Good morning. I'm Rob Owens with Piper. I'm the co-head of tech research, and focus my practice around cybersecurity and infrastructure software. Pleased to welcome our presenting firesiding. We love to create words, as you know. Company this morning, CyberArk, and Josh Siegel, the CFO, is up here with me. So Josh, thank you. Thanks for coming to Nashville. Thank you for having me. Been a couple of months since your conference here, but good to see you down here again. Thank you. It's always good to be here. Thank you for having me. Yeah. Cyber has been able to execute incredibly well. Like, you guys are kind of King Midas now, with everything you touch turning to gold, despite what's been a very uneven selling environment. So, maybe some of the puts and takes around what are the key contributing factors to just the success you guys have seen over the last year? Yeah. So Rob, I, you know, I think it starts with just the threat environment is at its all-time high, and I've said that last quarter, and I said it the quarter before, and the year before. It just continues to elevate, you know, across all of- across lots of cybersecurity, and the whole cybersecurity space. But then if you start to think about where within cybersecurity, then you start to see it focused on identities specifically. I think last night we had that great dinner, and I love the line that one of the CISOs gave that says that "Attackers are not fighting their way in, they're logging their way in. Mm-hmm. I think that that really goes to where the threat is around identity and around credentials. And of course, CyberArk has been a leader, you know, in the identity security space now for some time. And so when you think about where the money is going when it goes to investing in cyber, it's really key threats. It's what's keeping the CISO, the CIO, the board awake at night, really knowing that they're in a breached environment, and what do you do about preventing network takeover? And so I think CyberArk plays you know its strategy for a platform that does all identities, securing all identities from human to non-human, on-premise, cloud, and then of course extending it as well into machine identities. You know, we're really very well positioned to, you know, to really retain the budgets that are still there, even in this rocky macro environment that we're seeing. How do you get there? Last night we heard identity was broken. We just had a panel with an AI expert that said, "Identity is broken," and I think you're viewed a little bit more as a privilege-based company, less around that broader identity opportunity, so how do you get the word around your IDaaS solution? Because the proposition that you put forward around being a secure identity company does make sense, and then to extend it, even though the acquisition hasn't closed yet, to machines next. Yeah, so I mean, first of all, while we're, we very much started from the privileged space- Mm-hmm ... and from the privileged, from the PAM space, the classic- Mm-hmm ... PAM PAM space. What we're really working on and what our strategy has been for the last several years is really to create this platform now to help enterprises, and our CEO, Matt, likes to use the word "reimagine," what privileged access management is about within the enterprise. It's not just about IT administrators anymore. Of course, you need to secure them, but you also need to secure them in very modern cloud work environments. It's also, what are you doing for your developers, who are now also very privileged within the enterprise space? What are you doing for your workforce, like myself or yourself, who are, during the day, are going up and down in privileges- Mm-hmm ... depending upon, you know, what applications they're using? I get no privileges, by the way. They treat me as low as possible. Everybody... Well, your secretary, your assistant, probably- They have tons of privileges. So it's really about elevating the fact that all identities are privileged at some point during the day. And really, what CyberArk is about, and the messaging that I think we've been very powerful about relaying, is giving the right level of controls to the identities within the enterprise, regardless of who that credential is. Again, whether it's human or also whether it's machine identities, and you know that we've been very focused for many years now about securing secrets. Mm-hmm. And, you know, I guess we'll talk about it later, about where we're going as well for extending our machine identity scheme. Is it a different buying center, and is it a different channel to get to that workforce opportunity? Which is, I think, where people largely say- Yeah ... this is broken, right? Yeah. There's two leaders. There's really one leader in the space in terms of Microsoft, and they can't even get the hackers out of their own network, and then you've got Okta, which is obviously running into some trouble. So is that a different kind of distribution arm, different reseller, different partner, different buying center? So actually, it's moving more and more to the same, because what's happening, as we talked about the threat environment earlier, this morning, is basically all identities now are part of the threat environment. And where it used to be just about managing workforce identities, now it's about securing workforce identities. And they're realizing that just having single sign-on or multi-factor is not enough. So when CyberArk came into the workforce access, they came in first of all as the challenger, got feature parity, of course, with the big names that you were mentioning, but really extended it out about: Now, how do we think about securing the workforce? How do we manage the sessions that the workforce- Yeah ... is doing, when they need to be managed? How are we giving them capability around password management for all of their credentials, and all of their passwords, within