Welcome to the F-Secure Investor Day Deep Dive. My name is Timo Laaksonen. I'm the President and CEO of F-Secure. Welcome here in the room as well as online. We're going to be focusing today on something that frees our mind, and it's a new life in a way for F-Secure, as you just heard in the song that opened the event. It's our Tier 1 business. It is relatively new. It's only two years that we have been active in this market, two and a half years roughly. Now we want to give you a bit of a deep dive how that business is going, what kind of progress we've made, how do we see the future, and the related offering. I will be joined later by my colleagues, we'll get back to that a bit later. Growth and scale through Tier 1 partners. My co-presenters today, Bruno Rodriguez, our Chief Revenue Officer, and TL Viswanathan, our Chief Product Officer. As always, I don't expect you to read through this, but more or less, we're making statements here and there are all kinds of uncertainties in the world, and nobody can guarantee that all of this happens. That's it in short. It's the executive summary. I will set the scene by talking about how we are accelerating F-Secure growth through Tier 1 partners. Let's get going. 1.5 years ago, we had our previous Investor Day, about time you say. In that Investor Day, we had four topics that we covered, four strategic priorities. We wanted to accelerate our profitable growth. We had seen very low growth for the past years, we wanted to also make sure that we can fund further growth investments. Secondly, we wanted to deliver the number one security experience vision, and I'll get back to this and my colleagues will get back to this in their presentations, but we wanted to set the experience bar. We know that consumers have felt that cybersecurity and consumer cybersecurity is just way too complex to understand, so we wanted to make it simple and understandable and relatable. Thirdly, we said that we're going to be focusing on our partner business, and especially for growth on the Tier 1 partnerships, and thus the theme of the day. We also said that we want to optimize our direct business revenue and make sure that it is a strong profit generator for the company while we're focusing more of our new investments onto the partner business side. We had three things that we felt that are absolutely fundamental to be able to deliver on this. We need to expand our addressable market, both through Tier 1 and new verticals, and provide the best partner experience. Value increase through Scam Protection solutions, getting our partners and end customers to convert into Total from the separate applications that we previously provided. We came up with a new product category altogether, embedded security or embedded experiences. Then in terms of company culture, this is all done by human beings, and we saw that we naturally in our culture, we want to make sure that we have a growth mindset and agility in the changing world, more adapt to what we're seeing right now in the market than ever maybe. That was the setup in, let's say, 18, 19 months ago. Let's get back to what we've done. The rest of my presentation is very much about how we see the situation today and how we see our strategy developing in the future. When you're in any business, you need to understand what are the kinds of challenges and opportunities that your customers/partners are facing in their own business. Here you can see that we have listed a number of partner challenges. On the revenue side, their average revenue per user for the communication service providers out there is forecasted to decline 2% per year through 2028. That's never good. Their growth is hitting the ceiling. In terms of retention, this is across the industry worldwide, roughly 22% annual churn. Replacing a lost customer costs six to seven times more than being able to hold on to a customer. In terms of capital, vast amounts of money have been invested into 5G infrastructure, and the payback has so far been relatively meager. In terms of differentiation, everybody is fast, everybody has great prices. How do you work in this world? Now, we see that what we are offering to our partners, trust as a service, trust as a business, is actually a very good answer to all of these things. In terms of revenue, our services are high average revenue per user. It's recurring. In terms of retention, there is absolute wealth of information which confirms that customers who have gone for security services are more likely to stay with you. In terms of capital, embarking on the journey of providing consumer security services is fast and very lightweight compared to practically anything else that you can take out to market through a communication service provider. In terms of differentiation, the number of players that we see out there, I believe that Bruno is going to refer to this in his presentation. More and more of the big Communication Service Providers are starting to talk about trust as a core value proposition, not only as a value-added service, which I have practically banned as a term within F-Secure, but as a core service. Branded trust experience is something that the consumer feels and remembers. It goes way beyond a commoditized offering. That's why we believe that we are as topical and in a good place, the right place right now in the market. Now, I already mentioned this. AI fraud is actually now visible in such a scale that consumer expectations, regulator agendas, and Tier 1 product strategies are shifting as we speak. The problem of scams hasn't gone anywhere. EUR 442 billion were lost to scams across the world in 2025. AI fraud attempts, that's a pretty big number, 2,000% up since 2022. The response is that 93% of consumers out there expect their communication service provider to take care of their cybersecurity needs. 93%. We've been very partner-centric all this time. Good place to be, I would dare say. Tier 1 reaction, we've just picked up three here. Orange, Verizon, and Vodafone all highlight now trust as a very critical and core proposition in their offering to consumers. This, from our point of view, is a very good development. We claimed one and a half years ago that we will be going after Tier 1, how have we done? I'm sure that you've seen this picture of a globe before if you followed any of our previous streams. All of these names that you have on the slide are our partners. This is not the target segment. These are the ones that we're serving. In the lower left-hand corner, there may be one, CKH, that you don't recognize. It's Hutchison Three. We now serve 10 out of the 20 largest CSPs globally. 