Executive readout · one minute
Call research workspace
Read the call alongside every captured source. Audio, transcript, slides and SEC filings stay in one workspace.
Earnings call · FY2021 Q4
Executive readout · one minute
Read the call alongside every captured source. Audio, transcript, slides and SEC filings stay in one workspace.
Research coverage
3 live sources
Switch sources without leaving this page or losing your listening position.
Open the source you need; every reader stays inside this workspace.
Listen and read together
The spoken word highlights as audio plays. Select any word to seek to that moment.
Good day and welcome everyone to Palo Alto Networks Fiscal Fourth Quarter of 2021, Earnings Conference Call. I am Clay Bilby, head of Palo Alto Networks Investor Relations. Please note that this call is being recorded today, Monday, August 23, 2021, at 1:30 PM Pacific Time. With me on today's call, Nikesh Arora our Chairman and Chief Executive Officer, and Dipak Golechha, our Chief Financial Officer. Our Chief Product Officer, Lee Klarich, will join us in the Q and A session following the prepared remarks. You can find the press release and information to supplement today's discussion on our website at investors.PaloAltoNetworks.com. While there, please click on the link for the events and presentations where you will find the investor presentation and supplemental information. In the course of today's conference call, we will make forward-looking statements and projections that involve risk and uncertainty that could cause actual results to differ materially from forward-looking statements made in this presentation. These forward-looking statements are based on our current beliefs and information available to management as of today, risks, uncertainties, and other factors that could cause actual results to differ are identified in the safe harbor statements provided in our earnings presentation and our SEC filings. Palo Alto Networks assumes no obligation to update the information provided on today's call. We will also discuss non-GAAP financial measures. These non-GAAP financial measures are not prepared in accordance with GAAP and should not be considered as a substitute for or superior to measures of financial performance prepared in accordance with GAAP. We have included tables that provide reconciliations between non-GAAP and GAAP financial measures in the appendix to the presentation and in our earnings release, which we have filed with the SEC. We have several upcoming events, including a virtual Analyst Day on September 13th, starting at 9:30 a.m. Pacific Time. Nikesh Arora, our chairman, and CEO along with members of the executive team will provide an in-depth review of the Company, including growth strategies, financial objectives, and capital allocation framework. Management is also scheduled to participate and upcoming virtual investor conferences in September hosted by Citibank and Piper Sandler. And now I will turn the call over to Nikesh.
Good afternoon, everyone, and welcome to the Palo Alto Networks Q4 conference call. Today, I'm trying something new, so please bear with me. You just had the chance to view our ad campaign, which you are the first to see. We spent considerable time understanding what our customers truly want from us, and the consistent message from them has been the need for innovation at the forefront of cybersecurity. Our ad campaign, titled "We've Got Next," highlights the innovation our teams are delivering and our commitment to being your partner. I look forward to seeing this ad serve as a driving force in all our broadcast media, as we share it with our customers. Moving on, as you're well aware, we encountered several significant cybersecurity events in the last quarter, particularly concerning supply chain attacks where malicious actors attempted to compromise essential infrastructure components, granting access to enterprise and government systems. These vulnerabilities are being exploited by ransomware actors, and the ransomware threat continues to escalate. Our Unit 42 team reports that the average ransom demand in the first half of this year increased to $5.3 million, marking a 518% year-over-year growth. These attacks reveal ongoing deficiencies in enterprise and government infrastructure, driving demand and consolidation as companies reassess their cybersecurity strategies. In this context, our platform approach is proving effective. Three years ago, at our analyst day, we set out a strategy based on three fundamental principles. First, the network is transforming with the advent of cloud technology—a transformation accelerated by the pandemic, with SASE and virtual firewalls leading the way. Additionally, we enhanced our firewall platform strategy by incorporating software capabilities such as DLP, IoT, SaaS visibility, DNS Security, and SDRAM. Second, while the cloud is significant and here to stay, we now have seven modules in our Cloud security platform utilized by over 75 Fortune 100 companies. Our third insight indicated the increasing need for AI and machine learning to support the automation of our security platforms and security operations centers, which our Cortex platform validates daily. Underpinning this innovation strategy has been a surge of product releases at Palo Alto Networks. When I joined the company, we recognized the need to refine our innovation and product strategy, as many cybersecurity firms struggle to remain relevant. As shown in the slide, we've increased from 13 major releases to 29 this year, tripling our product release capability over three years. Of these releases, 11 were through acquisitions, while 53 were achieved through