7/29/2025

speaker
Operator
Conference Operator

Greetings and welcome to the Verona Systems second quarter 2025 earnings conference call. At this time, all participants are in a listen only mode. If anyone should require operator assistance, please press star zero on your telephone keypad. A question and answer session will follow the formal presentation. As a reminder, this conference is being recorded. It is now my pleasure to introduce Tim Pears, Investor Relations. Please go ahead.

speaker
Tim Pears
Investor Relations

Thank you, operator. Good afternoon. Thank you for joining us today to review Verona's second quarter financial results. With me on the call today are Yaki Fielson, Chief Executive Officer, and Guy Malamit, Chief Financial Officer and Chief Operating Officer of Verona. After preliminary remarks, we will open the call to a question and answer session. During this call, we may make statements related to our business that would be considered forward-looking statements under federal securities laws, including projections of future operating results for our third quarter and full year ending December 31st, 2025. Due to a number of factors, actual results may differ materially from those set forth in such statements. These factors are set forth in the earnings press release that we issued today under the section caption, forward-looking statements, and these and other important risk factors are described more fully in our reports filed with the Securities and Exchange Commission. We encourage all investors to read our SEC filings. These statements reflect our views only as of today and should not be relied upon as representing our views as of any subsequent date. Verona expressly disclaims any application or undertaking to release publicly any updates or revisions to any forward-looking statements made herein. Additionally, non-GAAP financial measures will be discussed on this conference call. A reconciliation for the most directly comparable GAAP financial measures is also available in our second quarter 2025 earnings press release and our investor presentation, which can be found at veronis.com in the investor relations section. Lastly, please note that a webcast of today's call is available on our website in the investor relations section. With that, I'd like to turn the call over to our Chief Executive Officer, Yaki Fiedelson. Yaki?

