Thanks for joining us today. For those of you who don't know me, my name is Madeline. I work with TAL doing cybersecurity research and networking, but you've seen me probably more on the cyber side. I'm so excited today to host CyberArk and, more importantly, to host Clarence, who, if you haven't had the chance to interact with him before, he does all of the strategy for CyberArk. It's been a very busy year for you, for the company, definitely for you in your role, and especially over the last few years as CyberArk's really evolved more from just traditional PAM. You guys have really kind of captured these tailwinds in the identity security market and evolved into so much more. Excited to host you today, and thanks all for attending. Yeah, happy to be here. Thanks for having me. With that, we'll just get right into it. First, just get this question out of the way. I know it's been obviously a tumultuous last couple of months. Just how are you seeing the market right now, especially in identity security and maybe more recent trends in kind of customer appetite as we're exiting first quarter? Absolutely. If I start with the broader macro, for identity security, we're all familiar with the tailwinds. I mean, it's just become so clear that identity is the number one defense factor because it's where all the adversaries are going to attack. That's really what dictates it. In all identity types, so human, the most privileged onto the workforce, et cetera. You're starting to see more and more attacks based on the machine and non-human identity. That's the backdrop. There's a lot of urgency there on the customer side, which ties into more of the macro question, which is, how are customers seeing? We talked about this during Q1 earnings. It's still, it's a serious problem. It's pressing. Even though there's some noise around with tariffs and all that, we talked about it at Q1. It's like demand is still there, still robust, not really seeing anything there. This isn't something that you can really put off. The stakes are too high, really. That's what we're seeing. Again, we're paying close attention to how things evolve. We know that our customers have to take that all into account, but we're well positioned there given what we do. Maybe just starting with kind of core PAM, and then we'll expand out from there. Can you give us your view on the core PAM landscape right now? How is growth in those core products, and where do you see that market evolving over the next few years? Yeah, so when you think about PAM, and that goes back to more of the traditional, so vaulting, rotation, et cetera, even onto the modern use cases. From a solution standpoint, that's where we talk about IT, again, with the core IT, traditional PAM users to cloud operators and engineering, even onto developer. That's this whole continuum of traditional privileged access management controls onto the modern. We think that first and foremost, it remains critically important to secure that type of access. There's still a significant amount of runway there in terms of the number of highly privileged users that are not fully secured, that are not protected by either traditional or modern privileged controls. That remains a very, very vibrant market for us. It's a growth market for us when you look at it in aggregate. As we have talked about, it is roughly half of our subscription ARRs between the IT and the developer solutions that cover this whole continuum from traditional PAM over to modern PAM. It is a very, very important market space for us. Again, there are expand opportunities, there are modernization opportunities, and there are also new land opportunities. There is still greenfield out there, even on some of the larger enterprises. Can you maybe refresh us all too on when you land a traditional customer who's really interested in the traditional PAM, right? That's not just a day one, everyone's on the platform. Can you talk about the tail that you have? Because that's a big driver of your continued growth in the market too, right? The tail in each of your customers to add new PAM users onto your platform. Yeah, that's absolutely right. When you think about the initial land, and even if it's PAM focused now, I will say that now the majority of our new logos land with typically PAM and something else, whether that's endpoint or workforce or something. We're seeing more of that multi-product, multi-solution land. When that happens, they focus on high priority areas. They're focused on specific teams, specific systems. It's rarely everything covered at once. From the time you land, you have this natural ongoing expansion motion for some time period to come, even just in PAM. You go from that to you introduce more modern privileged controls, and you're able to get more and more of the, you call it the cloud side of IT onto the developer side. That's more expansion opportunity. You think about what we have on the workforce side with not just classic SSO and MFA, but it is onto our privileged controls for the workforce. Secure web sessions, you throw endpoint protection into that mix, the browser, et cetera. You keep on going on to machine identity. We just see very, very strong cross-sell opportunities. Really, with our most strategic customers, we have established multi-year roadmaps with them, like how are we going to roll out these various solutions across our organizations. Many times, it is not just solution all at once across the entirety of the organization. You may have to go division by division. They may have acquired other companies, and we have to go into those operations and modernize there as well. There's just many ways we're able to grow both within the core traditional and modern PAM and also cross-selling all of our newer solutions. It's just a very exciting opportunity. You brought up an interesting point, right, of doing endpoint and workforce. I think we heard from Nikesh earlier