CEO Andy Ory on the secrets of 'opt-in communications,' the myth of unlimited bandwidth and his company's edge over Cisco and more
Not familiar with the terms “session border controller” or “session delivery network”? Don’t worry. Andy Ory, CEO of fast-growing Bedford, Mass.-based Acme Packet, is more than happy to share his passionate vision of how SBCs and SDNs — and the emerging era of “opt-in communications” — will change your business and the world. In this installment of the IDG Enterprise CEO Interview Series, Ory spoke with IDGE Chief Content Officer John Gallant about how Acme Packet is bringing identity, security and control to the wilds of the Internet, and why the world’s top carriers — and a growing number of enterprise IT shops — are relying on the company to reduce costs and develop a whole new generation of network services.
Your technology is widely used within service providers and, thus, widely used by enterprises, but Acme Packet might not be a company that IT leaders are really familiar with. Explain what a session border controller is, and what you mean by the concept of a session delivery network.
From a very high level — and I’m going to make it a little simpler than it actually is — the reason that the telephone system works is that it has a signaling system. A signaling system is like a series of traffic lights. Imagine that we go to New York City and we’re sitting in Midtown at three o’clock in the afternoon in a cab. Now, let’s say I have a little button, an app on my iPhone. I hit it and it turns off every traffic light in Midtown. What happens? We all grind to a halt. Nothing goes anywhere. If you remove a signaling system, all heck breaks loose, chaos ensues and nothing can go anywhere on the network. Well, we’re building a signaling system for the Internet.
A session delivery network is an overlay network that has both signaling and media, but it’s able to control, select, enforce and manage tasks, and manage the packets — like the cars — that are part of these flows. It provides things that the networks themselves can’t. [With the Internet] you can’t actually select an end-to-end path or enforce it. Why do you want to select an end-to-end path? Well, there may be quality, cost, source-based preferences. There are lots of reasons you may want to select something one way versus another. And then you want to manage it, police it. Just because you admit somebody onto the highway, you need to make sure that they only ship so much along that path, because you have a lot of other people sharing that path. If oversubscription ensues, things don’t work, particularly with interactive communication. It’s OK if it takes an extra 300 or 400 milliseconds for your email to download. It’s not OK if that happens with interactive voice or video communication.
So we’re building an overlay network for the global IP network so that things work, and that people can experience application service delivery that’s consistent with what they normally expect in a circuit-switched world where the path is actually a physical path that’s constrained and managed.
Can you put that into concrete terms for someone who’s used to using the Internet for voice and all kinds of things these days? What does your technology do behind the scenes that they don’t see?
We do things like trust, security, identity, reliability, capability and privacy. Here’s an example. When your home phone rings, you don’t even answer anymore without checking the caller ID, if you’re like most Americans. If it says “out of area,” you don’t answer it. That’s part of a signaled communication, right? It tells you, this call is from your mom or your dad. Things like identity are really important, and on the Internet everything is anonymous and free. That’s the real problem. Anyone can send you emails. You can’t really stop it. It’s very, very difficult. But emails don’t interrupt your supper; a telephone call does.
The other thing is that the Internet’s broken as it relates to trust and security. I’ll give you an example. Let’s say you’re a client of Bank of America. But you know Bank of America can’t send you any emails that you’re going to open. I don’t open emails from financial institutions. First of all, I don’t trust any emails that I get anyway. But if you open an email from Bank of America and it said that you know your account’s been compromised and you need to provide your passport or your license to reply to this email so you can prevent any additional identity theft, would you do it? No, of course not.
BEYOND ACME PACKET: Ex-Acme Packet VP forms startup Plexxi
You have no trust that that’s really coming from your financial institution. But what’s interesting is that you go home and you find a letter with a 22 cent or 40-cent bulk-rate canceled postage, and it’s on Bank of America letterhead with the red stripe across it. You open it up. It’s Bank of America stationery and it says your account’s been compromised, you’ve got to dial this 10-digit number to prevent any additional theft, and you do it. And what’s even more curious is that when you pick up that terminal on that network, and you enter those 10 digits, here’s what’s going to happen. Somebody’s going to answer the phone that’s going to lie to you about their name and where they are. You’re never going to meet them, nor are you ever going to expect that you’re going to be able to contact them again, but you’re going to tell them everything: who you are, where you live, what your account number is, perhaps even your Social Security and billing address. It’s really amazing. Because you trust that the 10-digit address you entered into that terminal is where that service provider, that network took you.
