Executive readout · one minute
Webcast research workspace
Read the call alongside every captured source. Transcript, audio stay in one workspace.
Conference · 2026-09-10
Executive readout · one minute
Read the call alongside every captured source. Transcript, audio stay in one workspace.
Research coverage
2 live sources
Switch sources without leaving this page or losing your listening position.
Open the source you need; every reader stays inside this workspace.
Listen and read together
The spoken word highlights as audio plays. Select any word to seek to that moment.
Hey, thanks so much to everyone for joining us at the Sentinel One session. Delighted to have Toma, founder and CEO, on stage with me along with Tonali. Relatively recent CFO. Hey, thank you both for being here. We really appreciate it.
Our pleasure.
Super happy to be here. Toma, we were just talking off stage on it's a really great time for us to pick your brain a little bit on some of the architectural shifts that are happening in cybersecurity. security. Maybe as a starting point, walk us through what one of your more sophisticated customer conversations look like. When they call you in and they say, look, we see the hogging face news. We see all of the agentic risks that we're taking on here. Please solve this problem for us. What do you say in terms of the customer journey response?
I think what's really important more than anything else is to separate the hype from kind of the actualities of these attacks. And I think what's interesting in these, you know, recent incidents that we've seen, fundamentally, there's nothing new. And I would try and kind of unpack that a bit. What these agents have done is nothing that a human attacker has not done in the past. So in essence, we're not seeing any type of new behavior. We are seeing a new level of velocity. We're seeing a new level of speed, but we're not seeing new techniques. And I think that's where it's becoming really, really interesting when you start to peel back, okay, what should people do right now? There is no magic solution out there from any cybersecurity vendor. No matter what you heard, there's nothing that solves the issue that we're facing right now in terms of the speed and the velocity. But with that, if you invest in better fundamentals and you can actually achieve better fundamentals faster, that is really your best shot at mitigating risk. And note that I'm saying not stopping the breaches, mitigating risk. I think in this day and age, if you claim that you stop breaches, that's unreliable. That's not credible. I mean, we're seeing all these breaches happen. and you read about all these breaches happen, products are failing. Everybody's failing. So this notion that we can stop it, we can prevent it, we can live in a world where these things are not happening, it's misguided. We can reduce the risk. I think that is the number one thing that we're letting our customers do, is figure out, okay, where should I be focused? I mean, there is an ocean of different ways where attackers can actually leverage AI right now to find, you know, these nooks and crannies to get in your environment. Another reality is that nobody is able to fix all of those. Maybe a few companies, but the level of hygiene that you need is just, it's extreme. I would say that, I'll take us as an example, right? I mean, we're a company too. We need to protect ourselves as well. And our hygiene has been extremely, extremely high for many, many years. Pre-metos, post-metos, all that stuff doesn't really matter to us as much when you think about the fundamentals that are needed. Being vulnerability-free, you don't need metos to tell you that you need to be vulnerability-free and fix all your vulnerabilities. The fact that awareness is expanding doesn't really mean that the problems were not there to begin with. I would even, you know, extend this to say that AI is not good at cybersecurity at all. We are bad at building secure infrastructure, all of us, combined. That's why AI, which is a great search engine, is able to find all these things that we have basically fucked up for many, many years, right? So we've got to really think about what's happening. It's not that AI suddenly is becoming so proficient. The problems were there. People were sitting on vulnerabilities for years. People were not fixing and configuring their environments for decades. The complexity, security vendors are also part of the issue. They're introducing more complexity into the mix. You know, you're buying a platform. You're actually buying sometimes seven different platforms from the platform provider. You're trying to stitch everything together. You're applying manual policies for something that moves at machine speed. like there's complete misalignment between kind of the pace of technology and the pace that AI brings and the status quo of our infrastructure. I sincerely don't believe that, you know, AI at this point in time is so remarkably good specifically and surprisingly just in cybersecurity. I mean, we're talking so much about cybersecurity. The problem is not the AI getting better. It's the state of cybersecurity itself.
My favorite thing is that there is when not seeing new techniques. Maybe I'll ask the question then, okay, so if the existing techniques get automated, scaled, happen faster, what is the limiting factor to being able to take the existing building blocks of the security architecture and make it more sophisticated to be able to deal with greater scale if it's the same technique?
