Executive readout · one minute
Call research workspace
Read the call alongside every captured source. Transcript, 8-K earnings release, 10-Q stay in one workspace.
Earnings call · FY2020 Q2
Executive readout · one minute
Read the call alongside every captured source. Transcript, 8-K earnings release, 10-Q stay in one workspace.
Research coverage
3 live sources
Open each available source without leaving this research workspace.
Open the source you need; every reader stays inside this workspace.
How the reported period landed and where the business moved.
Read the call
Read the speaker-labelled prepared remarks and analyst questions.
Ladies and gentlemen, thank you for standing by, and welcome to Qualys Incorporated's Second Quarter 2020 Investor Call. At this time, all participants are in a listen-only mode. After the speaker's presentation, there will be a question-and-answer session. I will now hand the conference over to your speaker today, Vin Rao.
Good afternoon and welcome to Qualys' second quarter 2020 earnings call. Joining me today to discuss the results are Philippe Courtot, our Chairman and CEO; and Joo Mi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to future events or our future financial or operating performance. Actual results may differ materially from these statements. Factors that could cause results to differ materially are set forth in today's press release and in our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statement that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. A reconciliation of GAAP to non-GAAP measures is included in today's earnings press release. As a reminder, the press release, prepared remarks, investor presentation, and supplemental historical financial spreadsheet are available on our website. With that, I would like to turn the call over to Philippe.
Thank you, Vinayak, and welcome, everyone, to our Q2 earnings call. We hope that you and your families are healthy and safe. Our priority remains the health and well-being of our employees while continuing to address and support the changing security needs of our customers. Since mid-March, we have seen at Qualys a seamless transition to a remote workforce environment and have continued to effectively deliver on all aspects of our business, including product development, operation, and support services. The unprecedented environment with the ongoing COVID-19 pandemic has created uncertainties for individuals and organizations across the globe. As companies are experiencing a never-before-seen explosion of remote endpoints connecting to critical assets of their organization, security of these endpoints is paramount. IT teams are responding to the challenge of ensuring that employees are able to work productively and securely from remote locations, and it is becoming clear that traditional enterprise security solutions deployed inside organizations' networks are ineffective for protecting these remote endpoints. We believe that Qualys is one of the few companies well-positioned in this security market evolution due to our priority of investing in the scalability and capabilities of our platform and our cloud-based architecture. Upon the onset of COVID-19, we addressed the needs of our existing customers by promptly releasing a remote endpoint protection service that will help them quickly address the challenge of securing these proliferating endpoints. This service, which we are providing at no cost for 60 days, leverages the Qualys Cloud Agent and its cloud-based architecture to deliver instant and continuous visibility of remote computers, as well as their installed applications. It provides a real-time view of all critical vulnerabilities and misconfigurations and remotely deploys missing patches for critical vulnerabilities. These patches are delivered securely and directly from vendor websites and content delivery networks, ensuring there is little to no impact on external VPN bandwidth. In Q2, we added malware detection capabilities to the solution, and customers that were already using the service could extend their free 60-day license for an additional 30 days. Malware detection uses file reputation and threat classification to detect known malicious files on endpoints, servers, and cloud workloads. In addition, this service is now available to US federal agencies with a no-cost 60-day pilot. We currently have over 650 companies, including nearly 300 customer prospects actively using this free offering. The Remote Endpoint Protection service is based on the multifunction Qualys Cloud Agent, which instantly provides visibility to remote endpoints, detects vulnerabilities, manages their security hygiene proactively, and patches them quickly at no cost. Our Cloud Agent is the technology platform for seven of our security compliance and IT solutions: Vulnerability Management, Policy Compliance, File Integrity Monitoring, Indication of Compromise, Patch Management, Asset Inventory, and the upcoming Certificate Management, with more to come. In Q2, we continued to see strong growth in our paid Cloud Agent subscription, with almost 43 million now, representing 81% growth from the prior-year quarter. We have continued to make strong progress on our goal of achieving ubiquity for our Cloud Agent. After organizations download our Cloud Agent once, it becomes frictionless for them to subscribe to our paid applications because no additional infrastructure is required to expand the solution with additional products. Furthermore, this multi-product adoption naturally increases the stickiness of our platform and makes us impenetrable to our competitors. Our competitors do not offer the same breadth of solutions or ease of adoption. This is demonstrated by the fact that the growth dollar retention rate of enterprise customers who have adopted five solutions or more stands at 99%. Our Qualys Cloud Platform, combined