organic innovation. This is just the beginning; we anticipate even more innovation as we progress through the year, which we'll discuss further at the Analyst Day. Our rapid pace of innovation is corroborated by industry recognition. As illustrated in this slide, we've been acknowledged in two categories for leadership in cybersecurity. In FY '21, we received six different accolades that affirm our leadership in six distinct categories. Our goal is to expand this category leadership this year and aim for double digits by year-end, demonstrating that our pace of innovation is robust and ongoing. Breaking it down into the three different platform pillars, our network-driven pillar, propelled by SASE and virtual firewalls, plays a pivotal role. At the pandemic's onset, there was much debate about the sustainability of the work-from-home trend. I can assure you that this trend is far from over; hybrid work will soon become the norm, and SASE will lead that transformation. All applications will require access from any location, and only Palo Alto Networks can deliver comprehensive capabilities with consistent Network Security across all our platforms. We experienced a remarkable number of large deals in this category; for instance, one of our largest deals involved a bank in the JPAC region, where the customer invested over $10 million in Prisma Access as part of their strategy. After a remarkable growth in our SASE product category, our customer base has increased by 50%, nearing 2500 customers. Additionally, 25% of these customers are new to Palo Alto Networks, indicating that our existing firewall customers are not only purchasing our products, but our new capabilities are further penetrating the customer base. Beyond the initial demand for Prisma Access, we recognized that customers seek more features. We recently introduced Autonomous Digital Endpoint Monitoring, also known as ADEM, which is becoming the standard. Bundling ADEM capabilities with other features around Prisma Access allows us to increase our Prisma Access deals over time by 25%. In addition to our SASE leadership, last quarter we launched our fourth-generation hardware featuring high performance and competitively priced appliances. The newly introduced PA400 offers ten times the performance of its predecessor, enhancing our presence in the enterprise branch, SMB, and international markets. Recently, a U.S.-Canadian retail chain, which previously utilized our services solely for corporate infrastructure, deployed the PA400 series to 23,000 stores. We are also witnessing a trend in hardware refreshes; after a period of delay during the pandemic, companies returning to the office are seeing increased volumes without creating additional infrastructure, prompting them to undertake refreshes in the hardware category, contributing to the growth we observed this quarter. Furthermore, we maintain a leadership position in our virtual firewalls. We recently initiated a partnership with Google, powering their new Cloud IDS using our VM Series. As demonstrated, the continued acceleration of our software follow-up business across various formats has allowed us to achieve approximately 47% of billings in a quarter that also experienced hardware growth. We concluded FY '21 with our software firewalls and Prisma SASE next-generation security ARR at $425 million, contributing to over $1180 million in our NGS ARR for the quarter. Regarding our Cloud platform, we identified this trend early on, investing three years ago in cloud-native security opportunities. There has been a surge of interest from venture capitalists in this market, validating our strategy, and we believe we are ahead of the curve. A key measure of our Prisma Cloud services' performance is the consumption of our services—in Q4, we had 2 million credits consumed, expanding beyond our initial modules of Cloud Workload Protection and CSBM. We have launched IAM and other modules, with over 100 customers adopting these in the quarter. A quarter of our Global 2000 customers now utilize Prisma Cloud, with total customer growth at 47%. Additionally, our acquisition of Bridgecrew has enhanced the adoption of Bridgecrew as customers prioritize cloud security; we are pleased with the initial results and progress of integrating Bridgecrew with Prisma Cloud. We continue to see substantial deals with Prisma Cloud, with our top three customers committing over $40 million in bookings this quarter. Our largest deal was worth $20 million for Prisma Cloud, where a customer expanded Cloud Workload Protection and CSP while integrating Bridgecrew across their entire cloud platform. Including our marketplace and VM Series, our Prisma Cloud business finished FY '21 with an ARR of $300 million. Switching to Cortex, we have 2900 customers utilizing our XDR Pro and XSOAR products, nearly doubling year-over-year. We recorded our very first follow-on transaction exceeding $10 million for Cortex in the pharmaceutical industry. Thanks to our platform approach, customers purchasing multiple products express a desire for XDR, network traffic analysis, and XSOAR. Today, we introduced XDR 3.0 to extend our pioneering XDR service to cover cloud and identity-based threats, providing organizations with a single console for holistic analysis. Expanse continues to innovate as a leader in the emerging attack surface management space, delivering unique integrations with our Palo Alto portfolio. In Q4, we launched an Expanse capability enabling the discovery of unknown cloud assets, integrating them into Prisma Cloud management. We concluded FY '21 with Cortex NGS ARR exceeding $400 million. Lastly, we are thrilled about Unit 42, which