I think you need to do two or three main things. One, visibility. We've talked about it, I think, throughout years on this stage, in the context of AI, but also not in the context of AI. You need visibility. There's this nomenclature saying in cybersecurity, you can't secure what you can't see. And it's very true. I mean, you've got to really have visibility into each and every one of these workloads, those parameters. Every piece of your environment needs to be monitored. And that, I think, is the basis for anything that follows. Then I think what's lacking is how do we get to the same type of velocity and speed to match what we're seeing with AI? And that comes through more automation and leveraging AI or machine learning in these environments to basically take the visibility, but find the signal fast enough before it turns into something that somebody else finds for you. And the last piece, and I think this is where it gets really interesting. It's about building more and more generic ways to understand that something different is happening. And I'll give you a simple story. You know, this is, I don't know, maybe four months ago, and it seems like it was a lifetime ago. But we had all these supply chain attacks, Light LLM, Axios, like all these libraries that developers are using have been poisoned. And then people using AI for development, Claude, Codex, all these tools, were automatically downloading these poison libraries, and Claude was just executing those on the device itself. So, in essence, in a complete automated manner, hundreds of enterprises, Fortune 500 companies, got completely compromised. By the way, the moment Claude executed that innocent library, all the secrets, all the password, everything you've had, also laterally in your network, was being pulled and sent out, which means that your collateral damage now and the need to fix, I mean, all the derivative kind of damages that happened because of it is also like a pretty long-haul remediation story. We, on the other hand, with a piece of software that was built 10 years ago, 10 years ago, I mean, the logic, we didn't know generative AI is coming 10 years ago. I don't think anybody did, including the people that built it, right? With that technology focused on the most generic aspect of cybersecurity, which means behavior, not exploits specifically, not viruses, not signatures, not Trojans, not ransomware, not the actual private cases of how you do badness, but focus on what badness generally looks like or how different it looks like from benign behavior, we've been able to stop all of these attacks with no prior knowledge, no prior understanding. The system just saw something. It didn't care if it was Claude or the user or an attacker. It didn't really matter because what it exhibited looked different. So the more we focus on generic ways to take visibility and then discern good behavior from bad behavior, whether it's a human user or the agent that's running on the machine or some SaaS workload that's now downloading stuff that it shouldn't, to me, that's the only answer. And very coincidentally, that's exactly what we built in the last decade or so. Now we're extending all of those things. models to also be applicable even in and through the introspection of the agent and the AI model itself. Right now, it's very focused on machine behavior. This is kind of the gist of endpoint protection. Now, when you add visibility, again, coming back to visibility, into what agents are doing, you're able to basically apply the same type of algorithms to discern, hey, is this agent really doing what it's supposed to do. And then we go, I think, even deeper into what I believe is going to be required here for AI alignment in general. And this is a problem cybersecurity never tackled. It's a complete new problem for everybody. How do you make sure AI stays aligned to what you want, to what humans need? And the only way to solve that is by matching intent with behavior continuously and all the time in a form that's external to the model. And I think that is by far the only thing I would invest on for cybersecurity in the next five to 10 years is solving AI alignment and AI safety. And I think there's a lot of corollary things that we do today for enterprise defense, but the AI alignment issue is going to supersede pretty much every other problem we see in cybersecurity. How do you do it? you leverage a lot of the knowledge that you have today and I think that you need to also get to this realization that the model is never going to govern itself and that people that want to solve AI alignment should not be investing in building some super intelligence because you don't need super intelligence to keep AI aligned you need something that is more balanced something that is designed to govern, not to be smart, just to know when intent differs from the exhibited behavior. And that's the entire thing. I mean, it's not simple to build, obviously, but it does in many ways resemble the core EDR problems that we've seen in the past. I mean, they were much more binary and file and attacker-inclined, but it's still about operations, And it's still about what's happening, and it's still about behavior. So to me, intent, behavior equals eventually AI alignment. How do you do it fast enough? How do you make sure that the model can't tamper protections, which is what we're seeing right now with guardrails? Yes, there's guardrails. There are safeguards, you know, where we just train the model, you know, to be much more safe. The model doesn't care. The model, we're seeing it right now play out in real time. The model does what it wants at the end of the day. The model does what it believes is serving to the goal that it was given. It looks at the guardrails and says, okay, I see the guardrails, but maybe I'll do this. It's almost like a kid, right? I mean, you give it all kinds of, hey, don't do that, don't do this, don't do that. Sure, yes, absolutely, I will not. But then sometimes you do. And I kind of feel like there is really no way inherently in the Transformers architecture that allows for that determinism to ever be exercised. So it's a question of the current architecture for LLMs. By the way, I don't think there's any certainty that this is going to be the dominant architecture for years to come. I think what you're able to build today with the velocity that AI coding gives you is maybe a complete new architecture for the future. Maybe it's time for us to contemplate how we build a new reasoning model and not one that leans on brute forcing chain of thought and randomizing tokens and using language as the basis. I mean, right now it works and we're putting more money into it, and we kind of feel, okay, the more compute we put in, the better outcome we're going to see. I have a question for everybody here. Where are the AI outcomes? Where are they proven in the market?