the enterprise? And when you think about you know, against other access players, you know, that are only doing that, then it's actually, you know, CISOs are coming to us and saying: "Hey, we're looking to now be much more of a security first minded around those credentials." And when you think about players like Microsoft that you mentioned, well, there it's, you know, we could actually wrap and extend above and beyond their MFA- Mm-hmm ... and SSO, and their basic identity management with our secure sessions management, with our password management and the like, and then they're getting kind of best of both worlds. Obviously, this story has tremendous opportunity. We look at Workforce, we look at Machines, we look at Cloud Secrets. How important in the near term is just what's left in PAM? The discussion kind of coming back to Privilege, which still dominates your revenue overall. Where are we in that opportunity in your view, and how important is that to kind of the near-term growth story? Yeah, I think, first of all, it's very important because while we have almost 9,000 customers, we only have 9,000 customers. Right. and there's another 50,000 customers- At least ... that, you know, that we're, you know, that are in our sights, and that we know how to target. So there's still a big unvended market to go after. And also for the vended market, there's the notion of those enterprises looking at how do we move beyond just kind of the basic kind of PAM principles to kind of a platform that allows us to do all of the identity security needs for hybrid environments and for modern workloads, and across all of our identities, and not just across our privileged credentials. So from our perspective, we're, you know, heavily invested and entrenched within the PAM space, knowing, though, that there's, you know, credentials that are also on the machine identity space, and the platform would be incomplete if you were only focused on the humans. How do we think about the biggest driver that either gets someone to move or modernize what they have? Ransomware, cyber insurance, just threat environment, choice D, all the above. I mean, where... Is there one or two factors that you think drive more so this awareness and drive customers to consider either upgrading what they have from a pre-existing standpoint and having the halo effect of more privilege? Or how should- Yeah ... how should investors think about that? I think you'll be amazed. First of all, if you kind of go to the fundamentals, like the cyber insurance that you mentioned, or ransomware, that's not about, you know, having to upgrade. That's just doing the basics and the basic hygiene. Those are things that you, believe it or not, enterprises are still just getting up to speed there. I mean, there's a lot who have done it, but there's a lot more that still have to do that, or they're doing it only at a certain level, and they need to expand within their organization of what other credentials are they protecting to ensure against ransomware. By the way, cyber insurance companies, more and more every year, are saying, "Oh, this is what we knew from last year. Now, what are you doing about the things we learned from this year?" So that's just basic hygiene, fundamental, and so forth. I think where you're seeing still continued growth within the identity security space is how enterprises are moving to a much more modern or digitized- Mm-hmm ... set of workloads, which is creating new needs, for how do you secure your identities, giving them the right level of privileges for the types of controls that they're doing. And by the way, they're not the same as what they were five or ten years ago. And we talked about, you know, one of the things CyberArk is very excited about how it's kind of moved its whole selling motion from, you know, around selling solutions, and PAM, and Endpoint, and Workforce, to selling towards personas. Because you want to give administrators all of the capabilities that they need to be able to do what they're doing during the day in a secure environment. You want to give to developers, who have a different set of needs, you know, their set of privileges and controls, and Workforce is similar, as well as Machine Identity, and then being able to do that on a singular platform. So it's where the enterprises are going also in their digital transformation that's creating new need for CyberArk. One of the big three buyers of security in its fiscal year end, in terms of the federal government, and I think you've spoken before how it feels much more linear and even now, but kind of thoughts and puts and takes around the federal fourth quarter, your calendar third. Yeah, I mean, we're, you know, we do in, you know, 10% of our business to all global governments around the world, which is... And a significant piece here, in the U.S., And, you know, some of the things that, you know, obviously the U.S. government works at their own pace, and, and on their own priorities. We're significantly entrenched there across the PAM space. And we just announced this year our FedRAMP High approval for EPM and Workforce, which were, you know, the two products that are only available, you know, they're only available on SaaS, and of course, we'll be extending that out to our other products as well. So we're... You know, the other area within, outside of federal, that also is very significant, in the U.S., is around SLED. Mm-hmm. A lot of them are actually asking for FedRAMP approval when they're going out and doing their work requisition for a solution. So, it's like you said, I think it's more linear than it as opposed to kind of a Q3 pop. But, we're very much focused on that market. And maybe touch a little bit around Endpoint Privilege Manager, EPM, as you, as you mentioned. I'm trying not to acronym over the next couple- Yeah ... of days. It won't happen. You've seen great success there. I think it