All right, here we go. All right, good morning, everyone. My name is Brian Essex. I'm JPMorgan Security Software Analyst. Thank you for joining us this morning. With me, I have Matt Cohen, the CEO of CyberArk, and Ehud Smith, their newly minted CFO. Thank you so much, both of you, for joining us. One thing before we get started, I do think for those listening via webcast, there's an opportunity to enter questions online, and I can take those as we go along. I'll also leave 10, maybe a little more minutes at the end for any of you in the audience live that want to ask some questions. With that, again, Matt, Ehud, thank you for joining us. Thanks for having us, Brian. Maybe a great place to start, you guys reported earnings yesterday. I guess maybe one of the things I wanted to do is just overall kind of like recap of the results and feedback that you've gotten from investors after you reported. Yeah, sure. Maybe I'll start. It was a strong first quarter start to the year for us. We had really, really strong net new ARR growth across the board, especially subscription net new ARR growth. We beat all of the guided metrics on revenue, on margin, free cash flow. Ultimately, what we saw was a start to the quarter that kind of spoke to the durable demand for our part of security, identity security. Ultimately, I think what we talked a lot about with the investors and on the earnings call itself was that the threat landscape around us is evolving at such a rate that even with this macro backdrop, people understand that they need to get their identity security programs and strategy under control. It's both human and machine, which I'm sure we'll talk about throughout today. We saw a nice growth in our machine identity business on the back of our Venafi acquisition. Ultimately, what we saw is that customers are still moving, forging ahead with their programs, and it was demonstrated in our results. The other side is we reiterated our guidance for the year. We thought it was prudent not to take up guidance given the backdrop, but that's based more on just conservatism than based upon anything that we're seeing in the market. Was that just a because we can kind of thing? Yeah, it was, listen, it's Q1. Always coming out of Q1, we have a history of being somewhat wanting to see what's going to materialize. In addition, just with the macro backdrop, it was like, let's wait another 90 days and see what happens. Yeah. On the macro, I mean, what exactly are you seeing? I I mean, you can't be seeing nothing. Is it that budgets are still durable and projects are just so long, just so large with long sales cycles that they're like a freight train that just kind of keeps going? Is it that maybe the buyers are seeing a heightened sense of urgency where the priority is kind of like moving up the stack? Maybe. You know, I think it's a little bit of both, which is when you think about, so first of all, let's start with what you said to begin with. Of course, they're noticing the macros. I go in and I talk with the C-suite at most of these organizations, and they're worried about tariffs, especially if they're in manufacturing or auto or retail. They're worried about overall spend environment. It's on their mind. We quickly transition to, OK, what do we need to do from a security perspective? As you said, identity security kind of sits at the top of where the spend would go. They're not shutting down all spend. They're shutting down spend that's, let's say, below a certain line. We're well above that line. It's back to what's our roadmap? Where were we planning on heading? In some cases, how can we actually speed up because we can't afford a security incident in this environment? Got it. And then maybe on the, I think you mentioned machine identity and recent acquisition of Venafi. What are you seeing in terms of momentum there? I mean, you had the acquisition, and then now you've trained the sales force, and you're working on the channel. Where are we in that process as Venafi becomes integrated with your direct and indirect sales force and when you might start to see momentum pick up there? Yeah, so we talked a lot yesterday about the momentum we're seeing in that side of the business and actually how it's exceeding our expectations. We're several quarters in now. The sales teams are ramped. The partner teams are excited and really starting to position out in the market. We see kind of these industry tailwinds kicking in for we spent a little bit of time yesterday talking about this CA Browser Forum mandate to bring certificate lifespans down to 47 days by 2029 with the kind of ramping down. Right now, certificates, which is a core piece of the Venafi business, was well over 300 days, the average lifespan. And when you have thousands and thousands of certificates, if it's a long lifespan, maybe, maybe you can maintain it with manual tools or with automated spreadsheets. When you start to think about having to rotate or reissue these certificates every 40 days, thousands and thousands, and if one does not get issued, your website, your applications are out. There is an outage. Basically, you can shut down your business efficiency, your business performance. When that starts to become real for people, it becomes a strong industry tailwind for our machine identity space. What we are seeing is like a dramatic increase. I use the word dramatic on purpose. In pipeline, we saw great execution in terms of close rates in the Q1 period. Ultimately, we are seeing the Venafi acquisition being ahead of schedule in terms of where we would like