility. Well, why do you want visibility? Because I need to manage my assets. Okay, that's a great use case. How else can we do that? Do we already have an existing vendor that does that? Do we already have an existing relationship with a vendor that does that? Does Tanium give us anything unique that will close a gap that will justify the investment? All right. This whole model is not to put a governance structure in place that stops anything.
It's to put a governance structure in place that aligns the investment to close a real gap that's documented, noted, and we need to prioritize it. This is a spider chart. You'll see the 11 areas of focus here. You'll see all kinds of topics here, right? You'll see physical security, you'll see identity, you'll see network, you'll see analytics, et cetera. But this is a way for us to demonstrate where are we at, where are we going, what kind of investment is it going to take to get us from a maturity level of 3 to a maturity level of 3.5? Then how are we going to align this against vendor investments and vendor capabilities that will help us realize our goals? All of this relates to the visibility, maturity from an analytics standpoint, and then optimizing spend.
This is something that's been very helpful with our management to say, we have an industry-recognized framework. We can map all of these areas to a set of controls on the back end, which are NIST related. If anybody wants to get into details, there's a whole spreadsheet behind this, and we can say, where are our gaps, what are the most important priorities to mature, then what vendors can we use to help us get there? We're on a journey just like everybody else. We've assessed ourselves against these 11 core domains. We're aligning our vendor relationships with who can help us simplify, who can help us collapse, who can help us get better data visibility, risk visibility, and take timely actions.
One of the exciting things about Qualys' direction, Qualys' product roadmap, we're not pushing our vendor, in this case, Qualys, to kind of see the light at the end of the tunnel. They're actually ebbing and flowing, right, with us to say, we're building out ThreatPROTECT, and we were doing something internally similar, right? They're building out agent views. We were looking at other agents to accomplish the same things, right? There's this ecosystem of Qualys pushing the envelope, us seeing that need, looking at alternatives at the same time, and being able to come together and blend our investments, our projects, our portfolio initiatives with their product roadmaps. We don't have to duplicate efforts, and we don't have to spend time creating something that's already on their roadmap. All right. I will be glad to take questions, and we can go from there.
Yeah, I think we're going to break.
Yeah. We try to follow the slide.
Yeah.
Okay. Thank you.
There's a change in schedule slightly. We're just going to break straight to Q&A right now.
There you go. I think the room is for. Come on. Come on.
Just for the webinar? Thanks. Mark, thanks for coming. Can I ask about the process you went through in evaluating the agent? What was it that you liked about it? How are you deploying it? When do you scan? When do you use the agent? Have you thought about it for endpoint VM?
Right. That's a good question. There's a heavy focus on endpoint detection and response, right, from an industry standpoint. We actually use an agent called Carbon Black for incident response. Right? For isolation, for investigation, for forensic type of activity. Where we're using the Qualys agent is to get the visibility that we need that we can't get from the network. Right? It's to complement the network view of ports, services, and protocols, getting the actual host configuration, the actual settings that are configured on the host, and blending those two worlds together so we can complete that risk posture. That's where we're focused. We're focused on externally facing servers that have web services, APIs, externally supporting transaction services.
That is our initial deployment of the agents. Then we will expand them into the back end of the infrastructure based on security zones and monitoring, if that helps. Does that answer your question?
Yes.
Hi, Sterling Auty from JPMorgan. With the number of new products that you are going to be phasing in, not only here at the end of 2016 but into 2017, talk to us about the back end architecture, the capacity that you have. Is there incremental spend that is going to be necessary to handle the increased compute loads? Does it change the way that you either store data points that are coming in, and does that have any impact on capacity as well?
Yeah, that is a very good question. There is an inherent advantage built into the bigger platform, single platform, where we are organically bringing all this information together. Depending on the solution, for example, like I said, ThreatPROTECT was something that did not require any additional storage or any additional investment from being able to bring that with just a few developers. We were able to bring that very quickly. If you look at solutions like file integrity monitoring or indicator of compromise detection, those will require additional investment, a little bit of additional investment from us in terms of the storage requirements, because it does generate a larger number of events.
