Okay, we're going to go ahead and get started with our next session. Thank you, everyone, for attending. Before we begin, given that it is the Extel voting season, if you do value the work that we do, we very much appreciate your support. With that, we're thrilled to have Clarence Hinton with us today. Clarence is Chief Strategy Officer and Head of Corporate Development at CyberArk. Before joining CyberArk in 2019, Clarence was SVP of Corporate Development at Nuance. Prior to that, he led strategy and corp dev for BMC and also held operational, strategic, and financial roles at Dell, Bain & Company, and Capital One. Clarence, thanks so much for being here. Thanks so much for having me. It's really my pleasure. Okay. Thank you. Just for the folks who haven't met you, please just maybe briefly tell us your primary responsibilities at CyberArk, and then we'll go from there. Of course. As Chief Strategy Officer, first and foremost, corporate strategy is all the different chess moves that are out there. That is, of course, a great deal of fun, very challenging. Think about traditional corporate development, M&A, strategic alliances. All of our partnerships that are not channel in nature, integration focus in selling together and creating strong mutual alliances for our customers. We also have a small venture practice that tucks in there. Perhaps my favorite aspect of my role is I am the executive sponsor for our Customer Advisory Board, which is beautiful because it feeds really into each of those other responsibilities very nicely. Wonderful. From a corp dev standpoint, I have to say I've covered CyberArk for a while. I think clearly the last 12- 15 months have been the busiest in CyberArk's history. Is this coincidence? Is it opportunism? Or did CyberArk enter 2024 with an intention to assemble a broader identity security platform? Yeah, it's many years in the making, as you know from having covered us. When we made the transition, really fueled by the Idaptive acquisition back in 2020 to a broader platform, really identity security. The need we saw at the time was when you looked outside of PAM to the other swim lanes, as we used to call them, they're all management companies. Really, identity was becoming a significant attack vector, and therefore had to be a defense vector. We knew that what we're doing with applying privileged controls to the most powerful users in the company, we could expand that more broadly on the human side initially, and then off to the machine side of it. That was a vision that started back then. You continue to build this out in terms of the capabilities we developed organically and some smaller tuck-ins. What really shifted for us and then what brought us to Venafi is that increasingly you saw, even on the certificate lifecycle management side of it, it was becoming more and more of a security concern versus what for a while was a bit of an operational concern, just worried about outages, what if I have certificates that expire. As that became increasingly important to our customers and they wanted to have the security conversations with us, we started looking for options there. We just found a great set of partners there who always had a security-first mindset and not only had a strong CLM offering, but also had very strong capabilities for the next leg of it, going into workload security and beyond. That was that. With With Venafi, it was just a significant move for us that made a whole lot of sense. We've been looking at the government side of things for quite some time. Again, this is driven by our customers. Our customers said, do you have another way for us to more effectively look at the lifecycle of these identities? Because, again, this is becoming less and less of just a pure management concern and more of a security concern. You want to make sure that you have the right level of privileges across the entirety of your workforce and that those change as people leave, as they change roles, et c. You can do this more dynamically, particularly when you look at your SaaS and modern applications. With this, we didn't see a strong fit for quite some time. We came across Deepak and Nitin and the Zilla team. Among the original thinkers in the space, clearly knew the problem well, very strong technology specifically designed for modern applications, modern use cases with security at the heart of it. Those just landed where they landed. It was a very, very busy time, but it's a continuation of a story we set out some number of years ago. Okay. That's great. Maybe let's dive in a bit into Venafi first. One thing I'm wondering about is just how you'd characterize, Clarence, the sales enablement of Venafi among traditional CyberArk partners at this stage. Also, how do you expect that it will evolve from here? Sure. First, it's important to note that it's the same buying centers and oftentimes the same buyers. There's a lot of synergy there, even in our own sales force before we get out to the partners. The entirety of our AE force is enabled as part of the enablement training we started this year. For our partners, that's progressing very well. Several hundred of our partners have been enabled on the Venafi solution. We're ready to go out and continue to position this as part of our broader identity security solution. That's all going quite well. A few hundred partners, I guess given that Venafi is a somewhat technical