with the capabilities of the powerful lightweight Cloud Agent, virtual scanners, and network analysis passive scanning, allowed us to create an effective and seamless Vulnerability Management solution that incorporates the four key elements of discovery, assessment, prioritization, and patch management into a single application called VMDR, Vulnerability Management, Detection, and Response, which went into general availability in April. The solution has been a huge success with our customers, and it's also driving further penetration of our Cloud Agent. VMDR takes Vulnerability Management to the next level by continuously detecting vulnerability and misconfiguration across the entire global hybrid IT environment and responding in real-time to remediate assets that are vulnerable or already compromised on a single platform with built-in orchestration. Currently, 600 customers have adopted VMDR, which includes approximately 200 new customers. In fact, 8 million out of our roughly 43 million paid Cloud Agent subscriptions have come from VMDR, of which 5.8 million were new agent subscriptions. VMDR has not only helped proliferate Cloud Agent but also sets a foundation for further upselling of our other paid applications. We continue to see good adoption of our free Global IT Asset Inventory, with almost 14,000 companies signed up and over 1,350 companies actively using the service. In terms of our other newer solution, we have continued to see strong customer adoption of our Patch Management solution, both in the mid-market segment as well as with large customers. In Q2, a large IT service firm selected our Patch Management application over several competing solutions due to its ability to easily and effectively patch remote endpoints without using limited bandwidth available on VPN gateways. This quarter, we also saw robust growth again for our Container Security application with a major enterprise video communication provider that has already deployed VMDR across its infrastructure adopting the solutions. In addition, our File Integrity Monitoring application continues to see solid momentum with a large Asian airline, having selected our FIM solution over a competing point solution in order to effortlessly leverage the Qualys Cloud Agent they had already deployed for Vulnerability Management. Now diving deeper, we were also early to recognize the importance of capturing all necessary telemetry via our sensors and the Internet while building the backend with the scale and computing capabilities needed to handle such a large volume of data. Today, we handle more than 9 petabytes of data, indexing more than 7 trillion data points on our Elasticsearch clusters, moving 14 billion messages a day on our Kafka bus, storing 400 million objects in our Ceph clusters, and pumping 1 million writes per second in our Cassandra log analysis engine. As a result, our highly scalable cloud-based platform enables us to address all four new market segments: Large Enterprise, Cloud Providers, the next generation of Managed Security Service Providers, and OT and IoT environments, providing a single pane of glass view across on-premise assets, endpoints, cloud, and mobile environments. Last month, we introduced our Multi-Vector EDR solution that moves well beyond the endpoints, not only reducing false positives but also making it easier to activate the response and greatly reduce response times and costs. As an app built natively on the Qualys Cloud Platform, our Multi-Vector EDR leverages power, scale, and accuracy to provide unprecedented visibility and telemetry by collecting security data from endpoints, adding context, and correlating billions of global events with threat intelligence, analytics, and machine learning. To strengthen our entrance into the EDR market, we acquired a software asset from Spell Security, a very innovative security startup in India, and now all security employees have joined Qualys in Pune. The team has unique expertise in threat hunting and malware research, as well as deep understanding of multi-vector attacks. They also have threat hunting products that will be fully integrated into the Qualys platform. Traditional EDR solutions singularly focus on hunting and investigating endpoints, malicious activities, and cyberattacks. Qualys' Multi-Vector approach provides critical context and full visibility into the entire attack chain by providing a faster, more automated, and comprehensive response to protect against those attacks. We are delighted with the strong adoption of VMDR by both our customers and managed security service providers, and by the interest that Multi-Vector EDR is generating with them. Moving from VMDR to Multi-Vector EDR is almost instantaneous as it only requires an update of our Cloud Agent, which is automatically done by our platform once the application is enabled. We're also pleased to announce that Infosys managed security services has now adopted both VMDR and Multi-Vector EDR. And here's a quote from Vishal Salvi, CISO and Head of Infosys Cyber Practice: 'We are pleased to partner with Qualys to deliver VMDR and Multi-Vector EDR solutions via our globally distributed network of the Infosys Cyber Defense Center. The highly scalable Qualys Cloud Platform will be deployed with agents and sensors and its forthcoming incident response capabilities provide us with the intelligence and analytics we need to effectively protect our clients and allows us to consolidate our security stack.' At Black Hat, we also discussed our upcoming Data Lake/SIEM solution, which we expect to have in early beta by the end of 2020. This is an important milestone and new opportunity for our company as current incident response solutions have become quite complex and costly, requiring organizations to use multiple vendors to collect the data needed and bring it into their SIEM with fully contextual information. Qualys' unique