Intrusion Inc. (INTZ) Earnings Call Transcript & Summary

July 22, 2026

NASDAQ US Information Technology Software shareholder_meeting

Earnings Call Speaker Segments

Anthony Scott

executive
#1

Well, hello and welcome to our webinar today. I'm pleased to share with you a preview of things to come as well as the results of some of the work that we've already done with the team from VigilAgent, our recently announced acquisition. Please see the forward-looking statement message now displayed on the screen. I'll spare you the reading of this statement in the interest of time. Joining me today is Mark Porter, President of VigilAgent, a key member of our Intrusion management team. And you'll hear a lot more from Mark in a moment. And also on the call with me is Blake Dumas, our VP of Engineering. Now just a bit of a preview of our go-forward business plan. In terms of addressing the commercial market, we will market, sell and support our commercially oriented Shield offerings primarily through the VigilAgent team and brand. And we'll also integrate selected Shield capabilities into existing VigilAgent technologies to enhance the effectiveness, speed to alert resolution and reduction of false positives. This latter issue being one that plagues nearly every cybersecurity team. And the VigilAgent team is already very good at this, and the inclusion of intrusion technology will help make this even better. And finally, we've been working hard to take advantage of some synergistic opportunities that naturally occur in situations like this. And I'm pleased to report that we've identified and have implemented nearly $3 million in annual cost of doing business savings between the 2 organizations that we'll take advantage of going forward. And on that, we'll say more about that -- those efforts in our Q2 earnings call. Now let me turn it over to Mark for a peek at some of digital agent's technology offerings, business strategy and why these things matter in today's cybersecurity space. Mark, over to you.

