Skip to main content

William Blair Growth Stock Conference

Tenable Holdings, Inc. (TENB)

Conference Call date: 2026-06-04 Concluded

Transcript

· tap a word to jump the audio 29:37 Audio
Jonathan Ho Analyst — William Blair

Thank you for joining us for our growth stock conference and today's session with Tenable. My name is Jonathan Ho. I'm the analyst covering Tenable for William Blair. Our speakers today are CEO Steve Vince and CFO Matt Brown, who will provide an overview presentation of the company followed by a fireside chat. Before we begin, I'm required to inform you that a complete list of research disclosures or conflicts of interest is available at our website at www.williamblair.com. As a quick reminder, the breakout session will be held in the Jenny B room, and with that, I'll hand it over to Steve and Matt.

Thank you, Jonathan. It's great to be here this morning, and great turnout. Tenable is the exposure management company, which means we help customers understand and reduce risk, and that mandate has never been more important than in the agentic era. Safe harbor statement, quick overview of Tenable. We're roughly a billion in sales and top line, sales and revenue. 2,000 employees over 40,000 plus customers and nearly 20,000 enterprise customers over the last five years we've doubled the top line and we've tripled the cash flow and more importantly the shape of our businesses has changed just as much as the size 30 percent of our total sales is from our exposure management platform which we'll talk about tenable one and that's leading to larger more strategic deals over the last few years we have doubled the number of six-figure customers. We have tripled the number of seven-figure customers, and the value we're delivering to customers is much more expansive. Quick backdrop about kind of the threat landscape and the market dynamics here. Losses from cybercrime are absolutely staggering. Nearly 10 trillion dollars this year. That number will grow to 16 trillion over the next three years. That's leading to and creating a bigger opportunity for cyber and temple, in particular, if you look at spend total spend in cyber over the next three years, that's expected to exceed 400 billion dollars at software services and other solutions. More importantly, is the shape and and the quantum of those dollars and where they're going, which is towards AI and securing AI systems, applications and models which are are now deeply tied to enterprise workflows. It's one of the biggest threat vectors in all of security that has created an incremental $35 billion a year opportunity for us on top of the $30 billion TAM for core exposure management. So one of the reasons why we're seeing more losses, more breaches, more spend in security is because over the years, we've become a very digital society and it's expanded the attack surface, and today organizations are managing about 2,000 cyber digital assets per employee. We're talking about servers, desktops, laptops. We're talking about APIs, containers, cloud workloads, identity stores, agents, and much, much more. And all of that compute, all of that visual transformation is resulting in more vulnerabilities. Today, the number of cves critical vulnerabilities and exploits is over 300 000. last year according to the national database there was 50 000 new vulnerabilities added alone if you look at mythos a lot of talk about mythos and the frontier model companies since its preview april 7th there's been the discovery of 10 000 new vulnerabilities some are 27 years old and so i think one of the big takeaways here is that we're living in a world where you're going to see the proliferation of vulnerabilities by 10 20 or even 30 X is coming and it's overwhelming security practitioners. And here's the bigger problem number of vulnerabilities is increasing. The mean time from vulnerability disclosure to exploit is not months like it was a couple of years ago. It's 1.6 days. so attackers are moving fast to weaponize ai security practitioners the average sla time it takes to remediate a critical vulnerability by the way it's not 1.6 days it's not 10 days it's not 20 days it's not even 30 days last year according to the verizon data breach report it was 40 days so this is a big problem proliferation of vulnerabilities and exposures and threat actors have a decided advantage as a result we need a new security model and the demand for and the importance of exposure management has never been greater this is a simple market texture of where security or where exposure management fits in to the overall security continuum the most important line here is breach which is the middle of the slide sometimes you call that boom in in the security market. Anything right of boom is detect and respond. It's where practitioners are actively triaging threats. It's where a threat or an attack is actively underway and you're trying to minimize the blast radius and you're often moving at human speed. And when defenders lose that battle, the cost can be extraordinary. On average, it's four to five million dollars of direct costs. That does not include the reputational harm lost customers and other soft costs so as a result we need a new model what tenable does and what exposure management is about is unified visibility unified insight and unified action it's about shifting the security paradigm from reacting from fighting fires and looking for plumes of smoke to fire proofing and exposure management gardner says that when companies do it they're three times less likely to see to be susceptible to exploit it's one of the biggest spending priorities in all of cyber so let's talk a little more about that before we do we're the recognized leader in exposure