Good morning. Welcome to WithSecure. My name is Laura Viita. I am the Investor Relations Director of WithSecure, and have the pleasure of wishing you welcome to this capital markets day, the first ever for WithSecure. Participants joining us over the webcast, welcome wherever you are. Our demerger is progressing to plan, and in only as little as four weeks from now, there will be, instead of one, two cybersecurity companies listed on Nasdaq Helsinki. We hope that we can provide you good insight on how WithSecure, the corporate security company, will operate, how it grows, and how it becomes profitable. This afternoon, at 1:00 P.M., the consumer security company, F-Secure, will hold their capital markets day. If you're in the room, it's enough you find your way back from lunch. For the webcast, we have a separate link, so we will provide instructions on joining the WithSecure capital markets day at the end of our morning. To the speakers. Forward-looking statements, so consider yourselves warned, and then to the speakers of today. These five gentlemen will be presenting today. To give a wide perspective of what we do, they're actually representing different parts of the company. There's obviously Juhani Hintikka, our President and CEO. After him, Antti Koskela, the Chief Product Officer. Then Ashley Clark, Vice President Commercial from our Solutions Business Unit. Then Janne Pirttilahti, VP of Cloud Protection, and then Tom Jansson, Chief Financial Officer. The agenda looks like this. Juhani, in just a moment, will give an introduction to the fast-growing security-as-a-service company, how the world around is changing, and how we plan to live with that change. Antti will talk about the opportunity, what our market is, how our product portfolio can respond to the market. Comes Ashley. Ashley knows our customers, who they are, how we sell different products to different customers. After the coffee break, we will have Janne Pirttilahti talking about Cloud Protection. Those of you who have been following us know that this is a new business that we're quite excited about, so we decided to give you an opportunity to know more from the best possible expert available. Last but not least, this is a CMD after all, there will be Tom Jansson, the CFO, telling how all this turns into the WithSecure financials. We will take all questions at the end, so note them, keep them for the end. There will be a long Q&A session. If you're following the webcast, you can put questions to the chat all the time, and we will take up with the presenters at the end. Now, with that, I am handing over to the CEO of WithSecure, Juhani Hintikka. Good morning, and welcome. This is our first WithSecure CMD, so glad to see so many of you here with us today, and also welcome to all of you online. This is also for us, a continuation of our Sphere event in this venue that we have just been entertaining two days, customers and partners, and listening to different kinds of presentations and views around our industry that is really a hot topic for many at this moment. Let me talk a little bit about what we're actually going to cover today, and what is the objective for us here. First of all, we'd like to talk to you about our vision for security as a service. This is an industry that is complex, and increasingly the customers are looking for partners who can provide them things as a service. We actually talk about the servitization of security. We will further demonstrate how we are positioned in this large and fast-growing market. Finally, we will show you how we enter this era of profitable growth, and we will also specifically focus on our cloud-native solutions, which are driving our growth going forward. Hopefully by the end of this day, or by midday, I should say, you're all well aware of our plans, and you're convinced that this is the right way to go, and we like what we hear. That's our objectives for today. Let me dial back a little bit and talk about some basics, who we are as a company, where we are coming from. We of course are a young company as WithSecure, but we've been in this business for over 30 years. We have this history of being in the cybersecurity business, being one of the pioneers, and of course today. We are the largest player in the Nordic market in cybersecurity. Interestingly, after first of July, we will have created the biggest and the second biggest cybersecurity company in Finland. In terms of revenues, just to give you a bit of that in terms of where we were at the end of Q1, EUR 131 million of revenue delivered by 1,250 employees around the world, various nationalities. We actually have over 70 nationalities. Over 90% of our people are also university-trained, so we have a fairly high level of education at our company. Our partners form a key part of our operation, so over 7,000 partners in those countries where we operate, and we have just been entertaining them here for a few days, and I think somebody just said that our partners simply love us. We are, of course, very happy and want to take that forward. Some key indicators. Starting from the left below, net revenue retention, really important metric, which is essentially telling us how successful we are of broadening our reach with our current customers and selling more to existing customers. EUR 64 million cloud solutions ARR. That is an important figure because that is something that is giving you a perspective of how big is that growth portfolio in our total revenue. 36% cloud solutions ARR growth, hoping to further boost that but already at a good pace. Finally, Net Promoter Score of 72, very high, which is telling us that our customers like us. They are happy with what they're experiencing. In terms of the revenue split, where we were at the end of Q1, you see that on the upper right-hand corner. The cloud native that I talked about is already 43%, and then we have the on-premise, which is essentially also covering many of those customers who will eventually migrate to cloud native solution. There is a transition going from on-premise to cloud solutions. It is the same transformation that the companies talk about when they say that they are transferring these operations to public cloud infrastructure. Consulting 35% of the total, an important ingredient in this total thing, because having both consulting and software services in the same company essentially gives us the possibility of flexibly serving depending on the market need. This is a dynamic, fast-evolving market. Consultants also give us the insight. These are the world's best hackers. They will give us the best insight as to where the market is going, and we will distill that knowledge into our products and services that we use for serving the market. Geographically speaking, we are, of course, a very much a Nordic and a European play. You see it on the numbers, on the percentages. Also importantly, we have a couple of markets where we are present, and they are among our top five markets, namely USA and Japan. Those are also both very important markets for us. USA is the most advanced cybersecurity market in the world. It's also good to be present there to understand where the market is growing, going. Many of our key large customers are actually based in the U.S. as well, and they expect us to serve them there. Naturally, we are there. In Japan, we have had a long-standing good relationship with many customers, and the Japanese market, of course, by nature is a relationship market. You go there not quickly scoring a business or a deal, but you go there, you establish the relationship, you build your presence, you demonstrate your quality, and then the business will come. We are in that situation today. To draw your attention to a couple of the really key metrics here from the previous one, cloud solutions ARR growth 36%, that is a really important indicator for us because it's telling us that we're growing, we are growing the ARR business, and we are transforming our company into a pure SaaS player from that perspective. The net revenue retention, that essentially is telling us that our land and expand strategy is working. We enter a customer with a certain entry solution, and then we broaden our scope, whether it's about the products themselves or with products and services to complement them. We have done this transformation already for quite some time. If you look at the numbers between 2019 and 2022, we have taken this step from 30% to 43% already in terms of the cloud native. We have a track record of doing that, and we will continue that towards our 2025 goal, which is obviously, as you can see, majority of the business would then be coming from this cloud native portfolio. The market. Obviously, cybersecurity is very topical at the moment. You read about it almost every day in the papers, different kinds of threats. It started with high-profile supply chain attacks recently. It went on to ransomware. Now, of course, the geopolitical situation is driving that discussion to a larger extent. The threat landscape continues to expand. It is also a complex market for many reasons, but one of those reasons is that, of course, we deal with the IT infrastructure and the processes, and there's a lot of legacy, and that is a complication. Sometimes the cybersecurity is not so much about bringing in a cybersecurity solution, but it is actually about doing things in a right way from an IT perspective. The competence gap. All of us, frankly, experience that today in the marketplace. It is our job to find the people, to train them, and broaden the reach in terms of the capabilities that we all have to serve this market and solve these issues. We have decided to take the outcome-based approach to this. What does it mean, outcome-based? It means that instead of talking about the different things we are doing, we're actually talking about the impact we are making, and we want to make it really visible for our customers, what that impact is, how we're helping them to sort out their problems. We would also like to make complex simple, so we will drive for simplicity, whether it's about the solution itself or whether it's just about the business model, how they deal with us. We have, for example, introduced to our partners the concept of being able to buy cybersecurity by consumption on demand. You pay for what you consume, as an example. We want to do this together. No one can solve all the cybersecurity problems alone. It, of course, means very much about the collaboration we already enjoy with our partners, over 7,000 around the world, working very, very closely together. It is also about us being close to large end customers, understanding where the market is growing and where the most attacked places are and what the problems are that we're covering. It can also mean some collaboration in the industry where we routinely share threat landscape information. The market. If we start from the left and look at what are the categories in the marketplace, this is obviously a huge market. If we look at our B2B cybersecurity products, in 2021 we were looking at a market of EUR 16 billion, and now we are foreseeing a 20% growth, taking that market size up to EUR 34 million by 2025. Really handsome growth in the marketplace. In the middle, managed detection and response. This is a market where there is a technology platform used for detecting and responding to threats