Ladies and gentlemen, thank you for standing by, and welcome to the KnowBe4 business update call. All lines have been placed on mute to prevent any background noise. After the speakers' remarks, there will be a question-and-answer session. If you would like to ask a question during this time, simply press star then the number one on your telephone keypad. If you would like to withdraw your question, press the pound key. Thank you. Now it is my pleasure to turn the call over to Ken Talanian, VP of Investor Relations. Please go ahead. Thank you all for joining us today. Some of our comments today, including those related to our guidance, may contain forward-looking statements that are subject to risks, uncertainties, and assumptions. Should any of these materialize or should our assumptions prove to be incorrect, actual company's results could differ materially from those projected or implied during this call. These risks are described in our Form 10-Q, and additional documents may be found on the SEC's website, sec.gov, and on our investor relations website, investors.knowbe4.com. During today's call, you'll hear prepared remarks from our CEO, Stu Sjouwerman, and CFO and Co-President, Krish Venkataraman. I want to remind everyone that we will discuss our 3 Q 2021 financial results on November 3rd. During the following Q&A session, we will only take questions on this acquisition. With that, I will turn the call over to Stu. Good morning, everyone. We have some exciting news, and I assume that the first slide is up. Can someone confirm that to me? Yes, Stu. Very good. With the acquisition of SecurityAdvisor and integration into the KnowBe4 platform, we are making a big bet to transform alerts from other leading cybersecurity layers into real-time opportunities to change human behavior. With this, we believe we are creating a new category called Human Detection and Response, or HDR. You may have heard of XDR, or Extended Detection and Response, from some of the newer cybersecurity vendors. If you haven't heard of it, XDR technology correlates signals from customers' existing cybersecurity stack layers and sends them to the SOC to reduce noise, to improve signal, and give the SOC a complete picture of the threat environment. This makes the SOC more effective in identifying and quickly responding to threats. With the addition of SecurityAdvisor to our platform, we believe we are creating a new category called HDR or Human Detection and Response. How this works is we connect to these other security layers through their cloud interface and pull in their alerts so we can analyze them and take real-time action. Additionally, once we have those alerts in our platform, we can apply our machine learning algorithms to identify which alerts provide more opportunities to correct human error real time. We have several ways to reach out to a user, including an integration with messaging platforms such as Slack and MS Teams, where we can send real-time nudges and micro-learning to correct behavior. This will represent an additional KnowBe4 SKU with what we believe to be an almost $5 billion of additional TAM to go after. This TAM is based on current targeting of medium-sized SMBs all the way up to mega enterprises. While we expect to close this transaction in Q4, we do not expect to have it fully integrated until the second half of 2022. Lastly, the purchase consideration consists of approximately $50 million up front with a combination of cash and equity and an additional $30 million in potential earn-outs based on hitting key milestones associated with product and ARR goals. Next slide, please. SecurityAdvisor already has 50 integrations with the most important vendors in the cybersecurity ecosystem. The SecurityAdvisor unique technology identifies the relevant human behavior-driven alerts from the firehose of data coming from these layers in the stack. Next, they map those alerts to technical moments, or rather teachable moments, that allow us to engage with the employee in real time to correct bad security behaviors. The system allows customers to integrate with multiple vendors and correlate human risk across those different systems, which finally gives organizations a highly accurate picture of their human risk. The identified risk data can be fed back into the customer technical control layers, which is important data for organizations adopting zero trust architectures. We can leverage these 50 existing relationships and make HDR a reality after it is integrated in the KnowBe4 platform. SecurityAdvisor's architecture is already highly scalable. It is currently running on AWS, built with a modern serverless architecture. This, combined with the strong engineering talent joining us as part of the acquisition, gives us confidence that the integration with the KnowBe4 platform will be smooth and that we can continue to rapid scale our business to efficiently serve customers of all sizes. Next slide, please. Those of you who follow us have seen this stat before. The most recent 2021 Verizon Data Breach Investigations Report found that 85% of breaches involved a human element. This can come in the form of social engineering risks, which is deception at scale, or technical error risk resulting from misuse of technology. We remain committed to addressing the human layer of security and with the addition of SecurityAdvisor, can expand our reach to integrate with all existing layers of security and tackle the human-related issues that plague them. If you look at the blue side of this graphic, you will notice that there are a few examples of issues that will pop up as alerts within other security software layers. For example, someone might plug in a USB or worse, a USB with malicious software, and