10 out of 20. Pretty good hit rate. Once again, Bruno is coming back to this, where we're excluding China from these numbers as we don't find it tolerable for us to actually go to the Chinese market because of the authorities and their regulation. The journey continues. We've won a lot of partners. What's happening now? If you look at the journey on the slide here, we set the bar at the end of 2024 to go for leadership in the Tier 1 segment. We won practically every single deal, practically every single deal that we've gone for in 2024 and 2025 and the beginning of this year since then. I can't guarantee that we will win every single deal going forward, but this is a pretty striking track record that we have here. Our value proposition and something in the way that we operate in the market has clearly struck a chord. Now, what we're naturally doing now is that once we have signed a deal, we work very hard to get that service launched together with our partner, and we want to be growing that user base. Very often when we sign the deal, there is no users to begin with, and then we have to ramp up over time so that we get the volumes of users and our license fees growing. We are now naturally, we're focused on carrier-grade delivery, activating users, attaching users, and running retention activities for those who have been out there already for a longer time. Now we have a pipeline. We don't leave it here. When you get the domino going, you naturally want to continue it, and it's only 10 out of 20 right now. There are both expansions and extension deals that we're working on and projects that we're working on with the partners we're already serving. Then, as always, we're also looking to expand the partner base with new logos. Bruno will talk a little bit more about all of those topics I had on the previous slide. Our midterm target, as you may remember, is that we will have high single-digit revenue growth, and our targeted adjusted EBITA level will approach 40% when our revenue approaches that EUR 200 million. This growth towards EUR 200 million is very much anchored on the Tier 1 business and the Tier 1 growth. It's not the only source of growth for F-Secure, but it is by far the fastest growing. It's solid double-digit growth. This growth, in hindsight, I would say is largely built on the Lookout Life acquisition that we made precisely three years ago. The first logos we got, Docomo and AT&T, were valuable. The understanding of how to build mobile-first experiences, important. Working to expand our embedded security portfolio, very important. A position in the U.S., which was strengthened through the acquisition, priceless. From that perspective, I would say that we would not be here talking about this topic had we not made that acquisition. Now, U.S. is our single largest growth driver right now in double-digit numbers, and partner business as a whole is the one that drives our growth for now. Something that may have gone unnoticed for many of you online and here in the room, is that we actually refreshed and updated our vision and mission as a company some four or five months ago, and it's now as follows, the vision: Live your best digital life. Trust for a world AI keeps rewriting. There's a lot of small text in there, which is actually very relevant, so I will make an exception here and I will read through it because I feel that it's very crucial. We are building the invisible layer of trust in consumers' digital life, embedded by the world's largest digital service providers, delivered through AI and scaled to every digital moment, shopping, banking, messaging, investing, socializing, and so forth, and the emerging agentic world. This is what we're working on. If you think about this and you read through that, we don't mention the word security a single time, whereas we talk about trust. From our point of view, we feel that it's time to start shifting our view from protection to resilience and from security to trust. This actually opens up much vaster potential for growth in the ecosystem where we function. We're not leaving security behind. We're just going one dimension further up in the logical succession. When we talk about trust, we believe that we've reached a trust inflection point. When you go to any kind of event these days, pretty much 90% of the talk is around AI. I bet there are lots of keynotes being given around the world right now where everybody's praising how AI is taking on the world and changing the world, and it does. One of the things is that the defining constraint for consumers in AI is not necessarily their capability to use AI, it is trust, or rather the lack thereof. There are already 900 million weekly users of ChatGPT, some 650 million Gemini from Google monthly users. 2 billion, actually 2.5 billion prompts are written to AI assistants every single day. 2.5 billion prompts. Everybody's using, but they don't trust it. It's quite a paradox, I would say. 84% of people, according to our global survey, among 10,000 consumers, 84% of the people don't trust what AI is telling them, or they don't have the capability anymore to know what's real online because of AI and deepfakes and so forth. The mistrust is there. Only 18% of people claim that they would be willing to give AI the capability to act on their behalf online. When we look at market surveys, they state that in 2027, which is no more than seven months away now, by 2027, end user activated activities online will be surpassed by agentic activities. Right? It's 2027, it's seven to 19 months away. That's very, very fast. If we see the disconnect here between people not trusting AI and the expectations that agentic will take on the world, there's a big problem here. We believe that when this fundamental mistrust exists now in this AI emerging ecosystem, whoever now holds consumer trust to begin with is in a good position as the market evolves. What our partners have is a long-term local, maybe years if not decades, of a relationship that they have and they can play on. We believe that in addition to everything we've done so far in F-Secure, and we continue doing it by the way, there is a once in a generation window right now to create a new category of services and solutions that we can develop and take to market. A new tech stack, naturally, lots and lots of AI-related capabilities are going to be crucial over there, like edge computing, or you could say on-device computing, federated learning and so forth, to drive down cost, to drive down latency, and to protect people's privacy. Tier 1 distributions. Tier 1s want to be on the AI boat. You already know that there are multiple big players out there who may be reselling paid services to AI assistants for the better versions or premium versions of these products. They want to get on this bandwagon and naturally, because we are already there, we want to leverage this moment. Securing AI that acts on your behalf, that's going to be crucial to create the trust that we get consumers along the journey. Finally, we see that also in the direct-to-consumer category, there is no category leader for providing