Hello, everyone. Welcome to the 2021 edition of Accelerate. This is our second digital edition, as we unfortunately still can't travel together and meet in person. The number of registrations and attendees today shows that you continue to be highly engaged with us, and I want to thank you all for that. Over the year, we have greatly accelerated our business momentum together, and last year was no exception besides the major challenge we have all faced. We are in a situation to accelerate more than ever to enable together with our partners the massive digital transformation you are going through. 2021 is about capitalizing on the strength of our vision, platform, our investment, and deliver an unprecedented level of growth and put all of us in a leader's seat. 2020 operated both as a catalyst and as an accelerator of the key trends that are reshaping the digital world. Let's take a look of the four key marker of this accelerations. All source of information highlight a very strong acceleration of the digital transformation investment. As you can see, a 44% growth between 2019 and 2021, reaching a $426 billion spending. We do see that the investment on transforming economy and corporate leveraging digital technology will continue to move forward beyond 2021. Let's take another look of the key marker. Home working. The global pandemic gave a really serious boost of the home working. Before the pandemic, forecast was about 30% working in 2023. As pandemic broke, home working become the norm in a couple of week. If you look at the Google search, the home working word alone and search was about 20%. We do see, as we move forward after pandemic, that a portion of home worker will still stay, a higher portion than previous pandemic. The transformation of our work practice will probably stay for the long term. In 2020, the investment growth in 5G reached a new level, 96% in term of growth, reaching a $8.1 billion spending. Mostly in the service provider and telco space, enterprise also, they're all betting on speed. They're also looking for the low latency value and the high flexibility that 5G will provide. We do see emergence of new applications: self-driving car, remote surgery, immersive game-changing application while you're on the go. Many, many more coming. It's just the beginning of this revolution where 5G will deliver high speed wherever you are. Cloud computing market has also grown at a very nice rate, about 18% during 2020, and is planned to reach $436 billion this year. Definitely, adoption of these new approaches on leveraging public cloud providers and cloud computing will stay and will represent a significant area of the digital transformation. It's also an area where we have to look about the security. All of these transformational domains comes with their share of risks. The digital transformation increased the attack surface in three areas. New areas are emerging, new applications are making our world more exposed, new ecosystems are being defined, all creating new weak points for data leaks. Homeworking definitely saved our economy during the pandemic, consequently connected more non-professional devices, home routers, and family-grade equipment for business-critical applications. The 5G bring a new world application, but the high speed and the low latency make the security a new challenge. Cloud computing increase the risk of data leaks, privacy breaches, and potential failure to comply. All organization had to face this accelerated evolution of their digital business. At some time, we are put in a very reactive position, looking for the right security solution to help solve those rising issue. Fortinet was the right vendor to turn to, allowing us to deliver together another year of growth. 2020 was another very successful year, providing the confirmation that our vision and our execution was right. As you can see, we reached for the first time more than $3 billion in billing. While growing at double digits, we also been able to generate a very healthy and profitable business, which allow us also to look for the future with all the necessary financial asset that is required. The operating margin was also generating at high rates, which provide us, of course, the way to invest more. We did. We did during 2020 again. We spent about $340 million in R&D. Innovation will drive the future success. That's part of the DNA of Fortinet. We also invested on capacity of people, both from an R&D but support, but as well on the sales. As you can see, we added in terms of sales capacity to better provide you value and services, about 30%. We also, as we have a very successful sales model leveraging the channel, launched last year our new program called Engage, and I will be pleased to share some of the new initiatives coming as today. Continue to, of course, solidify the technology and the expertise that we need to cover all aspects of your security challenges. We did acquire two nice companies that was completing, in fact, our strengths in terms of network security. This put, in fact, both from a growth and from an investment perspective, in a very strong position. As you can see, we serve all market segments, so we are now fully aligned to really provide the best value for each of you, whatever the market segment you are based. What is also very interesting, as we are almost exiting from this pandemic with a bit more hope as we speak, the downturn about GDP last year, which was about - 3.5% worldwide, will come to a positive GDP growth of 5.5% in 2021. This is a 9% shift, and that will happen in the quarter-over-quarter. Be ready, as you can see, 2022 also is expecting to a very highest growth in terms of worldwide GDP. Be ready for acceleration. Let's look at other key area of the investment, which are essential for the acceleration of channel. Our sales strategy from day one relied on channel, a trusted long-term relationship. Last year, as I highlighted, we launched the new Fortinet partner program called Engage. Now is the phase II of this program. The phase II come with new specialization that address the market requirement, such as OT specialization, Zero Trust architectures, and the security operation. It's also come with a much more easy way to do business with us. It's also coming with a completely new revamped cloud channel program. More to come during the breakout session, I'm sure you'll be very excited as I am on launching this new program. It's also about skill and knowledge. As you know, we are all facing this global skill shortage. The successful NSE program that we launched has also great help on, of course, providing value and transferring value to you, our partner, and to you, our customer. With more than 5,000 certified engineer worldwide, and during pandemic, we had about 800,000 registration to acquire expertise leveraging our NSE certification. As you know, we've been providing for free access to several level of this NSE certification. Part of the great program that we are providing, and of course, engagement with you, partner and customer, we are very happy with the evolution of this certification program. Together with your partner, we are ready. Now let's take a look at what is coming to us. First, look at about the success, why we are all together very successful answering all the challenge we are facing. Success do not happen by chance. Let me share with you few fundamental reason of the massive adoption of our solution. It start with the vision. Ken vision. The convergence of network and security, which was in the DNA of Fortinet from day one. This convergence has become essential to secure data that are being accessed and delivered from anywhere. It's about providing the freedom of choice when it's come to cloud journey. We are the only security company that bring your freedom back when it's come to the security cloud journey. We offer the broadest cloud offering. We provide the choice to go for any cloud provider. We provide the timing. You can keep the pacing while leveraging your existing investment on-prem and moving step by step on the cloud journey. It is about, of course, leveraging the choice from a financial but also from a technology perspective, whatever you want to have full cloud, hybrid cloud, or maintaining your existing on-prem delivery solution. It's all with a consistent security posture everywhere from any source of the storage of the data. Your cloud strategy, your policy, your priority still have to sit above any public cloud provider roadmap. That's what we are. It's about the rise of the edge. Ken, during the Accelerate presentation two years ago, has presented and predicted this. This trend has accelerated, boosted by 5G, a world of innovation at the edge, and it's coming. You can see, as I highlighted, self-driving car, remote surgery, and more to come. That create, in fact, much more new edge, which requires security to be delivered constantly across all edge, cloud edge, WAN edge, home edge, OT edge, and data center edge. Those predictions are real. Let's talk about the number, at least on how we have been able to tackle those new challenges during 2020. As you can see, our Secure SD-WAN was a great example of the merge of networking and security. We came late on the market, but we have been looking about the demand and what was the key blocking point to deploy this new SD-WAN technology across the world. That was by adding security, embedded security in this solution. With our great Secure SD-WAN, we have been able to do a record year, and we have been able to grow at 96% year-over-year from last year. We have been also enjoying a very nice position during the Gartner release in Q4 on the WAN Edge Infra Magic Quadrant, where we are number two. The cloud, it's again, another example. We grow about 60% or 64% of public cloud provider solution. Here again, the freedom of the choice and the same security posture that you have on-prem and on the cloud has helped to deliver such a very high number. Last, it's about, of course, the covering all these different edge and evolving on the Zero Trust Network Architecture. Here again, with our endpoint or EDR, we have been able to enjoy the 173% year-over-year growth. All of those numbers confirm the great vision, the great anticipation of the market trend, and the great execution that we have been all together been able to do. To explain why we are so successful in our vision of security, we have to understand the new security paradigm created by the Digital Transformation. Digital Transformation is driving a significant shift in the way all of us deliver technology and services to connect people and object to application. The infrastructure has been, for the last 20 years, centered around the data center. As you can see, it was more data center-centric, where we had almost 80% on-prem. It was the access to those data, which was mostly around the core networks, was accessing to all aging DMZ perimeter. Last was about the manual config. In order to allow access and control, it was all manual, very limited in term of automation. The transport layer was the link between the edge and the data center. The digital transformation is forcing to shift toward an hybrid cloud-centric world, where the data center is just another place where application are hosted. The enterprise edge span many different domain. Cloud edge, security applications, on-prem, and third party on the wider internet. You can see that there is most likely a shift from the on-prem and off-prem, about 50%, hosted or SaaS. Security need to be delivered everywhere with an end-to-end automation. Simply connecting people and things to applications, putting an end-to-end visibility, a policy enforcement, and an automation at the center of this new paradigm. This new paradigm affects in four dimensions. Architecture becomes distributed. Applications are delivered through SaaS. Security needs to be enforced everywhere. The management requires a total visibility across multiple vendors. Such a new paradigm demands a holistic approach of cybersecurity. In this context, Fortinet Security Fabric sees its core attributes more crucial than ever. It's broader than ever, now embracing the rise of the edge in all of its dimensions. It's natively integrated, and it's fully automated with an open ecosystem for third-party applications. All the set of solutions that cover this fabric are now in three main aspects: Zero Trust Network Access, security-driven networking, and adaptive cloud security. All started with what we call the Fabric Management Center, NOC-SOC automations, and the FortiGuard Threat Intelligence. In 2021, Fortinet brings the Security Fabrics to the next level. All building block are now integrated at the heart of the Security Fabric in one operating system, the FortiOS. Making this one platform able to enforce one policy consistent across all edges that sit above cloud diversity, and that keep all scenario open in an uncertain world. No vendor can claim they're in such a Security Fabric value. You will learn during Ken and especially John presentation how Fortinet and the FortiOS allow the Fabric to cover multiple new case. Let's take a look of those at least three element that I consider very critical as we see a huge demand moving in 2021. One platform, the Security Fabric, allows to secure the branch or the edge branch. With our Secure SD-Branch, it's a great, I would say, representation of the Fortinet strategy and success and execution. SD-WAN is the example where we started, implemented with listening from new customer, what's important, and embedded within our FortiOS all these networking features into a comprehensive security approach. That has helped us to gain a huge market share, putting us, as highlighted here by Gartner, in a leading position. SD-WAN isn't the only example. Our platform approach enabled us to offer an AI-driven, zero-trust access solution that is seen today as the safest path into a full XDR solution. An XDR with response across an expanded scope and automated user profiling and analytic behavior endpoint monitoring. It's all about managing the user accessing to the data and the application and understanding their behavior and potentially anticipate any leakage. This extension leveraging our FortiOS on the Zero Trust Network Access, we are about to do the same with the SASE. Our platform allows us to develop the most complete SASE architecture, including next-generation firewall-as-a-service, Secure Web Gateway, CASB, Zero Trust Network Access. It integrates natively application security in the Security Fabric and in our SD-WAN. It also provides a very secure approach for the home or remote user, providing the choice for agent or agentless, looking about the best security or a compromise between easy to access and security. It's all about performance. It's important that while those new homeworker access to the application they have working, they need to maintain high performance. It optimizes as well the network access and scale performance. Here again, Fortinet will offer you the freedom of choice to secure home edge with the best price performance ratio without compromising on security. Through our platform, the Fortinet Security Fabric, we are taking leadership on the various markets, such as the next-generation firewall market and the WAN edge infrastructure. What you can see here, we have done with many other, and we expect to move on the same leading position in the next two years. Now let's take a look at the benefit of this fabric and the one platform with one operating system. Look at first at the business benefit. We are all engaged in rationalization, especially during this very complicated time. Many company are running short on cash, investment, and must need to rationalize why they are doing this digital transformation. Security has no exception. They may have to spend less money or equal money to cover more aspects, including this new trend. The native integration of our features leveraging our Fortinet Fabric and the product landscape that we provide helped, of course, to leverage, in fact, this benefit from a TCO perspective, from also a rationalization in terms of dealing with less vendors. It also provides a security benefit. The Fortinet solution provides a fully third-party validated platform which no one can compare. It's the same security platform that excels, as I mentioned, multiple Gartner Magic Quadrants. It's not a suite of heterogeneous solutions artificially glued together sideways. It's a true, real security platform that allows you to react or anticipate on any attack that you are facing. Last, it's about the channel benefit. Our channel, as you know, with long-term relationship, we try to be the best vendor to deal with in enabling access to all market segment with our solution. All size of company across all size of program be able to deliver both on OpEx but on CapEx solution, and making sure that you have the choice to add the services on top of the technology we provide. It's about loyalty and long-term vision. Again, here, quite happy with everything that we have built and of course, very excited about the future. To conclude, I would like to leave with you with three takeaways. First, the vision. Vision has been proven and it's true, and is unique. I think it's fairly disruptive, not following everything that is on the cloud. We have a much more broader, more hybrid view on what's going on in the future. As you will hear from Ken, the future is also to secure all new edge is, in fact, the next major wave that we have to start today to anticipate, including home edge, including OT edge, including the cloud edge. The platform is just the advantage. Having one platform that allow you to realize through one single operating system, all security requirement that you need to deploy and you need to manage on a daily basis to improve your security posture. Let's, of course, look at 2021, and looking forward working with you both, you partner, but you end user, and make a very successful and a new record year. Thank you. Thank you for attending 2021 Accelerate, and thank you our customer and partner for their big supporting in the past year, from the very beginning, Fortinet founded 20 years ago. With all your support and help, we continue to grow faster than the market, with a CAGR in the last 20 years, average 45% growth year-over-year. We outpace the market growth about 10%. Also our superior technology and long-term investment all paid off, making Fortinet today become one of the leader in the cybersecurity space. More than 500,000 organization and government looking for Fortinet for the protection. We have one of the biggest deployment of a cybersecurity appliance in the world. With over six million FortiGate deployed, we account over 30% of the total global deployment, making Fortinet a leader in all this network security space. Also, we bring a lot of value to the shareholder. You can look at since IPO, and Fortinet value grow over 2,000%, and also the five-year and a two-year compared to our competitor. We're also the number one, outpace all the other competitors. I appreciate everyone supporting, including all the investor analysts attending today. And we keeping building the best, broadest portfolio and leading by network security, and also including the endpoint, including application, including the other infrastructure and the whole portfolio we have has the broadest in the whole industry. Most of these products are organically internally developed and making, working together from day one, integrate, automate together. This also leading by the innovation we have, with more than 700 patent we have, which more than double than any other competitor. We're continuing to lead innovation. We feel this is a key important part to keeping Fortinet growing, going forward organically and outpace all the competitors. Plus, from the business model, we have the best business model in the industry, which has both the growth and also the profit, compared to some of our competitor only have a growth and some other only have the profitability, but we have both. As also a result, Fortinet is the best credit rating in the whole cybersecurity industry. We are also the only cybersecurity company in the S&P 500 list, which reflect all the team working together, making Fortinet the best cybersecurity company in the space. Also, you can see, so the cybersecurity industry keeping changing every year. The attack surface is quite different compared to traditional firewall VPN market 10, 20 years ago when Fortinet started. Today, we are see there's three major focus we are doing. The first is a security-driven networking, which is also the vision Fortinet has since our beginning. We do believe security and networking need to be working together, making the whole infrastructure very, very secure. The second today is also you need to cover the core zero trust access, and that's where the traditional perimeter protection is no longer enough. You also need to protect all the mobile device. You also need to protect the application in the cloud. You also need to protect all the other part of infrastructure, both expand to the WAN, like SD-WAN 5G, and expand into internally, like all the internal segmentation, switching and Wi-Fi access. That's where the Zero Trust-based of protection is also very, very important. That's making the whole infrastructure is very, very important, including leverage the cloud to secure all the application in the cloud. With this Zero Trust concept, you can see we need to protect the whole infrastructure attack surface and also protect people work from home, work from office, and also the mobile when they travel. This whole infrastructure security is the key for today's cybersecurity. With all this, we also have the SASE, which is also we built different than compare our competitors. We have the SASE built in OS level. It's much better, deeper integration compared to other competitor has to use in different system or even different architecture to protect all different part of a SASE solution. That's where for Fortinet, even we take a little bit more long time, more effort to build in OS level SASE, but the benefit to all the customer, to the partner, and to the service provider is huge. I believe John Maddison will give all the detail, the SASE architecture later. We present these slides before. You can see going forward, Gartner do suggest to the edge and the immersive technology will gradually replace the cloud and also mobile device. Fortinet has the best technology and innovation to cover both today's solution in the cloud and also going forward for the edge protection. Edge will become more and more important with all the computing power move to the edge to process the real-time data and the traffic there. The key advantage Fortinet have over our competitor is this Fortinet Security Fabric, which is a broad integrate and automate. We have the broadest product, including not only the network security part, but also the endpoint side, the cloud side, application side with over 30 product family together. All this product mostly come from internal development. It's integrated together, designed to working automatically from day one, which is different than our competitor, mostly come from all the acquisition, which is very difficult to integrate and almost impossible to automate together. That's making Fortinet has huge advantage over our competitors. Today, we also want to introduce the FortiOS 7.0, which is a major release and has a few first come to the whole industry. The first, this is the first OS level, Zero Trust Network Access, and also the first time have the SASE integrated in the OS level, plus all the 5G feature, and also there's other 300 new feature including in this FortiOS 7.0. Fortinet become the leading cybersecurity vendor, has all this firewall based OS level, Zero Trust Network Access, and also the SASE solution. Together with the 5G SD-WAN, making FortiOS the richest feature among the whole cybersecurity, and also with the FortiASIC accelerate the performance and the computing power, also the best performed OS with all the feature together in the whole industry. You can see we continue to expand our total addressable market. By 2024, our total addressable market will be $93 billion. Not only we're leading the network security, which is about $50 billion-$51 billion, but we also have the Zero Trust endpoint solution. We also cover the cloud security. We also have the Secure Ops, including all the lot of new product we're keeping developing. All this together will continue to drive Fortinet's growth going forward. We're keeping our strategy to do a lot of long-term R&D investment and facility investment, the infrastructure investment, and also the supporting the marketing and the sales investment. The new headquarter will be open later this month. At the same time, we continue to build a global infrastructure to supporting our global business going forward. Fortinet also is a very social responsible company, we care the environment a lot. We want to make sure all the product we build is environment friendly and will be saving the energy. We also want to contribute to the community with all the NSE training we have, and also supporting education, supporting all the veteran program. We want to make sure all the people within Fortinet and also our partner, our customer, can leverage the resource, the opportunity we have here and continue to growing and continue to kind of grow together with the industry and making Fortinet the best company in the whole industry. With that, I go to the key takeaway. First, we want to continue to expand our platform, continue the long-term investment we have, including not only the technology, including ASIC, the OS, and also the new function, the new feature, the new product. At the same time, including the facility, including all the infrastructure, and also including the people, which is the number one more important. That's what help us to be the number one going forward in both the SD-WAN and also security-driven networking. Growth is the key word for 2021. With that, I want to thank you everyone to participate to this year's Accelerate 2021. Thank you. [Presentation] Hello, everybody. Welcome to Fortinet Accelerate 2021. This is John Maddison, CMO and EVP of Products. It'd be great to be in person, unfortunately online, maybe next time. Securing all network edges. I want to talk about a lot of things here, endpoint security device, network, cloud, application. If I take one message away, it's that the network is still very important, the security of the network and what's happening in the network are all these edges are forming that need to be secured. Our vision as a company, making possible a digital world you can always trust. One of the most recognizable symbols from Fortinet is the O in Fortinet. Sometimes it's called the grid, sometimes the O, that represents the trust. How are we going to provide that trust? Our mission is to secure people, devices, and data everywhere. What we want to be able to do is make sure we protect that entire attack surface, which has been rapidly expanding due to digital innovation. Patrice had this slide earlier on. It's the Gartner Magic Quadrants. We're in a leadership spot for two Magic Quadrants. We're in four other Magic Quadrants. We're mentioned in another two. Also, we're in six, what we call market guides. These are precursors to Magic Quadrants, new developing marketplaces, IPS, Zero Trust, email, operational technology, NAC, and SOAR. Gartner really recognizes the full breadth of the Fortinet portfolio. Again, we're leaders in the network firewall and WAN edge, sometimes called the SD-WAN. Often the leaders are very different companies, but even if they're the same company, they're completely different platforms. For Fortinet, it's the same product, the same OS, the same API, the same management product. Best of breed functionality, but on a single platform. Before I get into some of the product stuff, I wanted to talk about training. We have a huge investment in training. I think by now we're the number one cybersecurity training program out there. You can just see some of the numbers here. I think in fact, we're over 600,000. In fact, half of those certifications have been done in the last 12 months. As a partner, as a customer, you should be familiar with what we call the Network Security Expert program. It starts with foundational and solution orientated. These are all public already. All the way to our expert level, NSE 8. We provide a lot of these materials and curriculum to top universities and colleges around the world. Two important areas. One is what we call IT awareness. That's now inside our NSE 1. It's free of charge. We have over 150 customers already using this. Anti-phishing, for example. Also for larger customers, we have our strategic partnerships where we export the entire curriculum into their programs, IBM, Accenture, salesforce.com. By the way, we made all our training free of charge in 2020. It's always been free to our partners, and we're going to expand that program into 2021. Training is a very important investment for us. Okay, let's switch gears now into product and product strategy. You heard Ken talk about our organic platform development. This is very important. It's very easy for us to go and acquire a lot of different pieces and try and bolt them together. We don't do that. We develop the platform organically. If you cast your mind back, and I can, between 2000, 2010, really a lot of the data was at the endpoint. Endpoint security back then, antivirus was really important. Yes, there was firewalling, but it was more around stateful firewalling. Over the last 10 years, a lot of the data has moved into the data center, and the network has become very important. Sure, the endpoint has progressed and there's people off the network. If you look at firewalling, it's progressed into next-gen firewall, lots of content, and of course, the data center became very important. Over the last few years and as we go forward over the next few years, of course, cloud has entered, the network has formed different edges, and endpoints and devices will migrate to more of a zero trust type architecture. What's really important, though, is a platform. It's not just a platform at endpoint, a platform in the network, or a platform across the cloud. It's a platform across all three of those things that also includes identity and threat intelligence. The networking industry is very different from the cybersecurity industry. It's actually consolidated, and that's because although things have got much faster in terms of speeds and feeds, the functionalities remain the same. It's just faster switching, faster routing, faster Wi-Fi. The only thing that's changed a lot, probably in the last two, three years, is the application routing has taken over from enterprise IP routing. Still, it's a feeds and speeds game. Yes, there's some new technologies coming along, such as integrated security, AIOps, cloud networking, but the convergence of security and networking means you need to take high performance and high flexibility. The hub and spoke architecture of an an enterprise has been here for probably 10 years. The idea was to get everybody onto the network as quickly as possible to the data center and out into the internet. What's changed? Well, what's changed are all these edges. You now have a WAN edge. You have the LAN edge. You have off network, the home edge recently, due to the pandemic. You've got now different types of clouds, SaaS, infrastructure. We're seeing LTE and 5G as we go forward, operational technology edges, and so all these edges need to be protected. However, it's very complex to build the networking and then to build security on top, and so these edges will be protected by converged technology, security-driven networking. Same goes for the endpoint. If you look at the endpoint, as I said earlier, it's migrated from a signature-based system into behavior, where we just recently launched XDR, which is more of a platform network access, started as VPN. We need to look at all the devices, how they get on the network. That's migrating into a zero trust network access. Of course, identity is a very important part of security, and we've migrated from static passwords to multi-factor to even password-less as we go forward. All three of these technologies will come together under zero trust access. Of course, cloud. Cloud has gone from what we call a centralized to a distributed to a more centralized, and again, right now it's going back to a more distributed. It's gone from mainframe to personal computer to data center to multi-cloud, to cross cloud, and now back to edge compute. Gartner actually saying by 2022, 50% of enterprise-generated data will be outside of the data center. What's important here is to look at the shared responsibility model for security, whether it be the network, the platform, the applications, or the visibility. Depending on what type of cloud, you're going to need that shared responsibility model and make sure you have the tools and controls for that particular cloud. Let's turn our attention away from infrastructure back to the cyber threat landscape. I think everybody in cybersecurity is familiar with the Kill Chain. The Cyber Kill Chain itself really hasn't changed a lot. There's some different models out there, it really hasn't changed a lot over the last five to seven years. It starts with reconnaissance. It looks at weaponization, delivery, exploitation, installation, command and control, C&C, action on objectives. I think probably the most scariest thing we've seen over the last few years is state-sponsored, more advanced APTs. In actual fact, the kill chain hasn't changed too much in its own right, but there's been more focus on each part of the kill chain, more sophistication, more speed, more complexity. You need to be able to look at across the entire attack surface and