Welcome to Mandiant Q4 2021 and full year 2021 financial results conference call. My name is Sam, and I'll be your operator for today's call. I will now turn the call over to Barry Stern, Senior Vice President of Finance at Mandiant. Barry, you may begin. Thank you, Sam. Good afternoon, and thanks to everyone on the call for joining us today to discuss Mandiant's financial results for the fourth quarter and full year of 2021. This call is being broadcast live over the internet and can be accessed on the investor relations section of Mandiant's website at investors.mandiant.com. With me on today's call are Kevin Mandia, Mandiant's Chief Executive Officer, and Frank Verdecanna, Executive Vice President and Chief Financial Officer of Mandiant. After the market closed today, Mandiant issued a press release announcing the results for the fourth quarter and full year 2021. Before we begin, let me remind you that Mandiant management will make forward-looking statements during the course of this call, including statements relating to the company's guidance and expectations for certain financial results and metrics, the company's priorities, initiatives, plans and investments, drivers and expectations for growth and business transformations, expectations, benefits, capabilities and availability of new enhanced offerings, market opportunities, go-to-market strategies and strategic partnerships. These forward-looking statements involve a number of risks and uncertainties, some of which are beyond our control and could cause actual results to differ materially from those anticipated by these statements. These forward-looking statements apply as of today, and you should not rely on them as representative of our views in the future, and we undertake no obligation to update these statements after the call. For a detailed description of the risks and uncertainties, please refer to our SEC filings as well as our earnings release posted an hour ago. Copies of the documents may be obtained from the SEC or by visiting the investor relations section of our website. Additionally, the financial measures that will be discussed on the call are non-GAAP metrics, except for revenue and operating cash flow. Our non-GAAP measures exclude stock-based compensation, amortization of intangibles, non-cash interest expense on our convertible debt and convertible preferred equity, restructuring charges, accretion of Series A convertible preferred stock, and other non-recurring items. We provide reconciliations on the non-GAAP financial measures for the most directly comparable GAAP financial measures in the investor relations section of the website, as well as in the earnings release. In addition, the financial measures that will be discussed on the call are for Mandiant's continuing operations. With that, I will turn the call over to Kevin. Thank you, Barry, and thank you to all the investors, employees, customers and partners joining us on the call today. As always, we appreciate your interest and support in Mandiant. We entered the fourth quarter as FireEye, and we exited the quarter as Mandiant. With the divestiture of the FireEye Products business behind us, we are now laser-focused on the following four objectives. First, defending Mandiant customers by creating a multi-vendor XDR capability that leverages our customers' selection of their security controls. Second, extending our intelligence leadership position by leveraging our unique knowledge of cyber threats across our products and services. Third, advancing our security expertise leadership by responding to breaches that matter and helping organizations of all sizes transform their security programs to address new and novel attacks. Fourth, accelerating the adoption of the Mandiant Advantage platform as the vehicle to deliver all Mandiant capabilities to our customers. Today, businesses and governments face increasingly complex attacks, and yet their ability to defend, test, and measure the efficacy of their cybersecurity is most often vague and unreliable. We believe Mandiant has a critical role to play in identifying and closing security gaps with a clear method of validating security effectiveness. Today I will provide highlights to demonstrate our early success in relaunching the company as Mandiant. Now let me touch quickly on our Q4 performance before diving into highlights on the business. The fourth quarter of 2021 was the last quarter where our primary sales focus was on billings. It is the way we have measured success in the past and the mechanism through which we compensated our sales team. Our billings focus was effective and generated billings growth of 54% year-over-year to $229 million. Platform, cloud subscription, and managed services billings grew 83% year-over-year to $136 million, and services billings grew 25% year-over-year to $92 million, which were both record highs for our business. We ended the quarter with $410 million in deferred revenues. I am very proud of our team for posting such a strong quarter, and we look forward to the positive impact of our ARR-focused sales compensation plan now in effect for 2022 as we march towards our target of 30% year-over-year ARR growth by the end of this year. Frank will go into more detail on our financial highlights in his remarks, so I'll move on and discuss some operational highlights. In the fourth quarter, we had record billings, record revenue, and the highest ending ARR for threat intelligence. This success is rooted in our investment in a global research network. To deliver effective cyber defense, we believe you must have your finger on the pulse of adversaries around the world, constantly monitoring the development and deployment of their tools, their infrastructure, and their underground economies. You must study their targeting trends. You must have frontline experience responding to breaches globally. You have to understand every aspect of the threats to appropriately adapt your defenses and close your security gap. Our entire business model leverages and benefits from Mandiant's intelligence advantage. Over the last decade, Mandiant established this advantage by building and extending a global threat intelligence team, as well as elite security services to serve as the first responders to cyber threats. I would like to provide some additional details of our threat intelligence