Cool. Well, let's get started. Thank you all for joining. I'm Roger Boyd. I'm the cybersecurity analyst here at UBS. It's my pleasure to introduce Eduarda Camacho, who's COO of CyberArk. So thank you for being here. Pleasure. Of course. My pleasure. Awesome. Before we get started, if you wanna ask a question, you can submit it through the app. You can get the app through the QR codes on the table. There's also a mic being run around if that's easier. Happy to incorporate those questions. And with that, we'll jump into a quick fireside. Sounds good. Awesome. Eduarda, you're relatively new to CyberArk. Right. But, maybe you could just start with giving your background. I think most investors are aware of who you are, but just kinda your background, and what you've been focusing on at CyberArk over the past year. Sure. So I joined CyberArk in January, so it's gonna be here a full year soon. Before CyberArk, I spent more than two decades at PTC, doing very different go-to-market roles, living around the world, you know, Europe, Asia, and then in the last few years in the US. For those, you know, who know PTC and know Matt Cohen, we actually, I would almost say we grew up together there. We worked together like for more than 15 years in the organization. Then Matt left, came to CyberArk. I left. I went to BMC Software, so two different enterprise software companies, and now COO here since the beginning of the year. You know, I run all of the go-to-market teams and customer success teams. Obviously, you know, coming in, you know, Matt had this role before I did and before he became CEO. So we are very aligned in terms of how we think about go-to-market and priorities. So it's been more, you know, tweaking and, adding my own point of view a lot around the end-to-end of the customer experience that I've been focusing on. But, you know, and as in any company, continue to evolve the organization. Got it. Okay. Maybe that's a nice jumping-off point. I mean, I think most investors think about CyberArk as one of the smoother operators in the space. In the past 12 months, 11 months, like, what have you, what have you seen as areas where you've been able to tweak things and improve things? I'd say there's maybe a few areas I would call out. Continue to accelerate the, the investment and work around some of the partner channel overall opportunities. We see a lot of momentum and evolution in the strategic nature of our relationship with the, the global SIs. That just got accelerated now after the acquisition of Venafi and some of the other competitive dynamics. Aligned with the marketing around, you know, more program dollars around acceleration of adoption together with partners. The MSP route, I think that continues to be one of the big focus areas. So a lot of that tweaks in that area. Overall end-to-end experience, you know, making sure we get, you know, a very well-aligned machine all the way from adoption all the way to, you know, implementation, successful adoption, and expansion. experience, making sure our customers are in the latest of the platform so they can grow from there. Those have been some of the tweaks that I've been focusing mostly on. Awesome. Okay. Well, a couple things to come back to, but maybe let's zoom out a little bit and talk about. Yep. The platform story as a whole. I think five years ago, most investors and probably customers too thought about CyberArk as the leader in PAM, but maybe focused on PAM, and it's a much different story today, but I'd love to hear in your words kinda where you think you are in the transition. We all know kind of the breakdown of ARR, but kind of where do you think we are in kind of this broader identity push? It's again not having lived through some of the earlier days, but it's really interesting. I had the opportunity since I joined. I think I've been in all of the major regions, a lot of customers, either through our customer events that we do in 20 cities around the world as well as, you know, just visiting. And, you know, a very, I would say, very consistent, and well-received and resonating story about the transition of CyberArk, right, from being, you know, that strength around the core PAM to identity security platform and where we are and where our customers are in that journey. So as I think most everyone knows, like, from that space where we were, you know, we invented the PAM space and are still a leader in that space, you know, the broadening of that definition of identity security becomes so much more critical, you know, for CISOs and in general and where a lot of the breaches come, and really being able to talk and resonate when we talk to our CISOs and our channel partners around, you know, how that definition of privilege has expanded, you know, our vision that every identity in the company needs some sort, you know, the right level of privilege control. I think that transition, you know, you see it is not just us pushing it. You know, we see the CISOs. We see, you know, the market talk back at us in those terms. And I think that is a big part of that transition, right, where, you know, we are talking with the customers about, "Okay. And here's how you protect, you know, your high-risk workforce users. And here's, like, a comprehensive plan around machine identities, you know, both the Secrets Hub and now with Venafi. Hey, let's get a seat at the table and start having a real conversation about protecting, you know, your cloud developers." And, you know, that we have growing, exponentially growing part of the human identities that has possibly the least protections today when it comes to. So I think that transition, you know, both internally but also in terms of the resonance when I go talk to customers and partners out there is, it's done. And now, you know, it's building on that power of that story and that platform. Yeah. Yeah. I think, I wanna jump into non-human identity in a second, but just around core PAM. Mm-hmm. You've given the long-term target of what the ARR mix looks like over time, and it still calls for, I think, 50% PAM when we look at a couple of years. Have you talked a little bit about how underpenetrated you are within customers even in PAM? Can you just remind us kind of the view there and where you see that going, separate of kind of all the. Separate from the rest. So when we look, you know, when you see our subscription mix today, like, you see the numbers. We're reporting in Q3. We are 55%, 45%, right? 