Hello, everyone. My name is Jonathan Ho, and I'm the research analyst here at William Blair, following CyberArk. We're pleased to have joining us today for a presentation and a brief fireside chat. Before we begin, I'm required to inform you that a complete list of research disclosures is available at our website at www.williamblair.com. I'm really pleased to introduce our speaker today, Matt Cohen, who's the CEO of CyberArk. Matt will kick us off with a quick overview of CyberArk, and from there, we'll dive into some Q&A. So Matt, I'll let you take it from here. Thanks, Jonathan, and great to be with all of you today. So I'll give us a little bit of an overview of the company, the strategy, what we're focused on. I'll also touch base, we did do a pretty large acquisition about two weeks ago, and I'll touch base on that acquisition as well, just to make sure that I ground us in the strategic intent. And then we'll come over and do the Q&A. So CyberArk, as a company, first of all, has been around for about 25 years. It's actually our 25-year anniversary. And we were founded in this space called PAM, Privileged Access Management. And just to ground everybody who might not know what PAM is, PAM is a part of security. It's probably one of the most important and critical parts of security, where we were focused on the idea of who is the most privileged user, generally, it was someone sitting in the IT administrator, administrator group, and what are they trying to access? Critical infrastructure that was on-prem. And so PAM was invented to make sure that those critical users, when they're accessing the most critical infrastructure or data or information, we could protect them, we could secure them. Because, you know, 10, 20 years ago, the bad actors, the attackers, were just trying to get at those users in order to be able to take over an organization. Now, in the 25 years since, the very nature, the very concept of what is a privileged user has fundamentally shifted and fundamentally changed, and we've broadened our footprint from PAM, Privileged Access Management, to this larger space of identity security. Identity security as a whole, we're focused on the idea that in a world where the sheer number of identities continues to increase, and it's increasing both on the human, and you'll hear us talk about the non-human and machine side. So the sheer number of identities is going up, and the complexity of environments have changed from that on-prem data center to hybrid cloud, multi-cloud environments, from a well-rounded perimeter to people working from home. In that world of new identities and new environments, and the constant innovation that's happening from an attack vector perspective, we need a more modern, robust, platform-driven approach to how we secure identities across that whole spectrum. Now, we've been at this for a while. We've got about 8,800 customers. Those customers are focused in the upper end of the enterprise. You know, think Global 2000, you know, think about Fortune 500. But we've been increasingly moving down into what we would consider the low end of the enterprise, upper end of the mid-market. We generally serve customers that are over $500 million in revenue. So we don't go all the way down to the SMB space. We've been successfully growing the business, both through a perpetual to a subscription SaaS transition. We got through that transition a little over 2.5 years ago, so we're a fully recurrent revenue company with a large percentage, over two-thirds, of that being SaaS. Okay? We've been growing effectively. We've completed our most recent Q1 quarter at $811 million in ARR. That was up 34%, year-over-year from an ARR perspective, and we've grown over 30%, for the last several years from an ARR perspective. With that, we also, though, have a big opportunity ahead of us. We've got a greater than $50 billion TAM. Now, with the Venafi acquisition, which I'll talk about, it's a greater than $60 billion TAM, and that gives us an opportunity to, to expand beyond the 8,800 customers we have today, to, to deeper, to have deeper penetration within that customer base, but also be able to expand beyond. So why is this so important? Just for those of you who are maybe trying to understand the cybersecurity space, we use this phrase, and it's a really important one, which is: All roads lead to identity. Ultimately, the bad actors, the nation-states, the cybercriminals, what they are trying to get to is an identity. When they get an identity within an organization, they can then move laterally to find identities that have more privilege, and then they can move vertically up the stack to take over more data and information. And whether they're a cybercriminal that's trying to implement ransomware, whether they're a nation state that's trying to do, you know, nation state-sponsored espionage, they are trying to get to the identity. Every major breach, at the end of the day, you need to actually steal somebody's credentials to get in. You might get in through different methods, but that's ultimately where they're headed, and most organizations today, like greater than 90%, have had an identity-related breach in the last year. In fact, the large majority of them have had more than two. And this becomes the battleground, if you will, of the threat landscape that we find ourselves in today. So our vision as a company, based upon our years of experience, is the notion that every identity needs the right level of privilege controls to be secure. So again, where it was enough 10, 15 years ago to apply privilege controls to IT admins, we now need to figure out how to provide the right level of privilege controls. It's not necessarily as strong or as robust as the IT admin, across every identity. And