Welcome everyone. Thanks for joining us. I'm gonna forward to the slide that I'm on. This is the world-class management team that got us where we are. You'll notice that Lars is not on the slide today because he had some urgent family business that took him up north. I'll take care of his sales section as well. You have me for 50 minutes. I'm starting my stopwatch now, and I don't wanna kill you with death by PowerPoint, so actually I would prefer to go through the slides and then open it up for AMA as soon as we can, which is just much more fun. A quick background on our mission, how we got here. This is my fifth startup. The last company I built was focused on antivirus endpoint protection. Despite building a best-of-breed product, we continued to find the infected workstations all the time, literally with millions of endpoints there. We did a root cause analysis, and we found it's really social engineering that is causing the issues with infected workstations and data breaches. It was the human, the employee, letting bad actors in. Cybercriminals were manipulating employees at our business customers using social engineering tactics like phishing to breach into the organization. That was happening globally, large, small, for-profit, nonprofit, everyone is a target. As you're well aware, this recent conflict in Ukraine may devolve into more aggressive cyber warfare. The conflict itself is tragic, but the cyberattacks that we are seeing was exactly what I've been talking about. This is why I started KnowBe4, to enhance the global defense layer, really. Next slide, and that is slide number 7. Today we are driving a brand-new category, which is right next to and additional to the network identity web and endpoint. Those are the known four security layers. The fifth layer is the human firewall or human layer of defense. This slide you haven't seen yet. This is a brand-new slide. For people who haven't yet, I'm gonna turn the sound on my cell phone off. People who are kind of new to KnowBe4, the first two, three years I spent building the platform, making sure it scaled. We made sure that there was a good product-market fit. We worked out the marketing, the messaging, the pricing. Late 2013, early 2014, the first weapons-grade ransomware was unleashed in the wild. It was CryptoLocker. By the way, the evil genius behind CryptoLocker, Evgeniy Bogachev, is still not captured. He is enjoying his ill-gotten gains somewhere. That was the start of the whole ransomware problem, and that's an understatement. If you continue to move further to the right, we had a few acquisitions. Those were content acquisitions. There's SAC, a couple of others. We released PhishER 2019. PhishER was the second product that sits on the same platform. 2020, we hit the $200 million ARR, and we were named after Gartner, who had actually put us on the top right in the Magic Quadrant. Forrester put us in the top right on their, they have the Forrester Wave, which is very similar to Gartner's Magic Quadrant. 2021, if you look at the orange number there, we are pushing $300 in ARR. We're pushing 50,000 logos. We acquired MediaPRO, and that was to get the Compliance Plus product faster to market. In the future, we are gonna release SecurityCoach this year, and that I will talk about in a bit. There is another product called. It's code-named PasswordIQ. It'll probably be different. And that gets you a quick 10-year history in three minutes. You have not seen this slide either. This is my fifth startup. I've had ample time to study dozens and dozens of high-tech companies, and I have essentially I like to think a successful attempt to distill all the best practices from a number of companies that were doing really, really well, especially in the cloud space. You see Salesforce, Google, Netflix. These best practices are woven into our employee development and all the systems that we build in KnowBe4 to scale faster. Here's also something you may not have seen yet. This is slide 10. The top part is it's called. It's a product called Klipfolio. Klipfolio gives everyone inside the organization real-time metrics, hundreds of them, that give both live and projected trends. We manage by trends. You'll hear more about that. There are thousands literally of data points being tracked and monitored, so everyone knows exactly where we're at. The bottom one is something we built in-house. This is a customer health dashboard. To be able to do something like this, you need to have all the infrastructure that sits underneath. Every single customer in KMSAT, in the KnowBe4 platform, is being tracked by machine learning. We can see what they do, we can also see what they don't do. In Salesforce, this little section there, that widget you see, every customer success manager sees this particular widget in Salesforce and can see the health of that particular customer. This is, like I said, in-house production, which means you need a data lake. You need a quant team who can actually put all that stuff in a digestible format and with machine learning. I don't think you have seen this one either. You guys are getting some new stuff here. This is slide 11. I'm assuming all of you have heard and know, even personally perhaps, John Doerr. John has been in the Valley forever and has been evangelizing a particular management technology called objectives and key results, OKRs. OKRs are one of the best practices we find in almost every hypergrowth high-tech company. We have adopted OKRs three years ago. You know, ask Google, ask Netflix, anybody in the Valley uses OKRs, either automated or, you know, to some degree, paper systems, if you will. There are third-party OKR products out there, but we built our own in-house, and what you're looking at is a tool called Envisage, where we quarterly, everyone in the company has their OKRs. Everyone in the entire organization sees everyone else's OKRs. This tool also houses the org chart, which streamlines all the communications. OKRs give you four superpowers. They give you focus, because you do have to look at numbers and how they are measured, because objectives have key results as measured by, those are three magic words, and you have to be able to see where you're heading. Focus, alignment, because if you use OKRs, everyone forcibly is aligned. Tracking, there's stats, there's trends, and then there is stretch. That's the fourth superpower, which is how can you know, continue to expand and make sure your growth is, it actually gets realized. Execution is super important, and OKRs help there. Some of you may have seen this one before, so I'm gonna be really quickly through this one. We have a low penetration in a really large TAM with an open field to keep running. We really think this is a must-have platform. You cannot afford not to do this. However, less than 3% of IT spending is going to that human layer, whereas 50% of all the breaches are caused by that human layer. The disconnect is where we are focusing. Option number three, it is an integrated platform. We have content, analytics, behavioral science. We have AI, and we continue to invest, heavily invest in those areas to create sustainable differentiation, but to further run away from the pack at the same time. Point 4 out of 5, I have built KnowBe4 from day one with one major question in mind. Does it scale? That applies to not only the product, but also the organizational structure, product development, financial decisions. Does it scale? That helped us build an ARR of $285 million, and I'm talking end of Q4 numbers, serving customers of all sizes, and verticals globally. In short, founder-led, bootstrapped, we have a performance and data-driven culture. We have financial discipline, we have an ownership mentality, and the result is best-in-class gross margins and positive cash flow almost from the beginning. Slide 12 is the Verizon Data Breach Investigations Report. You can see that social engineering has always been relatively high, but has only climbed in the last couple of years. The 21, which we hope to see soon, is gonna look the same. It bears repeating, they say 85% of data breaches involves a human element. You have to solidify and strengthen that human security layer, and of course, the best way to do that is the KnowBe4 platform. This is slide 14. The disconnect is staring you in the face. The blue line are the number of reported data breaches. Note reported data breaches. There are a whole bunch of that are not reported, that you don't see here. The orange is the investment in information security. A conservative estimate is $68 billion, but if you look to the right of this chart, network, endpoint, web, and identity take practically all of them of the available budget. There's 3% that's being spent on humans. Basically, huge opportunity. Let alone with COVID and work from home, there is no such thing as the network perimeter. That has died. You're now talking about your employee who really is an endpoint, and that employee has access to several digital endpoints which they all use. That is desperately in need of proactive management because it is a huge attack surface. Gonna have a quick TAM slide. This $23 billion. Social engineering has been with us for a long time. It's not a big company problem, it's not a small company problem. It's global. Everyone is affected it. It is the largest problem that you actually see in security today. We are extremely well positioned to address the market to manage that ongoing problem. Now we built the TAM with a bottom-up approach. We looked at KMSAT, PhishER, Compliance Plus. We looked at SecurityCoach, the new product coming. We looked at amount of seats, and we looked at realized actual sales price. We just added that up, and this is how we get to our TAM. Now international markets, every market has its own maturity level, and every market has its own inflection point when you suddenly see people going, "Is anybody listening? I think the whole world is listening." They have this realization, "This is a real problem. This is not gonna go away. We need to address this. The one thing you will not hear KnowBe4 say is the word solution. We do not position this as a solution. We position this as a great way to manage the ongoing problem of social engineering. Because if you stop doing this, three months later, your problem is back. Which translates into a relatively high for our type of company renewal rate or low churn, if you wanna call it that. Note also that this total TAM is only a very small percentage has been penetrated. Which gets us to the last slide before we go to the sales for first Q&A and then this slide. This is slide 16. We've run this particular bit of math for 7 years now, and it started out with just, you know, maybe a few hundred accounts and then a few thousand. Now we're dealing with 6.6 million users that we run this over, and the numbers stay surprisingly linear. The first test is practically always 30%+ failure rate. 30+% of the initial end users click on the link and fall for the simulated phishing test. 3 months later, it's half. 12 months later, it's less than 5%. These are hard numbers. This thing works. It's never zero because we're still dealing with humans, but you decrease your risk 7 times. That's what keeps customers happy, employees happy because they see, wow. If you ask the employees, and I'm opening it up for a Q&A now, by survey, if you ask employees, "What did you think?" The first thing that comes out of their mouth is, "Wow, how can I share this with my family?" If you get that response, you know you've hit home, and they're motivated, they're engaged. Now it's rinse and repeat. With that, we have a bit of a Q&A for the first part, and then we'll go to the sales side and take the second part. You have a question right there, and there's your mic. How about that? That's a well-orchestrated performance. You talked about two new products coming. Talk into the mic. Sorry. Yes. Alex Henderson, Needham. You talked about two new products. You promised to tell us what they were going to be about. Yes. Didn't do so. I can tell you a little bit more about SecurityCoach. Now, keep in mind that I am stealing a little bit of thunder off Greg Kras, our chief product and cloud officer. He's gonna go in much more detail, but let me give you a bit of a you know, I'll lift the veil. Who here is familiar with a security concept called XDR? XDR. Okay, most of you. XDR takes your existing security layers, basically creates an umbrella. It pushes down the amount of alerts. It creates better visibility. It allows you to block attacks faster because you integrate a number of the security layers, and you can create automated workflows, automated security workflows. We're introducing, with SecurityCoach, a new category called HDR. HDR, we call this Human Detection and Response because what SecurityCoach does, and we will release this second half of this year, is you use the same security layers that the customer already has. We integrate with these products. You have a one-time integrate with your secure email gateway, integrate with your endpoint protection and five or six others. Once a user does something that is not secure, and they do that sometimes, the existing layer goes, "Aha." I'm giving you an example here how this is gonna work. Suppose I have an infected USB stick. All right? I plug that in my Windows workstation. The CrowdStrike endpoint sees, infected USB stick. What happens is that generates an event. That endpoint sends that to CrowdStrike's cloud. We have a connection with that cloud, and we see that happen in real time. We translate that event into, this is insecure behavior. This user needs to be sent through Slack or Teams or email an immediate, "Hey," call it one minute. "This is not secure, what you're doing here." We are able to bridge the gap between, on the one hand, user behavior, on the other hand, there is the training and simulation. Now we sit there right in the middle with real-time security coaching of secure or rather not secure behavior that we see happen in real time. That's a first for the industry, and that is what we feel is a breakthrough. That actually, we are showing that off here at KB4-CON by Greg Kras. That's the man. The other product is code-named PasswordIQ, which is gonna focus on, call it, to keep it simple, compromised credentials. Many people use a username and password in 10 different platforms. The hackers already have it, and they are using those credentials to try to get into other platforms of those user. There's much more to say about that, but we only have 15 minutes, so this is in the works. We are first coming out with SecurityCoach. PasswordIQ comes later in the year. Does that answer your question a little bit? A little. A little bit. Over there. Over there and then over there. We're gonna go zigzag down the line. Thank you. Fatima Boolani from Citi. Nice to see you, Stu. Yes. Thanks for hosting us. Hi, Fatima. I'll stick to this slide. Stu, one of the questions I get from investors a lot is, you know, this concept of replay value. Once you've have had a teachable moment- Uh-huh. Once you've educated your human layer that they shouldn't be susceptible to certain social engineering tactics, how does that chart that we have up there look in month 24 of adoption? You know, mathematically, you know, the leap is pretty profound from 31% failure rate to 5%. Sure. But how does that look in month 24? How are some of the ways we should think about sort of this concept of replay value of the platform once the workforce or the human layer has already been educated, so to speak? The word replay value, we need to define a little bit here because when you say replay, you can go into content, but also into the simulated phishing tests. When Goldman came in, they had McKinsey do a study in our space. McKinsey came back and said, "You know, the only reason, the number one biggest reason that customers leave their security awareness training vendor is that they think the content is stale." That was the number one reason. We have to find some other content. Well, first of all, we took that to heart, every month there's fresh content in our ModStore, so that stale content problem just is completely not an issue. The other thing you need to look at is, bad actors come out with new flavors, new attacks, new, essentially new vectors of social engineering through something else that hasn't been seen yet. If you look at that graph and you extrapolate that further back into or further into the future, you're really seeing this long tail that slowly goes down. I can look at the KnowBe4 stat because we track this. Now we certainly are not your representative account, but our phish prone percentage, it's at less than 1%, 0.5%, 1%. It will go down over time, but there will always be the risk of new users just coming in. They just get onboarded. Yes, they get trained. We find that is very, very successful to have an existing program in place, reinforce it, and make sure that new people that just got hired get thoroughly trained right from the get-go and simulated phishing attacks so they really get it. I hope that answers your replay value. Hi, Joshua Tilton, Wolfe Research. You guys had a target up for $1 billion in ARR. Yes. We still get a lot of questions from investors on whether this is really a platform story. Can you maybe just help us understand of that ARR, how much of it and the implied growth will come from the core security awareness training solution, and how much of it will come from other products or maybe even those that haven't launched yet? That's basically a totally valid question. You have to then first really define the word platform for just a second and truly know, is this a platform? Yes. No. Platforms tend to. Okay, you know, everyone calls themselves a platform, right? This is like you wanna be a platform because you have a better valuation. Let's just call it as it is. What a platform enables users to do is you get from the one hand, and this is now in general, right? Amazon as an example, there's a huge amount of third-party vendors that use Amazon as a platform to sell their stuff. When we say platform, what we are growing into is we have the KMSAT core, and we're adding additional products on that core, literally core platform that have different functionalities. We stick with our horizontal market approach because the products that we build are for everyone. We are not focusing on just like, you know, banking. The more products we are adding, the more strength we feel our platform has. This $1 billion ARR, I've done the math myself. If we'd just stick with the existing products that we have and not any new products, and we just execute, we will get there. It's just a matter of how fast we get to that $1 billion ARR. Yes, we're gonna add SKUs, 1 or 2 a year. Not insanely fast. Other vendors tend to go 6 SKUs per year, and they could ramp up to 25 products. That is not our model. 