Skip to main content

QLYS Investor Event Transcript

Qualys, Inc. (QLYS)

Investor Event Transcript 2026-08-11 For: 2026-09-30
Added on August 11, 2026

Conference Transcript - QLYS 2026-08-11

Operator

Hi, everyone. Thanks for joining. Really excited to have Qualys team with us here again this year. We have Sumed Thakkar, president and CEO, and Jumi Kim, CFO. Thanks again for joining.

Sumedh Thakar, CEO

Thanks for having us.

Operator

Let's start with last week's results. It was an excellent quarter, accelerated current calculated billing at 16% in the quarter. Stock reacted well, beat across the board, raised the guide, operating cash flow up 77%. really validates your strategies. Just what else would you want investors to take away from the quarter?

Sumedh Thakar, CEO

I think we're very pleased with our execution in the quarter, and we continue to focus on profitable growth, and we have been a product-led, innovation-led company, and so a lot of what we innovated around remediation, patch management, has really been the key focus for a lot of the conversations with customers, and so we're looking forward to now working with our customers to make sure that their post-methods focus on risk remediation is something that we can work with them and we can convert that into good opportunities for us given that the last four or so years we have done a really solid job with patch management, which is the area of focus. So just excited about what we're doing right now and the feedback that we're getting from our customers. And The goal is to continue to focus on executing it.

Operator

So, ETM was a big component of the strength in Q2. Again, CCB accelerated 16%, and that was partly due to ETM forward customers. So, could you just give a better sense of maybe what that means? Were those wall-to-wall deals? Like, what were they buying? What was the uplift? And then, how do you think that will play out for the rest of the customer base, and on what timeline?

Sumedh Thakar, CEO

I think, like we said, at a high level, the focus for customers has really been the remediation part with Eliminate and patch management. And what we're seeing is to be able to do a good job of that, customers are also looking at ETM as a way to really prioritize, hyper-prioritize the findings that they need to fix immediately. And so what we really saw was the customers that were already up for renewal in Q2, we have been having conversations with them. And so when Mythos came about, they were able to go back and work with their teams and get some additional budget to essentially make those renewals and upsells be bigger than sort of what we had anticipated at the beginning of the quarter because of the conversation we had and the maturity of the tool set. So really at a high level, that's what kind of drove that, and we're looking forward to continuing similar conversations as we get into Q3, Q4 as well.

Operator

Jimmy, you've been pretty disciplined about saying that ETM is not going to significantly ramp NRR this year. Newer products can take time to penetrate the base, but I guess what leading indicators should we look at in front of the NRR growth?

Joo Mi Kim, CFO

Yeah, for us, we believe that ETM will be the primary engine to drive growth in the near term and in the foreseeable future. With that said, given that it's relatively new to our customers, we don't think it's going to be contributing much to our revenue, at least on a material basis. And this is part of the reason why we decided to share the net dollar expansion rate of customers who had either ETM or CSTM subscriptions at a year ago period. because if you take a look at that cohort of customers and how they continue to grow with Qualys and that as we take you through that journey, hopefully you'll be able to see the progress that we're making and it will really be a best indicator of the success that we're seeing in the ETM initiatives today. So with that rate at around 107% for this quarter as well as last quarter, we're very pleased with the amount of spend and as they continue to grow with us, whether it be just a VMDR cross-selling to ETM or adding patch management on top of that, and that's validated by the percentage contribution by the product bookings. If you take a look at it on an LTN basis, ETM and CSAM currently make up 12% of total bookings up from 9% a year ago. And the same thing with patch management. It currently makes up 9% of total bookings up from 7% a year ago. So you can see that our newer products are really helping to drive our growth acceleration in the top line today.

Operator

So you've been a 10% grower really subtly for the past couple of years, elite margins, high 40% EBITDA margins. So now we're talking about potentially accelerating long-term growth. And so I think that was a big moment, a big takeaway from Q2. So I guess what does that mean to you? What are your aspirations there? And then I guess what needs to go right from here to see moving more towards mid-teens or aspiration?