Mark Porter

executive
#2

Thank you, Tony. Thanks to everybody for attending. We appreciate your time, and we're going to try to make this as useful as possible for you and get you some useful information and get over to the question-and-answers section as quickly as we can. And as I said, make it really as much as possible about you. Just a quick word on what is VigilAgent. VigilAgent is really about the combination of human vigilance with Agentic AI and what virtual agents can do. As we go forward, as Tony mentioned, our commercial go-to-market strategy will be built around the VigilAgent brand and leveraging all of the strengths of what we've built with the Shield technology and some of the capabilities that it brings. We are a truly Agentic AI native cybersecurity solution. And what we've really built now is the security fabric for enterprise that allows for any customer anywhere to plug into an open ecosystem that will be able to be built upon as their cybersecurity strategy and really as part of their business strategy as they move forward. I'm going to talk a little bit about how the market is changing and a little bit about why we're doing what we're doing. What we see time and time again and what we hear from partners and customers is they want more visibility. They want fewer tools. They want an integrated ecosystem. And when you look at the attacks that are out there that have been driven by AI, and there's a couple of big ones in the news in the last 24, 48 hours, they understand how the tools work and they do everything they can to defeat existing security tools. So we must be more vigilant as we go forward. We must be more focused on eliminating gaps and cracks between the tools. And that's why we're doing what we're doing. We'll talk a little bit about how it works later. A little bit about the concept of the Security Fabric for enterprise. We really believe that data is absolutely essential and taking telemetry from every element of the attack surface is more critical than ever. All of that said, as we look at the future and stop solving for all of the problems of the last 15 years and start looking at the problems of the next 15 years, there's a couple that are really on everyone's mind right now and really challenging problems. At the end of the day, this call is about why the rationale for this business and what we're doing to go forward that's going to give us leverage and give us business advantages. When you parlay the security fabric that we've built with the Shield capabilities and you start looking at how we can detect use of artificial intelligence, not just in attacks from the outside, but how we can detect against it from use on the inside. The major problems that are plaguing clients are that these virtual agents, these automated agents can do things at a pace that is not even close, can't be matched at all by humans. They can take massive amounts of data. They can jail break. You're hearing about all of these things. So we need to be able to know when AI is present in both authorized fashions know what it's being used for and then understand when it's not being used normally and when it's accessing things that it can't normally access. We also need to know when shadow AI is being used, simply employees putting your information into browsers, into apps, into all sorts of ways that they're using company information and leaking it out there into the ether or training other people's models on your intellectual property. So these solutions are going to present -- these challenges are going to present a need for more complex solutions. And with the Shield technology, we gain massive amounts of enrichment. So it's really critical. We've already demonstrated capabilities of being able to detect these sorts of things and demonstrated capabilities to be able to put them into the common back end of our system, which will allow for scalability and ongoing cost reductions around the management of the integrations of these solutions. So as we look forward, the single biggest piece that we see collectively is that we're going to be able to help our clients, our partners and their clients see around the corner, so to speak. We're going to be able to detect things that others can't and provide increased value. Now we're going to shift and talk a little bit about the Oracle. I'm going to actually show you the Oracle at work in a little bit. The Oracle is the core of our digital fully agentic workforce. The Oracle is able to go beyond what the traditional security solution providers can do, which is they can see things and they can create alerts. We're able to see we see over 1 billion events a day at this point. We've trained the Oracle on all of this data. It's been up and running for about a year now. It's been in production for almost that long, it's able to see things, it's able to make decisions, and it's able to act. That action could be escalating to a human, that action could be response capabilities that there's a ton of actions as we move to a world where cybersecurity requires virtually immediate action, the shortest meantime to conclusion and the shortest mean time to detection and response is absolutely critical. About 2 months ago, CrowdStrike came out with their annual survey that showed a mean time to break out the time at which the bad actor decides to go from lurking in the environment to taking action has decreased to under 30 minutes. It's around 27 or 28 minutes, and the fastest I saw was 24 seconds. We do not stand a chance with human beings out 24 seconds. We barely stay in the chance at 24 minutes. So we must get to conclusion very quickly, we must take action. Now beyond the cybersecurity piece of it, this is where our competitive advantage starts to take hold. The Oracle gives us a 99% cost in reduction per alert. It gives us scalability without being linear in terms of adding humans for every dollar of revenue. As our business scales, as we generate more revenue, we do not need to add humans in the security operations center in the way that traditional stocks do because we moved quickly and swiftly starting about 18 months ago to start making this happen. We are now in a position where we have gained a competitive advantage, a technology advantage training advantage in terms of what our AI can do. And as we look at the world today, while there may be a reckoning coming in the AI market in general, it's really important to understand that the AI market is segmented into 4 or 5 different types of companies that are leveraging it. And we're in a scenario where a reckoning around the high end around the token model and the collapse of that market actually benefits us and will further reduce our cost as we go forward as opposed to creating increased costs for us. We're going to jump quickly into the technology and show you a couple of things about how it works. I want you to understand, I'll give you kind of a quick overview of what you're going to see. We're going to show you how signals come into the systems. We're going to show you what it would take for an analyst to look at all of this data. It's really overwhelming. And we're going to show you how we move from that detection to a decision very quickly, and we're going to show you what an analyst actually sees. And then we're going to show you how an analyst