'Cause we have a whole new category at our disposal. This is, you know, lots of green space. We feel that there is a huge opportunity, and that $1 billion ARR is my personal big, hairy, audacious goal, but it is definitely real. Does that answer your question? Very helpful. Thank you. Okay. Over there, and then over there. Yes. Did you have one or? I did. Okay. We'll hop on back after you because you've been sitting there with your hand up for a while already. That's fine. Go for it. I know. Thank you very much. Brian Essex with Goldman Sachs. I was wondering if, as you've been public for some time now, are you seeing any change in... obviously you're going on market, and you're expanding internationally, and awareness of your platform- Mm-hmm. is increasing. Are you seeing changes in win rates? What is the bottleneck for faster adoption? Is it having a platform or more things to sell on the platform? Is it an elevated threat environment? Is it awareness of, you know, the impact that this can have and the ROI this can have on the platform? How do you think about, pretty broad question, but adoption of your platform- Sure. What might accelerate it going forward? You know, the funny thing is that the board has been asking me this very same question every year. If you look at the global market just for a second, Brian, the U.S. generally is the first large, I don't wanna call it sandbox, but to a certain degree it is because here's where you test it out. You get your product market, marketing fit, you get your pricing done, you prove that it is a viable market, and then you export that to usually first England, then it flips over to Europe. At the same time, Australia is one of those markets that follow soon. Every market has their own maturity level and their own inflection points. Usually, you have to start with PR because, you know, let's just face it, when we started 10 years ago, security awareness training had a very bad reputation. It's like, "Oh, that doesn't work," and, "You can't patch stupid," and, "We do this for compliance reasons," and, "It's checkbox and we're done," and, "Gosh, I hate this." Because generally, IT was tasked to do this. IT people are very good with computers, they're not that good with people. Are you now gonna ask an IT person to train the end users, which are already kind of, sort of adversarial to begin with because IT is always causing headaches, quote, unquote, quote, unquote. When I started, I was going straight into the teeth of, yeah, that doesn't work. End users are, okay, I'm not gonna use the word stupid, but they're not smart. You know, I was going straight into a vested scene where I said, "Listen, that's a huge missed opportunity." If you do this right, and you get them on-demand, engaging, interactive training that they actually understand and they truly, "Oh, wow," and I can also use this at the house, and then you combine that with simulated phishing tests that reinforce that training, then suddenly everybody goes, "Wow." Then you show stats like that, and they go, "Actually, we should do this." Now that actually we should do this is moving through the globe, every area in turn. Japan is a great example. They are nowhere. But this is why we start with PR, PR. Evangelizing. This is really an educational step that we need to intentionally do. To a certain degree, to answer your question, the faster adoption is driven by our capability to expand as fast as we can. We do that really step by step. We have a beachhead, we get there, we get viability, and then we step to the next one. Could we grow faster? Well, in this year, we are heavily investing in international development of those markets. We expect international to be a larger percentage this year than it was before. 7x really is a global TAM compared to just U.S. We're getting there. Helpful. Okay. Thank you. Okay. Now back there. You finally get your chance. Sorry about that. Hey, how's it going, guys? Hamza Fodderwala from Morgan Stanley. Good to see you again, Stu. Sure. Obviously, you talked about, you know, pretty large TAM. You're a leader in this, you know, growing market opportunity, nearly 50,000 customers, millions of users. I'm wondering, you know, from that installed base, if there's an opportunity to perhaps crowdsource a certain amount of threat intelligence. I think last time when we spoke, you talked about over 30,000 emails were being reported through Phish Alert on a daily basis. There's obviously a lot of copycat solutions out there that are trying to compete in this HDR market. How do you think that the data that you're getting from that install base allows you to perhaps have some sort of self-reinforcing mechanism, whereas Mm-hmm. You can constantly update and refresh. Absolutely. your solutions. Totally. For instance, we do this as we speak, in a few areas. We are working on expanding that dramatically. One good example is the ML in PhishER. We do get a huge amount of emails that are suspiciously reported to us daily. By the way, everyone, this is a unique data stream. Nobody gets all the emails that were missed by the existing filters. Think about that for a moment. What we see was missed by everybody else. We run that through our ML, and we then get an identification of, is this, you know, good or bad, ham or spam. That's only one thing. We do also see millions of phishing tests being sent out and click-through rates. We understand a huge amount of the nitty-gritty of what people fall for, in what industry, in what country, in what language. Those bubble up as well. We are actually sitting on a vast trove of data that we are running ML on. Greg can probably get you a little more detail in his presentation on exactly where. We do have a few slides about sales. Would you let me step through those real quick, and I'll pick out only the ones that are, you know, fresh and new, and then we can do a little bit of Q&A on the sales side. Is that okay? Yeah? Okay. This would probably cover every IT company in the U.S. There's nothing new here, but there are a few things that differentiate KnowBe4 over your general SaaS company. There's at least 10 ways to drive leads in the organization. We operate with service level agreements between sales and marketing. We know the ratios that a sales rep. Well, let's work it back. We know close ratios. We know the ratio that a rep gets in from opportunity to close. But we also know the demo to the opportunity ratio, et cetera, et cetera. All the way to the beginning, we know that a rep needs X amount of leads to get a demo. We've worked this back, and we know exactly the amount of leads a rep needs to make their quota. That is the service level agreement. We run the whole organization on dashboards. Every rep can see all their numbers and the numbers of their team. This is really a marketing engine, an inside sales engine, and then the customer success engine, which obviously, if you look at the total numbers, customer success generates more revenue than direct sales, because with this type of scale and, you know, pushing 50,000 logos, that is how that normally goes. I'm not sure if there are any questions about pricing and monetization. The simplicity is really simple. We charge upfront for all your users. There's only one exception. That's KCM. That is the people who do the compliance, so compliance officer. That's per seat. One fun thing to mention is Compliance Plus. That is our most recent SKU. They did better with Compliance Plus than they did with PhishER, and PhishER was already a very successful straight up into the right product launch. We're very happy with the Compliance Plus product launch, and we expect similar traction with SecurityCoach later this year. Part of the question you had there was, how are you gonna sell more to your existing customer base? Here's some examples. The most left bar, that's already a couple years ago, but SMB and Enterprise have kind of evened out to about 50/50 in the sense of dollars. If you look at logos, 12% of the current logos are enterprise sales, and enterprise is 1,000 seats and up. Like I said, international is a huge opportunity. We have 12 international locations now. The inside sales motion is very close to what we do in the U.S., but localized. Last, but certainly not least, we have invested in our channel partner base. We have a channel portal. We are seeing a major uptake in channel partners investing in our platform in the sense of training their reps and doing marketing to their existing customers and generating net new business that otherwise we would never had. That gets us five or six minutes for Q&A related to sales. Yes. Hey, Stu. David Hynes from Canaccord. I have two questions. Sure. The enterprise deals that you're winning today, what% of those folks are first time security awareness training buyers? The enterprise space breaks down in a couple of different buckets. Some of them have done this in-house, and it gets too much work. Building your own phishing platform is a huge pain in the butt, so they don't wanna do that. That's one bucket. There is someone who has tried an existing vendor, and they understand, yes, we need to do this. There are one or two. There used to be an email security provider who used to be public and who is no longer public. They acquired one of our competitors, and then they kind of gave it away as it's part of a bundle. You do that for a while, and then you go, "Yeah, but I need more." So we get a bunch of those. There are people, surprisingly enough, who haven't done anything, but that contingent is shrinking rapidly because everyone understands you need to do this. It breaks out in different buckets. We win most of those. Sometimes when it's for free, then all right, they take the free, you know, offering for a year, and then they come back because they say, "Mm, yeah, not what we need." We really have a whole series of really strong enterprise integration features, like direct integration with Active Directory. Is that me, or is it something else, that sound? No? Okay. We have recently released. Actually, write down the word SCIM, S-C-I-M, and Greg Kras there is going to explain what SCIM is. High-level enterprise integration supported by Microsoft. That's the short answer on the enterprise side. Yep, makes sense. Okay. Krish was always super adamant that, like, we will never do bundling, right? We hate the word bundling. That was when you had, like, 3 SKUs. Now we're getting to 6. We're gonna have 7, 8 at some point. Does the philosophy change on à la carte pricing at some point? Just kind of what's the thinking internally? No bundles. We prefer to enter the account with the security awareness training platform. Yes, I keep calling it a platform because I really believe it is. There are additional problems that these customers run into. They're not always the same problem, but our CSMs are very, very good in staying in touch with that account, understanding what they're running into, and they say, "Hey, you should look at..." Then it might be PhishER, or it might be Compliance Plus, or it might be SecurityCoach. We are not... You know, if you survey, if you actually survey IT administrators, and if you ask them, "Would you buy a suite, or would you prefer your favorite point solutions?" 75% buys the best tool for that specific goal. They don't want a suite. They don't want a bundle because they know that in that bundle might be seven products, but two or three of them are crap anyway, so. Okay, I'm just telling you as it is. You get straight dope. Yes. Hi, Stu. Rob Owens with Piper Sandler. Can you give us your thoughts around breach disclosure requirements? You know, I guess dovetailing a little bit earlier on Brian's question about potential catalysts that could drive acceleration from here. You mentioned that 50% of breaches are the human element, so Yep. At least could be a very good thing for your business. Mm-hmm. Maybe talk a little bit about, you know, the catalyst it can provide. Yes. Data breaches are a huge risk. I can stop right there because everyone here understands what those risks are. The regulatory environment actually starts waking up to this, and there are more and more stringent requirements. SEC just a few days ago was making noise about data breaches need to be reported in 4 business days. Directors need to be informed and need to be focusing on this. It is going our way. Data breaches as a particular risk, once these breaches are out there, bad actors they basically share all those breaches. We are in the process of getting access to that dark web huge database of all compromised credentials, and we can use that in our product as well. The risk of a data breach is a major reason why you would want to deploy a platform like this. Did I answer your question? Or if not, follow up. Yeah. I guess to a degree, you did. Looking at what might accelerate your business from here. Well, data breach is certainly a tailwind for us and regulatory development. The White House literally saying a few weeks ago, "Hey, train your users to recognize phishing attempts," that is huge for us. Vladimir Putin with his horrendous Ukraine crisis is another thing that makes people aware that you do need to prepare for a cold cyber war that slowly starts to heat up, and that is also tailwind for us. I could keep on going for, you know, for a couple of minutes, but there are major secular reasons why what we are doing is still early days. I guess second, maybe talk about your enterprise sales motion as you're moving up market. Obviously, you built a heck of a flywheel type of program that got you into the mid-market and low end of the enterprise. Yes. Talk about more of a direct element, I guess, and. The what element, sorry? A direct element and how you think longer term about targeting enterprises. Okay. We actually are, as we speak, executing on something called ABM. That's account-based marketing, where we have already identified a whole series of large enterprise accounts that we are actively going after instead of what we used to do, horizontal marketing to all IT, relevant IT people. If you look at the U.S. enterprise market for a bit, depending on who you talk to, there's about 15,000 really large accounts. We are in 5,700. So we have made major inroads in the large enterprise account. I think, Ken, 20% of the Fortune 500 is now already a customer, so that's a good start. We're not satisfied with that. We wanna get to 50%. What I like about our customer base is I like we have a large amount of SMBs because that is a very reliable cyclical business with a very high renewal rate that gives us a whole, you know, a very high level of stability. Whereas those enterprise deals, when you lose a $1 million deal, you know, that hurts, and it hurts real bad if you have nothing else. The SMB plus enterprise, 50-50 in dollars, but 1,288 in logos is perfect for us. Will enterprise get larger? Yeah, it will probably be 15 or maybe 20%, and that's a mix we like. That is where I need to call it quits because Randall is saying someone else needs to grab the podium. Which is indeed Greg Kras, who runs two of our sectors. He runs product, and he runs cloud. Product is customer-facing, and cloud is our internal infrastructure, so he sees both. Here he is. All right. I think I can take it from here. Yeah. Okay. You didn't steal all of my thunder. Good. Okay, good. I do get to talk a little bit about SCIM, which is. Good Everybody loves to talk about SCIM. Step up and take it away. All right, as Stu said, also, good afternoon, everyone. As Stu said, I'm the Chief Product Officer and the Chief Cloud Officer. One of those things that doesn't match the other per se, that's the Chief Cloud Officer. That means I run the internal IT systems and the business application systems at KnowBe4, which allows me to maintain a perspective of our customers and what the customers are going through and what a good vendor is and what a bad vendor is. There was a question about bundling. As Stu said, no bundles. As an IT buyer, no bundles. I loathe those. I have a lot of products that sit on the shelf because I don't need them, and it always puts a sour taste in my mouth, and it puts me on that list of who am I gonna migrate away from this year. I've got five of those already planned for next year, simply because I go, "I must be paying more than I should be for this because I'm not using the whole platform." From a product side, I want a product that is a no-brainer where the customer is getting what they're paying for, they're using that, and they don't. You know, they want those additional features or those additional SKUs that we add on to the platform. I will call it a platform as well. I have my reasons for it, because there is a lot of information behind that. A little bit of a quick introduction to the actual product lines that we have. KMSAT, that's the base platform. That's what we'll refer to where we keep all of the information about all of the users, their history when it comes to training, when it comes to phishing, the culture scores, the risk scores. There's literally billions of data points that we have now about the users inside of KMSAT, and that's part of that platform-esque idea, is that that information can be used in other places by other SKUs. Going down the road, we get to PhishER. PhishER was launched in 2019 as an additional product. When we launched it was a SOC tool. It was something that was designed for the security operations center. A little bit of an oddity there, because from a product philosophy, everything that I make, everything that my team works on inside of KnowBe4 is about enabling users to make smarter security decisions every day. This is my end point. This is what I have to focus on. I came from the security space, 20 years doing this, antivirus, patching, network, all of those other items, and it was very difficult on KMSAT to just keep in my lane, which is the human element, because everybody wants to just protect the human entirely and make it to where the human can't do anything wrong. As you can see from the breaches, that's the end result is that if you can get into and you can get something in front of the human, that's all it takes. Just get it in front of the human, and they will violate all of the different rules and things that you've put into place, and they'll take down your network from the inside. Whether they meant to or not, that's what's going to happen. Your technology controls will only get you so far. PhishER, like I mentioned, is for the SOC team. What brings the SEC? How does this make the end user have smarter security decisions when I have users reporting phishing emails to the SOC team? Where does that come in? We were able to bring that back around into the KMSAT platform about 2 years ago in the concept of PhishFlip, where you can take any phishing email reported by an end user and look for other instances of that and turn it into a simulation for the users that already received the message or for users that had not seen that message before. Now I am leveraging. The better trained some of your users are, the more likely they'll protect the other users that aren't as protected. In the same vein, they are helping train those other users to spot things, exposing the information to the end users of, "Here is your phishing score. This is what you've done. This is how well you've actually reacted to phishing emails," starts to get into a game. You start to actually realize, "Okay, I'm actually doing okay at this," or, "I need to be doing better than this." Nothing quite like social pressures to do better than what you could do. PhishER has actually now closed the loop on that product, and it is now part of making users make smarter security decisions on there. Compliance Plus was a content-based SKU primarily. We have a lot of customers that wanted additional training in other areas. Obviously, the security awareness training, we've got that. We are referred to. When a competitor doesn't wanna