Tenable Holdings, Inc. (TENB) Earnings Call Transcript & Summary
February 10, 2021
Earnings Call Speaker Segments
Brian Essex
analystOkay. Well, good morning, everyone. My name is Brian Essex. I'm Goldman Sachs' Security Software Analyst. So thank you for everyone for joining us today for our technology and Internet conference, the second half of it. Just a quick note before we get started, if anyone on the webcast has any questions they'd like to address, please enter those questions in the webcast portal. I'll leave some time at the end of the session and will do my best to get to as many as I can. So today, I'm very excited to have Amit Yoran, CEO of Tenable; and Steve Vintz, the company's CFO. I guess, so Steve and Amit, thank you very much for joining us. We really appreciate it.
Amit Yoran
executiveIt's great to be here. Thanks for hosting us.
Brian Essex
analystYou're very welcome. Anytime. And we have some exciting news this morning. So you have announced the acquisition of Alsid. So congratulations on that. Maybe if Amit, you could tell us about a little bit about the company and how it fits into your Cyber Exposure vision, we can start from there.
Amit Yoran
executiveSure. So as you said earlier this morning, we announced the intent to acquire Alsid, a French-based company that is focused on active directory security. So as you think about how the security landscape has changed over recent time, with the shift to work from home, with the shift and migration to cloud, with some of the high-profile breaches, identity, there are fewer and fewer control points, and identity is playing an increasingly critical role in corporate security. So Alsid has technology which can help enterprises assess the security of their active directory deployment and how -- where they may have configuration mistakes, where they may have hidden accounts and permissions that they were unaware of, as well as audit the ongoing monitoring of that active directory. So where new accounts are created, where privileges are escalated, where trust relationships are built. And so we're super excited and feel that this acquisition, this technology fit very elegantly into an important part of helping enterprises assess their Cyber Exposure.
Brian Essex
analystAll right. That's super helpful. And I want to clarify one thing in -- is there anything else -- in the Alsid press release, there's a line in there that mentions tightly controlling the privileges of accounts in active directory. Does this mean you're getting into access management? Or how should we think about how this fits into the overall, I guess, potential threat vector of active directory and the role that you take in that?
Amit Yoran
executiveYes. It's a great question and an important distinction. So we're not getting into the privileged access management types of business. Lots of great companies that are there, CyberArk and others, and we believe that those are tremendous partnership opportunities for -- they are a partner Tenable and tremendous partner opportunities for Alsid as a technology base. So the key differentiation, the key distinction is that in those privileged access management solutions, they're providing a brokered access to a router, a switch, a domain controller and making sure that those privilege accounts are accessing those critical resources in secure, using secure methods, so strong authentication, encrypted tunnels and things of that nature. Whereas the active directory and a secure configuration of that active directory means that people won't have access to the active directory itself. They can't create new accounts. They can't escalate the privileges of the accounts they have. And so those 2 solutions really complement one another quite nicely.
Brian Essex
analystGot it. Got it. Super helpful clarification. And maybe help me understand how this fits within the organization. Do you target the same buyer? Are you going to have to change your go-to-market strategy? Or does this kind of seamlessly plug into what you're already doing?
Amit Yoran
executiveYes. So as you know, Tenable has grown out of core vulnerability in the active market. So looking at desktop servers, workstations, assessing their configuration, and evaluating, auditing them for vulnerabilities and exposures and helping our customers translate that information into their understanding of exposure and risk. Over the last several years, we've expanded the vision to move from vulnerability management to managing Cyber Exposure. So looking at operational technologies, at control systems, manufacturing systems, looking at cloud-based infrastructure. In the last couple of earnings calls, we've sort of highlighted the acceleration of customers using Tenable to assess the security of their cloud environments, of their DevOps environments, including containers where we're seeing a lot of momentum. And so this just becomes another part of that critical technology asset base that our customers will want to assess, to understand the risk and exposure. And more importantly, get some good guidance about how they can tighten those systems before compromise might occur.
Brian Essex
analystGot it. Got it. And then maybe a little bit of the background of your relationship with the company? Is this somebody that you partner with? And how did that relationship evolve?