trust in this AI-driven world. From that perspective also, this provides us opportunities to combine partner and direct business and direct-to-consumer types of channels to market. There may be more that Bruno will talk about. That was all from me. Now we have a Q&A for anybody who wants to clarify something or have further questions. We will also have a Q&A at the end of each of the sessions that my colleagues will be running, and we will have a joint Q&A at the end of the session. You will have multiple opportunities to pose questions. Now the floor is open to people here in the room. Will Iina be providing the microphone to ones who may have questions? Then, also online, you can also pose questions to me. Hi. Waltteri Rossi from Danske Bank. First of all, thank you for the presentation. I'll start with the Tier 1s. What needs to happen for you to get the other 10 out of the top 20 CSPs? We believe that we need to be able to build the networks that are necessary to get access to these players in the first place. I would say that is something that you can't just repeat on autopilot. Every single case is different. People in these big players are different that we don't necessarily know, and that needs to happen. We need to find inroads. The word travels fast, and we naturally believe that there is a compounding effect of so many players already working with F-Secure that the word spreads. That will help. Nothing comes easy or fast in this world. I would say that the most important thing is that when we're looking at new players, for instance, in Europe or in Asia, we need to make sure that we have the inroads to get to the C-level and the SVP level of these players to talk about what we could do. I would say other things we have, solutions, scalable service model, knowledge of how to help them ramp up the services and drive value. That part, I would say that we're in a good place now. All right. Thank you. Did you say that the 20 top CSPs did not include Chinese ones? What is the reason? They do not. The reason is that the Chinese regulator typically requires backdoors into any security-related systems, and we do not go for that. You are currently not considering the Chinese market? We're not. Understood. Two questions about the partner business. You have said previously that the Total conversions are done. How many of your partners actually ended up upgrading for the Total, and how many of those, roughly, are today selling the Total package? I don't know the precise numbers today, my estimate would be that somewhere between 85%- 95% have already converted into Total. The things that are still happening to increase the value of that business is that we have multiple different modules in Total, and practically every single month we have new ones, for instance, who are going for Scam Protection, which they did not have before. There is value increase even in the cases where partners have already gone for Total. There are many who don't necessarily have today the password vault in use or VPN in use. On that front also we can expand our offering. The conversion has proceeded well. Thank you. Last one, you had this slide showing the partner challenge, and you showed that there is this ARPU forecast, which was a 2% decline year-over-year. Did that relate to your- To their revenue. Okay. When they are selling mobile subscriptions, broadband content, and so on and so forth, that related to theirs. What is your outlook on your partner channel? Our partners are clearly seeing ARPU increase through the introduction of security services. It's ARPU increase and better retention. The facts are clear. Great. Thank you. Thanks. Roni Pernu from Inderes. Hi. Maybe about the 10 missing partners from Tier 1. I'm not sure if you have commented this, but how big are the ones that you are missing compared to the ones you have in terms of revenue potential? The way that we have built this top 20 list is in terms of company valuation. They are all very big. The ones that we are serving are some of the biggest in the world, and the ones we're missing are of similar magnitude. All right. Maybe about the U.S. as a growth driver that you mentioned. Do you see a trend that U.S. CSPs would anyhow prefer U.S.-based cybersecurity companies? Do you have to prove yourself somehow more because you're European? No is the short answer. They want the best partner and best solution. All right. Maybe about the competitive landscape in Tier 1s and maybe how fast they are working with their AI capabilities compared to you. Do you see yourself as a first mover here? A bit difficult to say. I think that as you follow tech, you see that any and every company is very quick to say how they are focusing on AI and how they have AI-powered services. All of our competitors have AI-powered services. Doesn't come as a surprise. Any self-respecting tech company would do so and make that claim. Now, the difference maker really is that are we solving the same problems as we did before more efficiently with AI, which is good, and everybody does that, by the way. Or are we creating completely new kinds of solutions because AI allows to do something or the threats that AI poses to consumer trust, for instance, in a way merits for a new kind of category of solutions. There are big differences. I see much more of the first one, where we're building better solutions with AI. The completely new kind of solutions that you never had before, I would claim that we are at the forefront. All right. Thank you. No further questions from me. Hello, this is Hendrik Järvinen from SEB. What do you see are the risks of criminals using AI to sort of front-run the security development? Do you see any risks associated with that? It's a constant cat and mouse. The situation changes day by day. You saw the picture where I had the number 2,000% increase of AI-powered threats or attacks from 2022-2026. It's massive. I would say that we have kept pace. Of course, you can make forecasts about the future, we've kept pace. For instance, now in May, we launched the press release that one of our Tier 1 partners, Docomo in Japan, has just gone out with deepfake protection services. That's a completely new category of protection that we built. As the criminals move into that kind of area, so do we. I wouldn't say that there is cause for concern. All right. Thank you. One more question. Have you seen any key rivals reacting to your Tier 1 partner first strategy? We have competition in every single case. Our Tier 1 partners have massive procurement departments. They at least make sure that there is always some competitor or several competitors playing. I would say that there's competition. They have good technology, they have good people. We do need to work very hard to keep on winning business the way that we have. They are good. So far we've managed to find that margin of differentiation. I