from an identity perspective, we're focused on four major groups. You have the workforce, that's you, that's me. And how do we actually think about reimagining how we secure the workforce? How do we go beyond the notion of just single sign-on and multi-factor authentication, which are important, but commoditize security controls? How do we then go and actually secure IT, that's what we've been doing for years, in a modern way? How do we implement ideas around just-in-time or zero standing privilege to help us in that vector? How do we secure developers, which is the dirty little secret of every organization? The developers are the most privileged users in organizations. It's not IT anymore. The developer can actually spin up their own instances on AWS or Microsoft. They can grant themselves full privileges or entitlements. They can claim that they need access and production to do break fix in instances where there's a P0 or an enterprise down scenario, and these developers are sitting there as sitting ducks for bad actors to be able to hijack their identity, get into the cloud environments, and take over enterprises. And then machines, and machines for us is the new frontier. We've been in the machine identity space for more than a decade, but the idea here around machines is, a machine is an application, a new application. It's an IoT device, it's a bot, it's an AI-generated copilot account, it's a piece of code. Machines need to be able to communicate and talk to other machines. They need to be able to log into databases and retrieve content, retrieve data, just like humans. And we need to be able to figure out how to secure those machines in the same ways we think about securing all of ourselves, because as you proliferate the sheer number of machines, that becomes an incredibly difficult scenario for enterprise security teams. That is why we built out further our machine identity solution. So we were in the business of secrets management. I use this analogy to try to help explain the difference between what we did in CyberArk around secrets management and why we spent $1.5 billion two weeks ago to enter into an agreement with Venafi around what they do around certificate lifecycle management, SSH key management, and some of the other areas of machine identity. So I want you to think about a machine as like a human for a second. I want you to think about like an application. So, an application has different ways of identifying themselves. You, as a human, can sometimes log into a SaaS application, log into a data source, and you need a username and password to go do that. That's secrets management, the managing of those credentials so that we vault them, we rotate them, we treat them with a brokered session. That's secrets management. That's what we've been doing for years. But you also walk around with a license or a passport, and it has your name, your address. In the old days, it had your Social Security number. It has all the information about you to identify yourself. That's a certificate. So a machine and an application needs to be able to act like a human and log in with secrets, usernames, and passwords. It also needs to be able to identify itself when it's talking to other machines, when it wants to be listed on the Internet or be found on the Internet. That's a certificate. So machines have multiple forms of identity, and we need to figure out how to manage all those in a world of increasing complexity and increasing number, sheer number of machines. Our ability to bring Venafi and our solutions together allows us to be able to offer an end-to-end machine identity security solution, just like we're able to offer an end-to-end human identity security solution with taking workforce, developers, and IT. This is just a visualization for all of you of what this looks like, right? For each type of group, workforce, IT, developers, machines, there's a different level of complexity based upon the levels of access, the level of privilege that they have. And even for the workforce, for you or I, okay, when you're logging into your normal applications, you're a general workforce user. You can do single sign-on in MFA. But if you happen to have, administrative rights to be able to report out of your financial databases, you're a privileged user, because if we can steal that information, we can actually do a lot of damage. If you're a admin in HR, most of the day, you're a regular user. But if you log into the HRIS system, to your Workday system, you're a privileged user. So each one of these identities needs a different level of controls applied, and the basic security controls we're applying today are not enough. So our whole thesis is to bring forth a unified platform for human and machine, where we can secure identities and make sure they have the right level of privilege controls, and we think that will sustain us well into the years to come as we cross $1 billion, $2 billion, and beyond in ARR. With that, I will sit down and see what questions are on our minds. Thanks for that overview, Matt. You know, yeah, I'll give you a second to take a seat here, but, can we start out with a little bit of a higher level question and then dig a little bit deeper into some of your new announcements? You know, CyberArk has been building on its platform strategy and really making significant strides to add more capabilities to the portfolio. I think it's clear that CyberArk, as a niche solution, seems to be, in the rearview mirror at this point. And can you talk a little bit, about where customers are in that journey of seeing CyberArk as a platform and maybe what has to happen for customers to really embrace CyberArk across all of its solutions? Yeah, sure. Listen, I think it's been a fun journey, you