5/7/2024

speaker
Conference Operator
Operator

Good day and thank you for standing by. Welcome to the QALYS first quarter 2024 investor call. At this time, all participants are in a listen-only mode. After the speaker's presentation, there will be a question and answer session. To ask a question during a session, you will need to press star 1-1 on your telephone. You will then hear an automated message advising your hand is raised. To withdraw your question, please press star 1-1 again. Please be advised that today's conference is being recorded. I would like to hand the conference over to your speaker today, Blair King. Please go ahead.

speaker
Blair King
Director, Investor Relations

Good afternoon and welcome to Qualys' first quarter 2024 earnings call. Joining me today to discuss our results are Sumit Thakkar, our president and CEO, and Jumi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to future events or our future financial or operating performance. Actual results may differ materially from these statements. The factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC, including our latest form 10Q and 10K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. reconciliation of gap and on-gap measures is included in today's earnings press release. And as a reminder, the press release prepared remarks and investor presentation are all available on the investor relations section of our website. So with that, I'll turn the call over to you, Sumit.

speaker
Sumit Thakkar
President and CEO

Thank you, Blair, and welcome to our first quarter earnings call. Call has delivered another quarter of healthy revenue growth, strong profitability, and cash flow generation, reflecting our ongoing commitment to rapid innovation and customer success. Given the accelerated growth in scope and complexity of cyber threats alongside an intensifying regulatory environment, boards and C-level executives are increasingly focused on the business outcome of cybersecurity. This requirement makes seamlessly integrated security solutions a necessity for customers to effectively measure, communicate, and fortify the security posture. We believe the Qualys Enterprise TrueRisk platform designed to reduce friction, risk, and cost provides organizations with a foundational risk management platform for the future, and serves as a structural competitive advantage for both our customers and for Qualys. As a result, our VMDR solution with TrueRisk is not only fueling new logo lines, but also increases platform adoption, especially in the areas of cybersecurity asset management with external attack surface management, patch management, and cloud security. In Q1, healthcare, technology, retail, and financial services verticals all demonstrated strong VMDR demand with large deal sizes. Further underscoring the power of our platform, I will take a moment to share a couple of examples of how our customers and partners continue to expand their use of Qualysys capabilities to consolidate their security stacks. On the customer front, a marquee high six-figure bookings enterprise customer win in Q1 was with a leading business services company in the Forbes 1000. The customer expanded its VMDR with Truisk and batch management deployments while adopting cybersecurity asset management with EASM as part of an initiative to detect end-of-life and end-of-service software, monitor subdomains of its infrastructure, and transform its IT security architecture while replacing point solutions from pre-vendors to the single platform. The ability for this customer to significantly enhance its security program with comprehensive internal and external asset criticality, holistic risk scoring, ticketing, and automated patching across its on-prem cloud and container environments through a natively integrated platform and unified dashboard were all key differentiators compared to alternative next-gen and legacy technologies. The next event demonstrates how Qualys helps helped an existing Forbes 100 manufacturing company standardize on Qualys Enterprise Tourist Platform and consolidate risk factors from different Qualys modules into a single risk score with business context. This existing VMDR and token cloud customer was struggling with connecting disparate asset management tools and business processes across several subsidiaries and environments and needed to gain better visibility into its attack surface to uniformly contextualize, communicate, and manage risk. Recognizing the increased value they would gain by further consolidating on Qualys, this customer replaced its existing asset management tool and adopted our cybersecurity asset management with EASM solution in a six-figure bookings upsell. This customer is now leveraging multiple aspects of Qualys Enterprise Tourist Platform, spanning on-prem cloud and multi-cloud assets to quantify and prioritize risk reduction initiatives, increase organizational resilience, and give its CISO peace of mind. Investing in our partner program continues to be a key pillar of our go-to-market agenda as it bolsters our capacity, harnesses transformative solution sales, and brings new business to QALYS. Through these investments, we continue to advance our evolving partner ecosystem with two leading managed service providers in America. One recently expanded is offering Beyond VMDR to include our patch management capability. and the other standardized on Qualys as its preferred partner for VMDR cybersecurity asset management with EASM and patch management spanning both its federal and commercial verticals. The latter of these two wins is a testament to the investment we are making to expand our federal business and we're looking forward to hosting our first public sector cyber risk conference later this month. And with nearly 50 partners already on our recently announced new MSSP partner portal, to simplify their operations, launch