advantage is that we can leverage our robust scalable back-end and its array of sensors, which collect, enrich, normalize, and correlate trillions of data points across on-premise, endpoints, cloud, mobile, and soon OT and IoT environments. On the hiring front, we are pleased to welcome back Joo Mi Kim as Chief Financial Officer of Qualys. Her extensive finance, strategic planning, and investor expertise will be instrumental as we continue to expand the Qualys Cloud Platform and grow the company. We are also delighted that Ben Carr has joined Qualys as Chief Information Security Officer. Ben is a proven information and risk executive and thought leader with more than 25 years of experience in executing long-term security strategy. At Qualys, he is responsible for providing cybersecurity guidance and security strategies to Qualys' customers, leading the CIO/CISO Interchange, and securing our IT infrastructure. Finally, we are also honored to welcome John Zangardi to our board of directors. John has extensive experience in digital transformation and has successfully transformed the infrastructure of both the Department of Homeland Security and the Department of Defense, as well as modernizing their cybersecurity operations. We are grateful to gain his valuable insight and guidance as we continue to expand our Cloud Platform to deliver innovative security and compliance offerings. In summary, because of the very nature of our business model, which is nearly 100% recurring and the fact that our solutions have become mission-critical, we have greater visibility than many other security companies in our industry even in such difficult times, not to mention a highly profitable and cash-generating business model. Our product and platform achievements lay the foundation for our continued progress to enable customers to consolidate their security, IT, and compliance stacks while drastically reducing their spending. Importantly, this is core to the highly profitable recurring and growing revenue model we've built. With that, I'll turn the call over to Joo Mi to discuss our financial results and guidance for the third quarter and full fiscal year 2020. Thank you.
Thanks, Philippe, and good afternoon. Before I start, I'd like to note that, except for revenue, all financial figures are non-GAAP and growth rates are based on comparisons to the prior-year period unless stated otherwise. We're delighted with our increasing Cloud Agent subscriptions and multi-product penetration as well as strong adoption of VMDR, which lays the foundation for future revenue growth and industry-leading profitability. Our Q2 financial and operational highlights include revenues for the second quarter of 2020 grew 13% to $88.8 million. Please note our Q2 2020 calculated current billings were negatively impacted by the timing and amount of prepaid multi-year subscriptions, as well as requests for shorter duration invoicing, which we expect to continue to next quarter given the current market conditions. Our average deal size increased 7%, and platform adoption continued to increase as a percentage of enterprise customers with three or more Qualys solutions rose to 54% from 44% and the percentage of enterprise customers with four or more Qualys solutions increased to 38% from 24%. Paid Cloud Agent subscriptions increased to 43 million over the last 12 months, up from 38 million for the 12 months ended in Q1 2020, with 19% of the end customers up for renewal in the quarter renewing into a VMDR subscription, up from 4% in Q1. Our scalable platform model continues to drive superior margins and generate significant cash flow. Adjusted EBITDA for the second quarter of 2020 was $42.8 million, representing a 48% margin versus 42%. Q2 EPS grew 34%, and our free cash flow for the second quarter of 2020 was $24.9 million, representing a 28% margin and down 20% primarily due to recent changes in billing and payment terms for selected customers, given the current macroeconomic environment. Year-to-date, our free cash flow margin is 40%, and is up 6%. In Q2, we continued to invest the cash we generated from operations back into Qualys, including $4.3 million on capital expenditures for operations, including principal payments under capital lease obligations, and $25.3 million to repurchase 242,500 of our outstanding shares. We remain confident in our business model, driven by our foundation of nearly 100% recurring revenues and expanding suite of applications. We are delighted to be raising our full-year 2020 guidance for both revenues and earnings. We are raising the bottom and top end of our revenue guidance for the full year to now be in the range of $359 million to $360.5 million from the prior range of $354 million to $359 million. We are raising our full-year non-GAAP EPS guidance to now be in the range of $2.60 to $2.65 from the prior range of $2.46 to $2.51. We expect to maintain industry-leading margins in 2020 and continue to produce strong cash flow. And our Q3 guidance for revenue is $91.6 million to $92.2 million and for non-GAAP EPS is $0.65 to $0.67. For the third quarter, we expect capital expenditures to be in the range of $8 million to $9 million, which includes approximately $2 million for the build-out of our Pune headquarters. Due to COVID-19-related delays, the timing of spend on our Pune headquarters has been pushed out a few months and we now expect that $2 million of our original planned spend will occur in the second half of the year. As Philippe mentioned, we are very excited by the robust early adoption of VMDR and the launch of our Multi-Vector EDR application. We feel very well-positioned during this period of uncertainty due to the value provided by our Cloud Platform and our 20 apps, as well as our underlying highly scalable and profitable operational model. With that, Philippe and I are happy to answer any of your questions.