CrowdStrike will forward that alert along to our platform. Or someone might not have multi-factor authentication enabled on G Suite. We can take those alerts from CrowdStrike or G Suite and take real-time action to correct those behaviors and create a highly effective Human Detection and Response. Next slide, please. Also, we believe this product opens up the much larger SOC budget to KnowBe4. Our customers have historically bought our product mostly out of the broader security budget. With PhishER, we started to make inroads into the SOC budget, and we believe that SecurityAdvisor gives us further reach into that SOC budget as we position this new category of HDR. As our customers start to think about integrating our platform across their security stack, we anticipate greater interest from the CIO/CISO level coinciding with higher retention levels. Next slide, please. Here is the nutshell view of HDR. We correlate real-world, real-time human security events across the security stack and expect to significantly improve the efficacy of the SOC. This starts with funneling in alerts from whatever other security layers the customer already has in place and correcting their users real time. We leverage our existing platform to teach security fundamentals and test users with frequent simulated social engineering campaigns. We see this combination as a great addition to the existing capabilities of our platform, as we believe it will enable true behavior change and helps build a security culture much faster. Next slide, please. From day one, we have delivered quantifiable results to our customers. We're excited that SecurityAdvisor has been able to achieve similar results. In the green section, you see a few examples of quantifiable risk reduction enabled by SecurityAdvisor. For example, a customer with Palo Alto Networks Traps product and SecurityAdvisor were able to reduce endpoint infections by 99% by identifying high-risk users. Additionally, a customer reduced web violations detected by Zscaler by 50%, and another account was able to increase the number of users on G Suite with MFA enabled by 80%. We will combine these types of risk reduction capabilities with the 8x risk reduction in phish-prone percentage that the KnowBe4 platform delivers today. We have found that the 80/20 rule applies in security, where a small portion of the users make up the majority of incidents. Identifying and correcting these users is an important step, and note that the new unique SecurityAdvisor technology actually helps make customers' existing investments in their cybersecurity stack more valuable. Next slide, please. We believe the addition of SecurityAdvisor to the KnowBe4 platform accelerates our roadmap. We planned to bring this type of functionality to market ourselves, but we expect this will speed up the process. As I mentioned before, we believe this is a TAM expander for us with the addition of HDR functionality, potentially representing an additional $5 billion TAM to go after. From a go-to-market standpoint, this is yet another addition to our cross-sell capabilities and a means for us to continue to grow our wallet share and stickiness with our customers. From a technical standpoint, this brings an immediate enhancement to our R&D team by adding a group of talented engineers based in Silicon Valley and India for further global diversification. With this technology, we're also adding a much deeper insight into end-user behavior. We can leverage this to further enhance our current platform and build out new features and products. Over to the last slide. We're often asked how our products are priced, who uses each product, and where the budget comes from. I'd like to make it clear that SecurityAdvisor will be rebranded as a separate SKU and sold separately with one- and three-year subscription options. As I just said, we believe HDR is a brand-new category by itself. We expect that it will be priced by user and used by general users, IT security admins, and SOC analysts, depending on the size of the customer. With that, over to Krish for the finance side of things. Thanks, Stu, and good morning to everyone. I just want to take a moment to reiterate our belief that this will have a transformative impact to our technology platform. First, I want to walk you through the mechanics of the deal itself. As Stu already mentioned, the total estimated purchase price will be about $80 million. This is split between upfront payment of about $50 million and future incentives of approximately $30 million. The upfront portion will be paid in a combination of cash and our Class A common shares, while the future incentives are made up of cash, common shares, and restricted unit grants, which will vest based on future performance conditions being met. The goal is to ensure the team we are acquiring from SecurityAdvisor is incentivized to help drive product evolution, product integration into KMSAT, add additional security partners into the ecosystem, and collaborate with our efficient go-to-market sales teams on the commercialization efforts. The deal also brings us an India-based R&D team and gives us another center of excellence to grow our talent base. Now we have R&D centers in Florida, Brazil, South Africa, and California, and we're excited to add one more development center to our strong R&D team. The deal itself is expected to close within Q4 of 2021, and a full platform integration during 2022. We are really excited about this deal and believe there is a considerable potential upside for the new product. This is evidenced by our ARR target of about $40 million by end of year three for the maximum incentive payout. However, this represents a very modest cross-sell penetration assumption