Great. Good morning, everyone, and welcome to Needham Tech Week. My name is Matt Dezort, Senior Security Analyst here at Needham. It's my pleasure today to kick things off with the management team of CyberArk. As a reminder, this will be a fireside chat format. I'll run through my list of questions, but to keep it as collaborative as possible, please submit any questions you have through the queue or my email at mdezort@needhamco.com, and I'll be sure to prioritize those as they come in. With that, it's my pleasure to welcome to the stage CyberArk's Chief Financial Officer, Josh Siegel. Welcome, Josh. Hi. Thanks, Matt. It's great to be here this morning and really appreciate you organizing this conference and having us having CyberArk. So we can get going. Always a pleasure to have you on. I guess, firstly, congratulations are in order to you and on an incredible run as the CFO of CyberArk. What a run it's been. My hat's off to you. Just wanted to get that out there and say congratulations. And it seems like, you know, with Erica stepping in, almost a decade of experience at CyberArk, no beats are going to be skipped. Yeah. Well, thank you for that, Matt. You know, it's been. I've been at CyberArk over 13 years, almost 14 years. I joined the company. We were selling under. We were in the 30s. We had about 120 people in the company. We had a plan to go public. We went public. It's been a great run. And I'm looking to step down after 35 years, you know, CFO slash many other management and financial roles around the world, both in the U.S. and in Israel. Yeah, I'm willing to. I'm kind of looking to step down from this operational role. And we had this great succession plan with Erica, as one of my chief lieutenants in the department, who's been my partner for a long time. And I think we won't miss a beat, like you said. She's going to be terrific, a hell of a CFO. Definitely. I guess to start things off, maybe at a high level, you did just report Q3 results really spectacular across the board. I think you beat on every metric, raised the outlook for the full year. Could you just, at a high level, recap the results for us and maybe the one or two, three things that stuck out to you from a KPI perspective? Yeah. I mean, you know, the nice thing is that we and it's not just in Q3, by the way. I think we've been pretty consistent through the first three quarters of this year. Really, when we opened the year in the beginning of the year, we said, hey, we had a strong, a really strong Q3, even a stronger Q4 last year. And we're sitting here now looking at kind of a crescendo, continuing the crescendo through 2024. And so we kind of have met or exceeded our goals, I think, in each of the first two quarters, almost across all metrics. And in the third quarter, you know, we grew our ARR by 31%, which meant the net new ARR also grew in double digits, which in today's environment, if you think about our peers and you think about companies at our scale, that's, I think, puts us in a rare space. Even more so, what we're very excited about as we kind of came out of the transition last year, our number one focus was how do we get back towards strong profitability, continuing to expand our profitability and our cash flow. And already in Q3, we moved it up from Q2 and Q1, where we hit a 15% operating margin. We had a 21% free cash flow margin. So, you know, when you think about, again, you know, what that means, because we have to stop and pause for a second that, you know, we're in that rare kind of space of being a Rule of 40 company in this macro at this scale. And, you know, I think I will remind everybody that, you know, the Venafi acquisition that I'm sure we'll talk about in detail later on was not part of our Q3 results because we only closed the transaction on the 1st of October. But when we think about, you know, the guidance that we raised for Q4, even if we took out the Venafi piece, it would still be increasing our guide for all metrics. So I think those are important. I will point out the other thing. When we look at our net new ARR subscription for the third quarter, it was $59 million, and it served, and we really track this. Q4 is always our biggest quarter, but this was a record for us on a non-Q4 quarter. As I said before, it increased 11% YoY, which is a nice place to be in this environment. Yeah, the growth, variability, and margin expansion is definitely impressive, and you guys are, you know, top amongst the group in both of those departments. I guess to stay on the quarter, because it's been topical for some of your security peers so far in Q3, I guess, how were deal cycles and sales cycles trending? Did any deals get pushed out or pulled into Q3? Any sort of abnormal linearity to talk about? Or was it kind of just, like you said, smooth sailing and more grand execution from CyberArk? Yeah, you know, I think, you know, there was nothing abnormal about the quarter. I think that, you know, it is an enterprise. We are an enterprise vendor for software. So every quarter, there's some deals that come in, some deals that go out. So that's the whole notion of having the right pipe coverage when you go into the quarter to be able to set your guide and your forecasting. So I don't think there was anything unique on