Come up from, come down from Boston yesterday? Yeah, actually it was Monday night. Today's a, today's Wednesday. Oh, that's right, you can just leave open too. Yeah, I'm based in, I live in Boston, in Charlestown. Oh, nice. Yeah. Yeah, not in Weston. Okay, close to the office. Okay, welcome. I'm Jonathan Ruykhaver. I cover the cybersecurity space at Cantor. Pleased to have CyberArk from the company, the Chief Strategy Officer and Head of Corp Dev, Clarence Hinton. I'll get started. If anybody has a question, don't hesitate to raise your hand. I guess to start off, Clarence, from a high level, just talk about identity and the importance of identity. You know, we see all these social engineering- type of compromises that evade a lot of the traditional perimeter in, you know, email, whatever the tool is that is built to potentially stop that. Can't. It just seems like identity is the next perimeter in terms of where you want to build your security to stop these threats and stop ultimately data exfiltration. Just talk about the trends as you see them in 2024 and continuing to 2025. Yeah, absolutely. First, pleasure to be here. Am I good? Am I coming through? Get. Do you guys hear me okay? Yeah, I think that's better. Awesome. Awesome. You said it exactly right. In terms of the security perimeter, when you think about the migration of workloads and applications outside of the traditional firewall, which is many years in the making, you think about it still living in, you know, a hybrid Workforce where you do not even have all the people behind the firewall, and then you have lots of, you know, remote work with partners and others. You know, the concept, the traditional concept of network security in a hardened perimeter just does not make any sense, or it is just much less efficient and effective. I will say it that way. Attackers have seen this. Attackers are no longer spending a great deal of time trying to pierce the network firewall. Rather, they're finding individuals, they're finding identities, they're finding credentials and, and privileges, and using that to, to execute their, their attacks. That's, that's what we've seen. That, that's what's really driven, identity to the, to the forefront. The additional context is, as you've seen, you know, companies are just in different forms and, and stages of, of digital transformation. They have workloads and applications different places. They're seeing the attack surface really dramatically increase. It's not like they have a bunch more people. There, there's a, a critical shortage still of security, professionals out there. You, you can't go person for person, body for body. Already, it's, it's fairly common for an enterprise to have tools from 100 different discreet, security vendors. You do not, as a customer, you would not want to add another couple of tools to that mix or a couple of company systems, even if you wanted to. It is like, do you have the manpower to evaluate, onboard, etc.? That is really coming back to the combination of a consolidation of trust that the customers want to go to a smaller set of vendors that they really know and trust to address a larger set of cybersecurity problems at a very high level. Yep. You think about identity and how it's being served up and delivered. It's more increasingly becoming a meaningful platform. Yeah, it's interesting. I mean, I've known Udi for 15 years. And, I remember when the company went public and it seemed somewhat of a niche technology, large enterprise focus. That's where you saw the adoption. But, you know, the whole thesis as I see it is privilege is the key to an Identity platform. And we can talk about that more in detail. I think, you know, you guys see that also in terms of how you go to market now. It just seems like one of the questions I get is, well, it's been such a good story. They've executed so well. You know, isn't the market getting saturated? And it clearly isn't. I mean, I think you landed last quarter, 80% of new logos were PAM. That's right. That's right. We'll get into that. Before we do, let's talk about machine identity because I think that's the next frontier. Talk about the acquisition of Venafi and what that opportunity means strategically for the company for the next several years. Yeah. So, you know, there are so many different, different angles here. If you just, just look at a high level, we have thrown out the number that others have validated. There are at least, you know, 45 times the number of machine identities as there are human identities in a given enterprise. Just, and that is of all types. You are talking about physical and virtual endpoints and devices. You are talking about the applications, application infrastructure, Kubernetes containers, etc., the workloads running across. You understand how the number can get, you know, very, very large. You start to add on things like AI agents, etc. Yeah. There is really no ceiling to how high that number can go. We are in the very, very early innings of really getting to the point where customers are addressing the security problem associated with machine identities. As what drives that, again, it comes down to where the attackers are. The attackers are still very, very focused on humans. Increasingly, we are seeing breaches that feature specific elements of machine identity. The effective attack surface is much, much larger. I think we are in very, very early stages there. With Venafi in particular, you look at what we already have with secrets management, which is focused