Symantec's Transformation Pains: Industry Observations from M&A Expansion to Internal Audit
As Symantec announced its first-quarter fiscal 2019 results, it is undergoing multiple challenges including executive changes, business divestitures, and internal audits. Industry analysts point out that the veteran security vendor faces challenges in innovation pace and market communication in the endpoint security field, while the audit shadow and extended sales cycles add uncertainty to its outlook.

The cybersecurity landscape that Symantec faced at its founding bears only a faint resemblance to today's threat environment. As this cybersecurity company announced impressive results for the first quarter of fiscal year 2019 (Q1 FY19), it has undergone significant changes over the past several years, including mergers and acquisitions, leadership transitions, and an internal audit. Given that hackers are always two steps ahead of cybersecurity solutions, these changes are not an auspicious sign.
One of the problems facing Symantec and similar legacy companies is the perception of slowing innovation and conservative marketing strategies. Currently, customers and investors need renewed confirmation of security vendors' progress and reliability.
"Although this perception is often unfounded, Symantec (along with McAfee, and to a lesser extent ESET, Kaspersky, and Trend Micro) has struggled to loudly assert its dominance or authority in endpoint security," said Ian McShane, Research Director at Gartner, in an email to CIO Dive.
Although Symantec's stock has taken a significant hit since May due to the disclosure of an internal investigation, its products remain viable. However, the cloud of the audit still looms.
Analyst Perspective
McShane believes that enterprise customers might see value in the issues revealed by the audit rather than rushing to replace their security vendor. Admittedly, Symantec has systematically adjusted its business in recent years, but McShane noted: "Symantec previously seemed to be on a good trajectory of reinvention—especially in endpoint protection and endpoint detection and response (EDR), backed by strong technology acquisitions and organic enhancements."
According to Symantec's most recent financial report, its enterprise security business experienced longer sales cycles in the first quarter. McShane stated that a considerable number of the company's deals did not close as expected, and pipeline management in North America was one factor contributing to the delays. The company remained tight-lipped about specifics regarding the extended sales cycles, not clarifying whether it was related to new business, renewals, or product line impacts. Due to the ongoing audit, Symantec declined to comment publicly. But McShane pointed out that compared to "pure-play endpoint vendors," Symantec's portfolio is quite extensive, meaning it sells to multiple buyers, all of which can impact sales cycles.
"Symantec previously seemed to be on a good trajectory of reinvention—especially in endpoint protection and endpoint detection and response (EDR), backed by strong technology acquisitions and organic enhancements."
McShane stated that protecting renewal business is in Symantec's best interest, but without evidence of strong sales or effective marketing strength, new business may be hard to come by in the short term—this applies to Symantec and all endpoint protection platform (EPP) vendors. Replacing an EPP vendor is a daunting task. He said that existing enterprise customers would need to go through a lengthy process to completely switch EPP vendors, and unless they plan to adopt managed services within a broader security strategy, most organizations are reluctant to make such changes easily.
McShane noted that existing Symantec customers are likely satisfied with product enhancements over the past 18 months, but there remain two major areas of concern:
- "...vendor-simplified go-to-market strategies."
- "...the lack of a unified console or insufficient interoperability between certain areas makes it more difficult to replace existing competitor solutions unless there is already a catalyst for change within the prospective customer organization."
Years of Change Outline a Transformation Picture
Over the past several years, Symantec has made numerous adjustments in an attempt to refocus its portfolio on areas most likely to drive success and divest unnecessary burdens. In 2015, as revenue continued to decline, the company announced the sale of its data storage business, Veritas. Symantec had acquired the company a decade earlier, but during that period, demand for storage and data management software had declined.
Michael Brown, then CEO and President of Symantec, stepped down in April 2016. By August 2016, Greg Clark took over the role. Before Clark took office, the company announced plans in June 2016 to cut 1,200 employees. That plan was similar to the FY19 internal restructuring plan disclosed by CFO Nicholas Noviello in Symantec's Q1 earnings, aimed at cutting $115 million in expenses and reducing the global workforce by 8%.
But around August of last year, five months after Google downgraded trust in its SSL certificates, Symantec sold its website security and PKI solutions business to DigiCert to refocus on its core business—enterprise security and cyber defense platforms.
Timeline of Major Changes at Symantec Over the Past Three Years
- February 2015:Announced approval of a $1 billion stock buyback program.
- August 2015:Announced the sale of Veritas.
- April 2016:CEO Michael Brown stepped down.
- June 2016:Reports emerged of a cost-saving and employee restructuring plan.
- July 2016:Announced the appointment of Michael Fey as President and COO following the completion of the Blue Coat acquisition.
- August 2016:Completed the acquisition of Blue Coat.
- August 2016:Greg Clark became CEO.
- November 2016:CFO Thomas Seifert announced departure; Nick Noviello took over.