the third quarter that I would point to. I think overall, you know, we saw good revenue growth across each of the regions in the Americas and in Europe and in APJ. And we saw, you know, again, we and it's not just for one quarter. Actually, you can go back all the way my whole 13+ years. We're very consistent on kind of sticking to this kind of 60% of the business in Americas, close to 30%, you know, give or take 1% in EMEA and another, you know, the balance, which is going to be somewhere between, you know, 8+ to 10+, you know, coming in APJ, and again, I think we saw Q3 like that as well, and we really track that because the beauty of where CyberArk comes from is that it's the diversity of what we do. It's across all geographies, and we all know, and especially in this volatile economic period, you know, you really want to rely on that diversity across the different regions. Sometimes one is a tiny bit better than the other or more or less, but also across verticals, so you know, when we think about our diversity, it's also across verticals. And I think we have like nine verticals that each contribute more than 5% of our bookings pie. So we're able to afford where some verticals might be a little bit more and some might be less, you know, within a particular quarter and rely off of that. So, you know, that's how I would talk about the quarter. It's really just continuing to go out there and pound the execution. Got it. I guess let's go back to something you mentioned earlier, the acquisition of Venafi, which I think you guys closed, as you said, right after the quarter ended, October 1st. You know, lots of excitement around this acquisition. I guess to start, you know, how are early conversations with customers trending? I know you just closed it, but any anecdotes that you can give us to chew on, especially for your large customer base that doesn't have this solution but, you know, so desperately needs it? Yeah. So actually, you know, the whole deal and the interest from our perspective, you know, obviously we always knew about Venafi. We always knew about lifecycle management, you know, for certificates. And it's always been a machine identity that was another incremental market that we knew was out there when we think about machine identity solutions. But a lot of how this whole thing germinated was because of customers already coming to us and they're knowing about, you know, talking to us about our secrets management solution, which is, you know, 10% of our ARR and growing faster than the rest of the business, or at least, you know, one of the top growers, and coming to us and saying, you know, we also have this certificate problem, you know, with machine identities. You know, we've got the change of policy from AWS and from Google and from Apple now in terms of creating more velocity around that. You know, what are you, you know, where are you guys on that? So it kind of, we were always a part, we've been a partner since Venafi, with Venafi since 2019, but this notion that, you know, that, hey, maybe this is something that we also should be including in our platform, you know, kind of originally came from customers. So when we announced the deal, we actually did get kind of a real flow of inbounds. Already, we announced actually the deal publicly. We were at our customer event in May. And we actually already there, not only from customers, but from partners, how do I start getting trained on being able to be your reseller and, you know, on that. Now that we've announced the closure of the deal on the 1st of October, we absolutely have already started building pipe that, you know, it still has the same kind of six- to nine-month enterprise software lifecycle that CyberArk does, but it's to the same CIO and it's to the same type of an enterprise that we would sell, you know, our entire identity solution to. So we're actually very, very energized about, hey, this is really kind of a good fit for our already go-to-market and partner program. And it's not going to be a renovation within CyberArk to be able to, it's not even going to be an evolution. It's going to be more like an adjustment to now be able to sell Venafi. And the interest by not just the customers, but our partners to get involved on this has been extremely high. Got it. Now, of the handful of catalysts you just mentioned for the machine identity market, I guess there's cloud, there's regulation, proliferation of assets, the Google, Apple, and AWS changes that you talked about, all bound to accelerate growth of this asset as you integrate it, you know, into your platform. I guess of those catalysts, of those secular catalysts, you know, ignoring the go-to-market addition that you expect, which of those are most prominent near-term and driving, you know, buyer mentality today? With regard to Venafi? Yes. Yeah. So, you know, I really think that, you know, I think Matt did an excellent job on talking about it in the earnings call where he said, you know, it's really about, he called it the three V's, right? It's about, you know, volume, velocity, and variety. And, you know, when you think about what's going on here, you have, you know, just the volume of certificates, which is directly going to be driven by the fact that Google has changed the policy