Great. Good morning, everybody. Thanks so much for joining day one of the Stifel CSI Conference. I'm Adam Borg. I'm an analyst on the software team here at Stifel. Beyond thrilled to have CyberArk join us once again at the conference. Matt Cohen, CEO, Sri Anantha from IR, thank you so much for both being here. We're gonna have a fireside chat. I'll kick it off with some questions. Would love to make it interactive, so please raise your hand, and we'd love to get, get what's on your mind as well. So Matt, thanks so much for being here. We really appreciate it. It's great to be here with you. So maybe big picture, it's been a really busy few weeks coming off of RSA, the conference in Nashville, which was awesome, and of course, the Venafi acquisition. Maybe start off with the big opportunities that CyberArk is going after. Sure. You know, I think when we think about the world of cyber today, you know, and we like to say all roads kinda lead to identity in this threat environment, and there's some core reasons for that. It starts with the idea that, you know, organizations are really struggling with just the proliferation, the sheer number of identities that they have to manage, and those identities can be human, like you or I. They also can be machines, like applications, bots, IoT devices, even API or code. So all of these identities that they have to discover, they have to understand, they have to secure in some way, and then ultimately, they have to manage the life cycle of those identities through the process. They have to do that in an increasingly complex environment, where you not only are securing targets that are in the data center, you're securing targets that are sitting in Hypercloud, cloud, multi-cloud environments. So organizations, as they're trying to figure out how to, in this breach, in this threat landscape, keep their organization secure, they have to understand how to approach all of those identities and apply the right level of privilege controls against them. So CyberArk was born in this idea of IT admins, most, most critical privileged users, accessing on-prem infrastructure, and if we could secure that, we could secure the keys to the kingdom. That's what we used to say. Well, now, in a distributed world, people working from home, working from coffee shops, proliferation of identities, complexities of environments, now we have a world where actually any identity can be privileged at any given moment in time, and we need to make sure that we're applying new security controls, we call them privilege controls, across all of them. Our opportunity is to bring more identities into our identity security platform and make sure that every identity within the organization is secured by CyberArk. That's great, and that's a great overview, and we'll take a spin through the various parts of the portfolio. So even just starting in core PAM, you know, obviously, two decades ago, founded this, this area of the market, it still feels really under-penetrated today, just 8,800 customers. And so talk about the opportunity not just to go deeper within your install base, 'cause I think there's an opportunity there, but also, what needs to happen to drive net new logos? Yeah, so, you know, we, we were, Adam, as you said, we celebrated our 25th anniversary this year, you know, and the pioneers and the founders of PAM. And for a long time, PAM was kind of a holy sale, if you will. It was going out and trying to convince people that they needed this. And then over time, the breach environment again inflected on us, and you go back to some of the big industry breaches that were out there, you know, the Equifax breach and the Maersk attack, and all of a sudden, people realized, "Wait, privileged accounts, that's something we need to lock down." And that helped us start to penetrate, but we still penetrated really the upper end of the enterprise, right? The big financial institutions, the heavily regulated environments, you know, the big Fortune 500 accounts. Over time now, it's started to progress into the very vernacular of regulation, cyber insurance, other factors that everybody needs a PAM strategy, and that's allowed us to be able to continue to penetrate downmarket into what we call the lower end of the enterprise or the corporate space, you know, billion-dollar revenue companies and above. Within that space, we've started to deploy PAM solutions out of all these accounts, but people create PAM roadmaps that basically go on for 2, 3, 4 years, because you can't. It's not like a technology, like an agent that just gets deployed all at once. So you get started with the most critical users, and most critical accounts, and you expand from there. So our existing accounts keep coming back for more seats, more users, more accounts, as they expand their PAM programs and their PAM footprints, and when you bring that back to the very notion of what is a privileged account, you start to see more and more, opportunity to upsell your base. But as you mentioned, you know, there are thousands of accounts out there as you move downmarket that don't have a PAM solution today, and that's