just crossed a $100 million? Yeah. Which, good, but this could be an order of magnitude bigger, I mean, I just look at an endpoint space, we can call it $6 billion, $10 billion, and think on a relative scale basis, this could be a much bigger business. How much customer education is still required? Is it just certain verticals in terms of either healthcare, financial services that are looking at the technology, or are you starting to see it expand from there? Yeah, you know, I think a lot of identity security still requires of education for them to understand where are the true vulnerabilities- Yeah. despite, you know, when every, you know, every breach Mm-hmm That you're talking about and read in the newspaper usually is going to point to some credential. And certainly, on ransomware, it's become super obvious that taking away administrative privileges at the endpoint is the number one, you know, way to prevent, you know, ransomware. And so, you're right. I mean, we have over $100 million in ARR from that, and there's no reason that that doesn't continue to grow and be a significant player for us. You know, I think it's in highly and more regulated verticals, it's actually been the strong point, and I think that it's around education going across other verticals where they're saying, you know, are ransomware people going after me? Why would they go after me? But every company today has personal identifiable information. They all have their websites and taking credit card information, and so forth. So, you know, I think over time, we're seeing more and more verticals understanding that they're basically part of the threat environment. And, we're continuing to invest, you know, significant in that space. I guess your one CFO type of question relative to model transition, and you can do a little dance now if you'd like, 'cause it's been fantastic. But how should we think about the final phases in that ramp in free cash flow, which honestly, Josh, feels like you've been a little bit conservative relative to what you've given the street. But that being said, how do we think about that unwind, ramp back of free cash flow, and then your thoughts, you know, doing a pretty big acquisition coming up, just how you're gonna balance growth versus profitability and thinking about that free cash flow margin? Yeah, I mean, I think, you know, you referred to our transition going from 100% perpetual company four years ago to now 100%, you know, recurring revenue company based on, you know, subscription and SaaS, complete subscription and SaaS solution. Actually, you know, the cash flow, just physics, from the laws of physics and the way you build excels and the way the operational model works, it does become the last piece of the puzzle for getting the final inflection. We're starting to see, I would say, that last, probably the last year, this year, or going into next year, as we cycle through kind of all of the last two years' worth of where it was 85%, 90%, 95%. Excuse me, subscription renewals. By the way, there'll still be kind of a long tail of benefit from the cash flow for the next few years because, you know, even, you know, this year will probably only be, you know, 96%-97%, you know, SaaS and subscription basis, and you know, I think that around, you know, where we've come out, you know, we've raised our guidance now to being about $150 million this year. That kind of throws us, from a cash flow perspective, well into the Rule of 40, when you put it together with our revenue growth. I think we can see a little bit still more inflection as we look into next year. You know, we've been saying this all along. We anticipate being a strong cash flow generator going forward. When we start to get to our kind of longer term model, then we start to say, "Okay, we're, you know, we're confident on our ability to get to a balanced, you know, Rule of 40." And then it's a matter of if we continue to be bullish on the growth, you know, then we'll have to see about, you know, whether or not we wanna expand even further our cash flow margin or move it into growth on revenue. We think we're still pretty early on, you know, where we are on growth with identity security for a lot of the reasons that we talked about as it relates to PAM, but as it relates to our entire solution. So, you know, we're really focused on not leaving the growth on the table despite, you know, getting at least to the, even Rule of 40 over the next couple of years. Great. Maybe touch a little bit on the machines, and I've often called you the Terminator CFO. But, you know, I think as we move forward, there's a tremendous, tremendous opportunity in terms of machine to machine. So talk a little bit about the Venafi acquisition. Even prior to it, you guys had talked about machines and starting to engage that opportunity. So what Venafi brings to the table, some of the low-hanging fruit there? Yeah, I mean, CyberArk's platform is all the humans, and it's also machine identity. We to date have been very focused and strong and leading in secrets management. And you know, that's when you think about, you know, applications, you know, using passwords to talk to, you know, machine to machine. And we use some of the similar concept around our human, you know, security measures around those same application credentials, whether they're static or whether they're dynamic, DevOps, you know, secrets coming from the DevOps pipeline. And what we're really excited about is being able to add another $10 billion of TAM off of lifecycle management for certificates with the acquisition of Venafi that you know is just pending close some final close items. And you know what they bring to the table and why we are so excited about this acquisition is, one, when you think about where that market is around lifecycle management for certification, it's $10 billion, but not vended fully even close. How do you get to $10 billion? Is