to be in terms of momentum. It was further down on my list of questions, but since you mentioned it, can we dig into that certificate business a little bit and what it means? One, how do customers manage that lifecycle process for certificates now? You mentioned maybe manually and some automated, but maybe you could help us understand what the opportunity is there and how penetrated are automated solutions for that? Sure. Maybe just a layer on top of the question to help, again, for people who maybe are less familiar. When we talk about identity security, we talk about human and machine, and I'm sure we'll get to, we also talk about AI. In the machine space, there are multiple types of identities, ways in which applications, workloads, pieces of code, devices identify themselves for the ability to be able to access or authorize to get access to other machine data, applications, or systems. The machine identity itself can be what's called a secret. It's like a username and a password for a machine. It can be a token, a crypto key. It can also be a certificate. Almost all machines have a certificate on them. The certificate gets either issued by the organization or by a certificate authority. It basically is like, think about it as like your driver's license or your passport that tells other systems who you are and what you're allowed to have access to. It has an expiration on it, but that expiration can be either long or it can be short. What the industry is going towards because of security concerns, because of kind of the rate of change, is shorter and shorter lifespans for these certificates. That means that in order to be able to keep the machines up and running, to keep them protected and secure, you need to constantly be reissuing more and more certificates. That calls for a lifecycle management process that basically can discover these certificates, rotate or reissue these certificates, and then ultimately keep those organizations safe. That's what the Venafi offering does. It complements what we do on the CyberArk does on the secret side and the key management side. What we find is that five years or so ago, only the largest organizations were really worried about this because they had tens of thousands, even hundreds of thousands of certificates. As we start to see this lifespan come down, every organization, large and small, needs to deal with this problem. That brings into focus thousands and thousands, actually tens of thousands of organizations that today do not have a solution at all that can benefit from our solution. When we acquired Venafi, they were about 500 customers. We have 10,000 customers at CyberArk. All 10,000 customers are a great target for cross-sell of this motion. That is why we are so bullish on the opportunity to be able to grow that business. How meaningful can that business be for Venafi from a revenue perspective? Yeah, so it sits today at roughly $170 million ARR. We think that the total machine business for us, both certificates and secrets, is a billion-dollar business. We see it as our fastest growing line. When you combine the two together, we're well over $250 million of ARR, and we see it going to a billion in the next couple of years. Got it. This decision by the forum to adopt these standards, when does that go into practice? How might we see that in the marketplace? I mean, are mid and small-sized businesses going to wait till the last minute and wait till they can't? Yeah. Yeah, so it's basically a gradual phase-out from an authority perspective. It drops to 200 days next year, then goes down to 100 and something days, and then by 2029, it's down to 40. Since it's been set in stone, it's basically accelerated people's timelines. When we were at RSA two weeks ago, it feels like a whirlwind here, the number one question at our booth, and we had a lot of booth traffic, as you might imagine, was actually about this issue. Yeah. Yeah, great. Sticking with the theme of machine identity, you mentioned secrets. How does that play into Venafi and machine identity platform? Because you had the secrets business before. What does the combination look like? It is a synergistic combination because basically secrets just manages another machine identity type. Again, secrets is generally you're taking the username and password or SSH keys, and you're vaulting and rotating them as a centralized policy. If you went back 10 years ago, people used to hard code the secrets, the username and password, into the code of the application. That is a really bad practice. Luckily, the industry has kind of gotten away from that. If you still use static secrets that are one-time and never rotated, if that application gets compromised, you're basically opening up a giant door to your organization. The ability to be able to vault, rotate, and policy manage secrets, username and passwords goes hand in hand with the ability to be able to rotate and reissue certificates. By the way, it goes hand in hand with a newer offering that we came out with on impact around modern workload identity, which is kind of ephemeral or dynamic secrets. It is a universal or unique ID that only lives for minutes or hours. Across all of that, we are the only provider, the only platform that can do certificates, secrets, workload identities. We do discovery and put it in context. We do controls. We automate the lifecycle, and we do governance. It is a unique position because each one of those individual areas are often handled by point, tiny little point solutions, and we are the only one who can do it all. Got it. When