sale, does that, in your view, limit the percentage of traditional partners ultimately that can embrace machine identity? Or you see a very high ceiling as it relates to that? I see a very high ceiling. I keep going back to our sellers because we asked the same question even when we were contemplating the combination. Is this more of a technical sale? Is this something that our sellers may not be able to do? What we found early on, it's not even diligence as we were still evaluating, is that no, it's something that was very natural to our sellers, to our SEs, to understand, to pick up, to add to the, to put in the quiver, if you will. We're seeing something very similar with our partners. Very, very natural, very, very natural add-on. All right. Terrific. And then on Zilla, do you view their tech, so like their tech alongside the other vendors in the IGA space, right? Gartner has kind of coined this term light IGA, meaning that there's a group of vendors in this IGA space, in this governance space, where it's very easy to deploy, very easy to manage. The other side of the coin is they don't believe they have all the bells and whistles of the high-end solutions. With that said, how would you characterize Zilla? Where does it fit in? Yeah. When you think about what's really required for IGA, regardless of whether it's, I'll get back to traditional legacy versus light versus modern, which in our view is quite different than light. There are certain things that you must do. You must enable access request, review, attestation, that whole cycle. You must actually control in a very, very intelligent way the entitlements that are given to each member of the workforce, just based on what they're actually doing, right? Not so coarse-grained as just an AD group. Of course, you have to provision and deprovision the users as appropriate in real time, and even as they're changing jobs. There are certain functions that you just have to do. One thing that happens with light is that they just kind of pick off a few of those and say, well, these are easier, I'll just do those. You are leaving the rest of it unserved. That means you do not really have an IGA. I think partial is probably more accurate than light for many. Again, that is a trade-off that some have had to make. The real difference that we found is from traditional legacy to, as we call, modern, it is really the applications themselves. If you are thinking about traditional monolithic, very, very heavy applications, there is just a certain amount of effort that even requires to onboard the applications and to do any of the things we talked about in any depth. That's why there's typically such a services overhead to go in and actually manipulate the applications so that you can actually execute on classic IGA. Now, when you move over to modern applications, the SaaS and modern applications, there are different ways of doing the same thing that aren't as heavy, right? You provide the totality of the functionality that you need, but you take advantage of the modern architecture, the different protocols, the way to onboard and access applications. That's exactly what Zilla has done. It's actually covering every single one of the capabilities we discussed before modern applications and workload. There's no compromise in that. It's not just taking a small subset and saying, okay, we'll do it. Sometimes with light, it's partial both. It's partial capabilities and also partial applications. It still may focus just on some of the SaaS, maybe a subset of the traditional. That's really how we see it, the separation across the three, as I call it. Okay. That's very helpful. I know that Zilla, as a standalone company, did acquire some very big enterprises. Our understanding is that most of the customers, not unsurprisingly, were kind of more mid-market in size. I guess going forward for CyberArk, how do you see this playing out? Do you think it kind of is predominantly landing with mid-market for a period of time and then it kind of moves up market? How do you see that trending? Yeah. The core immediate product-market fit alignment is more of what we call scale. That is still good-sized businesses, like $500 million, $1.5 billion. Even lower mid-sized enterprises, we see very, very good fit. That was the initial focus, again, for the modern applications. We've received tremendous interest from our customers at the very high end of enterprise. They still require a modern IGA solution. This is not something that's limited to the lower end of the market. They're not seeing what they need from the traditional vendors there in terms of being able to port that over to the modern applications. There is very, very significant opportunity there. That is on a roadmap to ultimately provide modern IGA capabilities at the highest level to all enterprises, including those at the very, very high end. All right. Super interesting. Thanks, Clarence. As I said at the outset, you've been at CyberArk for a while. For years and years, as we both know, it was largely all about PAM. I know that you still predominantly land with PAM today, right? Nowadays, you can also get in the door with developers, with the broader workforce, with machines, and even now, as you just mentioned, with IGA. Realistically speaking, how will having these other solutions change CyberArk's ability to acquire new customers in the future? First, just going back to