to 90 days from 390 days. Apple just announced 45 days, by the way, as well, you know, from their perspective. So the amount of volume that enterprises are going to have to deal with, the number of certificates and the certificate rotations, you know, is extremely high. And that's, it's an easy one for even non-technical people like myself to understand. I mean, as somebody who has to operate an organization, and if I have, you know, 10,000 certificates, I can see the CIO saying, "Hey, I'll just have a room full of people, you know, dealing with the Excel." And then once a year, they go through and deal with managing those certifications. But if I have to deal with that on a quarterly basis, then this is something that's going to have to be automated. And because you're multiplying everything by, you know, 10,000. I think the other piece is then you got the variety, right? It's not just certificates. It's also, you know, you have PKI keys and you have Kubernetes and you have all of these other new digitized credentials that, you know, will have to be managed as well and rotated and managed. So you now have the volume times the variety and you're, again, exponentially growing it. And so, I mean, those are the factors that are really high. The other factor I would talk about is you think about, you know, what's going on with the post-quantum world. And the reason why I say that, while it's still something that is, you know, kind of several years away, maybe 2028, maybe 2029, maybe 2030, it's not something that you can wait until that time period to actually start, you know, addressing. You actually, I mean, you know, I'm old enough to think about Bug 2000 and already in 1998, you know, in 1997, it was already one of the most, like, biggest things that we had to discuss as an operator. I remember being an exec in a company when we were in the finance department, and we were already sorting out how are we going to deal with that, you know, one to two to three years in advance, and this is something similar. And by the way, that's going to also increase the volume dramatically, as well as another factor, so that's what we're looking at, and it feels like it's really a good time for us to get in the business. Appreciate all that great color. I guess staying on Venafi, you mentioned the channel, lots of partner excitement around the solution. We certainly felt it at the conference in May that you hosted. I guess, you know, how long does it take for a partner to get certified to sell Venafi? You know, when should we expect the channel? I think you talked about over 10x reach versus what Venafi had beforehand, right? When do you expect that channel kicker to really start to kick in? And how long does it take to get certified as an enterprise partner? Yeah. So I mean, I would think about it, there's two things, right? On the go-to-market, there's our AE team, right, which is the 10x of their AE team or maybe even more. And then there's the partners, which is even much more, you know, exponential compared to their partner program. Because with all due respect, while we love, you know, we love Venafi, but their go-to-market was not, you know, was not robust, particularly on the partner side. So if we think about partners, you know, they've already started their training process. We've already gotten in the first cohorts. And we should expect, you know, the partners already, you know, by middle of next year to be, you know, able to start to impact, you know, to impact growth, you know, going into the back half of next year. They're in process already today as we speak, you know, going through certification process and going through trainings and getting and also creating a waitlist for when those are done that we do the next group. Then I think on our go-to-market team, you know, they've already been, you know, training on it while they couldn't take it to market, but they've already been training on it even, you know, before we announced, you know, in October. They'll be ready to go, you know, in the beginning of Q1 to be able to start carrying it in their bag. We'll be expecting them the same AEs who will be selling our solutions to administrators, our solutions to developers, our solutions to the workforce. They're going to be selling machine solutions. And it's going to be machine solutions, which includes secrets management and includes all of the Venafi solutions as well. Got it. Got it. I it. I appreciate that. I guess shifting gears to another thing you announced last quarter, I guess, the Wiz partnership, you know, obviously Wiz is the prolific cloud security provider. You know, this should serve, I think, as a strong insertion point for you guys into the cloud and dev community again. You know, tell us about this partnership, how we should think about it as a driver for near-term revenue and new customer growth. Yeah. So we're really excited about the Wiz partnership that we announced last week. It actually also, like Venafi, it also came from the ground up. So it came from our customers, right? Because our customers were saying, hey, you know, we're running, you know, this Wiz technology, the Wiz software. It's great software. And it basically goes through and discovers, you know, all of the, you know, the misposturing