Hi, everyone. Thanks for joining. Really excited to have Qualys team with us here again this year. We have Sumedh Thakar, President and CEO, and Joo Mi Kim, CFO. Thanks again for joining. Thanks for having us. Let's start with last week's results. It was an excellent quarter. Accelerated Current Calculated Billings 16% in the quarter. Stock reacted well, beat across the board, raised the guide. Operating cash flow up 77%. It really validates your strategies. Just what else would you want investors to take away from the quarter? I think we're very pleased with our execution in the quarter, and we continue to focus on profitable growth. We are a product-led, innovation-led company, and so a lot of what we innovated around remediation Patch Management has really been the key focus for a lot of the conversations with customers. We're looking forward to now working with our customers to make sure that their post-Mythos focus on risk remediation is something that we can work with them, and we can convert that into good opportunities for us, given that the last four or so years, we have done a really solid job with Patch Management, which is the area of focus. Just excited about what we're doing right now and the feedback that we're getting from our customers. The goal is to continue to focus on executing that. ETM was a big component of the strength in Q2. Again, CCB accelerated 16%, and that was partly due to ETM for customers. Could you just give a better sense of maybe what that means? Were those wall-to-wall deals? What were they buying? What was the uplift? How do you think that will play out for the rest of the customer base, and on what timeline? I think, like we said, at a high level, the focus for customers has really been the remediation part with Eliminate and Patch Management. What we're seeing is, to be able to do a good job of that, customers are also looking at ETM as a way to really prioritize, hyper prioritize, the findings that they need to fix immediately. What we really saw was the customers that were already up for renewal in Q2, we have been having conversations with them. When Mythos came about, they were able to go back and work with their teams and get some additional budget to essentially make those renewals and upsells be bigger than sort of what we had anticipated at the beginning of the quarter because of the conversation we had and the maturity of the tool set. Really at a high level, that's what kind of drove that. We're looking forward to continuing similar conversations as we get into Q3, Q4 as well. Hey, Joo Mi, you've been pretty disciplined about saying that ETM is not going to significantly ramp in our hour this year. Newer products can take time to penetrate the base. I guess, what leading indicators should we look at in front of the NRR growth? Yeah. For us, we believe that ETM will be the primary engine to drive growth in the near term and in the foreseeable future. With that said, given that it's relatively new to our customers, we don't think it's going to be contributing much to our revenue, at least on a material basis. This is part of the reason why we decided to share the Net Dollar Expansion Rate of customers who had either ETM or CSAM subscriptions at a year ago period. Because if you take a look at that cohort of customers and how they continue to grow with Qualys, as we take you through that journey, hopefully, you'll be able to see the progress that we're making, and it will really be a best indicator of the success that we're seeing in the ETM initiatives today. With that rate at around 107% for this quarter as well as last quarter, we're very pleased with the amount they spend, and as they continue to grow with us, whether it be just a VMDR cross-selling to ETM or adding Patch Management on top of that's validated by the percentage contribution by the product bookings. If you take a look at it on an LTM basis, ETM and CSAM currently make up 12% of total bookings, up from 9% a year ago. The same thing with Patch Management. It currently makes up 9% of total bookings, up from 7% a year ago. You can see that our newer products are really helping to drive our growth acceleration in the top line today. You've been a 10% grower really steadily for the past couple of years. Elite margins, high 40% EBITDA margins. Now we're talking about potentially accelerating long-term growth. I think that was a big moment and big takeaway from Q2. I guess what does that mean to you? What are your aspirations there? I guess what needs to go right from here to see moving more towards mid-teens or aspirationally? Yeah, I think we kind of saw this whole need for remediation was going to accelerate, and we stayed ahead of that, and we're excited to see that there is an opportunity right now for us to work with the customers to have them adopt that additional patching capability, remediation capability. A lot of the innovation that we have done around AI with our recent launch of Agent Val for validation, which is also something that we did very different from every other VM tool. More recently at Black Hat, we launched Agent Insta, which is essentially the ability to get detections of latest vulnerabilities that are coming out within an hour of them coming out. A lot of that is being looked at very positively by the customer. There's an opportunity to move those customers from VMDR customer cohort, where they're scanning but doing a lot of prioritization themselves to upgrade to ETM, which then will allow them to do the prioritization, and then the ability to use Eliminate to do the actual remediation. We're looking forward to working through the conversations that we are currently having. We also announced the launch of Total AI 2.0, which is really an area that is up and coming now. When we talk about security for AI and AI for security, this is the focus on saying, how do we also leverage our position with these customers where we are so widely deployed in a lot of large enterprises to be able to give them visibility into Shadow AI, as an example. I think as we look at the next few years, we feel like the focus on remediation that has come about, opportunity with the federal government, the capabilities around Total AI that we are adding, are things that make us feel like this is something that we can continue to focus on and set ourselves up for continued