on application communication and pulling the secrets out of clear text there. When you move over to more of the device and workload side, obviously certificate lifecycle management is front and center there, but also workload security. Those are things that Venafi has. They executed at a high level there, but also they have the capabilities, vision, and roadmap to go beyond that and go to the longer tail of machine identity security. That is where we really saw the power in it. Combine secrets with their current capabilities with their vision and roadmap. It is just a lot of upside there. Yeah, it's interesting because Jeff Hudson, the CEO of Venafi, he would do these non-deal roadshows as he sells side invoices every year. The story never really seemed to change. The growth was always okay, but they never seemed to hit that inflection point where it could really go public. When I saw the deal, I was like, you know, I don't know. I think the question I want to understand, or the question I wanna ask to understand a little bit better about the market drivers is, what's changing the threat environment that really drives, you know, an acceleration in growth in Venafi? Because I think, you know, double-digit ARR growth, [Sri], correct me if I'm wrong. I think that's what it's looked like. The expectation is that goes into the mid-teens and then potentially higher by the end of the year. Yeah. If you go back to the threat landscape, the environment, rewind some number of years, 5+ years, and you think about the core of certificate lifecycle management, that was very much viewed as operational. Right? Yeah. If a certificate expires, you have an outage, that costs you real money. That was really the view. It wasn't, you know, and there was a security angle that was underappreciated because the attackers really hadn't started focusing there yet. Yeah. In our conversations going a couple years back with customers, with CISOs, they said, yes, this is a security concern for me. It's a security concern because attackers started to take note, and you realize the actual attack surface is massive. That is what's really changed. It's this combination of the attackers taking note and therefore CISOs realizing they have to address it and then understanding how massive the problem actually is. We're definitely seeing a swing there. When you go back to the solid performance of Venafi for many, many years, but not eye-popping, it was very much in that operational use case. It wasn't the security use case. There's the opportunity, the, the effectively the, the TAM really starts to expand when it becomes a security, a security concern, and you're actually having to address the long tail of machine identities that are out there and secure them. Yeah. Okay. I get it. So can you, can you talk about AI and how AI amplifies the problem of securing machine identities? What, what does that look like and what can that mean also for the market opportunity? Yeah. I mean, the construct we used, especially when we started to see the, you know, the explosion of GenAI is, you have protection, you know, from AI-focused attacks, protection with AI, and then protection of AI. The protection from, you know, unfortunately, the adversaries were, of course, the early adopters of GenAI technology. What that really manifested itself in was you have phishing attacks that are very, very, very good. Some of the classic tells and misspellings and all, they just started to go away. It just made them highly effective. You're starting to see GenAI be leveraged to build out better malware. Again, it's used to execute ransomware attacks. There are many things like that. The first phase is you just see everything that had been done before. It's amplified because it's better, it's faster, it changes more dynamically. Yeah. It goes back to you still need everything that we provide. You have to have, it's even more critical that as a customer, you have that coverage. That was the first. For us, in terms of leveraging AI to actually defend against those attacks and others, it's really, you know, leveraging the time and the resource and the capabilities of your frontline security professionals if you, you know, from a customer's perspective. We're building more and more of those higher order functions and capabilities into our product. You know, we'll talk more about that next month at our customer event. That's more of the protection, you know, protection with or security with, and again, with core AI and other things we'll talk about. I think the last part, when you think about, you know, protection of or security of, we have the models themselves, not something we've directly addressed so far, but there's definitely a security problem there in terms of those models, you know, and an adversary going in, corrupting the models to their own benefit, pointing users the wrong way. You have that. You have the data ingress and egress, you know, concerns, particularly in prompt sessions. You can have sensitive data from a company perspective going in and sensitive data coming back out, leaving you, you know, that leaves you exposed to an external attacker going and fish it out. Of course, you have AI agents themselves that, and we can talk about this, you know, later now, but that have the, they can scale like cloud and like machine, but you have to secure them also, also like humans. That is something we're obviously we've talked a lot about at our investor day, and you'll hear more about next month. Are those opportunities