what you mentioned, Greg, in terms of where we start. Yes, the substantial majority of new logo landing involves PAM, but typically involves more than PAM. The majority of those are PAM plus workforce, PAM plus endpoint, et cetera. This gives us, at minimum, more combos. You can see more multi-solution, multi-product capability lands with our new logos. We view that as positive in terms of PAM being involved because despite the fact that it's a somewhat mature market, there's still a tremendous amount of greenfield opportunity in PAM, particularly when you start to look at our modern controls, the zero standing access. That is the motion. What we're seeing already, and we talked a bit about IGA with Zilla, when you look at scale, look at low-demand enterprise, we're seeing activity with logos that are new, not new to us. That is a new avenue. When you look at Venafi, that will allow us to enable to land in places where they may have prioritized machine identities ahead or more that we haven't been as active in those accounts. It does give us an opportunity. When I think about it, it's really you see some Zilla, low-mid, you may see some Venafi-inspired, but really our modern privileged controls that you may have cloud-native companies that may not ever have what we call traditional PAM access. It acts as a very, very strong land for us with our secure cloud access, secure infrastructure access, et c., just our modern privileged controls where we can land in these environments and secure the most powerful human users out of the gate using modern stuff. Okay. Great. At your Impact Conference in April, you unveiled your agentic strategy. Maybe just briefly summarize the strategy for all of us and why you think CyberArk will be one of the winners here. Sure. When you think about the agentic AI, I mean, things are progressing tremendously fast here. You can draw an analog to the rollout of the cloud platforms. There is kind of the roll them out from a customer standpoint and hope for the best in terms of security. Before you know it, the attackers are there and it's the primary attack vector. You kind of scramble to catch up and figure it out. I think not only we learn from that, but everyone realizes that the stakes are entirely too high with agentic AI platforms to let that happen. The amount of the attack surface, the effective attack surface is just so much larger when you think about conceptually an enterprise being able to have a million-plus agents roaming around. Definitely as a collective industry, putting a lot more thought into deploying agentic AI platforms in a very, very secure way. We have a number of partnership discussions ongoing where we're looking to do this intra-platform, outside-of-platform. For us specifically, one thing that's so unique about AI agents is they act like both machines and humans. There's machine-to-machine access that humans could never contemplate. Then again, you can give them very human roles. You can basically make them demand admins if you were so inclined or any other type of admin, cloud ops, cloud engineering, whatever you want. They require both sets of controls. We have both sets of controls. Out of the gate, we're able to provide a level of security that we believe is really unmatched across the industry in terms of regardless of the mode that the AI agents are acting in, we can provide that security. That's what we're looking to bring together into a solution by the end of the year. Okay. So it is on track for a GA by year end. Okay. Great. And then just looking back over the past one to two years, the swim lanes have really blurred in identity security across so many of the major players. Obviously CyberArk, but also SailPoint, Okta, CrowdStrike, and others. How do you view the competitive landscape today and how much more vendor consolidation will result from these chess moves that you and a lot of these other large vendors have made? Yeah. I'll start a little bit with the consolidation term there because the aspect of the consolidation that's very, very meaningful to us at CyberArk is a consolidation that's driven by the customers, right? That's why we've used the term consolidation of trust. You have customers, especially larger enterprises, not at all uncommon to have discrete cybersecurity solutions from 100-plus vendors. You have new problems coming online. You have the long tail of machine identities. You have agentic AI. The last thing we want to do is add a few dozen more. They're really looking to a smaller set of strategic vendors like CyberArk to solve a larger portion of their security concern at a very, very high level. They're not looking for supermarkets or anything like that. For us, that's why we're so focused on providing best-in-class identity security across all solutions. That's just a little bit of the context there. If I go through each of the markets, you can kind of, if you divide it into more of the traditional market categories, think about classic PAM. I think we all know that. They have other competitors there. They're all PE-backed. It's been the same form of competition there for quite some time. We compete very well there. We do very well there. Once you start to go out into the broader workforce, it's a little bit noisier. You have Microsoft and Okta and others out there. For us, very, very focused on the differentiation associated with our privileged control layers