Erica and Clarence, it should be a great discussion. And, you know, if we reflect just on this past earnings season across software, it's been a pretty difficult, challenging season, for a lot of companies, but there's been, you know, two standouts, you guys and CrowdStrike. And I guess I just wanna—would love to hear, you know, what's driving such incredible performance from the CyberArk perspective? Yeah. So I think as you think about our overall growth, we're very excited about our platform selling motion. And so there's that really great land opportunity for us, not only in privileged access, which has always been our bread and butter, but also across the broader identity security platform. And, you know, consistently, we've been signing about 200 new logos in any given quarter, and that's really helped drive and fuel the growth over a longer time horizon. But then we also have that really strong expand motion. So our ability to be able to cross-sell and upsell across the base, across the product portfolio has really been very powerful as well. A lot of that has been driven by the tailwinds that we have in our industry, because at the end of the day, all roads in cybersecurity do lead to identity. And so when you kind of combine that with our really great execution, it's been driving that growth that you've seen. So our ARR has been very powerful. If you look at that subscription ARR line, it's still growing north of 50%, and I think, you know, our expectations are, is that we should be able to continue to have very healthy growth here. Maybe let's take a step backwards and talk about platformization in cybersecurity. Two quarters ago, right, Palo Alto came out with this, their definition of platformization, and I think it's been soup du jour since then. But if you look across identity, identity's been a little bit slower to get to that platform motion. So maybe could you talk about why that's been the case in identity specifically, and especially over the last year, how you guys have really transformed into being that more a platform identity player? Yeah, I think I can start with that. So if you go back to traditionally how identity's been set up with identity access management, you have the silos of privileged access management, access management, and identity management became IGA. In traditional legacy environments, you can kinda get away with that separation in terms of the actual capabilities. But as you move into more modern and more cloud-friendly, you know, cloud-forward environments, the lines of separation become a little bit blurrier, right? And so I think that's what we're starting to see in terms of actually having to deliver real security capabilities across all identity types, and to bring each of the disciplines to bear across the different identity types and the different environments. So for us, what we're really starting to see is, as identity really becomes the focal point of security for the attackers, and therefore also the focal point of the defenders, you know, a vendor like us coming to the forefront in delivering real security capabilities, the right level of privileges across each of the identity types, is really starting to resonate in a very, very meaningful way. So I think that is, that is the change here. That's what's driving a bit of the, you know, the convergence or we say, the consolidation of trust on the identity side. Because before, again, there were different silos, and you thought about each of them differently, and you thought about management of access and management of and governance of the identities, and it wasn't. It hasn't been until fairly recently. There's this broad-based thinking that you have to actually secure identities of all types, from the most privileged within IT, to the developers, to the broader workforce, external workers and contractors, and of course, the whole entire suite of non-human identities. So that's what we're seeing. Maybe if we just stay in privileged identity, how has that definition expanded and changed, especially as, you know, we've come through digitalization and then really moved to the cloud? Is everyone considered a privileged user these days? And how do you think that that's expanded your opportunity to continue to grow in that market as well? Yes, if you go back to that context, that's a lot of what we saw when we were focused, you know, more exclusively on PAM, is that you had this long tail of human and then even non-human identities that, under certain circumstances, could be privileged. And even if the users themselves didn't understand that, the attackers for sure understood it. And so therefore, you have this massive attack surface. And the only way to effectively secure that is to provide our principals to a broader set of identities. Now, again, you're not going to be able to vault and rotate and record every single user. So you need different types of privilege controls, which is what we start to, you know, develop both organically and inorganically with Idaptive and the like. But that's the mindset that it really, that it really takes to protect this broad range. But what I'll say is that, interestingly, as we go to market and go to customers with this broader identity security, you know, approach, approach, solution, set, and vision, oftentimes the customers will come back and say, "Yes, we're all in, but we have to finish the job that we started with traditional PAM." Because to your point, there are actually more identities out there that have very, very high levels of privilege, especially when you look to look to new environments like cloud environments, where you have tens of thousands of unique entitlements, whatever. So is this off now? Hello, hello? We good? All right, so sorry for making everybody deaf here, whoever's listening. So I'm gonna go through all that again. No, I won't. We don't go through all that again. But when you think about the cloud environments, for example, where you have tens of thousands of unique entitlements, many of which are extremely powerful. You therefore have all the admins, the developers, the