Qualys, Inc. (QLYS)
NASDAQ: QLYS · Real-Time Price · USD
182.94
-1.85 (-1.00%)
At close: Sep 24, 2026, 4:00 PM EDT
183.31
+0.37 (0.20%)
After-hours: Sep 24, 2026, 7:45 PM EDT
← View all transcripts

Analyst & Investor Day 2018

Nov 15, 2018

Philippe Courtot
Chairman and CEO, Qualys

Pleasure. I think today we're really in an extremely good position. It took us a long time to get there. As I mentioned many times, I think part of our success is the decision that Sumedh and I made about, I don't know now. I don't count the years anymore at my age. Which at least was seven, eight years ago, Sumedh, when we First of all, I was going to mention in my presentation, but I would repeat it, that we had, of course, some company wanted to acquire Qualys, some of the big ones, and we said no to them. They were a little bit offended.

Speaker 6

That's true.

Philippe Courtot
Chairman and CEO, Qualys

Because we believe that fundamentally, first of all, they didn't understand the cloud at all. They were still these enterprise software companies. For them, they were just trying to acquire best of breed solution and with their other portfolios. We said no to them. We also knew that we needed to re-architect the back end because we had done that first application. This internet technology were not that mature at the time when we started back in 1999. We knew that we needed to re-architect the back end. The decision we made is that we realized that we'd make two decisions. One was to put under Sumedh, ops, DevOps, engineering, QA, customer support, product management, which a lot of people were telling us that we're totally crazy. How could you do that? That's too much.

Again, that means they were not understanding the cloud because on the enterprise software, you have the assembly line, and so you pass the baton from one silo to the next, from the engineers to the QA, to this or that. In the cloud architecture and environment, all of these pieces have to work together continuously. Putting them under one roof was really the right organization structure. We realized that we could not find the talent in California because we needed people with the domain expertise and people who knew the cloud as well. There's not enough of those that we could attract.

We make the decision to essentially. We tried Beijing and we tried India in Pune, and we very quickly realized that China was not the place for us because we didn't have enough of the DNA, and you didn't want to really build a security company in China for reasons that I'm sure you all know. We finally decided to put all our eggs in India. We cloned that structure in Pune, in India, where today we have 650 people. There's a huge pool of talent, and it also allows us to essentially acquire also companies. The talent is coming to us, so we don't have to even reach to the talent. A lot of companies have looked at India as a pool of cheap labor.

I use the famous phrase of Jack Welch, which was saying, "We went to India for the cost, and we discovered the talent. We went to India for the talent, and we discovered the cost." In that order. We have built a fantastic, today, engineering ops, customer support muscle today, which is quite significant. Now today, with that cloud architecture that we have, the cloud has become the distribution channel, so we can bring our solutions almost instantly, globally, and of course, support them 24 by 7, et cetera. Everything is centrally managed. Everything is self-updating. In doing so, we eliminate a lot of cost. Are we powered up? Not yet. Oh, my God. Come on, guys. There it is. Could you move the. Okay. We need probably 15 seconds to get the Mac powered back up. Okay, here it is.

Okay, here we are. Okay, welcome, ladies and gentlemen. Now we start the formal presentation. What I would like to do this morning, today, first of all, we need to go through, of course, the safe harbor, which you know by heart, I'm sure by now. I give you a few minutes if you prefer to read through it. Now with that, we can go to the agenda of the. Essentially, we'll have a series of presentation from Sumedh and Melissa. Then we have one of our customers, which is Experian, which is going to really give you his view, the view from the customer. After that, we have an analyst from The 451 Group, which is a very experienced analyst, who was a CISO before, to give you his views of where the industry is going as well.

What I would like to do this morning is essentially tell you where we are now, where we want to go, and where we're going, essentially, how we see the industry changing and the role that Qualys, we believe we can play in it. First, what I would like to do is to go back to the early beginning. By the way, that screen doesn't work either. Very good. Okay. But that's Okay. Is it powered up? That's it. Okay. It is coming. Very good. Okay. Thank you. We'd like to go to the early days of, like Amazon, fundamentally, we started with books with a vision that it could essentially build a platform and essentially expand. We started with vulnerability management.

What we didn't realize, quite candidly, is the significant resistance that we will have from the security people because at the time, they were looking like the cloud as the place where you don't want to go. Why? Because you lose control, supposedly, of your data. That's the security people are supposed to keep the data safe at home. They didn't like that. However, what happened is that because of our architecture, the architecture of the cloud, which that cloud architecture, which allows us to essentially deploy at a much bigger scale than enterprise software. This is the story of salesforce.com versus a similar system. Suddenly, large companies were starting to have now to look at their vulnerabilities on the global scale instead of just looking at the perimeter or just looking at a few critical servers. Suddenly, they need to have the bigger picture.

Because of that, we essentially the scalability and the accuracy that our platform was, our architecture was providing us, allows us to essentially start to pick up speed. Interestingly enough, as you all know, salesforce.com started from the small end of the market and then grew to the larger company. We started, in fact, because of that from the large companies. Today, because of that, we build a significant customer base of more than 70% of the Fortune 100, about 25% of the Global 2000. Essentially building that with that one vulnerability management because of scale and accuracy. At the same time, as I was mentioning earlier, we could see the consolidation of that enterprise security industry, where the big guys, the Symantec, the McAfee, were starting to acquire the best of breed. Why best of breed?

Best of breed is because security has a unique need, is that you absolutely have to eliminate false positive and false negative. These are the enemies of security. You cannot call 911 if there's a burglar, you think there's a burglar, but no, it's a bird which knocks on your window. That's the part of security. It lend itself to a very fragmented industry because security has multiple facets. Of course, the best of breed were the one which had the less false positive and false negative, and the one therefore raising to the top. The McAfee, the Symantec, et cetera, was on a binge to acquire them to do vendor consolidation and hoping that they could provide a much more integrated solution. The problem is that with enterprise software, you just cannot do that. We knew that.

We knew that it would not work. That's also the other reason when one of these larger company became and tried to acquire our company, we say, "No, no" because we knew that they didn't understand the architecture that was needed to consolidate, which is essentially what is that cloud architecture is the ability now you have very large data centers in the cloud, wherever you want, infinite computing power, infinite storage capabilities, the Internet as the mean of communication. On the other hand, you have sensors or devices. Everything is again remotely managed, centrally managed, and self-updating. That's what allows to bring the computing power to essentially the world, while client server brought the computing power to the employees of a company. Of course, the mainframe were bringing the computing power to the very large and rich companies who could afford these large mainframes.

I'm doing the computing evolution in reverse here. That's what we did. Fundamentally, as I mentioned earlier, we embark in our 2.0, which is re-architecting the entire back end. That was a significant task. I already told you that one part of the big success was our decision to move into India. At the same time also, we're now expanding our solution. We did that very carefully, starting to look, again, we didn't want to acquire companies to essentially go into an adjacent market because we needed to really finish that platform. Acquiring a company with the wrong architecture didn't make any sense. We had the patience of saying it's going to take time. We also thank very much our investors, which understood that Qualys was for the long run. We have started to develop more and more applications.