Coding, customer experience.
Revenues, dramatic growth, amazing outcomes, transformative change for Earth.
Do you think this is because it's the wrong architectural model via transformers, or do you you think it's a change management problem?
Probably a bit of both, but I think that underneath it all, it's a question of trust. And I think we're just unable, if you're working with these models, like firsthand, you understand you can't trust this. It's just impossible.
If I just go down this thread for a second, if we solve the alignment problem the way that you're suggesting, then you get the trust, and then you get the unlock from a productivity and adoption system.
I believe so, but I also think that that's a deeply rooted architectural problem, because to do that in a way that is non-circumventable by the model or the software itself, you can't have security running at the same level, at the same layer, at the same ring that the model is running. Just in terms of compute, even today, if you take normal cybersecurity, if you're running in user space, I don't care what you do. You're toast. You're toast. Everything can bypass you. So these stories about user space becoming the thing and in the wake of the CrowdStrike outage and blue screening 8 million devices across the world, people are like, hey, get out of the kernel. You have to get out. Everybody's going to get out. Nobody's out. What are we, like two years, three years from that event? Nobody's getting out. And the reason you're not getting out is because the moment you're out, you're toast. Like you're in the same level that the attackers are, and you got no shot, no shot to prevent any type of an attack. So the need to be as low as can be in the operating system is a dire need in the question of AI alignment. And I would say that it's even more acute, you likely need at this point to even have either a new chip design, where you can separate compute for whatever security you put inside versus whatever is running the actual software and the model, or you need some form of a better security enclave. Even the security enclaves that we've seen today, Apple is an example. I think they've got really great security enclave capabilities. They offer you protection. You can load your software, and then they protect it via hardware. That got compromised also. So it seems like we would at some point need to really think about how we separate hardware in a manner that allows for security that cannot be bypassed, but by what it's supposed to be securing, which sounds pretty obvious, but it's really not the case today.
Yeah, super interesting. Let me ask you about this concept of taking the proprietary data set that's in Sentinel-1 and applying it to some sort of LLM technology such that you're able to get, maybe it's purple or maybe it's a continuous penetration testing loop where you can run offense and defense with agents to level up the scalability of the existing architecture. What are your thoughts on how that makes sense to someone?
Yeah, I don't know. I mean, it's going to be a jagged answer. I think that there is a lot of focus on vulnerabilities, maybe too much focus on vulnerabilities right now. This entire notion that you're going to have the red agent and the blue agent, and they're going to handshake each other, and one's going to find, one's going to fix, and everything's going to be miraculously pristine after that, I haven't seen it. I haven't seen it. And, you know, we've been red teaming our environments in an automated manner for years. And obviously, once we got access to more and more frontier models over time, we've used frontier models to do that as well. You find a lot of stuff. You still need humans in the loop. You still need to prioritize stuff. You still need to understand what's real and what's not real. And the fixing element, I mean, it's not just finding and fixing. It's finding, it's fixing, it's putting temporary controls, it's rolling deployment for production systems.
Who's going to let AI roll out the production system completely automatically?
