Winning With Security Ritesh Agrawal Product Line Director Rasmus Andersen Partner Sales Development
Agenda EMEA MARKET A LOOK TO THE PAST JUNIPER SECURITY VISION THE ROAD AHEAD WHAT CAN YOU EFFECTIVELY SELL TODAY INVESTMENTS THEMES SUMMARY
Security market grew 4.4% YoY Juniper market share grew 13.8% 80 % of partners expect revenue growth 72% of partners expect profit growth 83% of partners in state of transformation Change in what and how customers consume security. hosted security services grew 38% Q4 2015. Canalys March 2016
The 2015 (ISC)2 Global Information Security Workforce Study
The 2015 (ISC)2 Global Information Security Workforce Study
1800 1600 1400 1200 1000 800 600 400 200 EMEA information Security workers shortage 0 2015 2016 2017 2018 2019 Demand-meeting projection Supply-Constrained Projection The 2015 (ISC)2 Global Information Security Workforce Study
Over next 5 years, you will change WHAT you sell Hybrid IT Software-defined infrastructure Cloud Security Analytics Managed services Mobility HOW you sell Business outcomes Professional services-led Service level agreements Annuity revenues From IT supplier to strategic partner WHO you sell to CIO Verticals Lines of business Developer teams Born in the cloud Internal service broker
Security sales exceeded expectations in 2015, growing 5 percent year-over-year. That's not an accident," he said. It is a result of some really great work by a lot of people at Juniper that I'm extremely proud of. You're going to see a rolling thunder of security enhancements."
A Look To The Past
Market Addressability Verticals Domains Telco WebSP and Hosting/Colo Cable Enterprise Campus & Branch ($3.4B) Datacenter ($2.4B) Strategic Verticals (incl. XaaS/Cloud) Govt/Federal FSI Commercial Service Provider Edge ($400M) TAM $6.2B, CAGR 5% (2015-18)
FY15 reflection THANK YOU! First Y-Y growth in 5 years Domains $500 $ M Rev SRX Only Y/Y TAM Y/Y $400 $415-14% Y/Y $436 5% Y/Y Data Center 27% 13% Campus & Branch 16% 8% Mobile SP 4% 21% High-End SRX 67% Y/Y Growth $300 FY'14 FY'15
2015 Year of Rebound Areas of investment Execution Platforms refresh Virtual innovation L7 Services Refresh: SRX 1500, 3xx, 550, 5K/Gen3 vsrx2.0, csrx, vsrx on AWS, OpenStack/CloudStack Contrail integration 98% IPS efficacy, CP-lite, Tunnel scale UX/Management Cloud delivered Security Certifications Security Director 2.0 Sky ATP 1.0 12.1x46, 12.3x48 Gartner MQ SDSN Partnerships 2 nd place for Carrier Grade FW Vectra, Attivo, Cyphort, Skyhigh, Cylance Partnerships
Junipers Security Vision The Road Ahead
Security Trends Today Network security landscape has changed. CISOs Treading Water Pouring money in security, yet not any more secure Risks posed by threats vs risks to business outcomes Metrics of success: total number of attacks stopped vs reduction of risk Attackers are always gaining, staying ahead 16
A Change in Mindset Bring the whole network to bear. Start talking about Secure Networks. Realize threats are everywhere. They are already inside. They walked in your front door Recognize perimeter security isn t enough Detection and Enforcement should be enabled anywhere Acknowledge security is everyone s problem horizontal and vertical 17
The Software-Defined Secure Network Policy Detection Enforcement Create and centrally manage intent based policy directly aligned to business objectives Gather & distribute threat intelligence, from multiple sources know who the bad guys are faster Leverage cloud economics for real time analysis find the bad guys faster Enforce policy to the threat feed information, real time across the network adapt the network real-time 18
Detection Software-Defined Secure Network Juniper Building Blocks Third Party Cloud Security Feeds vsrx SRX Series Physical Firewall Virtual Firewall Security from the Cloud Detection Security Director Enforcement Juniper Cloud Security Spotlight Secure Threat Intelligence Mgmt/UI: Policy, App Visibility, Threat Map, Events MX Series Routers EX & QFX Series Switches Your Enterprise Network Sky Advanced Threat Prevention Policy Detection Enforcement Policy Security Policy Controller Third Party Network Elements Comprehensive suite of products: Centralize and automate security Instant threat intelligence and detection Dynamically adapting policy, deployed in real-time Consistent firewall capabilities physical and virtual
Use-Cases YOU can sell TODAY
Data Center Use Cases Enterprise Private Cloud Public/Hybrid Cloud Telco DC (xcpe) B2B XaaS/Web DC Hosting/Colo Virtualization/ Microsegmentation /NGFW AWS,/Contrail Integration, IPSec VPN Multi-tenancy, End-toend solution, Services Common Building Blocks L2-L7 Security, NAT, Automation Multi-Tenancy, Virtual, LSYS, Orchestration/Manage ment SRX vsrx Contrail & CSO NFX
