Thank you everyone for joining us. I'm Mike Cikos, analyst at Needham for the infrastructure, analytics, and security sectors here. With us today, I'm pleased to announce we have the SecureWorks management team, CEO Wendy Thomas. We'll just launch right into the fireside here. I'll leave a couple minutes at the end for Q&A, so feel free to write up your questions, and I'll try and allocate some time for you guys to get to those as well. Wendy, thank you for joining us. Thanks for having me. Absolutely. Absolutely. To kind of help level set for the audience, or anyone who's tuning into the webcast, can we maybe start with SecureWorks from, I guess, staring at the forest from a mile away, but, what is the main value proposition? What problem are you really solving for customers today? Sure. I mean, the value proposition for us is solving our customers' security outcomes, right? Better security, lower spend to protect their business and keep it up and running day in and day out. Our approach is different in terms of taking a new technology approach. You know, we've talked about XDR in the marketplace as being frankly that next generation of using artificial intelligence and technology to make the response time faster than the adversary. We talk about our mission as securing human progress by outpacing and outmaneuvering the adversary. You need a new kind of technology and security in order to be able to do that. That's great. We will be spending a good chunk of time talking about the tech. First, I'd like to talk about company transition, focus on selling Taegis. I guess maybe for perspective again, but, where was SecureWorks before this? Mm-hmm. What is the transition we're currently going through? We can start to talk about Taegis and the value of the platform. Sure. SecureWorks entered the security space back in 1998, so we've been around the block in. Mm-hmm. In terms of security. We started as a services provider, a managed security services provider, an MSSP. We were the best in the business. Right. Led the Gartner Magic Quadrant, had industry-leading margins, and went and spun out public from Dell Technologies in 2016. Around that time, we also stepped back as a leadership team and looked at step function spend and investments in security point products, as well as unfortunately step function costs of breaches in the industry. Everyone was spending more, but getting worse outcomes in terms of security. And for us, who was the leader in the space doing everything right, we thought, "This needs a new approach." That's where, as a business, with our board, we made the determination to invest in a new security SaaS platform, which at the time we called TDR, Threat Detection and Response. The industry has now got an emerging market quadrant called XDR, extensible detection and response. We launched that platform a little over three years ago, to hit $220 million in ARR and 1,600 customers. Very rapidly growing industry segment. Still very early days in terms of the hype cycle and the market penetration, so a lot of opportunity in the market space. That's been a fairly large transition for us to move away from managing others' point products and reselling those to really using our own proprietary technology to get to much better security outcomes. Great. With this transition that we're talking through as well, maybe you can, but could you just walk us through where we are? Are we middle innings? And has that meant we've been pushed out or pulled in just given what's going on with the current macro? Oh, good question. We are in our fourth quarter right now to finish our fiscal year February 3rd, and we've stated to the market that we expect to end this year with about 80% of our annual recurring revenue on the new business, and the preponderance of the remainder of that to that mix to transition in the first half of this coming fiscal year for us. Mm. We are definitely at the end of the beginning in terms of the transition from a services-led business to a technology platform-led business. There's still opportunity for us in terms of the adoption of XDR in the marketplace and the expansion of our distribution model with partners who provide services on top of that platform. Another thing that's been front and center for investors for the last, you know, year and a half now, but it's really macro, right? Would be curious what you're hearing anecdotally from your sales force or if you could give some examples even in the most recent quarter. Has there been a change in any way in customer behavior, customer spending habits, sales cycles, anything on that front? Sure. The security market's pretty resilient in terms of spend, and we've continued to see that play out. I was with SecureWorks in kind of 2008, 2009, we saw a similar sort of economic backdrop, and spend was pretty resilient through that period as well. It feels very similar to that time. What we have seen, and I've talked about on our last quarterly release and it has continued, is what I'll call greater scrutiny in the sales cycle that has lengthened the sales cycles. We haven't seen the, you know, "I'm not spending on security. My budget's been completely cut." What we've seen is, well, now this has to go through the CFO, CEO, and that approval process as they're kind of working through their own projections for their business, and that C-level approval has lengthened those sales cycles. Right. I guess to put a finer point on it, but one of the things that we consistently hear is, yes, there's more scrutiny, but at the same time, in the context of the broader-IT stack