can actually leverage the Oracle even after it's made a preliminary decision and how we can not eliminate human beings in the security operations center, but make our staff, our team, the best human beings and how one individual can do the work of 10 to 20 individuals by leveraging the technology and the competitive edge it brings. The couple of pieces about what you're going to see. We've been very, very clear with our partners and our clients, and it's really critical that we are fully transparent with them on how it all works that we have very, very detailed security logging on all of this. Audit trails for everything that happens and the ability to go and look at everything that's going on, on every single alert they do because the security provider role in their organization is about the most trusted role in all of this. I'm going to stop sharing here, and we'll come back to that in a moment and switch over to the tech. Okay. So it looks like my screen is properly displaying. What you are looking at is what a security alert looks like in a tool that we've built called our OmniQ. We believe it is absolutely essential to bring all of the information from all of the systems when an alert has fired and correlated against everything possible to give our team the best fighting chance to create an outcome for the customer, that's a positive outcome. So when you look at what's happening, you'll see that all the details related to a ticket from every system in our system have been brought across. This is called raw JSON. And I'm only showing you this because it's difficult to read, difficult to understand. And that's what the humans have to look at. We've created our audit trail right here. So you can see that everything that's happened on this alert has been looked at. And I'm going to show you a couple of key statistics here, this time to first action. Absolutely critical. It is the first human action in 9 minutes on a relatively modest alert, very common place. the entire investigation and that action took 15 minutes and all of the details related to our track below. This was for a false positive. So we spent all that time on something that was not even a we present -- actually, take it back. It was real. It's an anomaly. The question is whether it's benign and malicious, and we determined that it's benign. We bring all related alerts in the last 30 days, all the customer details, which I'll skip over, all tickets related to the customer in the last 30 days and the Oracle decision engine, which this is for our tracking, which would show why it sends it to the security operations center or not. And what the rationale was, and this is all done so that we can continue to improve its learning and its capabilities. And here, we give the analysts all of the capabilities that they would need to respond by pressing one of these buttons to some of the most common processes. All of that has really created some tremendous efficiencies for us on the backside of this. It is allowing us some key business drivers that we'll discuss after this. But the real magic is what happens here. I showed you that the Oracle has already scored. It looks at every single alert and has already scored it, made a decision as to whether to send it to the sock or not. If I were an analyst, I would know exactly what to ask the Oracle, but I'm not -- I don't know what most of that JSON means. So I'm going to ask the Oracle simply what should I do? Typically at about 4 to 6 seconds. The Oracle will give me step-by-step instructions on how I should handle this specific incident. It will recap what happened and what its decision was. It's already closed. So in this case, it tells me that I don't have to do anything right this second, but it walks me through what happened. This is a particular issue. And it gives me the rationale as to why it was dismissed. Now at this point, the Oracle is looking not just inside the organization. It can be looking outside the organization for enrichment from other sources. Each Oracle consists of about 5 to 7 sub Oracles that run specific processes, use large language models specific to the task and then verification agents that actually verify the answers. And if they like it, allow it to pass, if they dislike it, make it go rework the action. It is then put back together and put into the notes for an analyst which we'll go back over here. So there is both a customer view and an analyst view that is provided, and they see all of this right up front and all the detailed work that it already did. Before I asked it that question, of what should I do? So if you'll notice over here, it's asking me if I need to verify or take action, and it will often give me suggestions and say it's close and none is required. Now let's ask me if I'd like to search for related alerts or check the history of the rule. I'll ask it to search for related alerts, which is what analysts might do while they are looking at this and before it's been market false positive. And now it's going to take the knowledge of those 1 billion events per day that we're seeing and all the history that's logged in the data lake, and it's going to look back on that and have not only the benefit of all the machine learning and AI applied by every one of the tools, but it's going to have the real-life knowledge of all the humans and what we did with it. And you can see the amount of information that it's given me in this look back. It's found alerts for the user, it's found alerts related to the IP address. It's found alerts related to the rule. So it's looked across all of the data lake of all the nearly 1,000 customers, all of the feeds that it's getting all the information. And then it's asking me, what I like to pull the analyst notes from a true positive alert to see what indicators made it malicious, simply give it a yes. Now it's able to go and pull notes without having to look up tickets without having to look out past incidents in 2 prompts I've gotten to a place where I can look and I can either improve my own skills or I can be 100% certain that this is a false positive. So you'll see here, it's starting to tell me key takeaways. It's a legitimate tool to back up admin granted broad permissions as expected behavior. It's integrated with Azure AD. Now the specific case reference above shows that the rule does catch real threats when all of these conditions are met. The current alert is safe. In 3 prompts in about 15, 20 seconds, which would have been faster if I wasn't narrating, it has basically told me definitively that this is true. If I wanted to tune the rule, I could ask it to tune the rule or create filters, and it would give me all of the details that I would need, which I could then send off to the dev team to QC and put into production if it needed to be tool -- needed to be too. It may actually tell me in this case that it doesn't, we'll see what it says and then we're going to move on. So you'll see here it actually tell me to white list the app and here's how to do it. It gives me all the scripts that I would need to do it. So exclude Verified integrated apps is the highest impact. So now I could gain an efficiency in the sock and create higher customer satisfaction because as Tony alluded to, false alerts are the bane of security operations teams existence as well as something