11/5/2024

speaker
Michelle
Conference Operator

Ladies and gentlemen, thank you for standing by. Welcome to Koala's third quarter 2024 investor call. At this time, all participants are in a listen-only mode. After the speaker's presentation, there will be a question and answer session. To ask a question during the session, you would need to press star 11 on your telephone. You will then hear an automated message advising your hand is raised. And to withdraw your question, please press star 11 again. Please be advised that today's conference is being recorded. I would like now to turn the conference over to Blair King, Investor Relations. Sir, please go ahead.

speaker
Blair King
Investor Relations

Thank you, Michelle. Good afternoon and welcome to Qualys' third quarter 2024 earnings call. Joining me today to discuss our results are Samantha Carr, our president and CEO, and Jumi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to future events or future financial or operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today And we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. A reconciliation of GAAP to non-GAAP measures is included in today's earnings press release. And as a reminder, the press release prepared remarks and investor presentation are all available on the investor relations section of our website. So with that, I'd like to now turn the call over to Smed.

speaker
Sumedh Thakar
President and CEO

All right. Thank you, Mr. King. And welcome to our third quarter earnings call. Q3 was another quarter of rapid innovation for Qualys, reflecting our ongoing commitment to technology leadership, cybersecurity transformation, and successful outcome for our customers. As I have focused on product management and marketing in the last few months, I have personally spoken to many seed souls who are struggling with way too many security tools from shift left to runtime, creating too many findings that are overwhelming the IT and dev teams. leading to multiple siloed top 10 dashboards and an inability to articulate the true risk to the business stakeholders. They are feeling the pressure to articulate the ROI of their security spend and rationalize the security spend in context of the risk to the organization, to their CFO, CEO, and board members. Risk can only be mitigated if it is remediated and performed in a timely manner. There is an immediate desire to stop playing the risk whack-a-mole and establish a properly operationalized risk management process by implementing a modern risk operation center. At our recent QSC event in San Diego, we ushered in the next era of cybersecurity innovation by announcing the GA of Enterprise True Risk Management Solution, which is the world's first cloud-based ROC. ETM transforms siloed data into cohesive real-time risk management solution by consolidating Qualys and non-Qualys data from several technology design partners, including with AWS, Microsoft Defender, Oracle, Okta, and Forescout. The result is a single comprehensive AI-powered platform that aggregates security findings, unifies third intelligence, and provides organizations with actionable enterprise-wide insights to prioritize and remediate cyber risk with unique business context and financial impact via cyber risk quantification. Unlike some exposure management platforms in the market that only expose the exposure based on data their sensors collect and provide no remediation capabilities, Qualys ETM comprehensively provides a single risk view that goes beyond vulnerabilities across code repositories, on-prem, cloud, container, remote endpoint, identity, OT, and IoT findings from multiple existing security tools. in the customer environment along with patching and remediation capabilities. With ETM, Qualys has set a new gold standard in the industry for proactive cybersecurity risk management. Cyber risk orchestration is coordinated, quantification is comprehensive, remediation is transformed, and the enterprise-wide ROC at scale is now a reality. We see many parallels between this new market opportunity and the early days of VMDR, including a significant greenfield opportunity and being early to market. I encourage all of you to watch the video describing our ETM Powered Rock in more detail at qualys.com. We also announced MROC, which will enable many managed service providers to deliver services on the Qualys ETM as a managed risk operation center. Lastly, we announced a cyber insurance company is going to provide Qualys ETM customers with additional discounts on their premium for lower true risk score shared directly from ETM, allowing customers to transfer the residual risk to their business. With a rock delivered by Qualys ETM, we are now empowering C-level executives and security teams with out of the box, instant and actionable insights into trending risk specific to their vertical and map to their own data to preemptively identify prevailing threats well in advance of a potential security incident. With this new app, which we call TrueLens, going GA soon, CISOs and their security teams can immediately be notified of potentially impacted IT and IoT assets within their environment. The materiality of these assets to their business, the associated impact to their overall risk score, and are equipped with the ability to make a remediation frictionless and immediate with a simple click of a button. Alongside several other existing announcements at QSC San Diego, we were pleased to commence GA of both our True Risk Eliminate and Qualys Total AI capabilities, marking another milestone in Qualys' 25-year history of cybersecurity innovation. We are pioneering these categories, and both are key differentiators on our platform. These new approaches to cybersecurity risk management, along with several others on our roadmap in the coming quarters, arm our customers with the tools necessary to navigate an increasingly complex threat environment and regulatory environment, streamline security operations, and reduce cost. Moving to our business update, with many of our customers already embracing Qualys to help re-architect and consolidate their