Cloud Engineers, the Cloud Architects, they're now part of this privileged set where they wouldn't have been years back with more traditional traditional enterprise IT environment. So we are seeing, again, there's more broadly speaking, everyone can be privileged, and then even with the classic definition of privileged, there are bigger set of identities that fall into that as well. I don't know if that. Yeah. Is your mic on? I think so. Okay. [inaudible]. When you go into a new customer, do they know how many privileged identities they have? Or is that something that you kind of awaken them to, to say, "Okay, you know, this is your existing group that you thought were traditional privileged, but actually, here's the scope of what privileged identity should look like for your organization? I'd say that, broadly speaking, no. No, no one really knows the exact number. They have— Some customers have a better directional sense than others. When you're talking about the discrete humans, it's easier, but when you start getting into the... Again, this is the blur of highly privileged non-human accounts, but for example, service accounts, which are non-human identities, which we've protected for a long time with our PAM solutions, those can be more difficult to discover. So I think there's a lot more uncertainty there. But when it comes to identifying the specific users, they have a good sense for traditional, like domain admins, AD admins, et cetera. But when we talk about some of the things we're just mentioning, like cloud architects and engineers, developers, when it starts to get gray, that's where there's a greater degree of uncertainty. And, of course, with the non-human identities, it's really largely unknown for many categories. I think one of the things that we do do is we work with our customers to help them identify who those privileged users are, either on the human side or the non-human side. One of the reasons why we've consistently had such a strong add-on business is because of that expansion and that our ability to work with those customers to programmatically at the initial engagement, have them roll out a program. So they can say, "Okay, we're starting to identify where our human users are and then where those non-human users are, and we can help them map what will be the most critical to start with, and then expand beyond over a period of time. And maybe, Erica, if you could just go a little bit deeper into that, because I think this is a really interesting point and a good growth driver for CyberArk. Yeah ... if we think about core PAM, right? Right. A big misconception is that you're penetrated, you know, broadly in the market, so what's really the opportunity left? But, I'd love to hear, you know, how you guys attack this PAM deployment throughout the organization and what that tail is for growth. Yeah. So it's one of the things that I think has always been mischaracterized about CyberArk and CyberArk's growth potential, is that PAM initially was seen as being a relatively small market, and that expansion motion was eventually not gonna be as strong as we've seen. But consistently, when we look across our base, there are more users, and also the customers themselves are growing and expanding, so they're looking to have more and more security controls. And so one of the ways that we go in is oftentimes we define a specific set of users that need to be secured first. Oftentimes, it's those that have closest access to domain controllers, and then they'll expand beyond that to different types of users that are actually privileged. And so that expand motion, if you think about our business, roughly 30% of our ARR typically comes from new customers. The additional 70 comes from add-on, and a lot of that growth does come from privilege. Like, when you think about that subscription ARR base that we have, it's about still 55% coming from PAM, and that PAM growth rate is, you know, you look across those lines, they're all growing 50%, right? They kind of... The business has all been growing in step with each other, and that just shows the power of that expand motion, because a lot of that is coming from expand. Great, and maybe we'll take a different direction and talk about those other products outside of core PAM. Because I think a really smart way that CyberArk grows its business is by going into really hot cybersecurity markets, but in a very complementary way. What I mean is, you know, we see them in cloud security, right? But you're not competing with Wiz. We see you in endpoint security, but you're not competing directly with CrowdStrike. So can you talk about the markets that you play in with your identity products and the strategy behind that? Yeah. So let's start with the strategic approach, and one thing that separates us from others that have been in the identity access management, more broadly speaking, for a while, is that we really do focus on this think like an attacker mindset. So where are the attackers now? Where are they going next? That drives our strategy, drives our roadmap, and drives our prioritization. So as you go through those innovations, you know, think example four: well, why did we go into secrets management with Conjur? It's because we saw that developers, as they were building out applications, were, you know, when you're building connections to databases and identity stores, well, you need credentials, you need passwords, so they're hard coding them into the actual application. Of course, that's a huge security risk. So we go out, and it's taking a very, very similar approach that we do in PAM, bringing it to secrets management. We're abstracting that, broken the access, et cetera. When you think about the endpoint and least privilege at the endpoint, again, we have local admin access rights. This is extremely powerful access. We're giving it to end users who don't really need it, don't really know they have it, but every single attacker knows exactly what to do with the access. So you think about putting least privilege at the endpoint, taking away admin, admin rights, and only escalate as