Today, for those who were yesterday at our user conference, you have seen that we're embarking now in our third journey, which is, of course, the platform 3.0, where fundamentally we have now put all these pieces together, we have shown now our global as an example of the power of the platform that we have built, the ability that we have now to provide our customers with a Global IT Asset Inventory. If you ask any CIO today of any company, do you have a good idea of the assets that you have? The answer is no. The CMDB is not up to date. You finally cannot secure what you don't know. You also cannot manage your assets if you don't know what you have.

Things have become significantly more complicated today because not only you have on-premise, you have endpoints, but now you have cloud, now you have containers, now you have web applications, now you start to have OT and IoT devices. That's that inventory of assets which all now connect to your network or to connect via the Internet. The problem has become in space, today we have managed absolutely to provide company with our Global IT Asset Inventory, you will see that part of the demonstration of Sumedh for those who were yesterday. We're going to give you a more condensed version of what we have.

This is going to go GA at the end of the month. For essentially the known assets, wherever you can put an agent to capture that information and then with the passive scanning, we'll do the unknown assets and all that is going to be said and done by the end of the year. That is going to allow us to go directly to the CIO and to the CIO for our existing customers, I've already started to do that to say, "Mr. or Mrs. CIO," asking the question, "What about your Global IT Asset Inventory? I've got a solution for you. By the way, you already have the platform. By the way, I can also help you consolidate a lot of your applications, save you money," et cetera.

We have now the talk, if you prefer, and the goods for the CIO, and that's one of our big thrust and we're continuing, and you will see that in the presentation of Sumedh, consolidating more solutions. We are doing even more than that. Our vision, and I ask in the audience people about if they know WeChat and it's a fantastic application. For those who don't know WeChat is, in fact, an application that Tencent in China did, which integrates a lot of your apps. For example, today, if you want to get Uber, you go and you take your phone, you click on the app, and you click and jump, and you get your car, and you know how many minutes it's going to take, et cetera. Sorry.

You want to go and, essentially, maybe go to a restaurant or find a Starbucks. Now you have to go to Google Maps, for example. You want to tell a friend that you would like to meet there, so you have to use WhatsApp. Okay, you click another app and on and on. Today with WeChat, you can do that absolutely seamlessly in one single app. Whereby, okay, you go DiDi, et cetera. You can even have a sandwich being delivered the very moment where you arrive. You can do everything. You can, if you have a date, you can have flowers being sent, everything is done for you. Of course, at the center for all of that is the payment. Our vision here is very simple, is that as the center of everything we do is that global IT asset inventory.

You look today at these SIEMs, they don't even know what they protect. You have to know what you have, and you have to know that in real time. In other words, you need to know the status of that device at any moment, because if not, how could you secure that new, very global environment? Our vision is that we can fuse all of that. The question you could ask me is, why in America they have not done something similar? It's very simple. It's because today, the Google, the Uber, they're all competing. They don't want to share their customer base. They have different backends. When what happened in China, you got two payment providers, essentially, as opposed in the U.S., we have also a very fragmented payment industry. You got two payment providers, Alibaba and Tencent.

At the center of everything is the payment. What they did is they created a backend where they opened up their backend so that DiDi and everybody could start to integrate. The way it's going to happen in the U.S. is that it's going to be done through acquisition because it has to be done. You will see a Google acquiring Uber, et cetera. It's through these acquisitions, we'll finally see the consolidation, and then you will have that single app fundamentally. That's the very vision we have for security, is that we can now provide the single pane of view and bring all this information and bring the next, fundamentally, generation of incident response system where all the data comes at you. You are aware of the attacks, everything comes at you. You don't have to go and fetch it.

That's our vision, we're working very hard on that right now. You will see through the presentation of Sumedh, you will see that vision already starting to shape as we are bringing more and more information in that single pane of view. Again, we will show it. This is coming. I would like to discuss about where the industry is going. It's very clear to us that we are about to enter, or we have entered, in fact, a consolidation phase. That is fundamentally driven by the fact that the cloud platforms are really becoming very disruptive. Today, the view that we have is that you look at application like salesforce.com, for example. salesforce.com, as you know, has done a fantastic job at essentially bringing the cloud to CRM and build a fantastic customer base.

They also had to build the entire infrastructure in order to do that. Today, these platforms, whether it's Azure, whether it's Amazon, Google, Alibaba, IBM Cloud, today, they have already built all that infrastructure at the global scale. We are going to see some companies which are going to say, "Oh, I can do that CRM application, but I don't have to build all that huge platform." They're going to focus at providing an application which is going to be as sexy as possible, significantly more cost effective. Our vision is that we're going to see the cloud and you come to see today the number of applications which are coming on Amazon, et cetera. It's absolutely incredible at the speed at which. That's one factor of consolidation.

What happens, the established players, in order to continue growing, they are, in fact, grabbing other companies. We have entered into that mode where the industry's going to fundamentally collapse. We saw that in mainframes. Every mainframe company disappeared but one, which was IBM. Why did they survive? Because they fundamentally evolved. They changed their model of building mainframe computer to a model of being a middleware company and a service company. And the two architects of that transformation were Steve Mills, which essentially at the time invested, when I was young and beautiful like all of you, invested $1.5 billion in Linux, and people said, "Oh!" Which was a 50-people company.

These guys were saying, "They're totally crazy, IBM." No, they realized that they used that to encapsulate all of their old, if you prefer, mainframe, and emerge as, and create that new platform, and then move into service. The other person who came in was Lou Gerstner, who did the cultural revolution, essentially eliminating most of the top management to recreate a new breed of people and embark into that new journey. We saw the era of the minicomputers. The DEC, the Prime, the Data General. How many of them survived? Zero. The client server came in, now today that revolution, I believe that Microsoft is, in many ways, the IBM because they've been able to absolutely. I had a discussion with Bill Gates many years ago about that.

I said, "Bill, you need to go into the cloud big time." He was, "Oh, it's going to take time," et cetera. Now today, Microsoft has done a remarkable job of migrating fundamentally from a company with an operating system for the endpoint, essentially now to becoming a very powerful cloud platform. This is where we are. Of course, now today, if you look from the security angle now, you don't continue boarding and adding another application. Usually, the company, they have nine agents on average on their endpoints, and they have between 20 to 100 security and compliance solutions. This is absolutely unsustainable. It's all about now building security into the new digital transformation, as we call it.

Qualys is uniquely positioned there, again, from a technical standpoint because of our architecture, and because also of the fact that on one hand, we're already Google, Microsoft, Apple Computer, Oracle, they're all using us to secure their own infrastructure. We are now working with them to really build the security from the top. Their users, essentially security is built-in. They don't have to worry about security. It's already there. That's a big change which is taking place. I believe that Qualys is very uniquely positioned today because on one hand, we can help our existing customers, consolidate their stack, reduce significant cost associated with having to maintain and deploy all these plethora of security and compliance solutions.

At the same time, fundamentally giving them a much better visibility, increase their security and compliance posture on the old environment, and we are now helping them migrate and build security into the cloud. You will see that part of the presentation of Experian as well, that we're doing that with many of our customers already. This is, again, this is not a story. This is a reality. With that, I'm really very happy to introduce our Chief Product Officer that some of you know already. Sumedh.

