This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

Qualys, Inc.
5/6/2025
Ladies and gentlemen, thank you for standing by and welcome to QALA's first quarter 2025 investors call. At this time, all participants are in the listen only mode. After the speaker's presentation, there will be a question and answer session. And to ask a question during this session, you would need to press star one one on your telephone. You will then hear an automated message advising your hand is raised. If your question has been answered, To withdraw your question, please press star 1-1 again. Please be advised that today's conference is being recorded. I would like now to turn the conference over to Blair King, Investor Relations. Please go ahead, sir.
Thank you, Michelle. Good afternoon and welcome to Qualys' first quarter 2025 earnings call. Joining me today to discuss our results are Sumit Thakkar, our President and CEO, and Jumi Kim, our CFO. Before we get started, I'd like to remind you that our remarks today will include forward-looking statements that generally relate to future events or future financial operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC. including our latest form 10Q and 10K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. The reconciliation of GAAP to non-GAAP measures included in today's earnings press release. And as a reminder, the press release prepared remarks and investor presentation are all available on the investor relations section of our website. So with that, I'll turn the call now over to Sumit.
Thanks, Blair, and welcome all to our first quarter earnings call. We are entering a new era for cybersecurity risk management powered by real-time data, automation, and AI. Against this backdrop, we executed well in this quarter, resulting in a better-than-expected revenue growth strong profitability, and solid cash flow generation. Fueled by customer insights, Qualys' mission is to bring innovative new security tech solutions to the market. With over 25 years of evolving our platform to meet the next generation of modern security challenges, we have established a strong track record of converting operational challenges into secular competitive advantages while maximizing lifetime value ensuring frictionless outcomes at scale, and driving immediate ROI on security spend. In doing so, we believe we have built a new security industry paradigm, which today leverages our powerful real-time data processing capabilities across more than 18 trillion data points on a natively integrated platform to help organizations streamline their cybersecurity risk management program with a risk operation center, ROC. While a security operation center, SOC, is used for detection of threat actors after a breach, the ROC is needed by organizations for proactive risk management to reduce the chance of breaches by deploying the cyber budgets where the highest risk of loss is. Unlike other CTEM solutions that only reveal exposures without providing effective remediation, Qualys' cloud-native enterprise risk management ETM solution is purpose-built to deliver a single comprehensive AI power orchestration layer unifying security findings from multiple Qualys and non-Qualys sources to implement an effective ROC. By unleashing the scale of the Qualys platform, we ingest data from multiple sources, including tenable CrowdStrike ways, normalized risk signals enriched with threat intelligence, analyze adversary behavior, and provide organizations with actionable enterprise-wide insights to prioritize and remediate cyber risk through a common language of business context and financial impact. This holistic approach uniquely ensures organizations not only understand their cyber risk in quantifiable terms, but can take immediate action to reduce the risk that matters the most. With prospects of POCs more than doubling from last quarter and over 25 active POCs already underway since launching of GA a short while ago, we continue to see many parallels between this new market opportunity and the early days of VMDR launch, including significant greenfield opportunity and a growing demand. Embracing this momentum in the market, we further evolved our ETM solution through an expanding ecosystem of remediation solutions. In doing so, we have advanced our true risk eliminate agenda by enabling organizations to amplify third-party remediation tools with security insights from QALYS to prioritize patching or activate other compensating controls available through the QALYS platform. With this latest innovation, organizations can soon leverage a unified Qualys workflow with end-to-end automation, CMDB, and ITSM integration to prioritize rapid remediation across all environments from their patching vendors of choice. This is a strong competitive differentiator for Qualys, further neutralizes IT and SecOps procurement friction, and significantly expands our market opportunity by going well beyond patch management. Continuing this rapid pace of innovation, We're expanding our Qualys Total AI and TrueRisk capabilities to help organization address the evolving threats associated with LLMs. With this latest release, Total AI brings full visibility across ML supply chain data applications and pipelines to detect malicious code policy violation and advance multinodal exploits hidden within images, audio, and video files. By enhancing our AI security posture, AI SPM with native internal LLM scaling expands jailbreak detection and seamless integration into MLOps pipelines. We're equipping security teams with the agility and insight needed to protect modern AI driven workloads from development all the way through runtime while building what we believe is the most advanced AI security solution available in the market. In addition, with the launch of policy audit and audit fix, we are now providing organizations of all sizes with the ability to streamline audit operations by providing audit readiness reporting and automated evidence collection across 450 plus technologies and over 1,000 out-of-the-box audit processes for frameworks like PCI-NS, DORA, HIPAA, et cetera. This solution addresses a growing area of focus and cyber spend for CISOs as they are under pressure to ensure their organizations