All right, good morning, everybody. Welcome to TD Cowen's second day of our TMT conference. We are very happy to kick it off with CyberArk's management. Erica Smith, SVP, Finance and IR, Clarence Hinton, CSO for the company. This is a fireside chat, but for those of you who know me, I like to keep things interactive. So those of you with questions, do not hesitate to raise your hand. Clarence or Erica, maybe for the benefit of the audience, slightly less familiar with CyberArk, maybe briefly, can you provide us with a snapshot of what is it that you do, real briefly? Real briefly. See, I, I'll try, but if you go back to the beginning, briefly, very, very briefly, All the way back. All the way back. So the company was really founded on the concept of this digital vault. You know, put all your most important stuff in there. That quickly moved to, well, oh my goodness, people are putting their passwords in there, their shared passwords, and really that's where privileged access management was effectively born. And that, over the years, continued to expand the category, add capabilities like session management, monitoring control for those privileged accounts. We added EPM to endpoint protection. Again, thinking about those, the admin privileges, removing them from the endpoint for the local users, and moved on to the Conjur and the secrets management side, again, controlling the sensitive credentials, sensitive access. To get us to where we are now, we noticed that obviously we've been in security from the beginning, focused on identity from the beginning. Identity was really clearly becoming a primary attack vector. And there were some good companies out there managing identities, but there weren't strong security companies for the other aspects of securing the broader workforce. And so we really launched into this with our acquisition of Idaptive, but providing, you know, extending our security based on varying degrees of privileged controls to a wider set of users, right? And so you look at where we are now, and you can think about it with our a new framing, you know, by identity. So think about IT or extended IT. Clearly, that still has the domain admins, database admins, which is where we started on the PAM side, but you continue to extend out even to cloud engineers, et cetera, still within IT, the access security is different, right? So it's more just in time versus standard, standing access, with vault and rotation, monitoring control. You move over to the developer persona, there's more zero standing privileges. They really don't want anyone, anything in their way at all, but they still must be secure. And developers, one thing they love to do is add more credentials, add more non-human identities, and so that takes us to the third identity type around just all things non-human. And so clearly, if you go way back with service accounts, that's something that we've always protected. You move on to secrets with Conjur, something we protect, and obviously with Venafi, we expand to protect even more. Across all of that, you have workforce identity. That's... Everyone's familiar with the bread and butter, so SSO, MFA, those are you know largely commoditizing, though MFA still is not being 100% adopted everywhere, which is odd because it is an effective control. But there are other protections outside that that we really focus on. We focus on the differentiators. Look at Secure Web Sessions, post-authentication security control for the broader workforce, Workforce Password Management, enterprise-scale, industrial strength security in terms of protecting passwords and Secure Browser, you know, among other things, cookieless browsing. I'd even bring EPM back into that conversation. It's securing the endpoints, removing admin rights and privileges, effectively stopping those forms of ransomware at the endpoint. So it's really reimagining the way that people secure their workforce. Thank you for that. Earlier this month, you've announced healthy results, improved guidance for the year. From what we've said, it was a breath of fresh air, given the choppiness we have seen within the broader software arena. We all know what today is gonna look like with CRM results last night, Path. Is it the mission-critical nature of identity? Is it the SaaS transition? Is that the consistent execution that kind of, in a way, all those metrics have been propelling the company and its results forward? Yeah, I think it's really a combination of, of all three. Uh, so identity, securing identities is, is of paramount importance. No matter what reports you look at, it's going to be the top... one of the top couple of things that are on CISOs' minds, because that's still where the, the bad actors penetrate, whether that's the, the human firewall or more increasingly on, on the machine side. So that's, that's definitely one aspect of it. On the SaaS side, you know, we, we front ran this a bit in PAM in terms of offering a SaaS version of our product. For a while, we didn't think customers would, would be open to it, but they, they were, and we, we were ready. We're seeing the SaaS transition, you know, being particularly strong on the PAM side, and we have certain offerings that are only SaaS. And the overall execution, we brought on Eduarda Camacho, and she's just tremendous in terms of everything we're talking about here with the identity and security vision, the broader portfolio, the focus on each of the four primary identity types, aligning our entire go-to-market engine to that. She's just tremendous already. So I think it's really a combination of all three. ... Last week, we've attended your user conference, Impact 2024 at Nashville. Congrats, great event. But Monday, you know, we never have like, you know, a busy day without something happening, and like you've announced, I was thinking we're gonna have, like, an easy Monday, and boom! Here comes the