7/30/2025

speaker
Operator
Conference Operator

Greetings and welcome to the Tenable Second Quarter 2025 Earnings Conference Call. At this time, all participants are in a listen-only mode. A brief question and answer session will follow the formal presentation. If anyone should require operator assistance during the conference, please press star zero on your telephone keypad. As a reminder, this conference is being recorded. It is now my pleasure to introduce your host, Erin Cooney, Vice President, Investor Relations. Thank you.

speaker
Erin Cooney
Vice President, Investor Relations

You may begin. Thank you, operator, and thank you all for joining us on today's conference call to discuss Tenable's second quarter 2025 financial results. With me on the call today are Co-Chief Executive Officers Steve Vince and Mark Thurmond. Prior to this call, we issued a press release announcing our financial results for the quarter. You can find the press release on our IR website at tenable.com. We will make forward-looking statements during the course of this call including statements relating to our guidance and expectations for the third quarter and full year 2025, growth and drivers in our business, changes in the threat landscape in the security industry and our competitive position in the market, growth and customer demand for and adoption of our solutions, including Tenable One, cloud security, and exposure management, our ability to expand integrations with third-party tools and data sources, planned innovation, and new products and services, including new capabilities from our acquisition of APEX and our expectations regarding long-term profitability and free cash flow. These forward-looking statements involve risks and uncertainties, some of which are beyond our control, which could cause actual results to differ materially from those anticipated by these statements. You should not rely upon forward-looking statements as a prediction of future events. Forward-looking statements represent our beliefs and assumptions only as of today and should not be considered representative of our views as of any subsequent date. And we disclaim any obligation to update any forward-looking statements or outlook. For further discussion of the material risks and other important factors that could affect our actual results, please refer to those contained in our most recent annual report on Form 10-K and subsequent reports that we file with the SEC. In addition, all of the financial results we will discuss today are non-GAAP financial measures with the exception of revenue. These non-GAAP financial measures are in addition to and not a substitute for or superior to measures of financial performance prepared in accordance with GAAP. There are a number of limitations related to the use of these non-GAAP financial measures versus their closest GAAP equivalent. Our press release includes GAAP to non-GAAP reconciliations for these measures. I'll now turn the call over to Steve.

speaker
Steve Vince
Co-Chief Executive Officer

Thank you, Erin. We're excited to share our strong results for the quarter, discuss momentum and recent enhancements to our exposure management platform, including recent investments in AI, and highlight some key customer wins for the quarter. In Q2, we beat all of our guided metrics, delivering 12% revenue year-over-year growth and 19% operating margin. We attribute our performance in the quarter to the growing adoption of our exposure management platform, Tenable One, which was 40% of total new sales this quarter. Exposure management is about providing the unified risk-based and business contextualized view of an organization's cyber risk, enabling them to continuously prioritize and remediate the most critical exposures before they can be exploited. And the benefit of exposure management to our customers is clear. Unified visibility, smarter data-driven decisions, and faster, more effective risk reduction. For Tenable, this important secular shift in the market to preemptive security is resulting in broader asset coverage and larger deal sizes, including a growing number of six- and seven-figure deals. Mark will delve into our customer wins in the quarter, as we are seeing more customers consolidate on Tenable One. And now with the acquisition of Apex Security, which closed during the quarter, we are expanding our AI-aware and AI SPM capabilities in the platform, to secure the rapidly expanding AI attack surface. Reeling a little further into the specific areas of traction in the quarter, cloud and VM continue to be critical priorities for our customers within Tenable One. We also saw strong adoption with OT. As you recall, in April, we highlighted public sector as an area where we were expecting to experience some pressure. The quarter played out slightly better than expected in PubSec. driven largely by strong platform sales in our SLED business, which was aided by their June fiscal year end. Specifically with regard to U.S. Federal, we feel incrementally more positive as we head into the second half of the year, particularly in our RenovAce, where visibility is improving despite a spending environment with heightened levels of review and scrutiny. The momentum we're experiencing with our platform is a reflection of the importance our customers are placing on preemptive security. which is the practice of reducing risk before a breach occurs, rather than solely detecting and responding after an attacker has already gained access. We're building on that momentum by continuing to advance our product roadmap and extend our leadership in this category. Exposure management as a discipline is built on three foundational pillars, unifying visibility to discover and monitor every asset, unifying insight to contextualize and prioritize risk, and unifying action to mobilize remediation and measure impact. These pillars are essential to reducing cyber risk at scale, and Tenable is leading the way across all three. First, unifying visibility. Effective risk reduction starts with comprehensive visibility. That's why broad continuous discovery is foundational to exposure management. Tenable continues to make strong progress here, particularly in expanding third-party integrations across the security stack. We recently surpassed 300 validated integrations spanning cloud, application security, identity, and more, making Tenable One the most open and interconnected exposure management platform in the market. These connections not only expand visibility, but also lay the groundwork for deeper insight and smarter action. AI is also enhancing visibility by helping customers discover and classify assets that that might otherwise remain hidden from misconfigured cloud workloads to unmanaged devices and ephemeral containers. By analyzing network traffic, configuration drift, and usage patterns, our AI reduces blind spots and ensures customers a more accurate and comprehensive view of their attack surface. Second, unifying insight. Once assets and exposures are discovered, the next challenge is understanding what matters and what needs to be prioritized. That's where context comes in, and it's where Tenable sets itself apart. Our integrated data set, enriched with over two decades of exposure telemetry and real-time threat intelligence, powers a suite of AI capabilities purpose-built for exposure management. Tenable's AI doesn't just detect known risk, it's evolving to proactively identify emerging threats, map likely attack paths, and surface exposures that are most likely to be exploited in our customer-specific environments. It's being designed to use predictive modeling to assess the blast radius of vulnerabilities, analyze attacker behavior to anticipate their next move, and continuously update prioritization and conditions as they change. This isn't just a smarter way to triage alerts. It's a more strategic way to understand interconnected risk across hybrid environments and focus on what truly matters. And finally, unifying action. Insight is only valuable if it drives results. That's why we're transforming Tenable One from a system of record into a system of action. Our AI now delivers intelligent, environment-specific remediation guidance designed to help security teams reduce mean time to remediate and focus on what matters most. The majority of breach victims are compromised by known vulnerabilities that went unaddressed, not because the risks weren't identified, but because they weren't acted upon. It's a clear example of the last model problem, which is getting the right exposure data into the right teams with the right context to drive resolution. And remediation isn't just patching, it's adjusting configurations, disabling risky accounts, tightening access controls, and more. Exposure management demands a broader, more adaptive response than traditional vulnerability management. That's why we're embedding Automation, analytics, and decision support directly into customer workflows, closing the gap between insight and action. The result here is faster remediation, broadening adoption, and we believe a stronger position for Tenable as a leader in exposure management. And remember, in this new AI-powered world, we're seeing more frequent pervasive attacks leveraging AI, resulting in shorter mean time from known vulnerabilities to exploitation, which demands faster remediation. In short, while understanding, contextualizing, and prioritizing risk is critical, preemptive security increasingly means leveraging that visibility and insight to empower customers to act in real time and seamlessly integrate remediation into their process. I'd now like to turn the call over to Mark.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-