All right. Okay, good people are coming in. Well, good afternoon, everybody. Thank you for being here. My name is Hamza Fodderwala. I'm the U.S. Cybersecurity Analyst here at Morgan Stanley. With me, I have the pleasure of having the team from CyberArk. We have Josh Siegel, CFO, as well as Erica Smith, SVP of IR and ESG at CyberArk. Before I begin, just a reprogramming note for important disclosures, please see the Morgan Stanley Research Disclosure website at www.morganstanley.com/researchdisclosures. With that, we'll kick it off. Josh, Erica, thank you so much for being here. Josh, thank you so much for coming all the way from Israel. Thank you, Hamza. It's always great to be at the Morgan Stanley Conference. Thanks for hosting us. Excellent. maybe we just level set. you know, you guys reported earnings about a month ago. Their growth has been quite resilient despite macro challenges, overall for security. Just talk a little bit about how you're feeling about the pipeline, your ability to close that pipeline, as you're working through the SaaS transition. Yeah. I think you're right. I mean, CyberArk had a great year in 2022. Our ARR grew 45%. Our revenue accelerated. You know, I really think it's about, you know, not just 2022's pipeline growth, but actually we've been having enjoying really great pipeline growth for the last several years. When you think about CyberArk, we're selling into the enterprise, and you have sales cycles of six-nine months, you really wanna look at kind of pipeline growth over a couple year period. The other thing that we liked about 2022 as we think about being resilient, even in the tough macro environment, is that the engagement level with customers was high. Our win rates remained very solid through the year. We even, you know, from quarter to quarter we're kind of, beating out our own internal expectations on bookings that were reflected in the results. I think that, you know, the one part that it kinda did, you know, rear its head in terms of, you know, on not being as resilient as in the fourth quarter maybe related to, budget flush, you know, that we typically would see in the fourth quarter, and I think macro muted that. Overall, yeah, we're real happy with the demand environment, with the pipeline growth, with our win rates, and overall, the fact that Identity Security remains really at the, at the forefront of where enterprises are looking at for their security strategy. Got it. Got it. You know, you also had announced a CEO transition recently. CyberArk's longtime CEO and founder, Udi Mokady, transitioning to a chairman role, and now you've got incoming CEO, former COO, Matt Cohen, coming in. Just talk a little bit about that transition. What was the reason behind it, and what do you think Matt brings to the table to CyberArk after being COO for the last couple years? Yeah. I think, you know, it's actually an exciting time for CyberArk because, you know, Udi, as you mentioned, was CEO. First of all, he's founder, and he's been with CyberArk for 24 years since the beginning of, you know, founding CyberArk, and he's been CEO during that 24-year period, 18 of those years. I think, for Udi Mokady, you know, it's always been one of his passions to figure out how does he build, a great company, a built-to-last company as CEO, but then how does he remain engaged, even for much, much longer after that? I think, you know, he's kinda always had his eyes on eventually moving to an Executive Chairman, role position. At that point, it's a matter of, you know, what is the right timing to do that, you know, what's gonna be right for CyberArk, what's gonna be also right for making his successor a success in the CEO role. You know, we've known Matt now at CyberArk for three and a half years. We recruited him in as the Chief Revenue Officer. He was an executive in the leadership team before that, you know, in another tech company, very, very, very successful. After a short time, he actually became our COO. You know, some of the major points that Matt has done for CyberArk in the last. Since he's joined was, one, really build a go-to-market engine, structured around data, and really pushing on infrastructure around channel development and the likes. The other piece that he was really, you know, kind of ran the transition that we've all been hearing, that we've been talking about for the last two years on moving to a fully SaaS and subscription company, and he had that experience in his prior home and brought that leadership capability to CyberArk. Also, in 23 already, in 22, he was intimately involved with our design plan for what we're going to try to do this year as well as from an operating perspective. I think what he brings to the table is really a structure, deep structure of cross-departmental leadership. Strong on the go-to-market side, where he spent many, many years in his life, also strong on the operational side. He's very data-centric. A lot of the things that we've done now at CyberArk under, you know, Udi's leadership, and Matt took it forward, was, you know, how do you create a very powerful Revenue Operations team, for example? How do you make decisions around data? I think that's something that we're gonna see a lot of with Matt going forward, I think it's particularly timely when you think about the fact that now we're a fully recurring revenue company, SaaS-led, I think that becomes a lot more critical in growing that type of company, being much