I think about machine identity initially, I think about a relatively simple relationship. It is a network talking to a server or an application talking to an application. Now we have the agentic horizon. I think about something that can act like a human based on what that application is requested to do but can scale like a machine. How do you think about your agentic roadmap? I think at impact, you highlighted a little bit. You gave us a little bit of a sneak peek around what the roadmap looks like. Maybe talk about the opportunity there and what your roadmap looks like on the agentic side. Yeah, Brian, you framed it up really nicely. I think when we started down the path of the industry, started down the path of AI adoption, there's been a lot of focus on the data side of AI. How do you protect the data? Data leakage? How do you put in place kind of prompt controls to protect against prompt engineering? How do you protect the LLMs? I think that's an interesting space, but I think that space is pretty well covered by both existing companies and by a slew of startups. What's happening now, and as a CEO, I'm focused on it for efficiency and cost effectiveness, is the rise of AI agents. AI agents to basically augment or replace human use cases, human behavior, human work tasks. The idea here is, again, just as an agent, I'm sure you all are familiar with it, is it goes well beyond what a traditional automation provider like an RPA bot can do because these agents are task or outcome focused, and then they're left to be autonomous. They're left to be able to figure out the best way to go accomplish that task, just like a human. When you start to think about it like that, it becomes an identity problem, not a data problem. Where are these agents? How many are there? That's a discovery. What do these agents actually have access to? What are their entitlements? That's context. How do we actually authenticate these agents when they go in and log in to go do their daily work? That's authentication or credential management. When they're doing their work, what happens if they do something that isn't allowed? What happens if they elevate their privilege or elevate their entitlements? They go into a secret system that holds your data. That's session management. All aspects of an identity security platform come to play in the agentic world. As you said, you're trying to secure them as they're humans, as they're going about their day, doing their work practices at a scale that's even beyond the machine level scale. It must be automated. Our belief is that lifecycle, that circle of security, is best offered by an identity security platform. At Impact, we launched our Secure Agentic AI solution. We're working on a deep partnership with Accenture, with ServiceNow, with others out there in the market so that we can embed our platform capabilities from day one as organizations ramp up their agentic workforce. They need to think security. They can't leave that behind. It allows CEOs like myself to be able to push harder on adopting an agentic workforce because you know security is under control. I think the agentic world from a security perspective is in POC mode. I think we will see POCs throughout the course of this year. We're working with a lot of customers around that. I think you will see scaling start to happen in 2026. I think you'll see it start to impact our business model around those times as well. It's still a futures for sure, but it's a futures where there's not a company I talk to that isn't experimenting or trying something around their agentic architecture. Got it. That's super helpful. Also kind of segues into the next question is, if you've got privileged access, and I think about the identity space, or you've got privileged access management, you've got governance, you've got identity and access management. What dictates privileged access management as the right platform to expand into agentic machine identity? I think there's a governance peer that's trying to do the same. And there's an access management, public access management peer that's also announced an initiative to get into machine identity and agentic identity. What makes PAM and then specifically CyberArk's platform unique in your ability to win in that space? Yeah, I think it starts with organizations look for a partner or a vendor they can trust. The trust is built on the idea of, do you understand the real security challenges that our organization faced? This is ultimately a CISO conversation and a CISO sale. I think when you talk to security leaders, you understand quickly that the piece of security that got it right, that actually keeps them secure, that's a security-first mindset, is PAM. It's CyberArk. I think that creates a foundation of trust between us and our partners and our customers. I think then the question becomes really, how do you put in place the controls across workforce, IT, developers, machines that have the right level of privilege controls? How do you layer around that access management, governance, administration? The core of security, the heart of security is controls. I think that's what CyberArk does really well. That puts us in a pole position, if you will, from a trust position with our vendors, with our customers. They're more likely to trust us to expand out from our base than trust people who kind of live on the periphery of security, either in just pure lifecycle and governance or pure access, trying to come into the heart of security. Sometimes I talk about it like, in this threat environment, would you rather, in