All right. Looks like we're just about ready to get started. Okay, good afternoon, everybody. Thank you for joining us. Really delighted this afternoon to have the CFO of CyberArk, Josh Siegel, with us. Josh, thank you so much. I'm Hamza Fodderwala. I'm a cybersecurity analyst at Morgan Stanley. Before I begin, brief disclosure, for important disclosures, please see the Morgan Stanley Research Disclosure website at www.morganstanley.com/researchdisclosures. All right, I think I'm getting better at repeating that. Josh, thank you so much for your time. Really appreciate it. I wanna start by kinda level setting the conversation. You know, CyberArk has been one of the better, if not one of the best, cybersecurity stocks year to date from a relative performance standpoint. Can you talk a little bit about the demand environment for Identity Security? Why has it been more resilient relative to other areas of spend? Why is it such an important priority today versus, let's say, two, three years ago? Yeah. Great. Hamza, thanks for having us. By the way, maybe we should switch seats. Okay. Because this way I can look at you and. Yeah, yeah. No one wants to look at me. Now I can look at both, everybody. Yeah. Okay. Same question. Thanks for having us here at the conference. When we think about the demand for cybersecurity, you know, clearly we're all, like, exposed to what's going on in the macro environment and the likes, but... When you think about cybersecurity, the threat environment has never been higher than it has been over the last year, over the last two years, and there's a lot of obvious reasons for it. I mean, the Digital Transformation and, you know, COVID really spurned it, as well as it going on before that. When we think about CyberArk within cybersecurity, we're thinking about Identity Security. If you look at all the breaches around that's going on in the threat environment, you know, well over 90% of those breaches are going to occur because some credential, whether it's a human credential or a machine identity, was breached. Basically, it went through on the entire attack chain of moving from credential to credential until it got to finally where the bad actor was trying to get to, whether it was the personal identifiable information or the credit card information or the IP or for whatever the purpose was for the bad actor. CyberArk plays in cyber, in Identity Security. When you think about preventing, you're thinking about, what am I doing to secure proactively, not just manage identities, but actually secure the privileged users who are the IT administrators, the workforce which go up and down in privileges during the day, and of course, the application credentials. It's basically has remained, as you said, more resilient even in today's environment. Got it. Where CyberArk started was on the privileged access security side. These were IT administrators, the users that were really securing the crown jewels of the organization. Can you talk a little bit about how that privileged access security market has evolved to encompass not just users, right? You mentioned machines and how are some of the infrastructure changes within IT driving that? You know, first of all, application credentials has always been a major backdoor, and CyberArk's been selling, you know, for over a decade, you know, privileged access for application credentials as well. They were static applications. In other words, the credential was hard-coded into the application. It would speak to another hard-coded app credential into another application. Essentially, it was what we call static. What has changed and has made has proliferated even more machine identities that I was referring to, is the fact that now they're dynamic. There are dynamic credentials in the DevOps processes, for example. Every developer now, as they're doing, as they're working through DevOps processes, are creating what's called secrets. That's why we even call the whole thing now secrets management as opposed to application credential management. Those secrets are constantly, are dynamic in the sense that they're rolling up and they're rolling off, and they're co-constantly changing. That's been a result of the DevOps, you know, processes becoming big. Even with static applications, because of the digital transformation, so many more things are being automated. If you think about robotics processing, you know, which is now running processes through an IT organization in an enterprise, those are also still static. There's a lot more applications that are running credentials. Kind of where we continue to expand, you know, on the market is around the entire workforce, thinking about not just viewing the workforce for how do you manage your identity to know that single sign-on and multi-factor, which is pretty basic. Understanding that even the standard workforce employee is going up and down in privileges during the course of the day, whether it's, whether it's the treasurer who now has access banks or the head of HR, which has to access SuccessFactors or some, or some ticketing system for HR or marketing and running their social media feeds and so forth. What we, what we believe is really important for enterprises to think about is securing the entire organization, including the workforce now, as if they have the crown jewels as well, because they don't always, but they do during courses of the day, and that's exactly what bad actors are looking for. They're