growth and potentially acceleration of that growth. You spoke to some of this, but CISOs are frustrated, vendor lists are long, remediation needs to be a priority. I'm curious what you're hearing on budget growth or budget allocation. Again, we're seeing significant amount of money being poured into spending on AI, whether there's an ROI or like at least on- Yeah. ...token and app development. We're now beginning to see the full effect of what some of these novel Agentic AI attacks could unleash on security environments. I'm just curious what you're hearing on budget growth or expectations over the next couple of years maybe that could impact ability to re-accelerate. I think we always see this with our customer base, which is typically the larger enterprise customer base, that just because the number of vulnerabilities or findings have gone 10x, the budget doesn't go 10x, right? I think what it is, and this is what we commented on the earnings call as well, is as customers are going back really trying to understand what do they need to change as a process, not just a one-time jumping in and trying to change something. How do you essentially peg the security as a percentage of what you spend on your IT is, right? As people are still trying to figure out what their spend on AI is, we do see in the next couple of years, you'll kind of start to see a certain percentage of that spend for AI tokens, et c, will also translate into certain spend on cybersecurity related to AI as well. But it's too early right now to know exactly where that'll end up landing. But most customers are just right now at that early stage of saying, "Who's using AI in my organization?" "Who's not using AI?" is also a question these days. But that's kind of where everybody's sort of trying to figure out is if I know what the spread is, then I can start to figure out what that potential spend can be. The conversations are that if there is a net new spend happening on overall AI and additional AI deployment, then customers will look at figuring out some spend that will be focused on AI security as we move forward, but just too early right now. Okay. The idea that we want to move more towards a Risk Operations Center or ROC- Yeah. ...outside of a SOC and/or just a VM. The vision for the ROC, what does that bring in addition to the SOC and the VM? How critical is it to integrate with a competitor's data, for example? How is that- Yeah. ...maybe a surprising strategic advantage? Yeah, that's a great question, and I think it ties back to your earlier question as well. Look, at the end of the day, the SOC was always built as a way to find if an attacker is in your environment by looking at the log data and correlating log activity from different sources to see if we can find an actual attacker in the environment and then block them. That's where you've seen the evolution of SIEM, XDR, et c. But it's what we call as the post-breach side. I think on the pre-breach risk management, a lot of it just has been, "Oh, I have a dashboard for cloud security, I have a dashboard for endpoint security, I have a dashboard for container security." Which is a lot of it is just dashboard tourism. But customers struggle to sort of make the point of, well, what is the risk to the organization? That sort of goes back to the point that there is no framework or there has not been a framework like the SOC for post-breach or pre-breach risk management. The concept of a ROC, which is a Risk Operations Center, has really taken hold quite well with the conversations we've had because now CISOs see this as a way to have a business conversation as well about risk and how that relates to the business and the spend. At the end of the day, when you talk about risk, you're talking about reducing risk of financial loss. If you're not able to quantify what that financial loss is, how do you decide how much you're spending? A lot of the conversation about the ROC are less about the technical capabilities and stuff like that in terms of like, can I find this thing or that thing? But the idea that you still have endpoint risk, you still have cloud risk, and now you are going to have an added AI risk, then you are going to have an added quantum risk in the future. How do all of that normalize together so that you can have a picture of what the overall risk to the organization is? In that model, the idea of the ROC being able to provide that quick inventory detection, validation, and then remediation is helpful and the business conversation is helpful. But that also means that we have really opened up the platform so that we can take risk elements from other tools that maybe are areas that we at Qualys don't really do anything in those areas. Or maybe a customer is committed in terms of having a different scanner for the next couple of years, but they are struggling with too many findings. They want to leverage the ability of a ROC to tie to business and then figure out the validation and the remediation pieces. Then we can open up to that. With that, it also opens up the ability for Qualys to still make additional potential revenue on top of a different scanner that the customer might have and really opens us up to have the ability to pull data from other companies that are doing, say mobile security and pen testing and different things, so that we can give a holistic picture. For us, the ROC is obviously a way to provide customers a more business-oriented risk dashboard, but then also for Qualys as a way to be able to create opportunities to make revenue on top of areas where the customer might be using another tool for detection. Yeah. Foundational. Back on ETM or Enterprise TruRisk Management. When you engage with a customer at that level, does the buyer change, or can we talk about the buyer persona if the sales cycle at more strategic level becomes lengthier? Just thinking about upside to VMDR and then where that spend comes from, if it is from SIEM or just net new spend. Yeah. I think the buyer still primarily continues to be the CISO. I think sometimes when we talk about risk and financial risk, et c, we do end up talking here and there with the Chief Risk Officer in the company, sometimes the CFO. But primarily, the buyer is still the CISO. However, when you talk about deploying Patch Management and remediation, which everybody's looking at, then