Qualys, Inc. (QLYS) Earnings Call Transcript & Summary
February 26, 2020
Earnings Call Speaker Segments
Unknown Executive
executiveThanks for coming who are here in person. This isn't moving. Yes. And thank you for everyone who's attending live on the webcast as well. We have a series of presentations from the Qualys team today. So here we go. We're going to have Philippe Courtot, our Chairman and CEO, speak about how we're driving sustainable long-term growth in a changing security industry. We're going to have Sumedh Thakar, our President and Chief Product Officer, talk about some of our new product innovations, including VMDR, EDR and our data lake and SIM initiative. We'll have Laurie MacCarthy, our EVP of Worldwide Sales Operations, talk about our scalable sales model. We'll take a quick break then, and then I'll come back and talk about our scalable business model. And Philippe will come back for closing remarks, and we'll do a Q&A. Just a reminder of our safe harbor, since we'll be talking about forward-looking events. I'll let you all read that. And remind you that a detailed description of our risk factors is in our earnings release as well as our SEC filings. And if I can just remind everyone to turn off any cell phones, that would be great. I mentioned, here's the agenda. And with that, I will turn it over to Philippe Courtot.
Philippe Courtot
executiveOkay. So good morning. And as you know, that we made a decision 2 years ago, not to be on the [ floor, ] as I would say, and have our own conference here at the Four Seasons. And yesterday was a fantastic day, absolutely fantastic, with the full room -- the entire room, absolutely packed and where we essentially really showcased VMDR, which we'll talk about, which is really game-changing in the vulnerability management space but even more. And I will speak a little bit about that. So what I would like to start today here is with, essentially, my favorite subject, I've been saying quite a few -- some long time, that security is about to change. So we are really now at the crossroad. And be a little bit more specific about the role that we see that Qualys will play -- or is playing in it. So first, welcome to the era of cloud computing. That has been, of course, long in the making. And as you very well know, security has been absolutely incredibly resisting the cloud. And the reason was because the security people are saying, "I'm losing the control of my data. I don't know where the data is going to be." But this is an industry which has been absolutely resisting cloud computing. And today, there is no question that the cloud computing is taking over. The question is, today, fundamentally, if we look at cloud computing, what is cloud computing? And I don't know why that things didn't build correctly, so this is not correct. Okay. So that's okay. So anyway. So that's -- okay, fine. So what I've always said is that you need to look at cloud computing in a very different way. You need to look at the architecture. Cloud computing is all about a new way of distributing computing power, much better than what client server was doing. Client server was distributing the computing power, as we know, to everybody within the company through the architecture of the PCs and then the LAN, which became the WAN, and the servers. Today, essentially, the cloud computing is about delivering that computing power to everybody on the planet. And of course, what makes that possible? It starts with the Internet. The Internet has been the ability for everybody to connect and to exchange information. Now today, why don't 5Gs come in? Because 5G now is eliminating one of the limitation of the Internet, which was, in fact, the bandwidth essentially and the latency. A lot of people are talking about, "oh, now it's edge computing." Now today, what is going to be the edge in a 5G world? That edge could be the cloud because you're going have all what you need to manage the device somewhere in the cloud because the latencies are essentially being eliminated. So that's another big evolution coming. Now you cannot really secure something if you don't understand its architecture. So today, you have to look at the 3 components of cloud computing. The data centers, which are today absolutely highly fractured. It's all about computing power. It's all about storage. And you could have significant computing power, then the Internet is the means of communication. And then you have these other devices. So these are the 3 elements that you need to secure, very different than securing your corporate network, which is again, different paradigm. So if you look at the Internet itself, there is still work that we need to do to secure that Internet. And I'm really frustrated to see that not much has been done yet, but that will change. We saw Google, for example, having the initiative of pushing SSL. They did a fantastic job at that. Now today, they have a new initiative, which is DNS over HTTPS. And this is very significant. Why? Because if you do that, then there is no more ability for the bad guy to spoof essentially the website. And what is happening today? There are resistance. And now, the regulators are looking whether people are saying, that could advantage Google for whatever mysterious reasons, but this is something fundamental which is to be done. I was the former CEO of cc:Mail. I cannot still believe that today, the main protocol does not allow us to know who the sender is. When you pick up your phone and receive a phone call, you know, if it's in your directory, is that person calling you. Now you could see that's spam, et cetera, but you know at least who calls you. You cannot do that in mail, and that's what you got all these phishing attacks and so forth. If we could eliminate these 2 things, we will take out so much dollars from the bad guys that today, of course, they are enjoying. So that's something which needs to be done. And then if you look at the data centers, it's a very different way now to secure these massive data centers, and I will talk about that a bit later. And the same story at the edge as well. So if you look at what really essentially fuel that digital transformation that today every company must embark on, if not at the risk of essentially being eliminated, disintermediate. And we have seen that that every time there's a new computing paradigm, of course, those companies who can leverage it, have an edge over the incumbents of the past. So digital transformation is on. And of course, what helped to do that is the fact that ultimately, we had, starting in 1999, which at the time were called more Internet technology, when Salesforce.com had the idea of essentially building the CRM application in the cloud and delivering it to everybody in a much more efficient way than using Siebel system. And Qualys with that same vision of saying we could really deliver security from the cloud, which was at the time, a kind of [ unheard of then]. So -- and then you have this platform, infrastructure as a service and on and on, or platform as a service. And now you can have your hybrid clouds. You have all these tools, this open source tool today that you could use to essentially build that new infrastructure. And Qualys, in fact, we leverage that significantly. When in 2007, we realized now there's all these tools coming our way, so we could essentially go beyond the limitation of our original architecture, which was the LAMP: Linux, Apache, MySQL and PHP. And so we start to embark in integrating ElasticSearch, et cetera. So I've been myself questioning, we have today a flurry of open source coming out, and how did that happen? I'm old enough to have been through the [indiscernible] and all that open source environment, which has a lot of shackles. You could not really use that without doing this and that, all this obligation. Then suddenly, you have all these open source engine, so absolutely fantastic that you could get for free, and pretty well done, pretty well architected. So why? It took me a long time to discover that by the way. And it's one day when I woke up in the morning, I remember my conversation with Steve Mills many, many years ago, and Steve Mills is the unsung hero of IBM. He's the one that did the transformation of IBM by essentially realizing that you need to get -- well, get away from manufacturing mainframe and became, in fact, a middleware solution with a service component around. And the way he did it was to invest $1 billion in Linux. And I asked him at the time -- this was when I was young and beautiful like all of you, I asked him and said, "But why you didn't buy that company?" And he told me, "We would have totally destroyed it." So he had understood that that critical component that he had, he better make it free. And he didn't shackle Linux at all. And then you saw Red Hat productizing, et cetera. And then suddenly, you could encapsulate the entire mainframe work that he had with that Linux layer and emerge as the new company. And then Lou Gerstner came in and did what I call the political or revolution by essentially bringing new blood into IBM. So -- but that was then. Now today, you have all these engines. So it dawned on me when they say, "Oh, now I understand why." It's the Google, it's the Facebook, it's all these people who needed to build a totally new computing architecture at an unprecedented scale that certainly where they didn't want to be dependent on traditional enterprise software, which, in any case, we're not scaling. Our limitation at Qualys was nothing wrong with the Oracle database, but we couldn't scale it. So it's good for a certain number of things, but not for what we do now with ElasticSearch. So fundamentally, all these tools came in, and they realize that it was in their interest to set them free. Because if they would have kept them inside, they could not use the tools that other people were doing. So necessity is the mother of invention. And they totally unshackle the open source movement. So today -- that's why today, we have build -- expanded our platform, and you will see that significantly. We have 142 -- 140 open source engines. We pump on the ElasticSearch, we have 3 trillion data points. On the Kafka bus, we moved 5 billion messages a day. But now on Cassandra, I would have been able to pump 1 million [ rides ] per second into Cassandra. Why? Because we can take this open source. And what we do is we make them scalable for what we need, and then also make sure that they will speak together. And that's the secret sauce that we have at Qualys. This is that huge engineering effort that we've been making for years. And now there is a new thing which is DevOps. What is DevOps? Everybody speaks about DevOps. We had -- during our user conference, we had a dinner and we have various events where we brought some experts on the digital transformation. This -- Sanjeev Sharma, which is the guy which was in charge at IBM of their entire DevOps practice. So what is interesting here is that what we learned is the fact that this is exactly what happened today, which is happening to the software industry, what happened to the manufacturing industry, and let's say, the car industry, but just-in-time inventory. The fact that the robotics, all these things that you wanted to essentially automate as much as possible, that production, you didn't want to have all these parts being tested at the time when you were assembling them. So there's a lot of changes that took in the manufacturing industry. And today, you see with Tesla, where we even move to the next level, where now today, you can essentially upgrade your Tesla through the Internet. So this is what is happening today to the way we manufacture applications. So it's a fundamental movement. And this is the reason why I call that security has now -- is at the crossroad. On one hand, security's moving into engineering; and on the other hand, I will discuss that later, security becomes a more holistic view. So you have to really now -- because everything is connected with everything, you have absolutely to be capable of understanding your entire global IT environment, which is not, of course, very easy to do. Very few company knows what connects to the network, what is the inventory they have, how secure these things is, and that's what you will see with Qualys has absolutely solved a problem. And that's why we're so happy yesterday to really unveil VMDR and Sumedh will show you how powerful what we have done is. So today, it's all about now embedding security into the DevOps process. We, ourselves at Qualys has embarked into essentially embarking into the own digital transformation, the own DevOps of our platform. So we are really practitioners of DevOps, not just only integrating QA into the engineering process, but everything else. So DevOps is all about: you have to design; you have to code; you have to ship; and you have to run that code. And that's one single process. And now what is happening is injecting security controls into that process. So what does it mean for security? Again, as I mentioned earlier, it's a major change. At the scale at which we are today, you cannot continue bolting on this enterprise security solutions. You got to start to build in security in the 3 elements of that cloud computing architecture. It's that simple to say. It's, of course, very hard to do, but it's what you've got to do. So there's a lot of changes now that nobody can say they are not happening. I'm still very candidly, absolutely surprised to see that there's still that kind of a cacophony of security solutions out there. The last one is SaaS or [ SaaSe], I don't know how you pronounce it. The SDN with security all built in. And I look at that, and I'm certainly not as technical as Sumedh, but I look at that and I tried to understand, so what does really that thing do? So I look at it, think of it. It's a VPN. That's it. That's all. Of course, it's a VPN, which has been more sophisticated than in the old good days when you have to put the Cisco agent and so forth. And it connects essentially to these