at hand today? And is the company positioned to capitalize on them from a product standpoint, or is this something you're building to be able to address over the next, you know, one to two years? Yeah. So protection from, and that's what we do. That's what we've always done. So that's there here and now. You know, protection with, we started, we with the core and what we're doing, we're already building those capabilities into our platform, our individual offering. So that's in flight. And on the protection of, starting with the agentic AI, that's, you know, something we'll talk more about next month. So that's something that when we talked about our guidance, our TAM, all this, it was not included. Okay. Regarding the integration of Venafi, both in terms of the infrastructure, the operations, and then the go-to-market, can you just, you know, level set where the company is today? And then, you know, I'll, I'll, I've got a question just related to least privilege, but I'll ask that after you address this first question. Sure. So first and foremost is, when you think about, you know, how we're aligning strategically, operationally, technologically, we want to combine the capabilities of our secrets management. Okay. Offering that we had. That includes the actual product itself and the specialists we have selling that with everything that Venafi brings to the table. With those two assets, we have a second to none machine identity security offering, right, that covers the secrets. It covers certificates, tokens, etc. and it's really, really unmatched in terms of what's in the market. That's first and foremost. Now we can, we're combining the specialists from, you know, from each to provide leverage to our entire Salesforce. Now we're able to generate upside, and hit, you know, the plans and so and so forth for everything just by building these cap, providing the channel and the access that was entirely unavailable when Venafi was under private equity ownership. We talked about that. There's. Yeah. Really underinvested in terms of go-to-market feat and also in terms of air cover on the marketing side. That's super important. You know, making sure we have the right integration of the technologies going forward as well. That's the approach. Is there, so the notion of least privilege, is there an opportunity to embed privilege around machine identities, or is that not really what the risk is so it's not needed? It is absolutely needed. I mean, entitlements, you know, for me, when I think about least privilege, it is really right-sizing, shrinking the entitlements, which is also thereby shrinking the attack surface. Okay. That's viable everywhere. It's important. Yeah. Absolutely everywhere. In addition to just saying, here's your, here's your certificate as machine, go from do, do whatever you want, is, you know, being very prescriptive about what access that machine, that application, that workload actually has and for what period of time. Yeah. That's a very, very important aspect of securing machine identities for sure. It's much more than just access. Okay. Yeah. I just asked that because getting back to the notion of a platform around identity and being able to share the different technologies across that platform in terms of how you message to the customer is probably important. Absolutely. Yeah. Absolutely. And just quickly on the go-to-market for Venafi and secrets also, it seems like it's often the developer as opposed to who you traditionally target. Is there any change in the sales motion that's required as a result? Yeah. The very interesting and positive thing about Venafi is that, you know, we found even during our diligence that it's all in the CISO organization. That is typically where this lives, which is exactly where we target and sell anyway. Oftentimes we find it's literally the same buyer in an organization. That makes it very efficient for us and very effective, as we roll this out to our broader AE Salesforce. It's not like we're going and finding and learning an entirely new, you know, dialect of security professional. It's someone who's there oftentimes, someone we're already talking to. That makes it much easier for us to go and execute on the near-term cross opportunities. Yeah. Actually, on the mid to long-term land and expand as well. Yeah. Okay. Getting back to just, you know, CyberArk is an Identity platform. I think you, you know, you embarked, you did not really market around this, this, this broader capability until more recently. When you look at what you did on endpoint, you know, you expanded into cloud and secrets. You know, it seems like it has been a work in progress for a while, but, you know, talk about that vision, you know, what it currently consists of in terms of the products and, you know, are there additional projects? Bring up IGA because it seems like IGA really rounds out that, that messaging. Absolutely. I think, you know, it's really helpful to, you know, to speak to that in the context of our solutions framework. When you think about the different types of identities that we're securing, you start with IT. That's where traditionally, you know, the traditional PAM user lived. This is a broader set than that, broader than even the domain and other and database admins. That's the first thing we really think about in terms of how do you provide the, how do, how you secure those identities. I'll talk about the capabilities in a minute. You move over to developer. When developer, you think about this as, you know, really