However, at the end of the day, the event generator file integrity or for indicator of compromise are very similar events. We get that advantage of actually not having to duplicate and store those events separately as other individual solutions might have to. There is an inherent advantage built into being able to have that on a single platform. Because a lot of the common modules that are required for these solutions are already present on the platform, the amount of resources we need from a development perspective are not that much. Typically, we would have anywhere between 10-15 developers QA required to add an additional solution like file integrity monitoring to bring that onto the platform.
Where's Victoria? She went to the bathroom.
Oh, thank you very much. Steve Ashley, Robert W. Baird. My question is around hiring. You're about to roll out a whole bunch of products in the coming year, we've talked about maybe seeing some accelerated growth over an extended period of time. With that comes the need to add, I think we've talked about in the past, some challenges in terms of bringing on sales reps, especially the hunters. How do you view that going forward, and how do you see being able to meet that need?
Yes, I guess, in term of the hunters, as most of you know by now, our sales force is divided into two teams, the hunters and the farmers.
Use that mic.
In terms of the farmers, which essentially are responsible for renewal and upsell, I think we've really found a good formula. We hire them from our customers. Of course, we cherry-pick then those that we believe are the most interested and really capable. That's a very good success for us. In terms of the hunters, when we have done that, we have slightly changed our model, whereby we're now looking at people who may be less technical, but technical enough, because the key in the traditional enterprise sales model becomes the farmer. The way we engage a new customer today is to say, "Okay," we knock on the door, of course, and then we explain our value proposition, and then we try to drive them to a proof of concept. The way we sell is try and buy, essentially.
Now today, that proof of concept is not going to be done by the hunter, but it's going to be done, this is when the farmer brings. The big advantage for the customer is that he sees immediately the person who is going to be the one who's going to take care of him if, or her, if, of course, they selected us. That now allows us much more flexibility in terms of hiring these hunters, because in the past, we were looking more at people who could also do the POC, that was restricting our ability to hire hunters. I'm very confident we're now today looking at expanding essentially our hunter sales force, rather than the farmers, which I think we're pretty well-equipped at the moment, especially as we leverage more and more the partners as well. Okay, does that answer your questions?
Go ahead, Craig.
Craig Nankervis from First Analysis. For Mark, I wonder if you could just help us think about consolidation and how you weigh the quality of security you think you're going to get from one vendor delivering 10 or 15 solutions.
How do you weigh that versus just the whole traditional best of breed approach that you talked about? How do you get comfort that what you're consolidating to is going to meet what you need for regulatory and internal requirements for-
Yeah. Every time we talk to one of our clients, they're obviously the biggest financial institutions in the U.S. If we come to them and say, "Hey, here's our security stack, and here's our list of vendors," they've never heard of it, and they've never heard of one of those vendors, they're going to ask questions. There's an industry reputable piece of it. There's a vendor supplier risk assessment process, there's financial vetting, there's legal vetting, there's contracts, et cetera. There's an annual process that we go through to say, is somebody at risk of being acquired? Is somebody not performing? From a services delivery, performance, et cetera, standpoint, we have a very rigorous vendor and supplier risk assessment program.
To answer your question, if we put all of our eggs in the Cisco basket, for example, or all of our eggs in the Palo Alto basket, or all of our eggs in some other basket, there's risk associated with that. What we have to have is confidence from a roadmap standpoint, from a vendor performance, et cetera, and there's no ultimate guarantees 5 years from now. It is an active process. You cannot sign up, install the agent, turn it on, and assume everything's good. You have to have an active management program with the vendor, lockstep with them, and that's something that a lot of enterprises, they kick off a project, they implement a tool, and then they assume the operational pieces are going to be solid enough to address any issues that may bubble up.
A lot of times, the operational transition and turnover needs to be improved to allow quick visibility to maybe an agent that's not performing as it should, or it's consuming too many resources, or it's doing some behavior that it's not supposed to. There's not an easy answer to your question, it's a combination of active management, good operational turnover, healthy monitoring, then making sure there's a stakeholder that's looking at what are we getting from this vendor? Where's this vendor going? Where are we going, and what's that synergy look like? If there's too disparate of a trajectory, that's opportunity to reevaluate.