Sumedh Thakar, CEO

Yeah, I think, you know, we kind of saw this whole need for remediation was going to accelerate, and, you know, that really is, we stayed ahead of that, and we're excited to see that there is an opportunity right now for us to work with the customers to have them adopt that additional patching capability, remediation capability, and then a lot of the innovation that we have done around AI with our recent launch of Agent Val for validation, which is also something that we did very different from every other VM tool. And more recently at Black Hat, we launched Agents Insta, which is essentially the ability to get detections of latest vulnerabilities that are coming out within an hour of them coming out. So a lot of that is being looked at very positively by the customers. So there's an opportunity to move those customers from VMDR, a customer cohort where they're scanning but doing a lot of prioritization themselves to upgrade to ETM, which then will allow them to do the prioritization and then the ability to use Eliminate to do the actual remediation. And so we're looking forward to, you know, working through the conversations that we are currently having. We also announced the launch of TotalAI 2.0, which is really an area that is up and coming now, you know, when we talk word security for AI and AI for security. This is the focus on saying how do we also leverage our position with these customers where we are so widely deployed at a lot of large enterprises to be able to give them visibility into shadow AI as an example. And so I think as we look at the next few years, we feel like the focus on remediation that has come about, opportunity with the federal government, the capabilities around total AI that we are adding are things that make us feel like this is something that we can continue to focus on and set ourselves up for continued growth and potentially acceleration of that growth.

Operator

You spoke to some of this, but CISOs are frustrated, vendor lists are long, remediation needs to be a priority. I'm curious what you're hearing on budget growth or budget allocation. I mean, again, we're seeing a significant amount of money being poured into spending on AI, whether there's ROI or like at least on token and app development. But we're now beginning to see the full effect of, you know, what some of these novel agentic attacks could unleash on security environments. So I'm just kind of curious what you're hearing on budget growth or expectations of the next couple of years maybe that could impact ability to re-accelerate.

Sumedh Thakar, CEO

I think we always see this with our customer base, which is typically the larger enterprise customer base that, you know, just because the number of vulnerabilities or findings have gone 10x, the budget doesn't go 10x, right? And so I think what it is, and this is what we commented on the earnings call as well, is those customers are going back, really trying to understand what do they need to change as a process, not just a one-time jumping in and trying to change something, and how do you essentially peg the security as a percentage of what your spend on your IT is, right? And so as people are still trying to figure out what their spend on AI is, we do see in the next couple of years, you kind of start to see a certain percentage of that spend for AI tokens, et cetera, will also translate into certain spend on cybersecurity related to AI as well. But it's too early right now to know exactly where that will end up landing. but most customers are just right now at that early stage of saying who's using AI in my organization and then who's not using AI is also a question these days but that's kind of where everybody's sort of trying to figure out is if I know what the spread is then I can start to figure out what that potential spend can be so the conversations are that if there is a net new spend happening on overall AI and additional AI deployment in, then customers will look at figuring out some spend that will be focused on AI security as we move forward, but just too early right now.

Operator

So the idea that we want to move more towards a risk operations center or ROC outside of the SOC or just the VM, the vision for the ROC, what does that bring in addition to the SOC and the VM, and then how critical is it to integrate with a competitor's data, for example, or how is that maybe a surprising strategic advantage?

