To F-Secure's 2024 Investor Day. A warm welcome to everybody online. Good to have you with us, as well as here in the room. It's a warm welcome. We got our first snowfall in Finland this winter season, so it's not warm outside. This is a much better place. Our theme for today is unlocking growth. I'll get back to that in a second. Today's agenda is here. The times that we're indicating are Finnish time zone, so one hour ahead of Central in Europe. We are going to run in three sections. The first one is about strategy and market dynamics. We'll be focusing on what are the market trends, where do we see our customers developing their business, and why would we be the party that can win in this kind of market. We'll have a break after that, then we'll get to our portfolio. How does that portfolio drive and create opportunities for growth? We'll finish off by going through financials and also covering certain aspects of sustainability. That's the program for today. We have reserved roughly three hours and 20 minutes, 3:15, 3:30, depending on how quickly we will move forward, but around that time frame. These are the presenters today. In addition to myself, Bruno Rodriguez, our new Chief Revenue Officer, will be presenting the market dynamics and market trends section. TL Viswanathan, our Chief Product Business Officer, in that same section covering our portfolio, also our Head of Threat Intelligence, Laura Kankaala, both of our Product Management Directors for Security Suite, Eero Kukko, and for Embedded Security, Niko Kiukkonen, and then finishing off with Sari Somerkallio, our Chief Financial Officer. Prior to moving forward, I would also like to use this opportunity to invite some of our other leadership team members who happen to be on location today. There are some new faces and some familiar faces, I would like to introduce everybody all the same, who will not be on the podium otherwise presenting today. We have Nina Lehto, our new Senior Vice President of Services, who joined us end of August. Toby White, several years in the company, our Chief Technology Officer, Antero Norkio, a Veteran of War in F-Secure, who's our Senior Vice President of Corporate Development, and Kaisa Tikka-Mustonen, our new Chief People Officer, who joined us in the beginning of September. Thank you. Now moving on. The disclaimer, as always, we're making some forward-looking statements. We're not giving investment advice here. In your own time, I trust that you will read through this very carefully. A few words about practicality. After each of the full section, so both me and Bruno presenting, after that, we will have a Q&A, then we'll have the break. After the whole portfolio section, there will be a Q&A, and then at the very end, after Sari's section, we will all be here on stage, and you can pose questions on any of the matters that we have presented, covering any of the areas. For those in the room, we have the regular practice of you just raising your hand if you have a question, and there is the microphone that will be hurried over to you in no time. For those who are online, the chat is open already now. If you have any questions, just please post those into the chat and we'll cover those when we get to the Q&A. That's all about the practicalities. Why did we choose a topic such as unlocking growth? In a market which has been relatively difficult from the consumer trend point of view, sometimes you feel that you need a crowbar to unlock growth, and it's not straightforward. We've made a major acquisition 1.5 years ago. We acquired Lookout Life. That opened up completely new avenues for growth for the company. We had our previous Investor Day in September 2023, very quickly after the acquisition. Since then, a lot of thinking, analysis, and learnings and experiences have taken place, and that has quite substantially molded our strategy to what it is today. We thought that, okay, that's a good topic because now we are about growth. Also, we've referred, Sari and myself, in several of our quarterly results sessions into driving growth, setting the foundations for growth. We've only been able to scratch the surface, so we thought that, okay, let's go through this properly. Let's look at the market dynamics, the trends, what are the kinds of behaviors and needs that we see in our customer segment, and why would we have the right to win? Also, why is this the right kind of portfolio, actually, to then satisfy the needs and opportunities out there in the market? Those are the main themes, and then Sari will naturally give the financial view on the same. That's the reason for the topic that we have for today. When we finished off our Investor Day last year, September, this was my, I believe, last slide, more or less. We talked about growth fundamentals that we're putting in place in the company, first of them being expanding our addressable market. Prior to the acquisition of Lookout Life, we talked about especially going deeper into new vertical partnerships, not the typical communication service providers that F-Secure had been working on for a long, long time, insurance companies, banks, payment brokers, and so forth. After the acquisition, the tier 1 partnerships has been something that we have been vehemently focusing on as a new extension to our customer base that we've been serving. I'll go through a little bit what kind of achievements we've made on that front. In terms of value increase, we were talking very much about the need to bring new products to market. Embedded Security has been practically built from scratch in the past 15 months. We've extended Total substantially, and also with regards to Total, we have a new module that we've introduced. In aspirational culture, growing is not about only what you do, it's a mental state. It's the kind of aspiration level that you set for a company. These were the kinds of things we were focusing on. Just a quick recap of what we've achieved. We've set earlier as a target for ourselves to be the undisputed leader among the world's largest communication service providers by 2026. We may be closer already now at the end of 2024 of reaching that target than we even imagined. Naturally, the scope of our services may vary from relatively limited to a very wide scope. Now already six out of the top 10 by revenue in the world are being served by F-Secure. Excellent progress on that front. Like I said, some of these start small. Also, naturally, because it's partner business, our partners require time to actually grow the user numbers for our security services. The names that you have around the globe on the screen, I would want to say that these are all our partners. No, that's the target segment. When we talk about the largest CSPs, these are the kind of companies we talk about, these very names. They are the ones which are at the top of our target list. A development that we're seeing, and we're going to cover in much more depth in Bruno's section, is that especially with these bigger communication service providers, they've started seeing that the road to push price and faster speeds, the best times may be over, and growth needs to be found elsewhere. Not only revenue growth, but profitable growth. Security has now been identified by a good number of these players as the area to start investing in to expand what they have considered to be core. You know that naturally, voice and data, for some even content, has been core. Now security is starting, especially with the ones who consider themselves to be true market makers in their own countries or geographies, they are starting to extend security into the very core. AT&T brand promise, fast, reliable, and somebody help me. Secure. Secure. Secure. There we go. The most important one, fast, reliable, secure. They have it even on their tagline. It's becoming a real difference maker. New verticals. We are now focusing on the bigger new vertical opportunities, especially insurance companies and banks. Bigger is better. In addition to Europe, we're also exploring the market for these opportunities in North America. When we move on to the next section, are we doing something about value? I'll get back to this a bit later, but we have a completely new module in Total we call Scam Protection, and just one of the capabilities in Total, which is called Shopping Protection, we have prevented tens of millions of potential entries by our users into dubious shopping sites. Tens of millions in just a year. We launched Shopping Protection in November, December 2023 for desktops only, then during 2024 also for mobile devices. Already tens of millions of one-star ratings for shopping sites that people have tried to enter, and we've advised them not to. It makes a big difference. This is value as perceived by customers in a big way. I start at the bottom. First of all, we've talked about Total conversion a lot. 80% of our top 50 partners, I'm talking about the top 50 partners, 80% of them, 40, have already committed to multi-module Total. Not just Total, but taking multiple modules in use. Out of them, 70% are already live. I think that's 28. 28 of them are live. As we mentioned in our quarter three results session, still roughly 75% of all users using F-Secure security services, either directly or through our partners, are still using a single module or our previous generation product. There's tons of value still to be unlocked over there. Next one, Scam Protection being the new module and obvious need in the market, it is resonating extremely well with our partners. I dare say that 100% is a closer number than 90% of who's interested in Scam Protection. They all are. It is addressing a substantial need in the market, and naturally, that offers a business opportunity both for our partners and F-Secure. We've said already since 2022 that we aspire to become the number one security experience company in the world. We were super proud, roughly two, three weeks ago, in the AI Gala of the technology sector in Finland, to win the best user experience built based on AI in our messaging protection. That really made our hearts warm up, because that's precisely what we want to do. Not only provide security efficacy, but provide a fantastic user experience leveraging AI. As I mentioned already earlier, in roughly 14, 15 months, we have built the broadest Embedded Security portfolio in the world among any consumer cybersecurity company. I am impressed with our team. This brings me to the new culture empowering growth mindset. If you think of what does it take to grow, it takes good ideas, good technology, good salesmanship, good marketing, good partners, good value proposition, and a team that is pumped up and aspires to become a leader in the market. When I'm looking at what we've done, for instance, with Embedded Security in a record short time, how we've been expanding Total in the past, let's say 12 months or so, and continue to do so at the speed, it's breakneck speed right now, and this is what we need, and it clearly shows that our team is pushing the limits and is inspired to truly turn F-Secure into a market-leading company. It's not good enough to be an also-ran. We want to lead the market, and I think it's very visible now. Now, as we are serving already so many tier 1 partners, our technology, our services, every single aspect of our operations is getting to the next level. Not only Premier League, I would say Champions League. Now I'll just recap very quickly before I hand over to Bruno where we are with regards to our strategy. This is just a recap, which in a way paves the way for all the presentations that you will be hearing today. First of all, we believe that we're taking head-on the two biggest issues that are out there in terms of consumer cybersecurity today. On one hand, there's a scamdemic out there, and I just read one single number from here. In the past 12 months, the Global Anti-Scam Alliance, based on their survey, $1 trillion has been lost to scams in the past 12 months. I lose count of how many zeros you have in a trillion, but it's a lot. This is a massive problem, which by far shadows anything that we've seen in consumer cybersecurity in our past. It's a horrible problem that needs a very good solution. Secondly, complexity, still unsolved. Still roughly, actually more than two out of three users feel that this is just too difficult for me. It's too complex and impenetrable. I've always said that the worst feeling that we could ever leave consumers with is a feeling of hopelessness, right? That I feel like there is no way that I can stay safe, so I won't do anything because it's only a matter of time. We need to get rid of that impenetrable feeling that people may have. As I just mentioned, for our own user base, there is still 75% who haven't taken multi-module Total. When we have made our consumer surveys, consumers typically activate, no more than 10% of them activate a security service from their partner. There is a massive issue there that requires solving. On one hand, we are solving the technology and scam problem through a research-driven, AI-powered, holistic Scam Protection. These are the three things that are crucial. Research-driven, we have refocused all of our research around Scam Protection and scams, understanding them. Laura Kankaala will talk more about it. It needs to be holistic to make it easy for users so that they don't have to pick and choose from different kinds of bits and pieces. Powered by AI to be efficient in terms of good security efficacy, and secondly, provide a great and smooth user experience, which is the second point. We have made strides in providing even a greater user experience in our Total application. If you have had the pleasure of using Total, you see that it's a much more engaging service than it ever was before. It talks to the user, it guides the user. It tells more about what's going on in the world of security and threats. It's helping you. Also, our partner experience has been driven to the next level, and next year, I'll save it for later. Next year, we'll be making some great strides on that front even further. For instance, our partners who are using Embedded Security can now engage with us through an excellent developer portal that provides them with everything they need to be working with our technology. That's on what we're working on as a company. Secondly, what makes us different, we are the only company where every single thing we do, value proposition, business model, operational model, services, everything that we do has been optimized to drive partner success. Every single thing. Our skills and capabilities and experience in the company, and that shows. Secondly, especially when I talked about the bigger players and how they want to turn security to become a part of their core services, they really want to make it look like them. It's not enough anymore for them to have the same product as somebody else is selling directly to their customers. Why would they just resell something? They want to create something that is their unique value proposition, so it has a unique composition of capabilities. It has their brand, it has their experience, and is either integrated to an application they already have, like a CSP app, or it is a completely new app that has been built, for instance, from scratch to be their unique security service. We need to be able to make it theirs. Secondly, Total, in addition to co-branding, can go way deeper in making it yours from a partner's perspective, and Eero Kukko will be talking about that. Finally, we work with the kinds of names in the industry that everybody would be envious of, who are pushing us day to day to get better, who are asking for more, who are pushing the boundaries of where consumer cybersecurity should go. We both work with them and co-create with them. Just some of the names out of the roughly 200 partners we have. This was a quick recap of where we are as a company, how we've done in 2024, and what our strategy looks like. Now I would like to hand over to the people who will actually go much deeper into the details and provide you with depth that you will certainly appreciate. Thanks everybody for this. I will now invite Bruno to take on the clicker and start looking at the market. Thank you. Thank you, Timo. Hello. Good afternoon, everybody. My name is Bruno Rodriguez. I'm the Chief Revenue Officer for F-Secure. I'm a recent addition to the leadership team, been in the company for less than two months. Have quite some experience in the cybersecurity and IT market. I've been in this market for more than 25 years, and especially in cybersecurity and working with and through telcos. Before I start my part of the presentation, I would like to show you a short video from one of the market analysts. I don't know if you're familiar with Omdia. Omdia is a global analyst which is focused on telecom and technology. Michael Philpott is the research director. Michael's going to give you a few messages on why it's important for service providers to have a comprehensive cybersecurity solution. Okay? I'll leave you with a video from Michael for less than 10 minutes, and then we'll continue with my presentation. In my view, cybersecurity has become the most important