today that security has really evolved in the last few years where companies aren't necessarily just staying in their lane, but looking to really move out, expand their platforms. For identity specifically, there's been a couple of different themes, and we'll get to why there's no larger identity platform in a minute. Something that's been kind of prevalent is really just-in-time access. Who owns just-in-time access, right? CrowdStrike's coming out with their identity product that they say just-in-time access is going to be run through them. A lot of other vendors are starting to do this as well. Where do you see yourself sitting in that landscape and kind of those competitors who maybe once were on the outskirts of identity security now kind of putting pressure and coming inwards? Yeah, I think on one level, just seeing the interest in identity from non-identity players, it just speaks to the importance of this as an attack and defense vector. I'll put that out there first and foremost. There are market differences in how we approach it as an identity security leader versus some of the others. I mean, we're very much, we start from a preventative controls standpoint, and we're very much deterministic in terms of making sure that the right protections are in place and making sure that we shut down the attacks when they do occur across all the identity types. If you flip over to the other side, what you'll see for a number of these other players, they come in from more of the SOC standpoint. It's more signals and it's more probabilistic. It's just a very different approach. It is just basically taking what you may do in EDR and XDR and just applying more of an identity flavor to it, which is reasonable given the importance of identity. Make no mistake about it, when you are looking at putting real identity security controls in place, that is where we live and these other vendors really do not. It is a very separate type of motion and value prop. Do customers need both? Meaning, will CyberArk sit next to CrowdStrike's just-in-time product as well? Yeah, I think it's a very different thing. Again, when you're thinking about actually applying preventative, deterministic controls, that is where we live, where we're super, super strong. I think if you're looking for other flavors of other things to add into more of a SOC type solution, all that's fine. Oftentimes, it's different users, different buyers, et cetera. I just view it as more of a, it's more relevant for what they're already doing. It's not particularly related to what we do in terms of the controls we provide in terms of the real, I mean, just think about what we do for all identity types. It starts with the discovery and onboarding to protect with the right level of privileged control. That's whatever the actual credential is, securing that. You secure the access to it. You ensure proper authentication, and then you have session management and control. Then you have the lifecycle that goes around all of that, the supports, audit, and all. That is a lot that we are doing, right? You have to have real identity security controls to do that. That is not something you can do with a more probabilistic model that is more focused on the SOC. It is just a very, very different value problem. Got it. Switching and expanding out a little bit, identity security platform, identity security hasn't seen as much platformization as other areas of security. Why is that? What is CyberArk's opportunity here to kind of be that player that comes out on top? Yeah, so first, just start with what we have seen in the market. I mean, I think you've seen our customers out there who have offerings from 70, 80, 100 different discrete cybersecurity vendors. Now you have GenAI and Agentic AI security looming. You need more security. The last thing they want to do is add on another dozen, couple dozen security vendors. There is this overall movement towards vendors that are trusted by the customers. That is why we talk about it. Floris and I talk. It is this consolidation of trust. Trust is based not just on your current portfolio, but it is on the belief your customers have that you will stay out in front of the attackers and the threats, and you will be able to secure them over the long term. You are just seeing that in general. That's the interesting part of consolidation, less about the financial aspects of it, whether that be packaging the vendors may do or whether it's PEs going out and assembling things. That's not the interesting part of consolidation. It's really this consolidation of trust. You flip that over to what we were talking about before with identity really emerging as a primary attack vector by the adversaries and therefore must be a primary defense vector. You have a consolidation of trust that's centered on identity security. That's where we're living. To make this work as effectively as possible for our customers, of course, you deliver it on a platform. You have a unified user experience, unified in that for a specific role, for a specific identity type, they have everything in front of them that they need to be effective. On the back end, you have the appropriate level of shared services across the entirety of your offering so that helps with deployment, with management, with innovation, with scale, et cetera. That is what we really see coming together is those things. We feel like we are very, very well positioned as that all transpires. Maybe before diving into the different pillars of your platform, competition, Microsoft specifically, if they look at their security portfolio, their strength lies in identity security. You have other companies at the top end of the market as well, right? How do you view the competitive landscape? How is it changing? Where do you believe CyberArk's position today? Absolutely. If you start with more of our on the traditional PAM side, we know who the vendors are there. They're all