where new technologies like just-in-time PAM or zero-standing privilege for PAM, or our secure cloud access for developers, or even our EPM product, which is least privilege on the endpoint, they can be good landing and starting points for those new logos that are out there, and you can start to bring them on, and we think that the market opportunity for us is the runway is years and years of opportunity to go after still. Got it, and so if we started in core PAM, Adaptive several years ago got us deeper into access, and when we think about the workforce identity market, and I think at your keynote, you were pretty convincing that just basic multi-factor authentication, SSO, that's just not enough, and that the market really for modern threats requires a modern approach. So talk a little bit about the positioning that you have in access and what needs to happen to secure the modern workforce beyond core MFA and SSO? Sure, I think, Adam, you're gonna walk, it seems like, on the questions through, so let me just give you the framework for a second. The framework of the spectrum of identities that we talk about is workforce, IT, developers, machines. So our whole company strategy is based upon how do we win and secure workforce, IT organization, the developers that sit in organizations, and the machines? So on the workforce side, this traditional space of MFA, SSO, yeah, we've put out a point of view, or I've put out a point of view, which is it's time to reimagine how we secure that, you know, the notion that actually a workforce user is a non-privileged user is a fallacy in this market. You know, a normal user who every day logs into, you know, websites and Slack and other areas, but then happens to be the administrative reporter for your ERP system or your HRIS system, Workday. When they log into that system, they're a privileged user, and they have all the same capabilities, and if a bad actor gets their account, your Salesforce instance is down or your Social Security numbers of your employees is stolen. So it's time to reimagine how we think about securing the workforce. MFA SSO core security controls, you can get that from CyberArk, you can get it from Microsoft, you could get it from Okta or Ping. Okay, but what we layer on top of it is the ability to be able to add in core PAM-like concepts, like secure web sessions, which allows a session to be isolated and recorded when that user happens to be going to that application where they're a privileged user. Everywhere else, they just hit their single sign-on tile, and they go. For those applications, they hit their single sign-on tile, behind the scenes, we're able to do things like step-up authentication if there's risk. We're able to terminate the session if we see some type of behavior we don't like. And we're able to record the session so that we can understand what happened. So that's the kind of concept of reimagining workforce. If you combine that for a second with our secure browser, which is a whole new way of being able to navigate enterprise applications and browse the web in a cookieless format with password replacement, that helps us. And then we have Workforce Password Manager, which allows personal passwords to also be secured in our vault as part of that reimagining of the workforce. So our differentiation versus an Okta or a Microsoft is not my single sign-on in MFA is better than your single sign-on in MFA, 'cause it's not. They're all the same. It's my ability to secure your workforce is more secure because of all these other elements. Got it. That makes a lot of sense. And so if we kind of go through that portfolio and talk about the developer community, because, you know, securing the cloud is super interesting, especially as developers have access to production, test, and development environments. They're super privileged, and you've been pretty jazzed up about secure cloud access, so maybe help the audience understand what this is and, and what's the strategy this year to kind of further penetrate the base? Yeah, I mean, it's a line I used on stage, and I use it a lot, and it always gets, like, a knowing chuckle from CISOs, which is the dirty little secret in your organization is the most privileged users you have are your developers. Like, it's not the IT admins anymore. They're locked down to a degree. It's these developers who have full rights to spool up AWS or Microsoft or GCP instances. They actually can put it on their credit card, their corporate credit card. They can create applications. They can load those applications into a production environment, and then they claim they need full access rights, 'cause if the application crashes, they're also the bug fixers and the troubleshooters who go in. That's a privileged account, and that user needs to be secure, just like any IT admin, but it needs to happen in a way that doesn't interfere with their productivity. 