value-added service that telcos can offer their consumer base today. However, many telcos around the world are not yet maximizing this opportunity, leaving their customers exposed to online threats in the process, which in turn hampers their own ambitions of moving into new growth markets. Omdia's service provider consumer research team is focused on helping telco consumer strategy teams make the right strategic choices to deliver top-line growth. In recent times, the main growth has come from broadband and mobile data. However, the focus has always been on speed on the fixed side and largely on usage on the mobile. As markets matured and became more competitive, the trend, however, was simply to give more and more for the same price. In both the broadband and mobile spaces therefore, speeds and usage have grown exponentially, but global ARPU has remained static for the past 10 years. This, of course, was all relatively fine while subscriptions were growing. The issue comes as markets start to saturate. Without new ARPU growth, consumer revenues will also stall, and we're already starting to see this in some countries. As shown in the chart, although consumer connectivity markets remain big, reaching $1.3 trillion by 2029, it only has a a five-year CAGR of 2% at a global level now, and in some countries, this is heading towards zero. On the flip side, telcos have got to spend big, investing billions into next-generation fiber and mobile networks. Although peaked in 2022, global CapEx intensity was still 16.5% in 2023. If telcos are to continue to drive a return on this investment, it is vital that they now look for new ways to build their consumer ARPU and hence revenues. The key in my mind is to switch the marketing focus from basic speed and usage to this concept of quality of experience. This will both differentiate the brand and enable telcos to branch out into new areas, becoming what some term digital lifestyle providers. The key element of this overall quality experience strategy is security. Consumers must feel secure using their telco products. As one operator put it, "First, we must provide a quality experience, then we must provide a secure one." We're now starting to see this appear more and more in telco marketing too, with AT&T's fast, secure, and reliable strap line as one example. Cybersecurity is also the value-added service that consumers are most willing to pay for. Based on Omdia's 2024 Digital Consumer Insights survey, 70% of respondents stated that they'd be willing to pay more on top of their broadband bill for a cybersecurity solution that protected all of their connected devices. From our survey analysis, it's also clear that some segments are more willing to pay than others. Parents of younger children, for example. As you can see from the middle chart, there's a very clear correlation between the number of connected devices in the home and willingness to pay. Finally, telcos are the most preferred provider of consumer cybersecurity services, which makes sense given that they're the ones supplying the connectivity as well as the key devices such as the broadband gateway. We know from our research that nowhere near this level of consumers do actually pay, suggesting that either telcos are not positioning cybersecurity correctly, or they're monetizing it in other ways, or perhaps a little bit of both. Many telcos certainly offer cybersecurity as part of either their mobile or broadband offerings. In many cases, this simply equates to offering traditional third-party antivirus applications. A very typical telco offering is shown in the table. I'm sure that we're all fairly familiar with such services. These solutions have a couple of major flaws. Firstly, they don't protect consumers from more modern threats such as online fraud, for example, which is now the biggest type of crime. Secondly, they can't protect IoT-type devices such as security cameras, video doorbells, et cetera, which are increasingly entering our homes, but often come with little to no inbuilt security of their own. Thirdly, and perhaps the most important issue, is that they are completely up to the consumer to install and manage them. Thus, the telco has little to no control over the end customer experience. Adoption of these solutions, therefore, can be very low indeed, even when provided for free. To provide a more comprehensive solution, it is, in my view, therefore, that it is essential that telcos move to what I term total consumer cybersecurity. This is a more layered approach, starting with network security, which provides a base level of security, including network-based DNS. Router security, which once enabled, protects both the router and all devices connected to that router in the home, and also provides other functionalities such as device fingerprinting, which can also be used with other applications such as application prioritization and parental controls. Finally, endpoint security, which then protects devices such as smartphones and tablets as they roam onto other networks as they leave their home. The first two, from a consumer's perspective, are zero touch, the telco is in full control of that experience. Endpoint applications, of course, still need installing. However, this system can also be used to identify unprotected devices, provide guidance, and assistance to the consumer to resolve it. Although very much a layered approach, it is essential that telcos provide a single user interface that provides a simple control and management of the whole solution. In years gone past, telcos have tended to supply an application for everything, now they're trying hard to aggregate that into a more joined-up app strategy. By providing a single cybersecurity user interface as part of that wider strategy, not only will that simplify things for the end user, but also enable more sophisticated functionality, adding much greater value. One such functionality could be around security notifications, providing greater guidance and education to the consumer. Providing just a security product is unlikely to be enough to keep consumers safe. They need help, telcos are in a prime position to provide that education and assistance. It also doesn't hurt the telco to remind the consumer of the value that they're providing, as long as they get the balance right. Applications are not the only channel for this, they certainly can be used as one of them. To conclude, therefore, if telcos wish to monetize consumer security and position themselves better as a digital lifestyle provider, then they must invest in more comprehensive solutions that protects their customers from more modern threats across all devices and all networks. To do this, they will need to work with a vendor or vendors with solid track records in the telco industry, so they can utilize that experience to create optimized go-to-market strategies, as well as utilizing the strength of their vendor brands where necessary. In that vein, it's important that vendors also offer professional services, not only to help integrate solutions into the telco platform, but also to help them become more of a partner to the consumer when it comes to cybersecurity. Finally, it's important to look for solutions that can provide a single user interface with the flexibility to match a telco's position in the market and application and branding strategy, whether this is as a standalone app, a standalone app under a telco's own brand, or as functionality integrated into a wider telco app strategy through SDKs and APIs. I'm pleased to say that in Omdia's recent Market Radar in this area, F-Secure is one of the leading vendors that scored highly across all these areas. With that, I'd like to thank you for your time and your attention. Thank you. Good. Thank you very much, Michael, for the video. I hope it was useful. We want to get also inside of a third-party analyst on the market, especially on the telco market or the CSP market, which is so important for F-Secure. I will start my part of the presentation talking about the total addressable market that we see at F-Secure and the one that we want to penetrate. First of all, I think this was also covered by Michael a bit, I'll talk about how the consumer cybersecurity market is going to grow in the following years. According to Gartner, IDC, independent market analysts, the market in the next years is going to grow around 6%. This is for the consumer cybersecurity market. We agree on this, but we take it a bit further, and I'll give you our view on this market. Although the market is going to grow between 5%-6%, the overall market, depending on how you address this market, either with a B2C strategy or a B2B2C strategy through partners, the market can actually grow way more. The addressable market that you can get to with a B2B2C strategy is way bigger. The addressable market for B2B2C, we believe is going to grow 3x more than the standard market, thanks to many of the telco trends and CSP trends that we're going to be seeing later in the presentation. Although the market will grow around 5%- 6%, we believe we will see a growth in the next three years of around 17%, mainly because of the reasons that Timo mentioned before, but we will get a bit more into the details now. Why do we believe that B2B2C is the best way to address the consumer cybersecurity market? First of all, I think we've covered this previously in the presentation, Omdia said that 53% of consumers choose their CSP as the provider of choice for cybersecurity, and maybe around 14% were choosing their insurance company. Typically, they would look at a service provider, be it communication service provider or insurance or financial institution to provide cybersecurity. We also agree with this number, but we've actually seen a bigger one in our own studies where 81% are expecting their internet service provider to provide security. A big part of the consumers are actually expecting their internet service providers to provide security. Not only that, but they are also willing to pay for it. We saw it, Michael was also mentioning this, 56% are already paying for some or part of their security solutions, and 71% actually would be willing to pay for a more complete Scam Protection. As Timo mentioned before, scamdemic is a real issue right now for consumers. They really don't know how to address this situation, and they're looking for a Trusted Companion, somebody who can actually help them deal with this scamdemic right now, and that Trusted Companion is their service provider. As we mentioned before, F-Secure is all about partner first and working through service providers. Let's take a look a bit on the CSP market trend. What trends are driving the market for the service providers and for the communication service providers in particular? I think this quote is very powerful. There was a study that PwC did when they interviewed a lot of CEOs from telcos, and 45% of the CEOs they interviewed said that in 10 years, their company will not be viable if they continue on the same path. This is a really bold statement for a CEO to make of their own company. They need to change. The CSPs realize that they need to change, and the reason they need to change is because of two things. One is commoditization, which we talked about before, and the other one is convergence. We will talk about those two trends and a couple others that we see as well. These are the trends that we're going to cover today in the CSP market trends. Extending the core, how to avoid commoditization, how to establish convergence strategies, how the CSPs are building their own apps to unify customer experience, and what's happening in the router. Michael from Omdia was mentioning that there's more and more needs to protect the devices in the home. This has been a huge challenge for telcos. How are they going to do this? What's coming up as a market trend that will help them or not do this? Let's look at them one by one. I think we've discussed this, Timo mentioned before, the core services for the CSPs have typically been voice and data. That is commoditizing, has been commoditizing for quite some time, and these CSPs are looking at other services that they could offer to move away from the core. We could call this beyond the core strategies, where they're trying to sell different services and give different services to users that are, let's say, different from their core. Why are they doing this? First of all, as we said, the core is getting commoditized. On the other side, the value-added services or services outside of the core are expected to grow way more than what the core is growing. I think we were mentioning around 2% growth, Michael was mentioning for the core or even zero in some markets, or even declining. Where VAS value-added services in general are growing 13%, more than 13%. Okay, what about security? First of all, security is, from our point of view and what we're seeing, one of the key value-added services. It's so key that it's actually becoming core in many of the large tier ones, and we will talk a bit about that later. Why is security so important? First of all, there's a demand for consumers. We've seen that already. Consumers have this problem, and they need help to fix it. Also really important is profitability. Not all value-added services are created equal. A lot of telcos maybe are just reselling music. They're reselling content. They're reselling Netflix subscriptions. Are those really profitable for them? Also, consumers now know those services, and maybe they go directly to the source, and they don't have to buy it from the telco. They need to find value-added services or services that are really profitable for us. What we've seen in working with all of these CSPs for many years is cybersecurity provides up to 75% gross margin for the telcos as a value-added service. There's no other service that will give you that type of gross margin. This is one of the trends moving, extending the core, or let's say, trying to find services that will bring them away from the core, beyond the core. The other one is convergence. This is another big trend that all of the telcos are talking about. Typically, CSPs have treated their mobile and broadband divisions as almost completely separate companies. In many cases, they were just acquired and become part of the same company. There was not really a strategy for the broadband and the mobile together. This is changing significantly right now. I'll give you two examples. AT&T and Verizon, two of the biggest telcos in the world, are right now in the U.S. There is what the analysts are calling a race to convergence. Both of these two companies are racing to see who gets first to deliver a full convergence, converged solution or service combining broadband and mobile. Either they are combining or putting together their own divisions, like it's the case of AT&T, or even in the case of Verizon, they're acquiring other big players in their market to actually work in this convergence strategy that they're designing. One of the examples is the acquisition of Frontier Communications by Verizon in the U.S. Why are they doing this? What is the reason for the telcos to try to go for convergence? There's several points, but one of them, for example, is ARPU and the ability of cross-selling. For example, AT&T was saying that 40% of their fiber customers also have mobile solutions from AT&T. That's a big raise of the ARPU. If you have 40% of your broadband customers also having mobile from you, that's a big raise. The other one is reducing churn. What Verizon was seeing is that 50% of the-- Sorry, there was a 50% reduction of the churn when you combined mobility and broadband. It's also really important for them. This is affecting their top line. This is another strategy to go away from this commoditization that we were talking about. Okay, for the telcos, we can really see the advantage of trying to go to a convergence scenario, convergence strategy. What's in it for the user? The user is still very confused. They are looking for very simple solutions. They do not really care about these convergence strategies. They just want to make it simple. How are the telcos making it simple for the users in this convergence world? It is all about the applications. Most of the big telcos in the world right now are building their own applications or have been building their own applications or enhancing their customer care applications that they have with more and more services. There is a couple of examples here, Rakuten, for example, in Japan, and one good one is this one from T-Mobile, T-Life. I don't know if you can see that, but this is actually a quote from Omar Tazi, who is the Chief Product Officer at T-Mobile, he was saying two days ago in LinkedIn that T-Life, which is T-Mobile's application, is the number one spot lifestyle app on the App Store. Number one, not telco app, lifestyle app. Even bigger than Pinterest and Zillow and Ring and Alexa and Tesla, way bigger than all of those apps. They're the number one. Clearly the customers are looking for an app where they have everything simple. I know the telcos have been trying to do this via super apps for a long time, now I think that they