know, from the core of, "Listen, we are the provider of the most secure software in PAM to this broader story of identity security and what we can do there." I think we see that the platform story is starting to take off. You know, more than 50% of our new logos land with multiple solutions. They're not just to that spectrum, securing IT. They're securing workforce with endpoints, they're securing developers, they're securing machines. We've started to see that motion start to kick off, where these deals are becoming bigger and broader. When we talk with customers today, when we talk, you know, our relationship is with the CISO, it's with the CIO, and it's been, it's been helping prepare them to defend their budgets or support their budgets at the board level. And in the regulatory environment that we live in, these CISOs and CIOs are increasingly having to go into boards and say: "What's the most important thing that we can do?" And identity is at the top of that list. You know, it's other things there, too, like endpoint and cloud security, and then there's a whole host of other things. But identity is often the number one thing that these CISOs are pitching as this will reduce our risk. And so that means that in order for identity to work, they need a unified approach. They can't just do IT admins. For us, that's allowed us to be able to broaden our message, broaden our scope, and it's also been a big driver of our overall growth. Excellent, excellent. You know, as we think about the broader solution approach, you know, let's spend some time digging into this acquisition of Venafi. This is a company we knew well prior to the acquisition, but machine identity is not something that I think is easy to understand. Can you help us, you know, maybe understand how Venafi complements what you have with your existing secret solutions? We've gotten questions from investors saying, you know, is CyberArk just doubling down on what they already had? Yeah, I mean, I think it's a really good question. It's why I've tried to explain it. It's not a perfect analogy, but the difference between usernames and passwords and driver's licenses, and no one would think that those are the same from an identity perspective, you know, that's kinda helping us understand this broad spectrum of types of ways of identifying machines. I think what people need to understand more than anything else is we are at a moment in time where the sheer number of machines are going up. Like, just, just 40-to-1, 50-to-1, you hear these numbers. For every human identity, there's 40-to-1 machine identities. Now, think about the ability for enterprise IT and security to manage that number of identities, to make sure they're secure. So if we take the Venafi example for a second, where they have these certificates, the average life cycle of a certificate. You publish it, it's encrypted. It used to be years. The average life cycle of certificate now is about 350 days. Google just came out with a recommendation that the average life cycle of certificate should be 90 days. So in that world of complexity, where these, the need to be able to find, discover, understand, and then you need to be able to secure, and ultimately, you need to be able to reissue, rotate, just like a password needs to be rotated, this is a emerging crisis for security organizations. We believe that when you now have a holistic approach with one trusted vendor to the idea of a platform, we can actually approach the CISO with a unique solution here. Rather than having to buy point solutions for every little area here, they can just consume it from CyberArk. It's a great opportunity for us. As you said, Venafi's been around for a while. They were the market creator, but they also happen to have spent the last three years building the most advanced, from the ground up, SaaS-native capabilities in these areas. So when we evaluated them, it wasn't just evaluating them as the leader, $150 million in ARR, really profitable, so they're profitable, they're margin accretive for us, it was also they had the best platform, the best technology, which is so rare to find in a company of this size. Excellent, excellent. I mean, I guess the question is also: Why acquire Venafi now? The company's growing at about 20%, and the TAM outlined is $10 billion. So is this a little bit analogous to how the PAM market was viewed in its early days? You know, kind of small and niche-y. At least that's what investors told us at the time of Cyber, CyberArk's IPO, but it's proven to be far larger than folks expected. Yeah, and I think, Jonathan, you believed in the bigger market opportunity even back then, but it is a great analogy around PAM. PAM used to be seen as, in a word, niche, important but small, and maybe it's a subcomponent of the market. I don't think anyone believes that about PAM anymore. PAM itself, forget about identity security, is a broad, growing, sustainable market and a core aspect of the security strategy. But it took some high-profile breaches for that to happen. It took the Equifax breach, it took the Maersk attack, where the entire shipping industry was shut down. It took them to awaken to really the importance. We started to hear, you know, even other cyber CEOs come in and say, "Well, it all came down to a privileged account." And I think we are at the same inflection point in the machine identity space. It is increasingly at the forefront of where these attacks are happening. It's actually the soft underbelly of a lot of organizations. So you not only have the proliferation I was talking about, you have bad actors out there that are gonna target this space, and I think we are at that moment where it becomes much more mainstream, and then a company like CyberArk can take advantage