4/29/2026

speaker
Operator
Conference Operator

Greetings, and welcome to the Tenable First Quarter 2026 Earnings Conference Call. At this time, all participants are in a listen-only mode. A brief question and answer session will follow the formal presentation. If anyone should require operator assistance during the conference, please press star zero on your telephone keypad. As a reminder, this conference is being recorded. It is now my pleasure to introduce your host, Erin Carney, Vice President, Investor Relations. Thank you.

speaker
Erin Carney
Vice President, Investor Relations

You may begin. Thank you, Operator, and thank you all for joining us on today's conference call to discuss Tenable's first quarter and full year 2026 financial results. With me on the call today are Co-Chief Executive Officers Steve Fence and Mark Thurmond, and Chief Financial Officer Matt Brown. Prior to this call, we issued a press release announcing our financial results for the quarter. You can find the press release on our IR website at tenable.com. We will make forward-looking statements during the course of this call including statements relating to our guidance and expectations for the second quarter and full year 2026, growth and drivers in our business, changes in the threat landscape in the security industry, particularly regarding AI security, the expected impact of frontier AI models like anthropic mythos on accelerated vulnerability discovery, and the shift to preemptive security, our competitive position in the market, Growth and customer demand for and adoption of our solutions, including Tenable One, our exposure management platform, the expansion of Tenable One, including agentic AI security and orchestration through HEXA AI, and OT discovery. Research and development investments in Tenable One and our future results of operations and financial position. These forward-looking statements involve risks and uncertainties, some of which are beyond our control, which could cause actual results to differ materially from those anticipated by these statements. You should not rely upon forward-looking statements as a prediction of future events. Forward-looking statements represent our beliefs and assumptions only as of today and should not be considered representative of our views as of any subsequent date. And we disclaim any obligation to update any forward-looking statements or outlook. For further discussion of the material risk and other important factors that could affect our actual results, please refer to those contained in our most recent annual report on Form 10-K and subsequent reports that we file with the SEC. In addition, all of the financial results we will discuss today are non-GAAP financial measures with the exception of revenue. These non-GAAP financial measures are in addition to and not a substitute for or superior to measures of financial performance prepared in accordance with GAAP. There are a number of limitations related to the use of these non-GAAP financial measures versus their closest GAAP equivalents. Our press release includes GAAP to non-GAAP reconciliations for these measures. I'll now turn the call over to Steve.

speaker
Steve Fence
Co-Chief Executive Officer

Thanks, Erin. In Q1, we exceeded all of our guided metrics with 10% year-over-year revenue growth and 24% operating margins. Tenable One, our AI-powered exposure management platform, was 41% of new business this quarter, an eight-point increase from Q1 last year. In addition, we added 406 new enterprise platform customers and 43 net new six-figure customers. New customer ads and large deals with Tenable One continue to underscore our strong financial performance and balanced growth approach. The rapid advancement of frontier AI models is having a profound impact on cybersecurity, and there is understandably a lot of noise in the market. Recent announcements, including anthropic mythos, have demonstrated that AI can now autonomously discover software vulnerabilities at scale and speed we have not seen before. As a result, the number one question we are getting from investors is, what does this mean for the future of cybersecurity, and what does it mean for Tenable in particular? To start, as part of our ongoing research and development efforts, we are actively engaging with leading frontier AI model providers, including Anthropic, to better understand these advancements and help customers prepare for what's next in the cybersecurity industry. This is top of mind for customers, as we've seen a significant increase in inbound inquiry from our customers over the past couple of weeks, which Mark will cover later on the call. Our view is this. AI models are incredibly proficient at discovering previously unknown vulnerabilities. Number two, AI is also changing low risk vols in software quickly and at scale. And third, and finally, these two things will lead to a proliferation of new vulnerabilities and attack paths in customers' environments, overloading operational workloads for defenders. On that note, Let me be precise about where these models operate and where we operate because the distinction matters here. Frontier models like Mithos read and reason about source code. They find vulnerabilities such as logic flaws, injection weaknesses, and authentication bypasses by tracing data flows through a code base. That is application security research at the source code layer. It is genuinely impressive. and it is one stage of a much longer lifecycle for managing risk. Tenable operates on the other stages of that lifecycle, the ones that determine whether a vulnerability actually creates risk in a real customer environment. Specifically, customers need to understand their entire digital footprint and then assess for critical exposures. Exposures are much broader than vulnerabilities. They include overprivileged access, misconfigurations, shadow AI, and the real-world impact of vulnerabilities as they exist in our customer's environment. From there, Tenable works across all of these signals to prioritize and identify the likely and most critical paths of exploit by threat actors. So let me put this in pragmatic terms. There will be a window where adversaries hold a clear advantage in the AI era because we will see more exploits due to a tsunami of new vulnerabilities. That's exactly why the urgency for exposure management has never been higher. Organizations need to understand what exposures exist and which ones create real immediate risk in their environment. and then ensure those risks are remediated and verified. That is exactly what Tenable One is designed to deliver. For over two decades, we have built one of the industry's most comprehensive and proprietary data sets across IT, cloud, OT, which we have also expanded to AI infrastructure and apps and third-party data to solve the hardest problems in cybersecurity. Tenable One leverages this expansive data set of exposure intelligence to unify visibility across assets, vulnerabilities, identities, and misconfigurations, then applies business context and drives prioritized remediation across the environment. And that brings me to Tenable EXA AI, our new agentic engine, which we announced in Q1. TEXA is designed to take the prioritized exposures we identified, primarily in runtime infrastructure, and turn them into a coordinated action. It operates as an orchestration layer across the security ecosystem, automating, triage, and executing multi-step remediation workflows across a wide range of domains. Where Tenable One serves as the system of record for risk management, At its core, HEXA serves as a system of action for proactive risk reduction, coordinating work across humans and agents autonomously. It determines what matters most in the broader security context and drives the steps required to reduce exposure. This is a critical shift. Security teams today are not just dealing with more vulnerabilities. They are managing fragmented workloads across tools, teams, and systems. EXA brings all of that together, transforming exposure intelligence into coordinated execution at scale. EXA is built to execute automating complex tasks and orchestrate the right fixes across the enterprise before exposures are exploited. The result is a move from reactive response, where you wait for vulnerabilities to come, to consistent machine speed risk reduction, enabling defenders to operate with the speed and precision required in an AI-driven threat landscape. Now, with that said, we're also continuing to broaden our capabilities across asset types. We recently announced OT discovery to secure cyber-physical systems. These systems have historically required time-consuming deployments of specialized hardware, new agents, and bolt-on software to gain visibility. We've eliminated this friction by integrating OT discovery directly into our core solution inside the Tenable One platform. This is particularly important as the number of OT devices explodes with AI data centers and build-outs. And finally, before I turn the call over to Mark, I want to remind everyone we will be hosting an Investor Day as part of our Exposure 2026 Industry Conference. Investor Day will take place the afternoon of May 21st in Boston. We hope to see you there. With that, I'll turn the call over to Mark to walk through what we are seeing with our customers.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-