of credentials, the overpower of credentials. In other words, that they have the ability to do things that they shouldn't be doing for longer than they should be doing things, what we call the, you know, the overprivilege of credentials. And basically gives you a map of your entire estate. And basically the CIOs are like, this is terrific, really easy to use. We love it. And we have this beautiful map. And now what do we do? You know, because it kind of puts you into a state of, okay, we have work to do on identity security related to many of these things that we're seeing on the map. While we won't solve all their problems, you know, it really ties in directly to particularly the credentials that have unfettered access to cloud, right? The developers especially. You know, that becomes a huge vulnerability that before they kind of knew they had, but now they see they have it on a direct map. We're able to, you know, have kind of a nice, okay, now you see it, now you solve it type of a partnership between Wiz and CyberArk. You know, it came from the customers. We're already working with some customers on kind of this, you know, okay, you see it here, solve it with CyberArk type of an approach, and it's very exciting. It's something that is also at the CEO level. Matt has had, you know, kind of first started with his discussion with the CEO of Wiz, and after kind of it was bubbling up from the field and, you know, we hope to continue to develop it nicely. Got it. Yeah. Sounds really exciting. I guess shifting gears to another thing you announced this last quarter, workforce surpassed 100 million ARR. You know, that segment of your business is growing, you know, really strong for you guys. You've highlighted growth the past few quarters there. It seems like you're making some share gains. I guess remind us how CyberArk is differentiating from other identity access management providers and, you know, where we should think about your traction to date so far. Has it been enterprise, SMB, mid-market, and how big can this business get for CyberArk? Yeah. So I mean, first of all, I think, you know, if we think about how big it can get, it can get, first of all, it's one of our fastest growers, certainly growing, you know, faster than our midline and our core together, by the way, with secrets and our machine identity, you know, solutions. But, you know, the important part here is, you know, what was CyberArk's, you know, intent in getting into the workforce and access space. And, you know, we got into it several years ago with an acquisition, you know, for the basic tenets of what you need to be an access provider around single sign-on and multi-factor. And basically we spent, you know, the first, you know, the first time being kind of a me too getting to feature parity on single sign-on and multi-factor and kind of the basic commodity elements of being a player in the access market. But our full intent when we got into this space was not to be that me too around identity managing, but actually to create this identity security market, which is about we believe that the workforce, right, is a vulnerability spot and a key component of a zero trust network. So you can't have a full zero trust network unless you're also not just managing the workforce, but also securing the workforce. And so single sign-on and multi-factor are important. You can't really. You need to have doors and windows on your house to make sure the rain and, you know, and you keep out the easy stuff. But you really want to know what they are doing and in the session that the workforce is in. So you want to make it hard to get into the session, but you want to also follow them into the session. We heard. I was with investors yesterday and we used a great analogy. We were in a fancy office building in New York City and we said, look, you know, the guard outside, you know, you show them the pass to get in and they let you in, but he doesn't follow you around the hallways and open every door for you and listen to what you're saying. And I think that's the difference between what we're trying to do around workforce access and what, you know, I think what classical identity management players are doing with single sign-on and multi-factor, which, you know, frankly today is a commodity. So our differentiation is exactly that. We take those commodity items around single sign-on and multi-factor, and then we wrap them and extend them to include session management, password management, intelligent controls that basically might require reauthentication depending on what that application is or how long have they been on the network or if they sense any kind of weird things happening during the session and be able to create kind of a detection and response to be able to, like I said before, have if the human guard was actually walking in with you and checking and sitting with you as you were going into the meetings and if you do something suspicious, be able to put up the Heisman and reset the clock. So, you know, that's our differentiation. I think where that's played out for us, you know, is after we got to the feature parity in the first year, we now have kind of the feature value of being able to come out. And it's already been this way for, I don't know, you