complemented by people, experts, threat hunters that we and others provide into the marketplace. Here, clearly, we see this is one of the new areas of growth, and why is that? It's partly because of this competence gap that I talked about earlier on. Not every company can attract the right kind of talent to operate the technology, and sometimes also the technology is just so complicated that it's actually better to take the technology and some experts with it. This has created this managed services market, Managed Detection and Response. The U.S. started this, and now Europe is coming a little bit behind, so there's quite a lot of opportunity in Europe, specifically in this space. Then finally here on the right, cybersecurity consulting, the largest segment, quite naturally, because simply there isn't a product for every need. You will need people as well. That market is also growing, so we see an increase in demand, and we've seen that concretely ourselves. Market growing at a rate of 10%, taking to EUR 38 billion by 2025. Huge opportunities in all of this. What does it mean for us? Well, first of all, it means that we have different categories where we want to play, and even these large categories divide into smaller areas. We of course want to pick carefully where we are, where we play, and how we play so that we can differentiate and create the winning combination. The cloud solution portfolio that I talked about has essentially three key components. First of all, we have the products, the Elements. That is our product portfolio that we launched to the market approximately one year ago, and it's been very successful. This is a partner play, so our partners take these products to market. While we have been looking at creating state-of-the-art technology, providing the user experience that is required, we have also looked at the way of doing business and how can we support our partners in terms of the different billing models that we, or pricing models that we offer, what kind of programs there are to support our partners in general. We have also invested a lot in automation because many of these smaller partners, of course, we want to deal quickly, even without human intervention, so that they can order and have the product delivered without ever talking to a human, and that's fine for all parties concerned. We will continue to accelerate that, invest into that portfolio, and that covers very much today the mid-market. We are bringing basic capabilities in a very well-structured way, expandable. The modularity makes sure that we can expand flexibly, and we take that and bring that basic capabilities to the mid-market. In the middle, we have something called Cloud Protection. Many of the SaaS players that you see out there, they of course take great care in protecting their own system, whether it's in our case where we started from Salesforce, but there are also many other SaaS players. They obviously are responsible for the integrity of their own system, but they typically don't take responsibility for the content itself. We are there to look at the content and make sure that it's not malicious, and this is a huge opportunity for us. We will hear more about that later on today. As a third part, this is Countercept. This is the managed detection and response, and this is the services part. Here, clearly, we are complementing our offering with the services. We are bringing in people where they are required, recognizing the fact that not all problems can be sorted with products alone. This is clearly where we are also aiming for a little bit bigger companies and we have recently been very successful in winning some major accounts in this space that demonstrate our capability of handling end-to-end endpoints as high as over 100,000 endpoints in one company, one customer. Back to people. What I said earlier about the degree of education is visible. Over 90% of our people have a university degree, and they like us. When we look at the external ratings, Glassdoor rating, 4.1 out of 5, that is a really good rating because at the end of the day, we want to create the environment for our people that they will thrive, they see this as an opportunity for personal development, and they see our culture appealing. We think that culture is one of those cornerstones that we want to build, we want to nurture, and it's very, very resilient. When you look at companies, strategies change, organizations change, people change, but very often, culture is the one constant that is behind all of that. We pay a lot of attention to that. Over 70 different nationalities, we truly are a global company operating in roughly 15 countries. Our aim is to have one of the strongest cybersecurity talent pools in Europe. Of course, we need the right leadership team, and we have seen some change here over the past 18 months, and we're very happy what we have today, and not everybody is here today talking to you, but these are the people then that are part of the leadership team that we have. Finally, coming back to medium-term financial targets that of course are of interest to this audience. We have already talked about this before. Our growth target remains unchanged to double the revenue organically by the end of 2025, and I stress the word organically. This is our plan that we are executing at the moment. Profitability, EBITDA break even by the end of 2023. Let me end by recapping why do we think this is a good investment. We're operating in a large and fast-growing market. That is clear. There's a lot of demand, and it's just accelerating. We have a strong value proposition, and we see that we are generating high retention, both among our partners and our end customers. We have the portfolio, fast-growing cloud solutions powered by world-class consulting, all coming together very nicely. Finally, there is a plan to deliver the shareholder value. Ladies and gentlemen, let me end by leaving you with this and inviting the next speaker on stage. It's great to be here today. My name is Antti Koskela. I'm the Chief Product Officer for WithSecure. What I'm gonna talk about today with you is about what is our broad and unique security operations offering, why we do the things we do. I'm gonna talk about the customer-centric security outcomes that how we get the customer need-based portfolio and how it's interrelated. What I'm actually really proud, I've not been in the company for a long time, since September, but we have gone a long way with the cloud-native portfolio. I'm gonna talk about a little bit why we have cloud-native portfolio and how it's enabling the scaling of the SaaS business. I think that's an essential element. I'm gonna touch base on these three things. Let me start with the broad and unique security operations offering and the positioning we have selected. What you see here in the slide, you see here scope. There are companies which are focusing on either consulting or software. Then there are companies who do both, software and consulting. That's on the y-axis, so to speak. The other important point is that where the companies are originating from. We have a lot of North American players here, like Juhani mentioned, and then we here in Europe, I think we have mainly companies that specialize either in services or software. We think it's a quite unique place to be having both as software and services because in this business. I've been in software business 25+ years, and what is unique with this business is that we need to day in, day out, learn the things. Like last week, there was a new vulnerability on Windows. We covered on Thursday. Solutions to the market, to every user on Friday. This is not business where we wait, but we respond instantly, and that's why this, high-end cybersecurity threat intelligence, work we do every day with the customers, how we turn that into productized outcome is needed. Customers will not educate us how to build things we do. We need to know better. How this looks in practice? With this slide, we tried to depict the why the portfolio is done in this way and how the different learnings and different insight turn into scalable software platform that we can then scale with the partners. Let me start first with the consulting things. When we work, for instance, with incident response, we work with some of the 400-500 customers with the hardest cybersecurity problems out there. We get frontline insights and expertise that gets fed back into our products. Not only that, but then our products give the speed and precision to get these consulting outcomes. I think that's very important. We get the strategic learning into our offerings that which then drives the productization of this easy-to-use portfolio that we scale with partners, the Elements we talked about. Once we deploy Elements in full scale, of course, the cloud-native portfolio becomes highly scalable, helps the services, and the flywheel, in a way, works. It's not only about consulting. We have, like Juhani talked about, we have done a lot of experimentation now with the SaaS ecosystems. My colleague Janne will talk about the cloud protection for Salesforce. We get frontline insights from these ecosystems, and what is the key here is that when we work with these companies like Salesforce, we protect their content over there. We are benefiting from the same tech stack that we have underneath. I think that's what the key thing here is all about in this slide. The R&D efficiency comes from the common technology foundation that serves all the portfolio, and this is what cloud-native companies do. I find that super cool. I think I can't hide my excitement on that. The other piece we talked about, I'm not going to go to the specific points on the security outcomes, but I mentioned a few things how this again works. We describe our portfolio using different categories, consulting, managed services, our SaaS Elements portfolio, Cloud Protection, and underneath you have a shared technology foundation. What's the key here is that while these represent customer needs, it's the strategic learning we get. Let me take two examples for you. When we started to work on the cloud with some of the like infrastructure clouds, AWS, Azure, and the security in those ones, initially that started off as a consulting thing. That learning actually today is available as a managed service, Countercept Cloud Security Posture Management. What we are working right now is that obviously, how do we get this into the hands of our partners using the scalable method that we are having? That's really how the system here works. The core thing here underneath is that through our shared technology foundation, we can productize the security outcomes into easy-to-use, highly productized elements. I think that's the flywheel in a way, what we are having. I know that this is an analyst audience, but I want to talk about technology a bit, a little bit, what's under the hood or under the bonnet as they say in Britain. I've been working with my colleague William here, and I think, let me take an example that when you as an organization are using our products, so you would have a security solution from us, and that you have, what's your name, I think? Felix. Felix, you have a laptop, iPad over there. We would have a sensor in your iPad. The way cybersecurity companies work is that we collect telemetry. We collect telemetry, and based on