PE backed and kind of still in this more of a fast follower type strategy. We see them in deals. We feel very, very good about how we're able to compete and provide more value and leadership there for our customers. You move more into the workforce space, and that's where we see our innovation and differentiation really being on these advanced security controls that are born from our experience in PAM. SSO, MFA, yes, there are vendors everywhere who do that. When you talk about applying secure web sessions, you talk about incorporating industrial strength, workforce password management, and other innovations that will continue to come down the line. That's really what we're differentiated. We are looking for those very security-focused customers that want to provide high-end security for the entirety of their workforce. That is where we are strong. That is how we differentiate. Yes, it can be crowded in there, but it is not crowded for customers that are really focused on that security value problem. When you go further out onto the machine side, you start with secrets. We have had strong performance there. You combine it now with what we are doing with Venafi, more of the core certificate lifecycle management, but then going into workload, workloads, identity security management, and that all continues to bleed over into AI. In that area, I mean, you have HashiCorp, IBM on the secret side. We were competing very, very well there even before the acquisition. There are just a couple of competitors out there on the Venafi side. It's really you're competing against spreadsheets is the number one competitor there. On the AI side, it's a bit, it's still wide open, it's to be determined, but we feel very good about the collection of personnel, IP, and technology that we have to develop leading solutions in that market as that matures. Maybe on the machine identity side too, such an exciting part of your portfolio, and I know Venafi must be near and dear to you given your role. First off, the market, are we there for market awareness with your customers, or is it still market education? Can you talk a little bit about how you've seen the trend of adoption for machine identity? Of course, I'll start with the end answer. Yes, I mean, there's excitement, there's understanding, and we feel like we're hitting this market at a very, very good time. I want to say historically, it was viewed as more of an operational value prop, whereas you have an outage, you have expired certificates, you have real cost that hit the company, and there's also a security component. I think that's switched over to where that's still true. It becomes even more true when you reduce the timing from the lifecycle from 400 days to 47 days. We're seeing an increased focus on the security importance of that. That's quite frankly why you're seeing those times reduced, because there's a broad recognition that this is a security problem. There's a vast attack surface that exists if you have these certificates that can live for 400 days. We're seeing this convergence of the operational benefits and also the security benefits of providing a solution like this. You go back to what we're talking about in terms of consolidation of trust. This is a conversation that our customers want to have with us. It's difficult to have it for some of these other companies because they're thinking, "Wow, I have so many vendors already, and is this another conversation that I want to have? Do you know them? Do you know who's good?" I don't know, but they trust us. That's why when you have this announcement comes out with the shift to 47 days, our customers are rushing to us and say, "Okay, we need to talk. Let's see what we can do about this. Let's start to think through the roadmap and what that could look like. Who should own machine identity? Should it be PAM, core PAM, or IGA vendors, or are there other types of security vendors that offer machine identity security that are in a better position? I mean, when you talk to customers, what's the right place for them to land in terms of getting that initial machine identity footprint? Yeah, I think that part of this goes back to what we were discussing before in terms of just the consolidation, the platform, identity, all that coming together. Our customers have made it clear they want to have a leading vendor they can go to for all of their identity security needs. Machine identities are super important, and they oftentimes want to think about them in the same way that they think about their human identities, even though the dynamics of how you secure them are quite different. Again, you go through those controls I listed. It's the exact same things you have to do for humans and humans of all types and for machines and machines of all types. The technology you deploy may be different, but it's the same thing. They want somebody who understands the process, the mechanisms extremely well, and who can leverage code processes, best practices across all of that where necessary and appropriate. Most importantly, they actually can solve the problem. To finally answer your question, I mean, our customers made it loud and clear. They want to talk to the leading identity security vendor when it comes to that. It was very difficult to have any kind of a point product conversation. It would get lost. It would fall through the cracks. Maybe talking about AI with machine identity as well. How are you securing AI? Identity is in a really interesting place in the security stack because are you treating AI and especially LLMs and just the different applications you're seeing in enterprises as those human users more? Or how do you think about securing AI from an identity perspective? Yeah, so I mean, AI, it touches everything, and we're still just getting started. The very first thing when we very first started thinking about this is protection from, protection of, protection with. Protection