cracked the code, now they are really realizing how to do it. In the case of T-Life, this includes also security in that app. It's really important to be able to fuel or supercharge those apps with security, and that's something that F-Secure is very well positioned to do thanks to our embedded portfolio that TL will discuss later. Taking it even further, we have AT&T with ActiveArmor. AT&T security is a big part of their core. They're moving towards security, and it was part of their motto, I think Timo mentioned before. It's so important that they're building a security super app that includes all of the features of security that they are offering in a single app called ActiveArmor, and you can see there. This is not only cybersecurity, but includes call protections and other types of security features. AT&T is pushing big time to improve this application in the future, and you will see more of this later on. What about the smart home? This is something that also Michael was mentioning before, that the smart home, there's a lot of devices that are insecure, and there's a lot of devices that need protection, and there's not really a clear solution right now in the market to offer protection for these devices. What has been the main challenge here? F-Secure's had a solution for router security for years now called SENSE. Why hasn't this catched up? What is the reason why telcos or CSPs are not implementing this on all of their routers? The main problem here is that it's really difficult to deploy applications on these CSP's routers, on these CPEs. It's very difficult to do because all of them have proprietary operating systems. They're very closed systems, so deploying an app is really difficult, and not all of the companies can afford it. You need to work very closely with the router manufacturer. You need to build a specific app for that, and it's not easy to do. This is another trend that we believe is going to change in the next year and 2026 as well. The main reason is because of some initiatives that the really large telcos are putting on the table. These are prpl Foundation, and RDK. prpl and RDK are standard operating systems that are driven by the biggest telcos in the world. In the case of prpl, it's AT&T, Verizon, Orange behind it, mainly Frontier, and then RDK is Comcast, Deutsche Telekom, and Vodafone. They're all pushing for these standard operating systems. We also have Broadband Forum, which is across the line also generating standard protocols for these routers. I think it was the AT&T CTO who said this in one of the presentations. He said, "The home routers are going to have their Android moment." I really love this quote. It's like the mobiles before and after Android. Before Android, the mobiles were difficult to have an application. You didn't have a store. You need to have everything almost tailor-made for the different operating systems. Once Android was out, everything changed, and that was really easy to deploy applications in the router. That's what we believe is coming in 2025 and 2026, this Android moment. F-Secure, thanks to SENSE, is really well positioned to take advantage of this Android moment and deploy security in these routers. Until now, we're seeing things are going to change, and we're going to be able to deploy applications in the router. Which applications are interesting for the user? Of course, number one application, number one thing the user want when they have a router is good Wi-Fi. That's obvious. Right now, internet equals Wi-Fi. If you don't have Wi-Fi, you don't have internet. That's the first thing that they're looking for, good Wi-Fi. Wi-Fi management is going to be really important to be deployed on these routers. The second thing, and third, is security. That's the next killer app that they're looking for in the routers. Once this Android moment happens, security is going to be one of the most demanded applications in the router, and we will be ready for that. Okay, that's a bit about the trends. I will finalize my presentation talking a bit about F-Secure and why F-Secure is the best partner to help these CSPs, these communication service providers, and service providers in general, to transform their companies, taking advantages of these trends that we saw. Okay, I think one thing that we need to look at before I give you a little overview of the strategy is, what are the service providers like? Are they all the same? Do they all have the same needs? The answer is no, not all the service providers are created equal. We actually see three types of service providers in general right now, and of course, we have the direct business. I'll talk about these, and why this is important. First of all, we have the strategic partners. We've been calling these the tier 1s. This is the top 20 service providers in the world. This is not only telcos, not only CSPs, but other service providers as well, like financial institutions or insurance providers. The features of this, these have really large base, very high ARPU. They typically are the leaders in their market. As we said before, they're not only delivering value-added services to their customers, they're actually making security as part of the core. For them, one of the key things and one of the key questions that we get every time we talk to these service providers is, how can I be different? How can I compete with the rest of my market? How can you help me deliver something unique to the market in security? I don't just want to take your app. I want something unique. The needs for the strategic partners are very different. On the other hand, they have high investment power and high maintenance power. They want something unique, and they are ready to pay for it. Most of them, as mentioned before, these services that they want to offer, they're becoming part of their core. It's not that they're just adding security on the side, like they would add music or they would add video. Actually, they're adding security to all of their offering. The broadband needs to be secure. The mobile needs to be secure. Everything they do needs to be secure. Those are the strategic partners, very different. Major partners, before the Lookout acquisition, this has typically been F-Secure's sweet spot. We were addressing the major partners. They have high ARPU. They need value-added services as well, but they also value quick time to market and measured investment and reasonable operational costs. Total has been a winner here for years, and this is where we were coming from before the Lookout acquisition, the major partners. They're the top 100 service providers in the world. We have the commercial partners. Commercial partners are the rest. We're talking about top 100 CSPs in the world, but in the world, there's actually thousands and thousands of communication service providers. How do we get into those? Those are like the long tail of the partners. How do we address the long tail? If we could find a way to actually address that market in an industrialized fashion with a SaaS model, in a self-service model, for example, where those companies could actually have access to a security solution in a very easy way and convenient, that will allow us to crack that long tail of partners like many other technology companies have done in the past. That's also really important for us. The commercial partners, they are looking for quick time to market efficiency, a little bit of customization, but they don't need the full customized solution. They have limited investment power. They will not be ready to pay a lot up front for a customized solution. On the other hand, there is a lot of them, and the addressable market that these commercial partners are looking at is pretty big. This is another of the, you know, segments that we were looking at. Finally, we have direct business. Of course, you know that a percentage of what we do is for direct-to-consumer. This is a completely different business. They're concerned about the scams. They want a simple solution. Of course, we will continue to address the direct business, but the focus would be on those three. The point is that we believe so much that these types of CSPs are different and they have different needs, that we have restructured our company to actually better serve all of these customer segments. You will see changes coming up also in the company to better serve the strategic partners, better serve the major partners, and better serve the commercial partners. Okay. To end, I will tell you a bit about just an overview. I won't go in depth on each of these because my colleague, TL, will talk a bit more about our portfolio and how we are going to address these customer segments, but I'll just give you a bit of an overview. This could be right now how the customers for or the partners for F-Secure look like. We have strategic partners, which we don't have. We have six out of 10 of the biggest ones right here. We have the major partners, and then we have the commercial partner, which is the long tail that we're addressing. For the strategic partners, what are we going to do? What is going to be the strategy here? The key here is to win new partners in key markets. How we're going to do this is we're going to piggyback on their strategy of launching super apps and fuel those super apps with our smart SDKs, with our Embedded Security that Timo was talking and that TL will talk a bit more later. For the major partners, I think Timo mentioned this as well, there's a huge opportunity still here. A lot of our partners are not yet in Total Multi-Module, so there's a lot we can actually grow with our existing partners. Not only that, we have, we can say, an amazing proposition that we've tested traditionally for years in our markets like Europe, and we can still replicate this success story in other markets, in other geographies, like for example, North America and Asia. There's a lot of major partners in North America and Asia that could benefit from all the experience we have with a solution like Total, which is very proven, very easy to deploy, and the time to market is very short. Finally, we have the commercial partners. It seems like they are the smaller CSPs, and we shouldn't pay a lot of attention to those, but actually, I think it's not the case. This is what we call the long tail of partners. Probably we cannot address them one by one like we do with these. There is an opportunity to actually come up with a SaaS platform that would allow us to address that long tail and escalate from 100 partners to thousands of partners. That's really what we're going to work on in 2025, building that SaaS platform and addressing that long tail for hyperscaling. Just to wrap it up, I'm going to repeat more or less what Timo was saying before, why we win. I think the key point here is partner first. For me, this is one of the reasons I joined the company. That's really what I believe. Partner first, always. There is no conflict. Telcos or service providers will always be the first in our priority. If the telco is not successful, we cannot be successful. That's the only way we can be successful is if we really understand the CSPs and we really make them successful. TL will discuss a bit more about this, but we have an amazing product portfolio that is optimized for this telco success, this service partner success, with Embedded, with SENSE, with Total. We have a solution to actually match the need of every customer segment that we've seen so far. Finally, we understand scams like no other company. We don't only believe that scams are just another threat that we have to deal with, another yet technology. It's all about scams now. Almost all of the threats in the market right now are designed to actually scam people. You can't just add another technology on top. You need to actually stop the scams at every customer interaction, and this is really important. And the telcos understand this, and consumers actually want a solution to stop these scams. Okay. That's all for me. Timo, if you want to come up on stage, we can answer some questions. Thank you. [Non-English content] I'll get some water while the questions are preparing. Okay, first question's coming from the room. Hi, Felix Henriksson from Nordea. Thanks for taking my questions. I have a couple. First to Bruno, personal question. Okay. What made you join F-Secure, and can you expand a bit on your background with working with some of the largest telecom operators in the world? Okay. I knew that question was coming. It's the first question. It is the first question, let's get it out of the way. Okay. As you probably know, so my background, before joining F-Secure, I was working at Bitdefender. I worked for Bitdefender for 12 years already, where I was leading, in the last years, I was leading the telco business for Bitdefender. We signed top service providers in the world there. Before that, I was also in charge of the OEM division or part of the OEM division for Bitdefender as well, dealing with large manufacturers, like Cisco, like Check Point, and the rest of these. Before that, I was also working at Panda Security, which is another cybersecurity company. Before that, I was working a lot with telcos. I have both the cybersecurity and the telco experience in the past years. Okay, that's the second part of the question. Why I joined F-Secure, I think I've mentioned it during my presentation. I think what I really liked was this partner-first mentality. That was not the case in my previous companies, where there was a bit of a conflict between direct to consumer and B2B2C. Joining a company where every single person in the organization, except for our direct-to-consumer team, but every single person in the organization is thinking about the partners, how we can help them, how we can make them successful. Again, if they are not successful, we are not successful. There is no channel conflict. There is no problem. That's really what we want to do every day, and that's what we talk about every day. How can we help telcos be more successful? That's the main reason I joined. Second reason is the product portfolio. TL is going to talk about that. The fact that we have this broad portfolio of SDKs, for me, when I was coming from an OEM background where SDKs were really important, I was really surprised to see what F-Secure was able to build in 15 months. Amazing. It's a really broad array of SDKs that will allow us to fuel these super apps from the telco. That was the other. Of course, Total, for me, looking at it from the outside, was really the crown jewel of F-Secure in the past years. The fact that it was so easy to rebrand, so easy to deploy, that for me was amazing. I was really envy of Total when I was working at other cybersecurity companies, and that's another reason why I joined. Thanks. That's a good background. I guess when we think of the European telco landscape, many operators are struggling with their ability to invest, and ARPUs are very low when you compare to the rest of the world. If one were to buy into your value prop of higher ARPU, lower churn, it sounds like it's the perfect match for the telcos. My question is, what's the sort of main pushback from partners who haven't yet adopted Total or some of your other offers? Is it the cost? Is it something else? What's holding them back? I can do a quick one. Bruno gives you the right answer. From my point of view, what I hear is that many of the bigger players are indeed facing precisely what Bruno was telling, how their core services are facing headwinds. They put a lot of management bandwidth and effort into resolving those. They are doing their absolute best to make sure that their broadband services and their mobile services would be in a better shape, in some shape or form. They put a lot of focus on that, and while they're at it, everything that has to do with billing, with customer management, product management, and so forth, focuses heavily on those aspects. There is less bandwidth left for what you could do with something like security. I would say that some of the other markets they have already, in a way, emptied the bag with the core services, and they are clearly looking forward now. I completely agree with Timo. That is the case. We've seen some markets that are really advanced, and they really get it, and they are already there. They have been working on their cybersecurity offering for years now with a lot of success, and they're really pushing the accelerator. We'll see a lot of things coming up next year also from those large markets. Other markets that maybe haven't gotten that yet, and they're realizing that they have this problem. Some others are actually going in some directions which are not cybersecurity, like offering, for example, other types of services, like maybe even offering energy or offering other things in some companies. They're all trying to go beyond the core. That I think is, almost everybody has realized that, especially for the markets where you have really cheap telcos coming in with very low prices just to buy market share. The incumbent, the telco incumbent there is really suffering that, and they have to find ways to differentiate and add other services. Some of them are offering