'Cause if you go to a developer and you say, "I'm implementing a PAM tool," let me tell you, that developer is gonna either walk out of the room or do something else nasty to you, 'cause they don't wanna be slowed down at all. So our Secure Cloud Access, which is our version of PAM for the developer, allows them to have native access. They log into the cloud console, just like they did every other day. But when they're sitting outside of the cloud environment, they have no privileges. It's a Zero Standing Privilege approach. If someone steals their account and tries to log in, they have no rights. The moment they log in, they're applied, based upon policy, a granular level of privileges for a certain period of time and/or with a workflow to approve it. Then they go and do their business, they log out, it removes all privileges, destroys those credentials. So it's a more secure way to enable native access for developers, and to be honest, it's one of the big soft underbellies of organizations today 'cause they've let developers do whatever they want, whenever they want, for the speed of innovation kind of trumping the importance of security. So we kinda hit on the key constituents on the human side of the fence. And the machine side is super interesting, right? And we'll get to Venafi in a second, but talking about just core secrets management and the ability to, secure non-human identities, and candidly, there's been some incremental traction you've talked about in recent quarters. So maybe talk about kind of what the secrets management business is, what's leading to this growth, and then, of course, we'll talk about Venafi after that. Sure. So maybe just, I'll ground the audience first in... 'Cause it's like, to us in the, in the world, it's, it's, it's, it's, basics, but it's not always, which is what is a machine identity? Okay, so a machine identity is really pretty much anything that's being built in the modern world has a machine identity. So an application, if you build an application, that's, it has an identity to it. A bot, you bring a bot online, an RPA bot, an AI-driven bot, it has an identity to it. You have an IoT device, it has an identity to it. Actually, even just core APIs and code have their own identity. Why is that? 'Cause they need to be communicating with other machines or other data sources. So an application needs to go to a database to retrieve data, or an IoT device needs to log up into the cloud in order to be able to send its data up into the cloud. All of this communication requires protocols. Now, our core business, as Adam mentioned, before the Venafi acquisition, was secrets management. That's basically when a machine needs to log in to another source, it uses a username and password, just like us. In the old days, they would hard code... Developers would hard code the username and password into the application.... That's really bad, because if someone hacks into the application, they steal the username and password. Then you started to the vault, the idea of, "All right, so we'll take the password, we'll put it in a vault, and we'll broker the session." So the application grabs the password, just like a human, and logs in through an encrypted method into the data source, retrieves the data. The password's never known to the application. That's called secrets management. All right, that's been out there for a little while, but the problem is, the developers have really run wild with... They could use whatever tools they wanted to, to do secrets management, and a lot of times they chose open source tools, like Hashi or like the AWS Secrets store that sits within the AWS platform, Azure Key Vault, et cetera. So these native vaults, the problem with that is, while it helps with the you don't code applications with secrets right in there, it doesn't allow for security to have any control. If there's hundreds of vaults sprawled throughout an enterprise, how do you know if those passwords are being rotated? How do you know what's being used where? And that's where we've seen this inflection point in the secrets business, where security has started to get involved and said, "No, no, no, we need an enterprise solution here, one that we can control the policy behind." Again, allowing the developers to develop natively, let's make it easy to use. That's where our secrets portfolio has been, with native tools to enable that at enterprise scale, and that's started to take off for us. In the context of machine identities as a whole, just growing at an exponential rate. We talk a lot about 40-to-1 machine identities for every human identity that an organization is trying to manage. Just think about that. That's hundreds of thousands of machine identities that most of these organizations are trying to control. It's almost impossible without enterprise-grade tools. Super helpful. So when you layer on the secrets business that we just talked about, and then two Mondays ago announced, as we were all flying down to Nashville- ... the largest acquisition to date, $1.5 billion acquisition of Venafi, a company that's been around for a while in the machine identity space. So I guess a couple obvious questions would be kind of, what does Venafi do? How is this complementary with what you're doing with secrets management, and ultimately, why now? And the follow-up is, how could this