from is, okay, the adversary is typically an early adopter of any new technology. They come out, how do we protect ourselves from these new AI-enhanced attacks? It turns out you basically have phishing, phishing, and all that. It reaches such a high level of execution that it puts all the traditional controls you have in place even more to the test. The really protection from became more of deploy more fully, deploy to highlight. I mean, we had everything you need from a vendor perspective, but working with our customers to make sure you close these gaps given how effective these attacks were. That was that. When you think about protection with, it's very important for us to really incorporate AI into our solutions in a way that meaningfully increases the productivity and effectiveness of the end users and the admins at our customer side. That's how we're thinking about that aspect of it. That's what we're building into our roadmaps. You've heard that with our core announcements and more to go. Now, protection of, you have the classic LLM aspect of it. For us, and when we talk to our customers, it's really much more about how do you protect, how do you ensure that the right people are accessing the LLMs and they're only doing things that we want them to do in terms of. That's really focused our protection of initially. Now when you start to flip it over to Agentic AI, you have these bots, agents that have both machine and human characteristics. This is where we feel very, very well positioned given what we have, given not just the current portfolio, but the portfolio, the technology, and the roadmap that we have with Venafi, what we already have with secrets, and then everything we have in terms of human controls. That is the only way to effectively secure Agentic AI. We are working now to, we have talked about it at our customer event, but we are working now to pull together the solutions that will protect and provide Agentic AI level security. That is a different skill, a different solution, but it will require many of the capabilities we have now. Maybe a similar question to machine identity, but now to AI, right? Do your customers realize that AI is an identity security problem, or are they looking for just companies that are purely focused from starting from that AI lens? Yeah, they definitely realize that AI presents a unique and complicated identity security problem. Now, there are other elements of it. When you think about protecting the models themselves, where there is some different technology that's not necessarily identity-based, when you're literally thinking about locking down the models, that is a little bit different. When you're thinking about AI, particularly the AI agents, our customers fully understand that that is an identity-centered security concern. We're already having those conversations with them about how to protect and what they're worried about in terms of permissions, access, in terms of what happens if agents are corrupted and then turned against. It's like all the things that you'd see now, it's just that they're multiplied in terms of when you think about flipping access or corrupting access associated with an agent versus just a credential or a certificate. It's a much more powerful thing. Maybe moving to talk about the other exciting piece of CyberArk more recently is the acquisition of Zilla, right, and moving more into that IGA space. Can you talk around how you see IGAs being complementary to PAM? What was really the decision for CyberArk to enter this market, especially we just spent 20 minutes talking about core PAM and how important it is and all the growth drivers you have there? Why enter this market and why now with Zilla? Yeah, when you think about the IGA concern, it's really become a central thread for identity-related security and just identity security overall. What I mean by that is, you protect the access and you ensure the right levels of authorization, but you have to close the loop in terms of making sure that identities of all types are provisioned with the right access. It changes dynamically over time depending on the circumstances, situation, join move leave, etc. That's a thread that you really need to close the loop across all of your identity security solutions. It's no longer a management concern. It's now central to security. That's why for us, it was important for us to investigate and understand what was needed by our customers. What I can tell you is that with traditional IGA, this more on-premise, it's just everybody knows it's an expensive endeavor in terms of deploying and maintaining the solutions. It takes a long time to stand up applications. When you're thinking about months and years to stand up a few applications, and now we're in the world of SaaS applications and cloud, customers can't wait for that. They needed something better to reduce their attack surface. Again, it's a security concern. That is why for us, it was very important for us to see how and whether we could approach this in a different way. When we found and we discovered the Zilla team and Deepak and Nitten, we just saw something special there in terms of the people, the capabilities, the approach. There was a differentiated way to really deliver IGA and a modern approach to IGA that was lighter weight, quicker time to value, already leveraging AI to take some of the manual steps out and make it so you could cover more of your estate and reduce the attack surface fairly quickly. We have multiple threads here where there's a kind of a standalone motion of customers need this. Customers need modern IGA solutions all up and down the stack of sizes. We have tremendous interest from our customers there. There are also horizontal capabilities that are relevant everywhere. They're relevant IT, workforce, even machine identity. Now, there may not be the same code. That's something we'll work through, but we have a strong