that, we can decide what's normal for you and is there anything malicious happening that we need to react on? The way the technology work is that we collect data that drives autonomous decisions which are data-driven, so we get fast response to any incident. Of course, that's fueled by a lot of research I talked about. How do we get this one learning to everybody? That comes from the fact that then you have a cloud native, you have living services. Think these as Legos which are dynamic Legos. We assemble products from dynamic Legos that are all operating independently, and then the product gives you the outcome. Needless to say, we encrypt everything in the data, we take care of the privacy, and we have highly sort of structured things in the background that we have a certain implementation practices, that you only do certain things once, and you don't customize. What I mean with that one is that you have all played with Legos. Think about dynamic Legos. You don't wanna change the Lego, how it's structured, but you can innovate with extendability using a Lego paradigm, and I think that's how cloud-native software works. Again, coming back to you, Felix. Why it's relevant for you? We update your software 20 times per day, like was the case what I mentioned about the recent Windows. The engine updates on average, that's 20 times per day that's happening day in, day out. The cloud-native software, when it's in the hands of the Elements customers globally out there, we detect a staggering 500,000 topics per day. We respond, we detect and respond to incidents 8,000 times per day. That's how the scalability of the business model comes. It's efficiency through a common R&D stack, and then you can't be a SaaS company if you don't have cloud-native architecture. We have cloud-native architecture which scales with the use without scaling the cost. I think that's really important. Looking back, I think the key competitive advantage we think we have. We have been in the business plus 30 years, but we have earned the right to be the partner of choice for many, many organizations. We keep people and society safe. Many people who come to work for a company, they work for a cause. We keep people and society safe. That was the reason why I joined the company. It's a noble mission to do good. I think in this day and age, people want to have meaningful, sustainable outcomes on the companies they work for. The other bits what I talked about, when you are a SaaS company, you have a cloud-native platform. It's not just building blocks, but you really operate it day in, day out from the cloud. We have been rated number one by our partners and in the recent studies. The third thing, I think, which is actually the third and fourth bullet here, is the experimentation. We learn a lot from our consulting engagement, services engagements. We learn a lot from the engagement we do with app ecosystems. That has led us to be a category leader in the cloud content protection among the Fortune 500. Gonna talk about that later. It has allowed to us to have a market-defining detection and response solution. The last point is proven in the United Kingdom, the National Cyber Security Centre has certified us as one out of nine organization who are eligible to do incident response globally. That's who we are. Summing up, the broad and unique security operation offering, it ties up our services capabilities with our scalable software. It's about strategic learning and insights that we need to get day in, day out, that we keep the products like they are. Cybersecurity is not standard software business. This needs very much content research on the security that we then productize in a SaaS fashion. Second one, It's about the co-security and customer-centric outcomes. Our portfolio is structured so that it responds to specific needs. Last but not the least, what I wanna emphasize once again, you are not in the SaaS business if you don't have a cloud-native, autonomous software, which is data-driven machine learning DevOps working natively from the cloud. That's what we have here, and we are ready to scale. I think, Tom and the others will tell how this turned into numbers, but I think it's looking really good from my point. That's what I wanted to cover today from my part. We are ready to scale. That's where I leave my statement for today. Then for the next speaker, we're. It's we talk about the customers. Good morning, everybody, and thank you, Antti. My name is Ashley Clark. As was announced earlier, I'm the VP Commercial for the Solutions business unit. I have, if you like, in that role, an understanding of both consulting and managed services. Prior to that, I was a VP Sales for our Business Security Business Unit, which looks at the Elements portfolio as well as the Cloud Protection across the channel. I'm here today to talk to you guys about how we work, both with our customers and in terms of the go-to-market model. When talking about that, I would like to make sure that you guys take away how we are positioned to grow with our customers. How we are positioned not only to grow with our customers, but also to win new customers, and that we have a proven partner model that enables us to scale. Now, in doing so, I think it's really important, as we do with WithSecure, is looking at our customers first. With over 35 years experience, we understand our market. We understand what the enterprise needs. We understand where we are with the mid-market, and how we can scale to the small business as well. As Antti's already discussed, we have the portfolio which really resonates with these customer groups, and we have the go-to-market model which is appropriate for that customer base. It is so important to be successful in this market that we have both the flexibility and the understanding to use the go-to-market model that our customers need. If we first look at what are we doing, excuse me, in terms of growth, you can see that we have grown. We have over 140,000 customers. It's important to recognize that we serve these customers both direct and in partnership with our channel. It's not just about volume, it's about their profile. From the slide, you can see that we have a working relationship with the top six global banks. We have, as part of our customer base, over 40 Fortune 500 customers. Now, this is very significant because what we have to do is effectively monetize that. As Antti has already spoken, we have the portfolio. We understand our customers. This portfolio is resonating. The way that we are engaging with our customers is resonating, and you can see that the share of the wallet is increasing. We are on that path. Recently, Juhani mentioned this slightly earlier, we won one of the Fortune 500 companies we announced at the beginning of April. Now, it's very important to recognize when I'm talking to you about customers, unfortunately, I can't give the names. In the business that we are in, anonymity is super important. If you don't mind, I will talk about the customers, but I won't be able to give the names. This Fortune 500 customer, significant managed detection and response service, so our Countercept service they chose to use. That wasn't where it started. We started engaging with them around our consultancy services. We understood their business, the threats that they faced, and then we moved into incident response. Having helped them in a number of cases, we were then able to work with them. This is where the importance from a customer's perspective of co-security rings true. We understood their business, they trusted us, and we were able to expand to a significant over 100,000 endpoint managed detection and response win. It's not just about growing, or this is a proof point as you can see that we are accelerating, but it's also about the retention. Now you can see from this slide, we operate in a number of vertical markets. You can see that our customers stay with us. Why do they stay with us? Co-security. We understand them. They understand us. With that length of time and engagement, you don't have that if you don't have something that resonates that they need, that they recognize. You don't have 113% net revenue retention rather, without being successful. It means we're keeping our customers and we're growing. The acceleration of the share of wallet that I mentioned earlier is picking up. Again, Net Promoter Score, you don't get these kind of numbers unless you have a portfolio which resonates with your customers. We work in diverse markets. Right? We have the ability to scale. Let's talk about that in a moment, but just to recap. We have a broad customer base. We are accelerating our growth into it, expanding our service reach. We are winning new customers all the time. If we look at how, let's talk about the go-to-market model. We have two models. We have direct, and we also have channel. As I mentioned earlier, it's important to have both because our customers want to consume security services in the way that they need to. If we talk about direct for a moment, this is very much about the enterprise engagement. We need to work directly with our strategic accounts to really understand what's important to them and their business. That doesn't mean engaging with one person, it means engaging with a number and extending the network that we have across their business, so we truly understand where they are going, the threats that they face, that we can take that understanding and match our portfolio to them, and again, effectively deliver, land, and expand from a WithSecure perspective. Okay. Where we are with the direct model is it gives us an understanding, both of the customer, but also of the market. Again, co-security. We are the experts. They recognize that. We've shown. They stay with us. They use a multitude of our services. When we do this, we make the most of our customers, and we scale. We have to be able to address the other customer groups that I mentioned before, the mid-market and the small business. This is where the channel is very important. We have a number of groups here. We have several thousand channel partners. Again, why have we got these different groups? It's because the customers want to consume the services in different ways. Which is why having managed service providers, value-added resellers, are so important. When we're looking at scaling the small business element, this is where we've largely automated the management of the 5,000+ partners that we have working in that market. We're able to take the portfolio that Antti mentioned and extend and expand and grow that space. Where our team's, and my team's, focus is around preferred partners within the managed service and the value-added resellers position. Again, coming back to co-security, it's making sure that we understand their business, that we understand their customers, and it's working together to create value propositions that not only resonate in the market, but actually provide market differentiation. This is very much about one plus one equals three. Now, if we do this, as we have been, you will see the channel scale. We have the right partners. We have the right quality approach, both in terms of portfolio and in terms of co-security to deliver that market differentiation to truly scale. As you can see at the bottom of this slide, if you have partners that are working with you for 17 years as an