Nobody is doing that today. That's the one place I would not exercise AI. So to solve cybersecurity in this miraculous, one's going to see them, one's going to find them, and, you know, we're good. Haven't seen that happen. And look, again, we're a glass wing, you know, program participant. We're part of Daybreak. We got access to every model that you can dream of, like everything that's preview. We already have it. We've had it for a while. Obviously, you know, all the open source out there. I think the other realization is that there is no, like, supreme intelligence out there. These are largely, in terms of the level of reasoning and intelligence, these models are not very different from one another. Some are better at keeping course. Some are better at scale. Some have better speed, better course perspectives, better specialties. But in general, the reasoning quality is not dramatically different. But even when you take one of these models and you say, okay, I'm going to pick a model and I'm going to start fine-tuning it or, you know, doing some stuff post-training. And just to ground everybody, like doing stuff post-training is very, very limited. Like you're not changing the true innate behavior of the model. You're trying to kind of keep it in track. It's all done post-training. To think that you have done something post-training that is so dramatically better that it's going to win against adversarial AI, again I haven't seen that in our research and especially I mean at some point also becomes like a very like linear and binary question like let's say you're taking what's it called NVIDIA and then nematron that that thing yeah that stuff is not like even top 10 in reasoning performance by any benchmark honestly and then you say okay I'm going to use that as my base just an example i'm going to use that as my basis and i'm going to sprinkle some fine tuning in my data from years of doing cyber security and like the chinese open source models are probably like by a factor of five better than these models today i haven't seen them lag moreover i've seen them add incredibly incredibly sophisticated ways to scale their models that i think a lot of the frontier companies are coping today. That's the benefit they have when they're seeing something open source. But all in all, to just kind of pick one model and say I'm going to train this to be the best thing of all models, I think that's like total wishful thinking. No matter if you're you know, no matter if you know Jensen or not, I don't think that that changes stuff. Right? I mean, at the end of the day, you have to be agnostic. You have to understand where the limits are and I think in many ways I think what we're trying to do more than anything this is nothing to do with technology is to stop confusing customers to stop making pompous claims to stop thinking that you can develop you know something that is completely unprecedented gonna win that's the solution here you go it's right here let me open my jacket and give you the solution. None of that exists today, and that's part of the issue. And we're all trying to think around corners and understand, okay, where this is going. I think it's proven very elusive, not because we don't know exactly what the potential of damage here is, but more because these models are unpredictable. They, you know, kind of not only improve in an unpredictable manner, but they also lack precision in an unpredictable manner. So it's very interesting to obviously kind of go about and try and solve it, but then I always go back, in cybersecurity, it has to be fundamentals. People have not gotten their fundamentals together yet. So don't rush to deploy the AI security agentic spaceship slash red whatever on your whatever. That's not going to help you. Spoiler alert. You're not going to get more secure. You really have to start fundamentals. And I think that's why also we're seeing this amazing traction around runtime protection and around endpoint protection because it's very obvious. You're running AI workloads someplace. You need to monitor that workload. We don't need to talk too much about AI at that point. I mean, you need the visibility, seeing the visibility, seeing immediate alerts. You're seeing amazing signal coming from all these newfound workloads. To me, that has to remain the focus for at least the next year or so. The speed in which people are doing it, that has to change. So if anything, this day and age needs to give us this wake-up call, which I think it's, I don't know how many more wake-up calls this world needs to have about cybersecurity for things to move faster. But right now, you know, we also have to recognize the limits of what the infrastructure can absorb. You can't just deploy overnight across the world. You can't fix this globally, you know, in two days. It's going to take time naturally. I think it is moving faster, but it's moving faster incrementally. And I think just the level of confusion right now is also somewhat, I think, throwing customers into kind of a loop of, you know, what do they need to do? Who do they need to talk to? Who's going to solve it? It's almost like they're sitting there and they're waiting for their vendor that already kind of is preexisting to come and descend from the top and say, okay, now the problem is solved. Now, to be honest, we're all trying to do it. We're absolutely trying to do it. I mean, we're also getting to the point that we understand that the fastest way to deploy is actually not by talking to us. It's just by clicking a button on your console and starting to do things in a much more automated way. So a lot of what we're investing in today is this ability for our customers to just click a button and get it on with and not go to those protracted sales cycles that we're seeing in cybersecurity and, you know, deployment. We want to automate everything for you. We believe that's the real power in AI right now is that you can really automate stuff. It's a great search engine. It's a great automation tool. Everything else we'll be really careful with.
