8/8/2024

speaker
Operator
Conference Operator

If you would like to withdraw your question, press star 1 again. Thank you. I would now like to turn the call over to Sri Ananta, Vice President, Investor Relations. Please go ahead.

speaker
Sri Ananta
Vice President, Investor Relations

Thank you, operator. Good morning. Thank you for joining us today to review CyberArk's second quarter 2024 financial results. With me on the call today are Matt Cohen, our Chief Executive Officer, and Josh Siegel, our Chief Financial Officer. After prepared remarks, we will open up the call to a question and answer session. Before we begin, let me remind you that certain statements made on the call today may be considered forward-looking statements which reflect management's best judgment based on currently available information. I refer specifically to the discussion of our expectations and beliefs regarding our projected results of operations for the third quarter full year 2024 and beyond. I also refer to our expectations and beliefs regarding our proposed acquisition of BeneFi. Our actual results might differ materially from those projected in these forward-looking statements. I direct your attention to the risk factors contained in the company's annual report on Form 20F filed with the U.S. Securities and Exchange Commission and those referenced in today's press release that are posted to CyberArk's website. CyberArk expressly disclaims any application or undertaking to release publicly any updates or revisions to any forward-looking statements made herein. Additionally, non-GAAP financial measures will be discussed on this conference call. Reconciliations to the most directly comparable GAAP financial measures are also available in today's press release as well as in an updated investor presentation that outlines the financial discussion in today's call. A webcast of today's call is also available on our website in the IR section. With that, I would like to turn the call over to our CEO, Matt Cohn.