differentiation to help all of you understand our investments in research, which certainly leads to a different investment spending profile than most traditional software companies. Our investment in intelligence research includes a subset of approximately 150 of our 350 intelligence analysts aligned into six functional areas. First, we track intrusions that are conducted by nation-state actors to steal sensitive data, disrupt operations, or destroy data and systems. Second, we have a set of experts focused on criminal threats, including ransomware and other financially motivated cyberattacks. Third, we track cyber physical threats involving the manipulation or damage to energy and water or utilities and other critical infrastructure that relies heavily on operational technology. Fourth, we have a group of experts that track vulnerabilities and their exploitation so our customers can be informed and up to date with technical details of the latest attacks and refine their security posture to defend against these new attacks. Fifth, we have a group working hand-in-hand with social media platforms and governments to identify information operations involving disinformation campaigns. Lastly, we have a group focused on distilling all our knowledge and intelligence into executive-level security concerns. This drives risk management activities and security investment prioritization. The work products from these six areas of focus are available through the Mandiant Advantage platform, and they power all of our offerings on the platform. In addition to these six focus areas, we have a collection of employees that actively monitor ransomware groups and other hostile entities to identify group members, group objectives, including their techniques in targeting. This is essential work. It has allowed us to notify over 2,300 organizations in 2021 alone that were not Mandiant customers at the time, that they were either successfully attacked or about to be attacked. Our notification spared many of these organizations from business disruption. These are just some of the details that demonstrate we have an intelligence capability without rival in the private sector. Our intelligence research function provides a competitive moat, and it is already fully scaled. We expect to have exceptional leverage from now onwards as we grow our revenue with very little incremental research expense beyond current levels. Our security expertise is also market-leading, and I would now like to share a few brief highlights about Mandiant services. We had a record fourth quarter for Mandiant consulting, with revenues at $66 million, representing a 22% year-over-year increase, while growing services deferred revenue to $139 million. This is the 14th out of the last 15 quarters where services reported record revenues and the 11th out of the past 12 quarters in which services year-over-year growth was greater than 20%, establishing a predictable pattern of high performance. We now have over 600 professional consultants worldwide, and we continue to have great success recruiting talent as we believe our mission to be trusted advisors to the most important organizations in the world attracts great talent. Now I'd like to discuss some platform highlights. We are continuing to enhance Mandiant Advantage, our multi-vendor XDR platform, with an emphasis on capabilities to support our consulting and managed defense requirements. One important capability of Mandiant Advantage is to provide deep integrations with leading security companies. To that end, today, we announced a strategic partnership with SentinelOne. Mandiant Consulting can now leverage SentinelOne's Singularity platform to perform both incident response and our compromise assessments. By using Mandiant Advantage to leverage SentinelOne in engagements, our services can establish a natural leave behind of Mandiant Advantage to better defend our joint customers. In addition to supporting our consulting team, we are building support for the SentinelOne Singularity platform into our managed defense service, and we expect to make this offering available in the second half of 2022. We also plan to have strategic go-to-market alignment with SentinelOne to ensure joint commitment and penetration into our respective customer bases. SentinelOne Singularity platform is the third endpoint security platform that now Mandiant Consulting and Managed Defense supports, along with FireEye, their endpoint security, and Microsoft Defender for Endpoint. We intend to continue this trend and support other leading security providers with both our service offerings as well as our managed multi-vendor XDR capability. We believe over time that our Mandiant Advantage platform and managed XDR business will be significantly larger than our services business. We also believe the growth of the platform and Managed Defense will drive margin expansion, operating leverage, and non-GAAP profitability, and scale Mandiant as a critical partner for security operations teams to operate efficiently and effectively. Given our unique combination of frontline and global threat intelligence, our shift in focus from billings to ARR, and our plan to enter into more technical partnerships and integrations like our SentinelOne partnership, so we can offer the most powerful multi-vendor XDR solutions all give me confidence that Mandiant's growth will accelerate. I would like to now update you on our CFO search. We are in the midst of the process now, and we have several very qualified candidates and strong interest in the opportunity. Frank is helping us find and select the right successor, and I'll make a further announcement when I have more information to share. In conclusion to my remarks, Mandiant is more than merely a software company or a services company. We are a security company. We have a human component to our technology with our Mandiant Services who respond to over 1,000 security breaches per year. We have a global network of threat researchers in dozens of countries that speak over 30 languages, collecting, analyzing, and disseminating timely threat intelligence to power our offerings. We have technology, the Mandiant Advantage platform, to allow all organizations to take advantage of our security expertise and early knowledge of the new and novel threats. As a result of this combination of experts