That's a very important question that you raised, and I would like to add a few comments, and Mark, if you want to come in after mine. Security, one of the reasons why we started with best of breed is because security, at the end of the day, the enemy of security is falsehoods default negative. It's like an X-ray. If you go to get an MRI, you want to have the quality of the images so you could have a proper diagnostic. Same thing in security. In the past, the companies were naturally looking, you cannot have too many vendors. It's just not practical. They were looking at vendor consolidation, and this is why we saw that binge of the larger companies, Symantec, the Cisco, et cetera, acquiring best of breed solutions.
The reason why that strategy failed is because of the architecture of those solutions, which are enterprise software solutions. The problem with enterprise solutions is that they all require their own console, their own platform, their own specialist. Having one single vendor trying to integrate all that together didn't really work. In fact, you had Symantec and McAfee. That's what they did. McAfee did a pretty good try, very hard from a technical standpoint, through ePO, to try to consolidate all of that, but still it didn't really work. Symantec went the easy way. They just put that, as I used to say, yellow around and say it's all integrated. What we believed when we started the company in 1999, is that the cloud architecture was the solution to that answer. Why?
You can put naturally the data into one place, then, of course, it's all about acquiring the data. Then you put the data into one place, and then from there, it becomes very practical to give the security, the compliance, the IT view, all these different view of the same data. That's what allows us all this, it took us significantly longer than I ever thought, that you saw in the demonstration that Sumedh gave us today, that ability to see everything there. Why? Already the data is all in the backend. That's what really allows us to essentially consolidate, answer the question now today our customers have. It's not so much about vendor consolidation. It's about, and I think this is what Mark was saying in his presentation, it's about the stack consolidation.
We cannot have all these different solutions, then we, customers, being responsible for that integration of all these different pieces, even these vendors like Symantec and McAfee could not really succeed. How will a company succeed? This is where I believe we have reached now a point where this cloud architecture now are being the fundamental element to that consolidation of the cybersecurity, which is much needed. Do you have anything to add, Mark?
Yeah. You have to have more than one vendor, and you can't have 100. There's the sweet spot. The consolidation play that a lot of larger vendors have gone down of, I will just acquire, we've seen it time and time again. What do they do with the acquisition? Do they just maintain it, get revenues off of it from a maintenance standpoint, and not continue to innovate? Right, what are we stuck with? There's a critical piece of why are you acquiring? What are you going to do with that product? How's the integration story within that vendor?
Also, there's a sweet spot from probably a size standpoint of motivated, innovative teams and building something that has not been done before versus acquiring just to acquire and say, "We have that in the stable, but we're not going to do anything with it.
There you go. Go ahead.
Thanks. Bill Choi at Wunderlich. Question for Melissa. I appreciate the additional details you're giving out here on two slides, in particular, the newer solution adoption by customers so far. You see very healthy Cloud Agent for VM and incremental Cloud Agent for policy compliance. When you look two pages later, or actually maybe a couple more, page 75, you show what you think your potential customer spend will be, the bucket for Cloud Agent for the policy compliance is quite big and much bigger than even the Cloud Agent for the VM portion of the business. I just want to get a little bit understanding of what you're thinking there, what's driving that, and how people choose a Cloud Agent for the two different pieces today. For Mark, just a little clarification on what you said on your use of agents.
You mentioned using agents for the external-facing servers, which is for the VM component, then you talked about file integrity monitoring. Was the file integrity monitoring, where are you deploying that, laptops, servers? Is that what you're looking at to replace Carbon Black? Thanks.
Sure.
Yeah. I can quickly answer the first question. The delta is going to be the fact that policy compliance is already priced at a premium to vulnerability management. As I'd mentioned, we price for traditional deployments or Cloud Agents a 20% premium to the underlying subscription. Because you're adding a 20% uplift to already a higher price subscription, that's going to result in a higher dollar opportunity than the vulnerability management Cloud Agent.
Yeah.
There's another element-
Yeah
which is the fact that one of what has been limiting our growth, fundamentally, of the policy compliance is the fact that the need to do authentication, to get the credentials and all of that, which for many companies is really painful as well as the endpoint. We could not really go at all to the endpoint. This is where essentially you see the Symantecs use, et cetera. Where we see that there's much more opportunity to help us grow, if you prefer, essentially the policy compliance solution that we have, thanks to the agents.