would say that that stems now from the fact that just the mere number of references we have, our embedded portfolio, our partner centricity in how we help them build their consumer security business, that I would say is the differentiation that has helped us. Naturally, still, every battle is a hard battle. All right. Thank you. Thanks. I believe that we are now ready to move on to the next section. [Foreign language] Bienvenidos, Bruno. Our Chief Revenue Officer will now take the stage and talk about how we're actually running this business. Yeah. Over to you. Thank you. Thank Thank you, Timo. Good afternoon, everybody. We're going to talk about winning, launching, but especially we're going to talk about growing. Last Investor Day was, if I recall correctly, November 2024. That was quite some time ago. I think it was my second month in the company when we did that Investor Day, and a lot of things have changed since then. There's a couple of, we could say, important milestones that we have here related to Tier ones, which is what we're going to talk about today. It's all going to be about the Tier -one CSPs. First of all, last year we signed an agreement with Orange Europe as their preferred cybersecurity partner for the group. We have planned in the second half of the year the launch of at least two countries inside the Orange Europe group. At the beginning of this year, there was another significant milestone where we signed an agreement with AT&T, currently was one of our biggest customers, to expand our solution that we have, Active Armor, to include also Financial Monitoring, which is a completely new service. Okay, this was a significant expansion of our current agreement with AT&T. Very, very important. April this year, just a couple of months later, we both signed and launched a new security service with Verizon. This was the largest deal in F-Secure's history. We announced that already. Significant win with one of the biggest telcos in the world, Verizon in the U.S., and we will enhance their digital secure capabilities with Identity Protection and several other security and Scam Protection modules into their app. The final one, just last month, we signed and launched a new security solution with Docomo in Japan. Docomo was already our partner. We were empowering their Anshin Security app, and now we are enhancing, as Timo said before, we are enhancing that app also with very innovative Scam Protection and deepfake detection capabilities, which are first to market in Japan. Finally, we also announced that we signed a new Tier 1 CSPs. Unfortunately, we cannot disclose yet the name of this one, which is confidential, but the launch is now in planning. Significant traction with the Tier 1s in the past 12 months, as you can see. Okay, Timo stole a bit of my thunder here when he talked about compounding effect, because it is not only the fact that we are signing these four new deals recently and going to market with these advanced solutions with our embedded portfolio, is that these references are actually enabling us to also participate in significantly more projects in Tier ones. This is addressing the question of how do we get to that other 10 that are not working right now? There is two ways of doing it. One is using the references. There is no other security company in the market right now with these references in Tier ones. There is no other in our market. This will advance us. This is a compounding effect. The fact that we'll be able to win all of these would allow us to be better positioned to win also new Tier ones in the future. Here's another number for you. We've won all of these deals, what is really the business behind all of these deals, what is our addressable market right now? This is a very important number. If you take this is the globe that Timo was pointing out. If you take all of the combined subscribers from all of these customers that we have right now as our partners, you take all of their numbers, there are approximately 1 billion subscribers that we now have access to that we didn't before. This is a significant increase. If you take all of these, there are approximately 1 billion end user subscribers that we have access to in the three geographies that we are focusing now, North America, Europe, and Japan. Not only we have 10 out of 20, but we have now a significant user base that we can help our partners penetrate with cybersecurity. Take into account that significant or a couple of years ago, maybe four or five years ago, this was not the case for F-Secure. This is a big change and a big step in moving forward. Again, this is a huge untapped potential in this 1 billion base for both F-Secure, but also for our partners, because we are here to make business with our partners. Okay. Not only we have access to that user base, but we believe we also have another advantage, which is our business model. TL is going to talk later about our embedded portfolio and what capabilities of this portfolio has. I won't steal his thunder, I just want to talk about the business model. There's a difference between traditional cybersecurity apps that you resell and an embedded portfolio. Other consumer cybersecurity vendors, they work with CSPs, basically reselling their applications through the telcos channels. You have to compete. You are, like Timo said, we're not saying the word value-add service. In that case, you are a value-added service, and you are competing with other value-added services in that CSP. This is not our business model with embedded. Our business model with embedded is different. What we are doing is we are taking our SDKs, our security, and technologies, and integrating them into the telcos apps, be it their dedicated security app or even other apps that they may have. This is a completely different business model from just reselling an existing app. This is what turns a solution from a value-added service to a core service in the CSP. Okay. It's very difficult to turn a security service into a core if you're just an app that you're trying to resell. In this case, we are embedded, we are integrated in what the CSPs are doing in their apps. Really important. Okay. Going back to the EUR 1 billion, which is an interesting number, how can we turn that EUR 1 billion into potential revenue for us? Because those are subscribers that we now have access to with our products, with the CSPs' products. How do we could say, convince those customers to adopt security? F-Secure has been working with CSPs for decades now, so you know about this. During all this time, we have created a playbook, which includes all of F-Secure's knowledge on how to successfully market security solutions through CSPs. This is this compound knowledge that you have there with the five steps. Our plan now is to apply all of that knowledge that F-Secure has to that 1 billion addressable market