cloud access being the most important thing. Things like Secure Cloud Access, secure infrastructure access. That's really what we focus on with the developer persona. Then you have the broader Workforce. That is everybody who's there and may not have the, you know, may not need or utilize elevated privileges. You move over to the, you know, to the machine side and you have devices, workloads, and then AI. Now for each of those, and you alluded to this earlier, there's a certain set of security capabilities that we deliver with our platform, even if it's not the exact same code for each, but we have to provide these capabilities. It starts with discovery, and that's different techniques for discovering human identities versus machine identities. Like for example, machines aren't tethered to Active Directory, so there's a different system you go through. There's onboarding using any metadata you have during the discovery process so that you can protect them with the appropriate privilege controls. And those controls are credential management, could be passwords, servers, whatever it may be, entitlements management, which is where, again, you know, Zilla comes in, comes into play. It's authentication for sure. Yeah. Session monitoring and control. Those are the core privilege controls. All of that has to be governed by, you know, automated lifecycle management for each identity type. You can think about it as a grid where you have those, you know, six personas and three human, three machine against each of those capabilities. You know, there are many, many places where we're bright green, but there are places where we need to, you know, continue to improve and evolve. Absolutely everywhere we can, we leverage, you know, the capabilities, the knowledge, the code where possible, for each of those horizontal functions across each of the identity types. Yeah. It seems like a lot, you know, from a sales rep perspective, there are so many use cases and so many opportunities. And what I look at, and I just think core PAM, you know, machine is exciting, but core PAM is still an underpenetrated market. And then just when you look at identity access management within the Workforce, so what is it? It's single sign-on, it's two-factor authentication, and then you have these integrations with Active Directory. It's not really security. And I think privilege is really the foundational layer to really building out and delivering a strong, you know, Workforce Identity pillar. So just talk to that because I think you have a strategy where you're able to use elements of your privilege. You go in with a tool, it could be a Microsoft or an Okta customer, and you prove out, you know, the better security outcomes, and then that leads to an opportunity potentially convert that, you know, that whole customer to a Workforce opportunity over time. How does that play in that? First, you said extremely well. Thank you for that. If we start with the upside opportunity that still exists in privileged access management, I mean, there are a couple of things there. First, as we said, as you alluded to, as things continue to evolve and modernize, more and more and more humans are effectively privileged. Where you go far enough back, you only really cared about the domain admins and the database admins. Yeah. Now in the entirety of IT is highly privileged, and then it starts to spill out. I mean, developers, extremely powerful. Yeah. In term, you know, pre-prod and prod access in many cases. Absolutely there's still a very, very long runway in terms of the core privilege use case. You said extremely well, those things, SSO and MFA, I mean, they're, you know, MFA is somewhat a security control. SSO, not as much. It's a security problem when you think about the long-tail of the Workforce because even if a typical worker doesn't realize that they have privilege and elevated access, attackers know. Attackers go ahead and that's why for us, the approach on the Workforce side is to add the additional layers of security that apply our privilege controls, that methodology. Privilege slash slash into control. Absolutely. It's not necessarily the exact same code because as a regular user, it won't be natural to be vaulted and rotated, for example. But still we have. Yeah. Secure Web Sessions that is a form of session management control. We have secure browsing, which as just one example acts as another layer on top of MFA because, because of this browsing, you can't have, you know, you can't have attackers go in and take a cookie that's been authenticated by MFA and reuse it, which is one way to circumvent it. We have our endpoint privilege management solution. We have Workforce Password Management. You do have this kind of entry level of SSO and MFA, this, you know, commoditizing, but we have all these additional layers that we apply. That is how we're addressing the Workforce. We are both, you know, landing on top of and surrounding existing deployments, and we are also in cases completely replacing what's already there. We are flexible. We can do whatever. It just depends on the customer need. Yeah. We, you know, some of your competitors have had issues, compromises because of subcontractor access. And I think you've already targeted that use case. Absolutely. You could see how that could extend to the executive suite. Yes. You know, individuals that, you know, have access to certain information, i-i systems that, you wanna lock down more effectively. I don't know. It just seems like there's still a big, big