security, but maybe with not the right focus, and that's really what we have to work on. We have to really help them understand how security is profitable for them and how they will actually help them go beyond the core. The onus is on us, really. Yeah. To be able to convey these messages to C-level of these very big companies. Thank you. That's helpful. Hi, Walter Rossi from Danske Bank. Between tier 1 partners, for example, are there any restrictions if, let's say, AT&T is your customer, can some of their competitors be also your customers? You should probably really ask this from them. We are seeing that, especially when you deal with Embedded Security, there are so many ways how you pull that together into an actual value proposition and user experience. There are so many ways that even from using the same components, the outcome can be drastically different. From our point of view, you can differentiate, and a lot. Yeah. Contractually, are there any restrictions in your deals? We have no such contracts in place as far as I know. Sari can correct me if I'm wrong, I don't believe there is anything that would stop competition. That's also regulation-wise, that would be very questionable. All right. Thank you. On the addressable market, the figures you show, they kind of imply that there's also other players providing security services to these, your partners or potential partners. Can you talk about that? Who are the competitors or what kind of players, and how do you differentiate? Depending on the geographies, they vary. Depending on the product segment, they vary. If you're looking at readily available apps that can be co-branded or white labeled, there are many different players from different Gen Digital brands like Avast, Norton, LifeLock. There is McAfee, of course. In the U.S., there's Aura, there is Malwarebytes. There's a whole host of players. If you go more into Asia, somebody like Trend Micro from Japan has been traditionally quite strong over there. Here in Europe, we have the luxury of meeting all of them. If you go to certain segments of the market like password management, or you go into router security, then there is a sub-segment of competitors. If we then think of Embedded, less competition over there, fewer players. Names that we often bump into, Bitdefender, McAfee. Bitdefender also in the app market, by the way. Bitdefender, McAfee, or Trend Micro are names that we bump into. Anything I missed? If I can be a bit more bold. How we win. A bit more bold there. You look at what I like to call converged partners, a partner that will have a solution for broadband on the router and mobile and PC or laptops, F-Secure is the only one which is partner first. You have other companies, maybe like Bitdefender, who have also SDK portfolio, and they have a solution for router, and they have a solution, but they're not partner first. F-Secure is the only one that is really partner first with that product portfolio that TL Viswanathan is going to talk to you about. That is the why we win. That's the reason we win, and that I think is really our unique value proposition. All right. Thanks for a good answer. The last one from me for now. Again, AT&T as an easy example. If you look at their security portfolio, their security solution, how many other service providers are included in their portfolio? Because I'm assuming you're not the only provider. We are the only provider. Okay. You can cover the whole- On mobile app. Yes We are the only provider. We integrate also some third-party technologies into the solution, but we cover the whole application. Yeah. All right. Great. Thanks. Good afternoon, it's Matti Riikonen, Carnegie. I have three questions. First, when you talk about the consumer cybersecurity market growth of 6%, and then the business-to-business, to consumer market growing 3X, it sounds like a very high number. If we look at the listed companies and the known companies in the field, the usual suspects that you just described, actually many of them, we can't see that their growth would be that high. Yeah. Where does this market growth come from if it doesn't come from the largest players in the field, including you? Also going forward, if we look at the market estimates for these companies' growth, it's not even near the numbers that you're talking about. There's a certain discrepancy there. Could you please explain that? If I can just- Go ahead. Sure. Shoot. Okay. I think that the main difference here is addressing that market with a B2C strategy or a B2B2C strategy. Addressing that market directly, which is Norton and the rest, they are seeing a smaller growth. What we are seeing is that if you address that market through partners, which is mainly what we do, the growth is much higher, and there's no other company that it has this as their primary business model at this moment. This is why we believe that there's huge potential to grow in that market with a B2B2C model. Yeah. Another look at this is that the big players out there in the CSP market have traditionally been reselling some of these B2C products. They've been reselling. They are not that interested in that model anymore. They are shifting to a model where they build their own product that competes against the big brands that we know from B2C. This is a different, in a way, new big players are entering the consumer cybersecurity market, taking on the McAfees and Gen Digitals in their own market by providing their own product. That is the big difference. That market has not existed before, and it does not exist today, for instance, for Gen Digital. McAfee is doing its best, naturally, to play a role in there. We try to make it as hard for them as possible, and fair game. This is a new market, and that's why you don't see it there. There are other companies who have a partner aspect to their business, and they are trying to go after that same growth as we are. We are positioned, we believe, in a more ideal manner than they are. All right. You're basically saying that the market size and the growth is partly seen outside the traditional players. Precisely. Offline, it's the operators that are doing it. Precisely. Because of what we mentioned before, because of the demand of the user to get cybersecurity solutions from the operator. All right. Good. That makes sense. Your talk about this Android moment. Yeah. For home router business, I think it's a good term. Thirdline, I stole it from the AT&T CTO. Copy was fine. Yes. Would you have any practical examples of the names that are going to basically introduce that kind of services? When you say that most of the operators are doing it in 2025 and 2026. I would love- Where can we see that? I would love to give you those, but I'm not sure if I can. Yeah. When you will see them? 2025. 2025, you will see big operators launching in prpl. RDK is already in the field, so Comcast is using RDK. Charter. BT is using RDK. Charter, part of Comcast, using RDK as well. That's already there. prpl takes it at another level. It's even more open than RDK. The first deployments on prpl will come in 2025. There's a lot of them. There's some of them aligned already in the key markets, and we will see them in 2025, but I can't disclose the names. The standardization happening in prpl, it's called prpl Foundation, and the founding members contain names like what. AT&T You mentioned. Verizon, Orange, Frontier, Vodafone. All of the big players are behind that standard because it's in their best interest to make it really easy to deploy applications in the router. They would be able to go beyond the core. And sell those applications in the router. I think it's in their best interest. Until now, it was very difficult for them because each router that they had a different operating system, very tailored-made solutions. Now they want to open all of that so they can deploy services in the router. That's the Android moment that's coming. All right. Good. Thank you. Finally, when you talk about the penetration with CSPs, roughly 10% with cybersecurity services. How does that work? What's the penetration among these new verticals like insurance companies, banks, et cetera? Is it approaching the same levels, starting probably from a lower base, but how does it look from your perspective? Lower. Yeah. As I was going to say. Lower than the 10. Yeah. To begin with. It's a new market for them. There was a time, for instance, I moved to the U.S. in 2015, and that moment in time, many of the big U.S. banks were bundling for free, like a one device antivirus product, and those were not taken on actively, and it became just a cost for these banks, and then it was quickly discontinued. That wasn't a successful approach. Now, the new propositions that especially insurance companies are coming up with, they are much more integrating some of their own products with a cyber protection type of a product. Yeah. It's a new market for them. They're making very careful first initiatives, testing markets, training their own folks and learning the good habits in the industry. They are starting carefully. Banks and insurance companies are not ones who bet the farm and go full speed right ahead. The service takeoff rates are relatively low to begin with. Yeah. I think it's also a change in the consumers. As we saw before, I think Michael was mentioning, and we had some data on that as well, consumers see the CSPs as their natural provider for cybersecurity. They are providing connectivity, so therefore that should be secure. They see them as their natural provider. The insurance companies, maybe not that much. I think we saw it with 17%, if I recall. 14. Yeah. That's way lower than what we're seeing on CSPs. There's also less demand for consumers. They still don't see these companies as their provider of choice. It could be that with certain plans, like for example, if they're offering some type of cyber insurance, it will make sense to bundle it with cybersecurity because they're related on the same thing. That's not overall on all the insurances like your house or your car. They really don't see that their car insurance is going to come with cybersecurity. It's not that natural as your connectivity, for example. All right. Thank you. Good afternoon. Jaakko Tyrväinen from SEB. Given the importance of the security for the tier 1 players or the large ones, security becoming close to their core, are you seeing risk them insourcing their own cybersecurity? How you plan to play the game against such kind of a risk? Okay. First of all, they've done this on business security side or corporate security side, enterprise security, whatever you want to call the market. They have done some insourcing. AT&T has acquired assets. Verizon has acquired assets, I'm sure. Well, Orange. Orange has their services. Has done that. Yeah, they've done that. That's something where consultancy and the service element is much bigger maybe than the technology and the product element. In the consumer cybersecurity market, it's completely the opposite. These are not consumer cybersecurity technology building, app building companies. They're not built for that. At least for now, I am not aware of any moves where major service providers in the CSP sector would have acquired assets in the consumer cybersecurity market. In our risk map, that's not one of our risks. It doesn't make our top 20, for sure. Yeah. We don't have an active plan B because we don't get any indications of that. However, the CSPs are very careful at who do they choose as their partner. Yeah. You really have to be rock solid in your security efficacy. You need to have research that drives the innovation and the efficacy. You need to have experience. I would like to think, working for F-Secure, that also the fact that we have hundreds of partners, and they can draw from that experience pool of best practices of what works, that makes a big difference. If you have it in-house, that's all you see. They have a risk of becoming myopic. I don't see that risk. How about you, Bruno? No, I agree. Yeah. Good. Thanks. Bruno showed the improving and rather high willingness to pay from a consumer side. Given this, why the growth has been so moderate over the past few years? Has it been because of the situation of the market or the stage of F-Secure? Yeah, I don't know if I can talk about the past. Yeah. You can talk maybe about that. Yeah. My sins. There are partners who are decreasing in size from our perspective, and much of the good growth that we're seeing, unfortunately, is decreased by some of our declining partners. We've indicated earlier that there are some players, we already touched upon this with another question, there are some players, for instance, in Europe, who are having serious difficulties in their core business, and that's where all of their effort goes. Actually, the order from leadership is stop doing anything with value-added services or security and focus on broadband or mobile or whatever. That doesn't help us at all. Yeah. Because they have churn, churning customers may have had security, then we lose customers without any apparent reason. I would say that is the biggest one. Another example is we've had one partner, somewhere in the world, which signed up to one of our competitors in 2011. They left their user base as is, and they didn't want to touch it. That was from F-Secure in the past. Over the years, it's continued declining. There are such exceptions that actually, unfortunately, eat away some of the good growth that we're seeing. Yeah. Also, if there's market consolidation, like companies being acquired by others, that also affects. For example, there's some news now that, I don't know, Vodafone Spain is going to become independent or this other company is going to acquire, they're going to merge in the U.K. with Three. That really, what we've seen, is it almost paralyzes the company, and they just go back to the core and just try to do what they have been doing and not concentrate that much on value-added services. That also affects because they kind of put the pause on a lot of the things they're doing until they figure out how the acquisition is going to come and what's going to happen. I think that's also one of the drivers, I don't know, at least in the market. One of our big partners, once again, big partners somewhere in the world, made a massive acquisition. For practically three years, they did nothing with security because they were all busy with integrating billing and customer CRM and so on and so forth. Like three years. Yeah. Okay. Very good. Thank you. Hi, it's Atte Riikola from Inderes. Maybe one question from me so we can continue the presentations. About the Embedded Security business, you said you have done tremendous job in the last 1.5 years there. What kind of investments you have already done there in financial terms, or how many developers you have doing stuff on that business side nowadays, and what kind of investments you're going to do there in the future? Thank you for a good question, Atte. I am not able to answer that. We don't want to convey the number of developers and so forth. I will just say that in our own scale, we've made significant investments of money, research, and development into this area. It's been substantial. We will continue to make big investments in there. Maybe more of the focus will go towards new Scam Protection capabilities that are driven by our research. Maybe tuning a little bit down as we now have already quite a wide scale, but Scam Protection most likely will keep us quite busy. It's been a significant investment, especially this year. I would say that starting from roughly October, November last year, not even 1.5 years, we've built a portfolio that Niko Kiukkonen will be presenting to you later today. All right. Thank you. Thanks. We have no questions on the line. Okay. All right. Okay. Thank you, Nina. Now we'll take a break, and I'm waiting for Nina's instructions how long we can take. Okay, approximately until? Three. Okay. Yeah. About 37 minutes, and we will continue. Thank you. Welcome back then. Thanks. Thank you for the great questions. Welcome back, everyone, and a very good afternoon to all of you here in the room and everybody online following us. Let's talk portfolio. Of the many reasons, one of the reasons why Bruno Rodriguez joined us. We'll talk about the strategy, how have we been executing, and the approach that we are taking in the future. Overall, how is this driving our growth? I want to get us started by coming back to what are the biggest problems that we are solving. Timo Laaksonen touched upon those already, but I want to add a different color to talk about how it is shaping the portfolio. Timo Laaksonen's introduced the impact of scam financially. If you look at the frequency and why it is the number one cybersecurity threat for consumers, over 60% of users we speak to have been facing scams on a monthly basis. As you can imagine, a substantial proportion of those go through a fairly deep sense of stress and anxiety. It is the biggest problem, not just financially, but also emotionally impacting our consumers. We see scams differently, though, and that's the point I want to make. Our competitors, industry peers, see scam