that we have now in subscribers, and convert those subscribers, or let's say, help those subscribers increase their protection with cybersecurity solutions. Probably the next question is going to be, how many of those do you think you can convert? I'm already seeing here the audience thinking about that. This varies from one to another partner. We have partners that have 2% conversion, and we have partners that have 20% conversion or even more. This depends on the focus that they put on cybersecurity, the executive engagement that we have with them, how they are promoting cybersecurity in their channels, and many, many different factors. The point is that we know exactly how to get to this 20%, and we have a playbook that allows us to get there. Okay. Now I'm going to go a step further, and we're going to talk about what this potential revenue could look like. If you look at F-Secure's revenue from Tier 1 business in 2025, last year, it was approximately EUR 50 million from all the revenue that F-Secure was doing. What we believe is that the potential we have now with these references and this new subscriber base, applying the playbook that we already have, we believe that we have a future growth potential of around EUR 200 million. It's not going to be next year, this is the potential that we have. Of course, this is with the current embedded portfolio that we have. Later, TL is going to talk about some other future growth opportunities related to new AI solutions evolving around trust, which is also really important. I don't want to steal his thunder. Okay. We've been talking about Tier 1 CSPs. What about other channels? We've talked about other channels in the past as well, we are not completely, I could say, abandoning this strategy completely at this moment. We are now also looking at, given the embedded portfolio that we have and the flexibility that this portfolio gives us, we are now also looking at other channels, other adjacent partner channels that we can address. It's not only talking about how do we capture this other 10 of the 20, but can we also explore other verticals that could benefit from this embedded portfolio that we now have, and that has proven to work in really, really large CSPs. That's one. Then the other one, of course, are the AI native solutions, which we also need to explore. Of course, how do we take those solutions to our current channel. Also, how do we take those solutions to completely new channels that these solutions will enable for us. Because you will see later, these are very different solutions from what we have right now. It's a completely new way to deliver protection to our customers. Okay. Let me wrap it up. First of all, our right to win in the Tier 1 business has been confirmed. We have four new Tier 1 commitments in the past 12 months. That is very impressive, taking into account how difficult it is to win and launch solutions with really big Tier 1s. Second, we have a growth playbook that has been proven through decades in our existing partners, and can now be applied to this new 1 billion addressable base that we did not have access to before. This has just opened up a new opportunity for us to actually get the most out of these users. Finally, we have future growth available thanks to these new Tier 1 channels that we are looking into, and also exploring new AI solutions for existing and new partners. As a closing remark, we have closed, we have launched, and the next chapter is to grow. Now we have the system that is able to deliver that growth. That's all I had for today. Any questions? I've given a lot of numbers, probably there's going to be some questions on those. Roni from Inderes. Hi again. We have addressed these new verticals as maybe to embed ourselves into these new channels. We have to find the right ones. It will not be easy because there is also a significant new market driver, which is the rise of scams that are now really affecting a lot of verticals. For example, banking, financial verticals, and several others. That now we have a solution for that. I think the product market fit is now really good, and also the fact that we can embed into those app the best. Maybe one or does it include other that you're? That includes the whole base. Not only the current, but also the new ones. Okay. Thank you. Yes. There's another question. Yeah. Hi. Waltteri Rossi from Danske Bank. You showed that the adoption rate varies between 2%-20% between partners. Yes. You also said that you know exactly how to get to the 20%. Please tell us how. I won't say exactly how to get to the 20%, because that really will give some clues to our competitors. Maybe the question is why some have 2% and some have 20%. Well, it depends on many factors. First of all, we are working with some partners that yet do not take full advantage of the playbook. The playbook have different steps. We may see partners that, for example, this is not yet an executive-level topic for them, and it all starts from there. The first thing is you need to have executive buy-in from the top level of the CSPs. That's one thing that makes everything else trickle down. For example, we've seen some CSPs that are enabling some of their channels, for example, online, but they are not enabling the physical channels because maybe it's a bit more difficult to do that because you have to do trainings in person, so you have to do different things. The point is that right now we are seeing some of our partners doing part of the things of the playbook, not all of them. Our job, also in my team, is to make sure that we have consistent adoption of this playbook across all of our partners, and we have a dedicated team to do that and help them adopt that. We know that if all of them will follow those rules, they will get to those penetration rates. Thank you. Okay. Thank you very much. TL? Thank you, Bruno. Looks like I have to deliver a few thunders on your behalf. Good afternoon, everyone. Let's talk products. In this section, we'll speak to how we are delivering the market leadership through the lens of the portfolio and the products. Like Timo started as well, I want to talk a little bit about 2024, but through the lens of portfolio. Timo spoke to the company priorities, but from a portfolio perspective and focusing a bit more on embedded, keeping with the theme of Tier 1s, we set out very clearly to build the best portfolio in this industry. One that's broad, one that's relevant, one that's scalable and repeatable. We also spoke about how embedded and the emerging scam pandemic, is what the name we gave it, and how is it that driving our primary addressable market. Let's look at how have we done. As you have already heard, we are the undisputed market leader in this segment with not just the broadest, but also the deepest SDK portfolio in this industry. I want to draw your attention to two key points