of it. Excellent, excellent. Maybe switching gears to some of the announcements that were made at your Impact Conference, you know, can you talk a little bit about the value proposition of Cora AI and how well, or how do you potentially monetize AI as an opportunity? Yeah. So AI is fascinating, and everybody's talking about it, and there's really three ways it plays into cyber, and it plays into our strategy. Okay, first and foremost, you have to start there. It's being leveraged and utilized by the cybercriminals, the nation-states out there at a rate that I think people don't really understand. And it's not that it's creating, by the way, brand-new attack methods. Like, that's not the important thing. What it's doing is it's elevating the capabilities of the people who are out there. So everybody knows nation-states are the most feared. Like, they have the best hacking capabilities. Well, AI makes cybercriminals more capable of looking and hacking at the level of nation states. And it makes small cybercriminal syndicates capable of hacking at the level of big cybercriminal syndicates. And so we're in this threat landscape where AI is being leveraged day in and day out by the bad actors there, and they're not slowing down. So I know that wasn't the question, but we need to understand that that's shaping the attack landscape. There's a second area, by the way, which is the rise of AI creates new identities. Again, not to the question here yet, but it creates new identities, new bots. Every new AI copilot that comes on is a machine. It's a machine acting like a human, so that's really interesting to us for our strategy. But then there is the third element, which is: how do you build AI into your tools to be most effective? For us, we launched this idea of Cora AI. It's the brain of our platform. And of course, it has elements that everybody else has around a copilot or an assistant that sits next to the technology and allows people to set up the system quicker or use natural language to find information, 'cause that's table stakes. But we think about AI really as a brain, and it should do two things really well in our mind. One is it should help you analyze and then apply policy, because one of the number one things that fall down in the cyber deployments is actually the universal application of the right policy at the right time. Not the technology itself, but the policies behind the technology. So Cora AI is really focused on that. It's focused on discovery, so that we can discover all the accounts that are out there and what are they doing. And then ultimately, it will be focused on the data, and the uniqueness about CyberArk, as compared to other cyber providers, is we have data of in session. We have the data of what's happening when the user is actually accessing targets because we're watching and recording those sessions. So we can use that data to make the tool more effective. I don't see it as a monetization strategy. I know everyone always says, "Well, really?" And I'm like: No, it needs to make our tools more effective. It needs to make them more productive, and it needs to make people want to buy our tools more likely. So it's embedded in everything we do. We're not going to monetize it. That makes a ton of sense. Also at the show, you, you talked about ITDR, which has become a much greater focal point. That's identity threat detection and response. You know, can you, can you talk about how identities have become targeted in breaches, and, you know, how does CyberArk have some unique advantages, you know, when you look at this ITDR opportunity? Yeah, I think ITDR means a lot of different things to a lot of different vendors. By the way, identity, the word identity, everybody's in the identity business, but what does identity mean is also different for everybody. You know, a lot of people are coming at ITDR from the idea of, how do we actually really just detect and respond from the outside? So how do we, like some of the agents that sit out there, how do we understand the risk vector of the identities, and how do we watch for it so that we can produce a report, or we can produce an action that somebody else has to go take? Our view is, again, we're in session with the user. We understand what's actually happening, and so we should be detecting and re-responding, meaning watching and then terminating or adding step-up authentication or adding security layers based upon what's actually happening with the users, 'cause we're a control point. So we have so much of that already built into our platform that we're elevating it up to help make sure that it can be visualized more effective by the SOC, by the security teams. And so our approach to ITDR, again, won't be a separate module. We don't need separate modules for all this stuff. We just need more identities to come on the platform, more workforce, more developers, more IT, and more machines. And the way we get more of those identities is by adding in new services like ITDR. That makes a ton of sense. Just, just one final one on product. I mean, how do you think about the use of the enterprise browser? This has become a pretty hot space, in the IT security area. How does this sort of wrap everything around, you know, maybe a platform narrative, unify your products? Yeah, so it is a really interesting thing, right? And I think some of the things we can all just intuitively relate to. Every day, you go to your laptop, and you log into a browser, and that browser has not really changed much in the last 10 years. You know, maybe there's more extensions you can download, and maybe there's more, like, autofill of your password that you can put in there. By the way, those are awful security practices. Your ability to be able to download on your