Sumedh Thakar
Chief Product Officer, Qualys

Do you have the clicker, Philippe?

Philippe Courtot
Chairman and CEO, Qualys

Thank you.

Sumedh Thakar
Chief Product Officer, Qualys

Oh, thank you.

Philippe Courtot
Chairman and CEO, Qualys

There. Thank you.

Sumedh Thakar
Chief Product Officer, Qualys

All right. Thank you very much. I'm going to give an overview of what Philippe mentioned about global IT asset inventory and the visibility that we are working on bringing that today is not really available to most of the IT organizations and for different reasons, which is what I'm going to discuss. I did some of this yesterday. To expand on what Philippe was talking about, there's a transformation in IT. Today, we have to understand what's happening in IT to be able to understand what's happening in security because, of course, without the IT security doesn't exist. I asked this question yesterday, the audience, what did they think of when they think of digital transformation? The first thing everybody said, "Move to the cloud." That's only one component of it.

Most organizations are looking at a very holistic approach on the reason for doing the transformation is not just about a lift and shift, take my existing server, run it into AWS. It's about how are we significantly changing the way we do business using digital technology, which includes everything from moving your servers into the cloud, creating more APIs, creating mobile applications. Giving the workforce mobile devices so that they can be out in the field closer to the customers, being able to do these transactions very quickly. Then be able to communicate to them via different channels that are out there integrating with other apps. A lot of that is changing, and it's not just the movement to the cloud.

In fact, a lot of the manufacturing industries, for example, are going through their own digital transformation because their shop floors are completely becoming industrial IoT environments where every single machine is connected to some sort of a cloud, IoT cloud, where they are measuring the temperature, the speed of the fan. They're measuring every little telemetry information so that they can do analytics. They can look up front if a certain machine is going to have issues based on the trends that they see in the little telemetry information. That's also digital transformation. It's not just about the movement into the cloud. A hybrid cloud today, no matter what everybody says, is that just moving servers into the cloud is not going to give the visibility that they need in terms of being able to have their customers being able to interact with them.

Which means that the architecture as of today is a hybrid architecture. There's mobile workforce, there's laptops that are out there everywhere. You have hybrid cloud, containerization, and then of course the on-prem is still not gone. Containerization, I think of all of them, is probably the most significant game changer here because it is offering a very different portability to IT, which has not existed for a very long time. You've had data centers where bare metal servers were deployed, but then the environment and the apps running on them were very tied to that particular server, so moving it somewhere else was not really possible.

Cloud made it easy, but even though the concept of portability exists, not a lot of people are actually able to take their running workload in AWS and then just run it for a few hours in Azure because these cloud providers do have a lot of their own cores, they need their tooling, they need a lot of that work to be done around them. Today what is happening is the hypervisor is disappearing in a way, and a lot of the customers are also going back to bare metal and their private cloud, which is commodity hardware, a simple layer of OS on top of it. Being able to leverage containerization, which is, in fact, Qualys, our own infrastructure, our own data center. If I look at it about a year and a half ago, we ran 100% of everything we ran was on VMware.

Over 60% of our infrastructure does not run on VMware. We do bare metal, we do containerization on that, and we don't leverage any of these things because those containers can really be easily moved between the environments. Kubernetes, which is really the infrastructure as a code, is changing the way things are being deployed because you can very quickly move things around. You can decide how the infrastructure is supposed to behave and respond to the business needs. At the end of the day, everything is being done to respond to business needs. The ability to say, "Okay, if I see this much load coming in, then I can spin up these many containers, which will need these many other containers for the back end services," can all be coded in 10 lines.

That takes care of your entire infrastructure, which used to take a team of multiple people to manage that infrastructure and scale and grow it. These things are moving at a very fast pace. Kubernetes is an orchestration tool that you would deploy to manage your containers. You look at what's happening with AWS Fargate and Azure Container Service. These are container as a service orchestration already provided with the cloud providers. All you have to do is bring your container image and then they will manage all of it. They will spin it up, they will provide you the console needed for spinning those containers up and then moving them around. Which also means that these containers are becoming smaller and smaller, and they only are running very specific functionality and specific code that is needed.

Which is now going to another step further, which is the Lambda functions, is function as a service. Now you are not even bringing any component of your operating system with you. You're just saying, "Here's my code, run it." What does IT who has been deploying and patching and doing OS work, what does that mean when all you have is a function that gets run in somebody's environment? Once it's just a function, then you can run that. I talked about this yesterday. There's this concept of KubeFed, which is getting very popular, is the ability to have orchestration across multiple platforms as well.

When you're running something as a function, you're running something as a very lightweight container, it is significantly easier to spin it up for a few hours in Azure because maybe they're offering you a special Christmas rate for four hours, you can save a bunch of money by doing that. The portability really exists. IT infrastructure, which was, "Here's the 500 servers, I'm going to have someone sit there and watch them," is obviously changing and your perimeter is changing because of that. DevOps movement is really big. It's real. We see that ourselves. Pretty much all the decisions in terms of how the infrastructure is being pushed and how it's going to work in production is being done by the development team because everything is becoming a code. Of course they code it.

If you want, if this happens, then this is how infrastructure behave. If not, if this condition exists, then this is how it should behave. This is code, and the developers write that, and that movement is accelerating, which means that the decision makers on the tools is changing, the buyers are changing. The development teams are making a lot of the decisions on the data center side. What are the tools that we should use for IT, for APM monitoring, for security and all of that as well. On-prem is not really dead. Of course the data center footprint is shrinking. As I mentioned, your OT environment is becoming more and more digital. You have a lot more fulfillment centers. You have manufacturing units that are IoT connected, that are increasing.

In the traditional way of thinking of on-prem is they're physically under your control. Yes, that is actually increasing, it's not reducing, and it's all getting connected with each other. We've had customers who 10 years ago had a completely segregated OT environment that barely had any network connectivity, and everything was run in there, and in there you would have routers or switches that did not even have the ability to have a tap port. That is now changing rapidly. Corporate IT is changing, the traditional desktops and things like that are becoming laptops, and IoT devices are being brought into the environment more and more. If you notice that this projector, when Philippe was trying to get it working, had an IP address.

How many of these projectors does Bellagio have, and to what network are they connected, and what are they running, and how many vulnerabilities could they possibly have? Just think of how many that could be. These kind of devices are significantly increasing in the traditional on-prem, and I'm not even counting the example I gave yesterday of an internet-connected toothbrush that an employee connects to your office Wi-Fi network, and you have no idea about, and it has a vulnerability that leaks your password. Right? We'll have a separate conversation on why you need an internet-connected toothbrush. Enterprise mobility is increasing, which is not BYOD, so it's not employee bringing their machine or bringing their phone to check email. This is organization as part of their overall digital transformation. We talked about digital transformation on data center, digital transformation on the OT side, manufacturing.

This is digital transformation at the endpoint. To say, your employee's interacting at the bank, you walk into AT&T, or walk into Wells Fargo, first thing they do is they greet you with a tablet. I was just talking to Melissa. I'm a Morgan Stanley customer. Every time they come to talk to me, they come with a tablet, and they have all my information on that. That's what they flip through. They show me everything about my financial information on that tablet that he's carrying around. He goes to Starbucks, sits there, maybe forgets it over there, who knows. That enterprise mobility is enterprise-owned devices.