as yet another security problem to solve, most likely with yet another product. If you think about AV to solve malware, ransomware, if you think about identity monitoring product to solve or keep your identity safe on the dark web, well, this is just another problem that needs yet another product. We do not see it like that. We truly believe that scams are an umbrella threat landscape that actually bring together all the threat vectors that exist out there and systematically combine that with complicated and sophisticated social engineering techniques, where scamsters then identify, target, and scam victims. This is a very important distinction to make because this leads to what kind of solutions are needed to solve this problem. The other aspect of scams, which I think is making a perfect storm moment, is AI. It's not just enough for us to go back to what we have been doing and see how we can adapt, because AI is truly, and not the good side of AI, is proliferating scams at a scale and with realism that is becoming the biggest challenge. If I'm honest, it's not the competition that I'm worried about. It's the scamsters that I'm more worried about who have access to these tools. We think it's our job to stay ahead of them. The rest will follow. The other part is it enough? Is it enough for us to build the best technology to protect against scams? If you look at our data point on complexity, a sizable percentage, two of three or more than two of the three users we speak to find cybersecurity complex. We have not solved this problem as an industry. I think with the point solutions that our competitors are bringing to the market, we are just making this worse. With the extent of the threat that scam poses, and with an average of less than 10% users adopting the service, you can imagine how many users are exposed. We believe that the real problem statement is not just protecting against scams, but it's the way we deliver that protection and the way the users experience that protection. At this point, to take us deeper into the scam pandemic, I'd like to call upon Laura Kankaala. Thank you, TL, and really happy to see so many of you here. It's such a horrible weather outside, so happy you made it here in one piece, and happy to see all of you online as well. My name is Laura Kankaala. I work as Head of Threat Intelligence here at F-Secure. What that means is that me and the teams that I work with, we try to understand what's plaguing the internet when it comes to cyber threats, problems, scams. I've been working here at F-Secure for several years now, two years, actually. Before that, I worked as a cybersecurity consultant. My day job was to hack into companies to find vulnerabilities that could be exploited so that those could be fixed before anyone else gets in. When it comes to scams and what TL just said, I find the world that we live in today quite worrying because this used to be the standard level of scams. You would get an email or message, broken English. Finnish is my first language, broken Finnish would be the way that you would detect a scam. This is the world that was once, but it is not the world that we live in today. That is thanks to AI. With AI, it's, I hate to say it, but AI makes cybercrime more easily accessible. Even if you were not able to write a perfect love letter in the past, now you can do that with the usage of actual, legitimate AI tools. I'm not talking about tools that would be developed by cybercriminals. These are tools that are made for all of us, but cybercriminals and scammers, they have found a way how to use them to benefit their means. Today, actually, scams and cybercrime can be very, very convincing. Actually, it's the most convincing types of scams that get you. By looking at something, you are no longer able to tell if that is a scam or not. You can generate convincing text in multiple languages, images, audio, video. This is a deepfake. Well, I'm deepfaking our Principal Research Advisor, Mikko Hyppönen, here. This is the capability available already today, and it is only going to get better with time. While video deepfakes are still a bit more difficult to do, that is bound to change, thanks to the advancement of that technology as well. What is already very, very easy to do is, for instance, voice scams, cloning someone's voice. With one minute, 60 seconds of my own audio, of my own speaking voice as sample. I'm using, again, a legitimate tool to create an AI voice scam of myself. Now I'll play it. I have written here, "Hi, I'm Laura. I'm information security professional and an ethical hacker. Send me all of your money to my bank account." This is now something I want AI to read in my own voice. "Hi, I'm Laura, an information security professional and an ethical hacker. Send me all of your money to my bank account." Convincing? Yeah? I think this could fool my mother, even. The reason why I'm giving this specific example to you is that here in Finland, and globally as well, we are already seeing how these sorts of AI voice clones are being used to manipulate and trick people to do something that they shouldn't be doing. AI is just one part of the bigger equation that I see. AI makes it easier for anyone to create their scam context, to make it look good, to make it look convincing to people. That's not all. Today, this all relies actually on this ecosystem of different types of technical tools and capabilities that are available to essentially anyone. Anyone can go out there and buy a piece of malware. You don't need to be tech savvy to do crime online or scam people online. It's not only the piece of technology, but around when people are selling these pieces of technology, what they are also selling is knowledge. They are sharing information of how do I get people to install this malware? How do I steal people's data? This ecosystem is growing, and it is getting more mature. Not only that you can buy stuff, you can also get stuff for free. You can just Google, for instance, toolkits you can use to do phishing attacks, stealing people's information, pretending to be well-known brands and their websites. All of these things are available to anyone and with very little effort. AI, combined with this ecosystem of technological means of scamming people, that is the dangerous thing that I see. When those things are brought together, that is actually why we are seeing this scam pandemic. Here at F-Secure, we of course realize that malware and phishing, those are by far not the only means that scammers are exploiting and using when they're trying to get to people's information. That's why when we look at scams, we want to look at them more, I should say, holistically. We want to look at the scam, like all of the steps of a scam. We call this, well, here we are calling it scam tactics and techniques framework, we are also calling it scam kill chain. We are analyzing each step that goes into a scam to understand what are the techniques available to scammers. When we understand these building blocks that go into, for instance, how do scammers define the group of people or the individuals that they're going to target? How do they create the scam itself? How do they contact people? How do they hide their identity? How do they get access to people's data? How do they manipulate people? How do they spread the scam even further? Finally, how do they monetize the scams? By understanding these building blocks, we can actually have a better look at scams overall, because our aim is to understand all of the scams and their building blocks, because ultimately, no matter what the scam, the main purpose is to exploit technology in a specific way. If we can understand those ways, and when we understand those ways, we can build better protections. That's all. Thank you. Thank you, Laura. That's a scam, right? Building A feature or B feature and calling it Scam Protection is not really Scam Protection. We have to think about how we protect users from that. We'll come back and use this reference when we speak about the portfolio later, just shifting the focus a little bit on how are we shaping the portfolio, where are we focusing our investments? I want to call upon maybe three topics on how we're doing that. The first is that systematic shift from point solutions to a holistic and a seamless portfolio. We've also been there. If you recall my introduction slide, there was a time where you needed to solve some of these problems point. Very quickly, we have realized that if you want to address the umbrella landscape of scam and the umbrella threat that it poses, the only way you can respond to that is by building a holistic and a seamless portfolio where you can mix the capabilities in a form that responds to the entire scam kill chain that Laura just showed. That's the biggest shift that we have made, and Total today is a great example of that. If you look at the Scam Protection, which already Timo has highlighted, it's really our biggest area of focus and investment across the board. What's important to understand is that we are not just looking at researching and developing technology capabilities to protect users against scam, but we are equally researching the user experience that is needed to protect our consumers against scam. We also deploy what we call research to production model. While we absolutely have long-term research that is happening, but we do want to make sure that to stay ahead of these scamsters for the kind of tools that Laura was just showing, we need to be really quick in bringing new concepts, innovation, and research faster to our product, hence to partners, and hence to consumers. That's the model that we apply. Lastly, I think our focus on investment would be incomplete if I don't say that the third element of our focus is AI. With a twist. What I mean by that is, of course, this AI has come into prominence in the last couple of years with generative AI. We've actually been deploying AI in production for over 15 years now. From the early avatars of it, which was machine learning models, now to generative AI. Our approach to how AI is brought into the technology and product is we don't spray paint AI and then look for which problem can we solve with it. We are actually applying AI to problems that AI can solve. A great example of that is our Scam Protection module that is live today and already protects users from an SMS-based channel. It's in production. It was the award that Timo was referring to, is fully backed by an AI. This is not just an AI that is looking at how to improve the efficacy of protection, but it is actually understanding the context of the message. We are one of the very few and rare cybersecurity providers who has actually put this into production. Not dabbling on the sides with AI stamped everywhere, but very real results to show. That's the way we want to tackle and bring AI to the market and look at how users benefit from it. What these three subjects put together give us is a truly comprehensive and seamless portfolio that goes across platforms, whether it's iOS, whether it's Android, whether it's Mac, Windows, Linux. It's a portfolio that's enabled by our Research and Protection Platform, which has AI at its very core. Think of it like an engine room. It's an engine room where we have our foundational security capabilities, whether it's how we protect devices, how we protect users' identities, their privacy, how we protect smart home, and now, of course, how we protect users from scam. That's where we build our core capabilities. These are rendered as value through two product segments. One we call Total, which reflects F-Secure's experience and our intended experience for users. While I say that, it's something which partners can fully make their own. That's what many of the segments that Bruno referred to earlier already use today. It's also one of our biggest differentiators, that without breaking any code, we allow partners to customize and make the product their own. Scalability and repeatability is at the cornerstone of how we grow. Our portfolio is designed for that. The other aspect is Embedded. Embedded is about building or pre-building, let's say, the capabilities coming from the engine room into SDKs. These are like the building blocks that our partners use to build their own application. In that role, not only are we providing these building blocks to them, but we actually help and support and influence, in some cases, the experience that they want to deliver. There we are sharing our best practices. We have a very strong design team that consults partners on how they should bring this experience to life. The range of partners that this portfolio serves goes from the biggest ones, the likes of AT&T, and their product being called Active Armor, to super apps that we have done with fintech partners, to managed Wi-Fi providers. I can see many familiar faces in the room because I know I saw and met many of you last year. If you recall, I don't recall if I had the same slide or a different version of it, but we put this up last year and we set ourselves two key objectives. On Total, we said, how do we bring the best of Lookout Life and Total together? How do we launch Scam in a unique way? How do we really raise the bar on experience? That is what we had set our objective for Total. On Embedded, very simply, we wanted to build the broadest portfolio in the industry. Now, the question is, how have we done? To answer that question, I would like to call upon Eero Kukko and Niko Kiukkonen. All right. Thanks. It's been amazing year with Total. We've integrated Lookout, we introduced our first AI-powered Scam Protection capabilities, and we have even updated our user interface. It's better for the consumers, but it's also an industry benchmark in terms of flexibility for our partners. Let's look at some of the latest capabilities in a little bit more detail. One of the most common types of online scams is a shopping scam. A shopping scam could be a faulty product that you can't return, it could be a product that never arrives, anything in between that. It is extremely difficult for the consumers to avoid these scams. We see these in search results, we see these in sponsored links, in ads, and we even see influencers promoting shopping scams. It is really difficult for the consumers to actually detect what shopping site is a reliable one. From our point of view, we are actually combining multiple different sources with our AI technology to create the most comprehensive analysis of a shopping site. This is a great technology to understand shopping scams and detect them. While it is a great piece of engineering, it is actually not enough to keep the consumer safe. Why not? The reason is that we are all busy. Even if I provide the latest information for the consumers, they do not have time to open another tool. They do not have time to start reading about the site reliability. We are all busy. The protection needs to be seamless, effortless in the moment. That is why the Shopping Protection is integrated into the browser. As soon as you enter a shopping site, you'll see the site analysis directly in the moment, so you know if you're on a reliable site. It's available for all of your devices. We have the support in Windows PCs, on Mac, on Android, and iOS. There's no waiting, no additional clicks or effort required from the user. As soon as you enter the site, for example, on mobile, you see the icon, you can freely move it around, and you can even actually press on it to get more information about the shopping site and the reliability if you're interested in that. If you go to a banking site, the icon will actually turn into a banking icon and show you that this is a reliable banking site. We also turn on the banking protection, so we prevent other sites from stealing your data or remote access connections to the device. This is all effortless to the users. You're always protected without any additional effort. For the SMS, you already heard that we've introduced the award-winning AI-powered SMS protection. The important thing here is that while the competitors are looking at malicious links coming in the SMS messages, we are actually looking at the entire message context. This means that we can detect malicious links, but our AI can also understand if this link is related to the message context. Let's say you're getting a message from a courier that a new package has arrived, click on the link to agree on the delivery, but the link is actually not taking to the courier's address. Our AI can detect this and automatically decide that, hey, this is actually a delivery scam. Because we've trained our AI with multiple types of malicious SMS messages, we can also detect SMS messages even if they don't have a link. Once you have this protection on, it's seamless, always on, and protects you without any extra effort from the user point of view. Now, finally, on the UI side, while our updated user interface is better for the consumers, it's also amazingly flexible for the partners. Our partners can freely decide what are the capabilities they want to show on the client. They can change the look and feel, the colors, the branding. They can even change the corner radius of the