that customers view as our job to eliminate. Now I'm going to show you some other functionality of the tool very quickly. Actually, I'm going to click over here, I want to show you, as we alluded to in the slide, I want to show you some real-life statistics. We have 2 minutes and 37 seconds is the average time it takes for a decision to be rendered by the Oracle. It's run 4,436 jobs in the last 7 days for $276. The rough equivalent in human terms would cost at least $24,000 and more likely closer to $50,000 in human cost to get this done, depending on the time it takes. We have full governance over the back end. We can see any jobs in flight here. You see it says there are 4 running. You can see them actually processing. And then when we go down the jobs that have already processed, I can look at any individual job, I can pull it up and I can look at every single process that was run down to the millisecond, I can look at the number of tokens used and the amount of cost associated, the decision engine and as you saw in multiple different views, this is where the customers facing and the analyst facing is made. And when the analyst is working in this, they actually score this if they see the alert, thumbs up, thumbs down. If they thumbs down it, they will write notes as to why they disagree. So we're actually able to tune and continually improve the decision-making of the org. Finally, I'll show you the last piece of this. I've actually started this process here. If an analyst, I showed you where an analyst would be able to hit a response action. The beauty of a fully agentic system and it being native in everything that we do. is that there are 2 ways that an genic agent can take response actions. We can take response actions directly into certain tools or we can build workflows for them. We might have to teach and train it. and create hooks and ways for it to tie different systems. In this case, I've asked it to build workflow to disable a user from Microsoft ontraID when it sees 15 failed attempts followed by 1 successful attempt to log in. Let me ask why just for people knowledge, I don't really care about the 15 failed. I only care if they get in. We've got tools and devices that are out there to block these things. If they've gotten in the network, I wanted to do that, then I wanted to create a ticket and notify the partner as well. So we've taken -- in that case, we would have taken action. We would have created a notification to the partner, the client whoever needs to be notified. Now you'll see that it's asking me that it needs clarification on how it would like -- how I would like it to connect to certain things. I'm going to give it some answers, hopefully, the right ones. What's that -- and we'll see if I got the answers to the quiz right here. If it likes what I have done and understands what I now need, it will tell me what it wants to build and ask me if I want it to build this workflow this process, it apparently does like it. So I don't tend to hit apply to changes. And I've now built workflow to do those things. This -- this would have taken hours, days, weeks, depending on the complexity in the scenario. We had workbooks that were up to 3,800 steps. If I looked and said, you know out this, but I want to run an AI agent in here. I can actually cut that into the workflow. I had one gentleman asked me, how do I know this isn't just a bunch of pretty boxes because the code is fully built over here, and you can review it at it. Now it wouldn't put into production myself, if I were an analyst, I would send this off to our dev team for quality control and testing which in case you didn't notice over the window is too small, down here at the bottom actually suggests the tests, and I can run the test from here. In this case, our QC test -- our QC team would do this and deliver on that. Get out of the deck, flip back here real quick. I want to recap and shift back to business side of this and talk about the drivers as we go forward as we see them. We're very excited about what's happening. We've had really, really tremendous response both the intrusion partners and the visual agent partners. We've seen extremely high interest in inbound demand for licensing the digital workforce as a platform. We are currently moving to test this with a third-party solution, Google SecOps, little known company called Google. We will integrate the digital workforce directly with SecOps as a second stage of this potential partnership with a legal tech company. It's a very exciting opportunity for us. We've seen a number of others that have asked us to integrate with their platforms as well. So that takes everything that we've capital on in the technology side and moves us into a completely different kind of revenue stream of licensing the digital workforce and the capabilities and supporting them without the full managed detect and response, so we're excited about that. We've seen expanded revenue opportunities from existing partners and customers. And I talked earlier about this, but I can't stress enough the newest frontier in cybersecurity is going to be an AI agnostic detection capability across enterprise for both inbound attacks as well as legitimate use legitimate tools being used for malicious purposes as one of the most complicated products. with the Shield solution as part of our VigilAgent solution. We now have technology or what we call the religion of the agentless all those IoT devices critical infrastructure, we've really bolstered our solution capability set around that. AI is very, very hard to detect what is happening to your data. We're going to be able to do that because we get a tremendous amount of visibility into network traffic now that we didn't have before or we couldn't look at in the same ways. And we're going to be able to help customers see around the corner. All of these things are looking -- are really leading to tremendous opportunities in organic growth on commercial sector, tremendous opportunities in the inorganic mode because we can get a fast ROI as we ingest whatever tools a target may have bring in their tools, bringing their data. We don't necessarily need to expand the footprint of our human resource in those security operations. So these things, all of this technology at the end of the day, we feel very strongly gives us competitive advantages to our sales team, competitive advantages to our biz dev team that's going to be looking at inorganic growth as we've stated before. and really positions us well as the AI market creates tremendous opportunity for disruption. What I like to talk to our partners about and our team about is in a great new world where the tools are going to be free, nearly free or very custom where you can build your own operating system for your own business as opposed to the 80% software rules in that sort of world teams that are agile and quick and wheeled those tools better than others and find new novel ways to monetize those capabilities are going to be the winners. We have our distribution network in place. We are expanding that distribution network. We've signed multiple new partnerships, and we're seeing really significant growth opportunities with new licensing opportunities, not just of the workforce, but the data as well. With that, I will turn it over for questions to you guys.

