7/29/2026

speaker
Operator

Greetings and welcome to the Tenable Q2 2026 Earnings Conference Call. At this time, all participants are in a listen-only mode. A brief question and answer session will follow the formal presentation. Should anyone require operator assistance during the conference, please press star zero on your telephone keypad. As a reminder, this conference is being recorded. It is now my pleasure to introduce your host, Erin Carney, Vice President, Investor Relations. Thank you. You may begin.

speaker
Erin Carney
Vice President, Investor Relations, Tenable

Thank you, Operator, and thank you all for joining us on today's conference call to discuss Tenable's second quarter financial results. With me on the call today are Co-Chief Executive Officers Steve Vintz and Mark Thurmond and Chief Financial Officer Matt Brown. Prior to this call, we issued a press release announcing our financial results for the quarter. You can find the press release on our IR website at tenable.com. We will make forward-looking statements during the course of this call including statements relating to our guidance and expectations for the third quarter and full year of 2026, growth and drivers in our business, changes in the threat landscape in the security industry, particularly regarding AI security, the expected impact of frontier AI models and accelerated vulnerability discovery, and the shift to preemptive security, our competitive position in the market, growth in customer demand for and adoption of our solutions, including the impact of new pricing and packaging models, the expansion of Tenable One, including agentic AI security, orchestration through Hexa AI, and planned AI exposure coverage across third-party models. The expected benefits of our strategic partnerships with Frontier AI Labs are ongoing research and development investments, our capital allocation strategy, including share repurchases, and our future results of operations and financial positions. These forward-looking statements involve risks and uncertainties, some of which are beyond our control, which could cause factual results to differ materially from those anticipated by these statements. You should not rely upon forward-looking statements as a prediction of future events. Forward-looking statements represent our beliefs and assumptions only as of today and should not be considered representative of our views as of any subsequent date. and we disclaim any obligation to update any forward-looking statements or outlook. For further discussion of the material risks and other important factors that could affect our actual results, please refer to those contained in our most recent annual report on Form 10-K and subsequent reports that we file at the SEC. Today's discussion includes non-GAAP financial measures, These non-GAAP financial measures are in addition to and not a substitute for or superior to measures of financial performance prepared in accordance with GAAP. There are a number of limitations related to the use of these non-GAAP financial measures versus their closest GAAP equivalents. Additionally, please see our press release for reconciliations of GAAP to non-GAAP financial measures that we discussed today. I will now turn the call over to Steve.

speaker
Steve Vintz
Co-Chief Executive Officer, Tenable

Thanks, Erin. We're very pleased with our results in the quarter as we exceeded all of our guided metrics and are raising our outlook for the year. Tenable One was a record 50% of new business this quarter, continuing a strong upward trajectory. Earlier this year, we launched new pricing and packaging for Tenable One, introducing Tenable One Foundation and Tenable One Advanced. Notably, we are seeing greater than anticipated adoption of Tenable One Advanced, which reflects growing customer demand given the evolving AI threat landscape. Accordingly, larger lands and expansion deals with Tenable One helped drive average deal sizes higher this quarter, and it also helped increase our net dollar expansion rate to 106%. This is the first acceleration in our expansion rate in many quarters. The takeaway here is that our results are clear validation of our strategy and the opportunity in front of us. As AI reshapes the attack surface faster than most organizations can respond, we believe customers are increasingly choosing TempleOne as the platform that turns complexity into clear, actionable insight to reduce risk. And that differentiation is what's resulting in higher deal sizes, faster expansion, and durable leadership in this category. In fact, we believe it is becoming increasingly clear that companies who lead in this market will need three core capabilities to survive in the agentic era. First, the ability to understand every exposure across the enterprise. Next, the ability to prioritize tasks that matter most. And then, translate that intelligence into action. I'll discuss each of these three capabilities in a bit more detail. First, organizations must understand exposure holistically across the enterprise. AI is accelerating vulnerability discovery and increasing the volume of issues requiring attention. But vulnerabilities are only part of the attack surface. Misconfigurations, compromised identities, and other non-CVE weaknesses represent more than 60% of potential breach entry points, and we capture both CVE and non-CVE risks. As attackers operate with greater speed and scale, organizations need a unified view of all of the conditions that create business risk, not simply a longer list of vulnerabilities. Second, More findings make effective prioritization essential. Tenable combines broad exposure intelligence, deep contextual data, and decades of security research to help customers distinguish the exposures that create meaningful business risk from those that do not. This allows security teams to concentrate their resources on the relatively small number of actions capable of producing the greatest reduction in risk. And third, Prioritization is only as valuable as the action it enables. As AI models become more broadly available, the key to agentic security is not the model itself. It's what sits between the model and the customer's environment, ensuring that agents operate safely and accurately with human oversight and an audit trail. We call that the harness. Built into Tenable One, our harness draws on decades of exposure data, research, and our trusted sensor layer. HEXA, our agentic engine for Tenable One, operates within this harness to orchestrate the right fixes deterministically for customers. Digging a little further into HEXA, we continue to expand what HEXA can do. Just yesterday, we announced new capabilities that equip security teams with a coordinated fleet of agents capable of operating continuously, executing multi-step security tasks, and orchestrating remediation across the exposure management lifecycle. Together, the Tenable One Harness and HEXA's agented capabilities move exposure management from periodic analysis and manual intervention towards a continuous, always-on defense. As frontier models become more widely available, we believe this combination will become an increasingly important and durable differentiator for Tenable. In addition to the exciting AI capabilities we're building into our platform, we're also helping our customers secure their use of AI. With Tenable's AI exposure, we're extending coverage to include Gemini, alongside Claude, ChatGPT, Copilot, as well as major MCP deployments and AI-native development tools. Together, these capabilities give security teams a more complete view of where AI is used, the risk it creates, and where action is needed. As part of Tenable One, AI exposure and HECSA are highly complementary, helping security teams secure their organization's use of AI while harnessing AI to improve operational efficiency. And finally, we're deepening our relationships with the two leading frontier AI labs, Entropic through Project Glasswing and OpenAI through their Daybreak program. These partnerships are deep and broad working collaborations. We have access to non-public models. We're participating in joint research. We have early insight into how the attack landscape is evolving before these capabilities are broadly available in the market. More specifically, our testing as a part of Glasswing demonstrated that frontier AI can dramatically increase the speed and scale of vulnerability discovery. But it also reinforced that discovering more potential vulnerabilities does not by itself tell an organization where it is truly exposed or what it should fix first. The output requires a trust letter to validate and provide context to determine if an exposure is reachable and exploitable and whether existing controls can mitigate the risk. This is the direction the market is moving, and it's the direction we've been building toward. Customers need more than just another standalone AI feature. They're looking for an integrated platform that can act with the speed and context this moment demands. and that's exactly what we're seeing show up and how our customers are buying today. Mark will walk you through what that looks like in practice because it says a lot about where this shift is taking us.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-