looking for, when do I access this credential at a time when they're doing something that I can leverage to actually get to something more valuable or to another account. Over time, I mean, it's the infrastructure of digital transformation. It's just much more usage. It's the remote usage, and it's the fact that individuals and workforce are becoming much more privileged and not just IT administrators. Got it. You talked a little bit about the importance of Identity Security as we move more toward this hybrid workforce, as you're using more cloud applications. You know, when we used to think about Identity Security, initially you think about single sign-on and MFA, which is what you offer as well. You guys came through it from the roots of Privileged Access Security. Why is that a harder problem to solve for some of your competitors versus the access management side, which you said sort of is more basic? Yeah, I mean, first of all, it's just the pure access side of single sign-on and multi-factor is pretty basic. I mean, there's actually a lot more to that world which we are trying to bring to the table, which is we think is much more advanced usage, whether it's also provisioning, securing the session that the workforce is doing, like we do with IT administrators, or allowing them to have password management for their non-enterprise passwords, you know, similar to what you might get from, you know, a LastPass or something like that. There's a lot of things also on the identity side. To answer your question around why is PAM so hard for others to come to, and it's because when you think about, first of all, the IT administrators and the PAM side of the business, it's the crown jewels, always, not just part of the day. It's like 24 by 7. Their credential, if you break into that credential, you're only 1 or 2 or 3 or 5 steps away, but you're much, much closer to kind of what we call a network takeover, which is kind of the Holy Grail for a bad actor. They need to be on 24 by 7 alert all the time. These administrators are also working with all parts, all types of the IT network. It could be with firewalls, it could be with mainframes, it could be with cloud providers, it can be with Microsoft servers, and of course, you have all of the administrative access going on at all the endpoints. There's just such a broad variation of what you need to be able to manage, and it's not just kind of the same for everybody. Everybody needs to be looked at differently. One of the things that CyberArk has done over time and is that just to kind of help create the competitive moat, so to speak, is that we work out of the box with almost every piece of the IT infrastructure. Even if you have the technology to secure the PAM on the privileged users and the privileged credentials, you need to be able to interface when that privileged credential is working on any piece of the IT enterprise. We sell to, you know, mostly to medium and large enterprises, and when you think about your own at Morgan Stanley infrastructure or anybody here thinks about their infrastructure, it's much more than just a small shop. It's very hybrid. It could be multiple clouds, it could be on premise, it could be cloud, it could be legacy servers and things and more advanced and more advanced technologies and because of our experience, we work with all of them. Got it. Got it. Another thing that we're hearing more and more is cyber insurance, right? Cyber insurers are requiring privileged access security, more and more, as part of their underwriting criteria. How is that bringing you into customers beyond the large enterprise? How penetrative would you say that opportunity is? I think, you know, with cyber insurance, it's like, you know, we like to just collect more and more tailwinds to our demand environment, and I think that cyber insurance is one of them. I mean, if you think back, I mean, here we are in London, in the House of Lords and all the you know, the leading underwriters of the world. If you think back years ago, basically on the cyber insurance front, they would just, you know, raise fees to be able to cover their risk. Then they realized, I think in the last three years when ransomware become super abundant and the cost of an actual network takeover for an enterprise, and again, I'm talking about enterprise, even if it's a commercial-sized enterprise selling, you know, $1 billion a year, it still could be a massive expense to be on the front page of the paper for a cyber breach. I think that the insurance companies are saying, you know, "Okay, well, we can't just keep raising fees. We will, but we can't just do it ad nauseam. And so let's start to try to reduce the risk at the same time." Once they went under the hood to determine, okay, well, how do we ensure to help reduce the risk, the basic you know, cyber strategy principles came out. I mean, they're not a secret. They decided, okay, well, you need to have, you know, a firewall to make sure it's harder to get in, and you need to have, you know, something at the endpoint that gives, you know, administrative access, least privilege and reduces the ability of and can prevent ransomware, and you need to have privileged accounts, which are the 9 or 95%, you know, of network takeovers protected. If you'd, you know, do some of those basic things, then they're reducing their risk, and it helps to. That's why it's become a tailwind, because they understand they have to do both, not