11/15/2023

speaker
Walter Pritchard
Senior Vice President of Investor Relations and Corporate Development

good day everyone and welcome to palo alto network's fiscal first quarter 2024 earnings conference call i am walter pritchard senior vice president of investor relations and corporate development please note that this call is being recorded today wednesday november 15 2023 at 1 30 p.m pacific time with me on today's call to discuss first quarter results are the cash aurora our chairman and chief executive officer and deepak golecha our chief financial officer Following our prepared remarks, Lee Klarich, our Chief Product Officer, will join us for the question and answer portion. You can find the press release and other information to supplement today's discussion on our website at investors.paloaltonetworks.com. While there, please click on the link for events and presentations to find the Q1 2024 earnings presentation and supplemental information. During the course of today's call, we will make forward-looking statements and projections regarding the company's business operations and financial performance. These statements made today are subject to a number of risks and uncertainties that could cause our actual results to differ from these forward-looking statements. Please review our press release and recent SEC filings for a description of these risks and uncertainties. We assume no obligation to update any forward-looking statements made in the presentations today. We will also refer to non-GAAP financial measures. These measures should not be considered a substitute for financial measures prepared in accordance with GAAP. The most directly comparable GAAP financial metrics and reconciliations are in the press release and the appendix of the investor presentation. And less specifically noted otherwise, all results and comparisons are on a fiscal year over year basis. We also note that management is participating in the UBS conference, November 29th. I will now turn the call over to Nikesh.

speaker
Nikesh Arora
Chairman and CEO

Thank you, Walter. Good afternoon, everyone, and thank you for joining us today for our earnings call. Q1 was the first quarter of our three-year plan we presented in August. If I were to summarize the quarter, I would say the following. We continue to execute amazingly well in what is a volatile environment. On the geopolitical front, we've been contending with what's happening in Israel and Ukraine. On the hardware or product front, as you see, there has been normalization in the industry. It's something we've been indicating for a while. Backlog has been shipped, supply chain issues are behind us, and product growth is normalizing in the industry. We continue to see normal strength as we indicated in prior quarters in that category. On the macroeconomic front, business practices continue to adapt and adjust to new normal with higher interest rates for longer. Internally, on the product side, we've had one of the strongest starts to our fiscal year. In addition to various recognitions, we have delivered strong innovation across all three platforms. We launched an AI-enabled cloud manager and network security to continue our consolidation and platformization efforts towards zero trust. In SASE, we announced our intent to deliver enterprise browsers for the talent acquisition, which will solve one of the critical issues of remote access, which is not addressed today by any SASE vendor. We released the industry's first integrated UI for Code2Cloud and Prisma Cloud, and announced the acquisition of DIG Security to double down on data security for generative AI in Prisma Cloud. Last but not the least, in Cortex, we launched XIM 2.0 with Bring Your Own AI. On the go-to-market side, Q1 is seasonally a slower start as we kick off the new year, but the team delivered superior revenue and profitability, and we had our highest cash collection quarter in our history. We continue to see steady execution in our firewall, cloud, and endpoint businesses. On SASE, we continue to position ourselves in larger and more strategic deals. And XIM, while in its early days, continues to garner tremendous interest, giving us more comfort around our long-term intentions. So in summary, a strong start in Q1 towards our three-year journey. Early days, but confidence-inspiring. Let's dig into the details. Our Q1 revenue grew 20% and our billings grew 16%, while our RPO growth of 26% exceeded both of these and was driven by our next generation security capabilities. I would like you to pay particular attention to RPO versus billings. Deepak will talk about the difference at length and explain why the street might be confused with our future billings guidance. Our Q1 non-GAAP operating margins expanded by 760 basis points, driving 1.38 in non-GAAP earnings per share, and we generated a record 1.5 billion adjusted free cash