All QLYS transcripts

QUALYS, INC. (QLYS) Q1 2026 Earnings Call Transcript

49 segments

Prepared remarks

OperatorOperator

Ladies and gentlemen, thank you for standing by. Welcome to Qualys First Quarter 2026 Investor Call. The operator provided instructions to callers. Please be advised that today's conference is being recorded. I would like now to turn the conference over to Blair King, Investor Relations. Please go ahead.

Blair KingInvestor Relations

Thanks, Michelle. Good afternoon, and welcome to Qualys' First Quarter 2026 Earnings Call. Joining me today to discuss our results, Sumedh Thakar, our President and CEO; and Joo Mi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to product capabilities, future events or future financial or operating performance. Actual results may materially differ from these statements and factors that could cause results to differ materially are set forth in today's press release and in our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. A reconciliation of GAAP to non-GAAP measures is included in today's earnings press release. As a reminder, the press release, prepared remarks and investor presentation are all available on the Investor Relations section of our website. So with that, I'd like to now turn the call over to Sumedh.

Sumedh ThakarPresident and CEO

Thanks, Blair, and welcome to our first quarter earnings call. I'm pleased to report we delivered another quarter of strong revenue growth and profitability. With the accelerated progress of frontier models discovering vulnerabilities and writing exploits autonomously, the number of detections is going to go up significantly while the exploit window is going to shrink dramatically. The need for organizations to know their true risk to effectively prioritize and auto-remediate riskiest vulnerabilities in less than a day has never been greater. This is why we innovated with the ETM enterprise threat management platform, which implements an AI-driven risk operations center so customers can get the risks remediated instead of relying on dashboard-tourism with siloed products that increase their exposure. Given our #1 rating in the GigaOM Patch Management radar, with over 150 million patches deployed and over 40 million of these delivered autonomously in the last year with six-sigma accuracy, organizations are turning to Qualys as the trusted solution to help them move from current broken manual remediation processes to high-impact, low-risk autonomous remediation workflows at scale that go beyond patch management. And that's exactly where we are focused. With exploitable vulnerability volumes surging 6.5x and average time to exploit collapsing to under a day as adversaries weaponize vulnerabilities before patches even exist, security teams focused on theoretical exposure are overwhelmed. Just finding more and more vulnerabilities doesn't equal risk. Real risk is determined by whether an adversary can successfully execute an exploit path in an organization's live environment. That's why I'm pleased to report that our most recent addition to our agent AI marketplace, Agent Vail, is now generally available, powered by TruConfirm within our ETM solution. Agent Vail delivers closed-loop exploit validation and autonomous remediation directly to the agent. Using autonomous exploit validation at scale, we remove the guesswork for customers by running safe exploits over the network to confirm whether attackers will succeed in their breach attempts while enabling security and IT teams to focus on the less than 1% of threats actually exploitable in their production environment. In doing so, we have closed the gap between theoretical and actual exposure and believe we have set a new adoption standard in the industry. While traditional ETM solutions take days to pull scan telemetry from scanning tools and rely on theoretical risk scores ignoring mitigating security controls, ETM and its agentic AI workforce take a fundamentally different approach. Inside a continuously functioning loop, it detects vulnerabilities, validates exploitability, quantifies real risk, automates remediation and revalidates the exploit, optimizes and integrates with leading LLM and SLM. This end-to-end approach empowers organizations to be laser-focused on prioritizing only exploitable threats for the next logical step, which is autonomous remediation. Leveraging the agent era and TruRisk Eliminate, we are eliminating risk. Underpinning our risk-eliminated solution is our new AI-powered patch reliability score, a model trained on our proprietary data set of hundreds of millions of deployed patches, which predicts patch-induced outages before they happen, giving customers the confidence to deploy with certainty while setting a new standard for predictive, operationally aware patch management. With an umbrella of remediation solutions, including patching and other compensating controls, with less than a 10% rollback rate, the AI-native risk fabric accelerates, streamlines and democratizes security outcomes, transforming from “we think” to “we know” that it's being fixed at machine speed. In the context of the newest frontier AI models giving attackers the ability to discover diverse zero-day vulnerabilities, generate exploits in near real time and develop autonomous attack agents unlike anything the industry has seen, the feedback to our “get it fixed” approach from many of the CISOs I met at our recent EMEA event in London has been very positive. They shared their excitement about the rapid pace of new capabilities we are delivering, their deployment agenda and their ability to now autonomously monitor, measure and confidently remediate actual risk in multi-vendor environments in an era where just generating visibility dashboards is increasingly unacceptable. Our industry-leading capabilities are gaining broader recognition among our customers, partners and third-party analysts. Specifically, our Total Cloud solution was recognized as a leader in CNAPP in the Q1 2026 Forrester Wave report, and subsequently won the 2026 SC Award for Best Cloud Security Management solution. Both underscore our capabilities in delivering unified visibility with real-time detection and response at runtime across hybrid environments. It was also positioned as a leader in the 2026 GigaOM report for cloud entity and title management and, following our dual-pennant awards late last year, our threat research unit has again demonstrated its impact with the discovery of TrackArmor uncovering critical AppArmor vulnerabilities that can lead to root-level compromise and container escape across millions of