So when you begin to think about things like trust, the models come out of closed, privately managed, end-to-end signal networks. They don’t come out of the Internet. So, a session delivery network can provide many-to-many trust capability, which actually is really important. But there are a lot of other things that we do, too, and I’ll put them in the context of enterprise communications, because your [readers] are more IT- and enterprise-oriented.
Have at it.
I have enormous amounts of bandwidth from Verizon FiOS to my home, but so do all my neighbors. All of that bandwidth hits some sort of aggregation point and oversubscription is just a fact of life. The Internet is a loose confederation of a million different clouds of networks that share IP packets on a best-effort basis. That works well for best-effort communications, but doesn’t work well when [you need] quality, when you have an SLA requirement, the packet loss, latency and jitter that eats a telephone call or an interactive video. I have FiOS, but if I have one kid downloading a high-def Apple TV movie, another kid involved in a high-def video game experience and my grill catches fire, I want to be able to dial 911 and I want the network to recognize it. I want it to actually get through the morass of all the other stuff that’s not as important and I want it to go to the right law enforcement or safety agency so someone can show up in a timely fashion to prevent my home from burning down.
The notion of bandwidth being unlimited is a myth. And the notion of all communications being of equal importance is a myth. Some sessions are just more important than others. The Internet, the Layer 3 network, doesn’t think from a session point of view, it thinks from a packet point of view. It isn’t able to recognize and make these kinds of deterministic decisions that need to be made for people to really feel comfortable that the network’s meeting their global need. So that’s another example of what you get out of your telephone network that you don’t get out of your Internet.
Go into more depth about how this session control network can be utilized by enterprise IT shops.
Let’s talk about cost first. There is an awful lot of cost in communications because communications is a strategic tool that’s required for organizations or corporations to engage in core value creation. It’s [central to] coordination and control of different resources inside a company and dealing with customer-facing stuff, internal or external customers. Just look at how much money is spent on contact centers alone on an annual basis in the United States. It’s billions of dollars, billions and billions of dollars. It’s a requirement that your customers be able to communicate with you, and you meet their needs and effect some level of customer satisfaction or they’re not going to do business with you in the future. As that moves to video and other more bandwidth-intensive and network-intensive paradigms, the costs are just going up.
The first thing that’s happening is that if you can get rid of a second network, you can save a lot of money. You need an IP network of course, but you also have a TDM network and that costs a lot of money. If you can collapse it down to one set of infrastructure, you can do some really interesting things. You can aggregate the number of network connection points you have so that you can lower your costs. You can engage in networkwide licensing for communications to further lower your cost. You might have five different locations, and the high water mark at each one of those might be 1,000 calls, but you never have 5,000 callers on your network at any one time because the business rolls with the sun. Being able to buy a smaller number of network licenses might lower your cost. Then you have the notion of people who are calling between your locations, and they’re going out over the public telephone network, and you’re paying for it. You have your VPN or your own MPLS backbone that you’d like to actually move the communications along because you have the bandwidth, and it basically doesn’t cost you anything if you can do that. Also, you have resources in the field that are making long-distance calls and if you could have local hop-on, utilize your backbone infrastructure as IP, and then have far-end hop-off, you have two local calls as opposed to one international call. It starts to save money.
You can also save money when you start to look at your audio- and videoconferencing. We’re a relatively small company and we still probably spend $20,000 to $15,000 a month on audioconferencing. What if you’re a large multinational corporation with 50,000 people in the field? You’re spending a lot of money communicating, engaging and conferencing. When you go to videoconferencing, you’re using more and more bandwidth and it becomes really important to leverage the connectivity you’re paying for that you put between these locations. It saves an awful lot of money, particularly if you have a very distributed model like nationwide pharmacies, retail stores.
Each one of these stores has a data and a voice PRI connected to the network. Well, they never use more than six, seven calls on that voice PRI, but people need to be able to call the local store. What’s worse, and even more insidious, is that they’re paying for expensive, very uneven and low-cost call treatment of inbound-calling customers at each one of the stores, because a store isn’t going to spend a lot on a fancy PBX and voice mail system, much less have “zero out” to an operator. These companies are saying, “Wait a second; I have data connectivity to all my stores, why don’t I regionalize my connectivity? I’ve got very high call-treatment capabilities, and then I can route that IP call across my backbone to the local store, complete the call. If not, pull it back to a much, much more cost-effective, higher-quality call treatment environment.” All of a sudden you can start to cut thousands of connections to the network. When you think about what a voice PRI costs on a monthly basis, and you multiply that by 12 and then by 5,000, you say, “Wow!” You need to be preparing and laying the groundwork for higher-bandwidth communications.