average, let's think about that. That is a significant period of time. We have understood their business. It is so important, excuse me, to deliver co-security in that way, that understanding, that partnership. Again, the Net Promoter Score shows that we understand our business, and we understand their business, and we understand their customers. To wrap up, excuse me. As I mentioned the three key messages earlier, we are growing within our customer base. We are expanding. We are successfully executing the land and expand approach. We are winning new customers all the time. Our partners love working with us. We've just finished the first event that we've held as WithSecure Sphere, and we had hundreds of partners coming. If you pause there for a moment and you think, bringing people to Helsinki, to such a successful event, and what that means after COVID. Bringing people together is not normal yet. To have that response from both our customers and our channel partners is such a strong message to both us and you about how we are positioned to make the most of the opportunity ahead of us. Thank you very much. We're gonna have a short break now, and a bit of refreshment, and then Janne Pirttilahti will talk straight after about the Cloud Protection service. Thank you. Welcome back. Now the part that we have all been waiting for, Cloud Protection. Janne, please. Welcome back from break. Good morning. Thank you, Laura, for setting the expectations. My name is Janne Pirttilahti, and I'm leading our Cloud Protection business. I've got over 20 years background in security, originally product development, then product management, strategy, sales, all sorts of positions, various leadership positions, and now leading our Cloud Protection. I'm really excited about this business and therefore happy to take you to a short journey on this topic today. Three things that I would like to leave you with. Firstly, what is the need, really? Why did we choose to do what we did? Second, how are we doing as of today already with the business? It's fairly new business, but how are we doing so far? Thirdly, of course, what is the growth outlook? How are we planning to grow this business? These are the three key points that I'm going to make today. Juhani already touched upon this. What do all big cloud providers have in common? Be it Google, Amazon, Microsoft, Salesforce, who have you. Well, the fact is that they all do great security, actually. There is nothing wrong with security they do. One of the reasons we trust that them, also we as WithSecure, is that they do great security when it comes to infrastructure, physical networks, operating systems, their data centers. They protect themselves. They do also protect customers. It's not away from the customers, it is very much for the customers. But what is also true and in common is that under the surface, there is a lot of security things that they are not necessarily touching. Now, the details vary a little bit ecosystem by ecosystem. It could be that Google is doing something that Microsoft is not and vice versa, what have you. The key thing is that they don't take care of everything. There is always customers' responsibility. In cloud, these vendors call this shared responsibility model. We as vendors have our responsibility, customer, you have your responsibilities. Content typically being customers' responsibility. This is why we are doing cloud content protection and other things in cloud to help the customers to tackle these customer responsibilities so that they could leverage all the advantages of these modern cloud platforms. As mentioned already by Antti and Juhani, we started this with Salesforce for a couple of reasons. Firstly, Salesforce is massive ecosystem. Now, if you think of Salesforce as the cloud-based CRM, which it was when Marc Benioff founded the company back in 1999, you need to a little bit update your knowledge. They are all things digital when it comes to customer experience. It's not just CRM platform. It's a cloud platform for digital customer experience, exchanging communication data between businesses, between businesses and consumers. That's massive. Salesforce is serving over 150,000, most of them quite large organizations around the globe, some of the biggest on the planet. Their revenues last year, almost $27 billion. What's important is not Salesforce revenues, it's the ecosystem around. According to IDC, the ecosystem Salesforce enables around them is worth more than $100 billion already. Share of third-party software out of that $100 billion is estimated to be at $24 billion as of today, 2022, and all of these numbers are growing. All of these are in double-digit growth. Salesforce revenues, ecosystem, number of customers, so on. We play in a big market. Also, there are needs with Salesforce. There is very clear shared responsibility model. We don't compete with Salesforce. They say very clearly to customers, "We don't look into your content. That's your responsibility." There are use cases because data exchange ownership, while already in CRM, but more so when we enable communities, Service Cloud, which is their support services, digitalization platform, and so on and so forth. Now, the small print here is maybe not important. That's a lot of details to be read. I give you an example. I've seen three or four of these very recently, within the past three months. Customer, typically a big one, implements digital customer support using Salesforce Service Cloud. It enables them to funnel all the support cases directly to Salesforce, correlate that with customer data, process it very efficiently by the support agents. That's a nice way to do it. Salesforce grew this business during pandemic massively. Now, primary vector into the organizations when it comes to cyberattacks used to be email. It still is actually email. It's not the sole vector. There are many other ways to get into the corporation. It used to be email. You send an email with malicious file or URLs, you expect somebody to click a file, a link, something like that, then infect the machine and move laterally onwards. Email is very well protected nowadays. What have the adversaries done? They've moved to Salesforce. I've seen three or four cases where a big corporation was infected so that they are able to tell that this happened because somebody uploaded a support ticket with an attachment that was actually a virus. It was clicked open, we got infected, bad things happened. This is what we inherently prevent from happening. This is the profound need. It's not just support cloud and services, but everybody is using Salesforce for various interactions. There is data exchanging hands. You are sharing something to customers which maybe came from source that you didn't trust. You want to make sure that you're not sharing onwards anything you can't trust. You are intaking data from other businesses or consumers. As an insurance company, maybe insurance claims and with attachments or support tickets or what have you. This is what we protect, data, any unstructured data, files, URLs, messages. We inspect inbound, outbound data in the Salesforce platform. Now, it sounds elementary, but it's not actually very trivial to do. We integrate to Salesforce. This is natively available from the Salesforce ecosystem. That's important also. That's important for us, that's important for customers. I tell you why. It relates a little bit to our go-to-market model. We don't sell to Salesforce. Salesforce is not reselling us, we don't sell through Salesforce. We sell direct, typically to quite large enterprises. On Ashley's chart, this product went all the way from major enterprises to small businesses, which is true because the need is everywhere. Everybody has the same need, and there are Salesforce customers who are fairly small. Direct, we obviously sell to large enterprises and higher end of the mid-market because that's where the direct sales is economically efficient. We distribute software from Salesforce AppExchange. If you're unfamiliar with this, think of Apple App Store, which some of you have your mobile phones or Google Play. This is for business applications in the web. You download an application because we have natively integrated it to Salesforce. You install it, you implement in less than five minutes, even as a large organization, you're up and running with all the features, functionalities, security, visibility and things we are providing. That's great for customer, but for us, that gives scalability and delivery efficiency. We started the business quite small, shot some BB gun bullets, they hit the target. We shot more, they hit the target again. From the beginning of this year, we shot with the cannonball. Now we have dedicated sales and marketing teams, and I'm leading a business area which is dedicated only for this business because it's scaling fast, and we are serving major enterprises. We do collaborate a lot with Salesforce, and this is one of the keys to our sales scalability here. For us to double or triple or quadruple the revenues, we don't need to double or triple the amount of sales and marketing investment. We do things together with Salesforce, leveraging their account teams, platform teams, architects. We have joined customer events with Salesforce. Because we don't compete with them, they're super happy to do this with us, actually. We are complementing their offering. We are doing something for the customers that their customers truly need, and sometimes it might be that they need that in order to implement the Salesforce. They wouldn't even be able to use it for regulatory compliance reasons, for example, without us. That's what we do. The important thing is that it's scalable. Scales massively well. We found the formula for the sales and marketing scalability of this business. Now, where we see success so far, what comes to industries everywhere, and this is important, proof point so that we don't, we are not viewing a niche solution exclusively for fintech, for example. We have customers in financial services, manufacturing, high-tech, recruiting agencies, ad agencies, what have you. Absolutely everybody who is using Salesforce, which is 150,000 companies and growing, has this need. Geographically, we've been successful everywhere we've tried, where Salesforce is big. Unlike for the rest of WithSecure here, the biggest portion of business comes from North America. That's the biggest digital market. It's important to be successful there. We are really, really successful there. We will grow that still, but we will also grow elsewhere because the need is everybody, everywhere. We have global broad demand. Customers absolutely love us. We already shared from other businesses NPS numbers, NPS 72. Well, I have five out of 5 stars in AppExchange. Maximum. Don't get higher than that. Everybody gives us maximum ratings 'cause they need the solution. They are happy with the features they have. We get nice quotes. That's from a program director in an IT hall serving exclusively big banks. That's actually a public reference, but I'm still not gonna share the name, so. They recognize that Salesforce doesn't do everything, and they need us. We are serving multiple Fortune 500 customers. We are serving smaller customers also because everybody has the need. With the bigger customers, the important thing is that not only we have the