based on the addressable TAM. Next page, please. As you know, we have a strict focus on the human layer of security and a comprehensive vision for the future of security awareness market. Continuing the momentum we have seen in our cross-selling motion is a key part of executing this vision. We expect AR impact for this year to be less than $1 million for this acquisition. SecurityAdvisor has proved the market product fit, developed the infrastructure and integration layer, built the security vendor ecosystem, and just started to put the sales motion into effect with strong early results. By adding SecurityAdvisor technology, we are expanding our cross-sell motion that has already proved successful for PhishER, KCM GRC, and more recently, Compliance Plus. As Stu mentioned, we believe we are creating a new category called HDR. In doing so, we are unifying the defense at the intersection of social engineering and misuse of technology, expanding our dataset on the human behavior, and further providing our customers with a measurable ROI. In closing, I want to remind everyone that we will discuss our third quarter 2021 financial results on November 3rd. During the following Q&A session, we'll only take questions on the acquisition. With that, if the operator could open up the line to questions. Thank you. At this time, I would like to remind everyone, in order to ask a question, please press star then the number one on your telephone keypad. We'll pause for just a moment to compile the Q&A roster. Your first question comes from the line of Hamza Fodderwala of Morgan Stanley. Your question, please. Hey, guys. Good morning, and thank you for taking my question. My first question for Stu, just around the thought process of having SecurityAdvisor as a separate SKU versus having it rolled up into PhishER, because our thought process was always PhishER was very much geared to the SOC. This seems like a solution that's similar to that. I'm curious the reasoning behind having this as a separate SKU. Hello? Stu may be on mute. Let me have another try at that. Can you guys hear me? Yeah. Yes, Stu. Very good. Okay. Good question. The answer to that really is that PhishER is an actual, honest SOAR product, S-O-A-R, security orchestration. Whereas SecurityAdvisor really is a whole animal by itself, if you will. It's a brand-new category. It does something completely different. It's not a workflow product like PhishER and other SOAR products is. Moreover, positioning it as a separate SKU allows us to cross-sell this to both existing and new customers, and that was the reason why we did what we did. Does that answer your question? Yeah, that's helpful. Maybe just one follow-up for Krish Venkataraman. You mentioned less than a $1 million ARR impact in 2021, so I imagine SecurityAdvisor on a standalone basis, were they doing that much in ARR per year, or was it slightly more, or is there sort of some accounting write-downs that are reflected in that assumption? Thanks, Hamza. Yes, I think from an ARR perspective, they are doing under $1 million right now. I think more importantly, I think I just want to go back and reiterate the key driver for this acquisition. SecurityAdvisor at this stage has put tremendous amount of effort in building the security ecosystem, building the infrastructure layer, and more importantly, really ensuring the product market fit, especially with existing clients and the market. That was really the key driver of the acquisition right now. Less from a pure ARR perspective, given they had just started their sales motion in the middle half of this year. Got it. Thank you. Your next question comes from the line of Shaul Eyal of Cowen. Your question please. Thank you. Hi, good morning, guys. Congrats. Couple of questions on my end. Stu or Krish, do you need to educate your sales force how to sell this product? I think also maybe on the heels of the answer to Hamza's question, and is that the reason you're buying it now, but full integration is expected in the second half of next year? I have a follow-up. Let me try to answer that one because it's a sales and product kind of question. The initial integration that we are really wanting to deliver is super easy to use, and it's going to be another, we call them tabs, in the KMSAT platform. We are going to truly make this look like it is part of the KMSAT platform. We're going to take our time to make sure that this is scalable, easy to integrate, and existing customers are going to say, "Oh, yeah, of course," and it's easy. Yes, we are going to have to train our existing sales team on this particular additional SKU. It's not expected to be really hard because if you look at how SecurityAdvisor works, it's extremely simple to actually create the connection through the cloud. We will probably add additional sales engineers to support customers to get it actually rolled out. Does that answer your first question there, Shaul? Absolutely. Okay. I get it. Great. And- Did you have a follow-up for Krish? Yeah. I do, actually, for both of you, actually. You've done some tuck-in acquisitions in prior years. What are the puts and takes you bring to this transaction from your prior experience in buying and integrating similar assets, maybe different categories? I'll say this, if this thing is able to generate 40 million in ARR in three years, 80 million that you're paying, is going to be a steal. We'll get to that in three years. Just your thoughts, maybe high-level thoughts of compare and contrast prior acquisition versus this one. We've done, I think, six or seven at the moment. Most of those were, we call them content plays. We've built up a significant amount of integration muscle, if you will, especially with the recent MediaPro