This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

CyberArk Software Ltd.
5/13/2025
will be a question and answer session. If you would like to ask a question during this time, simply press star followed with the number one on your telephone keypad. If you would like to withdraw your question, press star one again. Thank you. I would like to turn the call over to Srinivas, VP of Investor Relations. Please go ahead.
Thank you, operator. Good morning. Thank you for joining us today to review CyberArk's strong first quarter 2025 financial results. With me on the call today are Matt Cohen, our chief executive officer, and Erica Smith, our chief financial officer. After prepared remarks, we will open up the call to a question and answer session. Before we begin, let me remind you that certain statements made on the call today may be considered forward-looking statements, which reflect management's best judgment based on currently available information. I refer specifically to the discussion of our expectations and beliefs regarding our projected results of operations for the second quarter, full year 2025 and beyond. I also refer to our expectations and beliefs regarding the integration of NFI and Zillow security into our operations. Our actual results might differ materially from those projected in these forward-looking statements. I direct your attention to the risk factors contained in the company's annual report on Form 20-F filed with the U.S. Securities and Exchange Commission and those referenced in today's press release that are posted to CYBROC's website. CYBROC expressly disclaims any application or undertaking to release publicly any updates or revisions to any forward-looking statements made herein. Additionally, non-GAAP financial measures will be discussed on this conference call. Reconciliations to the most directly comparable GAAP financial measures are also available in today's press release, as well as in an updated investor presentation that outlines the financial discussion in today's call. A webcast of today's call is also available on our website in the IR section. With that, I would like to turn the call over to our CEO, Matt Cohen.
Thanks, Sri, and thanks, everyone, for joining the call today. We're excited to kick off 2025 with a strong first quarter that exceeded all of our guided metrics. This performance highlights not only the critical role identity security plays in the broader cybersecurity landscape, but also our team's unwavering focus on excellence in execution. In Q1, we achieved total ARR of 1.215 billion, revenue of 318 million, an 18% operating margin, and generated 96 million in free cash flow, a great quarter all around. Our results continue to demonstrate that identity is the new perimeter and that demand remains robust. With more than 90% of organizations experiencing identity-related breaches, security leaders recognize that identity security is a mission-critical imperative. CyberArk is at the forefront of this imperative, offering the most comprehensive and most effective platform for securing every identity, human, machine, and now AI. Before I dive into the quarter, let's touch on the broader macro environment. As you can see from our results, demand for our solutions is increasing, and we continue to deliver strong growth. Despite ongoing macro uncertainty, we have not seen any impact on our business. Given the elevated threat landscape, cybersecurity remains a top priority for organizations. And within that, identity security is a non-discretionary investment. It is a foundational to business continuity, customer trust, and regulatory compliance. Of course, we are carefully monitoring the economic situation and its potential impact. And as we have always done, if we see any negative trends, we will be disciplined in our execution and make the necessary strategic adjustments. We have successfully navigated similar conditions before by staying close to our customers and infusing even more rigor into our go-to-market execution. Importantly, we believe times like these push customers towards our platform and consolidation, and specifically, consolidation of trust. Our confidence in the underlying demand trends was further reinforced recently with thousands of customers in attendance at the recent Impact and RSA conferences. At these conferences, I had the opportunity to engage directly with hundreds of customers and partners in one-on-one meetings. The feedback was clear and consistent. Identity security continues to be a top spending priority. Organizations are actively seeking to consolidate fragmented security tools, modernize legacy systems, address the growing challenges of machine identities, and get advice on how to integrate security from day one into their agentic AI initiatives. The level of strategic discussions we are having with the C-suite at our customers and prospects has never been more constructive and underscores the growing demand for our unified identity security solutions. I come away from these events more confident than ever in our vision and ability to win and drive long-term, durable growth. I want to center our discussion today around three key pillars that anchor so many of these one-on-one conversations I have been having. First, the identity security imperative, Second, our unified platform for every identity. And third, our relentless innovation. Starting with the identity security imperative. As I mentioned at our impact conference last month, we are living and operating in an exponential era, an age where the speed of change, the scale of threats, and the complexity of digital ecosystems are compounding at a pace we've never seen before. The threat landscape continues to intensify with state-sponsored actors, cyber criminals, and emerging threats like