be able to stop the kill chain at any one of these points. Okay, this is the most important part of our strategy. It's called the Fabric, platform to some, the Fortinet Security Fabric. The first thing it does is look across the entire attack surface, devices and users, applications, networks, IoT devices, 5G. It makes sure it can see, has broad visibility and protection of the entire digital attack surface to better manage that risk. It does that through these three pillars, the Zero Trust for devices and users, security-driven networking for the network, and adaptive cloud security for the cloud data center and applications. What's different about the Security Fabric is it's totally integrated. Because we've built it organically, each one of the components can talk to each other in a peer-to-peer way. It can exchange policy and threat information. It has a single Fabric Management Center to provide network operations and security operations. FortiGuard Threat Intelligence can be applied to any part of the Fabric, whether it be endpoint, network, or cloud. We also understand you've made investments in other parts of the infrastructure, whether it be cloud or infrastructure or data, endpoint, so it's an open ecosystem. We can integrate the Fabric into the major orchestration systems and the major clouds. The end goal for the fabric is to allow automation, the ability to drive self-healing networks and AI response instantly to any attack on your data, on your infrastructure, or on your users. The end goal of the platform is automation. Let's zoom in to one of the pillars. We need to deliver enterprise protection and that user experience at any edge. We use security-driven networking. What are the major technologies around security-driven networking? Well, the first one is the ability to operate at any one of those edges, LAN edge, WAN edge. There's a lot of vendors who just work in the cloud, or just work in the network, or just work at endpoint. You need to be able to protect any one of those edges. In certain instances, you need to provide very high performance, especially if you're in the core of the network or the core of the data center, so performance is very important. Also, things like SD-WAN, so it would be totally integrated inside the firewall itself. Now you have a secure SD-WAN, not only a next-gen firewall, but an enterprise-class SD-WAN. The same goes for SD-Branch with Wi-Fi and switching access. As we go forward, the digital experience is going to be very important, so monitoring it, measuring it, but also applying AIOps to the network end-to-end, from users all the way into the applications and through the network so they can self-heal anything that happens inside that network. As I said, integrating everything as much as possible, integrated 5G, and then making sure you can apply certified security. There's a lot of people who say they've got security. It has to be enterprise class certified security. What does that look like from a product portfolio, Security Fabric, security-driven? Well, it's LAN edge, WAN edge, data center edge, cloud edge. As some of you may know, our products have a very straightforward naming system, Forti, whatever it does. It's a FortiAP, a FortiSwitch, a FortiGate, FortiExtender, FortiProxy, FortiGate for SD-WAN, a FortiSASE, which is new, and a FortiIsolator. Let's go back to that edge diagram I talked about earlier. You can see how we cover all those edges. We cover the WAN edge, the LAN edge, 5G, SASE edge, cloud edge, data center, and OT edge. Our product portfolio inside security-driven network is able to protect all those edges across your network. Now, if you're in the industry, you know the acronym SOUP is always around. The latest one, I think, is SASE, and I just wanted to go through what we think about SASE, what's our vision around SASE. The first thing we want to make sure is that we have a flexible edge access, whether it comes from a client, whether it comes from a thin edge, such as a 5G connection through LTE, whether it comes to a more secure edge through SD-WAN. All those edges feed back into what we call our FortiSASE, which is our certified enterprise security, next-gen firewall, secure web gateway, and integrated Zero Trust Network Access. As we connect FortiSASE into the different clouds through our peering systems or through our APIs, such as FortiCASB, we make sure we monitor that digital experience. For most companies who are developing their digital innovation, the digital experience is going to be the most important thing to their users and their customers. Let's not forget, there's still a lot of implementations of appliances in data centers, in campuses, in clouds. Fortinet continues to push the boundaries of performance for our data center firewall. We're rolling out our Network Processor 7, our new SPU last year and this year, and our content processor. You can see some of the benefits here, some of the speed you get compared to CPU-based systems. It's usually about 10X, whether it be throughput, whether it be specific applications. Actually, very importantly, it's green. It actually is the most energy efficient consumption from a firewall perspective you can get. In fact, one of our NP7s equals 10 of the high-end CPUs in terms of performance. Imagine the savings in power and space. We'll continue to invest in this area as we go forward. All right. Let's switch gears a bit here. Knowing and controlling everyone and everything on and off your network, users and devices, Zero Trust Access. A lot of our customers are using our VPN technology, and in fact, during the pandemic, the start of the pandemic, they had to go from maybe 5% work from home to almost 100%, 1,000 users to 50,000 users. VPN technology allows you onto the network. It gives you access to the entire network. It is a one-time trust check, and usually because of the scope, has a generic rule set across all users. VPN needs to migrate forward. It needs to migrate forward to more of a zero trust architecture, both on and off the network, providing a continuous trust check for every session, application-specific access, and user contextual rule sets. Are you on and off the network? What time? What applications are you accessing? This architecture from Fortinet is more of a migration than a rip and replace. You migrate your client forward. You migrate your FortiGate and FortiOS forward to give you this zero trust network architecture. What are the products inside this portfolio? FortiClient, FortiNAC, FortiToken, FortiAuthenticator. As I go through all these products, you'll be interested to know that most of them have different form factors, agents, appliances, virtual machine, cloud-native, SaaS. Again, let's come back to this zero trust vision, zero trust architecture vision. What it's saying is that all users have application-specific access. You can provide session segmentation that go through a flexible proxy FortiOS. That proxy can be in your data center, it can be in our cloud, it can be on your campus. That gives you great flexibility. You apply device and user identity through our systems or through additional or external systems that you already have, then very importantly, you provide this continuous contextual-based trust through our EMS system per application access. From a product portfolio, in fact, there's two main products here, FortiClient, FortiEDR migrating to FortiXDR. There's two migrations going here at endpoint. One is the VPN migration to zero trust, encryption on network, on and off network visibility. The migration point, I think longer term, is that proxy sits in a SASE environment. The same's happening on endpoint, say migrating from EPP to EDR, eventually XDR. If you look at both of our products, FortiClient and FortiEDR, you can see there's a bit of overlap for maybe mid-size customers who just want antivirus or web filtering. Long term, we're going to try and bring these agents together in a single zero trust architecture. All right. Third pillar, secure any application on any cloud. Cloud security, adaptive cloud security. I talked about the migration of applications from data centers to public cloud to SASE as we go forward onto the edge. It's very important that any security or cloud security is available in a hybrid and cross cloud environment. You break it down. You've got to get to the cloud on-ramp, virtual networking, micro-segmentation. You've got to protect the platform. It may be the different clouds, it may be the data center through workload protection, container security, native security, then you've got to protect the application, mail, web, ADC. The third component of this is where are you inside the DevOps? Are you shifting left to protect more of that development environment, or are you shifting right? This all comes together in our adaptive cloud security portfolio. Hybrid and cross-cloud consists of network components, FortiGate VM, cloud networking, DDoS micro-segmentation, our platform, FortiCASB or FortiCWP. One of the fastest-growing areas are a set of rule sets that sits on top of native cloud security, such as IPS rules on firewalls or WAF rules on top of WAF firewalls, then, of course, application protection, FortiWeb, FortiMail, FortiADC. I'm not going to go through this slide in a lot of detail. It just shows you the amount of coverage you need inside these clouds, scaling from threat intelligence to the security centers. I talked about these rule sets sitting on top of native cloud security. Cloud security is very fragmented. You could use the existing cloud vendor, you can use our solution, you can use both, but we have individual roadmaps for every one of the major clouds out there. Bringing everything together through our Fabric Management Center, starting with its SOC, automate security operations across the Security Fabric. Traditional types of SOC security are very isolated. You put in systems such as threat hunting, malware analysis, you put in situational awareness, insider risk, EPP, EDR. Long term, this is going to migrate to what we call an extended detection and response system, a platform approach where everything is integrated, everything can share intelligence, and everything can use a cloud to make decisions very quickly. What does our portfolio look like for Fabric Management Center? Consists of endpoint, breach, incident response, so endpoint, you've got FortiEDR, XDR, which was recently announced, our sandboxing, our Deceptor, our FortiAI, and then incident response systems, Analyzer, SIEM, SOAR, and some new service offerings. Depending on the maturity of your organization, this can be very straightforward, such as sandboxing or Analyzer. As you get more sophisticated, more mature, you can make sure you can apply additional capabilities, whether that be deception or XDR or more sophisticated automation such as SOAR. We put our systems together such that a small business, a medium business, or a very large business, or some of our MSSP partners can scale the capabilities of their SOC to match their maturity. What's new with the Fabric Management Center SOC with 7.0? The core of the security operations, we have a single pane for the SOC, we have an extensive ecosystem, we have AI-powered threat detection and response from sandboxing to EDR. On the analyzer side, 7.0, we have this new service, SOC-as-a-Service, a new best practices capability, a FortiGuard outbreak alert offering. On the SOAR side, an incident war room, a mobile app, some new AI-based recommendations. The other part of Fabric Management Center is the network operations. Simplify network operations across the security fabric. Obviously, management's very important, and the single management console across all the products inside the fabric is very important. We started to add some additional capabilities. We started to add orchestration for things like SD-WAN. We started to add monitoring for the digital experience. The Fabric Management Center, NOC, again, can scale from a small business using something like FortiCloud, which provides a SaaS delivery of a lot of this functionality, all the way into a full-blown FortiManager that provides policy management, orchestration, and monitoring. One of the most important areas of a fabric is the Fabric Management Center. Fabric Management Center, two elements, as we said. One is the SOC, one is the NOC. You really need to try and simplify network operations across the security fabric. Three areas inside the Fabric Management Center, obviously, policy and management, configuration is very important, will always be very important, but we're starting to add orchestration inside there. Orchestration, for example, of SD-WAN, orchestration of SASE, and then monitoring, making sure you can look at that digital experience. Coming together across everything will be some form of AIOps, which provides that self-healing. From a Fabric Management Center, we have FortiManager. We also have FortiCloud, by the way, which is a SaaS-delivered cloud management system. A lot of the features and functionality of FortiManager, but more in a SaaS implementation, and then FortiMonitor, which is a recent acquisition. Similar to the SOC, you have this level of maturity. Again, for smaller customers, you may want to just use the SaaS management and configuration and policy management. As you go forward, for larger customers, you may want to look at the monitoring capabilities, so you're measuring that digital user experience. For larger customers, you definitely want to look at the orchestration. You want to make sure you're orchestrating across all those capabilities, across all those edges, both the networking functionality as well as the security itself. Where is the Fabric Management Center going long term? It's going towards self-healing network operations, the ability to heal and monitor and configure the LAN, the WAN, the data center, and the cloud edges. What's new in 7.0? FortiMonitor, Panopta acquisition, zero touch provisioning for SD-Branch, Policy Optimizer, best practice services, and now includes management of FortiProxy. Now, I just mentioned a new product, FortiMonitor. This is a SaaS-based digital experience monitoring, also a network performance monitoring system. It's SaaS-based. It measures endpoint LAN, WAN, data center. This actually has a lot of capabilities inside the cloud. As most customers drive towards that digital innovation, digital experience, this is going to be a very important part of the reporting structure to maintain that. It's very important to provide that threat intelligence to the platform. We refer to that as FortiGuard security services. There's quite a few of these individual services. It can range from AV signatures to IPS, to IoT detection, to management, security as a service. It can be applied to the endpoint, the network, or the cloud, and to any one of the form factors, hardware, software as a service, and API. We put these into these buckets of security. The first one is content security, looking at the content, and providing security there. There is the web security, then obviously user security and device security, and then as we go forward, more advanced SOC and NOC. Also available are what we call bundles. These bundles bring together some of these packages starting from ATP, advanced threat protection, to unified threat protection, to enterprise protection. The most advanced bundle is the 360, which includes everything. We just added SOC-as-a-Service inside there as well. By the way, if you are a larger customer, when I say a larger customer with maybe 20, 30 devices, then you should look at our enterprise license agreement, which gives you a lot of flexibility and operational savings. Again, as I said earlier, although we have a very extensive portfolio of 30-plus products covering the entire attack surface, we also have a very large ecosystem, in fact, 400-plus integrations, 200-plus ecosystem partners. This is very important that you're able to put the Fabric and connect the Fabric, supply that automation outside of the Fabric. With the Fabric integration, we have different types. One is what we call a Fabric connect, where we build into a major orchestration system or a major cloud. We have our own API, the Fabric API. A lot of companies from different areas have built into that API. We have a thriving Fabric DevOps community across cloud. Then we have an extended ecosystem, not only sharing of threat intelligence, but some of our systems can extend well beyond, like SIEM, for example, or NAC can extend well beyond our Fabric ecosystem to provide that coverage. It also breaks down into the different pillars. You've got a number of vendors who really focus on the networking side. We've got, obviously, there's quite a few vendors on the cloud side, on the security operations side, on the zero trust side. Some of these vendors may be competitors of ours, but we want to make sure that if you made a decision around a specific cybersecurity vendor or networking vendor, we can provide that integration. Now, again, we don't do a lot of huge acquisitions, but we do do acquisitions, and these acquisitions are really focused on specific technologies that we want to accelerate inside the Fabric. The goal is to bring them in and integrate them into the Fabric as quickly as possible. These are acquisitions over the last few years. You can see it ranges from security operations, FortiEDR, [Hylo], SIEM, [Stellops], ZoneFox around insight and UEBA and SOAR. The most recent acquisitions are FortiSASE, which is OPAQ, and FortiMonitor, Panopta a while ago. We also acquired some NAC and some FortiAP. Again, the ones which we acquired three or four years ago, a lot of that technology has already been integrated inside the Fabric. I can't go through every product in a lot of detail in 30 minutes. This summarizes what I've just talked about in terms of the product portfolio across both the security-driven networking, the adaptive cloud, zero trust, FortiGuard security services. Again, a very extensive portfolio, as well as being very open. We did announce a few weeks ago, FortiOS 7 with 300+ new features across the Fabric. That will be available at the end of this month. Again, the features range across the network, across zero trust, across the cloud, management, NOC, advanced services, et cetera. Do take a look at that. I think we're in beta 3 already, you can download and take a look at some of the new features inside there. I'm going to finish up. Thank you for listening in. As I said right at the beginning, my main message here is that most customers are driving towards a platform, but a platform that takes into account the network, the endpoints and devices, and the cloud and applications end to end versus just one of those. Thank you. [Presentation] [Presentation] [Presentation] Welcome to the VIP area of Virtual Accelerate 2021. My name is Ali Razavi, managing security operations in Fortinet SOC. [Presentation] In just a few moments, we'll enter the Fortinet virtual SOC for a guided tour. Meanwhile, we have Robert May, Senior VP of Product Management here to provide a warm welcome. Welcome to the Fortinet Virtual Security Operations Center. Just behind these doors here is the only SOC in the world powered by the Security Fabric Blueprint 7.0. In just a minute, I'm going to turn this over to our SOC managers to give you a guided tour. I know you're going to want to know where do I find more information. Let me take just a minute and show you exactly where to find all of this stuff in the tech expo. Okay. The first thing you're going to want to do is locate the tech expo. When you first logged in, you would have seen a menu on the left-hand side, and one of the options in that menu is for the tech expo. Go ahead and click on that. Now, once you've drilled down into the tech expo area, you're going to first be presented with all of the different kiosks which exist in the expo. These kiosks are ordered and grouped around the Security Fabric pillars. Let's go ahead and click on one. Let's click on Zero Trust Access. Okay, now that we've drilled down, let's take a quick look around. First and foremost, you're going to notice a central video. This video is really just a brief introduction, five minutes or so, just to walk through what are the different products and different solutions within the pillar, and it's also going to walk through the different blueprint elements that are important to that Security Fabric pillar. On the left-hand side, you're going to see a panel titled Meet the Experts. This really is your key to finding the most important latest demos for version 7. These are hands-on demos, in-depth, done by product managers, CSEs, and others. It walks through typically an end-to-end use case demo of a very important feature. On the right side, you're going to see links to things like the partner portal or the corporate website. Basically, the most important links which are relevant to this pillar that would provide more information for version 7 itself. Lastly, you'll be able to navigate between the different kiosks using the hamburger menu in the top left. That's a simple way to just jump between the different kiosks and the different blueprint topics that are there. All right, without further ado, let's get this tour underway. I bet you're excited to see the tech expo already. First, let's turn it over to a couple of our operations specialists. Next-generation network is the foundation of Fortinet Security Fabric. Jordan Thompson, VP of Product Development, is here to show you the latest updates on the network operation center. Hi there. I'm excited to show you a sneak peek of the new Fortinet Virtual Security Operations Center. We have standardized our deployment on the Security Fabric Blueprint 7.0. Today, I'll demo some of the products that we have installed, starting with the latest version of FortiOS. With FortiOS 7.0, I can now log in using my FortiCloud account. Granular access to all of my registered products and cloud services can optionally be controlled by the FortiCloud account owner using FortiCloud Identity and Access Management. One of the first things you'll notice is a variety of new dark themes, like this jade one. We are also getting back to our roots with a new retro theme. Let's check out which products have already been added to our Security Fabric. Okay, we have a FortiAnalyzer, several FortiGates, some access layer devices. Looks like Security Fabric is now set up using virtual domains. The fabric route has been split up to support multiple tenants. There is new integration with FortiAI. Here we can see it has scanned more than 200 files and already blocked 29. We have also expanded integration with FortiDeceptor, FortiMail, FortiNAC, FortiTester, and FortiVoice. All of these products seamlessly integrate with the security rating and Security Fabric automation features. Let's take advantage of the new automation framework to keep an eye on what is happening in the network. I can now trigger alerts based on events that happen anywhere in the Security Fabric. Here, we will enable a new alert based on FortiDeceptor. The insider threat event will trigger whenever FortiDeceptor detects an attack on one of its decoy VMs. Once the trigger is set up, we will add a new action to block any of the IPs reported by FortiDeceptor. So far, we've looked at some of the services running in our data center. We want to make sure that our internal applications are accessible for employees working remotely. FortiOS 7.0 supports ZTNA, Zero Trust Network Access, allowing us to securely grant internal application access to trusted devices and deny access to all others without the need for complicated VPNs. Let's enable access to our internal project tracking service. To grant access to this application, we first create a ZTNA server and link it to our internal application, in this case, projects.fortinet.com. Next, I create a zero trust policy to allow access to this server for endpoints with a specific zero trust tag. Here, I'll pick the project server and grant access to product managers. We're all set now on the data center side. You may be wondering how users will access these applications. Let's walk over to the next desk and take a look at FortiSASE SIA, Secure Internet Access, launching this month. FortiSASE protects remote workers by inspecting all of their internet traffic in the cloud while still providing fast access to internal applications in the data center. FortiSASE SIA provides seamless compatibility and integration with other Fortinet products and services, leveraging FortiOS behind the scenes. I've already logged in to the management portal using my FortiCloud account. Here you can see all of the other cloud service portals that I have access to. On the FortiSASE dashboard, we have the default security inspection rules applied for all users. Anti-virus protection is enabled, web filter is blocking access to malicious categories, and IPS is scanning for known threats. I can also optionally enable SSL deep inspection, file filtering, and data leak prevention. I've already linked FortiSASE with our LDAP services. Let's onboard our first user. Looks like an endpoint just came online. Let's see what they're up to. They appear to be active on social media. Let's block that. While we're at it, let's also block access to Google Drive to prevent users from leaking company documents. Finally, let's allow them to directly access that trusted application we configured in the beginning. Here, we will prevent traffic to our corporate project server from being inspected by FortiSASE SIA. When it reaches the FortiGate, the corporate policy we configured earlier will verify that the user's device belongs to the projects group and immediately allow access without an additional VPN. Great. Now all of our remote users have secure internet traffic as well as safe, direct access to our corporate applications. Talk about productivity. Sounds like we have an alert on the network. I hope the SOC team can help from here. Let's go back to the security operations center. We're in good hands as Ling Lu, VP of Product Management, oversees the service. She's going to look into a security alert and show us the latest Fortinet has to offer for your SOC. Hello. Welcome. First, let's take a look at the alert that has just come into the SOC. Here, I'm inside the FortiAnalyzer for the SOC module, I see a new alert pop up under Shadow IT. Click on alert. I see a user is trying to upload a protected file to Dropbox, an unsanctioned application, using his corporate email account. The upload is blocked by FortiGate, so no action is needed. Shadow IT is a new feature to extend SOC automation to the cloud via the FortiCASB connector on FortiAnalyzer. It allows the SOC to monitor cloud application usage, such as business versus personal apps, and flag unsanctioned usage and any potential file exfiltration. FortiGuard Outbreak Alerts is a new service available to your FortiAnalyzer through the enterprise protection bundle. This service is offered to protect you against malware outbreaks such as the recent Sunburst supply chain attacks. Here, we have collected all the resources you need to know about this outbreak and its detection. It consists of four pages. The first page is a summary that contains the background information about the SolarWinds outbreak. The second page shows details of the FortiGate coverage for this outbreak, along with the IoCs, event handlers, reports, and playbooks that help you to detect and hunt the threat. The third page is a kill chain mapping to show which stage each Fortinet solution covers. The last page contains the detection. All detector threats will be listed here. Click on each alert. It takes you to the incident analysis page so you can see the details of the detection and recommended remediation. As data and workloads are moving to the cloud, we see increasing demand for SOC-as-a-Service, which we are now offering through FortiAnalyzer Cloud. With this service, Fortinet SOC analysts around the globe monitor your network 24/7 to detect misconfigurations, policy violations, and security alerts, and escalate them back to you. It's really simple to onboard this service from FortiAnalyzer Cloud. Subscribe your FortiGate to FortiAnalyzer Cloud premium, or if your FortiGate is already registered with the 360 bundle, it automatically entitles to this service. Log in to your FortiAnalyzer Cloud instance and switch on Manage SOC service. You are now onboarded. The SOC portal is there for you to see all escalated alerts. We will notify you by phone for high-severity alerts and by email for all other alerts. In many organizations today, NOC and SOC teams are still separated. Both teams are on the front line of defense, and the line between them is increasingly blurred. It's important to bring them together given the overlapping scope and responsibilities of these teams. The Fortinet Fabric Management Center provides a single pane of glass for NOC and SOC teams to operate on a single source of data. It allows the NOC team to easily visualize and monitor distributed networks and to quickly identify and fix any network connectivity issues. It gives SOC team a wealth of security analytics to automate tasks for rapid response. Here, we have a high-severity SD-WAN event from the dashboard, and a single click will kick off a playbook to submit IT ticket for the NOC team to investigate. In FortiManager version 7, templates are expanded to simplify SD-WAN branch onboarding. They can be used to automate the onboarding process across tens of thousands of locations. Templates now support metadata variables, so you can use regions, locations, store IDs, and more to make zero-touch provisioning more scalable and fully customizable. A new SD-WAN branch can be provisioned and is up and running within minutes. The visual device map provides a single view of all onboarded devices for status as well as device health visibility. I hope you enjoyed our quick tour of the Fortinet virtual SOC. Let's head down this hallway where you can check out the virtual tech expo and learn more from other Fortinet experts. Hi, everyone. I want to first of all thank our partners, our customers, for taking the time to attend this session. This session is around simplifying SOC automation with FortiAnalyzer. I'm Satish from the product marketing team, and we have with us Ling Lu from the product management team as well. Many of you might have seen through the previous sessions, the Fabric diagram from Fortinet. In particular, what we are going to be focused on today is around Fabric Management Center and in particular FortiAnalyzer, which is a core part of the SOC offering that we have as part of the Fabric Management Center. The agenda for the day is first we'll talk about some of the key challenges we've heard our customers face today around the Security Fabric, and then we talk through how are those challenges being addressed through our solution with FortiAnalyzer. Then Ling comes on, talks about FortiAnalyzer and in particular, what's new as part of 7.0. Lastly, we leave you with a case study from a customer and then give you some next steps as well. If you look at it, most customers struggle with complexity of operations, and that's no news for the SOC teams as well. In particular, they're struggling with complexity because of one or many of these reasons that are listed here. Either it's because they have too many vendors in the mix, or they're struggling with too many alerts that are coming in, or they have slow response, or more importantly, I think the entire industry is struggling with lack of trained staff and we continue to have shortage of staff. All of these, or a combination thereof, are contributing to complexity of security operations for teams, small, medium, or large. How we address this is by simplifying the security operations based on a simple concept called SOC maturity. We define maturity based on the people, the process that they follow, and the technology that they use, and we put them in either level 1 SOC maturity or level 2 SOC maturity or level 3 SOC maturity. Fortinet offers a range of offerings that improve the efficiency of the security teams, like I was mentioning, across all maturity levels. This is an attempt to help you understand some of the offerings and how it kind of fits in our framework of simplifying security operations based on your level of maturity. All Fortinet Security Fabric customers are encouraged to establish an analytics and automation foundation with FortiAnalyzer, as you can see here in the sketch as well. Building on this foundation, as organizations have growing concern about threat landscape and have limited security staff, skills and processes, FortiXDR enables automated incident detection and investigation and response across the fabric. For organizations who have more diverse security environments, FortiSIEM, as a core part of our SIEM solution here, adds multi-vendor visibility and analytics. While organizations with well-defined security processes can utilize FortiSOAR to improve efficiency with orchestration and automation across their multi-vendor environment. This is just to help you understand how we think about simplifying operations based on the security maturity that your SOC team has. In the rest of this presentation, our focus is primarily going to be on that foundational layer, which is FortiAnalyzer. We wanted to take this time and give you a sense of how we think about our offerings and how we can help you simplify security operations across the maturity level that you have with your SOC team. Coming back to FortiAnalyzer and how FortiAnalyzer can help you automate your security operations, we think of it as three core themes that go into FortiAnalyzer that enable you with automating your security operations. The first is around security fabric threat detection and response, which is around automating advanced threat detection across the security fabric. In