These are devices the company has bought and given the employees to say, "This device, I own it, but you will use it for business." Of course, just like when they started giving out laptops, they are very much incentivizing ensuring that they are buying the proper licenses for all the different tools that are needed to protect those devices. Versus an employee bringing their laptop to work, the companies are not going to pay for their antivirus license and their Word license and whatever license. When it's your enterprise device, they will make sure that they are paying for the license for each of those tools, whether it's productivity or security. These are becoming indispensable to the business, this is not an optional thing. More and more organizations are just using these devices for conducting business.

Interestingly, like I mentioned, they are a direct window into the sensitive data that is being held in those backend data centers, just four digits away. That device somewhere at a Starbucks is only four digits away from a passcode for someone to be able to get in there and access that information. Enterprise mobility is increasing, and part of the digital transformation. Big movement into APIs, B2B, B2C, a lot more web applications, a lot more APIs in the way customers communicate and connect to the enterprises. I was on a plane with Philippe last year, and one of the ads in the newspaper said, "Sign up for a bank account by taking a selfie in our app." They're saying, "Okay, here's an app. Just take a selfie.

We'll enroll you, we'll sign you up, and then somebody may come to verify something if needed." That's another change that is happening, which again, is another window in the backend side into all of the sensitive information. The mobile app is communicating to the backend API to conduct a transaction when you say, "I want to move data from this account to that account." That API call says, "Post from account number to account number and amount." That's just one password away. To make that call is one password away. Make the call. How do you protect that to ensure that, if that gets compromised, somebody could be doing things that you have no idea about because APIs are called at such a large scale.

Of course, another movement which is happening quite a bit is also moving into software as a service. There's no infrastructure to manage. Qualys today internally, IT absolutely does not deploy anything. Everything from HR systems to our payments to employee systems is all online. We don't actually own the infrastructure. Now, we do need security around it. We need to know that the wrong people are not accessing it, that other people who maybe assigned the wrong access or employees who are sharing some of these things from SaaS platforms much more openly than they should be. There is no endpoint to deploy an EDR agent on because all of that is being done outside in somebody's environment. Of course, no applications to manage. What does that mean for security from a current state perspective?

There is no visibility in any meaningful way given the hybrid nature of the infrastructure and the scale and the ephemeral nature of how things are changing. If you do have the ability with KubeFed at some point soon to just move your containers from one provider to another or on-prem or back, and your devices are traveling between multiple cities and locations and all of that, how do you even secure something that you don't know exists or where it is? Despite all of the movement from whatever it is to containers, the first question is: Are you doing vulnerability management? Configuration assessment. The basics of security still continue to stay the same. You need to monitor the integrity of the files and your systems. Again, question mark. If I'm running a Lambda function in AWS Lambda, is that really a system that I'm monitoring?

Because it's just a code. Those are the trends and of course, the SIEM solutions, which have traditionally been very focused on. I get some firewall logs, and I correlate that with some endpoint logs to give some insight are not scaling from a volume perspective as well. Again, basically visibility to respond. It's visibility for the sake of visibility and visibility to actually be able to do meaningful response. You don't find out about a breach 6 months after and somebody spun up simple stuff. Just being able to have the visibility that you have a new server that got spun up in your environment, whether it's your data center, virtual or physical, to be able to go inspect that is so valuable. And we've had a compromise with this. Cosmos Bank had a compromise a few months ago.

Somebody got into the network and created a fake gateway approval server, which then was approving fake ATM transactions to Visa. If they just had a simple visibility that, oh, there is a server in this environment that's communicating on the network, that is not part of my approved list, that could have been prevented. That visibility to be able to respond is really lacking for the most part today. We ourselves are going through this with our FedRAMP certification, and there's a lot of demands on compliance, and those don't change. I was joking about that yesterday, as you know, we were all excited and we say we have cloud, we have containers, we have this, we have that. First question back is, "Okay, great. Show me your CIS benchmark report.

Show me your compliance report on all of your containers." We're like, "Oh, yeah, we didn't really think about that. How do we get that?" Right? Those demands are also increasing from a current state of security perspective. Can I give an example yesterday of a car, and how infrastructure really needs to have security built in? When you go buy a car, you don't go buy the car and go buy a separate seatbelt, and then go to another store to buy the best airbag. You go to some other place to buy a car alarm, and then some other place to then buy a parking sensor for security. You expect that when you go do that manufacturer has already done all the work of finding the best meaningful seatbelt, and it is all integrated.

You start driving, it's all taken care of. You don't even think about, is that even there? Because you expect it to be there. That's the ideal state of where security really needs to be, which is a transparent orchestration that we have talked about, is the ability to say, "Yes, I want to run a server, yes, I want vulnerability management and configuration assessment and these on it." Then it should all be orchestrated in the back. You are not deploying yourself 8 different agents and going and deploying 8 different consoles to manage those agents. Then deploying another log solution to then collect the data from all of that and then give you the visibility on top of that. Another orchestration solution to actually take response, to do response actions on it.

The more you are sure that every time you spin up a container or you spin up an API or you give out a mobile device, the security is already built in and following that is that transparent orchestration that's going to at least start to give you a significant amount of visibility, which really doesn't exist today because IT throws out the stuff, and then security has to figure out how to make it work. Which is why it has to start in the DevOps cycle, so it's already built in. Because now, let's say you don't have an agent that you put on each of the tablet that goes out in the field all over the U.S.

You give out the device, then IT now has to find and track down the owner somewhere, wherever they are, to try to get that agent onto that device. The resistance and the amount of effort needed is significantly higher versus if the gold images, whether it's a container gold image, a cloud gold image, or an IT laptop gold image or all of that, already had the necessary tooling built in, so that as soon as it went out, it would start giving you the visibility would be the ideal state. Of course, there is a need for real meaningful security analytics, which truly doesn't exist today. A lot of these SIEM solutions are all sort of log-based, and they try to correlate activity happening at a point in time in the past after the fact.

Being able to do these analytics upfront, and which is really surprising because a lot of the new industrial IoT data centers are collecting, like I mentioned, this telemetry information about the temperature changes on each of the machines or the fan speed on each of those machines. Then they use analytics beforehand to try to see if they can detect things that may happen in their environment or when things happen, they have a clear visibility. That paradigm exists, just needs to be something that security needs to start to look at as well. What is Qualys doing? First of all, do what you preach. Embracing our own digital transformation is the first thing that we looked at. We have been putting significant effort in continuing to build our platform.

We have had major changes happen, like I said, containerization, moving to bare metal, leveraging Kafka, Cassandra, Elasticsearch, significant shift in where we were significantly Oracle's database centric and Java centric. That has been changing quite a bit. We have many products, many customers, multiple shared platforms. We just spun up a platform in AWS recently, another shared platform, so that customers could just click and buy directly through AWS and it's provisioned on the AWS platform, which is, again, as I'm talking about, having that ability to spin up infrastructure or security with the infrastructure in a more seamless way. The number of private platforms continues to increase. These are across multiple different platforms, whether it's physical hardware, whether it's VMware-based platforms or small 1U appliances, or in AWS or Azure.