Mark Porter

executive
#3

All right. And we're happy to take questions. So -- yes. Just a second, while that happens.

Anthony Scott

executive
#4

In the meantime, there should be a Q&A button if you'd like to submit it or any at the top of your screen.

Kimberly Pinson

executive
#5

All right. Everyone should be able to themselves and turn your cameras on if they would like.

Mark Porter

executive
#6

Yes, please raise your hand if you have a question, hit the raise hand button [indiscernible] can call you at that line.

Anthony Scott

executive
#7

It may take people a moment to find button or where to unmute.

Mark Porter

executive
#8

I know I didn't do a good enough job explaining it all, so I can't believe there's no questions out there, but yes.

Anthony Scott

executive
#9

If you have a if you look at the top of your screen, you'll see raise your hand, button, you can click that or you can unmute yourself and ask a question as well. Well, Mark, I think you did a phenomenal job because there's no question, but if you have some to this is over, feel free to contact us. I'm tony.scott@ intrusion.com. Mark, your e-mail address.

Mark Porter

executive
#10

Mporter@vigilagent.com, that's V-I-G-I-L-A-I-G-E-N-T. Please feel free to copy us both and questions are really genuinely welcome. So thank you very much for your time.

Anthony Scott

executive
#11

All right. Let me just summarize to wrap up. I think what you've seen from the VigilAgent team is a really cool demonstration of using AI to do the necessary work that happens every day in a security operating center, very fast, very accurately with a lot more information that enables just a lot better decisions, quicker response. The other thing that excited me when I first met the VigilAgent team was the visibility that you get as to cost and also what the AI agents are doing. In many cases, AI is just a black box. You sort of put things in and you get an answer back and you have no idea how it's working. And I think the VigilAgent team has done a great job of not only using AI, but using it to explain to a human what it's actually doing and how it works. And then as you saw in Mark's demo, the ability to make constant improvements and corrections as new information is discovered or better methods are determined. So I think all of those combined together make this a brave new world for both cybersecurity in general, but certainly for intrusion in our VigilAgent team combined. So I want to thank everybody for joining with us today, and you can look forward to more in the next few weeks. We'll share more in our 2 earnings call in a couple of weeks. Thanks, everybody.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Intrusion Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Intrusion Inc. earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.