Amit Yoran
executiveYes. So we've known about the company for some time. We've been looking at, as we talk to CISOs, we are consistently asked about active directory. It's a pretty pervasive piece of technology on a global basis. And many security professionals, and a lot of CISOs understand that configuring active directory optimally from a security standpoint is really difficult to do. And they have a lot of concerns because they know how critical a role it plays in their security posture, especially as you consider the work from home and the cloud-based migrations that we've seen in recent times. And almost any time there's a breach, you see active directory exploited to create escalated privilege, to access the information or to create backdoor accounts and persistent access. So the security community and CISOs in particular, recognize the critical nature of the role that active directory plays, and they're looking for solutions. So we think it's a very natural expansion for our buyer, it's consistent with the use case that they turn to us for and trust us with already, and we're excited about the potential that this represents.
Brian Essex
analystRight. And that's a great segue, I guess. I mean, with regard to SolarWinds, the most recent, significant and probably the most significant, that's what we've seen. Is that the most obvious example of what you can point to or some of the benefits of what Alsid will provide?
Amit Yoran
executiveBrian, I think that's a great point. I mean, SolarWinds certainly, as high-profile as they come, and with 18,000 organizations around the world impacted, gaining a lot of attention and causing people to think through their own security programs. There's a number of lessons learned here. And I think SolarWinds is a great depiction of what typical attack campaigns look like. And part of that attack, what they call the kill chain, is not only establishing initial access, whether it's through SolarWinds, so some Trojan piece of software, whether it's exploiting a known vulnerability or some misconfiguration in a system, spearfishing some user, there's lots of paths in. One of the critical things that attackers do, one of the most critical things and most urgent things they do is escalate privileges so that they can get or compromise privileged accounts so they can get access to the information they want, and then creating additional accounts and creating back doors for them to enter a network or reenter a network if you discover their presence and if you try and shut them out through whatever primary means you've identified. So both of these things are the types of things that Alsid will identify from a configuration and from an assessment standpoint, and also provide the ongoing monitoring for and say, okay, well, new trust relationship was established. This account became part of this privileged user group and then types of suspicious things or the types of indicators that a compromise is underway. So we think both in the assessment phase as well as the attack discovery and recovery phase, Alsid plays, it can play an absolutely critical role.
Brian Essex
analystGreat. Great. And then I know you've got a lot of details in the release. I just want to, a question for Steve. Obviously, it's a pretty high multiple relative to some of the others in the market. I think about, I guess, the data in the release implies over 20x for 12-month revenue. How did you think about price? Obviously, it's an intellectual property acquisition, but maybe walk through that dynamic of the deal.
Stephen Vintz
executiveSure. And a couple of things come to mind. Number one, we look at build versus buy. This is a product that's very specialized, and there's a lot of domain expertise. The company was founded in 2016 and historically has been very product focused and engineering driven. So we're getting a best-of-breed technology in a very important market. Now we also consider the strategic importance and relevance here. This is expansionary to our TAM and an extension of our car VM use case. And so this certainly reflects our ability and our confidence to sell it, sell it to a similar buyer, selling it into the enterprise market, given our established distribution channels. It's hard to really take a revenue multiple for a company that spent a lot of time developing the technology and apply that on an LTM basis. So we think overall, the purchase price really represents and demonstrates our confidence and commitment to doing this and of course, this has great and strategic importance to us.
Brian Essex
analystRight. That's super helpful. Great. Maybe, Amit, back to you for a question on if we look -- start looking at the company on a broader level. And when we think about what we've heard from companies over the past year or so through the pandemic, we've heard a lot of conversation about digital transformation, or one accelerating digital transformation. Obviously, the threat landscape expands substantially when you do that. How has that affected the way that you see enterprises managing their security posture and it's all just accelerate, I guess, the priority of security. I mean security is always, I think, then thought of as an afterthought after you transform, then you think about security. Is that changing?