Linux systems worldwide. This, alongside our recently released research on the broken physics of remediation, further demonstrates Qualys' commitment to fortifying security operations and raising the bar on adversaries. The net result is that we have distinctly unified CTM exploit validation, cyber risk quantification and remediation into a single AI-driven risk fabric that continuously senses, reasons and acts across hybrid environments. With these capabilities and growing risk momentum that will soon autonomously trigger ITSM workflows, we remain laser-focused on accelerating ETM adoption throughout our vulnerability management and detection-response customer base and positioning Qualys for larger upsell opportunities over time. Turning to our business update. We have established a long history of converting operational challenges into strong competitive advantages demonstrated by customers spending $500,000 or more growing 9% from a year ago. That's why one of my favorite wins in Q1 was with an existing global 1,500-customer despite strong foundational visibility: their teams struggled to operationalize risk reduction across the growing mix of on-prem and multi-cloud environments, siloed tools, fragmented telemetry, a growing population of LLM-driven findings and millions of vulnerabilities with limited business context. This customer recognized the traditional severity-based prioritization methods were no longer sufficient and launched a strategic initiative to unify risk signals across their environment and operationalize the risk. Leveraging AI for security and security for AI, they expanded the Qualys footprint by adopting ETM and Total AI in a mid-six-figure annual upsell. By consolidating disparate signals into the Qualys platform, this customer now has a unified orchestration layer that delivers end-to-end visibility across the attack surface, including deep scans on their assets across binaries, open-source libraries and dependencies with centralized risk quantification, prioritized remediation workflows and measurable outcomes aligned with business risk tolerance. This win reflects broader ETM momentum as more and more customers turn to Qualys for evidence-based exploit validation and remediation while benefiting from the efficiency and scale of AI-native automation. Partners remain a key pillar for our growth agenda. In addition to a growing list of nearly two dozen certified MRO partners beginning to actively launch new services, we are seeing momentum build across all geographic theaters with a strong focus on AI and native risk. For example, one of our largest MRO partners is now in the process of bringing a case-ready AI-native risk solution to market powered by our ETM and automated remediation solutions. Additionally, through our strategic alliances initiatives, we continue to drive deep technology integrations, co-selling opportunities and demand-generation programs to drive innovation in security research through the latest models. We have partnered with OpenAI in their special access for cyber program and with Anthropic in their cyber verification program to advance our vulnerability and threat intelligence and allow customers to ingest these findings into ETM for further detection and remediation. On the cyber insurance side, we are also pleased to announce a new strategic partnership with Converge Insurance, leveraging the Qualys team solution to help their customers demonstrate strong security hygiene and qualify for meaningful premium reduction, advancing our vision of tying cybersecurity to business outcomes. Further supporting our growth trajectory in Q1, we continue to expand data testing of Q-Flex designed to help customers accelerate and broaden their adoption of the Qualys ETM platform. Based on strong early engagement and positive feedback, we're planning to build on this momentum by proactively identifying opportunities to extend Q-Flex to select customers and partners with a go-live date planned for later this year. And finally, as the federal government seeks to gain greater efficiency and replace outdated and costly on-prem deployments from years past with modern cloud-native risk management solutions, we are especially excited to host our third annual Qualys conference in Washington, D.C. towards the end of this month. We have made good progress growing our federal business and advancing our FedRAMP High status with large federal agencies, and we continue to believe this market will fuel a new leg of growth for the company over time. In summary, we are pioneering a new category in pre-breach risk management by bringing autonomous exploit validation, risk quantification and zero-day remediation together within a single AI-driven risk fabric that redefines how enterprises operationalize cyber risk. Complementing frontier models that discover vulnerabilities, our platform leverages proprietary domain data, real-time telemetry and deep operational context using sensors and agents behind the firewall to continuously discover assets, validate exposures, quantify risks, remediate threats and enforce company-specific policies, which are unavailable in the public domain. This is driven by our two decades of processing petabytes of structured telemetry, combined with industry-leading threat intelligence in a closed-loop system that compounds across thousands of customer environments every day. Frontier models are powerful and accelerate back-path analysis and triage. However, they need to be paired with a highly reliable control plane to consistently enforce accurate policy and compliance outcomes across live hybrid environments. This is where the unique value proposition for Qualys customers lives, and it requires deterministic, auditable, repeatable and trusted execution with effectively zero tolerance for error as attacks move at machine speed and increasingly require defenses to learn and respond in real-time closed-loop. Agent orchestration-driven policy and harnessed by flexible model choice act as a force multiplier further enabling precise risk quantification, safe remediation and even faster and more deterministic outcomes at scale. For Qualys, this means our massive data context, LLM and SLM integration and trusted execution serve as the system of record for pre-breach cyber risk management and translate AI into a packaged risk automation platform that delivers customers measurable risk reduction, zero-day remediation, governance outcomes and immediate ROI. With that, I will turn the call over to Joo Mi to further discuss our first quarter results and outlook for the second quarter and full year 2026.