best product, that helps, but we are WithSecure with 30 years of history, with credible organization, industry certifications such as ISO 27001, ISAE, SOC 2, and so on and so forth. We have HIPAA for U.S. healthcare industries for this solution. These are things that are not easily copied by some small startup. We are well set to further grow this with the large organizations. This is how we're doing so far. Moving on to what is happening next. Obviously, we are not going to stay with Salesforce only. We will do this with Salesforce, make no mistake. We will grow this with Salesforce, but we will go to other ecosystem, and the next one, and the next one. We have the roadmap for that, and that's the technology growth engine. Now we've proven that the business model works, and the core technology can be leveraged. We have technical scalability there. We can use the same core technology to go to next ecosystem. We have learned something about the commercial models, but there is also room to grow with Salesforce. We can go to rest of their offering. We are not everywhere yet. They have, for example, Slack, which they got through an acquisition couple of years, year and a half back, if I'm not mistaken. A collaboration platform. We are not covering Slack messages yet, but we are actually, we already have a prototype, so we are going to do that. That gives us more sellable items to even existing Cloud Protection customers and of course, to new customers. This building better product within Salesforce and outside Salesforce gives us growth both with existing customer base and outside existing customer base. On the commercial front, the second growth engine. This is going on as we speak, 'cause we started the big investments on sales and marketing from the beginning of this year, and we've already seen tremendous success. The sales cycles with this product, even for big organizations, tend to be relatively modest. We are going to expand geographically to where we haven't yet even really pushed the product. Then lastly, not least, we are going to capitalize on the group-wide synergies. Now, Antti talked about technological synergies with which are there without a doubt. This product benefits from the learnings from consultancy, from MDR, and also sometimes vice versa. The sales synergies are massive. Ashley mentioned we have, as WithSecure, more than 40 Fortune 500 companies, for example. Some of them are now using this product and this only, but all of them are, for example, potential consultancy customers. We have the case that Ashley spoke about. Fortune 500 company which started as consultancy, moved to MDR. Now that very company, to my belief, is a Salesforce customer. We may have an opportunity with Cloud Protection. It goes, again, both ways, and we are going to do more of this. Now reason why we didn't do yet is we just didn't have time. We were busy running to jump on a bicycle 'cause this product is growing that fast. Three things I want to repeat. There is a profound need for this type of security as partnership because cloud providers are not doing everything. They are fine with this. I said, Salesforce recognizes this. They share go-to-market with us because they view this as customer's responsibility. There is a profound need, everybody, everywhere, and this is why we are seeing a broad global customer base already. Lastly, perhaps most importantly, we absolutely know how to scale this. We already have plan, and beyond that, we are executing that plan as we speak. That was my part today. Thank you very much. My name was Janne, and next up is our CFO, Tom. From me as well. Tom Jansson is my name, and I'm the CFO of WithSecure. You have heard about our opportunity, you have heard about our products and solutions and about our market, go-to-market plan. I'm here to talk about how this translates into our finances, and also hopefully a little bit give you guidance on how to think about us when we embark on our independent journey as WithSecure going forward. The key message is to think about us from a financial point of view. As many of you know, especially here in the room, we had a share issue earlier this year, a successful one, which laid a great foundation for us to execute our organic growth strategy going forward. We have a strong balance sheet that we can go forward with. As some people already have mentioned, we have a strong momentum currently in our cloud portfolio and see that continuing also going forward. We have a clear path to profitability. Those are the key things that I wanna share with you today. First, maybe just a little bit of reminder, also financially, how the WithSecure business model works. We are, if you look at the high level, we are a subscription SaaS company, with the exception of our consultancy practice. If we think about Elements, as I believe Antti or the previous speakers spoke already about, the business model in Elements is one of the strengths also. It's easy to deal with us in all respects. As said, we have also created a usage-based subscription model from our customers' requests, which actually is, as far as I know, the only one on the market that is offering that. Our Cloud Protection that Janne spoke about is a pure subscription model, as well as the Countercept. On our consultancy, obviously, that is more either project-based, day rate, hourly based. There also we have a lot of customers that ask us for new things continuously. We have the recurring annual or monthly fees. As from a cash flow perspective, this is obviously also quite positive for us because customers pay us up front and therefore for those who follow us have seen that we have a substantial amount of deferred revenue in our balance sheet, and that's the driver for that. Hopefully this gives a little bit of reminder of also how our business model works going forward. If you look at the actual numbers, and this is a bit of a repetition from a lot of what have been already said today, you can see here that the dark blue bar is growing and has good momentum. Also important to note that also our on-premise is still a significant portion of our, but obviously we are expecting that to lower as we go forward, as they move to cloud-based solutions. Maybe worth mentioning though that our growth in our cloud mainly comes from new customers. There's a share of transition also, but the main growth engine is new customers for us. As well, our consulting is still a very important part of our business in many respects, also financially. Here you can see a repetition of this. We posted in Q1 just recently a 36% growth year-over-year, which it constitutes our momentum. As you can see from our previous numbers, this is growing faster at the moment. That's, obviously, a good thing, and we expect that to scale going forward as well. The consultancy being quite stable. Obviously, there has been some challenges in consultancy with the COVID earlier that had some impact on the level of business. We have had, as those who has followed us know, we have had some attrition, and so on that has sometimes a little bit impacted our delivery capability, but we look at that as very positive going forward, and it's strategically very important for us, as many of my colleagues have said. In terms of the numbers, we did a few divestments. One smaller one in the UK end of last year related to some government part of the business, and then we divested our South Africa consultancy beginning of this year. That had a seven million annual impact going forward on the consultancy revenue top line. To maybe a little bit give you guidance also what we think about our gross margin, and these are our ambition levels. If you look at the portfolio from that perspective, we expect Elements to be highly software gross margin. Our ambition level is in the 90%-ish region. This is pure software. In terms of the Cloud Protection, that there is some additional cost to operate in these partner platforms related to selling and other things. Our ambition level is a little bit lower on that part. On the Countercept, as has been said many times, there's also a human element in the Countercept solution related to threat hunting and some other things. Our gross margin ambition level is more in the 70s in this respect. As we have said, in terms of the consultancy, we are more in the high-end part of that, and therefore, we do expect our gross margin and services to be in the 50s. On all of these solutions, we still have work to do, but as we scale, this is the kind of levels that we are targeting on our different parts of our portfolio. As you can understand, as the majority of our revenue going forward will be in the scalable software part, we do expect our blended rate also to improve over time, which obviously is a key for our future profitability. If you look a little bit on what we expect from our future. As said, revenue, highly scalable, good momentum, and that we expect to grow going forward. Gross margin, as I just explained on the previous slide, our blended rate, we do expect that to improve as we grow. On our cost structure, our sales and marketing of part of the sales is quite high today. We do expect some scalability in that respect, even though that's an important part of this business and in general in this business, sales and marketing is important. We do expect some scaling effect on that going forward in terms of percentage of revenue. The same with R&D. Antti talked about our product portfolio. Obviously, to develop that is really key for us. As we scale, we do expect some percentage points gains also from that perspective when we go against break-even point and when we go then further to our midterm targets. The admin part, highly scalable. That's what we expect from our admin costs. We don't expect. There will be obviously some, but as there always is, we expect our admin cost to scale significantly compared to where it has been. With these markers, we're trying to point out how you can think about, should and should be thinking about as we're going forward, and what we are planning. Coming back to this foundation, financial foundation. As said, our cash position balance sheet will be strong when we go forward, and we are really pleased about that we have a great base to execute our organic growth strategy. Our equity ratio is also in a good position today. What it allows us, obviously, is that we can develop our existing portfolio, give opportunity to take short-term development opportunities as we see them develop in the market. This is obviously a market that evolves very fast, so we think this flexibility is important. Also potentially room for some short-term market opportunities. I would also mention that even though potentially this cash, but M&A continues to be in our toolbox going forward as well. That may be financially is a different discussion than. If I come back to what Juhani started with, I hope we have been able to demonstrate to you that we know the markets we operate in very well. We know our customers, and we know what they need. I would also mention that we have detailed plans that supports these targets. From that perspective, I think we are in a good place to have and post these medium-term financial targets, which is to double the revenue compared to end of last year, which was EUR 130 million. We see our way to a break-even point in terms of profitability in 2023, end