Finally, this is the perfect opportunity to have you opine on the future of the transformer architecture. Tim was just talking about look it doesn't happen overnight and you had this language in your script that I thought was actually very CFO-esque which is appropriate architectural changes are multi-quarter and multi-year in nature now you had a really clean July quarter so I think two things might be happening at once one to Tim's point things are happening a little bit faster And two, you have a little bit more of a handle on Sentinel-1 forecasting and having been in the seat for a couple more quarters. So talk to us about both of those things. What are you seeing in terms of pattern recognition, or rather what's changing on the pattern recognition for deals in the pipeline, conversion rates, salespeople productivity, all that good stuff?
So you're right. It was my second quarter this past one, And we don't just think it was a clean quarter. We think it was a great quarter. We're really proud of what we achieved. And for those of you who didn't go through our earnings, we actually beat on the quarter and raised our full-year revenue guidance.
And I think the magnitude is important because I actually think it was one of the larger beats in a number of quarters.
So thank you for noticing that. It was. And we actually raised by significantly more than the beat, just showing our confidence in the outlook in the business. So, you asked a couple of questions there. So, in terms of how customer conversations are going and this, I think you were alluding to the mythos moment and how is that impacting our pipeline and our deal cycles and conversion rates. So, we see a really strong demand environment and that is very, very clear in our pipeline. But my comment around this being a multi-quarter, multi-year tailwind for us in the industry still holds true. because, you know, borrowing from what Tomer just said, you know, we need to focus on the fundamentals. We need to focus on how quickly customers can actually absorb all this new technology. And I think from our perspective, you know, one of the areas where we're seeing a lot of strength and traction is in our AI security products. And that was one of the things that really drove the strength in our net new ARR and will continue to drive that. And those are great conversation openers with our customers. But just to give you an example, you know, I was on a customer call this week. It was a very, very large infrastructure provider, global infrastructure provider. And the CIO was saying, look, we need to clean sheet our stack and specifically our security stack because we don't want security to just be something that we do to protect ourselves and protect our customers. We want it to become strategic for us and for our business. But that is a multi-quarter conversation. And that is something that I want to bring all of the team across this company into. And yes, we want SentinelOne to be part of that journey. And please tell us what products you think we need. And, you know, again, this is where the power of the platform comes in. You know, the reason they wanted to speak to us is because we bring a true platform approach. But it's something that is going to take place over many quarters. And whilst we're definitely seeing it in the pipeline, like when you actually see that hit the revenue numbers, that's going to be over time. And I think that's great, actually, because it's cumulative impact. The other question you asked was around kind of the sales productivity and efficiency. And Tomer talked about, like, where we are seeing the benefits of AI. And, you know, one thing that's very dear to my heart and a metric that my team focuses on all the time is net retention. because we all know that it is way better business to keep and expand a customer in SaaS than to go out and acquire a new one. And you've seen really strong net retention metrics from us in the last two quarters, particularly in that cohort of $100,000 customers and above, which tend to be our stickier customers. And again, I think that's validation of the platform strategy. They are buying more and more products from us. And guess what? But when you buy several products from us and you're adopting our platform, you're much less likely to churn. And I think that is one of the things that's driving that productivity and that retention. And then the other thing is just amongst our sellers, you know, we are seeing improved productivity and we are seeing lower and faster deal cycles. So again, these conversations that do take, you know, six to nine months or sometimes nine to 12 months in the case of enterprises, large enterprises, we are seeing a slight contraction in that sales cycle, which is starting to come through in the numbers. And then finally, you know, on the renewals process, we started automating our renewals process, particularly for that really long tail. And we can touch way more customers, and we can actually reach out to them earlier in the cycle, and that's giving us a lot better predictability. And, you know, one of the things that I'm really going to be focused on as we go into fiscal 28 planning, Tomer and I are planning for the first time together, is how do we bring that number that, you know, as we think about net retention, how do we improve that number and really work on that churn and downgrade, particularly with all these new products to, like, just drive it higher and better?
