9/1/2022

speaker
Bailey
Moderator

Hello and welcome to today's SecureWorks second quarter fiscal 2023 earnings conference call. My name is Bailey and I'll be your moderator for today's call. All lines will be muted during the presentation portion of the call with an opportunity for questions and answers at the end. If you would like to ask a question, please press star followed by one on your telephone keypad. I would now like to pass the conference over to today's host, Paul Parrish, CFO. Please go ahead when you're ready.

speaker
Paul Parrish
CFO

Thanks everyone for joining us. With me this morning is Wendy Thomas, our CEO. During this call, unless otherwise indicated, we will reference non-GAAP financial measures. You will find the reconciliations between these GAAP and non-GAAP measures in the press release and presentation posted on our website earlier today. Please also note that all growth percentages refer to year-over-year changes unless otherwise specified. Finally, I'd like to remind you that all statements made during this call that relate to future results and events are forward-looking statements based on current expectations. Actual results and events could differ materially from those projected due to a number of risks and uncertainties, which are discussed in our press release, web deck, and SEC filings. We assume no obligation to update our forward-looking statements. Now, I'll turn it over to Wendy.

speaker
Wendy Thomas
CEO

Thank you, Paul. And welcome everyone. Our transformation into a leading XDR solution provider with a strong recurring revenue model is accelerating. I'm pleased to report that we crossed the $200 million mark in Tejas ARR in the second quarter. Tejas ARR reached the $100 million milestone 10 quarters after launch. And now just four quarters later, we've doubled to $200 million. Tejas ARR and customer count numbers continue to put us among the fastest growth rates in the industry with triple digit growth in both areas, reflecting the addition of 800 customers since 2Q of last year to a total of 1500 Tejas customers. In terms of our business model transition, Tejas now represents 56% of our overall subscription ARR. and we remain on track for changes to be approximately 75% of ARR by the end of this fiscal year. So why is SecureWorks approach to XDR resonating in the market? Our changes platform is unique in four ways. One, superior detection, which means accuracy and speed with complete attack surface visibility and applicability. We ingest more than 486 billion events daily including events across more than 100 integrations, which we enrich with industry-leading threat intelligence and tens of thousands of expert curated signatures. Across our current customer implementations, 60% of the data we ingest through Tagus comes from sources other than Endpoints. This speaks loudly to the value and economy of Tagus XTR that combines data from Endpoints with data from cloud environments, email, network, identity systems, business applications, and more. We leverage 27 petabytes of diverse data with our machine learning models, combined with industry-leading threat intelligence, to produce best-in-class detection speed and efficacy. And we have a growing suite of proprietary advanced detectors, like our hands-on keyboard detector, that was trained on more than 3 trillion events. Using the power of machine learning, this detector recently identified a malicious post-exploit activity with an initial access vector never seen before. It's a perfect example of where we focus our machine learning research on the new techniques, tactics, and procedures where we do not yet have deployable threat intelligence or signatures, but that can be deployed with a high signal-to-noise ratio. For customers, this means we only alert when it matters. leading to a significant savings of valuable SecOps resources when leveraging Tagus. In short, Tagus lowers our customers' risk across their enterprise at a lower total cost of ownership, delivering the highest return on investment. Two, unmatched response. The second way our XDR platform is unique is the SOAR capabilities native to Tagus provide one, rapid and automated high security value response actions, things like host isolation or automated re-authentication prompts. And two, orchestrated workflows that quickly kick off customer remediation work streams, made easier with out-of-the-box integrations with providers like ServiceNow, Zendesk, PagerDuty, JIRA, and many others, maximizing efficiencies for our customers. It also means live access in under a minute to an expert SOC analyst via the live chat feature in our Tagus UI. We believe we lead the industry in speed and quality of response with the fastest time to detect, label, notify, and investigate among XDR providers. Three, we are open without compromise. Transparency and open interoperability have always been first-order principles for Tagus. Our platform was built from the ground up to integrate market-leading technologies and deliver incremental security value on day one. It's not about raw data aggregation. It's value delivered through actionable, security-relevant insights. And SecureWorks is committed to rapidly expanding integrations for Tagus with market-leading technologies so our customers get better more comprehensive detection with less time and effort to get to security value. For example, with the recent additions of Netscope and Skate Offense to our technology alliance partnership, we've expanded the reach of TAGE's OpenXDR to include additional solution areas being used by our customers, including SASE, CASB, and OT. We don't approach these partnerships as simple data exchange