Amit Yoran
executiveWell, I think we saw during the pandemic, that security is not the top priority. As organizations face this radical and immediate shift to work from home, and an inability to go on-site to access data centers and the requirement to shift to cloud, transform to a cloud in a much more aggressive time line and way, the first order of business is keep -- make sure that you can keep conducting business. And then security became a very near-term follow-on step. Okay, this is what we've done. Now we need to understand that risk. So in many aspects, during a normal cycle, security can be a critical enabler, understanding the risk associated with migrating a specific application or suite of servers to a cloud can give you the confidence to do it, it can give you the planning, the opportunity to do that in a more secure fashion. So we think this -- being able to assess and understand the risk of these types of initiatives from a cybersecurity perspective are actually tremendously empowering. I think the asset acquisition is a great example of how the shift to the cloud can be done in a more secure fashion. When you shift to the cloud, when you migrate to work from home, there are fewer control points than you had when you were operating within a corporate building. And so in those types of environments, identity and authentication and all of the things around the user become incredibly important. And so that's where we feel the ability to audit, assess and provide ongoing monitoring for active directory and directory services is a very integral part of understanding Cyber Exposure and managing cyber risk.
Brian Essex
analystAll right. That's helpful. And I think -- I mean, you mentioned on your call that vulnerability management is becoming a strategic priority for CISOs. And we heard it from one of your peers on their earnings call last night as well. What do you think are the key drivers for increasing performance? And what do you think this means for VM spend over the next several years?
Amit Yoran
executiveWell, we're very bullish on the VM market and the opportunity in front of us. So as we look at vulnerability management more broadly, but specifically through the lens of our customers and what we're seeing out in the market, we look across the customer base, and we've got a terrific customer base, 50-plus percent of the Fortune 500, 30-plus percent of the Global 2000. We see that we're only about 30% penetrated in those accounts. And so there's tremendous growth potential. They may be covering one business unit, one geo, one specific application where that's required from a compliance perspective. But they're now thinking about vulnerability management and cybersecurity more strategically. So the ability to expand, the ability to grow by continuing to sell into the customer base, it represents a tremendous opportunity. We also see the ability to sell new asset types, so not just assessing traditional desktop servers, workstations, but assessing cloud-based infrastructure, assessing DevOps environments and containers, assessing web applications, assessing operational technologies and control systems in manufacturing and factory floor and power types of systems. So there's a -- not only growth in VM, in traditional IT, there's the opportunity to assess modern assets, and we're seeing a lot of traction. I think we called it out in our last couple of earnings calls, the increased momentum we're seeing building in that cross sell. And then also a lot of greenfield in vulnerability management, which people, sometimes surprises people. It certainly surprised me when I came to Tenable about 4 years ago. But we look at this, and we're trying to be transparent about it. So we consistently see that about 1/3 of our new large enterprise transactions are coming to us from greenfield. So they have no Tenable, they have no competitive VM product, no organic VM capability. They're relying on an annual audit or an assessment from a big 4 or a security consultancy. In addition to that, we're transparent about our new customer lands on our enterprise platform. Last quarter, it was -- it was over 400. And I'd say every quarter that I can recall, it's been over -- well north of 300. So we see a lot of expansion opportunity in the existing customer base. We see a broadening of the types of assets we can assess. And hopefully soon, active directory will be part of that. And we're seeing a lot of greenfield and not a lot of new customer acquisition, which are all very healthy signs for us that there's great market potential still ahead for us.
Brian Essex
analystGot it. That's helpful. And I guess on the competitive front, how does that -- how do you typically get your foot in the door? Is it maybe through either go testing Nessus and that gets into the organization or it becomes a more critical priority. So vendors look for best-of-breed and maybe there's a best-of-breed versus platform conversation. What -- how does that -- what's the typical entry point into a competitive displacement?
