All right. Fantastic. We will go ahead and get started with the Fortinet session at the Goldman Sachs Communacopia + Technology Conference. I'm Gabriela Borges. I cover software here at Goldman Sachs. Delighted to have on stage with me, Ken Xie, CEO and Co-Founder, and Christiane, CFO. Thank you so much for joining us today. Thank you for hosting us. Thank you. So Ken, one of the ideas that we're exploring real-time is this idea of a cyber frontier model within a cybersecurity company. The thought process is, as a cybersecurity company, you have an incredibly rich proprietary data set that you've been hoarding for 10, 15, 20+ years. Because ML has been at the heart of Fortinet's roadmap- Yep. ...since the time of its founding, how do you think about what a frontier model, a cyber frontier model within Fortinet could look like? We definitely develop a lot of our own expert model. Also, probably maybe not a separate company, also build our own infrastructure, including the global data center with GPU, and already launch more than 20 AI-enabled product, more in the secured operation side. Like I said, the data is super important. We have a majority, more than half the global network security deployment, give us a lot of data to analyze at the global intrusion attack landscape there. So that also fit in our own kind of infrastructure model, the kind of AI infrastructure we feel we have pretty good view of what happening globally. But definitely also you need to use AI to find or protect the other AI, which we feel is driving the huge growth going forward, which is really the new market we have not seen since we did Analyst Day two years ago, which is a huge opportunity, including both the enterprise level AI security, which we see a lot of internal segmentation, which is really the machine-generated traffic actually is a huge increase. At the same time, some service provider, especially the neocloud provider, I hope that market for AI service provider neocloud probably can be bigger than the traditional carrier or some kind of a security service provider, because definitely AI changing the whole landscape, both in enterprise, in some service software industry. So that's where some AI service provider will play more important role, especially in the security. Let's pick up on this AI service provider thread. When I think about one of Fortinet's strengths with the cloud cycle, it was with the telecom service providers, and that has been a core part of your business for some time because of the performance and cost benefits that Fortinet delivers. Talk to us a little bit about what that looks like with the AI cloud cycle now, and maybe as part of that, the opportunity that you may have with neocloud, for example. Yeah. I think, first, just like SASE, we always believe there's a bigger market for service provider or even on-premise SASE or Sovereign SASE, the same thing for AI. Besides the frontier AI model, there's always some service provider, there's always some kind of on-premise AI SASE kind of security, because they want to keep the data in their own kind of infrastructure process locally. Not just some international, but even some big company in the U.S. have the same thinking. That actually drive the AI security, also drive some kind of a neocloud. It's similar like a Sovereign SASE. We feel it's a huge market and bigger than the cloud-only SASE by some early SASE provider. The same thing for AI security. The neocloud had another layer of AI service compared with some hyperscaler. That's the part we feel eventually will drive more security need for whether sovereign AI or some other local AI security market. Probably Christiane also see a lot of, especially from Europe. Yeah. There are certain regulation. I think that the opportunity for us, because we develop a technology stack that others can operate, whether it is the Sovereign SASE stack or whether it is the infrastructure security for AI clusters. We see us well-positioned for more of those regulatory environments where sovereignty is mandated. Especially in Europe, there is a lot of initiatives right now to build out AI infrastructure through local companies. We want to be part of that journey, the security journey for AI infrastructure, similar to how we are partnering with global telcos on building out Sovereign SASE. That has been a theme for Fortinet for a long time, that we partner with others to help build out infrastructure. I think right now it is an inflection point with more infrastructure going on-prem, not only going to the cloud, that Fortinet is well-positioned. Especially on the AI side, not only for service providers, also for enterprises. Cloud AI frontier labs are expensive, and so more and more customers are rethinking how much they should do themselves and build out their own GPU clusters and secure them and deploy open source models versus using AI through the frontier labs. I think that is going to be a long-term theme that is going to play out over many years. There is one key difference compared to the traditional carrier service provider to the neocloud provider. Yeah. The neocloud make decision much faster. They make decision in months. You can see we give example in earning, like Q1, there is neocloud. One of them, they evaluate, they decide to purchase the same quarter for a few million. Q2, they study 5x or 10x bigger. You can see they make decision in months compared with the traditional carrier service provider. They take years to evaluate and make decision. We feel it is pretty strong growth, but