Okay. Thanks everybody for joining. My name is Adam Tindle, and this is part of my cybersecurity coverage here at Raymond James. Very happy to have the team here from ZeroFox. Interesting story, just reported earnings and still came to our conference to present, so we appreciate that. James Foster, CEO, more affectionately known as Foster. Tim Bender, CFO. And our format's gonna be a fireside chat. So, obviously, if you have any questions along the way, please feel free to pipe in, raise your hand. We'd love to keep it as interactive as possible. But with that, Foster, if you can maybe just take us back to the founding of the company, a little bit of the elevator pitch on what problem you were trying to solve and, the key IP around that. Sure. We founded the company about 10 years ago now. So the startup days are way behind us, and we've hit this nice meaty kind of growth stage, where we saw an opportunity, where the world was changing, security was gonna have to change, where organizations were gonna adopt more technologies that they didn't own, they couldn't control, they couldn't put agents on, and they couldn't put firewalls around. And succinctly said, that's where we saw external cybersecurity being born and created. You know, the world prior to 10 years ago had spent the last 15, 20 years putting agents on devices, and there's great companies out there still crushing it, putting agents on devices. You've seen a tremendous amount of revenue change hands from the McAfee and Symantecs of the world go to the CrowdStrike and SentinelOnes. You've seen a lot of organizations over the last 25 years separating the in from the out. You know, we call those the perimeter and edge players, the Check Point, the Palo Alto Networks, the Fortinet, the Zscaler. We saw that opportunity to say, "External cybersecurity is gonna matter. You're gonna wanna know what's happening in the deep and dark web. You're gonna wanna know what's happening in social media. You're gonna wanna be able to protect mobile apps. You're gonna wanna be able to protect domains, digital assets that can't take agents, can't have firewalls." And, we're the largest standalone player now, working on that problem set, and we've been doing it for about 10 years. Perfect. Mm-hmm. Tim, since earnings is fresh, do you wanna maybe just refresh us on some of the key metrics from this morning and that you reported? Yeah, I think the first—the one I like the most is we achieved our second consecutive quarter of free cash flow positive. So, big hurdle for us, certainly as a CFO for years. As Foster said, when we started together, when I joined in that early, you know, stage of growth, you know, spending money to grow, but now kind of hit a little bit of an inflection point where we're starting to see profitability, and so, really happy about that. But, revenue, really strong. Our subscription revenue continues to grow. I think we're up in the mid-40s% year-over-year. This is actually the first quarter we could present kind of comparative numbers, given that we had the kind of complicated De-SPAC transaction. Subscription margin, 73% was up again. Those are, like, some of the real key metrics that I took a look at, so. Perfect. And Foster, back to, you know, kind of the founding of the company, there's you alluded to it a little bit, but you've had a couple key acquisitions along the way, IDX, LookingGlass. Can you maybe just expand on that strategy, you know, why you went down that path, and what those assets brought to the company? We saw an opportunity to really accelerate the breadth of the platform over the last four quarters, four years. And we've taken a different approach in the philosophy of what we look at acquisitions. There's a lot of companies out there that take a maybe a best of suite approach. They buy a company, they put it in their go-to-market distribution engine, they sell two products alongside each other. We don't do that, and so when we look at a company, we look at a company that's got great tech prowess, great customers, dedicated people, but probably some things that haven't really figured it out in go-to-market. And we take that product, we integrate its core capabilities and features into our platform, and then transition their customers over to our platform. So we have maintained that one platform, unified experience and approach, which we think will have a nice rising tide effect for us long term. And that's something that we've been doing for each acquisition. You mentioned LookingGlass. It's the company we bought earlier this year for external attack surface management. When we launch those native features in our platform here this winter, it'll be a really nice win for us 'cause we'll be the only converged platform out there offering DRP, threat intelligence, and attack surface management under a single unified experience. Perfect. And, you also hosted an innovation day to, you know, sort of highlight some of the innovation happening at ZeroFox, particularly AI-related. Yeah. What were the big takeaways from that session, and how does AI fit into the strategy and outlook? We've been using AI now for the better part of eightish years. And it's come through and manifested itself in all