stack, Qualys VMDR has translated into an enviable customer base, broad adoption, and notable industry recognition. As recently announced, Qualys' VMDR with TrueRisk was recognized by GigaOM as a comprehensive risk-based approach to vulnerability management and a leader in the category for the fourth consecutive year. We believe Qualys' placement as a leading vulnerability management solution further validates our investments in the platform and continues to represent the high watermark for securing customer environments today and in the future. Given Qualys' demonstrated track record for delivering greater value to customers, our VMDR solution with TrueRisk is not only fueling new logo lines, but also helping to increase platform adoption, especially in the areas of cybersecurity asset management with EASM, patch management, and cloud security. Let me share a couple of recent wins. which illustrate why companies turn to Qualys to help consolidate their security tools and fortify their security operations. In Q3, one of my favorite wins was a large federal government agency becoming a Qualys customer. This new customer was previously using multiple legacy and next-gen solutions to manage a variety of risk management use cases across their security IT and DevOps teams. In addition to the complexity of using multiple point solutions, The government agency was also frustrated with increasing costs associated with on-prem deployments, the inefficiencies of operating siloed systems, and elongated remediation efforts. Looking to migrate to a natively integrated cloud-based FedRAMP high-impact level ready solution that meets the CISA binding operational directives, we displaced five of the existing vendors in a seven-figure bookings deployment using multiple Qualys modules right out of the gate. These initial deployments included cybersecurity asset management with EASM, VMDR, and with TrueRisk, patch management, policy compliance, and EDR. Through this highly strategic and competitive win, the customer is now able to leverage unified dashboards that provide them with greater insights and automation than any of the competitive solutions that they had evaluated, while taking full advantage of a natively integrated platform. This win alongside a separate seven-figure upsell with an existing large government agency customer and a significant state win are a testament to our ongoing investments to expand our federal, state, and local government business in the United States. Continuing our global expansion, I'm pleased to announce that IRAP in Australia has recently assessed QALYS at the protected level. This achievement opens the door for Australian government agencies and commercial organizations looking to comply with the ACSC essential aid strategy as well as their PSPF requirements to meet their country's most stringent security and compliance standards. Our successful assessment follows Qualys' approval as a cybersecurity service provider to the Victorian state government for vulnerability management services. Qualys has been selected through a highly competitive and extensive vetting process and is being bundled into managed service delivered by ENY. Turning to the momentum we are seeing with our TotalCloud CNAP solution in a mid-six figure booking upsell with a financial services company in the global 200, this existing VMDR and CSAM customer selected TotalCloud to scale their container deployments to over 70,000 hosts, monitoring millions of Kubernetes container images daily. Through its evaluation of competing cloud security providers, this customer determined that alternative point solutions added complexity to their operations, lacked integration, and missed detection, which hindered their ability to assess risk and consolidate their security tools. Today, through a highly scalable natively integrated CNAP solution, this customer is leveraging the Qualys Enterprise to its platform to combine runtime insights with proactive risk management while actively detecting anomalies, preventing zero-day attacks, closing compliance gaps, and remediating risk with ITSM integration through a single dashboard from code to cluster. These capabilities provide the visibility, automation, and cloud hygiene necessary to defend against today's adversaries and represent a significant long-term growth opportunity for Qualys. Our growing partnership leadership in the Cloud Market was also recently recognized by Gartner in its July 2024 Market Guide for Cloud Native Application Protection Platforms. With seamlessly integrated solutions delivered natively on our platform to solve modern security challenges, more and more Qualys customers are beginning to understand how cybersecurity transformation drives better security outcomes, saves time, and costs less. As a result, customers spending $500,000 or more with us in Q3 grew 15% from a year ago to 200. Consolidation isn't just happening with customers, it's also embraced and prioritized by our partners where we continue to see an increase in new customer deal registration and cost sales. We believe the expansion of our partner program continues to reflect our strengthening brand awareness and strategic position in the market. We believe our natively integrated platform that comprehensively measures, communicates, and remediates cyber risk brings a highly differentiated value proposition to our customers as they get more security using fewer resources with the Qualys Enterprise Tourist Platform. With a unique opportunity in this environment to further strengthen our strategic position as the partner of choice for customers looking to re-architect and consolidate their security tools, To evolve, to solve modern security challenges, we believe we can continue to grow long-term, maintain best-in-class profitability, and invest in key initiatives aimed at further extending the gap between Qualys and the competition. With that, I will turn the call over to Jumi to further discuss our third quarter results and outlook for the fourth quarter and full year 2024.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-

Investor presentation