more data-centric. Let's talk about Identity Security. Identity Security is still a top three priority amongst CISOs out there, and, you know, big market, $15 billion+ based on industry estimates out there. CyberArk is coming at it from the angle of inside out. You're securing the crown jewels, you're doing the privileged access, and now you're building out authentication capabilities with some of the players out there. Why do you think that gives you the strategic high ground, if you will, versus other players in the market? When you think about where all the breaches are happening, they're all anchored on identity. That's the one constant theme about where breaches are happening. I think the other piece of the puzzle is that once they're happening, what is the process and the attack chain for those breaches? It's basically lateral movement accelerating, taking on more and more privileges and control points. Really what CyberArk does is be able to lock down that lateral movement and break that attack chain. When you think about an enterprise security strategy, you're thinking about, okay, you know, the breaches occur, but now how do we ensure that we prevent against network takeover? By doing that, you have to block the attack chain. It really gives kind of every CISO. We think we're viewed as a must-have on the cyber portfolio front because you want to avoid the big expense of that network takeover, where personally identifiable information gets exfiltrated or ransomware or you can't run. Identity becomes the one constant theme for all the breaches. One other thing to add is that when you think about the migration to the cloud and digital transformation, nearly every user, human user on, within an organization can become a privileged user depending on what they're doing. From our perspective, when more and more workloads migrate to the cloud, what's really gonna be critical is taking those intelligent privilege controls and layering it on top of that access in a seamless way. From our perspective, we think that you have to come from a PAM point of view to be able to deliver that solution in a way that will really secure the enterprise. That's why, from a position of strength, we think it's really important that you come from PAM. Got it. Makes sense. Let's talk a little bit about some of the catalysts that have been driving growth, there have been a lot, right? Just the tailwind around Identity Security as more and more organizations are moving to the cloud and more heterogeneous IT environments. Another one you talked about has been cyber insurance. What's been some of the dynamics there either for Josh or Erica? Yeah. you know, I think, the cyber insurance opportunity is really just another tailwind of putting a stamp of why is PAM, why is Identity Security, you know, so important, to prevent cost to the enterprise. you know, the insurance companies have understood that, they need now to manage the risk of all the policies as they're sold, and they're trying to understand from the enterprises, what are you doing about, okay, there's going to be the breach, but what are you also doing about to ensure that there's not gonna be a cost to that breach? When you think about what they're looking for, it's, you know, obviously, identifying the, protecting the identities through Endpoint Privilege Manager, through Privileged Access Management of those controls, again, to stop the attack chain, which prevents the, you know, the real expense of building up for that's gonna be covered by the insurance policies. These are all products that CyberArk sells. You know, we view it as another key tailwind together with other regulations. It could be GDPR, it could be California Privacy, it could be SOX, it could be, you know, all sorts of financial controls, PCI, and, it's, it's gonna be a long tail, for CyberArk. Got it. Got it. The multi-product momentum at CyberArk has also been quite strong. I think if we think about it, there's the core PAM, there's the DevOps, EPM, and then Access Management. Can you remind us roughly how that breaks down, and where do you see most of the growth opportunities? Yeah. Hamza, when you think about the subscription, the ARR, you're looking at about 55% of that ARR coming from Privileged Access Management, whether or not that's cloud or the self-hosted. It's heavily weighted toward our Privilege Cloud offering. When you look at the remainder, it's about 20% coming from Endpoint Privilege Manager, about 15% coming from our Access Management solutions, and about 10% coming from Secrets Management. I think the wonderful thing that we've seen over the last couple of years is that actually everything's grown in step, meaning that the opportunity for us to grow across all of those areas has nearly been equal. We've seen incredible growth rates across PAM, EPM, Access, and Secrets Management. As we look forward, we continue to expect to see that all of those opportunities be significant for CyberArk. I think if you look at our target to get to $1 billion of ARR by 2025, I think we expect that that complexion will look pretty similar when we get to that $1 billion target because we have a land and expand motion. So even with PAM, we actually land with a smaller number of actual users than the customer needs. The definition of a privileged user has changed dramatically in the last couple of years, so there's an even more significant opportunity to expand. Then the, our other