- March 2017:Google announced plans to stop trusting Symantec's legacy SSL certificates and to shorten the acceptance validity period for newly issued certificates.
- August 2017:Reached an agreement to sell the website security and PKI solutions business.
- May 2018:Announced the launch of an internal investigation after a former employee raised concerns; the U.S. Securities and Exchange Commission (SEC) became involved.
- August 2018:Announced FY19 restructuring plan, including an 8% reduction in global workforce.
- August 2018:Received a Nasdaq deficiency notice due to delayed 10-Q filing caused by the internal investigation.
- August 2018:Confirmed receipt of five Symantec board nominations from hedge fund Starboard Value.
In 2016, the company completed the acquisition of Blue Coat, which was said to solidify Symantec's position as the industry's "largest pure-play cybersecurity company." According to the announcement, the deal aimed to combine Symantec's existing "threat telemetry" capabilities with Blue Coat's ability to protect users from threats across networks, web, mobile, or cloud. Symantec paid $4.65 billion in cash for Blue Coat, underscoring the company's still substantial cash reserves. The acquisition was meant to usher in a new era, yet two years later, innovation has stalled.
Symantec is still trying new initiatives, such as migrating to the cloud and building an enterprise platform, but the question remains: "Are they moving fast enough?" asked John Gomez, CEO of Sensato, in an interview with CIO Dive. But to be fair, "I think that question could be asked of anyone." Notably, much of Symantec's current enterprise leadership consists of continuations from the Blue Coat acquisition. President and COO Michael Fey, Executive Vice President and CFO Nicholas Noviello, Chief Strategy Officer Brian Kenyon, and Chief Technology Officer High Thompson are all executives who continued in their roles at Symantec.
McShane believes the Blue Coat acquisition brought Symantec "leadership with a good track record of successful execution" and "the first stable leadership team in years across successive CEOs." The stability brought by leadership changes had a constructive impact on engineering and product improvements, ultimately benefiting customers.
How Is the Audit Progressing
In May, during the release of fourth quarter fiscal year 2018 (Q4 FY18) earnings, Symantec announced that the Audit Committee of its Board of Directors had initiated an internal investigation. The audit stemmed from concerns raised by a former employee about financial matters, but no further details were disclosed. Symantec "voluntarily" contacted the U.S. Securities and Exchange Commission (SEC) to inform it of the investigation and would provide more information as the investigation continued. At the time of the announcement, the company stated that its financial results and guidance "may change as a result of the investigation's findings." The company was gathering information and would submit the findings to the SEC once all evidence was compiled.
But in August, in its first quarter fiscal year 2019 earnings announcement, Symantec stated that it had not yet filed its annual report (Form 10-K) for fiscal year 2018 (FY18) and the fourth quarter, and said subsequent periods remained "open from an accounting perspective" and could be adjusted based on the investigation's findings.
"There is an opportunity in the current market for an 'Apple of cybersecurity.'"
"Under the rules applicable to 10-Q and 10-K filings, the company cannot be held responsible for inaccuracies in that announcement," said Anders Bylund, a technology and entertainment expert at Motley Fool, in an email to CIO Dive. "This review is an ominous sign, but the information we have now is not enough to treat the 30% stock drop as a foregone conclusion," Bylund said. The severity of the audit is not yet known, but it sends a signal to investors that the reported financial condition cannot be taken at face value. Even if a restatement is inevitable, Bylund believes it is not the worst-case scenario.
Bylund noted that Apple experienced a similar internal investigation in 2006. The company had to review certain stock option grants between 1997 and 2001, and by the first quarter of fiscal year 2007, its revenue hit a record $7.1 billion, according to the announcement.
Innovation Is an Industry-Wide Issue
The cybersecurity market is highly competitive, filled with vendors offering similar solutions. Secureworks, IBM, and Verizon were listed alongside or even slightly ahead of Symantec in Gartner's 2018 Magic Quadrant for Managed Security Services. However, the composition of the Magic Quadrant does not fully assess Symantec's capabilities. From the perspective of enterprise customers, many cybersecurity solutions on the market today are largely similar, with little substantive differentiation.
"There is an opportunity in the current market for an 'Apple of cybersecurity,'" Gomez said. Setting aside financial performance, in terms of innovation leaders, Gomez does not see a true one. He said the current cybersecurity landscape is reminiscent of a time when there were over a dozen word processing software options on the market. "In the end, you kind of scratch your head and ask: 'What's the real difference between Microsoft Word and WordPerfect?'"
Security experts say Symantec cannot significantly cut its product lines because it relies too heavily on them. Companies like Symantec and LifeLock are in a bind: they cannot cut products that customers are still buying and are satisfied with. "You have to innovate your way out of it," Gomez said. This is an industry-wide issue, not unique to Symantec. Innovating without losing market position is a major challenge. The company has an "excellent threat intelligence team, but that's threat research, not technology research."