That’s the cost side, but how does this change the way a business works?
These are examples of ROI. But the really exciting thing is that everything’s going to change. The telephone world is going to lose and the Web world is going to win.
First of all, we are all federating along economic and social landscapes, and the only way you can deal with a communications environment that federates along those ways is that it needs to be IP because it needs to fit into application service delivery that’s far more intelligent.
We’re moving from ubiquitous communications to opt-in communications, and this is really key. You get an IP device. It does video. It’s got a screen. It does data. It does everything. But it’s your phone as well. You turn this phone on and you’ve entered the Internet, which is free and anonymous communication. Anybody can ring your phone all the time. Then it occurs to you that you can actually take your phone and stick it behind, say, your Facebook page, and only people that are friends on your Facebook page can ring your phone. You moved from ubiquitous communications to opt-in communications that follow your social landscape.
I’m not saying that Facebook is going to be the AT&T of the future. What I am saying is that applications and services are going to emerge that allow us to federate our economic and social lives in a way where we can control who can reach us, when, how and under what circumstances. That is a major, major change.
The other change that’s going on is that for the first time in history we are seeing communications and applications and technologies move from the consumer and the home into the enterprise. It used to be the other way around. It’s amazing. The only way the enterprise can get control of this is to convert everything to IP so that you can secure, normalize, integrate, manage and align these communication flows with your service infrastructure. That is a huge driver. On one end, you’re moving to IP for your voice communications and soon your video communications because you can save a lot of cost and you can leverage your existing infrastructure. That’s network phasing. But [you’re also] phasing your internal customers, you’re moving to IP because it’s the only way you can integrate and normalize, secure and gain control of what’s going on.
And in the end, we’re going to see the emergence of communication-enabled business processes. Today, a business runs with a whole bunch of processes and it has a completely orthogonal infrastructure for its voice communication and perhaps even its video communications. By moving to IP, the business is collapsing and integrating those two infrastructures. You’re going to be able to put contextual, secure, high-quality, regulatory compliant, voice and video dynamically into all your customer-facing applications. That is going to transform the way we deal with each other and our customers.
Can you give me an example of this communication-enabled business at work?
Let’s say you think you’re in the wrong 401(k). But you don’t know anything about 401(k)s and you’re not going to spend four days reading about them. One option is that you pick up the telephone and dial into a contact center of Fidelity. But that’s expensive and Fidelity doesn’t want you to do that. You don’t want to do it because it takes time and nobody ever hangs up as a customer from a contact center and says, wow, I’m really glad I made that call.
Here’s what’s going to happen, and it’s going to happen very, very quickly. You access Fidelity via your iPhone or iPad and you’ve authenticated yourself and established a secure tunnel. You’ve even mucked around, moved stuff and done stuff. If you need some help, contextual help, you can hit the “happy” button right there on your screen and it has voice, video, chat or all three, already secured, already authenticated, with high SLA, regulatory compliant, and fully contextual, saying, “Hello, John, how are you doing, my name is Andy. I can see what’s on your screen and you’ve been looking at 401(k)s. Would you like help? Here, let me put on your screen three different 401(k)s that I think might be interesting. I can see you’ve rolled your cursor over the middle one. Click on the dialog box and you’ll get a 30-second video from one of our portfolio managers.” You do that and at the end the customer support person asks if that’s where you want to move your money over to. You say yes, click on the little dialog box at the bottom and in three minutes you’re going to have a confirming email that as of close of business today your account will be swept and all your money will be moved over into that 401(k).