Joo Mi KimCFO

Thanks, Sumedh, and good afternoon. Before I start, I'd like to note that except for revenues all financial figures are non-GAAP and growth rates are based on comparisons to the prior year period unless stated otherwise. Turning to first quarter results. Revenues grew 10% to $175.6 million. The channel continued to increase its contribution, making up 52% of total revenue compared to 49% a year ago. Revenues from channel partners grew 17%, outpacing direct, which grew 3%. As a result of our strategic emphasis on leveraging our partner ecosystem to drive growth, we expect this trend to continue. International, with 15% growth outside the U.S., was ahead of our domestic business, which grew 6%. U.S. and international revenue mix was 55% and 45%, respectively. In Q1, as expected, there was no meaningful movement in our net dollar expansion rate, closing the quarter at 104%, slightly up from 103% last quarter. More importantly, we'd like to turn to a new metric that we plan to disclose going forward on a quarterly basis: net dollar expansion rate of customers with a prior-year purchase of ETM or CSAM subscriptions. We believe that this metric is currently the best indicator of success for our ETM strategic initiatives, with ETM innovation having stemmed from strong customer demand. We anticipate ETM adoption to drive higher net dollar expansion rates. However, given that ETM adoption is still in its early stages, we have decided to include CSAM customers in this cohort so that the metric has more weight to it. In addition, as a reminder, ETM is essentially an upgrade from CSAM. So we believe that this is an appropriate baseline to track and measure going forward. In Q1, the net dollar expansion rate of the ETM/CSAM cohort was 107%. As more customers move into this cohort, we hope to see consistent and meaningful improvement to our overall net dollar expansion rate and thereby drive accelerated revenue growth. Moving on to product mix. Our differentiated new products continue to drive growth. First, ETM and CSAM combined made up 11% of total bookings and 14% of new bookings on an LTM basis in Q1, up from last year's 8% and 9%, respectively. Next, patch management made up 8% of total bookings and 15% of new bookings on an LTM basis in Q1. This compares to 7% and 16%, respectively, in Q1 of last year. Lastly, Total Cloud made up 5% of total LTM bookings in Q1, unchanged from a year ago. We believe that these differentiated products, combined with increased contribution to bookings in 2026, give us an opportunity to increase market share and maximize share of wallet. Reflecting our scalable and sustainable business model, adjusted EBITDA for the first quarter of 2026 was $83.3 million, representing a 47% margin, the same as last year. Operating expenses in Q1 increased by 8% to $67.5 million, driven by investments in sales and marketing, which grew 17%. With this strong performance, EPS for the first quarter of 2026 was $1.95 per diluted share and our free cash flow was $93.6 million, representing a 53% margin compared to 67% in the prior year. In Q1, we continued to invest the cash we generated from operations back into Qualys including $1.7 million on capital expenditures and $53.9 million to repurchase $505,000 of our outstanding shares. Since commencing our share repurchase program in February of 2018, we've repurchased 11.2 million shares and returned $1.3 billion in cash to shareholders. As of the end of the quarter, we had $306.6 million remaining in our share repurchase program. With that, let us turn to guidance, starting with revenues. For the full year 2026, we now expect revenues to be in the range of $721 million to $727 million, which represents a growth rate of 8% to 9%. This compares to prior guidance of $717 million to $725 million. For the second quarter of 2026, we expect revenues to be in the range of $177.5 million to $179.5 million, representing a growth rate of 8% to 9%. While we believe our approach to pre-breach cyber risk management provides