particular, we have a subscription service called Indicator of Compromise Service that enables our customers to identify any anomalies within your environment through the subscription service that is powered by our FortiGuard Labs. The second core theme is around security automation and whether your team has a low maturity or medium maturity, we enable you to unlock the automation features that are part of FortiAnalyzer. Lastly, we believe FortiAnalyzer is a core foundation, and on that foundation we have the subscription security operation services that can be attached as you feel your SOC maturity is improving, you want to add more services on top of it. As you would see in a bit, we have new services that are coming out as part of 7.0 that enable you to improve your visibility, improve your automation on top of the foundational layer, which is FortiAnalyzer as well that you have. What are the core use cases for SOC automation with FortiAnalyzer? The first core use case is around Security Fabric analytics. Whether customers have three FortiGates or they have FortiSwitches or FortiAP is behind those FortiGates, at the end of the day, they want very simple visualization and analytics that are happening within their environment, FortiAnalyzer immediately helps you with that single pane visibility with Security Fabric analytics. The second key use case is around advanced threat detection. In particular, like I was mentioning before, when you enable the Indicators of Compromise Service on FortiAnalyzer, immediately we can enable you to identify anomalies within your environment very easily. Compliance is the third key use case. We have canned reports for PCI DSS, the situation awareness report, which is governed by NIST and so forth, that enables you to accelerate compliance quickly as part of FortiAnalyzer. Lastly, based on your level of SOC maturity, we enable you to augment your SOC teams and improve your SecOps risk and compliance posture as well through the automation of SOC through FortiAnalyzer as well. With that, I want to pass the ball to Ling to talk more around FortiAnalyzer and some of the key feature updates as part of 7.0 as well. Thanks, Satish. SOC teams require multiple areas of expertise and have to deal with many tools such as SIEM, sandboxes, threat intel systems, ticketing systems, and so on. There are simply too many alerts for SOC to monitor, alerts overloading, and these lead to slow response and missed security incidents, increasing the chances of security breach that can have severe consequences. FortiAnalyzer provides the SOC team with a wealth of security analytics and built-in incident response frameworks to automate SOC processes for rapid response. Let's take a look at the Fortinet SOC solution as it stands today in three main areas. First, threat detection and incident response. FortiAnalyzer provides fabric logging, reporting, and security analytics out-of-box for the SOC to monitor entire Security Fabric attack surface. It keeps things very simple to understand and simple to operate. There is very little extra configuration and rules tuning required. Today, it is integrated with the majority of our Security Fabric products such as FortiGate, FortiWeb, FortiMail, FortiSandbox, FortiGuard, FortiClient, and so on. It also has built-in SOC and UEBA for advanced threat detection. In 6.4, we added SIEM database so it can process security logs from Windows and Linux OS. Second, SOC automation. We have an incident response framework that provides playbooks to automate SOC tasks, built-in event handlers, alert triage, and threat hunting reports. Third, cloud services. Along with all of this, we also provide cloud services for SOC. FortiAnalyzer platform as a service is available through FortiCloud and FortiGuard IoC service and SOC service available to FortiAnalyzer for threat detection and rapid incident response. The upcoming ordering guides make ordering products and services much easier. They contain all the necessary information in the digestible format. The easiest way to buy FortiAnalyzer is through hardware bundles or a VM subscription bundle. The hardware bundle includes the hardware, the first year enterprise protection bundle, which contains the FortiCare support, IOC, and SOC subscription. Renewal bundles are available. The VM subscription bundle is an all-in-one bundle that contains VM subscription, 24/7 support, IOC, and SOC service. It is worth noting that the new FortiGuard outbreak alert service will be included in the enterprise protection bundle. FortiAnalyzer licensing is based on gigabyte per day logs. Sizing number of gigabyte per day for your customer can be challenging, particularly when information such as log rates or new sessions per second are not available. Fortunately, we have a sizing tool that we have been using internally today and should be available from FNDN soon. If your customer needs a cloud-based logging analytics solution, they should go by FortiAnalyzer Cloud platform as service. The basic FortiAnalyzer Cloud logging and analytics is included today in the FortiGate 360 Protection bundle. The FortiAnalyzer Cloud premium subscription supports advanced logging and analytics, and it includes the upcoming new FortiAnalyzer Cloud SOC-as-a-Service. The innovations for version 7 FortiAnalyzer fall into three areas. The first area is Security Fabric detection and response. In FortiAnalyzer version 7, the logs for new Fabric devices such as FortiEDR, FortiDeceptor, and FortiAI are now supported. For scalability and performance, we are adding a capability to FortiAnalyzer to horizontally scale up a FortiAnalyzer deployment for threat detection. Basically, you have the FortiAnalyzer orchestrator to oversee and coordinate all the FortiAnalyzer instances in the cluster, and data are stored and processed in each FortiAnalyzer, but it's accessible from the single console of the orchestrator. UEBA is further enhanced for accurate detection and more coverage, and SIEM correlation and analysis are expanded for more advanced threat detection use cases. The second area is SOC automation. The FortiSOC module today is a part of incident response framework on FortiAnalyzer. This built-in module provides basic SOC automation within Fortinet Security Fabric core products with minimal configuration and setup designed for customers to easily adopt the SOC. Today, it has the connectors to FortiOS, EMS, FortiGuard, and FortiMail. You can create SOC playbooks for automated incident response. As the SOC grows, it needs more advanced automation and incident management capabilities to scale up the operation. FortiAnalyzer 7 has a FortiSOAR container to make this transition easier. It comes with four SOAR capabilities to help accelerate your SOC maturity. Now, connectors in version 7 extend this automation to cloud. The XDR connector allows an XDR cloud to query FortiAnalyzer data for extended endpoint detection and response. The FortiCASB connector allows FortiAnalyzer to automatically uncover Shadow IT, such as unsanctioned application usage. Some SIEM vendors may provide similar capabilities. FortiAnalyzer makes things super simple, and they work out of the box. It does not require special tuning, it saves your security team tons of time and effort to get things going in your SOC. The third area is SOC cloud services. As data and workloads are moving to the cloud, we see increasing demand for FortiAnalyzer as a service. Today, we already have self-managed FortiAnalyzer platform as service available for SOC. Now we are expanding to a managed SOC-as-a-Service offering. With this service, Fortinet SOC analysts monitor customer FortiGate logs for network and security events to detect misconfigurations, policy violations, and security alerts and escalate them back to the customer. Two types of deployment are supported. FortiGate directly sends logs to FortiAnalyzer Cloud, or FortiGate sends logs through an on-premise FortiAnalyzer that forwards the logs to the cloud. The license model is very simple. You only need to add a FortiAnalyzer Cloud premium subscription for each FortiGate. FortiGuard Outbreak Alerts is the service available to our FortiAnalyzer customers through the Enterprise Protection Subscription. This is the downloadable content package from FortiGuard, including event handlers, reports, and playbooks for malware outbreaks. To make things even easier for the SOC team, we now have FortiCare best practice services available. You don't have to figure things out yourself, and no matter if you have a new deployment or are upgrading an existing system, this annual subscription service will have Fortinet experts available for consultation to ensure your deployment or upgrade is successful. Finally, I would like to mention there are plenty of resources available from the Virtual Tech Expo on FNDN for SOC solutions, including various demos and videos to showcase FortiAnalyzer SOC automation and incident response capabilities. FortiOS 7.0 will be GA'd at the end of Q1, and FortiAnalyzer and FortiManager 7 comes a few weeks later in April. This is all from me today. Satish, back to you. Thanks. Thank you, Ling. Very quickly, I want to summarize through a case study and leave you with some next steps. This is a customer story about Kent ISD, which is a small school district with about 20 schools out of Michigan. By the way, this is again publicly available on our resources section as well. Their primary objective was to have advanced threat protection against rising cyberattacks against K-12. They had, as you can see, a very small IT security team. They want to minimize the resource involvement in terms of either bringing up, improving visibility or even resolving incidents. They wanted to implement that central single pane for their team for visibility and analytics and have the best price to performance. Net net, they went with a FortiGate next-gen firewall, behind that is also an analytics engine, which is FortiAnalyzer, to enable them to have that central visibility and more importantly, help them to automate their operations with a very small IT security team. I want you to take away three key things from today's session. The first is FortiAnalyzer enables the Security Fabric threat detection and response. In particular, as you would see, like Ling mentioned as well, as part of 7.0, we have increased the Indicators of Compromise offering that we have, more importantly, we've also brought in behavior analytics to enable you to reduce risk and improve your behavior anomaly detection as well. Fabric event handlers to enable you with response and automating the response. We have also incorporated new Fabric event handlers as part of the Security Fabric detection and response. The second key takeaway is around automation. Now, we seriously consider FortiAnalyzer as a platform, and based on the SOC maturity, we want to give you a choice to incorporate advanced automation as part of adding new containers like FortiSOAR, which is our security orchestration, automation, and response offering that can be easily attached to FortiAnalyzer as well to improve your SOC efficiency. We've also incorporated the connector into FortiCASB so that you still have that single pane visibility. Though you have these breakouts that are happening into and accessing into your cloud, you can bring that intel back into your hybrid enterprise as well and leverage that to identify risks across your hybrid enterprise. Lastly, SOC cloud services is the third key takeaway, which is we have SOC-as-a-service to help you augment whether you have an MSSP or whether you're a customer who has a SOC team. We want to augment your SOC team by providing you Fortinet aware intelligence and being your L1 into the security fabric to identify any anomalies or violations and bring it back to your attention. Best practice service. We see customers struggling with following best practices in terms of what to do, what automation, what playbooks to apply, and so forth, and we have the service to enable you to take full advantage of your FortiAnalyzer and automation features that are available as part of FortiAnalyzer as well. With that, I want to leave you with some next steps on the web. You can search for FortiAnalyzer, whether it is as the Intel or AI-driven security ops trailer, you can find FortiAnalyzer as part of related products, and we keep that up to date. The next thing is NSE Insider. We actually have an NSE 3 around FortiAnalyzer, which we also keep up to date. I urge you to please take that FortiAnalyzer lesson. Lastly, there is a dedicated fast track around SOC automation in addition to Fabric Management. We urge you to please take part in that. There's also going to be a hands-on lab, so please take advantage of that. With that, I want to thank you for your time today. I hope you have a fabulous rest of Accelerate 2021. Thank you again. Hello, welcome to Accelerate 2021. This session, we will discuss how to create a resilient endpoint security strategy for the era of remote work. My name is Tsailing Merrem. I am the director of product marketing. Joining me is Roy Katmor. He is the general manager for our endpoint business and the visionary for our endpoint security strategy. I've been working at home for close to a year, and the pain point that facing the CISO has not changed, rather exacerbated by remote work at scale and in a hurry. The first thing is a lack of visibility. It just gets worse when people are sent home in a hurry, many company are letting employees having more latitude in terms of downloading applications, at the same time feeling anxious about not having the visibility and control. This also led to breach anxiety, knowing that the hygiene can be better and also with the accelerated threat landscape, ransomware scares, and the associated business disruption. The last thing is, let's not forget the security teams are also sent home and facing the advanced threat landscape, yet they have to deal with a barrage of alerts, causing fatigue and potentially burned out. All these pain points, it's getting worse by the situation we are facing today. We want to talk a little bit and give you a framework how to think about remote work security and how to establish endpoint resiliency. Essentially, shifting the mindset is like, it may not be possible to prevent 100% of threats. Let's look at all the tools we have at our disposal to reduce the risk of getting attacked or reduce the risk of a breach and the business disruption. Number one, we talk about visibility is important. Having visibility alone is not enough. It's essentially knowing what are potential threats, but doing nothing about it is not very helpful. The idea is you want to have the visibility. You also want to have the ability to take action, essentially preemptive controls. The next thing is, and that essentially is prevention and hygiene, and equivalent to doing all the right things. Also have the mindset that endpoint compromise is going to happen, and how do you protect the endpoint, and what solution you put on the endpoint will allow the endpoint to self-defend? Not just to block malware, but also identify potential unwanted applications, identify malicious processes, and shut it down in order to self-defend. Once you identify those malicious activities on the endpoint, how do you help the endpoint to "self-heal"? Essentially, it's almost like giving endpoint immune system, right, to self-heal, to roll back the malicious changes. Let's face it, when you have 80%, 90% of your workers working from home, the old way of reimage, rebuild may not be realistic. Let's look for a way to have remote remediation as part of your strategy, so you can basically decide what type of incident you will use remote remediation, and then essentially roll back using the tool. What you have when you have no choice, then you use the reimage and rebuild. When I talk to analysts, they have estimated about 55% of enterprise has adopted EDR, and they're still in various stage. One thing I've noticed, that the early adopters may have adopted EDR five years ago to augment their endpoint protection strategy. They are sitting with two disparate solutions, EPP and EDR, and they're looking to consolidate the endpoint security. The later adopters, the mainstream buyers, now are looking for a single unified solution for EPP plus EDR in one integrated solution with one integrated agent. Why are the security leader looking for things like that? Just thinking back to the strategy I was talking about, they want to strengthen security posture. They want to prevent as much as possible, doing the right thing, have security hygiene across a wide range of endpoint and workloads. The other thing is maintain business continuity. Understand the breach may happen, understand your endpoint may get compromised. The idea is how do you have the layer of tools to detect early, respond quickly, and recover to get business back to normal as soon as possible without interrupting business continuity or minimize interruption of business continuity. This means factory will continue to churn out goods. This also means retail sectors, that their customers are not being turned away. This means hospital can continue to help patients. This means school can continue to have remote distant learning without being interrupted. The last thing is when you think about CISO, they are thinking about their employees, their security team. We also want to help them address the challenge, and the EDR solution, combined EPP with EDR solution can help streamline security operations, having better visibility, and enhance the SOC maturity when you select the right tools and with the automation. Essentially, get your SOC employee out of the business of doing mundane manual work. Let them do something that's more interesting and higher value. If possible, you selectively use help of security services so you can have a 24/7 SOC while allow your security team to actually have a good night's sleep. The use case for EPP and EDR combined solution is we talk about today we're going to focus on remote work security. We also know that a very front and center for people when they adopting a combined solution is for ransomware protection. Because ransomware is not just file-based malware. Some have fileless, you want to have behavior-based detection, real-time containment, and essentially just shut down the malicious activity right away. The security leaders are also looking for this type of robust endpoint solution with prevention, detection, response to help optimize incident response process, to accelerate the mitigation with playbook automation and incident response. Also looking for the adjacent MDR service to help them essentially lend a helping hand to augment the security team. Another thing I also see is OT security. OT traditionally has been lagging behind because they have legacy operating systems. Almost those kind of systems, you touch it breaks. They are really concerned about not doing something too intrusive. Looking for a solution that can safeguard those systems while maintain business continuity. Because in the OT world, you have to make sure the system availability is extremely high, but we also know the adversaries are targeting them, knowing these systems are ancient. This is another very important use case for a combined solution that have prevention and detection response. Next, I am going to invite Roy to join me, and Roy will talk to you about FortiEDR. He will give you a product overview and his vision of building this wonderful solution and what's new, very exciting new feature coming up in 5.0. Take it away, Roy. Thank you, Tsailing. On the FortiEDR product overview. First, a recap of the product end-to-end, including version 5. As a reminder, the product is split into two main areas, the pre-infection, pre-execution, where we have two segments there. The first one is the discovery and attack surface reduction, which allows us to discover applications, IoT, and raw devices, enrich them with vulnerabilities, best practices, and ratings, and allow to reduce the attack surface according to the best practices of the organization, namely, the ability to filter vulnerabilities and restrict the access to applications or devices that have extended vulnerabilities that do not comply with the current policy. On the prevention side, our machine learning AV has now extended to also include the FortiGuard threat intelligence web filtering. We have a sandbox with two clicks integration, so you can actually integrate a sandbox into the process. New files that are being introduced and downloaded from the internet, for example, could be vetted within a sandbox, and we support a cloud one and on-premises one. We added a host firewall, and so you can actually restrict down by applications, by networks, by domains, and so on. On the post-infection side of the house, we basically separated into the detection, where our detection is spiced with code tracing. We do have the smoking gun, those memory infections, those beacons that are going and extracting in-memory. We correlate all the activities together while holding all the forensics, all the execution-related stacks together. You can have the smoking gun and, of course, the very surgical remediation that is associated to this. All of that is done with a very tight classification, so we can take later on a very pre-canned incident response. It's not just a matter of auditing. Of course, we introduced a very in-depth forensics within the new threat hunting that was added in version 5, and we'll talk more about it. It's also about protection. We talked about prevention and attack surface reduction in the pre-infection. In the post-infection, we are the only vendor that can stop malicious connections or file tampering in real time, even though compromised. We never assume that we are being deployed in a new and fresh environment, and we understand that there might be already infection, and therefore, we allow to defuse those and create a micro containment and buying time for the team not to have the consequences of an attack. When it comes to response, it's very understood right now that we'll do our best to reduce the attack surface, prevent what we know, defuse what was already in while auditing very extendibly. If we're already infected, we obviously need to introduce also a respond and investigation that allows us a better automation and orchestration around the different tools, and version 5 holds in store an extended ability to activate, according to the classification, different tools according to the context of the attack. When it comes to remediation, in the same way of the response, we also allow to clean and roll back. Even in cases of a ransomware, we have a patent that allows us to do that and roll back in real time when we discover that there is a ransomware that is activated as in action. As long with that, we can have a full remediation, including isolation, including IoTs, and with an extended response to a NAC or socialize IPs to the firewall, sending emails, opening tickets, and all of those are pre-canned recipes that we allow to utilize. When it comes to what's new in version 5, we separated it to three main areas. The first one, we need to support more, and the breadth of platform coverage is a key to our success with not leaving any version behind. If so far we supported the Windows from the XP Service Pack 2 and all the way to the newest and all the macOS and Linux flavors that are more associated with the Red Hat, CentOS, Fedora, and Ubuntu. Moving forward, we removed the kernel dependency that we had before, and that's in order to support the Big Sur or macOS 11 that was released late last year in 2020, and basically pushed out kernel vendors to the user space. By doing so, by that support, we actually expanded our Linux outreach to be enabled to have an application-based solution. Now we can support more operating system, even though we do not have the kernel extension for those with a full functionality and parity with what we had before, and added more also, a platform as a service and infrastructure as a service related distribution as Oracle Linux and the AMI, the Amazon Machine Interface. Within the coverage, we introduced the fabric telemetry analytics of the extended fabric, so we can actually digest our own Fabric insights into the EDR platform in an XDR fashion, enrich those, and again, respond in an extended way. From a security efficacy, along with the asset control, discovery and control and the pre and post-infection we discussed before, we added a CPRL, the intelligence of FortiGuard into all of our platform, which means the machine learning-based AVs now can actually have an enriched intelligence to it, which added us a web filtering or the idea to block requests that are going into known malicious or suspicious host IPs or domains. We added a host firewall that allows the user to basically control applications, domains, and network-related just like any personal firewall, all controlled through a single pane of glass. From a SOC efficiency, along with a code tracing forensic that is unique to us to have the smoking gun and the Fabric-powered IR recipes or playbooks, as we described before, we added a behavior-based threat hunting. The idea behind that was not to just look at an audit in its very native, uncorrelated fashion, but to actually take the data logs as they're coming in from the endpoint, and as I mentioned before, could be from an extended resource, correlate them together, and try to identify behaviors within raw logs. Along with those lines, we added to those behaviors also the MITRE tag, so you can now go into record and click and find what kind of MITRE technique are they associated with. We added a third-party integration to our Fabric-powered playbooks. It's not only Fabric on the response, but you can orchestrate beyond the Fabric and activate other firewalls, other mail, and other services within our pre-canned recipes. A little overview about our new extended behavior-based threat hunting. As many other EDR, we are collecting a lot of data and a lot of activities. We separated the activity into process-related, file-related, network-related, registry-related, and also event logs. Which could be the raw logs that's coming as a feed or raw logs as exist on the host. Again, there's no need to jump from a host back to the system. The system control the host and allows us, in many ways, you can get any file from the threat hunting. You can view any running process in the current, in the past, and filter those through. One of the nicest features that we did here are the facets or the ability to actually have the heuristics and machine learning on top of the raw data that is called activity in order to identify behaviors that are already within the data or within the benign data that we assume that it's benign. I'll give an example here. The behaviors, for example, as you can see in this example, could be any kind of behavior that could be associated with benign, but also known to be a technique or a known attack flow. We try to flag that for the user, so the user won't need to look at millions or hundreds of millions of raw data, but actually look at it in a correlated fashion of behavior. For example, lateral movement, command and control, privilege escalation, first use of a protocol, execution, log deletion, and so on and so forth. If you're going just to understand any SOC engineer that has a suspicious of, for example, a very common use case, do we have lateral movement, benign or not? Do we have those or not within a code, within our environment? You can now actually go in, filter out by lateral movement, by behavior, which we already flagged that exist within the data that you're currently filtering, see the MITRE technique that is associated with it. It's completely guided a workflow that we created here, and of course, get the data and try to validate whether this specific behavior that we're looking at, which is a very small portion of the entire raw data, is something that we are familiar with within the organization or not. We can actually start an initiating investigation according to that beginning of a needle of the big haystack of all the raw data that is collected within threat hunting. As I mentioned before, FortiEDR Fabric integration was extended to also third party. Within our pre-canned playbooks, you can find within the FortiGate, FortiNAC, FortiSandbox, of course, FortiSIEM sending through a Syslog, and FortiSOAR recipes. You can also integrate third parties as other firewalls, Active Directory, other mail providers, and other log collectors. All of those, of course, allows us to respond faster and in a scalable way across the board. A little bit about the ordering guide, just a few things to know, and I'll go quickly through a Q&A on this. The biggest changes that we introduced, we are selling in packs. The packs are 25, 500. We added a new pack group, 2,000 and a 10,000 seats. EDR has an MOQ. All the different SKUs that I just mentioned under the different packs are bundled with a 500 seat MOQ, besides a single all-in-one MDR blended end product that can allow 100 seats and best practices. To choose the best FortiEDR bundle for a customer, it always something that you need to fill the budget of the customer, the need of the customer, of course, according to the RFP and RFQ and the competitors. We put a very detailed comparison between the different vendors that we can share. You know what you're looking for, you know where is your budget, I'm sure we can find the best bundle for you. The right services is, again, we force best practices on all of our services. The reason is, we want to have a full satisfaction with the product from day one. It's an alternative to a jumpstart, but the idea is that when we leave the customer site, the customer is deployed, tuned, and ready to go in the best security posture that we can have. We extended our MDR services. I mentioned a little bit about XDR. We introduced a managed XDR from day zero to help our customers to integrate our fabric together and take an extended response and triage across the different products. Of course, we have MSSPs, and there are plans for MSSPs across the board that allows us to get closer to customers and go under the MOQ for customers who need that services. Those partners are certified within the fabric and Fortinet certification named NSE. Back to you, Tsailing. Thank you. It's really exciting to see what's coming up in 5.0 and all this integration that your team has been busy putting together. Next, I am going to talk to you about customer success and third-party testing. Essentially give you some validation, because by now you've been thinking this solution looks great. Is it proven? I want to share this story with you. This is one of my favorite story because we talked a lot about early adopter that typically will start with EPP and a separate EDR and move on to an endpoint security consolidation. This is one of the such case, one thing I like about this even more is because there's a sequel to it. Wait for it. This customer is a well-known power tool manufacturing. It's one of the Fortune 500 manufacturer of industrial tools and household hardware. The challenge is the CISO basically come to us and told us they're using three vendors. They start with a traditional endpoint AV, and then he knows that prevention is not enough. He also is aware of a file-based detection is not enough. He also acquired an EDR solution, what I personally call it a first generation EDR solution to augment that. Knowing that the first generation EDR solution is operating under the assumption that endpoint will get compromised and as a result is hypervigilant, churning out a lot of alert, and potentially some of them are false positive. He knows for his small team, they are not able to triage all this barrage of alerts. He hired a third-party company, a managed security vendor, to handle MDR service. That essentially is outsourced SOC. This outsourced SOC has a SLA of 72 hours, which is not ideal, and he recognized that. He is on a mission to look for a consolidated solution because as you have seen, most of the enterprise is on a path to consolidate as much as possible, because when the systems are consolidated, especially our endpoint security, it just works so much better. His requirement is vendor consolidation, and he also want to work with a solution that has its own MDR service. When your EDR solution has its own MDR service, essentially you have your own team using the tool, and MDR team is going to demand the engineering to make sure the system and the solution designed is efficient to use by the Security Operations team. That's his requirement. When he reached out to FortiEDR back then, that was enSilo. These were his requirements. He was very clear. He believed his company had a good security posture because all of these processes he put in place. His goal was to find a solution that could help him with consolidation while providing service. The efficacy should be equal to what he had. That was his benchmark. When we put in FortiEDR as a POC, right away the team discovered there was a malware. It was a cryptomining malware that was running in, I believe, over 10,000 of endpoints. It was basically moving around his environment unimpeded. You can imagine the CISO's dismay. He was very upset. He went and talked to the EPP. He was like, "Hey, this is a malware. This is a file-based. This is pretty trivial. You guys should be able to block it." The EPP vendor essentially just apologized and say, "Hey, you know we're not perfect. That's why you bought an EDR solution. Go talk to them." He went and talked to this first generation EDR vendor, and the EDR vendor essentially pull all the log and say, "We detected it along with 14,000 other alerts that we just fired in the past 24 hours, but nonetheless, we detected it." If you are any CISO, whenever you hear things, this is an absolutely