team and talent, technology, capabilities, and know-how that can really strengthen the IGA-related aspects of machine identity as well. That was a lot, but we're very, very excited about it. It was a very, very key element of our overall identity security story and kind of an open problem for many of our customers. When you think about where Zilla sits, I mean, is Zilla replacing other IGA vendors? Is Zilla complementary to other IGA vendors? What is the opportunity there? Yeah, when you think about this, because it takes so long to deploy a traditional IGA, what you're seeing is this is covering what the teams haven't been able to get to yet. This is a way to more rapidly, more expeditiously provide this level of governance to your longer-tailed applications, SaaS, and even select on-prem applications, quite frankly. That's really what we see now, whether other solutions are deployed. Sometimes yes, sometimes no, but there's a tremendously large greenfield opportunity here in this market. Even when there are incumbent solutions, there's plenty of space for this to work alongside. Alongside doesn't even necessarily mean you're right beside. It could mean different departments, different users, different applications. There's just a tremendous amount of upside and opportunity here. Maybe in the last couple of minutes too, I know we didn't go through your whole portfolio, but if you could kind of touch on to some of your other products outside machine, outside IGA, and outside of core PAM, where are the opportunities there? And then for anyone who does have a question, we'll save one or two minutes as well for that. One thing that's extremely important that I just want to reiterate is that if you go back to this PAM to modern PAM, that's where a lot of the innovation is happening. That's with this movement from the IT solution with the more classic PAM type users, the main admins and others, to the cloud engineers, cloud ops, over to the developer. That's where we just see a tremendous amount of opportunity for us to deliver real robust, modern, privileged controls to those new users and new use cases. As we have secure cloud access, secure infrastructure access, it's like all of this just-in-time, highly secured access to cloud consoles and infrastructure. That's very, very important, especially when you think about getting into the longer tail of uncovered, highly privileged identity. That's something we're very excited about and where we're spending a lot of our time and energy continuing to invest and modernize there. That's the one thing I'd want to make sure that we had. Again, even on the workforce side, just adding those layers of security control beyond the more highly competitive classic SSO and MFA, but adding the additional layers of security controls, that's very, very important because you still see that that's the most significant area of attack surface on the human side is this long tail of general workforce where the adversaries know how to elevate the access, move laterally, and then get to the highly privileged users that they really want. Maybe I'll see if anyone has a question. Otherwise, I'll ask one wrap-up. Anyone? Yeah, as I was saying before, we really see that as more of something that complements what they're already doing, more endpoint and SOC-based. If nothing else, it brings more attention to the importance of securing identities. It's just not at all related to what we do in terms of the proactive nature of our controls and the very deterministic nature of our controls. It's a different thing that I think is just more viewed as much more of a complement to EDR, XDR, and different SOC solutions than anything directly mimicking what we do at all on the classic identity security control side. Fact we don't see many new competitors in the privileged access market. Does it mean that it's difficult to do, or does it mean that it's not attractive enough to enter the market? Yeah, on the classic side of it, I think that it is difficult to do. What you see are you see some startups coming more on the modern controls, where they'll try to just very specific slices of it. You see there's plenty of companies shown up there. It's just a difficult entry point, especially when you go back to never mind wanting a vendor to come in and solve your highly privileged access problem. You want one vendor to come in and solve the vast majority of your holistic identity security problem. They're there. It's just difficult to gain traction given the dynamics in the market and given is that really where a customer wants to add another couple of vendors to their roster is tricky for them. I guess in the last couple of seconds here, one question for you is from your seat, Clarence, do you think there's anything that investors are underappreciating about your story right now or anything that you'd like to end on from that perspective? I will not go into underappreciating. Just one thing I just want to make sure I highlight is that across the spectrum of what we are doing, there continues to be upside opportunity. There is still, even though there is a relatively higher penetration of the more privileged identities, there are still so many that are not protected. We have the upside opportunity there. As we go further and further to the right, there is an extraordinarily long tail of unsecured machine identities of the types we know about before you even get into the future with Agentic AI. There is just a massive, massive opportunity for us. The way we view it is it is a massive, there is a lot of ground we have to cover to effectively secure our customers. We are excited by that. From an investor standpoint, a massive, massive upside opportunity. Lots of open space in terms of both going deeper, further adoption, and going broader with the adoption of our newer solutions. Perfect. Great. Thank you all. Thank you, Clarence. Thank you so much.
Loading workspace