some insulation in the face of ongoing macro volatility, this guidance continues to assume no material change in our net dollar expansion rate, with moderate growth contribution from new business in 2026. Shifting to profitability guidance. For the full year 2026 we expect EBITDA margin to be in the mid-40s, implying mid-teens increase in operating expenses and free cash flow margin in the low 40s. We expect full year EPS to be in the range of $7.44 to $7.65, updated from the prior range. For the second quarter of 2026, we expect EPS to be in the range of $1.73 to $1.80. Our planned capital expenditures in 2026 are expected to be in the range of $8 million to $12 million and for the second quarter of 2026 in the range of $1.2 million to $3.2 million. As the impact of the macro economy is still unfolding, we are closely monitoring the business environment and adjusting our priorities accordingly. That said, considering the long-term growth opportunities ahead of us and our industry-leading margins and planned further room for investment, we intend to continue to responsibly align our product and marketing investments to focus on high-impact initiatives — driving more pipeline, accelerating our partner program and expanding our federal vertical. As a percentage of revenue, we expect to prioritize an increase in investments in sales and marketing with more modest increases in engineering and G&A. With that, I would be happy to answer any of your questions.

Questions and answers

OperatorOperator

Operator provided instructions. The first question will come from Patrick Colville with Scotiabank.

Patrick Edwin ColvilleAnalyst (Scotiabank)

In your prepared remarks, I mean, I think you did a really good job of conveying why risk quantification, testing whether an asset is exploitable with runtime context, the ability to patch and revalidate all make Qualys at low risk of AI disruption in the enterprise. But what I want to ask, though, is there's a lot of hype around Anthropic Claude, Midos, OpenAI, GPT 5.4 and other frontier models. Are they leading to more inbound interest? And if so, how will those inbounds and that surge of interest translate into the financial model in 2026?

Sumedh ThakarPresident and CEO

Yes, that's a great question. And I think our customers who are in this every day understand pretty well that this is going to lead to more disclosures of patches and vulnerabilities from multiple vendors that they use. On the positive side, I think these models are helping companies get better at finding these vulnerabilities themselves versus waiting for third parties to find them, but it also means they're going to lead to more patches being announced by multiple vendors that customers will have to deploy. The challenge will be that once patches come out, attackers leveraging AI can reverse-engineer those patches and find the exploits. It really becomes a game of how quickly you can apply the patch that the vendor provides in a matter of hours and not wait for days and weeks as often happens today. That's where a lot of the conversations we have had with our customers focus. We're seeing a lot of CISOs and customers reaching out to understand how our patch management capability, remediation capability and exploit validation capability will help them because they all need to provide an update to their boards on how they are going to fight against AI-induced attacks. The response cannot be more manual remediation. They need a response that anchors in fighting autonomous AI attacks with autonomous remediation. They see us as a trusted vendor having deployed 150 million patches already and 40 million of those fully autonomously deployed. A lot of those conversations are positive right now, but of course it's early stage, and we need to work through how these conversations translate into pipeline and outlook. As Joo Mi said, we're not changing guidance today. But we are happy with the inbound engagement we're seeing from customers trying to understand how to respond.