just play with their fee structure, but also to have enterprises reduce the risk. Got it. To shift the conversation to sort of the broader macro environment, right? Security, you mentioned, you know, obviously relatively more defensible than other areas of IT spend, but certainly not immune to the macro pressures. You've, you know, been through, You know, one or two cycles with CyberArk. I'm curious, all the secular tailwinds you mentioned, you know, certainly are there, but anything that you're seeing on the margin maybe on the macro front that, you know, you worry about or you're considering as you think about your outlook for next year? Yeah. I think, you know, when we think about next year, obviously, we're looking at, let's call it the harder visibility of what will happen. We know what's happening today. We know what happened over the first nine months of this year. The fact that there's, you know, there's this macro volatility going on, we wonder, okay, well, is there going to be a moment where things either turn to worse to the right or maybe starts to turn better to the left? When everybody's thinking about their next year plan, they're thinking about how do I hedge for that? Clearly, we need to t he visibility of what this type of environment gives, you know, any type of an executive in an enterprise, reason for concern 'cause we have to kinda gamble which way things are, which way things are gonna go. You know, I think we always are in, you know, we're not worried about the actual threat environment. I mean, not, you know, that we're praying for new threats, but, we, you know, we see that that trend has left the station, so that's always. In harsher economic environments or geopolitical environments, we actually see the threat environment going up usually, historically. The other thing that's interesting about where we get some comfort from the demand environment is in this type of a, in this type of an economic environment, you're seeing a lot more companies make downsizing decisions. Downsizing decisions actually is a big proponent for insider threat as well. Insider threat is something that is protected by, is one of the first things you're gonna do for, you know, to have make sure you have privilege controls and workforce controls and application controls. That's actually there's been a lot of discussion around the rise of potential insider threat when you have people being laid off or some volatility within the organization. On the negative side, for me, it's really the visibility, that it's really hard to know what's gonna happen and in what quarter it's gonna happen. Got it. The other thing that we're hearing in this macro backdrop is around consolidation. The average enterprise is using 50 different security tools. They're using multiple identity tools as well. It seems to me, CyberArk is really building this broader Identity Security platform story. You've got 20% of your ARR not coming from access management, another 20% that's coming from the Endpoint Privilege Manager. Are you seeing more consolidation within your customer base than you have, let's say, a couple of years ago? Do you think right now is the time for you to double down on that, continue to consolidate the market, and that might include maybe perhaps pursuing some inorganic opportunities as well? Yeah. Absolutely with our success in really moving into the Identity Security space as opposed to just the privilege space, we're seeing and we have, you know, tons, you know, lots of proof cases over the last year where actually our customer base is either moving from the PAM and incrementally moving into our Identity services, and those are all services right now 'cause they're SaaS platform, and as well, moving into, you know, Secrets Management as well. It's happening, I think, in part, one, because I agree with you that enterprises are trying to look to reduce their vendors, but also because we're really able to offer this in a very competitive way. I mean, one of the things that's exciting for CyberArk that's happened in the last month is, you know, we came out in an industry report for now not only being the leader in far up to the right in PAM, we're actually now in the leader space as well for access. We were able to move up from the visionary into the leader space. It really makes us the only company in the world that is in the Leaders quadrant, both for privilege access and for identity access, which allows us to really to stake a claim on true Identity Security. It allows us to really talk to enterprises about thinking holistically across your organization. How do you think about securing all of your credentials, whether they're human, whether they're machine, whether they're static or dynamic, whether they're in cloud or whether they're self-hosted, and multiple clouds for that matter as well. That, that gives us a very powerful statement, and I think, you know, we're still at kind of at the beginning of that larger story, but I think that, it resonates well. Right now, every CEO, CFO is having to deal with the question about growth versus profitability. It seems you guys have always been a profitable business prior to the transition and, you know, you'll get back to those margin levels at some point. When you think about that, right? Right now, it seems like relative to other some of your competitors who are struggling, cutting OpEx, you have a time to really a keen opportunity to continue to consolidate that