that we can add on top of that. We talk about workforce password management, secure web sessions, secure browser. EPM on the endpoint side, we believe, is another layer of security that applies to the entire workforce. Again, noisier there, but we feel very strong about our security-related differentiation. Move over to the machine side of it. Again, the number one competitor for classic certificate lifecycle management is spreadsheets. That is still very much it. And that's becoming less and less viable. We've seen the duration go to 90 and now 47 days is likely by the end of 2029. In terms of the certificate. In terms of the certificate lifecycle, yes. That is just becoming untenable for customers. That is going to open up more and more of that market. There are a few other vendors out there. Again, we feel very, very strong about the capabilities that we brought on, the team that we brought on, and quite frankly, the roadmap that we have there. As you move further to the right, it is more and more just open in terms of the, if you are not seeing super strong competition. I should point out secrets management. That is the machine part of it. Even prior to Venafi, we had very, very strong performance there even before kind of the noise in the market with Hashi and IBM and all that. That is just, it has really continued. That is another very, very strong component for us, a relatively favorable competitive environment. That's the whole landscape, I believe. Okay. Okay. That's very thorough. Appreciate you walking through that. You did a few minutes ago just very briefly reference Just in Time or Zero Standing Privilege technology. Many other companies are talking about this as well, Clarence. Maybe just for everyone, describe briefly what is Zero Standing Privilege. Also, given CyberArk's role and how you have helped customers over the years, I guess, could the uptake of Zero Privilege actually reduce the moats around CyberArk's business? How do you sort of see this moving forward? Yeah. I think first it is good to call the differentiation across Just in Time versus Zero Standing. Just in Time is, hey, there is access that is around. And for users, like, oh, well, we will add you to this group briefly or we will give you these privileges. But the privileges are always there. The accounts are there. You still have a fairly large attack surface. We all know the adversaries are very, very good at finding those things, even if they are not intended to be out in the wild. Zero Standing access is very different in that the account does not exist. The access to privileges does not exist until the point of request and approval. As soon as the session is over, it is all gone. For us, it is very, very important to minimize the attack surface. Because again, at CyberArk, it's one thing that really differentiates us among identity security vendors is that we always have this think like an attacker mentality. We try to stay ahead of the adversaries. Where would they go? Where's the next place they look to attack? That is why for us, Zero Standing access is very, very powerful. It is the appropriate way to go as opposed to Just in Time that you see kind of sprinkled everywhere. For us, we just viewed it, we talk about our modern privileged controls. We believe it's a way to expand the scope of highly privileged accounts that can be covered. You may hit a certain limit in terms of when you think about the really classic traditional controls in terms of how far you can go as you get into more cloud engineering, cloud operations, and then particularly when we go over to the developer side. We view it as expanding the overall market opportunity so you can cover more and more and more of these highly privileged identities. Okay. That's great. Maybe we'll ask one more question and then we'll pause for any questions in the audience. I just wanted to come back to M&A. At this stage, again, post-Venafi, post-Zilla, are all the major puzzle pieces now in place or could CyberArk continue to potentially acquire companies that are bigger than what we would classify as a tuck-in? First, we definitely feel very, very good about our coverage of the identity security space, but not done. One way to think about it is for the different capabilities that we want to provide across each of the identities, it is discovery and context and then onboarding to secure with the right level of privilege control. That is credential security, whether it is a password, a secret, certificate, whatever it may be. It is authentication, authorization, the session management and control, and then wrapping all of that in the lifecycle of the particular identity to enable audit and so forth. We need to provide each of those capabilities at a high level across the entirety of our solution set. If you go left to right, starting from the IT solution to the developer workforce, et cetera, you see lots of really, really dark green in terms of we have it covered there. We're constantly looking to fill in any areas of middle green, if you would. As you move to the right with machine identity, we have some areas of dark green as well. I think this is more, and this is for the industry, there are areas that are more wide open with the coverage. We're continuing to evolve because the nature of the identities themselves is continuing to evolve, especially when you get all the way out to the right and you're