devices, which are outside of your network, back to your Internet. And without that as the next hard thing in security, give me a break. This is something which is not live long like the CASB. We created that old category. There is still very important component within the CASB. But here is -- do you think the Internet or your corporate network is going to last very long in the era where everything connects through the Internet? Of course, that network is shrinking. And a lot of these networking function are moving into, some at the edge, some in the cloud. So the world is really changing. So that's the point I want to make. So we are on the verge today who have passed the tipping point. Change is coming, resistance is futile. Those who do not adjust, do the change fast, it may be very late for a lot of companies. But if they don't do that, they are going to be -- absolutely become irrelevant in a very short period of time. So the big question here is, of course, what is the role that Qualys play in that fundamental transformation? So the first thing we did, and this is what VMDR brings to the market, one of the components, we provide unprecedented real-time visibility across your global IT environment. And why can we do that? I call it, the platform stupid. We invested, since 2007, significant amount of time and energy to recreate a platform that can absolutely take all the data we need, and this is using 3 major technology that were combined. One was a scanning technology that we had mastered many years ago, so we can scan every [ API ] on the planet, every website on the planet. The problem with the scanning is that the scanning doesn't give you real time. It has a lot of constraints such as, okay, you need to essentially do authenticated scan if you really want to be precise, which means you need to have the credentials, and then you to have scanning windows. So okay, it's, well, it was good then. It's certainly not good anymore as much as it was. It still has its value but not the value it had in the past. So then we brought the agent technology. We have now more than 30 million agents out there. Our agents are very unique in the sense that they do very little. We call them Cloud Agents because they are part of that cloud architecture. These agents, 3 megabytes, very small, capture any changes wherever we can put them in any device that we can put them on, whether it's a virtual machine, whether it's, of course, a laptop, whether now today, a phone or containers. We have really pushed our agent technology significantly. And then we bring all that data, which is now real-time data that changes in real time, back to our back end where we index everything on ElasticSearch. And that's why today we have 3 trillion data points that we index. The big advantage of that is that now, we can correlate all that information, of course, and return information in hundred of milliseconds. So we have really real-time or semi-real time. And then we added the passive scanning. But the passive scanning, we don't look at as another technology. No, it's another way of getting information. Anything that connects -- that comes in and out of your device. It is also the network analysis that you're going to have. And then we bring all that into our back end where we can analyze, correlate and then enrich that data. And that's really the secret sauce of Qualys. So essentially, we are also -- we have been doing is, in that philosophy, is realizing that it's all about embedding security into this cloud platform. So as you know, we have been working with Microsoft, for example. Where today, if you go to the Azure Security Center, and you want to essentially know what is your inventory or your assets on Azure, you go to the Security Center. You click on the link, carries you to a Qualys agent, which is already there, embedded. You have now the entire view of your assets on Azure. And then you click on the second link, and we give you the security and compliance posture of those assets. And that's -- thanks to the Qualys agent, which is there. And then you click on a third link, which has nothing to do with Qualys. You create your playbook and now you remediate. Because, of course, remediation is an environment. It is very different than the patching in your old, if you prefer, enterprise network. So essentially, security has become click, click, click. Nothing to install, nothing to update, just bring your policies, and then you have the view. And the view is essentially continuous view of the security and compliance posture. So we are doing more of that, of course, with these other players. Most of them, as you know, are already using Qualys to essentially secure their own infrastructure. The Google, the Amazon, the Microsoft, Apple computer, et cetera. So the other thing that we have been doing is, of course, add DevOps practitioners. We understood the necessity to build security into the DevOps process. So we have integrated a lot of our solutions now with the DevOps tools, and there's plenty of them. It's incredible. But now what is interesting, and this is another change which is coming to the security industry big time, your customer has changed. It's not anymore the security team. It's the developers, which, their role is essentially to develop these applications, remember [ to ] call them, ship them, run them and now, secure them. So these customers -- new customers are a little bit different. If you have been with engineers, you understand how they think. So you try to go and sell them something, they -- "I don't have the time for you. "Show me your code. Get away. Let me look at the code." They look at the code. "I will call you back, don't call me. I will call you." If they like your code, they call you back. If they don't like them, they won't call you. And then they will call you back and say, "Yes, I like what I've seen. But what did you -- could you do this, this and this and that?" If you don't really answer in time or -- and correctly, they forget about you. If you do, "Oh. Great. Okay, let's go and discuss." And then they call you back again. And they say, "Now I'm interested that -- let's discuss about the road map." But you remember, this is the old good days of this enterprise tech companies where providing fantastic slides about the road map, and about this and all this -- an industry analyst, creating all these beautiful quadrants and all of these things, all that is gone. These engineers will want you to discuss about your road map, but it's not your road map, it's their road map. So they were the ones that are new. This is what I need. And again, if you answer correctly, then you have established a very good bond. So -- but that requires a very different process. So integration with all these DevOps tools is becoming very important, of course. And finally, what we have been doing now is expanding our capabilities from the detection to the response. So what is very important to understand, that a lot of people tell you about response. The problem of security, as every security specialists will tell you, is the problem of false positives and false negatives. If you cannot eliminate them, you cannot do a proper response. And even more, you cannot even automate that response because you don't want to automate something which certainly is not correct. So it's, again, a very big change. So we have been very diligent at ensuring that -- the detection capabilities. We're measuring the quality of our scans in Six Sigma. In fact, we're better than Six Sigma, which involves 1 million scan that we do, with less than 3.2 errors. So -- and then of course, we have now with the agent and all that technology, we have increased our detection capabilities significantly. And now that we have done that, we are moving into the response, that's what you will see part in VMDR. We are expanding our agents, also capabilities to do more automate, more response. And Sumedh will take you more about that. So now, so what is VMDR? So Sumedh will really show you. But it's essentially something very unique. It's not a bundle of solutions. We have a lot of this security solution that we build on the top of our platform, but that was the first step. Now what we have done is integrating a lot of these solutions into one single application. And that application allows you to do: ability to detect anything that connects your network; creating your full global IT asset inventory globally; synchronize that with your CMDBs. From there, where you can now do vulnerability management at scale, not just on the end point, but across on-premise, end point, cloud containers, mobile devices, et cetera. And then you can start to take response. And in order to do that, you cannot do everything at once. You need to make sure and you prioritize. So we have introduced a prioritization engine, that Sumedh will show you, which is extremely sophisticated and very easy to use, which allows you to essentially look at your priorities in the context of your environment and of the attacks. So it could really eliminate those vulnerabilities that essentially are important. Some people tell you, "Oh, with my solution, you only -- we have 3% of the vulnerabilities." This is nonsense. Why? Because you cannot say that only 3%. It depends. So some vulnerabilities may be very important when others are not. And that vulnerability in that one environment, they have a very low risk, when in that other environment, has a very high risk. And this is what Sumedh will show you. So this is very important. So the second thing, of course, that because of that, VMDR has become now a true foundation of what a lot of people talk about, again, which is a risk-based vulnerability management. In order to do that, you need to make sure that you have the correct data. That you have all the context you need. That is not just looking at CVEs, and having a kind of arbitrary score that is going to do that. You need to really understand absolutely the vulnerabilities in the context of your environment, and the context of the more global environment. So that is not a walk in the park. And that's what VMDR has done extremely well. And I don't -- you don't need to trust me, you can see it. And VMDR is going to be shipping in less -- in a few weeks. And this is absolutely something fantastic that we have done. And Sumedh will show you that. The other thing that it is, it is -- as we know and you discussed that, we're now moving into the incidence response market. Why? Because today, the current incidence response systems are not cutting it anymore. And why? Because you look at the traditional offsite, and essentially QRadar, they were essentially analyzing logs, and giving you a pretty good analysis. They were normalizing the logs, et cetera. So you have a pretty good view of what was happening in your logs. But today, logs are just a component of security. You need to understand significantly more information. And so they are not -- they were never designed to do that. Then Splunk came in, and Splunk essentially simplified the ability to create these workflows, making the system more agile. They did a very good job of that. It's a very good application. The problem that today you have with that second generation is that, essentially, you still have to collect the data. How do you collect the data? You need to have multiple different applications that were never designed to speak with each other to bring that data, analyze it, correlate it. Is that really -- it's absolutely a daunting task. And then you need to have the people trying to code all of that. And then from there, you need to create your workflows, which of course, they are [ trying ] to really help you do that very well. But then you have a lot of false positives. So now you need to ask people behind the screens, which, when they look at an incident, say, "Okay, is that really something which is relevant to my company? But I need to look at that or this." So now you have to go fishing to try to bring a lot of information, so this analyst, essentially, can use the human mind to really prioritize and really focus on the incidents and then take the response. So VMDR is, in fact, the foundation, and Sumedh will talk more about that, about all the things that we are doing to essentially, now that we have captured all the data we need, that we know that that data is clean, that that data is probably normalized, categorized and then enriched. Now we can certainly provide that next generation, as we call it, of incident response. And the way we look at EDR, it's another application on that platform because essentially, if you look at EDR, it's detecting malware on the end points and then the response. So today, the solutions that are in the market are essentially, either they just tell you that you have malware and then good luck, or there are more managed security solutions where you have humans behind the scenes, which are really helping you manage that. So our goal here is by eliminating the false positive, as I mentioned earlier, and having much cleaner data and greater visibility. That now suddenly, we can automate as much as possible with a response and then enable managed security service providers to provide the human element. I've always believed when we started Qualys, the premise is where we'll not have professional services. Today, we don't have a single person doing professional services because it was all about capturing the data, packaging the technology. On the other hand, now it's enabling. You never want to mix, fundamentally, a business in a business, which, on one hand, you build the technology, and on the other hand, you provide the service. It just doesn't scale. So you need to pick up your battle, and so the battle we picked was, we're all packagers of technology, and that's what Qualys has done. So with that, essentially, it's a great pleasure that introducing Sumedh, which you know we promoted recently as our President. So Sumedh has built a fantastic team in India. We are today, 800 people in India. And we decided in 2007, Sumedh, it was?