Thank you. And our first question is from Erik Suppiger with JMP Securities. Please go ahead.
Hi. Thanks for taking the question. Can you talk a little bit about linearity? How did the pandemic play out through the quarter?
Yeah. I'll take that question. So, linearity, we didn't see any material highlights to note under linearity. It was similar to last quarter.
Okay. And then on VMDR, can you talk a little bit about how much adoption you've seen with – of using the Patch Management component to that?
So we have a big demand for Patch Management. There's no question that this is an application that is really coming up and VMDR makes it much easier because obviously the last mile is you patch and it's at your fingertips. So, yeah, it's very significant. And we see what's really interesting is both on the mid-market, but as well as with large enterprise. In fact, I mentioned on the call that we had a large enterprise which really adopted not only VMDR but they also adopted a big deployment of Patch Management.
And who are you displacing or who do you see on that patching front? Is that BigFix?
Yeah. It's interesting is that it's not so much of the displacement, it's fact that it's become – it starts more like adding, for example, is much easier, of course to – with our solution to patch the endpoints. So we, in fact, believe in some cases, they could continue using, for example, SCTM for other solutions, but on the endpoints, it's much easier to do it with Qualys, so – and other Patch Management solutions. But essentially, it's adding to what they are doing. And we see more and more appetite to essentially move to a solution at Qualys, which integrates their entire – from discovering new assets to identifying the vulnerabilities on those assets, to prioritize the remediation, and then remediating. We also have, by the way, the integration with some customers; they don't take the full Patch Management solution, but they take all the information that we provide them with the superseding patches and so forth, so they can continue pushing that into their own Patch Management solution.
Very good. Thank you.
Thank you. Our next question comes from Shebly Seyrafi with FBN Securities. Please go ahead.
Yes. Thank you very much. I want to drill down on the current billings. It looks like it grew by 13% year-to-year, down from 15% the prior two quarters. And I saw what you said in the script, so what would current billings growth have been versus 13% reported had duration not changed or declined?
Yeah. So we have a healthy business. It's a little difficult to specifically normalize growth rate to account for the multiple different impacts because, for example, one of the reasons why it impacted is because the renewals were not done at the anniversary of the initial deal. There could also be changes in billing terms that we've highlighted in terms of the shorter duration billings as well as the amount of pre-paid subscriptions that have a negative impact basically in the first year upon renewal, you see that fluctuation. And so what we'd like to point to is year-to-date consolidated current billings are up 10% from last year, which supports why this trajectory of our annual revenue guidance is the best proxy for business momentum with our current bookings confirming our guidance. If you take a look at our annual revenue guidance, we did raise this basically from – the prior high end is our current low end, and our bookings actually came in better than expected this quarter, especially from new.
I want to correct myself, current billings was up 7%. Like you said, 10% for the first half, but I'm trying to see because you expect these moving parts to linger, looks like for the next few quarters. And I just want to know when you think things may normalize such that your current billings growth can go back to the historical something like 15% or so. Do you think it's two quarters long or four quarters long?
I think it's a little too early for us to talk, given the uncertainty of the environment. Basically, at this time, we are leveraging our strong financial position to accommodate customers that are asking for shorter duration invoices as well as the late billings, which is another factor that we should take into account in addition to the renewals not being done at the time of the end like renewal.
Okay. Last one for me is Spell Security. Do you have estimated incremental revenue and expenses for that company?
Yeah. So for Spell Security, it's a small tuck-in acquisition, similar to what we've done before. We don't see a material impact to our top line or expenses from that acquisition.
Okay. Thank you.
Thank you. Our next question comes from Alex Henderson with Needham. Please go ahead.
Thank you very much. I was looking at the revenue associated with the customers that have bought the highest number of units, and it actually shows the revenue declining from $270 million to $257 million, even as you're adding more revenue per customer. And I was wondering if you were including in those statistics any of the free solutions that you're offering. How – why is it – why is the average revenue declining on your top customers?
Yeah. Average revenue on the top customers could fluctuate depending on the category that as customers move into different categories. And another factor that we should consider is we're relooking all their metrics to make sure that they're all still relevant to customers. I think that one of the metrics that we've highlighted before is the multi-product adoption. With the launch of VMDR, VMDR is really counting as – we're counting it as core product. What we said before is generally we expect it to be a revenue-neutral impact because, for example, for VM-only customers, we do expect them to see some uplift as they renew into VMDR, where some other customers who used to collect – like several other Qualys products, they may be spending a little bit less.