Patrick Edwin ColvilleAnalyst (Scotiabank)

Very clear. And can I just — Joo Mi, you very kindly last quarter provided us a soft guidance for 7% to 8% current billings growth in 2026. Is the point you were trying to make in the prepared remarks that that remains the case? No change to that level even with the strong Q1 performance and the positive vibes Sumedh was just talking about?

Joo Mi KimCFO

Yes, that's correct. If you take a look at our Q1 performance, it was a solid start to the year. We're very pleased with the Q1 results as well as what we anticipate for the rest of the year. However, we don't see any material change for the full year today. So given that, the baseline still remains at 7% to 8% for current billings for the full year.

OperatorOperator

The next question will come from Roger Boyd with UBS.

Roger BoydAnalyst (UBS)

Sumedh, it was a strong quarter from a new customer add perspective, particularly for Q1, which is typically seasonally a little bit lower. Can you just talk about what's working right now from a new logo perspective? And then everything you just mentioned from a patch management and remediation standpoint, to what degree is that impacting the new customer conversation? Any metrics you can give around attach rate of patch management or TruRisk Eliminate would be great.

Sumedh ThakarPresident and CEO

Yes, great question. If you look at where we are with patch management, it's roughly 8% of LTM overall bookings and 15% of new bookings. Good execution by the team and focused execution is key. If you recall our messaging around RSA and our focus on agents last year, what everybody is talking about now is how to quickly autonomously remediate things. This isn't an accident — we've been delivering capabilities around patching, going beyond patching to exploit validation, and those messages are resonating with customers. We're encouraged by conversations around ETM. At the end of the day, risk measurement and risk management are critical because a company can't just deploy all patches. Anchoring prioritization to risk is very important so you eliminate the right risk with the minimum amount of change to avoid outages. ETM does the hyper-prioritization, but for ETM to be successful you need high-quality detection capabilities. One concern customers have raised after these models emerged is the question of false negatives with second-tier scanners; the time it takes to get signatures out and to find findings versus scanners like Qualys, where we are updating signatures multiple times a day and adding capabilities to reduce false negatives, is very important. Those conversations are culminating in positive outcomes for ETM, which is still early, and ETM and Eliminate conversations typically go hand-in-hand. While it's early for ETM, we are encouraged by the conversations. We'll continue to execute. We're happy with how Q1 went and will continue working with partners to bring additional new logos and to get more upsell through MRO services for existing customers.

Patrick Edwin ColvilleAnalyst (Scotiabank)

That's really helpful. And then maybe just a quick one for Joo Mi. On Q-Flex, you talked about building out pipeline and identifying a customer pipeline to extend that procurement model to. Can you just talk about the customers you see as a good fit for Q-Flex, and any thoughts on when that push could start this year?

Joo Mi KimCFO

Yes. Q-Flex is targeted towards our enterprise customers who need flexibility to cover an anticipated forecast for the full year. Typically they're looking for the comfort of pre-purchasing or pre-committing to a higher amount with the ability to swap out different products and offerings and try newer solutions throughout the year. We've been talking with a select group of customers that have the budget and are willing to pre-commit to higher credits with Qualys, with the ability to swap products and try new solutions throughout the year. We're pleased with the momentum we have today, and we do plan to go GA with Q-Flex later this year.

Sumedh ThakarPresident and CEO

I would add that Q-Flex is a good example of a model that will be helpful for customers given the current environment. We didn't have exploit validation earlier last year, but now that we do and we're driving more focus on patching, Q-Flex customers will have more flexibility to use credits to pivot toward more patching if an event comes up and won't have to go back through procurement repeatedly. Exciting early conversations with large customers and we look forward to going GA by the end of the year.