allows us to proactively support customers, transitioning us from a peacetime product provider to a wartime ally during their times of need. We launched proactive capabilities last quarter, and our Unit 42 business ballooned by 11 times in Q4 due to this service. A significant engagement we've encountered is ransomware readiness, with 39 readiness assessments completed and an additional 300 in the pipeline. We anticipate that these services will drive increased product adoption among our customers. You can observe our leadership signs—customers are consolidating and integrating security. As a company, we've focused on enhancing our presence with customers and securing larger deals. I'm excited to share that we had 18 customers sign transactions exceeding $10 million in the quarter. We also welcomed our first customer who surpassed $100 million in booked business during a fiscal year as they standardized Palo Alto Networks across their enterprise. Our Millennium customers have now reached 986 as of Q4, reflecting a 30% increase for the third consecutive quarter. The results of our strategy are evident; we achieved revenue acceleration in Q4, reaching $1.2 billion. Our billings rose to $1.8868 billion, marking a 34% increase, while our NGS billing topped $1.18 billion, surpassing our guidance. Additionally, our FY '21 performance showed ClaiSec with an ARR of $734 million and revenue of $602 million. As we enter FY '22, we are further aligned around our One Palo Alto Networks strategy, benefitting from the ability to cross-sell our platform. I'm also pleased to announce that we achieved our first $2 billion quarter. While you see the $1.868 billion figure, our actual bookings exceeded $2 billion when factoring in RPO and revenue, which is credit to our dedicated team and the trust our customers place in us regarding cybersecurity. In Q4, we clearly observed strong momentum in our business, with accelerated product revenue. This is revenue we expect to sustain into Q1 due to the impending hardware refresh and the fact that we didn't ship everything from our product business in Q4. We've also witnessed remarkable growth in cross-platform adoption; 43% of our customers purchased all three of our platforms, 28% purchased two platforms, and 29% purchased one platform. Notably, customers acquiring two platforms had deal sizes three times larger than those for a single platform. Additionally, for Global 2000 customers that adopted all three platforms, some deals were 14 times larger than our largest single-platform deal. Observing the effectiveness of our platform consolidation approach is quite promising as we successfully encourage customers to deploy multiple platforms. It is evident to us that our transformation is in progress. At our Analyst Day in September 2019, we provided FY '22 targets, and our recently released FY '22 guidance significantly exceeds those initial targets, as you'll see. As Dipak will emphasize, our total company revenue growth is in the mid-twenties, surpassing our prior 20% CAGR target set two years ago. Our business is evolving more rapidly, and NGS growth is accelerating. I eagerly anticipate sharing new guidance for the next phase of Palo Alto Networks at our Analyst Day in September. It is clear that over the past three years, our product and strategic transformation into a cybersecurity innovator is succeeding. Now, we need to present our strategy for how we will effectively and efficiently scale this business over the next three years. Several factors give us confidence in our objectives for FY '22 and beyond. To outline how I envision growth for FY '22 and how we plan to scale, I believe there is pent-up hardware demand that will manifest in Q1 and throughout FY '22. We've also launched new hardware form factors, generating enthusiasm among customers, and we anticipate continued benefits from industry-wide cloud adoption extending into FY '22. As mentioned, work-from-home is the new normal; it is not ending soon. I believe the SASE momentum is just beginning. There's extensive growth potential not only for FY '22 but also beyond. Additionally, I don't believe that manual processes can keep pace with the increasing sophistication of cybersecurity challenges. Therefore, there is significant growth ahead for both the cybersecurity industry and Palo Alto Networks. Regarding scaling, we introduced the speedboat concept three years ago, and it is functioning effectively. We continue to refine it for growth and productivity. We also see opportunities for synergies as we foster a more unified sales motion. Some products are yet to be launched, and you will see these throughout the year. We anticipate that as we unveil these products, the benefits of our innovation and investments will become apparent in this year and beyond. Our journey to the Cloud is well underway, but we still have a considerable journey ahead in optimizing our cloud expenditure. We believe there is potential for long-term margin expansion. We also anticipate sustainable growth within the cybersecurity industry. We expect our top-line growth drivers to combine with a moderate pace of investment in FY '22, as we plan to add fewer employees than the previous fiscal year. Some of our expectations for acquisitions will be incremental rather than substantive in the upcoming year. Beyond FY '22, we expect to see our operating income grow faster than revenue, and we will provide further updates to investors on this during our Analyst Day on September 13. To conclude, our excitement about "We've Got Next" as we head into FY '22 is evident. I will now hand over to Dipak, who will discuss the specifics of our Q4 performance and guidance.