We have pretty much private platforms in almost all the infrastructure that is out there. We're seeing almost a trillion security events annually that we have been processing. The number of scans has been increasing significantly. You could see that we're doing almost 3 billion Kafka messages on a daily basis. That's just to show the amount of usage that is happening on the platform as these solutions are communicating with each other. We are at 620-plus billion data points. At the beginning of the year, we were about 280. The amount of data that we are collecting and indexing is significantly increasing, and very soon we will be approaching a trillion by the end of this year as well. Just small to show that the platform work ongoing has really had a significant impact.

If you were there yesterday, you saw a lot of the demos and the speed at which customers were able to get the data out, which is that two-second visibility that we have talked about. We're trying to get it down to one second, but that second is resisting right now. We'll get over that. Architecture-wise, I think, just to give that In a way, it's a simple architecture. My engineers will disagree with that, with all the work that they have to do on it. You have sensors collecting data, pushing it into a back end, and then there's UI and API. That's the cloud architecture. That's what we have built. No complicated, multiple master of master consoles and things like that you have to open up different things. In that sense, it's fairly straightforward.

From a strategy perspective, we just always continue to try to add more sensors. With some of the acquisitions we have done, which I'll talk about, we just continue to add more sensors. Separately, the teams continue to add more and more capabilities with microservices and all of that. Another team continues to add more and more apps that give more visibility at the top. We're going to add a team that kind of goes across this, which is going to look more and more at security analytics, as we talked about earlier. The sensors, again, really about ubiquity. It's about coverage, about addressing physical data center, virtual data center, cloud, containerization, laptops, mobile devices, passive scanning, which is going to go beta, and I'll demo that today as well.

Nothing can escape the Qualys sensor if it is communicating on the network. If it is not communicating on the network, honestly, we probably don't care about it. Anything that is meaningful and communicating, we are basically going to pick it up. We continue to keep pace with a combination of agentless, agent-based, and passive. We continue to keep pace with looking at the infrastructure that is changing, and the Layered Insight acquisition was another way is how do we address something like AWS Fargate, where you may not even have your own server to put anything and to run it. We'll talk more about that as well. The platform continues to increase. A lot of people ask, "Hey, why? How come Qualys is able to do so many apps and so quickly?" It's not just a factor of number of people.

We've hired in Pune as well. It is also the architecture, the ability for us to spin up multiples. Each of these applications have their container and well-defined architecture, and then they communicate with the rest of the platform in well-defined APIs. When we have to spin up a new UI or new application, it's much faster, much well-defined because the base of the platform is already defined. Then these teams, then they just come in and get their sensor connected into the back end, and then they basically just pick up the relevant information and start processing it, and then they start displaying it. That's one of the big reasons why that architectural changes that we have done are helping us create so many products at such a fast pace. It's not just a factor of the number of engineers that we have.

We continue with the, as we see with patch management coming up, the acquisition with Layered Insight. We are making more and more headway into extending our solution into remediation and response as well, not just visibility, because it makes a lot of sense to have an integrated response, because we have toGo look at your CCTV in one place and then run five rooms across to close the door. Later, by that time, the intruder is already in. If these systems are connected, they can have a better response. If they are actually connected to the central backend, it's even better, instead of trying to collect information at different times and combining it together. The remediation response, we are of course something that's focusing on. Rapid expansion of the R&D org, as Philippe mentioned, we are I think what, 600 something plus.

I have to be careful because these things change on a daily basis now. We get 15 welcome emails every Monday now, 15, 20. That's a big part of it. We're getting great talent. This talent is helping us innovate very fast because they are empowered, and they are able to spin up in their own container, new capabilities onto the platform. Another thing that we are focusing on now is, and we gave a little preview of that yesterday, is the data lake. Security data lake is bringing large amounts of security-related information and then correlating that and providing flexible insights for customers so that they can see the trends and have that visibility and not have to try to hire large teams to build something to get that visibility. It is another area that we're focusing on, in the next year.

From a technology acquisition perspective, we really didn't do much until before last year or a year ago. In the last year or so, we have really focused on acquisitions and on investment as well. Focused very specifically on the specific sensors so that we can acquire that technology and a good small team that can then integrate with the platform and integrate with our team. From an acquisition perspective, the first one was Nevis, which we did about a year ago, I think. You already see that live demo running. We had a Wi-Fi hotspot, it's still there, set up that anybody logs in to that hotspot on their phone or whatever it is.

Within 10 seconds, we're going to show that device in Qualys and show you what it is and what the operating system is and what IP addresses and what services is it connecting to. The earlier example I gave you of Cosmos Bank, think about that. If they had that ability to say, "I always have 327 servers in my environment. Wow, there's something that's communicating. I don't even know what it is, but there is something new that is actually communicating on my network." They could pick it up in a matter of 10 seconds, that is significant. That's why that global IP asset inventory with the passive scanning is so important, and that's what the Nevis acquisition really gave us.

The second phase of that is going to be the secure access control, which is traditionally the NAC, the network access control, but network access control is heavily reliant just on specific firewall type IP address and port rules. What we are doing is really bringing it to a higher level with bringing the capabilities based on the application and the use cases, not just an IP communicating with another IP. Mainly because that NAC capability was fine in the past when you had specific servers that had specific IP addresses. But if you did move a bunch of your containers that are running your backend production system from Azure to AWS for four hours, those kind of capabilities completely break down. You cannot have it based on the network level anymore because the network is changing so fast. NetWatcher was about the event correlation platform.

That was a little sneak peek that we gave yesterday on the security analytics and the data lake project that we are working on. They have been integrating that technology as well. 1Mobility acquisition, this is really huge in terms of the number of devices that we can address out there from an enterprise perspective, the number of iPads and Android tablets and Windows tablets that are being given out, that are being sent out, that are being used by the customers. They have a deployed technology, which is very similar to the Qualys Cloud Agent technology. It's basically extending that cloud agent architecture level to their sensors. We basically now go to an existing customer who has millions of IPs that they're scanning with us on the data center side, in the cloud, and also on the desktop side.

say, "Here, we can bring all of your X thousand tablets as part of this entire overall solution." You will see the visibility of that tablet as it is communicating to the backend container on the same platform, versus an AirWatch or somebody who's just providing that capability completely independently just to see the visibility on the device from an IT perspective, not really from a security perspective. I'll talk a little bit more about that as well. Layered Insight, this is the most recent one. Very exciting because it gives us a leapfrog from the technology into the runtime container space.

Qualys has had a solution that we brought to market a few months ago, focused on containers in the DevOps cycle, the ability for us to provide our customers full visibility into images that are being pushed out as containers and making sure that those vulnerabilities are actually fixed through Jenkins, through DevOps tools, through CI/CD pipeline, even before they become vulnerabilities in production, has been something that our customers have been quite excited about. We have more and more customers deploying that solution, that has been more on the DevOps side. It has had a significant impact, by the way, just from a technology perspective.