OperatorOperator

The next question will come from Kingsley Crane with Canaccord.

Kingsley CraneAnalyst (Canaccord)

Sumedh, I guess just to start off, I'm curious how important access to something like Midos preview is for your business at all? Then more generally, talking about the growing marketplace of generative AI solutions, we've seen a pretty significant jump recently even with GPT 4.7. What is the future of that type of integration with agents for the platform? And how relevant is inference as a line item for Qualys if you look three years out?

Sumedh ThakarPresident and CEO

Great question. It's less about a particular model and more about the direction these models are going. We've been leveraging open-source models as well, and we're excited to be part of OpenAI's TAC program, which gives us access to cyber models that are roughly equivalent to Midos, and to be part of verification programs. Since we've been doing a lot of exploit and validity research ourselves, these models, whether two frontier models or open-source models, help us do a better job of figuring out exploits that we can safely create for customer environments so customers can test at scale through the Qualys platform. They also help us find mitigations that don't require a patch; we reverse-engineer patches to identify other mitigations that can be leveraged to deploy compensating controls on machines without immediate patching, which is valuable when customers have only hours to decide how to mitigate a highly exploitable vulnerability. That research is something we've been doing and these partnerships accelerate and broaden our options to help customers. So I see leveraging these models, whether through research or integration to pull findings for customers to run through the millions of Qualys agents they have installed, or via our own agentic AI solutions, as important. We use different small and large language models to optimize outcomes, whether chat or AI agents taking action. Given we uniquely do exploit validation and patching, we have an interesting use case for these models.

Kingsley CraneAnalyst (Canaccord)

That's really helpful. And for Joo Mi, it's great to see the continued efficiency in the business. You've talked about R&D growing a bit more modestly than sales and marketing this year. So a 2% growth year-over-year, is that about what we should expect for the rest of the year? And bigger-picture in such a dynamic time for cybersecurity, what would get you to invest more in R&D? I understand you're efficient operationally, so I appreciate that context.

Joo Mi KimCFO

Currently, we're forecasting OpEx growth in the mid-teens. Sales and marketing continued to grow strongly, around the 15% mark. Last quarter it grew 18% year-over-year; this quarter it grew 17% year-over-year. With sales and marketing potentially ramping in the second half, the remainder of the OpEx is allocated for R&D for the most part. We would invest more in R&D if we see justified returns, especially with AI investments. Given that, we're guiding to mid-40s EBITDA margin, which implies mid-teens growth in OpEx.

OperatorOperator

The next question will come from Jonathan Ho with William Blair.

Jonathan HoAnalyst (William Blair)

I just wanted to better understand the breach risk management opportunity, how maybe this changes from prior approaches, and what makes Qualys better positioned than other competitors to offer this solution.

Sumedh ThakarPresident and CEO

Great question. From a Qualys perspective, this isn't a wholesale change; we've been building and innovating around the ETM platform and the concept of a risk operations center for a couple of years in preparation for a surge in vulnerabilities. You can't fix everything manually, and you can't just move from scanner to scanner. The idea of creating a risk operations center and ETM is to create an outcome where things are fixed for the customer in a matter of hours. This is different from many CSAM solutions that wait for data from different scanners, create reasoning, but then they don't do the patching — they pass it off and lose time. What we're seeing is demand for an end-to-end solution. At RSA we demoed Agent Vail going from finding a vulnerability, validating the exploit, applying a mitigation and revalidating the exploit as fixed in under 15 minutes. I don't know if any CSAM solution can really do that to deliver a fixed outcome. With ETM, we focus on CRQ — contextual risk quantification — because vulnerability and patch counts will explode and customers need to think in business terms and budgets. They need to prioritize what to fix. That's why ETM's integration with cyber insurance is meaningful: if you have a strong score and cadence of fixing vulnerabilities, you can qualify for a premium reduction. ETM blends CSAM-style collection, exploit validation and remediation to deliver an outcome. We're seeing customers more open to autonomous remediation and patching given the changed threat landscape, and that is a positive for us.

Jonathan HoAnalyst (William Blair)

Excellent. Just one quick follow-up: Does Midos potentially expand the number and types of assets you would cover, and might it accelerate adoption of more products on the platform to deal with increased complexity?