Venafi acquisition. So maybe can you provide us with some, some metrics, the thought process around that move into machine identity? What does it bring to the table? And maybe the overall vendor consolidation that we have been seeing and has been a topic du jour within the broader cyber arena. Absolutely. So when you go back to the identity types and you just click on the machine or non-human identity, we've thrown out these metrics based on our research, you know, 40x, in terms of the number of non-human identities to human identities. There are other vendors out there, other research shops that go on either side of that. So it's a known thing. Even so, the vast majority of attacks for some time were still focused on that human firewall. We're seeing increasingly that shifting. And so for us, we always want to stay ahead of where the attackers will be. That's one thing that's differentiated CyberArk, is our, especially our labs capabilities. That's how we think, that's how we drive our roadmap and many of our strategic decisions. So for us, when we start to see the next levels of non-human identity becoming the next areas where it's likely for attackers to really pounce, that's where we start focusing our investment there. So you think about what we've... And we talked about it a bit. You think about the service accounts, that's always been part of what we've done, move to secrets, and now it's the certificates and the keys associated with the endpoints, the server, the infrastructure. That's the, you know, the current wheelhouse of Venafi. But then you move on to modern infrastructure, like think containers, and Kubernetes orchestrates them. They have a strong offering there that we're very excited about. Move on to workload security. So you think about the roles that must be secured in cloud, and you think about the service accounts in cloud. They provide us a very strong path and long-term runway to protect those as well. So that's really what we're – that's where the thought process is beginning to protect the long tail of non-human identities as attackers increasingly go there. In terms of the opportunity, again, I'll mix the metrics and the opportunity. We talked about there are $150 million of ARR, you know, very strong. They'll be accretive to our margins, so that's all a very strong profile. But in terms of the near-term opportunity, we have 8,800 customers, they have 550 or so. The overlap is a couple hundred. So you have well over 8,000 customers of ours that need the solutions that they have. It's just a massive opportunity for us when we think about the ability just to go back and cross-sell. So what they have currently, and you think about, you know, down the road, the things we may be able to do, is very, very exciting. And we've talked about the, the TAM, and, we estimated about $10 billion or so incremental TAM. And that's really focused on the core. That's not getting into the, to the cloud roles and cloud service accounts and all. That's not really in that number. And, and the Kubernetes, certificates, that's not really in that number in a meaningful way either. So there's still possibly more down the road, but even so, that gets us to a $60 billion TAM annualized. You know, a few years when Erica was talking to you all, it was, you know, $20 billion or so. So the 3x increase, we're very excited about. So, you know, $20 billion. I still recall back in 2013, 2014, when we initiated on CyberArk, one of the pushback, like, you know, PAM, privileged access management, more of a limited market, has its limits, more of a niche. Maybe talk to us with, you know, here we are sitting 10 years after the IPO, $11 billion market cap. Talk about the opportunity, the opportunities that you're still seeing within PAM. And as we think about the PAM story, you might recall it, it has been underscored by a great displacement opportunity, but in recent years, plenty of greenfield opportunities. Can we take those characteristics from the PAM and start and apply them to machine identity as well? Absolutely. It's a phenomenal question, and on the PAM side, yes. You think about historically, when you're focused on the domain admins and the shared accounts, and you think about it that strictly, yeah, there's a certain limit to how many accounts you may secure, but, you know, very quickly expanded beyond that to, you know, a number of different admin types and personas that we've talked about here. So just there's a natural expansion. Even if you have still a fairly strict definition of a privileged user, that's expanded naturally over time, but we've really seen this pick up. The. We talk about identity and security and extending privilege controls to a broader set of users. The more we push that and the more we expand our portfolio, the more it comes back to: Will I have to make sure I've completely and fully deployed my PAM solution? Because typically, even though it's a limited set, if you think about it in the strictest sense, many customers just go with the tip. It's like just the tip of it, make sure that's secure and and don't fully, you know, fully protect the privileged estate. So we're seeing continued expansion of what you think about as the normal privileged users within our own accounts, large initial expansions within new accounts, and then you have this expansion to... Well, you have others on the edge of IT and getting into developers that also look privileged. And so the scope of what is privileged-... It is expanded in a very, very meaningful way. And if you think about TAM or even SAM, relative to the vendor market, it's still several multiples of that. So still quite a bit of opportunity there. And as you mentioned, there's greenfield opportunity, meaning some meaningful customers still don't have any PAM, and even within those that have it, expansion opportunity, and of course, there's a replacement angle as well. On the