own whatever extension you want, your ability to be able to store your personal passwords in the Google, quote, unquote, "vault" that's sitting there, that's just like chum for the sharks that are out there trying to hack into your environment. So we have this, this, this, this browser that basically hasn't changed, and it's the most used enterprise tool in all organizations. So fundamentally, something has to change. Now, our belief is we're not gonna, we're not gonna make you all learn a new browser. We're not gonna make actually everybody log into that browser every day... But when you're logging into critical infrastructure, critical, critical applications, or when you are actually in a high-risk moment, we would like you to go through a more secure browser. For example, a browser that doesn't have cookies on it. Now, we don't want to ruin your browsing experience, so let's store those cookies centrally in the CyberArk server so that you can still grab those cookies, have the same browsing experience, but if someone hacks into your laptop, they can't get your cookies. They can't actually hijack your session. Let's make sure that we replace all passwords. Actually, best case scenario, let's do a passwordless from day one. And then ultimately, let's use that browser and more secure browsing experience, as Jonathan mentioned, to be a point of entry into our platform so that you can do everything you need to do: PAM targets, workforce targets, SSO, all from our platform in a browser. That's the CyberArk Secure Browser, and again, it's something we give away for free with our platform to get more people into using our platform. That makes a ton of sense. You know, your sales team is now being tasked to sell a much wider range of products, in, you know, some pretty competitive areas. How do you equip the go-to-market to succeed and incentivize the sales force to take on these more complex deals? I mean, you were clearly the market leader in the core PAM space, so it's probably a little bit easier for them to sell that product. Yeah, no, they, they walk into a customer with a PAM tool in their, in their bag, and they're known, and they're understood, and they walk in, for example, with a reimagined world to secure the workforce, where they're competing against a Microsoft or an Okta, and it's a little bit harder. The way you enable any sales team is, A, you understand what are they actually capable of introducing, and where do they need specialists or expertise that overlay on top of that? And if it's really complicated, then you take the sale away from them, and you make somebody else sell it. The good news is nothing we're selling requires a separate sales team. Just parts of the portfolio require a little bit of deep expertise, so we've enabled them with some overlays. We have an enabling program that's built on demand. So when they're in the Salesforce instance and they're looking through to create a quote, they can get all their enablement materials right there around all of our solutions, around all of our demos. We have investments coming online with AI so that we can make them more efficient in how they even are able to use a copilot chatbot while they're on site. All these things become part of how you enable a modern Salesforce. By the way, you ca-- you don't just enable your own Salesforce, you enable the channel partners 'cause they're the true extension of who you are. I think the cool thing about what we do is it's all within identity. It's one of the reasons I don't want to get outside of identity. There's plenty of TAM here. Even if Secrets is a far cry from selling SSO, it's still within the world of identity, and a seller can learn it, and they can sell it, and they can be effective. Great. We have time to take one question from the audience, so if there's anybody with a question, go ahead. Yes, could you discuss regarding the acquisition, the technology standpoint, how similar is their technology to yours? Is there any integration requirement? And then secondly, is there a sales growth opportunity beyond what they might have achieved on their own because of the two of you working together? Yeah, sure. So the question really is around Venafi and the idea of, you know, what's the technology overlap and maybe a little strategy there, and then what about go-to-market and how we bring them to market. So from a technology perspective, I think there's an opportunity to build our secrets, the username and password version of machine, into their technology so that we have an end-to-end machine identity story, and then to start to leverage and take advantage of shared services we've built into our platform to make sure that there's a seamless integration between the two. That will come out over time. Again, they have a great tech stack, so I don't want to interfere with it, and I think it's ready to go to market, and I wanna be able to bring it to market fast. Which brings us to the second point. Absolutely, like, just keep your mind around the idea that Venafi has low 20s number of quota-carrying reps, and I've got 10-15x the number of quota-carrying reps, and every one of those reps can go sell this. Venafi had a minimal channel presence. We have, everyone knows, a great channel presence. We have all the big SIs, we have MSPs, we have distributors, we have our ability to go through the AWS marketplace. So our go-to-market engine on top of their tech stack and this market opportunity is absolutely the thesis, and we should be able to accelerate growth that they would have been done independently because of just the very nature of being in our wheelhouse to go bring to market. Great. Well, thank you so much, and looking forward to the Q&A session in the Adler Room. Thank you.
Loading workspace