nightmare because the problem is you have so many product that's firing alert and finding the relevant alert that's actually associated with real threat is so difficult. That's why he has the outsourced SOC. The MDR vendor's like, "Hey, we file the alert. You hire somebody to triage it, go talk to them. He went and talked to the MDR vendor, and the MDR vendor reminded him, he's like, "Hey, our SLA is 72 hours. As you have seen a lot, there's over 10,000 logs, like at 13,000 or 14,000. We are working our way through, and that's what you hire us for. This threat that FortiEDR has discovered is less than 24 hours. We have two more days, and trust us, by then, if it's not for FortiEDR, you wouldn't be none the wiser. We would triage it, block it, and life goes on." Needless to say, that wasn't a very good answer, and as a result, this manufacturer has been our customer for a couple of years by now. The idea is he reduce the risk exposure having a combined solution and having a solution that essentially can self-protect. Whenever we discovered a threat, it can automatically isolate the process specifically on the malicious action. Essentially laser focus on the malicious action and pause the attack. Also it's a single agent, so the machine learning is learning from the subsequent detection function, as Roy has mentioned earlier. Also we have better SLA because of MDR service, and the SLA is within 24 hours, all the alerts are triaged. Another thing is, I can tell you, our MDR team is darn demanding. They do tell the product team how to continuously improve the operational efficiency to make them more streamlined, and our customer also benefit from that. I mentioned this story has a sequel. As you remember, at the end of last year, there was a SolarWinds hack that got a lot of coverage. Essentially, I believe about the assessment is about 18,000 SolarWinds customer was infected. This attack, this operations hiding menu, once the customer are infected, essentially there's a backdoor and it's beacon out, and this allegedly a nation-state attacker is then basically pick and choose which company they want to attack. There's a twofold. The first onefold is customer that has SolarWinds Orion product are really concerned because they have a backdoor, and that potentially make them vulnerable. Even if this nation-state attacker doesn't utilize it because they are not their priority, other attackers can take the advantage and be opportunistic. The other fold is they are not sure if they are the target. The action what we have taken is, this is right before Christmas, and as soon as the news broke, one thing our team has done is our MDR team start research and work with engineering team to analyze the security incident, identify the IoCs based on the disclosure, and start searching across our entire environment and notify all of our customers if they have this, what I call poisoned DLL, essentially that is a backdoor. We then work with the customer to determine are there subsequent level of compromise. Is it because we know the attacker's method and techniques? Beyond this DLL, this backdoor, are there any subsequent indicator of attack happening? We work with our customer to identify the compromise, and we also develop tool to quickly helping the non-MDR customer to determine if they have a backdoor, if there's a subsequent compromise. For the customer I mentioned earlier, we get on the phone because they were really concerned they were using SolarWinds. We get on the phone, identify and reassure them how our solution can protect the subsequent payload and help them ensure that we will continue to monitor for additional indicator of attack, and also provide guidance to the security team to close out the backdoor. The result is, any time this is part of our threat research team, any time when we identify a potential threat or identify an alert and that later confirm is an attack on one customer, we use that knowledge to threat hunt across the entire environment and benefit all of our customer. We use that. We have identified some early strain of ransomware attack. We have helped several customers to identify early stage attack when it was still using Cobalt Strike. These are some of the examples. The third party testing. We are participating in AV-Comparatives. AV-Comparatives is an ongoing test. Essentially we submit the product twice a year. The product sits in their lab. It does continuous test. AV-Comparatives has been upgrading their testing tools. In the past, they have a malware test, they have a real-world test. Now they have enhanced real-world test. We are participating in all these tests. You can see not all vendors that claim to have EDR capability are participating in this. Fortinet, you can see that we are working with them, and you can see we have very high detection rate and very low false positive, and these are important. Again, as you have known, with Fortinet, we are committed to get third party tests because a lot of time our competitor or you may encounter vendors that come to talk to you about all these things, they need to prove it, and this is our way to continuously testing it to improve our product and also prove it. Watch this space. We are also participating in MITRE ATT&CK test, and there is a new MITRE test that include the protection testing. This one I'm especially interested because the prior MITRE is all about detection and telemetry. As you know, you can fire 14,000 alert, if you don't have an accurate way to block it doesn't help many of the customers. We are very glad to see MITRE has a new protection test, we have participated in it. Three key takeaway. You have listened to Roy talking to you about 5.0, all these new feature, I'm going to net it out for you. We are continuing, we are committed to have a broad security coverage across Windows, Mac, Linux, we'll continue to protect legacy OS. We also will have the user discovery capability to discover IoTs and other devices that you cannot put an agent on it. Why? We want you because you are only as strong as your weakness. We want to make sure we have a broad security coverage so there's no hole in your coverage, and we give you the visibility you need to cover your security. The next one is efficacy, because you can fire out all the alerts, but if you're not able to surface the important one and provide action. This is I have always talked about. Having visibility alone without action is just going to induce anxiety. This can mean preemptive virtual patching when we discover vulnerability. This also means when we discover potentially malicious activity, we can shut down that activity, essentially defuse the attack, and pause the attack so your team can take the time to investigate, and we can also help you with our AI-powered investigation engine to surface the important event that your team needs to look at. The last one is all that is going to fuel into a more efficient SOC. Essentially, it's going to make your security team more satisfied at work. The mundane work can be automated and have a real-time response. In case they're taking a break or they have to go home or take care of personal business, knowing that if there's a threat, we can pause it and buy them time for other additional detection and response. We also have MDR service to help you to augment the existing team. Moving forward, we are adding behavior-based threat hunting to allow the SOC team to do more proactive threat hunting. Because now they have the automation to take care of the mundane, boring things, and now they can do things that's interesting and higher value, like proactive threat hunting. Also with XDR, the Fabric integration, now we have extended Fabric response and also XDR. There are the resources. For public resources, I will recommend you to go to the FortiEDR page and click on resource. We have multiple recorded webinar. One I personally really recommend is if you have ransomware anxiety, there is a ransomware webinar, and that one I talked about ransomware preparation, taking you through all the stage of how to prepare against ransomware. Just as simple as having a discussion. If this happened, do you want to pay ransom? Give you tips on how to ensure your backup and recovery is ready enough. The discussion is beyond endpoint protection. For partner folks out there, we also have partner resources. Go head over to the partner portal. I have mentioned that we are expanding our coverage to the entire Security Fabric, starting with endpoint detection, with extended response. We just launched XDR. XDR means extended detection, AI-powered investigation, and extended response. It's fully automatable across the Security Fabric. There is a session on XDR, so I highly recommend you to check it out. That's all the time I have. Thank you very much for taking the time to listen to this session. My name is Tsailing Merrem, and thanks to Roy to share the roadmap with us. Have a great rest of your day. Hello, welcome to this Accelerate breakout session focused on leveraging sandbox and virtual security analysts to empower organizations to tackle the volume, speed, and sophistication of cyber threats. My name is Damien Lim, part of the Fortinet product marketing team, focused on our breach protection solution and products. Joining me is Brian, a Fortinet veteran and product manager for FortiSandbox, and Jack Chan, another veteran at Fortinet, who is the product manager for FortiAI. To provide context, FortiSandbox and FortiAI is part of the breach protection solution that is under our AI-driven security operations and is part of the overall Security Fabric. In today's agenda, we'll cover cybersecurity challenges and the solution approaches, and one of such solution is the use of sandboxing for zero-day threat protection, and the other is the concept of virtual security analysts to aid the investigation of these threats. We'll then delve into the FortiSandbox and FortiAI unique capabilities and the validation of these solutions, and then wrap it up with a recap and next steps. For now, let's focus our discussion on how an organization can evolve their security to deal with the challenges that cyber attackers pose. Most organizations adopt a security framework to plan their information security strategy. One such example is to leverage the seven stages found in the Lockheed Martin Cyber Kill Chain as the context to help provide guidance. Foundationally, a security operations team should have a good baseline in securing all threat vectors or entry points against the delivery of known threats as the first stage. Then move into adopting sandboxing as a method to protect against delivery of unknown and zero-day attacks. In the next evolution of security ops maturity is the adoption of deception technology to detect the attackers performing reconnaissance. Finally, organizations should consider adopting sophisticated AI such as the virtual security analyst that can serve to automate the cumbersome task of investigating the many threats and really help with the objective for Security Operations team to achieve that peak efficiency and with the ability to scale even further. To keep up with the evolving threat landscape, organizations must grow beyond securing against known threats by blocking zero-day threats and then later progressing through the other kill chain stages as a result of threat investigation. A zero-day threat is a piece of malware that embeds an exploit designed to bypass underlying security controls, increasing the success of that particular attack. An example of a sophisticated ransomware with its ability to self-propagate throughout the network would be WannaCry. At least that's something that comes to my mind. It really gained its infamy due to the ability to infect entire networks by exploiting a Microsoft SMB vulnerability and was able to cripple quite a number of businesses. Worse yet, there are many variants created subsequently, including the NotPetya variant and other forms of malware. This led to the challenge for most security operations to investigate those volumes of threat alerts that has traditionally been manual and time-consuming, especially when looking for patient zero and other infected systems for mitigation. To solve these challenges, we'll take a look at these breach protection technology use cases. To block zero-day threats delivered to organizations, sandboxing is a critical component of their defenses. FortiSandbox is designed to analyze and assess for zero-day threats and generate indicators of compromise in order to reduce risk by sharing the latest zero-day threat intelligence with existing security controls to protect against known threats. A security analyst is instrumental in investigating the delivery of those types of threats, and then throughout the different stages found in kill chain, ending with the actions on objectives. Due to the shortage of experienced staff seen in many organizations, FortiAI, with its deep learning, can help supplement security operations with a virtual security analyst to dynamically classify the malware and its life cycle, including the identification of patient zero. Now, this greatly benefits security operations with increased efficiency of the threat, lifecycle response, and solving the operation skill issue. All of these solutions can be applied to an OT environment, as FortiAI and FortiSandbox passively monitor for targeted attacks aimed at ICS and SCADA systems, thereby reducing the risk of OT-based threats. Our AI-driven breach protection solution, consisting of FortiSandbox and FortiAI, will help transform an organization's security posture by providing them powerful security that takes security ops to the next level of their maturity through the use of AI-powered security technologies that enables them to secure business continuity against sophisticated, evolving malware. While implementing powerful security is an important endeavor, that security needs to be applied to both IT and OT segments for a holistic approach to defense, and this helps security ops close off any gaps and secure the dynamic attack surface. Lastly, organizations can reap the benefits of SOC automation through the integration of our breach protection solution with any existing security controls via the Fortinet's Security Fabric. This provides security operations the ability to scale and increase SOC efficiency without increasing budgets. With that, let me turn it over to Jack and Brian. Hi, guys. This is Jack from the Fortinet Product Management team. I'm representing Brian today also, our FortiSandbox PM, and I'm going to present both FortiSandbox and FortiAI to you. Let me start with FortiSandbox. FortiSandbox is a well-proven technology for almost a decade now designed to detect zero day exploits-driven attacks. What makes FortiSandbox unique is its ability to analyze both IT and OT targeted malware in a safe virtual environment. In that virtual environment, it mimics the endpoint desktop and simulates OT services to discover the true intentions of objects. For example, a Word document that has the ability to download Trojan or ransomware, a PDF opening a port to communicate with Modbus. The result of analysis are put together in a comprehensive report that includes the indicator of compromise, the IoCs, and MITRE ATT&CK mapping. Also, FortiSandbox has machine learning. Two, in fact. One is to build in static analysis, and the other in the dynamic analysis to accelerate the discovery of unknown malware and improve detection. Lastly, the real secret of FortiSandbox lies in its ability to share zero day threat intelligence in real-time with a few things. First, the FortiGate to block these threats in the network and any lateral movement as part of the threat response. Other and third party security solutions to enforce zero-day threat protection for email, endpoint, applications, and many more. Sandbox community to share benefits from threats found by other Sandbox devices as well. Because of its proven zero day detection capability, wide array of features, and broad integration, Sandbox has been helping to automate breach protection across the entire attack surface. Now, let me step into FortiAI. Here are some infographics to show the strength of FortiAI. With a high detection rate, Fortinet can detect threats and provide verdict in sub-second. It's suitable for high-performance demanding environments such as ISP, big enterprises, managed service provider, where you need line-rate throughput, where FortiAI VSA, the Virtual Security Analyst, is trained in the cloud and is exposed to 200 billion+ features, and we take the highest quality, around six million features, into the on-prem hardware and VM solution. One of the biggest differentiator of FortiAI is the use of artificial neural networks, so that it does not require to run the file itself for malware discovery. Instead, it breaks the file down into thousands of features to go through the neural networks for analysis and provide the verdict. Virtual Security Analyst itself can link and correlate infections and find the root cause of infection, such as worm-based attacks, and looks for malware outbreak as well as its variants. Combined with on-prem learning, where FortiAI will learn from customers' traffic, the goal here is to reduce the false positive and increase detect rate further. It can identify what we call an attack scenario, where FortiAI, based on the feature analysis, will reveal the true intention of the malware, whether this is an info-stealing Trojan, banking Trojan, coin miner, ransomware, and so forth. Basically, this is your personal malware analyst. In terms of fabric integration, FortiAI will integrate with FortiGate for submissions. It has fixed and JSON output and also support third-party ICAP clients. Also the latest, we've added a FortiSOAR connector, where you can submit files to FortiAI from FortiSOAR. Let me share with you what's coming in the year for 2021 for both FortiSandbox and FortiAI. What you see in the gray boxes are the existing features or coverage for the products. The aqua color boxes are what's coming in 2021. Like all roadmaps, disclaimer applies here. Roadmaps do change and prioritize often, it will be good for everyone to understand the AI-driven ops direction for today. Let's take a look with FortiSandbox first. While FortiSandbox is designed to identify zero day with static and dynamic analysis, the sandbox teams plans to introduce code emulation to emulate executable files behavior. This will be done after the pre-scan at the same time with the VM execution. Adaptive scan with FortiSandbox is about dynamically allocating resources, like Windows VM and Office instances, to adapt the file types to be scanned. For example, you might have more office files at a particular time, so you don't need as much Windows VM. FortiSandbox will dynamically adjust the clones and resources to scan, hence making it more efficient. With FortiAI, the main focus for this year will be on network traffic analysis. Some people call this network behavior analytics, which is to identify anomalies traditionally next-gen firewall or IPS alone cannot pick up. This puts FortiAI in par with other vendors like Darktrace or Vectra AI. Network traffic analysis, NTA, will be released as a function under virtual security analyst around Q2, Q3. Basically, your virtual security analyst will help you identify the anomalies. In terms of broad coverage, the two solutions already cover a wide range of vertical, such as OT, MSP, government, et cetera, and FortiAI will have plans to move to public cloud space starting with AWS. The last piece of the roadmap on the right-hand side is the fabric integration. This has always been the strength with Fortinet, allowing more customers to enjoy automation and integration within our own solution. One area is the FortiSandbox custom management. We are discussing FortiAI and FortiSandbox integration as well, taking leverage in the strength of both, and the traditional logging and SIEM integration with FortiAI. More excitingly, we are looking also to do FortiGate and FortiAI inline blocking to utilize the speed and the sub-second detection with FortiAI. Now let's take a look at some of the ordering guide. This guide on the screen here, you can see the different offerings and main features. There are two main offerings for FortiSandbox, which is cloud-based. That is SaaS, PaaS, public and private cloud, and also the CapEx. Each offering will have different capabilities, the easiest way to buy is based on the number of files. We refer to this as the file throughput, which range from hundreds to several thousands. In any case, you may not have a way to calculate or estimate your files throughput, and you can buy based on number of users. Lastly, if you need more capacity, FortiSandbox natively support clustering up to 100 FortiSandbox node, which means two nodes will have double the capacity and 10 nodes will be 10 times. This guide will be published very soon. With FortiAI, the ordering is actually much more simpler. The easiest way to buy, similar to Sandbox, is based on files per hour, and you have to decide whether you're choosing a hardware or VM. With hardware offering, we have the FortiAI 3500F with the GPU. The GPU pretty much work like ASICs on FortiGate and makes the file scanning much faster with the neural networks acceleration, and VMs are roughly 25% of the hardware power. You would also like to ask yourself what fabric integrations require. As we mentioned before, FortiSandbox is a very mature product with lots of fabric product integration. At the moment, FortiAI is catching up in this space with the FortiGate file submission via OFTP, FortiWeb via ICAP, and also FortiMail, et cetera, are also in pending in the pipeline. What if my customer is MSSP? FortiAI has been designed with the MSP in mind. When you look at logs, reports, et cetera, you can actually filter on the VDOM devices, et cetera, which is key for MSP. If you're thinking about ordering FortiAI hardware with the GPUs, think about whether you need the extra SSDs. As I've shown the product picture here, you can add multiple SSDs to mainly increase the log retention. Lastly, let me touch on the different FortiGuard services, the flexible offering, and the assistance from our solutions. A range of services to ensure the success in the products. First, everyone understand FortiGuard provide the dynamic updates, the signatures, the lookups, the neural networks updates, so that we keep the security updates at our pace and let the customers focus on their main goals. Of course, all the FortiGuard blogs on the malware research, like the latest SolarWinds attack, for example. In the middle here, we've got security on demand. Basically, we've talked about the different flexible offering that FortiSandbox offer, whether you want as a cloud service for lower-end FortiGates, or whether you want to have a dedicated VM environment of your own, we call it platform as a service, or different public cloud or private cloud installments. Of course, the reliable assistant from our tech centers, from our partners and Fortinet professional services. You will see actually more RMA options, for both of the products. Lastly, on the resources, apart from what you can find on our website, the demo centers, white papers, et cetera. We've touched on some of the release schedule here. Timing might change, but we're roughly looking at FortiSandbox version 4 to be released around Q2 2021. FortiAI with two versions this year, with 1.5 planning at around March, April time. The NTA, the big sort of thing, next thing coming out for FortiAI will be around Q2 and Q3 2021. Don't forget, if you log on the partner website, you have a range of partner resources to help you with both solutions. Now let me hand over back to Damien to talk about the customer success stories. Thank you, Jack. Let's take a look at the customer and third-party testimonials associated with these solutions. For the first customer success story related to FortiAI, let's take a look at the Identity and Citizenship Authority, which is a federal entity that provides identity services for their large population, and they are tasked with centrally authenticating these different IDs, if you will, with the various government services provided. For example, validating the ID of an air traveler during the purchase of an air ticket or when they are boarding a plane. For private businesses, such as authorizing of bank transactions. This particular customer embarked on a project to protect their networks and services against state-sponsored attacks, as well as looking for a suitable security solution for the air gap environment that they are building. In the first use case, this involves that notion of self-defending networks and web services, and it can be achieved with FortiAI's ability to apply self-learning to sub-second threat response for sophisticated and continuously evolving threats. With the FortiAI self-learning ability, they're able to leverage a security solution that continuously evolve as it inspects for threats in their private internal networks that is completely air gap. In terms of deployment, FortiAI specifically was integrated with FortiGate and FortiWeb through the ICAP protocol. Why did they choose Fortinet? FortiAI's detection investigation response performance, they were able to leverage that to save on CapEx spending on adding more malware detection capacity on their existing solution, as well as realizing savings on the OpEx side in terms of hiring even more staff, if you will, to manage that ever-growing solution. Due to FortiAI's sub-second analysis, FortiAI was able to whip through the large volume of uploaded materials even faster, and this led to the increase in customer satisfaction score for the ID services that they provided. Lastly, as a government entity, they are subjected to different audits and to ensure they meet all these different regulations for what they provide. FortiAI not only meets but exceeds, right, all these different requirements, thus they are assured on the cybersecurity business impact and penalties. For FortiSandbox customers, many are adamant with the various benefits it brings to the use cases, such as complementing it with the next generation firewalls or secure email gateways, as seen in this particular Gartner insight example. This and many more can be found at the Gartner Peer Insights page that collects FortiSandbox reviews by various industry peers. There are a number of published customer case studies available on fortinet.com, including the example here as a quote from National Benefit Services that simply state the fact that FortiSandbox efficacy by catching 16 unknown malware the moment it was deployed. Furthermore, FortiSandbox efficacy and TCO are affirmed by reputable third-party test vendors such as NSS Labs that recommends FortiSandbox in the breach detection test and separately in the breach prevention test. Lastly, ICSA Labs, the testing arm of Verizon, enjoins NSS Labs with the certification of FortiSandbox in its Advanced Threat Detection Test. On a side note, FortiAI capabilities are unique in the market today, and we are actively exploring a collaboration with third-party test vendors, stay tuned. With that, let me provide a quick recap and next steps. Fortinet is driving towards a breach protection solution that provides powerful security by enhancing malware detection engines with machine learning and improving it further with new emulation engine that improves efficacy even further, and improved ransomware detection and adaptive scan to push that performance of sandboxing much higher. Also deep learning is the key for the future of cybersecurity. By applying it in the form of a Virtual Security Analyst found in FortiAI, it has the ability to investigate threats like their human counterparts, but in sub-second. Expanding those deep learning capabilities further is to investigate anomalies found in the network covered, such as the network traffic analysis functionality. All of these improvements elevate an organization's existing security posture and reduces the business disruption due to the sophistication, scale, and volume of threats. Besides that, our breach protection solution can be applied to the IT segment of an organization to protect attacks aimed at Windows, Mac, Linux, and Android devices. Also in the OT segment, including ICS, SCADA, used in verticals such as manufacturing and utilities. Besides the devices themselves, our solution supports a multitude of applications such as Office, PDF, HTML, Java, and many more, including services such as SMB as well. All of this helps security operations close off the gaps with the comprehensive coverage of the dynamic attack surface. Lastly, our breach protection solution enables an organization to build automated defenses with Security Fabric. This is highlighted with the deeper interoperability with Fortinet's portfolio. Example, FortiSandbox native integration with FortiGate, FortiMail, FortiClient, or FortiAI's inline blocking with FortiGate, and also support of third-party security solutions through REST API, ICAP protocol support, and STIX. All of this combined really helps with automating that threat protection, thereby driving better efficiencies within the SOC processes and allows security operations to scale even further. For the next steps, I encourage you to take a look at the FortiSandbox or FortiAI on fortinet.com where you'll find data sheet and other pertinent information regarding these different solutions. If you'd like to sign up for training, you can do so via the NSE training, where we offer a number of modules from the NSE 2 to level 7 covering these different topics. You could also participate in an upcoming Fast Track session on FortiSandbox, where you have the opportunity to speak to an expert and experience a hands-on training. Keep in mind, FortiAI is coming really soon to Fast Track. Lastly, if you are interested in the other technologies I mentioned earlier, including deception, to evolve your security operations, feel free to attend the session highlighted. With that, I'd like to thank you for your time and hope you found this session helpful. Cheers. Hi, everyone. Thank you for joining us today. This session is around how you can rapidly respond with FortiSOAR. I'm Max Zeumer from the product marketing team, and today I'm joined by Ling Lu, the vice president of the product management team. I'm sure that throughout sessions you've seen this in one way or another. Before we dig in, I just would like to touch on the Fortinet Security Fabric and how it provides visibility and protection to better manage risk while being integrated with our single Fabric Management Center. Our focus now is automation, which is leveraging our AI-driven security pillar for fast and efficient operations. This is the pillar that FortiSOAR falls under and supports the extended efforts. FortiSOAR has done extremely well in supporting mature SOC teams to rapidly respond while optimizing their SOC as being part of the fabric that differentiates us from SOAR-only solutions on the market. With our agenda, it's pretty straightforward. We're going to discuss, me personally, walk you through some of the cybersecurity challenges and solutions and a little bit of an intro to FortiSOAR. Then Ling is going to dive into further detail on the product, its innovations, and what's new. From there, I'm going to touch into some customer stories and summarize a little bit of what we discussed about today. According to Gartner, SOCs are now ever-increasing numbers, shifting investments, resources, and time from threat prevention to threat detection and proactive response. They also state organizations are dealing with increasingly aggressive threats where rapid response, only minutes at best, is required. This forces organizations to reduce the time to respond, typically by delegating more tasks to machines. What are the complexities that some of you might be very familiar with that are causing organizations and SOCs to shift to a proactive response and to delegate more tasks to machines? The first one starts with too many vendors, and this is because a lot of products do not coordinate or integrate well with each other, and that creates this difficulty because it adds further context switching during, for example, an investigation or just to identify what tasks an analyst has to complete on that given day, ultimately reducing the visibility and creating a fragmented scenario. What further ties to this shift is the overwhelming amount of alerts that are coming in and how you deal with them. This directly develops alert fatigue. We know they're time-consuming, and it creates opportunity to further miss alerts that might have had that common link and other developments. In particular, when you're trying to identify the severity of an alert and how critical it might be or not critical it might be, creating an additional posed risk of missing a key alert. The next complexity that helps push these SOCs to shift to this research that Gartner has done are the fact is, there are too many manual and slow response processes, and these repetitive and manual actions across those siloed tools takes too much precious analyst time, and sometimes it can take days to understand incidents and investigate threats which impede and slow down your overall response, adding to the time and length of investigation, as well as the amount of time you spend sifting through those endless alerts at the start of a potential investigation. This last complexity, the cybersecurity talent shortage. When you compound or blend the first three complexities we just discussed, teams are often understaffed with an enormous task to face, turning a challenging situation to a more difficult one when you've maxed out the working capacity of the talent you currently have. These are the factors that are contributing to these shifts of resources and focuses that Gartner is stating. We want