also in the early stage. Maybe let's talk about early stage growing to the longer-term dynamic that Christiane mentioned here. Tell us a little bit, Ken, you just mentioned, I think you said neocloud, they make an initial decision in 1Q, and then you can see 5x-10x bigger of a deal in 2Q. Did I understand that right? Maybe just talk a little bit about the progression on what you're seeing in the pipeline. A lot of us from the outside, we try to track CapEx. Is that the right way to think about what the trajectory of Fortinet's data center neocloud business could look like over a three-year timeframe? Or any color you can give us on how to think about this opportunity. It's still pretty early stage. Right. It's difficult to compare to the traditional carrier service provider, they have 20, 30 years or whatever the history we're working with them. We know their model all this quite well. But neocloud, they're still in the ramp-up stage, but they have a huge capital. They have a huge infrastructure they try to build. I feel it's still more in the early stage, more protect their own infrastructure or build up. If you look on different layer, they're mostly in the infrastructure layer right now. They're not quite in protect the model application there yet. But once they suddenly offer the service in the higher layer, definitely there's other wave opportunity. Right now, they're more building infrastructure, protecting infrastructure. Could be come from a utility, energy OT layer, could be the infrastructure of this layer. But they are making decision, they are move much faster. They see the demanding for their AI cloud service is huge. I talked, I think in the Q1 earnings release about building out reference architectures. The neocloud won't buy and put it on the shelves. They will buy firewalls and related services as they deploy the data centers. It's critical for us to be in early, so that we can grow with them. That's where most of the mid-size neoclouds are probably more likely to be our customers because they won't have their custom components, proprietary components. Yeah, that's where the ASIC advantage, perform advantage are huge compared to other competitors in that space. Christiane, you started talking a little bit about enterprises running more agentic processes, more open source, more open weight models in-house. My next question for you is, how do you both think about network traffic at your existing customers? Maybe there's two pieces. There is the classic firewall. When do you start to get a bottleneck in throughput because agentic activity has gone up? On the Sovereign SASE piece, are you already seeing a change in network activity because of agentic, and what are the implications of that? Maybe we'll do the data center, the classic firewall, north-south traffic question first. The classic data center, I would say customers just start building out their own infrastructure as they see cloud costs increasing month over month now. As they also see what do they want to do with AI. We have the partnership with NVIDIA, right? We are securing GPU clusters. We are also doing it internally, and that's a big market that enterprise customers are increasingly interested in now. On your second part of the question was on the SASE side, right? Yeah. Are you seeing an impact in your SASE network? When you look at your network capacity versus the amount of network traffic, are you starting to see the trajectory of network traffic change because of agentic activity? I put it this way. Probably the recent AI-driven traffic is more like the east-west traffic, whether within the data center, within the enterprise. Also, a few months ago, probably it's well-known, is the first time machine-to-machine traffic overpassing the human-to-human, human-to-machine traffic on the whole internet now. That's where the enterprise, they definitely want to have a better visibility, better control, especially in their own data center campus, what kind of traffic, what kind of things AI agents doing there. That's where we see increase of this new internal segmentation, replacing the traditional network device. That's where the convergence we talk about for 20, 30 years starting accelerate by this AI kind of adoption there. There's also a lot of new area, which whether the neocloud, there's the Sovereign SASE, that goes beyond the traditional network security doing there. That we see is a new market opportunity compared to the traditional network security or replacing modern network security or SD-WAN. This is where we see it's a new market, especially the on-premise Sovereign SASE as compared to before the cloud-only SASE. From our feedback, most enterprise like this hybrid model. They do need on-premise, they do need some kind of Sovereign SASE, but they don't have much choice before. Somehow, when we combine this SD-WAN SASE firewall together in the same OS, can be deployed on-premise in the cloud or with a service provider, it's opened up huge opportunity for us. We see quickly not only the new market, but also suddenly replacing some of the existing player. To the point, customers are buying higher FortiGates compared to the past. How do we assess this? Basically, the average ASP for us is increasing, yeah, net of price increases. So we see true ASP increases, which suggests that within each band, low-end, mid-range, and high-end, they are buying bigger devices now. What we don't quite know, of course, is whether they are buying bigger devices because they're planning for more network security