say us by name, they just refer to us, "The one with all the content." That's great. John Just, content guy, just walked in. I apparently said too much about content, so I think he has a slide later on. He'll talk about that. Because the users like the content and they like the fact that we have multiple different publishers that we've built up over the years, it makes it all look and feel a little bit different. When you're telling everybody the same story, which you may have to do, you can do it in a different fashion and not have to go to a different vendor. It's all right there inside of the platform. KCM, which is our governance, risk, and compliance kind of a backwards item there, but now ties in because we're selling to the compliance group inside of the organizations. This is where the actual frameworks can be deployed in organizations, and they can start to meet those regulatory requirements that are continuing to expand and track that. We're doing integrations actually right now on where we are taking the information from Compliance Plus, or sorry, from KCM, and integrating that into the KMSAT platform, so that the results of the activities done inside of KMSAT can be used as evidence and proof inside of your KCM platform. A few different things there. Now we'll go into the future of things. This seems to be everybody wants to know how are we gonna do more things. SecurityCoach. I have a few more slides, so I'll be done with this one. SecurityCoach, short story on that one. We had a roadmap of things that we wanted to do, and we wanted to have more insight into the actual behaviors of users. Phishing was wonderful. It's so easy to go ahead and just say, "I'm gonna send you a phish, and if you click, I know. Whoops, you clicked." It's great. People that have bad passwords. Well, it's a little bit more difficult to walk around and say, "Yeah, Ken, can you tell me your password? I'll tell you if it's good or bad. ABC 1 2 3. Okay, two things about that. One, we need to talk a little bit about the fact that he shouldn't answer that. Two, the password was bad. Now, if I train him not to give me his bad password, well, now I have a problem. Good, he didn't share the password, but it's a crap password. So we need to know more about the actual behavior of users that shouldn't be going on. SecurityCoach is where I'm able to get that information. So we have, as part of the acquisition, we've got a pre-built collection engine with many integrations, with many relations with security vendors in the space, so that I can see all the times that users run into security controls that are protecting them. That's okay, I'll do an overly dramatic representation of that. Airbags. Airbags are a wonderful thing. How many people have tested their airbag in their car on purpose? That last part there is important. Not many people really wanna try that out. Think about that when you think about security controls in the organization, things that stop you from going to malicious websites or stop you from possibly putting in that USB key or attaching a certain type of document or putting in a password token on the wrong website. Those are all airbags that are going off and protecting the users. The user doesn't know it, though. It's not quite as bad as a 200-mile-per-hour impact with a balloon in your face. It's also something I don't wanna do to your users. SecurityCoach lets me tell the user, in a nice way, "You just got your ass saved by a security product." Because all of them have some failure mode. They all have some level where those will not work. It's a new website, it's a new threat. It's a risky behavior. SecurityCoach is there to target that, to let the user know, "Hey, you keep on bouncing off guardrails. That's probably not the best way to go through life. If you stay more centered, chances are that if you start to stray off and something hits you, it's less likely that you're gonna go right off the edge with it." That's my way of thinking about SecurityCoach, is to see those other behaviors that I could not see in the past. Which takes us to PasswordIQ or code name PasswordIQ, which is focused around just the fact that I can't ask everybody that work in here, "Are you using a password that was in a breach? Have you changed your password recently? Who here has the name of a pet or a loved one in their password?" If you feel like I'm talking to you directly, I apologize. There's some training we have on the things you should do. But I need to stop asking that question of the users. I need to tell the users. I need to show the users. I need to give that to the admin, and I need to have more insight to those types of things that are occurring. If there's a breach that occurs and, Ken, I'm gonna pick on you again. Ken shows up in a breach, and there's the, you know, four-legged friends breach comes up, and he's got a password on there. Okay, great. Later on, there's the large format photography breach that comes out. Ken also, because he likes to take really good pictures of those four-legged friends, shows up. He's got the same password on there. Well, that's an indicator that perhaps he needs to stop using the same passwords in places because it's easy to guess, or it's just got a different character on the end. PasswordIQ, hence that's where this name came from, is it's starting to be more intelligent about information about breaches and the password uses of people. Again, the end goal being smarter security decisions by people. I'll get to questions here, and I promise I will explain SCIM, just because that's just a goofy one. Let's go next slide, please. The clicker. Oh, I get the clicker. Oh, this is so novel. Okay. Used to having people do this for me. Okay. On this next one here. Well, great. I could actually just talk about that. This particular one shows the actual progression of awareness assessment of your users when you first get them, training the users, phishing them, analyzing that data, integrating into the security stack, manage and remediate. These are kind of the circle that we go through. The way to look at it is I'm particularly a fan of the bottom here. It shows over the life cycle of our products that it's admin pushing it on to the users. That's classic security awareness training. The old thing that Stu mentioned, everyone had a bad attitude. You have people that call them IT professionals that are dealing with users. Users are a problem. That's a good way to start off any conversation with someone that doesn't like someone trying to teach them something. It doesn't really go well. You have users that are looking at the admins, and the admins are in their ivory tower, taking away all the cool little software features that they had and making it difficult to log in, and now I have to have a phone to log into my computer. There's a bit of friction there. It was admins pushing training down to users. As we release things like the PAB, you start to get a little bit more feedback. Users are actually sharing some information. You get to the point where you're actually using the information from the users to train the other users. There's a little bit more of a teamwork culture. When you find organizations that have very, very good phishing results and very good training results, there's actually a generalized culture of security, not an enforced security. They're thinking about it. That's what we wanna get to. The extension of the platform is into HDR, so definitely based off of XDR, people know that. We are extending it even further out of the technology into the human side, and that is where we, and why we purchased SecurityAdvisor, because it allowed us to get into that market a little bit quicker. How do we get into and grow faster from a SKU perspective? We find someone that's doing something that was in alignment with what we were going to do and say, "That looks good. Does it work? It works? Great. Let's go ahead and put that together. As part of my roadmap discussion tomorrow with all the customers, I'll be talking a little bit about SecurityCoach and doing some surveys over our customer base to find out what integrations are most important to them. Don't wanna spoil the surprise, so don't tell any of our customers, but there's gonna be some slides where I say, "Which technologies are you using right now so that we can prioritize which ones we're gonna integrate with?" All the answers, I've already integrated with them. So I just wanna be able to go ahead and make sure that there's not a lot of people that put other, but everything that's on there that's being fed as part of that poll, they've already been done. So it's a little bit of a, you know. I'm making sure that it's easy for me to meet the expectations of what are we gonna integrate with first. This is, by the way, the list of those integrations that we have that came as part of SecurityAdvisor, and we've been working with all of these different vendors now to ensure that we can still get the information. What are we going to do? When we come back and actually feed information to a user that says that they did something that they shouldn't have done, bouncing off that guardrail, testing the airbags, whatever analogy you'd like to use, we wanna make sure that those messages that come back are relevant and actually something that makes sense to them, so we're building the content around that. It's gotta be brief. I don't really think that people wanna get an hour-long training assigned just because they ended up on a website that's known to host malware. I think it's better just to go ahead and say, "Hey, how did you end up there in the first place? You know that you can't just trust everything on the internet." These are the integrations that we have that we're continuing to add more on. Based off of the feedback from the survey tomorrow, I'll go ahead and look at adding in more integrations because a lot of these actually have a lot of information that I can use about the behavior of the users, and I don't have to build agents. I don't have to build software that I have to deploy. I can just take that information, pull it into KMSAT, and then use it to train some more of my AI models that I have. Expanding into the security budget getting more, this is where one of the things that Stu pointed out earlier was where all the IT spend is right now. It's in those technology solutions. That's held usually by the security operations center. They hold that budget, and they're always looking at that technology of like, what's the best and what's the greatest out there. It's also a group that is plagued with alert fatigue, 10,000, 20,000, 50,000 alerts constantly coming in. Every one of those is our users bouncing off of those guardrails. It's difficult. What are you gonna do with that? Remember, we're talking about people that don't really talk to people or want to talk to people or have the right way of doing that, and how do they do it en masse? If we can get the SOC to like the product, which we've done very well with PhishER, we can get the SOC to say, "You know, we have all of these other these tools. Maybe we could stop getting the alerts of every time these things are working and reduce the amount of times that we do that." If we have a 5% failure rate on this too, let's say a 1% failure rate on your secure email gateway. That's not the number. It's closer to 5% if you look at what we see in PhishER. Let's say only 1% of the time it misses a threat. Well, if you can't make that any better, just how about less times that you actually bounce off that guardrail? And that'll reduce your risk. In giving that to the SOC and saying, "Reduce the amount of alerts that are coming in," reduces the risk and makes it where you can actually spend more time looking at the alerts that are coming through. That is where we're going with SecurityCoach. PasswordIQ. Apparently, I just need one slide. I could just talk to the slide all day long. This is a little bit. This is a preview of PasswordIQ, which actually does exist. It is in beta with customers. We have 50 customers that are actively using it. We are continuing to add more into the product as we've done it. This one worked actually really well. I'll give you a little bit of a feedback on that. We gave it to the 50 customers. They went, "Okay." They started using it. They addressed the users that had bad passwords and said, "All right. Great. So now what do we wanna do with this?" We went, "Wow, that's good. It's just working." It's only when new customers come in that they have some effect to that, which right now in today's market, I would imagine it's fair to assume a 20% staff turnover in most organizations, which, by the way, is the number one way that longtime KnowBe4 customers don't get to a 0% phish-prone percentage is because 20% of your staff comes in, a third of that staff fails their first phishing test. Y'all are more the math guys than I am, but if you were to go ahead and say 20%, 30% of 20%, somehow that stacks up and you end up with somewhere around a 5%, call it 7% phish-prone percentage inside of an organization. I think I did that math right. Thank you. All right. I wanna give time for questions, but the first one I'll just say SCIM, System for Cross-domain Identity Management. I know it's. Everybody was dying to hear about that. It's just a feature that we've added into the platform recently. I say just a feature. Our customers are adopting it in the thousands, right now, because it makes it easier to automatically synchronize users through things like Azure and Okta and OneLogin, Ping Identity. They're all just basically rolling on at the moment. It just makes it easier for them to make sure that we know about those users, because the sooner we know about the users, the sooner we can enroll them in their mandatory onboarding training and get them into phishing. With that, let's go for questions. All right, we'll go with you. Get a mic. Thanks. Alex Henderson again. I hear what you're saying about the PasswordIQ product, but then I think, gee, if I'm a hacker and there's a database with a bunch of passwords in it might be a pretty interesting target. Can you talk about the security of your platform's ability to have a bunch of passwords in it that might be an attractive target, and why anybody would want to build that database that then could be hacked and utilized as a source of malfeasance? Ooh, wonderful word there. Thank you, Alex. You do sound a little like Brian Jack, who's our CISO, and Alessio, our privacy officer, and the voice in the back of my head going, "This is a bad idea." PasswordIQ is definitely architected around on-premise. There's a component that's on-premise that needs to actually look at none of the passwords of the customers or the customer site ever gets to our environment. We do not want that. We will not be putting that there. It's part of the reason why we're still working on additional functionality on PasswordIQ, because not everybody has an on-prem anymore. That's something that we're looking at. If you're purely Azure, then you don't have an on-prem store of passwords that I can talk to, so we'll have to do something else around that. The answer is we just don't have that problem. We maintain databases of passwords from breaches. Any hacker that's worth their salt, they have those databases. That's where do you think we get them from? One other question, the comment about SCIM cross-domain that sounds very cross-domain in cloud-native environments. I don't really think of you guys too much in that kind of arena. I think of that as sort of more Kubernetes machine-to-machine type stuff. Can you clarify whether you're doing anything in that or whether this is just feeding information into like the Okta cloud? What that is when you talk about cross-domain, their SCIM is an architecture that was originally one of the major stakeholders in SCIM as a protocol, SCIM as a protocol by the way, that Microsoft chaired, and they wanted a standardized method of sharing user information to other platforms. By supporting SCIM in our platform, any identity provider, Okta, OneLogin, Azure, they can share their user information with us so that we can do automatic provisioning. It's just quality of life for customers to have that. All right. Thank you. Brian Essex from Goldman Sachs was wondering on PasswordIQ, how you anticipate the dynamics of penetrating the market with this platform as opposed to, you know, password management tool. We're seeing like, you know, personal password management companies start to gain enterprise traction, enterprise class, you know. How you think that would be perceived differently and what the opportunity might be for one versus the other? Password management tools are we're definitely starting to see more adoption, which we're very happy about seeing that. That means that some of our training that we say over and over and over, "Please use a password manager," is starting to work to the point where users and enterprises are starting to do that. Password managers have some insight into what good passwords are and what bad passwords are. However, they're not an end all be all as far as making sure that the user's not sharing their password with other locations, and it's gotta be in there in the first place. We did talk about internally acquiring or building a password management tool, and it starts to become. It's more of a tool for the end user. It doesn't actually educate the user of what they're supposed to be doing. We said, "Nope, we'll let the password managers do that, and we'll just establish really good relationships with those organizations." 