machine identity side, you can think about it as similar but earlier. So there, if you think about the TAM relative to the vendor market, I mean, this, in terms of percentage, the vendor market is like single digits percentage of the overall TAM. So there's still a very, very long runway, and there are a number of things that are pushing customers, companies that way. So you just think about the sheer volume of certificates as you have more and more non-human identities that must be, you know, with certificates, must be tracked, issued, revoked, renewed, et cetera, especially in modern environments. And the alternative to a certificate lifecycle management solution is manual with spreadsheets, and that's just unsustainable. You know, I think we've talked about it a bit, the threshold we've seen in our research is kind of this 5,000 certificates. Companies start to blow through that very, very quickly, when you look at the different types of non-human identities that require and use certificates for authentication. So that's really, that's really how we think. And never mind the fact that even if you have the number of certificates staying the same, which you don't, you have very explosive growth. Now, the lifetimes of those are dramatically reduced. And you go back a few years ago, it was commonplace to have a certificate that may last a year, and now the norm is more of a, you know, a few months. And with Google, you know, likely to bring the standard down to 90 days or so, that's the talk. But again, these modern environments, you're talking about days, even hours of duration for some of these certificates. So even if you have a similar number of certificates, it just doesn't work to manage those manually. Understood. Last night, we had Okta reporting results. I've mentioned before the term, breath of fresh air in a choppy reporting season. In Okta, specifically following a couple of, you know, more challenging quarters. I think we look at it favorably. I wanted to bring Okta into the discussion, maybe into the competitive arena discussion. First, maybe how do you guys look at Okta's results from kind of last night? Is that indicative of, I think, overall, all in all, a healthy market trend that we're seeing within identity? And secondly, is there a status quo from a competitive arena? Have we seen any new entrants? You know, some of the bigger platform providers have started talking more about identity, maybe through some partnerships, maybe through some small-scale acquisitions. How do you see that from where you sit? Absolutely. So starting with Okta, I mean, again, for them, solid results, as you mentioned, given the trend. We haven't seen any indication that they're kind of out of otherwise from the security issues, but it does speak to the strength and the importance of identity overall. And, you know, their solutions in terms of the integrations and the automation UI, they have some stuff there that's, you know, very, very, very solid. Just, it's not necessarily security focused by their own admission. So again, it speaks to the importance of identity, even on the management side still. But for us, we still see massive opportunity when you think about effectively securing, you know, the broader set of workforces and really reimagining, you know, what that means. It's not just SSO, MFA; it's the other things I mentioned before. I won't go back through them. So that's how I'd encapsulate that. On the broader competitor front, well, when you think about traditional PAM, we know who the usual suspects are there. And first, they're stable, they're fine, but we're the clear leaders in the market, and strategically, they do a lot of kind of fast following. And that's, you know, all PE-backed, and that's—they're very comfortable in a fast follower kind of mode. And that, that's how that market really operates. You look more on the secrets side, and that's one where, you know, we talked about earlier today, its importance has never been up for debate. What you really have is this, and we're beginning to see the security concern leaders and the developers, and the budgets all converge on the importance of it and what is needed. And we've been able to really advance what we're doing there with our innovations around Conjur Cloud, Secrets Hub, et cetera, that satisfy all the needs. And then, you know, we, you know, Hashi is the other competitor out there. We know they had some business model, you know, challenges, you know, and, and now they - it was announced that they're going to be acquired by IBM. So you can make your own, come, arrive to your own conclusions on what that kind of means in that space. And on the broader workforce side, again, we see a number of like Okta and others, good identity access management companies, but the focus on security just isn't really even... You know, look at others like Microsoft. You know, they're having their own security challenges as well. So again, we're really focused on reimagining, re-envisioning workforce security, bringing these other controls to bear. Questions from the audience before we proceed? You. [audio distortion]. Mm-hmm. I think you talked about a little bit about guidance, your long-term guidance. Can you talk about your standard [audio distortion] ... Great question. So, the question was, as we kind of think about the acquisition of Venafi, how we're gonna approach the long-term model, what that means to the standalone model from a long-term perspective. So as we think about our financial metrics, we've kind of haven't updated the long-term metrics we put out about 18 months ago. But the business is tracking, and we feel very confident in our ability to hit those long-term metrics for 2025 and 2027, even without Venafi, for all the reasons Clarence just talked about. The fundamentals of the business are incredibly strong. Privileged access continues to grow, and our platform, both