don't fail audits while at the same time reducing their spend in audit readiness with automation. in not only detecting the gaps, but automation and also fixing them. Moving to our business update, we have hosted several risk quantification workshops attended by many of the most forward-thinking CISOs around the world in recent quarters, and the message is clear. Organizations are increasingly anchoring pre-breach cyber spend to quantifiable risk reduction in their business, which is easily articulated to boards and business partners. CISOs want a platform that speaks a unified language of risk while letting their teams choose their own tools with various components of the stack rather than trying to consolidate multiple vendors into a single platform. This requirement necessitates a centralized risk fabric that seamlessly unifies the underlying tools of choice to effectively measure, communicate, and fortify an organization's risk posture while reducing complexity, operating costs, and time to remediation. As a result, our technologies are not only fueling new logo lands, but also helping to increase product platform adoption, especially in the areas of VMDR, cybersecurity asset management, patch management, cloud security, and increasingly delivered through Qualys' ETM solution. With thousands of customers consolidating on Qualys Enterprise Tourist Platform, let me share a couple of recent wins, which illustrate why these companies are turning to Qualys to help unify their security tools. quantify and immediate cyber risk in their environments and achieve better security outcomes. First, an existing Global 100 multinational media company with a rapidly growing multi-cloud and container environment determined that managing siloed tools added complexity to their operations, lack integration and misdetection while hindering their ability to assess risk and centralized remediation. This customer chose Qualys to transform siloed risk factors spanning core repositories, endpoints, identity, cloud container, IT, IoT, and network assets into a cohesive real-time risk management solution by consolidating Qualys and non-Qualys data. This included purchasing eight Qualys modules and deploying ETM to begin operationalizing their ROC. and consolidating ingested data from WIS resulting in a seven figure annual bookings deal, including a mid six figure total cloud CNAP upsell. We are now quickly migrating numerous data sources in the Qualys platform and delivering a vendor agnostic orchestration layer with full visibility of the back surface, centralized risk assessment, quantification, prioritization, and remediation while unleashing the operational efficiencies of security stack consolidation. Looking ahead, this customer is now in the process of planning to power its rock with ETM across 30 separate entities worldwide. Further advancing our TotalCloud CNAP momentum is another marquee seven-figure annual booking swing with a global 50 financial services company. This existing customer launch initiative is trending its cloud and container security solution against advanced threats, close security gaps, and remediate risks with ITSM integration to a single dashboard. It also needed to meet increasingly stringent global regulatory requirements and extended its on-prem visibility to multi-cloud and container environments. Through its evaluation, this customer chose our TotalCloud CNAP solution and is now leveraging the Qualys Enterprise TrueRisk platform for complete visibility across its entire attack surface to quantify and prioritize risk reduction initiatives and increase operational resolution and compliance. Our growing leadership in the cloud market was further evidenced in GigaOM's a data report, ranking Qualys as a leading outperformer in cloud workload security. With customers beginning to perceive Qualys as a leading risk management platform that consolidates and orchestrates multiple security solutions and workflows, we are growing increasingly confident in our ability to drive long-term growth and gain market share. This confidence was again bolstered in Q1 with customers spending $500,000 or more with a growth 6% from a year ago to $230. Consolidating workflows isn't just happening with customers. It's also embraced and prioritized by our partners, underscored by an increasingly strong mix of new business and significant growth. As we continue to endorse a partner-first sales motion, partner-led de-registration includes again Q1. In addition, we have now certified six leading partners who are actively marketing the delivery of our fresh new managed risk operations, MROC services, and just beginning their efforts to capitalize on a centralized and automated approach to pre-breach risk management on top of ETM. Further advancing our momentum towards a global ROC ecosystem, we look forward to certifying few additional strategic partners in the months ahead who have already demonstrated a firm commitment to steering this new initiative with Qualys as their MROC partner of choice. And finally, as the federal government seeks to show efficiency and replace outdated and costly on-prem deployments from years past with modern cloud-native risk management solutions, we are especially excited to host our second annual federal conference in Washington, D.C. towards the end of this month. We have recently made good progress advancing our FedRAMP high certification status, and we continue to believe we are on track to achieve authorized milestones later this year, fueling a new leg of growth for the company. In summary, Qualys is increasingly well-armed with fresh new capabilities to further strengthen our strategic position as the partner of choice for customers ready to centralize their response to cyber risks, solve modern security challenges, and reduce costs. Looking ahead, we believe we will continue to outpace our competitors, extend our leadership in the market, and build upon an already strong foundation to drive durable long-term growth in the business. With that, I will turn the call over to Junie to further discuss our first quarter results and look for the second quarter and the year ahead.
You're reading a preview of the QLYS Q1 2025 earnings call.
Free account.