1Password is one that I personally have a lot of conversations with about best practices and things that they should do. To go ahead and guide users to proper usage of those things. Helpful. Thank you. Hi, I'm Hamza Fodderwala, and thanks for the presentation. I had a question about the SecurityCoach and the other side of things. Mm-hmm. It seems like to really make that product work, you need to have a comprehensive view of the security posture for that end user, right? Wherever they might exist within the organization. How long does it take you to have that view of the end user, right? Figuring out, for example, like, hey, like Ken's security posture is really bad, but Brian's is really good, right? Mm-hmm. Like, Ken's a high-risk user, so let's watch him. Does that happen after, like, the first phishing campaign? Does that take a couple of years to really get that granularity? Oh, no. Oh, God, years. I thought you were gonna say days. The answer is minutes. Many of these security tools, because we're using information from existing endpoints that are in the organization. I say endpoint, I always think of CrowdStrike. It's just 'cause that's one of those easiest integrations that we've had, and we have a good relationship with them, and that's just there. Some of them are gateways and perimeters. When they first enable the integration of the logging into our platform, there's a history that comes over. I believe that for Check Point now, on average, it's 90 days that information is kept, so we already know right off the bat. In fact, that's part of the onboarding process of SecurityCoach. You may be wondering, like, onboarding process, you haven't shipped it yet. Well, we are building the onboarding process now to actually make it to where when a customer says, "I wanna try out SecurityCoach," they can put in their integration, and it will come back immediately with, "Okay, here are the top 10 users in your organization when it comes to security alerts that they've generated over the last 90 days. And here is the remediation options that you can use to catch those when they continue to happen." The important part of SecurityCoach that sets it aside from other solutions as well as our own solution is that it's one thing to come to someone well after an infraction. It's another thing to come back in real time when they're probably remember why they did that or how they got there or why they did something that would bounce them off of the guardrail. That gives us our coachable event right then and there. As long as the customer has some of the, Where's that integration? As long as they have some of these items here that are set up and monitoring for security, which I would put quite a bit of money on the customers having at least one or two of these types of tools in their organization, we'll be able to start showing them what we would do in their environment in a matter of minutes from the integration point. Maybe to follow up on that, just to be clear. The integration comes with 90 days of logs from the partner that you are onboarding. Yes, I'm using CrowdStrike. Okay. CrowdStrike has 90 days that when they say, "Oh, you wanna enable another company?" Splunk, as an example, you buy Splunk, and you attach to CrowdStrike, you're gonna get 90 days of history over into Splunk, which is great. Now you have umpteen thousand events. We do the same thing, and we're gonna come back and like, "Okay, these are all types of events where the user can be trained. These are all things where the user is responsible." We wouldn't want to say, well, in a managed environment, tell the user you need to patch your workstation. The user doesn't get to patch the workstation. That's someone else's job. We're going to, as part of that first integration, come back and say, "Here are all of the elements that we find where the human could have... If the human knew better, you would never have had this occur. Okay. Hi, Madeline Brooks from Bank of America. Just one question on the PasswordIQ. For the beta group, is that a mix of enterprise and SMB? If so, what has been the feedback, and does it differ from both the groups? It's a mixture between the two. I don't know the exact split. We didn't target one size for the other. The feedback on it was very good. It was, they found the users that were doing things, and that it was actually easy enough to go to the user and automatically through the platform, the platform's got groups that are set up that say, "Okay, does anybody have this type of transgression? Please go ahead and send this type of training or message over to the user." Easy for them to actually roll out and use, from that standpoint. The biggest item, though, is we wanna make sure that we actually have that on-prem, in order for PasswordIQ, as it exists in that beta, they have to have the on-prem domain controller, and that, thankfully, is going away. More and more organizations are moving to purely cloud identity management. PasswordIQ is going to have a lot more in it when it actually does launch than what it does just from that demonstration that I had there. Got it. Thanks so much. Yes. We're gonna make sure that Randall gets all of his steps in. You're throwing it to me. I'm not that big of a catch. Thanks, Greg, for doing this. Just with respect to the monetization model around PasswordIQ, I just flipped back to slide number 20, and I noticed that it's one that's still sort of missing from that page. I'm curious if you can, you know, certainly there are some features that you are looking to add to PIQ, but I'm curious if you can give us some parameters as to what the monetization model would look like for a solution like that because it seems like it would be more unique relative to the rest of the portfolio. It's going to be priced by employee. That much I can guarantee you, just because that is the way that we license things. We do the land and expand model, but we land large. That's. I took that directly from Lars' deck. He likes to say that we sell into the entire organization with everything. Same thing applies when we do go out with PasswordIQ, just like SecurityAdvisor. It'll be licensed by the employees. As far as pricing, I don't have any information on what that pricing would look like. Did that answer the question? It did. Yeah. Okay. I was just curious because, you know, there's probably two modalities, either on a user basis or a volume of password basis. It's definitely gonna be user-based on this one. One of the things on PasswordIQ is just to go all the way down the road of some of the conversations that we're having on it because I do have more growth to do on that. I wanna engage the user more directly on there, where the user is actually interacting and seeing more value for themselves. As we continue to go and more time is being used in the platforms and our customer base becomes more mature, they're looking to see what's the next step? What do I get to? You get through the idea of awareness, just teaching that something exists. Then there's you can lead a horse to water, but you can't make him drink. The same thing goes, you can teach a user not to click, but they're still gonna click, right? Or they don't pay attention, or they don't take it to that next level. That's where PasswordIQ is kind of focused on, is that next level of getting the users to actually go above and beyond just their passwords at the office, but what are their passwords in their other life? Because if I can compromise you at a personal level, that's something that most people don't really like the idea of being compromised. But at an organizational level, it doesn't matter how I compromised your end user. Everybody's, you know, the network is everywhere now. The home computer is oftentimes used as the work computer. Now, large organizations have the luxury of locking it down to only being used in work computers, but that's a small percentage of our customer base. If we look at those SMB markets, anything under 1,000, they're using whatever computer they can get their hands on to do their work when they're at home because that's the way things have moved. All right. I think I've got time for another one until someone tells me I don't have time for another one. Yeah. It's the last one. All right. This is the last one. Make it good. Thanks for the question. I just wanna go back to SecurityAdvisor for a minute. When we spoke to users about the product actually before you guys bought it, they made it seem like it was an either/or decision, like they would have SecurityAdvisor or KnowBe4. Can you kinda just help us understand how your customers are going to consume SecurityAdvisor? Do they also need to have the KMSAT offering, or do they just buy a module called SecurityAdvisor, SecurityCoach going forward? No bundles. They're going to buy KMSAT, and then KMSAT is going to actually. Again, I'm not trying to have to use the word platform, but as a platform, SecurityAdvisor from a technical integration point is leveraging the existing KMSAT platform to do all of the user knowledge as well as all of the history tracking of the behaviors of the users. The components from SecurityAdvisor at a technical level are a separate technology stack that then feeds back into the APIs that we built into KMSAT, and we just create automations around those. It's the customers will have to have the KMSAT. Specifically, they'll have to be platinum and above in KMSAT because they need to have a minimum amount of content. They need to have the automations there. They need all of the integrations. The SecurityAdvisor will sit on top of that as another component, which also means that those smaller organizations that may not have any of these other tools there, they're not pressured into buying that. They may not need to use it. As far as SecurityAdvisor's pitch of, "This is all you need. You'll be able to do this without having to do any awareness training," that's that was their marketing. That's how they were gonna go after it. The correct answer is you gotta have some level of training. You've gotta have larger items inside of there. Microsoft, I'll end off on this. I think it was a couple months ago. Microsoft has simulated phishing in their platform at one of their subscription levels, and they've got some training that they acquired from Terranova. John, you're nodding. Yeah, it was Terranova. They were asked in a conference, well, what about being able to have additional content or do additional simulations? Microsoft said, no. If you want to be able to do that sort of stuff, you need to buy KnowBe4. To me, I'm going, oh, that's pretty much what I want to hear, is when Microsoft says that's beyond the scope of what we're going to do here. We're checking a box. You want to go ahead and actually fill the box, KnowBe4 is the way to do that. For that reason, we have a very good relationship with Microsoft. In fact, part of that good relationship is why the SCIM integration has been something that's taken so much time, and why Stu brought it up is they couldn't release the feature. They held it for almost 2 months because it had to go through. They knew the amount of customers that were going to jump onto it when it was first deployed. The regression testing that they need to do on their side was significant. So they had to go through a bunch of hurdles just to be able to allow us to release that feature. I think in the first week we had over 600,000 end users that were on there, and we didn't tell any of our customers that we'd released the feature yet. That's just the ones that found it. Adoption is quick now with this many customers. If I'm a platinum user, do we have any idea what the uplift my price would be if I also tack on SecurityAdvisor? I do not know what that is. It's going to be. It's not free. Ken. Pricing will look similar to KMSAT. Oh, there we go. Okay. Now he's my handler for these things because I would just come up with a number. Pricing will look similar to KMSAT. This is not going to be a minor, you know, $0.50 or something like that, unless you're already paying $0.50 a user because you're giant. Okay. All right. I believe that was my last question. Hopefully, everybody enjoyed that and that he asked the right question for me to end off. With that, I believe I am going to turn it over to John, and I only stole a little bit of your thunder. Oh, and by the way, you have to click your own slides here. Okay. Yeah. Fine. Thanks everybody for joining us in person and those of you who are on the line. It's actually great to see people and not Zoom squares, so this is awesome, and see some reactions. I'm John Just. I'm the Chief Learning Officer here at KnowBe4. What that puts me in charge of is all the content that we create. I'm in charge of creating all that awesome learning content. We have a large number of folks all over the globe now that are involved with doing that. As you can see, and may have heard many times, we have the largest library of content, and this might be a familiar slide, although you'll notice the numbers are different. The numbers are up. We now have 13,000 phishing templates. We have more interactive learning modules than before. We have more video modules. We have more posters. This is not just, okay, we're adding more and more constantly. As Stu alluded to earlier, the always fresh content is huge for us. I kind of chuckle when we get the question every time. It's like, "Well, what do they do after 12 months? And what do they do after 24 months?" They've, like, solved the problem, right? I really love the managing, the ongoing problem. The way to think of this, and I know we're not big on sports analogies in the tech world, but we're playing defense here, right? We can't just roll something out and say, "Don't click on stuff," and, you know, expect that, okay, now we're not clicking on things. It's definitely managing that ongoing problem, and it's definitely from a lot of different avenues. You can see here, there are games, there are newsletters and security documents. We're moving to more digital signage as the workforce is more remote and hybrid-oriented. We're going to be sending these sort of things out on an ongoing basis. What we tell our customers is, you want to train like a marketer. This is not a problem where you're going to check the box, send something out once a year, and then, yep, everybody knows it. If that were the case, then we wouldn't have a business. I'm kind of glad that it's not the case to a certain extent. But again, you have the changing dynamics of the threat landscape, and then you have retention of folks. They have a lot of things on their mind. We're happy to see a lot of our customers these days that are training monthly. Not training monthly with big chunks like you take your finance education, but very smaller targeted education that's going to give them what they need as an organization. You'll notice we also have assessments for culture and security knowledge. We have ways beyond just phishing at this point. With SecurityCoach, we're going to have even more data. Between those, we have about 2 million completions of users' data that have completed these surveys and assessments to determine where are the weaknesses within the organization. The organization can actually pull out. Well, it seems like we have an issue with communication or incident reporting or mobile device security or remote working or VPN, and they can target that set of monthly training and then give that assessment again. These are scientifically valid assessments, so they're not tests or like some of our competitors have. We've done a lot of work in making sure that what gets tested is actually valid for what is going to be the behavior that's out there in the world and the perceptions that are going to be. They can measure their progress along that way. We have recommendations also for them based on AI that looks at their given vertical now where they are in the world regionally and gives them recommendations for what are other people taking that have similar data patterns as we have. Mainly around the phishing alert right now, but as we build that database with SecurityCoach and get even more data absorbed in, we can have more insight into the various behaviors. I'm sure Perry will give you more information about how we can change that behavior into changing to a security culture. But a big part of that, again, is that ongoing training. I'll just make one more point on the freshness of content. We constantly are iterating every year. Since I've been here, we've really accelerated the ability to create our content and still produce it at a high level. A high level of production and accelerate the distribution of that content. I can tell you, every year, we come out with a new year of Kevin Mitnick's training, right? Which Kevin does demos about what the latest threats are and that sort of thing in that demo. Every year, though, people ask, "When is the next one gonna be coming out?" Right? It was launched in the fall this year, then it was in 34 languages in January. That was not soon enough for everyone. It's not like people could come into this market and go, "Okay, well, we did that last year." We've been iterating for years now to be able to build the high-quality content that we have and to be able to deliver that in a timely manner with the latest threat landscape. It's very short turnaround times because, again, we're playing defense, we're looking out there, what are the trends in the threat landscape? What are our customers asking for? What are they interested in? We're adding content. We're not just doing that for the sake of saying we have the largest library. We're doing that because we have that demand from our customers. We've talked about the different types of content and training like a marketer. We wanna have engaging types of content. We wanna have multimedia in different formats, interactive, giving real-world examples. You know, you can't quite see probably some of these, but you'll see social media posts, okay? Sometimes we come across customers, and they say, "Okay, well, we're just focused on phishing at this point," because maybe they had an incident or a near miss. We'll say to them, "Well, is it why you had those near misses, could it be, or the incident that you had, that your people are posting way too much information on social media, right? Or could it be that they were already in because they had a compromised password?" We already talked about a lot of what, you know, the PasswordIQ we're gonna be getting in the future. We have a ton of training around passwords. Oftentimes it's not one thing, right? That leads to that better security behavior and ultimately a security culture. It's all these different areas, and giving them real examples and real practice via games, via interactive training modules is very important. I know I've mentioned before, and for those of you that haven't been here before, we look at the ratings by our end users. A focus of ours is end user engagement. We're not looking at this as, okay, we've got completions. Let's see what the checkbox is. We have focus groups that we conduct. We're trying to actively engage the end users and see what are they interested in, what's connecting for them, and how can we make those connections. One example I like to give about this is, many times we had a great training module a few years ago. We did some focus group work. We looked at the survey comments. We get surveys at the end of each of our training modules, so we look at the data. In both the comment analysis and in the focus groups, people said, "Well, this is great, but this doesn't happen all that much." Right? "It's not that frequent. This is like scare tactics." In our next iteration of the training modules, we're really focused on letting people know it's a shameful thing when these sort of things happen. It might have happened within your organization. It might have happened to, you know, one of your vendors. What makes it in the news is the tip of the iceberg, and that's actually what the interactive was called, The Tip of the Iceberg. You had to guess how frequently these attacks happened and how frequently it made it into the news. That was a really engaging way, and we saw results in the ratings and the scores where people said, "Huh, I guess maybe I should be paying more attention to this, and I should be engaged in this training." Because if they're just gonna click through it and they're not gonna be engaged, then all the hard work we're doing is important because it'll you know, the phishing is important as well, and at least they're thinking about security for that amount of time, but we wanna make it as engaging as possible. We're constantly iterating to make sure that we're connecting with those end users. The way that I like to think about it is it's a dialogue with those end users, where we're getting that information back from the surveys that we collect, the comments that we collect in the focus groups, so that we can consistently iterate and engage even more each time we release this new, fresh content. I mentioned the content centers that we have all over the world, and these are the content centers. The centers of excellence that have the KnowBe4 badge on them are actually where our more of our