they have to bring in additional stakeholders. They have to bring in the IT team, they have to bring in the CTO organization to make sure that the patching, et c, doesn't create an outage. And of course, that's where with us having deployed 150 million patches and 40 million of them autonomously, we have that ability to say we have Six Sigma accuracy, so that helps. But it's still something that takes some time for them to figure out what the new process is going to be, what do they do with the existing tool for patching. Maybe they replace the existing tools. In some cases, they keep the existing tool for certain use cases, and they're using Qualys for the other use cases. As one of the customers I spoke to recently said, they look at it as the big red button, where they're going to let IT do some of the patching that they do normally. But if some new outbreak comes and they need to get something fixed in the first eight hours, then they're going to just use Qualys to do that because they don't want to wait for the IT team. So in some cases, they're replacing, in some cases, they are layering the elimination capability on top of that. In other cases, they need to pull data from their other security teams, like cloud security into Qualys ETM to give that holistic picture. So there are different stakeholders within the security and IT team that get engaged. We're continuing to work through that and have those conversations. You've done a lot of work with agents yourselves, and I think that that is very interesting and still underappreciated in the market. We already talked about how customers value remediation. So in terms of detect, validate, and fix, which is the hardest to pull off, is it fix? And then if another platform wants to bolt on exposure management- Yeah. ...why would it be harder for them to execute that fix stage? Yeah, look, it is not that patching solutions have not existed, right? They have been there for many years. What is the difference is that the native platform that we have built, which really brings the focus not on the post-breach side, but actually on the pre-breach side, the ability for us to have these signatures, with the research threat research that we do that is focused on vulnerabilities. Then the ability to convince the customer that this remediation that we do is something that is not going to create an outage, are the key parts. At the end of the day, you need high-speed detection, which is a week and a half ago when we at Black Hat, we announced our new agent called Agent Insta, which is the ability for customer to know within the first 60 minutes of an advisory coming out if they are impacted or not, versus waiting for two days for scanning in the way traditional scanning happens. Second is Agent Val, which is again, another way that Qualys uniquely looks at not from just an endpoint perspective, but from an outside-in perspective of running the exploits ourselves so that the customer does not have to figure out with a red team or something to do that individually. Then finally, it gets into the patching capability. I think a lot of conversation is now happening with other vendors saying they are also going to add Patch Management. The thing that because we have done this for a long time, what we have matured into, patching is not the only solution for remediating risk. So what we have done is we have created the ability to first, number one, have the option to actually apply a different fix, which is a mitigation that does not require a patch that reduces the risk of an outage. The number two is because we have deployed over 500 million patches, we have built an AI/ ML model that allows us to provide a reliability score to a customer of a brand-new patch, so that when they go to deploy, they actually have confidence that this is a high reliable patch versus low reliable patch. So the ability to execute a file on a system to run a patch has always existed. I think where we have added a lot of the intelligence with Agentic AI capability is the ability to significantly reduce the number of things that you need to patch. The second is giving you alternatives to patching. The third thing is actually providing you intelligence based on AI to say, "Is this patch going to create an outage or not?" So they can make better-informed decision. The last piece is actually added the autonomous remediation capability, where we already have 40 million patches that customers have deployed with no human intervention. Yes, there are other platforms that are focused on post-breach detection, can say, I can find a vulnerability here. But today, a lot of the exposure management solution are just giving you another exposure dashboard. They're not actually fixing it. Exposing exposures is not really what people are looking at right now. We feel pretty good about the intelligent capabilities that we have built. It's not just the ability to execute a file to run a patch, but it's a lot of that intelligence and workflows around it, that make it a lot better for them rather, instead of just having a basic functionality to it. In years past, we've talked about the implications of quantum computing and Post-Quantum Cryptography. The Q-Day could be moving up and progress has only accelerated. We have a bunch of quantum companies at the conference this year. Has it created more interest in Patch Management or just thoughts on implications for the cybersecurity space at large? Yeah, I think I've done this long enough now to say that every time a new technology comes, there's a lot of hype about it. Right now, of course, it is AI security, but in a few years it's going to be quantum. If you go back to cloud and even if you go back to other things, whenever a new technology comes, the basic four pillars always remain the same. Number one, do I have it? Whether it's cloud, whether it's quantum, people don't know where my certificates are, where my AI is running. So these are the pillars of the ROC. Which is inventory. No matter what it is, do I have it? Number two is, can I assess it for issues? So, whether it's a vulnerability scanning, whether it's an AI model, whether it's a cryptographic key or an algorithm that is not quantum safe. Number four is prioritizing. I cannot fix everything, no matter what it is. Whether it's cloud findings, it's AI findings, people are not going