Hey, good morning, everybody. Welcome to our Fortinet fireside chat. We have the honor of having Christiane Ohlgart, the CFO of Fortinet; Anthony Luscri, I hope I said that correctly, from IR; and [Aaron] with us today. If you have any questions, I hope we can keep this interactive. There is a box up there on the right to submit your question in, and then, I will fold it in. In the meanwhile, kick it off with one. So, we just finished the quarter, and can you walk through some of the highlights and what stood out to you the most during the quarter? It was really a fantastic quarter. Yes. No, I agree. It was a fantastic quarter. What stood out, and it really started, I would say, last year already, but that we see broad-based demand across all our geos. Very successful across the world and accelerating demand for hardware and build-out of networks. That is where some of the growth in FortiGate's hardware growth was extreme, I would say. Not that we have not had it years ago, but not lately, s o, it was a great quarter accelerating from prior quarters, and we continue to see good demand for multiple use cases that whether it is OT, whether it is the build-out of SD-WAN networks and improvements, whether it is the build-out for AI infrastructure and AI-enabled networking. Also, the fact that basically all our devices improve your security posture, even a switch or even an AP shows that this one OS and one security fabric is really resonating with our customers. I think that the Q2 showed nicely how it all comes together when demand is there. Yeah. Yeah, it was really impressive. One of the things I wanted to ask on Unified SASE, g rew 35%, now represents 1/4 of the sales, and FortiSASE's billings more than doubled. So, which part of the Unified SASE portfolio is doing the heavy lifting? The SD-WAN networking, the cloud security, or the on-premise enterprise deployment? I was trying to really get a better handle on that b ecause it seems like you have a large SD-WAN install base. We do have a large SD-WAN install base, and that's where we are benefiting because the customers have everything they need to extend it to their cloud platform, and s o, get a unified posture for in-network and remote users. We continue to embark on that story and trying to sell more of the SASE, but also, depending on the needs of the customer, making it available with more functionality that allows them a Unified SASE play. This is where Ken created that SASE firewall market, where he really wants to say it's not either/or. It is a big market. You need functionality at the edge of your network, which our OS can do that is similar to what you do in the cloud with the SASE platform. But you don't always need to go out to the cloud. Also, as our competitors start selling hardware to improve their cloud SASE platforms, it's a big market that if you want to have unified security for your users, you need both. That's where we will continue to innovate and believe successful in the market. We were late with the cloud, but we've always had the hardware. Our competitors were faster with the cloud, now, they need some hardware. So, it's playing all in our favors. Yeah. Then, on the metrics, which metrics do you think we should focus on more? Billing ARR on this? Because you get both, and a lways, when I do the post-earnings call, I try and figure out which one I should really concentrate on. I mean, they're both important, but. Yeah. I think they signal different parts, what's going on in the business. Yeah. Billings is current quarter activity, but i t's also impacted by the mix of hardware and services. ARR gives you a good impression on how successfully we are selling services and growing our service portfolio in all the different stacks. It also gives you, in contrast to revenue and in contrast to billings, a little bit more of an idea, is this a more service-centric pillar or is this a more hardware-centric pillar? I think between all these metrics, you get good insights into what are we selling. Okay. Well, that's fair. Then, Ken described the combination of secure networking and unifying SASE as the SASE firewall, which I thought was really interesting. And that's over $2 billion growing 34%. Is he framing that because of the buying pattern you're seeing or what's the reasoning behind that? Yeah, I think the reasoning behind it is that we are seeing success in the combination of hardware and software or hardware and services, and with sovereign SASE being an important aspect in Europe, yeah, and more legislation around sovereignty, I think it's an important differentiator that SASE is not only a cloud-delivered service, but that SASE is a broader market that includes the firewall at the edge of the network in the data centers, not so much for SASE, and a lso, our continued innovation and what do customers really need when they want to have a holistic security picture that also has low latency and good speed for security. If you heard about our press release that we launched in combination with earnings around the outpost functionality, it's actually very innovative. Even though we are using a firewall to do the work, it's functioning as a SASE PoP that is controlled by SASE but then can be used in very rural areas or very locally. So, you're reducing your dependence on cloud PoPs that may not be close to where your customers need SASE security. So, we are continuing to innovate between software and hardware and the cloud posture to make sure that our customers get what they need to secure their users. Yeah. Ken mentioned that SD-WAN and SASE bundle was launched a few months ago and is growing very strongly. So, this bundle raising per dollar deployment, I mean, I thought that was pretty interesting way to bundle it. Yeah. It's a combination of factors I think that is important. One is in this SD-WAN bundle, we are including all the services that are improving your SD-WAN functionality and security. You don't need it necessarily for SD-WAN technology, but it improves what you want to do. It speeds up the traffic and so on. The