needed for things like adding printers and, and things like that. You continue on to, as you mentioned with, with cloud. It's like, well, with cloud, you have- The access to the consoles, it, you don't need standing access to, to the console. Again, this is very PAM-like, highly privileged access, but it's a different type of access. You want dynamic, just-in-time, zero standing access to the cloud consoles is more appropriate. And you look at, you know, securing the workloads and the infrastructure behind the cloud, again, is dynamic, just-in-time access and security. So for us, it's always thinking about what the next attack, what the next attack surface is that the attackers will go after, and then the most effective and appropriate way for us to apply privilege controls to it. And given that focus, that's why you see us go into these markets, and we're not stomping on, you know, ground that's being trodden by others because we're not going through and just checking boxes on different markets. We're not going and chasing TAM. We give you updates on TAM because it's needed, it's appropriate, but we're going after the most important security problems as we see it, as we look to secure the entirety of the identity vector with the appropriate privilege controls. Maybe if we could just talk a little bit, too, around your technical moat that you have in these markets as well, and what makes customers come to CyberArk for these solutions? Yeah. So I think as you think about customers coming to CyberArk for our solutions, it really does stem from the fact that we're the leader in this space, right? And exactly what Clarence has been talking about, that we are really kind of going after that, those attack vectors that are most critical to the customers. And so when you look at privileged access, specifically, it's always been, "CyberArk, you're the leader. You can't go wrong with going with CyberArk," right? We have the broadest solution, we have the solution that covers the most use cases. And then when we went into kind of the access or the Single Sign-On MFA market, it was never about trying to just go head-to-head with the other players in the market. It was about taking our unique approach and applying those privilege controls and taking that security first notion. And one of the beautiful things that, you know, we talk about, Clarence has mentioned it, is our ability to wrap those controls even around other vendors' solutions when you think about Single Sign-On and MFA. So if there is another vendor that has a SaaS solution out there, we can just take our controls and wrap them around and then keep, create a beachhead for us to expand at a future date. More and more, we're seeing that competitive position really be driven by the fact that customers wanna have that consolidation of trust. So they're looking for fewer vendors when it comes to that identity stack, and we're the ones that can secure the most use cases. If you think about our move going into Venafi, that acquisition is another opportunity where they're looking to us to actually be able to secure those, non-human and machine identities beyond what we're doing in secrets management, and we really will have that opportunity. But it will be the breadth of that offering that will create a really great competitive advantage for us in the broader identity security market. I definitely want to talk about the acquisition because I think it's a really important strategic path for you to be on. But I guess before that, too, you know, as you think about becoming this broader identity platform and having products outside of core PAM, are you starting to see customers come to you for those different use cases as the initial landing spot? I'll start with kind of the landing on some of the additional product solutions, and then, you know, certainly add in there, Clarence. But I think, yes, what we are seeing is, if you look at the lands, we still see a lot of our customers, about 85% of our customers, land with our traditional solutions for the IT persona, right? So privileged access. We have about 10% of the customers that will land with the endpoint solution, and then the other 5% tends to land with the workforce identity or the single sign-on and MFA solutions or the ancillary products in that have privilege controls surrounding that. But what we also are seeing is that increasingly, about 50% of those customers that land, even more than 50% that land with our privileged access solution, are taking two or more solutions along with that. So it's not just a land with PAM anymore. It's a much broader landing spot across the portfolio, and I think that's an important distinction. It's one of the reasons when we went through last year and we were a bit consistent in our net new logos at about 200 per quarter, we actually saw that new logo land, the dollars coming to us, increase meaningfully throughout the year, last year. It's because they're landing with more and more of our portfolio, and again, it comes back to the consolidation of trust, people wanting to buy from CyberArk and believing that we can give them the security controls they need in the face of the attack vectors that they're facing. When you go in, you know, if you think about vendor consolidation, right, we heard CrowdStrike earlier this morning say, for every $1 you spend with CrowdStrike, you save $6 from all the vendors we consolidate. But again, identity is a little bit of a different beast, right? So are you coming in and consolidating other vendors, or is it truly just more of a greenfield opportunity? Because there really is not as much, you know, in terms of legacy vendors in these new areas in the market, like cloud security, right, and like secrets management. Yeah, and I, I can start with that. And so the, the way we're thinking about Consolidation of Trust is, as, as we all know here, the typical enterprise, you have 70, 80, 100+ discrete security ISVs that they're, they're really dealing with and managing, and there's still unaddressed but security concerns and questions. The last thing they want to do is go out