speaker
Yaki Fiedelson
Chief Executive Officer

Thanks, Tim, and good afternoon, everyone. We appreciate you joining us to review our second quarter results and the progress of our SaaS transition. Our Q2 performance reflects our continued strong ARR growth and cashflow generation as we accelerate towards the completion of our SaaS transition and make investments to capture our growing market opportunity. Today, I want to remind you of what sets Verona apart as the leader in data security. In today's ever-changing environment, one thing remains constant. Data will continue to be created and shared and usage of AI has only accelerated this trend. At the same time, attackers do not break in. They log in and they need to secure data and the challenges involved are greater than ever. Verona takes a data-first approach and help companies to locate their sensitive data, visualize who has access to it, automatically lock it down, and then automatically detect and respond to threats on it. Performing only one or two of these tasks is insufficient to protect data, and what sets Verona apart is our ability to successfully do all three of these tasks on data everywhere. In the second quarter, this approach contributed to an ARR growth of 19% to $693.2 million as we advance toward completing our SaaS transition. We SaaS ARR now representing about 69% of total ARR. Year to date, we generated $82.7 million of free cashflow up from $67.3 million through the same point last year. I will review our results and our updated guidance in more detail shortly. We continue to experience strong demand to our SaaS platform for both new and existing customers, primarily due to the superior experience that Verona SaaS and MDDR offers by enabling automatic data security with minimal effort. Additionally, I'm also proud to announce that we achieved the federal program authorization enabling us to offer our entire SaaS platforms to the federal sector. Demand from both new and existing customers looking to protect cloud environments with Verona continue to positively inflect and is becoming a material contributor to our business. This is driven by the investments we have made in our platform to expand our use cases, going wider and deeper and entering new markets, including DSPM, our ability to protect cloud data represents a significant untap growth opportunity for us and transitioning our customer to our SaaS delivery model is helping us unlock this market's potential. Data security market is rapidly expanding because of many factors, including AI usage, the proliferation of data and involving complies. As a result, data security markets like DSPM are receiving new investments and focus, which is creating more budgeted line items and increasing our opportunity. Looking at the DSPM market, other we see usually focused on discovery and classification in cloud databases because it has the lowest barrier to entry and they don't address more challenging problems like securing the data by automatically fixing risks and detecting threats or scaling to analyze large, unstructured data sets. With that as a backdrop, it is important to note that seeing a problem does not solve a problem. Discovering classification may find sensitive data but they do not secure it. This generates potential exposure without providing a solution. Varnish has made significant investments to expand our coverage, wider to both find and secure the data everywhere it leaves by providing more complete and -to-date visibility than typical DSPM technologies. As a result, customers are consolidating their data security budgets with Varnish. I would like to dive deeper into why we win in competitive deals within the DSPM space. Our edge lies in the breadth and depth of our platform. Following three-step approach called Find Fix Alert, all three critical components are needed to secure data. While DSPM point tools focus on discovering sensitive data, Varnish is the only data security vendor that does more. Not just finding sensitive data but also finding where it is unprotected, fixing the risks by locking down sensitive data automatically and continuously monitoring and alerting on unusual data activity. I will talk about the first step. Find, Varnish not only discover and classify all of our customer's data but also map all the controls that you lock it down, analyzing permissions, identities, entitlements, masking and labeling, which creates a complete current inventory of risks. We know exactly where sensitive data lives, how it is exposed, who has access and how that access was granted. We also watch data usage, tracking every time user accesses, modifies or delete data. To use a simple example, Varnish watches the bank vault compiling an inventory of everything inside, every person that can access the vault, including everything they touch and can access inside while logging all activity in and around the vault. And all this happened without impacting the customer's experience. Now, I will talk about step two, fix. The holy grail of security is ensuring identities have access to the right data. And this is very hard to do because you need all the right ingredients, which we provide. Varnish understands how data is being used and where it is unnecessary exposed because we watch all data activity and connect identities to data. Our policies develop through extensive experience with thousands of large customers are designed to intelligently and automatically mitigate risks such an access to data that identities should not have or no longer need. To continue our example, because Varnish knows who can access the vault, what the role is and what they do regularly access, we can remove unneeded access like stale access from a former intern that works at the competitor or a bank employee that has moved to another branch but still have the keys to the vault. Finally, let's talk about step three, which is alert. Since Varonis see every touch of data, we can baseline user behavior and detect threats or abnormal behavior in real time. Because we watch data directly, we generate alerts with very little noise. This enables our MDDR team, which is powered by AI to efficiently watch customer data and investigate, validate and prevent breaches with a 30 minute SLA on ransomware and without customer effort. To wrap up our example, Varonis watches the vault and can sound an alarm when a receptionist try to access it after hours or when a bank manager start going in and out of the vault more often than normal and with more cash. I would like to contrast our approach to what we see from DSPM providers. Starting with step one, the first key difference is that most DSPM providers schedule scans and use sampling as opposed to viewing all the data to discover and classify sensitive data because they cannot do it any other way. They do not track data activity so they don't know when data is added or changed. So their information is immediately state and they lack scalability view everything. Sampling allows them to scan quickly but this also means that significant amount of potential exposed data is never found and they cannot deliver full picture of risk or compliance. And because scans are scheduled, their picture is always out of date. As a result of these shortcomings, they try to avoid risk assessment. Would you be willing to store your money at a bank that does not have security camera and try to protect it using a lease that only includes 10% of its inventory and is only received on Fridays at 5 p.m. Moving to step two, because DSPM providers don't map or track access to sensitive data, there is no viable safe way to fix risk that they find. As a result, these providers just generate service tickets leaving overworked security teams to manually address them. We hear from Prospect that this approach leads to time consuming busy work and oftentimes followed by a data breach. Finishing with step three, DSPM point tools cannot detect threats to perform any meaningful forensics in an event of a suspect or actual breach because they don't track data usage, there is no activity monitoring and no user behavior analytics. Going back to our example using DSPM point tools, you like trying to understand how a bank was robbed and what was taken with no security cameras or footage, no record of who had access to the vault and an outdated and incomplete record of what was in the vault. To wrap up, DSPM tools focus on discovery and classification or mostly in the cloud. They are compliance, band-aids and not security solutions. Varanis not only discover and classify data but also intelligently and automatically locks it down everywhere and watches it for threats. Our approach results is vastly reduced risk and much lower likelihood for a data breach as compared to alternatives. Customers understand it in our ability to showcase these outcomes automatically at scale is why we are winning. And other key drivers of our recent success has been the secular plan of AI usage this quarter we expanded our coverage to protect open AI charge GPTs enterprise. We are also excited to announce an update to our strategic partnership with Microsoft. This update is focused on joint feature development which builds on our existing innovations to help organizations adapt Microsoft Cope-Alert security. While deepening our integration with them, together we are addressing one of the most critical challenges which is ensuring AI tools and LLMs do not expose data by align our engineering efforts we are accelerating our ability to drive secure AI adoption. With that, I would like to briefly discuss a couple of key customer wings from Q2. The first one I would like to talk about is a large healthcare organization of over 20,000 employees that was concerned about their ability to respond to ransomware and comply with SEC disclosure requirements for the AWS environment. They were evaluating the ones against the DSPM point tools and it became clear that only the one is could meet their success criteria Our ability to cover petabyte scale cloud environments and provide customers with the tools to avoid breaches and finds without effort were capabilities this point solution could not match. In contrast, the DSPM tools can a small sample of data that quickly became stale and could not provide any meaningful outcomes as a result. This decision was an easy one to choose the ones. We again saw strong demand from existing customer looking to convert to our such platform. One example was a defense contractor with over 25,000 employees. The new CISO who was undergoing a digital transformation project needed to modernize the data security strategy. The CISO stated the future of cyber security is data security and was quickly on board with Veronis SAS understanding the need for automated protection. This is also a key example of our Microsoft Better Together partnership then they will use Veronis to automate the purview labeling program and automatically reduce exposed data and proactively stop threats. They purchased Veronis SAS with MDDR for hybrid environments for pilot and Azure. In summary, we are excited by the many tailwinds we are seeing in our business. The simplicity and automated outcomes of our SAS platform, the adaption of AI and growing awareness of data center cloud security are driving increased momentum in our business. We may focus on executing on the tailwind as we capture our massive and growing market opportunity. With that, let me turn the call over to Guy Gallo.

Disclaimer

This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.

-

-

Investor presentation