to, at Fortinet, simplify your security operations by helping you choose an offering aligned to your SOC maturity. Fortinet offers a range of components that improve the operational efficiency of security teams of all sizes and maturity levels with four unique yet integrated offerings. It starts with the Fortinet Security Fabric customers, who are all encouraged to establish their foundation with FortiAnalyzer, analytics, and automation. Building on that foundation in this framework, as organizations have this continuous concern about the cyber threat landscape and have limited security staff, as we previously discussed, skills and processes are also impacted in this. FortiXDR enables this automated incident detection, investigation, response across the security fabric as well. As an organization or a team might become slightly more mature, for organizations who have perhaps a more diverse security environment, FortiSIEM adds this multi-vendor visibility and analytics. Then at the peak of that is FortiSOAR. While organizations with mature SOCs, sizable security stacks, and well-defined security processes can utilize FortiSOAR to rapidly respond while improving efficiencies with advanced orchestration and automation across their multi-vendor environments, they're enabled and at the peak of our framework. This is truly designed to help customers, as we mentioned, at each stage of their maturity, identify what product is ideal for them at the current stage they're within. With that, we want to point out some of the key fundamental focus areas, in particular for 2021, that FortiSOAR has, and it starts first with the rapid response. We enable organizations to accelerate their response and coordination through comprehensive case management, orchestration, automation, and cross-collaboration, which supports teams that need a force multiplier, which is critical. The second key focus that we have is SOC automation. Over the last year, we have structured the products I just discussed in our portfolio to meet SOC teams at every level of their maturity. FortiSOAR serving as the peak of that framework, meeting enterprise teams that require full orchestration and automation of security processes across multi-vendor environments. This is because FortiSOAR is an agnostic offering. Lastly, our last key focus area are cloud services. This is essentially to help streamline deployment, management, and onboarding with best practices. FortiSOAR in the cloud will enable enterprise customers who want to move their SOC from on-prem to the cloud, where enterprises would no longer have to worry about managing evolving infrastructures while supported by our best practice services, allowing for flexible deployments and seamless configuration. These best practice services are going to be our FortiSOAR experts that are going to really help jumpstart that configuration as you deploy. I want to take a moment to touch on fundamental use cases that FortiSOAR has. When you take a look at the unified incident management use case, it's designed to streamline and centralize visibility and control, which battles that product fragmentation SOC teams faced, which we discussed earlier, enabling teams to utilize existing security tools and increase their efficiency. The second use case is alert triage automation. Through FortiSOAR, alerts are automatically prioritized, assigned, correlated with other alerts while providing recommended actions to the analyst. This risk-driven prioritization allows teams to focus on the critical threats while removing false positives. Third use case would be SOC optimization. FortiSOAR provides jumpstart out-of-the-box use cases, out-of-the-box dashboards, and out-of-the-box reporting, but also retains flexibility and adaptation with all the above. This allows teams to quickly optimize their overall processes and identify key SOC metrics that enable them to implement automation, resulting in the reduction of manual processes. Lastly, our SOC collaboration use case. You can run a multifunction or distributed SOC with FortiSOAR's dynamic team workspace. This is extremely valuable for cross-collaboration amongst teams, even beyond the SOC. For example, real-time communications during a crisis management scenario is crucial, and FortiSOAR allows SOC teams and organizations to have communications with multiple departments such as legal, marketing, key executives, and this results in accelerating response coordination, which is incredibly valuable. Now I'm going to pass it over to Ling, who's going to dig further into the FortiSOAR product, its innovations and enhancements, and much more. Thanks, Max. Security teams are facing increasing challenges such as the skill shortage, manual processes, and disparate tools. SOC teams require multiple areas of expertise and are dealing with the multiple consoles such as the SIEM, sandboxes, threat intelligence systems, ticketing systems, and so on. The SOC team has too many alerts to monitor, alerts overloading, and these all lead to slow response and missed security incidents, increasing the chances of a security breach, and can have severe consequences and break your business. FortiSOAR helps coordinate, execute, and automate tasks for security operations, allowing the SOC team to respond quickly to cybersecurity attacks and to improve their overall security posture. Today, it is very successful in large SOC operations such as the banking, government, oil and gas industries. Let's take a look at the Fortinet SOAR solution as it stands today in three main areas. The first area is the rapid response. FortiSOAR today comes with built-in capabilities such as the alert incident management, ticket case management, and team collaboration. From managing alert triage, incident investigation, and escalation to remediation and response, all from a single unified console end-to-end. This makes life in the SOC so much easier and enables them to respond quickly to security incidents. This platform is designed to allow large security operations to eliminate alert fatigue and contact switching, and to optimize their processes to accelerate incident response. The second area is SOC automation. FortiSOAR today has more than 350 plus integrations with third-party vendors and over 3,000 playbook actions for security orchestration and automation. The out-of-box content packs provide the SOC team with the ready-to-use incident response playbooks. Playbooks can be customized to streamline complex SOC processes and build consistent incident response workflows to improve SOC productivity and efficiency. The third area is cloud services. FortiSOAR platform as the service today is only available from the public cloud. In version 7, more cloud service are coming that will be available from FortiCloud. The new FortiSOAR ordering guide makes ordering for sales partners and distributors much easier. The easiest way to buy FortiSOAR for on-premise deployment is through a VM subscription bundle. It comes with two editions, Enterprise edition for enterprise customers and the Multi-Tenancy edition designed for MSSP customers. The Multi-Tenancy edition has a couple of different deployment options. The VM subscription bundle is all in one bundle. It contains the product subscription license, plus FortiCare support and FortiCare best practice service. It comes with two users by default. User add-on license are available if you need to add more. Sizing license capacity for FortiSOAR is relatively straightforward. You size based on number of users. If a customer needs a cloud-based deployment, they should go with the FortiSOAR cloud option, which is coming in Q2 timeframe. FortiSOAR container on FortiAnalyzer, you need to buy the FortiSOAR Enterprise license. There are three key areas that we have been working on for the FortiSOAR seven release. First thing first, rapid incident response. FortiSOAR today comes with building capabilities such as alerts, incidents management, tickets, case management, and team collaboration. With the version 7, we have added the incident war room. This allows SOC to easily launch a collaborative space to deal with the critical incident or crisis. Various stakeholders and teams across the organization can be summoned together in a very short period of time for quick mitigation and containment. The war room can be set up with just a few clicks from the incident or alert view. It consists of sections such as incident contacts, investigation arena, and impact analysis. The info center holds hot links to various collaboration integrations like the conference bridge, the group chat, the wiki, and the hotline to responders. The FortiSOAR mobile app is available from FortiExplorer. This puts SOC in the palm of your hand, and team members can respond to alerts or incidents quickly when they are on the go. There are a quite number of new integrations with the Security Fabric such as FortiAI, FortiNAC, FortiSandbox, FortiGuard to allow rapid response from analyzing and identifying threats to quarantining devices for remediation within minutes. Upon detection, playbooks are set off to ask Fabric devices to take immediate action. I would say that this is one of the FortiSOAR differentiators. It can leverage Security Fabric for rapid response. If your customers have Security Fabric products, tell them about FortiSOAR right now. It is super powerful when you know how to leverage these products together. The second key area is SOC automation. SOAR is all about using orchestration and automation to streamline SOC processes and automate SOC tasks, freeing the SOC team from manual, repetitive, and mundane tasks. Let the machine handle the things it's good at, and let humans focus on more cognitive tasks such as the threat hunting and forensic analysis. Today, FortiSOAR has various incident response playbooks to handle different SOC use cases. 350+ connectors to third-party products, out-of-box content packs that contain various playbooks, the best practices, and use cases for a SOC to jumpstart. With the 7, FortiSOAR is now available as a container on FortiAnalyzer. Anyone who has FortiAnalyzer can download the FortiSOAR app from Fortinet Cloud and have it running on FortiAnalyzer, all with the simple click. This automates the install and deployment process and seamlessly integrates with the FortiAnalyzer out-of-box content packs and playbooks available for SOC to use. Note that FortiAnalyzer VM or FortiAnalyzer high-end appliance 3000 series and above are required to support FortiSOAR container. For Security Fabric customers who are looking to establish a SOC or accelerate their existing SOC maturity, this is the most cost-effective way to go. The AI-based recommendation engine is available from version 7, pushing intelligent automation to the next level. AI machine learning is leveraged for smart suggestions of alert severity, threat type based on pattern similarities, and also learning from past human analyst triage results. False positive alerts can be automatically identified and then closed, so human analysts won't waste time looking at them. Another thing we've added is the connector wizard to automate the connector creation process. A customer can quickly build their own custom connectors within minutes and then publish it across platforms. The third area is cloud services. We've seen growing demands for cloud-hosted FortiSOAR. Today, we can set up FortiSOAR in AWS, and with version 7, FortiSOAR cloud is available for our customers. You can easily spin up a FortiSOAR instance in FortiCloud. The FortiGuard Outbreak Alert service is also available for customers FortiSOAR deployed on premise. This service makes all resources such as playbooks and threat intel available to protect customers against malware and against outbreak situation such as the recent Sunburst outbreak, the SolarWinds, helping customers to detect and also hunt the threat. To make things even easier for the SOC team, we now have FortiCare best practices service available for FortiSOAR. You don't have to figure out things yourself, no matter if you have a new deployment or are upgrading existing systems. This annual subscription service will have Fortinet experts available for consultation to ensure your deployment or upgrade is successful. Finally, I would like to mention there are resources available on FNDN Virtual Tech Expo. FortiOS 7 will be GA'd at the end of Q1, FortiAnalyzer 7 and FortiSOAR 7 will come a few weeks later in April. That's all from me today. Max, back to you. Thank you, Ling. FortiSOAR's had an amazing year, but how and who are driving that? I'd like to take a moment to walk you through some brief validation in customer success that highlights what is driving FortiSOAR. I'd like to quickly touch on that FortiSOAR has repeatedly been in Gartner's SOAR Market Guide as a vendor, including the most recent release supporting the validation of the product as it aligns with the convergence of three critical technologies that produce SOAR. Furthermore, I'd like to highlight a customer success story about an organization named Secure Cyber Defense, that's an MSSP that leveraged FortiSOAR, not only to remedy the complexities we've discussed earlier, but actually to expand and increase their business and revenue streams. Their challenges started off with battling alert fatigue. They wanted to enhance their threat response efficiencies. Another big one was that the cybersecurity skills shortage had an impact. They had a lot of very senior-level talented analysts that were bogged down with repetitive L1 analyst tasks that could be more focused on critical initiatives. Their goals were to increase productivity and effectiveness of their SOC team. Also to have a differentiator from their competitors within the MSSP space and expand revenue streams. What they were able to do was accelerate post-implementation of FortiSOAR, their response to perceived threats from 45 minutes manually to two minutes in some cases. What's also really unique is that they were able to develop a new seven-figure revenue stream. This is dedicated because FortiSOAR, in combination with FortiSIEM and FortiEDR, enabled Secure Cyber Defense to pursue this new business opportunity that would have not been possible if the firm had still been reliant on manual investigations. Now that they're no longer reliant on those manual processes, they are providing a managed detection and response, MDR, also known as service, and processing and responding to security events. All told, FortiSOAR has created this new seven-figure revenue stream for the firm as a result of implementing it. In addition to that, when we take a look at their SOC efficiencies, they were able to implement the FortiSOAR case management functionalities to seamlessly replace their ticketing system in just one day. Lastly, they created a new FortiSOAR use case where they used automation beyond just investigation purposes, which is a differentiator for the product, to track the national power grid and weather services to identify if there is a breach or power outage in one of their customer locations. This became a phenomenal customer success story because they were able to remedy the issues they were battling on the SOC side, but also expand their overall portfolio and business to the implementation of FortiSOAR and additional fabric products that I mentioned earlier. If you'd like to read the full case study, I've provided a link here where you can really read the entire story, and it's quite an incredible success story that they had that triggered with FortiSOAR. I'd like to take a moment to highlight some of the three key takeaways and recap the enhancements and innovations and some of the information Ling had discussed with FortiSOAR 7.0 in particular. The three key takeaways. First, start with rapid response. When we take a look at this, these enhancements, in particular, a big takeaway is an instant response war room. Which is also supported by the mobile app. What this does is it increases overall efficiency by enabling teams to have faster coordination between their departments in a crisis management scenario, for example, and expand operational visibility through the mobile application by having the SOC in the palm of their hand. The next or second key takeaway from what we discussed earlier is SOC automation. You've heard Ling highlight when touching on our enhancement details, the FortiSOAR FAZ container. This not only provides a trial experience to users, but it can accelerate the maturity of these users. When you combine that, as a big takeaway, and then you combine that with our jumpstart content packs that provide out-of-the-box use cases, it will enable these lower-level maturity SOCs to accelerate much faster, because not only they'll have the full capabilities of FortiSOAR within their environment, but then they can add the jumpstart content packs with those out-of-the-box use cases to their environment and quickly get that going. Lastly, our cloud services as our third key takeaway, the FortiSOAR cloud. This really is designed to simplify deployment, reduce the management complexities, and when you add in our best practice services, what you get is our FortiSOAR experts that will support all the overall configuration and apply their expertise and knowledge during these configurations so you can quickly get started. This is really critical for teams that want to move from on-prem to the cloud. That is our last takeaway from what was discussed earlier. I'd like to take you through some next steps and resources, depending where you are at in your journey with FortiSOAR. The first thing I recommend is going to our webpage. On our webpage, you will find our free trial, which is our FortiSOAR Community Edition. You'll be able to see how it works to its fullest capacity and implement some of the efficiencies, and see how it can help your team rapidly respond, and really get in there and play around with the product to further your understanding. I also recommend, as Ling mentioned earlier, to take a stop at our virtual expo. Under our AI-driven security operations, you will find an incident response section, that's going to detail a lot of new information and deeper dives into FortiSOAR and what's to come in FortiSOAR that will be of great benefit for your understanding on where the product is going. Lastly, for resources. I've listed out our resources that are available on our website, where you can find everything from data sheets, e-books, solution guides, case studies, multiple webinars, and our Fuse community where we share best practices amongst customers and our FortiSOAR experts, which is extremely valuable. I hope you've enjoyed today's session, and thank you again for joining us, and we look forward to you taking a deeper dive into FortiSOAR. Take care. Hello and welcome. I'm Jon Speer, Director of Product Marketing. My co-presenter today is Dan Hanman, the Director of Product Management. Thanks for joining our session, Applying Advanced Threat Analytics for Earlier Threat Detection. This is a session focused primarily on FortiSIEM, and if you're confused by that, then you're in exactly the right place. It's time to expand your understanding of what a SIEM can be and must be to get in front of today's threat environment. I'll spend a few minutes level-setting on the customer pain points that we consistently see and focus our solutions on. Dan will then give a quick introduction to FortiSIEM and announce some exciting new features and capabilities that you'll find in the latest release. Then I'll wrap up with some real-world validation and leave you with some key takeaways. Before I move into the challenges that FortiSIEM focuses on, let's also take a moment to recognize the unfair advantage that FortiSIEM has if you're already a Fortinet customer. The Fortinet Security Fabric creates a SOC foundation that is so much more powerful than anything else available in the market. It's broader with more products, more integrated within the Fabric Management Center and security operations, more automated with more workflows across all elements. More fabric-ready partners have joined the ecosystem. Fortinet's Open Fabric ecosystem is a community of leading technology vendors and threat-sharing organizations that are committed to delivering complementary solutions for stronger security posture and protection to customers. It's one of the most extensive cybersecurity ecosystems in the industry, with over 400 technology integrations that are pre-validated, documented, and faster to deploy. Customers gain a wide range of scalable and secure complementary ecosystem solutions for visibility and protection of their entire digital infrastructure. Organizations face many security challenges. Across almost all organizations, whether based on size or vertical, these tend to be common to them all. Threats can be many and varied, looking for that single chink in the armor to compromise a system with the threat coming from phishing emails, vulnerable systems, misconfigurations, or lack of risk management. The external threat continues to evolve, and we must be positioned to detect these evolving threats and the ability to collect information from multiple vendors and use that data to identify threats quickly and effectively. The inverse to external is the internal threats, which have been some of the most high-profile compromises in the last decade. The challenge of detecting insider threats is that users typically have been granted broad access to resources, allowing for large amounts of data to be accumulated and moved to nefarious actors. How can we detect this anomalous activity by a negligent user or malevolent actor? Visibility is a broad challenge, but every organization should understand what assets they have, whether they are in service, whether there is performance issues, and of course, any security incident affecting the asset, service, or organization. Sounds simple enough, getting this state of visibility is often not trivial, and until understood, the management of organizational risk will remain a challenge. Lastly, compliance. With penalties, reputational damage, or in the inability to process transactions, compliance to a framework is common to organizations. Whether or not compliance is the main driver for a SIEM, using a compliance framework or good practice will help focus an organization's cybersecurity maturity. Applying the appropriate people, products, processes to conquer these challenges has immense value to most organizations. Keeping up with digital transformation can be really challenging for a SOC, and it's easy to end up with blind spots as parts of the business move forward without enough consideration for how the security team can monitor. One option is to try and slow down the business. Of course, the better option is to leverage technology to help you keep up. You will never have enough talented analysts, perfectly documented processes, or time to manually mitigate every incident and keep track of who did what and when. Leveraging technology to risk prioritize what gets worked on next, optimize investigations, and provide preset remediation actions is critical to scaling a small team to accomplish big things. Likewise, the ability to easily scale out is critical, whether it's adding more locations, a bigger team working investigations in parallel, or giving more horsepower to just crunching through higher event loads. The SOC must keep up with the business and go where the business goes. SIEM use cases have been pretty consistent over time. They tend to be a little different in focus depending on the size of the organization, the type and level of regulatory compliance they're under, and the maturity of the SOC capabilities. Like many areas of technology, what was once reserved only for the large, highly funded, or highly regulated eventually become achievable by smaller teams with smaller budgets. Advanced threat detection is one of those areas that was shifting towards mainstream SIEM anyway, but got a pretty big boost recently from the SolarWinds situation. Teams that previously focused on how to best stay on top of alerts and work cases quickly are now also looking for ways to recognize more advanced threats, such as watching for known indicators of activity earlier in the attack chain. Insider risk has always been a concern for security ops teams, but previous to the last couple of years, has for many seemed like a threat that they just couldn't afford to take on. As compliance and risk management teams have responded to ramped up regulatory expectations for a more comprehensive insider risk management program, combined with the widespread availability of machine learning for behavioral analytics, this has now become a relatively lightweight add-on in terms of overhead load to the team, but a big payoff in terms of earlier detection. Visibility has long been a cornerstone of SIEM, being able to monitor the infrastructure, see what you have, and overlay events. Of course, FortiSIEM's approach has always been to go significantly further in this area than the rest of the market, from discovery to configuration management, risk scoring, extending to the cloud, even monitoring remote worker endpoints. Finally, optimized response is a fundamental use case for SIEM. The notion that the SOC can work much faster with a deployed SIEM than it would if, for instance, they just had a log aggregator product and a bunch of security point products. Every part of the job should be enhanced, and they should be able to handle a much larger workload. When asked for proof of compliance rather than becoming a project, the SIEM must do most of that work for them. FortiSIEM meets these challenges and use cases by accelerating threat detection with machine learning and other advanced analytics, delivering real-time visibility of even the most complex multi-vendor ecosystems, and always finding new ways to improve scale and operational efficiency for the architecture, the individual analysts, and the organization overall. Let's dig into the specifics with FortiSIEM's Head of Product Management, Dan Hanman. Thank you, Jon. Now let's take a deeper look at some of the product and feature updates coming in FortiSIEM version 6.2. Let's take a quick recap at some of the main solution components within FortiSIEM, though. First of all, FortiSIEM uses a correlation engine to detect incidents in near real time with over 1,300 rules out of the box, covering everything from security, of course, as well as change, but also performance and availability. It supports multiple different vendors. We have a user entity behavior and analytics capability, UEBA, to be able to profile user behavior and alert on anomalous activity. FortiSIEM also provides a NOC and SOC capability, expanding the visibility from just security-related events and incidents, but also allowing us to understand the devices within the environment by discovering those and collecting performance information. Finally, around compliance, there's over 1,200 reports out of the box, compliance reports, fully customizable, covering the common compliance frameworks. As Jon mentioned, some of the customer challenges we see, we have different solution components within FortiSIEM to meet those challenges. Looking at how we license FortiSIEM, it can either be purchased as a perpetual license, a subscription license as a term license, or an MSSP pay-as-you-go program. We can be deployed as either a virtual appliance or hardware appliance, where we have a collector appliance, which is the purpose of collecting events and monitoring devices. You have a mid-range appliance, which is a 2000F, or a higher-end appliance, which is a 3500G that provides the main FortiSIEM capabilities. When we're licensing FortiSIEM, it's really licensed on the number of devices. Some other aspects also come into this as well. Total number of events per second is one. If we are asking the question of our customers and organizations how many devices, how many workstations or endpoints are needed, we can ask another question about how many agents are needed. Why you would need an agent is if you're needing to collect a broader set of events, collecting events at a much higher event rate that you cannot achieve using an agentless protocol, or if you have file integrity monitoring requirements. The other question to ask is how many users need monitoring for UEBA. Once you understand the number of devices, number of agents, and number of UEBA, it's a very simple calculation to work out the service points. Once you have the service points, you can choose the correct FortiCare package and optionally choose the FortiGuard IoC package as well. It's pretty straightforward licensing. It's built off number of devices, whether or not you need agents, whether or not you need UEBA. Let's delve a little bit deeper into what's new in 6.2. First of all, around accelerated threat detection. Analytic platforms, and in particular SIEM, require two core fundamentals. One is the ability to scale to manage the demands of the organization or scale as an MSSP business grows. Two, be able to scale the correlation and detection engine as more events or logs are received, new use cases are identified and incorporated, or still simply be able to perform real-time correlation and alerting. Whilst these two seem to be table stakes for SIEM, not all platforms can provide this level of scalability. Whilst one of the fundamentals should be the ability to scale, really the value that a SIEM provides an organization is the ability to detect threats and help achieve compliance or reduce and manage risks where other controls may be lacking. A SIEM can provide organizations a great deal of value as part of their security strategy or simply a tactical solution to address a specific use case. Now that we understand we can scale to meet almost all demands, what have we done to improve detection? Well, I've already mentioned that we've got a UEBA capability within FortiSIEM, and that was added to the previous release at the end of last year. This incorporated core elements of FortiInsight, our pure-play UEBA platform, directly within FortiSIEM in two main areas. One is around the FortiInsight agent capabilities have now been embedded within the FortiSIEM agent, and this new UEBA capability on the agent creates events of user interactions between resources or files, and these events are then sent up to FortiSIEM's appliances. Within the FortiSIEM, we now have the FortiInsight machine learning module embedded. Now that we have the agent telemetry coming into FortiSIEM to build up a user model of what is normal, and then if we see anomalous activity, we're going to generate an alert. One ideal use case for this is around insider threat, a notoriously difficult adversary to detect. Not only can this new UEBA agent telemetry be used for machine learning, but also as part of the standard FortiSIEM capabilities, such as the correlation engine, reporting on user activity, or adding information to dashboards.In the 6.2 release, we've got some new UEBA dashboards as well. FortiSIEM's file integrity monitoring capabilities have been improved to help with compliance and change management, and also be able to pull in the files that are being monitored directly onto FortiSIEM so that you can do a comparison between what's changed. In this release, we've significantly increased the number of security rules within FortiSIEM. We've added around 500 new rules. I'll go over those in a bit more detail in a moment. Let's move on to real-time visibility and multi-vendor ecosystem. FortiSIEM is a little bit different to other SIEMs on the market, as it does provide this NOC and SOC capability. First and foremost, FortiSIEM is a SIEM, and it provides these two additional capabilities. The first is that it discovers the environment using standard operational protocols like SNMP or API integrations, so that we understand what the device is. Is it a FortiGate or is it a switch? What's the firmware of this device? What's the configuration? Let's start monitoring that configuration for any changes. Once that discovery is complete, FortiSIEM then monitors the device for performance, such as CPU, memory, interface utilization. This is quite unique when coupling it with security incidents and events. It provides a wider set of context to the analysts. We have also added a new integration with FortiGuard IOC service, allowing customers to perform lookups directly into this service and get more context on the IP addresses, domains, or URLs. Then move directly into the FortiGuard IOC service and perform additional investigations on their indicators. This is granted as part of the FortiSIEM IOC subscription. Efficiency is an important aspect within SIEM. We often call SIEM a force multiplier, as one of the key value propositions is to multiply the efficiency of a user or an analyst, and that requires a positive user experience and ensures that there is the necessary context available. One of those areas is around FortiSOAR, where there's an out-of-the-box integration between FortiSIEM and FortiSOAR available today. We'll be looking to do much deeper integration between those. If you are not already aware, FortiSIEM already has a remediation framework available to automate some of the more straightforward scenarios. In 6.2, we've added a lightweight workflow so that when an analyst needs to perform a remediation, there can be an approval step before that action is executed. As MSSPs are a growing customer base for FortiSIEM, some of their requests have also filtered down into this release, such as SAML for single sign-on, an important part of the user experience moving between an MSSP portal and into the FortiSIEM instance. We've also optimized areas around agent management, and the use of agents are becoming more significant in the deployment as we add more capabilities around file integrity monitoring, UEBA, and event collection. We've also added some new fabric content. This includes new