Good morning, everyone. Welcome to the Citizens Technology Conference. Really happy to have you all here. I can't think of a better way to kind of start my conference doing one of the domains that I love in security, which is identity, and on top of that, I can't pick a better identity company to start my day with as well, and so excited to have CyberArk Software today with us for the first presentation of the day, and CFO Erica Smith, welcome. Thank you very much. It's great to be here, Trevor. We'll kick off with some questions, and then I think we'll have plenty of time then to have the audience chime in as well, if that works. That's perfect. So I want to get into product announcements and different things that you've been talking about at both the Investor Day, earnings, the recent earnings, et cetera. But I want to kind of step back and maybe talk about you for a minute. Newly appointed as CFO, first few months on the job, what kind of, you obviously are a CyberArk veteran, so you're not necessarily new to the company or the story. But what new insights or surprises, maybe even, have you seen kind of in the first few months of your tenure and just kind of given the new dynamics, new role? Yeah, it's very exciting to take on the new role. And I think the great thing about this transition is very similar to the way we handle most transitions within CyberArk. It has been very deliberate and programmatic from an execution perspective. So Matt, Josh, and to some extent, Udi, have been great about easing me into the role over the last few years from an expansion of my responsibilities perspective. I would say that the biggest insights that I have taken away is, as we have gone through and have had some of these conversations in the last couple of days, the pace of our business and the execution has been remarkable. But also the fact that we've done the multiple acquisitions this past year with going through the diligence process with Venafi and then most recently Zilla, that certainly has been something that in my old role I had a lot of exposure to, but I wasn't as integrated into the formal diligence process and negotiation process. So that's been a really exciting expansion of my responsibilities. And also from a business perspective, it has been interesting to walk through that process around how we integrate those companies deeper into CyberArk and then be able to make sure that we turn the integration into an execution machine, which has been a definitely interesting part and expansion of my role and responsibility now that I've become CFO. Cool. Great. Well, I want to talk about Venafi and Zilla, but I want to try to make this have a decent flow of stuff and not keep you too much kind of moving around. So at the Investor Day, you talked a lot about kind of the whole team talked a lot about the opportunities around AI and specifically agentic AI. And you have Impact, your user conference, coming up. And I know you're saving some of the kind of larger announcements for your customers, which makes sense. But can you just give us maybe, if not a spoiler or a preview, just kind of how you guys are thinking about that opportunity generally, what the products kind of might look like, how they might integrate in with what you're already doing, just a flavor of kind of what might come at Impact? Yeah. So from our perspective, when we think about agentic AI and the fact that many of these agents are going to act a lot like humans and their ability to be able to perform tasks, but also be autonomous and also be replicated. And so when you think about that exponential expansion, we also believe that they will need to be managed much more broadly. It's not just about something like an IGA solution or a point product from a security point of view. Or even when you think about our acquisition of Venafi and the expansion that we have, when you think about our Secrets Management business, it's not about one piece of our product portfolio that we think will actually address the overall agentic AI problem or challenge that our customers are facing. We actually think it is going to be the broader platform for us to be able to go in and take the entire lifecycle of that agent, but also secure that agent with the right level of controls, and then be able to provide visibility back into the organization so they can actually see what's happening within their environment. And that's something very unique to CyberArk because we have the pieces of the overall puzzle from a business perspective and from a platform point of view. And so there'll be more to come when we get into our Impact event. But we are very excited about the opportunity. It's not something that we've integrated into our expectations for this year from a business perspective. And even when you think about our long-term targets that we outlined just last week when we were together at the Investor Day, it's not something that we're assuming has a meaningful impact on our business. But we do think that there is a tremendous opportunity, particularly given the fact that, again, these agents are going to look and feel a lot like human beings. And so you're going to need those various pieces of the puzzle and of the platform to be able to secure those identities. Awesome. Sounds like, OK, more to come. Got it. Yes, more to come. We will stay tuned. Let's talk about Venafi and Zilla. I guess maybe on the Venafi side, since that one's more, well, not more recent, but has had a bit of a longer kind of time kind of with you guys. How much, from a technical integration perspective, which you talked about a little bit, but