Hello everyone. Before I begin, please note that all comparisons are on a year-over-year basis, unless specifically noted otherwise. We delivered results ahead of our guidance across all metrics as we continue to grow and transform our business. In Q4, we saw sequential revenue acceleration driven by strength in our hardware appliance business and in our next-generation security portfolio. We also continued to grow billings and our remaining performance obligation ahead of revenue as we build future predictability with the higher mix of recurring revenue. As a reminder, billings is total revenue plus the change in total deferred revenue, net of acquired deferred revenue. In the fourth quarter of 2021, we delivered billings of $1.87 billion, up 34% and well ahead of our guided 22% to 23% growth. The size of the deals with our large strategic customers grew and our total customer account expanded with over 2500 customers added in the quarter. Q4 revenue of $1.2 billion grew 28% and was above the high end of our guidance range. Growth was driven by strong demand across all geographies and major product areas. Total deferred revenue in Q4 was $5.02 billion, an increase of 32%. The remaining performance obligation or RPO was $5.9 billion, increasing 36%. We believe that RPO has meaningful insight into our backlog as it includes both prepaid and contractual commitments from customers. By geography, Q4, revenue growth was strong across all regions. The Americas grew 29%. EMEA was up 25% and APAC grew 28%. A hardware appliance business accelerated in Q4, driving product revenue of $339 million, growing 11%, and contributing 28% of revenue. Customer reaction to our refreshed on the 400 series and 5400 series appliances was positive. We saw strength overall in network and data center refresh and appliance sales through from customers standardizing on our platform. Subscription revenue of $535 million increased 37%, support revenue of $345 million increased 35%. In total subscription and support revenue of $880 million increased 36% and accounted for 72% of our total revenue. The gross margin was 75.3% up 100 basis points as compared to last year, driven by improvements in both our products and services gross margin. While the top line outperformed, the operating margin was 17.5% down year-over-year as expected. At some pre-COVID expenses returned in the fourth quarter and we continue to hire top talent, adding headcount in our go-to-market and engineering organizations. We ended the fourth quarter with 10,473 employees. Net income for the fourth quarter increased 12% to $162 million, or $1.60 per diluted share. A non-GAAP tax-effective tax rate was 22% GAAP net loss was $119 million or $1.23 per basic and diluted share. For the full-year billings of $5.45 billion grew 27% and total deferred revenue was $5.02 billion, an increase of 32%. Fiscal year revenue of $4.26 billion grew 25%, an operating margin of 18.9% was up 130 basis points as COVID-related impacts led to lower operating expenses throughout the year. Non-GAAP net income increased 27% to $614 million or $6.14 per diluted share. Turning now to the balance sheet and cash flow statements. We finished July with cash equivalents and investments of $3.8 billion. Days sales outstanding was 74 days, a decrease of 7 days from a year ago, driven by a combination of strong collections and improved billings linearity. Cash flow from operations was $326 million, free cash flow was $298 million as compared to $302 million last year with a margin of 24.5%. For the full-year free cash flow was $1.39 billion, which was up 69% with a margin of 32.6%. Adjusted free cash flow for the year was also $1.39 billion up 43% with the full-year margin of 32.6%. Cash conversion remains an important part of our framework in supporting total shareholders. Our firewall as a platform swaps billings grew 26%, reflecting another strong quarter as we continue to grow faster than the market. While we saw an increased contribution to the firewall as a platform growth due to increased product demand. A majority of firewall as a platform growth continues to be driven by software firewalls, including our VM series and Prisma SASE. Next-generation Security, or NGS, exited the year at $1.18 billion, exceeding our original guidance of $1.15 billion. Within NGS, we continue to see exceptional growth in our SASE and software firewall portfolio, as well as strength in Prisma Cloud and Cortex. For ClaiSec, we were happy to have achieved results that were consistent with our fiscal year 21 financial goals. As we have gone through our fiscal year 22 business planning and oriented the focus of the Company around one Palo Alto Networks, we wanted to ensure our metrics reflect this One Palo Alto Networks strategy. We believe a focus on NGS ARR growth, and our transformation metrics are the best measures of progress on our strategy. In the appendix of our earnings slide deck, we've included the fiscal year '21 results and that SEC and ClaiSec. Our capital allocation priorities are unchanged and aligned with the optimization of long-term shareholder return. We remain focused on investments for organic growth and targeted value-creating acquisitions. We didn't close any acquisitions in Q4. And at this time, we believe we have assembled the key pillars needed to execute our platform strategy. We expect the incremental M&A in fiscal year 22 as compared to the recent past. Under our share repurchase authorization during the quarter, we acquired approximately 846,000 shares on the open market at an average price of approximately $388 for a total consideration of $328 million. Our Board of Directors authorized an additional $676 million for share repurchase, increasing the remaining authorization for future share repurchases to $1 billion, expiring December 31st, 2022. Moving now to guidance and modeling points for the first quarter of 2022, we expect billings to be in the range of $1.29 billion to $1.31 billion, an increase of 19% to 21%. Revenue is expected to be in the range of $1.19 to $1.21 billion, an increase of 26% to 28%. Q1 product revenue growth percentage to be in the low double-digits, we are providing