traffic or whether they want to deploy more of the functionality, whether it's SD-WAN, whether it's quantum encryption, whether it's all the AI visibility that comes with the new OS. That's hard to say, right? But we definitely see that customers are preparing for more requirements, more cybersecurity needs, and all the functionality innovation that we are constantly rolling out with our OS versions, yeah. I am curious how we think about. It is a little bit of a pricing question. You are talking about an upgrade cycle where previously if I would have bought a firewall at X gigawatt capacity, I am now buying one size up. What is the typical pricing delta between the different SKUs or cohorts? Is there a way to frame that? It is very different by low-end versus high-end. The high-end has a big differentiation between the 1,000 model and 3,000. Right Versus in the low end. But it is meaningful from an ASP perspective. Right. Yeah. Yeah, that makes sense. What is the AI visibility that is in the new OS? In the FortiOS, there is a lot more functionality as to AI visibility, where is the traffic going, which model traffic is sent to, what type of auto contextual, is there personal data in the prompt. A lot more visibility that we are providing through the FortiGate and related products that customers may want to deploy when they have more agentic traffic, and they want to sanction the AI use a little bit more in their company. Also a few because some AI models that in market have found a vulnerability hole there. Working with all the frontier company, try to quickly helping customer defend this kind of AI-found vulnerability. I say it is still probably most of this vulnerability is still not in the wild yet. On the other side, we keep importing customer. Maybe you need to quickly patch in quickly whatever, but I feel some customers still behind. That also probably some other customer, they just try to buy some extra layer protection, whether by internal segmentation or protect the new attack surface or even add a multiple layer defense. Like network security, usually the first layer, because if you have more vulnerability in whether OS layer, browser application, definitely the networking can help in defending the first layer. That we see also kind of increase the business for us, especially in the enterprise space. How much has this changed in buying behavior? We will talk now about some of the cyclical dynamics in your business as well. I am curious how much of a change you have noticed in customer behavior since early April when some of the more advanced frontier models first came out. How much of some of these dynamics that we are talking about can be pinned or isolated to that type of dynamic? Definitely that has raised some awareness. Someday, some AI, whatever, security outbreak may happen. That is where we do pushing customer need to be upgrade sooner, but they also have their kind of balance because there is certain operation cost to upgrade. There is a certain budget or some other things they need for the extra protection there. I feel we are keeping working with them before the bigger whatever things may happen. In general, I would say these discussions have helped with advancing cybersecurity discussions to the executive level. It was there before, but now I think the need for doing something if you have aged environments is very clear. It is a combination of factors. It is not only missiles, right? It is also the nation-state attacks, whether it is in the U.S. on the water infrastructure, whether it is internationally from Russia on the infrastructure in Europe. There is a combination of companies being afraid of more attacks, less time to identify them from AI, and then also the threat environment increasing from other actors that are out there in the world from geopolitics. Both sides, I think, are advancing discussions on investments in cybersecurity and how to best secure your infrastructure against these accelerating threats. Very good. All right. Let us talk about the memory environment. Bring us up to speed a little bit on what you are hearing in the field from customers, specifically around pull forward on the firewall side because of memory pricing. I feel we are more different compared to five years ago, the supply chain issue. That time, we definitely see more pull forward and also the increased inventory in the channel, even in the customer side. Since then, five years ago, we did a few change. Once in, five years ago, when customer buy the hardware, you have up to one year to register to enable service. We shorten that 1- 90 days now. That is where making customer no incentive to buy anything beyond 90 days because otherwise the service will be suddenly applied as a channel. It is a FortiCare service. The second one, we also closely monitor the channel inventory, so we do not see increase in the channel inventory. That is where avoid the pull forward and which happened five years ago. But also we see some component, like memory, where we're more using the DDR5, DDR4 compared to the HBM, the high bandwidth AI using kind of memory. So that price also kind of stabilized a little bit now compared to six months ago. There's huge increase. That also kind of stabilized the whole supply chain a little bit. On the other side, we always keeping the, we call the same growth margin, health and growth margin. Different than some component company, memory company, you see their growth margin, big increase or big drop. But for us, we are pretty maintain the same. That's where