flow in Q1. If you look at what's going on from an overall cybersecurity perspective, we have never seen as much adversarial and consistent activity at scale as we have seen in the first quarter. Unfortunately, we don't expect this to abate anytime soon. As a consequence of this increased activity and in recognition of our customers' commitment to us, this week we announced a Unit 42 Rapid Incident Response Retainer at no cost to all of our strategic customers, aimed at providing additional support during this escalating threat landscape. Ransomware attacks are increasing in frequency and severity. The ransom amounts being paid are also increasing. Bad actors are doing damage in a much shorter amount of time. As an example, in a recent engagement of our Unit 42 team, we saw an instance where bad actors extracted 2.4 terabytes of data in just 14 hours. There's also some evidence that the adversaries are beginning to leverage generative AI as a tool to make attacks more sophisticated. Not just that, based on what we are seeing in Unit 42, most attacks are now happening on the back of vulnerabilities in widely used software and APIs, such as a widely exploited MoveIt file transfer software. Unfortunately, these bad actors remain elusive, with no apparent significant increase in convictions in high-profile attacks, and therefore, not surprisingly, this malicious activity continues. At the same time, U.S. publicly listed companies and their boards are confronted with new SEC disclosure requirements around prompt public reporting of material cybersecurity incidents and the enhanced oversight responsibility that comes with that. This result is a continued focus across organizations on understanding security posture, cybersecurity risk, and how to mitigate this risk effectively. This increasingly involves not only the CISO, but the entire IT organization, legal, finance, and the CEO and the full board of directors. This space of malicious activity and the board-level focus on cybersecurity risk is fueling a strong demand environment. Customers often have multiple strategic priorities in cybersecurity, and our broad portfolio enables us to align with these priorities. In Q1, the cost of money remained a constant discussion, and customers' significant focus on this topic is becoming the new normal. The way it manifests itself in our business is that there is always a payment and duration discussion in final deed negotiations. Given our strong balance sheet, we can use a mix of strategies to navigate the environment. This includes annual billing plans, financing through PAN-FS, and partner financing. Whilst this does not impact our business demand or the impact to annual revenue or annual metrics, it does create variability on total billings more than before, depending on financing used or the duration of contracts. I am not concerned about the demand for cybersecurity for this quarter and upcoming quarters. Nor am I concerned about our ability to execute The billings variability is a pure consequence of the payment conversation that we're having with our customers, and this is validated by the fact that we continue to see strong RPO and low churn, suggesting this is a cosmetic impact to our business. We continue to see strong interest across our next generation security portfolio, and we're making progress on our platformization journey. I'll highlight a few deals to talk about the diversity of opportunity across platform buys, as well as the geographical distribution of our deals. For example, A federal government agency signed a $25 million expansion transaction, including adding Cortex-XDR and Prisma Access in highly competitive situations and expanding their network security footprint. This customer has now spent over $100 million of its lifetime across our three platforms. A large global SaaS provider signed an $18 million Prisma Cloud transaction to consume modules across the portfolio. The customer is already a customer for our network security and Cortex platforms. A large educational organization expanded its relationship with us in the first quarter in a $15 million transaction, adding XIM, Prisma Cloud, and an expansion of its network security footprint. And lastly, a nation state signed a $28 million deal, that is a first of its kind, standardizing on both SASE and XIM. This is a long sales cycle and represents our systematic approach to platformization. The story in these deals has been playing out across our large customers. As of Q1, 56% of the global 2,000s has transacted with us across Strata, Prisma, and Cortex. This continued focus on customer cyber transformation has fueled the 53% growth in NGS ARR to report this quarter as we broke through the $3 billion milestone. Another exciting news, as of Q1, recurring revenue across Palo Alto is 83% of our total revenue from 77% a year ago. Let's turn on to updates from our