9/2/2021

speaker
Operator
Conference Operator

Good morning, and welcome to SecureWorks' second quarter fiscal 2022 financial results conference call. Following prepared remarks, we will conduct a question and answer session. If you have a question, simply press star, then 1 on your telephone keypad at any time during the presentation. At this time, all participants are in a listen-only mode. We are webcasting this call live on the SecureWorks Investor Relations website. After the completion of the call, a recording of the call will be made available on the same site. Now, I will turn the call over to Andrew Storm, Vice President of Investor Relations. You may begin.

speaker
Andrew Storm
Vice President, Investor Relations

Thanks, everyone, for joining us. I'm Andrew Storm, VP of Investor Relations at SecureWorks. And with me are Wendy Thomas, our CEO as of tomorrow, and Paul Parrish, our CFO. During this call, we will reference non-GAAP financial measures, including non-GAAP revenue, gross profit, gross margin, operating expenses, operating income, net income, earnings per share, EBITDA, adjusted EBITDA, and cash flow from operations. A reconciliation of these measures to the most directly comparable GAAP measures can be found on our web deck and press release, which are available on our IR website. Please also note that all growth percentages refer to year-over-year change unless otherwise specified. Finally, I'd like to remind you that all statements made during this call that relate to future results and events are forward-looking statements based on current expectations. Actual results and events could differ materially from those projected due to a number of risks and uncertainties, which are discussed in our press release, web deck, and SEC filing. We assume no obligation to update our forward-looking statements. Now, I'll turn it over to Wendy.