in global threat research, I believe we are the only company that has the actionable intelligence required for organizations to close their security gaps. This is what differentiates the capability we deliver via the Mandiant Advantage. With that, over to you, Frank. Thanks, Kevin, and hello to everyone on the call. Before we move on to the details of our Q4 results and our guidance for Q1 and full year 2022, let me remind you I'll be referring to non-GAAP metrics except for revenue and operating cash flow. I'll also only be talking about Mandiant continuing operations. Now let's look at our reported results. Billings increased 54% from Q4 of 2020 with a strong performance in platform cloud subscription and managed services and our professional services. We ended the quarter with record deferred revenue of $410 million, which is up nearly $95 million sequentially. The platform cloud subscription and managed services category grew billings by 83% year-over-year in the fourth quarter, bringing full year 2021 growth to 66% over 2020. Growth was driven by solid demand and record billings across all Mandiant Advantage platform modules and our managed defense solution. While we encourage you to look at revenue as the best metric to evaluate our professional services performance, it's still worth noting that professional services billings were up 25% year-over-year in the fourth quarter. Our ARR ended Q4 at $279 million, or 23% year-over-year growth. We did see less translation from billings into ARR in Q4 as it was the last quarter of total contract value or a bookings-based comp plan for both Mandiant and FireEye sales reps that were still selling Mandiant solutions. As a result, we saw a significant increase in average contract length, moving from 22.1 months in Q3 to 24.9 months in Q4. In addition, we had a higher mix of renewals, including two renewals in the $15 million range, one of which was a multi-year. In Q4, we added 225 new logo customers, up 2% from Q4 of 2020, and closed 32 transactions greater than $1 million compared to 28 in Q4 of 2020. Turning to the translation of our strong billings and ARR performance into revenue, Mandiant revenue increased 21% from Q4 of 2020, with a strong performance in platform cloud subscription and managed services and our professional services category. Our revenue of $133 million was at the top end of our guidance range we provided in last quarter's earnings release. The platform cloud subscription and managed services category grew revenue 18% year-over-year in the fourth quarter. Professional services revenue increased 23% year-over-year in the fourth quarter, capping a very strong year of consistent 20+% year-over-year growth across all quarters in 2021. We ended the year with $139 million in services deferred revenue. Now let's look at gross margin, operating margin, and cash flows. Our gross margin for the fourth quarter was 63%, up from 60% last quarter and 59% in fourth quarter of 2020. The platform cloud subscription and managed services gross margin was 72% in the fourth quarter, up from 70% last quarter and 67% from Q4 of 2020, driven by increased scale in our subscription business and reduced allocations of IT and facility into COGS as a result of reimbursements from the Transition Services Agreement, or TSA, to support the FireEye Products business. Professional services gross margin was 54% in the fourth quarter, up from 51% last quarter and 49% in the fourth quarter of 2020, primarily due to reduced allocations of IT and facilities into COGS as a result of reimbursements from the TSA. Our operating margin for the fourth quarter of -17% was an improvement from last quarter's -27% and from -22% in Q4 of 2020. Improvement in the fourth quarter operating margin was primarily driven by leverage from our revenue growth and the start of the TSA reimbursements beginning on October 9, which had the effect of offsetting some of our IT, facilities, and G&A expenses. Operating cash flows for the fourth quarter were -$10 million, compared to -$14 million last quarter and compared to -$2 million in Q4 of 2020. Now let's turn to our current outlook for the first quarter and full year 2022. As a reminder, beginning in January 2022, our validation deals are recognized 100% ratably as a result of changes to on-premise validation deployments, which now enable customers to receive real-time intel updates as part of the Mandiant Advantage platform. For Q1, we expect ending ARR to be in the range of $291 million-$297 million, which implies a year-over-year growth rate of between 23% and 26%. We expect revenue to be in the range of $128 million-$131 million. On a year-over-year basis, the midpoint of our guidance range implies revenue growth of approximately 13%. We expect a year-over-year growth rate for the subscription revenues to be in the range of 3%-5%. Given Q1 2021 included approximately $8 million in upfront validation revenue, the change to ratable rev rec had an impact of approximately 15 percentage points of year-over-year growth in our subscription revenue category, and 7 percentage points in our total revenue year-over-year growth rate. We expect a year-over-year growth rate for services revenues to be in the range of 20%-22%. We expect gross margins of between 59% and 60% in Q1, which is down year-over-year, primarily due to the validation rev rec change. We expect an operating margin of between -22% and -24%, implying a slight increase in operating expenses from Q4, primarily driven by an increase in payroll taxes that normally occurs in Q1, offset partially by less marketing and branding costs in Q1 versus Q4. We expect earnings per share of between -$0.13 and -$0.15. For 2022, we expect an accelerating ARR growth rate throughout 2022, ending Q4 at a year-over-year growth rate of 30%. We expect revenue of approximately $560 million at the midpoint of our guidance range, representing growth of approximately 16% for the year. We expect a year-over-year growth rate for SaaS revenues to be in the range of 14%-16%. We estimate the headwind from the validation rev rec change to impact the subscription growth rate by approximately 13 percentage points. We expect a year-over-year growth rate for services to be in the range of 16%-18%. We expect gross margin of between 61.5% and 62.5% as the subscription portion of our business continues