three platforms that are the engine driving our success. First, in network security, we continue to drive innovation across our portfolio and see momentum as customers drive towards zero trust architecture. This month, we unveiled PanOS 11.1, or Cosmos, and Strata Cloud Manager, unifying the management of all of our three form factors and all security services in a single pane of glass, and also leveraging AI to analyze security policies, reduce misconfigurations, and predict and prevent disruptions. Customers who have invested in our platform by deploying all three form factors continue to grow rapidly, up 34%. Of our top 100 network security customers, 60% have purchased all three form factors, up from 50% a year ago. On average, these platform customers spend more than 15 times of the rest of our network security customer spend. The story is similar in SASE. Having just seen our innovations gain multiple industry recognitions in SASE in the second half of our fiscal year, we've continued to invest to build on a leadership position. We're seeing strong momentum in SASE, with ARR growth of approximately 60% in Q1. We also saw 35% of our 5 million or greater network security transactions include SASE, up from less than 10% a year ago. Today was the first day of our event called SASE Converge, where we unveiled several enhancements. We have enabled SASE to access applications with performance faster than the internet. We added visibility and control over interconnected SASE applications and enabled safe access to GenAI tools to ensure data isn't inadvertently leaked. Lastly, we added remote browser isolation technology for an extra layer of security. M&A has always been an important part of our strategy. Last week, we announced our intent to acquire talent cybersecurity. We see an opportunity to expand the addressable market for SASE and solve an important customer problem. As many as 36% of workers classify themselves as independent workers, who often use unmanaged devices for work. In addition, employees increasingly use personal devices for accessing business applications. To enable access for these devices, security teams have an impossible trade-off. They are forced to either ignore security entirely in favor of flexibility and user experience, or to adopt cumbersome technologies like VDI. Talon is a pioneer in the emerging enterprise browser category, and when combined with Prisma SASE after closing, we will enable users to securely access business applications from any device, including mobile devices and non-corporate devices, with a seamless user experience. We intend to include this capacity capability with Prisma Access after closing, and customers will be able to extend the same best-in-class security to unmanaged devices. Moving on to Prisma Cloud. We continue to see a strong endorsement of our integrated platform strategy. This traction is evident in the strong growth of our multi-module customers. We have seen particular success here with modules released over the last two and a half years. There has been a consistent pattern of seeing 100 plus customers for new modules in the first full quarter of launch and rapid growth after that as the benefits of these new modules are broadly understood. This enthusiastic adoption has driven our strong conviction in adding key new modules, including some to our acquisitions. Our IAC scanning capability, which came through the BridgeCrew acquisitions, and CICD security, which came through CIDR, are two such examples. This new module traction is helping to accelerate Prisma Cloud new business ACV in the last quarters. In Q1, we also unveiled a major new Prisma Cloud release, Darwin. Darwin further differentiates our unique position across code, cloud infrastructure, and cloud runtime. Darwin enables a view across all elements of cloud applications, including cloud services, infrastructure assets, compute workloads, API endpoints, data and code. Darwin can also help customers understand risks with deep context and overlay active attack attempts in near real time. Our full coverage from core to cloud enables fixes to be applied immediately versus the months most vulnerabilities take to be passed. About two weeks ago, we announced our intention to acquire Digg Security, which will bring an award-winning data security posture management capability Prisma Cloud. With almost 70% of organizations having data stored in the public cloud, the sprawl of new cloud data services, and the adoption of generative AI, we see an increased need to identify sensitive data, effectively manage user access, and implement robust security measures to prevent unauthorized internal and external access to this data stored in the cloud. After the close of proposed acquisition, DIG's capabilities will be integrated into Prisma Cloud Platform to provide near real-time data protection from code to cloud. Moving