the U.S. world, U.S., would you rather the FBI, CIA go out and do lighter security, or would you rather the TSA be in charge of terrorism? It has to be core security at its heart in this environment. I think that's what puts us at the forefront. Got it. Super helpful. We touched on governance slightly, but on Zilla, you recently made an acquisition of a small governance vendor. What's the initial feedback been and how has traction been through sales organization? Yeah, I mean, you go into every acquisition and you have your thesis and you have your upside of what you're hoping and you have your downside. As I mentioned, on Venafi, momentum continues to build and we're in this really strong place. On Zilla, now it's only been six weeks or eight weeks since we closed. I'm amazed by the level of conversations we're having with customers. They basically have spent years and lots of dollars implementing traditional IGA for their on-prem heterogeneous environments. That's in the upper end of the enterprise. In the lower end of the enterprise, they've avoided IGA solutions because it's incredibly heavy, incredibly hard, time-consuming, and costly. What Zilla brings is what we call modern IGA. It's the ability to be able to stand up and integrate to modern applications and SaaS environments, your most common on-prem environments, cloud environments in an incredibly quick time to value. Think days, not months or even years. The ability to be able to do user access reviews and provisioning for those environments. What we expected is that a lot of our enterprise clients might be hesitant to even talk about it. As you go down market, okay, we'd have to do a lot of pushing of the message. What we're actually finding is our enterprise customers and kind of across the market are pulling us into the conversation. They're saying, yeah, we're a little stalled. I'm not denigrating the vendors that they have on place, but they were built for a different era. They were built for an era where it was a very static workload. It's a very static data center. They're saying, we have hundreds and hundreds, for example, of SaaS applications, and the entitlements are not understood. We're circulating manual spreadsheets that tells everybody who has access to what in their ERP system or in their Workday system or in their Salesforce system. We can stand up with Zilla a quick, modern IGA solution. Again, incredibly early days. I would not say that it's still six to nine months sales cycles. We're six to eight weeks in. The conversations have surprised me with the level of openness. I kind of went into some of those conversations a little sheepish when I got started around like, hey, all right, I know you've got X, Y, and Z provider. They are engaging and saying, no, no, no, no, no. We want to talk about this with you. Let's see where it plays out. I think Zilla will be a big piece of our 2026 plan. Great. How do you think about the competitive environment there from the perspective of, I mean, you've got public governance vendors that have built SaaS platforms. You've got an identity access management vendor that's nudged their way into governance as well. It seems as though there's just a lot of share to be had from legacy providers, your Oracles, IBMs, HPs of the world. That's where there's a lot of friction. How do you perceive your go-to-market strategy? Is it going to be kind of displacing those legacy vendors, or is it going to be going head to head against some of the other kind of public identity specialists in each of the governance and access management categories? I think day one, you go in and you stand alongside whatever IGA tool they have, and you basically modernize their approach, again, for SaaS applications, for modern cloud environments, and you sit side by side. I think then over time, you have conversations with customers around what do they want to do around realizing their total footprint from a governance perspective. I think when you talk about a provider like SailPoint, who's embedded in a lot of these organizations, you're not talking about trying to replace them out of the gate. That would be a silly conversation. When you mentioned the other provider you were referencing on the access side, Okta, listen, that's head to head, and we believe we have a significantly superior solution from a standpoint of how they come at it, which is at the group level, which is a very, very rudimentary way of doing governance and entitlements management. We come in at the granular entitlements level within the actual target applications. It's just a more practical and more efficient approach. I think those are two different answers. For SailPoint, you kind of sit side by side, and I think we can coexist. I think for Okta and for this piece of the product, it's certainly head to head. Got it. One more, and then I'll open it up for questions because I think at that point we'll have less than 10 minutes left. I wanted to ask, I'll jump ahead here and ask about your partner and MSP strategy. I think you mentioned Accenture. How is that evolving, and how is that different from what you've kind of worked with in the past? I mean, I think we think of our partner strategy and partner program as a unique differentiator for CyberArk. The global SIs, all of them have dedicated CyberArk practices. We go to market together. We from day one weren't trying to be a services provider. That was helpful in terms of building those relationships. We have really strong reselling relationships with some of the best in the business, like Optiv and