Sumedh Thakar
executive2012 in India.
Philippe Courtot
executiveYes. So to essentially really -- we had so much engineering effort to do that we knew we could not find the people in California. So we started to go abroad in India, and that has been a fantastic success. We attracted a ton of talent. And financially, I don't tell you what it means because today, if we were going to essentially bring -- doing all that development in the U.S., instead of spending 16% of our revenues in engineering, we will be spending 35%. And so that difference, of course, goes into our profitability, which means we can continue investing. Investing into our technology, expanding the platform, which is really where our focus is. So with that, Sumedh?
Sumedh Thakar
executiveThank you, Philippe. So Philippe promised a lot of stuff on my behalf that I'm going to talk about. So I'm going to focus a little bit more today initially on VMDR launch that we announced yesterday, that we're going to have in March, and then talk a little bit more about things that are coming later this year. And I think to understand VMDR and why it is significant to a lot of organizations, you really have to look at security and what every organization is trying to achieve, which is really to reduce their time to remediate for any security event. Today, the way they do that is by deploying many, many different solutions, trying to collect that data, telemetry, building their own data lake or pushing it into Splunk, or something like that, to try to get that up-to-date information about what is going on in the organization so that they can go and address that remediation. And that's really the time that they are exposed to risk. So at the end of the day, everybody is trying to say, "How do I mitigate the risk and prevent anything happening in my network, in my IT environment? And how can I address that quickly?" And today, that process, when you talk about an example of how that is really illustrated and how organizations suffer, this is data that we collected from our back end where we, of course, have a huge number of customers who are leveraging Qualys to be on top of the security issues, the vulnerabilities, configuration issues that they have to prevent these kind of breaches. So when WannaCry came about and was released as a vulnerability in March, that -- customers who were a little bit at the forefront of being able to do authenticated scanning or have agents, we saw immediately a surge in the number of detections that we had. And then we saw a sort of a little bit of remediation. So some people who had a good cadence of being able to patch their systems, were able to do that. And we saw a little bit of a dip. Then that vulnerability, which was just a vulnerability initially, became something that somebody could exploit. So EternalBlue came out as an exploit. And that, of course, is when it becomes critical. The exploit allowed us to be able to reverse engineer. Our researchers reverse engineered that exploit and then came out with the detection that we were able to use remotely. So we are able to detect that vulnerability without authentication. So the customers that were not running agents were not be able to do authenticated scan because of the pushback that they were getting from IT and their internal teams. When that remote detection came out, the number of detections increased significantly, which is that delta between those who were not doing authenticated scans, and now we're able to detect it with just a regular remote scan. But even after that, given the amount of vulnerabilities that the customers had to focus on or they're trying to do, they have a hard time trying to prioritize the ones that, in their organization, that they need to fix. So you saw that even if the detection surge, it was a flat remediation. Not a lot of them were really jumping on fixing it. Of course, as soon as that one exploit was now used in a ransomware attack, and WannaCry came about, that's when organizations had to rush, put all the resources, jump to really try to get that remediated. And they sort of enter into this emergency remediation phase where they are dropping everything and trying to get that thing patched just to be able to protect themselves from being attacked. And that really illustrates that a seemingly simple challenge of an end-to-end vulnerability management program, that involves detecting all the assets in the environment, being able to inventory them, being able to categorize them, being able to detect all the vulnerabilities, leveraging authenticated scans, agents, still a challenge. A lot of them still doing remote scanning only because they are not able to get their IT teams to deploy authenticated scanning. And then after that, given the number of vulnerabilities that keep coming up, being able to prioritize the ones that they need to focus on to fix first because those are the ones that are going to get exploited or are being actively exploited, so that you can reduce the amount of risk that they have is -- ends up being a different tool. Patch Management, a configuration management, being able to deploy the right patches in a timely manner, even if you are able to identify all of that, becomes a bit of a challenge. And this process, really, which needs to be something that they can go through very quickly to reduce the time to remediate, to reduce that risk, ends up being a combination of multiple different tools, a separate discovery tool, maybe from ServiceNow or somebody trying to sync with the CMDB that's potentially out of date. You have a separate vulnerability management tool that is being leveraged. A lot of companies leverage a separate threat prioritization using the same or other tools that are focused only on prioritization by pulling all that data out. And then they don't really help with remediation, then there is a struggle with the IT teams to get those patches deployed in a timely manner given the number of different tools that they have. So that really increases the amount of time that they have and really lead to the breaches that they face because they are really not able to identify the vulnerability or prioritize it or fix it. So when it comes to asset management, of course, the rapid expansion IT infrastructure, creates a very dynamic infrastructure. And enterprise tools, like the discovery tools that are out there, really are not -- don't have the architecture that is needed to stay on top of a multi-cloud, multi-container, multi-infrastructure environment. And so they only feed or collect information in bits and pieces to update the CMDBs, which pretty much are always out of date because they don't have the latest information being provided into them. And so customers don't really have a good idea of all the assets that they have and what is running on those assets to even detect. And of course, what you don't know is going to be used to compromise the organization. Even if customers have a big list of IP addresses that are live, that doesn't help them because the attribution of which business unit or which application or which group does that asset belong to, to determine what is the priority of that particular asset. Is it -- what is the criticality? How critical is this asset? Is it just a lab machine? Or is it an actual finance system that does -- running your [ SIF ] payment gateway? How do you identify that is a very manual process, and it's pretty often out of date. And that's the big challenge that they face with asset management. On the vulnerability management side, of course, more devices means even a lot more vulnerabilities are being discovered. A lot of them still struggle trying to leverage authenticated scanning to get a better insight into those devices. Prioritization is missing or there are tools out there that talk about prioritization, but they only prioritize the vulnerability based on CVSS rating, which really does not say much because they do not take into consideration the asset context. So you may have a vulnerability that is a CVSS base score of 10 because bad things can happen and it can be easily exploited. But if that vulnerability is on a large machine that is 10 layers deep inside your environment, maybe you don't care about that. Maybe that -- there is a exploitable vulnerability. But if a configuration is set up so that you need a network level authentication to log into the machine, which is, well, NLA, that vulnerability may not be important or critical at all because the authentication to the machine is disabled on the network. Just because there is a vulnerability on the device detected may not mean that vulnerability's active because maybe that service in which that vulnerability exists is not actually running on a specific machine. So while the vulnerability itself may have very bad things that it could do, a lot of organizations struggle to prioritize their bringing in the asset context. And a lot of these prioritization tools that are out there only focus on the context of the severity of the vulnerability and not the asset context. And that's why taking a risk-based approach becomes much harder because now you are sort of getting into a situation where you feel like you have the sort of forced patch. Even that seemingly critical vulnerability may not be something that you need to really spend effort patching first because it may not be exploitable on a bunch of machines based on the context and the risk that that particular vulnerability brings about. Once that is done, response is not just about patching. There is many mitigating responses that can be done, and they are not well integrated. Like I gave the example of the NLA. A lot of times, you don't have to necessarily kill the service or patch the software. You could just enable network-level authentication on a bunch of boxes, which is a configuration setting. That's going to mitigate the vulnerability. Sometimes you can quarantine the device on the network only to be accessible from a certain set of machine, in which case, you're not as worried because you have different layers of firewall built. In some cases, you may have to deploy patches. But then going in the large organization, going to different teams, in different countries who are using different tools, SCCM, WSUS, BigFix, all of these, which were good at a certain point of time to be able to deliver patches for systems that were on-prem, may not and do not actually rise up to the occasion to be able to take a patch and just say, get this patch across all my systems globally, whether they are in the cloud, whether they are on laptops that are outside my environment, or whether they are my on-prem system is a big long process because there are many different tools that are involved. On top of the fact that there's a different group, and there's a whole bunch of process that goes in change control, all of that, to really