opportunity for. No, there isn't. This is something you mentioned, but the broader identity access management outside of PAM, it was never about, it wasn't originally about security, but then it became about security for that exact reason. You have to take a different approach, and that's what we've done. You know, when you look at the competitive environment around privilege, there are some legacy companies, BeyondTrust, who actually had it compromised that may have benefited you. In terms of some of the bigger companies like Microsoft and the other public company in the IAM space, I mean, even when you look at what SailPoint's doing and potentially Ping with ForgeRock, talk about privilege as a technology and the challenges of bringing a competitive product to market because it seems like vendors have tried and they really haven't succeeded. What is it? What is the challenge? First, when you go back to the essence of CyberArk, going back to Udi, when it was founded, I mean, it's always a security-first company and security-first approach, before that became what was needed in the industry. That has never changed. That's only amplified. You know, there's a model we have internally, think like an attacker. That's what informs our product roadmaps. It's what's informed in many cases our M&A approach, like, where are the attackers going next? What are they looking for? How can we continue to provide security for our customers? That's where a lot of the innovation is as well. I mean, we're heavily focused on secure. I think for, if you think about how others approach it, even others that are, you know, you think about more direct competitors in PAM, it's more of, okay, we have to check the box on these security capabilities. Okay, now, now we do whatever other stuff we're going to do. If you think about other classic Identity players, again, there's, whether it be, whether it be more of the automation, the front end, the backend kind of audit use case is like, that's the core. Again, it's like, okay, let's try to build in some security controls, whereas it's not the first thing. For us, it's the first thing, and you have to get in the head of the attackers, and you have to innovate with that in mind, which, really, really no one else among those you've mentioned is really committed to and has really executed on. Yeah. Yeah. Okay. Good point. I know you touched on Zilla, but talk about, you know, it's a modern IGA solution. I think you've described it that way. What is the difference then to some of the more legacy tools around governance that other public companies sell? And then just touch on the sales strategy. I'm curious, you know, there's gotta be a huge cross-sell opportunity, but that land in expand motion as well. Yeah. If you think about IGA, at its core, it's basically determining who has access to what, what systems and applications and ideally what they can do within those systems and applications. The bulk of the traditional market is large on-prem applications, and deep integrations to determine who has access to what, what they can do. You wrap around that just the ability to say that I'm compliant, to pass audits, et cetera, proving that you have this system in place. That's traditional. Now the concern with that is, you know, just given the nature of the problem, given the way that systems are architected, it is very, very time-consuming and expensive to even deploy. There's some, you pick your multiple anywhere from $4-$6 of services for every dollar of license to implement the systems. Easily, you know, takes six to nine months to get the first, you know, critical mass of applications online and covered. For many, you know, we hear things like there's 50%, 50% completed at some unacceptably long, long time. It's a challenging problem. You think about that and then you think about how the effective infrastructure is expanding, given, you know, at the top of this, what we covered with SaaS applications, with cloud platforms, with the uses of GenAI. When you take that and you think, you need to apply, you need to govern those as well, you can't do that. I mean, you can't throw that expense. Not only you can't, but you don't necessarily have to because when you have more modern systems, you can take a more modern approach. When you have designed-for-purpose solutions like Zilla has, you start from a different place, still with the mindset of getting to rapid time to value. Instead of it taking, you know, six, nine, twelve months to get up and running, you take, you know, a couple of weeks to get the first applications up and running, if not, if not sooner. That, that's really the opportunity. It is a SaaS-delivered solution. You mentioned how a lot of legacy products are built for on-premise. All those natural benefits you see, ease of use, lower cost of deployment. In terms of the go-to-market, is it initially, I would assume, going to be targeted at the install base? I think you've got 8,500 customers to go after. Yeah. That's very fair. We think about it really in terms of two different customer situations. One is a customer that's, you know, think about it, larger, more traditional customer, some stage of digital transformation. They may have a legacy deployment of IGA, but still they have this issue of, you know, I'm modernizing, so I have SaaS, I have cloud, I have GenAI. I need to govern that as well. Typically you look for a different solution there. We see an opportunity there. Of course, a number of customers fitting that profile in our