and add another 1-2 dozen vendors to the mix to solve all these problems. So that's, that's the, the first aspect of it.... But also, this is an area where you can't, you can't check boxes with security, not, not if you're serious about it. So all of our customers want best of breed, but they want it, you know, as much of that best of breed, you know, talking about a best of suite as they can from the most credible vendor. So for us, we're increasingly seeing our customers come to us and even encourage us to get into new areas and say: "Well, could you also solve this problem for us?" And of course, they're saying: "Let me make sure I understand everything that's in your portfolio, so we can evaluate it closely." Because you develop this incumbent type position as they look to expand their footprint. Oftentimes, that does mean displacing an existing tool that they may have. Oftentimes, it does. Sometimes it doesn't. It just means you have first right of, you know, first right of offer, refusal, whatever you may call it, not in legal sense, when it comes to them adding new capabilities. So that's really how it—we see it from our perspective. So yes, there's greenfield from the new capabilities, and we feel we're strongly positioned, but we're also replacing and effectively consolidating vendors as well, both existing, more established vendors and also some of the startups that you know at times can be marginalized when customers are looking to consolidate with. Sure. And, maybe now we will focus on Venafi, really exciting acquisition. I guess, high level, easy question: Why machine identity and why now? Sure. I'll start, you know, at this point, Erica and I, we both go through this. But if just to frame how we think about non-human identities, and again, I talked about some of this, but may have when I had a bad mic as well. But you start with the service accounts. It's a smaller number of identities, so we give this 40 times or whatever. You've heard 40, 50 times non-human to human ratio. That's a smaller set of identities. It's not diving into that, but very, very important, very powerful identities. But again, we've protected for quite some time with our core privileged access, so we're not new to non-human or machine identity. Then you move to, as I mentioned, secrets, a larger number here, and I described what those were before in terms of secrets and code. We've done that with, with Conjur. Now, again, these are places that attackers were going, and we start to look at where attackers are spending more of their attention. They're starting to capture, gather, steal these certificates associated with endpoints. So think laptops, desktops, servers, you know, physical and virtual, and use those to do what they always do, move laterally, escalate, et cetera, until they get to their desired endpoint. So for us, it's very, very important to start to protect this set of non-human identities, and the numbers start to get quite large. What's particularly exciting about Venafi, not only do they effectively create that category, but they've also invested heavily in the more modern infrastructure. So when you think about containerized environments, you're looking at an order of magnitude greater number of non-human identities. You think about the Kubernetes, containers, et cetera, with their TLS Protect Kubernetes. You think about the north-south traffic, certificate lifecycle management, internet to the clusters. They handle that, as well as the east-west, effectively serving as the with Firefly, serving as the certificate authority for the Kubernetes environment, for the underlying clusters themselves. And there's a path to with the focus on workload, machine identity, management and security, to address the long tail of non-human identities. So think the cloud roles, think the cloud service accounts, et cetera, they get to an even larger set, and the actual workloads running across each of those combinations of clusters and containers. They have investments and thought leadership as well. So all of this, this represents the new, the new attack surface, with this vast number of, of identities, and for us, it became really acute when we have our customers increasingly saying: "This is a real problem for us. We have to think about security here. Work with us on a solution." So this is really... It's important for us, to, to address this, and again, we've been talking about it for, for a while, last year and a half, with a, a crescendo of activity, so here we're, we're taking real action. The other thing I'd just add from a financial perspective that also gets us super excited about Venafi is the fact that they have historically been a 20%+ grower. Obviously, a smaller vendor, as many small vendors were impacted last year by the macro environment. But I think from our perspective, when we look at our 8,800 customers, they have about 550 customers, a little bit more, but there's only 200 customers of overlap. What does that mean? That means there's a massive room for us to take their solutions and be able to cross-sell those solutions into our customer base. And we actually know from our diligence and also from some independent research that we've done, that it's actually oftentimes the same buyer. When you think about that sales motion, it really does reduce the friction for us to be able to sell this solution. Clarence just articulated the fact that it's a real problem for our customers, but we can take our extensive sales force and actually take it to those customers. Beyond that, when you think about it geographically, they were really about 80% of their business was in the Americas, right? We're 60% in the Americas, 30% in EMEA, and 10% in APJ. That international expansion is really considerable, and then we can also take it to our channel. Then, you know, the top-line suit is certainly really exciting, exciting, something that we've been focused on, but they're also very highly profitable. And so when you think they're going to be accretive for us immediately, which we've always and traditionally had very strong margins, but both from a