kinds of different hype cycles. Eight years ago, we called it machine learning, then it went to deep learning. We implemented computer vision when facial recognition was really exciting or really controversial, depending on which side of the aisle you were on. Everybody in the world was worried that your face everywhere could now get mapped out to your person and your individual. And so as a matter of fact, like, we stopped calling it facial recognition in our platform for a few years. We called it facial comparison technology. Hmm. Everyone was like: "Oh, that's much better. That feels safer. We like that. Right. So now we get to generative AI and large language models, and everyone's like: "Oh, don't, don't take my data and use it to train your LLMs. Like, you could figure something out that the bad guys could figure out." I think that kind of worry wave will work itself out in the coming quarters. But we use LLMs like everybody else. We were the first public cybersecurity company that I know of that talked about how LLMs were used on our platform. So we summarized intelligence for our customers and provided it back to them on our physical threat intelligence reports. Then we also are using generative AI to help create intelligence and create alerts now for our customers. It will have a continued meaningful impact in just the same way computer vision did with us. You can't build tech without computer vision to look at high rich media content like pictures, audio, or video. You have to use that kind of tech, and if the alternative approach is doing it manually, and a lot of our competitors ten years ago still do it manually today, and they just try to find low-cost offshore centers, we build the tech and do it at scale. So- I'm gonna get into some financial metrics here in a second, but any questions on the technology? Sure. Sure. So full disclosure, I'm from RJ Technology, from the organization itself. Wanted to ask the following question: We see a lot of potential threat intelligence around, around brand recognition issues. How have you used artificial intelligence to protect, you know, with a high level of fidelity, alert, like, laterally amongst other, maybe, let's say, one CISO or one president of a, of a firm, a financial firm, has this type of brand identity, threat intelligence that you've curated. How do you use artificial intelligence to maybe talk to other financial institutions about what similar concerns that they should see? Maybe I'll use an example to help articulate how we are doing it. Okay. Given the example of a CEO or executive of a financial services firm getting targeted, you know, the brand targeting. When I think about brand targeting, it typically manifests itself in one of two ways: Someone trying to target the brand of an executive, as you mentioned, or the brand of the organization, which happens through fake domains, logo usage, you know, look-alike, likeness, kind of impersonation. Sure. And so in each of those, you'll need computer vision to do either facial detection to say, "Is this picture of James Foster?" And you'll have trained your system with pictures of James Foster to then do a tremendous amount of computational analysis to go, "Is this face the same as one of these faces that I've now trained on?" That's how we do it on an executive level, and then you'll say, "Great, image match." And then you'll go through and do fuzzy name matching to say, "Does the name also match? Does the bio match? Does the information from where this, you know, executive I'm trying to protect match, i.e., location, work location, etc.?" The second thing you do on a brand side of the house is very similar, but it's logo-based basically, right? Is this logo the same? And so it's more complicated, though, because you've got to then say, first, is this logo that you've also trained your systems on in this set over here? So you have to do what's called image-within-image identification first. Is this image within this image? And then you've got to say, "Okay, is it the same?" Now, when you impersonate a brand, unlike an executive, you're also looking for maliciousness. Are you phishing for logon credentials? Is it a logon page? Are you trying to steer someone to another page that may be a watering hole attack? And so you'll start to use machine learning or deep learning to do link analysis to say, "Is this taking me someplace bad? Is it malicious?" And then lastly, the real AI stuff that's now kind of becoming more in vogue, the Gen AI and kinda deep, beyond deep learning, AI side of the house, is the TTP analysis below. And so is this a one-off targeted attack, or am I seeing it elsewhere? What other links can you tell me about it, and what are the probabilities that it could hit somebody else of my like, in my region, of my size? And so we can use a Gen AI model that we have right now and go, "This is the probability that it hits somebody else in financial services right down the road. This is the probability it hits somebody in financial services in London, and maybe this is the probability that it hits somebody over in Singapore." So, and those- Is part of your threat intel platform? Yeah. Okay. Yeah. Yep. Now, look, it's customers like it until you tell them they're about to be attacked. Right? And they don't like it when the models say that you're about to be attacked, and there's a high probability with high confidence that you're gonna get an attack within 90 days. 