What just happened there? Think about that. And then think about everything you do on the Web. Think about booking airline tickets. You’ve got two ways to book airline tickets and they’re totally different. One is telephone-based and one is Web-based. With the telephone-based way, you call up a travel agent and you actually can’t see anything, you just hear the clicking of the keys. You get about as good a service as you’re willing to press for, and as committed as the travel agent is. The person is basically saying, when do you want to fly, where do you want to fly to, here are your options. The alternative is you go to Expedia or Orbitz or Travelocity or Delta.com and you look yourself, and you type in different parameters, airports within 50 miles, you type in different departure times, you just look at different stuff. But wouldn’t it be nice if you could get a little bit of help inside of your Web session? The person doesn’t have to ask you who you are. You’ve already authenticated yourself. They don’t have to ask you where you’re going because they can see your screen. And when they put data on their screen it appears on your screen. Oh, by the way, so you need a rental — if you need a rental car when you’re in Seattle click on the Hertz button. By the way, if you click on the Hertz button, you don’t go to Hertz and they ask you who you are, where you’re flying, when you’re coming in. They’ve got all your data already secure inside the session and they can decide what they want to do.
We’re going to see really rapid innovation that’s going to occur with interactive communications. What a session delivery network does is it allows the underlying IP infrastructure to be driven by the innovative applications and services that are at a higher level, and that’s what’s so exciting. You’re really going to see the whole world change in ways that human beings relate to, because we’re visual creatures, we’re auditory creatures.
Andy, talk about the competitive landscape. Who are your core competitors and how do you differentiate yourself?
[We compete in] two worlds — the service provider world and the enterprise world. In the service provider world, we were first. We had the initial vision. We’ve invested more than everybody else and we’ve built an ecosystem of technologies and partners that really have made us stand head and shoulders above everybody else. We’ve got five different delivery platforms. We’ve got purpose-built technologies, and we run on general-purpose computing as well. We invest more. We hired more people in the last 12 months than any of our 40 competitors have in total working on this problem set. The business scale of our competitors just isn’t there. That’s why we end up with 65% of the service provider market globally. That’s a dominant market share. We work with almost every major service provider in the world.
But who do you compete against? Is it the Ciscos, the Alcatel-Lucents of the world?
There are 40 companies we compete with in the service provider space. There is no No. 2 — as I define that — in the first quarter there was nobody with even an eighth of our market share. It’s a highly fragmented group of 40 companies that we see in one-off situations, regionally, market vertical or specific customer engagement. Huawei would be an example of a company we’d see in Asia. But it’s really all one-off competition.
In the enterprise space, our main competitor is Cisco, because Cisco is the dominant enterprise infrastructure provider for IP. But the enterprise market last year grew 70% and we grew 98%. I would argue that our domain expertise is truly defensible. And domain expertise is a combination of management focus, experience, investment, vision — just time under the wheels. It’s very hard for people to replicate that quickly. All we do is we build these technologies to build out a session delivery network. We don’t have 17 different business units to do 40 different things. And given that complexity is increasing, the role of our technology becomes more and more important.
It’s heavy lifting to do what we do. Some people say standards are emerging and anyone can make a session border controller. But actually what’s going on is this disaggregation of devices and applications, this complexity of address schemes and business models, this uncertainty of network transport is causing all sorts of issues. Our technology ends up reconciling all that so this stuff works. The end-user experience is simple and it’s high quality, and that’s a very high hurdle for people to compete with us on. I think we ought to continue to take market share in the enterprise space.
Andy, what percentage of your revenue today is enterprise versus service provider?
I would say that directly, in terms of products put onto a customer prem, I think it’s trending somewhere in the high teens — 17%, 18%. You know I would have expected it to be higher. It’s just that our core business kept on growing faster than I would have anticipated. That’s why it is kept down in the high teens. But if you look at the technology that we’re selling to service providers to connect to enterprises for SIP trunking and other enterprise services — products directly [deployed at] enterprises and indirectly on the access portion of service providers network — it’s at least 30%, maybe even a third of our business is enterprise-related.
Give me an example of an enterprise customer you’re working with today and what you’re doing for them.
We have one particular enterprise customer that’s one of the largest financial institutions in the world, and we’ve sold millions of dollars of gear for them to build applications to enable their traders to be more efficient in taking data that appears on their screens from a whole bunch of disjointed applications to make a very, very quick telephone call set up securely as IP sessions. It’s much more complicated than click to dial, but that’s a good way to think about it. It’s transformative. They’re saving time for their key value creators engaged in high value-creation activities.
One of the big things enterprises are dealing with is this move to cloud, either public, private or hybrid cloud. How would do you enable cloud or make cloud easier?
Once you collapse all your service infrastructure into IP, you have an endless amount of permutations for the architectures you can use to deliver these services. So we’re very much cloud-centric. A lot of our services and applications can be delivered in a hosted format, which is a fancy way of saying cloud. We built out the largest platforms in the industry, all of which are geared around people distributing and offering cloud based services.
