This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

KnowBe4, Inc.
5/10/2022
Ladies and gentlemen, thank you for standing by and welcome to the Know Before First Quarter 2022 Results Conference Call. Please be advised that today's conference call is being recorded. All lines have been placed on mute to prevent any background noise. After the speaker's remarks, there will be a question and answer session. If you would like to ask a question during this time, simply press star, then the number one on your telephone keypad. To withdraw your question, please press star one again. Now it's my pleasure to turn the call over to Ken Tolanian, known before as Senior Vice President of FP&A and Investor Relations. Please go ahead.
As a reminder, our commentary today will include non-GAAP financial measures, information regarding our non-GAAP financial results, their limitations, and reconciliations of our GAAP and non-GAAP results can be found in our earnings release, which was furnished with our form 8K today with the SEC, and may also be found in the supplementary financial information available on our investor relations website at investors.knowbefore.com. In addition, some of our comments today, including those related to our guidance, may contain forward-looking statements that are subject to risks, uncertainties, and assumptions. Should any of these materialize or should our assumptions prove to be incorrect, actual company results could differ materially from those projected or implied during this call. These risks are described in our form 10-Q that will be filed in accordance with the filing deadlines established by the SEC. These documents can be found on the SEC's website, sec.gov, and on our investor relations website. During today's call, you will hear prepared remarks from our founder, CEO, and president, Stu Schauerman, and CFO, Bob Rich. Lars Lettenhoff, our chief revenue officer and co-president, will join our question and answer session. And with that, I will turn the call over to Stu.
Thank you, Ken, and thank you all for joining us today. We're excited to share our results with you this morning. We started another year of strong execution with first quarter results exceeding our guidance. We had a record quarter with about 38% year-over-year annual recurring revenue growth and a seasonally strong 31% free cash flow margin. As many of you know, I started KnowBe4 to help organizations manage the ongoing problem of social engineering. We're the only public company dedicated to securing the human layer. We continue to innovate in this layer and our announcement of a brand new category called HDR, Human Detection and Response, is a prime example of this. I'll come back to that later in my remarks. The emphasis in cybersecurity has traditionally been on legacy controls. However, the exponential growth in cyber attacks and their relative success proves that organizations cannot solely rely on security software infrastructure. Recent examples of this are the cyber attacks seen during the tragic ongoing conflict between Russia and Ukraine. For example, near the end of March, the Ukrainian government reported severe cyber attacks that crippled UKR Telecom, one of their largest communications providers, collapsing the nation's network connectivity to 13% of pre-war levels. Another more recent example came about a month ago. In mid-April, the Department of Energy, CISA, the NSA, and the FBI all released a joint advisory report about a new malware tool set called Pipe Dream. This highly sophisticated malware toolkit was designed specifically to target the kinds of industrial controls that are used in power grids, factories, water utilities, and oil refineries. For context on the potential devastation that an attack like this could achieve, we only have to look back less than a year ago to the incident with the Colonial Pipeline. It's now being reported that the bad actors were able to gain access due to a single compromised password that was later found in a batch of breached credentials on the dark web. Poor password hygiene, which originates from human error, crippled oil production across the eastern seaboard. Now, we saw the headlines at the time, but what many don't realize is how close the situation came to shutting down entire subsets of the economy. A later declassified assessment by the Department of Energy reported that the country could only afford another three to five days of disruption before mass transit, chemical factories, and other refineries would have had to shut down from a lack of diesel fuel crippling distribution. Unfortunately, attacks like these are only part of an ongoing trend that started years ago and continues to accelerate. So much so that Gartner predicts 30% of critical infrastructure organizations will experience a security breach by 2025 that will result in the halting of an operations or mission critical cyber physical system. When you combine this with Verizon's widely reported statistic that 85% of data breaches involve a human element, it becomes abundantly clear that securing the human layer is a matter of national security. This sentiment has already been echoed by the Biden administration on multiple occasions. It is clear that this problem is escalating in the private sector as well. Just last February, the Anti-Phishing Working Group reported that phishing attacks hit an all-time high in 2021, tripling that of early 2020. December of 2021 saw the highest number of attacks ever recorded. They're becoming more effective as well, with the number of organizations falling victim to ransomware in Q4 2021 hitting the highest number seen in the past two years. While alarming, I'm sure that these statistics come as no surprise to anyone. The unfortunate reality is that in a lot of these cases, bad actors are manipulating the human element in organizations without any regard to their size or industry. Untrained or poorly trained employees are walking liabilities that could bring potentially devastating consequences to the operations of any organization. With that being said, employees who are properly trained using an effective platform and are frequently sent realistic phishing simulations have the potential to become one of the most powerful security assets of those same organizations. That is why we are dedicated to helping our customers transform their employees into a successful last line of defense against cyber attacks. And our efforts have not gone unnoticed. I am proud to say that we were once again recognized as a Forrester Wave leader in their security awareness training category, ranking the highest across all of their scoring criteria. In their own words, KnowBe4 brings size, an established product, and a strong vision. As