to scale up, partially offset by the headwind from the validation rev rec change. We expect operating margin of -13% to -15%. These ranges result in non-GAAP earnings per share of -$0.36 to -$0.38 based on weighted average shares outstanding of 240 million. Embedded within our annual guidance are several assumptions. Our operating margin range assumes the TSA reimbursement as a result of the divestiture continues through approximately the end of Q3 of 2022. Our operating expenses include non-recurring branding costs in the amount of approximately $10 million. Operating expenses includes approximately $20 million in stranded costs relating to legacy facilities, systems, consulting, personnel costs, and contracts required to provide ongoing support of the TSA that are not expected to be reimbursed. I realize there's a lot of detail here, but to summarize, we expect to exit 2022 with Q4 ARR year-over-year growth rate of 30%. We expect 2022 revenue growth of approximately 16% at the midpoint of our guidance, which would have been approximately 6 percentage points higher were it not for the Ransomware Defense Validation rev rec change. We expect the validation rev rec change to dissipate for 2023 and expect acceleration in 2023 with revenue growth at 25% or more over 2022. We expect to deliver operating leverage by improving our operating margin loss in 2022, and we expect to achieve non-GAAP operating margin profitability for the year of 2023. We achieved a significant milestone in Q4, divesting the FireEye Products business, which I believe puts us in a stronger position to consistently deliver accelerating growth and improved operating leverage. We look forward to discussing our strategy and long-term model in more detail at our virtual Analyst Day on March 10th. I will now turn the call over to the operator for questions. Thank you. If you'd like to ask a question, please press star followed by one on your telephone keypad. If for any reason you'd like to remove that question, please press star followed by two. As a reminder, if you are using a speakerphone, please remember to pick up your handset before asking your question. We will now take our first question from Jonathan Ruykhaver of Baird. Jonathan, your line is connected. Please proceed. Jonathan, how are you? Yeah. Hello, guys. Been good, Kevin. I'm wondering if you could touch on just the ARR expectations that you've talked about for fiscal 2022. When you look at it implies- Yeah. Net new ARR that's basically- Mm-hmm. More than what you added over the last couple years. Just talk about your confidence- Yeah. In that target, maybe what you see in the pipeline Yeah. Sales capacity gives you, again, that confidence. Yeah. A couple thoughts there. First and foremost, comp plan absolutely matters. When you look at our billings in Q4, I remember going, "Wow, that's eye-popping billings. That's fantastic." Then when you peeled it back i t came to 22% ARR growth, and that is because our comp plan was based on billings, and you see that in the extended contract length. One of the things we are doing is everything that Mandiant does that scales you can buy through subscription is make sure that our comp plan marries to driving ARR growth. That's the first change we made that will make a difference, period, in a positive way. It may shorten the contract length, Jonathan, but it will increase ARR a few points. We just get a lift right there. The second thing is we're launching several new offerings, like active breach intelligence and then a very simple, lightweight, and affordable Ransomware Defense Validation that I like. I believe the partnerships matter. That's a hot market to say, "Hey, listen, Mandiant's got your back. You give us security telemetry from supported products, and we've got you covered." You know, I call it the shields up. Others call it, probably more professionally, extended detection and response market. I believe in that market. I believe that's a way our Mandiant people can be a seamless extension, even though it can be, you know, 90% tech behind it. It allows people to use our experts as a virtual extension of their team. As we expand to partnerships like SentinelOne, like Microsoft, those partnerships matter we wanna go in and say, "You get the Mandiant brain, the Mandiant analyst to defend you regardless of the technology you're using." I buy that. That to me is what we're betting on. I can tell you it resonates when I talk to folks. What we've got to do is continue the innovation to support it. I think, you know, we got Microsoft done. We're getting SentinelOne done, and we're gonna have others, you know, and that's why we're excited about that strategy. That's helpful, Kevin. I wanted to also, as my second question, just touch on channel sales. I know you hired new leadership last fall. Yeah. Can you just update us on your thoughts regarding the channel opportunity beyond just fulfillment? Curious on the role you might see for SI, systems integrators and the public cloud providers. Yeah, Jonathan, this is Frank. I think one of the things that we really pivoted to with some of the newer offerings is really making it fit the channel much better than some of our, you know, previous offerings that were more focused on the security professionals. I think, you know, we're trying to build products that fit the channel, things that can go down market, that are easier to demo, easier to deploy. I think some of the new offerings that Kevin mentioned will fit the channel a lot better. You know, if you look at where we're at from a channel leverage perspective, we only have a significant opportunity ahead of us. You know, that's not an area that we've done great in the past on, but I think we feel pretty good about some of the new offerings and some of the new focus areas there and some of the investments we're making in the channel. Okay. Very helpful. You know, big thing, you know, and Jonathan, even I'm going back to revisit your question, too. You know, I thought about it as well. You know, one of the. It was without a doubt, the largest reason why we were losing Managed Defense customers was they were choosing a different endpoint technology. Literally, by going to Microsoft or SentinelOne and other endpoint techs that we're gonna be working with, we save those, you know. People are making decisions based on