One of the critical issues is around security and controlling access when moving to cloud. It seems like your technology could play a really important role in ensuring that.
Absolutely. I do not believe that homeowners and enterprises in the future are going to want to take non-signaled communications just to save a few pennies — because you won’t know if you’re really going where you said you’re going. You won’t know if you’re really talking to who you’re supposed to be talking to. You won’t know whether the communication is really private. There are a lot of things that you won’t know if it’s not over a signaled network or session-oriented network. This whole notion of architectures and separating people from the application servers and having multiple domains partner together to deliver end-to-end services, clearly a signaled network creates a determinism, it creates an expectation of quality and enforces a type of security.
You were talking about Cisco and you mentioned that unlike them you are focused on one market, while they have lots of other products in lots of other areas. But how do you sustain your growth? Do you see, using [Cisco CEO] John Chambers’ phrase here, adjacencies that you can branch into?
Let me share with you how massive I believe this opportunity is. If you look for an analog, look for routers and email. Seventeen, 18 years ago, Cisco was making routers. Why? Because enterprises were packetizing their infrastructure to do email, the only application really that was driving them. Son of a gun, wouldn’t you know it, every single enterprise on the planet packetized their infrastructure and connected up with a router, and what was built was a routed network. And the routed network allowed for innovation. Then, in relatively short order, email became one-tenth of 1% of what was flowing across those networks. Amazon, eBay, Wikipedia, Yahoo, Google all started flowing across these networks.
So now we fast-forward 17, 18 years. We’re making session border controllers, and the reason is because you’ve converted your service infrastructure from voice to VoIP and I’m doing the same. When my enterprise wants to talk to your enterprise who wants to talk to a service provider, if we’re going to do it in a secure, high-quality fashion there are going to be session border controllers to connect each one of our enterprises and networks together. Every network in the world, every single one, is racing to move their service infrastructure to IP. Voice will all be VoIP and when session border controllers connect up every one of these networks, VoIP is going to be one-tenth of 1% of what really flows across this overall service infrastructure. You’re going to find applications and services and enterprises dealing with their customers saying: Whoa, I can control, select, enforce, manage, measure, monitor, encrypt, and be encrypted on the path end to end. I can do things that I could never do before because I have that capability. VoIP is going to be like email was to the Internet. If that follows, there’s hundreds of thousands of connection points and we’ve shipped 14,000 units. Most of them are made in pairs, so that’s maybe 8,000 edges. I’m saying there are hundreds of thousands of edges. We’ve shipped $1 billion of product in the aggregate since we started and we’re only 8,000 edges in. That’s why I think this is an enormous opportunity. We are in the first inning of this opportunity. I’m not looking for adjacencies for things that are similar but really aren’t part of an SDN. I think we have a long way to go before that happens.
Give readers some sense of the number of service providers you’re working with today.
You could take any market and cut it in half and have the more valuable half on one side and the less valuable half on the other, and we dominate the more valuable half. Ninety of the 100 largest service providers in the world are working with us. Twenty of the 25 largest cable companies are working with us. We have more than 1,000 service providers in 105 countries. What’s interesting is that from a service provider point of view is that you get in because you’re an innovator, but if you become important, if you become fundamental or strategic to their future, you become an incumbent. It’s easier to pry the lid off a paint can with a toothpick than it is to get an incumbent out of the service provider’s network. Why? Because it takes years and years to approach the service provider, to get them to understand, to do testing, to do training. You do all this testing, you do all your initial deployments, and after four or five years, you’re starting to offer services, they’ve really started to hitch their wagon to your train. What’s interesting is that we’re so lightly penetrated. I think that as this market really starts to move from the early adopters and initial projects to converting their overall infrastructure wholesale to IP, that we are going to benefit by that conversion as an incumbent benefits strategically when their partner/customer ends up making major changes using their technology.
What should our IT leaders expect from Acme Packet in the year ahead?
We will enable more to be done in an increasingly complex world in a simpler fashion. There is a significant ROI vector and a real value creation enhancement to integrating your communications with your business processes. Our technology is almost like a Swiss Army knife that allows you to use any of your business processes, any of your networks, and all of your infrastructure with whatever devices and applications you choose to use to make your business more valuable.