here. By the way, if you just count the number of modules there, it's probably one a month from the time we made the announcement. Pretty rapid. Scam Protection, entire portfolio, probably covering all channels that today we find exposure with, and now including deepfake, that just went live with Docomo. We've also introduced a completely new category under financial protection that is now live with AT&T. All right. All of this, like I mentioned, in give or take two years or so. Right. It's not just the product or the modules or the capability and technology. Those are critical foundations, it's about also the how we leaned into the experience for partners and developers. What you see on the right as the moving image is actually an actual live sample app that has every single module that you see here embedded in it, which is then available to developers on our partner side, who can then build their experiences on top of it, test it in matter of days and weeks, and now maybe even hours with AI agentic coding. We have collapsed the time to launch. This is, of course, from a product build perspective. There's a lot more that needs to happen to go to launch, including, the channel set up marketing, and Sorry, as Bruno said, executive buy-in. From a product standpoint, the time to value is the fastest that we have seen in this market. I remember talking about this specifically with some of you last time on. There is investments that is to be made to build this portfolio up. Where is the ROI? Can you repeat it? For all the opportunities that Bruno touched upon that we're working on in Europe, in AsiaPac, we have over 90% repeatability of this portfolio. What that means is that we are able to compete, win these opportunities without net new engineering work needed to build a capability. It doesn't take away the work that we have to do to integrate and ensure that the product is ready to be taken to market. From a pure capability standpoint, that's the level that we are at, and this is a KPI we track extensively in the product organization and also at the company level. Any deviations to those are taken into account with very strict guidance on why. This is not just a KPI we have landed at. We have maintained it, and we intend to keep directionally a very high level of repeatability going forward. Just building the portfolio of capabilities and SDKs modules is not sufficient, right? Another area of investment for us and fundamental investment has to build what we call as a Tier 1 platform, which gives us the availability, scalability, and resilience needed to deliver these services to the names that Bruno and Timo mentioned. Right? The likes of AT&T, Verizon, and we are well on track to hit the golden rule of the four nines for consumer services in the market. That is less than an hour of downtime in the whole year. Just to give you a sense, I won't go too much into detail, what this entails. This entails our services running on multiple AWS regions in the world to just in the U.S. The ability for us to run services, move traffic seamlessly without any data loss or service degradation if sites go down. This means ability for us to ensure that we can manage overload, auto-scale based on volumes that go up and down. The ability for us to monitor and maintain our services end-to-end across this portfolio. If you put these two together, the portfolio, which is the broadest and deepest, and the platform that now looks like this, that's the real moat. This is the one that's not easily replicable, and this is also the one that brings a very high entry/exit barrier in this business. This is where we have been investing at rapid pace and delivering what you see. Bruno briefly touched upon this, I will go a little bit deeper. What does the scalability bring in terms of opportunity? I'll mention two. One, what you see as a picture, as a visual, we have 160+ CSP partners that we serve. The top half, 20, 30, 40, they want Embedded as well. They want Embedded to be sitting alongside Total. That's an opportunity to pick the right selected embedded capabilities that would make sense in the MyCSP app, that drives higher engagement, that drives higher usage, and we build call to action to Total to drive adoption. That's one clear opportunity that we're able to tackle with a portfolio that is elastic, and we are able to scale down the capabilities and the volumes as needed. I think there was a very good question about, is embedded giving us an advantage with new channels? In my opinion, it absolutely is. Because all the basics that you see in the portfolio, which is the capability needed for protection and trust, and the scale that is needed with new digital service providers, fintechs, e-commerce, you name it. These companies that are digital natives, they operate at scale and operate at availability and latency figures that only this platform can serve. From a portfolio standpoint, this does give us the options. We still need to make the channel, but this gives us the option, a portfolio that allows us to start looking at those options as and when it's the right time. Timo spoke about the 93% of users, especially now as scams are accelerating, wanting to get that trust and protection from their CSP partners. We see that. We see that scam as a problem to solve, Embedded as a way to solve it, and Tier 1 as a channel to take it, is really that product market fit sweet spot that we have now found. We see that both through the lens of consumers wanting to spend through Tier 1s and Tier 1s themselves doubling down on security and trust as a portfolio. That's reflected in our growth guidance this year, where we are guiding to grow twice as fast as the overall cybersecurity market and in line with where we see the growth for our CSP-led consumer spend. You have seen this picture before. I just wanted to bring this embedded portfolio in the context of the larger overall portfolio that we run as a company. A couple of very important points. What you now see that did not happen 2024 is that the embedded security SDK is not only a product SKU that is being used for delivering to Tier 1 partners, we use it ourselves. We use it ourselves to build Total, and we use it ourselves to build Halo, that was recently launched as our new AI-native consumer product, still in beta. Now, what this means is that the return on the investment that we made into embedded is now broader than just the partners themselves. This means that now Total as a unit, Halo as a unit, are not spending engineering effort to build core capabilities. They have the best-in-class capabilities coming from Embedded, they focus on building the partner and the user experiences on top. We are dogfooding our own portfolio. That's one important aspect. The second one, Horizon. Bruno spoke about it. There was a question regarding adoption. Horizon represents an AI-native