So, are you including in that any of the free solutions or is that not included in the number of solutions?
No. It only includes the paid solutions and it's incremental solution that's being added.
Great. So, the second question with the – you've obviously got a lot of free stuff out on the market today. You talked about Patch Management and the free Asset Inventory, a number of programs. If you were to tally all of those free customer subscriptions up, what type of sum are we talking about? How big a chunk of business would that be? And to what extent – I'm assuming that that predominantly starts to roll off the free into some of the paid version of it. What type of conversion rate do you expect? And I think that's mostly in the fourth quarter, is it not, since most of that runs through September?
Right. So, one thing that I'd like to highlight is because we're a subscription business, our model is to really allow customers to buy at their own pace. Customers do trials and then often expand at the time of renewal for existing customers. We realize that with several of the products that we've launched, it's great that we're seeing adoption and some traction in terms of the active usage both with respect to the Endpoint Remote Protection as well as the Asset Discovery and Inventory. We are tracking it, but at the same time, we don't – it's not that we expect everyone to convert to paid. We wouldn't be surprised if some people continue to use our free service, which is fine, because we don't offer free service as a half-baked offering. We really don't push products to customers. We really see it as based on the customers' need, and we do expect some to convert. I do think that's a little bit early given that a lot of the products are fairly new.
...any of those products, so that would then force them to make a decision?
Yeah. So let me add on the Endpoint Remote Protection, 60-day free trials as we do have at least – and we estimate we can see that there's very happy customers. In fact, some have even deployed very largely. So we expect to see some of these customers convert to the paid subscription when the program ends, as you mentioned, that will be at the end of September. Of course, we have other services which have been very successful, like the Global IT Asset Inventory, which is used more for lead generation and that are now today fully integrated with VMDR. So, as you can see, we've skinned that cat in different ways. One way of looking at these paid services is to look at them as lead generation creating, of course, exposing the power of our platform to customers. We have a team to onboard them and to upsell them as well. This is part of our marketing strategy. It's a very cost-effective marketing strategy because, for us, we can deliver software at a very cost-effectively.
Okay. Thank you.
Thank you. Our next question comes from Yun Kim with Rosenblatt Securities.
Thank you. Congrats on a pretty solid quarter and welcome, Joo Mi. Philippe, one metric that really stands out in the quarter is the acceleration in the adoption of multiple products, growth in the percentage of the customers with 2+, 3+, 4+, 5+, all accelerated from prior trends, not just 4+, products. Can you specifically point out anything particular that drove that acceleration in the quarter, and what are you expecting in terms of that trend going forward?
The trend will continue. What you see with some of these – it's a combination of a few things. With some of these products is the maturity that we are reaching with these products. We see that very clearly with File Integrity Monitoring. We are also seeing, of course, Patch Management, has been also a very good uptake while waiting to get the Unix and the IOS patch capabilities, which are coming in a couple of months, if I recall correctly. It's imminently going to boost further the adoption. Of course, we see more and more is the interest in the platform itself, where you've got all the solutions integrated. VMDR is a huge success and it addresses not only essentially – all of our customers have no reason to look for other solutions today. This also helps us in penetrating and displacing current competitors. So, VMDR is a big success and we anticipate with the Multi-Vector EDR, which, of course, is brand-new, will go GA at the end of the month, early September the latest, that we have already significant interest with Multi-Vector EDR. Remember, one thing is that for all of our customers that have the agent already installed, moving to EDR or Multi-Vector EDR is a no-brainer. They can immediately try and buy essentially. So that gives us a huge advantage with all these agents that we've now deployed.
Okay. Great. Thanks for that. And obviously now, with the initial success with the VMDR and a lot of high-profile product launches ahead, it's pretty clear that you have a platform strategy that is beyond your core VM footprint. Can you update us on any major go-to-market initiatives you may have planned to support all the product launches and where you are in terms of that product positioning today? And in that regard, any plans to increase sales and marketing to support this? Perhaps any new sales and marketing initiative to accelerate adoption in the marketplace?