AI-driven exploits increasing in both frequency and sophistication. Identity is the connective tissue of every digital interaction across every user, system, cloud, and application, making it foundational to any modern cybersecurity strategy. With identity at the center of virtually every breach It's crystal clear that if you don't have a strong identity security, you simply don't have security at all. We are seeing the identity security imperative proliferate across the three different identity groups that our platform is purpose-built to protect, human, machine, and AI. For humans, privileges have proliferated across the entire spectrum of identities, including IT admins, cloud ops, developers, and SaaS admins. In today's dynamic work environments, every employee interacts with sensitive data or critical systems. Identity security requires us to reimagine privilege as a dynamic, contextual, and tightly controlled concept delivered across the workforce without friction. We're bringing layered, in-depth defense to every human identity without compromising user experience. Applying privilege controls against all identities is among the most complex, cybersecurity challenge, and our deep expertise and leadership position sets us apart from the competition, which you see in our results. When it comes to machine identities, a year ago you heard us talk about a 45 to 1 ratio of machine to human identities. Today it's over 80, and that number is still rising rapidly. These machine identities are granted access to critical infrastructure and sensitive information, yet they often operate without oversight. Without an identity-first approach to securing machines, organizations leave a massive blind spot in their defenses. Identity security is the only way to bring visibility, control, and governance to this rapidly growing attack surface. With the addition of Entify, our machine identity solutions are setting a new standard on how to address this challenge. And turning to AI, we are seeing AI everywhere, embedded in organizational workflows and opening the door to new use cases. It's challenging how privileges are assigned, creating new identities, and becoming a force multiplier for both defenders and attackers. The need to secure AI agents, both autonomous and human-directed, is becoming increasingly top of mind. And as we dive deeper into the depths of agentic approaches, it's increasingly understood that securing AI agents is an identity security problem, not a data problem. The identity security imperative is clear. to meet the exponentially increasing threat landscape by securing every identity with the right level of privilege controls. Which takes us to our second pillar, our unified identity security platform. Our platform starts with the idea that discovery in context is critical. Understanding what identities exist across human, machine, and AI, their associated access rights, risk profiles, and appropriate privilege controls is foundational to any effective identity security strategy. Once discovered and onboarded, applying industry-leading privilege controls is the most essential step and cornerstone of our differentiation. Privilege controls that cover credential management, authentication management, session management, and entitlements management are the secret sauce of our platform and create a deep, competitive moat against all competitors. Next comes policy automation, which is also crucial. Given the scale and scope of modern identity security, it's no longer enough to merely impose policies. They must be automated. We offer automated enforcement of contextual security policies to eliminate manual overhead, reduce time to value, and support rapid scalability across complex environments. Along with policy automation, you need to automate life cycles, which is the ability to onboard and offboard dynamically provisioned entitlements and provide just-in-time access. with the goal of streamlining security to reduce risk and ensure continuous compliance. And lastly, governance and compliance are essential for meeting the growing oversight both within organizations and increasing regulatory standards being imposed by government organizations. As we'll talk about later, with Zillow's modern IGA, we are setting out to free organizations from the longstanding challenges of legacy IGA. These components are the building blocks and the unique differentiators of our platform. They are the blueprint for how we talk with our customers and partners. More importantly, they enable us to deliver measurable customer outcomes, reducing cyber risk, strengthening business resilience, satisfying audit and compliance, all while increasing efficiency and automation. This is why, while customers may come to us hoping to solve one use case, instead, They often expand to secure additional identities across our solutions and consolidate on our platform over time. Moving on to our third pillar, which is innovation, at Impact we introduce new solutions and capabilities across human, machine, and AI identities. And I want to highlight a few of them one more time today. For securing human identities, we announced the availability of Zillow provision and comply modules. Since we closed the acquisition, customer feedback has been overwhelmingly positive, especially around how CyberArk and Zillow can simplify access reviews and automate provisioning across modern environments. Both customers and partners recognize the powerful combination of having modern IGA on our platform and the synergies we are confident we can realize. On the machine identity side, we announced our secure workload access solution, which combines modern workload identity management with CyberArk's secrets management capabilities for the industry's first and most comprehensive protection