This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

Qualys, Inc.
2/9/2023
Good day and thank you for standing by. Welcome to the QALYS fourth quarter and full year 2022 earnings call. At this time, all participants are in a listen-only mode. After the speaker's presentation, there will be a question and answer session. To ask a question during the session, you need to press star 1-1 on your telephone. You will then hear an automated message advising your hand is raised. To withdraw your question, please press star 1-1 again. Please be advised that today's conference is being recorded. I would now like to hand the conference over to speaker today, Blair King. Please go ahead.
Good afternoon and welcome to QALYS' fourth quarter 2022 earnings call. Joining me today to discuss our results are Sumit Dhikhar, our president and CEO, and Jumi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to future events or a future financial or operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we'll present both GAAP and non-GAAP financial measures. The reconciliation of GAAP and non-GAAP measures is included in today's earnings press release. And as a reminder, the press release, prepared remarks, and investor presentation are all available on the investor relations section of our website. So with that, I'd like to turn the call over to Smith.
Thank you, Blair, and welcome everyone to our fourth quarter earnings call. We delivered another quarter of strong financial performance, reflecting a year of accelerated revenue growth and industry-leading profitability. In terms of innovation, 2022 was a strong year for Qualys as we expanded our platform and our market opportunity. We introduced ContextXDR to enable high-fidelity detection and response capabilities for our customers. We released VMDR 2.0 with TrueRisk, to enable comprehensive risk coding and ITSM integrations. We brought external attack surface management into our cybersecurity asset management application. We unified multiple context vectors around asset criticality, vulnerability, and system misconfiguration with asset telemetry in a single agent and brought a unique EDR application to market. Further flexing the power of our platform, we introduced our cloud-native Total Cloud with FlexScan, which pairs agent and agent-less zero-touch assessment options with comprehensive cloud posture management and container security. These innovations allow our customers to reduce complexity as they standardize on a trusted platform that delivers an immediate ROI and lower total cost of ownership relative to siloed and traditional detection-only technologies. With CISO increasingly focused on comprehensive risk management, we have upgraded our TrueRisk platform capability to ingest third-party scans into the Qualys cloud platform which we call Enterprise True Risk Management, and is now in preview with our customers. Regardless of which vendor scans an organization's environment, with this enhancement to our True Risk application, Qualys is now providing enterprise customers with a holistic enterprise-wide risk score based on asset criticality and our Cloud Threat Database, which is a unified threat intelligence platform of over 25 threat feeds. What makes this capability so special is our ability to then reduce an organization's enterprise risk score by leveraging Qualys' remediation application with automated workflow through a unified dashboard. Additionally, TotalCloud, which is our cloud-native risk management solution for public cloud, is now GA, and since our acquisition of BlueHexagon in October, we've already added a new cloud detection response module to our TotalCloud solution. As organizations increasingly prioritize Moving workloads to hybrid and multi-cloud environment, we view this new ML AI-based technology for zero-day threat hunting and response as another strong competitor differentiator in a rapidly evolving market. Looking forward, we will continue to seek out opportunistic acquisitions to further enhance our platform, accelerate our time to market, and further expand our market opportunity. Now turning to our sales and marketing execution in Q4, we continue to witness organizations broadly responding to evolving macro by applying additional layers of scrutiny to spend and dealing project start dates. We believe that this increased scrutiny comes increased opportunity as organizations standardize on trusted platforms to consolidate security stacks, leverage automation, and achieve expedient remediation of risk. Qualys is a unique, organically built platform to address this need. Nevertheless, to fully capitalize on this opportunity requires first to go to market execution. Over the last year, we have made some meaningful progress on several fronts in this regard, including successfully growing the sales and marketing teams and investing our sales enablement and operations functions. We still have work to do in our sales execution. This is particularly evident within the context of today's market dynamics and persistent macro headwinds, which resulted in lower than expected bookings growth in Q4. Accordingly, I'd like to share a couple of planned personnel and alignment changes within our sales and marketing organizations, which position us for forward success. Earlier today, we announced the upcoming departure of our Chief Revenue Officer, Alan Peters. We thank Alan for his contributions during his tenure at Qualys as we continue to grow and scale our sales organization. In the interim, I will be overseeing the sales team as we focus on product-led growth inherent in Qualys. We are fortunate to have a talented next-level team of regional sales leaders who are energized by our competitive position in the market, and I'm confident in our ability to effectively drive our business forward as we search for Allen's successor. Additionally, I'm pleased to announce Pinkesh Shah, who joined Qualys in November of last year, was recently promoted to serve as our new chief product officer, overseeing both product as well as marketing. Given Pinkesh's strong background in product-led growth, We believe having both product and marketing under the same leadership will help increase a return on our investments and drive operational efficiencies in our go-to-market motion. It's great to have Pankaj on the team, and we're