on to Cortex. We continue to invest across our product portfolio and expand our customer account as we see continued adoption of XDR, XOR, Xpans, and XIM. In Q1, we had several industry recognitions of our innovation. Cortex-XDR was the only product in the industry to achieve 100% protection and detection in the Round 5 MITRE evaluation. Additionally, XOR, Xpans, and XIM were all named leaders by third parties as quarter. We grew our Cortex Active customer count by 25% to over 5,300 customers. Our traction overall in Cortex is essential as it allows us to sell our transformational offering XIM. XIM has had a very fast start since we released the product just over a year ago. After a strong FY23, XIM's first year of release, which included over 200 million in bookings, we followed up with a strong Q1. We saw our first expansion purchase of XIM, an eight-figure deal, and in Q1, our largest XIM customer to date was deployed with over 300,000 endpoints. We're seeing Ex-Im transform customer security operations and significantly improve their security outcomes. This includes significant reductions in the meantime to detect and resolve security incidents. On the back of potential customers hearing about early Ex-Im success, our pipeline for Ex-Im is over $1 billion, of which $500 million was created just in this past quarter. As I began my remarks, Q1 was the first quarter of us delivering on the three-year plan we presented in August. We're driving profitable growth, investing in innovation, next-generation security, and the industry's largest dedicated security go-to-market organization. At the same time, leveraging the scale of Palo Alto Networks. Demand for cybersecurity is strong, given the backdrop of attacks and the ever-increasing focus and scrutiny around cyber risk. Execution continues to be paramount, given the macro conditions, and we will continue to be adept in responding to changes in the environment. We will manage for long-term growth, operating margin, and free cash flow, and ensure we continue to transform the business and build revenue predictably. You will see this through RPO, and most importantly, our current RPO. Our long-term forecast thesis remains intact. Whilst we expect short-term variability in billings, we don't expect this to have a meaningful impact on our ability to deliver our three-year targets. With that, I will turn it over to Deepak.

speaker
Deepak Golecha
Chief Financial Officer

Thank you, Nikesh, and good afternoon everyone. I'll cover the specifics of our Q1 results, additional details on drivers behind the results, and our Q2 and fiscal year 2024 guidance. For Q1, revenue was $1.88 billion and grew 20%. Product revenue grew 3%, total service revenue grew 25%, with subscription revenue of $988 million growing 29%, and support revenue of $549 million growing 17%. We saw consistent revenue contribution across all theaters. America's grew 20%, EMEA was up 19%, and JPAC grew 23%. The strength of our next generation capabilities continues to drive our results, with NGS ARL exceeding $3 billion for the first time and growing 53%. We saw strong contributions across this portfolio in Q1. We delivered total billings of $2.02 billion, up 16%. Total deferred revenue in Q1 was $9.4 billion, an increase of 32%. The main performance obligation, or RPO, was $10.4 billion, increasing 26%, with current RPO just under half of our RPO. As Nikesh mentioned, we saw the rising cost of money have an important and incremental impact on customer behavior in Q1. We are responding to this in the ways we have discussed previously, including using annual billing plans, financing through PAN-FS, and partner financing. In Q1, this had a negative impact on our billings, although as you can see, we saw strength in NGS ARR and revenue. Our non-GAAP earnings per share was significantly ahead of our guidance, growing 66%. This was driven primarily by the significant increase in our non-GAAP operating margins, which expanded 760 basis points year over year. We continue to benefit from the scale inherent in our business, especially as some of our next generation security offerings scale. We again delivered strong cash flow in Q1 with trailing 12 month adjusted free cash flow of $3 billion, achieving trailing 12 month free cash flow margins of 41%. Moving beyond the top line, gross margin for Q1 of 78% increased 370 basis points year over year. We again saw year-over-year improvements in product margins with the normalization of the supply chain environment. Service gross margin improved to 78% as our newer offerings continued to gain scale. Our operating margin expanded by 760 basis points in Q1 as we saw higher gross margins and efficiencies across our three operating expense lines. We are pleased with our operating efficiency progress against our medium term targets. We continue to make significant investments to support