One of the debates in cybersecurity for some time now, and especially over the last couple of years, has been the importance of scale. And in some ways, you have well-scaled relative to some of the new entrants in the space. On the other hand, you've got two or three really large competitors that sometimes have a larger microphone and throw more dollars at the problem. So from a CFO perspective, if you're trying to reduce churn and grow NRR, how do you do that in a way in which you can use your sort of middle-of-the-road size as an advantage? And maybe there's a better expression for that relative to the companies that just have much bigger R&D and SMB budgets.
Yeah, so I'll answer that, and then I'll let Tomer comment on R&D as well. So, look, I think a couple of points I would make there. We feel like we are able to make the investments we want to make, and, look, you can see for yourself how well some of those emerging products are doing. Like, we've seen record growth, and in some cases, like in the case of AI security, so prompt and purple AI, like meteoric growth. We tripled our ARR year over year in that product. So we feel like we are able to make those investments that we need to make in the products where we see real outsized opportunity to grow. And that's notwithstanding the competitors, and yes, they are formidable competitors. We feel like we're formidable. And our win rates continue to improve year over year. So we're seeing those competitors, and our win rates are, like, we're getting better over time. The second thing I would say is, you know, we also invest in our go-to-market. And, you know, one of the things that I just touched on earlier, automating renewals, that's something where actually we're seeing better productivity from our sellers, and we're able to take some of those savings and reinvest in areas, again, where we see the ability to deliver outsized growth. So I feel like from where I'm sitting right now, we really have the potential to take advantage of the time in this opportunity, in this space, to make the kind of investments we need to make to continue growing and hopefully accelerate our growth.
I would say R&D and our technology, I mean, versus the competition, that is not my number one concern. It's far from being my number one concern. Honestly, I mean, you would say with our size, with our position, with like all this stuff, we still have the best technology in the market. Like we would show up every day to POCs with the world's leading companies, and we win time and time again, regardless of the size of Microsoft or Palo Alto Networks or CrowdStrike. So I would say size is just not a good reflection of quality of technology. Bigger microphones, for sure. More confusion, for sure. Controlling a narrative or weaving a narrative, for sure. I think that's our challenges, by the way, as a company at that size, which to me, by the way, is quite foreign. I'm a technologist. To me, it's like I just want to build the best stuff ever and make sure the customers are protected. Instead, you know, we need to kind of come up with all kinds of counter fairy tales for what these other people are telling and saying and trying to promote. It's part of the game. We all get it. I wish that in this day and age, people would actually focus on what's important and what matters and not, you know, the fairy tale stories about how identity is going to solve a genetic protection today because I just bought a company, but three months later, you know, identity is just going to be one sliver. I just bought another company. That's going to solve it for you. And we all eat it. Like, customers eat it. Analysts eat it. Everybody's eating it. And I kind of look at it kind of sometimes with like deep, deep frustration on like, why do people continue believing in those stories? I mean, these stories change if you just go back three months, four months, six months, it no longer holds. What they've said, what this market has been saying six months ago doesn't hold today anymore. The brilliant acquisition that you've done nine months ago, nobody cares about it today. but we all have like very distinct short term memory I would say and we kind of move and move and you know the human brain works in a very susceptible way sadly and I think that a lot of folks have learned how to manipulate that to be honest and I think that's the main thing we're dealing with right it's dealing with confusion it's dealing with the kind of fear uncertainty and doubt that people are fueling into the space instead of really being like almost like in a very dry way, technical about the problem and technical about the solution. And, you know, let's just go and solve it. Let's not tell stories all day long. Let's just focus on how this thing is getting risk from here to here in a quantifiable, measurable way. Those stories that you're telling on earnings calls, they're not doing it. I'm saying it also about myself. Like to me, it feels like a cybersecurity theater that's completely disconnected from what's actually happening in environments. sorry to be so blunt today but no that's why we love you because you're direct and blunt so hey please join me in thanking Tomer and Tomer thank you all appreciate it