TENB Investor Event Transcript
Tenable Holdings, Inc. (TENB)
Conference Transcript - TENB 2026-09-16
Rob Owens, Analyst — Piper
Good afternoon, everyone. I'm Rob Owens with Piper. I head up our technology research group and cover the cybersecurity and infrastructure software universe. Happy to welcome our next management team, Steve Vince, co-CEO of Tenable.
Speaker 3
Thank you, Rob. Great to be here.
Rob Owens, Analyst — Piper
Steve, welcome. Thanks for coming to Nashville.
Speaker 3
We always enjoy ourselves when we come.
Rob Owens, Analyst — Piper
That's good. That's good. Should we start with football games over the weekend? Ken, you had probably a pretty good weekend there.
Speaker 3
I don't think this is the time or place to talk about how good the Ravens will be this year, but that's the topic of another conversation.
Rob Owens, Analyst — Piper
They looked very good. So, unfortunately, my chargers did not, and I'm out of my suicide pool right away week one. So, maybe talk a little bit about the second quarter and that dollar expansion rate taking up for the first time in several years. and speak to the puts and takes around retention, expansion, and the opportunity for this to be sustained moving forward or potentially an accelerant.
Speaker 3
Sure. Good question here. So just a quick recap on the quarter. Basically, over-delivered on the top line and the bottom line and raised your outlook for the year for both revenue and earnings per share and gave a very strong free cash flow guide. I think $268 million in revenue, so almost $270 million. Over a billion for the year it makes us one of the largest security companies in the world I think one of the ten largest pure play cyber security companies the other thing I'll say here's what we delivered over 300 new enterprise customers and One of the things we talked about on the call even though we don't guide to CCB. We understand directionally that CCB is a directionally a corollary to what we sell we said that our CCB is tracking better than expected since the beginning of the year when we provided an initial estimate of CCB of where we would land for the full year. We said on the last earnings call that CCB is so far as tracking 8 to 10 million better. The expansion rate was higher in the quarter. It was the first time the expansion rate ticked up since 2022. And why is that well mythos was released in April so during the course of the quarter and while we acknowledge that the demand signals are really strong from customers in a post mythos world both at the top of the funnel bottom of the funnel we had we had one of our best quarters for net new six-figure customers we said that look the first tell on accelerating growth because mark and I have been very adamant very public about our ability to inflect growth higher here in the first tell will be in CCB, so revenue is somewhat of a lagging indicator. And with regard to CCB, the early leading indicator will be an inflection in the expansion rate. So pleased to see the expansion rate tick higher. We have confidence in our ability to continue to drive that higher as customers look to expand. And I think it's also fair to say that Mythos is one of the biggest demand catalysts that exposure management, the category, will ever see here. And we like how we're positioned, and we have a big role to play here as well.
Rob Owens, Analyst — Piper
So unpack that expansion and that acceleration within the customer base in terms of is this them moving to Tenable One, allowing them broader exposure, and so kind of the uplift in there, is it kind of sticking with what they have and just having more assets? Are they adding more capabilities on top? Kind of stack rank for us.
Speaker 3
Within the quarter, Tenable One, which is our exposure management platform, was 50% of new sales, which was an all-time high for us. We said in terms of total sales, we acknowledge, but by the end of the year, we expect Tenable One, that's a percent of total sales, to approach 40%. So very pleased with what we saw in the quarter. One of the reasons we had one of our best quarters ever for net new six-figure customers is because of Tenable One. Selling prices are higher, close rates are higher, you know, the highest renewal rates. And one of the big reasons why is because it covers a wide range of domains. So, yes, asset expansion, we have an asset-centric model. As customers deploy more agents, more applications, more AI infrastructure into their environment, they increasingly turn to us to not only expand but also to secure more of that. So asset expansion is a part of that. We have a number of products that are integrated into the exposure management platform. So, yes, there's some core VM capability in there, but it's also OT. It's also things like cloud security, identity, ASM, historically have been sold in the market as standalone point products. But to say that customers are migrating to Tenable One because of consolidation really understands, undersells the value. So, Pettable Ones, and specifically exposure management, solves a much, much bigger problem here in the agentic era. It's about unified visibility. So, you do have a complete inventory of your entire digital footprint, whether it's on the network, in the cloud, on the factory floor. To be able to take all of that data, enrich it with ownership data, asset criticality, external threats, to identify your most important exposures is not optional survival in this area. And then more importantly, HEXA is our agentic engine to help orchestrate fixes. So in short, the value prop of Tenable has evolved quite a bit historically here from the find-it company, the visibility company, to the fix-it company, and HEXA and AI plays a very important role.