management don't take our word for it look at gardner we're in top right in the exposure assessment platform mq forester has a uvm report idc has their version of it which exposure management we're top right there so leadership is clear so what is exposure management you know what is it and what is it not first it's not vulnerability discovery we're not in the vulnerability discovery business the frontier model companies are and they're doing it quite well they're racing to build the world's leading intelligence layer the best correlation engine that the world has ever seen and we're big fans of that and we that's why we partner with them and that's why they're we're working together doing joint research that's why we have access than non-public models and that's why we're deeply embedding them into our exposure management platform but discovering new vulnerabilities is not what we do yes we've discovered 500 new vulnerabilities since our ipo in 2018 but here's what exposure management is first it starts with discovering your entire digital footprint all of your app your systems your app your systems your workloads um whether it's on the network whether it's in the cloud whether it's on the factory floor we discover all of that are your devices and systems and we inventory it and then we enrich it with ownership data so if there is a breach we can tell you what vulnerability and what device and who owns and who's responsible for that data more importantly we assess all those devices and systems network cloud manufacturing facilities for vulnerabilities and exposures to be clear a vulnerability and exposure for us is not just a cve a critical vulnerability a finding a bug in a code matter of fact much of what we the data we collect is not that it's misconfigurations it's compromised credential it's over privilege entitlements and access and it's often operational errors in the race to deploy new technology in the race to to innovate and then more importantly it's the prioritization of those right you can't triage and remediate and patch everything not in the agentic era and so we're able to identify a critical vulnerability determine if it's been recently or frequently exploited and we can tell you if that vulnerability is on a device or system that has sensitive data we we have we determined the context and the criticality of that data. And moreover we're able to chain all those things together in a way to identify critical attack paths. Critical attack paths that threat actors are likely to take to exploit your most sensitive data, and then it's the remediation piece of it. that's our north star it's the aggregation of all the data that we collect to be able to provide the context so security practitioners can take action to reduce risk in an automated way and do it deterministically with confidence and we can validate if that action was taken what's indeed did secure reduce the exposure and our platform is built on three critical layers here the first layer is our basically our surface and signals and over the last 20 years we've earned the trust to be placed have sensors on a data center and an enterprise network we've earned the trust from fortune 500 companies to do passive network monitoring and telecommunication systems and oil refineries and manufacturing facilities we also have we also have agents that deployed on endpoints and cloud workloads we also have identity telemetry that's both on-prem and in the cloud so in aggregate it is it creates major moat for us it's infrastructure it's sticky it's hard wand and um it's uh it's an important part of what we do and the rest of the platform is built on that which takes us to our exposure data fabric we over the years have have 1.7 nearly two trillion of findings these findings um it allows us to take raw telemetry data and turn it into a unified model so we can help customers assess risk across a wide range of domains and able to correlate it decorate it score it we also ingest data from other security companies and by the way we're leveraging the frontier models to help us explain risk better to help us do reasoning better and correlate better and then more importantly what all that provides is the third layer which is hexa our agentic engine that we released a couple of weeks ago and we announced our exposure conference in our investor day hexa is our agentic engine that sits on top of our data fabric and it comes with a fleet of agents customers can build their own but we also have a lot of agents that are in hexa that allows you to automate critical workflows that allows you to take action whether it's isolate an asset on a network whether it's apply a patch whether it's changing a configuration and even over the course of time adding and compensating controls but it is our north star it takes vulnerabilities and turns them in the fixes. It takes manual workloads and automates them. And it also takes lots of manual systems into a single unified platform. So super excited about where we're going. And AI creates certainly major tailwinds for us. So the right way to think about us in context of ai is number one securing the attack surface that ai creates ai applications systems models workloads that's proliferating all that needs to be secure all of that is important to discover and assess and then be able to monitor prompts and tie it back to your policy and then the second thing is the force multiplier on the on the insights that we can deliver and more importantly the action we can take not only to help customers understand risk but to reduce it in an automated way so defenders can fight ai with ai move um at machine speed which is what this threat environment demands so that'll turn it over to matt brown our cfl