Sumedh Thakar, CEO

That's a great question, and I think it ties back to your earlier question as well. At the end of the day, the SOC was always built as a way to find if an attacker is in your environment by looking at their log data and correlating log activity from different sources to see if we can find an actual attacker in the environment and then block them. And that's where you've seen the evolution of SimXDR, et cetera, but it's what we call the post-breach side. I think on the pre-breach risk management, A lot of it just has been, oh, I have a dashboard for cloud security. I have a dashboard for endpoint security. I have a dashboard for container security. A lot of it is just dashboard tourism, but customers struggle to sort of make the point of, well, what is the risk to the organization? And that sort of goes back to the point that there is no framework or there has not been a framework like the SOC for post-breach or pre-breach risk management. And so the concept of a ROC, which is a risk operation center, that has really taken hold quite well with the conversations we've had because now CISOs see this as a way to have a business conversation as well about risk and how that relates to the business and the spend. And at the end of the day, when you talk about risk, you're talking about reducing risk of financial loss. If you're not able to quantify what that financial loss is, how do you decide how much you're spending? So a lot of the conversation about the rock are less about the technical capabilities and stuff like that in terms of like, Can I find this thing or that thing? But the idea that, you know, you still have endpoint risk, you still have cloud risk, and now you're going to have an added AI risk, and then you're going to have an added quantum risk in the future. How do all of that normalize together so that you can have a picture of what the overall risk to the organization is? And so in that model, the idea of the rock, being able to provide that quick inventory detection, validation, and then remediation is helpful, and the business conversation is helpful. But that also means that we really opened up the platform so that we can take risk elements from other tools that maybe are areas that we at Qualys don't really do anything in those areas. And or maybe a customer is committed in terms of having a different scanner for the next couple of years, but they're struggling with too many findings. They want to leverage the ability of a rock to tie to business and then figure out the validation and the remediation pieces. then we can open up to that. So with that, it also opens up the ability for Qualys to still make additional potential revenue on top of a different scanner that the customer might have and really opens us up to have the ability to pull data from other companies that are doing, say, mobile security and pen testing and different things so that we can give a holistic picture. So for us, The Rock is obviously a way to provide customers a more business-oriented risk dashboard, but then also for Qualys as a way to be able to create opportunities to make revenue on top of areas where the customer might be using another tool for detection.

Operator

Yeah, foundational. So back on ETM or enterprise to risk management, when you engage with the customer at that level, does the buyer change, or can we talk about the buyer persona? if the sales cycle, you know, at a more strategic level becomes lengthier, just thinking about upside to VMDR, and then where that spend comes from, if it's from SIM or just net new spend?

Sumedh Thakar, CEO

Yeah, I think the buyer is still primarily continues to be the CISO. I think sometimes when we talk about risk and financial risk, et cetera, we do end up talking here and there with, like, the chief risk officer and the company is sometimes the CFO, but primarily the buyer is still the CISO. However, when you talk about deploying patch management and remediation, which everybody's looking at, then they have to bring in additional stakeholders. They have to bring in the IT team. They have to bring in the CTO organization to make sure that the patching, et cetera, doesn't create an outage. And of course, that's where with us having deployed 150 million patches and 40 of them autonomously, we have that ability to say we have Six Sigma accuracy, so that helps, but it's still something that takes some time for them to figure out what the new process is going to be, what do they do with the existing tool for patching. Maybe they replace the existing tools. In some cases, they keep the existing tool for certain use cases, and they're using Qualys for the other use cases. As one of the customers I spoke to recently said, they look at it as the big red button where they're going to let IT do some of the patching that they do normally. But if some new outbreak comes and they need to get something fixed in the first eight hours, then they're going to just use Qualys to do that because they don't want to wait for the IT team. So in some cases, they're replacing. In some cases, they are layering the elimination capability on top of that. In other cases, they need to pull data from their other security teams like cloud security into Qualys ETM to give that holistic picture. So there are different stakeholders within the security and IT team that get engaged. And so we're continuing to work through that and have those conversations.

Operator

So you've done a lot of work with agents yourselves, and I think that that is very interesting and still underappreciated in the market. We already talked about how customers value remediation. So in terms of detect, validate, and fix, which is the hardest to pull off? Is it fixed? and then if you know another platform wants to bolt on exposure management, why would it be harder for them to execute that fixed stage?