Yeah. The bucket, by the way, is like six times bigger for the policy compliance than for VM on the cloud. That's huge numbers. Is that what you're seeing? Well, obviously, you're not seeing that with your customer update now. When does that happen?
Well, as I said, look, we see the opportunity to sustain our growth rate and accelerate it over the next few years, but it's early in terms of deployments. Ultimately, the pace of adoption of new solutions is not easily predictable.
To answer your question on the agents. The agent deployments that we're doing right now are for visibility. They're not for incident response. All right? Our Carbon Black footprint is on our corporate space, so our corporate endpoints, laptops, desktops, et cetera. The Qualys universe for us is in the commercial space. We're not trying to replace Carbon Black with the Qualys agent. We're deploying the Qualys agent in the commercial space to get that visibility that we need on the externally facing services that we didn't have before, and we're trying to reduce the agent footprint of other vendors by deploying the Qualys agent. We can do patching, we can do local scanning, et cetera, and get better visibility, if that makes sense.
To add also, if you look, our agent will, of course, enable us to move into the incident response world as well. This is more in the 2018 timeframe, where now suddenly we can do, of course, naturally, once you have an agent, that's why you can do incident response. Without an agent, it's very difficult.
One of the things we did internally, we have to go through a justification process to get an agent approved to be deployed. There's a threshold that we have to meet that says, "Okay, well, why do we need an agent? How much memory does it consume? What's the consumption of resources on the system? Do the systems have the bandwidth?" There's all these things because we have multiple agents running for antivirus, for asset management, for file integrity monitoring, et cetera. We can't just add an agent just because we want to. We have to add an agent because we get capability that we don't have, and we're simplifying and we're consolidating our stacks. Those were the requirements that we had.
To that point, we're very proud of having had such a big adoption of our agent, $1.3 million agent. Nobody would have believed that we could achieve that in such a short period of time, which speaks very well to the quality of our agent.
Bandwidth
bandwidth. They have very little CPU consumption. The architecture of these agents is really the big differentiator. Again, they now are enabling a lot of new services.
Just adding to that, as I mentioned as well, these are our ratable revenue recognition model.
see material impacts and new solutions to 2017 revenue, and that our growth may not be linear as well.
Okay. I'm here for Sri. It's Summit Redstone. I have two questions. One's for Mark, one for Amer. The deeper question is for Mark. Enjoyed your presentation. Just curious, you talk about how you like Qualys because of their integration, how they talk, the various groups talk, APIs. You're also talking with the other vendors, and as they buy that specific solution, a point solution into their kinds of integration. Can you give a couple examples of vendors who are trying to integrate things like that? I guess, can you characterize more in terms of the technology lead that Qualys has with their products? For me, the other vendors, they could start putting their data on the cloud and try to get it more of an integration, too. How much of a lead do you think Qualys has in terms of timing relative to competitors you talk about?
The other question, maybe more of a question for Amer, is you talked about the trials for the product rollouts. Just curious what the conversion rates have been from trials to premium. Thank you.
Yeah. The answer to the first question, Qualys has been leading, I think, in general. Right? Full disclosure, we have Tripwire. We've had Tripwire for years. They've not innovated their product. Their product is basically the same as it was five, seven, eight years ago. Right? We have a project on the books to convert from Tripwire to Qualys. We've already used their policy compliance tool. We will test out their FIM tool. We expect to get cost savings, and vendor consolidation, and better data management on the back end with ServiceNow integration, et cetera. That's a good example of we've had Tripwire for a compliance checkbox, but we've not had Tripwire from a security, risk, analytics, and response standpoint. It's literally been a compliance tool. We want tools that are not just compliance tools. We want tools that are risk analytics tools.
That's why we're moving the direction we are. I would say Qualys has been leading and continues to lead based on what I've seen, and there's a lot of vendors out there that are hanging their hat on technology that's 10, 12, 15 years old, and they're not continuing to innovate where they need to.