tech alone. It will, you know. We'll be able to grow it faster, and at the same timeframe, we'll be able to protect our base far better, by working with other endpoint technologies, and quite frankly, other security technologies besides just endpoint. Thank you. You're welcome. Thank you, Jonathan. Our next question is from the line of Hamza Fodderwala of Morgan Stanley. Hamza, your line is open. Please proceed. Hey, guys. Thanks for taking my question. Yeah, sure. I thought for my first question, just real quickly, wanted to address the elephant in the room. There are obviously some reports around a potential acquisition by Microsoft. Any comment on that whatsoever? Yeah, Hamza, as a matter of policy, we're not gonna comment on rumors or speculation. Okay. Fair enough. Yeah. Just thought I'd take a shot there. Just for a second question for Frank. You know, when you think about the puts and takes around the acceleration of 30% ARR growth, how should we think about sort of the underlying drivers behind that? Between things like net expansion rate, which I think is, you know, a little bit above 100% now, or like customer count growth or, you know, larger, you know, deal sizes up front. Like how should we think about the path to 30% ARR growth exiting this year? Yeah, I think, Hamza, we feel really good about that. If you look at our guidance for Q1, we're expecting ARR to grow between 23% and 26%. If you look at the new offerings that we're launching and some of these partnerships, you know, they only benefit, you know, each quarter thereafter. If you think about like the SentinelOne partnership, you know, the real traction and new deals that will come for that will likely be in the second half of the year. Again, acceleration there. The attack surface management acquisition we did in August, you know, had a great Q4, and, you know, we're really excited about kind of launching that in the year. Then if you think about kind of the stage and maturity of, you know, validation and automated defense, all those subscription offerings kind of move forward in 2022, which should provide a pretty big boost. Kevin did mention earlier that, you know, we do feel that we're gonna have better retention on the managed defense side as we continue to add new endpoint players. Got it. Just to clarify, so it sounds like customer count growth, module upsell. That's sort of in that order how we should think about the path to 30% ARR growth. Yeah. I think, you know, if you look at where we sit today, less than 20% of our customers have more than one module. So we have a huge cross-sell opportunity just going from one module to two modules to three modules. Yeah. You know, Hamza, you got me realizing, you know, when I wrote my first earnings script, it was all about all the reasons why ARR was gonna go to 30%, and then I went some other direction. Here's the reality. We have more to sell. We have focus on selling it. We have compensation alignment to sell for ARR. We have partnership alignment now because we're not in endpoint, network, cloud SIEM, and email security anymore, like FireEye when we were all one company. We get real partner leverage, and we can go out and get that. With that, you get better retention. You know, we've already done the unglamorous integration of every module. You can now have the platform and all the modules, and it's one experience. That's something that doesn't sound like a big deal. It absolutely is because as we deploy now, we're working for instead of just deploying a module, we deploy full platform with one module activated, and it makes it very easy for us to scale. It's a small thing, but it has a tremendous influence on the buying patterns, just having it all integrated into a single experience. Thank you. Thank you, Hamza. Our next question is from Brian Essex of Goldman Sachs. Brian, your line is connected. Please proceed. Great. Thank you, and thank you for taking the question. Kevin, maybe if, Yeah You know, we could start by just touching on, you know, now that you've spent some time operating, you know, with the ability to cross-sell the controls diagnostic platform Yeah. I guess the endpoint, you know, endpoint partnerships notwithstanding, but outside Yeah ... of endpoint, you know, where have you seen the most success selling in other platforms, or should we expect to see similar partnerships with broader, like, network security vendors like maybe a Palo Alto- Yeah With better integration there? Like, how should we think about that strategy going forward? Yeah, Brian. I'm gonna do everything I can to not nerd out, and then Frank's gonna fix this. Network security integrations are easy. It's that simple. The true differentiation for us usually is endpoint interrogation. That's where Mandiant doesn't just say, "Hey, you may have a problem." We like to have that premium experience of, "Oh, you have a problem, and we can fix it for you." That usually requires endpoint technology to verify. With the network stuff, it's just all the formats are similar. You know, the telemetry data from PAN versus Fortinet versus other technologies, for the most part, we can already absorb those and work with those. Technically, we can already work with the network-based security organizations. Where we like to go deep and apply our expertise just happens to be more differentiated on the endpoint and finding the new and novel. Usually, what you'll get is on the network security platforms, you see the smoke. To see what's actually causing this fire, you gotta go to the endpoint and figure it out. That's a long-winded way of saying this. With the network security stuff, we can already leverage it for the most part, and we just gotta, you know, we have a new leadership in charge. Marshall Heilman, our CTO, is leading those technical partnerships, and he used to lead our Managed Defense. He's gonna go out there, and we're gonna get, you know, in my opinion, we're gonna pursue partnerships with the security vendors that our customers are relying on to defend themselves. What we provide with the Mandiant Advantage is that Mandiant analyst automated. You know, all our intel, all our expertise, and quite frankly, a big button saying, "Hey, what do you think about this?" We wanna become part of the workflow for the security operations that are using all these, you know, different