solutions, we actually do have an expand motion as well. We think that that will be consistent, pretty consistent plus or minus a couple percentage points as we look ahead the next couple years. Got it. I mean, speaking of the land and expand motion, you know, the SaaS transition has helped aid in that. I know it's pretty early days on the renewal front, what do those net retention rate look like these days? Yeah. It's a question we get frequently. The net retention rate do look great, right? It hasn't been a metric that we've disclosed yet, and the reason we're not disclosing the metric at this point is that we typically have one and three year contracts. What we've seen, we kicked off the subscription transition in 2021. We've gone through one cycle of renewals, but we believe that in order for that metric to be more meaningful, we'd like to get through another cycle or two of the renewal base to be able to give a real indication of what the business and the renewals look like. As probably everyone in the room knows that's been through a subscription transition, sometimes those numbers can be higher, and we wanna make sure that we set the benchmark in a way that looks really indicative of the business. Now, all of our solutions are incredibly sticky, and with that expand motion, that's why we're very confident that our net retention rate will be healthy when we look forward. Josh, high level. You know now you're, I would say, through most of the subscription transition as far as your net new ARR is concerned. There's obviously still a support base. We've seen a lot of cloud transitions in software not go particularly well. What would you say are the one or two things that has helped CyberArk execute this transition well? Yeah. Thanks for raising that 'cause we're really proud about what we did at CyberArk in the transition. You know, we thought it would take, from all the homework that we did, you know, eight, even more quarters, from the time that we kicked it off. As we talked about last year, we actually were able to get it done in five quarters. We were able to get over that threshold of where we said more than 85% of our bookings was coming from SaaS and subscription. We're proud of that. I think some of the key points of success for us was, one, obviously you really need to make it a full company initiative. I talked about Matt Cohen before leading this initiative, he really created this whole cross-functional organizational team that was then broken out into over, I think, 100 employees that were involved in all different aspects of how do we transition this company and meet our goal of, you know, how many quarters to transition. We kind of divided it into there's obviously the compensation is critical, and you have to really get that right to be able to drive the right incentivizations. It's also around the right packaging of the products that you're doing. One of the things that we really focused on is how do we create more value for the customer so that they were aligned with us for this transition of CyberArk. It wasn't just what's good for CyberArk, it's also what's good for the partners as well. I think that was really critical, how we thought through the technology, the products, and the packaging around that. I think the third piece is, and I talked a little bit about it before, is the more that you are a full SaaS and recurring revenue company, data becomes that much more critical. Understanding what are the mechanics, what are the data behind what customers are buying, what are they using, and rates and things like that. From a perpetual company, we looked at different types of data. We had to really kinda make a move of how everybody's mindset was within the organization for how they were. What kind of data they needed to be focused on, and then how to use that data to be able to get to our mission on the transition. Got it. Speaking of data, maybe I'll throw this to Erica. You know, AI has been a big topic, and I think CyberArk had some research recently about how these new AI techniques are being used to, you know, mutate and create new malware. Talk a little bit about how CyberArk sees the threat landscape evolving as a result of AI and what you guys are doing to help with that. Yeah. It's a great question. We're really excited about the ChatGPT research that the team did. We have this entire organization within the company that actually focuses on essentially threat hunting. They look at the latest and greatest technologies and see how that can be impacted or will impact the threat landscape. With ChatGPT, you mentioned that it was constantly or continually evolving from a malware perspective, which has massive ramifications for a company, right? It really does emphasize the fact that organizations have to think like an attacker and actually take an Assume-Breach mindset. That's exactly what CyberArk does from a solution perspective. We can help our customers come in and lock down that environment through heightened privileged controls, whether or not that be time-based access or it's putting the credentials in a vault, depending on how you're working. No, that type of solution will really does reinforce the fact that you have to take or enable our customers to take that Assume-Breach. This is one of the areas that we expect to continue to evolve and only accelerate now that AI is really in the mainstream. Got it. Pretty exciting stuff. Josh, you've got the majority