and manage quality capability and significantly reduce remediation times for their customers. We are increasingly well positioned to expand our reach to customers of all sizes. Additionally, we strengthen our alliance with a leading system integrator, which is now actively bringing our total cloud CNAP solution to its customers. We believe the broad expansion of our partner program over the past several quarters continues to reflect our strengthening brand awareness strategic position and value position in the market. With tightly integrated solutions delivered through a natively integrated platform to solve modern security challenges, more and more quality customers are beginning to understand how cybersecurity transformation drives better security outcomes, saves times and costs less. As a result, customer spending $500,000 or more with us in Q1 grew 19% from a year ago to 192. Since our inception, driving innovation is at the core of Qualys' mission. We are excited with our upcoming Enterprise True Risk Management application, which marks the next stage of expansion of our platform, building on top of the success we have seen with VMDR with True Risk. The ETM capability will enable VMDR customers to upgrade to a more holistic cyber risk management platform that goes beyond vulnerability management. The Enterprise True Risk management solution holistically aggregates and normalizes trillions of first and third party data signals, correlates risk factors with assets, threats, and business context, detects, visualizes, quantifies, and prioritizes risk, and makes remediation frictionless and immediate with simple click of a button. With these newest capabilities, all natively integrated on a single unified dashboard, Qualys is once again well-armed with powerful new platform capabilities that broadly measure, communicate, and remediate risk across the entire attack surface, including IT, OT, applications, cloud, and multi-cloud assets. Moreover, our comprehensive AI-powered insights are now converting detected risk into optimized remediation actions across our platform solutions with our out-of-the-box, instant, and actionable insights mapped to an organization's own data to preemptively reduce risk in their environment. The feedback from many of the CISOs I met at our recent QSC MEI event in London has been very positive with respect to the deployment agenda's excitement about the rapid pace of new capabilities that we are delivering and their ability to monitor and measure risk reduction ROI for the cybersecurity spend. Further advancing our true risk capabilities, I'm pleased to announce we recently brought MITRE ATT&CK matrix prioritization into the Qualys Enterprise True Risk platform. By combining over 25 sources of threat intelligence with the MITRE ATT&CK framework, we are now further enabling organizations with a holistic attacker-centric view to predict and identify critical risks to their business based on the ATT&CK tactics and techniques. With this advancement, we believe Qualys stands out as the only enterprise-scale solution to combine contextualized risk quantification and the MITRE ATT&CK framework to help organizations proactively prioritize, manage, and reduce cyber risk with enhanced detection, integrated risk quantification, and automated response for a threat-informed defense in a single platform. Continuing the pace of disruptive innovation, we are now organically unifying cloud Entitled Management, CIEM, into our total cloud CNAP solution. With this new capability, customers can manage cloud entities entitlements and enforce the principle of least privilege access to cloud infrastructure and resources. Combined with additionally newly introduced capabilities such as container runtime security and Kubernetes posture management, we have created what we believe is one of the most comprehensive cloud native security solutions in the market with a unified actionable dashboard for immediate threat prioritization and remediation for build through runtime with built-in trip detection capabilities. Finally, as we continue to extend our technology leadership across the entire platform, I'm pleased to announce our cybersecurity risk management 3.0 solution with highly differentiated new capabilities in external attack surface management and third-party integration for comprehensive asset inventory. With these innovations, security teams can now leverage our patent funding technology to reduce accuracy and detection gaps with immediate lightweight vulnerability scanning, seamlessly attribute previously unmanaged external assets to the organization with confidence, and evaluate asset-based business risk per subsidiary or acquired entity. Combining this unique approach to EASM with integrated tourist scoring capabilities and actionable dashboards to proactively manage tech debt further strengthens our position in the market while enabling customers to de-risk the entire attack surface. In summary, a company's uniformly recognized security transformation is fundamental in combating today's heightened threat and regulatory environment. As a result, customers are increasingly looking to reduce the risk exposure through the adoption of natively integrated risk management platform instead of deploying a collection of disparate point solutions stitched together through the invoice. We believe that with our organically integrated cloud-native platform built to holistically measure, communicate, and ultimately eliminate cyber risk, Wallace is laying a foundation for future growth and is well-positioned to drive long-term shareholder value with a balanced approach to growth and profitability. With that, I will turn the call over to Jumi to further discuss our first quarter results and outlook for the second quarter and full year 2024.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-

Investor presentation