of 2023, and then moving forward, more a software-like company EBITA, closer to 20% or so. From that perspective, we feel that we are in a good place. If you look at this year, and we posted this outlook just this morning on the market, this is gonna be a transition year for us. We knew that from the beginning. We do expect our cloud-native products to grow approximately 30% this year, so we see the momentum continuing and even somewhat accelerating in the second half of 2022. Our real revenue, not the ARR, but our real revenue last year was EUR 51.8 million. The comparable revenue for the entire group, we expect that to be in the low double-digit rate this year. If you compare it without the divested consulting businesses, our base for that was EUR 122.8 million. The profitability is, as I said in the beginning, as planned, will decrease this year. We have mainly because we continued to invest and increase our run rate last year in relation to sales and marketing, and also that included the brand as well as R&D. We do expect the EBITA also to start scaling in the second half of 2022, meaning that it will be better. I hope, as a summary, I was able to give you the financials on this. With that, I would call back Juhani for a recap and summary, and then we go to Q&A. Okay, I hope you found that informative, and hopefully we were able to convey to you a picture of the opportunity and our plans in tackling it with our cloud-native portfolio, the plans behind it, the execution we intend to take forward. We clearly see this is a huge opportunity. It's not difficult to understand that when you read the papers and look at the ever-evolving threat landscape. This is more of a question of picking your battles, understanding where you can really excel and be a world leader, and that's what we intend to do. We have carefully looked at the categories where we will compete. We're conscious of the fact that we're taking on the global companies, we're taking on the best cybersecurity companies that are out there, but we are also one of them already. We have been in this business for over 30 years. There's profound understanding and expertise in this company about this market. Just to give you one data point, people talk about machine learning and AI. This company has invested in AI-based solutions for the past 17 years. We didn't just think about it yesterday when we started reading about it in the papers. In many respects, we are a forerunner. We talk about the security as a service. We think that increasingly this is about making complex simple. Really demonstrating to people, companies who don't necessarily understand cybersecurity, and they don't have to be the experts in cybersecurity, they can turn towards us. We need to give them that service, and we need to make it simple. That's why we call it servitization of security. We're uniquely positioned, the market is large, we see that we can grow. Finally, specifically, we're also making this transition with our cloud solutions portfolio into a pure SaaS company that has that as its main growth driver. With that, I will end the summary part here. Now I would like to just ask my colleagues to join me on stage. Maybe Laura, you will do the facilitation then regarding the- With you. Q&A. We have people here in the audience, and then there are plenty of people online and we will be taking questions facilitated by Laura. All right. Maybe we'll first call the questions from the room. Felix, please. Yes. Thanks for the presentation. Hang on. There's a microphone on the way. Thanks for the presentations. I have quite a few questions. I'll go one by one. Perhaps the first one is directed mainly to Ashley. I just wanted to get a brief update on the MDR business model and the contract structures there. What are we talking about in terms of average contract lengths, annual values, and the length of the sales cycle as well, and specifically? Yeah, the sales cycle, frankly, varies quite dramatically. In some cases, especially when businesses are under threat, they can move very quickly. Where we are from a structure Perspective is that frankly, they are typically probably two years in duration. On the channel partner, I guess your focus, I guess if we look back a couple years, has been more on sort of, you know, focusing on the larger, what you've been calling as gold and platinum partners and trying to get to bigger ticket sizes throughout those. I'm just wondering if the focus at the moment in terms of the partner channel is on expansion or rather focusing on the larger partners in the channel or somewhere else. I think frankly where we're trying to make sure, as I said on the talk earlier, is that we have the right partner ecosystem. I think that we've automated the traditional resellers so that the. If you look at our legacy business, it's actually very strong for us. With the growth, when we look at the preferred partners, I think it's, you know, we have a good portfolio. Where we are looking to expand is more in that managed services space, and that's as the markets progress across the different regions globally. Thanks. That's helpful. On Cloud Protection, I just wanted to ask if you could provide us any sense of the size of the business at the moment in terms of number of customers and revenues, and also perhaps describe the competitive landscape there a little bit? Well, if I start with the number part, so yeah, we, as you know, we don't disclose that detail at the moment. At the moment, we have gone to the cloud native portfolio, and that's what we gonna run with this year. Well, I can comment on the competitive landscape briefly. It varies a little bit ecosystem by ecosystem, specifically on the Salesforce where we have the most revenues, most customers now, all of it basically. There are two or three somewhat competitive solutions, all of which we consider inferior in terms of features, functionalities. We haven't really seen these in the market in like real customer cases. They don't have any traction in AppExchange, which is the public data available. Our understanding is that there is some competition, but it doesn't seem to meet the customer needs, and we have couple of years advantage when it comes to technology, and more importantly, building the relationship with Salesforce, which is really difficult to copy. Thanks. Finally, a couple questions perhaps to Tom. I just wanted to ask on the guidance for this year and especially the acceleration that the cloud revenue growth for the second half of the year. What's this sort of visibility based on? If we think of your longer term financial targets, obviously the growth target is ambitious, requiring faster growth than the overall market. I just wanted to hear your thoughts more about that and if that's more of a reflection of huge market share gains or rather growing in certain pockets of the market that are growing faster than the average. Thanks. Well, if I start then maybe then hand over to Ashley or Juhani a little bit. I think in terms of the acceleration, yeah, I think we do expect the momentum to keep continue and also to, as said in the outlook, accelerate second half of this year. Maybe in terms of the market and so maybe you guys wanna shed some light on that. I can start maybe just to say a few words that it's important to understand also that we are not starting from scratch here. I mean, with regard to the partners and the software portfolio called Elements, there's been excellent work that's been done over the past three years in kind of first of all developing the portfolio so that it meets the partner and customer needs, and then ramping up the other capabilities to support our partners. I think what we've seen over the past 12 months is evidence that these decisions have been the right ones, and they're really kind of yielding momentum and business. As experienced here over the past two days when we have customers who simply just said to us that, "You're great. We love you guys." Part They say it partly because some of our competition is they are very large. They're very large American companies and, when they pick up the phone and wanna talk to a CTO of a large American company, well, they don't get that CTO on the phone, but they will get our CTO on the phone, and we can be agile and flexible, and that is also partly why we can be so competitive, and that gives us confidence. That train is moving, and it's moving at an accelerating speed. If we look at the cloud protection, cloud content protection market, we have just scraped the surface. We have started with Salesforce, but obviously it's not a big secret that we're looking at other ecosystems as well. Can we do the same thing? It's not necessarily about, again, building a separate go-to-market because these large Fortune 500 companies, they typically have multiple of these ecosystems or these software platforms in use, not just Salesforce, but other platforms as well. Obviously we could then kind of utilize that relationship that we have already built on top of Salesforce for expanding further on. Maybe we'll get back to that later on when we talk about our plans later on in the year and next year. That certainly is a big opportunity for us. Finally, when we look at Countercept and we look at the dynamics of the market related to complementing customers' capabilities, either with our consultants or with our threat hunters, it's a natural demand that is there and it's just increasing, largely driven by the shift to public cloud environment and of course the evolving threat landscape at the same time. Anything you wanna add? It's good. Okay. Thanks for the answers. That's all from me for now. Thanks, Felix. Maybe you can pass the mic just to the person behind you. Thanks. Hi, it's Jakob Törneke from SEB. How is your cloud native portfolio, how does that differ from the situation, let's say, three years ago? What have been the key concrete advances in terms of the cloud native portfolio? Antti, do you wanna take that? Yeah, I think if I look at the way we build, of course, the product is that we are continuously updating the software, so it's not just that we deliver it once, and then it's there. We continuously update all the latest threats. We have learned a lot, for instance, on ransomware. I think we showcase some of our innovations here at the event. I think with these app ecosystems we have, we are learning new file types, like very concretely a malware that comes through the PDFs and these kind of things. These get into these dynamic Legos, and then they are going to the customers with the branded offers that we have. I think it's a continuous flow of innovation that goes underneath. Okay, if I continue, let's say, compared to the situation three years ago, have you changed your sales and marketing strategy or the methods how you enter the market? I think frankly what we've done is we have evolved to really meet the need. If you look at where we're approaching enterprise, where we're looking at the upper mid-market, we are putting much more focus behind preferred partners and making sure that our enterprise sales organization really understands how to engage to be successful. That's a greater focus. Then the automation, as we spoke about a couple of times around that sort of smaller business, has been established so that we can free up the investment of resource to go into those markets. Maybe