projects. Instead, we do so from our rich heritage and long experience running security operation centers, where data from each source must work in concert to provide incremental security value. And one last important point on our approach to being open without compromise. Cages customers use the same UI as our security experts, which enables seamless collaboration and rich context for security events, allowing us to work with customers of any scale, and security depth. And finally, CAGIS is priced for predictability and clear value for customers. CAGIS is priced on a per endpoint basis with no hidden data overage charges, providing customers with predictability of spend. And for an easily comparable per endpoint price, we provide more, covering a customer's entire security estate, including endpoint, with an industry-leading one year of data retention as our standard offering. That's far beyond the typical 30 days that other XDR and EDR solutions include natively, largely because their data architecture was not designed to scale to big data in addition to fast data. How can we do this at scalable margins? Our data architecture. The security operations use cases we've experienced over decades have informed the unique data architecture that gives TAGIS a powerful competitive advantage in terms of speed, scale, and security value. Evidence of this unique approach to data includes superior data labeling and normalization to feed higher fidelity detections and filter out noisy alerts. We optimize our approach to streaming or real-time versus batch processing in support of detection analytics and machine learning use cases. This allows us to develop new detectors quickly to prove out their security value while providing industry leading time to detection for our most sophisticated analytics. We also optimize our use of search, designed for speed when warranted and for cost efficiency for longer term storage and retrieval. Innovations like these, drawn directly from our security expertise, enable us to price our solution on a predictable per endpoint basis. while still supporting a full spectrum of other cloud, network, and business system telemetry with more favorable data retention options and scalable margins, a distinct market advantage. In addition to more customers seeking XDR, we are seeing customers displace their SIMs for XDR. While the SIM market is worth close to $5 billion, we increasingly hear from prospective customers that their SIMs are essentially noise engines, they're ineffective, A recent new customer win selected SecureWorks over their SIEM for the following key reasons. First, predictable endpoint pricing versus their SIEM's data volume-driven pricing, which disincented them from securing their entire environment. Cages' standard 12-month data retention was key to this customer's threat-hunting objectives, and they gained value from the incident response built into the Cages offering, rather than requiring incremental investments and challenge. And while the endpoint detection and response market is $9 billion and growing, we've heard from prospective customers and we know from our XDR visibility that EDR alone misses much of the threat. We recently alerted one customer to an exploited Confluence server monitored by a third-party EDR product where the threat actor ended up downloading scripts and running crypto miners. Yet there were no native EDR alerts, but we detected the activity with Tejas XDR from the native EDR source telemetry. We also saw the same exploit on a different server from that customer's DNS logs where there was no agent installed, demonstrating the real power of XDR. When customers have XDR deployed across the enterprise, it's common for our threat intelligence to flag network traffic to command and control addresses and then be able to tie that back to the endpoint being exploited. While maintaining 100% visibility of the entire enterprise is always a challenge, With XDR, our customers are more likely to gain early visibility into a part of the kill chain to enable them to quickly take action. With the Cages platform, SecureWorks is delivering the most transparent, interoperable, and open XDR solution, with EDR natively included. The adversary will not get complacent, and neither will we. This past quarter, we've been joined by Mike Aiello as Chief Technology Officer of SecureWorks. With more than 20 years in security, Mike is shaping the next horizon for Tagus and bringing his customer and industry experience to our leadership team. Prior to SecureWorks, Mike was the Chief Product Officer for Human Security. And prior to that, served as the CEO of AppGate, the Product Management Director for Google Cloud Security, and as the Chief Information Security Officer for Goldman Sachs Consumer and Commercial Bank. We're bringing the best of everything to the table decades of security operations experience, an open and interoperable XDR platform with a unique data architecture, and the best security talent the industry has to offer. Today's markets are turbulent, driven, shaped, and reshaped by many forces, but we remain focused on keeping our customers secure, on defining the future of threat detection and analysis. and on driving superior long-term and sustainable growth and value creation for investors as we execute on our strategy and complete our transformation as an industry-leading XDR provider. I want to thank our customers and partners for joining forces with us and thank our teammates for their hard work and commitment to realizing SecureWorks' mission to secure human progress. With that, I'll turn the call over to Paul Parrish, our CFO.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-