GuidePoint and others. In addition, as you mentioned, we continue to build up and scale the MSP program, which often are standalone MSPs, but can be also the SIs or the Optivs of the world who are building out their MSP practices. I think you see more and more of the business shifting to an MSP model because of the complexity. A lot of these organizations just kind of say, hey, this MSP, just take this off our plate. I think you'll see more and more of that drive growth over time. As those MSPs standardize on the CyberArk platform, I think that makes it so that we win anytime the MSP wins, which is what we want. Got it. With that, are there any questions from the audience? If you could do me a favor and wait for the mic, and we've got someone running up here with that. That way they'll hear the question on the webcast. Thank you. Two questions. First, certificates eventually will become real-time. How close are we to that? I have heard it articulated that that needs to happen. That is inevitable. Secondly, how do we think about agentic AI identification? Is there going to be a tail number for an aircraft that allows us to whitelist agentic AIs to determine which ones are valid and which ones are nefarious or bad actors? Yeah. Great questions. I think we are moving to real-time on certificates. By the way, we're moving to real-time on all credentials. On the human side as well, the idea of static usernames and passwords, the idea of standing access with entitlements, all needs to move to dynamic and real-time. I think you're going to see it on the human side. You're going to see it on the machine side, and you're certainly going to see it on the certificate side. On the certificate side, we talk a lot about kind of post-quantum and what happens then. I think that is the driving factor for kind of the ability or the need to be able to replace everything real-time or even move beyond kind of traditional certificates and have dynamic certificates, which is something we're able to do with our platform today. Our platform today can actually replace the old RSA algorithms, put in place the new algorithms as part of the NIST framework, and be able to rotate that for all certificates so that you can do real-time. Maybe it's not every 45 days. It's every time you have a crack in the algorithm. I think that is a real place where we're headed over the next couple of years. Security leaders understand that. They're preparing for today, but they're actually thinking about tomorrow, and you need an enterprise-level tool like CyberArk offers. I think on the agentic side, you will see all of that come to play. That is why I talk about kind of discovery and context, authentication and credential management, lifecycle management, compliance, and governance all around the agentic world. For sure, each agent as it comes online is going to need a unique identifier or a unique ID. It might be in the form of a dynamic certificate. It might be in the form of a dynamic key, or even in some cases, it might end up being a crypto key. In those cases, absolutely, there will be a unique identifier for every agent. There will be orchestrator agents that maybe live for months, years. There will be the agent farm itself that might get stood up for a minute or an hour or a couple of workdays. All of those will need a unique identifier. That is why the CyberArk platform is so key because we will need to be able to discover them, then understand the entitlements, and then watch them. A lot of people are missing that element. They think it's all about just authenticating the agent. It's about watching the agent for anomalous behavior, not only if it's a bad actor, but what happens if that agent grants itself extra privilege or extra entitlements? We need to be able to turn it off on the fly. Thanks for taking questions. On the certificate lifecycle management business, can you talk about who are your direct competitors today? Who are you disrupting because of their legacy offerings? Yeah, sure. It's an interesting market because if you followed the Venafi business for years, everybody always thought they were about to break out. It's like 15 years and they're about to break out because they were the leader by far. There really wasn't any breakout moment because I think it wasn't the moment yet. It wasn't the moment yet where the forces around us were driving the need for this enterprise-grade, enterprise-level solution. They lived in the upper end of the enterprise. I think what you and because of that, there wasn't this large emergence of competition. There's a few privately owned companies. There's a company called Keyfactor. There's a smaller company called AppViewX. They kind of compete in the standalone certificate lifecycle management business. Some of the certificate authority providers have really lightweight lifecycle management. Think of it like basic use cases. Sometimes people will build an automated system with ServiceNow or Microsoft. None of that really speaks to the scale and the enterprise grade that's required. None of that integrates with secrets and other form of machine identity types. None of it is built into a platform that also integrates back to the human side, which we haven't talked much about today, but also is sitting on our platform. In this market at the moment, we believe that the competitive thrust is less than just going in and helping people understand the why now to act, whereas it's obviously more competitive on the human side. I'll leave one back in the back. Good morning. Thank you for taking the