be able to get to that point. So essentially, organizations stay exposed for a very long time. And that's really where we are focused on creating the ability with VMDR to have a single platform where detection of those devices, we can really take a true risk-based approach, right? That's the foundation of what we're trying to do here is, as we have talked many times, Qualys is really bringing a lot of contextual information into the platform to be able to correlate for these kind of situations, right? It's not just the fact that there's vulnerability management solutions out there that talk about, "oh, I have a list of software installed on the machine, which means I can detect all the vulnerabilities." But being able to bring the entire context of everything that is happening, including process that are being spun up, what's running, what's not running, what network connections are being made, which traditionally is being looked at more an EDR domain and not a vulnerability management domain. Combining all of that together on a single platform gives us the ability to create a true risk-based solution that is addressing that vulnerability or prevention that they really need to have so that they can focus first on preventing the breaches, or like all these malicious software, or a malware that is exploiting configurations, misconfigurations or software on the machine to go and breach the system, can really be now looked in from a risk-based approach. So VMDR, which we are going to talk about is really created as a seamless solution that goes end-to-end from being able to discover their devices, assess the device. So I can -- why we call that as a real game-changer because today, all of these things are looked at individual silos, individual tools, individual teams. With VMDR, when we combine all of that together, it gives that ability for an organization to discover all of their global devices using a bunch of different sensors, network sensors, agents, cloud connectors, container sensors and all of that in a single platform, bring all those devices together, auto-organize these devices. A lot of times, as I said, organizations struggle to automatically categorize. A new device comes up, the security team has no idea who is the owner, what's running on it. How should I classify that? Bringing that ability to be able to look at what the device -- where the device came up? Which network it is in? What software is running on it? Or there's a payment software running on it, which means it should be tagged as a PCI machine. There is an ElasticSearch database running on it, which means it should be tagged as one of my indexing services that is indexing financial information. A lot of that can be auto-organized with the new asset tagging, which is a rule-based capability that customers can put in place. And that really significantly brings a lot more structure to their asset data. Of course, with the included agents, they can do a continuous assessment of their environment, not having to worry about doing scanning and scheduling a bunch of these things. They can get a -- absolutely, whether it's a cloud, whether it's a laptop that is outside their environment, or whether it's an on-prem system, it is going to continuously assess changes happening on the device to be on top of all of the vulnerabilities that are being -- or misconfigurations that are being detected on that. And then the new context engine, which I talked about, really helps them prioritize by taking not just the vulnerability context but the asset context into place. So there is a vulnerability that came out last year called Seven Monkeys, which is really on a terminal service that's running on a device, and it can be exploited pretty easily on the network if you don't have NLA, which is network level authentication-enabled. So what does that mean? Our engine will now take into consideration, not just the fact that that vulnerability is very high severity, but it will say how many systems have NLA disabled on them. And those systems that have NLA disabled may not have that version of software installed. So now we narrow that down to say, out of the machines where the authentication is disabled, only these machines actually have that particular software installed. And out of those machines -- just because the software is installed does not mean that the software is actually running on the system. So now we can take that context and say that we can narrow it down to that specific set of systems where all these parameters are true, and that is absolutely the highest risk that needs to be addressed, and all these other systems are not at high risk, and they do not need to be addressed as the first level when you take a risk-based approach. Once that is done, the ability to leverage the same agents that they already have to quickly deploy patches. So going from the detection of the vulnerability to finding exactly which patch needs to be deployed on the specific machine is really important because that is where a lot of time is lost. And then the ability to leverage the same agent from Qualys that already is being used for vulnerability assessment, asset discovery configuration assessment to also push the right patches and create an automated way. So we have customers asking, "How can we do that as a policy-based approach?" I always want all my laptops to have all their Adobe patches automatically installed. I don't want to have people approving it and going through change control or anything like that. So picking a tag, detecting the vulnerability and then auto-patching it is something now that the system can do, which, again, ends up significantly reduce the time to remediate because it is doing it in an automated way. So I have a very quick demo. So yesterday, we did a very detailed set of demos, and those videos will be up in a couple of days on the website. But just to kind of give a quick idea of how this thing is going to look for the customers and function, how easy it is that they will start with the critical assets. So in this case, they pick their windows assets as tags, which are auto created based on some policies that they have set in place. Every system coming in is tagged correctly. As soon as they do that, they see that 379 systems with 3,500 vulnerabilities are detected. We're leveraging the prioritization, attack surface and all of that. We can now say 15 systems out of those need -- have 21 unique prioritized vulnerabilities with 7 patches that need to be deployed instantaneously. We can bring all of this inside with the new context engine. They can go in and say, create a new patch job. And immediately, they can take those systems, those highly prioritized patches, click submit. And within a few hours, their systems are going to pick up those patches and get those deployed. So that's revolutionary in the space where today they struggle at every single aspect of trying to get the asset information, trying to get the information about the patches, trying to get the information about the assets, prioritizing them, detecting vulnerabilities and pushing it to different teams to do the patching. And this is really why VMDR is -- we're calling that really as a game-changing and a new category because this is what vulnerability management future is going to be. Anybody who's looking for -- that's what I believe is that, anybody who's looking for vulnerability management is going to say, "We need to VMDR, which does the discovery assessment, prioritization and the deployment of the fixes in one seamless workflow, and something that can reduce the amount of time that this thing stays out there and exposed." So apart from all of the workflows, the big change that we are also doing with VMDR is coming up with a very simple asset-based model. So making it extremely easy for our customers to now basically just go and say, have x number of assets, and we come up with a pricing for that, which includes any number of virtual scanners, any number of passive sensors that they need. It includes additionally, things that were not there earlier, which is configuration assessment, detection of patches, inventory across the board of your cloud container, mobile devices, the normalization, classification of assets. Of course, it includes vulnerability management. But it also includes the ability to leverage VMDR into the CICD pipeline as well. So this is not just about the running systems, but using VMDR to ensure that vulnerabilities are detected and fixed in their CICD pipeline, so they prevent those from ever going to production, is also included in that complete bundle of VMDR, which is, again, a very revolutionary in the way it's being packaged, and the way that it is actually created as an end-to-end workflow instead of just bundling various modules together. One of the things that Philippe talked about is being a platform that we have enhanced significantly. We also now have the ability, and this is something we are going to do when we go GA in March, which is all existing customers, who are vulnerability management customers, are going to be automatically upgraded to the VMDR experience UI where they get the ability not to have a lot of the workflows, their dynamic dashboards, ability to create customized widgets, the ElasticSearch back end. All of that is going to be upgraded at no cost to them at all, so that they will start to get that experience of being able to get all that asset inventory and the workflows and all of that seamlessly done. And then from that point on, in addition to the customized dashboards, the efficient searching and the entire global asset inventory, existing customers will get the additional inventories plus additional sensors at no additional cost. And then they can, in the product itself, start the 30-day trial to do configuration assessment, trade-based prioritization, alerting patch detection and all of that, which is the full VMDR. They can do a 30-day trial right there. And once they do the trial, then they can very easily upgrade to that. So when they do the trial, they get the experience of the full UI. And this really is possible because of the cloud native, as it's been called today. A cloud-native SaaS platform we have built, where we have the ability to, in one go, essentially enable all customers to upgrade them and then have the ability to experience all of the new capabilities that we are bringing in the product and not having to go and get a separate trial version, and install it, and run it, and do a POC or any of that. And that's really significant. Of course, that's possible because of the multiple years of efforts that we have put into building the cloud-based platform, which essentially is a combination of all these different sensors collecting continuous data. There's a lot of vendors out there that talk about how agentless is the best. And then there's a bunch of