or budget, cybersecurity typically thought of as being better insulated. So, we would care to hear what's your view on that insulation comment. Do you think that is playing out to a certain extent, or do you have any sense based on customer conversations? IT. Do you just wanna put this mic on you? Oh, sure. Just the other one. This one's not working? Yeah. Yeah, it's not working. All right. Just put that on. Better? Before. One, two, three. Sounds the same to me. Oh, that sounds... Oh, we hit the mother loader. Do we need to start again? Everything I said is fantastic and fascinating. Sorry about that, Dan. The comment on insulation. The IT spend. Again, anecdotally asking, and of course, I read everything I can possibly get my hands on. It does look like there is pressure on technology spend, as with all vendor spend these days. But that the security piece of that is not only resilient, but potentially growing in the sense of it's not under as much pressure as the rest of the technology spend. I think the promise of certain systems investments to save a lot of people and time on the general technology side doesn't necessarily play out. Again, we still see security, fairly resilient for the moment and no signs of anything dramatic changing otherwise. That's great to hear. And if I shift gears to the market, right? We're talking about XDR, MDR. I know you had said that this TDR platform really launched about three years ago. I wanna say that XDR, MDR, those buzzwords really came in vogue maybe in the last 3-5 years. Can you give us a sense of the size of the market penetration levels, just because there is such a momentum behind these rallying cries? I'm interested in how much of it's coming from the vendors or how much of that demand is really being fed by the customers just looking for, I guess, better scapegoats in their cybersecurity posture. Yeah. We built this platform in response to customer feedback from many, many years, it reflects a few things around addressing customer security challenges that as the market has come to understand the intent of XDR, it has only increased the consideration. The percent of customers or prospects considering investing in an XDR security platform. I'll talk a little bit about the customer pain points, and then I'll talk a little bit about the hype cycle, if you will, of the XDR market. The original challenges that customers were looking to solve were that they had deployed all of these point products to secure your laptop. They had firewalls around the network. The proliferation of spend in different security niches was increasing, right? You saw that in stock prices, and you see that in just general industry spend. The fact is, breaches were going up because adversaries weave in between those point products. The concept behind the D in XDR, the Detection piece, is that you have an absolute dome over the entire technology estate, so that you can detect adversarial infiltration in the environment where there is no, you know, detectable software or malware deployed yet. From a company who understands adversarial behavior, their tactics and techniques for penetrating an environment, we do about 3,000 incident response engagements a year. Plus have a SOC. We basically have coded into our platform the ability to detect those behaviors based on individual threat actor, typical entrance techniques. The expansion of detection to be much more holistic, so across cloud endpoint, the way an adversary comes into an environment, as opposed to trying to just protect the front door and somebody else has to worry about the back door, that's the fundamental change in terms of the detection. The second piece is the R in XDR, and that's the Response. You know, we've talked about dwell times of an adversary who's compromised your credentials and gotten into the environment but hasn't found their way into the financial system or the other crown jewels of the company, the manufacturing line, the pipeline. That just a couple of years ago was about 40 days. Right now, it's about two days. The time for them to inflict damage on an organization has radically declined. The ability to detect that, prioritize that, and automate the response and remediation to that, it's fundamental and that's why you have to do it with technology instead of people, which was the second piece behind us realizing we wanted to take a platform-based approach to the security challenge. The last piece customers ask for around XDR is that they want you to complete that swing, right? In the past, everything would set off the alarm bells, something bad is going on. They couldn't tell you whether that bad thing really mattered and distill it down to only the things you need to spend time on, and they couldn't complete the swing to automate that response. This is a completely different approach to security to save the need for people and frankly, save the need for mistakes, for those who don't necessarily know what they're looking at or how best to evict the adversary from the environment. Can you build on that last piece? Like, the idea that because we know that we're hearing for a number of years this labor shortage. Yes As far as the technical expertise, right? You're saving customers on that front. You're pointing them in the right direction, and it's this whole solution set, it goes from the detection to the remediation and just pointing people in the right direction. In that R piece, again, when we think about XDR, like, how is it you guys are driving differentiation for your customers there? If this market is booming and there are