acquisition. This is a pure technology buy. The way they did their whole buildup is actually a perfect fit for what we need. They have proven product market fit. They have a first small batch of customers. For us, their R&D team is a great addition to our existing team, and the rest of the integration is going to be relatively simple from an organizational perspective. What we are going to focus on most right now is the technical integration, and like I said, we're going to take our time to do it right the first time. Thank you so much. Good luck. Thank you very much. Your next question comes from the line of DJ Hynes of Canaccord. Your question, please. Hey, good morning, guys. Congrats on the deal. That sounds super exciting. Stu, I wanted to ask for just a little additional context behind the deal. How long have you known SecurityAdvisor? What was the genesis of the relationship? Was it a competitive process? Did you float the idea by any of your customers? Anything along those lines would be helpful for us. Absolutely. We had, and still have, actually, a long-term roadmap with a number of products on there that are all building on top of each other in the sense of features, functionality, and benefits for the customer. As an exercise, earlier this year, we mapped our existing roadmap to existing M&A candidates with relevant IT. We discovered at that point in time that SecurityAdvisor was available. They were contemplating either M&A or a Series B. For us, with the existing patents that they had, this was a very good opportunity to go M&A and integrate that into our existing platform. We believe that that actually gets us to market two years early. On our end, this was practically a no-brainer. Yeah. It sounds like a great opportunity. Krish, a follow-up for you, just in terms of the magnitude of the upsell opportunity. I think we've talked about with PhishER and Compliance+ it being somewhere in the range of a 30%-40% ASP uplift. How would you characterize the opportunity here with SecurityAdvisor? I think, DJ, it's important to understand that, first of all, Stu spoke about muscle memory. I think there's a lot of muscle memory associated also with the ability to cross-sell. For us, we have really proved this cross-sell methodology, right? If you look at the last couple of years, there's been a tremendous amount of cross-sell opportunity on our PhishER product, our KCM GRC, as well as Compliance+. So we're going to use the same true and tested methodology that we have actually built from a sales perspective, a sales motion perspective, and we're going to use that same thing on SecurityAdvisor. As you heard Stu mention, we're taking our time to integrate it right, to build a level of automation, to ensure that our sales teams understand how they can cross-sell the product, and use a lot of the learnings that we have used from the other products from a cross-sell perspective to drive further AR enhancement. I think you have heard me say this before, we are not a bundle company, we are an AR-enhancing company. for us, this acquisition, this added product, will be all about adding additional AR. Now, we are still working through understanding the pricing associated with this product, and in genuine KnowBe4 fashion, it's all about understanding the market, understanding the price point, and ensuring that the price point is accurate so we can cross-sell at a high sales motion. more to come next year. Yep. Understood. Thank you guys for the coloring, and congrats on the deal. Your next question comes from the line of Alex Henderson of Needham. Your question, please. Thanks. Just a couple of quick ones, if I could. You said that there was no cost impact in 2021, but could you give us some parameters around what you think the addition in headcount and additional spending relative to this business would be in CY 2022? That's a great question for Krish. Thank you, Stu. Thanks, Alex. I think one of the key drivers of this acquisition also is not only the additional skill, the capability, but as Stu mentioned, and I mentioned, it's adding an additional R&D center of excellence. For us, that's going to be in India. from a cost perspective, this year, we believe the cost will be minimum. if you look at next year, our focus will be building out the product, building out the integration, but taking advantage of this center of excellence in India to generally help in the integration effort. we believe we're more excited about the revenue growth potential of this business, and we believe the expense impact to be in line with how we think about our future margins that we already provided. No quarterly OpEx estimate for beginning of the year that we can fold into our models, I guess is what you're saying. The second question, if I could, does this impact your net retention numbers, or is this going to be sold independently of the core products? Let me take a stab at that one. We expect our net retention to remain at its current high levels or actually increase. The more modules you have in the account, the higher stickiness you achieve, and especially with a product like SecurityAdvisor. We feel that once we've integrated with their existing cybersecurity software layers, it gets harder and harder to unseat us. From that perspective, we feel that this is significantly widening and deepening the moat in the sense of the competitive space. If I could just throw one last one in. Have you had conversations with any of the 50 integrated partners in terms of their ability or willingness to integrate cross-selling with you? What is their attitude towards the importance of the product for their sell motion? Thanks. Sure. SecurityAdvisor has already made significant inroads. Let me give you one