dashboards for the likes of FortiEDR, FortiADC, Deceptor, the new incident dashboard as well. Now when you log into FortiSIEM, as long as you've integrated these devices, then you'll see these new dashboards ready to go with new rules and reports as well. In 6.2 release, we've extended our support for OT and IoT use cases. We've added new third-party integrations with OT vendors. We've added a new use case that allows organizations to model their infrastructure using the Purdue Model within FortiSIEM. Alert on activity such as traffic crossing multiple Purdue levels, and able to baseline communication between OT devices. This can be represented in dashboards and of course, within incidents. We'll have a new OT dashboard, and new events and incidents that will be triggering if we see suspicious activity. The MITRE ATT&CK Enterprise View provides organizations with an understanding of tactics and techniques adversaries are using. With the additional integration of this framework into FortiSIEM, it allows us to understand the rule coverage that the out-of-the-box FortiSIEM rules provide against the ATT&CK framework. Therefore, we can understand where we may need to improve coverage as well. In this release, we've added over 500 new rules to improve the coverage against the MITRE ATT&CK framework. These can easily be understood by going to the coverage view. In addition to understanding the rule coverage, you can also understand the incidents that are occurring and plotted those on the same framework, but now we can see what tactics and techniques are associated with those incidents. As we progress in the investigation, we can simply click on one of the incidents, and we'll understand all of the different types of techniques which are being used, be able to click on the techniques and go to the MITRE website directly, or bring up a summary of what that incident is, and able to quickly understand what the pattern was that detected that incident. We still have the ATT&CK view, we renamed this the MITRE ATT&CK Incident Explorer that allows us to see, on a per device basis, the incidents as they progress through the different tactics in the ATT&CK view. You can click on any of these bubbles to drill down into more information about the instance and down into the actual triggering events themselves. Where do you get more information about FortiSIEM? Please visit the Virtual Tech Expo, check out the Fuse community for FortiSIEM, and also the resources on the Fortinet website. Thanks, Dan. That's fantastic. Really exciting stuff. Now I'd like to share some market success, but first let's talk about the Gartner Magic Quadrant for SIEM. As many of you probably know, Gartner continues to update their Magic Quadrant for SIEM about once a year. This is the 2020 release here, which was based on the product as it existed mid-year 2019. They had many positive things to say, including recommending FortiSIEM for all Fortinet customers and a strong recommendation for MSSPs. Nonetheless, they did keep us in a niche quadrant. Two of the largest shifts in the SIEM market over the last couple of years have been the focus on UEBA and the shift towards SIEM as a service, really a hosted or SaaS version of products. Of course, fully managed SOC services as well. Among many other enhancements, as you just learned, FortiSIEM does now have fully embedded UEBA that we think is quite competitive with the rest of the market and was included in Gartner's survey for the upcoming 2021 SIEM MQ report. They have not been particularly generous regarding our decision to not provide a SaaS version of the product, and instead using some of the top MSSP partners in the world as our delivery partners. It's not entirely clear yet how the 2021 rankings will come out, but we're actually optimistic that they are recognizing FortiSIEM's many unique strengths and look forward to the new report. Of course, there are other reports in the market, and I'm excited to talk about one by the SIEM users themselves rather than just the analyst. Great example of one of these is the SIEM Data Quadrant report from SoftwareReviews. They are pretty selective about only showing those vendors that have enough customers that have come forward and take the survey. You can see that it's really just down to those that have quite a bit of product in the market, and others drop out. Obviously, LogPoint did a great job of rallying their install base to take the survey, which tend to be smaller European businesses. By their own calculations at SoftwareReviews, FortiSIEM came in second overall, with really no campaign that I'm aware of, just purely organic users coming forward. What really stood out for me as well in this report is that when they segmented the survey data, FortiSIEM jumped way to the top for large enterprise customers with a net promoter score of 76 and 100% planning to renew. It was interesting to see that these customers had almost no consideration of cost as well. They are completely focused on product features and capabilities. Okay, let's wrap up and remember what we covered. First, we've been investing heavily in threat detection on a couple of fronts simultaneously, expanding the behavioral analytics that can profile what is normal in your environment and alert when suspicious anomalies occur, leveraging what the information security community is sharing in terms of effective rules, correlation rules across whatever products they're using, making sure that all of them are available to use by FortiSIEM customers. Second, we are committed to the benefit and value that MITRE ATT&CK framework can deliver to FortiSIEM users. This latest release is a huge step forward in being able to leverage the framework to easily see what coverage you have and, of course, where you may not have coverage so that you can focus there. Fortinet is continuing to deepen the FortiSIEM integration with the Security Fabric and our Fabric partners with more powerful and specialized dashboards, API hooks, overall tighter integrations to ensure that FortiSIEM is the most powerful and flexible SOC interface into the Security Fabric. Finally, there are several new integrations designed to enhance user experiences. To give the analyst an enhanced experience by linking investigations that include Indicators of Compromise with the new FortiGuard IOC portal, where they can choose to drill in for more info, find out what related indicators they should keep an eye out for, even submit requests and questions directly to the FortiGuard threat researchers. For our service providers especially, taking advantage of existing single sign-on services so that they can provide their customers with a great segregated access to the FortiSIEM UI and make their introduction into FortiSIEM just that much easier and smoother experience. Well, thank you for attending our session, and we look forward to working with you in evaluating whether FortiSIEM is right for your environment or that of your customer. Thank you. Hello, welcome to this Accelerate breakout session focused on using deception technology to raise the bar for the attackers, forcing them to abandon their efforts in targeting your organization. My name is Damien Lim, part of the Fortinet product marketing team, focused on our breach protection solution and products. Joining me is Moshe, VP of Product Management, instrumental in driving success of FortiDeceptor. To provide context, FortiDeceptor in today's discussion is part of the breach protection solution that is under the AI-driven security operations and as part of the overall Security Fabric. In today's agenda, we will cover the cybersecurity challenges and solution approaches. One such approach involves the use of deception to defend against external and internal attackers. We'll then delve into the FortiDeceptor's unique features and the validation of the solution, then wrap it up with a recap and next steps. Without further ado, let's discuss how an organization can evolve their security to deal with the challenges that cyber attackers pose. Most organizations adopt a security framework such as NIST, MITRE ATT&CK or the MITRE Shield framework or Lockheed Martin Cyber Kill Chain to plan their information security strategy. In our example, we will leverage the seven stages found in the Cyber Kill Chain as a guide to our discussion. Foundationally, a security operations team should have a good baseline in securing all threat vectors or entry points against the delivery of known threats as a first stage. Move into adopting sandboxing as a method to protect against the delivery of unknown and zero-day attacks. In the next evolution of SecOps maturity is the adoption of deception technology to detect attackers performing reconnaissance. Finally, organizations should consider adopting sophisticated AI, such as the Virtual Security Analyst that can serve to automate the cumbersome task of investigating threats and its objectives. Security operations teams can achieve peak efficiency and can scale even further. To improve an organization's security posture beyond malware protection, a defensive strategy should revolve in identifying the threat actor and their tactics in the early stage of the attack, such as those involved in the reconnaissance activities. According to Verizon's Data Breach Investigations Report, the survey found two-thirds of the breaches can be attributed to the external threat actors, while the remaining one-third attributed to internal threat actors. The other challenge organizations face is the rising cost of mitigation. This is based on the success of a security incident or a breach, and thus is an important focus for many organizations to avoid that as much as possible by detecting and responding to these attacks at the earliest opportunity in the Kill Chain. To solve these challenges, one should consider deploying deception to disrupt the reconnaissance activities as seen in the first stage of the Kill Chain mentioned earlier. By leveraging FortiDeceptor, an organization can create a fabricated network of fake IT assets and high-value lures that facilitate the engagement with attackers through decoys that simulates real devices and applications with the intention to expose and then to respond to them. Furthermore, an organization can extend this fake network to the OT segment by recreating the OT network with fake OT devices that respond to these protocol commands. Lastly, by complementing deception with in-place SIEM and SOAR, organizations can enrich their security incident response by taking advantage of intelligence generated by FortiDeceptor to accelerate threat hunting and perform pinpoint orchestrated response to threats. FortiDeceptor is designed to deceive, expose, and eliminate external and internal threat actors. This provides security operations with powerful security that helps further improve their security posture through the use of deception technology that enables them to secure business continuity against threat actors and their tactics. Implementing powerful security is an important endeavor, that security needs to be applied to both IT and OT segments for a holistic approach to defense. This helps security operations close off any gaps and secure the dynamic attack surface. Lastly, organizations can reap the benefits of SOC automation through the integration of FortiDeceptor with existing security controls via Fortinet Security Fabric. This provides security ops the ability to scale and increase SOC efficiency without increasing budgets. With that, let me turn it over to Moshe. Thanks, Damien. In the next several slide, we will cover the FortiDeceptor technology and the new upcoming feature, and also the new ordering guide and knowledge resources to use. FortiDeceptor combine the notion of honeypot with threat analytics and threat mitigation into one solution. Specifically, FortiDeceptor create decoys to lure attackers and inspect their behavior to generate accurate threat intelligence to block both external and internal attacks before any significant damage occur. Fortinet is the first major security vendor to offer deception technology beside a handful of deception startup. The offering is available as a hardware appliance and a VM form factor. FortiDeceptor detect threats to asset that cannot provide their own telemetry, such IoT sensors, SCADA, and medical devices, and detect threats moving inside the network instead of detecting threats on egress and ingress traffic. FortiDeceptor provide visibility inside the network while focusing on targeted threat detection of APT-grade actors, and also APT malware missed by other security tools. Furthermore, FortiDeceptor is integrated with FortiGate and FortiNAC as part of the automated threat response process, and also FortiSIEM, FortiSOAR, and FortiAnalyzer for broader visibility. Now that we understand FortiDeceptor technology, let's focus on the product long-term roadmap. In the next 12 months, we will release three major version that will support our product vision and use cases. The deception decoy and lure are the bread and butter of the product, and we will expand our decoy and lure offering by adding more platform and IoT/OT decoys and more deception lures like Active Directory and decoy files. In parallel to our decoy and lure expansion, we will also improve the decoy and lure authenticity by allowing features like MAC address changing, domain decoys, and ensuring correlation between the deception lures and the Active Directory environment. Deception technology generate threat intelligence and attack attribution information to improve response effectiveness. FortiDeceptor will leverage FortiSandbox and FortiAI to run more in-depth malware analysis to enrich the threat intelligence IoCs. Beside the threat intelligence creation, FortiDeceptor will share the IoC across the Fortinet Fabric and third-party security tools using the market standard like STIX and TAXII. As part of our OT offering, we will release a rogue appliance with more features specifically for the OT environment. The Fortinet Security Fabric is designed to simplify the management of organization entire security architecture. FortiDeceptor is already part of the fabric by integrating with FortiGate and FortiNAC for threat response isolation and FortiSIEM, FortiSOAR, and FortiAnalyzer for broader visibility. FortiDeceptor will expand the fabric integration, focusing on FortiGate as part of the network topology map and FortiSIEM with credential theft protection module. We will improve the scalability over large distributed network and also will provide richer context and more useful telemetry to improve the SOC threat hunting capabilities. FortiDeceptor version 3.3 is a major release, and the GA version will be released at the end of March 2021. As you can see, we expand the decoy and lure section dramatically by adding five new decoys and several deception lures. The new SCADA decoy will protect against OT attack, and the new ERP decoy will protect against sensitive data exfiltration attacks. The new point-of-sale decoy will protect against financial data exfiltration and theft attacks. Under medical decoys, we will offer two different decoys, PACS system decoy and infusion pump device decoy, to protect against medical record exfiltration and medical devices attacks. The Git decoy will protect against supply chain attacks like the SolarWinds one. To increase the decoy authenticity, we also add a feature that allow modifying the decoy MAC address. In addition, we add new deception lures such cached credentials and fake network connection lure that protect from password dump attacks and detect attacker early in the Kill Chain. We add a new set of IPS signature against SCADA attacks to expand our OT solution offering. In the Fabric Integration section, we add another FortiGate integration where FortiDeceptor will be part of the topology map feature. FortiGate admin will have the option to see FortiDeceptor appliance status and the decoys that are up and running in real time. We also expand the tight integration between FortiDeceptor and FortiSOAR by adding more playbooks, and also increase the integration level between FortiDeceptor and FortiSIEM as part of our SOC efficiency use case. The new central management as a single console will allow us to manage and deploy remote FortiDeceptor appliances, get their alerts, and provide alert analysis from a single console. We also improve the software license activation by moving to a new protocol over SSL and improve the safe list features to add more flexibility for the whitelist capabilities. Now, let's move to the ordering guide. FortiDeceptor license in Q1 will have no changes. FortiDeceptor license in Q2 will have a minor change regarding the new decoys. The new decoys, ERP, POS, PACS, and Git, will be under the current SSL VPN SKU. In mid-Q3 2021, we will change the entire FortiDeceptor license model. The new license will be a subscription bundle based on the number of network VLANs the customer is willing to cover. Of course, FortiCare ARE and all the deception modules will be included in the bundle. FortiDeceptor ARE technology and the FDS engine are unique in the deception market. FortiDeceptor is the only deception technology with IPS, AV, web filter that monitors the threat activity at the decoy level. Unlike other deception tools, our IPS engine provides more context to the attack by identifying the network attacks itself, like exploit name, instead of presenting an alert with just a decoy network connection description. Important to add that our IPS engine also contains SCADA signature as part of our deception OT capabilities. Another unique capability is the web filter engine that analyzes the traffic from the decoy to the internet to detect and analyze any vector and command and control connection that the threat actor and malware use while compromising the decoy. FortiDeceptor Fuse page is maintained and updated weekly with content related to sales, marketing, proof of concept, best practice deployment, and videos covering the core components of the product. We also have a very active Teams group called deceptor_fdc that I highly recommend to join. For hands-on labs, we have a fast track session for partners that allow us to deploy and test the product. We will refresh this training session after the release of version 3.3. For SE training and demo, we will have a cloud platform that will allow the SE to deploy and test the product for training purposes. We are expecting to have this platform by the end of Q2. I will now hand it over to Damien for the remaining portion of this presentation. Thank you, Moshe. We'll round off this presentation with a customer case study, and lastly, a quick recap. On FortiDeceptor's customer success story, I'd like to discuss this large media conglomerate in Europe that was looking to bolster their security architecture to detect and respond to both external and internal threats via a layered approach to security, with the eventual goal of consolidating all their various security solutions. They went with the deception technology since it allows them to redirect external and internal threats from their hosted media platforms as well as their sensitive data, and provides them with an early warning to de-escalate these threats. Since their IT security team is shorthanded, they have a strong need for automating their security solutions. Currently, there are a handful of vendors offering deception, with a majority of them being startups, and that created concerns around regional support gaps and a disruption to product development due to the possibility of acquisitions. To overcome these concerns that they had, they went with Fortinet for this particular project because it came from a well-established security vendor offering a global follow the sun support, as well as the commitment to the homegrown FortiDeceptor investment. Most importantly, FortiDeceptor integrates with their in-place FortiGate deployment, thus fully automating all threat responses. The best part, they saw immediate value after the deployment of deception as they caught an internal user performing port scans and attempting an unauthorized connection to one of their decoys. This really helps with eliminating the actual threat before it escalated even further. With that, let's discuss the key takeaways of the FortiDeceptor solution. FortiDeceptor is a powerful addition to any organization's security strategy by focusing on the attackers themselves. FortiDeceptor provides a timeline-driven threat campaign analytics that reveals the attacker's intention and tactics, including malware details from the integration with FortiSandbox and FortiAI. FortiDeceptor also automatically learns the types of endpoints, servers, and services that is found in that particular organization, so it can recommend the appropriate interactive decoys, layouts, and services to be provisioned. Now incorporating deception is part of the proactive defense, and this really helps elevate an organization's existing security posture and reduces the business disruption due to the external or internal threat actors. Besides that, FortiDeceptor broadly covers the IT segment of an organization by simulating Windows and Linux clients and servers, but also OT and IoT segment, including ICS SCADA, ERP, medical, and point of sale systems for all these various verticals. Besides the devices themselves, deception supports various applications and services, including things like Git repository, VPN, SMB, SQL, and many others. This helps the security operations to close off gaps with this comprehensive coverage of the dynamic attack surface. I'm Peter Salkowski, Fortinet's Vice President of Investor Relations. I'd like to welcome everyone to Fortinet's 2021 Analyst and Investor Day, and thank everyone for attending. Presenters today are John Maddison, Fortinet's Chief Marketing Officer and Executive Vice President of Products, and Keith Jensen, our Chief Financial Officer. There will be a video presentation that will be available for replay on the investor events section of our investor relations website. A copy of the slide presentation as well as a transcript of the Analyst Day will also be posted on the investor relations website later today. For today's agenda. John will start off today's taking a deeper look into some of the topics he presented earlier today at the Accelerate 2021. A replay link of John's Accelerate 2021 keynote, along with the Accelerate keynotes from CEO Ken Xie and CRO, Patrice Perche, along with all three presentation slide decks and transcripts are posted on the investor events section of the investor relations website. After John, we'll host a brief Q&A session with our sell-side research analysts. Keith will then review Fortinet's growth drivers, summarize the company's consistent financial performance over the past several years, and provide our 2023 financial targets. We will then conclude a longer Q&A session where Keith will be joined by Ken, Patrice, and John. During both Q&A sessions, we ask that you please limit yourself to one question. Before I turn the day over to John, I'd like to remind everyone that during today's Analyst Day, we will be making forward-looking statements and that these forward-looking statements are subject to risks and uncertainties, which could cause actual results to differ materially from those projected. Please review our SEC filings, in particular the risk factors in our most recent Form 10-K and Form 10-Q for more information. Our forward-looking statement reflect our opinions only as of the date of this presentation, and we undertake no obligation and specifically disclaim any obligation to update forward-looking statements. Last, I'd like to remind the analysts that if you want to participate in the Q&A session, that you need to access the Analyst Day using the Zoom links that I sent you earlier. Will now turn the presentation over to John. Thanks, Peter. Let me see if I can share my screen here. All right. Peter's given me 20 minutes to get through this conversation, I'll make sure I focus in on the relevant points. Two main points. One was, although we announced FortiOS 7.0 about a month ago, it's going to be available at the end of this month. It's really expanded what we call our platform, the fabric approach, across the endpoint, across the network, and across the cloud. There's not many vendors who can support that platform across all three of those areas. We also deliver it via our appliances, software, virtual, and SaaS delivery as well. I think the main topics I'm going to talk about in terms of product will be SASE, although by definition seems to change depending on who you're speaking to, but also Zero Trust. Across those two things I don't see I can share my video. It doesn't seem I can share my video, but there you go. All right. SASE and Zero Trust are use cases that span across multiple products, one of the issues customers are finding is that because they've got point product A, point product B, point product C, making those use cases work across all those different vendors is almost impossible for them. Further evidence that a platform is going to be the solution going forward. The second point is our partners. Today we announced AT&T from a SASE partnership perspective. They've been working on this for a while. Taking SASE and implementing it through the network is absolutely the best way. SASE consisting of SD-WAN and secure web gateway. For sure, SASE and implementation with the service providers, we do find that there's a lot of conflicts with SASE-only companies or SaaS-only companies. A lot of channel conflicts. Our strategy is to partner with our channel, including inside that will be our large service providers as well. From a vision/mission perspective, who is Fortinet? As you know, and as you speak to customers, this digital innovation is just accelerating, and as they accelerate that, it just expands the attack surface, and they really want to make sure that they secure both the people, devices, data, and infrastructure. What we're seeing is a greater collaboration between the CIO and the CISO teams as we go forward. Who is Fortinet? We're definitely, as you know, one of the top cybersecurity brands, and we really focus on delivering a platform that covers that entire attack surface. Now, at the TAM, it's always interesting to me when I see companies put up TAMs, and sometimes I don't know where they get the information from because they claim TAM that I've never seen them operate in, but this is our TAM. It's backed up by a lot of Gartner information. Obviously, we do that through Magic Quadrants and Market Guides, and I'll talk a bit about that briefly. Our TAM, it stretches from users and devices across the network, across cloud, and security operations. We operate both in the network security world, the networking world, as well as the cybersecurity world. What trends are we seeing? What's driving the marketplace across endpoint, network, cloud, and the cybersecurity, security operations? At the endpoint, obviously, there was work from home. We're still seeing factories IP-enabled, and I'm going to zoom in on the zero trust architecture for that, which is a migration from VPN. Network security, what we're seeing is a lot more edges appear. It used to be a very well-defined perimeter, now we're seeing a lot of edges appear. I'll talk about SASE, which is a component of that. Cloud security, we continue to see the rollout across hybrid, across cloud, and we're seeing it migrate all the way back into distributed or edge compute, and so adaptive cloud security and secure approach. I'm not going to have time to probably go through much else than zero trust and cloud edge SASE. There just won't be enough time, but let me focus on those two areas. Let's zero in on the security-driven networking, network security, networking, accelerated convergence. We're absolutely seeing the convergence of networking and security. There's no way you can defend and protect all these edges without having a converged solution. It's just too complex and too costly. This convergence is starting to happen rapidly. When I look at the TAM, we looked at the TAM earlier for network security. What Gartner have are Magic Quadrants, and these are well-defined buying centers, network firewall, secure web gateway, SD-WAN, switching, and wireless. There are some markets, like IPS, intrusion prevention, we've gone from a Magic Quadrant to being a Market Guide and a static Market Guide in that it's not really changing much. The long-term destination for such a marketplace will be consolidation inside one of the existing buying centers, we've seen an awful lot of the IPS marketplace get consolidated into network firewalls as we go forward. Then there's new market guides, which are new markets, up and coming markets, which either form their own Magic Quadrant or do a merger with an existing Magic Quadrant. There's kind of three of them right now in network security. There is the performance monitoring and detection diagnostics, there is the digital experience monitoring, and of course, SASE, which everyone wants to come in here and talk about. When we broke down and looked at the forecast, this is Gartner's forecast for network security. I'm just focusing here on the network security marketplace. I've not included network performance monitoring diagnostics. Through our acquisition of Panopta, we are in that marketplace now. I've not included it in the TAM right now. You can see there's not a huge amount of change, to be honest, in the size of the pie slices as we go forward. Yes, secure web gateway increases a bit. SD-WAN increases two points. Switching increases slightly. Firewall, maybe one point. The overall percentage of market share of firewalling and SD-WAN and web gateway, wireless and switching remains pretty much the same. It's around a 10% growth into 2024. Gartner did recently publish, in fact, back in August, another view of this marketplace. This is their SASE definition, secure access services edge. What they did, what SASE really is a number of those existing marketplaces repackaged into this framework or architecture. You can see here that what they've taken is the fundamental components of a SASE company include SD-WAN, includes secure web gateway, include firewall as a service, zero trust, and CASB, which obviously go across the endpoint, go across into the cloud, and go across the network. How does that change? Again, it doesn't change too much. You can see SD-WAN increases a bit more. The secure web gateway decreases, they're pretty much the same. In our minds, to be a main SASE player going forward, you need all of these components. You need all of these components delivered at the edge, cloud edge, WAN edge, and LAN edge. Just to kind of show you who's in these marketplaces, we've taken the Magic Quadrants for network security. We've taken the Market Guides for network security. You can see the different players and the different parts there. The secure web gateway is a marketplace we actually are very active in. Gartner's definition is a bit strange on why they allow certain people into that Magic Quadrant. I think that will change as we go forward. What's our key strategy here for security-driven networking? The first thing is enterprise-class networking at all edges. That is the cloud edge. Obviously, at the cloud edge, we need to be able to provide that from our data centers, our cloud. At the data center edge, very high performance needed and required there. At the LAN edge, either through Wi-Fi and switching. At the WAN edge, through SD-WAN. At the up and coming 5G edge, LTE edge. We're also doing a lot of work on the OT edge. Remember, OT used to be air-gapped. That's going away, and that's creating an edge there. One of our key goals is to be able to supply or be able to network, provide enterprise networking at all these edges, whether they be cloud, data center, LAN, WAN, or OT, through hardware, through software, or through SaaS. Any one of those can be used across all those edges. The second component of security-driven networking is enterprise-class security, and I often hear people say, "I've got security. It's in the cloud. Don't worry about it." No one's tested it, no one's looked at it, and no one's certified it. We have tested and certified all our security components, whether it be the content, whether it be web security, user security, IoT, OT security, our advanced operational and security operations capabilities, as well as the integration of more advanced support services as well. I definitely feel like this is an area that people are going to look at at some point, because you can't just say, "Trust me, I've got great security." You need to make sure that that security is tested and certified. Then we bring all of that together through the Fabric and the platform. Yes, you could have one of these components. Yes, you can have some security, but the key is then to be able to bring that all together in a platform, to be able to orchestrate any one of those edges in terms of networking functionality, to be able to deliver security, any level of security or any part of security stack at any one of those edges. Then to be able to make sure that it fits into the ecosystem of the customer. The customers have made some investments into large platforms. Needs to be a platform that covers the attack surface and all the security components, but also needs to be able to integrate into the ecosystem of the customer. This is why FortiOS is very important to us. I always tell customers it's probably the most important investment from a Fortinet perspective, is that this stack, this full stack of networking and security capability, can sit at any one of these edges. It can sit in an appliance at the WAN edge. It can sit in our SaaS-delivered cloud edge in SASE. It can sit as a powerful perimeter security next-gen firewall in the data center edge. It can apply security to the LTE edge, the