Sumedh ThakarPresident and CEO

Yes. These models can find vulnerabilities across any codebase, and that's where the comprehensive nature of Qualys sensors — covering network assets, endpoints, firewalls, VPN devices, cameras, IoT, cloud and containers — matters. The customer interest is to cover as much as possible natively so they can get quick scan results and not have to wait. If you can natively scan more asset types and get faster, higher-quality results, customers are more willing to consolidate. Many customers today do dashboard tourism with separate dashboards for each scan domain. If they can normalize signals and focus on what matters, validate with exploits and remediate those, that is the ideal operational approach. How these conversations proceed will be interesting, but it does push customers toward a unified workflow.

OperatorOperator

The next question will come from Rudy Kessinger with D.A. Davidson.

Rudy KessingerAnalyst (D.A. Davidson)

I'm curious on ETM sales so far. Are you getting that full dollar uplift on those early sales so far? And on the 107% net expansion rate for the ETM/CSAM cohort, does that expansion percentage include upsell from purchasing ETM? Could you break that number down a bit further?

Joo Mi KimCFO

It's a little too early to comment on actual dollar uplift versus list price; the cohort of customers with ETM subscriptions is still small. The 107% figure includes customers who purchased CSAM or ETM. The way we calculate it is: we take customers who had ETM or CSAM subscriptions one year ago (Q1 2025), use their revenue then as the denominator, and compare it to the same cohort's revenue in Q1 2026 as the numerator. So the percentage reflects total spend by that cohort, not just the ETM or CSAM subscription amount. Our hypothesis is that these customers will upgrade from CSAM to ETM or adopt ETM, and that cohort will be stickier and generate higher upsell over time. That's why we're tracking this metric to see if we're successfully upgrading CSAM customers to ETM and whether that drives the upsell we expect.

Rudy KessingerAnalyst (D.A. Davidson)

Got it. That's really helpful. And secondly, what does sales productivity look like and how has that been trending? Given increases in sales and marketing expense outpacing revenue growth, is that more marketing dollars or where is that investment going?

Joo Mi KimCFO

The majority of the increase in sales and marketing is driven by headcount. Our sales and marketing headcount grew over 10% and is focused on direct sales, ETM sales, and channel management. We see huge upside in the business and are moving business from direct to indirect via partners, which requires investment. Productivity isn't at the long-term level we expect yet; there's room to increase efficiency. For now, we're investing more to capture the opportunity rather than optimizing for productivity immediately.

OperatorOperator

The next question will come from Joseph Gallo with Jefferies.

Joseph GalloAnalyst (Jefferies)

You mentioned guidance today reflects NDR staying flat. ETM NDR is 107% and expected to grow. How should we think about the timeline for acceleration of total NDR? Are there pressures or offsets that might keep that number flat over the next couple of quarters?

Joo Mi KimCFO

Our net dollar retention has been around 103%–104% for the last few quarters. For our baseline guidance, we assume that remains the case because ETM is still in the early stages, and we don't foresee a significant ramp in adoption this year that would materially move company-level NDR. Macro factors and geopolitical conditions could be headwinds, which could be offset by increased demand for our solutions. But for guidance purposes, we're modeling a baseline case where NDR remains roughly flat for the year.

Joseph GalloAnalyst (Jefferies)

That's super helpful. As a follow-up, you mentioned geopolitical tensions. Is that the main factor, and have you seen any changes in budgets over the last 90 days — are customers prioritizing AI spend over cyber or vice versa?

Joo Mi KimCFO

We monitor this through customer conversations with existing customers and prospects. Announcements from major model providers can be a disruption to discussions: they can increase interest but also lengthen sales cycles. So there are puts and takes. Some opportunities accelerate while others see longer decision timelines. Modeling the baseline at the start of the year accounted for those dynamics, and we continue to watch conversations closely.

Sumedh ThakarPresident and CEO

So far, we haven't seen any material changes to customer budgets related to cyber; conversations are roughly the same. We're being prudent about potential shifts, but no major changes to report yet.