other part is we added kind of a teaser license for SASE. Customers don't need to go through a buying cycle to buy the cloud SASE, just if they want to roll it out to the whole organization, they will probably need more licenses because this teaser license per device only includes, I don't know, 10 or 20 users. It's a good way for customers to explore our cloud solution if they have a competitor. Yeah. And because it's so easy to roll out the policies from the firewall to the cloud SASE, we believe it's a good way to potentially grab more market share. Yeah. It's a really good starter package, but you can insert it in maybe a competitor domain where they're. Exactly. Pretty dominant. Yes. Okay. All right. So, then, I shouldn't think that there's going to be a huge jump in billings or ARR right now because of that. It's just a minimum, right? But it's a good marketing opportunity. Correct. It's a good starting point. The increase in ARR, we will see over time from the SD-WAN service attached to the firewall. But then, the driver for SASE growth will come from upselling on these starter licenses. Yes. Very clever marketing ploy. All right. Then, on the SASE billings grew 35%, and the Unified SASE ARR grew 18%. One of the things I had some people ask me about was that because the contract length or the hardware content that drove the difference of those two metrics? So, it is mostly the hardware component. O kay. Yeah. That drives the difference between what you see in ARR growth or service growth and what you see on the billing side. Yeah. Okay. Then, FortiSASE adoption reached 19% in large enterprise. That was one thing I have to say when you first launched it, because you have such a large mid-market base that I really felt that that would be where it would be attractive, but you have done really well in the large enterprise. So, what is happening on the AR side of that? And then, who do you see the most in these bake-offs, or who are you taking share from on the large enterprise with your FortiSASE? I would say, yeah, in the large enterprise, we typically need to displace competitors, and it is a little bit harder. Yeah. Yeah. Who are we taking share of? We are taking share in customers that have a very distributed environment. If you are cloud-only, you may not benefit as much from Fortinet, and this is where I think, a ctually, larger enterprise is our sweet spot because they are not born in the cloud. Most of the larger enterprises have their own data centers. They have multi locations. So, a different setup. Smaller entities, SMB, t hey do not need as much security, and they are probably more born in the cloud and fine with some of our competitors now. Yeah. Yeah. It is a gradual upsell motion, and I think we have said it in the past, about 90% of our SSE customers are in our installed base, so upsell from existing SD-WAN solutions. So, we continue to do that. Yeah. Yeah. Then, the other one is that Ken sized the sovereign and on-premise opportunity to be 2x- 3x the cloud-only market. So, what do you expect in financial results over the next two years, though? It confirm that market size or show your traction, which we look for in metrics. I mean, there will be no necessarily new metrics related to the sovereign SASE. You will see it in hardware growth; you will see it in ARR growth over time. And s ince, I mean, typically, who would be the buyer of sovereign SASE? It could be large enterprise, but in general, I would say it's the large telcos that want to set up sovereign environments for specific customers, f or example, public sector customers or that want to compete with the cloud providers, which for them, right now, is harder because they can only resell that. And we believe because we have good relationships with the telco customers, that this is going to be a good growth market for us. Yeah. And then on your pipeline, would you say that it's equally split between the sovereign opportunity and the hybrid? From a pipeline perspective, I would say sovereign is still developing. So, the hybrid is still a bigger part of the overall pipeline. Specifically, sovereign is also more, right now, a European play where regulations are going to drive that. And then, once that's successful, I think more countries may go down that route because they want to be in control of the infrastructure. Well, one thing I've always noticed, and I think it came out back in 2025 when you did the presentation in New York, and you talked about international, and you brought in all your salespeople from Europe and Latin America, and Canada. I left that so impressed on how much share you really have in Europe and Latin America and Canada. And how did you end up having such a good ground gain in those different regions? I think our focus has been on global sales for a long time, and many of our competitors have focused first on the U.S. And so, it has allowed us to grow faster internationally, and that's why if you look at the sales force from a people perspective, we are smaller in the U.S. compared to our competitors, but we have more people and also more channel partners in many of the larger countries abroad, and t hat has given us an advantage. Of course, I mean, if you're ahead, others are trying to chase you. So, it's always a game, right, where the markets are. No, I understand. Your international always stands out every quarter. Yeah. Okay. Then, we're switching over to firewall and hardware cycles. So, the product revenue grew 52%. That was just phenomenal. Second consecutive quarter acceleration. So, I want to kind of dive into the number. Was it unit growth versus higher prices? Had you just had that price increase or what was really you think some of the drivers behind that? Demand, refresh? I was just trying to get in more. It is clearly demand- driven, and we couldn't achieve that growth without unit growth and without the demand. That said, and this is why I had this in my prepared remarks, what we saw in addition to unit growth, and even if we normalize for price increases, we saw ASP increases