Amit Yoran
executiveYes. We do have -- the great news for Tenable is that we've got tremendous brand recognition and brand loyalty and trust in our Nessus product, which is really a sort of beloved foundational security tool to assess and audit systems. So we have tremendous respect, confidence and trust across the security community. When it comes to vulnerability management, at this point, we're the largest provider, and we invest very heavily in R&D, on the VM front more than our primary competitors combined, and we've been doing so over the course of multiple years now. So with lab testing, we have significantly more, 20-plus percent more coverage of vulnerabilities. We have 6 Sigma accuracy, so fewer false positives, fewer false negatives. And when you look at what the analysts and people in the security community say, we really are best-of-breed in that space. So that usually gets us an invite to the dance, if you will. And when you test the products, again, because of that level of R&D investment, but also because of the account management, the customer service, the support organization, the services that we offer and deliver, we show exceptionally well in competitive bake-offs and where there's a technical assessment, we almost always come out on top.
Brian Essex
analystRight. Fantastic. I guess, on the opportunities of market penetration, I also want to touch on MSSP penetration, which came up recently. So you're increasing investment in the MSSP channel, how do you anticipate that may impact the business now that you've got substantial growth of partners on that platform.
Stephen Vintz
executiveWell, we think MSSP is a new route to market for us and an exciting opportunity for us long term. It also reflects our investment in the product over the past couple of years with certain -- with product in hand, we now have -- we're now aligning the investment, to go out and add new partners. We've got hundreds of partners over the past couple of years, even brokered partnerships with some of the largest MSSPS. So certainly, a new route to market for us, one that we're excited about, one that we're making investments in. And keep in mind that we've always been committed to the channel. We're, I think, the only company in our space that works directly with the channel, whether we source the deal or the channel brings opportunities for us. And over the past couple of years, it's created a lot of leverage in our business. Years ago, 4% of our business was channel in. We said a couple of years ago, over 20% at the time of the IPO, and now it's even much higher. So in the past, we've been focused on going into new markets, working directly with our channel partners, our distributors and our resellers. Now with product in hand, we're making a commitment to the MSSP market, which we think long term, could be very compelling for us.
Brian Essex
analystRight, right. Excellent. Maybe I want to, on the product side, maybe an update on success and traction so far that we've gotten with Frictionless Assessment, since it was made available in the AWS marketplace, maybe around late November? How meaningful is that to the platform?
Amit Yoran
executiveFrictionless Assessment, it's something that we're particularly -- I'm particularly excited about. As you said, it came out late in Q4. And so early in the go-to-market with that. But it represents tremendous opportunity and a really strategic shift in how people think about and conduct vulnerability management, and how they can think about assessing the security of their cloud deployment. So for those of you that don't know, Frictionless Assessment allows us to go in through our cloud-native connectors, initially with AWS, to use the APIs that are available to us through AWS, to assess -- well, first of all, identify what systems exist, whether they're active or not within that AWS environment. And then to assess the security and integrity of those systems and their level of Cyber Exposure. And to do it without deploying additional agents and to do it without impacting their performance and to do it without introducing risk into those operating environments, which are often mission-critical. So in a typical cloud environment, historically, we may have visibility into, call it, 15% of their cloud-based assets because there's a reluctance to or a concern about deploying agents and impacting live mission critical systems. Then using Frictionless Assessment, we can literally just flip a switch and have a continuous and instantaneous understanding of vulnerabilities, risk associated with all of the systems in that AWS environment. So as you said, we're early in the go to market. We have many users at this point, using those -- leveraging those cloud connectors, testing a few systems with frictionless, but they're already asking questions about 5,000, how quickly can I turn up 10,000 or even significantly more systems in my environment? And the answer is immediately. All you need is licenses. You don't have to deploy any software. And so customer response here has been -- early feedback has been tremendous, and it's something that we're particularly excited about.
Brian Essex
analystGot it. And maybe I need to follow-up on that. You mentioned your cloud-native nature of that platform. And a question I get a lot from investors is, when they talk about Tenable, they ask me, is it cloud-native and it depends what product you're looking at. How do you think about -- and maybe this is a question for Steve around unit economics. But how do you think about building a platform with cloud-native versus hybrid in mind and how that benefits the platform longer term. How do you respond to investors that are looking for more exposure to cloud-native products?