market. Do you think right now is actually the time to double down on growth? We're continuing to invest in growth. This year, we're always were with the theme of investing in growth, partially because in order for us to invest in growth, we actually have to do it in advance because it takes our sales teams time to ramp up. It takes the sales cycles are six to nine months. It's a bit because we sell into the enterprise space, software enterprise space, we do have to be thinking about these things in advance. We are still bullish that the Identity Security market is a growth market. I think in this economic environment, we need to be more prudent about thinking, okay, doubling down is kind of 2021 language as opposed to 2023 language. Absolutely, we don't wanna leave money on the table, and we want to be sure that we're able to be there through 2023, assuming, you know, that the demand environment remains and the economic environment, you know, suitable to it and mostly that means around especially investing in the go-to-market side. Got it. Just a couple more questions and then I'll open up to the audience. You're at the tail end of the subscription transition right now. The ARR growth has accelerated throughout the year. To what degree is that ARR growth being driven by your existing maintenance base converting to SaaS or subscription? Yeah. To a very small degree. I mean, if we saw 49% ARR growth on Q3 to Q3 last year, it's just in the single digit percentage points of that are because of what we call migrations or conversions from kind of maintenance to either SaaS or to self-hosted subscription. We should be clear about when one of our customers actually migrates from a maintenance contract to either moving everything to the cloud, which is a kind of a, you know, one part of their story, or saying, "Okay, I want to buy more seats of what I had, but I'm going to subscribe now," because those new products that we're selling to subscribe to are much more feature rich than what they had bought as a perpetual product. They say, "Well, let's go backwards and move all of my perpetual product to the subscription product in order to enjoy the feature rich of the subscription product." That's really a tech upgrade, so that's kinda similar to what we were doing when everything was perpetual. We'd go back to them and say, "Don't you wanna buy all these additional features to your perpetual story?" It's only the piece of the business, so some piece is maintenance that goes to the subscription, but a big piece of that incremental ARR is because they're paying more money because they're getting a lot more product on a per seat basis. But in the end of the day, I think, you know, it's still a small, less than 10%, is moving over to, is kinda the right hand moving to the left hand. Any, like, early data points you would have what the typical ASP uplift might be moving from support to SaaS? You, you know, when we think about it's kind of a range between 2 to 3 times. It depends on whether it's moving to another, you know, a self-hosted environment, but with a new product, or is it moving. If it's moving into the cloud, it's going to be in the higher multiple because it's a more expensive product 'cause we're now hosting the service. We can figure 2 to 3 times. Got it. On the profitability front, you're at the stage of the transition now where the revenues are accelerating 'cause you're lapping some of the transition headwinds. When do we start to see the more meaningful margin leverage come through over the next few years? Yeah. I think the way we're looking at it and what we talked about is, you know, this coming, you know, in the first half, let's call it kind of a, we have a kind of a three-year post-transition, you know, window. If you think the first half is gonna be a slighter, a smaller slope, but improving operating margin. The revenue, we're already seeing a swing back. You know, last year was in mid-single digits, I think 8% growth. You know, this year we're, you know, we're, as the guide is around, closer to 20% growth. We're already seeing that swing back, and that will continue. On the operating, that will help us with the operating margin, but it's gonna be slower in 2023, but then the slope should steepen in 2024 and 2025. Right. That's because more of the sales are now coming from the renewal base. Yeah. It's because when you think about, in 2024 and 2025, I mean, today we're almost between 85 and 90% of all of our new business is SaaS and subscription. Next year, we'll be at 90%+ of the business will be SaaS and subscription. When we think about, like two years from now and three years from now and four years from now, what happens is that you, our maintenance ARR is going to be, you know, maybe 10% of the business, and all the rest of the ARR is gonna be coming from licensed SaaS and subscription. Once we start to round trip, you know, 80% and 90% of our ARR going through, you know, with license, we kind of get back to how we were as a perpetual company. I mean, that's just how the kind of the math works. Assuming we do our homework and we execute well on the renewals. Got it. All right. Any questions from the audience? Hey, thank you very much. Talking about ForgeRock, do you think the transaction should be approved? If so, why or why not? ForgeRock? Yeah. Approved by? By the FTC. Yeah. I actually don't have a strong opinion about it. We, you know, we're okay if it gets approved and we don't really