Thank you for joining us for our Growth Stock Conference and today's session with Qualys. My name is Jonathan Ho, and I'm the analyst covering Qualys for William Blair. Our speakers today are CEO Sumedh Thakar, as well as CFO Joo Mi Kim, who will provide an overview of the company, followed by a fireside chat. Before we begin, I'm required to inform you that a complete list of research disclosures or conflicts of interest is available at our website at www.williamblair.com. As a quick reminder, the breakout session will be in the Richardson Room upstairs, that'll be starting at 10:00 A.M./ 10:30 A.M. With that, I'll hand it over to Sumedh and Joo Mi. Thank you very much, and thank you for having us, and thank you for coming. At Qualys, we really are working with a lot of organizations globally to help them manage their overall cyber risk. We look at ourselves as a partner in overall cyber risk management for our customers, and especially on the proactive risk management side, and especially in today's environment, where AI is being leveraged by attackers to find vulnerabilities in the code base and to create exploits for our customers. We're really focusing on making sure that they are able to find ways and solutions that they can protect themselves by remediating the right issues in their environment and doing that in an autonomous way. Then helping them think through on their cyber risk posture, overall posture management and remediation in the context of overall business losses, as well with our Risk Operations Center. Awesome. Yeah. Thanks for that overview. I wanted to just get started with the main topic of discussion, which is what is happening around Mythos. Can you give us a sense of how you think about the potential impact of Mythos, what it means for Qualys, and what your customers are seeing today? Yeah, I think an overall impact on the industry really is that models like Mythos, whether it's GPT - 5.5-Cyber or other open source models, are really helping software developers find vulnerabilities in their code base much quicker than they would have otherwise with manual testing. Typically, once they find these vulnerabilities, they have to disclose those vulnerabilities. Qualys has always been focused on, once vulnerabilities are disclosed, how do we help customers find those issues within their specific environment? Just because a vulnerability that is being disclosed is exploitable out there in the wild doesn't necessarily mean it's exploitable for a customer in their specific environment with the specific controls that they have. What we are seeing right now is more of a shift for customers towards a longer vulnerability disclosure testing and remediation process, where typically IT teams would get 30 days to fix critical vulnerabilities. A lot of the focus now with the ability for frontier models to actually create exploits using AI, and be able to exploit end customers using AI. A lot of our customers are really looking at how they can leverage similar capabilities from an AI perspective with a combination of different models to make sure that they can test the exploit on their own environment themselves, and then the ability to remediate it themselves. That's where we are seeing a lot of the conversation, customer shifting, that as the number of vulnerabilities is going to increase, the number of exploits are going to increase. How can they make sure that they are prioritizing testing in their own environment and fixing the key issues that they have in a matter of hours? That's where the conversation is shifting. Got it. Just maybe building on that last point, it seems like with Mythos, there's going to be a significant increase in the number of vulnerabilities uncovered. As we've seen, Claude has just really stepped up its game in terms of not just finding the vulnerabilities, but the ability to exploit them. With that shorter window that companies have, how do you think about the fit within your platform, and how do you take finding those vulnerabilities, patching them, how do you think about the fix side of things as well? I think the really good news here from our perspective is that we really saw this momentum in terms of remediation coming a few years ago. We innovated on our platform relative to other companies in that space by actually creating abilities to remediate natively on the platform, which is very differentiated in the way that I think about it, is the ability to actually fix the things and not just create another dashboard and send a dashboard to somebody. What I really feel right now is the focus is shifting more towards being able to do autonomous remediation or remediation where customers can show to their board and management is when they are being asked by their boards, how are you going to respond to the AI leverage vulnerability exploitation? You cannot go back and say, "We're going to do more manual remediation." They really need to have a response, in my mind, that actually helps them convince and show to their board that they are embarking on a journey of autonomous remediation for these vulnerabilities leveraging AI, and not say, "We need more headcount for more manual remediation." From that equation perspective, the fact that we innovated around this early on in the last two to three years. The fact that Qualys has deployed 150 million patches with Six Sigma accuracy already in the last 12 months. 