add one topic still on the previous. I think we don't only work with Salesforce. One of the things, I think, past three years what based on the learnings we have got, we have introduced in Elements portfolio Cloud Protection for Office 365 because I think that fits into the cloud family. This is another example of the continuous flow of innovation that's coming up. Okay, thanks. Finally, on Cloud Protection, what is the typical deal size, if I may, and have you been able to cross-sell other services to the one Cloud Protection client? In terms of the deal size, we don't disclose those, and they vary. Of course, just the fact that we are selling to Fortune 500 companies gives you an idea that they can be substantial. Maybe Janne can continue from here from the dynamics of that. Sorry, can you repeat the latter part of the question? Cross-selling potential on the clients one on- Very good. Cloud content protection side. There absolutely is a lot of cross-selling potential. This is what on my latter growth engine I actually refer to as one of the key pillars that we are capitalizing group wide, not just technological, but commercial synergies. Now, we have actually handful of cloud content protection customers who started at consultancy customers. We did consultancy on their security posture. We found out that one thing where you have massive gap is Salesforce. Let's have a discuss. The examples exist. There is more to do. All right. Thank you. Veikko Pekka. Hey. Veikko Silvasti from Danske Bank, and thank you for the presentation. Quite impressive. First, let's start with the questions on technology. Antti, please. You mentioned that you started in September. Yeah. Can you please just tell quickly where you come from, and then maybe proceed from there. What do you think are the main white spots in which F-Secure's portfolio, and what's the roadmap to augment these white spots at the moment? Very good question. My background, I was a CTO and BU head in a company called Comptel, so that we divested to Nokia. In Nokia, I was heading Nokia Software's global engineering. I did advisory at Elisa, recently advising Elisa in a couple of international software acquisitions. I think I just love to work with Juhani. I think he called me, and here I am. I think you work with the people. I think I have a strong background in different realignment turnaround and growth initiatives plus 25 years in the business. That's my background. Antti, you told us that you've done some due diligence before you joined the company. Yeah, actually I did. It's that I've made a solemn promise to myself. I think that's the one thing, it's that I only work for the companies that are truly cloud-native and SaaS-based. That was my sort of due diligence, what I did on the company. That was one of the things why I think it's that, "Oh, this is a wonderful opportunity, good platform to innovate." I think the other thing is that building software is about experimentation, and that's key part of our value. When we have the strategic learning from the customers, that's how you build the product. You don't bring technology just in a lab. You build it with the customers. What drives our customers? A transition to cloud, from these complex IT environments to cloud. You have already seen that we're introducing elements for the customer cloud journey. We're gonna do more of that. Also the customer estates are full of different SaaS applications. You have heard what Janne is doing. We have Office 365. We are gonna do more of that. That these cloud and SaaS environments are gonna be more and more important in addition to the endpoint that we have been historically serving in the customer estate. That's gonna be the focus for us. Clear. You think to reach your maybe vision of the R&D pipeline and so forth, you think you can do it? Do you have the capacity and ability in your own R&D team, or do you think you need to go for talent acquisitions or active hires? I think, as I mentioned, that's why I talked maybe unusually a lot about the cloud-native thing, because we are a cloud-native company today. I think we have a world-class engineering kind of people, cyber experts who work in a top-notch environment with AWS. We can build a lot of things with our engineering and, but of course, like Tom said, M&A is always an option, but I think we have a good talent in-house we can build on. Great. Thank you. Maybe moving on, few questions on the Elements platform. What's the market potential of this platform, let's say, in Europe alone? Maybe can you help us understand whether the market that you're targeting, let's say from 100 FTEs up to 5,000 FTEs, these companies, are there any companies that do not have any cybersecurity product at the moment? Or is it fully penetrated and it's about upselling now EPP and EDR on top of that? Why don't I start, and then I'll hand over to you, Ashley. The market, of course, you saw a reflection of the total software product market there, and it's huge. Obviously this is a subset of that market because that market would also cover then larger enterprise product portfolios and so forth. We don't break it down and we don't have a number for you there. I would say that suffice to say that it is large. To your question about are there still kind of companies who don't have any capabilities, I'm sure there are. I think increasingly, of course, once you move into this mid-market segment, I think they start having some basic capabilities in place. It largely also depends on what type of company, yeah, you're dealing with. If you think about the end customer, some of them are more tech-savvy and some of them have their own CISO organizations and so forth, and many of them don't. Those who don't, I think, we provide them with an easy way of deploying certain robust rudimentary capabilities that are required. Anything you wanna add, Ashley? I think the other piece, just to refer back to what I spoke about earlier, which is the partners that we work with. That co-security approach is all about developing that value proposition that resonates in the market that differentiates. As Juhani says, the growth can be in terms of new customers that have never done it. I'm sure there are, but actually you're really looking at how you can augment their security posture and that total value proposition that will help the change. We've seen some great success in that. As we saw on the slides earlier, we're increasing the wallet share all the time. Yeah. It's fair to say that with Elements, it's not about blue ocean. You're not growing in an uncontested market. It's more about winning the market for yourself. Yeah. Okay. Clear. Maybe moving on to the Cloud Protection side, Janne. Well, obviously, I would've liked to hear what's the size of the business. That's not up for grabs today. Maybe can you just explain us what's the potential size of it? Let's say five years from now, only with the Salesforce platform or ecosystem, what could the size of the business be? Are we talking about tens of millions EUR in revenue or hundreds? Well, you can count it back really yourself if I give you the numbers. What I gave you 150,000 currently customers of Salesforce. This is public information. Salesforce discloses this. This is IDC estimate based on Salesforce revenues, but currently share of independent third party software currently $24 billion on around Salesforce, and that is growing. As Salesforce revenues grow, this independent third party software also grows. Now that's not all security, but it's safe to say that security portion, the potential there is not millions, not tens of millions, but it's, you know, we are talking about billions addressable market now. Currently, we are clearly the market leader. Where we will be in a couple of years, who knows? Clear. Only Salesforce, we are talking about a market size of over EUR 100 million. Maybe, where do you think you're going to expand next? What kind of ecosystems there could be? Could you help us understand this? The strategy work on that one is ongoing. We have done a lot of research. We are looking obviously at market potential, which is meaningful. Where can we technically do this quickly enough? What makes sense? What are the current customers? What do they need? Where we have the potential sales synergies, all of that plays in. There is plenty to do in Salesforce. We are doing Slack next, that I'm sure about, which is almost solution of its own. That's a totally new 'cause Slack and Salesforce customer, if you would draw Venn diagram, they almost don't actually cross. You have almost different customer base. Of course, Salesforce interest is to bring these together, but that was different company, big company, they brought it together. Now, exactly which one, unfortunately, I can't say. I don't want to give you a promise which I wouldn't be able to hold myself true to. We know how we evaluate it, and there is about 25-35 good-sized ecosystems that we could consider and Is it, Janne, so that anything with files and URLs, I think? Anything with any sort of communication, files, URLs, users, which is a lot. Clear. Okay, thank you. Sounds promising. A few questions on consulting unit. First of all, quite little information on consulting today. Focused on the software side, but the question is now how to improve this consulting unit. I just wonder that Google is willing to pay over $5 billion for Mandiant. That's basically providing consulting, a team size of, let's say, 600 consultants and so forth. Demand is massive. How come you're not able to grow with the consulting unit at the moment, and how are you able to fix this? All right, let me start with your comparison to Mandiant. It's good to know that Mandiant is not just comparable consulting, it's also comparable to our Managed Detection and Response, so that unit would cover all of it. Broadly speaking, that would be a services/technology proposition, and we are of course doing very well in Managed Detection and Response part. Now to the pure consulting part, I think looking at it from the market perspective, the market demand clearly is there, and we are facing a lot of demands. This is more, and it's not just us, I think it's across the industry, this is a question of balancing the supply and demand. There simply is more demand at the moment than there are consultants. We are experiencing that, everybody else is experiencing that. How do we tackle that? Two ways. One of them is that we are taking people from university, we put them through our academy, and we train them. This needs to be done because we simply can't just be hiring people who have the expertise. That won't be enough because in consulting business, revenue growth equals headcount growth. We need to be on that one, and we have no plans to contain it in any way. Of course, we want to grow our consulting business as well. Wherever possible, we obviously try to also utilize these synergies with the rest of the portfolio being an entry point to other solutions as we heard here. We also do quite independent consulting for certain customers that require a third-party independent. The other thing we do, obviously, is to hire people like everybody else. We've had attrition, we need to kinda hire more people. The only way we can tackle this issue about attrition is making sure that, well, we have a competitive package, and we provide a working