technologies. Network security will happen. Endpoint security will definitely happen. You know, even over time, I could see us figuring out, "Hey, how do we work with some of the email security folks as well to make sure we can test and kinda code that?" By the way, obviously cloud. Gotta have cloud visibility, know your assets in the cloud and be able to defend at the big infrastructure providers. Got it. That, that's helpful. Maybe kind of we can dovetail into your SentinelOne partnership. Yeah. How practically should we think about your ability to leverage Mandiant Advantage, how it's integrated with Singularity, and is there any overlap there? Yeah ... with what you may have had left over versus what they come to the table with in Singularity, that kinda makes it maybe more complementary in certain situations? The biggest thing we wanna do with this is really enable our consultants to respond to breaches with it. That means be able to deep dive and interrogate a box when whatever security programs folks had just didn't work or a process failed or the attackers were that good. First and foremost, we like endpoint security companies like SentinelOne, where we can do incident response with it. They'll like that because we'll get the phone call, we'll go respond, and maybe we use their tech to do it, and they get, "Wow, that's a nice introduction into a new customer." We also wanna be able to do compromise assessments. There's gonna be, you know, other security providers that we're gonna look to partner with to do the same things. From the incident response and consulting standpoint, we do wanna work with the endpoint providers that allow us to successfully carry out our mission of being the best in the world at responding to breaches. In regard to Mandiant Managed Defense and the Mandiant Advantage, we wanna be able to take telemetry in, and the first thing you do with any technology is, can we get great detection capability with that technology? Hey, you've got a problem. The second step is a deeper integration to verify, hey, it's not just detection, but we have confirmed problem. That's where we wanna go with the endpoint techs. It's a little bit more than just getting an alert from SentinelOne going, "Okay, SentinelOne thinks this is bad. Let's tell a customer that SentinelOne thinks this is bad." It's gonna be we get an alert from SentinelOne, interrogate box and say, "Oh, it is bad. It worked. We got a problem. We've got a threat on the network." I'll leave you with this thought, Brian. Historically, people have always said, "Thank God my endpoint triggered on this piece of malware. It saved the day." What it didn't do is trigger on three other things that the bad guy happened to be doing. It gave people a false sense of, "Oh, we're good to go," when in reality, they missed other things the attacker was doing. Long-winded way of saying we're gonna go deep on the endpoints. We wanna be able to inspect and confirm incidents on the endpoint. We may not get there overnight, but the reality is that's our intention. Got it. Have you seen a lot of traction with Defender, you know, with, you know, just referencing another partnership? Yeah. What, you know, you said a lot. Here's what I have seen. When we- Right. First off, in regards to defense, when we go in, we've had customers say, "Hey, we're going over to Defender." We didn't have to say, "Well, okay, surrender the account." We support that, too. You know, every endpoint's a little bit different. You know, there was a time, you know, when we used a FireEye endpoint for everything. We'll get different things from different endpoints, but we absolutely are defending Microsoft or Defender, you know, the Defender endpoint customers. Got it. Very helpful. Thank you. Yeah. Thank you, Brian. Our next question is from Rob Owens of Piper Sandler. Rob, your line is connected. Please proceed. Thank you. Thanks for taking my question. Just wanna focus on, you know, obviously a busy fourth quarter with the divestiture. Anything else logistically that you guys need to get done, or do you have all the pieces in place? You've got the new compensation as well to move forward from here. Just thinking of the risk profile around execution. Yeah, Rob, I think, you know, our biggest risk, I think, was Q4, when we were kind of finishing out the year as two separate sales forces, but still trying to sell both sides of the fence. You know, as we enter 2022, we feel really good because we've got one comp plan aligned with kind of the corporate goals of really maximizing and increasing ARR. Yeah, I think the divestiture, kind of the risk of any disruption's behind us. You know, we obviously have an ongoing TSA that is going well, that, you know, will carry through, you know, the good part of 2022. Yeah, I don't see any real challenges that we're facing. I think we've got, you know, the right team to go tackle, you know, what we're trying to do, and I think we've got a lot more laser focus on really driving the things that are gonna, you know, take this company to the next level. On the services side, with the guidance for 2022, any governors on growth or anything intentionally there that's kind of holding that back? 'Cause it would appear that, you know, you've probably got as much business as you can... Yeah ...address from an incident response perspective. Yeah. Yeah, Rob, you know, it. I always wonder if I should answer it this way, but I'm going to anyway. We're not growing services as fast as we can. We're not a services company. We don't wake up every day and go, "Let's maximize services growth." We wake up every day making sure we have the right people to do the right things, and I think growing between 20% and 22% like we have for years is actually really performant. You're right. I mean, I guess we could look to inorganically grow or hire faster. We haven't. We like the component we have because it's doing very strategic work. Does that mean we say no to the inbounds? Yes, it does. Does it mean could we grow it at, you know, higher? Yes, we could. For us, services is strategically important as we build our platform and our XDR capabilities. We're happy with how it's performing. That's the best way to answer it. Rob, I think, you know, one of the things we're really excited about is the fact that we have been building up a services deferred revenue