focus of our content is. We have some partners on here, such as lawpilots and Canadian Privacy, that have very specific training, as well as Kontra. Those are our three partners. The others are where we have offices and resources. The ones with the badges are where we have full teams. We're not just talking about someone who's reviewing the content there. We actually have production teams that we've set up, enabled with our technology to be able to create content in region for that entire area. That's basically the footprint there. SAYA University is a little different. We contracted with them to build content for Japan specifically, and we also have a presence there as well. Any questions on this slide or anything I've said so far? Because I'm gonna hop into Compliance Plus next. Yes. Good, good. I'll repeat the question. In terms of the content that we have internationally, do we have everything we need to grow in the regions that we're targeting? The answer would be yes. We have everything we need. We are targeting very many of these regions, as was mentioned earlier, and we have more content than usually the local competitors have. Of that library I just mentioned, there's a good mix, and we do this on purpose, where we don't have a mix of everything at every level across the levels, where they can have 300, 400 pieces of content available in their area. Most of the competitors that we're going up against, you know, one large one has 50 translated in 34 languages versus we have hundreds. We have a larger library than most of the competitors that we're going against in those other areas. Is all the content that we have exclusive to us? Very good question as well. 99% of the content that we have is exclusive to us. We do license, as I mentioned, that lawpilots, which is five courses of the 1,500 pieces of content that we have, as well as one course from Canadian Privacy is not exclusive to us. You're talking about six out of 1,500 pieces of content that's exclusive to us. Also good question. Anything else? All right. We're supposed to be engaging and not put you to sleep. That was my whole thing on the last slide, so I'm trying to engage with you. This is important. Yeah. Okay. All right. We launched Compliance Plus June 2021. This is a new product, a new SKU for us. It leverages the same platform and same technologies. I'm gonna tell the story later on in my session about Compliance Plus that a lot of it started here at our conference back in 2018 when I started. We'd heard a lot, and we'd got a lot of market intelligence, but this is a great time to come out and actually talk with people. They were very frank with us. "We love your content for security awareness training. Can you make the same quality of content in some of these adjacent areas, such as compliance?" We thought long and hard about that and what made the most sense, and went forward with this library, which currently has over 200 pieces of content. We have a content team that sort of built to build the KnowBe4 branded. As you heard Stu mention earlier, along the way, MediaPRO came up at a great opportunity to accelerate our go-to-market here and as well as accelerate our go-to-market internationally, as they had some international presence and some library that we could also leverage to focus on international earlier for compliance. We have started in North America, and then later this year we'll be launching internationally with compliance. We feel like they are very complementary in that a lot of people are doing compliance education, right? If I'm in a market, say in Germany, where I'm already doing compliance training, but I'm not mature enough with security awareness training, this might be the tip of the spear within some of those organizations where we can come in and say, "We'll get the platform, get Compliance Plus, and then we can sort of back into security awareness training." You might be not ready within your culture to do some of the phishing yet, but if you have this good feeling and it's been successfully done and the platform works really well for compliance training, you might get better leverage to be able to work into doing security awareness training. For now in North America, it's sort of worked as in the reverse way, but we feel very strongly for internationally, this could be a foothold for us in a lot of instances. You know, I mentioned the localization. Here's you know, what we've done. For compliance, we're not there yet for Compliance Plus. But with security awareness training, we've worked very hard over the last four years on process to keep churning out new content and have that be a high quality. We've added key members to the team that have a lot of experience, both in security in these regions as well as linguistics and making sure we're getting across everything. Here's some examples of how we're not just translating this. We're not just making it subtitles, where it looks like a very American product, and then it's going to just have the subtitles on it. It's actually going to have local talent, local imagery, and local language that that's gonna make it feel like it's a locally developed product. That's going back to that earlier slide about our regions and having key resources there to be able to make sure that that's the case. Because we're going back to we wanna engage, we want this to really resonate. We've made huge investments in that area of making sure that it's going to do so regionally, not just in North America. Speaking of engaging content, we had our biggest fan first ever Inside Man. Some of you have seen the Inside Man. Inside Man is a series. Perry's one of the original minds behind that, and you'll hear from him later, where we actually follow along with, I don't wanna spoil it for anybody if you haven't seen it, but it's a hacker who turns into a white hat and is doing security. It really has resonated. You'll see things on Twitter and Facebook where people are like, "This is better than Netflix series that I watch." Very high production value, really engaging, really story driven as opposed to being, you know, lesson driven. We get the lessons across, we get the information across, but it's certainly the story comes first in order to engage those learners. A great supplement as we've added optional training content. Optional training content, by the way, has taken off like I never thought. I'm up here telling you I love our content, and I think it's amazing. I had lower expectations about how many people would actually take training on their own than what ended up happening. We've had tens of millions of people now actually take optional training on their own at this point, which is crazy. Inside Man is our flagship series for part of our Diamond package, which is the highest level package of training that we offer. We did an actual premiere coming out of COVID. We had entries from all over the globe. Weirdly from Alberta, Canada, like 50. I think they just wanted a trip to Florida, so we flew the winner down to Florida. This was Minnesota, who actually wanted a teacher in Minnesota that was using it in her classroom as part of the education for a cybersecurity program. She ended up half filming some of her students, and she ended up winning, so we flew her down for the premiere. We had a full-blown premiere where we had the actors come in and answer questions about it and created a bunch of YouTube videos around the release. It was extremely successful, and we'll definitely be doing this again as we come more and more out of COVID. We think we'll get even more people that we can invite and have even more locations where we can do this. It was super exciting, and I wanted to share that with you, that season four is out, and we did a formal premiere. We also did great premieres in London on a smaller scale, in Oslo as well, and we have one coming up in Berlin next month, that will be doing those worldwide premieres of season four of The Inside Man. With that, I'll take some questions about content and then turn it over to Perry. Greg takes a long time. I'm the fast one, so. I just had one question. Sure. Can you guys describe engagement metrics around the use of this third content and how does that correlate with last year? Yeah, I mean, a bunch of metrics of engagement. We have completion data that we look at. We have data that's coming from where people are within the module and what they're engaging with and where they're spending the most time. You know, completely frank and honest, we have some people who are playing the game of how quickly can I get through this training, so we see that too to a certain percentage and a decreased percentage as we make it more and more relevant, and more and more engaging. We see that rating data, so we have survey data that comes out of that, which is what did I respond to this? Did I give it five stars? We ask three questions. We ask, is it relevant to you? How was the presentation? How was the timing? Those are the three questions we have them rated on, and we get all that data, and then we get comment data as well. We're constantly looking at this data, not only about our annual refresh, but also what are they pointing out in the data that they would like to see more of? What are they engaged with? What are they complaining about? What are they interested in? Not always are we gonna just address their complaints, but we're going to find a way that we're gonna get them engaged in another way from that complaint, right? That's a huge part of what we do. Yes. I think you mentioned, John, that one of the attractive parts of the MediaPRO, they're international. Yes. I think later on in the session, you talked about the 34 languages. Correct. that you have proficiency with marketing, like Yes. I'm wondering. The other piece is probably around, I guess, the launch or the relaunch of Compliance Plus into international markets now that you've integrated it into the North American content as well. Can you kind of sort of- Sure. Definitely. Yep. What MediaPRO allowed us to do is launch with a North American library that much faster, that's number one, so that we could get to international quicker. It wasn't that we looked at MediaPRO and we said, "Oh, well, MediaPRO has all this content that's in a lot of languages." It was that we could fill the library of Compliance Plus for North America in twice, you know, in half the amount of time that we would be able to do that. Now we can turn and face international that much quicker. They did have some international presence, and they did have some multinationals that we could leverage as part of that, and we continue to do that. That's part of the story. Part of the story is just capacity. We've made an internal investment. We did a buy or build analysis. Should we buy someone off the market, or should we build this and ourselves? We did that with our board involved as well and some high-level discussions about what made the most sense. We were already on the path of build. Then when MediaPRO came along, we said, "Okay, well, half their sales are from compliance already. We can fill what we would need to do on that build, accelerate our go-to-market for North America, and get a little bit of a jump-start in international, but we really want to use our international go-to-market for that." The relaunch with international is really going to be later this year. We're building content. We're not doing a big bang like we did with Compliance Plus. We're actually releasing everything we finish it. We're just releasing it as part of the Compliance Plus library currently, and that helps with some of the multinationals and some of the large organizations. Then midyear, we'll go really after it and say, "Now we're ready in these markets, Germany, Switzerland, you know, the Netherlands, U.K.," and we'll actually push that and say, you know, "Here's what we wanna do." We've had some excellent people within those markets, early adopters, sign up already because they see the promise of it. It might not even be in their native language. English is the international language of business, which is great for us. They've signed up for it, but they're also helping us inform what that's gonna look like in terms of the content roadmap and rollout. Does that clarify? Yeah. I mean, maybe just as a follow-up to that, because compliance is a very big space, maybe relatively more niche than saying that, do you have aspirations to get to 34 languages or should it be final time or is that? Yeah, let me repeat that question, too. Do we have aspirations to get to 34 languages in compliance content? In some instances, yes. There's like general anti-bribery and anti-corruption and ethics that transcend and are very useful for multinational organizations to roll out. However, we've taken a more segmented approach with compliance than we did with security awareness training. Because of local laws and local regulations, compliance requires so much more referencing those local differences. What we're doing now is actually breaking that out and having the teams locally build that. There'll be some common things that are available at 34 languages, and then there'll be some things that are very specific to, let's say, the German market that no one will ever have any interest in taking here in North America. The library will be a mix of those. It'll be a mix of what we get with 34 languages, which is the common best practices around what you need to know and how you need to perform. If you're a multinational, you're gonna have to go, okay, well, data privacy within the European Union is very different than it is in California, than it is in Japan. I have to pick particular modules for those markets and address it that way. Any other questions? All right. Perry, you're up. All right, I'm gonna see if I can make up a little bit of time as well. We'll see. Fingers crossed. Actually, before I start, maybe I won't make up time. I'm gonna give you a little bit of background on me. I'm kind of unique in the security awareness vendor space, in that I've kind of seen security awareness from about every angle you can. I ran security awareness at a few large multinational vendors, so the Fidelity National Information Services, Alltel Communications before it was bought by Verizon, and did a little other work there as well. I also ran the security awareness market research area at Gartner, doing the Magic Quadrant, working with all the security awareness vendors, and then also helping CISOs and awareness program leaders around the world, really think about this and think about the discipline of security awareness. I've been living in the market for security awareness and the discipline of security awareness for probably longer, and in more depth than a lot of people in the world right now. I think that gives me a unique perspective that I get to exploit in good ways as we approach this from a market. One of the things when it comes to awareness, there's a fundamental reality that we have to think about. The way that I phrase it is that security awareness as a market term serves a purpose. Security awareness as a thing in and of itself doesn't really do much because awareness doesn't actually change anything. Awareness just means that we have some head knowledge. There's a gap between knowing something and intending to act on it, and there's another gap between intending to act on that thing and actually doing it. We all, you know, have things that we wanna do and we never do, and we have things that we tell people that we're gonna do and we never do. We have to deal with this knowledge-intention-behavior gap. Then out of that flow, what I call three realities of security awareness. Just because someone's aware doesn't mean that they care. If we try to work against human nature, we will fail. What an employee does is way more important than what they know. There's always this knowledge component that comes along, but it is in service of a much greater goal. It is in service of either, you know, complying with something, which is checking the box. That's not the great goal. The great goal is to reduce risk in an organization. The way that we reduce risk in an organization is by driving secure behaviors, building a secure culture, and then ultimately impacting the decision matrix of every employee, and then ultimately impacting the way that they interface with technology. That means that we get into things like behavior science. We have to really deal with the fact that humans are lazy, they're social, they're creatures of habit. They're gonna take mental breaks. They're gonna do things the easiest way possible. They're influenced by those around them, and they like to build pattern-based realities. That's where things like SecurityAdvisor come in. You know, this acquisition that we made, this is a solid step into the world of behavioral nudging. This, I think, is the future for this entire market, really. I mean, you do have some vendors that are gonna say, "We only do content," or, "We only do phishing." When you think about actually reducing risk within an organization, it is taking behavior science, it is infusing that with technology and forming it through all the other data that's available, and then in the moment, intervening with somebody. That's why SecurityAdvisor is so big for us because it really cements our ability to do that in a real way. It also moves us up this wheel. When you think about the market for security awareness, there's kind of an evolutionary path that it's taken, which is it started out with people trying to solve some very technical problems and saying, "Here's how you do this the right way." It grew into saying, "All right, we do that. Let's replicate that." That's where the vendor market comes in and says, "We can help you do that faster and cheaper, and we can help you sustain that." It grows into saying, "All right, let's now affect some behaviors. Let's deal with phishing." The phishing market emerges from that. Ultimately, what we're moving to is realizing that the human is an endpoint, and the human is a human endpoint that's managing virtually, you know, hundreds, maybe even thousands of other endpoints when you take in IoT as part of that. We really have to be thinking at the human level in reducing that risk in a meaningful way. That means that this idea of human risk management, human detection response becomes the central theme that we need to orient around. Then everything else is in service of that, whether that's content, whether that's phishing, whether that is the next big thing, you know, these new shiny things that people are doing around escape rooms and AR and VR and all of that. If people do that out of the framework of reducing risk and dealing with human detection and response, then it's just shiny stuff. Everything that we're gonna do ultimately is gonna tie back to that reduction of risk in some meaningful way in dealing with the human as that uber endpoint. This is really just my understanding of the evolution of security awareness as I've seen it. It's also evolving to match the maturity of the CISO in that role. Early on, we saw CISOs that had a very cavalier cowboy approach in the way that they did things. They didn't really understand how to be a good business player. They started saying, "Oh, you know what? Metrics and all of that is important." They started to take that on, and we started to see the evolution there. Ultimately, the awareness market kind of trails that a little bit. As we're starting to see the CISO really have a seat at the table in a meaningful way, that's when things like security culture become very meaningful, very important, and something that can actually be achieved because the CISO now is in a position to affect the political outlook of an organization. When that happens, that means that they can start to set some of the value structures within an organization, and that can be pushed down and reinforced in meaningful ways. One of the interesting things that we did at the end of last year is we wanted to say, all right, so security awareness and the maturity of security awareness within organizations definitely does happen in phases. There is a maturity level that we should be able to derive by saying, all right, if somebody is doing X, Y, and Z, based on the outputs of that, how mature do we think that they are? Up until now, within this market, there have been a few maturity models that you may have seen. SANS puts out one, their security awareness maturity model. It's based on a capabilities maturity model. It is very coarse-grained, would be a nice way of saying it. It is basically a finger in the air. You look at it and you say, "Yeah, I feel like I'm a level two because of the way that they've described it." It is not data-driven. It is not evidence-backed. One of the things that I wanted to get to, you know, since we've got over 47,000 customers, in fact, we got a lot of freaking data. That means that when we start to try to say, "Let's add some precision to something. Let's understand the maturity of our people," we should be able to derive that 'cause we've got billions and billions of data points about everything that these people have done, all at the organizational level, and at the individual level. We should be able to look at that and say, all right, where is that person on a maturity curve? Where's that department on a maturity curve? Where's that organization on a maturity curve? Let's even be able to roll those up and say, where are these regions from a maturity standpoint? That's the value that data gets us, and that's the value that these, you know, large numbers of customers that we have gets us. Because ultimately, what we wanna do is push everybody as far to the right in this as we can get them to where they're in level four or level five. That's where we start to see real meaningful reduction of risk. The more data that we have, the more we can help encourage people to make better decisions with the way that they set up their programs as well. This is all about making the human the last line of defense. There are several things that I mentioned just kind of in passing as I was talking about the way that we're ramping up on the maturity model and the other things that we have that really get to the fact that we have a lot of strategic moats in place. 