Yes. This is a very good question. Our strategy since day one was to really build that multi-platform. It has been a huge undertaking, which we've been able to do because of the significant engineering team that we have now in Pune, India. We're close to 900 people. That was not a walk in the park. It was very complex. We had to inject a lot of the newer technologies like Elasticsearch, etc. So, that's where our focus has been. At the same time, not only beefing up the computing power of the platform, but also acquiring telemetry. The problem today that you see with security is that in order for you to have context, you need to build – you need to collect data from multiple different applications, and you have very little idea of how good that data is. And that's the problem that the SIEM today faces. It's costly, it's complex, but then to correlate, to analyze, to enrich that data is also not that easy. That has been our overall strategy. So today, finally, our platform and VMDR demonstrated that we could now integrate all the solutions. Multi-Vector EDR is our ability now to go well beyond what the current EDR solution offers, because we have significantly more telemetry. Our next big theme is to essentially move into the SIEM space, which I mentioned earlier, we are planning to go beta in at the end of the year. One of our unique abilities is automatically creating the Global IT Asset Inventory; you cannot secure what you don't know, end of the story. That ability allows us to provide the necessary context. We get that from the combination of our agent, which brings information and our passive scanning and network analysis, bringing all that data into one single platform. We are beginning to prefer solutions that carry significantly more dollars, when you look at the EDR marketplace, for example, the EDR marketplace is not just endpoints, but the fact that you have many of them. And when you look at SIEM, it's a significantly bigger standpoint. To answer your question, we are expanding our marketing and sales capabilities to bring these solutions to market. We have a large customer base which is a huge advantage, of course, because we can bring very cost-effectively those solutions to our customers. Our go-to-market strategy includes that we now have a platform that becomes very attractive for managed security service providers, as they need to move beyond monitoring to response, which is what Qualys provides. We already have a large number of managed security service providers using Qualys. They are all moving into VMDR, and you saw the announcement I made about Infosys, adopting the EDR solution. We see that as another channel to bring these solutions to market, as well as consuming our incident response solution, core to managed security service providers.
Great. Thanks for that detail. But one question I do have on that is that do you plan to accelerate the sales headcount addition for your sales team?
The big advantage we have is that, in proportion, because we are going to be able to do bigger deals. Of course, you get more – you can spend more as a result. It's not going to change really our profitability. We're not going to deploy a lot of salespeople again. Our model is try and buy. It's very effective. Again, I mentioned our managed securities channel. We see that as a very big channel to bring all these new solutions to market. This doesn't mean we need to put a lot of salespeople in the field, but yes, we are building and expanding our sales force everywhere.
Thank you. Our next question comes from Hamza Fodderwala with Morgan Stanley.
Hi. Thank you for taking my question. Philippe, I was wondering if you can comment a little bit more on the competitive landscape in Vulnerability Management and the sales cycles for Q2. Because, clearly, I think as far as your solutions are concerned, providing more visibility and efficiency in a more distributed work environment, the prioritization of that is clearly increasing, but we're not fully seeing that reflected results quite yet. So, I'm wondering if you could comment a little on those two aspects, sort of the sales cycles, and the competitive environment.
Sure. The sales cycle has not changed essentially. If you look at the enterprise market, it is much more a displacement market. In the mid-market and the small enterprise, it's a much more rapid market, but the sales cycle has not fundamentally changed. What has changed today is, with the entrance of VMDR, we have totally differentiated our solution vis-à-vis competitors. Today, we have two main competitors, or less, I should say, are Tenable and Rapid7. Tenable is essentially a VM company; they don't have the platform that Qualys has. Rapid7 is a quality company, which essentially gave them a kind of a SIEM platform. Today, Qualys is entering that SIEM market, and we don't see them competing that much more on the VM side. They are more essentially moving, and their growth is coming from that low-end SIEM market that they have addressed. We are coming up with what we call the next generation of SIEM, which goes well beyond the mid-market and targets large installations as well. We are extremely well-differentiated against traditional competitors. The question becomes, who can build out the platform that Qualys has built and how long it will take them. We have been working at that for a long time; this didn't happen overnight, and we have focused on that, and today, we feel very happy. With the VMDR introduction, we've demonstrated the power of what we've done. Now with Multi-Vector EDR and very soon with our incident response solution, which is entering alpha now, and that we plan to go beta at the end of the year.
Got it. Thank you. That's helpful. And then just one quick follow-up for Joo Mi.
Sure.
Any way you could quantify perhaps the impact of the shift toward lower durations and some of the renewal timing that impacted current billings?
Yeah, we're tracking that internally. In terms of the shorter duration invoices, we've experienced a couple million impact to that. With that said, one of the reasons of why we're not actively managing the quarterly billings is because we have industry-leading margins with our operating cash flow margin at 33%. We wanted to make sure that we take this opportunity to leverage that to help out our customers where it makes sense. We do expect to get paid at the end of the day, and this is part of the reasons why we've highlighted that we've had a great quarter, where the bookings came in higher than what we expected. Billings are just not indicative of the billings bookings performance this quarter.