cash flow perspective, operating margin, and from an EPS perspective, they'll be accretive right out of the gate. So those synergies, both top line and the contribution to the margin, makes it a very financially attractive acquisition as well. Maybe a two-part question for that go-to-market strategy with, with this product, right, is, you know, the first part is maybe help us understand on a like-to-like basis, which identity is more vulnerable, a machine identity or a human identity? And then to follow up with that, do you think the market has reached that inflection point in, with your customers, where your customers do understand this is more of a need versus needing to go out and do that market education? ... Yeah, it's a really, really compelling and interesting question with, you know, I'll talk about it this way. So with the human identity is overwhelmingly the most heavily attacked, and, as we had one customer describe, your end users will go through great lengths to disclose and give away their credentials. So the human firewall is quite porous and quite weak. That's why the attackers keep going there. However, it's also the most heavily protected identity, right? So it's understanding this balance of, well, that's you have MFA for the human identity. You don't really have that for non-human. So, and you have varying degrees of power. You have some humans that are extremely privileged and powerful, others not as much. So it's really a mixed bag there. We do see the balance of power shifting to a weight somewhat from, from human identities because they're so heavily protected. You go to the non-human side, by default, they're very, very heavily privileged. Now, to date, they're not as heavily attacked because it's not as straightforward to get there. It's you can't phish a non-human identity. You can phish a human, right? But once you get there, almost certainly, you oftentimes have less to do in order to actually escalate privileges once you find one of these powerful non-human identities. So it's a very, very ripe attack surface. Again, a little bit more difficult to get to versus a human that you can phish, and you can't go out and necessarily find all the credentials out on the dark web, even though increasingly you can if they're certain they've been stolen. So that, that's, that's starting to happen. But you take the combination of typically highly privileged on the non-human side, vast in number. It's a massive attack surface. It's just a matter of time before that becomes a real massive problem, even relative to the human side, where, again, that's where most of the attacks are because there's so many different ways to get to humans. I don't know if you had anything to add. We only have a couple of minutes left, so I'll see if there's any questions. I could keep going for a while, so break it up. Anyone? Okay, great. So, then I guess just turning over quickly in the last couple of minutes more to that business model. You know, CyberArk has always been historically incredibly profitable. Obviously, now capturing more of those growth opportunities and you know, on the tail end of that transition more to SaaS and subscription. So how do you think about investment, not just over the next 12 months, but over the next, you know, two to three years, as well as that balance of profitability? Yeah, great question. So I think as we look at our financial model, we have always very much valued profitability. Even when we were a much smaller organization, we were giving investors, you know, 20+% operating margins. And I think from our perspective, we continue to have that commitment to growth and profitability, but we're at a much larger scale now, and we believe that as you look out for the next few years, you will see leverage across our lines. So when you think about the R&D line and the sales and marketing line, specifically, going out the next few years, you are going to continue to see that leverage. But the wonderful thing about our business model, you mentioned our subscription transition, which finished up a year or so ago now, but we still are just-- or we're just beginning to see the fruits of that in the free cash flow, right? And so you saw a very strong free cash flow in the first quarter. You're going to see that free cash flow as we go through the year here. But what's going to happen is that that will still continue to expand into the next few years. And so we will continue to balance that growth and profitability. Even with this acquisition of Venafi, we believe that we'll be able to retain and expand our margins, and that you should see that cash flow potential continue here from this point forward. What are the important areas of investment over the next couple of years? Yeah. So I think we're gonna continue to invest in R&D across the board. I think we're looking at the various areas where, you know, I'll let Clarence talk certainly about some of the strategic areas where he's been focusing on. But then we'll also continue to expand on the channel side as well as on the direct sales force side. So on the strategic part, I'll pass it off to Clarence. No, I think we've talked about a lot here. It's an ambitious, you know, undertaking to protect all identities, human, non-human, end-to-end, with the appropriate level of privilege controls. Again, we focus and prioritize based on where the attackers are and where we think we can provide the strongest solution. By no means do we have it all covered 100%. We believe that we're systematically reducing risk, but it's an ongoing effort. And so you go identity type by identity type, use case by use case, making sure that we can provide the highest levels of security in a way that's unobtrusive, in a way that actually provides value to the business. And there's a lot in that. And so we'll continue to do, you know, a lot of this organically. We'll leverage our partnerships, and we'll selectively acquire where it makes sense. Great. Perfect. Well, we're out of time, so Erica and Clarence, thanks for spending the afternoon with us. Thank you. Appreciate it.
Loading workspace