vendors that say, "No. No. Agent-based is the only way to go, Agentless is not good." Really, at the end, you need a full context from all the different sensors to collect telemetry, and that's what we have done, really focusing on having many, many different types of sensors that can collect all kinds of information, whether it's on-prem, cloud, multi-cloud containers, passive sniffer and all of that. Putting into a very powerful back end. So where we, today, of course, have multiple different products, which we are now starting to combine into very seamless workflows, more and more. And of course, we have multiple shared platforms. We have private platforms globally that are being deployed, not only on-prem, but also expanding into AWS, Azure, GCP as well. And the scale of the platform today has been enhanced significantly with the efforts that are put in the last couple of years to be able to address the security analytics and all of that that I'll talk about. But even today, the platform has been enhanced to be able to do 5 million -- 5 billion messages on Kafka daily. That's what we're seeing. We have 3-plus trillion data points that are indexed in ElasticSearch. We're already over 30 million cloud agents that our customers have purchased. So you can see that acceleration of the platform and the capabilities that we are adding with all of the open source engines that we have put in place. As we continue to do that, there's quite a few initiatives coming out later this year. One big expansion we are doing is in the ICS, OT environment. So being able to not -- cover not only on-prem, mobile devices, containers, cloud and all of that, but also as more and more industrial control systems are getting connected to the Internet for making them IIoT, this is becoming something that a lot of customers starting to focus a lot more on. So Qualys is now releasing the ability to have ICS-specific scans, the ability to discover industrial control system, to scan them, to detect them with passive sniffers to be able to find and detect vulnerabilities. So bringing that as part of VMDR will be happening as well soon. We're also now focusing on SaaS security and compliance. So we will soon be launching a beta of our ability to detect misconfiguration security issues with customers, not only their on-prem and cloud systems, but also SaaS systems. So within the same Qualys platform, they can detect misconfigurations on their O365 deployments, their Google G Suite deployments. Soon, we'll be adding Salesforce and other solutions as well. So SaaS, as more and more environment is moving into the SaaS, the ability to look at all of that together is also important and that the platform is being expanded. To bring that visibility as well into the same exact platform. While VMDR is our first detection and response capability that we have announced on the prevention side, of course, now with the enhancements that we're doing in the platform, we're going to release very soon a new version of our agent that basically does the entire EDR, where not only can it detect patches and processes and all of that, it also will have the ability to take response actions to kill a process, to quarantine a machine, to kill a network connection, be able to quarantine a file as needed. So really bringing EDR capability but within the context of the entire network, and not looking at EDR only in the silo of an end point. Because, of course, when you have that machine, that end point that is getting compromised, it has been compromised maybe from a compromised printer in your environment, which can have lateral movement moving into that. And a lot of the EDR-only, they focus only on agent-based approach. They don't have passes and efforts to detect traffic coming out of devices where we -- you may have missed putting an EDR agent or something where you cannot have an EDR agent. How do you detect devices that are printers that are compromised in the environment? You cannot put an EDR agent on a printer. How do you bring that ability to take all those devices together? That's what the security analytics is going to focus on, which I'll talk about. But also enhancing our platform this year to do, not only detection, but also response in the cloud environment. I have AWS accounts. I want to ensure that those S3 buckets always stay up to my policy. Not just report that there are S3 buckets being spun up that don't need the policy, but also have the ability to automatically go leveraging Qualys solution and fix those configurations. The same goes for containers. Not only -- today, we are already very strong on being able to discover vulnerabilities in containers in the CICD pipeline, also monitoring containers at run time. But can I have policies that help prevent certain things happening on containers? Being able to prevent the execution of a system command, let's say, through a container. So that capability is in beta right now, where we're able to -- in a private beta with some customers, where we were able to provide them instrumentation, which is a small piece of code, which is essentially a function-level firewall that goes inside every single container and can actually now provide detection and response capabilities in real time on the containers as well. And a lot of the EDR solutions, they don't really expand their capabilities to the containers either. On the mobile device, we have made a serious effort to now, as part of VMDR, put out a Android and iOS agent for enterprise handheld devices that can give free inventory for the customers, like they get on all the rest of the assets. But then ability, later this year, to also put policies and make changes -- remove corporate information from certain devices, block access to you, to you block certain apps of those devices, be able to reset configurations like PINs and passwords on mobile devices. That detection and response capability is also being added to the platform. We're significantly enhancing that capability as well. I mentioned earlier about SaaS. So again, it is not just about assessment, but can I go in and change the public permission of a bunch of files that is now exposed on SharePoint or OneDrive which should not have been exposed publicly. Being -- taking a policy-based approach to detection and response around the SaaS environments as well is something that we are adding to the platform this year as well. So as you can see, there's a lot of different types of infrastructure that are being addressed in a single platform, and which is why that security analytics and data lake that we have started talking about last year, and we are working on very aggressively right now, is going to be significant because now instead of looking at traditional SIMs, and if you -- it's very interesting, if you look at that latest Gartner Magic Quadrant, pretty much all those who are there at the top are solutions that started as log management solutions for IT to be able to look at historic information coming from logs and be able to pinpoint trends that say why something bad happened with my machine. They were never really designed architecturally to be able to have real-time ability to say, "Oh, I see this particular activity that happened on a particular end point. Can I, in real time, query a back-end to be able to say is network-level authentication enabled on that? Is that service running? Was there another connection that is actively being made right now?" Because the logs are coming into these systems with delays. And when they come in, they -- you don't -- the only way you can get full context is you have to put every single piece of information that you ever have pushed into these systems. SIM solutions, which, of course, they charge you more and more and more by the data. This is something with the Qualys platform customers who are leveraging more and more and more of those apps already have their data, which is that 20 -- almost 20 petabytes of data we already collected. A lot of the data -- and a lot of these SIM vendors talk about a new thing called enrichment of the data, and that is something that Qualys already has. The context of the asset in real time of what is on it, what's running, what process executed, where is this device located at this point of time is already available in the platform and in data structures that are not based on log-based architecture. They are based on instantaneous availability through ElasticSearch, through Kafka, through all of that. And that is what really makes our data lake approach and security analytics, on top of the data lake approach, something that is very different than the traditional SIM vendors who are really based on the log information. So they really take Qualys data or data from other vendors, convert that into log entries and then push it into their SIM solutions to try to do some sort of a correlation. And a lot of that is now being built in directly into the Qualys platform. And this is sort of a brief architectural slide on how we are working on our data lake platform and our correlation platform where, of course, the more Qualys apps that they are using that information is already in our platform, and then adding certain third-party sources like firewall logs and things like that. We can ingest data from third-party vendors as well, third-party IT solutions, Amazon, VMware and others as well as Palo Alto firewalls and Cisco firewall. And then essentially, with the new architecture that we have put in place, we're able to process a lot of this information in real time, being able to correlate that in real time, and sort of a lot of these SIM solutions who are adding this kind of a capability after the fact on a database that is not really meant for that. With that, we're able to add machine learning natively as well as the enrichment, which is already built in, which really makes that architecture and the ability to provide much faster analytics than the log-based analytics, I think, is going to be the significant differentiation. And as Philippe mentioned, that VMDR is that first step that we are taking in that direction. But the security analytics is something that we are really actively working on to be able to deliver that sometime later this year in our first beta with some of the selected design partner customers that we are already working with who are pretty fed up with their current SIMs and either have themselves started to create some sort of a data lake around ElasticSearch or are -- were looking to do that, and then they came to Qualys. And with that, we really have a very strong design partner program for this particular solution that we're working with to get to that particular level. So that was a brief overview on security analytics. And that's my presentation. So I think I would like to now invite Laurie to come on up and give a brief overview of our sales strategy and model. Thank you.