this transparency, this quarter, non-GAAP EPS is expected to be in the range of $1.55 to a $1.58 based on a weighted average diluted share count of approximately 101 to 203 million shares. For fiscal year '22, we expect billings to be in the range of $6.6 to $6.65 billion, an increase of 21% to 22%; revenue is expected to be in the range of $5.275 to $5.3 billion, an increase of 24% to 25%. We expect next-generation security ARR to be $1.65 billion to $1.7 billion, an increase of 40% to 44%. We expect product revenue growth percent to be in the mid-single-digit to high single-digit range year-over-year. We expect operating margins to be in the range of 18.5% to 19%. Our Non-GAAP EPS is expected to be in the range of $7.15 to $7.25 based on a weighted average diluted count of approximately 104 to 106 million shares. Adjusted free cash flow margin is expected to be greater than 30%. And we will report RPO and recommend this as an attractive metric as it captures the full value of our contractual arrangements and is a good indicator of future revenue. Additionally, please consider the following additional modeling points. As I mentioned earlier, we hired aggressively in the second half in fiscal year 21, supported by confidence in our fiscal year 22 outlook for revenue and billings growth, with expenses from this investment flowing into the first half of fiscal year '22, and some return of COVID expenses, we expect operating income will be shifted to the second half of the year, in fiscal year 22, as compared to fiscal year 21. And we expect an approximate 43% to 57% first half, second half splits during the fiscal year '22. We expect our non-GAAP tax rates to remain at 22% for Q1 and fiscal year '22, subject to the outcome of future tax legislation; we expect net interest and other expenses of $4 million to $5 million per quarter. We expect fiscal year 22 diluted shares outstanding of 104 to 106 million shares. And for Q1, we expect capital expenditures of $35 million to $40 million. For the fiscal year, we expect capital expenditures of $205 million, which includes approximately $40 million related to our Santa Clara headquarters. Finally, I would like to invite you to join us for our virtual Analyst Day on September 13th when Nikesh, myself, and others from our team will provide an update on our company and product strategy, financial outlook, and ESG plans. In closing, we are entering fiscal year '22 with strong momentum. We're pleased with our operational execution and organic growth prospects as drivers of continued momentum. With that, I will turn the call back over to Clay for the Q&A portion of the call.
Okay. Great. Thank you, Clay. Thanks for taking my question here. Nikesh, maybe for you lots of good stuff to hit on in the quarter. But maybe I'll just focus on next year's billings guide to start. Is great to see, I think the guide of 21% to 22% billings growth next year. That's better than where you started fiscal '21 in terms of billings growth expectations. And of course, subsequently beat, can you just talk about what's going into that higher starting point for fiscal '22? And maybe as part of that, how you're thinking about overall security spending in the areas that Palo Alto operates? Thanks.
Saket, thanks for your question. As you know, when we went into FY ‘21, we're all looking at what's happening with the pandemic and we're trying to figure out how the pandemic was going to impact security spend, how the pandemic was going to impact our customers coming back to work. What we realized in the course of the last year, is that business must continue and, in that context, customers have come back and realized this way of working is fine. Not only are they working in terms of creating productivity and delivering their services, but also this way of working in terms of upgrading their IT infrastructure and, of course, staying ahead of the cybersecurity threat landscape. So, in that context, we have a little more confidence going in this year where we believe the customer is going to go, of course, the pandemic hopefully will ease itself out over the course of the next few quarters. But in the context, we feel a little more confident, therefore we've been able to understand what we can do as a business and share the guidance with you. In terms of cybersecurity spend, as I said, the volumes of technology consumption have gone up in the pandemic no doubt. I don't think this is a one-time blip; that's kind of normal, I think this is a new normal. And that new normal needs to be protected, and to be able to protect it effectively, you are seeing customers looking at consolidation strategies. I shared with you the 3 platform purchases, the 2 platform purchases. In my 3 years at Palo Alto, and finally, I’m finally seeing customers wanting to consolidate and not deal with fragmentation; they're realizing this is a losing battle. If you want to take point solutions and trying to integrate them yourselves. Now, that's our bet, has always been our bet, but it's not a bet that is contingent on us having a platform you have to buy it all. It's contingent on us being able to deliver best-of-breed capabilities and as I shared, we've gone from two to six, hopefully from six to double-digit this year, which means we actually deliver best-of-breed capability to our customers, even with the challenges. So that's what gives us the confidence, Saket.
Thank you for your response, and congratulations on a strong quarter. I believe the results will surprise many, especially considering the robust performance in billings for next-generation products and the operating margins exceeding expectations. However, there has been significant concern regarding product revenues due to supply chain issues. It seems those issues did not heavily impact your performance. You mentioned product revenues as you transition into fiscal year 2022. Will this guidance account for any supply chain challenges moving forward? Additionally, regarding the projected growth for fiscal year 2022 at mid to high single digits, is this growth sustainable beyond that fiscal year, or is it primarily a result of catching up on demand for hardware? Thank you.