existing install base, very ripe opportunity. You have more digital native, born-in-the-cloud companies that they don't have any, they don't have a traditional IGA solution because they don't have those assets. That is a net new for us where we can, we can go in the land and be aggressive. And that, there is some of that in our install base, but there, you know, there is new logo opportunity there as well. Right. Okay. Let me see if any question from the audience. We're good. Maybe, maybe just touch on the federal exposure, in DOGE, you know, is that a risk in terms of personnel that you're dealing directly with related to the procurement cycle? If bodies are no longer there that were handling that responsibility? You know, it's kind of a mixed message. You know, a lot of companies in security are saying that the contract vehicles are intact. There is some risk in, you know, that maybe the funding gets pushed out, but ultimately those deals are expected to close. Maybe just touch on what you're seeing. Yeah. First, obviously something we're watching closely. On the contract side, that's similar to what we're seeing as well. Again, watching it closely. For context, it's important to note that our global, you know, Fed business is roughly 10% of the entirety of it. Within the U.S., Fed is less than half of that. The exposure is much more limited than it is for others. Not seeing anything in terms of the dynamics, you know, some of that's given the contract structure you talked about, but also the overall exposure for us is fairly contained. Yeah. It seems like the federal, the calls we do, one federal reseller in particular, he continues to highlight, you know, growing pipeline with CyberArk and no deal pushed out at this point. Cross our fingers. Right. The other thing I just wanted to touch on, oh, go ahead. Are you finding you have enough talent to meet the needs of your growth? Yeah. I don't know if you could hear in the room, but the question is, do we have enough talent to meet the needs of our growth? You know, we've continued to grow our headcount. Excellent question. We've continued to grow our headcount, you know, effectively in conjunction with our overall growth, largely organically, but also inorganically. We're bringing in very, very talented individuals from Venafi and then also from Zilla. You know, we feel like we're in a good place. We are cognizant of the fact that there, as I mentioned, is a global, you know, cybersecurity professional shortage, but we continue to be a landing spot of choice for many of those professionals. We feel good about that. We will continue to be smart about how we grow, how we scale talent, and look to not necessarily grow, as clear in our guidance, not grow that linearly with the top line, being more efficient and effective. So far, so good. We've been able to add what we've needed. I think one of the final questions I have is just, we, we've seen the success of this platform strategy in terms of large deals. I think the company has commented that they're seeing a greater frequency of deals closing with a broader number of products. Can you just speak to that from a go-to-market perspective? It's, it's, you have so many use cases you can address. Are companies looking to solve a specific problem with a specific tool that was how security operated historically? Or are you hearing from C-level executives that they're, you know, truly looking at a more cohesive, you know, product portfolio that works together? I think that's one of the big changes in the industry I've observed over the last 10 years. I’d just love to hear what you're seeing. No, absolutely. In terms of what the CISOs want, need, et cetera, I mean, it's kind of this both in terms of their specific needs, but there's this holistic vision and approach. Where we're really gaining traction is with our AEs, our customer-facing, you know, sales resources, being able to deliver the whole vision of what we can do. You go persona by persona, go through all the capabilities and say, "We're here for you." Then listen to the customer problem, whether it's a focus on cybersecurity risk reduction, response to an audit, specific to digital or operational transformation, or even just a straight automation and operational efficiency type of approach. You take that and then you figure out the landing spot. Even if it is a very specific landing spot, we tend, we are helping our win rate, our win rates by giving our customers the comfort that we have much more to offer. You are seeing, you know, quick, you know, quick follow-ups with expansions. Having said that, we are also seeing, you know, many more instances of customers landing with, and even new, new logos landing with multiple different solutions. We are seeing it, we are seeing it both ways. Even if we land with just a, a more of a, a point type offering or a point problem, we have this opportunity to expand and our customers expect that. It gives, it gives them great, great comfort that we are able to do that. That goes back to the consolidation of trust. It's like, would you rather, they'd rather work with CyberArk, solve this problem, and know they can solve a much wider berth than go in and have to rifle shot and get a dozen different vendors to solve all these different problems. We can solve at a very high level. Yeah. Yeah. That rifle shot approach isn't really working. All right. I think we are out of our time. Clarence, thank you very much. Yeah. Thank you. Look forward to seeing you again soon.
Loading workspace