industrialization of that 38-years+ knowledge that F-Secure carries. The data that we have as a bedrock, we put that together to drive that adoption with these partners. There was a question of how these partners get to these levels of adoption. Of course, we have amazing people who are in front of these partners talking to them about it, now we have an industrialized AI-native platform that gets them the data, that tells them where to focus, that tells them which cohort they can go after to try and make those adoptions happen. Right? The portfolio overall is now tightly integrated, highly mature, and a portfolio that can support multiple business models across all of our segments. The levels of efficiency and repeatability we are now aiming for at a portfolio level is also very high. Where is this going? I will take the trust topic that Timo introduced a bit further. I think it's needless to say that AI is probably the single biggest diffusion and disruption, pick your word, in our lifetime when it comes to technology. One of the best and one of the biggest impacts to consumer behavior we see is the way users consume information, search for information. That has changed. A billion-plus weekly active users, 900 ChatGPT alone. If you add the rest of it, well, over a billion. That's a lot of people using AI every single day, many hours in a day. Do they trust it? Do we trust it in this room when we get an answer back from one of these AI assistants? Our instinct says, Let me double-check. Let me make sure this is fine. The consumer behavior has changed. The trust has not, but the behavior has. What we expect, everywhere we speak about agents, and clearly in lots of spaces, the single biggest that we hear about is how agentic coding has been one of the silver bullets so far. What we also see clearly is agentic interactions for consumers surpassing app interactions in 2027. That's again, a massive pivot. If the introduction of ChatGPT was the moment for this inflection, OpenClaw earlier this year is the point of inflection for that, where you will start to see a lot more consumer use cases, shopping, investment, banking. Already there are so many agents trying to manage your equities. Is it mainstream yet? No. Is that a trend? Yes. Those are the two big movements we see, and the question is, how do we prepare for it? On one side, we see scam accelerating because of AI. We have users who are unable to trust this, but still have changed their behaviors to use it. All this means that there are fundamental capabilities that we need to tackle this inflection that did not exist before. That's the direction of travel for the embedded portfolio. The SDKs becoming agents where we can action. Timo spoke about action. It needs to come from the capability that we have the ability to take actions. How do we orchestrate across various touchpoints that the user face? Gateway. MCP. It's essentially Model Context Protocol. It's like a gateway of how agents and AI systems talk to each other. If you think about user talking to multiple AI systems, how do we build a trusted gateway that they could put in front of them so that they're not exposed, and they can trust what comes back? This entire stack, and there was another presser we had a couple of weeks ago partnering with Q2, and together, this is the foundational work that we are doing to make sure that the embedded portfolio goes even further and deeper, not just from security like Timo said, but to deliver trust. That's the direction of travel. We look to build the portfolio for trust and for delivering trust with fundamentals built as embedded capabilities. We have two concepts that are already in work for the two topics that I mentioned, for the two inflections I spoke about. One, billions of users interacting with AI assistants but not being able to trust, and the second one, how agentic workflows start to take shape. Let me take the first one. We call it the Trust Guard. What is Trust Guard? Think of it like a trust wrapper or trust hug, whichever one you like, which intends to bring the trust back to that conversation. We don't want to change the experience and truly the benefit that assistants bring. We want to keep that intact. What you see on the left here is users being able to connect to ChatGPT, Gemini at the moment, and in the future more, to the assistants of your choice. Then interact as they normally would. There is a guardian that's watching over this. There are a couple of use cases that I mentioned there. I'll talk about one of them. A very simple one, but a very powerful one. You get loads of responses back from the assistant, but you don't really know where are they getting this information from. That's one of the first points where the trust breaks. What you see there on the picture is a very simple view in the bottom that says, This is the sources from where this information is gathered. You see a very famous F-Secure green tick there. We suggest that these are fine, they are safe. It's just a glance. It's just a visual glance that, oh, it's all good, I can trust the response. Look at your PII is personally identifiable information. This is information that points to you as an individual. It's quite possible that we are so caught up with our conversation that we give information that maybe we should not be giving. Account numbers, phone numbers, where you live, et cetera. This is, again, the agent Angel being able to spot that and say, Hey, we think you should not be giving the information out. Do you still want to go ahead? This is not changing the core experience of what the user wanted, but making sure that slowly but surely they can start trusting it. I'll make one comment before I go to the next one. Bruno spoke about the role of Tier 1s in this, right? We're still exploring that, by the way. Most of these Tier 1s, in one form or shape, are talking to or partnering with these large AI ecosystem companies. We think there's something there. Trust Path. One thing that we have not done very well as an industry is being able to connect the dots. We have been excellent at point protections, SMS protection, WhatsApp protection, browsing device. They live their own cycle. If you are a user, you just want to shop, you open a browser on your phone when you're on the tram, you want to see what I want to buy, you go home, you open your desktop, you want to complete that transaction somewhere else. You don't complete it. Next day, you go, complete the transaction back on your app. Then you have messages coming on your phone saying, This is what you ordered. This is when it'll be delivered. Multiple channels, multiple platforms, but the same intent. For the first time in this industry, if I may say, we want to connect these dots, and that's what we call Trust Path. To seeing is believing, let's play the video. This is me, and this is a crisis. What do you