40 million of those patches are already autonomously deployed with no human intervention, with almost no outages that have been created. Because of our understanding and focus on that, we have gone beyond patching and created the ability for customers to create mitigations that they can deploy without a patch that gives them more confidence that they can go into remediation without creating outages. Because of over 500 million patches that we have deployed on our platform in the last few years, we've been able to leverage ML and AI to create a Patch Reliability Score model that gives customers the confidence that they can autonomously deploy a new patch, because we have seen how this particular patch could behave in that environment, giving them higher confidence in terms of how they can move into that particular space. I think today, where the focus is, we need to come up with a roadmap on how we're going to respond to AI scale exploitation with AI scale remediation and autonomous remediation. We see that our customers are really coming to us, given how we have been able to deploy this and having those conversations on how we can help them come up with a roadmap for autonomous remediation, rather than just scanning more and creating more dashboards. Yeah. One of the biggest challenges that we typically see from enterprise IT organizations is that they already have a 2-ft -high stack of paper that shows all the vulnerabilities that are in their network. Either the patch is not available or they're just unable to fix many of these things, it can break other things as they apply those patches. Having a workflow that can be increasingly automated, increasingly put into place to speed up that process is really key. Mitigations, if you're not able to patch, is just as key as well. One thing that we think about as well is that if we start to go into an agentic AI world, this potentially creates new opportunities. How do you think about new products that you have, like TruConfirm, Agent Val, and what are some of the moats that you have around some of these workflows? Yeah, that's a great question, [Jonathan]. I think we've never really been into the vulnerability discovery phase in terms of code-based vulnerability disclosure, which the models are doing. Our focus has always been how do we take those particular vulnerabilities that are being disclosed by these vendors, helping them really figure out which of these in their environment are actual risks to them, and being able to help them remediate. To that extent, we recently released a report called "The Broken Physics of Remediation," which highlighted that less than 1% of vulnerabilities discovered in any organization are actually exploitable by attackers at any given point of time. To your point, when they have stacks and stacks of these things to fix, they cannot take the risk of fixing everything because it can potentially create outage. The focus for us, and what we have been able to do, is really understand the customer-specific environment. They have all kinds of devices. These devices interact with each other, databases, load balancers, Windows devices, Linux devices. How can you safely assess those in a matter of minutes and hours when new vulnerabilities come out? How can you prioritize them, but not just based on threat intel, which is available everywhere, where somebody will say, "This particular vulnerability is being exploited in the wild." Okay. Customers do have other security controls in place. They might have an EDR, they might have a firewall. How do you make sure that that particular vulnerability that is being exploited by attackers out there is actually not attackable in your environment? What we see that only 1% of the vulnerabilities are exploitable out there in the wild, but even only 20% of that 1% is actually exploitable in the customer's environment. How do we safely help the customer find out to run the exploit themselves? This is where TruConfirm, as you mentioned, is a very differentiated capability where we leverage these frontier models to reverse engineer the exploits and create safe ways for the customers to test those exploits themselves before the attackers get to it. That's number one. With that, they are actually able to reduce the number of findings that they need to fix from that 1%- 20% of that 1%. After that, we use similar research that we do with AI-based models to actually then come up with mitigations that don't require a patch. How can we then say that, "Yes, you could fix this with a patch, but by the way, you could also apply a mitigation that will prevent the exploit from happening without applying a full patch, which creates a higher risk." One of the key differentiators is that because we have seen a half billion of these patches ourselves, and we have built models around that, we can fairly uniquely give a visibility, in my opinion, of how a future patch can be highly reliable or less reliable, so customers feel higher confidence. As they are moving into the autonomous patching world, it's not that the ability to patch a given file has not existed. The confidence in that we actually exploited it ourselves, we confirm it is exploitable, and we have applied a mitigation that does not require a patch, and we have high confidence in that. Those factors are the differentiators in my mind, rather than just saying that given a file, you can patch it. Excellent. Just given the tremendous interest that we're now starting to see from customers with this challenge and maybe a raising of the priority of vulnerability management, Joo Mi, how do we think about the potential impact of Mythos from a guidance perspective? What have you baked in, if anything, and what sort of timeframe should we think about in terms of that impact? Yeah. From guidance perspective, there's really not much of an update from our last earnings call, which does not incorporate any potential incremental revenue from the introduction of these newer models. We're very excited about the top-of-the-funnel activity. We're having very engaging discussions with our existing customers and the growing pipeline. As always, what we expect to see is sales cycles have a tendency to have it take time to play out. What we expect to see is later on down the road, we'll be able to glean more visibility into how these particular opportunities are progressing and then be able to be in a position to give more of a meaningful update to the guidance, if any. Excellent. Just given that this is a relatively recent occurrence, where do customers typically find budget to pay for these types of products? Could they potentially tap into AI budgets in order to pay for some of these solutions? What we've typically seen is that with the release of the most recent versions of Claude, with Mythos, there's an increasing pressure for the CIO, CISO to be ready to deploy agentic AI when needed. If security is a concern, they're getting approvals for some of