Data Center Use Cases Use Case Customer Needs / Identifying Characteristics Scale Features Management Products Customer Benefit Positioning Notes Enterprise Private Cloud <4G Virtual FW, 10G-100G Physical FW for DC Edge & Core. Virtualized DC, Physical DC Edge and DC Core, L4-L7 security, microparameterization and micro-segmentation. Carrier Grade FW Orchestration using VMWare vrealize or Openstack/Contrail. Unified physical and virtual security management. Automation Core & Edge: SRX 5K, 1500 Virtual: vsrx Services: Sky ATP (1500), IPS, AppSec. High performance, HA/6-nine reliability, Unified physical and virtual management with SD, Automation, Integration with Contrail/Openstack & QFX, Highest performance/core and lowest TCO on virtual FW. Integration with vrealize/vcenter is fine. Competitive overall. (NSX integration is planned for H2 2016) Public/ Hybrid Cloud <=1G Virtual FW 1G-10G VPN for intercloud connectivity AWS workload, IPSec VPN, L4-L7 services Hybrid/Multi-cloud cloud with Openstack/Contrail or VMWare environemnt Unified physical and virtual security management. Automation Edge: SRX 5K,1500 Virtual: vsrx on AWS & Contrail/Openstack integration Services: L4-L7 Services including Sky ATP, IPS, AppSec. Hybrid/multi-cloud connectivity using IPSec VPN, unified physical and virtual management with SD, advanced L4-L7 services for cloud, utility pricing model Competitive overall: Differentiated in Openstack/Contrail environment Telco DC [xcpe] <=1G Virtual FW for xcpe High density/low TCO MSPs needing distributed branch management platform [CSO, ucpe, vcpe] NFVs with L2-L7 security services Unified physical and virtual security management. Automation Platform: NFX NFV: vsrx, vmx Orchestration: CSO SDN: Contrail. End to end solution to reduce Opex and increase topline. Open platform for 3 rd party NFVs. OSS/BSS integration, fits into 3 rd party ecosystem, flexible architecture to pick best of breed individual solution components, pay-asyou-grow business model Differentiated: End to end solution with Contrail, NFVs, CSO, NFX. Capture mindshare with csrx high density/low-tco POC
Data Center Use Cases Use Case Customer Needs / Identifying Characteristics Scale Features Management Products Customer Benefit Positioning Notes B2B XaaS/Web DC 10G IMIX physical FW L2-L7 security services, VPN, Carrier grade availability/ha, Scale Automation, GUI based policy management Core & Edge: SRX 5400, SRX1500 Services: IPS HA/6-nine reliability, Automation Competitive overall Hosting/Colo <=4G Virtual FW IMIX per tenant 32 LSYS Physical FW 10-40G IMIX Physical FW Mutli-Tenant environment. L2-L7 security services. Virtual and Physical FW. Except when >32 LSYS is required Unified physical and virtual security management. Automation Platform: vsrx, SRX 3xx, 1500, 5K. Services: L4-L7 Services including Sky ATP, IPS, AppSec. High performance, HA/6-nine reliability, Unified physical and virtual management with SD, Automation, Integration with Contrail/Openstack, Highest performance/core and lowest TCO on virtual FW, pay-as-you-grow business model Differentiated: vsrx and Contrail/Openstack MSDC Competitive overall 100G+ IMIX physical FW, 40G/100G Interfaces L2-L7 security services, NAT, VPN, Carrier grade availability/ha, Scale Automation/ NetConf Core & Edge: SRX 5K, MX for CGNAT High performance, HA/6-nine reliability, Automation, Modular Scalability (Pay as you grow)
Campus and Branch Use Cases Secure Router and Managed CPE xcpe and SD-WAN Campus and Branch NGFW Internet Internet Wireles s APs Multi Services Gateway L2 Switch Enterprise HQ / DC Multitenant Multitenant D S DI NI o e A E t S WAN M M S Connectivity e Controller c A n Aa Al y M t w i c s Private Cloud Retail Public Cloud IPSec VPN D N A e DI ta A I oa SA M A S WAN e M c M w M Connectivity w Controller IPSec VPN IPSec VPN vcpe SRX NFX Retail Internet Campus Edge Firewall HQ or Campus Branch Firewall Branch Offices Branch Office Devices Bank Retail Remote Office Common Building Blocks SRX vsrx Contrail & CSO NFX