47,000+ customers is something. When you have that many customers, you have a ton of word-of-mouth, you have a ton of people that have decided to be with you, and they are naturally becoming, I mean, that's what makes Microsoft make statements like what Greg talked about before. "Hey, we do this, but if you actually wanna do the real thing, see the people that are doing the real thing, you're gonna wanna go with KnowBe4 because they've got this figured out. They're the ones that are really investing in this in a heavy way. Customer count, we've been doing AI and machine learning longer than anybody else in this industry, and we have the data, which is the blood of all of that, to actually make it work in a meaningful way. We have all these acquisitions. We got global presence. We're continually building things that reinforce the value proposition of KnowBe4 as the de facto leader within this space, and also making it very, very, very difficult for anybody else to catch up in a meaningful way. You might have somebody that says, "Oh, I perceive a market gap in that maybe KnowBe4 hasn't done X yet, so I'll spring up and I'll create X." But that's. They're gonna create a point solution. They're never gonna be able to create the depth and the breadth that we have across everything. I can almost guarantee you there's not gonna be anybody that's thought about something that we haven't already thought of. They might approach that, they might get to market faster in some way because that's the only thing they're focusing on, but we're probably focusing on that same thing in our roadmap and developing that in a much more robust way. When that hits the market, it's gonna make a big impact. We have tons and tons of things that set us apart from the competition in this. One of those that is undeniable is the dataset. Again, 47,000+ customers, all these different training events, all these different simulated phishing events, the data that we can bring in through API calls, that is rich, valuable data that can be used to train AI and machine learning. That is rich and valuable data that can be used for reporting. That is rich and valuable data that can be used to chart maturity levels. All of those things come together, again, in ways that nobody else within this market can replicate, and which will also inform the way that we build out the product and the platform, as we go forward. The other cool thing that we're seeing in this is we talk about the maturation of the market and the discipline, is that there are lots of other groups around the world that are starting to catch on. One of the big things is that we used to look at the NIST guidance, and they would make very general statements about what security awareness was. I mean, they had a pretty thick document that said, "You need to do security awareness," but the guidance in that wasn't that great. In the most recent version, they've started to actually say, "You need to do simulated phishing testing. Here's what that needs to look like." This has become something that is recognized and standard in the industry right now, again, because it comes back to it is one thing that evolved ten years ago. You know what it did? It actually said, "You can take a behavior, you can use that behavior, you can train that behavior, and you can actually reduce risk in your organization by doing that." We're not just now putting content in front of people's eyeballs. What we're doing then is actually starting to train somebody into becoming a better participant with the security of their organization and reducing the risk. What you see now is that the regulatory framework and the auditing frameworks and all that are catching up and codifying that within those, again, because that's what reduces risk. That's what builds something real within an organization. From a competition standpoint, what we've seen is that this. You know, when I was tracking this at Gartner, every week it seemed like I was speaking to a new security awareness vendor. They were popping up. It was undeniable that this market is greenfield, and there's a lot of room for new competitors. There's a lot of room for new ideas. But KnowBe4 has been so far ahead in all of this that what it is doing is it's showing people that there is success to be had. But with that being said, a lot of those competitors are kind of way back. They have almost no hope of ever being able to catch up with us. The competitors that started at the same time that we did back in the 2010 timeframe, which were at the time PhishMe and Wombat, PhishMe rebranded as Cofense, changed their strategy a little bit, and has basically fallen off of the relevance map completely. Wombat sold themselves to Proofpoint a few years ago, have had some integration struggles, and are basically just being bundled in and given away with everything. They're way less innovative, way less relevant than they were five years ago. Outside of that, though, there's a few interesting new things that have come up, and I'll give credit where credit is due. We do see folks like CybSafe in the U.K. emerge. They got some funding from the government there. They're working in a very behavior-based way of approaching things. They have some interesting ideas, but that's all they do. It's a lot of consulting. It doesn't scale. They're only gonna be able to do a certain amount. If they can't fix the scalability problem, they're just limiting themselves. You have folks like Living Security that got some good credit in the Forrester report recently. They started in the escape room space. They had to do a hard pivot with COVID. They codified that a little bit in video and things like that. They’re struggling with scalability. They're struggling with learning what it is to be a new company. If you followed them at all over the past year or so, they've had a lot of problems in the senior management ranks, and so I think that that's been holding them back as well. They do have some interesting ideas. Again, they don't have a full platform. They're naturally limited in what they're gonna be able to do. They can never scale at this point the way that we can, but some interesting ideas. Outside of that, it's a lot of, you know, a lot more legacy companies that have just kinda drifted. What they've started to try to do is figure out one thing that they can do and try to focus on doing that pretty well. In doing that, they're naturally limiting themselves. The other thing that we're seeing them do is they take missteps in the way that they invest in those. They might say, "We're gonna focus on phishing," but they're not thinking about this in a way that does some of the randomization that capitalizes on some of the behavior management principles in the same way that we do. What they're doing is they're unwittingly giving people a false sense of security because they're not putting real good best practices in that. They're not rotating and doing randomization of templates. They're not focusing on AI in that. They're creating these limited pieces of functionality. They're putting all their investment in that, and they're really just not growing to where the market is going to need them. They're not becoming as meaningful as they could or should be. I'm seeing some very strategic mistakes that a lot of these vendors are making. Now one of the good things about us, though, is as we continue to grow, we're seeing ourselves, you know, 47,000+ customers. That becomes very trackable to some of these organizations like Okta that are, they're, you know, single sign-on types of vendors. They're seeing KnowBe4 become a destination of choice within that, and we're getting recognition of that. We're seeing ourselves, you know, reflected in the work that they put out when they say, "Hey, these are the vendors that are doing really good things, that are getting way more traction than everybody else and showing up on our radar over and over and over." I'm gonna show you something a little bit deprecated real quick, but this is the Gartner Magic Quadrant. While they were doing that, they've retired the Magic Quadrant for this space right now. You'll see way back at the beginning where KnowBe4 emerged, when that Magic Quadrant started, and then over the five years that Magic Quadrant existed, the continual progress, very dramatic progress every year that KnowBe4 had, and then finally ending up in the top spot within that Magic Quadrant the year that it got retired. A couple slides earlier, let me go back here, you saw the Forrester one. This just released about a month ago, I guess it was. We took the top spot in that for the second year in a row as well. One of the things that we're also doing, I think better than anybody else, is anticipating where the analyst market, where the analysts are hoping the market goes over the next few years. We're staying very much ahead of the rest of the pack of awareness vendors by having really good conversations with the analysts, really good conversations with our customers, and then good conversations with the awareness community as a whole to say not only what are we doing well, and let's keep doing that, but where do we need to be growing so that we're relevant three to five years from now as well. Here's the same recognition in G2 Crowd. Again, very much separated top right. We're seeing, you know, lots and lots of recognition across these as well. With that, I know that I'm trying to catch us up a little bit. Do you have any questions for me. I'm always happy to chat offline too. Yeah. I see four. Wow. Okay. I think, let's grab her first. Perfect. Yeah, we have to use the mic because we're webcasting with an audience. Okay. Good point. Hi. Madeline Brooks at Bank of America. Yeah. I just wanted to talk a little bit about HDR and where you see that fitting in with your competitors. It seems like KnowBe4 is really banking on this to be a critical piece of security awareness going forward. Yeah. Have you seen it from, you know, you'd mentioned the legacy vendors are drifting? Have you seen them starting to invest in the space? If not, does that surprise you? I have seen over the past two years, there's been a lot of rumblings within the other vendors saying, "Hey, we know that we need to be doing this," because the conversation has shifted from content in front of eyeballs to how do we actually change behavior. One of the ways to change behavior in real time is what we call nudging. People are saying, "How do you do real-time, you know, just in time behavioral coaching?" You know, nudging, in other words. There's lots of conversations around that. A lot of the other vendors haven't invested in it specifically. What we have seen, though, is some very small vendors pop up, like SecurityAdvisor, that are saying, "This is gonna be the thing that we kind of stake our flag in." Of course, we bought SecurityAdvisor, which we believe was the best of that crop. But I would say you'll probably see a few other significant moves. If the other vendors are wanting to stay relevant in this space, they're either going to innovate in that area or they're gonna pick up a small vendor like SecurityAdvisor. One of the cool things that we're seeing, so if I can also read a subtext in your question, was do we really think that this is the right bet? For us. Is focusing on this type of behavior, type of technology, the right step for this. If you look at the narrative that's coming out right now within the core awareness community, so the people that are doing awareness within their organizations across the world, the thought leaders that are doing this. The phrase that has been adopted this year and used over and over and over again from SANS, you know, Lance Spitzner over at SANS, to even the folks that I've seen at Living Security and everywhere else, everybody is saying this is actually about risk. This is about dealing with human behavior. Now, the good thing for us is we're the only ones that are within the product building that out in a significant way right now. Everybody else is saying, "How do we build processes around this? How do we have a conversation at our executive level the right way?" Yeah, we'll have that conversation at the executive level. We'll inform people about best practices on process. We're actually gonna have technology that enforces that and puts those right practices in from the very beginning. Just as a quick follow-up, if I look on slide 20 from the presentation. Yeah. In the adoption column, we have KMSAT being the organization-wide land. Do you expect that SecurityAdvisor is actually going to take that spot or become more of a land versus a new, you know, a cross-sell or addition to? No. KMSAT is the platform that SecurityAdvisor's gonna have to have in order to function well. Even if you look at SecurityAdvisor pre-acquisition, there was a question before about, hey, some people were saying, "I'm either gonna buy SecurityAdvisor or I'm gonna buy KnowBe4," before we acquired them. That was kind of a false bind that the marketing department from SecurityAdvisor would put people in. The reason that they were able to do that with a straight face is that they were gonna build some of their own content. SecurityAdvisor on its own is just, you know, sending something out in Slack or Teams or something like that. It's only relevant if you have something to send in Slack or Teams or whatever. They had not built that part out in any meaningful way. KMSAT is the thing that fuels all of that will use those nudges to their fullest extent. Thank you so much. All right. We'll go back. I had a question about Fortinet. I guess they announced that they were getting into this business last week, and just your thought on some of the big vendors getting into the training area. Yeah. I mean, it validates the market. That's the best thing that I'll say. The other thing is that if you look at what Microsoft did with their partnership with Terranova, if you look at Barracuda a few years ago, of course now they were just kind of shifted hands again. A few years ago, that was a consolidation play with Barracuda buying PhishLine. A lot of that is because they want to sell the blinky light thing. They wanna sell the secure email gateway. They wanna sell their core product. What they're trying to do then is tick a box in another column that says, "We do this, but we're also gonna help with this human side," which means their major investment's always gonna be in the thing with the blinky lights. It's always gonna be the technology-based thing, and then the human side thing is gonna be a side issue, and they're gonna devalue that over time. I would say the same thing with Fortinet, is they've been kind of playing around the edges with this. They're trying to say that they're doing that in a more significant way, but that investment is gonna dry up. That's just my prediction. All right, let's go to the back. Hi, Perry. Thanks for doing this. Brian Essex from Goldman again. Yeah. Just real quick question on the Forrester Wave chart. I noticed Kaspersky was on there. I think total revenue run rate, they're like $220-$240-ish. Any idea how large they are in security awareness training? You know, we're hearing about, you know, migration off their platform at an accelerated pace in the- Yeah. Endpoint space. Are you also seeing any of that in your space? I mean, us at KnowBe4, we've not seen anything with our product. As we monitor Kaspersky, I think, yeah, that we're gonna see more and more of that. In fact, I was one of the advisors to Kaspersky back when I was at Gartner, and my major piece of advice for them at the time is, "If you wanna be relevant in the security awareness space, you gotta spin off another company and change your name." Because if you wanna be relevant in the U.S. market, for sure, because most of the U.S. was not wanting to deal with that, and same with the U.K. as well. Their security awareness offering was interesting. It's not standard. It was very much like, "Let's simulate a board game, and let's do some interactive role play and things like that." I don't think it was ever poised to be a mainstream thing that most of the market would actually support. I think it was people that had a passion about that thing, that core idea, they were running after that, and they were being funded as an experiment. We never saw them as a serious competitor in this space. Got it. Maybe just to follow up, I think Cofense maybe directed a little bit more towards service provider market. Yeah. Do you find that market attractive, and are there limitations with regard to the way that