those newer projects. How do you think about that? Yeah, that's a great question. The way I see it, and this is my belief, that this is more of a change in the way security is being looked at by CISOs when it comes to remediation versus in the past, Heartbleed or Log4j was just like, let's quickly scan something more. As the industry overall is looking to pivot more towards autonomous remediation, which the CISOs have not in the past looked at. They always thought, I can give 90 days to the IT team to fix things. Now, as always, if there is a compromise, it's not the IT team that has to go in front of the board and the SEC why there was a compromise. The CISO has to be responsible for going and explaining. What we are seeing is there is a lot of interest from CISOs right now in saying, "I need to pivot more towards a model that's sustainable, where I can start to introduce autonomous patching in a phased manner." The conversations are really happening around that, and I think that's where I feel like the opportunity is right now to work with these customers so that we can move them into figuring out how they can go and have the conversation about, because of the structural change, we don't see that on day one, they're going to be like, "I'm going to deploy autonomous patching on everything." They're probably going to start with 20%, 40%, 80%, and then move towards that. The question becomes, where does that budget come from, right? Is this budget coming from maybe they have an exposure management solution that's just giving them more dashboards and not actually helping them fix? In some cases, that might be the thing. In other cases, we talked about this a little bit, is that if it's a dollar for just the scanning piece, it's an additional dollar for the ETM piece, which includes agentic AI and the confirmation. The additional dollar on top of that is coming from the ability to eliminate things, right. Part of this can come from, because ETM has agentic AI capabilities built in, customers can leverage some of their AI budget, because that's going to make their team more efficient, leveraging ETM. They'll have AI agents included as part of ETM. This helps them say that, "Yes, we have an AI solution that is actually making it a lot easier for us to deal with the Patch Tuesday," as an example, because AI agents are available. In some cases, the validation testing we do, they might actually be able to put the budget that they have for their red team or their purple team, because they can actually automate a lot of the manual testing of validation that is happening right now, or a breach and attack simulation solution could be something that they're looking at. In some cases, and this is why it's still early in the conversation, customers might be looking at maybe their patch management solutions that they can replace, which are very old school, and they're paying for those. Maybe those patch management solutions will be something that can come in, right? I think that overall cyber budgets have been growing at low single digits many times. With AI, there is some additional opportunity that can come up as well. It's still pretty early in the conversation. Customers are just having that conversation in the last couple of weeks with us to say, "Where can I position this? Is it a AI automation? Is it a breach attack simulation type testing capability? Is it a remediation capability?" Based on where they have the budget, they might look at replacing one or the other, is what we see right now. Got it. Just speaking of prioritization, the narrative for the vulnerability management space for some time is that it's been deprioritized on a relative basis, and that's maybe caused some customers to choose tier 2 scanning solutions, less focused vulnerability management solutions that are part of broader suites. Do you think this change with Mythos, where now people are waking up and saying, "Okay, we've got the Blackwell -trained models, but the Vera Rubin models are coming. It seems like things aren't going to go back. They're going to only get worse from here." Does this change the narrative around tier 1 scanning prioritization and importance? Yeah, that's a very good question. I firmly believe that it does, because maybe one year ago it was like, okay, sure. We take a few days to get the signature. We scan it. We create a report. That goes to the prioritizing team. They take one week. It goes to the IT team. We create ServiceNow engineer tickets. They fix it. That takes another week, was okay. With the speed at which the real vector of attack is now shifting more from unknown vulnerabilities being attacked to known vulnerabilities that have not been patched. Once a patch is released, attackers are using AI to reverse engineer the patch to find the exploit quickly. Now the threat really shifts from the patch is available and it's been 24 hours and you haven't patched it, and that's where the attackers are now coming and going after your environment, right? I think as that is really happening, I think that gives an opportunity really for us to say where customers are basically saying, "Well, if I have to get it fixed in the first eight hours, right, and my tier 2 scanning solution is taking two days to add a signature, how can I even rely on something like that? Because I'm already dead in the water right now, and I'm not able to even find the vulnerability." We definitely feel like conversations are shifting in terms of customers wanting to understand how can we help them find those issues quickly. Because you cannot fix it if you don't even know that you have the particular issue. That's where we are seeing the conversation, and that's where, again, before Mythos announcement came about in April, at the RSA Conference, we actually demonstrated the use of agentic AI with Agent Val, where we were able to discover a vulnerability with a signature, then actually run an exploit to validate that in their specific asset it was exploitable, apply a mitigation that did not need a patch, and then revalidate by running the exploit again that it was fixed in under 15 minutes. If you're talking about that kind of timeframe, you don't have