The reason I would add is that it's a very difficult point to apply vendors, and you saw that with Siebel with their versus Salesforce. You cannot really feel your architectures or all about the architectures. You have to re-architect your solution totally to have a cloud-based solution. That's a huge undertaking because not only it takes a lot of money and time, but also you need to have the domain expertise in your company. That's why we never saw of all the mainframe company, how many of the mainframe company became client server company? None. They all disappeared. IBM, which changed their business model. The same thing is happening here. There's nothing new here.
On the lead side, we typically, on a quarterly basis, we see conversion from overall number of leads to trials. It's approximately 10%, but those that convert to trials, we see over 25% conversion to customers. Our focus is take the lead to trial. We do all kind of nurturing campaigns and syndication and education to the industry. We convert the leads to trials because then we can engage with the customer. A TAM is talking to them on the phone or in person. They have a trial, and then from there it goes. Our sales cycle varies specifically on the SMB side from 60 days to 90 days, and on the enterprise it can go up to basically 6 months.
On the trial also, what we try to do and like, if you prefer, what your typical enterprise software solution do, is that we try to really have our customers doing the full trial. Just try it completely. Just not do a small POC. We don't charge you for it, but try as big as you like. The reason is because, of course, the inherent scalability that we have, this is our huge differentiator against this enterprise software solution, where you need to go and install the software, et cetera. With us, essentially, it deploys. If you do a trial on your internet-facing devices, you have absolutely nothing to install. Now, if you want to do the full trial with our agents or with our scanner appliances, you have to install them, but we FedEx the appliance to you. Two days later, they arrive.
Five minutes later, they're installed, and from that point of view, you don't touch them anymore. They are self-updating, centrally managed. Same thing with our agent. You push them, that's it. They're installed, and then you don't touch them anymore. That's a big advantage that we have, and that's where our model is really try and buy, and which of course, is very effective on the sales process.
I'd like to add a little bit about, you said they can move to the cloud, and as Philippe said, they have to re-architect it. It's not just going to be take the VM and put it in the cloud. A lot of these solutions that we talked about, Tripwire or Symantec ESM, they were built to say one console supports five, six, seven, 10,000 agents at the max. If you were to move that into the cloud, all you're doing is basically hosting 10 different consoles in AWS. To actually re-architect that, they are going to have to actually go back and say, "We need to leverage CloudGuard, new technology. We need to leverage Elasticsearch," which is basically redoing the entire back end if you really want to make it elastic and scalable. That's going to be the difference.
While just moving the VM is just going to be easy, it just really doesn't give any advantage except not having to host it.
Just one question?
Yeah, I'll go ahead. Erik Suppiger of JMP. A question for Mark. You had mentioned the vendor, Tanium. I'm curious if you've evaluated them, if you have any thoughts how they might compare to what Qualys is talking about. Secondly, as you consolidate more functions into that Qualys deployment, what multiple of spend will that generate per endpoint that you're looking at? How much of a markup does that create for Qualys? More broadly across Qualys management, how can we gauge the success of your new products over 2017? Are there any particular products that we should be looking for in terms of a quicker ramp than others? I think you said that the revenues may not be too material. One of the metrics has been the Cloud Agent deployments, that's been a big help, what else can we monitor to gauge your success?
Yeah. I'll start with Tanium. Tanium obviously has gotten a lot of press lately, and they're very successful. What we were looking at Tanium for was, can we get real-time visibility to a configuration status on all of our endpoints? Real-time security and compliance monitoring. Does every one of our endpoints have disk encryption, antivirus, DLP agents, Carbon Black agents, software deployment agents, et cetera? Our use case for Tanium. We have not purchased Tanium. We've just continued to evaluate it. I'll tell you why we haven't chosen it yet, or haven't chosen it. We looked at Tanium as, can you help us displace one of our existing technologies? Tanium could not do that. They could augment and enhance visibility on top of our existing footprint of agents and software, they could not displace.