different elements to make it seamless integration to the rest of their portfolio. This is not something that we just built on the main screen, but it's actually a key part of Total, and it integrates to the Total user experience. The latest addition here are our partner quick actions. With these, our partners can actually bring their own services and their own applications directly inside Total. This is a way for our partners to further differentiate their offering and promote the services and applications that they have. I hope you're as excited as I am about Total, but if our partners want to build in their completely differentiated user experience from the bottom up, we have our embedded offering. Thank you, Eero. Yeah, let's take a look next into our Embedded portfolio. As you heard already, Timo and Bruno explaining why we are so excited about our embedded portfolio, as well as what type of opportunities we see here. I'm going to cover what type of actions we've taken in order for us to come up with this portfolio during the last year, as well as what we have learned while working with multiple strategic partners around this portfolio, and also why we have a good reason to claim that our embedded portfolio is the broadest, the most holistic, as well as the smartest out there. Let's start with the broadest. What you know today has the most holistic security application, i.e. our Total. We have taken those individual security experiences and converted those to be available in form of embedded SDKs. That also, of course, includes what Eero just presented, so the Shopping Protection, Scam Protection, both available in form of embedded SDKs as well. That's not all. We have also already productized embedded-first SDKs, which are available for our partners in form of an SDK that we don't yet even today have launched with our Total. That makes the portfolio the broadest one. What we are also doing to make it also holistic, we are not focusing on creating these SDKs under single security experience only, like for example, identity. We cover all the different security experiences. We protect the device, we offer the Scam Protection, we have the home security for the routers. That makes our portfolio then also holistic. Why this is then important? Well, what we have is also the flexibility. Partners have the right and freedom to pick and choose from this large number of different SDKs, the ones that are fitting the best into their branding, marketing, app needs. It's not only that, due to the fact that we have large number of these different SDKs, that enables also huge number of unique combinations of these SDKs to be built in form of the applications. That allows our partners to differentiate, which is hugely important. One aspect of that differentiation is visible here. If you look the application samples here, on the left-hand side, there is a security power app that takes many of our SDKs, integrates it together, and offers a holistic security proposition towards the end users. On the right-hand side, there is a fintech app, which just integrates our identity experiences together with the financial-oriented application. In the middle, there is a Wi-Fi management app, which takes our home router security and integrates that to be part of the app. Bruno already mentioned the importance of the router security in our portfolio. That's also one aspect of this holistic portfolio what we can offer. Our CSP and ISP partners are expecting their providers to be able to cover all the products from security solutions point of view, what they offer to their end customers. This broad portfolio what we have, makes us really a unique provider in the market. We are one of the few ones that can offer this holistic proposition for our CSP and ISP partners. It's not only the number of SDKs that matter, and now we come to the smartness angle. We apply our partner first across the Embedded portfolio as well. One level of smartness that we implement is within the SDKs themselves. We are offering cross-SDK experiences out of the box to our partners, so that, for example, if you place your personal information to our secure vault, that same information can be also used to trigger and activate your identity monitoring. These are seemingly small things, but very important for a good user experience, and this is why and how we help our partners here. The smartness is also part of the tooling that we offer. This was also mentioned, I think Timo mentioned our developer portal. It's not only the documentation that we offer for our partners. We also provide purposefully built tools, like our sample app, which has testing capabilities for the developers, so that they can fast and easy manner verify and validate their designs. With this whole thing, we can then enable our partners to ramp up these experiences fast and easily. It is not enough today to have only these SDKs. What we are doing behind the scenes, we are also enabling cloud-to-cloud integrations against our existing partner cloud infrastructure. That is important for them to be able to activate the users, get the notifications to the users, build insights based on our data combined with their application data. This is where we have done big steps as well during the last year. It does not even stop there. We also provide our partners the possibility to benefit from the decades-long experience what we have in terms of building great user experiences on top of the security products. Many of our partners do not have that capacity or competence. We offer them with UX consultancy that they can benefit from in terms of creating the best possible UX when they combine our security features with their unique application capabilities. We are also supporting them naturally in their application development, pre-launch, go to market, post-launch activities. In two words, we care. This model that we've applied, we've gained very good feedback so far. We have also implemented already many improvements. We will continue doing the same. We are not saying that we are ready here, and we are definitely not stopping here. We are continuing to improve this for our partners. What we are going to focus next, like it was mentioned already, our target is to bring more and more of the innovation in form of SDKs to be available for our partners. Here I can refer to Laura's excellent presentation, what you can think of what we are planning to do there. We are going to increase the usage of AI across the embedded experiences. That's important for us as well, as it was mentioned by TL as well. With that, I ask TL to come back and take it over from me, please. Thank you. Thank you. Thank you, Niko, and thank you, Eero, again. Just to put this in perspective, everything you heard from Niko is give or take 15 months. It just reflects what Timo said, the breakneck speed. The necks are still intact, we're certainly going fast. Before we go to the growth dimension of how the portfolio is driving growth, I want to add a few maybe aspects to the portfolio. Niko spoke about the holistic nature and how we are bringing these capabilities together. I want to bring back a point that Bruno mentioned in his section about the opportunity with convergence. Convergence is really about converging the user experience to begin with, right? The way we look at Total embedded within Embedded, all of it being powered by the same engine room, which we call Research and Protection Platform, is fundamental for convergence. Right? I think there was a question in the previous section. I think Bruno mentioned that we are one of the only players who can bring this together. This, again, speaks to why and how the portfolio is positioning us well to capitalize on the opportunity with convergence. So far, you only heard the broadest portfolio. From this slide on, it's also the smartest. I think that's important to note. I'll conclude the portfolio section with one key distinction. I go back to the slide that Eero had shown, and I want to play out a couple of scenarios for you. There is a webshop. As a user, let's play this out. As a user, there's one option where you go to a webshop, you do your shopping, you browse an e-commerce website, and you have a nice, beautiful icon that tells you that you are safe. Scenario B, you are a user. You go to a webshop. You take out a camera. You're actually on the phone, so you take another phone. You take a picture because you don't know if this is a real webshop, and you send it somewhere. You wait for it to tell you if this is a good webshop or not. Which experience do you think the users will want to adopt? Any guesses? Maybe I can guess for the whole room. I certainly want an experience that is non-intrusive, does not bother me with what I actually want to do, and does the job of protecting me when I need it. If I were to summarize the portfolio, I would say that is the difference between F-Secure and what everybody else is doing, at least with scams. Okay. Let's talk about how the portfolio has been driving our growth strategy, right? We spoke also last year, and I think Bruno mentioned it in his section, there are two key pillars of our growth strategy. One is how do we drive greater value and growth from our existing install base? Right? We have a huge number of partners and consumers behind them. How do we consistently move them to a higher value product, and that impacts ARPU and growth? Last year, we have increased the annualized ARPU with Total by 9% in the partner segment and by double digits in the direct consumer segment. Not only that, of all the users that we have, of course, on Security Suite, 24% of the users are now on multi-module Total. That means these users have access to a minimum of two value modules from Total. We have more modules, right? Just to put this in context. This number, when we met last year, was 9%. Between when we met last year to now, we have more than doubled the number of users who are on multi-module Total. Across our entire base of partners, 42% of partners are on multi-module Total. Overall, I would say we've had a good year with Total and driving the strategy of value from our install base. Having said that, I think both Timo and Bruno noted the opportunity that still exists. There is still 76% users available for us. Realistically, maybe all of them would not get there, a sizable portion of that number remains as an opportunity for us to drive value and growth from. This is both from moving the existing base to a higher value, but also upselling newer value-added modules and features into that base. That will continue, especially into the major accounts and commercial accounts, where a bulk of these partners sit. Our second growth driver was with Embedded. How do we get scale? How do we go after scale? Of course, led by our strategic accounts and the Tier 1 strategy, how have we done? Not only have we built the broadest and the smartest portfolio, we're actually delivering it to four of the 10 Tier 1s globally. You can see that as four of the six that were mentioned earlier. We are delivering this portfolio to them. That is giving us access to 20 million monthly paid users, approximately. Needless to say, there are many more opportunities in the pipeline to follow. On Embedded, we've had a very good year. Not only in terms of building out the portfolio, but actually playing out the growth strategy in terms of accessing scale. Bruno mentioned about the standardization of the routers. I would like to add that F-Secure is also a part of the prpl Foundation, along with all the carrier names that they will mention. We are actively in both the prpl and the Broadband Forum, contributing and influencing and in that standardization process, which means we have had a portfolio that's ready for prpl. We already have RDK deployments. We are ready for this Android moment from a portfolio point of view. The other dimension is even more interesting. We've been actively investing, and if I may say, have built the biggest ecosystem of partners in terms of auto manufacturers, Wi-Fi providers, and they will all, at some point, move to one or the other. Between them, that's giving us access to more than 50% of the CPE market. Overall, if you look at both the portfolio dimension as well as the ecosystem dimension, we are well-placed to capitalize on that opportunity. I want to close by talking about our approach that we're going to take. Timo touched upon this sort of combination of security and how we secure the users, but also how we do it. That is an approach we call Trusted Companion. We truly believe it's a very unique approach that looks at not just protection, but focuses on truly reimagining how the consumers will experience this protection. If you look at where it begins, it begins with going back to the word we have now used across all the three sessions, holistic. Users expect a holistic and a seamless sense of security, where we prevent scams, protect users from scams, and in those rare cases, are able to restore and support consumers financially and emotionally for those who do fall victim, unfortunately, to scams. The prevent part here is quite interesting because I think it's been sort of underplayed in general, I feel. If you think about getting the right information, relevant information at the right time to users, we truly believe that we can prevent users from even getting onto a list of victim. That's where the protection starts. With protection, of course, what you see at the center, these are not features. We don't do URL protection and call it Scam Protection. This is shopping scam, banking scam, investment scams, gaming scams, romance scams, employment scams. I refer back to the picture that Laura was showing. That's the scam. That's going to need a lot more than one feature to try and solve it. That's the protection we want to offer. What you have seen already in Eero's section with Total and SMS Scam Protection, I think there are three extremely critical elements that makes this approach unique. It's the how we deliver this protection. I again go back to that example of how do you want your shopping scam to be protected? Do you want to keep taking pictures, or do you want it to be in the moment? Of course you want it to be in the moment. That is extremely important. We do not want users to be distracted, disturbed from what they're actually wanting to do. We want to deliver an organic security experience. It's our job to know that there is a scam attempt. It's not the user's job to know that this might be a scam. If they already know if this is a scam, well, then what good is the product? I think that's the important part of where it shows up. Context. I already mentioned with the Scam Protection, for example. It's not enough for us to know the channel, the context of which channel is being used for scam, but also what is the intent? To go to the steps that Laura was showing, we will have to learn and predict that this was intended to be an investment scam so that we can give and take the right next actions from there. That's how the context plays an important role. Finally, we all live, I think, in a world where everything we consume digitally is personalized. Can you imagine Spotify not telling you what you want to hear, or Netflix not showing me the content I want to consume? If entertainment can be personal, security, which by default should be personal because I behave differently than probably everybody else in this room, I want my own security profile, and that's what brings us together. I'll finally say that in addition to the core capabilities, when we speak about research, there are foundational capabilities that we still need to add. Some of them are already existing, but we need to keep enhancing and going deeper and deeper in those. These are about right from the channels that are used for scam to how we can crack social engineering. How do we truly understand how scammers reach the victims, and how do we get behind those? As you can imagine, all of this cannot be done without AI. The contextual, the personalized, and understanding social engineering. These are areas where we will apply AI. That was my section. Before we go to the Q&A, we would like to play a video for you that I think very well summarizes what you've heard from us since morning, and I think truly captures our passion for security experience. Scams aren't just evolving, they're exploding. They're smarter, faster, nearly impossible to detect. When others see chaos, we see patterns. While they see confusion, we see clarity. We don't just fight scams, we understand them. For millions of people, staying safe is complex. It shouldn't be. That's why we're making it simple, seamless. We're revolutionizing protection, using AI not just to react, but to predict, not just to defend, but to prevent. Working silently, tirelessly, protecting your every move. We're not doing it alone. Together with the world's leading service providers, we stand united across continents, connected across cultures, protecting millions who dream, create, and connect every single day. This isn't just about security, it's about trust. This isn't just about technology, it's about transformation. We're not just changing how protection