The ability to eliminate a large number of the vulnerabilities up front in the DevOps cycle, it really reduces the workload that the teams have to go later, because we will see that a new server comes up, which already has three-year-old vulnerabilities on it. Now the team is spending all their time patching. That happens for 10 servers every day, and a significant amount of time is spent on that. Just from a pure technology and process perspective, that DevOps thing is very important. Of course, once it goes to production, there are still going to be new vulnerabilities that are discovered out in the wild that may apply. There will still be compromises that can happen on the container, somebody compromising your container, and at the end, everything runs on something.

That container is running on some system, which could run a command, which could compromise, give visibility into your container. That still exists. That runtime capability of saying we instrument. Very similar to the agent technology. We instrument or we have an agent that looks at every single thing that is happening on the system and sending it back to the platform so we can correlate and give the visibility, is very valuable. Their architecture was very similar to the Qualys architecture, which is why the integration and bringing them into the solution makes perfect sense, because now we can give the full end-to-end of scanning those images in the DevOps environment, providing the ability to make sure that at a runtime, these things don't get compromised.

Some of our competitors only provide the ability to upload an image, they'll give you a report of the findings, nothing on the runtime side. This is again, a significant advantage with bringing that technology onto the platform. Of course, another investment that we had announced is with 42Crunch, a very interesting API solution, which again, covers both the DevOps side, ensuring that the definition of these APIs is tight, ensuring that those APIs are not accepting things that they should not accept. Doing that in the DevOps cycle, having a runtime element in production where you can actually then front those APIs with capabilities that will block malicious traffic to those APIs, block incorrect access to the APIs, provide another layer of authentication and authorization, are some of the capabilities that they offer.

We are working on integrating that as part of the platform as well. With that, I don't know if I missed a few products in here, but I think the slide is fairly accurate, Melissa goes over that 100 times. Just to show you the breadth of the support and the coverage, I think that we could slice and dice this in many different ways. You could look at it as asset management, security compliance. You can look at it as DevOps versus runtime. You can look at it many different ways, visibility versus remediation or whatever it is, but we have the goods. It's how you LEGO that thing to create a different view every time is really the thing. From a roadmap perspective, as we talked about at the earnings call, patch management is going beta.

We had a demo yesterday. We had huge interest from the customers. Every single customer wanted to have that ability to deploy those patches as soon as they find those vulnerabilities. We're really excited about that. Passive network sensor as a new sensor, adding data into our global IT asset inventory, is going beta as well. It's running here in our production environment, here at the show and in our offices. That first beta is already out, in a internal beta perspective, the external beta will be happening in a couple of weeks as well. The global IT asset management inventory, I should say, which is the known assets.

We try to divide this between assets that I know, which are the things that I'm scanning because I know that I have them, or the things that I have in agent, or I am using a cloud connector to pull those devices, versus the unknown or the unmanaged asset. I have no clue, somebody connected a toothbrush to my Wi-Fi. How do I know that in 10 seconds? Better yet, how do I then use the security access control solution to just deny or put a simple rule that says, "Nope, anything that's a toothbrush or anything that's not a Windows server can be on this particular network," is the ideal thing. That's the beginning. We're bringing this capability we'll expand that later.

Overall, in the first half, we're continuing to work on a beta for the secure access control, allowing customers the ability to control access to their critical servers. Leveraging that technology and leveraging the up-to-date information that Qualys is picking up from all of our sensors, so we have a lot more up-to-date view. Some of the solutions, like Forescout, they don't really do as much of the assessment themselves, so they are reliant on the customer buying that solution and 5 other different solutions to integrate each feed into their solution to be able to provide some of these capabilities. We will have a significantly more integrated solution from that perspective. We have had certificate view, which has had significant uptake customers getting visibility into the certificates that are expiring. That's a cornerstone of any compliance program.

You need to ensure no TLS 1.1, no TLS 1, no expiring certificates, no self-signed certificates. We did the free community service around that, has had a really big response. Now we are going to have the certificate management capability as well, which is the ability to renew a certificate right through the Qualys console. Not just say it's expiring, but actually now click a button and say, "Yep, I want a new certificate." Then second phase of that will be now I use the cloud agent to also deploy that certificate, because by that time, we will have gained a lot of good experience being able to deploy patches onto the systems. So we'll be able to then go in and deploy certificates as well. Cloud security management, again, we have had cloud security assessment, we have had cloud view. The cloud view is the free part.

Cloud security assessment is the paid part, where you get an assessment, not just a view of inventory. Now we are working on bringing cloud security management, which is the ability to have remediation and response. Not only will I tell you that this particular bucket has public access, but then you can write a rule or press a button through Qualys, which will then run the Lambda function in the back end and fix that issue instantly in AWS. That's another integrated end-to-end capability that we are bringing. Mobility, as I mentioned earlier, we're also going to have a beta of the mobility solution. So we will be able to give out the Qualys mobile cloud agents that then customers can deploy and get that visibility.

Then the runtime container security solution, we are integrating that into the platform, and that will give customers who are already using our solution for DevOps to now just in the same console, in the same UI, have an ability to say, "That's good on my DevOps. Now let me look at my runtime as well." I still have time for demo. Sean, how am I doing this? Escape out. The demo is not loaded. This might work. It's working too fast. Hold on 1 second. iTunes think this is the best time to update your computer right now, which I disagree, but it disagrees with me. I don't have a decline. I have a decline. Review, playback. Let's go with this. Let's see if this works.

I'm not sure how to do a full screen on this one. Okay. Really? Just went away. Do you have Sean here? Sorry about this. Oh, okay. All right. I did a quick video of this. Really? Well, at least it's updating, I guess. Okay, there you go. All right. This is a global asset inventory. Just to give you a preview. This is in beta with about 30-plus customers today. They love it because they are seeing things and trends that they had no idea about. Even just simple things like Oracle's now gonna start charging maintenance for Java. How many Java installations do I have in my environment? No clue where to go to find that information. CMDBs are completely out of date. How do I know at this point of time, in near real time, how many installations do I have?

Those kind of capabilities are being provided here. You can see the asset distribution. We use the existing Qualys sensors, agents, scanners, combining all of them together, and then this asset inventory will add a layer of normalization and categorization out of that. It's one thing for customers to say, "I want to find all of Java on my servers." Who defines a server? The customer has to create some rules, usually to say, "Windows, this version is a server, that Oracle version is OEL is a server, and this is a server." With this, we completely normalize that. With a team of 15 people, we've built a whole library out-of-the-box. We'll classify hardware, operating systems, break down the categories.

What you will see is that in this case, we have broken down computers, so detecting everything from notebooks, cloud, printers, security cameras all in one console. They can click, see all the security cameras, get the details of that particular camera. You can go down into notebooks. There's 1,000 notebooks, but across multiple different manufacturers. There's Lenovo, there's Apple, there's ASUS. This is all near real-time information coming from agents and scanners. You can group them in different ways. Look at exact model numbers, how many assets you have. Customers not have to define any of these rules. Out of the box, the information coming from Qualys sensors works here.

We even go down to tell them exactly this 13-inch MacBook with 2 Thunderbolts that was released, I think only in Japan, was picked up by the agent to show this in the environment without the customer having to do any of this thing. You can look at it by market version, which is interesting. Again, being able to say, "Show me just all my High Sierra machines," just by running a query. You can see there computers, notebooks, which are High Sierra, you can find that very quickly. You can look at the software. You can see all the storage instances I have. Categorizing that these things are storage. If you see out of the box, we picked up everything that is storage related, software running on your environment from Dropbox to Sync or whatever it is.