thinking about agentic AI security. That's where we spend more of our time looking to build out our solutions and capabilities. We believe we have the wherewithal and the capabilities to do what we need organically. There may be opportunities to cover more sooner, and we can redeploy some of our valuable in-house resources to do other things if we find the right match inorganically. That is really how we think about it. Good coverage overall, always looking to get better, always looking to move everything to the dark green full coverage. Okay. Makes a lot of sense. With that, let's open it up for any questions in the room. If you have a question, please raise your hand. We do have mic runners that will come to you so you can ask your question. Any questions? We covered a lot. We did cover a lot, but I'll keep going and ask a couple more. Again, if you do have a question, please do go ahead and raise your hand. Let's actually maybe take the commerce of everything because we have seen CyberArk, in my view, CyberArk has been the best executing cybersecurity company dating back to the beginning of 2024. That's no small feat. We've just seen this incredible consistency during a time when a number of other companies, quite frankly, did not show that or at least not to that degree. I guess the other side of this is things have gone very well. You clearly feel like you've strengthened your product portfolio substantially, right, with Venafi and Zilla. It's early days in terms of both of those. What actually worries you the most as it relates to CyberArk's ability to continue to grow at a healthy rate for many more years? Yeah. As you mentioned, the table is set for success in terms of a very, very large TAM, very strong portfolio, proven ability to execute there. It is really, first and foremost, continuing to execute to stay ahead of the adversary. That is really how we are wired. They are very, very aggressive and savvy. We have nation-state attackers. We have cyber-attacking syndicates with a business model and division responsibilities and roles. They are highly, highly sophisticated. First and foremost, that is what we view as the number one competitor, the number one adversary. Constantly fighting to stay ahead of them. I think we do have just the ongoing execution as we continue to sell and execute at a high level. We do not take it for granted. I think that's something we're extremely focused on is really the training, enablement, messaging, the continued development of a real robust platform in terms of front-end and back-end and the admin tier. I think that's really it. Staying ahead of the attackers and our own kind of business execution and then continuing to build out the platform to support all this growth. All right. That's terrific. Any questions? As it relates to Venafi, do you think, Clarence, that Venafi will enable you to land a lot more logos going forward, or is it by and large about driving higher cross-sell? I'd say in the near term, there's such a tremendous cross-sell opportunity where something like 9,500 of our logos, classic CyberArk logos, did not have the Venafi solution. There's just kind of this built-in runway of cross-sell. Having said that, we do see a meaningful opportunity to potentially land with that. As we mentioned, PAM has been a lot of what we're doing in terms of the land motion, but it's PAM Plus. I definitely could see a combination of PAM Plus Venafi lands going forward. It's really both. This goes back to execution. We don't want to take our eyes off the ball in terms of making sure that we're really pursuing the cross-sell opportunity of Venafi. This is right in front of us. It could be a source of new logo landing either solo or in conjunction with other solutions. In secrets management, you briefly brought up IBM and Hashi. Obviously, IBM acquired them some time ago. There was a time when they were hypergrowth, quite frankly, doing extremely well. Their growth did substantially moderate. Obviously, again, now they are part of a bigger company. What impact has that? Because these events were set in motion a while ago, right? What event or impact, I should say, has that acquisition had on CyberArk in your view, if any? I'd say first and foremost for the secrets management business, as I mentioned, it really started to hit a nice stride before any of that happened. You just really saw the product-market fit and brand and broader story really come into focus. If anything, as that happened, there's a little bit of disruption. There's a little bit of an incremental tailwind. It wasn't at all an incremental catalyst, really. It's just a little bit of a tailwind for something that was really landing there in terms of our SaaS solution on the secrets side, Secrets Hub that's highly differentiated. Just so many things really, really lining up. Yeah. I have to say it's been impressive too, just from my seat over the past two, three years, just seeing CyberArk becoming more relevant with developers as well. It gives you, again, just another way to get in the door, another way to sort of sell the CyberArk product portfolio. I think that's been really additive from that perspective. Absolutely. Appreciate that. Absolutely. With that, we're unfortunately out of time. We'll wrap it up here. Clarence, thank you very much for a super interesting session. Appreciate it. Thanks for having me. Absolutely.
Loading workspace