Amit Yoran
executiveI'll start off and then turn it over to Steve. Everything that we've been doing for more than 4 years now is cloud-native by design. So if you look at our Tenable I/O platform, could-native, you look at what we're doing with frictionless, cloud-native. You look at what we're doing with DevOps and containers, cloud-native. You look at the ability to assess network effect, the ability to do benchmarking against peers, the ability to assess hygiene, your level of hygiene and preparedness against because, all of, Lumin, all of those things are cloud-native. That said, it's incredibly important to us because it's incredibly important to our customers that we also operate and enable hybrid capability and that we continue to enhance our on-premise products. So adding functionality like predictive prioritization. Yes. Cloud-native, we also added that functionality to our SC and for our SC customer base because it's an important capability that they need. And most of the enterprises that we work with, and I would say, almost all large enterprises, are not exclusively cloud. They're increasingly cloud. New technology is going into the cloud, but many of them, and I would say almost all of them have some amount or even a significant amount of on-prem and legacy infrastructure that's critical to them, that they need to be able to manage risk around. And so we want to make sure that, yes, we're cloud-native, but that we're not leaving or forgetting the risk associated with on-prem. I mean people could be cloud-native, but when SolarWinds pops or a SolarWinds-like incident rears its head, just about every government agency was concerned and potentially compromised and about 18,000 enterprises around the world were. So it's this hybrid environment that we think is mission-critical today.
Brian Essex
analystGot it. That's super helpful. And we've only got a few minutes left, so I didn't want to neglect some financial questions for Steve. I guess the first one, I've done after your earnings, you got a lot of calls and questions around your guidance. So maybe if you can help just kind of set the stage there, philosophy behind setting the guidance. I mean you've got a pretty good track record of meeting or raising, but how did -- and obviously, with the acquisition maybe it's a little bit higher now. But how would you frame that philosophy? How do you think about setting guidance for '21?
Stephen Vintz
executiveSure. Well, first, we're coming off of a great quarter. We grew CCB 20%. Short-term RPO, I think, was 21%. We talked about customer velocity. We added over 460 new enterprise customers, one of our best quarters ever, 66 net new 6-figure customers, that was our best quarter ever. So certainly transacting a lot of business during difficult times and a lot of large deals. So we are clearly having success in the market. And I think that's a reflection of our best-of-breed focus and our commitment to the market. We also saw an uptick in expansion rates. And we said on the backs of broader asset coverage and more cross-sell. If you look at the past couple of quarters, how it played out, when the pandemic for surface, we grew CCB in Q2, calculated current billings, 13%. We talked about some timing of deals that kind of came in late in the quarter that weren't invoiced and weren't reflected in that number. And then in Q3, CCB growth was 21%. If you kind of normalize the timing of some of this -- these deals, midyear, we grew 17% in the average of those 2 quarters. So now we saw only step-up in the fourth quarter. So by any measure imaginable, we clearly had a good quarter. That certainly gives us a lot of confidence, momentum going into the year. The CCB number is something that we haven't guided to in over a year. When the pandemic first surfaced, we talked about really how it's influenced by multiyear prepaid deals, early renewals, a multitude of factors that make it difficult to forecast. But given how the quarter's played out and our success during the year and specifically in Q4, we felt like it was the right thing to do to provide a CCB guide for the full year. It's a starting point for us. There's a lot of selling left. It also doesn't reflect some of the potential tailwinds from SolarWinds that could potentially lead to better spending environments. The new administration here in the White House certainly has a stronger bias towards cyber. And is advocating some pretty sizable spend with -- in the U.S. federal sector. We have one of the largest footprints in U.S. Federal. So we look at it and say, hey, going into this year, we have a lot of confidence coming off of a strong quarter. There are some things that are not contemplating the guidance, such as SolarWinds, which frankly, are difficult to estimate at this time. And also the timing of that, and we look forward to updating investors throughout the year on our progress.
Brian Essex
analystGot it. Super. With that, I think we're out of time, so unfortunately. So guys, congratulations again on the Alsid deal, and Amit and Steve, thank you very much for joining us for our conference. We really appreciate it. Thank you for all of you on the webcast. I certainly enjoy having you on as well.
Amit Yoran
executiveGreat, Brian. Thank you.
Brian Essex
analystHave a great day.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Tenable Holdings, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Tenable Holdings, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.