for the hardware, which means that customers are moving to a little bit bigger boxes. That's a clear trend that we've seen, I think, since Q4. We believe that AI plays a big role in it, not necessarily only for AI security, but also for traffic. Customers are looking at upgrading their networks and making them more performant because they know there will be more network traffic in the future. Got it. Then, the other thing that I noticed when I do my quarterly channel checks with everybody, all your VARs, one thing that comes out is the CVEs. You have had several of them. You have patched them. I get feedback from the channel that, well, we are still buying, that you guys are quick to patch, that you are fine when you are quick to patch. And that has been like some of the bear case on the stock. I am giving you an opportunity to kind of talk about your CVEs and do you see it impacting sales? I know last quarter, a couple of people were worried that maybe they would not buy as much because of the VPN one, but I am just letting you kind of tell me what you think of that and how fast you patch it, and it really is a pipeline problem or not. I think what we saw at the end of Q2 was not a new vulnerability, right? It was really cyber hygiene, and then, our competitors are always good to blame Fortinet on their CVEs. The key challenge that we have is we have so many products and we have so many firewalls that we have sold that are being used that, of course, Fortinet is a prime target. It gives everybody a good talking point when somebody has a problem. It does not necessarily need to be a new vulnerability. That said, I think the reason that on the one hand, we still sell very well despite having vulnerabilities, because we have been very open and upfront with the fact that we are searching for vulnerabilities to improve our code quality and to patch them as quickly as possible, versus others that may not have that rigor internally to find problems in their own code. We will see what happens over the next couple of months with some of the Mythos capabilities or similar AI capabilities to identify code issues faster. Yeah. But Fortinet has been extremely transparent. We have signed up to these transparency guidelines. We patch fast. We are constantly reviewing our code to make sure that we are ahead of the game. But, that said, we have a lot of customers, we have a lot of devices running, and not every customer is as diligent as a highly regulated enterprise customer or public sector customer with their patching, so t here is always risk for us in our customer base that certain vulnerabilities can be exploited. We are working on a number of different initiatives, including virtual patching, through the IPS engine to save the devices until the customer patches them themselves. It is a constant worry of ours. We need to keep our customers secure, but we can only keep them secure if we validate our code as well. We want to be the first ones to find something. Yeah. Let's talk a little bit about memory. Ken said on the last call that you adjust prices monthly up or down based on the component cost, such as memory in order to keep the gross margin steady. Since the memory costs have leveled off, how are you thinking about pricing changes for the rest of the year? In that last recent increase, how much did that add to billings growth? I know I've had a couple people ask me that question. As we said, the price increase to billings growth was high single digits, and t he reason that we can't be more specific is because we really need to look at what have we been selling. Yeah. In the end, it's a mix of software and hardware. Hardware, of course, had more increases, but all the service components did not necessarily increase. If you look at the billings mix, it was high single digits. On the price increases for hardware, we still see the kind of shortages in the market for memory components. While the prices have leveled off or stabilized, it's still hard to get memory components. So, there may be certain parts that still, you need to pay expedite fees or something to get enough memory, and we are evaluating on a product-by-product basis whether we need to increase the price or not. But also, of course, Fortinet always wants to remain competitive, and we are evaluating extremely well what the competitors are doing. I mean, they've been increasing their prices also, right? Everybody has the same situation. Yeah. All right. Then, a little bit on the refresh cycle which I have a little bit of a hangover on. What share of the unit shipped in the 2020 to 2022 window that have already been upgraded? Are you seeing the firewall cycle shortening from the five years because of the amount of traffic? It seems like there must be, you said earlier people are moving to larger performance throughput boxes, so h ow much has been upgraded? You have another upgrade cycle for 2027 too, but it does not seem like the refresh is really the number one driver of your revenue either, right? No. The refresh is not the number one driver. The refresh or upgrade cycle, how we wanted to frame it a little bit more carefully is something that gives us good talking points and also inspect with the customer whether they need new architectures, whether they can expand, whether more products that we can sell. Fortinet will always have customers that have devices they need to upgrade. I think we have seen good success that our existing customers continue to buy from us. But you also have very different use cases that have, I would say, different useful lives. OT has a little bit of a different useful life than maybe network security b ecause you typically put a device out there into a, let us say, manufacturing plant or into a pipeline to secure pipeline traffic and so on, and these do not always get upgraded every five years. You also have different cycles for APs, because APs with a Wi-Fi 5, 6, 7, 8, I mean, there is going to be continuous upgrade and refresh cycles. And w e are rolling out more security into these devices b ecause, for