and ending Q4 at $139 million. It does give us a lot better visibility and gives us a little bit more opportunity to hire a little bit ahead of the curve because we have a pretty good view into upcoming engagements. You know, similar to 2021, you know, we typically overachieve a little bit on services just because we target kind of to grow at the high teens, but we tend to grow a little bit over 20%. You know, as we look at 2022, I think we feel really good about the demand environment, and I think we feel really good about our ability to hire and ability to retain. What typically drives that overage then? Is that pricing or is that utilization? Huh. You're actually getting more headcount towards the end of the year? It is bursty chargeability when you do IR. Sometimes you're the emergency room doctor. Okay. Okay. Okay. What you see is a spike in what I call chargeability. The hours that people work, they're working them. That's traditionally it. I think our rates are very competitive, meaning for an elite services corps, we charge the right amount. You know, and Rob, I'm old school when it comes to, like, the fastest way to have a morale hit in services is to have anyone on a beach. You know what I mean? I have to admit, we probably run them hot a little bit. All right, guys. Thank you very much. Thanks, Rob. Thank you, Rob. Our next question is from Jonathan Ho of William Blair. Jonathan, your line is connected. Please proceed. Hi, good evening. I just wanted to maybe start out with Log4j and, you know, maybe what you're seeing out there in terms of either pipeline build or just opportunity set- Mm-hmm As we start to think about this vulnerability. Yeah. Jonathan, you know, first and foremost, I remember when it happened. I think it was like December eighth or ninth. It was a Friday. The whole security community, both private and public sector, jumped on this thing in a fashion that probably preempted a lot of problems. At the same timeframe, what it brought to the forefront is an immediate need to figure out where are your assets and where are the applications that your applications actually depend on? Many of us have third-party providers that may have actually used Log4j that have created complications at scale that we just weren't used to solving. I can tell you this, from our business standpoint, yes, in the first three days of Log4j, you know, the exact number I think we could track was over 70 inbounds. Hey, we need some help here. We couldn't respond to all those. When you look back on Log4j a month and a half later, I think, my hat's off to the security community, both the private sector and the public sector, because we preempted an avalanche of significant compromise, and we got everybody thinking, where are our assets that matter? What are their dependencies? What's in our supply chain? I think right now, that's what the problems it brought to bear were. That would be attack surface management, asset management, third-party provider management or vendor supply management. Those sort of things came to the forefront. Every once in a while, we'll probably see a long tail of an incident or two from this. Log4j was a big vulnerability. It seems like in our industry, every few months, one of these pops up. You always get what I would call an indirect lift to the business. You know, you just all of a sudden executives, it's like free marketing for cybersecurity at large. Hey, cybersecurity matters, and so obviously there's more attention on it based on Log4j. That's kind of how it impacted the industry from my lens. You can talk to other vendors, get different answers. Our customers, most of, almost all of them went through without a significant incident, and they probably are a heck of a lot faster right now in determining third party and software dependencies. Got it. Just one for Frank. Can you maybe help us understand or just remind us if you've given us this before, what the margin structure will look like after we sort of get past these, you know, post-transition costs as well as stranded costs, and maybe the timeframe that you're thinking about to get through, you know, either the TSA or the stranded costs? Thank you. Yeah. Jonathan, we expect right now we're estimating in our guidance that we would, you know, provide this most of the TSA services through the end of Q3 of 2022. We will have some stranded costs because it will take a little bit of time to take some of those costs out even after the TSA ends. That's why if you look at, you know, what we gave for guidance for 2022, you do see some leverage beginning in 2022. The most important thing, I think is, you know, given the one-time costs that are hitting 2022 and the headwind from the validation rev rec change, we're very confident that we could be operating margin profitable in 2023. Pretty significant kind of move. When we get to Analyst Day, we'll kind of give you that walk from our 2022 guidance to our long-term model. Thank you. Thank you, Jonathan. Thank you, Jonathan. Our next question is from Doug Bruehl of JP Morgan. Doug, your line is connected. Please proceed. Hey, this is Doug on for Sterling Auty. Thanks for taking my question. Hey, Doug. Congratulations on the quarter. Thank you. I guess the biggest question would be, what do you see in terms of demand from the government vertical this quarter? You know, now I'm sitting here going through every interaction I had with the government. You know, I'm gonna have to go back to my traditional answer, Doug. I mean, quite frankly, Mandiant's always had a great relationship with a lot of different governments. We are a security company, and we recognize the responsibilities that that brings and governments were formed to provide security to their citizens. I mean, we've always had a strong relationship there, and we always wanna be interacting with the folks that have the same mission that we have inside of government. Frank, I can't really give it much more color than generic as you know. Doug, in my prepared remarks, I did talk about, you know, a couple $15 million deals and one of which was, you know, with the government. I think we, you know, we started their new fiscal year off really strong and, you know, got a really strong pipeline with the government. I think, you know, as Kevin mentioned, you know, we'll continue to kind of strengthen those ties