okay so i'm going to jump into some of the numbers uh what steve just laid out was super important um to understand the opportunity that's in front of us but i think it's also under important to understand where we've come from and the foundation that we're starting from so you know one of our strengths is is the depth and breadth of our customer base we've got over 40 000 customers spread out over 160 countries we've got over 8 000 channel partners and our revenue is highly recurring so you can see here these numbers are as of q1 which ended in march but 96 of our quarterly revenue was recurring in nature over the past several years these this is revenue on a trailing 12 months basis we've grown revenue 13 and as of the end of q1 on a trailing 12 months basis we've now exceeded 1 billion dollars in revenue for the first time and so i give some of that context because the opportunity in front of us is massive but it matters where we've come from we're coming from a really really stable base of consistent growth and a vast customer base and all of these customers are becoming increasingly concerned about the threat that ai poses and they're looking to tenable to help them address those very specific concerns while we've been growing our top line revenue we've also been growing our profit which is a really important thing for us to balance both revenue growth with profitability growth and you can see that's increased tremendously over time on a ttm basis in q1 we're now at 22.7 percent op margin which is up from from just over 10 several years ago and that's translating to additional cash as well so cash flow generation super super strong which is increasingly an important part of our story one of the things that we've been doing with that cash is we've been buying back a lot of shares we believe that our stock is trading at a price that doesn't represent the true value and as a result we've been leaning in heavily on share repurchases at the beginning of the year we asked and the board authorized an incremental authorization to our share repurchase program of 150 million dollars bringing that authorization over 300 million dollars we've leaned heavily into that so spending 130 million dollars in the first quarter and we're going to continue to do that throughout the year again because we think that's a really good use of capital right now so i want to talk a little bit about tenable one steve laid out why tenable one is so important for our customers for our customers being able to use Tenable One for identification and to gain insights and then finally for action with HEXA, the benefits to our customers are clear. But the benefits to Tenable for our customers being on the platform are also clear. So we know that customers that are in the platform have longer contract durations. So Tenable One customers have contract durations that are more than 10% longer than our non-platform customers. We know that Tenable One customers spend more money with us. They have much higher ACVs. In fact, Tenable One customers, ACV there is two to three times our non-platform customers. Those customers also expand more. So average expansion when our customers do expand is more than double in the platform versus not on the platform. We know that there's a competitive differentiation. So when we're in head-to-head bake-off situations with our competitors, when we lead with Tenable One with the platform, our win rates are significantly higher than when we lead outside of the platform. And then finally, moving customers from being not on the platform to in Tenable One, we see a significant price increase. We have two Tenable One platforms now. We have Tenable One Foundation and we have Tenable One Advanced. And this is relatively new for us. Standalone customers that are doing standalone VM today, moving from standalone into tenable one foundation, they see a modest price increase of about 6%. For us, that's important. It's a nice on ramp for those customers to get into the platform. And then they can expand from there and move on to tenable one advanced. The tenable one advanced price uplift is 60%. So quite significant. The idea is for us to get them into the platform, ideally expand and then move upward. And we're meeting our customers where they are on their exposure management journey. So we're already seeing early success with this. There's new pricing, new flexible pricing that goes with it that we've been able to see some some real benefits from already as well. What this translates to is that within the platform, we're seeing growth growth in the mid teens right at the non-platform growth is about mid single digits you can think of that as sort of our legacy business that's important because it matters for what our growth algorithm is today and then also as we look ahead this is what the growth algorithm looks like so today platform customers represent about a third of our business and again growing it about the mid-teens non-platform is the remainder and growing in mid single digits and that's translating to high single digit revenue growth today what we expect though over the next several years is that tenable one will continue to occupy a larger portion of our overall business and will continue to grow in mid-teens and when i talk about that growth rate that's adjusted for platform change. So if a customer was spending $100,000 with us not in the platform before they convert to the platform and maybe now they're spending $115,000, that's 15% growth in the platform, not 115% growth. So this is all normalized for platform change. The composition now of the revenue as we look ahead to 2029 is that more than half of our business is going to be on the platform while continuing to grow mid-teens and the rest is continuing to grow mid-single and that translates to increasing revenue growth in the high single digit to low double digit revenue growth range what we really are trying to do is get roughly 20 percentage point shift in the composition of the business moved over and growing in mid-teens and that's how you get that two to three percentage point growth um in the revenue growth rate that we expect to see over the next several years so what does it translate to in terms of midterm targets we had an investor day a few weeks ago put these midterm targets out i wanted to share them again with you all here you can see the fy26 guidance there at the midpoint where we're growing high single digits in revenue and that's translating to about 24 percent margin for op income and free cash flow unlevered free cash flow margin at 27 percent. We expect again by leveraging the growth that we're seeing in the platform that by the time we get to exit 2029 that revenue growth is going to begin to inflect higher and we'll see accelerating growth in the high single digits to low double digit revenue growth well at the same time we'll continue to add profitability so getting from op margin adding roughly 150 basis points per year from the end of 2025 coming a little bit from a gross margin we expect to basically maintain that level at 82 or so most of it coming from sales and marketing and a little bit of gna to get about four percentage points over the next three years. So that that sort of lays out the foundation from a from a financial perspective and what we see, as we look ahead to exiting 2029. So I think I know we want to leave at least a few minutes for some for some q&a. So I'll just advance to the next slide. And we can take it from there. Yeah,