example, an AP can also be a SASE access point for us. For us, every device has a security posture, and so that is where we see good success, our customers adopting not only firewalls, but also the adjacent devices that help them secure their networks. Yeah. Right before earnings, you announced the AI internet firewall, the FortiGate 1200G. Is that targeted for these neocloud players or large enterprise, is that the target market for this particular box? I think it's a large box, but it's not the largest box. So, depending on the size of your AI deployments, you may want to default to that, but there are bigger boxes for way bigger data centers that we have. Right. It's just one of the newer ones that we pointed to is good for AI security, yeah. And you did talk on the earnings call about the AI data center buyer, and that they came back again. So, are you ramping up a new overlay sales force for that, those particular neocloud buyers, or what's any change in your go-to-market to address them for this particular appliance? Yeah, we are definitely looking at hiring more sales employees, and also potential overlays to address AI build-out to understand what the customer needs. But this also comes together with working with NVIDIA, because they are very much involved in selling the chips, and so getting in on early on these opportunities. And we just announced this morning also a small AI acquisition. Yeah. And so, we will definitely be on that AI journey as much as our competitors. It just always we build internally, and then we add and tuck in acquisitions to advance our roadmap. Yeah. The other thing you did really well last quarter was secure networking. It seems like with the OT, the AI data center, the LAN E dge, and campus, it seems like you sold a lot of switches last quarter in some of these deals. That was actually, I mean, I always knew it was part of your program, but any commentary that you can tell why that was, it seemed more prevalent this quarter than other quarters. Is it the traffic in the network? It's a new architecture design? Is it, you know, what's driving them moving towards you rather than maybe doing a Cisco upgrade? Yeah, I think that what we do differently with our network equipment is that we do the inspection at the entry point into the network, and w e can do that with our switches as well, if they are controlled by a FortiGate. Now, we have this FortiLink technology. We can try to keep threats out of the network very early on or block them, and t hat's what many of our customers really like about our security fabric and the integrated FortiOS. Would this seem like they're more like your install-based customers, or would there be newer logos that would buy your networking and your security products? Or is it more of an upsell? It can be both. O kay. Probably, you know, customers look at us for the FortiGate first, but then, as we educate them around all our other products, they realize that there is a whole product suite that works together. So, they evaluate the benefits of having it work together for security versus maybe every single network feature that they wanted to have initially. We see good success there. In these deals that have the combo of the two, would it come more out of the network refresh budget or the security budget or an AI budget? From the enterprise side, who usually throws the budget for you? That's a little bit unclear to us, right, w here the budget is necessarily coming from, but it would definitely be more the network organization that is looking at the benefits of the enhanced security, and then working with the internal buyers as well. Yeah. Okay. When Ken described your customers converging on networking and the security, it is because of the, it seems like, the operating system. So, when you win the consolidation, what is typically being displaced? Is it switches, routers, legacy APs, Wi-Fi gear? Is it a combination of all the above? It is generally a combination of all above that we consolidate on. When I talk to customers, and typically, it is of course larger customers, but they all have pressures from an operating margin perspective, from a cost perspective. They are looking at how can I improve my cost, and they do not only look at what they pay to third parties. The highest cost in most enterprises is your people. So, how can I make sure that I can operate my IT department, my network security, everything I need to do with fewer people? That typically means you want to consolidate some of your technologies, so you get economies of scale when you are operating your network. I see these discussions a lot, especially the C-suite looks at what can Fortinet do for them, versus best- of- breed technologies that only few companies I think are really striving for. Was that kind of a surprise to you this quarter, or have you always seen a secure? I mean, you have talked about it in all your industry events that secure networking. It just seemed like this quarter, it was a bigger driver or there was just more meat to it. Has that been building because people really need to move their legacy architecture? I am just trying to understand what the demand is and are people realizing you finally have all the solutions, and it is easier to consolidate? Yeah, I think it's, the benefits that we've seen over the last couple of quarters is that really all geos are investing. Sometimes, you have more of a trend in one country, and then it takes longer until other countries are investing, too. Right now, with AI, with the threat landscape, I mean, the threat landscape has increased. So, this is securing your network, securing your applications is not a nice-to-have anymore. I mean, everybody is a little bit scared of what AI can do to your security posture, s o, the AI threat landscape, or the threat landscape is increasing because of AI making it easier to exploit different, not vulnerabilities, but also trick employees, find open ports, find weak passwords, right? All these things are so much easier to exploit now that the discussions are accelerating, how