know, the last couple of years. And I think in the last year, we've really started to kind of have that traction of being invited to the dance to be able to say, hey, you know, we want more than just single sign-on because we see that and we can point to, you know, an abundance of breaches where that just wasn't enough and they were able to bypass that. It would have been very handy in that breach situation to be able to have the intelligent controls and the session management that we would be able to add to that while after given the access. You know, if you think about it in terms of the competitive environment, so obviously, you know, we have that moat with the Oktas and the Microsofts who are much more, you know, around good access and they have good products. But, you know, we can extend even if they have, if they have an Okta, then they might look to us for the full solution. If they have a Microsoft, they're probably getting a really good price for it. And then we have a lot of instances where we just wrap and extend, you know, above that. So I think that's where we are, that's where we are at access. You know, how big will it get? The market is gigantic. You know, it's as big as the PAM market. But I think, you know, the race is on for continuing to work off of our install base who already have PAM because that's going to be, you know, the buyers and the enterprise buyers that really understand this notion of identity security and not just about, you know, managing the access for the workforce. So we see, you know, frequently that it is a landing point for us. We probably do, I don't know, 5%-10% of our new logos on an IAM land solo, but it generally will be either an add-on to our existing customers or will frequently be bought by our new logos in addition to starting with admin. You know, we're, you know, we see it continuing to be one of the faster growers for CyberArk. Really exciting stuff. I guess let's shift to another equally exciting opportunity. I think, you know, a market where you enjoy maybe a little less competition and Endpoint Privilege Manager, right? I think a couple quarters ago, you guys called it out as surpassing $100 million ARR. How should we think about that market, the competitive environment there? You know, sort of same question, how big could EPM be? Clearly, it seems like this is something that, you know, everyone needs. I know you guys have initially started with highly regulated industries, but I guess has that reached an inflection point where you're starting to see this take off outside of, you know, those markets? Yeah. So, I mean, we're, you know, Endpoint Privilege Manager is, and we kind of almost even, you know, it's basically critical for all, you know, for prevention of ransomware attacks. It's also critical when you think about, you know, what the attack chain is of most attackers, which is bad actors try to get in on the endpoint and then they try to utilize the administrative access at that endpoint. And by the way, that endpoint could be workforce endpoint. It could also be a server endpoint as well. And then, you know, access that endpoint, which is unprotected, and then jump and elevate privileges as it goes through the rest of the network. You know, we, you know, I think we started to see, you know, fast growth as especially when ransomware became, you know, so prevalent. It's now kind of growing, you know, together with the rest of our business. You know, we'll actually, one of the things that we're really excited about with EPM is the tie-in, and it also goes to our whole notion of why it was so important for us to expand identity security to include the workforce. Because when you, the EPM can actually, when it's sit and tied in with the workforce, then you actually have like a really ironclad, you know, security on that endpoint because you can start to use, you know, you can start to use the access, the same agent with the EPM and the access and be able to have kind of more passwordless type of movement through the network, you know, with those two joined together. That's where this is going, that's where this is going down the road. From our perspective, we're actually, you know, it's this notion that you don't want to look at each one as a point solution. You don't want to look at EPM just as securing the administration. We want to look at that as you're securing the workforce. It's interlocked with the endpoint, which is securing administrative access, but it's interlocked with that access play as well. And then you have, you know, all of the rest of the solutions around the administration and around the developers. When you think about it that way, the picture becomes complete and you're able to sell any and all of these solutions because you have all of them. And it becomes a much more, you know, clear, you know, clear strategy for the enterprise to say, hey, I need to think about maybe a platform for the network. I need to think maybe about a platform for the endpoint, but I need to think about a platform for all the identities from the endpoint, you know, up through the IT administrators. And then we're like that. That's where we're positioned. Got it. I guess let's shift gears to channel and MSSPs. I know you guys have been making strong