our top line growth expectations, including investments in product and engineering, building sales capability, and supporting our ecosystems and our go-to-market organizations. Turning to the balance sheet and cash flow statements, we ended Q1 with cash equivalents and investments of $6.9 billion. Q1 cash flow from operations was $1.526 billion with total adjusted free cash flow of $1.489 billion this quarter. As is typical for our Q1, this cash flow performance was primarily driven by strong collections in the prior quarter based on the strength of our Q4 bookings. collections in the quarter, but based on the strength of our Q4 bookings. Over the last several weeks, we announced that we have entered into definitive agreements to acquire two companies. On October 31st, we announced our intent to acquire Digg Security Solutions for approximately $232 million in cash, excluding the value of replacement equity rewards. On November 6th, we announced our intent to acquire Talon Cybersecurity for approximately $435 million, excluding the value of replacement equity awards and inclusive of cash on Talon's balance sheet at closing. We expect both transactions will close in our second quarter of fiscal year 24. During Q1, we repurchased approximately 300,000 shares on the open market at an average price of approximately $227 per share for a total consideration of $67 million. As a reminder, our share repurchase program is opportunistic, and we're committed to returning cash to shareholders over the medium term. Stock-based compensation expense declined by 250 basis points as a percent of revenue year-over-year. As expected, stock-based compensation ticked up slightly as a percent of revenue quarter-over-quarter with the issuance of a portion of our fiscal year 24 grants. On a year-over-year basis, we continue to manage our SBC down as a percent of revenue in line with our long-term plans. Before turning to guidance, I want to frame some of the impacts that we're seeing on our billings. As Nikesh noted, we see strong demand in the market and continue to see customers make a technical selection of offerings across our portfolio. From here, we see more customers asking for deferred payment terms, either with annual billings, financing through PANFS, or pursuing external financing. Some customers are looking for additional discounts for upfront payments as they grapple with the cost of money. Our strong financial position, which includes $7 billion in cash, cash equivalents and investments, combined with our many options in dealing with this dynamic, gives us significant flexibility. This can impact our billings trends quarter to quarter, and we're reducing our billings guidance to account for this through the fiscal year 2024. RPO and CRPO have more of a direct impact on future revenue. This quarter, with duration towards the low end of the range we've seen over the last several quarters, we saw strong trends in CRPO. As we see low customer churn, we're confident that, independent of specific billing terms and contract lengths, we can continue to grow RPO at levels that support our forward revenue growth ambitions. Now moving on to our guidance for Q2 in the year. For the second quarter of 2024, we expect billings to be in the range of $2.335 to $2.385 billion, an increase of 15% to 18%. We expect revenue to be in the range of $1.955 to $1.985 billion, an increase of 18% to 20%. We expect non-gap EPS to be in the range of $1.29 to $1.31 per share, an increase of 23% to 25%. For the fiscal year 2024, We expect Billings to be in the range of 10.7 to 10.8 billion dollars, an increase of 16 to 17 percent. We expect NGS ARR to be in the range of 3.95 to 4 billion dollars, an increase of 34 to 35 percent. We expect Revenue to be in the range of 8.15 to 8.2 billion dollars, an increase of 18 to 19 percent. We expect our fiscal year 24 operating margins to be in the range of 26 to 26.5%, up 190 to 240 basis points versus fiscal year 23. We expect our non-GAAP EPS to be in the range of 540 to 553, an increase of 22 to 25%. And we expect adjusted free cash flow margin to be 37 to 38%. Additionally, please consider the following modeling points we expect a non gap tax rate to remain at 22% for the second quarter and fiscal year 2024 subject to the outcome outcome of future tax legislation, we also expect cash taxes in the range of 230 to $280 million. For the second quarter, we expect net interest and other income of $55 to $60 million. We expect second quarter diluted shares outstanding of 339 to 342 million shares. We expect fiscal year 2024 diluted shares outstanding of 338 to 343 million shares. And we expect fiscal year 2024 capital expenditures of $175 to $185 million and $40 to $45 million in Q2. With that, I'll pass it back to Walter for the Q&A portion of the call.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-

Investor presentation