works, we're changing how the world stays safe. Every digital moment, every connection, every time, F-Secure it. Thank you. That was all about the portfolio. I can take some questions, and maybe I'll like to invite all the other speakers on the stage as well. Hi, Walter Rossi from Danske Bank. Just to make clear, at least to myself, is it so that the Total portfolio is meant to be addressing major and commercial partners, and then the Embedded is for Tier 1s? I would say that there is no hard line that says that Total is not usable by tier 1 partners. We have some that use Total. There is no restriction. We're not drawing any boundaries of what portfolio is used in which segment. That's why we call it a portfolio that's truly seamless. If I look at where there's a more natural affinity for which partner is looking at what kind of portfolio, I would say that major and commercial accounts are certainly inclined more towards Total, strategic accounts and strategic partners are inclined a bit more towards Embedded. We absolutely see the possibilities of us to take this portfolio across all partner segments. In fact, in the Embedded pipeline, we already see some, let's say, major account and major partners who are seeing a business case, and they're seeing the value of building their own services. There is no hard and fast rule, but I would say that the inclination is towards that. All right. Thank you. I actually have a question for Timo, but he's not there, so maybe I'll save it for a while. Hi, Felix Henriksson from Nordea. A couple questions. Firstly, on the clarification on the ARPU uplift figure that you said 9% year-on-year. Was this referring to the increase in your total ARPU in the partner channel? Previously you've talked about + 20% ARPU uplift per customer when they shift to Total. I just wanted to get clarification there. No, actually, what we have said in the past is that when we shift the base to higher value, the ARPU impact on a per customer basis is expected, and we see anywhere between point or 20% to going up to 80%- 100%. That's what we have said, and that is still true. What 9% represent is the annualized ARPU. Why? Because the partners adopt Total at different points time in the year. In many cases, they are looking at first introducing the multi-module Total to only new customers, whereas the base is still remaining on the lower value ARPU. In some partners, they are moving the entire base to the higher value ARPU. There are different considerations. When you annualize this entire and average this out, we have still seen a 9% increase. That's what it means. Got it. That's clear. On scam protection, you're not the only consumer security company that talks about it. Do you feel like you're a frontrunner in this area, or have you been a more reactive player to what the competitors are doing? We think we are absolutely a frontrunner in scam protection. For some of the reasons that I mentioned, again, I would not claim that we are the only one talking about it. Certainly, our competitors are talking about it, but they're talking about it in the context of, like I said, it being another threat, another problem that needs to be solved with another app. The other perspective being that the experience of the way our competition is looking at it is very much that the user needs to know. That is what I think fundamentally separates us from what competition is doing. That's the area of research, and that's the area of differentiation we are absolutely going deeper into with our investments, with our research, both on UX and experience as well as technology. Got it. Finally, can you just at least refresh my memory on the economics of the Embedded Security business? How does the revenue model work and the revenue sharing with the partner there? How do you make money on that business? I'll hold that question because Sari has specifically, I think, a slide just to answer that. Okay, fair enough. I look forward to that. Thanks. Hi, it's Matti Riikonen, Carnegie. Related to the economics of this Embedded Security and additional contracts in Tier 1, what in practice do you need to do when you sign a new contract? What kind of investments does it require from your side? When it starts to run, is there a step increase in the hosting costs, additional dedicated team? Where does the cost base come from in addition to the normal investment in R&D? I won't speak to specific numbers. I leave that for Sari. I think like Timo mentioned, the last year has been, of course, a year of very focused and substantial investment because we had to get the portfolio to this point. The principle, not just with Total but also with Embedded, very much remains repeatability and scalability. I think the breadth of the portfolio we have now allows us that, let's say, a massive proportion of the scope tends to be coming from what we have. In that sense, the investment, I won't call it investment, let's say the cost associated to when we have to deliver a project are around that project, which means there is work to be done to do some specific integration. Niko spoke about cloud-to-cloud integration. There could be a variant that the partner has. That's just honestly business as usual when it comes to such sort of projects. It's not that we have to create a portfolio every time we win a partner. I think that is the investment we made last year already, and now we are scaling this out with the existing deliveries that I mentioned and as expected, also with the cases we see in the pipeline. All right. Thank you. We have no questions from the line. All right. Thank you very much. I'll call on Sari. I think he had still a question. I missed completely. Yeah. Atte Raita from Inderes. Maybe just a quick product-related question. At least I have seen lately news about those QR code scams. Is there some business opportunity or idea to build some capabilities to your scam protection product for that? I think I have the perfect person to answer the question. Laura, do you want to take that? Yeah. Sorry. Yeah, for the QR codes, that is an interesting topic, definitely. For us, we see QR codes as links. What you do when you scan a QR code is essentially you open a link, and fortunately, we have already plenty of capabilities to detect those. In some instances, of course, we could think of some further innovation, but I will have to give the boring answer that QR code is a link, and therefore, it's a rising threat for sure, but we already have a lot of capabilities around that. All right. Thanks. Yeah, we are prepared. Again, I think I go back to the point, maybe slightly different aspect of the response is that that's the reason why we're building the engine room of capabilities, because like Laura said, QR codes are a combination of links that are out there to scam you. The answer is not that what are we doing for QR codes? The answer is that we have the core capability to respond to a scam that's based on QR code, but look at it in this holistic dimension. We are well-placed to respond to that as it scales, the problem scales. Now I'll wait if there's anybody I missed. All right. Thank you very much. Sari. Thank you, TL. Good afternoon. I hope you still have energy for the final part of this day. Main part of my presentation is to talk about our updated medium-term targets, which we published yesterday, and I will dig a little bit deeper into some of those areas, then a couple of words about the ESG area. This is what we published yesterday, updated medium-term financial targets, and the four areas are exactly the same as before. I'll start by just going through what we actually are saying here. In growth, it's two parts, high single-digit growth, which is those of you who remember, that's how we started with the independent F-Secure, the same target as we had. You heard Bruno talk about the industry growth around 6% and how we see that it can be higher than that for ourselves being focused on partner business. We feel this is a reasonable target and this is where we aim to be without any significant changes and additions. There is the addition that there is significant upside from major Tier-1 deals. This comes back to this Tier-1 business that we've been talking about for the past year. We see there are big opportunities, but there are many ways how you can call this business. We have talked about binary and digital and lumpy business, where it can take a long time to get a deal. It can be a long time, and we don't know whether we actually get it or we don't. We don't know if it takes half a year or if it takes two years before we can launch something. We can have several scenarios, but there are multiple outcomes, and that's why it's really difficult to give a number like we had in our previous guidance. What the significant here means that if we have a significant deal, then that's something that we would publish as a stock exchange release. Exact numbers, what the threshold for that is also a bit challenging because the ramp-up times of the deals are different than the lengths of the contracts. Let's say that we talk about tens of millions during a contract period, which could be three years or five years, sort of ballpark type of numbers. Profitability, adjusted EBITDA margin approaching 40% as revenue reaches EUR 200 million. Here is the EUR 200 million that we've mentioned before, which we still believe that we are going to reach. The point here is that you don't see a year when we are there, but there is a size. We are in a scalable business, and our profitability scales with the size of the company. That's why we wanted to present it in this way. Dividend policy, similar to what we said before, around or above 50%. There is this addition that which can be adjusted as long as leverage is higher than the targeted level, which is basically now. We are now in that situation still for a while when leverage is higher than the targeted level, and this gives us the freedom to have a lower dividend. You have asked us many times that how does the liquidity work with the high dividend and loan repayment. We have also seen that there is a challenge to combine these, and that's why we have added this. Leverage target remains the same, that we want to get lower than the 2.5x. What has then changed here if we look at where we come from? First of all, you see that we have taken out the time perspective that earlier we said that this was by 2026. Now we don't, we just say medium term. Of course, medium term is still the three years ballpark. Now this can be valid also next year for the next three years. In terms of the growth, the positive thing is that we see that there is a strong Tier 1 pipeline. It is in our hands, and we really believe it will happen. The lead times are long. We've been mentioning this in a couple of our interim reports already that we have some challenging customers that have then offset the good things that happen in the other areas of the business. In that sense, we are a bit late from our original schedule. Also, I think it's really important that there are multiple scenarios. This is something that we are learning also internally to deal with the scenarios. There is a scenario that where we could reach the old target as well, but it's maybe not the most likely scenario, and it might take a bit more. Definitely we are going for the EUR 200 million. There is no question about that. The profitability. Still remains the fact that this is with high gross margin, even if it's lower than earlier. It's a very nicely scalable business when we grow. We have now made lots of investments into our capabilities, which you have seen in the profitability and in the OpEx levels, CapEx levels. That has maybe been the key reason why we have now come from 42%- 40%. Again, if we grow more, so we see that it will continue to scale. Then there are these ramp-up impacts. I think most of the cost ramp-up has happened. Of course, when business grows, we still need to do things. In that sense, we are not ready, and we have the ongoing restructuring in the company where we are also saving money to invest again more. There are capabilities at our maturity that we are still working on and the customer projects. Really, when we mentioned on the previous page, actually, there was the subheader which refers to this 2025 as a ramp-up year. That especially refers to the top line. When we say this in terms of CAGR, our growth, so you should not just use a ruler, but can assume that leveraging the pipeline and ramping up the ongoing customers will take some time. Not the fastest yet next year, but definitely believe in the future. In dividend yield and leverage, so this liquidity and debt repayment are facts of life that we are balancing with those and what we will propose for dividend next year so that you will hear then when we release the results. Now we have some freedom here. In terms of the debt repayment, so originally the loan we took for the acquisition was 3 + 1 + 1 years, and currently we have exercised already one of those options. After four years, we would have some EUR 100 million still of the loan remaining. If we use the last option, so then five, it's around EUR 70 million. We need to refinance at some point anyways. The question is that how and when we do that. PPA amortization, so of course, they are not visible in EBITDA, but will have an impact on our EPS. There the lifetimes are 5 to 15 years, mostly 15. Those will continue for quite a long time. If we dig a little bit deeper into the revenue part and especially around the Tier 1 dynamics, which you have also asked about several times. A little bit going through with what kind of components we have there. The same components also can exist in the major and maybe not so much in the commercial partners, but major. In that sense, nothing new, but now as the numbers are so big, so good to go through. Not in all, but in many of these deals, there is this NRE fee, non-recurring engineering, could also be called a setup fee or project fee, but NRE is typically used. There when we sign a contract, after that we can invoice this, and it's recognized over the whole contract period. Let's say it would be contract three years and it would be EUR 1.5 million. It would be 500,000 per year that we get revenue from that. Big difference between cash flow and the actual revenue. In many of these, we have annual maintenance fees. There are some cases where actually the whole service is paid on annual basis. That's not the norm, but something like this can exist, and then those would be invoiced once a year, starting from the time when the service is launched. Again, invoicing only once a year and then recognized over the period. Of course, a bulk of our revenue would come from the actual services, which are typically based on subscriber numbers. Sometimes there could be revenue share, but often it is a price per subscriber. These cases, billings and revenue equal each other on monthly basis. In that sense, it's simple. If we start with the new service, for example, this case that we announced in March, so it is a new service. The success of it depends on how successful the product is, how do consumers appreciate it, how well the marketing goes, how much marketing is done, and so on. Normal business ramp-up. There are cases where it could be actually either an existing product, which we maybe can take over from a competitor. That also can happen in this business. Either through some kind of stepwise migration or even overnight. We could not start from zero, but start from a bigger amount. After that, again, it's normal evolution of the product. From revenue point of view, could be a similar pattern if this is part of a bundle. Again, there is immediately a base that we get paid for. Of course, the business logic is very different because then it's not only our product, but the whole bundle and how that works. Typical components and the way how this works in our revenue. If that was more for the strategic tier 1 partners, so then of course, this total that we have talked about is also very important and more in the major and commercial partners. Here in this graph, on the left-hand side, you see the bar that we showed last year when the multi-module Total was 18% of this total revenue. We have made here huge progress. Now it is already 47% of the aggregated amount here. That, of course, is a bigger number than the number of subscribers, because here the ARPU is higher. The aspiration is that we get rid of the purple part, which is like legacy platforms, legacy products, but we expect there to be some maybe use cases or then some slowness where it remains as a single module product. Clearly, bulk of the revenue should be in multi-module Total. A couple of words relating to the reporting of the Lookout Life acquisition. Since the acquisition, we have reported the organic growth, so the old F-Secure growth numbers, and that we will then discontinue at the end of this year, because now the years have not been comparable, so it's been logical to tell that. As of next year, so Lookout Life has been also 12 months in the comparison period. Good to remember that it's still not quite apples to apples. You see this purple part in this graph, and