how much heavy lifting, if any, really, is left there? And then the follow-on to that is how, once you're sort of done, I know you guys have already hit the road running with go-to-market for there. But does that help incrementally kind of increase once that's all fully baked in, if you will? Does that help kind of the process? Yeah. I think the great thing about the Venafi acquisition, as you know. We closed Venafi on October 1, and so really the first quarter, a lot of the time was spent on solidifying those integration plans and ensuring that we were ready to hit the ground running when we got into January. The technology integrations were already beginning to be worked on right out of the gate, and so there's a number of very rich, robust technology integrations that are already in place between the traditional TLS Protect, which is where Venafi makes the majority of their revenue from, and our secrets management business, so we were already able to address those use cases out of the gate. Now, the second phase of our integration process from a technological perspective will be to make sure that that user experience and that the customer is able to benefit from those in a very seamless way. And some of that will be UI, some of that will be deeper technology integrations back on the back end. But none of that should really be a gating factor from the expansion of Venafi from a cross-sell perspective. What we're really going to be focused on and what we've been spending a lot of our time on is on the go-to-market machine and that go-to-market engine. And the great thing is that when you think about the technology development that has to happen in that back end, it will very much be taking place at the same time as those reps are ramping and the pipeline is building. So in any enterprise software, it's six to nine months sales cycles, particularly in our business. And so when we closed in October, we really were able to enable those reps from a direct rep perspective in Q1 when we did our kickoff. And then now they're building that pipeline. And so when that technology integrations and all of that user experience, the benefits that our customers will get, that should be happening in parallel with that enablement that our customers and also the partners, which are going to play a key part of this for us as we move forward. Got it. OK, so it sounds like kind of things moving multiple tracks together, ideal timing kind of when it's all coming together. Absolutely. And I would say just to add on that, when you think about that partner integration perspective, that is really one of those things that is also ramping now. Our reps have been ramped, but those partners are something that we're spending a lot of time focused on, making sure that they have that technical enablement to be able to hit the ground running as the pipeline continues to build and be able to implement and integrate Venafi broader into their identity security strategies as they look ahead. Perfect. Let's switch to Zilla, a little different flavor, not quite as well established of a company. Certainly, it's just smaller, but exciting because it's allowing you guys to really, I think, put a flagpole down in IGA. Yep. Can you just give us a sense of, I think it was 120+-ish customers that what they came up with? Good memory. 125. So can you just give us a broad kind of view? Are they big organizations, small, vertical kind of orientation? Just give us a sense of kind of what's there now and then maybe where that goes kind of in the near term. Yeah. So I think one of the really appealing things about Zilla for us was the fact that they did have some great momentum in the market. So they had those 125 customers. They also had signed 50 new logos last year alone. And they only had less than a handful of reps that were focused on that sales motion for them. And so when we were able to dig in from a diligence perspective and look at them and their customer base, what we saw was that they were that 125 was really well diversified. There were some large organizations. There were small and medium-sized organizations. They were across verticals. But I would say the common thread, because they're solving the modern use cases, is that they were technologically forward organizations. So even in the financial services firms that Zilla has as customers, you tend to see that they are the organizations that lean into the cloud a bit more than some of your traditional larger enterprises in financial services or insurance that we had seen. But the diversification was really powerful because we think they can serve where our sweet spot is in the large enterprise, but they also do reach lower into some of those mid-market customers where we think we can have a really nice landing spot potentially, and very similar to what you've seen us do with kind of access or some of our endpoint privilege management solutions. So we think that'll be a nice compelling market for us as well. Awesome. That's super helpful. From the way you describe it, it kind of makes some of Matt's comments around just the strategy for IGA and where you displace, where you don't, where you might kind of go side by side kind of makes a lot of sense just kind of giving that additional detail. So thank you for that. Excuse me. Can we do a little bit of PAM now, if that's OK? Of course. Going back to the core, you laid out kind of a new persona-based subscription ARR look where you've got the kind of machine and workforce bucket, and then you've got the IT and developers, which is great. Throwing me off my game a little bit because I'm used to seeing