other competitors out there, how are they talking to the market and what are some of the differences that you're able to demonstrate? Sure. There's a couple of areas of savings for customers, certainly in terms of people. It's not just a volume of security analysts and workload, it is a diversity of the skill sets you need around security expertise. Mm-hmm. Not only is the platform doing the detection and response capabilities of what comes in, it's running automated playbooks around hunting for additional adversarial activity in the environment. It's getting ahead of the threat, if you will. That's a different skill set than a SOC analyst who's investigating certain alerts. The variety of expertise that you would have to have in-house to have this level of security outcomes is also as wide as the volume requirement if you haven't automated the process flow. For customers, they save in a couple of ways on that front. Clearly, in terms of in-house staffing requirements, we generally see there's about an 85% reduction in today workload versus tomorrow workload with the technology. They also save from a security point product perspective. If you think about your phone, you no longer have a separate camera and a separate GPS device. The security platform is the same thing. Many individual point products today, Next-Gen AV, EDR, those are now features of an integrated XDR platform that lets customers reduce their total security spend while actually getting better security outcomes from it. Great. On that consolidation theme too, we were just talking about Next-Gen AV, you are right. Are there other pieces of the cybersecurity, I guess, landscape that are then being consolidated into, I guess the XDR solution that you currently have today? Are those the primary two areas that can fall under this platform? The primary transition we see is from legacy SIEMs to XDR because the promise of SIEMs really was never realized. Yes, they aggregated a lot of data, but in order for you to maintain the detection capabilities, you had to tune that SIEM constantly. Your integrations, your detections, It was very difficult to do proactive hunts. You had to write your own searches. The staffing that you needed to both configure and maintain the configuration of that to be effective was pretty expensive and hefty. When you think about a cloud-based platform where those search queries are run for you, the detections are constantly updated, the data's not just aggregated for compliance reporting, but normalized for better and less noisy detections, that is just a better animal that for SIEMs, they don't have the response capabilities. They don't have the investigation capabilities that are automated. It not only replaces what they had with something better, but extends it all the way to remediation. That's probably the biggest current use case for replacement. Again, as other standalone products really can just become features of a module of a platform, vulnerability management, scanning, AV, EDR. It's an opportunity to very smoothly and safely from a customer perspective, transition out of those individual point products, and expand with the platform, on their timeline. Okay. If I'm thinking about SecureWorks now in this broader XDR market, I wonder if it comes back to the 3,100 incident responses that you guys have had in your history since 1998 now in the market. Like, what is it that SecureWorks is doing differently to compete with Taegis versus other XDR vendors, right? The legacy SIEM makes sense as a replacement, but XDR versus XDR, how is it you guys are going to market? The biggest difference for our XDR platform is we talk about it being open without compromise. Mm-hmm. There are XDR players in the marketplace who start from what we call a proprietary stack. You must use my endpoint. You must use my firewall. I am a public cloud provider, so if you have a hybrid set of public cloud usage, there is a challenge there. We are security first in terms of a pure play and completely open around all of those technology stacks. We have the ability to interoperate with those, and frankly, most companies don't have a clean stack. They do acquisitions, so they've got multiple endpoint vendors. They've got multiple firewall configurations. The ability of that platform to provide the interface for managing an entire security program holistically with the underlying technology choices of the CIO or the business being able to change and evolve over time smoothly, without forcing rip and replace, without forcing situations where something is not visible to the platform. This solves that problem in a way that other vendors who force you to use some piece of their stack only, creates a lot more open flexibility for customers. Great. Another thing that we hear about in the industry as well is alert fatigue, right? The idea that you just get a number of alerts, some of them may be more important than others, some of them just not even that important. How is it Taegis is trying to solve for this and to reduce that workload for your customers? One of the things about the platform is it is also open with respect to the source of detections that we prioritize as something to investigate. Let's just say that you have a variety of endpoint vendors, firewalls, a couple of public clouds, and the alerts that come from those as potential issues, in the Taegis platform, you can see the source of it. On average, 99% of those we deprioritize as noise. Either they're duplicative, events or they're simply, anomalous but not malicious. It is quite easy for our customer, whether