the time to wait for two or three days for tier 2 scanners to find things. You send it to somebody else for validation, is it really even true? Do the mitigation. I do feel like the shift in the speed of the exploitation of these vulnerabilities means that customers are definitely wanting to make sure that even before they get to remediation, they're actually finding it quickly either. The ability to deploy the signatures in a matter of four to six hours or two hours right now, which is what the tier 1 scanners really focus on, and having high-quality signatures and not missing a signature become all the more important with the new threat that we are seeing. Absolutely. It's definitely going to be interesting once the broader Mythos models are released. We see what the threat actors can do with enhanced capabilities. They're the ones that tend to lead the charge as opposed to on the responsive side. When we think about patch management, which is sort of closing the loop for a lot of these solutions, traditionally the approach has been with many of your customers, they'll scan with vulnerability management, identify the threats. Then they hand it off to an IT team that has to go and actually do the patching. These are folks that are not necessarily security aware. They sometimes clash with the IT security people who are like, "You got to apply the patch right now." They're like, "No, we're going to take our time." Yeah. How do you think about making this more integrated? Is there potential changes in the processes coming because of the urgency and the threat that is created by Mythos or other things? Yeah. I would say that it's not that they clash sometimes. They clash every time, right? That's the reality is because the balance between operational risk versus the security risk, right? You have the security team that is finding the issues. They're passing it to the IT team. Now, this was in an era where we had that time and a week or two weeks or 30 days to do certain things. Also the reality was that if you are just using an exposure management tool that is not really prioritizing things for you, IT team gets frustrated because the security team gives them 10,000 things to fix, and they're not really prioritized. They just say, "You need to do that." The IT teams don't like it because there are other things they do come, they fix it, they come back, and the security team says, "Great job. Here's your reward. Here's 10,000 more." We're now having a conversation that says, "By the way, the reality is less than 1% of these vulnerabilities actually are causing risk to the organization. How can I make you the hero that fixed the 13 vulnerabilities that actually reduce the risk to the organization?" You can very well fix 10,000 issues and make zero impact to your risk, or you can fix 13 that are very tested and targeted, and you can get those things fixed. Now with the added requirement that you need to fix those in a matter of four hours and eight hours, and you don't have 30 days, the IT teams' patching solutions are typically not set up for that kind of a response. That's where we are seeing more conversation, and we kind of started to see that a couple of years ago as our patch management solution has been increasing in deployment with customers, that they are bringing the IT and security team together. In some cases, they might look at replacing their IT patching solution. In other cases, they're saying for the less than 1% where there is a hyper risk associated with it, the IT team is leveraging a solution like Qualys as a cybersecurity patching solution, while the rest of the 99%, which may not be a risk right now, can still be patched with the IT team's regular patching solution in the next one week, two weeks, 30 days, and 90 days, right? What we are seeing is that a blend of that coming out. Why does IT push back? First of all, don't give me things that are not actually causing risk. That's where the hyper prioritization with ETM and testing comes into play. The second pushback is, "Well, what if I patch and it creates an outage?" That, again, where our innovation around the ability to give them solutions that don't need a patch and still mitigate the issue, the ability to give them a way to make sure that they actually have a reliability score beforehand from half a billion patches that we have seen, gives them higher confidence to say, "I feel better with autonomous patching because you're really only fixing 20% of the 1%. You are using reliability scores based on what you have learned, and you are using solutions that don't require a full patch can actually be mitigated. I feel a lot better about going with this integrated solution rather than I have to go do my own research, kind of figure out which potential file I could deploy, which might fix the particular CVE. What we have achieved on the platform right now, I feel is really a differentiation because it's enabling that workflow instead of this, I am one solution, I scan, I hand off to another solution that's going to patch. That's not necessarily giving you the confidence that this is the right thing that you are doing and that what you're supposed to do. We're excited about the investment in the innovation that we have done over the last two, three years to be ready for this kind of a moment that we are seeing right now with Mythos. Excellent. One of the significant improvements in capability, even pre-Mythos, is with Claude Code and the ability to do more vibe coding, more complex projects. As we all know, AI is perfect when it writes its code and doesn't create any additional vulnerabilities. A lot of this stuff is now being deployed to the cloud. How do you think about the importance of CNAPP and sort of your broader platform as you grow in these different areas? What's the opportunity around the cloud space as we start to see the deployment of AI-written code? That's a great point, and I think as we are hyper-focused right now on vulnerabilities because of Mythos, I think when you step back, risks to an organization come from a couple of other areas as well. I feel like we're not far off from where there can be an AI model that is only leveraging