So, Keith, thanks a lot for your question. I also want to thank you for the balanced note; I thought you had a good assessment of our opportunities and challenges going as a quarter. Like you said, we are seeing the pent-up demand get released. We are seeing some impact of refreshes. We are seeing some impact of some of the new form factors we've launched. We are working diligently, as I'm sure everyone is, with our suppliers to make sure that we're able to bridge the supply and demand gap. So far, we've been able to make it through Q4. Based on current visibility, we don't see challenges for Q1 going into it, which is why we've given you a guide for Q1; we will keep working with our suppliers. I think the supply chain issue is going to mitigate itself in the Q3 or Q4 timeframe, anyway, in the industry. When there is a supply issue, a lot of the manufacturers, a lot of chip companies are actually working twice as hard to try and bridge the gaps. And we're also working hard with them to make sure we're very transparent about our needs in the quarter. So far, we have guided with the anticipation that we will be able to keep managing our supply chain balance the way we have been able to manage for Q4. And in terms of your sustainability, I would welcome you to the Analyst Day on September 13th, and we’ll talk more about it then.
Great and thank you for taking my question. You talked a little bit in the prepared remarks about your success in the XDR segment. I was wondering, given all the noise in that segment, Nikesh, if you could unpack a little bit where the competitive landscape is, and why Palo Alto is winning at this point. Thanks.
Thanks, Rob. Look, XDR is a competitive space, it is a new transform endpoint space which has a lot of players. And there were some legacy players in that space who lost ground to some of the newer players in the space, and we all know who they are, and Palo Alto came out with a product, which was highly technically capable and competitive. As we've shared with you, we have won various benchmarks in the industry versus other players in the space. So, we are seeing dogfights or catfights or whatever the right analogy is in the customer space where we get in contention with a competitor. And it gets competitive, and it becomes a question of, can you deliver the XDR capability we want? But I think over time what's happening is that customers are looking at it as a more expansive approach. I think this is not just about the endpoint part; it also needs to look at how do you combine lateral network traffic analysis, how you put, take that together, and minimize the number of alerts that you're getting from different parts of the infrastructure. As we just announced this morning, we've integrated cloud capability in there, so now you can take a look at your cloud estate and take the alerts from the cloud estate combining with a lot of their endpoint, combining with a lot of their network traffic analysis and trying to see how do you minimize the alerts and how do you see a correlation amongst all those alerts. Not just that; we introduced identity analytics this morning too. So, I think over time, the XDR category is hurtling towards what used to be the SIM. And what's going to happen over time is XDR will engulf that space, but with a much more intelligent, normalized point of view where you can actually look at and say, this is valuable to me. The SIM of the past was a data aggregation exercise and the intelligence was left for the customer to determine. I think XDR is bringing that next-generation capability to the SIM where it's cross-correlating prior to that; reducing your noise, giving you more relevant information. That's what's going to be the future. So that's why XDR, whilst competitive, is highly strategic, and it behooves us because we have multiple pieces of the puzzle where we actually have cloud security capabilities, we have firewall capability, not just on hardware, but across our virtual form factors. So being able to bring all that data makes sense of it and provide value to the SOC is where I think XDR is going. I think we're well placed in that space.
Great. Thank you for taking the question, and congrats on the results, Nikesh. One quick question on the ClaiSec business. Wanted to understand, I guess maybe on next NGS overall, confidence in the guidance, how much cushion is in that number? I understand it's nice to see you leaning into ClaiSec with investment. Where are you investing for growth, particularly in sales and marketing? And maybe to cap it off, management changes that we saw this quarter, particularly inviting BJ to join the Company. How that plays into the investment in ClaiSec as that remains a meaningful opportunity for you?
Thanks, Brian. You know, as we went on the speedboat strategy, our first job was to make sure that we had product-market fit. And in the early part of our strategy, we shared that we began to see product-market fit, which really, I think Q4 2019 was when we started to see traction in the space. We spent the majority of the last 18 months after that trying to make sure that our sellers were able to understand the power of all the capabilities that Palo Alto has to offer. And we have some phenomenal results in terms of what percent of our core sales team can sell Cortex, can sell Prisma, and those numbers keep rising because we're trying to ensure that our sales team is able to pitch the entire portfolio to our customers. And that's exactly why we had the success we've been able to share with you, in terms of customers buying three platforms, two platforms, or one, and we believe that opportunities are still further ahead in terms of us being able to penetrate our entire customer base with our cloud capabilities, our SASE capabilities, our Cortex capabilities. So, we think there's more room to go. We are investing in more coverage and more capability, both in the U.S. and North America, as well as in international markets. That's one part of it. In terms of the management change, I'm delighted that BJ Jenkins has joined us at Palo Alto Networks. He was the CEO of Barracuda Networks. He understands security really well. He's a very seasoned phenomenal sales leader and also a great human being. He's going to come manage our teams, drive that growth continually further. I also shared with you that part of our success as a company is being driven by very large deals. If you want to be the platform provider of choice, we have to be able to engage at the highest level for customer organizations and convince them of our not just portfolio approach, but its best-of-breed capabilities. Amit is going to continue to do that. He is working closely with BJ and Rick Congdon, our Head of Global Sales, and they're going to partner together and try and address the needs of the customers from the top down, which allows us more bandwidth, more capability, and more management strength in being able to do that. So, the sole part of the plan is to create an ability to go target customers at the highest levels, trying to create large deals where they see a long-term transformation and be their cybersecurity partner of choice.