One of our requirements is, if we can't simplify. We can't get better visibility. We can't optimize spend, we're not investing in it no matter how good it is. Tanium really has a creative architecture from a peer-to-peer communication standpoint. The use cases that we gave Tanium, they couldn't solve. An unmanaged endpoint or a client connecting into our network that is not a Fiserv asset, those were our two primary use cases we gave Tanium. They were not able to solve those for us based on their architecture. They can give us visibility we don't have. They can give us real-time status. We have not chosen them just based on the evaluation of what the use cases are that we gave them. If that makes sense.
Is that something Qualys could do then?
I think so.
More, and more.
So as we-
I believe so.
Some of the things that he was talking about, as I showed in the demo, is the real-time visibility across the assets and asking all my assets, what do they have? Do they have this agent? Which is basically saying, do they have this service running? Do they have Carbon Black service running? All of that visibility out of the agents that we already have, we provide them that out-of-the-box.
For us, the most interesting conversation we had with Tanium was not only can you give me real-time compliance monitoring of all my security controls, can you autocorrect all of them in real time? Based on our use cases, we've obviously not selected them.
Which is the piece that Sumedh will have to build.
Right. The second part-
We can build, but again, it's going to take us some time.
The second part, he talked about the unmanaged endpoint. That's exactly what the passive scanning actually addresses, is giving that visibility into saying, "We don't know what this is, but it's connecting, it's there, and this is what it is doing." We bring that into the platform, and then you give the ability to say, "Can I then use this to maybe push an agent or do a deeper scan," turning around and doing that. That combination of agent-based, agentless active scanning, and passive scanning will give that visibility exactly the way he's looking for.
I'll handle the second question. We will continue to give color on how our new products are doing. In addition to the Cloud Agent we've talked about throughout Protect this last quarter. We've added new metrics, such as the % of enterprise customers purchasing more than three products. We would expect you to see that as an indicator of progress with the new solutions. We'll continue to share information like deal sizes and probably add some of the new metrics that we shared today, if they make sense on a quarterly basis, like number of customers with average spend over $100,000.
To answer your specific question about what our anticipated spend is versus our current spend, we're looking at two and a half to three times.
Okay.
Yeah.
Sterling Auty from JPMorgan again. Two questions. The first one is, if I think about Qualys as a 20%+ grower into the future, what does vulnerability management, broadly speaking, in terms of all the products that are vulnerability management, need to continue to do? Obviously, you've shown the chart here, good consistency for the last couple of years, [19%-20% ] [audio distortion]. Does that need to continue at that level to have the overall business grow at 20%+, and what drives that? Is it going to be further penetration into the existing customers, or is it going to be further new customers coming onto the platform?
Yeah. I think there's actually a number of scenarios in which we could see the mix shift. I think you could see some of the other solutions outpace Accelerate their growth such that you see slower on the vulnerability management. We could also easily see vulnerability management staying 20%. That's because, as I pointed out, these additional new solutions that we've rolled out that are in the family of vulnerability management, Continuous Monitoring, ThreatPROTECT, and the Cloud Agent. In terms of what's sustaining the growth, it's these added solutions that are part of related to vulnerability management. ThreatPROTECT allowing you to prioritize the actual vulnerabilities, that's an easy upsell for someone, the Cloud Agent.
In terms of momentum, we see a lot of opportunities still with existing customers because as I'd mentioned, even with existing customers, we're not fully penetrated in terms of the number of IPs that could be scanned. We also see, if we see significant adoption of ThreatPROTECT and the Cloud Agent, that'll drive revenues significantly higher on vulnerability management, recognizing the ratable revenue recognition.
Yeah. I will add, one thing also, if you just look at the broad numbers, one, we have 62% of the Fortune 50 as customers and about 24% of the full Forbes Global 2000. One, we are under-penetrated still, or not fully penetrated in the large enterprises, still significant sales within all of our large customers on the VM side still, because they're not fully deployed. Also, if you look at the broader market, we have a huge still opportunity to continue with VM. We believe that the PCPA, which is that one new appliance, is significant in countries like in Asia, like in countries where they are not really.
Middle East
In the Middle East, where they are not totally cloud-centric yet. We see still a huge expansion of our VM, albeit it's now starting to be at a pretty good base. It's only 24% of the market, that's a global market at the end, still. There's still room to grow. Adding more and more solution or integrated, of course, absolutely will accelerate our displacement capabilities.