Got it. Thank you very much.
Thank you. Our next question comes from Brian Essex with Goldman Sachs. Brian, your line is open.
Apologies. Yeah. I have mute on. Good afternoon. Thank you for taking the question. Philippe, I was just wondering if you could maybe give us a sense of conversations that you're having with customers, particularly after what we've seen high demand for endpoint identity firewall spend, are you seeing any derivative spend now that these more disparate networks may need to focus on security posture now that they've addressed those kind of initial concerns in a more distributed environment?
I'm not so sure – could you repeat the question? I'm not sure that I understand.
Yeah. I'm just trying to get a sense of the conversations that you're having with customers from a budgeting and spending perspective, particularly after we've seen high demand for the obvious work-from-home solutions.
Yeah. Okay, makes sense. What happened is that COVID has highlighted for a lot of companies the fact that their enterprise security solutions just don't – they are not built for that world where essentially everything is connected with everything across the Internet. That became very visible. The first visibility is how do you patch a system which is outside of your network? It creates a lot of difficulties. Companies had to buy more VPNs, more of this, more of that. It has given the wake-up call that it's about time that people rethink their security infrastructure and layering on all these enterprise security solutions is not only costly. The move to the cloud is happening in our industry. There's no question. It used to be that our industry was very resistant to the cloud for security reasons, and now minds are changing. Our discussion with customers is about consolidation. That's their number-one priority. They cannot continue spending so much money maintaining disparate solutions; they don’t even find the people to do that. They're looking for solutions like Qualys, which consolidates as many solutions as possible. This was our vision, it took much longer to get there than we thought. Building the platform was far more complex than we thought, but we kept going, if I may say so, and it serves us well. You also see that our agent – one single agent provides a global view that people are looking for. We see today a lot of interest in our Multi-Vector EDR. This market is growing fast because of the need you just described, but it's also a market that requires a lot of consolidation as well. I think we're very well-positioned.
Got it. That's super helpful. I just want to follow-up with maybe one for Joo Mi. I think someone touched on earlier about – particularly for enterprise customers with over four solution stacks, LTM revenue per customer coming down slightly, but it looks like if you look at all the categories, you're coming down. So, I guess I'm wondering what are the other categories? How are those affected and what are the drivers of that? Maybe it's a customer growth issue or a mix issue.
In terms of some of the other categories, some of it is attributed to the fact that we've rolled out a lot of smaller solutions. With the newer solutions that are coming out, we're expecting them to be priced similarly to VM. We anticipate this will rise ARPU over time. For example, we talked about Patch Management, FIM, and IOC, that will have a similar deal size, whereas some of the smaller solutions we've launched, like Continuous Monitoring, is not priced as high.
Got it. But, I mean, if I look at this, can I infer that – it looks like it implies that just overall revenue per customer has gone down. Is that not the case?
Overall, the average deal size we mentioned in the prepared remarks, it is up 7% year-over-year.
Okay. All right. Thank you very much.
Thank you. Our next question comes from Gur Talpaz with Stifel.
Okay. Great. Thanks for taking my questions. Philippe, you noted that you've added malware detection this quarter alongside the launch of EDR. I want to understand more broadly what your confidence threshold here is in competing in more traditional endpoint markets. And I think beyond that, what are you seeing in terms of customer interest thus far?
There's a very big interest. The Malware Detection that we added with our 60-day free Endpoint Protection is detection, not response, because we didn't have yet the capabilities of response in our agent, and that's what is coming up with Multi-Vector EDR, which gives you the full solutions. The differentiation between our solutions and other solutions is that all endpoint solutions today only have information about the endpoint. We have all the telemetry, we can look beyond the endpoint, which is important. We have a technically advanced solution that allows you to do certain things much more easily because it provides access to all that information, and with the capability, you don't have to go fishing, as I call it. We think we have a very good solution. The advantage we have is that we have a large usage of our Cloud Agent, and for us to upgrade to – for our customers to look at the solution, it's easy because it involves an instant update of the agent to give them that response capability I just discussed. We have already customers in the field that can try our Multi-Vector EDR. We call it Multi-Vector EDR because the attacks are multi-vectored. It's not only about the endpoint; you need to know what that device connects to because the device could be attacked from another part of the network. That's why you need that full view, not just the endpoint view.
That's helpful. Thank you. And Joo Mi, maybe one for you, just kind of building on the last question, how should we think about products like EDR and SIEM serving as the lift, if you will, to the ASP or average deal size?