switch edge, and the Wi-Fi edge. What the customer gets is the ability to switch on any part of a networking capability and then apply security wherever they want to across all these edges. As they go forward and as they shift different things, maybe there's a shift from work from home back to the office. Maybe you continue shifting things into the cloud, and it goes into the edge compute. Maybe you continue IP enabling your OT infrastructure. As these shifts happen, you can update that networking capability, and you can increase or decrease the security depending on where the use case is. It's all consistent enterprise class because you're using this enterprise class operating system stack across all those elements. That's why FortiOS is so important, and it can all be applied to a single policy engine across your entire end-to-end endpoint network and cloud security. I'll just kind of highlight the SASE offering that came out with our 7.0 FortiSASE. Again, people take the SASE definition and weld it in or mold it to whatever they've got. The fundamental tenets of SASE are two components. One is the convergence of networking and security, and the second one is a platform approach, not a point solution. A platform approach or a framework approach to the edges as you go forward, the services edge. From our perspective, there's three really important components. The first one is you absolutely need to be able to apply a flexible edge access. That edge could be a work from home user. It could be what we call a thin edge, where the device, in this case, for example, is a 4G or 5G device, doesn't have the footprint to put the security on. Then there's what we call a secure edge. A secure edge would be one of our SD-WAN devices. That can put a full security stack, but even if you don't put all the security there, you still need some security on SD-WAN. So these different, these flexible accesses from the edge gives the customer the ability to protect all those edges. Once you hit our cloud, you hit the first thing is security-as-a-service. So you may want to apply secure web gateway capabilities, or you may want to apply isolation web browsing or next-gen firewall or firewall-as-a-service. We've also integrated Zero Trust. Your Zero Trust Network Access use case can also be derived using the SASE access proxy. Then the third component, which we think is going to be extremely important going forward, is that digital experience monitoring. I've put all these things in place to make it more flexible and more secure, are my users and devices, by the way, getting the right experience end-to-end, from how they access the network through the network and into the cloud. The peering of our data centers, the monitoring of the experience and the high availability, and then the ability to see via API security into clouds where you can't even provide any of your own security, becomes very important. To us, SASE consists of these three things. Access edge. Okay. Usually an appliance for SD-WAN, some sort of device for 5G or some sort of client. We then provide security as a service in the cloud, in our cloud. We then provide digital experience monitoring, which provides that glue and that intersection between the user experience and the application. This is all rolled out under our FortiSASE umbrella. I'm looking at time here. I've got a few minutes. I'm going to see if I can squeeze in the zero trust. Zero trust access, this marketplace is dominated by identity, actually, although you did have VPN and NAC and OT security as well. From a size perspective, again, access management is dominating. Zero VPN and zero trust is also going to be very important as you go forward. If you look at the market guides and the Magic Quadrants, it's quite fragmented. A lot of activity around zero trust and VPN migration. Here's the biggest issue with zero trust. It's great technology. It's probably technology that we should've been implementing a while ago. It really does upgrade your VPN access big time in terms of giving you specific application access and constantly doing a contextual view of per session on what's going on, and then also providing that user and device continuous identity check as you go forward. Absolutely without doubt, VPN has served us well over the last 20, 15 years, but it will evolve forward into zero trust. We believe, however, we have a lot of customers on our VPN networks, obviously, our VPN solution set, that it's an evolution versus a revolution in terms of you can just wipe the slate clean and start all over again, but you're going to have to make all these different vendors work together. From a vendor perspective, what do you really need from a zero trust? First of all, obviously you need that zero trust agent sitting on the endpoint. You can use files and stuff, you really do need an agent to get the best experience. We also believe, obviously, you need that authentication of the user and devices, multi-factor as you go forward. There's the most important piece, which is the access proxy. Access proxy provides that granular access to the applications and also connects the user session into the contextual engine. Now, as you go forward, once you're on that application, a lot of customers and enterprises also want to apply more advanced endpoint security, such as EDR, because once you're on there, you've got to keep that behavioral monitoring going on across that endpoint. What I find a lot of times is that across a specific customer, you've got a vendor A for Zero Trust agent, you've got another vendor for EDR, another vendor for identity, another vendor for proxy, and it just goes on. It's almost impossible to get a true Zero Trust networking working across so many different vendors. I'm not saying you need one vendor, but I'm saying you can't have five or six vendors. This doesn't work. For our solution for Zero Trust, one of the key components inside there is FortiOS. That becomes the access proxy. The flexibility we can have is that that access proxy can be in the cloud through our FortiSASE solution, but it can also sit in the customer data center. Their existing VPN termination point can be the access proxy for our Zero Trust solution set. We think there's other marketplaces, on-campus marketplaces, which could replace core switching and networking to the Zero Trust Architecture and proxy. The key for us is that we've got our FortiClient, our FortiZTNA, our Authenticator, Token, EMS, and FortiOS that provides an end-to-end Zero Trust solution, where the proxy can be in the cloud, in the data center, on the campus. We can integrate with other components, so identity systems out there, for example. We believe this is a great migration from our existing FortiClient and FortiGate customers into a use case Zero Trust that works across all these components and will arrive in our FortiOS 7.0. Let me stop there at 21 minutes, I think. Unusually on time, see if I've got any questions. All right, John. Thank you very much. I will point out there's another dozen slides after this, but you're right, we've run out of time. We are going to open up for Q&A. I will remind everyone that John's slides will be posted on the IR website after the presentations, hopefully very quickly after. Just again, a reminder, please raise your hand to ask a question and please do limit yourself to one question. We've got limited time and lots of people want to ask questions. First one up is going to be Michael Turits from KeyBanc. Michael, go ahead. Just introduce yourself, Michael. Thank you. Should be unmuted. Yeah. Thanks very much. John, you guys announced the partnership with AT&T today for SASE. Can you talk about that decision to partner with service providers for the, let's call it the networking services component? By contrast, some of your competitors have built their own network of POPs, others are partnering with cloud providers. Do you get enough control over the end product and over the customer if you're this way versus these other strategies? To be clear, we'll do both, okay? I don't think you can supply a SASE platform or SaaS platform without experiencing it yourselves and understanding it yourself. We'll do both. We'll have that offering. We firmly believe that once we've built that technology, transferring or enabling our big service provider partners is the best way into the marketplace. As I said earlier, we absolutely see channel conflict all the time between service providers and some of the pure SaaS vendors. We believe you have to build it so you know how to build it, and then we can transfer some of that technology to our service providers. Thanks, John. Thanks, Michael. Okay, next up is Jonathan Ho from William Blair. Hi, good afternoon. In terms of the breadth of offering that you just sort of described, can you maybe talk a little bit about how in the SASE and zero trust world, having that broad of an offering, does that provide an advantage to you relative to some of the deals that you're doing out there? Can you talk about specifically why it's an advantage to be able to offer, I guess, a more holistic set of solutions? Thank you. Thanks. Yeah, definitely customers have had enough of buying all these different point solutions. When I speak to them, it's not that they want to go from 30 point solutions down to one. They want to go from 30 point solutions down to seven or eight platforms that interwork and work together. One of the most common ones we have is Microsoft, and we have eight different integrations into different Microsoft. We're not saying it's one, it's seven or eight, but they need to work together. They're going to a platform. They just can't support so many different point products across network and cybersecurity. The advantage for us is that sometimes I see us enter a customer with one of the products. In fact, it could be anything. It could be authentication, it could be our WAF in the cloud. We've always got something that's available to enter a customer. The advantage long-term, though, is that they can then build out their Fabric within that kind of architecture they decided on the seven or eight platforms and truly deliver those use cases. It's not a point product anymore that can deliver Zero Trust or SASE. It's just impossible. You need that platform approach to be able to deliver that. Sorry about that. Next up should be Brad Zelnick from Credit Suisse. Awesome. Thank you so much. John, really appreciate the presentation. Maybe a variation of the last question. You talk about platform and interoperability of solutions in implementing a SASE architecture. I just wanted to maybe understand competitively and through the lens of the customer journey, what distinguishes Fortinet. Because at this point, many vendors are approaching SASE from different starting points. Zscaler with proxy, Menlo Security with browser isolation. Cato, I think, began with firewall as a service. Palo Alto has a number of assets. Where does the customer journey begin for a typical Fortinet customer, and why is that a better on-ramp to SASE versus others? As you look out on the horizon, is it always going to be patchwork, or do you think there ends up being winners and losers here because you're all swimming in each other's lanes? I think the losers long term are the point solutions. There's not many vendors like ourselves who have enterprise class security across endpoint, across network and across clouds. If you're trying to measure the digital experience, if you're trying to provide security across that attack surface, if you don't see part of it, how are you going to protect it? Our long-term advantage is that we can sit across any of those edges, that we can provide enterprise security across any of those edges, and that we can deliver it via SaaS or appliance or software or agent. That's our advantage. There's a lot of people who are just in the cloud. There's a lot of people just in the network or just at endpoint. Our ability long term to sit across all those three is our biggest advantage. Yes, some customers, let's be honest. Let's look at the SASE marketplace today. What is it? It's 95%, maybe more, secure web gateway as a service. That's what it is. It's people who have migrated their proxy, more often than not, Blue Coat proxy, into a cloud proxy. That's where the market is today. However, it's going to expand as people expect the orchestration between their SASE and their SD-WAN, as they expand their integration into the cloud through CASB, or as they expand and make sure that any endpoint through zero trust, on and off the network, gets that protection per application. The advantage for us is the use cases. It works across all these different elements, and we have all of them in place. We spent the last, I don't know, I'm going to say 10, maybe eight or seven years building it organically versus trying to bolt it together with acquisitions. We do acquisitions, and Panopta was the latest one, but they're small, and we buy it for the technology. I think it's really hard to build a platform like ours if you don't do it organically. Coming back to your question, Brad, I think our advantage is that we can sit across any part of the edge. We can deliver appliance software and SaaS, and that gives us the ability to deliver these use cases like no one else. Excellent. Thank you so much. Thank you, Brad. Next up is Brian Essex from Goldman Sachs. Yeah. Thank you, Peter. John, thank you very much for the presentation. I was wondering if you could maybe touch on, you talked about the convergence of network and security, and from the perspective of legacy or incumbent network equipment vendors, what are you seeing there in terms of the way that they might be approaching SASE, particularly given the legacy install base they might have, maybe the presence of the campus edge as a competitive advantage. How are they thinking about this? Well, I think what networking vendors have done, and I don't think I said this at the beginning, there's a big difference between networking vendors and cybersecurity vendors. One's hardware and performance, and one's software. Well, if you listen to my presentation, I go through that a bit. I think they've been able to kind of buy and bolt on cybersecurity components over the last 10 years. You just can't do that forever. It becomes even harder when you've got to do it in the cloud or SaaS delivered. I think they're really struggling, and we see that in the marketplace. When the customer says, "Hey, I want this converged solution, and I want to be able to put security on the WAN edge or the cloud edge or the data center edge, and I want it to be consistent, and I want it to be enterprise class," they just can't deliver that. It's just impossible because they're trying to bolt things together. That's what I've seen, and it gets harder and harder because the customers get frustrated because they've been promised by some PowerPoint it's all coming together, and years later it's not. They're becoming very frustrated. Got it. Thank you. Thank you, Brian. Next up is Gray Powell from BTIG and Keith Bachman from [BMO Capital Markets]. Hey, Peter. Thanks. Can you hear me okay? Yep. We can hear you. Perfect. Yeah. I just wanted to follow up on Brad's earlier question, and maybe just from a different angle. Fortinet's always had some level of secure web gateway capabilities, and I think it's been pretty successful in sort of the small and mid-market. Historically, I'm not sure if Fortinet's really been thought of as a replacement for pure play proxy architectures in larger enterprise. Could you maybe talk about how that's changing and in particularly, as you focus more on the SASE product set? Yeah, it's a good point. I think I kind of mentioned it a bit in the Gartner Magic Quadrant for Secure Web Gateway, that for some reason, a couple of years ago, they put in that you have to be a cloud proxy to be in there. Even though we have got substantial revenues of Secure Web Gateway, whether it be proxy or whether it be through our full proxy or through our FortiGate, we can do that. For us, I think as we go forward, we now have that capability in the cloud. I think we'll get access to the Magic Quadrant, and I think you'll see us accessing the enterprise marketplace through there. When you look across cybersecurity and you look across networking, I didn't show you, if you look at one of my presentations from Accelerate this morning, I kind of flash a slide with all our different products across all these different areas, it's substantial. I probably would say that one of them that wasn't quite enterprise class was the proxy capability, that'll be fixed in our FortiSASE offering. Got it. Okay. Thank you. Great. Just as a reminder, those slides are up on the website, as is the replay for the analysts that didn't get a chance to see them this morning. Next up, I believe, is Keith Bachman. If you do have a question, please do raise your hand. We've got about nine more minutes left in the Q&A. I think we'll get a few more in here. Keith, you're up. All right. Thank you very much. Thank you, John and Peter. My question is going back to the market slides, where you had growth rates. I just wanted to see if you could flesh out, A, how you're viewing the growth dimension surrounding firewalls versus firewalls as service versus virtual firewalls. What do you see as a key opportunities or risk? Then, B, to broaden out the question a bit, how do you think Fortinet fits into that as architectures converge surrounding firewalls, a piece of the node rather than an entire solution as SASE becomes more prominent. Just trying to see what the risks are or opportunities for Fortinet as you think about the growth of the firewalls in those various pockets. Thank you. Good question, Keith. Good question. First of all, I think firewalls as a service is a tiny marketplace, and it's just very different. The Secure Gateway moving from data centers to cloud makes a lot of sense, architectural-wise and everything else. That will just move into the cloud. It's like email. When I first started doing email security back in 2007, it was all appliances. Well, it's moved to cloud. It's close to the application. Web gateway needs to be close to the cloud edge. Firewalling is very, very different from an architecture and network perspective. I don't think Gartner could even give you any estimate. I know from SASE, it's a complete guess. They have no clue what the firewall as a service marketplace is. If they did get to a detail, I think it'd be less than $100 million. Will it be there eventually? Yes. It's going to be very small. I think the more powerful components of the firewall marketplace as we go forward, I think it's going to become about 10%. It probably already is about 10% virtual. We have a very strong FortiGate virtual machine offering. There's still going to be a need for appliances at these edges, internet-facing. There'll still be a need for appliances in the core, where you need super hyper-scale performance. The other area we think will be very interesting will be the micro-segmentation cross-cloud. That is, even though you have native cloud firewalls from Azure and AWS, and by the way, we apply management and services sitting on top of a lot of that native security, as we've announced recently. We think a cross-cloud firewalling micro-segmentation strategy gives you that kind of firewall in the cloud and cross-cloud that used to be predominantly an east-west data center technology. I think it's going to migrate to being cross-cloud. It also gives you that visibility that you can take and transfer back into your north-south or endpoint network WAN capabilities. Firewall as a service to me is just a tiny speck and will remain that way. It will be there, and we offer it today. I think that the bigger component to us is still making sure we can sit in the middle of a data center, sit at the edge of a network. I don't know anybody yet that really wants to put a virtual machine at the edge of a network facing the internet. The risks are tremendous. We do see micro-segmentation cross-cloud as being an important part of the firewall marketplace going forward. Great. Thanks, John. Next up is Fatima Boolani from UBS, and Ben Bollin, you're on deck. Hi. Thanks for taking my questions, and thanks, John, for the presentation. John, I wanted to ask you about the AT&T opportunity and the partnership there, but maybe a bigger picture question around the SASE/SD-WAN market opportunity bifurcated between the service providers and carriers and the enterprise, because my understanding is that you're able to cater to both in different ways. I'm wondering if you can talk about those compatible but still different opportunities. Another good question. I think the marketplace is about 50% enterprise DIY, 40% service provider, and 10% just cloud SASE-oriented versions. We are very strong in the enterprise because a lot of it was just switching it on for us, and enterprises like that now. Service providers are different in that they need to scan across multiple customers, they need more sophisticated orchestration. We're just kind of, over the last year or so, entering that marketplace. It was slightly different for us. We're starting to provide headway, but we don't think it's going to be isolated SD-WAN. It's going to be more of this SASE. Remember you saw my definition of SASE earlier, is SD-WAN, it's web gateway, firewall as a service, CASB, and Zero Trust. What we're going to see is that our customers are going to say, "Yeah, we want to do SD-WAN." This is like AT&T. They said, "Well, we could do SD-WAN with you, but we've got a network-only version of that. Why don't we do a SaaS version which includes SD-WAN, that includes a secure web gateway, that includes some of these other applications going forward?" I'm having the same conversation with all the service providers. They're saying that, "Let's take our platform approach across our network into the customers." They're hearing that from their customers as well. Does that make sense? I do think, and I've said this, and our service provider customers know this, that they've taken the easy route out over the last five or six years. They've just said, "Oh, this is OEM something, a marketplace, a SaaS version," because it's easy. They're realizing now that if they just keep doing that, they're going to get devalued into being just transport, especially since MPLS is getting turned over into SD-WAN and broadband. They absolutely know they can't just OEM this going forward. They need to have their own solution. Thank you, John. Next up, Ben Bollin from Cleveland Research. We've got two after Ben. We're going to have Andy Nowinski and Tal Liani. Andy Nowinski from D.A. Davidson and Tal Liani from BofA, and then we're going to wrap up the Q&A session. We'll try to get all three of them in. Ben, you're up. Thanks, Peter. Thank you, John. Bigger picture, interested in how you think about the incrementality for Fortinet, either wallet share or cohort expansion as customers evolve into Zero Trust and SASE. Also interested any thoughts you have within the customer footprint for the ones who are most prepared to make this transition and already in play versus those who seem to be maybe lagging the most. Thanks. Yeah. No, good question. I split those two up. Zero Trust to me is definitely something that is going to swallow the VPN marketplace. We have a certain percentage of the VPN marketplace, A, we want to make sure that all our VPN customers migrate to our Zero Trust versus somebody else's. We also think that Zero Trust allows us to go after the new marketplace plus other VPN vendors as well. To me, that is an incremental increase in market opportunity. SASE, as I keep saying, is 95% secure web gateway, where we have a presence, but nowhere near the size of some of the larger vendors in that. I see that again as being an opportunity for us. I am not worried that it is firewall as a service being such a tiny component of that. It doesn't really affect our firewall business, but we see it as an opportunity to go after the proxy cloud secure web gateway marketplace, and again, tie in other things like SD-WAN or CASB integration as we go forward. Again, I keep saying this, there's people who are in the cloud, there's people at the network, the networking vendors, there's the end-point vendors. By the way, our Zero Trust, we want to upsell people into our EDR solution and XDR solutions as we go forward. We think it's new incremental market opportunity, but even more so to cement our situation and the customers by building a use case across multiple products. Thanks, John. All right, next up is Andrew Nowinski from D.A. Davidson, then we're going to end with Tal Liani from BofA. Andrew, you're open. Thank you very much. I just want to ask a question on your access proxy. I know you said it was essentially FortiOS, but I'm wondering if that's synonymous with the proxy that Zscaler has and now Palo Alto offers as part of their Prisma Access solution. I was wondering if you could just compare and contrast access proxy versus those two at a high level. Thanks. Well, think about the access proxy and proxy web gateway are different. The traditional secure web gateway proxy is a certain marketplace, and it's protecting users, and you apply security to that access to the internet. The access proxy needs the ability to apply per session against a contextual engine, given an identity-based policy of the end user's agent. They are similar from an engine perspective, but very kind of different marketplaces. For us, FortiOS can be both. It can be that secure web gateway proxy. We have quite a few customers actually, who use it, our FortiGate, as a proxy, a web gateway proxy. It also will be their Zero Trust Network Access proxy as well. Again, the amount of features and function capability we can put on FortiOS, whether it be at the proxy, whether it be at the WAN edge, SD-WAN, whether it be a Wi-Fi controller, whether it be a 5G controller, this is what gives us such an advantage that we can play in so many different marketplaces with the same stack. Great. Thanks, John. Last one up, Tal, and then we're going to move on to the next presentation. Tal, are you there? Hey, can you hear me? We can hear you. There you go. You may get a different name on the computer because of technical issues, but I have two questions. The first one is, if I ask your typical customer, historically, if I ask them, what's the one benefit of Fortinet, the answer is major price advantage, 40% discount. The question is whether you maintain this kind of price advantage, also in a SASE model. The second question is, with other companies, we have seen that SASE is a replacement of appliance revenues, and there's always a decline in product revenues, an increase in SASE, and it creates some differences between revenues and ARR. In your case, it looks like your focus is slightly different. Can you talk about cannibalization versus non-cannibalization business that you're forecasting? Sure. Let me answer those two. The first one, absolutely. We have such a price performance advantage for core networking, not just firewalling, but also SD-WAN, by the way, that customers obviously talk about that. They should also be talking about that it's not just performance, but it has enterprise security and has all the networking features. It's not just the performance. They wouldn't buy it if it wasn't enterprise class. We wouldn't be in the middle of many large financial organizations if it was just cheap. I always say, yes, great value, but it's absolutely high performance and high effectiveness. I think the second part of your question, what's happened is SASE, because it's also 95% secure web gateway, has ripped the heart out of Blue Coat proxy appliances and transferred them into the cloud. Absolutely, 100% agree with that statement. As I keep saying, firewalls and services are tiny clouds. Firewall and service is tiny. I can't even register it. That's not ripping out our appliances and putting them in the cloud. I think the long term for that marketplace is more around virtual machines, native and micro-segmentation. That's the bigger challenge to traditional hardware appliances. SASE and firewall as a service is not. Okay. Does that answer the question? You may have to come back on mute due to time. We can always come back to that in the second Q&A after the CFO presentation. John, thank you very much. Thanks. I'm going to open the floor. Thank you, Peter. I appreciate you acknowledging what an accomplishment that was for me to get my screen to present. Yes, it was. Let's see if it is slide advance now. All right. Good morning, everybody. Thank you very much for being here today for Fortinet's Analyst and Investor Day, and I am indeed Keith Jensen, our CFO. As I begin our presentation, I share our safe harbor slide and highlight that I'll be making forward-looking statements today. These forward-looking statements are subject to risks and uncertainties, which could cause actual results to differ materially from those projected. All statements made today reflect our opinions only as of the date of this presentation, and we undertake no obligation and expressly disclaim any obligation to update forward-looking statements in light of new information or future events. Let's take a quick look at the agenda. I'll start by highlighting our investment thesis, discuss several of our industry and company-specific growth drivers, and then review our financial performance for the past several years. I'll wrap up by highlighting how the diversification of our business model and customer base has led to our very consistent and highly financial performance. Finally, I'll conclude by providing our medium-term financial model, and we'll follow the presentation with a 30-minute Q&A session with our senior management team. Throughout this presentation, you'll hear several recurring themes about the cybersecurity market, what uniquely positions Fortinet as an industry leader, and the drivers of our consistent and sustainable growth, profitability, and cash flow generation. Cybersecurity is a massive market with growth driven by long-term secular tailwinds. Fortinet is an industry leader with our proprietary ASIC technology and integrated platform, enabling us to secure people, devices, and data anywhere in any form factor. Our revenue is diversified across geographies, customer segments, and industry verticals. With service revenue representing nearly two-thirds of total revenue, we have a sizable recurring revenue base driving sustainable and predictable financial results and a margin profile that leads to significant free cash flow. Fortinet's history of innovation has spanned more than 20 years. Our strategy of build versus buy, consistent financial performance, and conservative financial policies have led us to where we are today. More than $3 billion in annual billings, free cash flow of over $900 million, non-GAAP gross margins approaching 80%, non-GAAP operating margins in excess of 25%, and having just reported our 11th consecutive year of GAAP profitability. Our strategy of balanced growth and profitability was recognized by both Moody's and S&P. These credit rating companies recently graded Fortinet as a strong Triple B investment-grade company. Importantly, 30% of all network security firewall units in the world have a Fortinet label, more than the next three companies combined. We have over 500,000 customers worldwide and are approaching 700 U.S. patents. In summary, that's who we are. This slide illustrates the results from our balanced growth and profitability strategy. Not only did our revenue growth outpace market growth for each of the last four years, we also increased our non-GAAP operating margin 950 basis points during that same period. Fortinet's almost all organic revenue growth for each of the last three years has been approximately 20%. Our higher margin, more predictable service revenue grew at a three-year CAGR of 22% for the period ending December 31, 2020, and service revenue now represents nearly two-thirds of our total revenue. Despite the pandemic, 2020 product revenue growth held firm at over 16%. In the group of major network security companies, such as Check Point and Palo Alto, Fortinet was the only company to post double-digit year-over-year product revenue growth in 2020. I'd like now to discuss several growth drivers that have contributed to our strong performance over the past several years, and that we expect to drive our growth as we go forward. There are many drivers behind the growth in the cybersecurity industry that simply put is about bad actors getting more and more sophisticated while targeting a continually expanding attack surface of edges that include data centers, WANs, LANs, public and private clouds, 5G, OT, and IoT. Given this backdrop, we estimate our total addressable market will grow from $65 billion in 2020 to approximately $93 billion in 2024, representing a 10% four-year CAGR. Importantly, the TAM estimates exclude related services such as our FortiCare support and FortiGuard security updates. Central to the $93 billion TAM is network security at $48 billion. Network security largely includes physical and virtual next-gen firewalls, as well as secure infrastructure, components of 5G and SASE and SD-WAN. SD-WAN, Fortinet is at the epicenter and growing dramatically. Our continued focus on organic innovation means we have, and we will continue to add capabilities to our Security Fabric platform and our integrated operating system, including zero trust security capabilities, cloud security, and security operations. Our solutions include a complete range of form factors and delivery methods, including physical and virtual appliances, cloud, SaaS, and perpetual software, as well as hosted and non-hosted solutions. Together, they provide a range of security solutions and form factors, enabling broad, integrated protection of hybrid environments