one of the largest and most established vendors in this space, KnowBe4 has an enviable growth trajectory. We believe that this is the kind of recognition that confirms the great work that we're doing. I will now walk you through our key results which highlight our execution during Q1 2022. First quarter results exceeded our expectations across the board with continued balanced growth in both top line and profitability, as well as seasonally strong free cash flow generation. The productivity of our direct sales and channel teams continues to deliver wins for both our SMB and enterprise customers across all industry verticals. This resulted in nearly $306 million in ARR, which is up about 38% year over year. We believe this performance demonstrates our market-leading position in the human-centric cybersecurity space, and we continue to remain focused on innovation in order to meet the needs of our customers. Our vision for the security awareness market defines KnowBe4's product roadmap. This includes both exciting new features and new products. A great example of this is Security Coach, the product that we're planning to release in the second half of this year, following the integration of our Security Advisor acquisition. With Security Coach, we believe we are creating a new category in cybersecurity called Human Detection and Response, or HDR. How this works, is we connect through their cloud interface to existing layers in our customer's security software stack and pull in security alerts so we can analyze them and take real-time action. As discussed previously, we believe this new SKU will add an estimated $5 billion TAM as well. I'm pleased to announce that the integration is still on track for a full release in the second half of this year. Our R&D team is laser focused on making sure this new SKU, which is highly technical in nature, will be an easy upsell, cross-sell into our existing customer base in the simplest way possible. This is the kind of automation that supports our high-velocity sales motion as well as reinforces our proven go-to-market engine. For an update on the timeline, in early Q3, will begin a closed beta of Security Coach. An open beta will follow later in Q3 with the product poised for general release in Q4. Looking at new features for the KMSAT platform, there is one we are particularly excited about. We have expanded the AI capabilities even further with Ada-recommended optional learning. ADA stands for Artificial Intelligence Driven Agent, and it's been a core feature of our platform for years. One of its functions is to look at failed phishing security tests, the attack vectors of those failures, the training results, and how often that user reports suspicious emails. We then apply ML to recommend and deliver an informed personalized phishing campaign. This latest feature now adds on to this by recommending additional content for an end user based on their specific interests. With these new features, we continue our path towards individual risk reduction at scale, which in turn reduces risk across the organization. New products and features are a key driving factor in the strong momentum of our new business wins. As a reminder, this is one of the few areas in cybersecurity, if not the only one, that isn't a purely replacement market. We believe we're still operating within a space that is overwhelmingly greenfield with a global penetration that we believe to be in the low single digits. While most of our new business wins are greenfield, we also continue to see a number of competitive displacements. The Greenfield wins continue to show that the value of security awareness is resonating with customers, and we believe that our competitive wins are further proof that our platform and customer support rank well above our competition. Here are a few examples of our global wins that we've had this last quarter. We had a 130,000-seat deal with one of the largest technology companies in the world. This opportunity was a perfect example of a competitive displacement. The customer cited frustrations with their current product that our platform capabilities could immediately account for. Some of the reasons that our platform was chosen were our smart groups functionality, our robust Active Directory synchronization capabilities, and the customer's ability to run global phishing campaigns with an arsenal of multi-language truly localized templates. We displaced a competitor in a 45,000 seat deal with one of the largest clinical labs in the world. They cited stale content as the primary reason for the switch. Finally, we've won a 40,000 seat deal with one of the largest school districts in the nation. This opportunity went through an RFP process where we were chosen due to our wide array of training content and automation capabilities. The strong momentum we've been seeing in the international markets has continued as well. In Japan, we closed a 50,000-seat deal with a top printing company. We also closed a 66,000-seat deal with a French multinational specializing in gas technology. In Australia, we had a 42,000-seat deal with a top university. We closed a 30,000 seat deal with a British multinational food processing company. And finally, we had a 30,000 seat deal with a German multinational, one of the largest building material companies in the world. These are just a few examples of the types of wins that have become a monthly occurrence for us. We believe that they demonstrate how our customers continue to embrace not only the considerable risk reduction our platform brings, but also the thousands of hours we save IT departments in triaging security events. Given the current shortage of skilled IT workers, our strategy of building time saving features into our platform has paid off. This also remains a critical focus for our product roadmap. With that being said, I would like to thank our employees and partners for the dedication, commitment, and customer focus that has brought KnowBe4 to its market leading position today. I am super proud of not only our financial results, but the great group of people driving this company and contributing to our communities. And this has not gone unnoticed. In Q1, we earned the number one spot for the EnerGates 2022 Top Workplaces USA Awards in the thousands to 2,500 employee category. We were also named a Top Workplace in Tampa Bay by the Tampa Bay Times for the seventh consecutive year. While we believe that our financial results speak for themselves, the unique award-winning company culture that we've developed here is one of the driving forces behind this continued execution. And with that, I'd like Bob to discuss our financial trends.
You're reading a preview of the KNBE Q1 2022 earnings call.
Free account.