Laurie MacCarthy
executiveThank you. All right. Hi, everybody. Laurie MacCarthy, EVP of Worldwide. So I'm really excited to talk to you guys today about how we're going to deliver our amazing new application to our clients. Some of you may know that I have worked for Qualys for 8 years. Before that, I've been a client of Qualys for the better part of 10 years. So I'm very deeply, personally invested in delivering this new application that we've worked for the better part of 18 years to create because I've been a part of building and creating this for most of that time. So let's get into it. Oh, we're going to go the other way. Okay. Here we go. All right. So we're going to talk about how we're going to bring VMDR to market for general availability. Oh, I'm getting a little bit to the asset-based pricing model that we have created and talk a little bit about our customer transition and interest. I want to give you a little insight into 3 clients that we've actually transitioned already. And just summarize a little bit growing into 2020. So what makes our pricing model scalable? We're now transitioning to a per asset licensing model. That's going to be consistent across all our employer and customer sizes. So we're going to now move towards a single pricing per asset for our small business, our medium enterprise and our enterprise. We're going to make it really easy to grow your business. We're going to grow right with you, one price per asset for our application, which is going to service your entire organization. Our key revenue drivers, as you've heard, we're going to be the only solution in our space that's going to provide you global visibility. We're going to see everything in your environment. We're going to show you that. We're going to automate your entire VM life cycle. We're going to give you everything you need to provide all of the security for every single asset in your environment. And we're going to consolidate multiple enterprise security and compliance solutions in one application. Now as we've said, this is not just rolling together a bunch of services. This is an entirely new application, which is going to really change how you're able to secure each and every asset in your environment. And then of course, with today's dev ops mentality, we're going to be able to build our security right into your digital transformation as unique as that is, for each and every different organization's transformation journey. All right. So for the customer transitions, as we're preparing for our release in March of this year, we've already seen a lot of traction. We have 24 customers that we have already moved into our VMDR, which has generated $7.3 million in bookings to date. And we have currently 567 quotes out right now, which is going to be giving us about $24.8 million of projected revenue so far right now, and that is growing by the minute. So we're very excited about the direction that this is taking and all of the interest that we've seen already. So what I'd like to do now is just talk about 3 of the clients that we've transitioned so far. One of these is a client that is in the health care vertical. So this one is a not-for-profit that I worked very closely with our team in dealing with. We were engaged in a head-to-head bake-off with 2 of our biggest competitors, Rapid7 and Tenable, and this was for their entire scope, 70,000 assets. At the time, the client was asked by their C-level to take a look at the competition, demonstrate the value of what Qualys is bringing to the table and pit that against the competition that was out there. So what was it that we brought to the table? Why did we surpass our competition in this situation? Right out of the gate, the per asset pricing model, as I described, that single cost per asset was a huge win for us in this situation. Procurement loved it, the C-level loved it. It was simple. It was everything you need, one price, here you go. They really found that that was a key win for them in selling to their C-level, why they should be with Qualys. The restrictions on sensor infrastructure. So what that came down to was this particular organization grows a lot through M&A, et cetera, they're constantly buying up little other health care organizations, the idea that they didn't have to go back to the kitty to get additional funds for more agents, more sensors. They could grow as they needed to grow with unlimited sensor licensing and agents, huge wins, they could just do what they needed to do. That was a very big win. So our VMDR offers them that. That was great for them. Global asset inventory. Like a lot of our clients, a lot of organizations out there, what do you have in your environment, very difficult challenge for them. We offer them that full visibility, a way to organize it, a way for them to really get on top of what they have, identify that, be able to put that prioritization around it. That was a very big win for them. And then the workflow we built in there. Our prioritization was really going to take them up to next level, the way that they were able to organize how they were tackling the threats in their environment. So that was very important for them. And that is one of the reasons that we really were able to win that deal. Our next one here, and this is one that I really feel is very idyllic, this is how I see a lot of our deals rolling out this coming year. This is the financial. This was an existing customer engaging in a merger and acquisition. The company they were merging into was a -- had a big deployment of a competitor, Rapid7. And what we did here was we went in and VMDR was a perfect fit. They were looking to virtualize their environment in a lot of different ways. So VMDR offering unlimited agents, unlimited virtual scanners, was a perfect fit for what they were trying to do. And so that was a big win for them. I threw in there FedRAMP-certified. Being in banking, that was a very important feature for them. The threat intelligence prioritization, that enhancement that we've added was very big for them. We actually displaced [ Canovere ] as well as Rapid7, which was huge. And then the way that we priced our single asset pricing, we were able to provide them a structured deal that allowed for an excess budget, and we were able to foray that into the purchase of additional services. So they also went with our File Integrity Monitoring, our cloud security, our web application scanning and our container security. So I'm sure many of you may know from listening to prior earnings calls, et cetera, when we have multiple services with our clients, our retention rate on clients really goes right through the roof. This is a really great story for us because that's where we want to be. We want to be able to have multiple services with our clients. So this is a really great situation. In this particular case, we actually doubled this account from $1.2 million to $2.4 million on a multiyear account, and we're looking at a really great relationship with these guys moving forward. And then the last one here, this is one of our SME clients. It's a C2C customer. A lot of cloud presence with these guys. We were up again against Tenable.io and Rapid7, so another head-to-head bake-off. 5,000 assets continuing to grow. These guys are expected to double in the next few years. Better choice for them, why we came out on top, single-pane perspective was really important to them. VMDR offering all of the things they needed, container security, our cloud presence. This was really important to them. Because they are a smaller business, they are strapped both financially and people resource-wise, so the fact that they have the full life cycle, the patching, et cetera, absolutely untouchable by our competition. We're the only solution that could give them, soup to nuts, be able to run the whole entire program right with one company, right on one platform. So no one could come in and do that. So that was pretty much how we sealed this one up. Our AWS and Azure asset identification really was superior to anything else that the competition could offer. And one of the things that this company particularly liked is how our VMDR is structured, all of the different features that we have in there. You can build upon those as you grow. As your business grows, we're going to grow with you. And they really like that because over the next 12 to 18 months, they're going to look at expanding additional services as they're growing and their business needs will grow, their security needs will grow. So this was a really great example of how we can set a long-term strategy, understanding [Audio Gap] into the future. So in summary, what we've done is we've really listened to our clients. They want an easy way to get the whole thing done and make it simple. So per asset pricing. You want to see everything in your environment, that global visibility. You want to have a solution that's an all-in-one cloud-based app that's going to automate that entire life cycle. You want a single price for it. We're giving that to you. Qualys has always been the company that goes out and listens to its clients and really tries to understand how do we take our solutions and fit that to what their needs are, and that is what we've done here. I think that we have yet again shown that we take what our technology is and we put it to exactly what our clients need. And that's what we're doing here with VMDR. So I think that, over the next year, this is going to continue to be what our clients are going after, and our numbers will continue to show that. So that's where we're going to be with our revenues. So great. Now I'd like to bring up Melissa Fisher, and she's going to talk a little bit about our strategies here for our business model.
Melissa Fisher
executiveWe're actually going to take a quick break. We have lunch outside if people want to pick up their boxes. And we'll start again in 10 minutes to 12:05. Thank you. [Break]
Melissa Fisher
executiveSo welcome back to everyone on the webcast. Hopefully, people on the webcast got to grab some lunch as well, and obviously, those in the room did. Today, I'm going to talk about how our cloud platform model drives a highly scalable and sustainable business model. As you have seen, we have demonstrated strong organic growth with a compound annual growth rate of our revenues in the high teens, and our EBITDA and free cash flow having grown at a significantly faster pace over the last 3 years. This demonstrates the leverage inherent in our highly scalable model. We have no customer concentration, and we serve from SME all the way up to enterprise, as Laurie discussed, with enterprise approximately 77% of our revenues in 2019 despite being only 20% of customers, and that's because of the larger subscriptions they purchase. We're also well balanced from an end market perspective, with our largest verticals being financial services, services and consulting and technology. Everything we do is centered around our cloud platform, from our product and operations strategy to our sales delivery. With the expansion of our product portfolio to 19 applications and coverage across on-prem, cloud, end points, mobile, OT and IoT, we have multiple revenue growth drivers with new customer prospects, existing customers, channels and verticals like the Fed market. With our newer solutions like Indication of Compromise, File Integrity Monitoring, Global IT Asset Discovering Inventory, we significantly increased our total addressable market. And we estimate that market to be growing at a low teens CAGR to $21 billion in 2021. Compared to the market growth, we have outperformed the market with our revenue growth at 18% over the last 3 years based on a compound annual growth rate, and that's been driven by older solutions such as Vulnerability Management, Policy Compliance, Web Application Scanning, but also contribution from newer solutions like the Cloud Agent and Threat Protection. And yet we still have a significant opportunity to cross-sell in our existing customer base. You can see that only 63% of our customers have VM and only 24% of our customers have the Cloud Agent for VM. There's also a meaningful opportunity to still upsell existing solutions as we know that our customers are not fully deployed in their environments. Adding new customers is also part of our growth strategy. And despite having almost 16,000 customers and subscribers of free services, we only have approximately 4% of the global enterprise market and 1% of global SMEs. The power of our cross-sell model is exemplified by the increased multiproduct adoption we have seen across our enterprise customers with 2, 3, 4 and 5 solutions, which is a testament to our successful land-and-expand strategy. You can see that 48% of our enterprise customers have 3 or more solutions, and that's almost double the amount 3 years ago. 28% of our enterprise customers have 4 or more solutions. That's more than 3x the amount 3 years ago. And 15% of our enterprise customers have 5 or more solutions, 5x the amount 3 years ago. This multiproduct adoption has been bolstered by the strong growth in paid cloud applications. As I mentioned earlier, approximately 24% of our customers have the Cloud Agent. But there's still significant opportunity, even within those customers, because we know it's early in terms of deployment on the end points. Multiproduct adoption positively impacts our retention rate as well. Enterprise customers with 2 solutions have a gross dollar retention rate of 94%, but multiproduct adoption increases stickiness. So enterprise customers with 5 solutions have a best-in-class gross dollar retention rate of 99%. And this also drives higher average revenue per customer. So enterprise customers with 3 or more solutions spent 4x out of a 1-product customer and enterprise customers with 5 or more -- 4 or more solutions spend over 5x that of a 1-product customer. Multiproduct adoption is one contributor to our industry-leading margins, which has also driven very strong free cash flow growth with our free cash flow margin having reached 42% in 2019, excluding the onetime CapEx related to our Pune headquarters build-out. Our highly profitable operational model is due to significant efficiencies in cost of revenues, R&D and sales and marketing, which I'll cover in the coming slides. So despite having nearly doubled the number of cloud applications that we offer, we've maintained a relatively low-cost of goods sale -- low cost of goods as a percentage of revenue. And that's because we have an extremely efficient architecture. All of our solutions are built into one platform, and so we need a large support and operations team to make enhancements. Also unlike many companies that have been built through acquisition or maintain hybrid architectures, we don't have multiple architectures to maintain. We also leverage open source technologies from the invest in making them scalable. And we also benefit from having a large portion of this talent in Pune. We continue to grow our base of talent there. Today, approximately 79% of our R&D head count is based in India, and we're successful in doing this because unlike many companies who have gone to India for back office, we've gone there for front office, things like new product development. And as a result, we have very low turnover. Our Pune operation also has given us significant cost leverage. Since all of our R&D talent in India in 2019 had been in the U.S. at the effective average salary, our margins would have been 25 percentage points lower. In terms of sales and marketing, we leverage the platform as a distribution channel, enabling our customers to try and buy from the platform delivered over the Internet, unlike on-premise companies that need some people on-site to do demos or installations. Also unlike many companies that utilize a, what we call an Armani suit sales force, we utilize a technical sales force, which enables our sales force to pick up new solutions because of their background. And they're successful because they know our product, they know the market, and they know the challenges in deploying different solutions. So when you put it all together, you see how the platform model contributes to significant operating leverage, which has driven our industry-leading margins, enabling us to continue to grow our foundation of recurring revenues as well as maintain strong profitability. So now I'd like to welcome Philippe Courtot for closing remarks.