do when there's a crisis? You go to Mom. My mom solves problems, always. It's a personality. Today I got one. These silver glitter, size 36. They are on every feed, every story, every group chat. The shoes. I'm obsessed. I will not survive Monday without them. Mom doesn't ask why. That's the best thing about her. She sends the agent. Rules first. EUR 200, size 36, 30 minutes, go. Zalando, nothing. Boozt, nothing. Widening. Every shop gets a background check first. Vibe check, basically. Green, green, amber. Keep going. Shop four, right shoes, half the price. Suspicious and buried in the page, evil instructions for the agent. Nice try. Blocked. Redirected. Smaller shop. Never heard of it, but clean. We're in. Mom calls me in. The face. These ones? Those ones. She takes the wheel. She likes to do the last bit herself. Price, tick. Size, tick. Silver glitter, sparkly tick. Card, single use, burned after, just in case. Address fields glowing green. No funny business. She presses buy. She feels powerful. I let her have it. Two days later, a text. Customs, urgent, click here. Already seen it. Wrong merchant, wrong amount, wrong everything. Mom puts the phone down. Problem solved. Door, shoes, done. Worth it. One ping. All clear. Mom doesn't read it. She trusts it. That's the trick. Protection that makes you live your best digital life. Thank you. Questions? Hi, Roni from Inderes again. Maybe going back to the 10 missing Tier 1 partners. In terms of product platform, is it currently mature enough or is there something that is missing in order to get the missing partners? From a product fitment perspective, I would say not much missing. We are there, but like Timo said, like Bruno said, to win these deals, portfolio is an important cog in the wheel, but not the only cog. It's relationships. We have to make sure that we are in the right place. There are procurement processes as well, but from a portfolio standpoint, we are there. All right. Thanks. Do we open up to common questions? We got the whole gang together again. The three amigos, right? Any questions online for any of us? Yes. We actually have two questions here from the line. Okay. Let's start with Patrick Donegan asking about Sense. Can you provide an update on the global momentum around Sense, your home router security software? Okay, that's not in our Tier 1 focus proposition. That was not, in a way, by purpose, it was not in the center of our attention. It's not something that we're looking onto as a Tier 1 proposition as much, as it is for retail and major and commercial partners. On the Tier 1 sector, we're not focusing on that one, but naturally, it is available. One final question. Most of your Tier 1s you have now as customers operate in multiple regions. Are your solutions available to all of their user base in all regions? If not, what percentage of the total user base are you addressing currently? There are actually, for instance, AT&T and Verizon, SoftBank, Docomo, KDDI, they are very single country propositions, and they may have, for instance, limitations in terms of they only go after their fixed broadband customers or only their mobile customers. There are differences there, and I don't have the precise numbers, but not all of them provide our services to their whole base necessarily yet. For instance, somebody like Orange works in many countries, so does Vodafone. In those cases, we are serving still a small subsegment of their total regional coverage that they have. Yeah. If I may add, I think one part is how the partners offer those services to their customers. Our solutions and products are available in all our focus markets. Yeah. Thank you. Those were all the questions from the chat. Okay. There is still one more question from Walter here. Yes. Waltteri Rossi from Danske Bank. Two questions, basically. Could you please explain in simple terms what the Qutwo partnership means for you, and what do you get from them? Okay. First, my response and then the right answer from TL here. Q2 is how they pronounce their name, by the way. First of all, we have a development program and business proposition program around Trust Guard and Trust Path that TL just covered. They are a partner to us in terms of research, engineering, and implementation, complementing our skills specifically on things that have to do, for instance, with on-device AI, federated learning. We have skills on those fronts, but there is always lack of enough people, and we have seen that Q2 is an excellent partner for us on that front. In a way, you could say that they expand our knowledge base and they accelerate our time to market. Just to add, I think I spoke about the direction that we are taking with embedded as a portfolio that forms the basis for the value that we want to deliver to address the trust gap. Those capability set are very concrete outcomes we will build through this partnership. Of course, on top of that, like I said, the experience of how the user actually gets that value of trust is also something that we will build on top. I think like Timo said, a lot of core research, AI specialization, right down to the silicon, all those capabilities is what Q2 brings. Okay. Thank you. As the second question, kind of relating to discussion in the news lately, where actually your main owner mentioned that due to maybe excessive regulation that you face as a listed company, it might actually lower your competitiveness compared to private companies. How do you see that? Do you see that as an issue in practice? We focus fully on developing F-Secure in the environment where we operate. We don't mind about the rest. We work on compliance and regulations as necessary. We just ram on, and our shareholders and our board then, they draw conclusions. I see that, for instance, right now, we could have lighter processes and lighter needs for documentation and reporting. Yes, there would be a benefit, but right now we're doing fine as is, and we're focusing on that. Okay. Thank you. Thanks. I don't see any further questions here in the room. Oh, there's another one. Oh, there is another one. Maybe one more about the pipeline of the 10 missing Tier 1s. Could you comment on that? How many do you have active talks with currently? No. Okay. I understand. Thank you. Sorry about that. Iina, that was all? Okay. I believe that we're now done, and 40 minutes ahead of schedule. I hope you don't mind that we were able to run through everything slightly faster. Thank you very much for joining. We intend to do another Investor Day deep dive, most likely towards the end of November, with a new topic being Trust and how AI is affecting that, and how do we see that market evolving. That's something that you can look forward to. In time, we will be sending you a save-the-date message on that one. Thanks for joining, and have a great day. Thank you. Thank you. Thank you.
Loading workspace