Thank you, Dipak. To allow for broad participation, I would ask that each person ask only one question. The first question will be from Saket Kalia of Barclays with Keith Weiss of Morgan Stanley to follow. Saket, you may ask your question.
Yes, absolutely. Look over the last 12 months, we've made tremendous amounts of progress in both these products and you look at Prisma Cloud about halfway through the year we introduced four new modules, three of which have been built internally by the teams and one was the Bridgecrew acquisition being integrated for micro-segmentation. We've seen a lot of good early customer adoption of those and going forward, I anticipate we're going to start to see mainstream adoption across the installed base and new customers as well. XDR, with the announcement this morning, I think it just shows the continued pace of innovation that we are able to drive. Extending it to Cloud, extending it to identity analytics, introducing the new advisory modules, and a whole host of other capabilities as well. And as Nikesh already alluded, you're seeing us start to extend the analytics, as well as the data aggregation layer to additional data sources and additional intelligence.
Well, Well, Jonathan. We digest as we eat. We took the 11 product capabilities, and if you look at our NGS revenue or NGS billings, a lot of their NGS billing is from a majority of acquisitions that we integrated into our platform. So, it's not like we have undigested parts of our acquisitions. There are parts of our acquisitions where we'd like to see more traction, but for the most part, I think the way to interpret it, Jonathan, is that when I walked in 3 years ago, there were many trends in the Cybersecurity industry where we were not a player. We were not a player in SASE. We were not a player in cloud security. We're not a full player in the XDR space, and that was a concern for us. We needed to become a player, and the cost and time required to build capability will take us four to five years. That is where being able to look at the market's trends, by the best in the market, which has already shown product-market fit was the right approach. Today, we have to be very careful as we evaluate companies because pretty much in categories where we think there are relevant trends, we already have a product. So, acquiring anything in that space would require us to spend a lot more time integrating, figuring out what to do with their customers. We have 2 competing products, and I principally do not believe in having two products in the same category because it creates confusion, destroys the strategy, and increases unnecessary complexity in the organization. So that's why our opportunities to expand in categories are limited. We've decided at some places we want to play and we want to play to win; there are some places we're not going to play. We don't want to play in identity. So it doesn't matter if there is an open space and there are companies out there. We're not playing there; we're playing in Cloud Security where we will be very aggressive, we're playing in automating security capabilities and replaying a network firewall business. And there we believe we have huge complementary capabilities. And as you saw from the slide, we're building lots of organic capability. We did 53 product releases in the last three years, are all showing up, hopefully in the billings that you're seeing that we're able to provide more capabilities, more subscriptions to customers. That's the way I would interpret the M&A answer; does it mean that we might tuck in a product company here or there? Yes. But it also means that we're not looking for substantive acquisitions at this current point in time. Thank you, Brian. The pandemic has played a role in accelerating the adoption of SASE. Over the past two years, customers have made significant commitments to cloud purchases, engaging in the development and gradually shifting their workloads to the cloud. This transition has led them to realize that they don't need to send all their traffic back to their data centers. Instead, they can route traffic to where the data resides, whether that is in the public cloud or their own data centers. This type of traffic routing and splitting necessitates pushing routes to the edge and implementing SD-WAN. Additionally, security at the edge is essential. Most of our customers who have secure data centers with our firewalls can seamlessly extend that capability to the edge using Palo Alto technologies or Prisma Access without altering their policy infrastructure, ensuring consistent security across all platforms, applications, and devices. We are recognized as leaders in this space while many competitors lag behind. In this context, we believe we are well-positioned to deliver genuine SASE solutions, significantly enhanced by our software capabilities. I am confident that every company in the Fortune 500 and Fortune 100 is currently navigating this transition, indicating that the market is far from saturation. This shift is not solely focused on security; it fundamentally revolves around networking. Organizations are moving their traffic from MPLS to cloud-delivered security and networking solutions, leveraging underlying network capabilities from providers like GCP, AWS, and Azure, alongside our security services. Gray, what has happened is with the supply chain initiatives that we saw in the industry, we've seen pretty much every player in the industry tweak their pricing for the upcoming year. And we've done something similar. It's in the low single-digits from a price increase perspective, as you know, the net yield is contingent on a competitive situation. What the customer pays, what discounts have been negotiated with them. So usually, typically you don't see the yield fully dropped to the UPMLl. It will have some pull-through to our numbers as when those price changes are affected in the field. But it's low-single-digits, it's just consistent with supply chain issues that the industry is seeing. Well, as you know, the federal year-end is September. So, I think it's too late for them to have any material impact this fiscal year. I think they're busy trying to get the new government in place, with changing a lot of people and administration usually takes, it takes in the first year of administration, takes a few weeks, months to work through those changes. So, I think we're going to see stuff happen in the next fiscal year for the government. They have great intentions. They want to make sure