Philippe Courtot
executive[indiscernible] to the Q&A.
Melissa Fisher
executiveOh, you want to do the Q&A?
Philippe Courtot
executiveNo. No. we'll do the Q&A then, so closing remarks will be quick. We need to bring the chairs and all of us, and then you can start to ask questions. So let's bring the chairs. And maybe you can go to the next slide, no? Yes. That's fine. Sumedh and Laurie. Good. Could you bring my phone, Sumedh? Thank you. Okay. Very good. Okay, so thank you very much again for coming. I think the lunch was wonderful, don't you think? A bit short. So anyway, so please, we open up for Q&A. So anybody who wants?
Unknown Analyst
analystIt's on?
Philippe Courtot
executiveYes, it should be on. Yes.
Unknown Analyst
analystYes, I guess, the first question was for Melissa. Related to the drop in your costs in 2019, it looked fairly significant. Can you talk a little bit on how you were able to change the trend from the last 3 years? And what brought you from, I think, 22% down in '19?
Melissa Fisher
executiveWell, we've actually been extending our margins over the last few years. As I talked about on the cost of revenue side, we leverage open source technologies, we invest in making them scalable. Our teams have gone through very -- utilizing modern technologies. For example, how the [ indiscernible] of extensive tools like VMware. We're always looking to rationalize and make sure that all of the enhancements in making the platform are done in a scalable way, so that we get economies of scale essentially from that. And the R&D side, as we've talked about, we continue to invest in building great talent in Pune, which has given us benefit on the cost side. And in sales and marketing, as I mentioned, we've been leveraging the platform as a distribution channel. Our release of free Global Asset Discovery and Inventory was one example of that. And so that's given us economies in that area as well.
Unknown Analyst
analystI don't know if this is for Laurie or for Melissa, but could you give us a sense of what the pricing uplift might be going from sort of an existing bundle to moving to a VMDR-type solution?
Philippe Courtot
executiveSo I could even take that answer. It's not that simple because when you do such a drastic change -- so overall, what we try to do now today, what we have is enough. As Laurie mentioned, we have connected with enough customers, discuss their old pricing versus the new pricing. So what we see now is what I thought will happen, is that give us more opportunity to essentially, for our customers, to expand their scope. So although maybe if you look, in some cases, the price may be similar or a little bit less, for example, with VMDR. We have more, but then it's also given the ability to expand. So what I can tell you is that it has been absolutely, extremely well received. And now today, of course, our priority is to essentially connect with all of our customers to essentially start precisely to have that discussion. This is the old -- if you stay with the a la carte, which they could continue, if that's what they want, or if you want to go to the VMDR, this will be the different prices with licensing. It has been extremely well received. So the goal of VMDR was, first of all, to, one, give to the customers what they always wanted. They always have asked that to us. But we could not really give it as a bundle because if a bundle, it's all about discounting, you don't give that ability to really bring that as one application. So that's, of course, we waited for that. They all wanted to have an asset-based pricing, especially the large companies, because of their global deployment. So we give them that -- that to them. So all in all, I mean this is absolutely a huge success, and we're very happy. So what I believe is that it's going to -- so the other goal was to make us even more stickier. As you have seen, people who have 5 solution, the retention rate is pretty high. So now with VMDR, it's going to be almost impossible to displace this. Nobody has what we offer. And so that's, of course, give you very good additional dollars because it's better retention rates. When you have a pure subscription-based model, why, that's significant profits that you bring to the bottom line. And so the other thing that the goal of VMDR was, and now I'm again convinced that we will achieve that, was to make our agent ubiquitous. By having simplified the only one unlimited agent for inventory, et cetera, we now empower the security people to do what they can, every -- they could not do before, which was one of the reason why the vulnerability management market was not really that hot because you had to remediate, you had to fight with IT, you had all these different silos. Yes, the vulnerability is very important, but then you needed to prioritize them. It was so complicated, so complex that this is a market, which albeit becoming more and more mission-critical, was still a market difficult. So I think we're totally changing the market here. Because now suddenly, you can really take care of your vulnerabilities across the entire global IT asset inventory, which you realize, it creates greenfield opportunity as well, vulnerability in the cloud, vulnerability in containers, vulnerability here and there. Now you have that entire view. So that's what we have done. So we cannot really tell you about these kind of numbers yet. I can tell you, it's very well received, and it's a fantastic platform. And making our agents ubiquitous also open up significantly new opportunity as well. Three million-plus agent is already quite significant. I think with VMDR, we're going to move into the hundreds of million. And our platform has been architected. So we could really handle all that additional capacity. Okay? And another question on this side? Don't be shy.
Peter Jenkin;Herald Investment Management;Analyst
analystPete Jenkin from Herald. If you -- Can you just talk a bit about other sort of operational technology and how you might then see it sort of outside of the non-traditional IT environment and expanding your capabilities into those areas?
Philippe Courtot
executiveYes. Great question. And as you will see, our platform is already -- and then Sumedh will really be very specific, but the key point is that we're already architected correctly for the new OT and IoT world because again, of having adopted in 1999 a cloud-based architecture. So -- and you will see how the significant progress we're making into the space. So Sumedh?
Sumedh Thakar
executiveYes. So today's typical OT environment actually is a combination of different devices. So some that are -- the very core manufacturing robots, then there's a lot of controllers and systems that are running Windows and different kinds of operating system where our customers are already deploying agents to get visibility into that, which is collecting additional information. And now with the ability for the same scanners that they have now to be able to talk the additional protocols like 800 IP and other protocols, we are adding that ability into that same scanner, the same console to be able to collect this additional information about devices that are talking. These are different types of protocols to collect that data and then leverage the same back end that we have in place to basically assess them for the known vulnerabilities that are already published by these vendors. And so it's going to be an expansion that, again, is not going to be something where they need to deploy a whole bunch of different platform. It's really going to be an extension of that platform that can now understand a few other protocols as well.
Philippe Courtot
executiveAnd in addition to that, we have already a fantastic customer base, which are really asking us for that. So we have currently, today, quite a few initiative with very large companies, manufacturing companies, with whom we are working to essentially bring that to market. We have also -- an additional thing that we don't speak that much about is that because our agent is so light, and it's pretty easy to create an agent, so we have recreated web and SDK, which we have not really make a lot of noise about. But then looking at the IoT world, it's very important to also if you can put an agent -- wherever you can put an agent, you have the view of the inside. And then of course, with the passive scanning and at the scale at which we do it, you have the ability to see it, what's coming in and out of the device. You need both to really have the insurance that that thing that connects is really secure, and it's not going to create problems. So with an SDK, you can think that IoT vendors would now suddenly very easily create their own agent because we're not going to be able. Today, we have an agent, for example, on ATMs as well. So -- but on ATMs, which really have the Windows-embedded system. And I'm not going to do -- we're not going to go and design the agent for every different type of IoT devices. However, given the SDK, writing 3 megabytes of code takes some time, but it's not also that complicated because we have everything on the back end to really take care of that data and as well in real time. So that's the space. But unlike some people that you hear, there's so much noise in that industry that are telling you, oh, we got the solution, the this, the this and that. These things takes time. You really need, again, to make sure that you identify the devices properly, et cetera. You've got to have the quality is #1. You cannot have false positive. The enemy of security are the false positive. And it's the reason why that industry has been so fragmented because there's multiple facets to security, and those who are the best of breed were those like we were, and still are, in vulnerability management, we were the one with less false positive, the most accuracy. And then -- so those who are doing that becoming the best-of-breed, and then you have the first consolidation of that industry, all is a big company, the Ciscos, et cetera, and the Symantec and McAfee, buying the best-of-breed solution, trying to integrate all that into a seamless solution, impossible to do because it's enterprise software. We always believe, and now we're proven right, that if you could bring the data into a cloud-based architecture, in one single place, that's where you can do all that correlation and everything. And then you can naturally create the best-of-breed solution, but then totally integrated. That single pane of glass, that mythical console that security has been looking for, we've got it. And now you use cloud to see it with VMDR. But look at how long it took us. We started that rearchitecture in 2007. I know that Sumedh doesn't work...