Let's say that you don't want to have Box in your environment because you're going with Dropbox. This visibility is available out of the box to the customers. They can group them by different names and find out exactly how many instances of Box, and then drill down specifically into the seven machines that will have Box running, we can find out who has them, where they are as well. You can also look at client operating systems. We classify versus server operating systems, find out exactly how many Windows 7 devices, client applications, just saying how many productivity tools do I have? How many commercial versus non-commercial databases do I have? If you look at client hardware again, MacBook Pros, operating systems that are missing patches. End of life, this is a big functionality, very critical.

Just knowing end of life hardware, knowing end of life software. As soon as our agents are picking up the software, we bring that information back. Our Kafka backbone will process that. It will tell you with the library that we have created now over the last year, we'll know exactly which devices have support from the manufacturers have stopped, that you can identify those and start taking remediation actions accordingly, and then you can of course slice and dice it by the different categories of software. Again, GA versus end of life. I have another dashboard I created for corporate IT focus. If you want server side versus corporate IT side. Here it is a lot more about the software types, device drivers versus productivity software. How many Word and Windows.

That's important to not have all of those clubbed together, identify quickly anything that's open source. In this case, let's see productivity software. I have everything. That's really the cool part. The ability to just say, "Show me productivity software," not, "Show me OneNote, and then Excel, plus Outlook, plus PowerPoint, plus this, plus that, plus Google Docs." That's the key here that we have helped customers. Just say, "I want to see productivity software." It'll tell you exactly how many of these are installed. Think of license lifecycle, entitlement management, being able to deal with license audits. You could easily do that here. Drill down specifically into Microsoft, see end of life that is still deployed in the environment. You can filter that by end of life. See how many instances. Group it by market version.

You could say, "How many 2013, versus how many 2010?" Still 191 Office 2010 installations I have in the environment. Just click. You'll see all the details, the specific machine on which we can see that. Of course, integrated with the Qualys platform. Customers tagging from their business unit, business criticality, all of that is already provided as part of the integrated solution. Customers don't have to do anything. Windows 7, we want to end of life that. Still 25 assets that we have in there. Another use case is going to be tracking KPIs. It's one thing to say I will go and do a query, and I want to find that, but then how do you trend out of the box without pulling this information, putting it into Splunk, some other trending system.

I just want to say I want to deploy Windows 10 and reduce Windows 7. You can just track that out of the box here. Are my trends going up? The ones that I want, are they going down? Endpoint protection software that's end of life or devices, if they're reducing, are they staying at a constant pace? Very cool thing about unauthorized software. Customer can define themselves what is unauthorized software. We call this category called potentially unwanted software. This could be different things like BitTorrent and FakeFlash and whatever it is. They actually installed something and named it FakeFlash. Again, it helps you really narrow down and quickly identify the specific machines.

Now, in this case, we found the specific machine that has that, and then the exact location of that device and how many seconds ago, and who's the user, who owns it, and when was the last time that they rebooted their system. Of course, because it is integrated into the Qualys platform, everything related to, oh, wow, they have that software. What other software do they have? What vulnerabilities do they have? Do they have open ports? Is it a server that is running containers? All of that is integrated into the single view. Another dashboard that I put together is more around cloud. No, I have corporate IT. Here again, just to show the Qualys sensors that are connected to this environment, this IT asset inventory. We are bringing the information related to the IT assets from multiple different Qualys sensors.

There could be passive sensor, active scanner, mobility agents, managed versus unmanaged. This was the part I was telling you about, integrated into this global IT view. The beta, once it's launched, will also have an unmanaged part. The earlier one was just, I know the device, I have installed an agent, I have a scanner running against it, versus, I have no clue. This thing is just communicating on my network. We will identify and categorize manufacturer devices. Just being able to say, how many Lenovo devices, how many mobile devices? Can categorize those by, say in this case, let's do product. No, model, sorry. I know exactly how many iPhone 7 do I have, purely without ever talking to the device or having an agent.

Purely looking at the traffic, using fingerprints and machine learning that we have developed, we are able to tell you all this information just on the phones, and then I'll go and show other things as well in the environment. That we give that visibility in near real-time. In this case, if you saw, I clicked on the phone and I'm picking up information about the phone as of a minute ago, in this case, or in some cases, when was the last time we saw that particular device. We are picking things up down to the seconds or minutes in most of the cases. All this information coming purely from looking at what's going on on the network, specific version of the OS, exact part model numbers.

If that same device gets picked up between offices by the passive sensor and the device is moving from floor to floor to floor, we will be able to see that this device got picked up and this is what the device is doing. What else do I have? This was interesting because, here you can see a conference room, Stonehenge. If you've ever visited our HQ, we have new conference rooms that have a very nice tablet outside that we use to schedule conferencing and things like that. It's connected to our Wi-Fi network. We're able to pick that up because it's something that is connected to our network. Just purely by looking at Wi-Fi traffic, we're able to pick up the manufacturer, the conference room information, and then we will also go into the category.

Now we know tablets versus smartphone versus desktops versus mobile devices, and then drill down into that was the conference room. There may be some other things. What was interesting, and I know Sean is here from IT, but they haven't deployed those in a uniform manner because some show up as the number and the name, as Golden Gate, others show up as a conference. We need to certainly fix our provisioning to have more consistency. I would have never known that at all if I didn't have this visibility. We also were able to, in fact, pick up devices on our network that did not have a Qualys agent because somebody brought their personal device or IT did not install an agent on it. We were instantly able to say, what are those agents? Again, same concept.

You could do Windows, and say, where detector service is BitTorrent. You don't have to go into the specific various different torrents that are out there. You could just say, "Hey, show me everything." We could have just said, "Show me everything that's a laptop," for example, that has BitTorrent, and it would have picked it up. Again, all picked up only based on the passive scanning. That gives you an idea of this traffic summary.

All picked up purely by looking at the communication of the device, all the protocols, the family of protocol, how much data is coming in, how much is going out, grouped by the service, information so that we can. Like I said, the first step is the identification with the sensor, then we will soon be able to extend that into traffic pattern analysis, anomaly detection, CNC communication, network-based IOC, and on and on. Just to give you a flavor of what we are already picking up, we're just working on the back-end side of it. We can basically get down into saying, did this device transfer a large amount of information, and within what time frame? Then use that to say, is this doing exfiltration? How can you go quickly today? You're an IT or security guy.

You get an alert, failed user logins on one machine, or you get an alert saying, Qualys has detected an indication of compromise. You want to know, what did the device do? Did it send out a large amount of traffic? What protocols was it communicating with? What IP addresses? You have to go to some other system, pull up logs from the past, and do a lot of report building to be able to see that visibility. Here, click and drag. Back to the inventory, the total inventory. This is a cloud resource dashboard. As I said, digital transformation is not just about the devices connected on my network, but also the things that are in the cloud and containers.