help... What could you do to help accelerate their growth? Sure. So within that landscape of machine identities, I talked about applications, bots, code, IoT devices. Each of those have actually, this is what makes it so complex, multiple forms of identities based upon what it's trying to do. So one form of identity is your user, the username and password it uses to log in. That's secrets. Another form of identity, for example, is certificates. Certificates is an encrypted view of the digital footprint, if you will, or fingerprint of the machine. It allows it to be able to identify itself, so that when it's logging in to other applications, communicating with other applications, it can be recognized, so that the internet can recognize it, so that it can be listed in websites and in other areas. So all of that information about the machine is held in what's called a certificate. The Venafi team invented what's called Machine Identity Management or Certificate Lifecycle Management. That was the idea of being able to discover those certificates, and then being able to do things around automating their life cycle, because what happens is those certificates expire, and if those certificates expire, then that machine stops working, and you have an outage. Believe it or not, that happens to companies all the time. That's an operational headache. But in addition to being an operational headache, it's a security nightmare, because as the machines go out, then it's easier for the bad actors to be able to get access to those certificates. In addition, a lot of times post-breach, you need to be able to rotate all your certificates in order to be able to encrypt them with new encryption and with new information. All of that is what Venafi does, and they've been doing it at scale for many years. Why now? Because of what I've been talking about, about the machine identity landscape. Like, the, the, the very nature of machines has taken off. The very nature of the number of machines has taken off. The complexity of certificates, what we do around secrets, there's things called PKI keys and, and the ability to be able to manage those. There's SSH keys, there's modern environments, like Kubernetes environments, have their own view of certificates. All of that needs to be enterprise managed at scale, and we think the combination of their technology with our go-to-market engine is the, the, the secret sauce. So they are-- Despite being around for a while, they're a $150 million ARR company. They have 550-ish customers. They play in the upper end of the enterprise. We believe that with our go-to-market scale, they have 20-something sales reps. We have close to 300 sales reps. They had minimal channel partners. We have the best channel partners in the world, from the SIs to the MSPs to the distributors. We take their tech, which is a modern, SaaS-based platform version of what they've been doing, put it into our go-to-market engine, we can, we can really accelerate growth, and that's the thesis of the acquisition. Maybe one big picture, dream the dream question, then we'll open it to the audience. So, we talked about this in the past, but if you think about when organizations increasingly adopt chatbots, those chatbots have to handshake with different systems to take action on behalf of humans. Having standing privileges for those chatbots seems like a really bad idea. Yeah. Given what we've talked about in the first 20 or so minutes around zero standing access, giving elevating privileges, and then returning to zero standing access, isn't the push towards AI more broadly, and chatbots in particular, just an accelerant to the overall opportunity for you guys to help secure these new types of identities? Yeah, I think we go back to the very thesis of there's a spectrum of identities within an organization that needs to be secured. AI-generated identities is gonna be one of the biggest and fastest-growing elements of that spectrum, and chatbots are a great example. Chatbots are—or AI chat, AI copilots are the next generation of RPA bots that were happening over the last 10 years, and those needed to be secure. We have software, we have product solutions that secure RPA bots from all the big providers, so they can go do their work, and AI was no different from that perspective. And so as we see all these machine identities coming, think about your vision in your head of an AI machine. They need to be secured like any other identity. I think it's a big opportunity for us in a zero-standing privilege world to be able to go do that. It's why the overall investment in machine identity for us as a company is going up. By the way, there's other areas also that are technology waves that are affecting the machine space. Quantum computing will be critical in the machine identity space. It's critical across all security, but those same certificates that I just described have an encryption layer to it, and you need to build those certificates to be post-quantum protected. And you have to be ready for the idea that those are often gonna be breached. So what do you need to be able to do? Find them, rotate