for all non-human identities that matter, giving security teams visibility and control throughout the machine identity lifecycle. I did want to pause to quickly mention another key development in machine identity security around the lifespan of certificates. The certificate The Certification Authority Browser Forum, which sets guidelines for certificate life cycles, recently voted to significantly reduce certificate lifespans from 398 days to just 47 days. Major industry players, including Apple, Google, and Microsoft, supported this change, emphasized the growing need for automated management of short-lived certificates. In an increasingly complex security environment, this is top of mind for our customers. At the recent RSA conference, this industry change drove more traffic to our booth than any other topic. Customers are realizing that the time to get this part of the machine identity security under control is now. The final major innovation we talked about was in the field of agentic AI. Agentic AI sits at the intersection of human and machine identity security. AI agents, are machine identities that act like or on behalf of humans, proliferating at machine scale, gaining access to and granting privileges over critical infrastructure. As a result, they will require the same security principles as human identities, and soon, billions of AI agents will require robust access controls, governance, and privilege management frameworks. To address the security challenges of AI agents, we introduced our secure AI agent solution. which integrates our platform capabilities with AI-specific discovery and context, privileged controls, policy automation, lifecycle management, and governance. We expect this solution to be widely available to customers later this year. Additionally, we announced a strategic partnership with Accenture, integrating our identity security platform with Accenture's AI refinery. Together, we'll offer customers out-of-the-box security for AI-driven agents, ensuring secure adoption, of emerging AI technologies at an exponential scale. Beyond these highlighted announcements, we also launched major innovations across workforce, IT, developer, and machine solutions that deliver incremental value and real-world security controls to meet the demands of the current and future threat landscape. The product and engineering team at CyberArk continues to amaze me in their ability to lead the market. As I said, Q1 was a great way to start the year. And I did want to quickly highlight just a few deals from the quarter to illustrate how we are delivering valuable customer outcomes across our platform, as well as an early Zillow deal. In a deal that showcases the power of our full platform, a leading U.S. enterprise software company replaced a competing PAM vendor, prioritizing CyberWorks' ability to deliver a complete identity security platform. They are boldly focused on just-in-time access and zero spending privilege to secure IT and developers. and a complete solution for the machine identities in a multi-figure, six-figure ACV deal. In another full platform deal focused solely on modern use cases, a leading U.S. healthcare company wanted to secure modern cloud workloads for developers, protect their entire workforce, both the user and at the endpoint, and secure machine identities with Secrets Hub in another multi-six-figure ACV add-on deal. We continue to see great momentum with Venify and this quarter, a Fortune 100 financial services company, who is a long time side of our customer on the human identity side, is now deploying all of our certificate lifecycle management and PKI offerings in a competitive multi six figure ACV deal. And in a great Venify deal that demonstrates our cross-sell motion, PDS Health, a leading integrated healthcare support organization, who has been a CyberArk customer since 2019, built on that longstanding relationship, expanding further on the machine identity side with our certificate manager and zero-touch PKI in a six-figure Q1 ACV deal. The excitement around Vanify deals continues to build across our go-to-market teams, and stories like this are becoming commonplace as the business begins to scale. Finally, in a Q1 Zilla deal, We saw early success after the acquisition closed with a financial services company who landed as a new logo with a six figure ACV deal, replacing a competing legacy IGA vendor. The customer highlighted that the acquisition by CyberArk gave them strong confidence in closing out this deal and starting their modern IGA journey. In summary, I want to leave you with the following takeaways today. First, The identity security imperative is real and accelerating. As the digital ecosystem grows more interconnected and decentralized, the threat landscape is not just expanding, it's evolving at an unprecedented pace. Organizations must respond. Second, CyberArk is uniquely positioned with the only unified platform for securing every identity and addresses a critical pain point for overburdened CISOs by simplifying identity security. Third, our relentless innovation is strengthening our competitive mode as we solve our customers' problems of today and the future. Fourth, cybersecurity spend and certainly identity is defensible in all macro environments as organizations realize the importance of protecting their most critical assets, particularly in this escalating threat environment. And finally, we are executing with discipline and confidence Our go-to-market teams are an exceptional differentiator for us. Our continued execution and strong demand environment positions us to deliver strong growth and profitability. Now I'll turn it over to Erica to walk through our strong financials and updated guidance.
You're reading a preview of the CYBR Q1 2025 earnings call.
Free account.