Rob Owens, Analyst — Piper
And maybe drill down on HEXA and the ability to close the loop quicker. I think the world is changing rapidly relative to the tools the bad guys have. In effect, I think the bad guys are actually somewhat ahead of the good guys, putting you in that good guy camp, just from the standpoint of friction in traditional processes and things of that nature within organizations. So talk about what Hexa brings to the table. Talk about Tenable's ability to close the loop more quickly, which I'm sure is what customers are starting to ask for.
Speaker 3
Well, Hexa, in short, is our agentic engine. It's part of our harness, and it orchestrates autonomous defense. And so we live in a world where it took 26 years for there to be 300,000 CVEs. That was the number of CVEs at the beginning of the year, which is basically errors in software. This year alone, year to date, post-mythos, there's been nearly 60,000 new CVEs. There's 12,000 new CVEs just in August alone. So we live in a world where there's a proliferation of applications and agents and infrastructure here. So the attack surface expands. There's more exposures and vulnerabilities. By the way, we're not in the automated, we're not in the vulnerability discovery business. We are in the orchestrated remediation business. We can tell you if those CVEs and non-CVE risks exist inside your environment. and so security defender overwhelmed with workloads the ability can't patch everything can change configurations on everything so that's where the visibility the prioritization the ability to match machine speed threats with machine speed action is absolutely critical and you have to do that deterministically and so hexa is helps customers either apply patches change configurations determine the existence or the absence of compensating controls can quarantine an asset or isolate an asset. And it's also model agnostic. So if customers want that routed through a frontier model, we can do that. If they want open weight models, and there's a lot of concerns about enterprise sovereignty here, so customers have the ability to download a fully parametered file on their infrastructure, it's cheaper, more flexible, we can do that as well all through HEXA. And the right way to think about tenable in the context of the security continuum is, look, for years the market has been spent a lot of money, a disproportional amount of spend on detect and respond. Arguably, that's really about response, not necessarily security, but that's an important job. Runtime, detecting, responding. We're on the proactive security side. And so we live in a world where you can't patch everything, you can't secure what you don't see, and to be able to take actions, deterministic the right actions with the right fix the fewest actions have the biggest impact on risk it's going to be important the last thing I would say here and hexa plays a big role in all that we just released it in Q2 as part of our foundation and our advanced packages and which are new pricing and packaging which we just launched a few months ago and 80% of all customers are choosing the advanced package, by the way, which has a 60% uplift in comparison to standalone Tenable1 and VM. So the last point here would be we are working very closely with the frontier model companies to integrate their models into the platform. Yes, we're a part of Daybreak. Yes, we're a part of Glasswing. And so Glasswing means we can take Mythos 5 and scan our own code base. We're one of 150-plus companies that has been vetted to do so. But investors can do their own research, but to my knowledge, I'm not aware of any security company, anyone on the planet that has been given permission by the White House, by Anthropic, to be able to integrate a frontier model, that those five, the most advanced model, into a live product, into 10 of the one, which is what we announced last week. So frontier model companies, even open white models, will help us solve an even bigger problem in security and help customers move from react and despond technologies to this proactive mindset.
Rob Owens, Analyst — Piper
So new pricing, new packaging, what about a consumptive element? You mentioned in the last, what are we, five months now, you've had 20% of the all-time CBEs discovered in the center. So how do you attach to that? Because there's got to be an opportunity beyond where you're at from a pricing packaging standpoint. What do you have now? But help investors kind of dream the dream a little bit in terms of this dynamic, because obviously we're going to see more CBEs. We're going to see more day zeros. And we would love to see your model more so attached to that opportunity.