them, re-encrypt them, find them, rotate them, re-encrypt them. That's another wave that's coming our way on the machine identity space. Super helpful. What's on your mind? The Venafi acquisition. To my understanding, the R&D team is primarily internal, but for the CyberArk team, the R&D team has always been in, like, Israel. So like I'm wondering what the cultural, kind of the communication between those two, those two key teams, and possibly like what you're doing to make sure then that they function as, as, as one unit. Sure. Maybe just repeat the Yeah, so the question was really around the Venafi's R&D headquarters and locations versus the CyberArk's R&D, and how are we managing the cultural fit and the awareness. So first of all, from a Venafi perspective, they actually have R&D resources all around the world. Salt Lake City is where a lot of their original product was built. They've got a really nice center in San Francisco as well. That's where their modern SaaS platform was built. They've got an R&D center actually in London, which is where their Venafi Firefly product and their Kubernetes product is built, and then they have some lower-cost region as well. By the way, CyberArk has distributed its engineering group. For sure, the biggest group is still in Israel, but we've got hundreds of people in India. We've got a center in San Francisco as well, right nearby the Venafi location, and we've got resources in Boston. So we've been learning how to develop in a distributed environment over the last five or so years as we built that out. We spent a lot of time on culture fit between the teams. We think there's a really strong culture fit. The teams really got along well through the diligence process. And we'll work in a distributed environment like we do today anyway. So I don't think it's a real risk factor for us, but we plan on maintaining their existing R&D hubs. Other questions? With the FedRAMP, now that you're FedRAMPed, I'm wondering what would you be displacing on endpoint management and PAM within the government now that you've been bought? Sure. So the question was around FedRAMP, and given our recent certifications around FedRAMP, what would we be replacing, and what does it really mean for the business overall? So first of all, just an update there. So we were granted FedRAMP high certification for our EPM product, Endpoint Privilege Management, which is least privilege on the endpoint, and for our access product, MFA, SSO, secure web sessions, that side. We've not yet completed certification for our PAM product, for our Privilege Cloud product. First of all, why do we choose EPM and Access first? Because we don't have an on-prem version for those products, so the only way we could sell to the federal government is to get it FedRAMP. They're SaaS-only products. We've been in the federal government for decades on the PAM side with our on-prem product. We have a great footprint throughout the agencies. And so, you know, we are the PAM product of choice within the US federal government. We will be FedRAMPing our Priv Cloud, our PAM SaaS solution, and that will be a more modern way for them to be able to deploy it. But in the meantime, we're still able to sell them the PAM product that we have today. For EPM and Access, on Access side, it's the same competitors that you would expect. You know, it's Okta, it's Microsoft in that side. On EPM, there really is no competitor that's FedRAMP-certified. EPM as a product is-... A little bit misnamed to some people, because of the endpoint people side, they think EDR, they think CrowdStrike, they think SentinelOne or Microsoft. EPM is really about implementing least privilege on the endpoint. What that means is you remove local admin rights from your workstation, Windows, Mac, servers, so that no changes can be made to the environment, and then you implement a back-end workflow whereby you can create policy for which applications can be downloaded with what approvals, and how can you actually make changes in that endpoint. It is like the more secure way of locking down an endpoint. So an EDR is watching, detecting, alerting, and responding. An EPM agent is basically saying, "No changes, nothing can happen." And if you're going to implement some level of ransomware, you're going to have to actually down... Have someone implement or click on an executable, which will create the download of the code onto the endpoint. EPM blocks that from ever happening. That's the concept. So it's a shared footprint with an EDR agent, and it basically protects the EDR agent, because the first thing that, by the way, the attackers want to do, is turn off the EDR agent so they can go about their business. Well, if you can't make any changes to the endpoint, you can't turn off the EDR agent. So long way of using your question to talk about EPM, but EPM itself is really in that market, there's nobody else who's FedRAMP. Maybe from kind of bigger picture to maybe a little bit more tactical. Software companies in recent weeks and months have sounded a little bit more mixed on, on the demand environment, on execution and, and overall