of your new bookings, the vast majority of those are subscription now. You still have a couple hundred million or so, on maintenance and support. To the extent that you have data on this so far, what is the uplift from a support customer moving to the SaaS product? Yeah, I mean, we're basically seeing about 2x-4x move on the increase from when companies are saying, "You know what? We have our existing install base. We wanna particularly if we wanna go to a cloud environment, then we wanna move to Privileged Cloud and move to the SaaS environment," we'll see that type of an uplift. You know, we're excited about it. What's been good is that it's actually, it's been happening gradually and over the last couple years. It's not like, you know, if we look at our 45% ARR growth rate last year, only single-digits% was coming from actually customers converting or migrating from their from their maintenance piece over to either SaaS or subscription piece. The good news is that there's still this huge, you know, tail left for us to, you know, continue to work with on those customers, and we were still able to grow on expanding our install base and bringing new customers. We, we like the uplift and the impact that we're able to get when they move because in some of the things that Erica was talking about, we're able to really expand them across our entire end-to-end platform. Are there any incremental levers that you're looking to pull to move that support base perhaps faster? Not exactly. We're really, we're really in favor of moving at the customer's tempo. One of the things at CyberArk is that we're very customer-centric. It's one of the reasons why we only now did this transition in the last couple years, 'cause we thought it was only now the right timing where we could be aligned with our interests, also aligned with the customer. I think what, you know, what I said earlier is that we think that if we do it naturally with the customer, there's enough growth from our existing install base that's already doing SaaS and subscription. There's enough greenfield and new enterprises out there, new logos to go after that we think kind of the gradual trend is fine. We also are, you know, we enjoy the maintenance base. It's a lucrative and, you know, strong financial base for us, but we're willing to go with the pace of customers' journey. You know, one of the things that you saw with the SaaS transition was, a reduction in the sales cycle. I think you mentioned that. What does the sales cycle look like now for the SaaS product versus the on-prem? We still typically see a six-nine month sales cycle. I think the area that we continue to see a more efficient sales cycle is with the add-on, the fact that that velocity of that add-on business is coming quicker. When a customer lands with a SaaS solution, they're typically adding on new users faster than what they would have done in the perpetual license model. We're seeing that flywheel effect kick in. We also see the opportunity to expand into the other solution sets, really take advantage of that Identity Security Platform and the shared services to be able to more quickly evolve into the other solution areas. We're excited about that as well. Got it. Last question, I'll open up to the audience. Profitability. CyberArk, prior to transition, had best-in-class margins, close to 30%, and that was at a much smaller scale as well. Do you see a path to get back to that? Any color you could give us on sort of the timeframe around that? We definitely see a path back to profitability. I mean, as we know, you know, through the transition, the, you know, the P&L from a profitability's perspective, got turned on its head. Actually, and we gave color on this all along through the transition, if you really kinda think through and kind of equate on an apples-to-apples basis, our perpetual, our SaaS and the subscription business to perpetual, we were actually profitable and still profitable today, you know, through the transition. Maybe not at the 30% levels that we had in the year that you're talking about, but definitely well into the double digits, and in some cases, you know, north of 20%. If you were to look all the way back to the beginning of the transition and compare it to 5%, you know, where it was 95% perpetual, we would actually be, you know, very attractive on the profitability side. Where we are now as we finish the transition, we hit our trough on profitability in 2022, where we're expecting to see improvement this year in our guidance we provided. Then we expect to see even accelerated profitability when we in 2024, and then again into 2025. You know, we're very focused on this profitable growth to give us, you know, get us back to the Rule of 40 in 2025. The reason why it ramps in 2024 and 2025 is 'cause that's when the base comes up for renewal? It's the one. Exactly. When we have more in 2024, more of the full flywheel. I mean, it's partial this year. Yeah. It'll be more so in 2024, it should in 2025 already be a full round trip. Got it. Anyone in the audience have a question? We got one over here. How do you view your competitor Delinea as they're trying to expand from the small SMB mid-market towards the enterprise segment? Do you foresee going to a pricing competition with them? Yeah. We've competed with Delinea is now a combination of two distinct companies, merged into one, and we've competed with them over for quite a long time. I think from