that the Cybersecurity posture of the country, of infrastructure is improved. You've seen some executive orders in that regard. There is a very positive mindset in terms of leaning in and solving many of these problems. I'm hoping that may lead to a positive impact on the Cybersecurity industry. Thank you, Joel. I think my personal view, and I'm new to the industry even though I have been here for three years; I don't think there are many options in the industry to consolidate Cybersecurity spend. I think there were some phenomenal players in the market who had amazing capability in their lane. What we've done in the last few years is build multiple lanes where you can buy the product in the space that really strongly, or you can buy a product that connects across those lanes. And that's what we're proving with our Prisma Cloud, with our SASE strategy, and our firewall strategy. We're adding more software capabilities. So, I'm going to tell you about my background. I think we're well-positioned for the consolidation around a majority of our platforms at the same time, you don't have to buy it all from us if you don't want to; we're still integrated with other players in the market. If your infrastructure is designed or you actually have infrastructure players that you're deployed. In terms of correlating that to identity and endpoint well, we are an endpoint; XDR is the new endpoint play where we do both EDR capabilities and XDR capabilities. So, as you see, the transformation of relief from the traditional endpoint vendors to the XDR vendors, we have a play there. Well, thank you very much, Nikesh. I wanted to flush out a little bit on the consolidation fee, but in a different direction; if you could just talk about your SASE wins. And are there some common themes within the SASE wins, where are you winning and why? And perhaps on the other side where you're not winning and trying to understand as part of that theme is how are you winning within SASE, within your installed SASE versus perhaps even getting into some new customers that might turn into something more for Palo Alto? But if you could just talk about some common threads within your SASE environment? Keith, I'll ask Lee to share insights about our wins and the reasons behind them. As I mentioned earlier, 25% of our Prisma Access customers are new to Palo Alto. Typically, these customers have existing firewalls that lack the extended SASE capabilities they desire and will eventually need to replace those firewalls. In the future, as those competitor firewalls reach the end of their life cycle, we hope to transition these customers to our SASE solutions, leveraging our hardware in the process. Lee, would you like to add to that?
Yeah, I think there's been a significant change in the market in terms of what customers realize they need; from sort of thinking about users, employees that are off the network, and sort of being like a nice to have, like maybe I can connect to some sort of subset of applications, some of the time, and that will be acceptable to the new realities of the hybrid workforce, where it's very clear that employees need to be able to access all applications, all of the time. And for the enterprise, there needs to be a full security stack to protect those connectivity’s. And that shift really favors our position with present SASE, our ability to secure all applications, our ability to provide true enterprise tested enterprise-grade security and to do it in a way that is consistent with what many of our customers already have deployed for our campus environments, branch-office environments, etc. And as Nikesh mentioned, that trend can come from two different directions. It can come from our existing customers who are really happy with us and extending out to SASE or vice versa, customers that come in with SASE and then can extend into the campus and branch office environments.
Evening, everyone. Thanks for taking the question. When you look at recent performance and even the forward outlook, how do you think about your share performance? Your share gains versus wallet share expansion within your customers. And then Nikesh, you talked a little bit about maybe within the networking, but what are IT silos do you feel like are donating spend into security as a whole? Thank you.
Thanks, Ben. You saw we highlighted one of our customers became our first customer to spend $100 million with us. And we have a few who are just short of that. So, it wasn't the only one who was getting there. So, I think part of that gives you a sense of consolidation of spend and us getting a higher share of wallet. But I'd like to see it as us providing the capabilities to our customers. Are they able to do everything with us, they don't have to go and go stitch together multiple vendors because today there is a very high cost of stitching security because the cost is our ability? We're doing all the stitching for our customers, at least giving them the ability; they can go secure the enterprise and go do other stuff in terms of your question about where different parts of IT are probably contributing. I think there is a large network contribution around the whole SASE topic because that's effectively, not just a security play but also happens to be a network play. And that's where you'll see and you'll find, many times that our firewalls are procured either by the network team or the security team. So, you'll see that the whole network security space, there is a back and forth between whether it comes from the network budget or the security budget. I think the same thing in the Cloud; people haven't quite figured out that the Cloud requires its own capability from a security perspective. And we're seeing that being baked into the budget. But very often that capability is coming out of the Cloud spend where we're also able to go get credits from the public Cloud CSPM to have the customer pay for that. And with that, we will conclude the Q and A portion of our call today. I will now turn it back over to Nikesh for his closing remarks. Well, I just want to say thank you, everyone, for joining us today. We look forward to seeing you at our upcoming investor events, and especially our Analyst Day. And I do want to take a moment to say thank you. Thank you, thank you to our employees, our partners, our customers, and everyone who made these results possible. Have a great day.
SEC filing · Item 2.02
Filed Aug 23, 2021 · complete as-filed document
SEC periodic report
Filed Sep 3, 2021 · complete as-filed document