in the expanding digital attack surface. Fortinet has shipped over 30% of all firewalls and currently has over 500,000 customers, evidenced by our sizable footprint. Nearly one out of every three firewalls deployed globally carries the Fortinet name. This sizable deployment provides us with invaluable insights into evolving threats and vulnerabilities, which allows us to drive real-time updates to our customers of all sizes and geographies. The inherent economics of scale that come with 30% of units deployed drives lower unit costs and may stress the competition as we annually add over 50,000 net new customers. For the past few years, SD-WAN has shown to be a driver for both network security market and for Fortinet. We offer a unique product that combines security and SD-WAN functionality in a single appliance. Because of this, our SD-WAN billings increased to over 11% of our total billings in 2020 from almost zero in 2018. Analysts believe the SD-WAN market will grow at 30%-40% in each of the next several years. Looking at our pipeline growth, we tend to agree, and at the same time, we expect to continue to grow faster than the market. It's important to note that SD-WAN is a feature of the FortiGate operating system. For us, SD-WAN is yet another firewall use case. Like other firewall use cases, customers often attach a variety of fabric platform products. Another growth area for Fortinet has been the move upmarket into larger enterprises. While expanding into larger enterprises represents an opportunity and a journey, these two bar graphs illustrate our success thus far. We've seen a number of deals over $500,000 and $1 million, and the related billings grow steadily. This slide shows the consistent annual and largely organic billings growth clustered around 20% for the last four years, resulting in 2020 total billings of around $3 billion. FortiGates and non-FortiGate fabric billings grew at a compound annual rate of 17% and 35% respectively. We believe the 35% growth rate is affirmation of our broad and integrated platform strategy. Next, we're going to take a closer look at the non-FortiGate fabric platform. These bars provide a closer look at the billing contribution from the fabric platform. The balanced growth between infrastructure and cloud fabric drove 2020 combined billings to 39%, resulting in total billings of $743 million. Driven by our three-year compound annual growth rates in the mid-30%, cloud offerings generated billings of $237 million for 2020, and infrastructure products such as Analyzer, Manager, Endpoint, Mail, Sandbox, Secure Access products, et cetera, generated billings of slightly over $500 million. It's worth noting that cloud and infrastructure fabric billings are on a pace to be a $1 billion business as we exit this year. This slide provides a summary of cloud and infrastructure fabric products. It's a bit of an eyesore I know, but I include it here to make Peter happy because he often gets asked what's in cloud and what's in fabric by the analysts. Let's move on. So far, I've shared how Fortinet's diversified business and financial model drives consistent billings and revenue growth. We've also looked at several growth drivers that we believe will contribute to future growth. Now let's turn to profitability. We continue to drive increases in our product gross margin through growth in our cloud delivery and software solutions and meaningful improvements in our hardware bill of materials. At the same time, services gross margin is benefiting from the mix shift to 24/ 7 support and economies of scale. Taken together, we've improved our total gross margin and maintained our reputation for price for performance leadership. This leadership may pressure competitors' pricing when competing against us and mitigate discounting pressures on us. I'm going to pause here for a moment as the sirens go by. Okay. On with you, I guess that's the all clear. Improvements in gross margin and expense leverage have resulted in strong operating margin growth. While we've been increasing our margin, we continue to invest in future growth, including increasing our sales capacity. For example, in 2020, we increased our sales and marketing headcount by 22%, very similar to our 22% CAGR from 2017 to 2020. At the end of 2020, sales and marketing accounted for just over 50% of our headcount. With our growth and a business model that bills and collects cash up front for service contracts, we continue to consistently grow our deferred revenue, free cash flow, and free cash flow margin. To put our strong free cash flow conversion into context, we've benchmarked our free cash flow margin against the S&P 500 constituents. Our top 10% standing is testament to our business model driving strong deferred revenue growth, our ability to grow margins with our ASIC advantage, and efficient working capital management. As for our capital allocation policies, we have a clear hierarchy of uses of cash and free cash flow in order, debt reduction when necessary, reinvesting in the company through R&D, CapEx investments, and other organic initiatives, investing in inorganic alternatives, i.e., M&A, with a focus on smaller scale acquisitions with minimal execution risk, returning excess capital to shareholders through opportunistic share repurchases. Our free cash flow generation has not been the result of any letup in investments in our business. Our high level of liquidity has enabled us to internally finance our R&D spending and, where appropriate, fund tuck-in M&As. We've invested over $1 billion on innovation since 2016 and $160 million on several tuck-in acquisitions. In 2020, we bought back $1.1 billion of our stock, and since 2016, we've repurchased 32.5 million shares for $2 billion. From the start of 2016 to the end of 2020, Fortinet stock price has increased 377%, over three times better than the other two pure play network security companies. As we work to transition to a more efficient balance sheet, last month, we issued investment-grade bonds totaling $1 billion with an average annual interest rate of 1.6%. As I stated today, our diversified business model has resulted in consistent company performance and a more predictable business model. The next three slides highlight the consistency and predictability associated with Fortinet. These four graphs illustrate the consistency of our operational metrics. Whether you're looking at discounting, average contract term, renewal rates, or service attach rates, each of these metrics have consistently tracked within narrow bands over the last three years. Our revenue by geography shows almost perfect consistency for all three of the geographies year-over-year. As would be expected, we have posted very similar CAGRs from 2017 to 2020. As I stated previously, our consistent and predictable performance is a result of a very diversified customer base, whether it's by customer size, geography, or industry vertical. To illustrate our customer diversity, I would note in the last four years, no single customer represented more than 2% of billings in any single quarter. The geographic diversification is especially interesting. We have customers in over 80 countries that individually represent less than 3% of our billings, yet in total, they represent 50% of our billings. This diversity helps mitigate the impact of country-specific events that impact local economies. At the same time, this diversity drives our need for a broad solution set, as our customers are not easily pigeonholed into one type of security solution. For example, large U.S. enterprises may have strong financial resources, regulatory runway, internet access, and housing arrangements appropriate for remote for work and learning. These same advantages may not exist across all geographies, customer sizes, and industries. Just a quick recap on the first quarter and 2021 guidance that we provided on February 4th. As you'll note in the footnotes of this screen, we expect the recent bond issuance to impact 2021 EPS by approximately $0.05. A couple of additional modeling points, and as a reminder, my slides will be posted on our investor relations website. Now I'd like to share our medium-term financial targets. Over the next three years, we expect continued growth. Looking out to 2023, we expect billings of at least $5 billion and total revenue of at least $4 billion. Based on 2020 actuals, these projections equate to three-year CAGRs for both of approximately 17%. As for margins, we expect our non-GAAP gross margin in 2023 to be approximately 80%, and our non-GAAP operating margin to be at least 25%. Through 2020, we achieved the Rule of 40 in nine out of 11 years that we've been a publicly traded company. We define the Rule of 40 as revenue growth plus non-GAAP operating margin. We look beyond 2023, our long target is to continue to achieve the Rule of 40. I'd now like to invite Ken, Patrice, John, and Peter to join me for the Q&A session. Peter, you want to open it up to questions? Thank you, Keith, and congratulations for making it through that with share your screen. Anyway, we're going to start with the Q&A. Just like before, please raise your hand if you have a question. Also, if you could lower your hand after asking the question, so it just cleans up the queue a little bit. I appreciate that. We're going to start with Adam Tindle from Raymond James, as the first question because he was left over from the last one. Go ahead, Adam. Adam, you're still unmuted. Yep. Can you hear me now? We can. Okay. I was going to say my congrats to Keith as well for the screen share. I did want to ask a question maybe for Ken or John. Earlier today, you introduced the industry's first hyperscale data center firewall. You talked about how the NP7 chip is the equivalent of 10 high-end CPUs. I'm wondering, with that context in place, do you envision perhaps hyperscale companies becoming more meaningful customers over time? I'm asking that because we often hear investor fear over public cloud as a potential threat to Fortinet. Wondering if there's an aspect where you can flip that narrative and sell into the Amazons and Microsofts of the world, whether it's chip license or product directly. Yeah. This is Ken. The answer definitely is yes. We do working with a hyperscale customer and also a big service provider and enterprise, to have our advantage on the chip, especially they have a huge computing power advantage, being used in their environment, whether in the data center, in their campus, or in the service provider network in the cloud. Thanks. Do you think that can be meaningful over time, or is that something that has changed today with NP7? Is that a new message? Yeah. We still in the middle of a ramp-up NP7 with our own product refreshment. We do have a few case working with some big, whether the provider or some cloud provider, try to see how to using the NP7 in their own kind of environment built together with their other product. Like I said, we also kind of feel because NP7 also tightly working with FortiOS, and with other. That's also the reason when we released the FortiOS 7.0, we keep adding a lot of other feature. It's all come from the huge computing power advantage from ASIC, which the general purpose CPU has difficult to compete. We don't have the same CPU as any other competitor. Because the huge advantage, computing advantage come from ASIC, easy for us to add more function in the OS and also apply some of this huge computing power advantage to certain service provider, cloud provider. It's definitely one of our direction going forward, but there's a lot of detail need to work within and also try to see what's the ROI and also what's the position going forward. It's a regular cloud provider, service provider is a huge market we're working with for long term, and also we'll keep the same strategy going forward. I say probably will still take a couple years to be meaningful. Right now, it's still in a little bit early stage. Understood. Thank you, Ken. Thank you. Thank you, Adam. Next up is Mandeep Singh from Bloomberg, and on deck is Sterling Auty from JPMorgan. Great. Thanks for taking my question. I was wondering if you can tell me what sort of product headwind you see on the MPLS side with the workloads moving to the cloud. Who do you view as the main competitor on the cloud workload security side? Is it Zscaler, CrowdStrike, or more of the firewall as a service vendors? John, maybe that's a question probably for you. MPLS is gradually being replaced by SD-WAN, so that MPLS displacement is working really well for us. You saw some of the revenue numbers from Keith. That's just going to continue. I think right now the market is still only 50%. That's a huge market opportunity for us. In terms of the workloads in the cloud, the cloud security marketplace is so fragmented. You've got some native cloud, you've got a bunch of startups doing the container security. There's just hundreds of vendors in there. It'll shake out eventually. Again, we have more of a platform solution in the cloud across the network, the platform itself, and the applications. We'll work with native solutions. We also have partners. I just think it's very fragmented. If you look at the market sizing there, it's tiny still. That marketplace is just really emerging still. Great. Thanks, John. Next up is Sterling Auty from JPMorgan, and then Saket from Barclays after him. Yeah, thanks. Hi, guys. You showed, Keith, in your presentation, headcount growth in sales and marketing. I think the CAGR was around 20% or 22%. Looking forward, the medium-term targets has 17% growth in billings and revenue. I'm curious, what kind of sales and marketing headcount growth do you anticipate being necessary to support that 17% CAGR going forward? Yeah, I think we're very pleased with how the business model works out for us, starting with the gross margin at 80% and staying above 25% as we continue to add sales headcount capacity. The real question is the trade-off between capacity and productivity, as this year plays out and as the next several years play out in terms of the midterm model. I think the headline is that the model works with the hiring that we've shown and the margins that we're delivering. Got it. Thank you. Okay, next up, Saket from Barclays. Or sorry, from Yeah, from Barclays. Yeah, absolutely. Can you hear me okay, Peter? Yeah. Okay, great. Keith, thanks for the color on medium-term targets. Maybe the question that I've got as part of that is, can you just talk about how you envision that $5 billion in billings, roughly, in terms of FortiGate versus non-FortiGate? Maybe related to that, how have you thought broad brush about product revenue as part of that kind of longer-term forecast? I think the split between FortiGate and non-FortiGate, as I noted before, what we've seen in the numbers thus far is an affirmation of the strategy. We expect to see continued affirmation of the platform strategy, and I think that message has been clear throughout the presentations today, including John as well. Looking at longer-term mix between product and services, the second part of the question, Saket, it's just like any other quarter in terms of guidance. The revenue from service revenue is very visible and predictable, and I think you can probably pencil that out and then reverse engineer what that number implies about product revenue growth. Got it. Thank you. Okay. Next up is Gregg Moskowitz, followed by Tal Liani. Gregg, you're up. All right. Thanks, Peter. Hi, everyone. I actually have a follow-up to Saket's question. Okay. Tal, we lost you. Peter, can you hear me? We can hear you. Go ahead. All right, great. Sorry about that. My question's actually a follow-up to Saket's. As workloads continue to shift to the cloud and as security correspondingly moves more towards cloud and cloud subscriptions, does that create more uncertainty as it relates to that $5 billion+ billing target for 2023? Or do you feel very comfortable in terms of kind of getting there, regardless of how things unfold over the next couple of years or so? Thank you. Yeah, I would probably say that regardless of how things play out, keep in mind that in that fabric number that we're talking about, that includes some SaaS revenues and some other things of that nature. It won't be new to us to see some of that mix shift that you're kind of inferring, if you will, a little bit, to the non-FortiGate part of the business. Great. That's helpful. Thanks, Keith. Thank you. All right, Tal Liani, you're up next, followed by Brian Essex from Goldman Sachs. Yes, hi. I'm going to ask two questions that were asked before. The first one is, Saket asked a good question. Of the $5 billion, how much is FortiGate versus non-FortiGate? You gave an answer that is in line with the target, but can you elaborate? In your view, what is FortiGate and non-FortiGate in the $5 billion? Second question, I asked this question before, and I'm going to expand it. Fortinet has a price advantage in the FortiGate products. You're anywhere from 40%, even more than 40% cheaper than competition. What is your main selling point with SASE? Meaning, can you maintain price advantage in SASE versus other SASE solutions? What is the basis for any price difference? If yes or if no, can you also discuss what's the main, basically, selling point, or what's the main advantage versus other SASE solutions that may try to offer a similar service? Thanks. Yeah. I'll run that and then maybe hand off the second part about the SASE pricing advantage as another concept like that to John. I think if you look at those slides and as we're going through the exercise of putting them together, it really becomes very apparent how consistent the business has been. Whether you're looking at revenues by geography, whether or not you're looking at product service mix, whether or not you're looking at the FortiGate versus the non-FortiGate part of the mix of the business. With that backdrop in mind, I would expect that those trends that you're seeing in those charts are to continue. We really don't see something that's disruptive that's going to charge a shift dramatically from what we've seen in our trends, whether that's product versus services or whether that's FortiGate versus non-FortiGate. John, do you want to talk about SASE? Lots of comments on SASE. Yeah, this I can answer. Definitely, the answer is yes. We maintain the price advantage, whether it's SASE or some FortiGate or other product. All come from the huge architecture advantage, the computing power advantage we have over competitors. That gives us a better performance, lower cost, at the same time, better gross margin. For the SASE, we are also the first one integrated SASE Zero Trust into the OS level. I don't see any other competitor doing that yet. It takes a multiple year effort. We first integrate SD-WAN, some other CASB, and then the other part of SASE, we integrate the OS the same thing for the Zero Trust. Which will make it not only we have price advantage, but also easy to manage and has more function. That can be also used in like enterprise, they can deploy themselves, and also service provider, they can easily deploy themselves. Instead of today's solution, you have to have multiple box kind of different OS solution to handle that. It will be more easy to manage and provide better security, more function compared to competitors, and has a price advantage and a cost advantage. If you're very successful with SASE, let's say you're extremely successful out of the gate, does it make an impact on margins? Meaning, your expenses are tied to a relationship with AT&T. Does it have any fixed expense element that might pressure margins at the beginning and later on? Can you talk about how your margin progression would be with SASE? I think if you look at today's SASE compared to some of parts deployed, probably on average, they are maybe like 3x- 4x more expensive. The benefit really is kind of goes to whether the vendor or service provider help them to manage that. With this FortiOS 7.0, because all integrate together, so that enables some enterprise, big enterprise, also some service provider more involved handle themself. That's what helping drive better business model and better margin for whether the service provider or maybe pass the benefit to the service provider or to the enterprise themselves. That's for us, really integrating OS levels, just the first step. We also keeping pushing to the ASIC level. We're keeping increase the performance of the SASE component and make it even better, more kind of a cost advantage compared to the other, whether they have a different box or different kind of part of infrastructure or compare all we have whether the same OS or even go to the ASIC level. That take a lot of investment, but the benefit also is huge in the long term. Got it. Thank you. Thanks, Tal. Moving on. Brian Essex, you're up, Ben Bollin, you're on deck. All right, great. Thank you, Peter. This one's maybe for Ken or John. Particularly as we see the roll-outs of new products and the levers for growth ahead, the catalyst for product cycle tailwinds. How do you think about penetrating the market by segment in terms of entry-level, mid-level, high-end? It looks like you're getting great success at the high-end of the market. Is that where you see things going forward, or is this more of a develop at a high-end and let the technology trickle down type of strategy? Just trying to understand where you might be spending money to more effectively penetrate the market and where you see the best reward. Yeah. I think that's a good question, and also it's a good strategy as direction we're moving forward. We also have a rare chance to have Patrice, our CRO here on the call to answer question. I think Patrice can give some more detail, and maybe Patrice can go ahead. Thank you, Ken. Definitely we had a very strong footprint across the three segment from mid but high and also the service provider space. I would have to say that depending on geos, we are leading all these segment, but definitely the aim is also to capture more of this very large part of the enterprise segment. We're putting a bit more effort here, especially in North America. We realign this segment approach across the board. We leverage, in fact, the technology providing the same kind of architecture for the mid, but the large and very large enterprise customer. The platform that we deliver, that's the beauty of the platform, is that we can deliver on different form factor, both software, virtual or appliance, with a different form factor on the appliance as well. That match all the different element. Definitely we'll leverage this more segmented approach with much more focus as we move forward. Just one comment on the entry, mid, and high-end. Just remember our entry level, we built our own SD-WAN chip in our appliances, and that's driven a lot of that business as well. I think across all of those segments, entry, mid for segmentation and high-end for hyperscale are all very relevant marketplaces we built differentiating technology for, whether it be the system on a chip, whether it be the SPU or the content processor. Great. Patrice, Ken, and John, thank you. Thanks, Brian. Next up is Ben Bollin from Cleveland Research, followed by Fatima Boolani from UBS. Thanks, Peter. Keith, I wanted to ask a question to you about the gross margin and operating margin framework for the midterm model. Could you take us through how you think about the potential levers supporting upside or downside, I suppose, to those figures? Do you have any incremental investments built in your assumptions for OpEx as you have more diversity in go-to-market or supporting fabric? Last is, any thoughts on the productivity of your sales folks as they progress from new to experienced and are selling more applications? Thanks. Again, I would look at our trends in terms of margins and what you're seeing related to the service gross margin as well as the product gross margin. Each successive generation of chip has shown the ability to take cost out of the BOM, and I don't think there's really a reason to think that that's not going to be the case to some extent going forward in the future. Having a "hardware company" that's throwing off 80% gross margin or thereabouts is no small achievement. It's probably a pretty good target for us to have. Then it's just really that we want to continue to balance how much we leave in the operating margin line versus how much we care to invest for other ideas going forward. For us, investments oftentimes it's the engineering team as well as the sales team and the marketing team. When you look at the sales team, you get very different times to productivity, if you will. Our sales people that are focused on the channel, for example, can reach "productivity" very, very quickly, and that could be accretive to that margin. When you're hiring a true large enterprise salesperson, you're probably going to have to offer them a much longer runway. I think important in that is that what you did not hear me say was moving away from the channel at all. I think in Patrice's comments earlier today, he made a similar observation. The channel has been and will continue to be critical to our success. The fact that we're continuing to add sales headcount suggests we're moving away from the channel, but rather partnering more closely with the channel. I don't know if Patrice will want to add some more to that. Yeah, definitely. I can even take the example of the SASE and the SD-WAN leveraging the service provider. If you look worldwide, as John was mentioning, there was a quick, I will say, solution that has been adopted by those large providers, whether it is AT&T, Orange, or NTT in Japan, leveraging this proxy base, covering the work from home needed. Long term wise, they clearly have been asking us to work more closely on delivering and building, in fact, the solution that they can deliver themselves. They own the network, they own the access. Our view is that we want to leverage like we leveraged the very large enterprise reseller, those service provider that we build long-term relationship, which have been deploying SD-WAN. Now as we have SD-WAN and we are in the place of the edge, we will leverage the SASE. That's a strategy that I think will deliver very great results. That may create much more pressure on existing cloud provider that has to build and they have their infrastructure to compete with the service provider while they are not still making any money. It will be a very interesting future situation that will happen. I have to say as well, the cloud services when you deliver SASE or proxy-based SASE is very easy to displace because there's nothing to remove from the edge or from the core network from the customer. It's just an OpEx, so it can be very quickly replaced. It's very more critical to own the infrastructure and to own, in fact, the edge and the core. Then you have a much stronger relationship and long-term engagement with your customer. That's another element where we see we can come back very quickly leveraging all the channel on this new transfer. Hey, Patrice. Thank you. Next question up is Fatima Boolani from UBS. Keith Bachman, you are on deck. Thanks, Peter. Keith, my question is for you. I'm looking at the business and the revenue segmentation where you've got about 40%, pushing up against 40% of revenue from subscription revenue, so your FortiGuard portfolio. Can you maybe give us a refresher on how exactly you're going to market with FortiGuard today vis-a-vis the bundles you have? I think I may have noticed some reconstitution of some of your bundles under user and device and some of these other disciplines. Wondering if you can just give us a refresher on that, and to the extent there's any pricing increases built into your forecast, especially as I think about the price performance advantage you have versus your competitors today. Sure. No dramatic pricing increases are built into the model or into the guidance, pardon me, the targets that we just talked about. Just as I frame out the services conversation, service is now at 65% of our business. That's split roughly 45%, 55% between FortiCare, traditional support, and FortiGuard, the security part of the business. That mix has been very consistent for a few years now. Has not really changed when you look at it, and I don't anticipate that that's going to change dramatically in the midterm period of time that we're talking about. Not really familiar with changes in the bundles. Maybe John Maddison has something there that I'm not thinking about. Yeah, just a small change. We added SOC-as-a-Service to the 360 bundle. 360 is the premium bundle, it has everything in it. That's just a small change there. Otherwise, the bundles, the ATP, UTP, the Enterprise and 360 remain the same. Thank you, Fatima. Next up is Keith Bachman from BMO, and then Michael Turits from KeyBanc on deck. Okay, thank you. I wanted to ask about the non-Forti side of the revenue, and if you could just highlight in the recent 12 months, what have been the key drivers of those revenues? You had the slide up, the Peter slide, we'll call it. What are the key drivers, and how might that change, or what's embedded in your expectations when you put out those three-year targets? What are the key drivers you think of the non-Forti side of the revenue? Embedded in my question is just wondering how important is channel expansion associated with that non-Forti side of either revenues or billings? I think about areas such as CASB, and I don't think about Fortinet as a leader in CASB. How important is it to expand the portfolio with the non-Forti side as you think about the next three years? Thank you. Yeah. Thanks for the question. I keep looking at it each quarter for the product that's going to jump out, if you will. This is the one that is just driving this number. Truthfully, it really is kind of a story of a rising tide lifting all boats. I do believe that when you get into a Secure SD-WAN solution, Secure Branch, where it brings along the switches and the secure switches and the access points, those two combined are probably around a third of the non-FortiGate, probably a little bit less than that. You really have this kind of a mix between software solutions, cloud solutions, and infrastructure fabric. The real growth driver there, I don't know, is about adding more products to the non-FortiGate suite, if you will. It's more about expanding into our customer base. The first sale for the company is not always a FortiGate firewall, but the clear majority of the time it is. I know we're seeing other instances where other products will sometimes sell first. The typical use case is we sell the firewall, whether it's a physical or virtual firewall, and over time, we continue to expand. It really plays back to some of John's commentary earlier today about the platform strategy, about things like vendor fatigue, and CISOs and CIOs going through a phase of rationalizing their security spending, and us being there now and can use the term of being more patient, if you will, and sometimes taking longer to get it right on a common operating system. All those things are driving the opportunity to view the fabric part of the business as an expansion opportunity. Okay, thanks very much, Keith. Thank you, Keith. Both of you. Next up is Michael Turits from KeyBanc. This is probably going to be the last one as we're coming up on the bottom of the hour here time frame. Michael, go ahead. Great, guys. Thanks for getting me in. On margins, Keith, the guide was 25%-27% this year. The Street's at 26%. You just guided up, "over 25%" going forward. How do you think about margin expansion and maybe longer-term margins? Are we there yet, in other words, and that's it on margin expansion on the EBIT side? How do you think about that in the next couple of years? What about cash flow? Should whenever we're seeing in EBIT margin direction, should we be seeing cash flow margins moving parallel? I think we framed the conversation, starting with the idea of balanced growth and profitability, and I sometimes like to say we've been doing it for several years, but I think the reality is you can see that Ken's been doing it for 10 years, if not 20 years. We've been, I think, very straightforward that some years we see the opportunity within that framework to tilt the bias one direction or the other. This is a year that we think the tilt is towards growth. As you start looking out at 2022 or 2023, I don't know that we're really at this point taking a position, if you will, one way or the other, in terms of whether it's a year that's more conducive to growth or a year that's more conducive to profitability. That's kind of a wait and see, if you will. I don't think that it's just going to be a linear world for us in any way, shape, or fashion as we go forward. Of course, this free cash flow margin, I think really does, it ties to the growth in the billings number. It also ties to the continued improvement in that operating margin number. As such, it'll be contingent upon where we're at within that framework each year between balanced growth and profitability. Thanks, Keith. I would add to that, I think the other part of that long-term target is the Rule of 40, and the fact that between revenue growth and operating margin, we would expect those two to add up to at least 40, as they have nine out of the last 11 years, and expecting to in 2021 based on our guidance. With that, I'd like to thank everyone for attending today's Analyst Day. As I noted earlier, a replay of this event, along with the copies of all the slide decks and transcripts of the events, will be posted on the investor relations website hopefully complete. I will get them there as quickly as I can. With that, thank you very much. Have a great day. If you have any follow-up questions, please feel free to reach out to me, and I appreciate you for attending. Thank you very much. Have a good day.
Loading workspace