'Cause then they ask questions that, "By who?" "Well, these are the most probable threat actor groups with our threat actor database that target organizations like you," you know. And then they'll ask more impossible questions: "Well, how will they attack us? How will they get in? What will they do?" I'm like: "Hold on, back up," right? "Storms are coming. I can't tell you where lightning is gonna strike." So yeah. Mm-hmm. Scary. I hate covering cybersecurity. It just makes me paranoid. Let's talk about financial metrics today. Sure. ZeroFox has the platform side and the response services arm. Can you talk about maybe the growth and margin difference between those two? Sure. So first, as I mentioned, the platform up in the mid-40%s year-over-year. A little bit of inorganic in that as well, no doubt. But growing organically in the mid-20%s consistently. From a margin standpoint, I think if we go back maybe, you know, four or five years, we were in kind of the mid-60%s, and we've upped margin, you know, contributed maybe one or two points a year, every year, all the way through. We're at 73% now, at least for Q3. We should end the year at about that. And our goal is to continue to add, you know, a point or two of margin as we can along the way, as we tick up. 80%s is our long-term goal. I won't tell you what long-term is yet, but eighties is our long-term goal. You know, historically, we've always, you know, proven out the ability to add a margin back to the business. On the response side, it's I mean, this year has been a phenomenal year for us, I think. ... response revenue might be up as high as maybe 90% at one point. It, it's really gangbusters. We mentioned in our press release, one large deal that we had this quarter from a, you know, a name that everybody would recognize in this room. We've had, you know, several of those style, or size engagements this year that have really, fueled the growth. That does have a little maybe a negative impact on the margin to a degree. The margin is compressed a little bit for these big deals. Well, if you think about a breach or a response deal, there's a upfront notification piece that, that's a pretty low margin, where you have to notify the impacted population. But then once that population enrolls for the protection, that has the similar characteristics of our, our platform business. So once a person is enrolled into the digital risk protection and ongoing, you know, credit monitoring, you know, that's a 70% margin business either. So even that element of the business has two components. On average, it's, you know, gonna be between 15% and 20%, depending on the magnitude of the deal sizes. That brings the combined kind of financials to about a 38% margin, which, you know, does give people, as Foster says, KPI confusion. They look and see a software business at 38%, but you have to look at... In our mind, you look at it and say, "Hey, you know, software business at 73% is right in line where we need it," and the breach business certainly contributes to cash flow. And then our OPM contract is pretty static at about 20%. What's led to that inflection in the response business and that large customer? Has there been, you know, any sort of change in the platform to enable a large customer to adopt, or what was the change to have that business accelerate? I think it's been the change in just cyber breach activity and, you know, MOVEit, all those type of, what were the—Log4j, all those were the ones that, I mean, what you hear about and see about and read about, you know, we're getting the benefit downstream as it relates to response. We've proven, you know, with the larger deals that we've been able to take on, executed well. We're getting more and more at bats, and we're winning those at bats. And then, Foster, maybe if you wanna talk about the cross-sell opportunity. It seemed to be some, you know, natural cross-sell between the two platforms, but- We did, yeah. On the earnings call this morning, we talked about how we saw increased cross-sell and upsell opportunities that have actually started to play out now in the last quarter. And so, you know, in our enterprise sales cycle, we don't, our enterprise sales cycles aren't years, right? Even though if you look at our ASP, our ASP has grown every single year for six years in a row, and I think that story tells that, like, the platform is better than it's ever been, continues to get better. The market continues to mature. Our go-to-market continues to mature, where customers are more willing to spend more money on this problem. I think the problem set is probably the key, that the problem set continues to grow. In cyber, if your ASP goes up, it could be a lot of the first things I talked about, but ultimately, it's, are customers willing to spend more money to protect themselves against a problem set? External problems are the only thing people care about right now. Like, you don't care about anymore somebody coming in and doing insider threat, walking