Just one follow-up. You showed the penetration, 29% for web application scanning, 8% for policy configurator. For the products that are not kind of VM helper or VM expansion, some of the other areas, what is it in the new products that hopefully will drive the kind of penetration you saw with web application scanning versus the lower penetration on some others?
What we see today, for example, the file integrity monitoring is a no-brainer. It's a no-brainer, why? Because we absolutely eliminate significant cost. The cost today, it's not that the, for example, the third-party solution is not a good solution. It is a good solution, but you have to update all the agents on all the different version of Windows. You have to have hundreds of servers to manage all of that. We eliminate significant cost. Same thing on the policy compliance as well. That we see FIM as a significant, as really something which will be a driver. We also believe our detection of indication of compromise because of the very unique way that we do, again, it's very straightforward. You saw that on the presentation of Sumedh.
Not only we can do like everybody else, get the hash, but we have also that notion of family, and also we have the ability to provide you with the suspicious devices that you want to investigate as well. This is quite unique and all of that, again, is already available in the platform. You just have to deploy the agent. That's all that you got to do. You do that, and deploying agents today is very easy. We see a lot of these new services, picking up speed relatively quickly. Of course, as Melissa said, it takes some time to start to bring that to the revenue. Certainly, on the booking side, we will see that.
I have a question. Okay. Yes. Steven Kasch with Stephens. It's probably for Sumedh or Amer Deeba. I guess I'm interested in Qualys' place in competing platforms like, or maybe not competing platforms, but a SIEM or CMDB. I still think it's early in the game, but just generally, what's the competitive landscape look like there, with regards to maybe your VM solution inside the SIEM or something like that? What's the pricing monetization strategy for that longer term? Also, do you think this could be a material growth driver for Qualys? Maybe not in 2017, but 2018, 2019, 2020.
Yeah. Very good questions. On the CMDB side, the biggest issue CMDB have is the information being up to date inside the CMDB, and there is no good way that people today have in doing that. With our agents collecting information for the CMDB to be able to know exactly what's installed, what's on it, and taking that real time is what is feeding and making those CMDBs really much more effective by having that information synchronized. If you take the example of ServiceNow with what we did, we actually built a connector that is synchronizing the information that our agents are collecting into the CMDB for ServiceNow, making that CMDB significantly better in terms of the visibility that it's providing. For us, we charge for that connector in ServiceNow. Getting that Qualys information fed and synchronized into ServiceNow is what we are focusing.
Today we don't compete directly with the CMDB because we don't focus on the capabilities around the management that come with the CMDB. The core of the CMDB, which is the data that's in there, is something that we are the ones that are keeping that up to date, and that's what we are actually feeding into. Today we see uptake on that. We see our customers leveraging the APIs to update their CMDB. From a revenue perspective, I don't really see that by itself today, but it is certainly a driver. The fact that as people realize that this agent is also not only is it going to give me vulnerability management and compliance, it's also going to help my CMDB be up to date.
That's going to drive even more the consolidation for them from a agent perspective to not to have to have another inventory agent additionally deployed on their systems.
To add on, Sumedh, also on the SIEM side, the biggest piece that's missing is the asset data in all the SIEMs, and they come to us for that information. With QRadar, with Splunk now, we're building these native apps, not just to bring vulnerability data, but the most important component is the asset data, which everything evolves around that. We become the source of truth for all these assets, and we keep it up to date, and we bring all the other data around it from the platform, which makes the SIEM better correlation, better analysis, better reporting for the customer. We're trying wherever we can to get native in all of these SIEMs, so we just become part of the SIEM, a very important component.
We're also reducing from the SIEM perspective, instead of the way the SIEMs are being deployed today, they're collecting a lot of raw data information, putting into the SIEM that increases the cost and the complexity of the SIEM. With the Qualys solution, providing a lot of this correlation out of the box already in our platform, the information that needs to be synchronized into the SIEM now is much less and much more high value, high accuracy information that needs to go in, which really reduces that.