Speaker 3
Well, there's two ways. And we're doing exactly that, Rob, and that's a good point. So there are consumptive aspects to our pricing and packaging. We do that in two ways. Number one is HEXA. We talked about the customers. We announced in the second quarter that we have hundreds of customers already out of the gate that are going in, prompting, taking an action, prompting, and then 90% of all actions that HEXA recommends, customers accept. So we sell tokenized packs for HEXA. We sell that in foundation, more so in advance. So if customers want to be able to fix, change configurations, compensating controls, you know, pie patching, whatever the case may be, you can buy tokenized packs for that. So that is an add-on SKU that we just made available here, I think a few weeks ago. The second thing is we launched Avis Serial View. That was last week as a part of our partnership with Anthropic where we're integrating Mythos 5 into the platform. And what does Avis Serial of you do here. When we assess a device or a machine or whatever the case may be or a system, there's a lot we learn about it. Yes, we can identify the existence of CVEs. We can determine misconfigurations. We can identify access and entitlements, but we also pick up and collect in our raw telemetry data a lot of low-signal exposure data. It could be a mid-level CVE on an internal host. It could be a stale service account that has admin rights. Individually, maybe not significant, doesn't make it into our prioritization and risk scores, but when you run it through a mythos-like model, it delivers and chains together incredible insights. So that's what we're first in market to deliver last week for our partnership. And those are tokenized scans and assessments that customers will be able to do. They're a little more expensive than your traditional scan. But you can buy tokenized packs. It delivers greater insights. So customers have a choice.
Rob Owens, Analyst — Piper
Obviously, there's a consumptive element to it, and we expect it to have an impact on the selling prices. without a doubt the criticality of exposure management's increased significantly you know be that mythos or what we've seen with hugging face what we've seen over the weekend with whoa we don't know where these models are going but that also invites a lot of competition a lot of noise and you now see open ai talking about their new system crowd strike showing kind of an autonomous capability of red teaming attacking and then blocking how do you think about the evolution of the space and the defensibility of where you guys sit currently.
Speaker 3
As I look at it, I think there's two types. There's a convergence coming. You have build time capabilities on the left, and you have runtime capabilities on the right. I believe you'll see a convergence. I think you'll see runtime companies shifting left and build time companies shifting right. So it is important to be able to block, stop, or kill agents. By the way, I think you're going to see legislation from the USG that talks about having these kill switches in some of these frontier models. By the way, I think that's more enforcement. That's plumbing. I don't think that's a feature, but I do think it's going to be important. So you'll be able to block, stop, or kill maybe through Salesforce, Agent Force, maybe through the frontier model companies. There'll be a number of ways in which you can do that. But to be able to take the right action, orchestrate the right fix. What's important here is the context. And the exposure graph is absolutely going to be critical. The exposure graph is a graph of all of your exposures, all of your agents, all of your identities. To be able to correlate that, deliver visibility so you understand the right fixes at the right time is essential. And I think the runtime players are, I think that's an important, that's an important aspect for the runtime players. I think the ability to take action will be important for the build time companies such as, like, Attenable. We're, look, we're not in the visibility company. We're not the visibility company. We're not in the in the ability just to identify risk. We're in the fix it business. Not find it, but fix it. And so Hex is our engine to be able to integrate with the tooling. to block-stop-kill, to take an action on an endpoint, to be able to change a configuration, to be able to add a compensating control. All that's going to be important. I see the convergence of those two markets, and I think it makes security better. I think it makes customers safer. And I think there's a big role to play here by each. I don't think there's a winner-takes-all and one security economy will prevail on this market.
Rob Owens, Analyst — Piper
Fair enough. It's been an interesting year. I've been through SESPocalypse, and we're going to get disruptive everywhere to, oh, my God, maybe cybersecurity truly is the real enabler or the bottleneck, however you want to think about it, maybe lend some perspective to where you see potential disruption and where you see potential augmentation with what's going on with the frontier models. I know through the new partnerships and things of that nature, but help investors kind of what are the puts and takes around this opportunity in terms of pitfalls they should avoid and how this looks for cyber?
Speaker 3
Well, I would say this. If you look over the last 40 years, every major technology shift has demanded more security. Not sometimes, but all the time. Look at the PC era and what's the operating system. I don't think anyone relied on Microsoft to say that they were secure. It gave way to a whole host of new security companies and categories. The shift to the Internet, Obviously, we saw things like firewalls and vulnerability management. The shift to cloud, right? CSPM, CNAP, and a whole host of acronyms in cloud security that would be too long of a list to name every one. And AI is that next big shift. And so right now, the focus and the spend is on building out infrastructure, and rightfully so, but eventually it will turn to security. And I know if you look at, in the case of the frontier model companies, Their aspirations are to be the intelligence hyperscaler. Well, you look at the hyperscalers today, you look at Microsoft, you look at Google, you look at AWS, there's always been this need for independent assessments. There's always been this demand for security companies to secure part of that infrastructure, part of those compute environments. I don't think frontier model companies, who knows what the S1 will say and what they'll eventually do, but right now what they're offering in market today is the ability to identify and automate the discovery of vulnerabilities at the source code layer. A lot of this is publicly available. The real moat's data. We're deeply embedded in runtime infrastructure, behind the garden, firewall, and we have the largest data fabric that's non-public in the market. So data will be the new moat. It'll be above the intelligence layer at the application layer where you can take actions deterministically. Part of the, HECS is part of our harness there. It'll be below the intelligence layer, which is the infrastructure, which is our vast network of sensors. And so we, sensors on domain controllers for Fortune 500 companies. We do passive network monitoring for water utilities and electrical grid companies or on telecommunication networks. We have agents on endpoints. We do cloud workload analysis and identify misconfigures with an audit trail. So all that is sticky, hard-won, years to create, and that's what feeds really the data fabric. And so data is the new moat. I think Frontier Model Companies will help us accelerate and deliver more innovation and help us solve bigger problems.