55% PAM, 45% non-PAM, both growing, but the non-PAM growing faster. So at some point in time, it's gonna, right, catch up. When it comes to the strength of the PAM and the growth in the PAM, you know, and I'll address your how much we are penetrated. It's, I think, you know, from the penetration in our install base, we say around a third, 30%. And a lot of the growth vectors there, a lot of it is on the story around modern PAM. So really the defined expanded definition of what a privileged IT user is, more use cases, cloud workloads, operations, all of that has really been driving. And then opening up to the developer community, that has been really driving the strength and the growth in the PAM. But again, the rest of the portfolio, growing at a faster pace, is eventually gonna catch up. When we say 30% in our installed base, like, you know, you see on the overall market, you know, it's a much less penetration, maybe less than 10%. Yeah. Got it. Okay. To jump into non-human identity, you made the acquisition of Venafi earlier this year. I think the challenge is becoming more obvious. The millions of TLS, SSH certificates out there, IoT devices, different agents now with the generative AI. Venafi had some very large, I think, important customers, Southwest Airlines, BP, some other big ones. But it's a rather small business. And the question I get from investors is, "Why isn't this bigger already?" So I'd love to get in your words kind of why you think the non-human identity automation lifecycle management business takes off from here? We believe the, you know, two parts of that story. You know, why the inflection point now and a little bit where, you know, the dynamics around the, the Venafi growth rates, right? So in terms of just the, market inflection or, or the why now, you know, in, in those inflection points, you know, the way we think about that, even before the Venafi acquisition, you know, secrets, the secrets management piece had really seen the acceleration. And I think part of that is just the companies, the CISOs realizing, like, with the scale of the, of the machine identities and the complexity that, you know, it really became a big focus area. So we talk about the volume of the identities being one of the factors, right? Volume, meaning, you know, one human to 45 or even already one to 50 in some studies, and machine identities growing so exponentially. But also, there's a lot of different types of machines, right? You know, the data centers, but also the workloads and the API bots and the IoT devices and all of that complexity. And so you add the volume with the complexity, the variety of the types of accesses, right? Certifications and the secrets and the tokens and the PKI and all of that complexity or variety, it just creates those two dynamics, right? And I think the third one we've been saying, third V, it's the velocity, which is all of that is changing so rapidly. You have ephemeral workloads. You have machines being spooled up and spooled down. And it just created, I think, that inflection point where the complexity is just not anymore possible to manage with, you know, a homegrown solution or a manual process. And then you add on the regulatory or the Google, you know, effect of, you know, two-year rotation certificates to 90 days. And that just accelerated that. So we believe. I believe we believe. I'm just very bullish about it, that the inflection point is there. It's been there for a few, you know, maybe a few quarters. You know, Venafi had invested heavily on, and, you know, great company, great people, invested heavily on the technology from a SaaS perspective, but decided to do it from scratch. So, you know, a lot of companies will lift and shift. They did. They built it from scratch, which is better for now and for the long run, but it created a delay in the go-to-market, and not a lot of investment in a go-to-market organization. They would recognize that. I think, you know, that's what created a little bit of a slower growth pace for them in the last, you know, few quarters, which we believe we bring the strength of the go-to-market that can accelerate. Yeah. Okay. I wanna move to go-to-market in a second, but just one more on Venafi. You've talked about Venafi adding, I think, about $10 billion into the. $10 billion to the PAM. You gave some color on the earnings call about kind of what that means at a customer perspective in terms of the upsell. Can you just remind us how big incrementally Venafi can be relative to a PAM deployment? What we see today, I know if you see the average size of their ARR, it's almost 3x the size of ours. So we think, like, a $1 PAM, you know, if your customer is it's a $1, it's almost 2.5-3 on the Venafi side. That's how much it brings. And I think we also mentioned, right, there's not a lot of overlap in terms of the installed base. So we have 8,500 customers. Yeah. Of CyberArk that are