question. Two-part question. First is, could you maybe elaborate on why your moat is better than Okta and some of the other players you mentioned? Maybe help us understand the architecture. Secondly, an average organization has over 80 sort of vendors, and there is so much innovation in this space. Maybe help us understand how should we get comfortable given the landscape is changing so much that somebody else would not come and perhaps disrupt you. Thank you. Yeah, so let me answer the second part first. I think what security teams and CISOs are looking for, and it's not actually overplayed. It's actually not talked enough, is consolidation, not more fragmentation. They're looking to figure out how to bring tools together onto common platforms. No CISO is looking for one platform for everything, but they're looking to drive common platforms around identity, around cloud, around kind of next-gen firewall, and around identity. Within identity, I think you're going to see more coming together than people launching out to other tools. I think also when you look at all the any of you who are at RSA or you walked around, you heard about it, all these little tools solving little use cases are features, not companies. I don't think that organizations, especially enterprises, are going to trust their security strategy to companies that may or may not be there in years to come. I think as you look at that outline, you see them trying to consolidate, and certainly they're going to consolidate to one of the bigger platforms. Going back, that brings you back to the first part of the question, which is, okay, what is our differentiation, for example, versus Okta? On the access side, their bread and butter, workforce access, customer access, I think at that stage, access itself, single sign-on, multi-factor authentication, it's kind of become a commodity. That's the little secret in the industry is if you're just trying to do SSO MFA, to be honest, if that's all you're trying to do, you're probably going to do that with Microsoft because you're going to get it for free, and you're going to scale the business that way. What is our differentiation versus Okta or Microsoft is our ability to layer security controls like secure web sessions, secure password management, greater levels of privilege controls on top of SSO, on top of core access components. That's where we try to differentiate from Okta or from Microsoft. In that case, we are clearly fighting from the behind, meaning we are not at the scale of Okta or Microsoft for core workforce access. When this buyer is security-minded and really wants to integrate security back to a platform, that's where we win. If you take the governance side, the modern IGA side, that's what I was referencing to Brian, where their new product that they brought out, their OIC or OIG product, it sits with a mindset coming from an access perspective. It thinks about governance in terms of groups and roles, which is what you normally find in a directory. We don't believe that actually that's the right approach to governance. We want to live at the actual individual entitlements layer that sits in the end application, not in the directory itself. That's what differentiates us there. On core PAM, I don't think I really need to explain that, but what they're doing in PAM is one of those sliver use cases. It doesn't cover the full PAM landscape. Sorry. Thanks, Imran. Can I actually flip the question? What about bigger companies like CrowdStrike? They are competing with you, right? Because they have a bigger platform, bigger distribution, and can buy the smaller guys and compete with you. Forgive me for asking this question because I heard from another company that a lot of times people view you that you are more of a single point of, so how do you compete with the platforms? Sure. I think to the last piece, go comb through our results and you'll see that actually our business is growing across all parts of our platform. While there's still healthy growth in PAM, which is what people know us for, the other product suites from endpoint to access to machine is growing at a significantly higher rate. Our deals are actually multi-product, multi-solution. In fact, nine of our top 10 deals were across human and machine last quarter. I think the results kind of show how people are buying from us as a platform. That's versus certainly the others who are competing in our direct space. When you bring in a CrowdStrike, I have a lot of respect for CrowdStrike. I think they are a phenomenal security company. I think they have a great go-to-market engine. The way they think about identity, the way they're talking about identity is from the endpoint and from the point of view of the SOC. That is a different organization and it is a different approach. It is never going to cover the kind of standing policy and standing authority and architecture that you need in order to be managing identity across an enterprise of 20,000 or 30,000 people. CrowdStrike's PAM solution that they launched is a sliver solution that basically allows you to look at what's happening on the endpoint and grant access or not access to small targets like Entra and AD in that area. That is not how you run an access strategy or an identity strategy for an enterprise-grade company. It is a nice, again, feature add to their EDR or endpoint platform, excuse me, but it is not going to solve an identity security problem. Great. Thanks, Imran. With that, I think we're out of time. So thank you, Matt, Erica, and thank you all for joining us.
Loading workspace