Rob Owens, Analyst — Piper
I'll turn the public sector, being the fiscal fourth quarter. I think you mentioned a strong public sector last quarter, if I remember correctly. but just how things are shaping up on that front. Obviously, there's been a lot of disruption in the federal government over the last couple of years, which I think is causing some friction out there, but we just love your perspective.
Speaker 3
Well, this year, the demand environment is much healthier, much more stable in comparison to last year. We saw Doge, and there was disruptions in procurement at the broadest level, not just security. So we have a better spending environment, which is great. And we talked about a sizable OT win on our last earnings call, you know, in our public sector business. And what we have also seen here over the last couple of months is a huge wave of new AI security policy from the U.S. government, coming from Sean Cameron Cross, the National Cybersecurity Director in his office, the NCD. We're talking about establishing Gold Eagle, which is a national vulnerability clearinghouse that spans both public and private agencies, and we're also talking about things like binding operational directives, which is U.S. government wants to be able to provide these dynamic risk-based frameworks to be able to harden federal systems, protect critical infrastructure, focus on state and local matters. We have leadership in public sector. We are one of a small number of companies working closely, directly. I've had personal conversations with the National Cybersecurity Director, but one of a small number of companies, part of these task force, part of securing critical infrastructure, part of helping them solve these problems that the agentic era presents.
Rob Owens, Analyst — Piper
Great.
Speaker 3
Questions? Well, the use cases are different. We have Foundation, we have Advanced. And Foundation, it's a 6% uplift. Advanced is a bigger quant to step up. It's 60%. So overwhelmed with the response from customers who are choosing the Advanced package. Keep in mind, we've launched these new packages last quarter. So of the cohort of customers that have selected or are buying this new package, they're choosing, obviously, the Advanced package. I'm not sure if we'll continue to play out that way, but we're certainly pleased. is one of the reasons why the net new six-figure customers has been one of the best since over the last five years. The use cases are different. Foundation's more about visibility. And so there's capabilities in there, for example, where we, AI Aware, which we can discover all of your AI applications, your browser plugins, your models. So the big focus there is visibility, unified insight, whereas the advanced package comes with broader CNAP offerings, more agentic capabilities. Hexa is prominently featured there with much higher usage limits, which is the action ability. So the ability to automate a workflow, the ability to take an action either with a human in the loop or autonomously is the big value add for the advanced package. So So it's really this evolution from FindIt, which is what Foundation can help you do much better than standalone VM because it's cross-domain, but it's also this evolution into FixIt, which is Advanced, which is cross-domain visibility and remediation, which PECSA plays a big role It's a good question, and we have a great relationship with the frontier model companies. I think they recognize it's hard to have a conversation about AI adoption without having a conversation about security. So they recognize that the security community is really important to them. We have access to non-public models. Mythos is a good example. Mythos 5 is a good example of that. We're doing joint R&D research together. We just launched, speaking of HEXA, which comes with a fleet of agents that you can use out of the box that takes specific actions. But also we have an agent exchange where customers who are creating agents in HEXA can push them out on the exchange. and we've partnered with OpenAI in that regard where they're helping secure those agents in that exchange. So I think they recognize that there's a big role here, security and Tenable in particular has a big role to play here in this notion that you can't possibly detect and triage every alert, every incident. And this realization that we have to shift our thinking, have to shift our focus, have to shift our budgets from detect and respond to proactive security. They believe Tenable has a big role to play here. We are the leader, unequivocal leader, we believe, in exposure management. And so I think they are picking market-leading companies to help solve some of these problems, which in turn could help drive more AI deployments. They need the security community and they need some of the established players.
Rob Owens, Analyst — Piper
We have time for one last quick question, if there is. Steve, thank you very much. Thank you, Rob. Appreciate it.