environment that is really motivating and interesting. For many of these consultants, it means about personal growth and development. We need to give them access to really interesting projects where they can learn more, and importantly, learn from the best. We take pride in having those people in our payroll who can also teach others, and that is very motivating. Finally, the underlying culture. Culture is our operating system, and you don't build it overnight. We would like to be the preferred workplace also for these people and to understand what drives them and other people in our company. Great. Thank you. Final question. Yesterday, the co-founder and main owner, Risto Siilasmaa, gave a very insightful speech on the state of European tech and so forth. One theme was that European cybersecurity tech is very scarce and so forth. Is his own speech that basically being European helps demand? Or have you actually seen that some partners or some customers are demanding to have European cybersecurity tech? Now, this situation has evolved over the past six months quite dramatically after the Russian invasion of Ukraine. You know, needless to say that we probably have more demand than a Russian cybersecurity provider in the market at the moment. That is clear what we are experiencing and some others as well. That's very concretely what it means to be a European player. There's another aspect to it and I know Risto talked to that as well, which is that in Europe, we have a certain legislative framework which actually supports quite well the protection of data, privacy, and other things. This is increasingly important for end customers, and we think this will be a plus, a benefit, for a European company because we immediately stand for something when we say that we come from Europe, even if we serve the global market. Thanks. Right. Are there other questions in the room? Alex. Hi. Felix Henriksson again from Nordea. Just a quick couple of follow-ups, maybe touching on the current geopolitical situation right now and how things have evolved. I know I asked this in the latest earnings call as well, but what are your current thoughts about the sort of accelerating market growth on the back of the current situation, and do you sort of see market share gains up for grabs at the moment from the situation with Kaspersky? Without naming any names, I would just simply say that the French and German government agencies, for example, have given out recommendations to use Russian cybersecurity vendors. That, of course, means that market will be taken up largely by others. Thanks. Perhaps to Tom, I know you're targeting to achieve your 2025 top line organically, but what role does sort of inorganic growth and M&A play in your thoughts? I'm sorry, could you repeat the question? Sorry, we couldn't quite hear. Yeah, I know that you're targeting your 2025 top line organically, but I'm wondering what role does inorganic growth and M&A play in your thoughts at the moment? Well, I think at the moment we say that it's part of our toolbox and we evaluate the market situation, our own situation, and, you know, what we strategically can see as a need. As we said, we are in a quite good position, we feel in terms of the organic growth and scalability of the company. Got it. Thanks. Okay. Shall we move on to online questions next? If no more questions, or you can still ask, but I'll just hop on stage. From the webcast, first of all, some of you are asking if the material is available. Yes, it hopefully has just been posted to our website. WithSecure.com investors, you should find it there. If not yet, then it will be on very soon. We have a question from Matti Riikonen, our analyst. What explains the difference between the gross margin ambition levels in Elements and Countercept? You wanna take that? Yeah. Sure. Like I tried to say that Elements is a pure software play, so that is only the gross margin only consists of you know the hosting costs and so on. But in Countercept there is also a human element in the solutions, so there's threat hunters, which is very scalable, but still it obviously is not the same gross margin then because you have these human costs in that. Okay. The question continues: how do you expect consulting to contribute to top-line growth in 2022? I think, you know, you've heard our projections in terms of our financials, so they are of course what they are. I would say a little bit longer term, we hope to accelerate still the consulting delivery capacity, which is currently the bottleneck. We hope to accelerate that and further then contribute even more to the overall growth. Very good. A couple of questions on the cloud. How large proportion of Salesforce customers are currently using your product or any other relevant KPI for the addressable market? In three years' time, what do you think the number could be? I think it's almost impossible to give a number to that. I think we have some data points that we have shared, how many Fortune 500 customers we are sharing, or other data point would be that Salesforce has 150,000 customers of their own. How many of those 150,000 we're tackling today, I don't remember the exact number, but it is low compared to the 150,000. We're just in the beginning of accelerating. If it just wasn't clear from the previous presentation, I think we have a huge opportunity which we have started, and we have some first mover advantage there. It's just for us now to run as fast as we can. Good. Is your relationship with Salesforce an exclusive one? Sorry, Janne Pirttilahti, maybe I'll start this. Salesforce has a program that they work with ISVs, independent software vendors. That means they qualify them to be part of their overall partner portfolio and be represented on their AppExchange with their application. There you can take it into use, which means that they have been pre-approved, pre-qualified by Salesforce, and there are certain technical requirements that you need to fill. You can't just go in there and start selling. We have done all this, but we are not exclusive. There are a few others as well that work there. Personally, I think the best exclusivity is earned by your quality and the work that you do in that ecosystem. In the month of May, we held, I can't remember the exact number, but close to 10 joint customer events with Salesforce. This tells a story, I think, on their support pages where they recognize the need for shared responsibility and say that we don't look into the content. They say that if you want to do this, go to AppExchange, look at this solution, and there is only link to our solution. There is this. All right. Very good. There's a question which I don't understand, but hope one of you understands. Do you operate in or plan to expand into the OT security? Operational technology. Thank you. That has been every now and then in the cards, and operational technology obviously means operating systems in factories, those kind of things that you would find in the context of manufacturing, for example. I think in certain instances we have done a little bit of that, primarily, I think, in our consulting space, but it's not currently something that we're very focused on. All right. Mika V. Häkkinen, who's watching us on webcast: "How have you succeeded in hijacking customers from Kaspersky and company? I would imagine that to be a good direction to acquire more customers. Have you focused specific customer acquisition activities to go to that market? Yeah, of course, our partners have been active in that space, and we also directly do go to market. All right. Then again, back to the cloud protection. Are there any meaningful differences between providing security services in other ecosystems than Salesforce? How big changes product-wise do you have to make in order to offer your products elsewhere? There are differences between ecosystems in terms of what is the shared responsibility exactly, and sometimes they can be meaningful, sometimes maybe not so much. The key is that there is no ecosystem where the cloud vendor would take care of absolutely everything, so that doesn't exist. Now, Santtu said we have actually, in a way, similar technology for Microsoft 365. So the core technology, all threat intelligence, all of the cloud scanning things are shared. Then there is this layer which is the native integration to Salesforce or to Microsoft, for example. So there is a lot of work. It's not easy to copy, but at the same time, there is much work under the surface, which is not easy to copy either, but that's our scalability on technology. I think the key thing is that, it builds on our secret sauce. It's not just building an app. Mm-hmm. That's what you should take away. Okay. How likely is it that Salesforce will provide its own cybersecurity software and replace you, and what is the bene- That would go against the model they have advocated in the marketplace, so we don't see that's a likely scenario. Okay. There was a question about talent acquisition and retention, but I think we already answered that very comprehensively. that is currently all that we've received. now one last chance to ask questions or put questions through the chat. Veikko. Yes, one more question on the tech side. Now you have over EUR 90 million net cash. Obviously, M&A will be, as you say, in the toolbox and so forth, it will probably happen. Now we talked about operational tech. No, okay, that's not in the focus. What is in the focus? What would be this kind of technology that you want to have in your maybe, let's say, Elements platform, or something else? Thank you. Thanks for the question. I think when you look at it from a customer perspective, it's about security operations. You identify, you protect, you detect, respond, and then you recover. That's how the day in the life of a CISO would look like. When we look at it then, what we do, I think where we're gonna invest. Like I mentioned, we're gonna invest in making sure that our cloud capabilities get stronger as the transition to cloud goes. We will get these capabilities from our managed services to the Elements. Of course, we will invest in the things that Janne is doing, that is we go to. Those would be the key thing. I think in the past few years, I think, big area has been that we have, in a way, got a common stack, I think, across the technologies for the detection and response, which is now live with all the products. Mm-hmm. Are we gonna further enhance that one. I think it's across the board, but very much towards cloud and this new type of threats enterprises and corporates are facing. Great. Maybe, like, I have no question on that. Would you be in the M&A process? Are you looking through? Are you doing the? Yeah, I look after the portfolio for the company. Absolutely, I would be involved. I think there's an M&A person, I think, in Tom's team, but I think, from the portfolio content point of view, I would drive that for the company. Clear. Thanks. All right. I think that concludes our program for today. Hopefully you got what you came here for, and it was a pleasure to see so many of you here, and thanks for being active online as well. I think we'll just simply end here, and thank you for everybody for participation. Thank you for the speakers. Thank you, Laura, for facilitating. Thank you. We're closing the webcast. Thanks for joining us online. Goodbye. Thank you.
Loading workspace