not Venafi customers. Yeah. And as we transition to this go-to-market kind of topic, I mean, what's been the reaction? The customer reaction sounds pretty positive to Venafi. Mm-hmm. Then that Matt has talked about has been the GSI interest. Can you talk about the level of interest with the service or the systems integrators around building programs around machine identity? I think the fast reaction, you know, of the GSIs, has almost been the most surprising aspect of this. I mean, we were expecting a pretty positive reaction from the customers. We had it from the market. The GSIs, we announced the intention, back in May. Immediately, we saw the traction from the GSIs wanting to get information, even just through, you know, separate entities, you know, get trained on Venafi and building practice. It's been, I think, not just for me, but also, you know, talking to Matt and others, the fastest that they've ever seen, like, the GSIs react in terms of wanting to be ahead of the others and compete for who certifies first and who puts more people through the programs. We still have, you know, one of the areas that we've been preparing in anticipation is making sure we have the training, the enablement, not just to train our people, but especially to train the partner ecosystem. It's been pretty amazing. Now, that combined with even the dynamic around the whole machine and even secrets, you know, it just brings all of the machine identity practices to the forefront of the strategic areas of investment with our partners. Got it. Okay, and maybe more broadly around GSIs. I'd always thought that CyberArk did pretty well with. Mm-hmm. GSIs around PAM. I think you've talked about some ways to improve that. If you can expand on that. And then as you think about unlocking opportunities across the platform, how do you think about doing that on a per-product basis versus selling the entire CyberArk Identity suite as a whole? Does that make sense? With the GSIs or just in general? With the GSIs. Yeah, so I think some of those areas of worst tweaks or elevation with the GSIs is, you know, the realization from their size and some changes to align more towards, you know, instead of having, you know, the PAM and kind of keeping it, you know, to the traditional definition of PAM, you really see them, you know, broadening that to, you know, what they call modern PAM programs, which are much more inclusive of the other offerings of the portfolio, being both on the developer side, you know, starting to get the secrets piece in, you know, getting into the high-risk workforce side. So that's been a lot of, like, this concept of the modern PAM programs and how that becomes broader in terms of the scope. It's been where I've seen a lot of the evolutions as well as, you know, working together with us on elements, you know, as we enrich the platform, you know, the how we think about AI, how we think about securing AI. There's been a lot of great, I would say, strategic discussions with the GSIs and alignment around that. Another area, I think, separate from the GSIs, but the GSIs are part of it, is also the investment around their MSP capabilities to bring us to other partners, bring the CyberArk and the whole identity security to other parts of the market. Yeah. That are, you know, maybe less capable of adopting it and less big an MSP offering. Yeah. That kinda leads perfectly into my next question, which is the same question for MSP. How do you enable them? And I think there's a loose estimation that Matt and others have talked about that maybe 40% of the cybersecurity tool stack will be delivered through some form of managed service provider. I know you launched some MSP-focused tools. Mm-hmm. Including the dashboard, a console earlier this year. But what else are you doing to drive engagement and operationalization of those partners? Yeah. I think we've, you know, we've been. That's when I said one of the areas of tweaks, right, in terms of investment, you know, both from marketing but also from programs in terms of recruiting and developing and enabling some of those MSPs, both standalone as well as, you know, additional to GSI-type contracts and reseller-type contracts. Investment from a product perspective on those functions, you know, on those types of capabilities like the portal that really, you know, helps scale that business from an MSP perspective, working very closely with those partners. You know, this is one area where we are learning from them, right? Mm-hmm. What works and putting the investment. It was one of our top strategic initiatives last year, continues to be this year, and it will continue to develop because we truly believe if it's gonna be 40% or up or down, but it's definitely gonna be a big portion of how, you know, we together can service that market from a security is gonna be through the MSPs, so it's accelerating very nicely in terms of growth rates, but we believe, like, we are just at the beginning of where that journey is gonna be. Yeah. Maybe to focus on a couple other products. The Secrets Management product. Mm-hmm. You've, I think, everybody's talked about that starting to accelerate. It sounds like the competitive environment's gotten a little bit more favorable. How do you think about the trajectory from here? And how does Venafi potentially add to that? How do you think about the combined solution there? So a couple of things. Even before, right, the Venafi acquisition, I think we had seen a really strong acceleration on the growth on the secrets in the outside of, you know, even before Venafi. It's from the portfolio, it's the fastest growing area. It's secrets. And I think it took a while for us to find