results. Yet candidly, CyberArk continues to execute, quite, very, very strongly, not just this year, but over, over recent periods. Maybe give an update on kind of what you're seeing in the demand environment overall to the extent you can, and kind of what's the overall cybersecurity prioritization like overall within IT budgets and cyber, identity security within cyber budgets? Yeah. So maybe the best context I can give from that perspective is if we rewind the clock to when the macros really got tough, kind of towards the end of 2022 and all the way through 2023, and then where we are today. So I think first of all, from what we see in the cyber world, macros aren't worse than where they were a year ago. They're just not. You know, budgets in 2023 versus 2022 were generally flat, and most of the executives I talked to. Generally, when I talk to the executives today, their 2024 budget is up 5%-10% on the cyber budgets. So there's more money to spend. Within there, there's, of course, greater scrutiny, greater approvals, the CFO gets more involved. That's been the case throughout the entire macro. We've said all along, cyber is better than general software, and within cyber, there's haves and the have-nots. You want to be in identity, you want to be in endpoint, you want to be in cloud. Those are the three areas where budgets are flowing a little bit more freely. And then within those space, you want to be the leader that basically has the relationships, that you want to have the partners and the SIs who have the relationships, and in that case, you can get your process through. You're still going to have two extra approvers, and it's going to take a little bit longer, but certainly throughout last year into this year, it hasn't gotten any worse from what I've seen into April and May. It hasn't gotten any worse. You know, it takes more work, it takes more execution capability. It's not a good macro by any means, but, you know, I hear the same... I see the same headlines from the software at large. And I'd say, by the way, that that's happened, you know, at times throughout 2020, end of 2022, 2023. Got it. Any questions? Maybe on SaaS for a minute. So, you know, obviously, CyberArk's gone through a really successful transition to subscriptions, subscription and SaaS, and it feels like it's even inflected more towards SaaS more recently. I think you're now over 70% of bookings coming from SaaS, from called the mid-60s previously. How is SaaS helping, I guess, a couple across a couple areas across the business? Be it lowering the friction of adoption, helping to go more down-market, or even the velocity of upsells. Sure. Yes. I mean, first of all, it was. This is my second time going through the subscription transition. This one was significantly better. One of the reasons was we were SaaS heavy, so you're not going from on-prem from on-prem to on-prem, you're going mainly from on-prem to SaaS. So as you said, we're generally two-thirds SaaS, one-third on-prem subscription. It's further amplified by the fact that not only is SaaS taking off for PAM, but all of our new product areas are SaaS only. So as they become bigger pieces of the pie, obviously, the overall SaaS mix is going to go up just by the very nature of thing. Access, EPM, Secure Cloud Access, even Secrets, which was an on-prem footprint, has shifted over to a SaaS-first strategy. So SaaS absolutely is taking off. SaaS drives faster deal cycles. More importantly than the faster deal cycles, 'cause we still have long deal cycles, you know, 6-9 months, sometimes 9-12 months, is, it drives faster second-time buys because you get deployed much faster. So we can sell in Q1 and go back and sell them again in Q3, Q4. We see that type of deal cycles for deal number two in a SaaS world. Generally, deployment times are down exponentially. You know, an old PAM program might take 6-12 months just to actually even get to first-time value. Now, you can get to first-time value in 90 days. PAM programs themselves are still long programs. That hasn't changed. It takes, you know, multiple quarters, multiple years to really roll out a full PAM program, but you get started in the first 90 days, you're getting value. That's a much better, much better place to be. Secure Cloud Access, you can start to get value in days and weeks. That's a really good place to be. So I think SaaS really changes the dynamic of our, of our market, and, and, and it helps us drive faster cycles. You know, I use this, this... I shared this with a few people this morning. I'll share it in the larger group, which is, like, at our Impact event, which was last, last 2 weeks ago in, in Nashville, we had this giant crowd, and we had all our partners there. You know, the partners said to us, like: "Let's go partner on how to deploy faster." Why? Because they know the second deal, the third deal, the fourth deal is on the other side of these new products to go through. So it's an exciting place to be. Awesome. I think with that, we're out of time. Matt, thanks so much for being here. Everyone, have a great rest of the conference. Thanks again.
Loading workspace