it is numbers that we have told in our interim reports, but might be sometimes a little bit challenging. Related to the accounting after an acquisition, so the deferred revenue is fair valued, and that has had a major impact still in Q1 this year. After this, the numbers are smaller and will continue until April next year. Now the 0.2 or 0.3 just in the middle of those numbers, so it's related to the AT&T deal, and then the original contract ends then. We have a new contract with them, so don't worry about that. Good, too, if you want to compare apples to apples, so you need to take into account those purple numbers. Looking at the funding and what we do with our cash flow. Of course, the first thing is that because we want to grow, we need to fund the growth, which we have been doing. We look at Rule of 40. We want to ensure that we are optimizing the profit and growth. Here we have actually used, during the last couple of years, a little bit more, both OpEx and CapEx, to ensure that we get the future growth that we really believe in. What is left after that, so we have the debt that we need to take care of. You see that the leverage has gone down, but now at 3.1, still way to go to get to the 2.5, which is the target. That we are working on, and then balancing that with the dividends that we have been already talking about. Typically you also ask about M&A. I would say that this is not the focus area right now. We see plenty of internal opportunities, everything that has been talked about during today. If there is something that would be appealing, it is within the Scam Protection area, within AI, and anything where we could deliver relevant differentiation. With this leverage situation, so of course, currently the financing is not obvious, so it would be something smaller. If there is something bigger and super relevant, so then we would need to think about the merger option rather than acquisition. When the financing situation gets stronger, and we get to the leverage target, so then of course there is more freedom again. About the Lookout Life, so there, of course, integration has been completed, like we have said, and the synergies are tracking quite well. Any new Tier 1 opportunities would be counted as these synergies. Just a couple of words about the ESG. Here, of course, from reporting point of view, this is a major topic and things have changed a lot. Already the 2023 sustainability report was much more extensive than what we started with, but now it will really be a lot. Of course, it's done based on the regulation, and I think that probably the sustainability report will be around 160 pages or something like that, so plenty to read. I think earlier there's been some questions about how we are disclosing things, so then I believe that then we are disclosing everything that is needed. Our key commitments remain the same that we have talked about earlier. This about protecting digital moments, protecting people. We see that we are in a very nice business because our business is already very sustainable. When we get the question, do we have sustainability incentives? We actually see that looking at our revenue growth, that is a sustainability metric. Also in our incentives, we look at the employee satisfaction. That is also. There are basically two sustainability metrics on our agenda. Of course, responsible business, that covers corporate governance, where we need to do things right, but this is also where we see the environmental part. Our footprint is pretty small, but of course, we need to deliver our own share. We are still considering the SBTi decision, but targets are already aligned with CSRD and Paris Agreement. Fellow experience is another part of this social area, so of course, it is important that we take care of our Fellows. In our cost structure also, Fellows are the key, and they are the ones who are actually building our future, so we need to ensure that they are happy. Key takeaways from F-Secure equity story. We are a scalable, highly profitable SaaS business and with a very strong cash flow. We are already now a global leader in the CSP channel. We've been that already for a while in the Tier 2 and 3 segments, but now we also see a path to the Tier 1 area, and we are very well positioned through our partnerships. I hope you have enjoyed this message today, and now we can all take questions. Oh, sorry. Actually, Timo will say a few words before we take the questions to everybody. Timo always has a few words to say. Yeah. I hope that we covered now our growth story in a way that you understand better why we believe in what we're believing in terms of our potential growth. As Sari said, we published our new medium-term targets just yesterday, and naturally you need to understand why we use those very numbers and how we believe that those are achievable. We started by me looking at how did we do this year? What is our company strategy? What is the problem we're solving? How do we differentiate from the rest? Bruno went through the market dynamics. Why do we believe that especially what we call strategic partners, the Tier 1s, are the opportunity to capture right now and why we are in a position to win in that market. TL and the team was going through why can we actually offer something in terms of a value proposition and concrete offering that strikes a chord out there in the market. Hopefully, that made sense. I whispered to TL later on that I would buy the story and the goods. Now, that's what we've gone through. I'd like to invite my colleagues over here, if you don't mind, to take questions. I believe that there was at least one question from Walter, which he said that he would like to ask from me. There's at least one. Please. Hi, it's Atte Riikola from Inderes. Still a couple of questions left. Maybe first about the business case where you jump into new Tier 1 and replace the existing cybersecurity vendor there, and you start immediately get obviously a bump in your revenue. Are you having lots of that kind of discussions with different partners and is it a real possibility in the short term? Yeah. I would say that those partners who go and immediately convert their whole base to our service, they are not the majority. That's almost an exception, but there are definitely some which can be really noteworthy. It's not the typical way. The typical way is to gradually grow, which is what we're seeing in 2025. All right. Then about the profitability target, let's say you're still aiming to grow every year, and still you're saying that you need to reach the 200 million revenue level to reach the 40%. It seems like your growth is not that scalable in the coming few years. Where is all of that growth going? Is it ramping up those tier 1 capabilities, or where is the money going? I think that Sari presented it quite well. There are investments we need to make in the generic R&D. There are projects which are taking quite a lot of time. We signed and announced one Tier 1 deal in March this year. That is going live towards the end of this quarter, so it takes quite a bit of time. To ramp it up, it takes, once again, quite a bit of time. There was no previous service that we replaced. It's a completely new service, so it takes time. From our point of view, the Tier 1s provide us with the opportunity to have bigger jumps every now and then. In our typical major and commercial partner world, it's all phased. I would still say that this is a very much volume driven in terms of profitability. We have made massive investments, and we will continue to drive the scam protection agenda heavily in research, development, and promotion, becoming a thought leader in the area. Yes, we are making investments. Growing revenue, better profitability. The scale is there. The scalability is there. Sari, what would you say? I think that was very good. Okay. All right. About the growth target. We know that the market situation hasn't been that good in the short term, how much you're leaning on those targets that the market situation improves? Not at all. All right. Last question. We know that the interest rates have been coming down, how is it affecting your cost of debt? What floating rates and what Euribor is it tied to? Three months Euribor. All right. Thanks. Three questions left. On the growth target, if you look at the current consensus estimates and basically also your stock price, the market doesn't really seem to be buying into the high single-digit figure also because you haven't really been able to demonstrate that level in the past. I guess my question is, you've outlined very well today on your own expectations, but when can we expect to see a pick-up in your growth rates in the firm numbers so that we can get convinced about this target so that it's not just wishful thinking? There is no wishful thinking anywhere in our planning. It's based on analysis and experiences that we have from our business. Our own view is that in 2025, we will still see some more moderate growth towards the end of 2025, hopefully picking up speed. If we land major new strategic partners, that may change the picture, but that is something that we will communicate when those things would happen. When we now announce the medium-term target, so we had this 25 disclaimer, so please don't use a ruler, was the idea of that sentence. Of course, the 25 guidance, the proper outlook will be given then when we announce the full year results. Then, of course, we will tell more. If there are any of these significant deals, so there will be stock exchange releases, and then we will there try to outline how they will ramp up and what of these scenarios that I was showing that what can be expected to the extent that we are able. Great. Can you give us any sense of the magnitude of the drag coming from the declining partners that you've highlighted now more recently? How many millions of euros are we talking about if you annualize that, for example? I think the best we can say is that you've seen negative growth numbers in Europe. Those are the reason for that. There are still the growing Total parts included in those numbers. Okay, fair enough. Finally, on CapEx, how should we think about that going forward, since you have been capitalizing your R&D costs a bit related to the Embedded Security ramp-up? What's the sort of prudent run rate going forward that we should expect? Of course, it's been increasing quite a lot if we look two years back. Now it's manifold what it used to be. I hope that it's not going to grow with the same rate. No exact details about that. The assumption is that if there are clear investments that are related to a customer delivery, those would be CapEx that are amortized over the contract period. As our SDK library develops, it should be less work because something is already available off the shelf, and I hope that the infrastructure type of investments are smaller. At least the independence part is done. Thanks for the presentation. Hi, Matti Riikonen, Carnegie. I go back to the operating leverage assumptions behind your long-term targets. You have tied your margin target to the EUR 200 million revenue rate. Now, the market is expecting roughly EUR 160 million in 2026. I was just wondering then what kind of scalability assumptions you have in the 40% and EUR 200 million. What happens if you deliver just the EUR 160 million? Is your margin going to be significantly below the 40% in that case? Could you give us a rough estimate whether it would be several percentage points lower if the scalability in top line doesn't materialize? Yeah. I'm not going to give any numbers, but if the difference is 160 versus 200, so it is a different scale, so it will be lower. Right. Inside that equation, what role does the sales mix play? If your growth is coming from Total contracts or if it's coming from Embedded Security contracts where the scalability is lower in the beginning, does that play any significance in the margin? If it just so happens that you would get most of the revenue increase from Total contracts. Yeah. Would it then be more beneficial for margins instead of having coming from Embedded Security contracts? Total is more profitable. It's immediately from the beginning. You remember we used to have over 90% gross margin, it's clear that that is extremely profitable growth. The thing with the big tier 1 deals is that as it's price times volume, the volume can be very high, maybe the percentages are not as high, the euros are big. There can be some features that are related to a unit cost that in the ramp-up phase, the unit cost can be higher, when we get to bigger volumes, it also gets more profitable for us because we get lower cost per unit. Right. Finally, regarding 2025, it's fairly easy to talk about growth expectations at capital markets days, but the short term is also quite crucial for the capital markets, and the long term is composed of many short terms. Yeah. Now when you fail to tell anything about 2025, you kind of leave the markets in a bit uncomfortable position because we don't know yet what you will promise for next year. Basically, we would be quite maybe optimistic to basically pencil your current expectations to our models before actually knowing what you plan to achieve in 2025. Is there anything that you could do short term just to kind of bridge us t o your thinkings about next year. I think that is a fair comment because we are fully aware that we need to deliver the growth and show it. I think there are not too many companies who, at this point, give guidance for 2025. We just need to work on showing the track and the guidance you will get then when we are ready with our next year plan approved by the board. I would guess that it will come in February when we release the results, unless the board hears your feedback and wants to behave differently compared to how companies normally do. Fair enough. At least we tried. We tried. Expect nothing less. Walter Rossi from Danske Bank. On the growth target, just to make sure, is it so that the high single-digit ambition or target is totally excluding any new Tier 1 partners? No. The question is the significant ones. For example, this year we have had two press releases about Tier 1 deals, so they would not be in that significant ballpark, but then the header of the release would be stock exchange release. Okay. Fair enough. Thanks for clarifying. Is it possible to try to put it into smaller pieces, the high single-digit target? How much do you expect coming from Total upgrades, which now looks like that there's a lot of partners lie with Total? What portion of that will come from Total upgrades, and how much from new customers completely? Anything you can say? I'll start. Yeah. It will be a combination thereof. I don't think that in our high single-digit growth target, there would be any one that would be completely overshadowing the other ones. Expanding our position within existing partners, winning new partners in major accounts, major partners and commercial partners, as well as ramping up Tier 1s. I would say that relatively, give or take, similar size expectations in all of them. Getting to the 200, these strategic partners play then a bigger role. I think Bruno was explaining quite well how there are expectations for each of the segments. We see that there is a possibility to grow in all of them. All right. Thank you. Hi, Jaakko Tyrväinen from SEB. I could continue a bit on the same topic and the Tier 1 potential. You said that you have now six out of the top 10 Tier 1s globally. My question is how much you have of the theoretical full potential of these clients already, and how much of the future planned or the future growth ambition will be coming from these existing Tier 1s? There's a wide range. There are some Tier 1s right now where we have maybe no more than 5% potential covered with what we have in our scope. That's all. We may have somebody where we are like 80%, 90% of, in a way, how far or how big a scope could be. Maybe the adoption levels are nowhere near where they could be. This is true for all of them. Right? In terms of service scope, I'd say anywhere between 5% and 70%, 80%. With regards to adoption, in many of the cases, we're in very early stages of getting deeper penetration into the full customer base. There's tons of potential in the ones that we've already signed. There's another aspect that we may have this narrower scope, and there may be big continuation agreements available at some point in time, which may be massive. Naturally, we are working on such cases also. We are working on completely new strategic partnerships that we are not serving today. Good. Thank you. Matti already covered the rest of my question list. Yeah. Matti's good. Yeah. We have no questions from the chat, so I think those were all the questions for today. Okay. All right. Thank you for all the questions from the room. Thank you to my- Thank you fellows here beside me for running their sections. Thanks everybody joining online. We hope to see you latest in our quarter one results release in February. Quarter four. Sorry, quarter four. Quarter four results release. Thank you, Sari. before that, I wish you all a great holiday season. Thanks for attending.
Loading workspace