2/5/2026

speaker
Michelle
Conference Operator

Ladies and gentlemen, thank you for standing by. Welcome to Co-ops' fourth quarter 2025 investor call. At this time, all participants are in a listen-only mode. After the speaker's presentation, there will be a question and answer session. To ask a question during the session, you will need to press star 11 on your telephone. You will then hear an automated message advising your hand is raised. to withdraw your question, please press star 1-1 again. Please be advised that today's conference is being recorded. I would now like to turn the conference over to Blair King, Investor Relations. Please go ahead.

speaker
Blair King
Investor Relations

Thank you, Michelle, and good afternoon, and welcome to Qualys' fourth quarter 2025 earnings call. Joining me today to discuss our results are Smith Dakar, President and CEO, and Jumi Kim, our CFO. Before we get started, I'd like to remind you that our remarks today will include forward-looking statements that generally relate to our future events or future financial operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC, including our latest form 10Q and 10K. Any forward-looking statements that we make on this call are based on assumptions as of today And we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. The reconciliation of GAAP and non-GAAP measures is included in today's earnings press release. And as a reminder, the press release, prepared remarks, and investor presentation are all available on the investor relations section of our website. So with that, I'd like to now turn the call over to Smith.

speaker
Smith Dakar
President and CEO

Thank you, Blair, and welcome to our fourth quarter earnings call. As threat actors continue to compress time to exploit, we believe the next phase of pre-breach risk management will be defined by an agentic AI-driven risk fabric with out-of-the-box business quantification and automated remediation to respond to the speed of these threats. Against that backdrop, we continue to execute well in Q4, demonstrated by another quarter of strong revenue growth and profitability. In my conversations with hundreds of CIOs and CISOs, as well as security leaders from many of the world's largest and most innovative organizations, one message has remained consistently clear. Reducing cyber risk isn't about detecting more exposures. It's about operationalizing a cyber risk management program that aligns spend with risk tolerance. In doing so, CISOs are increasingly prioritizing the unification of fragmented security stack into a centralized risk fabric, one that serves as a credible alternative to single vendor platforms by bringing diverse risk vectors into a prioritized measurable view of risk that the teams can confidently communicate and remediate at machine speed. That message was further amplified at our recently concluded ROCCON conference in Mumbai with attendance of over 30% from last year's event as we again broadened the agenda to include a business track. And with the advent of AI, which is democratizing cybercrime and enabling adversaries to operate with unprecedented speed and sophistication, this need is only intensifying. As a result, we believe that the future of pre-breach risk management belongs to vendor-agnostic agentic AI-powered solutions that continuously predict, assist, confirm, quantify, prioritize, and remediate risk across on-prem and multi-cloud environments. Over the past years, we continue to execute relentlessly towards this vision. delivering meaningful platform innovation to help customers reduce risk faster, operate more efficiently, and stay ahead of an increasingly dynamic landscape. Accordingly, in 2025, we broadly expanded the QALYS ETM platform, the third-party data, and launched a powerful new orchestration layer that unifies QALYS and non-QALYS findings, applies our industry-leading correct intelligence, and delivers a business contextual quantified view of risk with built-in prioritization and automated remediation. Building on this foundation, we introduce an agentic AR risk fabric that assesses and normalizes diverse internal and external data sources, applications, and machines. We extended these capabilities with a first-of-a-kind AI risk management marketplace, enabling security and IT teams to quickly augment their existing workforce with highly specialized autonomous experts that significantly reduce time to remediation, increase accuracy, and reduce costs. To further close security gaps, we again organically enhanced ETM with a natively integrated identity security posture management solution at a time when identities have become part of the new AI perimeter. And further flexing the power of our platform, we are now confirming exploits before customers are compromised. While traditional continuous threat exposure management solutions rely on a theoretical risk score and ignore mitigating security controls, ETM takes a fundamentally different approach. On a single platform, it uniquely detects vulnerabilities, validates exploitability, applies remediation, and revalidates exploit using agent AI workflow. The net result is that Qualys is redefining how organizations manage pre-risk risk management. While competitors continue to focus on detecting vulnerabilities or mapping theoretical exposures, Qualys has moved decisively beyond that model. We are pioneering the first authentic AI native risk operation center, ROC, a new category in cybersecurity designed to centralize an organization's response to threats, spanning expert confirmation to autonomous remediation. Powered by our ETM solution, the ROC, that present a fundamental divergence from traditional CTEM tools. Competitors can point to exposures. They can't quantify cyber risk in dollar terms that matters most to the business, and they cannot adequately fix that. ETM fills that gap. This is what sets Qualys apart. We don't stop at detection and non-quantifiable prioritization. We natively integrate CTEM, explore confirmation, risk quantification, and remediation operations into a single AI-powered workflow, leveraging both quality and non-quality data sources. In doing so, our architecture orchestrates and implements a perception reasoning