when we see the component increase, we increase the price. But five years ago, we also decreased the price when we see the component price drop or the kind of shipping cost drop toward the end of COVID time. That's also, I feel we built some good trust with our supplier, with our customer partner. We just want to maintain the same growth margin, and we are just by based on our own supply chain cost changing. I think so far working out quite well. At the same time, we do want to maintain about six months inventory, as to meet certain rush order or big surge of demanding something like that. I think that's also working well with us. And we do working with all the components supply, the manufacturer directly instead of go through a third party. And our own ASIC, we're keeping about one year inventory. The system level, we're keeping about six months. So we have some buffer. We feel we can help and smooth out the whole things. Let's stay on this idea of channel inventory. So the 90-day dynamic makes complete sense to me. The channel inventory dynamic makes less sense to me because, of course, the channel is actually selling through because customers are actually buying. Maybe just explain why the fact that channel inventory is low suggests to you that there's no pull forward. Because the 90-day, right? Sure, yeah. The two go together. On other side, we also discourage channel to buy too much inventory. So we can control whether the discount or some incentive, make sure they just have enough inventory to grow their business instead of just sell. That is keeping more inventory because the price may increase. But we also told them the price may drop. A few years ago, we do drop the price. So if you have too much inventory, you are also probably stuck with some of the inventory. That is where we told no need to pull forward or some extra inventory would not help. Yeah. I know none of us are memory analysts on the stage. Your comment on pricing coming down is a really good one because it is based on what you have seen in pricing. I say stabilized because we are- Stabilized. Yeah. Sorry. I mean, historically, you've adjusted pricing both up and down. Yes. Yes. My question for you, and maybe it's more of a how do we think about this? Most of the data points we see around hyperscaler CapEx and supply demand, for example, suggest that things may get worse before they get better. I guess my question for you is, do you envision a scenario where memory pricing goes from being stable to actually Fortinet being in a position to lower prices at any point in the next one year, two years, three years? I see the price increase of some shortage more in the HBM, which is more like a high bandwidth AI. Yeah. This is a good point. Because we are more using DDR5, DDR4, that's more- They're really point. ...traditional at the system level. There's a lot of smaller manufacturer, memory manufacturer doing that DDR4, DDR5 compared to the HBM is only a few bigger manufacturer, memory manufacturer doing that. So in that level, seems a little bit more stabilized compared to the high HBM memory. Yeah. Christiane, you have the wonderful job of setting expectations, not just for the second half of the year, but also longer-term. Fortinet just put up a 52% product growth number. Yeah Which is incredible. In the past, you've talked about, look, in a normal year, product revenue likely grows north of 10%, if I'm remembering right, there is the share dynamic that we've- Yeah. ...all talked about. Christiane, tell us a little bit about how you would advise us to think about the normalized growth rate of Fortinet over the next 18 months when you're going to be comping the 52% year-over-year number. That's a good question, it's a difficult one. Overall, we see a good demand environment. We think there are continued tailwinds from all markets, whether it's AI, whether it's Sovereign SASE, whether it's regular SASE, OT, quantum, it plays out across the board, right? That's also why we're saying we're guiding one quarter at a time because there are so many dynamics playing out right now that while we have visibility of how the pipeline shapes, it's hard to say whether decisions are accelerated or playing out in normal course, right? From a long-term growth perspective, we had benefits right now from pricing on the product side, which was a little bit higher than on the overall side, of course. But we saw great unit growth as well. It is not just pricing related, but if we assume the pricing dynamics are a little bit more consistent, we will not have that same impact next year. I think that is where we are still evaluating what more from a unit growth perspective, how much more can we grow there, and then how does it translate into billings. We are also very focused on attaching more services, selling more services, and building out that portfolio because the service revenue is what renews and gives us long-term growth as well, and the penetration in the customers. We are not coming out with 2027 numbers yet. I think we are feeling good about 2027, but we need to assess the unit volume in the different product segments as well as the service attach rates and renewals and how we come out there. I think what we feel good about is that we are outgrowing markets. Right now the growth for cybersecurity market looks really good and with more focus on on-prem and sovereign deployments as our customer base is extremely global. I think hardware has seen a resurgence, and so I think we are well-prepared. Well, maybe allow me to ask