OperatorOperator

The next question will come from Shrenik Kothari.

Shrenik KothariAnalyst

Thanks. In light of frontier AI, the explosion in exploit discovery and now Agent Vail for broader remediation, you also emphasize pathway patching which you've discussed before. I know you mentioned early customer conversations — any anecdotes or proof points showing this has become a real budgeted operating priority for customers beyond conceptual interest?

Sumedh ThakarPresident and CEO

Yes. An anecdote: a few days ago I spoke with the CEO of a very large Canadian bank. Their challenge was how to quickly get a reliable patching path and who to partner with. When I explained we already provide exploit validation and elimination capabilities, he was excited because he could go to his board and demonstrate a partner that enables rapid patching and mitigation rather than waiting days or weeks. That led to an immediate conversation about starting a POC. Resistance to integrated autonomous patching is easing; customers are asking, 'Do you have patching capability, because that's what I need to show results.' They want the ability to rapidly find, validate with exploit checks, and remediate in a matter of hours, not just find more issues. That's why integrated patching and exploit validation is resonating and leading to concrete conversations and trials.

Shrenik KothariAnalyst

Great. Just a quick follow-up on NDR: what moves the needle for the next leg of growth? You're guiding off a base case with no assumed NDR movement, but you have Agent Vail GA, better ETM mix, continued channel strength and international strength. Is the conservatism mainly due to sales cycles and needing more proof points on monetization, or is legacy product mix drag also a factor?

Joo Mi KimCFO

It's based on historical adoption timelines. New products like CSAM and ETM take time to become a material portion of bookings. ETM has been GA for a little over a year, and ETM plus CSAM currently make up 11% of bookings on an LTM basis. Conversion and upgrade from CSAM to ETM will take time to materially move company-level NDR. So while we see early signs and positive customer conversations, we believe it will be gradual and therefore are conservative in our baseline modeling for this year.

OperatorOperator

The next question will come from Brian Essex with JPMorgan.

Brian EssexAnalyst (JPMorgan)

On the back of increased capabilities of foundation models in the security space, thinking about vulnerabilities across operating systems, packaged software and custom applications and OT environments — where are these models best placed for vulnerability discovery and potential exploitation? How does that change the risk profile of customers and how they may use your platform to mitigate those risks?

Sumedh ThakarPresident and CEO

Great question. Helping software developers find vulnerabilities in their code is a key benefit of these models and will lead to more disclosures. In theory, if developers find them first, they patch them, but attackers can also reverse-engineer patches or chain low-severity vulnerabilities into more dangerous exploits. That's where TruRisk differentiation is important: we have demonstrated we can surface low-CVSS vulnerabilities that are likely to be chained or weaponized earlier than others. Our platform provides the context to say which vulnerabilities matter in a customer's environment and to prioritize accordingly. For cases where patching isn't feasible — some OT assets or specific environments — ETM offers mitigations and compensating controls, like removing unused packages or configuration changes that reduce exploitability. The goal is not only to patch but to remediate and eliminate risk in multiple ways. Our approach of validation, prioritization and remediation — including mitigations that avoid immediate patching — gives customers more options and better outcomes.

Brian EssexAnalyst (JPMorgan)

Makes sense. One quick Q-Flex follow-up: could Q-Flex accelerate migrations to ETM for existing customers?

Joo Mi KimCFO

There is potential. We're working with a solid group of customers to adopt Q-Flex now and plan to go broadly GA by year-end. Q-Flex can help customers pivot usage across products during the year and could support ETM adoption among existing customers.

Sumedh ThakarPresident and CEO

We already have conversations where Q-Flex complements ETM adoption. Customers appreciate flexibility, especially given rapid capability changes and events that require shifting spend quickly. Q-Flex can be helpful even for customers that aren't the largest enterprises.

Brian EssexAnalyst (JPMorgan)

Right. Makes a lot of sense.

OperatorOperator

That is all the time we have for questions. We want to thank you for your participation. This will conclude today's conference call. Have a good evening.

Transcripts come from a third-party provider (Alpha Vantage), not first-party parsing. Speaker titles are as supplied and are not normalized.