can I improve my security posture? Then, an integrated security, of course, trumps fragmented security because everybody knows if I need to build a lot of integration points, that's another area for potential failure. So, I think it's the timing that really works for us in addition to attractive pricing. Yeah. OT billings accelerated 55% year-over-year. What's driving the acceleration? I know in Minnesota we had recently an attack, 30 water systems in the town next to the one I live in. So, what are you guys seeing driving that? I mean, that's one obvious driver, but are more of the communities in the state and the local governments more interested in it? Which segment is really driving that growth? We see OT across the board, and I think these flashy news articles around water systems being compromised, or last year, Jaguar losing so much money because they had a ransomware attack, or the airport terminals going dark in Europe for a while, or GPS signals being intercepted by the Russians. All these things drive awareness on how critical it is to secure your infrastructure. In addition, so many more aspects of your life get digitized, right? So, we are involved in EV charging station security, which would fall under OT for us, right? It's across the board. It's also across the size of customers. So, there are a lot of small manufacturers that are vulnerable now because they haven't put as much thought into security. So, we sell OT across all customer segments, of course, into public sector, but that's not the only customer. It is across the board, and because it is a very hardware-centric play, we have an advantage. Yeah. Do you have an overlay sales team for that, or would that be covered by the commercial or the different sectors? The way we are organized is we have an account manager that owns all the sales to one customer, and then, he brings in specialists. We do have OT specialists that know how to [audio distortion], that knows all the protocols that need to be secured, how to integrate IT and OT networks. While we are educating our generalist account managers, we definitely have an OT overlay function that helps these account managers be successful and also work with partners. There are specific OT partners. We have specific industry partnerships, let us say with Rockwell and Honeywell, Siemens, Schneider Electric, to integrate our solutions into some of their equipment. All of this requires special knowledge. How would you size the OT opportunity today versus, I would say, two years ago? Just in terms of now. I would say the opportunity, again, is growing with more digitization in every segment of your life, w ith more exploitability, interceptability of wireless signals, traffic, and so on. So, it's a growing part of our market, and what has increased is definitely awareness, I think, not only in the companies that it needs to be secured, but also across the board, across the boards, executive management, that this is a very important part of your business that you don't want to be going down because of an outage or a cybersecurity event. So, would you say that's another area that you are probably maybe adding more experts to help the sales team? Absolutely, yes. Like the cloud piece? Yeah. Okay. Perfect. All right. Then, RPO group, $7.7 billion, 16% year-over-year. Current RPO was 12%. What does the gap tell us in duration for us? We are comparing numbers [audio distortion], u p one month, we were around 30 months average duration. Okay. For services in Q2. The billings or the deferred revenue growth is a large number, right? To increase that significantly is harder than growing your service billings in a quarter. But we see good success, and we see it in the deferred revenue number now, which makes us very comfortable now. Okay. On services, three service metrics moved at different speeds during the quarter. You had service billings grew 26%, total deferred revenue 17%, and service revenue at 14%. I might have said service billings, shouldn't have said that, but w hat is the gap between those? Is it the deferred? Service revenue is pretty much mostly coming from the balance sheet, right? There's very in-quarter new activity. Service billings gives you the in-quarter sales, and some of it is renewal, some of it is attached to hardware, and some of it is services only. We definitely benefited from large hardware sales because we attached a lot of services. Then, deferred revenue, if you look at the numbers, it's 4x the service billings. To move it up, takes a lot longer, right, than because it's such a large number. Overall, we are pleased because current deferred, total deferred, and the same on the RPO is not a big difference for us. It has kind of dipped and is sloping up, and so, that's where we are comfortable that we are doing the right things on the service side now. Would the AI-related services be added to FortiGuard, or are those incremental SKUs at an incremental price? It's both. Okay. We have incremental services, but we also have incremental products, right, s eparate products that help with securing AI infrastructure or securing AI risks. Then, the OS, the FortiOS, has a lot of built-in security as well, which we are delivering with FortiGates, with switches, and APs as well now. Okay. So final question. We are getting down to the end here. So, you framed 2027 on the call as two questions, how much share you can take from others, and how much you can grow within your base. So, taking those in turn, which is a larger contributor in the next year? Ooh. I think it is new markets. Okay. I think it is new markets. So, new markets that open up for us in our existing customer base. It is also new markets that we are competing with with our competitors, but that we are, I think, positioned for very well. Well, I really appreciate your time today, and thank you very much for joining me, and I hope my questions were okay. Yeah, absolutely. Thank you for the questions. Thank you for the opportunity for us to present Fortinet's success and where we are headed.
Loading workspace