Sumedh Thakar, CEO

Yeah, I mean, look, it's not that patching solutions haven't existed, right? So why, what is, they've been there for many years. What is the difference is that the native platform that we have built, which really brings the focus not on the post-breach side, but actually on the pre-breach side, the ability for us to have these signatures with the research, threat research that we do that's focused on vulnerabilities. And then the ability to convince the customer that this remediation that we do is something that is not going to create an outage are the key parts. At the end of the day, you need high-speed detection, which is a week and a half ago when we had Black Hat, we announced a new agent called Agent Insta, which is the ability for customer to know within the first 60 minutes of an advisory coming out if they are impacted or not. versus waiting for two days for scanning in the way traditional scanning happens. Second is Val, which is, again, another way that Qualys uniquely looks at, not from just an endpoint perspective, but from an outside-in perspective of running the exploits ourselves so that the customer doesn't have to figure out with the red team or something to do that individually. And then finally, it gets into the patching capability. And I think a lot of conversation is now happening with other vendors saying they are also going to add patch management. when the thing that, because we've done this for a long time, what we have matured into, patching is not the only solution for remediating risk. So what we have done is we've created the ability to first, number one, have the option to actually apply a different fix, which is a mitigation that does not require a patch that reduces the risk of an outage. The number two is because we have deployed over a half a billion patches, we are providing, we have built an AI ML model that allows us to provide a reliability score to a customer of a brand new patch so that when they go to deploy, they actually have confidence that this is a high-reliable patch versus low-reliable patch. So the ability to execute a file on a system to run a patch has always existed. I think where we have added a lot of the intelligence with agenting AI capability is the ability to significantly reduce the number of things that you need to patch. And then the second is giving you alternatives to patching. And then the third thing is actually providing you intelligence based on AI to say, is this match going to create an outage or not? So they can make better informed decision. And the last piece is actually added the autonomous remediation capability where we already have 40 million patches that customers are deployed with no human intervention. So yes, there are other platforms that are focused on post-bridge detection, can say I can find a vulnerability here, but today a lot of the exposure management solution are just giving you another exposure dashboard. They're not actually fixing it. So, you know, exposing exposures is not really what people are looking at right now. So we feel pretty good about the intelligent capabilities that we have built. It's not just the ability to execute a file to run a patch, but it's a lot of that intelligence and workflows around it that make it a lot better for them rather than sort of just having a basic functionality to do it.

Operator

So in years past, we've talked about the implications of quantum computing and post-quantum cryptography. the queue date could be moving up and progress has only accelerated. We have a bunch of quantum companies at the conference this year. So has it created more interest in patch management or just thoughts on implications for the cybersecurity space at large?

Sumedh Thakar, CEO

Yeah, I think I've done this long enough now to say that every time a new technology comes, there's a lot of hype about it right now. Of course, it is AI security, but in a few years, it's going to be quantum. But if you go back to cloud and if you go back to other things, whenever a new technology comes, the basic four pillars always remain the same. Number one, do I have it? Whether it's cloud, whether it's quantum, people don't know where my certificates are, where my AI is running. These are the pillars of the rock, right? Which is inventory. No matter what it is, do I have it? Number two is can I assess it for issues? So whether it's a vulnerability scanning, whether it's an AI model, whether it's a cryptographic key or an algorithm that is not quantum safe, Number four is prioritizing. I cannot fix everything, no matter what it is. Whether it's cloud findings, it's AI findings, people are not going to fix everything. So the prioritization based on business context and threat intelligence stays the same. And then the final piece is you have to get it remediated. So in some cases, it's a patch. In other cases, it's fixing a misconfiguration. In the case of AI, it's going to be ability to put some controls around the agent, et cetera. And then when quantum comes, people are going to want to know if I have quantum unsafe algorithms or certificates, how do I quickly rotate those? So the technology essentially is still what you're using for mitigations and patching is the quality of being on the endpoint agent. We can run a bunch of different remediation that goes beyond patching, and one of those will be what can we do whenever you have a quantum unsafe situation. Qualys agent can deploy a new certificate or rotate the certificate where we want to approach as an example. So, again, we feel like the platform holistically has been built to be able to address different technology that comes our way and which is really what the rock is about and put it in the context of risk, right? Just because you have quantum, how much risk does that add to the business? So how can we help the CISOs make that point to the board so that they can ask for additional funding? So I think these things will come, but the basic framework stays the same.