action loop, enabling autonomous agents to collect real-time telemetry, reason through risk signals, plan response workflows, and execute actions. This enables organizations to holistically predict emerging risk across infrastructure, cloud, application security, IoT, and identity, safely confirm probable exploits, prioritize threats based on business impact, remediate through patching or other compensating controls, and verify the effectiveness of the remediated tactic. This end-to-end vendor neutral approach is catalyzing a paradigm shift in pre-breach cyber risk management where customers aren't just seeing their risk holistically across the risk stack. They are validating it, quantifying it, and reducing it continuously and autonomously at scale. By aligning security and IT decisions directly with business priorities, We are providing organizations with measurable proactive risk collection that brings customer value. Armed with this fresh new set of capabilities and early momentum already validating this model, we are now laser focused on accelerating ETM adoption through our VMDR customer base and positioning Qualys for larger upsell opportunities over time. Moving to our business update, with customers spending $500,000 or more with those growing 4% from a year ago to 215, let me now share a couple of recent wins, which illustrate why organizations ready to centralize the response to cyber risk are turning to Qualys to help unify their cybersecurity stack, quantifying the immediate risk in their environment, and fortify their security operations. First, an existing Global 50 customer was struggling under the weight of multiple unintegrated security tools, millions of vulnerabilities, and limited visibility into the overall risk profile. Traditional prioritization efforts were unable to adequately filter critical findings, leaving security and IT teams without the necessary business context to act decisively. Consequently, this customer selected Qualys and launched a strategic initiative to unify their security stack by transforming silos with risk signals spanning on-prem and multicloud environment into a cohesive agentic AI native risk management solution. This included expanding the ETM deployment to further operationalize the ROC with ingested third-party data from several sources, resulting in a mid-six-figure annual bookings of . By consolidating these data sources into the Qualys platform, we are now delivering this customer a unified orchestration layer and full visibility of their attack surface centralized risk assessment, quantification, prioritization, and remediation workflows while unleashing the operational efficiency of the stack consolidation. This expansion of the ROC underscores the power of our platform and reinforces Qualys' ability to unified signal, operate at an autonomous defense layer, strengthen customer outcomes aligned to the business risk tolerance, and advance our leadership in the industry. Leveraging our MROC partner ecosystem, we are also pulling new business into Qualys. During the planning stages of launching a new ETMPOC with a global 200 company in Latin America, we secured a seven-figure annual bookings upsell, which included our and policy audit solutions. This win demonstrates the leverage of our partner-led motion and our ability to convert early engagements into meaningful multi-solution growth. Turning to our federal business, we achieved a mid-six-figure expansion as one of the federal government's most visible shared security services. utilized by several large government agencies nationwide. Faced with an overwhelming volume of security issues that limited resources to continuously assess risk across augmented tools and manual workflows, this customer chose Qualys for its cloud native high authorized platform to enable a centralized government program that quantitatively prioritizes risk with automated assessment standard output, and low operational overhead. Given the success of this deployment, we are now working towards a multi-agency ETM rollout representing a significant upsell opportunity as this shared service system prepares to operationalize its risk operation center. These results, alongside another six-figure upsell with a separate large federal agency, reinforce our ability to align technical capabilities with operational outcomes. that address modern security challenges and underscore the long-term growth opportunity in our federal business. Beyond these wins, they're also gaining more leverage from our partner ecosystem. As we continue to endorse a partner-first sales motion, partner-led deal registration increase again in Q4, reflecting deeper alignment and execution across the channel. In addition, with well over a dozen certified MROC partners actively launching new services, Momentum continues to build towards a global rock alliance fueling our capability, harnessing transformative solution sales, and bringing new business to Qualys. Further contributing to our growth profile, in Q4, we continued beta testing QFlex to help customers accelerate and maximize adoption of the Qualys ETM platform. Given the strong customer response and early success of this model, we plan to continue to focus on proactively identifying opportunities to leverage QFlex to enable select customers and partners to accelerate the adoption of WALIS solutions in 2026. In summary, we are fundamentally changing how organizations manage pre-breach cyber risk by unifying CTEP with expert confirmation risk quantification and automated remediation powered by an agent-AI risk fabric. Our rapid pace of innovation and strategic investments are driving strong competitive differentiation, deeper ROC adoption, broader engagements across large federal agencies, growing partner-led execution, and initial QFLEX success. Looking ahead to 2026, we'll continue our disruptive innovation, further advance our global market investments, and execute our rock vision with a balanced approach to long-term growth and profitability. With that, I will turn the call over to Jimmy to further discuss our fourth quarter results and outlook for the first quarter and full year 2026.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-

Investor presentation