the right balance from a go-to-market and even from a product on how do you balance, you know, not interfering with developer speed of how they wanna develop and a security imperative. But, you know, the portfolio, how we developed a portfolio, you know, Secrets Hub has been one of the fastest growing parts of the portfolio, Conjur Cloud, where it's transparent, right, for the developers developing the apps, but you have all the security controls in the background, you know, working with your multiple cloud providers. I think we really hit the mark there in terms of, like, balance between experience, security. I think that has accelerated because it's a problem to be solved. And I think, you know, that's there. That's resonating. The competitive dynamic with, you know, with IBM, you know, intention to acquire Hashi has created tailwinds for us, I think, from a concern, you know, a seasonal concern around, you know, the evolution of that portfolio, you know, inside IBM. It has especially accelerated the interest in our partners, in our GSI communities. You know, it was an immediate reaction, as you can imagine. So all of, you know, the real need, the exponential of the machines, the security mindset, and that balance accelerated. And now with Venafi, you know, I think there's different parts of that integration. So the most obvious one and the first one we'll work next year is, you know, Venafi has a control plane that really allows, you know, you in the security organization to see, you know, all the certificates and the keys and their status and where they are. Like, integrating the visibility of secrets into that control plane is gonna be one of the first ones. Yeah. But then from there, I think there's, you know, many, many other areas where, you know, the joint story and the joint development will continue to build. That being said, we don't need to wait for anything. Our go-to-market organization has the two in the bag to go sell. Our channel partners too. We'll early next year, you know, release, like, a joint bundle when the right use case is to sell it together. We can sell it together. We can sell it separate. So we are not depending on, let's say, the integration. But obviously, the more you integrate, the better the value it's gonna be. Yeah. Got it. Okay. You talked a little bit about Secrets Hub and. Mm-hmm. What's going on with kind of cloud developers? We'd love to just get a broader perspective of the strength with Conjur Cloud and Secure Cloud Access. I think relatively newer products that you're not really given metrics around. But what's the momentum there? If you could talk about the competitive environment there, it would be interesting as well. It's a new area for us. Again, you know, securing it both from a secrets perspective, right, and then, you know, from how the developers even access, right, their day-to-day workflows, where, we see that as one of the higher potential growth, opportunities, you know, that community. One is, broadly unprotected and two, the fastest growing human identity for sure. You know, we've had, you know, very fast growth product in our Secure Cloud Access, in our Conjur Cloud portfolio from a small number but a very high fast, growth rate. And, again, striking that balance where we are not interfering with the, with the workflows and the way we work of the developer community, but you're securing them and removing privilege and granting just-in-time privilege and, zero standing privilege, to this to this community. From a competitive landscape, you know, on the secret side, Hashi. On the other ones, we believe there's more very niche type of applications. We think there it's a lot more of a team sport in that, you know, you've seen the announcement around the Wiz partnership as one of the areas where we are coming together as a team sport to really secure. Mm-hmm. That cloud environment. That doesn't mean we only partner with Wiz, but it's a very deep technical partnership integration. We're just saying, you know, like, even in our customer impact event in Toronto, I was there a couple of weeks ago. The Wiz CTO was there. There's a lot of good, you know, I think aligned view on how to secure, you know, them coming from the visibility, discovery, contextualization of, you know, the cloud entitlement just coming from, okay, now that you found this, you know, how do you actually manage it, right, and do something about it? I think it's a really strong partnership that we can build in. So I would say that one very nascent, very niche, like there's no dominance. And then I think, again, finding the right partnerships and the right model there is what's gonna unlock more growth for us. Yeah. I wanted to ask about Wiz, but. Mm-hmm. I mean, it sounds like a deep technical relationship, not a ton of overlap from a technology standpoint, maybe a little bit around cloud entitlements. But how about on the go-to-market side? Is there an angle to that as well? And And expand on that. That'd be great. Yes. So for now on the go-to-market, first of all, you don't see a lot of overlap, right, as we said on technology. On the go-to-market, they've been historically, you know, very strong on the developer side, right, on cloud side. They don't have so much of a strength on their CISO relationships. Also much younger company, right? They've had time to develop those relationships. We come from the enterprise side with the strengths of the enterprise relationships and those two coming together. Right now, you know, we are doing that at customers, you know, when the right occasion in the customer is. It's not a more, you know, deliberate, you know, full-fledged go-to-market strategy. But it's