it around kind of products. And we've talked about that, I think, on this stage. Actually, each year, I've kind of been using it as my baseline to try to see how things are moving. But when we did some math just based around where you think things will be bucketized versus where they were and when you've talked about subscription contribution before, it seems like the PAM business, from our kind of estimates, seem really strong. How, I guess, durable do you feel like the growth rate is around PAM? If you'd like to share kind of where you think that is or what that looks like, happy to hear it. But just more broadly, even, how much kind of momentum is there still within that kind of legacy, but still very much core and important part of the business? I think I love talking about PAM. I think even if you think about the way that the organization has infused privilege controls across each of our personas, when you think about the workforce persona and even that machine and non-human persona, privileged access really is core to everything that we do because it's one of the hardest security problems to solve, and so when we think about the durability of demand in that IT and developer persona, we believe that there is a long runway for growth, not just in new logos, but also in that expansion. Because what we still consistently see is that customers will only start with a small portion of their overall user base, and then they continue to expand. But the really interesting thing that we're seeing is when you think about that developer persona, which is a pseudonym for kind of more modern cloud workloads, right? And that can be an IT persona that's actually using or doing more and more in cloud environments, but they need that more modern approach to privileged access. They need to be able to secure zero standing privilege, and they need that just-in-time access into those very dynamic cloud workloads. And so our ability to not just sell that traditional seat, that traditional privileged user, or which we're now kind of rebranding as the IT persona with additional functionality, but where we're really seeing a lot of traction is the fact that we can move between those more modern use cases down into the more traditional standing access and standing privileges. And so we're seeing within those large enterprise customers that they're buying more and more users, and they're saying, "We need this user to have that full suite. They need to have standing access, but they also need zero standing privileges, and they need just-in-time." So they want to be able to have those users move between those different technologies. And that's been one of those things that I think when you think about the modernization of CyberArk, we've really modernized our privileged access business. And we're seeing the fruits of that in those growth rates because those customers are able to expand and address their cloud security challenges as well. Great. You touched on it a little bit, but in terms of your kind of talking through PAM and the dynamics there, but it's very much about personas now. And I know you've sort of moved the go-to-market more towards that type of orientation. Just internally, externally, conversations with customers, how has that maybe changed the game or kind of made things more easy to understand? Or what's kind of been, I guess, the results of that move or that shift? Yes. I think we've really seen last year was the first year that we formally introduced the persona-based selling, and I think one thing that became clear right out of the gate was the fact that we were speaking the same language as the customer. And so we could go into that level of engagement, and we could say, we're not going to try to talk to you about PAM, access, machine identities, secrets management. Let's talk to you about your identity security challenges, and let's talk to you about the fact that your workforce user is going to have to have privileged access at some point in time during their day. And how are we going to make sure that that user is getting the right level of controls and the right level of security that they need? And your developer, what does that look like for you? So what we saw was we were really able to much more effectively address their challenges. And we were also able to go in with more of that platform sales motion. And you saw that really show up in the fourth quarter. You saw it show up throughout the year in many of the examples that we talked about from a win perspective. But it became most clear in the fourth quarter when we were able to land with our three largest deals were seven-figure deals or full-platform deals. And that was, I believe, directly attributable to the fact that we were going in with a solution selling motion. But we also had another fourth new logo that actually was in the top 10 but didn't quite make the top three list, which was another seven-figure new logo deal, which was the same type of a use case where the customer really wanted all of our offerings to be able to move between the human and the machine side. And that use case and persona-based selling was a big part of it. Super helpful. And I think that tees up my next question. I think you had mentioned something on the fourth quarter call around the upsell motion for Venafi having a CyberArk direct seller that owns the account and the Venafi kind of person layering in to help be that specialist. Kind of begs the question, do you see that kind of as a temporary kind of solution, as their motion, as the two suites come together? Or given you've got IGA, you've got a lot of stuff on the