you about 4Q, where you have given implied guidance. Talk to us a little bit about, we get this question well, the implied guidance implies that unit growth slows from something that is much closer to 52%- Yeah. ...to something that is in the single-digit range. Right. Then you layer in pricing on top of that. It is a very dramatic deceleration. Help us put that in context. I think that we were very clear that Q4 was not yet factored into the annual guidance from a full perspective, right? Because we do not know how Q3 plays out. After Q3, we have better visibility. We continue to see strength in the pipeline progression and also on the demand side. But you will hear it after Q3. Very fair. Okay. One of my favorite times covering Fortinet was when you announced the Enterprise bundle, and you upgraded from the UTM bundle. This was back in 2015, 2016. It drove such a beautiful upgrade cycle on the services side of your business, which is very high gross margin. Yeah. So Christiane, you sort of alluded to this here with attach rates. Tell us a little bit more about, there is a new bundle that came out recently. Right. Talk to us about the upgrade cycle and what is the premium. With UTM to enterprise, it was 65% the cost of the box going to 80%, so we could do some really neat math around that. What does that look like in today's upgraded bundle cycle? We are still selling a good share of higher-end FortiGuard bundles, but not everywhere. What we did with the SD-WAN Bundle is actually something that I think is very unique. We are selling to our customers the SD-WAN services that would typically not buy FortiGuard, but we've also embedded what we call a SASE starter license. For customers that are deploying SD-WAN, it's so compelling to also deploy our FortiSASE solution because it's the same OS, it's the same policies, and it's very easy to deploy. Now if they have the starter license, they can test it out. Depending on the size of the FortiGate, they get 10- 15 users. They can use it in the IT department. If they see how easy it is, how efficient they can manage it compared to having a cloud-only SASE SSE solution, our goal, of course, is to upsell them when the competitors come up for renewal, and then it's an easy rollout because they were already able to configure it all. That's where I think the new SD-WAN Service Bundle is not only selling more services to customers that would have traditionally not sold as many, it's also our ability to get in early and show the value of our SSE OS FortiSASE solution, and then upsell as the customers may want to transition. Because every customer is afraid of switching, right? You don't want to make a big investment when you don't know how it works for you, but if you can test it out and then you see how easy it is, then the switching costs have been reduced quite significantly. There's other additional surveys we're going to launch later this year, more related to the AI security, more related to the SASE, especially the Sovereign SASE, on-premise SASE service, which we feel also will help in drive the additional service, which already starting deploy in the field with the new FortiOS 8.0 we launched early this year. Order of magnitude, how do I think about the pricing uplift from some of these dynamics, like the FortiSASE starter kit, SD-WAN Service Bundle, AI security bundle? The bundle we launched for the new customer, I think a 50% or 55%. Right. I mean, 20% is FortiCare. Yeah. ...that's normal, right? Typically, it's an additional 35% full cut that we are targeting customers which would have normally only bought FortiCare. That's I think the beauty here. Then upsell from there if customers like FortiSASE. The 35% is for the SASE starter kit? No. No. It's the- SD-WAN level SD-WAN services that make one SD-WAN more efficient. Customers can use SD-WAN within the OS, but then there are certain extra services they can deploy to get more visibility. Yep, I hear you. Then when you figure out what the configuration looks like on AI security, there would be another potential uplift. Correct. Off of that 30%. Yeah. Very good. Maybe we will end here with a question on the trajectory of services revenue. Every quarter, Christiane, you get the question on, well, product revenue did this, services revenue did this. There is lag effect, it is accelerating, it is decelerating. Maybe just level set for us, how do you structurally think about the growth in services? Could we be in a period of acceleration for even though product revenue is likely going to decelerate from the 52%? How do we think about the acceleration cadence for services? Service revenue is a combination of the product stack, right? Some products have more services, and some products have fewer services attached. Then also the unattached services. I think Fortinet is attaching. First of all, we sold more FortiGates, and Ken has been talking about all the markets that we are playing in. I think the growth for FortiGates will continue to be there, which allows us to attach more services. We are launching new services, and we also have newer software, like with the FortiAI gate, which is sold as a software subscription, which then also increases our ability to attach services. I think we're preparing for more service growth, right? But some of it comes with additional hardware growth, and some of it is attaching more to existing infrastructure. Fantastic. I think we can leave it here. Please join me in thanking Ken and Christiane for their time. Thank you so much. Thank you.
Loading workspace