We are very optimistic about this. With the launch of VMDR followed by EDR and Data Lake and SIEM coming after, we believe this will drive our ARPU higher, increase the dollar retention rate, and drive acceleration in revenue overall.
Thank you. Our next question comes from Matt Hedberg with RBC Capital Markets. Please go ahead.
Hey, guys. Thanks for taking my questions. Philippe – and maybe I missed it, but – or could you comment on sort of some of the geographic trends you did domestically here and then overseas in terms of when economies start to reopen?
I think we see – yeah, I think the US is our market. We're not seeing, in fact, much difference fundamentally between all the markets, and we see very, very good adoption in Europe and in Asia Pacific as well. So, we have not seen significant reduction in demand. The reason is simple; we have nobody working in our offices, obviously. However, this is our network that we need to maintain continuously because that's a network that connects us together. You need to secure that network; that's why we have not seen a significant reduction in the demand. We see conversely a lot of companies asking for price concessions, payments, etc. We see, of course, some companies that are going bankrupt or will go bankrupt, that’s the dynamic. For us, instead of speaking of reduction, we try to change the debate, saying 'why don’t you consolidate? You spend so much maintaining disparate solutions, why not take a solution like Qualys, which integrates everything and drastically reduces your total cost of ownership?'. You don’t need to worry about the integration between different solutions; it’s all done for you and you don’t need to worry about the infrastructure cost because this is a cloud-based solution. We are extremely well-positioned.
Got it. And then I know you've taken a very active role in sales, effectively running sales for several years, but I believe you promoted Laurie to EVP Worldwide Field Ops last year. As far as I can tell, I don't think she's with the company anymore. I'm wondering if you could comment on that and just sort of like the overall sales initiative.
As you know, we have replaced Laurie, and in fact, as you know, we have very long-term employees at Qualys, but not everyone stays forever, obviously. Now we are very well positioned here. We have, in fact, promoted somebody from within to take her role and who is doing very well. Again, as I mentioned earlier, we are looking at expanding our sales force today. We are well-positioned to getting there.
Thank you. Our next question comes from Sterling Auty with JPMorgan.
Yeah. Thanks. Hi, guys. I think you mentioned a couple of times on the call that bookings in the quarter were stronger than expected. Early in the call – in the Q&A, you mentioned linearity was the same as it was last quarter. If that's the case, then I guess – I wonder why wasn't revenue in the quarter actually stronger than the reported number?
Revenue – when we guided to the revenue, it was $88 million to $88.6 million and we actually reported a revenue of $88.8 million. It came in higher than what we had expected. Is that what you meant, Sterling?
Yeah. But I guess I would call that more in line with the top end of the range – or maybe were the bookings slightly above what you expected in the quarter?
Yes. And coupled with the fact that sometimes our bookings are based on a consumption model as well, given our established partnerships. We do have consumption-based utilizations that could be factored into it, but overall, yes, we were expecting our revenue to be somewhere in the midpoint of our revenue guidance range, and we ended up coming in a little bit higher at $88.8 million.
Got it. And then one follow-up on the VMDR and EDR. Can you remind us – I think you have some different pricing models, especially with VMDR. How is the uptake under that pricing model, and what should we take away about the revenue contribution looking like for this year?
The pricing model is different. We are now using an asset-based model which makes it simpler for our customers to procure. I'm not so sure that I understand exactly your question in terms of the impact on what.
On revenue for the year. So, given your new products, so not knowing how much contribution you expect to see in total revenue for this year, is it meaningful, is it de minimis, is it a slow ramp, a fast ramp?
No, no, VMDR is moving very well. We have a huge adoption of VMDR as mentioned in the numbers. This is very healthy business and it populates the agent. It makes us much more sticky because you have all of these solutions totally integrated. We think it's a huge success. VMDR is a huge success.
Thank you.
Thank you. And I’m not showing any further questions in the queue. I would like to turn the call back to Philippe Courtot for his final remarks.
Okay. Thank you all. We are very excited to see our new solution coming, VMDR. It's been a fantastic, as I mentioned earlier, solution. We're now bringing the Multi-Vector EDR. As you can see, we are now moving into detection and response, VMDR, EDR, and we have more to come. We are looking forward to launching our new incident response solution. Thank you for your time, and again, thank you very much.
And with that, ladies and gentlemen, we thank you for participating in today's program. You may now disconnect. Have a wonderful day.
SEC filing · Item 2.02
Filed Aug 10, 2020 · complete as-filed document
SEC periodic report
Filed Aug 10, 2020 · complete as-filed document