and continue to actually embed, you know, new products into the government. You know, we've always obviously been really strong on the services and intel side, but I think we've got some pretty big opportunities on the managed defense, automated defense, and validation side as well. Great. Thank you. I appreciate your time. Thank you, Doug. Thank you, Doug. Our next question is from Saket Kalia of Barclays. Saket, your line is connected. Please proceed. Okay, great. Saket, how are you? Hey, Kevin. Hey, Frank. Hey, good, sir. How are you? Thanks for taking my questions here. Frank, maybe just to start with you, I was wondering if you could just talk a little bit about net new ARR in the quarter. Very clear the comp plans, you know, on billings versus ARR feels like the driver. I'm wondering how net new ARR kinda compared against your expectations for Q4. You know, with it being down versus Q3, I wasn't sure if there was anything with just a seasonality perspective that we should keep in mind. Yeah, I don't think it's anything to do with seasonality. I think it really is to do with the last quarter of a comp plan for both the Mandiant sales reps and the FireEye sales reps that are, you know, no longer gonna be selling Mandiant solutions. So I think what you saw was a maximization of the total contract value and not a maximization of ARR. So, you know, clearly, you know, we believe that, you know, had we been on the ARR comp plan in Q4, you know, that ARR growth rate number would have been much higher. You know, it's hard to tell exactly what it would have been, but probably pretty similar to Q3's growth rate of 26%. As we look into Q1, you know, we're right kinda in that zone of 23%-26% going forward. You know, a lot of the new offerings we're talking about, I think will continue to gain traction throughout the year. We feel really good about ending the year at 30%. Q4 is a great billings quarter, yet it didn't translate as well as we would have liked to in ARR. Okay, got it. That makes sense. Kevin, maybe for you, it sounds like the better alignment with endpoint vendors here is very helpful. Right to your point, Microsoft, SentinelOne, maybe there's some more down the road. But- Right. I was wondering how you sort of think about the competitive dynamic with some of the managed offerings that some of those endpoint vendors offer themselves, as well as- Sure. As well as their own sort of XDR integrations. Maybe this touches on an earlier question, but you know- Yeah. Is this complementary or is it competitive? Yeah. There may be times where there's overlap and that there's some competition there, and there may be some vendors who work with an endpoint where there's far less competition. Here's what I can tell you. With some, we can have, you know, memorandums of understanding and have a go-to-market alignment. Here's how we're different. The global intelligence, and that's actually, Saket, you walked into it to some extent. I was gonna go with the ARR team or the intel team, and I went with the intel team today. No one's gonna rebuild the global intelligence capability that we have, and it does matter. You combine that with us responding to over 1,000 breaches a year, and our intel baked into our XDR capabilities is something that I don't think a controls provider or platform provider is gonna have because we have the privilege of showing up when their stuff didn't work. I mean, that's what incident response is. If there's a way to circumvent a platform, we're the first ones to see it. In security, I call it popping the balloon. When a needle hits the balloon, you got a problem. One attack that works against a platform is a significant problem for those users of that platform. You have to think of compensating controls, and the fastest way you're gonna get those is Mandiant. Second is our validation component. We absolutely went vendor agnostic so that people can trust the Mandiant brand to validate what works and what doesn't work based on these new attacks. Let's run them in a safe and simple way and say, "Hey, the XDR is working." Imagine somebody went with an endpoint vendor and their program to manage it. That's fine. Use us for validation and use us to find stuff that maybe they don't detect. And then our services go beyond scope because they're bespoke at times anyway, so there'll always be a services room there. Yeah, not all, you know, with each partner, we're gonna have to explore how we can best work together and jointly defend the customers. Got it. If I could squeeze just a third kinda housekeeping question in here for you, Frank. I think it was asked in a different way earlier, but can you just talk about sort of what the expense either annually or rather for 2022 is, or on a quarterly basis is for 2022 in terms of how much expense Mandiant incurs to fulfill those TSAs? I know they start to roll off after Q3, but can you give us a sense for what the dollar amount is that you kind of keep as stranded, right, and that will eventually go away? Sorry, does that make sense? Yeah. I think it's about. Yeah. Yes. It's roughly in the $20 million range. Is that $20 million for the quarter or $20 million for the year? No, for the full year. Okay, got it. It winds, you know, various work streams wind down throughout the year. On balance, we'd expect most of the work streams to go through the end of Q3. Got it. Very helpful. Thanks for having me on, guys. Sure, Saket. Thank you, Saket. There are no additional questions waiting at this time, so I'll pass the conference back over to Kevin for closing remarks. Thank you very much. I believe our biggest near-term market opportunity is to offer the most preferred controls agnostic XDR solution, with our threat intelligence, our validation, and our services serving as our differentiators. Third-party integrations will be critical to our growth in this component of our business. Therefore, we intend to roll out a steady cadence of important partnerships to better protect Mandiant customers. I look forward to speaking with all of you and updating on the partnerships as well as our long-term model at Analyst Day meeting on March 10th. Thank you very much. That concludes the Mandiant fourth quarter and full year 2021 financial results conference call. Thank you all for your participation. You may now disconnect your lines.
Loading workspace