to fix everything. The prioritization based on business context and threat intelligence stays the same. The final piece is you have to get it remediated. So, in some cases, it's a patch. In other cases, it's fixing a misconfiguration. In the case of AI, it's going to be ability to put some controls around the agent, et c. When quantum comes, people are going to want to know if I have quantum unsafe algorithms or certificates, how do I quickly rotate those? The technology essentially is right. What you're using for mitigations and patching is the Qualys being on the endpoint agent. We can run a bunch of different remediation that goes beyond patching, and one of those will be what can we do whenever you have a quantum unsafe situation. Qualys agent can deploy a new certificate or rotate the certificate, would be one approach as an example. We feel like the platform holistically has been built to be able to address different technology that comes our way and which is really what the ROC is about, and put it in the context of risk. Just because you have quantum, how much risk does that add to the business? How can we help the CISOs make that point to the Board so that they can ask for additional funding? I think these things will come, but the basic framework stays the same. We're getting up on time, so we'd like to offer the opportunity for anyone to ask a question in the audience if they'd like. Sounds good. Joo Mi, you're running at high- 40s EBITDA margins, and we're talking about aspirations to re-accelerate growth. Would just like to hear more about where you're thinking about investing that incremental dollar, and then maybe what you could see in a cohort like ETM to recalibrate and invest more to drive further acceleration. Well, as demonstrated by your Q2 results, I think it's a pivotal moment for us. If you take a look at our Current Billings, this is the first year that we've kind of implied guidance that points to a real meaningful acceleration. In the last couple of years, Current Billings growth had decelerated from 13%- 9%- 8%. Current year implies 9%- 10% based on our guide, which kind of demonstrates the upside opportunity that we see in the business today. I think that there will definitely be tailwinds given the post-Mythos era, what we could do with their newer products. It's not just one product, for example. Even though we believe in ETM, that will generate sufficient amount of growth to really accelerate to the double digits that we're looking for. We believe that other products like Patch Management and Total AI 2.0 will help to contribute and help us to get our Net Dollar Expansion Rate, which is our KPI, back up to that 110+ level that we've seen before in our history of Qualys. Right now, we've seen a nice trend upwards from 103- 104- 105, with the rest of the growth coming from new logo acquisition. I think that there is definitely more room as we continue to execute, and we'll have to wait and see what that really mean for us in the next couple of years. Okay. So $300 million free cash flow, significant buyback authorization. Curious, maybe your thoughts on M&A broadly. If you're thinking about valuations in the security space, I think valuations can be pretty full on the AI side or maybe what could complement the platform at this stage. Yeah, I think, we always continue to look for these kind of opportunities. I think our focus right now is, if you look at what customers really liking the Qualys capability is because of the integrated ability to actually get to the patch in the first eight hours. Because everything is coming together instead of having siloed platforms. As we're looking out there and we're looking at what the customers are really looking for, we continue to look at different options. I think there's opportunities that we look at, whether it's in the Current focus with remediation and opportunities to have different options of remediation maybe some companies are providing, is something we look at. Then as we look into future AI security-related things that are interesting things that different companies are doing in AI. We continue to be open and balance between buyback and opportunity to do an M&A. That's been kind of consistent in the way we've looked at it, and we continue to stay open to that option. Okay. To bring it home, for some that do not look at security space all that much, they could look at a company like CrowdStrike and see them moving into VM and be concerned about that or some of the newer cloud security players and think that that could squeeze you. Clearly, Q2 is a big statement quarter, and we are on the path to re-acceleration. So why is that wrong? Or help us demonstrate the value of Qualys, that the numbers are clearly showing us. Yeah, I think, given what we are doing and success we are seeing in the overall space of vulnerability management, which in my mind also includes remediation. I think we see different players have come in the last couple of years, but they are offering findings and vulnerability findings that we have been doing for a long time. But we are much, much farther ahead in terms of our ability, in my mind, with the broader remediation capabilities, the ability to provide you patch reliability scores. The ability to actually showcase that we have deployed 150 million patches or almost 500 million patches the last few years without creating outages. I think when you compare that to, say, somebody who is giving you more findings, nobody wants more findings. People want less findings and actually get those findings fixed, and that is really what we are offering. When you are going to rely on somebody to fix those findings, do they have a track record that you can actually trust that they have done that for a long time versus somebody who is adding capabilities newly? I think that focus that we have kept and innovated well before the market versus people jumping in now, I think that creates trust with our customers, where customers trust a solution that has had that ability to have that many patches deployed. We continue to see more opportunities for us to grow, innovate, and create that gap with anybody else who is trying to compete by now adding patching, where we are much farther ahead of just patching already. Sumedh, Joo Mi, thank you so much for the time. Thank you very much.
Loading workspace