speaker
Wendy Thomas
Chief Executive Officer

Thank you, Andrew, and welcome, everyone. I first want to say what a privilege it is to serve as the CEO of SecureWorks. This company has a remarkable history in the security industry, constantly evolving to secure an ever-changing technology landscape by outpacing and outmaneuvering the adversary. Our approach is grounded in solving customer security pain points. And the three themes that we always hear is that they're looking to reduce overall risk to their organization while optimizing their security investments and navigating the shortage of security talent. To reduce their risk, Customers need a grid of security controls to protect their data and applications, and they need the technology to enable the prevention, detection, and protection capabilities to respond to today's security threats efficiently and effectively across their entire technology environment. Listening to our customers, we developed Tagus, an integrated cloud-native security platform that provides customers with both the security controls and the operational enablement they need to achieve superior threat prevention, vulnerability reduction, rapid detection across the full range of threats, and the fastest time to remediation. Solving these pain points for our customers creates significant opportunity for us. And the emergence of XDR, extended detection and response, and MDR as security categories validates this vision. In our view, XDR will become the primary security offering with the current suite of standalone security tools and applications becoming features that we offer, enhancing our TAM to over $40 billion by 2025 as the endpoint protection, SIM, vulnerability assessment, and other products become features of holistic XDR solutions. While competitors are making claims in the market every day, there are three clear reasons CIOs and CISOs are choosing us. First, our software was purpose-built to be an XDR solution. XDR at its core is really a big data challenge, an opportunity to use data science to solve security problems. And what you design software for, the architecture you build to support it, matters a lot. We architected, designed, and developed Tagus XDR from day zero with the XDR vision in mind. Our solution takes all the relevant security telemetry from our own proprietary data sources, as well as third-party sources, across our customers' entire IT ecosystem, endpoint, network, cloud, and business systems, for comprehensive and timely visibility. Cages supports both streaming and batch data ingestion, enabling advanced detectors to identify malicious activity as it's received. This provides analysts timely detections. coupled with one-click response actions to drive efficiency and faster time to remediation. Our second advantage is the powerful combination of a security platform with analytics and detections fueled by the deep security expertise that comes from staying in the fight with our customers each day. Security is one of the few arenas where you regularly face a highly motivated human adversary, empowered with technology, and collaborating amongst themselves to hone their craft. We do the same. We constantly enhance our detection and prevention capabilities by leveraging what we learn about the threat actor behavior, their techniques, tactics, and procedures each day. We see adversarial behavior from every angle through our daily security investigations, incident response engagements, and adversarial testing opportunities. Further, our counter threat unit and data science teams conduct proactive research on threat actors and their changing targets and tools to ensure we're keeping our customers aware of and prepared for the latest, most relevant threats. All of this knowledge is turned into machine-readable software that accelerates the protections for all of our customers. And the end result is an incredible breadth and depth of automated detectors and threat context to help our global customer outpace and outmaneuver the adversary at scale. And if a customer needs an expert opinion, they can simply use the intuitive built-in chat functionality we provide that makes it easy to collaborate with experts 24 by 7 for live personal help. And lastly, our fundamental understanding of how to manage and efficiently run a security operation at scale is a powerful, powerful differentiator. SecureWorks has efficiently run first-class security operations as an industry-recognized leader for over two decades. With Tagus, we are putting that expertise in the hands of our customers and partners. As one example, we continue to expand our library of orchestration playbooks and connectors in Tagus XDR. These playbooks and connectors enable our customers, partners, and our own security analysts to work efficiently by integrating with a variety of third-party tools and automating what would otherwise be manual tasks. These capabilities enable us to deliver services at higher margins than peers, and we're sharing this knowledge with partners. Customers are looking to optimize their investment in security with a platform that integrates with their security controls, unifies visibility across their entire environment, and that enables highly efficient and effective security workflows to optimize limited security resources. and partners see that we can help them build a profitable, quality business around security services. To bring this all to life, let me give an example. Recently, an employee at a large manufacturing customer was prompted to run what turned out to be a fake update to their Google Chrome browser, designed to allow the adversary to collect information about the system and its users to send back to their command and control node. Tejas detected this pattern of activity within minutes, and sent an alert showing the expected attack chain. By quickly isolating the host and resetting the credentials of impacted users, we were able to prevent the script from installing Cobalt Strike, a popular tool often used to set up future ransomware deployments. Cages enabled the rapid shutdown of the entire attack early in the kill chain. Here's another important part. This very same customer also had endpoint protection from another vendor in place. that did not prevent the attack, and the customer didn't hear about it from them until about 10 hours later. While some believe endpoint protection is enough, marrying our holistic visibility with our breadth and depth of detections is table stakes in today's security environment. Detecting attacks earlier in the kill chain is the key to preventing costly breaches. To translate this to success in the market, We're proud to share that Tagus, just two years after its launch, has crossed $100 million in ARR front, tripling from a year ago. I'd like to put that in the context of our total business for you. Our total revenue and gross margin reflect, one, our success in shifting our CTP MSS customer base to Tagus, and two, the shift away from some non-strategic offerings. First, shifting CTP customers to Tagus. We call this resolutioning because Tagus is fundamentally different, a more holistic approach to security that extends from detection to automated investigations and response capabilities. When a SecureWorks customer resolutions, they upshift their entire security posture. They expand to full coverage of their estate, gain access to the best security runbooks for detection and response, and they can easily collaborate with our security experts. We make the planning and implementation and the overall transition an upgrade experience. And we typically gain higher average revenue per customer, or ARPC. Our overall ARPC, including the subscription services on our counter-threat platform, is $117,000. Our Tagus Resolution customers spend $156,000 on average with us. I'll share a recent example of resolutioning. We've historically secured firewalls for this large, well-known public company for several years. And when the Colonial Pipeline attack happened, they made the decision to invest in expanding security across their entire environment, particularly for endpoints. During an evaluation process that engaged and assessed the top endpoint and security providers, they test drove Tagus and were impressed not only with our endpoint security, but also how easy our product was to use, and our ability to secure their entire environment. No one else could compete on that front, and the result was a multi-year, multi-million dollar deal for us. Plus, as part of the engagement, we connected them with one of our service partners to provide them with managed firewall services, a solution we no longer offer. The end result is that we have a customer getting a great security outcome, and we've improved the quality of our revenue mix. This example also illustrates the second area of transformation in our business. We've chosen to move on from certain bespoke and outsourcing-type security services, and we've been reducing our exposure to non-integrated third-party resales. These revenues are simply not strategic to us long-term and have been typically lower-margin contracts for us. We're moving apace to both transition CTP customers to TAGIS and exit non-strategic service lines, Our expectation is that Tagus ARR will eclipse CTP ARR and MIX next year, and that by the end of next year, we will have transitioned the substantial majority of our current CTP ARR off of that platform. Finally, as the XDR and MDR markets come into their own, industry analysts are evaluating competition, and Tagus is consistently showing up as a market leader. Austin Sullivan awarded us the 2021 Customer Value Leadership Award for the global XDR market with special recognition for our meaningful degree of automation. We were referenced as number eight in the top 100 software companies of 2021 and the highest ranked security software pure play by the software report. Recently, Forrester named us a leader in their first MDR wave assessment. as did IDC for their first U.S. MDR assessment. These are proof points of the agile and customer-driven way SecureWorks is transforming. As part of that transformation, I'd be remiss if I did not recognize, congratulate, and thank our incredible employees for their tremendous execution and their unwavering commitment to our mission. Now I'll turn the call over to Paul Parrish, our CFO.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-