these configurations also to create an exploit for you. Only leveraging identities as a way to create an exploit. When you look at overall risk, and that's where with the Risk Operations Center that we innovated with and our ETM solution, we're actually taking a view of the broader risk for the organization where vulnerability is one piece. We're also bringing misconfigurations. They could be cloud misconfiguration from CNAPP, they could be misconfiguration around your assets. We're also bringing identity-related information, combining all the risks together to give you a single risk score, align it back to the business. Sometimes saying, "I'm not going to fix it because the loss to my business is not that significant," might be the correct answer that we are sometimes afraid to give. ETM allows you to have that. I always give this example of saying, your exposure management might give you a score for a business unit where the risk score is 950 on 1,000, which is very bad, a very high-risk score. Another is 750 on 1,000, it's not that bad. Which one will you fix first? You're definitely going to focus on the 950 first, because that's very high. The moment I tell you 950 is on a business unit that is making you $5 million a year, 750 is on the one that makes you $500 million a year, your risk score just went out of the door. You're going to focus on the one that has a lower risk score. Thinking of risk as just vulnerability and not broadening it, and then thinking of it without the context of the dollar values is really not meaningful, and that's where our innovation around ETM and the ability to actually pull in other risk factors is going to be very important for customers as they look at the broader picture. Again, vulnerability counts have gone up seven times, but cyber budgets are not going up seven times. You're going to have to prioritize what actually is a risk to me. There is no doubt that every CISO is a risk manager now. When they are a risk manager, because they cannot fix everything, how do they make sure that they have the right platform that is giving them the visibility into a business risk is something that becomes very important as well. That's where our focus on how do we go beyond just vulnerability management and give you the broader picture becomes as important as well. Yeah, that makes a ton of sense. Especially in the context of having all the AI data that you have. everything that you've collected, it seems like you're able to bring AI to your customers as opposed to being replaced by AI or the whole AI eating software narrative. Can you talk a little bit more deeply about those moats? Yeah. What you bring to the table that really can't be replaced by an agentic system? Yeah, I think as we talked about, something like when we are uniquely deploying 500 million patches and seeing every outage that is caused by that and every rollback, a model, as an example, with the Patch Reliability Score, is a model that we can build because we are uniquely seeing in a captive environment how patches are being deployed in what type of customer, what type of operating system. That's one way that we look at it. Many times, customers are, even if they have access to a model, don't necessarily know how to simplify the usage of that for their particular enterprise in the context of cyber security. With ETM, it's not just a frontier model. We leverage very smartly a bunch of different models. Some are SLMs, some are open source, some are LLMs. For the customer, they were looking for an outcome. When they are really just looking for an outcome using AI, in the back end, we can distribute their queries, their questions, their asks across different models and give them in a very cost-effective manner, is something that is also very advantageous to them. Ultimately, when you see that this Frontier model, as an example, was let alone in a sandbox, and it went and tried every single thing and tried to create an exploit path. Of course, at the point, that model doesn't care whether it brings your system down when it is trying an exploit, and that's what happens. Again, our ability to leverage similar models and then create safe exploits so that you can test it yourself without waiting for the attacker to bring your systems down, so you can fix things, and then from that, create the right mitigations, are some of the things that we see our customers see that as something very differentiated, which are not something that these models are doing because they're really focused on saying, "Upload your code, I'll tell you how I can go about doing some of these things." We're excited about partnering and looking at not only with the frontier models, but also leveraging open source and other models that are coming, and then eventually moving into that environment. Also, like I said, vulnerability management is just one piece of the overall risk puzzle. The ability for us to look at the broader platform, and when you talked about cloud earlier, the fact that our CNAPP solution today in the Forrester Wave was put right next to the top -tier Wiz, as an example, means that customers now have a very interesting option where they can get a broader platform with the cloud security as one that is built into that versus a platform that is just based on cloud security. The same thing, if you have a solution that is just cloud security, it tells you that you have 30 buckets open to the internet. What does that mean to my business loss? If you cannot explain that, those 30 buckets are being used by a developer who has a laptop that has a particular risk, and how do you combine that together? We do see that there are multiple opportunities here for us to provide unique differentiation and work in partnership with a lot of these newer models that are coming out to give customer a lot more of an integrated, simple to use, and outcome-based solution, rather than just giving them a playground where they can play things as the differentiation. Excellent. Unfortunately, we've reached the end of our allotted time, so we're going to continue the conversation up in the Richardson Room. Thank you very much for attending. Thank you.
Loading workspace