a very young partnership, and we'll evolve it from here. Got it. Okay. Any questions out there in the audience? I just wanna make sure I'm not missing anything. I'll press on. Just around identity, I, I think you've talked about that opportunity is, sort of evolving where you can go at that from, an additive piece of technology that sits on top of other workforce identity. Mm-hmm. Products, or you can go in and replace the whole stack. I mean, what are you seeing from customers? And are those conversations changing? Are they kind of staying constant? Are you having more success doing the full stack? And how do you think about that kind of replacement opportunity over time? Yeah. So on the workforce side, like we always said, that, you know, we have a very small percentage penetrated, right, on even on install base and definitely of the overall, you know, addressable market there. But where our differentiation comes in and they're, you know, aligned to our vision, right, of those privilege controls, you know, the applying the right ones in the right moment to the right identities, it comes into the workforce in two ways. As you said, it's either a full competitive replacement, and we'll talk about that, or it's a complementary, you know, to your SSO MFA that is already in place. So the dynamics we are seeing is, you know, when you have kind of very security-minded organizations, CIOs, CISOs that are really thinking about the workforce and managing more not so much from an operational efficiency but adding the security layer, two things may happen. One, you know, they have more legacy types of solutions. Sometimes we see it with CA-type products or RSA or Oracle, and they're, like, doing a full-fledged replacement. In those cases, you know, when we are in there, we are in there because they have that security orientation. And we end up competing with the Oktas and with the Microsofts. But we compete on we have the SSO MFA, and then we add the security controls on top. We win more than our fair share of those deals because we have that security on top, and, you know, it's a security-minded type approach. Many other occasions, you have the same type of security-minded CISOs, but they have, I know, they have Microsoft. They have the Oktas deployed. And maybe they've done it the last two, three years. We don't see it occasionally, but we don't see a dynamic of, okay, now I'm gonna rip and replace this. I'm gonna start again. I know I think we always say, like, we don't wanna compete just in SSO, MFA to commoditize, not our, you know, where we differentiate. We wanna either compete with the whole stack with a very competitive offering or complementary to what they have. And that's really what's been driving the growth in the workforce. Again, you know, after secrets is the second largest part of the [audio distortion], the highest growth in the portfolio. Got it. Okay. Maybe one or two more. CyberArk introduced the Secure Browser a little while back. Mm-hmm. I think the intention was to not monetize it. It would kind of serve as a jumping-off point to help customers adopt the broader platform. But would love if you could just talk about kind of customer reception of that. It feels like broadly we're hearing more security companies talk about Secure Browser and the role it could play and potentially, user access scenarios. But what's been the CyberArk viewpoint and what's been customer reaction? Yeah. We still have the same approach, right? We are not monetizing it. We are putting it in the hands of, you know, our customers that own the platform. Again, from the two perspectives, right? One, jumping point to, you know, as a jumping point into other areas of the platform. But, you know, from a security perspective, right, it's still, you know, the most widely used and very targeted, right, from post-authentication hijacking and others. So we've been having really good feedback from customers. We have customers that have, you know, widely deployed it. We have others trying different use cases. And we'll continue to monitor that evolution. You know, we have very specific targets in terms of driving the adoption, again, not from a monetization but because of the value that it brings to drive adoption of Secure Browser to installed base. We still believe, you know, the approach of making that as additional value into the platform is the right approach for us. Gotcha. Okay. Maybe I'll, I'll slip one last one in. But I think at your Investor Day back in 2023, CyberArk talked about roughly a third of net new ARR coming from new logos. Mm-hmm. Is that roughly still the goal internally? And you now have Venafi, which is a pretty big cross-sell opportunity, upsell opportunity. You've expanded kind of the presence with the GSIs and MSPs, which probably helps on new logos a bit too. Is that still roughly kind of the target when you think about the growth formula? It's still the same, and we could still keep that third, you know. I think, you know, we've been pretty consistent about saying we wanna be above the, you know, 1,000 in every given year. We continue to think that and execute on that. It's not getting any easier, right, to go and capture new logos, but we've been, I think, all of those different routes. Venafi is another landing spot for us, right? Because again, you can land with workforce. You can land with PAM, EPM. You can land now with Venafi too, so it's another driver there to keep that, but one third is still our target. Got it. All right. We'll wrap there. But thank you very much. It's been a great conversation. Thank you. It's been great. Thank you all for joining. Thank you. Thank you. you. Thank you.
Loading workspace