our perspective, we think that we are at more of an enterprise solution. They haven't really made as many inroads upmarket as. While they have a strategy to move that way, we do think we've got a great competitive position from our perspective. We also think that the oftentimes what we've seen when an organization goes through a merger or moves hands within the private equity world, there tends to be a bit of disruption in the near term. I think they, Delinea is in the first phase of that merger of those two organizations. To a certain extent, we see it as an opportunity for us to continue to strengthen our leadership position in the enterprise. As we move downmarket a bit into that kind of mid-market segment where we traditionally haven't played, we do think there's an opportunity for us given that the changes that have happened within that organization. Any other questions? Okay, I can continue. Going back to growth versus profitability. When I think about CyberArk, you're still very under-penetrated in your market opportunity. I think you're the only identity vendor that hasn't had to meaningfully slow hiring or do a RIF, and seems like execution is quite strong. How does that factor in terms of your thoughts on growth versus profitability? Do you think this is a time to invest, or are you gonna maybe pull back a little bit? Yeah, I, you know, we're definitely in investment mode for growth because of what you said, that we're under-penetrated in the opportunity. We're in a leadership position. We've recently really expanded our position of strength to now cover the entire Identity Security market. You know, we are the only company in the world that is a leader in the Magic Quadrant for both Privileged Access and for Identity Security. You know, as we said also earlier, CISOs and enterprises, and even going downmarket, they're understanding that they need to look at a much more holistically all identities within the organization as privileged, as Erica was talking about before. Also not just for human users, but also for machine identities. I mean, there's 40 x the number of machine identities, as there are human users in any organization. We're investing for that growth opportunity, not to leave money on the table. At the same time, though, we're also focused on profitable growth and leveraging our model to be able to get back to that Rule of 40 that we talked about. When we think about what's gonna weigh on that Rule of 40, on the balance on margin and on growth, at this point, it looks like it's gonna be on the revenue growth side. You know, we think that when we think about revenue growth, we think about it in multiple years 'cause everything is a long cycle for us. Sales cycles are six to nine months. Bringing AEs up to speed is six-nine months. Development cycles are one-two years, you really kinda need to invest ahead of the game. All the time that we see the next several years in our favor and our position is coming from one of leadership, we'll be in investing mode, but still always improving the profitability. Got it. Got it. Any other questions? By the way, just wanna pause real quick. No? Okay. The channel, I mean, one of the things that we heard a lot was CyberArk going through a lot of these marketplaces. Curious how that's been a additional lever of growth for you guys in the last couple years. Our channel investments generally have really been a great driver of growth. The really important thing for everyone to know is that we still think that there's a lot more room to drive efficiency across the channel. When you think about the marketplaces, we made a significant investment in the AWS Marketplace last year. We've seen the business going through AWS more than double. I think that really reduces the friction within the sales process, right? You're able to get a faster sales cycle 'cause you're leveraging the paperwork from AWS as well as some of the credits they may have within the organization to really speed up the efficiency within the sales process. We believe that there's a lot more growth to get, through the AWS channel, and we're really looking forward to seeing what, how we can drive more of that in 2023. Got it. Last question just on capital allocation. You do have a considerable amount of cash on the balance sheet. How are you thinking about M&A build versus buy, as you know, plan to get to a multi-billion dollar ARR company? Yeah, you know, we've been acquisitive. Most of them have been either, they've been a combination of tuck-ins or actually, kind of a make or buy decision, as you pointed out, like Idaptive, where we decided to buy on the access front in order to bring us closer to market, and buy us a couple of years on time to market. Conjur was another example where we acquired to bring us closer to market faster. When we look going forward, it's going to be those two levers. One is, okay, do we just want, kind of a tuck-in for more, technology or features? Or is it going to be, are we working on something on our roadmap of vulnerabilities that we know are going to be critical to the enterprise? This particular opportunity now is there for us to be able to bring that faster to us in market, and to your point, to then be able to even, you know, move our needle on the ARR. We'll be looking at those things as well. Got it. Well, with that, Josh, Erica, thank you so much for your time, and thank you for joining. Thank you, Hamza. Thanks.
Loading workspace