have a position there, and I don't really have a strong opinion. Okay, thanks. Any other questions? Maybe one more from me. You mentioned the margin level is getting back to when you were a perpetual company. When you were a perpetual company, I think your operating margins were peaking around 30-35%. Is that the kind of margin level we could see you get back to long term? You know, I think the first stage that we kinda geared investors towards is more the kind of the rule of forty, kind of, balanced rule of forty. But when we're at a rule of forty for a fully recurring revenue company. It's a very powerful model, even compared to kind of a 30% operating margin on a perpetual, where you have a lot less visibility on being able to replicate it, and you're much more at the mercy of the economy and volatility within the marketplace. Once you're really on a fully SaaS recurring revenue company, then you're able to be much more strategic on keeping that growth going forward because you have so much more power and visibility in the model. It's also easier model to leverage, when you choose to do so. Got it. Got Got it. Any sense you could give us on... I know it's still early days for the SaaS and subscription business when it comes to renewal. What do the net retention rates look like for some of the early contracts that have come up for renewal? Yeah. I mean, so far it is early. The reason why it's early is because, you know, we just started selling SaaS and subscription contracts really in 2020, you know, towards the end of 2020 and mostly into 2021. A lot of we have a two-year duration, so really it's kind of next year or the year after, we'll start to see the lion's share and the bulk of those renewals. What we've seen so far is where we wanna be for renewal rates. If we can continue at these numbers, we're not yet publicly disclosing what they are, but they're renewal rates that are in, you know, best of class nature of what you'd wanna see. We're expanding them. I think that investors can see that because we look at our ARR, and we talk about two-thirds of our ARR coming from existing customers and the third coming from new customers. You look at that growing at 49%, you have to have a high renewal rate in order for that to happen, and also a good expansion of those for that to happen. You also know that a third of that ARR is coming from new customers, so you realize that it's not only at the expense of expansion. Got it. Any other questions from the audience? I can keep going for sure. One over here. Just coming. Thank you. If you have any pushback on the renewal, what is it? What was- If you have any pushback on. Have you had customers say they're not renewing and they're going to competitors? The typical point where we may not have a renewal is actually probably if they bought it and never used it. In the context of they either bought it because of some compliance problem or audit, you know, issue, and then they never really felt like that was, you know, that was. They didn't have their back into it. We have, you know, there have been times where we've lost to competition, but it's, you know, our renewal rates are very high, you know. It's a sticky product, so when they're using it's very hard, it's very hard to want to replace because it's going through the entire IT infrastructure. There's a lot of policy and controls and, I don't have enough anecdotal you know, stories to be able to tell you that there's one particular hotspot for why they don't renew, except for, "Oh, yeah, you know, we just didn't use it. Can I have a follow-up? Zscaler this morning was suggesting that you don't need firewalls. You just need Zscaler. What are they not telling us and what is your offering? Yeah, first of all, we, you know, we don't, you know, we're not in the, we're not in the firewall space, so that's, that doesn't impact us. I, you know, I think that, you know, I'm not a, I'm not an expert enough on Zscaler's positioning, but I do know that you need Privileged Access Management and Identity Security, if you want to have a proper cybersecurity strategy within your enterprise. I don't think you'll find anybody who would disagree with that statement. Anybody have CyberArk specific questions by any chance? Maybe last question from me. The channel has been a real force multiplier for you guys, and you talked about these cloud marketplaces. Maybe just quickly, if you could talk a little bit about how that's been, you know, driving additional sales for you guys. I mean, the main thing around channels, there's two areas. One is enabling and training advisory firms and partners has been a huge point of success. The marketplace that you brought up, specifically AWS, it basically allows us to take advantage of all the enterprises that are using AWS already. Many of them have credits with AWS for their usage of their cloud usage. Selling through AWS, it really reduces the friction for those customers 'cause they're actually able to use the credits in order to purchase CyberArk, you know, solution. It's been a nice, incremental channel for us to develop starting in 2022. We expect to expand on it in a, you know, going into 2023. You know, any time that you can reduce friction with your customers and make it a little bit easier for them to actually put the PO in is a winner. All right, Josh. We'll end it there. Thank you so much for your time, and thank you everyone for joining us. Thank you, Hamza.
Loading workspace