that a ground up type of analysis in terms of large customers and certs? It's the market, it's the market view- Okay. of what that TAM capability is. And what we see at our inflection points around where it's going to become more and more vended is, you know, you have the pressure from, let's say, Google talking about reducing their life cycle requirements from the 400 days today to 90 days. We believe other, you know, cloud providers, you know, are likely going to fall in line there. And when you think about enterprises today needing to manage 5,000 or 10,000 or even more certificates that they once were doing once a year- Mm-hmm - or more, to now once a quarter, it creates an entirely different scenario within their organization, and absolutely will require automation. In fact, if you kind of read about why even Google, you know, wants to do this, is because they want to force that automation into- Sure ... into the enterprise, and make it more secure and more automated and more efficient. So, you know, that's one thing, and then you can kind of throw in, you know, things around quantum computing, which is around the corner. Not here today, around the corner, but I can tell you that enterprises are thinking and worrying about all of their encrypted solutions, about where are they going, and are they going to be quantum-proof over the next several years? And that's going to be, I think, another inflection point for the market. I think when you add on that, what Venafi has done in the last, you know, two to three years around developing a ground-up, modern-based architecture for their, lifecycle management, which they were a leader on from an on-prem perspective, you really, you know, get now - we get, you know, an advantage to being able to be best in, you know, best-in-class and solution added to, you know, added to our identity security platform. And I think the, you know, the third piece is, you know, what's in it for CyberArk from a financial modeling perspective? Everything Venafi does is incremental to what we do. There's nothing in what Venafi does that we either need to kind of that either cannibalizes what we're doing or that we need that we're not interested because it's something they were interested in and that we weren't. So it's 100%, incremental to us. They're, they're a non-GAAP, profitable company. They're a cash flow generating company, and so, you know, from a CFO perspective, I'm super excited, to be able to bring on board, a, an acquisition, meaningful acquisition, that actually will continue to move us in the same direction as where we're going, for, for being, having a great financial model, over time. And, you know, we're, we're well, positioned on our balance sheet to be able to, to fund this acquisition, today. We're cash flow positive, as we talked about, $150 million- Mm-hmm ... this year, and that expanding going into the next couple of years, so we're actually in a good place. Great, and you mentioned 9,000 CyberArk customers. Can you help us understand how many are Venafi customers as well, and within the 9,000, where you see the opportunity of 5,000 certs or more? Yeah. So they, Venafi has, I think, you know, somewhere around 550 customers. Mm-hmm. Maybe half of them are joint CyberArk customers. Okay. So there's a gigantic greenfield within CyberArk that we believe you know we'll be able to incorporate the Venafi into our go-to-market. And the other thing you talked earlier about you know who's the buyer of access and we've been successful starting to get successful there because actually that buyer is you know is not distant to us. Here it's also it's the CIO. So we immediately can move that into our go-to-market engine with our partnership engine whether it's with our advisory firms whether it's with Marketplace AWS Marketplace whether it's with MSPs whether it's with all of our resellers and distributors and immediately give that engine to the same buyers. As well as our AEs, now just needing to learn the product, but not needing to learn a new address to go to. Great. I've got time for maybe one question. Go ahead, E. Yeah, can you talk a little more about kind of the environment you're seeing, sort of cloud and kind of how you're competing with your access product into that public sector around the sector? Yeah. So on the general PAM, it's basically we have a lot of private equity-owned, you know, competitors that we stay very close to and, you know, very strategic against, and we see them. But I think... and one of the things that we do there is constantly create a bigger and bigger moat about our offering, and covering, you know, cloud and modern workloads and more and more machine identities just to create, you know, that moat there. When we talk about Secure Cloud Access, you know, right now it's about. You know, there's a lot of emphasis on discovery, and there are some great companies out there, some of them we talked about last night, really doing discovery around cloud access. But where we come in is, okay, you've discovered all these credentials. Now, how do you control what they're accessing, and what are they doing in the session that they're accessing? Mm-hmm. And that's where it becomes a security play, that's critical to our whole kind of theme of strategy, of giving the right level of controls to the different credentials. And we're very excited. We had a great example that we talked about in the last earnings call with SAP, you know, coming in. They were an EPM customer, and they came in and said: "Hey, we need to now have, for all of our developers, this capability of zero standing access to modern cloud workloads." And you know, that just really shows how important it is. And I think also as you know, in terms of against our competitors, it creates an additional, you know, it really widens that moat. All right, Josh, we're at time. Thank you. Great. Thank you. Thank you.
Loading workspace