Campus & Branch Security Use Case Customer Needs / Identifying Characteristics Key Features Scale Management /Orchestration Key Products Customer Benefit Positioning Notes Secure Router/managed CPE Strong IPSec, VPN, Routing, FW Extensive WAN & LAN connectivity Medium/ Large and distributed enterprise deployments Centralized Management with SD Multiple automation tools Auto install and One touch provisioning Branch: 3xx, 550M Mgmt: SD LTE: CBA Superior Price/Perf Complete security services Path to SD-WAN Competitive in large and distributed enterprise deployments Opportunistic in integrated LTE markets NGFW/APT Excellent App identification NAC Integration Easy add-on of security services for SR/L3-L4 deployments Effective Zero-day threat detection(sky ATP) Geo-IP, C&C and Custom Feeds for third party integration Branch FW Any Scale NAC deployed or <= 2 AD domains Central management with SD easy policies, reports and remediation Branch: 3xx, 550M Campus: 1500, 5400 Bundles Mgmt: SD Easy add-on of NGFW feature set Comprehensive Security services Inline blocking for zero day threats Competitive in Small/Medium Size deployments Customers looking for consistency across DC, Campus and Branch security solutions Pursue installed base refresh(netscreen) Cloud-CPE NFX250 and vcpe Security NFV Services Automation Any scale deployments (Enterprise or SP Managed) CSO and Contrail Branch: NFX250, vsrx Mgmt/Orchestrati on: CSO, Contrail Simplified management / deployment at scale Differentiated with Cloudbased platform
2016 Focus - Service Provider Edge Domain Gi Firewall SecGW Roaming Firewall Scale / Performance / Modularity /NGFW / DDoS/ CGNAT IPSec VPN/ Scale / Reliability/ Automation GTP/SCTP / Billing / HA / Automation Common Building Blocks SRX vsrx
2016 Focus Service Provider Edge use-cases Use Case Customer Needs / Identifying Characteristics Scale Features Management Products Customer Benefit Positioning Notes GiFW 40G-100G FW 1M CPS, 230M Sessions Scale-up/out with virtual FW Carrier grade reliability/statefull HA, CGNAT, L7 Service (URL filtering), DDoS/Screens Mindshare to go virtual/vnf Automation HW Platform: SRX 5K [L4- L7] [Performance/Scale] Virtual: vsrx Scale-out High performance, HA/6-nine reliability, CGNAT scale and feature richness, 40G/100G interfaces, Screens, Rich L4-L7 services Differentiated: Virtual scale-out architecture, capture mindshare with early POC with vsrx Sec GW 40G-100G IPSec 10K-50K tunnels <150 Tunnel setup rate Carrier grade reliability/ha, IPSec VPN/PKI, Advanced routing Automation/ZTP Platform: SRX 5K HA/6-nine reliability, Carrier grade routing, Automation Competitive overall Roaming FW 10G-40G IMIX FW 1G-5G VPN Carrier grade reliability/ha, GTP/SCTP Support Billing interfaces (Dimension), Automation Platform: SRX 5400 HA/6-nine reliability, Automation, Complete GRX protocol support, End to end SRX solution with GiFW/SecGW/RoamingFW Competitive overall
2016 Product Transition Update 2015 NOW SRX100 SRX 110 SRX 210 SRX 240 SRX 550 SRX 650 SRX 1400 SRX 3400 SRX 3600 SRX SRX 5K Gen1 IOCs SRX300, Additional SKU* SRX 320+VDSLPIM* SRX 320 SRX 340/345 SRX 550M SRX 1500 SRX 1500 SRX 5400 Bundle* SRX 5400 Bundle* SRX 5K Gen2/3 IOCs *In pricelist and new ones coming soon.
Investment Themes
Investment areas Enterprise Domain Use-cases Secure Router NGFW / UTM Advanced Persistent Threat Mitigation Software Defined Secure Network Execution SD-WAN Integrated LTE, VDSL vectoring Remote Access CSO integration User FW Performance/scale, AppFW Unified Policy TCP Proxy scale with UTM On-box management with logging/reporting Greatwall 20-40G Price/Performance Mid-range 1RU FW Platform support, File APIs, Protocols, File Types, SD Support, STIX/TAXII/Cybox, 3 rd party feed API Switch/Router port action Partners: End-point (Cylance), CASB (Netskope/Skyhigh)
Investment areas Datacenter Domain Use-cases DC Edge and DC Core (ALL) Private Cloud Public/Hybrid Cloud Telco Cloud B2B XaaS/Web-DC Hosting/Colo SDSN Execution Greatwall 20-40G Price/Performance Mid-range 1RU FW On-box management with logging/reporting NSX and Contrail based micro-segmentation VXLAN Overlay awareness vsrx/csrx support for Azure, 100G vsrx Contrail/CSO with vsrx, csrx Scale-up vsrx (100G), csrx with NGFW features LSYS transition plan using Virtual SDSN Integration with Private/Public clouds
Investment areas SP Domain Use-cases Gi-LAN SecGW Roaming FW Software Defined Secure Network Execution MX Screens, MPC gaps, Summit 3RU, SRX 5K and MX SPC3, vsrx scale-up, vsrx 3GPP features Common VPN (SRX/MX), vsrx scale-up GRX gaps Evolution to MEC/Telco-NFV
Summary Delivered several new offerings that you can sell today Will continue to make it easy for you to sell Investing in differentiation and addressing key gaps Thank you for your partnership
Discussion Questions 1 Is SDSN differentiating, and what else needs to be considered? 2 3 4 Where are you winning and losing today? Do you believe you can leverage the 2016 use-cases to win? How else can Juniper expand Security Partner business?
Thank you