Operator

We're getting up on time, so we'd like to offer the opportunity for anyone to ask a question in the audience if they'd like. Sounds good. So, Jimmy, you're running at high 40s EBITDA margins, and we're talking about aspirations to reaccelerate growth. would just like to hear more about where you're thinking about investing that incremental dollar and then maybe what you could see in a cohort like ETM to recalibrate and invest more to drive further acceleration.

Joo Mi Kim, CFO

Yeah, as demonstrated by your Q2 results, I think it's a pivotal moment for us. If you take a look at our current billings, this is the first year that we've kind of implied guidance that points to a real meaningful acceleration. In the last couple of years, current billings growth have decelerated from 13% to 9% to 8%. Current year implies 9% to 10% based on our guide, which kind of demonstrates the upside opportunity that we see in the business today. I think that there will definitely be tailwinds given the post-mythos era of what we could do with our newer products. It's not just one product, for example, even though we believe in ETM that will generate sufficient amount of growth to really accelerate to the double digits that we're looking for. We believe that other products like Patch Management and Total AI 2.0 will help to contribute and help us to get our net dollar expansion, which is our KPI, back up to that 110-plus level that we've seen before in our history of Qualys. Right now, we've seen a nice trend upwards from 103 to 104 to 105. With the rest of the growth coming from new logo acquisition, I think that there is definitely more room as we continue to execute. and we'll have to wait and see what that really means for us in the next couple of years.

Operator

So $300 million pre-cash flow, significant buyback authorization. Curious, maybe your thoughts on M&A broadly, if you're thinking about valuations in the security space, I think valuations can be pretty full on the AI side, or maybe what could complement the platform at this stage.

Sumedh Thakar, CEO

Yeah, I think we always continue to look for these kind of opportunities. I think our focus right now is, if you look at what customers are really liking the Qualys capabilities because of the integrated ability to actually get to the patch in the first eight hours because everything is coming together instead of having siloed platforms. So as we're looking out there and we're looking at what the customers are really looking for, we continue to look at different options. I think there's opportunities that we look at, whether it's in the current focus with remediation and opportunities to have different options of remediation maybe some companies are providing is something we look at and then as we look into a future AI security related things that are interesting things that different companies are doing in AI so we continue to be open and balance between buyback and opportunity to do an M&A so that that's you know been kind of consistent in the way we've looked at it and we continue to stay open to their option okay so to bring it home I mean for some that don't look at security space all that much.

Operator

They could look at a company like CrowdStrike and see them moving into VM and be concerned about that or some of the newer cloud security players and think that that could squeeze you. Clearly, Q2 is a big statement quarter, and we're on the path to reacceleration. So, you know, why is that wrong or kind of help us demonstrate the value of Qualys that the numbers are clearly showing us?

Sumedh Thakar, CEO

Yeah, I think given sort of what we're doing and success we're seeing in the overall space of vulnerability management, which in my mind also includes remediation, I think we see different players have come in the last couple of years, but they are offering findings and vulnerability findings that we have been doing for a long time, but we are much, much further ahead in terms of our ability in my mind with the remediation, broader remediation capabilities, the ability to provide you patch reliability scores, the ability to actually showcase that we have deployed 150 million patches or almost half a billion patches the last few years without creating outages. And I think when you compare that to say somebody is giving you more findings, nobody wants more findings. People want less findings and actually get those findings fixed. And that's really what we are offering. And then when you're going to rely on somebody to fix those findings, do they have a track record that you can actually trust that they have done that for a long time versus somebody who's adding capabilities newly. I think that focus that we have kept and innovated well before the market versus people jumping in now, I think that creates trust with our customers, where customers trust a solution that has had that ability to have this many patches deployed. And so we continue to see more opportunities for us to grow, innovate, and create that gap with anybody else who's trying to compete by now adding patching. We're much farther ahead of just patching already.

Operator

Sumedh and Jimmy, thank you so much for the time.

Sumedh Thakar, CEO

Thank you very much.