truck now, a lot of different domains, is there going to be maybe some specialization within the sales force coming future down the line? I think the interesting thing that might be underappreciated, and I actually think is part of the reason why we were so successful in navigating some of the macro challenges that many organizations faced in 2022 and 2023 and many even in 2024, is that we actually did have specialists already. So we were calling them at one point in time the Speedb oats, which were just overlays. They were specialists that were focused on, at the time, our MFA and single sign-on solution, and at the time, our Secrets Management business and the Endpoint Privilege Manager. And what they were doing was they were able to just add a level of technical depth that our enterprise sales reps didn't have the capacity to kind of go into. And I think this newest introduction of Venafi is just a continuation of that motion to a large extent. And I think we think it's going to be critical to ensuring that we're able to scale the Venafi business. But we also think that there is some benefit as we go deeper into the broader platform for our enterprise reps to have some more support from a technological perspective. When you think about kind of pivoting from an enterprise rep when we're moving higher up into the organization, because now that we're selling more of a platform, we are going deeper into the CIO and the CISO suite. You tend to see that having that level of technical expertise gives you more credibility, particularly when you're moving into the non-human identities because there is a bit more technology that you have to get into from a scale perspective that is a bit different than what our enterprise reps have had to face on the human side, where I think the motion, while I definitely think that our Speedb oats gave them a lot more traction and cover, I think that on the non-human side in particular, that's going to go a long way. Great. Well, we're getting towards the end, and I don't want to hog the mic. So I will, at this point, set it out to the audience. Any questions for Ms. Smith and for CyberArk? Just on your most recent acquisition, getting you deeper into the governance, is it my understanding correctly you're sort of coming in targeting underneath SailPoint? So SailPoint up here, and your guys are coming in down here. Is that the way to think about it? And I guess what's a reasonable sort of if you have 10,000 customers, they have 100. What's a reasonable cross-sell assumption that you model? Yeah, it's a great question. I would say so the question was, with the Zilla acquisition, are we coming at it from a lower part of the market as opposed to SailPoint, who is coming at it from a higher end of the market? So what I would say is, as opposed to bifurcating the market into large enterprise and lower end, our approach is just different than SailPoint. So SailPoint kind of covers the on-prem environments and the legacy environments. They also have some modern use cases as well that they're addressing. But what we're going to be able to do with Zilla is more extending into those modern use cases, which we do believe we can sell into the large end of the enterprise as well as down into the mid-market. The difference is that we are not today reaching into the on-prem environment with Zilla. So we're not going to go all the way back into the traditional IGA use cases, which tend to be very resource-heavy, very service-heavy. We're going to be focusing on those modern use cases. So that would be the biggest differentiation as opposed to kind of high-end, low-end. We can sit alongside SailPoint, meaning that if a customer were to have a traditional SailPoint deployment, we could address some of those more modern use cases and sit alongside a SailPoint with a Zilla. And then when you think about that cross-sell motion, they only have 100 customers. They have about $5 million at year-end of ARR. We're assuming that we can double that this year. But it will take, just like I talked about with the enterprise sales cycles, it will take time for us to enable our reps. They only had approximately three enterprise reps selling. That's why having them sell into the 50 new logos last year was so incredibly impressive. But I think it's going to take us. We're in the process of enabling our team now, and then we'll go in to enable the channel. We should start to see some traction as we move through 2025. But it would be. be. It's a bit early for us to start talking about numbers of customers we'll cross-sell into. I think as we move into 2026, we certainly think that the momentum will very much pick up pretty quickly next year. Will you use the existing Salesforce, do you think, to sell Zilla, or will it be a specialized separate Salesforce? So the question was if we would use the existing sellers or we would deploy a specialized sales force. So today, the way we're approaching it is that Zilla will be sitting within our workforce identities. So when you think about that persona-based selling, we're kind of selling across the workforce, the IT and developer, which are many of the PAM use cases, and then our machine identities. And Zilla will sit in the workforce solution area for today. And I think we'll refine that go-to-market motion when we get deeper into the integration process. But for today, it's going to sit inside of our workforce solution. All right. I think to keep the schedule on track, I think that's all we've got. So thank you very much. Thank you, Trevor. It was a pleasure. Appreciate it. Great to see you. Thanks, everyone.
Loading workspace