out with a USB with your data on it. You care about getting hit with ransomware from somebody in Eastern Europe that's outside of your jurisdiction. You can't go after them with law enforcement. Law enforcement tells you right now to, "Don't pay," and we see 60% of our customers still paying. So you've got this disconnect in the advice you're being given and the actual threat profile that's out there of an organization, and it feels like the deck is stacked against you. And so our customers are coming to us on, you know, and saying, "Hey, you guys are doing this different. You're helping me go after and dismantle attackers that are persistently coming after me." We like that. We haven't seen a response provider that's been differentiated in a while. That's why Tim said we're up, like, 90% right now, and we've leaned into that market share opportunity. And so LockBit is the number one threat actor out there we've seen right now this year. And, you know, one of the stats that we just publicized in The Wall Street Journal was that the LockBit financial services attacks are up 50% year- over- year. And so, you know, it's a, it's a, it's a game changer, and they're affiliated with, you know, CIS states in Eastern Europe. Interesting. So- Rewinding, back a step, you know, the platform is a lot more holistic, so it's a little bit harder for us to understand the competitive set. But if you were to, you know, kinda talk about the key competitors that you're often going up against, who would they, who would they be? We see Rapid7 a lot, you know, from a public company standpoint. They've made some interesting acquisitions along the way. You know, I know our ASP is larger than theirs, and they typically serve more kind of mid-market-ish customers. But they do have an offer out there for digital risk protection and threat intelligence. They bought a company called IntSights- Mm ... at this point now, a couple plus years ago. But they take a different approach, right? They've got a really good long-term vulnerability management practice that they've kinda used to bolt on their platform, but they've taken a best of suite approach, where they don't do heavy integration with technology. They're comfortable with customers logging into different platforms. I think they do a really nice job in maybe bundling products together as a part of their vulnerability management renewals, and this seemed like an add-on. But where we see this is customers get sold one thing during an acquisition and then get frustrated during the life of that contract and then come back and say, like, "If I'm gonna log in to two or three things anyways, I'm gonna just go back to buying best of breed, as opposed to best of suite, and I want best of platform." And that's where ZeroFox wins, and you see us beating out our competition. Makes sense. So speaking of them or just, I guess, the broader competitive environment, we're sitting here in early December. Would love to understand a little bit more about demand trends. Always helpful to look at things, you know, today versus a year ago or a quarter ago... and the second derivative, you know, what's changing? I think we've heard from a lot of companies about tight budgets and extra signatures required and stuff like that, but just curious what you're seeing here real-time and how that's changed. Sure. I'll point out maybe just a couple, right? There is a Middle East effect that's happening right now, right? In general, Israel is not a cyber tech buyer, they're a cyber tech exporter. And so we get questions from time to time on like, "Hey, is you, you're not selling into Israel as much?" I'm like: Well, no one sells security into Israel, to be clear. Mm-hmm. Like, I don't know a single company out there that's, like, talking about that. But, the areas in and around the Middle East right now are certainly distracted. And so I think about any net new big projects, in general, when there's crisis and conflict, cybersecurity has typically, come to the rescue, and you've seen that be a, a buoy. Right after the crisis physically dies down and when loss of life is no longer a concern, you start to see people saying, "Okay, I need cyber." The cyber activity in the Middle East right now is incredibly real. Folks on all sides are using it as justification to attack their neighbors, and so I think that that will have a, a ripple effect next year. You'll see that play out to probably be a boom for cybersecurity providers that are mandated, and I think we'll be part of that. But I think for the next quarter or more, depending on the longevity, like, it could be a little bit of a headwind versus a tailwind, but I think a tailwind will have an after effect. North America, Western Europe, still performs really nicely and well for us. Our enterprise customer base, we see strong demand there. We aren't getting some of the pressures that we hear about others in the kind of public space on headwinds. We aren't experiencing that since then that. Could be small numbers. Right. We're the smallest guy out there, I get it, so it could be small numbers, but, we just put up the best quarter in company history. We had the best public sector end-of-fiscal year in company history, and our