you might be able to scale on that platform? I mean, Cofense really, their major play is saying that we're like a managed SOC for human incident response. Right. We will sell into managed services providers and, you know, third-party services providers like that. Their line, the Cofense way of thinking about things naturally doesn't scale well because it means that you have to have human eyeballs on screens looking at some kind of AI-enriched thing. It's kind of, you know, AI suggested data, human-enriched intelligence, and then there's some decision based off of that. That doesn't scale the way that we need things to scale to continue to get to the reach that we want. I would never say never within that, but it doesn't match our core philosophy right now. All right. Super helpful. Thank you. Yeah. You're good? Okay. Is there anyone else? Great. I think I've gone to my time limit. I'll move this. I am not gonna do that jump. We don't need to hire Tina. Yeah, no, that's not gonna happen. That was very impressive, Perry. Seriously. It's very agile. Well, hey, good afternoon. It is really, really good to be here. It's great to see everyone here. I think, as I think John said, it's great to see, you know, human beings and, you know, real bodies as opposed to faces on squares. Really, really great to be here. I'm sort of questioning the sequence of this. It feels like we should have maybe crescendoed with Perry as opposed to, you know, sort of being introduced to me. You know, hopefully this won't be too big of a letdown. Really, really happy to be here. I'm in week six. I've been, you know, six weeks on the payroll. You know, really getting myself oriented, starting to almost feel like I've got a little bit of equilibrium. It's been, you know, I will say it's been a really good transition. You know, Krish was extremely supportive, very generous with his time, really making sure that, you know, we didn't have anything that was falling on the floor. He's on the phone. Thank you, Krish. Honestly, the rest of the leadership team has been incredibly supportive. This is an amazingly talented group of people. You know, it's great that you guys have hung in here for this day and, you know, had the opportunity to get the exposure that you're getting to this team because it is a very high quality team. You know, I think you know, I expressed to some of you in our introductory calls in sort of my first week here, you know, that there's a lot of high quality infrastructure here. Stu actually shared some of that with you guys early in his presentation. You know, some of the financial infrastructure that we have, you know, a lot of the data that we actually manage the business by, and it is a really, really impressive. You know, I call it a very impressive sort of headlights view into the business. You know, I've been in many, many businesses where most of our time is sort of looking in the rearview mirror at how we did as opposed to looking, you know, out the front windshield. This is a business actually that really does a good job looking out the front windshield. I'll just move to the first slide real quick, and I'm gonna try not to be super duplicative because there's been a lot of these things that have already been touched on. Honestly, I wanted to take a moment early on in the presentation to actually sort of remind everyone of the fundamentals of our business model. This is, you know, really the same principles that the organization was founded on by Stu. All of these four things were key fundamentals 12 years ago, and they're obviously, as we continue to scale, remain very, very key fundamentals for us today, an absolute part of our corporate DNA. It actually dovetails with some of the questions that actually I got when in some of our introductory calls actually. Because some of the questions that I got from the folks in this room were, you know, what were some of the things that actually attracted you about KnowBe4? This is a great business model. You know, it's a business model that I've been sort of trying to, you know, migrate my career to. It is, it's just a very, very strong business model, right? It's you know, the revenue is 100% SaaS-based. You know, it's highly forecastable. It's recurring in nature. We'll talk a little bit on a future slide in terms of you know, sort of the recurring nature of the revenue and some of the longevity of our customers and contracts. You know, the forecastability and predictability of this model is you know, is really, really advantageous. You know, Stu, I think talked about this sort of careful balance between growth and profitability that has always been sort of a day one mandate. You know, that's really proven a long history of consistently positive free cash flow, and really creating a business that really focuses on that balance between growth and profitability. As we are scaling, obviously you would expect and we are seeing margin expansion. That's exactly what you would expect to see as the capability of leveraging the cost structure, and that's obviously what you've seen over the last several years. You know, the platform is very sticky, and we're gonna continue to use this platform nomenclature because it really is a sophisticated set of plumbing that we are sort of bolting functionality onto. You know, logo retention in excess of 90% in both SMB and enterprise is pretty clear evidence that as we continue to make the platform more relevant, make the features and functionality more relevant, you know, it ultimately just ends up being stickier. That obviously is reflected in the retention. You know, we talk about sort of the no-brainer pricing, and it's, you know, look, you can do $285 million of ARR divided by 47,000 customers and figure out, you know, that's pretty easy arithmetic. That is really no-brainer pricing, at least in my judgment. I, you know, the four people that have gone before me are much higher experts on this than me, but I can tell you that that seems like just no-brainer pricing to me. You know, Stu also mentioned the whole concept of scalability. I mean, it's interesting. I'm in week six. We have stand-ups every day. We have management meetings twice a week. The focus on scalability and asking the question, not only around product, but just around sort of simple business processes, you know, is this scalable? It's a really important part of the DNA of the company. It's a question that we really ask ourselves consistently across a broad spectrum of activities around the organization. Let's just take a real quick peek at some recent financial highlights. You know, it is April 20. You know, Q1 is not public. We're still in the process of sort of closing that. You know, what we're seeing here is stuff that you've already seen again. I know most of you have seen this before, but just wanted to kind of highlight and remind everyone, you know, really how this business model is balancing both strong growth as well as profitability. You know, we obviously now have achieved some very significant scale, and we'll, you know, obviously continue to see that scaling in as we sort of move forward. You know, we have achieved significant scale, right? We're reaching approximately $285 million in ARR, $277 million in annualized revenue using Q4 annualized run rate. You know, we're continuing to deliver rapid top-line growth, 2021 seeing over 40% growth in both ARR and revenue, and you know, throw RPO in there as well. We're absolutely moving upstream. You know, we've talked about the fact that the ARR is reasonably balanced between SMB and enterprise where the customer mix is not. You'll see that actually in a future slide in terms of you know, how we are moving upstream and how that's actually impacting the financial results. You know, in terms of profitability, gross margins are north of 85%, support our long-term profitability. We ended the year with free cash flow margins in excess of 25%. Again, operating margins continue to scale, and we leverage the fixed cost structure of the business. You know, this kind of profitability isn't new to the story. It's really been sort of a fabric of the business for the last 12 years, and it's really part of the DNA of the business. The one thing I did wanna do is just briefly focus on sort of this first column on the revenue side. On that last slide, you know, we showed you ARR, and we showed you our annualized revenue. Sort of just kind of staying in the theme of the business model, we just wanted to take a moment really quickly to just sort of illustrate the alignment between these two metrics. You know, this obviously is no surprise. You guys have all seen this in your own models. But we thought we would just illustrate the math. You know, although we don't guide specifically to ARR, you recognize that there's a very, very close relationship between the quarterly GAAP revenue on an annualized basis, and our actual reported ARR, you know, which we do report publicly. You know, those two line items are very, very closely coupled. When you sort of look at this arithmetic, you know, it ranges anywhere between about 1.5% difference to somewhere around 4% difference. You know, it's a very tightly aligned metric between the annualized quarterly revenue and ARR, which you would expect. You know, sort of in that 2%-3% relationship is kind of the midpoint in that range. We wanted to stay on the growth theme for a second. I know you guys have actually probably seen these, and you've certainly heard us talking about these growth pillars. Hopefully one of the things that you took away from the previous presenters is this is a company that is very, very hyper-focused on goals and execution. That really has enabled us to deliver very durable and consistent growth. You know, you've probably heard us talk about these five growth pillars, certainly at least the first four growth pillars. You know, the previous presenters have spent a lot of time on the last growth pillar, which is, you know, introducing new products and introducing new SKUs onto the platform. You know, the growth pillars are landing new customers, expanding internationally, growing our partner network, which by the way, those two things are very, very closely coupled, cross-selling and upselling our platform offerings, and then obviously introducing new products. You know, it's obviously no surprise that landing new customers is a big part of our pillars. You know, we've gone from roughly 20,000 customers to now approaching 50,000 customers, just over the last few years. Landing new customers is obviously pretty obvious. The market is still overwhelmingly greenfield. I have a few comments on the TAM in a future slide, just so you can hear the words from my mouth as well. You know, unlike other areas in cybersecurity, this is not a displacement market. This is really mostly a largely greenfield market. The human layer remains a relatively new category where global penetration is very low. This is a very key growth pillar both in SMB and in enterprise. You know, the next two are really closely aligned, our international expansion and growing our partner network. As Stu said, given that the international TAM is many times greater than the domestic TAM, you know, we really are doubling down on our international efforts, which we've talked about on sort of the last several earnings calls. You know, and candidly, recent world events, you know, has heightened the threat level, particularly in Europe. We've had considerable presence in Europe, and obviously the threat level will be more acute there. You know, the logic in terms of us doubling down in our international efforts is, it makes a lot of sense. You know, these markets are re-reaching the same inflection point that we saw domestically a few years back. Now the international market is quite different, which, you know, we have talked about as well. You know, it's quite fragmented. It's unique at the regional level with different levels of maturity, you know, which is really why the international execution strategy is tied closely to, you know, continuing to grow and develop our partner network outside of the U.S. You know, as you heard earlier, and Lars loves to use this terminology, you know, these channel partners are really our force multiplier. While we, you know, continue to have internal reps doing a lot of the, you know, sort of the lead mining, you know, really virtually every non-domestic deal is fulfilled through a channel partner. The expansion of this channel partner network is really important for us to be successful in our international efforts. You know, cross-sell, upsell motion, we talk a lot about that. You know, it really hasn't been that long ago. You know, we've just recently sort of moved from largely a single product organization to one with over 22% of our customer base using multiple products. This has really been a large area of the transformation of the business. Now the momentum just sort of continues to improve and continues to increase. You know, obviously this shift has resulted in the platform being much stickier, which we talked about a little bit. You know, 22% of the customer base using multiple products, logo retention for both SMB and enterprise being in excess of 90% each. You know, this is obviously very exciting for us. While we still have a lot of the base to mine, you know, when you think about that with 47,000 customers, we still have 36,000 customers to mine for multi-product. You know, we are seeing an increasing number of new logos purchasing multiple products at inception. I don't want to talk too much about the last pillar. Greg's talked a lot about it, Perry's talked a lot about it, but, you know, obviously innovating and introducing new products is really important to our future growth. I wanted to just stop for a second and just talk about the TAM for a minute, and Stu's already talked about it. I think we've, you know, you guys have certainly seen the number. I wanted to sort of give you my perspective as a, you know, incoming CFO, 'cause obviously this was something that I was very interested in. You know, I thought that it would be the right thing for me to do a little auditing on this. It really is the product of a very granular analysis prepared by our team of data scientists. When I say, you know, these are Ph.D. level folks, this isn't a couple of analysts in my FP&A team. These are very sharp data scientists and quant guys that are inside of our organization. It was a very robust bottoms-up approach, stratified by product. Again, as Stu said, it utilized our actual realized pricing per product, and it was really applied across 50 relevant geographies. You know, the end result is really an overwhelmingly greenfield TAM of $23 billion, and that's what we're executing against. I'll give you a couple of additional growth illustrations on the next slide. I like to refer to these slides as our southwest to northeast charts. Think Tucson, Arizona to Bangor, Maine. You know, you've probably seen these, but or something similar to these before. You know, we have been able to drive a 48% ARR CAGR over the last several years with a 28% CAGR in logo growth during that same time. Again, getting back to the relationship between those two numbers, you know, that relationship absolutely illustrates a couple of things. Number one, you know, it is clear evidence that we are moving upstream in terms of customer value. And two, it is also evidence of the cross-sell, upsell motion that we have covered earlier. Again, 28% customer growth, 48% ARR growth. You know, those are pretty clear illustrations of the upstream action that we are actually implementing against and the cross-sell action that we are implementing against. This really has happened across the board, both cross-sell into SMB as well as new enterprise logos coming into the portfolio, both domestically and internationally. Obviously, the GAAP revenue is congruent with the trend in ARR. Again, this is a SaaS business model, high visibility, and the revenue is recurring in nature. The predictability and the congruency between GAAP revenue and ARR is evident obviously on these slides. We do typically sign deals, you know, in excess of somewhere in the 1-3-year range. Normally, they're the average life of these contracts is somewhere just under 2.5 years when you look at the entire portfolio and average the life of the revenue streams at inception. Real quick back to the durability concept. This is actually an illustration, you know, that we believe sort of supports that whole durability concept with respect to our revenue portfolio. You've probably seen charts like this before. Each one of these layers actually represents a revenue vintage. You know, obviously, the important dynamic when you look at this slide is that each one of these layers is growing as opposed to churning and contracting. That's obviously a really very important dynamic that we've been able to experience and execute against. This is a really good illustration of the retention dynamics of the revenue base, which as we, you know, already talked about, is over 90% retention. This also, you know, this also sort of introduces the net dollar retention topic, which you've, you know, heard us talk about the fact that we land large. Really what that means is with new customers, we typically land across an entire organization up front. You know, if an organization is gonna commit to securing the human layer, it just can't only cover a part of its employee base. That's just not how it works. This makes our sales motion a little bit different than the typical land and expand model because we really get 100% of the ARR up front. Because of this, you know, NDR has not been as meaningful a metric that we operate on. With that said, you know, we disclosed this, I think, for the first time at year-end last year, with 108% NDR being a very respectable metric. The cross-selling success is obviously having a big impact, which is actually a pretty good segue into our next slide. Again, another one of these southwest to northeast charts. These charts actually do illustrate the trend that we've been seeing in the cross-sell motion, right? This is sort of the transformation into a multi-product company, quantifying the success of these cross-sell motions. You know, interestingly enough, the actual number of customers with multiple products on the platform has more than doubled every year for the last few years. That's a CAGR of over 240%, that has more digits on it than most CAGRs that I'm used to seeing. There's you know this is a lot of traction over a relatively short period of time. Again, interesting enough, at you know at 22% penetration, which is a very, very good performance, it really does mean that we still have an existing base of over 36,000 customers that we haven't yet cross-sold additional products to. That's obviously a very exciting opportunity for us that we continue to mine. Given the fact that Compliance Plus, which is a product that launched in the middle of 2021, you know as you heard earlier, has sort of outperformed PhishER when we launched PhishER. You know, it really puts us in a position where we're very excited about the future of the cross-sell opportunity and how that will ultimately end up impacting the revenue stream. So I have one more bar slide, which is the next slide. Again, you know, we've talked about a couple of times, we definitely like to highlight that we focus on of sort of a balance