Jonathan Ho Analyst — William Blair

presentation, where I kick it off in terms of the questions, and then we'll turn it over. We probably have time for one question from the audience as well. But I think the primary question I have for you is when we think about mythos and we think about this potential gain in function from the next generation of models that's coming out there, not only is it more capable in terms of discovering far more vulnerabilities and far more quickly, but there's also a chain capability that allows you to put together there are multiple exploits, that's far more dangerous than what existed in prior versions of these models as well. And so I can imagine the day that Mythos becomes generally available, then suddenly, all of the bad actors that are out there, all of the threat actors, they're going to have a field day, initially putting this to work, identifying all these vulnerabilities. And suddenly, your customers who are already overwhelmed in terms of the number of vulnerabilities they're dealing with pre-mythos are going to have a very, very difficult time. In a lot of our conversations with these types of customers, they're asking us what they should do. And so can you help us understand when they come to you, what does that conversation look What can you do to help them? And what does that do ultimately in terms of the ability to translate to revenue?

It's a great point. And as Jonathan just laid out, there's something called the defender's dilemma in cybersecurity, which is the threat actors just need to exploit one thing to be successful, whereas defenders need to secure everything. And if you kind of look at the defenders dilemma today, there's a proliferation of vulnerabilities. The attack surface has expanded. There's the adoption of new technology. By the way, we haven't even talked about agents on average. I think you're going to see hundreds of thousands of agents from companies over the course of the next couple of years. all of that needs to be discovered and secured so when it comes to how we can help our customers number number one um i think we talked about this on the last earnings call an investor day but the level of engagement with our customers has been absolutely overwhelming they're turning to ask asking us what can we do and um and our advice is is this um because we're partnering we've partnered with anthropic we're a tier one partner we've partnered with open ai we are part of the oncd the office of the national cyber security director task force helping the federal government who arguably is the most sophisticated consumer of cyber technology in the world helping them share identify best practices and working to help reduce their risk in state and local matters critical infrastructure and federal systems systems and it's really simple in a post mythos world number one discuss like first of all know what you have discover your entire digital footprint it starts there what systems do you have is it on the network workloads in the cloud devices on the factory floor enrich that with ownership data so if you understand if there is a attack or a risk like who's responsible and you can move fast in hours minutes not not in terms of of days and weeks and then And the most important thing is assess and prioritize, though we there will be a proliferation of vulnerabilities, and it's not just a one time thing that it'll continue to play out here of the course of of of quarters and even years. So prioritization is not optional. What are your most critical exposures in exposure management? It's the fewest actions that have the biggest impact to reduce risk and to do that in a very automated way. That's what we're all about here. And in order to do that and to do that deterministically and allow defenders to have the confidence to do that, it takes our exposure data, the context, the data fabric. So know what you own, ruthlessly prioritize, and then move at machine speed.

Those three simple things. Yeah, and I'll connect to how that generates revenue growth. exposure management has never been more important and there are now greenfield opportunities for companies that have not taken exposure management seriously in the past, or perhaps early on in their exposure management lifecycle. Those companies are now faced with a reality where prioritization is absolutely critical understanding what's in your environment and what are you going to do about it is necessary now. And so there's a there's brand new opportunities that are happening. In addition to that, you have now you brought up a great point, which is these models are not only good at discovering new vulnerabilities, they're also really good at chaining together what could have been low critical criticality vulnerabilities and changing those together to to form an advanced attack. Well, what that means then is that our customers are going to need to need to scan more of their environment. I mean, it's not good enough to focus just on a subset of their, of their environment. They're going to need to scan more. And for us, that means within the platform, that's an expansion opportunity. So we have both new opportunities. We have expansion opportunities and, you know, as we hopefully laid out a little bit in, And in the slides, we're coming from an incredibly strong position, having our roots in VM and having established this category of exposure management, really ourselves, leading the And again, and not just us, it's Gartner and it's Forrester and it's IDC saying it. We believe this opportunity is ours for the taking.

Jonathan Ho Analyst — William Blair

Go ahead.

Sure. The question really is talking about stock-based comp and how that's impacting those numbers and if we had adjusted for stock-based comp, what the cash flow would look like. I can't tell you the exact numbers. You're saying if stock-based comp was cash instead, is that sort of ... No, no, no. Your question really is just, hey, take the stock-based comp as a percentage of revenue and just deduct that from the margin. And we're basically at high teens right now, down actually year on year from stock-based comp as a percentage of revenue. And that's something that we're gonna continue to manage and look at. I mean, the reality for us of stock-based comp is we're in a really competitive environment. And when you look at our peer companies, we're in pretty good company with how our stock-based comp as a percentage of revenue ranks relative to our peers. and and you know it's it's a competitive environment to go higher so sure so depending

on your view so we generate meaningful cash flow even when you include stock-based comp as a cash charge yes so that's just want to be very clear about that yeah yeah so is there a question or

yeah yeah i mean we think of it as compensation as well and so we expect that that as a percentage of revenue is going to improve somewhat as well as we get from now until 2029 so we'll continue to make progress flat as a percentage of revenue no it's not going to be flat in total no but the growth in cash flow will far exceed the growth in stock-based comp so we've reached the end of our

Jonathan Ho Analyst — William Blair

time so thank you very much and we'll continue in the breakout session up in jenny b thank you