incremental investments there, especially in the MSP segment. I think you've called out incredible momentum and I think deal sizes there are 50% larger on average. I guess, you know, how much of your channel comes from MSPs? Maybe talk about some of the investments you're seeing there and traction in that market. Yeah. So MSP is a critical part of our partner program. I mean, if we think about our partner program, it's resellers, distributors, and it's advisory firms. And then it's also marketplace and then there's, you know, the MSPs. And it's actually what's interesting about the MSPs is that while it definitely is an avenue for us to get lower market, right? Because it's not, it's kind of a classic solution and way for mid-market and what we call corporates, you know, to enjoy a lot of, you know, a lot of the identity security infrastructure. Believe it or not, it's actually large enterprises are going the way of MSPs as well. And we're seeing that and we have, you know, numerous examples of it. So we're not kind of thinking about it only as a down-market play. We're thinking about it as actually, if we're probably sitting here five years from now, there's going to be a pretty significant percentage of enterprises going through MSPs using identity security. And so that's why, you know, we want to be able to see as many of those as possible today using CyberArk as their foundation. And we've seen it for, obviously we have many that are using it around for Privileged Cloud. I think a couple of quarters ago, we announced an MSP that adopted even our access as their foundation for providing access as an MSP to their customer base and it had to rip out one of our competitors. Well, I won't say who. And so it's really, it's something that we're investing in. One of the things that we did in the last, this year is that we announced and we released it already. So, MSPs are already enjoying it, a kind of a centralized console so that it allows our product to look much, much more like an MSP type of a business arrangement for them where they can look centrally across all of their deployment environment and be able to get reporting that's centralized and data and things like that. And those are the types of things that we'll continue to, you know, to release along the way. Then, of course, it's just pure, you know, blocking and tackling investment on managing these and selling to them and ensuring that they want to work with CyberArk as the preferred identity security vendor. Got it. I guess three minutes left here. Let me shift gears again to profitability. You mentioned it earlier, really impressive free cash flow margin expansion, 21%. I guess the question is, you know, you've laid out the 25 and 27 targets, which are obviously now aged with Venafi coming on board, that being accretive to gross and operating margins. Maybe talk about your levers for continuing to generate free cash flow growth from here as you sort of lap the, you know, the tailwinds from the SaaS transition and how we should be thinking about that relative to operating margins. Yeah, I think that, you know, we put out the free cash flow, you know, for the guide for the year and it's exceptional. It's, you know, again, it's, you know, as we think about that plus revenue growth, we're well into, you know, we're well into the Rule 40, you know, environment. And I think as we, one of the things that I would point out is that we got the inflection of the post-transition this year of it really expanding even beyond our operating margin, our net income margin expansion. So, which we kind of thought might come later at the end of this year and into 2025 because it was kind of, you know, the flow out from the end of the transition, but actually we saw it this year. So I think as you think about 2025 and 2026, yes, we intend to continue to leverage our operating margin. So therefore, by definition, we expect our free cash flow margin to expand, you know, beyond, you know, with the expansion of the operating margin, but we're not going to see, I think, the same jump or inflection off of it. So we'll see kind of it go together with the, as we leverage our operating margin, which we still intend to do into next year, you'll see leverage in the free cash flow. But I think that kind of step up that we did happen this year and from here on in, it'll be closer to just leveraging it kind of the same way, the same level that we would be leveraging the operating margin. And I think I'd end on, you know, when you think about we hit 25 long-term goals in 2024, which is great. I love it. And so now I think the way we think about it is kind of next year is kind of that bridge between our original 2025 goals and our original 2027 goals. And that's kind of where I would end it. Great. I think that perfectly brings us to time here. Josh Siegel, it's always a pleasure to have you guys. Appreciate you joining us here at Needham Tech Week. For all the clients that tuned in today, please enjoy the rest of the conference and thank you for tuning in. Great. Thank you, Matt, and also congrats to you. I know that this is kind of the first year and new role for you and we miss Alex, but you know, congrats to you on your new role. Thank you very much. Appreciate it. Great.
Loading workspace