enterprise ASP grew. I think, I like what I see there going into the next year. Okay. Good, Good, good. Maybe just talk about your go-to-market and how the products are priced. You know, is the go-to-market more of a channel strategy or more direct? And then how are the products priced? Are you bundling? Is it more of a platform or...? Yeah, we have taken an approach where, quite honestly, we've probably innovated at a greater pace than maybe product marketing and pricing and packaging has kept up with, which has been a nice to have. I mean, like, like Tim said, we're up 90% in services, 45%-50% in the- Wow! SaaS platform year- over- year, and so we've just done a really interesting job. I mean, we were 250 employees strong three years ago, just under 1,000 people today, and so, I mean, we've really hit it out of the park. But I think we're, we're quickly approaching this time where, we could probably rethink some of our pricing and packaging, resimplify, and maybe even increase adoption and increase value distribution for our customers, and at the same time, capture some of that white space. And I think there'll be some upside for us, next year as a company when we do that. Let's round it out. We've got a couple minutes left. Definitely want to touch on cash flow and profitability. I know that's been a big positive for the company. Foster, what was the timeline for free cash flow as you anticipated becoming public, and how are you balancing growth and profitability? Well, three quarters ago, we said to the market and the world, we'd generate cash flow and be cash flow positive the end of next year. And the market came back and slapped us and said: "Nope, try again." So we came back, you know, at the end of Q1, we said: "Look, it's gonna be the second half of next year, not the end of next year, we'll be ready." We got slapped again, so then we said: "Look, let's not mess around. We're gonna be cash flow positive next quarter." So we turned cash flow positive in Q2, and I think the writing is still on the wall, where, like, Q2 cash flow positive was $600K-ish. I think the market was like: "That's adorable." "Please do more." We roughly doubled quarter-over-quarter here to Q3. We're gonna get, like, "Hey, doing a better job,"- Mm-hmm. Still not there. And so I think, our expectations and what we are guiding towards is, we have more to do, we can do more. It's line of sight, it's just gonna take us some time. We hit two quarters in a row. We accelerated that by a year, what we were initially guiding towards, and, you know, I think it will, we'll continue to improve here next quarter. And we will be cash flow positive next year as well. So, we've hit that inflection point as a company, and, we know the market that we're in, so it's not lost on us. Yeah. More work to do. Tim, what are the major levers to keep durable free cash flow generation like Foster talking about? I mean, I think part of it's just, and I've said this all along, it's the scale and the business model. You know, we get to a certain size where, you know, most of your sales come from existing customers. That comes in at a much more cost effective than going out and hunting the new business. So balancing, you know, solid net retention, solid gains in that with the new business, we'll just continue to add that cash flow. We have the prepaid subscription model, so, you know, that's gonna, you know, advance cash ahead of revenue and, you know, EBITDA or, you know, operating loss. So I think it's just continued execution across our model. We don't have anything, you know, crazy as far as, like, growth rates. You know, we're not having to take costs out of the business. It's just moderate and execute like we are. Perfect. Maybe just to wrap up, Foster, would love maybe just a little bit of insight on the feedback that you get from your investors, you know, what they're asking you to do, and the key message that you'd like to leave with potential investors today. Look, I think it's, you've now shown us that you can do it. Just continue to do it, and do it faster, right? I mean, that was kind of it for growth and profitability. And, you know, we've made a couple of acquisitions here in the last couple of years, and so working through those synergies faster on the, cost side of the house is what something we've been able to do the last two quarters. We're not done. If you think about the tail of most acquisitions, and especially in the world of office space or leases, like, some of those will play out here in Q4, some will play out next year. We have more work that will just naturally be done, that's not hard work, as Tim said, like, over the next couple quarters, and I think that'll meaningfully be done by next year. And then, on the revenue synergy side of the house, we've taken a different approach, and so putting the products together in a unified platform, we've got customers already using it today, and we launch it to the world. You know, think of the cost for all of those new launches already into our price. It's all upside, and so I think, we've got a lot of opportunity for us next year. Sounds exciting. Yeah. Foster, Tim, thank you so much. Thank you. We'll look there. Thanks, Adam.
Loading workspace