Sumedh Thakar
executiveMore than 24 hours.
Philippe Courtot
executiveEvery day, yes. He's got only 3 shifts. He's got the shift in India, the shift here. So we kind of fabricated another fourth shift. But so anyway. No, he did a fantastic -- he and his team have done an absolutely remarkable job. Any other questions? Yes?
Unknown Analyst
analystJust how do you view the upsell opportunity in the customer base? I mean is there any way you can quantify that? And then just from a sales compensation perspective, any changes to sales comp plans to internalize new customers versus upsell of existing customers?
Philippe Courtot
executiveYes, quantifying upsells. You can do old model that you want, et cetera. But it's really relatively difficult to do. However, our compensation, the way we compensate is very -- it's also very scalable. So because of our model, we had essentially a sales force, whether it's for the SME or the SMB or the large enterprise, divided the hunters and the farmers. And that's the scalable model we built back in 1999. So we decided at the time that we didn't want to have the Armani-suit sales guys because the Armani-suit sales guys, the way you compensate them and motivate them is they are elephant hunters. And then if you have a pure sales of subscription-based model, you don't want the elephant hunters. Because you run out of elephants pretty quickly. But it's -- because fundamentally, the last thing you want is sell more, you don't want shelfware. So which means our land-and-expand strategy has always been based, let's not try to do too big of a deal, let's try to get one customer, even if we start small, and then we'll grow it. And growing it is significantly less expensive than trying to go and get more dollars and a lot of shelfware, which is exactly what the enterprise software has been doing for years. But again, that was the model then because then if you don't sell that thing, then your competitors will be the one taking everything and have shelfware for 6, 7 years, and then you cannot do anything. It's too late. When you have that pure subscription-based model, you don't want absolutely to sell them more than what they can consume. But then -- so now we have, of course, the farmers, it's very easy now to build a scalable sales force because the more customers you have, you adjust your technical account managers, as we call them. We have done some tweaking to the model. Now today, what we have is the MASA, which is the major account solution architects, which are handling less accounts, but the big, bigger ones, significant message, generates significant amount of dollars, like you could have one person doing $10 million, $15 million a year. And then we compensate them on the upsell and also cap because, again, we don't want them to push more than what the customer needs. And on the new business people, of course, we give them reasonable goals, but you do not incentivize them to really do big deals. And so that's what is very unique in our model. And it's also -- it shows in the profitability. Another question? Yes?
Unknown Analyst
analystAs you push this product and this new strategy, do you foresee any challenges, say, either internally or from your competition to this strategy that you are pursuing?
Philippe Courtot
executiveOh, right. I mean yes, this is a very good question. Is that -- if you look today our -- at the competition, who are they? So today, you have the traditional competitors, which are essentially, today, there is essentially left the Rapid7 and Tenable. When we started many, many years ago, there were like 12 competitors. And so today, the -- all the issues that they have, if you look at what Rapid7 did, Rapid7 moved much more into the same market. And it's about 30% of the revenue today are seen with the acquisition that they made in Ireland, and they've integrated their VM solution. But their VM solution was never -- they are not at the scale of what Qualys does. So we've been competing less and less and less on the specific vulnerability management segment with Rapid7. However, now with our SIM, we're coming back big time because our scheme of SIM because of the architecture of Qualys again is going to cover the entire spectrum of very small to very small to very large. So we have that scalability which is very hard to do. But we have that -- this is in our DNA. So once we start to compete with them big time, once we, of course, deliver the SIM. Tenable is very different. Tenable have the kind of a disparate architecture. They have Tenable.io, which is a cloud-based solution that they started a few years ago. So they are very, really far behind on that cloud solution. Then they have the Security Center, which is an enterprise solution. They may tell you in their brochures that all that work seamlessly together, trying to show our kind of an enterprise software, different code base, can work with something which is in the cloud. It's not really that easy. And then they've got other solutions like the passive scanning, which on another architecture, and then the Container Security. So for us to really race to the challenge that we have now put in front of them, they will have to rearchitect. Rearchitecting is not a walk in the park, to really fuse all these different things into a single solution. And that's a lot of work. And so I'm not losing my sleep. And then -- sorry. And then the other competitors could come for those which were more the cloud natives. And these cloud-native solution, the disadvantage they have today against Qualys, and that could be because companies who started in the cloud and created for other type of applications. So the challenge for them would be that they still need to collect that security data because they weren't -- they didn't start here. So albeit they have the good architecture, they will have to create all these sensors, these collectors, all of these, bring all that data, normalize the data, analyze the data, et cetera. That's, again, not a walk in the park. And so I think we're extremely well positioned. And the result is because we have been patient. I mean we really shied away of doing acquisitions right and left to pump up the top line. We've been really criticized many times. Why are you so profitable and then growing so slow at, say, 15, et cetera, percent? It's not that slow. But no, we knew that we needed to expand the platform. We knew it took time. So why'd you go and spend dollars? And I will give you one specific example of that fundamental strategy that we had. We acquired Nevis Networks, a very nice company in India, competitors to ForeScout. And cleaning their clock in India, but they were not really outside of India because the architecture was -- the solution was far better. However, they were enterprise software solution. So we acquired them not for the hundreds of millions of dollars that you will pay to buy any kind of American company. It was a few million dollars. We move them to Pune. And in fact, they were in Pune, if I'm correct. So they were in Pune. And we asked them to essentially rebuild everything that they had done on the Qualys platform. We didn't take -- we absolutely didn't sell anymore their enterprise solution. So we didn't take care of the revenue. I didn't want to pollute our model with enterprise software that we'll have to continue and maintain and so forth. Say, okay, 100%, you go and you rearchitect. That's our passive selling solution. It took us about 3 years to do that. So for 3 years, we didn't take any revenues, period. And so that's the philosophy that Qualys has. It would require some determination and patience, but we understand the complexity. As I said earlier in my presentation that the cloud computing is a different architecture. And you've got to really look at security with that architecture in mind and understand where are the security challenges. You cannot take the old things like DEC. If you recall DEC, Ken Olsen never believed in the PC. He thought his minicomputer was far better. Look at what happened also with Siebel Systems. Tom Siebel never believed that the cloud will do anything to him. So you've got to look at that new architecture and really be very attached to it. And what we did very uniquely at Qualys is also realized that the cloud was also a new business model. So we build everything around that foundation that we had. And that's what makes us unique, and that's why we're so profitable. Okay.
Howard Smith
analystHoward Smith from First Analysis. I wanted to kind of follow up the intersection of the last 2 questions, the competitor and then some of the sales attach rates and things. So you tell your quality of your architecture and your advantages, et cetera. But you do have competitors, take Tenable, for example, that's very aggressive out there with their sales force, has a different profitability model. Do you feel, with how you're approaching the market, that you are in all the accounts at the time they're making the decision, that your coverage is there to match all your competitors so you can tell the advantages of your platform, et cetera?
Philippe Courtot
executiveYes, that's an interesting question. So -- and I like the way you quote with a different profitability model. Because if you look, of course, at Tenable, I mean this is a lot of red ink. The -- do we cover the entire market? Not really, because in order for you -- for us to compete, for example, at the low end, we needed to have the solution package so we could gain absolutely velocity. But today we have the solution. So now to go to the market, to that low end market where they thrive more than we do, it's very easy for us to do. We just absolutely do a lot of degeneration, try and buy. So -- and for us to cover the part of the marketplace that purposely we didn't want to cover because it would have been too complex, too, and then go into a pricing battle, didn't make any sense. So again, that patience I talk about. Now today, boy, I mean we have a lot of guns, and this is -- you're going to see all the campaigns that we're going to do. And the cost of doing that are absolutely minimum because everything is available, try and buy. And the cost of doing this lead generation campaign, and we are, by the way, building the entire, what I call, the marketing platform. So one of the things we're doing now is essentially building all the systems so we could increase the velocity, automate even our sales process. We're now using, for example, a fantastic thing that Salesforce.com brought now recently to market, which is their high velocity sales system, which essentially they productized the solution that they were doing to essentially empower their sales force to go and essentially and manage and promote their solutions out there. And now we're today solely integrated. So that allows you from a lead, you can have the entire cadence and you can track all of that. So you can now automate that process. So these are one of the things we're doing, building that marketing, if you prefer, origination machine. The other thing we did also is that the beauty of bringing all these solutions, you still need to have some kind of technical touch. So we build in India a team we call the technical account representative, which are people we hire from the best technical schools and young. And they come here, and this is what we call the Mr. Q agent. Whenever you connect to Qualys, you have that agent available. And behind, you have technical people which are there not to sell you, they are there to help you. Also putting significantly more videos now. That's another big thing that we're doing to, again, scale into this market. When I look today, we have, let's say, 10,000-plus SME customers. We could have 50,000. But now we've got the application, and now we're putting the machines to really get to them. So the other thing that we're doing is putting more and more tutorials in the product itself. So building a lot of these things. So making, again, a highly scalable model. Okay? Another question? That's it? Okay. Thank you very much. Thank you. Have a good day.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Qualys, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Qualys, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.