looking forward to his leadership in helping execute our long-term growth agenda. As we diligently address the challenges brought on by today's market uncertainty, we remain confident in our long-term strategy and trajectory. I've met with over 100 CISOs over the past few months, and their message is clear. They are looking to pivot to platform-based solutions to solve their complex security problems. In face of an evolving macro escalated threat environment and cybersecurity skill gap, organizations need to reduce complexity and cost while presenting measurable risk reduction initiatives to board and C-level executives. This was underscored at our recent Qualys Security Conference in Las Vegas, which brought together over 500 Qualys customers and partners. Several customers in attendance highlighted their ability to measure their organization's security posture by leveraging the Qualys cloud platform while reducing risk and cost. One customer stated that through VMDR, with true risk, they reduced risk and eliminated 60% of critical vulnerabilities in a very short amount of time without having to buy separate threat intelligence feeds. Against this backdrop, we had several positives in Q4. We continued to see the steady adoption of VMDR, which is now deployed by 48% of our worldwide customers. A few key seven-figure VMDR wins in the quarter included two Global 500 financial institutions, which chose Qualys for its ability to replace traditional siloed security tools and enhance security posture on a unified platform, and a Global 50 insurance company that is leveraging VMDR to not only detect but also immediate vulnerabilities in both on-prem and cloud workloads. Beyond these wins, I'll take a moment now to share a couple of additional successes with customers who are consolidating their security stack to optimize, spend, and reduce risk. First, a new logo, Fortune 1000 web hosting company, selected cybersecurity asset management, VMDR, and our risk and remediation application, in a seven-figure competitive win replacing point solutions from three vendors with one platform. The ability for this customer to significantly enhance its security program with automating scripts, comprehensive internal and external risk criticality and quick remediation, CMDB sync and alerting on a natively integrated platform where all key differentiators compared to vulnerability detection-only solutions in the market. In addition, in 2022, highlighting organization's strategic focus on high-quality real-time asset inventory, we expanded our engagement with an existing financial services customer, signing an over $800,000 upsell deal for Qualys cybersecurity asset management solution. This customer is standardizing on our cybersecurity asset management solution due to the rich asset context end-of-life visibility and real-time inventory they are able to get out of the same agents and platform they have already deployed for VMDR. This enabled them to enhance their investment in Qualys platform by consolidating solutions, which is important to customer in current macro environment. As more and more customers are beginning to perceive Qualys as a leading security platform, they have As a leading security platform that they can leverage to solve their complex and difficult security problems, we are growing increasingly confident in our ability to drive growth and gain market share. This is evidenced by the continued growth in our large customer spend, with customers spending $500,000 or more with us growing to 116 Q4, up 27% from a year ago. Turning now to our growth initiatives in SME, SMB market, where we have witnessed slower growth, we have introduced new product packaging, VMDR TrueRisk, VMDR TrueRisk Fix-It with patch management, and VMDR TrueRisk Protect-It with both patch management and multi-vector EDR. These new packages offer simple, easy to deploy, all inclusive cybersecurity solutions to manage, remediate, and protect against continuously emerging cyber threats and reduce risk for the small customers. We believe that the convenient packaging and pricing of this offering will help streamline the sales process for our partners, reducing time to value, and further advance our value proposition in the SME, SMB market. In addition, we are pleased to share that in Q4, we expanded our partnership with Oracle. Oracle Cloud Infrastructure, OCI, began offering a fully managed vulnerability scanning service that enables Qualys customers to leverage their vulnerability management licenses to scan their OCI compute virtual machines. I'm also pleased to note that OCI has selected Qualys' vulnerability management solution to help scan their internal environment for vulnerability. This is a testament to the effectiveness of Qualys in securing cloud infrastructure and advancing our partner ecosystem. Finally, I'm pleased to announce that Qualys recently received FedRAMP Ready status at the high impact level on our newly introduced GovCloud platform. Currently, this is the only FedRAMP high-ready platform offering inventory vulnerability management and patch management in a single unified workflow. With government agencies increasingly moving workloads from on-prem environments to the cloud, this marks the achievement of a key milestone and makes Qualys the only modern alternative to legacy scanners for federal, local, and state government agencies. Given this certification, our consolidated platform and our investment to establish a public sector presence. We believe we are now well positioned to address a new vertical that will help drive growth in the long term. In summary, the cybersecurity market is a mission-critical technology. We believe our natively integrated platform that is quantifying, remediating, and reducing risk brings a highly differentiated value proposition to our customers as they get more security using less resources out of a single Qualys platform. We'll continue our disruptive innovation and further enhance and advance our go-to-market investments to crisply execute our long-term strategic vision with an already proven approach to balancing growth and profitability. With this, I'll turn the call over to Jumi to further discuss our fourth quarter results and outlook for the first quarter and full year 2023.
You're reading a preview of the QLYS Q4 2022 earnings call.
Free account.