they're in a proof of concept with us before the sale or after the sale, and they're quarterly looking at, you know, what's the value I'm getting from this platform, 99% of the noise goes away, and they see the 1% that matters and the actions that we take on their behalf to protect them. Taegis also, or the company also talks about Taegis having industry-leading ROI, right? I'm curious, in that ROI lens, what are the main factors that the customers are looking at? Cause again, we were talking about the 85% reduction typically of workload for headcount purposes. There's multiple avenues. Sure. I'm just curious, like, how you guys are measuring that comment. We actually work calculators with customers on this front, but we think about it in three pieces. One is clearly the staffing requirements, which we've talked about. The second one is that consolidation of vendors. It's again features of a platform included in the price, and that's easy enough to calculate with contract dates and rates. The third one is the cost of risk to the business. In some ways, that it can be difficult to count as a savings, but when you understand the assets that are generating most of your revenue and the power of the protection of those for a day of uptime, say, we can help them focus in on the areas of their business that create that risk. More importantly, that's the conversation with a cyber insurer to reduce your cyber insurance rates because the controls that you have around the sort of revenue or cash flow generating assets in the business, could be a website, could be your manufacturing facilities, that's the third leg of the stool in terms of the ROI on security investments. If I go back to the consolidation theme for using XDR or Taegis, right, is it typically customers are doing their due diligence on the market, making sure they're keeping up on cybersecurity posture, or is it more like, "Hey, I'm frustrated with my legacy SIEM," or, "Hey, my next-gen AV is up for renewal, and I need to take a more thoughtful approach as I'm gearing up for the world in 2023 versus where we were in 2021 or 2022," right? Where does that conversation really start? Or how does it begin for them to start tinkering around with XDR and letting them know? It's funny, two years ago, it was a technology early adopter. Mm-hmm. This is a better technology. I want leading-edge security technology in my organization. They, you know, didn't need the marketplace to tell them XDR is the thing. Today, the conversation is starting with a different call to action, and that is: How do I think about optimizing my total security spend and frankly, technology investments, while getting the win-win of better security outcomes? The level of market awareness that's out there in terms of considering XDR is just higher because we've been in market for a longer period of time. The call to action in the past that might have been a breach or a breach in the industry, that call to action now is an opportunity to get the win-win of less total spend and better security outcomes. We're in a different part of the curve. Right. Which hopefully would stand up in a, in a weaker macro. You're looking to drive those savings, right? Not only is there potential for that consolidation play, but also if new dollars are being put into cybersecurity, it sounds like they are being dedicated to XDR too. There is a mounting market behind that category as well. We do. Every report that comes out, the awareness and the consideration, and just honestly, the questions that I, that I get about it are quite different and, and reflect a sort of higher level of base knowledge of the opportunity. Okay. Let's see. Just to cycle back to the transition of the business, right? One of the things that management has spoken to, again, with this transition towards more of a pure software play and this platform with Taegis, is the idea that you're gonna be hopefully, exiting non-strategic services. Mm. Right? Can you give us a sense for where we are on that exiting? Maybe just as an example, like what are some of those non-strategic services? Can you give us an understanding or maybe roundabout way of thinking through the margin profile for those services as well? Sure. As I said, we're coming to the end of the beginning, if you will, in terms of exiting this year with about 80% of the business on the new platform. When we looked at the original managed security services business, there were really two areas where we didn't want to continue operating. One was what I'll call services that were people-based only. There was no technology enablement of those services, and the margins reflected that. Think device management who had changes on firewalls. There really is no differentiation other than price between one company versus another. The second piece, or second area of businesses that we've exited is pure resale of other third-party security products. The original business was to manage those products, and in many cases, we would resell those products. Those are the two areas that we've been exiting out of. Now, on some of the services, it has made sense to transition those to partners who do provide broader IT-type services, as they also begin to offer security services on top of the Taegis technology platform. There's been a some ability to build some of those new partnerships of enabling other managed services providers to buy the software of the Taegis platform. The remaining 20% that we're looking to exit then should be mostly spun down by the end of, I guess, this next year then when we think about the exiting