of both growth and profitability. You heard it from Stu, you heard it from me earlier in terms of describing the business model. It's just part of our corporate DNA, and these margin trends are really an indication of the benefits of us beginning to achieve scale, and maybe not beginning to achieve scale, but achieving scale. You know, this is a company that has really focused on efficient execution. I do believe that these slides are pretty clear evidence of that efficient execution, both from a scaling standpoint as well as balancing the growth and with profitability. You know, we're continuing to make significant investments in growth to capture share and take advantage of this market opportunity that we have in front of us. We are also demonstrating the ability to leverage our cost structure as we scale. It's reflected in the non-GAAP operating margins. It's reflected in the GAAP operating margins. It's obviously also reflected in the free cash flow margins as you know, these favorable dynamics of the SaaS model. You know, our focus to be fiscally responsible in terms of capital allocation and capital management are sort of producing these southwest and northeast charts. I'm going to sort of wrap it up because you guys have been all at it for a really long time. I thought we would actually conclude on a slide that Stu presented earlier because I think it's actually a relevant and appropriate sort of conclusion slide. Again, we're sitting on a huge opportunity in front of us, you know, where we have established ourselves as a clear market leader. You know, we have a platform that continues to get more and more technically sophisticated, you know, creating larger moats, including, you know, a broad patent portfolio, strong AI, ML capabilities. You know, and honestly, our metrics really speak for themselves. You know, the Southwest to Northeast charts, I think, did a good job of illustrating the scale and the durability of our growth. You know, we've talked consistently about the fact that, you know, we're balancing the whole growth and profitability equation really baked into our corporate DNA. I certainly have seen no evidence that that's gonna change anytime soon. Just really thank you all for your attention for the last several hours, you know, arriving to Orlando and being part of this event. It's really great to see everyone. It's great to have you guys have the ability to have access to this team. We will open up the floor to see if you might have any more questions for us. Yes. Obviously, questions for our CFO first, but then we open it up to a general, kind of an AMA for everyone. From a mic perspective, obviously, we would need to pass the mic. First, let's go from left to right for a change. Let's go- Got a lot of hands. Slowly that way. Otherwise Just a quick one from me over here. It sounds like from your commentary, you expect the Russia-Ukraine crisis to possibly be a positive for the business. Are you guys seeing anything that could, you know, from what's going on overseas, that could negatively impact your ability to maybe expand internationally? Well, you know, and Stu, let me know whether or not. I mean, you know, we do no business in Russia. We do no business in China. You know, we're very well established in the U.K. We're very well established in Germany. We're becoming more and more well established across Europe. You know, the threat, I would say that the sort of the threat level as a result of of these events are probably making the risks in Germany and the U.K. and part of those places more acute. You know, if we were trying to aggressively expand in Russia and China, I would say that some of these events may be negative to us. No. That's absolutely not the case. We have really very consciously not even touched both Russia and China for very obvious reasons. We're not planning to have offices there, though those are not markets that we are interested in expanding into. Not too many people know, but the Russian economy is like the size of Italy or maybe Brazil. They make a whole bunch of noise, but they are punching way above their weight. So there's not all that much money there to begin with, not in our space. We feel that current threat levels are essentially tailwind for a platform like ours. Any other questions? Let's go back over. Hamza Fodderwala. All right. Thanks for taking my question. Just two quick ones. First one, for Bob. Thanks for the presentation. It sounded like earlier in your commentary, you're kind of alluding to perhaps the unit economics internationally are not gonna be as strong as they are domestically, which I think is not unusual, at least initially, when you're ramping. How do you think about closing that gap longer term as you get more scale? Well, I mean, that's the last word is scale. I think the response to that question has been, and it's the right response, is that there are, you know, investments that we need to make internationally in terms of establishing infrastructure, establishing, you know, teams of functionality, things like order processing. We have a shared service center, you know, in the Netherlands, and that needs to be staffed up a little bit more in order to be able to be responsive to time zones and responsive to scaling. Each one of the international markets does have its sort of unique nuances. There is, you know, there's market awareness marketing that needs to be done, brand marketing that needs to be done. There is sort of, you know, language investments that we need to make in the platform as well, in the content as well. Sure. All of those things actually are sort of upfront investments that make the unit economics for calendar 2022 and potentially calendar 2023 a little bit different than the long-term expectation. Oh, sorry. Give it time. Okay. Got it. I should have just said that. Now we'll get there. Sounds good. Just one quick follow-up, too. I think in the past, you talked about how in your contracts, there's a built-in 10% price increase every other year. No. It's not? Okay. There's nothing built in. Is that something you exercise or? We, over the last 5-6 years, what we have simply done is every other year, from December 31 to January 1, we have just added $1 per seat to the basic KMSAT platform. Okay. That is based on, really mostly the huge amount of content that we've added and a whole bunch of really strong features that were added to the platform over those two years. The strategy is to continue doing that, but this is not cast in concrete. We are essentially being flexible with that, but that is the intent. We've had practically no pushback on that particular strategy of slowly increasing the pricing. You have to understand that we are and have been applying the Google pricing strategy to conquer a new market, which is, as opposed to you price it as high as you can and what you can get away with, we are pricing as low as you can and still be profitable, and then start adding features and slowly move pricing up over time. Because this is how you penetrate new markets and actually develop them. Thank you. Sure. Brian. Great. Thank you. Bob, good to meet you in person. You too. At least a little later. Thank you for the presentation. I guess I wanted to piggyback off of, like, two comments. One you made early on in your presentation, which is, you know, a lot of this market is not displacement. Then another slide, I don't recall where it was in the presentation, but it showed, you know, I guess three or so different budgets that each of the products, I guess penetrates. How do you think about controlling spending, maybe on the back of that, how do you think about controlling spending for areas like compliance where it may be a displacement? Then also how you think about managing unit economics as you are penetrating different buyers or different budgets to increase your attach rates across the platform? Let me grab that one. Yeah. Okay. Sure. You're right. The Compliance Plus SKU is to a certain degree displacing compliance training in larger organizations because they have an existing vendor. In many of the SMBs, that is still greenfield, and so you have to break that out in different buckets. The existing compliance training market is highly fragmented. We've done our own research. There's many vendors, and we are actually presenting our price level at roughly half of what the average pricing for those types of training modules are. We are indeed talking to a different person in the organization if it is a larger size account. The SMBs, guess what? It's almost always the same person as the director of IT who does everything. We are actually expanding our Salesforce database with dedicated compliance accounts, basically job functions, so we can directly market to them. Got it. Helpful. Thank you. Okay. Thanks. Over there, Fatima. Thanks, Bob. Nice to meet you in person. A couple of speed round questions for you, and then I have a follow-up for Stu. The dollar net retention rate metric that you talked about and that you disclosed at 108%, you know, completely appreciate that that is very much tied to the fact that you have to go wall to wall with KMSAT, which is what you planned with. But I'm curious if you can give us some perspective on how that metric potentially differs between your SMB base versus your enterprise base. Then, a question on the profitability metrics that you shared with the southeast to northeast section of the slides. You know, in terms of the gross margin expansion that we've seen in the last couple of years, you know, how replicable is that from here? Are we sort of sitting at a ceiling? And then on a related matter, with respect to operating margins and free cash flow margins, can you give us a reminder or refresher as to the delta between those metrics, why they wouldn't track more closely? So- It's a lot. Sorry. What order we wanna take those? Repeat the last one more time. Just the Just the disparity between your operating margins and your free cash flow margins. I suspect it has something to do with the contract durations that you're seeing in the base, but quick sort of refresher on why that disparity would be so wide and what would cause that gulf to sort of shrink between those two, considering you are a SaaS-based business. I mean, I actually don't think I think that the relationship between those two numbers is actually been pretty consistent. The free cash flow, the absolute free cash flow number versus the absolute operating margin number, non-GAAP operating margin, so you get, you know, get the non-cash stuff out of there. That sort of differential, if you sort of look at the last several years, is not meaningfully different. This last year was a little over $40 million. I think the year before that, 2020 was somewhere in that neighborhood. And this is really just a function of, it's really just a function of working capital for the most part, right? It's just really a function of, you know, we collect, you know, we collect 12 months of cash up front. As ARR is sort of vectoring at that level, you know, you're always collecting the cash for the most recent 30 days of sales transactions. So you're always collecting a sort of higher level of cash. The differential hasn't been, you know, meaningfully, you know. I mean, it's obviously growing as ARR gets bigger because the last 30 days of sales is bigger, but not, you know, it's not like we have 90-day DSOs. So it's not like. You know, it's just. It's. They're pretty closely tied, uh, from, I mean, from my sort of forensics over the last 3 years when you look at the absolute free cash flow dollars versus the operating income dollars, that relationship is pretty consistent. Just to close out, any commentary on how we should think about the gross margin trajectory, given we've seen such a massive improvement in the last couple of years? Any high level observations or comments on net retention rate, bifurcated between the SMB base and the enterprise? Yeah. I think on the margin side, I think this question got fielded quite a few times in the year-end earnings call. You know, 2022 is, you know, we are doubling down on international investments. When you look at sort of the guide with respect to what margins are expected to look like in 2022, it looks inconsistent with 2021. It is really around sort of the question that we were talking about in terms of unit economics of international. You know, the answer is very similar to what Stu said. We'll get there. I do think that the margin profile of the business is really on a path to getting back to 2021 levels and expanding on 2021 levels as we scale the business and ultimately have the ability to leverage the fixed cost structure. Because the fixed cost structure is not scaling at the same pace as the variable cost structure. We do, you know, we're investing in sales, we're investing heavily in marketing, we're investing heavily in lead gen, we're investing heavily in brand awareness in markets that aren't aware of us or that are not as mature in terms of awareness training. Yeah. We'll get there. Huge headcount. Right. Yep, exactly. 2022 is big investment in international. Yeah. On the NDR side, you know, Stu, I don't know if you have any different thoughts, but I don't believe that the NDR formulas or the NDR metrics are meaningfully different between SMB and enterprise. Now No, they're actually surprisingly similar. Yeah. Now I do. You know, Stu made the point earlier that if you lose, you know, an enterprise churn is painful, right? That, you know, this is much more impactful, obviously, on NDR if you lose an enterprise customer. You know, the good news is that, you know, we're cross-selling and upselling and adding, you know, both SMB and enterprise logos at a very acceptable pace, very admirable pace. Very good. Next, over there. Hi, Bob. Thanks again for the presentation. Changing topics entirely. KnowBe4 has been acquisitive. I'm curious about your take on how do we measure the success of an acquisition that you do? What's the quantifiable way that you look at acquisitions? Stu, I'd love to hear your response to that as well. You know what, Rob? Get over here, man. This is Rob Henley, our- Rob walked in. Corp dev man. He is the guy to answer that question. Here you go. Introduce yourself. Hey, everyone. Yeah, Rob Henley, VP of Corp Dev. I've been with the company about five years. We've been through seven acquisitions, the most recent one being SecurityAdvisor. I think on SecurityAdvisor, our key metric for measuring there is ARR from the new product when we launch it. That's gonna be the key thing we're looking at every day once we get that product out. Overall, we generally track two or three high-level goals from each acquisition we do, and we report progress on those to the board quarterly. We track, you know, a whole host of metrics underneath that for each acquisition, but it kind of varies depending on the strategy. SecurityAdvisor is obviously a new product. That's the goal, launch that product and get it out there and generate ARR from that product offering. Um- Can you share the goal that you have for SecurityAdvisor? It's closely tied to the earn-out numbers that I think have been discussed when we did the acquisition announcement. We talked about our $40 million earn-out threshold over the three years. Thank you. Rob. Appreciate it. Rob. The- Nice to have you. Yes. This is how new I am. Yes. It's a great opportunity for Bob here at KnowBe4 for basically everybody he hasn't met yet. Yes, go ahead. Hi, Madeline Brooks from Bank of America. Nice to meet you in person. Just one question. You know, if I look at how you ended the year and then fourth quarter as well, it's really strong growth, and we're excited about it, but the stock has been relatively flat since the IPO. What do you think investors are missing? I have an opinion. If I look at how we've been doing compared to a whole bunch of other IPOs, we're holding our own. There's a, I don't wanna call percentages out, but a number of IPOs are trading below their initial day. As far as I'm concerned, we are just focused on execution. As a CEO, my job is to look five years in the future and continue to build that ARR. There is a bunch of. The world at the moment is not happy. So there's a lot of volatility, risk on, risk off. I just have to focus on ultimately creating shareholder value long term, and I cannot be too distracted with, you know, the stock price being as volatile as it is. We're not unhappy at all. Let us do our thing, and we're just gonna get there. I would just recommend waiting till the earnings call and you will see how we're doing. Thanks so much. You bet. Anybody else? Over there, back. There's a lot of people that are losing. Yes. Losing power on their computers. They're all back in the corner. Yeah, that's right. Powering up. Yeah. Hey, David Hynes at Canaccord. I wanted to ask about Compliance Plus. Yes. Remind me on the pricing construct, like, where you're landing versus incumbents there. I thought I remember you saying something like we're half the price or something. Yeah, we did market research. We have in our midst, right next to you, John Just, and he is gonna grab that mic and answer your question. The follow-up to it would be just, like, what has been the competitive response, right? I mean, those have to be massively profitable cash cow businesses for the incumbents. They're not just gonna let that roll off their books. Maybe talk about what you've seen in the market as a follow-up. Okay, we'll break that in two. John will answer your initial question, and I will answer your follow-up. Yeah. I think on average, you're looking about $15 per seat, per user, and we're coming in at about $8 per user, $7-$8 generally. Yeah, going in, again, with a price that is a no-brainer. Obviously not as mature of a library, like I mentioned, 200 pieces of content. A lot of our current customers realize we're a content machine and engine. They say, "Okay, well, they have 200 today. They're probably gonna have 400 next year sometime." That's probably a pretty good estimate. The response has been sort of mixed. Obviously, there's some interest in what we're doing, and there are some people who have done the opposite, where they're doing compliance training, and then they're trying to dip into security. I think a lot of people are thinking this is a lot harder than you think, right? I don't think they're too worried about us coming in with all our customers at this point, but they should be. The other side is, have we seen any competitive response? Not really. The reason is that like I started out with DJ it is a fragmented market. There are no clear leaders. There is no 800-pound gorilla in that particular space. There's a bunch of mom-and-pop shops. There's a couple of smaller ones. There's one or two public companies that do this. But they are not necessarily marketing powerhouses. I'm expressing myself mildly. Anybody else? We have two more minutes, and we're a little bit behind, but we can take one or two more questions. If there are no more questions, then thank you very much for making it out here and suffering through three hours of slides. I hope it was tolerable. We hope you will stay because there are many very interesting breakout sessions where you can go do deep dives and get into the nitty-gritty. If you have to fly back, have a good trip back, and we hope to repeat this soon. Thank you very much. Yep. Thanks, everyone.
Loading workspace