speaker
Matt Cohen
Chief Executive Officer

Thanks, Sri, and thanks, everyone, for joining the call today. We started the year with a clear vision and strategy to strengthen our position as the identity security company. In the second quarter, we executed against this strategy exceptionally. and our results exceeded expectations with momentum continuing to build across all aspects of our business. After a strong first half of the year, and with our proposed acquisition of Venify in the second half on track, we are well positioned to extend our leadership across all identity use cases with our industry-leading platform and solutions. More on Venify later, but first, a few highlights from our strong second quarter. Net new subscription ARR was 56 million. That's a record outside of our seasonally strong fourth quarter. Subscription ARR of 677 million grew 50% year-over-year. Total ARR of 868 million grew 33% year-over-year. And our Q2 results significantly exceeded guidance across revenue, operating income, and EPS. We delivered record total revenue of $224.7 million, growing 28% year over year. Non-GAAP operating income came in at $23.7 million, highlighting the operating leverage in our business model. Non-GAAP earnings per share was $0.54 And we are pleased to report $41.7 million in free cash flow, or a 19% free cash flow margin for the quarter, another proof point of the subscription flywheel effect and the power of our business model. We are incredibly proud to be among an elite class of software companies that delivered faster than 30% ARR growth, increased net new ARR year over year, and drove meaningful upside in profitability and free cash flow. That's a testament to our relentless focus on driving profitable growth, our expanded position as the leader in identity security, and the unique value proposition of our unified identity security platform solving clear and present needs for the CISOs around the world. The strength of our results and business momentum gives us the confidence to raise our guidance for the full year 2024 on all metrics, which Josh will discuss later. Today, CISOs recognize that traditional methods of securing identity no longer work. Three forces, new identities, new environments, and new attack methods are fundamentally redefining the market. The modern enterprise has to secure four different types of identities or personas, with each one having unique challenges and levels of complexity. The four groups are workforce, IT, developers, and machines. These identity groups are increasingly accessing heterogeneous targets located on-prem and in hybrid and multi-cloud environments, meaning security has moved from perimeter-based to identity-centric. Given this complexity, it's no surprise that in today's threat landscape, all roads lead back to identity. Last year, 93% of organizations were victims of an identity-related cyber attack, and nearly all of them more than once. As I talk with customers and experts around the world, it's evident that a new paradigm for securing identity is required. This new paradigm centers around our fundamental vision that every identity, human and machine, needs to be secured with the right level of privileged controls. CyberArk's unified end-to-end platform is the only one to deliver on this vision. Increasingly, this is resonating with customers, and it's driving tremendous business momentum and fueling our growth. In Q2, the strength of our platform and land and expand execution resulted in strong close rates and robust pipeline build. Customers are allocating significant portions of their budget to identity security, consolidating spend, and most importantly, consolidating trust with CyberArk. As an example of all these factors coming together, we can look at a strategic customer pro-deft. Less than a year ago, the International Government Agency landed as a new logo with a seven-figure deal that secured IT users with PAM, workforce identities with identity and EPM, and machines with sequence management. Since then, they have grown with CyberArk, and this quarter, they further expanded their workforce protection with another seven-figure ACV deal. The deep relationship we have formed with ProDesk and the speed of expansion after initial land shows the power of our identity security platform and how it is well aligned with what great organizations like ProDesk need to do to be secure. As the scope of PAM programs continues to expand to include shadow IT, database and cloud administrators, as well as high-risk workforce users, we are continuing to help our customers modernize their identity security programs with broader, more agile privilege controls across these personas. In a rip and replace new logo win, a leading biotechnology company signed a six-figure deal to replace a competing PAM vendor. CyberArk's comprehensive identity security platform was a key differentiating factor as the customer wanted to modernize not just the protection of the IT user with Privileged Cloud, but also enhance security for their workforce with Workforce Password Manager and protect machine identities with Secrets Management. Every organization today has a substantial and rapidly growing developer population. In the pursuit of speed and efficiency, developers are often afforded always-on privileges with only light, if any, security in place. Here, too, we have to shift the paradigm to one of security first, without interfering with the developer's pace of innovation. At the foundation of our developer solution is our secure cloud access, or SCA, functionality. SEA applies the principle of least privilege access to developers, data scientists, and cloud engineers, while allowing them to work natively and efficiently without having to change their preferred workflow. In the second quarter, we continue to see strong traction with this offering. In a deal that included SEA and Privileged Cloud, leading enterprise software company SAP saw standing access just-in-time access and zero standing privilege from a unified solution as the key differentiator for choosing CyberArm. With SEA, they can now seamlessly enable a zero standing privilege approach while fully securing their modern cloud environments. On the spectrum of identities, the need to do things differently is especially top of mind for securing workforce users. Each workforce identity is more powerful today than ever before and can become privileged throughout the workday. Traditional SSO and MFA functionality on their own don't provide the security needed, as evidenced in many high-profile breaches. In the second quarter, our workforce solution was once again one of the strongest performers because we are solving this critical customer problem. We reimagined workforce identity by wrapping MFA and SSO with more controls that secure web sessions, the browser, and manage passwords. In addition, workforce protection extends to the endpoint with Endpoint Privilege Manager. The following two deals showcase the power of bringing privilege controls to the workforce. A U.S. financial services company who's a longtime CyberArk PAM customer had a need to keep its workforce more secure by managing passwords. With WPM, they can now do exactly that. The ability to add secure browser and secure web sessions on top of their existing vendors, SSO and MFA, means they can also benefit from the additional security layer of CyberArk's broader access suite that's integrated within our platform. In a different example of the importance of least privilege at the endpoint when securing the workforce, a major aviation company chose to protect their workforce workstations by implementing our EPM solution. Choosing to deploy EPM with our FedRAMP High certification, they landed with a high six-figure deal that closed through the AWS marketplace. In machine identity, we had an outstanding quarter, and our momentum continues to build. Underpinning our current machine identity solution are Conjure Cloud and Secrets Hub, which, when combined, empower the developer with agility and security within their native workflow. In one outstanding deal from the quarter, a major airline, who is a longstanding CyberArk customer, recognized the need to move its secrets management strategy within the security team's remit. We quickly demonstrated the value of CyberArk Secrets Hub, resulting in a mid-six-figure ACV deal. We believe that the market for protecting machine identities is inflecting, and we have increasingly heard from customers that there's an urgent need to protect all machine identities. Machine identities themselves are growing exponentially due to the increase in cloud computing and the rise of AI. The machine identity landscape is also becoming more complex with increasing regulatory scrutiny and emerging standards like Google's guidance to rotate certificates every 90 days. All of this is happening as machine identities are increasingly targeted by adversaries as a weak point in organizational security controls. We are very excited to be building out and expanding our leadership position in machine identities with the pending acquisition of Entify. which is undergoing regulatory review. All machine identities need to be discovered, secured, managed, and automated to keep their connections and communication safe. Venify's machine identity management solutions are complementary to CyberArk with no technology overlap. We believe that by combining our secrets management with Venify's modern machine identity management, certificate lifecycle management, and SSH key management, we will set a new standard for end-to-end machine identity security. As you can see from these deal examples, our platform provides the ability to land in multiple spots and with multiple products. In the second quarter, we signed 245 new logos, and approximately half of these new logos landed with two or more solutions. In other words, customers are protecting multiple types of identities with CyberArk from day one. In addition, we had a strong quarter of expansion within our base across all our solutions, but machine identities with secrets management and workforce identities with our access offerings were particularly strong. At Impact, our marquee customer event held in May, attendance was up more than 25% compared to last year. We showcased that we are the frontrunner in innovation and are expanding the capabilities of our identity security platform. all serving our fundamental vision of securing every identity, human or machine, with the right level of privilege controls. We announced exciting product innovations across the whole portfolio, but I want to highlight two of them here, Core AI and ITDR. CyberArk's Core AI provides identity security-focused artificial intelligence embedded within our identity security platform. Our unique data set on the behavior of all identities enables Cora AI to do more and ultimately effectively analyze sessions, detect threats, and recommend action. In addition, user and admin lives are made easier and adoption is faster with an addending security assistant that understands natural language. This will fundamentally transform how users interact with our platform, significantly reducing the time it takes to deliver critical information and analysis. Identity Threat Detection and Response, or ITDR, is sometimes discussed as a separate market or product. We at CyberArk believe ITDR capabilities need to be part of a broader platform. They should not just be about monitoring the vendor's infrastructure or limited to Active Directory. They need to look across all identities to detect identity risk and then be able to take automated response before damage is done. Our ITDR capabilities powered by Core AI will detect and identify risky behavior, anomalous use of secrets, and much more. The powerful combination of Core AI and ITDR enhances security, improves resiliency, drives increased productivity, and enhances engagement with our platform. In summary, I want to leave you with the following takeaways from today's. First, momentum continues to accelerate in our business. Identity security is a top priority for CISOs and customers are consolidating spend with CyberArk. Second, our solution selling is increasing our momentum in the market. Applying the right level of privilege controls to every identity is a security imperative that is recognized by boards, by the C-suite, security teams, and increasingly by operations and developers. Third, we are leading the charge when it comes to thought leadership and execution in the identity security space. Our ongoing innovation and pending acquisition of Ventify will further extend our leadership position and competitive mode. and help further solidify our position as the identity security company. And lastly, we are executing. Deals are progressing at a faster pace, and our close rates remain strong, a clear testament to the fact that customers are allocating budgets to identity security. Momentum continues to build across our entire business, and the strength of our platform is driving our outstanding results. With our 28% revenue growth and our 19% free cash flow margin, we were a solid Rule of 40 company in Q2. I'll now turn the call over to Josh, who will talk about our strong financial results and the increase in our yearly guidance.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-

Investor presentation