of those businesses. Absolutely. Okay. With the preponderance more in the first half. Understood. Understood. Okay. We spoke about the product, right? I know that you guys are taking this thoughtful approach here. It's not just product, it's also Go-to-Market, right? Mm-hmm. I think you touched on it just now, but the business is also embracing a partner-first approach. Can you talk about how the Go-to-Market had been previously structured just for context, and then was partner-first always in the cards or where is it you guys are going with that? Sure. With a services business, think about the sale of that as a pretty bespoke kind of statement of work type of sales process. We had a very direct sales model previously because of that customization and level of expertise required to craft those contracts. As we moved to both a product sale with XDR and VDR and vulnerability management, plus a very standardized service of managed XDR, the ability to enable partners to sell those services is obviously much more scalable. We started a partner program about two years ago now. Started to see good traction with those partners. Did make the move to a completely partner-led sales model December 1st in North America because we have the sort of momentum and traction with the right partners in the marketplace. There's a second layer that's a longer-term vision layer for our distribution model, which reflects we are trying to transition toward a model where we're enabling other services providers to basically use Taegis as their security program platform. We then launched, a little over a year ago, a managed security services provider partner program to enable those partners to build out their own SOCs, their own incident response services, but using Taegis as the technology underneath of that. As we've demonstrated to them the very scaled high margins of managed XDR that we were able to achieve with those customers who take services from us today, that's a very compelling value prop relative to the margins they're making using a SIEM or other platforms in the marketplace. There's kind of a two-part transition there, to partner-led, as well as then from there, much higher percentage of MSSP partnership sales. Can you talk on that second point of the program with the MSSPs? There's a number of other security vendors who are trying to, I guess, be thoughtful and work with those MSSPs as well. How is it again, SecureWorks is attracting these MSSPs? Really, I guess the question comes down to how is it you're investing to ensure the success of that program? Yeah. We always talk to them about who would you like to learn how to run a scaled high margin, effective managed services business, the leader in the Gartner Magic Quadrant for more than a decade. We know what right looks like, and we built the technology to support what right looks like, in terms of automation and consistency and keeping the workload low in terms of noisy detections for the analyst. When they see how that is run, we provide them kind of a how-to step-by-step program of how to start that process. Many of them start reselling our managed services, our MDR, and then move to starting their SOC once they've got the sales process down and building that out. We very much have an instruction manual that's straightforward about how to build a very scaled, effective business for certain customers. Probably a softer but more qualitative question here. If I think about, again, those MSSPs and building them into the program, how do you balance the volume that you want to make sure that you guys are continuing to grow, but at the same time, the quality of those MSSPs to ensure that they appropriately understand the value proposition that you're trying to deliver to them and their customers? We have a very targeted list of partners that it makes sense for them and for us to Go- to- Market together because the level of trust that is required in security is extremely high. It is important that if you're gonna put your brand on a partnership and a service delivery that it gets the level of quality delivery that you're looking for. Again, it's careful selection of partners and a very tightly integrated launch process and then ongoing, you know, customer reviews and QBRs and that kind of thing to make sure we're getting there. Great. again, just thinking out loud, but with respect to the partner program, if I look at over the past year, probably two years at this point, with the transition towards more of a Taegis offering- Mm-hmm. The customer base, it does feel like the vast majority of Taegis customers today have been migrating from what SecureWorks had previously offered. The thought process is that with this new partner program, it really then opens up the market opportunity that you guys hadn't been addressing previously with Taegis, or it's another lever that you can pull to better address those organizations. Is that a fair way to think about it? Yeah. Think about it as really expanding the distribution into additional market segments, especially geographically, globally. In terms of our current concentration, about 35% of our business is outside of North America, total revenue, and that's concentrated in sort of Western Europe, Japan, ANZ areas. As we think about expanding in terms of the global opportunity, there are partners who are very specific to geographic expansion and those who are maybe specific to certain industry verticals or that type of thing. It makes sense for us to be able to have a few targeted partners that expand that distribution and scale our existing sales