example. CrowdStrike, in their marketplace, already has an opportunity for customers to buy the SecurityAdvisor product and integrate it with their platform, and there are others that have a similar kind of setup. A lot of groundwork has already been done, and we expect that to expand once we have done the integration. Thank you. Your next question comes from the line of Brian Essex of Goldman Sachs. Your question, please. Great. Thank you. Good morning, and thank you for taking the question. Maybe if I could tack on Alex's question. Stu, I think you talked about connecting through other security layers through their cloud interface, partner cloud interfaces, to analyze alerts and identify threats. What is the nature of the data that you're bringing on the platform? Is there a storage component to this, or is this primarily real-time in nature? Are there any kind of economic impacts, either from a cost of storage or acquisition of data perspective on your platform? Yeah, good question, Brian. Essentially, let's just take an example to make it a little real, if you will. Suppose an end user in accounting plugs in a USB stick in a Windows machine. The CrowdStrike platform sees that happening, and it reports that up to its cloud. The SecurityAdvisor has APIs into the cloud of CrowdStrike and receives that alert and immediately can identify that as, "Oh, that is something that is potentially dangerous," and maps that technical alert into a message that goes down either through Slack or Microsoft Teams or email to that particular user in real time, and immediately alerts that user with, "Hey, this is not company policy," or whatever the alert is going to be. There's a micro-learning unit there. There is a certain amount of, call them technical. You can give this a number of different names, right? Let's keep it simple. There are technical bits of information that travel from the end user workstation into the existing stack cloud, which then get transferred over with an API. There is some storage involved there, but we don't think that the storage there is going to be pushing on margins, if that is what you're asking. Storage these days is no longer a component in the actual cost picture. Got it. That's super helpful. Maybe just one follow-up. What about, I guess, data ingestion the other way? Are there compelling types of data or behavior analysis that SecurityAdvisor produces that maybe can be ingested by other XDR platforms for their usage? Absolutely. Within SecurityAdvisor, we are able to create, call them, a virtual security score for a particular user that can be used as input into other platforms like XDR, for instance. You could even go to the point where if an existing user throws off sufficiently high alerts that all indicate insecure behavior, other products can take that as input, and I'm now talking zero trust, to start throttling down the access of that end user to a point where the only thing they can do is do a training, and then only their machine gets released. Mm-hmm. Got it. Very helpful. Thank you. Okay. You bet. As a reminder, if you would like to ask a question, please press star one on your telephone keypad. Again, that's star one. Your next question comes from the line of Roger Boyd of UBS Securities. Your question, please. Hi. Thank you. Wondering if you could maybe talk about that incremental $5 billion TAM and what that assumes around upsell and cross-sell. Recognizing this solution sort of blends the line between security awareness and SOAR, but just wondering, relative to this automated approach of inserting training directly in response to risky behavior, is this an alternative to longer format KnowBe4 security awareness, or is this truly a complementary solution you expect that you can upsell to all customers today? We truly expect it to be complementary. The existing platform is extremely efficient in driving down that phish-prone percentage, which is one of the main attack vectors at the moment. If you can combine that with real-time alerts that correct a user the moment it happens, we feel that that is a very valuable additional functionality that is practically the same value as the KMSAT platform itself, and that loops us toward the TAM. Krish has alluded to the TAM earlier, and I think he can explain a little more how we got to that $5 billion number. Krish? Okay. Thanks, Roger, for the question. The way we think about TAM is actually alluding back to how two things about the vision and the integration of SecurityAdvisor to the broader customer base that KnowBe4 is going after. This product is going to be targeted towards the mid to large SMB market, where we have an extremely large customer base already and a growing customer base on a monthly and a quarterly basis. More importantly, expanding our presence into the enterprise and the mega enterprise space, where a number of these vendors have already built an ecosystem into, and we can tap into that already developed ecosystem that SecurityAdvisor is bringing to the table. The way we actually built out the TAM is using that combination of available SMB, both domestically as well as internationally, and enterprise clients domestically and internationally, with a price point we believe will be attractive for large-scale expansion of this product, similar to what we see with PhishER. Crystal clear. Thank you both. At this time, there are no further questions. Very good. Thanks everyone for making the time and thanks for your questions. We're excited about this new opportunity, and we hope to talk to you soon on our earnings call. Thanks very much. Ladies and gentlemen, this concludes. Goodbye today's conference call. Thank you for participating, and you may now disconnect.
Loading workspace