from a land perspective and an expand perspective, have been tracking ahead of our expectations as it relates to the guidance numbers that we put out there. You layer on top of that Venafi, who actually accelerates our time to even get to a Rule of 40, and we feel even better about our ability to kind of track ahead of where the numbers we talked about for 2025 and 2027. In terms of updating those guidance numbers, you'll have to, we have to close the acquisition, which is expected in the back half of the year, and then we'll take another look at the long-term model and determine the right time to kind of refresh those numbers. But at this point, we wanna wait until we close, and then we'll take another look at the numbers. [audio distortion] Yeah, so quantum, it obviously changes the entire game for encryption, right? And, that's another important factor for us when we think about when we're considering, you know, Venafi, you'll need to change those certificates out more rapidly. That'll be a forcing function, if you will, at some point down the road. The time horizon for when it becomes real is still unclear, but it's a significant enough change that we, you know, we spend a lot of time in our research labs looking at this, thinking about, okay, once that happens and you have to rethink encryption, what does that mean for us as defenders? So we're spending quite a bit of time on that. In terms of corp dev... And that's more on the strategy side and on the technology strategy side. In terms of corp dev, it's not like there are companies out there that have really figured out. They're not startups who've said that, "I have the answer in a post-quantum world." We're looking, you know, both on the investment side, because we have a small venture practice as well as the corp dev side. And that's something we're actively, you know, considering pursuing. So that said, still, it's important, it's a meaningful shift. We feel, you know, incrementally better about it on the other side of Venafi, but, you know, we still have to pay attention to the future, what it holds. And maybe as we stick on, on the product front, when we think about the cornerstone or the broader identity, so double-click on PAM, machine identity now, access management, what about IGA? What about the governance side? Yeah. Yeah, and so when you think about the traditional landscape of IAM and the three swim lanes, so obviously, privileged access management, access management, IGA, those disciplines, they were very, very separate when you think about on-prem traditional environments, and we think for the most part, that made sense. I think you start to see earlier some crossover between access management and privileged access management, as we discussed, because what is the definition of privilege? But really, when you move into hybrid cloud, multi-cloud environments, modern infrastructure, those lines start to blur quite a bit, right? And it's difficult. It's difficult to effectively secure identities in cloud and multi-cloud environments if you don't bring capabilities to bear for me. So for us, when you look at our Secure Cloud Access offering, it really combines disciplines, you know, for each. It has a certain level of identity management and governance. It has varying degrees of access from what looks very much like privilege to what may be more of MFA plus, and that's how we protect the, you know, the users in modern cloud environments. But again, if you're looking at traditional IGA, you know, we still have a good, you know, constructive partnership with SailPoint. That's not an area of investigation really for us right now. So that's how we really think about it. As you go more modern, the lines blur. That's just the nature of it. But for the traditional mainstays, we think, you know, companies like SailPoint do a good job there. And I've asked you the same question last week during the management track. Hopefully, I'll answer better this time. Oh, you answered great. You know, 10 days have passed since announcing, you know, Venafi, your largest-ever acquisition. No resting on your laurels for you? Or maybe kind of talk to us about, you know, the first, like, you know, 10 days after, because that has been, again, the biggest one to date that we've seen out of CyberArk. Yeah, no, no resting, for sure. Obviously, you know, we need to get to the closing here, and we're in the integration planning stages, and we're very, very excited about it. But there are other things that we're, you know, we continue to look at and investigate. So that is, you know, that is ongoing. But the first 10 days have been really, really incredible. If you think about our partners and our customers alike, they're excited about the combination, about they want to learn more about what we're doing. They want to, you know, they want to do more with us, with us combined, and we're having to govern those conversations a bit, and particularly on the customer side. But even on the partner front, you know, we had a number of meetings where it came up, whether that's go-to-market partners or technology alliance partners. They'll lean in and say: "Yeah, but I really want to talk about Venafi because there are more things we can do there." And in some cases, we go back and talk to the Venafi team about your partner X or Y, like, "Huh, we haven't really had those conversations with them." So it's opening up net new opportunities. It's not just, you know, one and one is two. It's one and one is, you know, greater, some number greater than that across partners and customers. So we're very excited about it. Final questions from the audience? Let's see, we're beginning to run out of time. All right, with that, Shaul, thank you so much. Erica, thank you so much. Thank you. Good luck. Thanks so much. Thank you. All right. Thank you, everybody, for attending. Have a good day. Thank you.
Loading workspace