force that supports them. Great. I have a couple more questions on my side, but wanted to open it up before I chew up the clock. Does anyone here have any questions before I keep going? All right. Happy to keep rolling. Listen, okay. For you guys, you also have this Technology Alliance partnership that you've been talking to in recent quarters as well. Can you provide color as far as the importance of that partnership program in the context of the Taegis platform? How strong are those alliances when I think about you guys? Every vendor's talking about them, right? How much of a bridge building is there that's actually taking place? This is very important. In having been in the space where we were managing all the leading security point products, we have good relationships across the industry and a deep understanding of the products that are out there and kind of how they work together or don't work together. For us, we launched the Technology Alliance program not quite a year ago. It's about a twofold cooperation, if you will. One is technological, so that not only do our products work together inside of the integrated XDR platform to give customers optimal security, visibility and actionability. There's the technical aspect of that interoperability where there's mutual benefit in terms of the observations of the security platform. The second one is really the Go-to-Market piece. Especially these days, getting scale in terms of, you know, customer events together and access to each other's bases to expand spend. That is the moving away from a resell model to really going to market together in a way that makes sense for customers. Great. I know that you guys had also launched SecureWorks Taegis for Japan just a couple of months ago, right? I think this feeds into what you were talking about as far as the global growth strategy. Is the Japanese market specifically a large contributor revenue, or does it just demonstrate the fact that SecureWorks anticipates taking Taegis to a global scale over time? Are there more regions to come? How should we think about that rollout? We've been in Japan for about a decade, and so we do have a very loyal customer base of quite large customers there who are global in nature for the most part. We launched a Japanese version of the platform, an instance of the platform back in, I guess it was November, both to address one of the largest security market opportunities in the world, as well as to be able to transition the existing base there to the new platform. Spent a week in Japan to do that announcement. The receptivity there is very good. It's interesting, the knowledge of XDR was quite high there in terms of the technological, you know, we want that next generation of what best looks like. Those conversations were actually really proactive around how to, how to best transition that to a global model, because most of those organizations are distributed globally in terms of conglomerates. I think that's a really good growth market opportunity for us. We closed a couple of deals fairly quickly after launching there, so we like that long-term growth. Terrific. Terrific. I meant to highlight this earlier, but when we were talking about the protection that Taegis is providing for customers, right, the deployment, you guys are not dedicated to specifically just on-prem or just cloud. Like, how do we think about the different environments that you guys touch for your customers? Are there any restrictions in that respect? Because we do hear about that from other security vendors occasionally. No, I mean, that is the beauty of the openness of the platform and the interoperability, is that no one has these pristine technology estates that never change, right? The ability to meet customers where they are in terms of their desired technology design is one of the key differences for the Taegis platform versus other, what I'll call proprietary stack XDR providers. 'Cause the world out there is very mixed. Honestly, even if you're all public cloud-based, you want flexibility to move between different public cloud providers should you have a cost structure challenge. We just see the agility and versatility of the platform to work with their technology changes to be a key selling point of kind of future-proofing their security investments. Great. Last thing, with just a couple minutes left, but I think about you guys, we were talking about the exiting the non-strategic services, the growing base for Taegis, the change to the Go-to-Market with Partner First, and then the strategic. Like, there's a number of things. If you wanted to leave the audience with maybe one or two things to really highlight as far as management's priorities or what we should be looking at from the outside in, what would those top priorities be from an investor standpoint coming from you? Yeah. From an investor standpoint, we are kind of reaching the end of that beginning where the go-forward business model is clean, the cost structure, the duplicative cost structure from the two platforms is about to come out. What you have is this gem of a 80% year-over-year growth business hitting, you know, $200 million + in just a few years, hidden underneath of a business model shift. The opportunity in terms of the valuation is quite good. It's really just getting that story out there of click one level down to that underlying business, and we think that creates a great opportunity for investors. Terrific. We'll leave it there. Thank you everyone for joining us today. Definitely appreciate it. Thank you, Wendy. Appreciate it.
Loading workspace