For example, if we take Splunk, taking every single vulnerability detection and every time that we detect it and putting in the Splunk is significantly higher amount of data that customers have to pay for to index that versus now taking a feed directly from ThreatPROTECT that says, "Okay, this is exactly the assets that actually have vulnerabilities that may be exploitable out there," is a much smaller percentage, and thus they can actually reduce the data that they need for correlation to get better results.
Melissa, it was helpful how you can lay it out, you quantified the three-point headwind to revenue growth from the end of the MSSP extra revenue and FX. Can you help us think about what that means from an EBITDA perspective? Was there much cost that was tied to the MSSP revenue this year? Is there much cost that comes out because of the FX move? Is it more like a 10-point headwind to EBITDA, as we think about next year?
There's no extra cost associated with the MSSP contract. Yeah, it sort of flows through as you take it out, at the end of the day, it's going to be pretty immaterial. Again, we haven't guided to margins next year for you yet, it'll depend on kind of the overall picture based on revenues and costs.
Okay, we'll take two additional questions for the webcast portion.
Yeah, the effect plays both ways. In other words, it hits the top line, on the expense side, it's positive as well.
Yeah.
In terms of EBITDA contribution, it's about to wash.
Okay.
Right.
Hi, Jack Andrews with D.A. Davidson. Philippe, seemed to me one of the key themes coming out of your user conference last month was this whole improving your messaging and improving communication at all levels of your organization. I was just wondering if you could talk a little bit about the specific tactics, maybe on the sales and marketing side, that you're going to be employing around that, and specifically as it relates to, I guess, improving your messaging at the C-level executive function.
Essentially, you saw that, in fact, I hope you saw that in my presentation already. We talked about today, I can give you the value proposition of Qualys in one slide, which is that two-second visibility, the ability to synchronize, of course, the visibility on your asset and synchronize with CMDB, providing you the continuous view of your technical and compliance posture, and the indication of compromises, and of course, reducing your spend. Essentially, our effort today in terms of messaging, et cetera, is focused around RSA, which is now coming pretty fast, which is essentially in the, I think it's-
Second week of February.
Yeah, the second week of February, where we are going to see all these demos. You are going to see all that live, et cetera. The product will be these new services. Probably will be already quite a few of them in beta. This is where we're essentially showing, if you prefer, that new image of Qualys, that consolidator, if you prefer. That's one thing. The second thing is that we're really gearing up to bring that messaging to the CIO, as I was mentioning to you earlier.
The big advantage we have with that is that we will start that effort, of course, to the CIO for existing customers today, so they could also have the vision that Qualys sees and we have already embarked, by the way, already that with a few CIOs for existing customers, where we are in fact currently working with them to help them provide that global view of their global IT assets. Those are going to be use cases that we want to bring. That large corporation, et cetera, is already doing this and using that with Qualys. These are the assets. That's the way we've always done our marketing and our messaging, to really have our customer speaking rather than us speaking about. That's what is going to be the thrust. We'll put most of the pieces together.
It's all about, as I said, really throwing the gauntlet, if you prefer.
One last question.
Okay. A volunteer for the last question? Oh, here.
We have a winner.
This is for Melissa. Sorry if I missed what your point was on this one slide about getting more leverage on each dollar of incremental revenue. It's gone down to about $0.19 per dollar. Was there a trajectory? You talked about investment year, this year, next year. Does that move higher before it moves back down? How do you think about that over the next two years of new product ramp?
Sorry, does what move higher?
There's a chart about expenses to incremental revenue.
Right.
That's been going down pretty significantly, down to 19. I'm just saying over the next two years, as you're in an investment mode, does that go back higher to more incremental, or do you get less incremental or more incremental over the next two years on the spend?
Right now, where we are with new solutions, they're not at scale, that's why you're seeing higher expenses associated with those incremental revenues. As we scale these new solutions, we're not going to need much more expenses, because think of our fixed costs for running a product is relatively low. It's 15 people on a product, let's say, on an R&D team. As those revenue scale, the incremental becomes very low. Today, we're still in investment year because the solutions haven't scaled yet. We're at a higher end, is how I think about it.
Great. That concludes the webcast portion of our Analyst and Investor Day. Thanks everyone for joining us.
Okay. I also wanted to thank you very much. Very much appreciated for your presence and your questions. Thank you very much.