Here within the IT asset inventory, global IT asset inventory, we are building a cloud-based dashboard that basically gives you the trends of AWS, Azure, Google VMs running in there, the regions in which they are running. I do see a map on this screen. Here it just looks like dots that are hanging out, having fun. I'm going to click in the cloud, specifically, databases that we picked up. Just saying databases, could be hundreds of databases. How many of them are end of life? We even picked up a MongoDB, it's not just a traditional. We categorize that as NoSQL versus RDBMS database, all out of the box. Right?

Of course, funny enough, the only one that is not end of life in the environment is the MongoDB, because you can patch it pretty quickly compared to some other databases on this list, which I will not name. Again, PostgreSQL database running in AWS, who's the user, get into the details of that. Location. Hmm, we saw it six months ago, that's interesting, what happened to that one? Of course, being integrated, you can click and see the vulnerabilities. I see an end of life. What kind of vulnerabilities exist on that device? Because you also have Qualys VM module enabled, you will be able to pick that up as well. The unmanaged, there was one more thing I wanted to show. We're making a big investment in fingerprinting OT devices, as well as industrial IoT devices as well.

Some of that is already starting to take effect in the platform. The team was able to pick up industrial automation and control category. Just say, "Show me all my industrial automation devices that I see," purely picked up by looking at the network without sending packets or anything like that. We were able to pick up two PLCs, an S7 server, and those who are geeks about this, apparently this is a big deal. For me, means nothing, but it's from Siemens. This one is from Rockwell. We are already building significantly that library, we'll, of course, be working with the different vendors, manufacturers that are out there to significantly increase those capabilities as well. Am I doing okay on time, or am I over? I could do another short demo in that case.

Yep, there's a model number, CPU, oh, and traffic summary. Again, is that PLC communicating to anything outside of the STEP 7 protocol? Another use case I want to demo. Again, that was more specific on IT asset inventory. I talked about digital transformation. Digital transformation being something that starts all the way from your mobile device all the way back to your on-prem AIX server that nobody knows who owns it and nobody wants to touch it, but it's still part of your system because it processes that transaction. Final transaction, where the code was written by somebody 25 years ago, and nobody knows how that works. It's still there today.

In this example, I'm going to show how putting together the mobility solution we acquired, Layered Insight and container security, API security, how we will be providing a much more comprehensive view of the entire digital transformation from a security standpoint in this environment. Here's the upcoming secure enterprise mobility, which starts by picking up all of your Android, iOS devices that have an agent. How many of them are corporate-owned versus employee-owned? Getting into apps with expired certificates, the ones that have weak encryption. Again, these are company-provided apps, hard-coded keys. Passcode not present, big deal. Like I said earlier, your sensitive information is just four digits away. We picked up station 10 has an Android tablet. We can get into the details of it.

We can see all the information about encryption and all of the location of that particular device, the user who's logged in on that particular device as well. Go into the apps. We will show all the apps installed on that tablet, of course. As an enterprise and the ability to have an enterprise app store so that the enterprise can push their own apps through the Qualys solution so that only those apps, let's say, are allowed to be downloaded outside of the other apps is important. The cool thing is that then it shows that the enterprise needs you to have the auto service booking and the customer feedback app on that tablet, and it's not there. One of them is missing, the other one is found.

It's not just a diary of like, "Hey, here's Maps app and this app." It's about making it relevant to the enterprise from a business security compliance perspective as well. Remediation, I talked about ability to just take an action, lock the screen, format the device, de-enroll, find certain things, find the device, buzz it. All of that capability will be built into that particular platform. This is about API security. We've kind of mocked up what we are working on in terms of the API security capabilities around saying this is the service center API. The tablet has that app, which is now talking to the back end service center API. What is the security of this particular-- How many vulnerabilities does that app have or the API have? How many of them are confirmed?

In this case, we have details about that API, what version of Swagger. There's a certificate that's on that API that's expired. Guess what renew, clicking Renew button will do? Will use the Qualys certificate management capability to renew the certificate right there. You don't have to wait for days for somebody else in some other team to try to do that. A lot more details around the specific API actions get pushed, things like that. We detected a SQL injection vulnerability in that particular API. This is, again, talking about DevOps, that API, of course, we detected a SQL injection vulnerability, but the development team that then pushed it should have done a good job in Jenkins and the CI/CD pipeline, leveraging the Qualys built-in app, which would have then have told them upfront, even before it ever went to production, exactly how many vulnerabilities they have.

They should have never allowed the build to pass. Jenkins, you can say, "Don't pass the build if anything above severity 5 is detected by Qualys out of the box." If they had done that would have been interesting. There's a few things that we're working on in terms of software composition analysis to provide the same type of capability as I mentioned, but more in the traditional images. Or when the developers are building WAR files and binaries, they can actually detect open source software that is being included in that to build that Java application, and then be able to identify which ones of those are vulnerable libraries that are being included, and then being able to eliminate, like in this case, there's Struts, which was a big deal, of course. Being able to say 10 development projects are running Struts.

What's the license? Then being able to say that there's remote code execution, with this CVE in. Again, this has not even made to the build console. This is the developers building these things on their machine, and we can show very specific information with connectors in their machines that will tell them before they check anything in. As I mentioned, that application is now running in cloud. You have those APIs. Those APIs are containerized, running in AWS, for example. With the cloud view, we're able to show that that service center API is running as a virtual machine and has these containers running on it. One of those containers has an issue, API_3. What are the vulnerabilities on it? You can click on that particular container, and it will show you. This is the Layered Insight integration that we are working on.

It will show that httpd tried to execute a shell, which is an attempted compromise. If you click on that, with the Layered Insight instrumentation plugging into our platform, we could tell exactly when this event happened, that the web server tried to execute a shell. Horrible. Worst thing you could do. We had issued a deny on that one, completely integrated into the platform based on these rules. I got a couple examples here. You have another virtual machine that you can click and then be able to see that are vulnerable. In this case, expired certificate. Again, found a virtual machine in AWS with an expired certificate. What's the grade? What do I need to do to fix it? In this case, you will basically use the renew functionality. You can go click on that 1 virtual machine.

In one place, you will see vulnerability management, configuration assessment, cloud security assessment, expired certificates, and more apps, and more apps, and more apps, and more apps at some point. Let's pick example of another virtual machine that we picked up in AWS that has security groups that are exposing vulnerable instances. You have instances running there that are vulnerable, and then you have ports that are exposing those vulnerabilities to the outside. You will be able to then take action to change security groups, stop the instance, or do some other action. Then we're also exposing more and more direct threats, vulnerable instances accessing S3 buckets.

Again, there are point solutions today that offer some of the functionality, but you cannot then quickly go from one to another to say, "How do I click here, find out the vulnerabilities on that instance?" Something like, Evident.io will then be able to provide you just that kind of a visibility, but not tell you how many vulnerabilities and configuration issues are on the instance that is running in that security group, which has the access to the compromised S3 bucket. Here, you should be able to do that in about 4 clicks. Once we improve the UI a little bit, probably about in 2 clicks. Those are the couple demos that I wanted to do. Going back to presentation. As I showed you, again, individual point solutions, little tools can give you bits and pieces.

What we have been focusing on for the customers is an integrated solution, starting from ITS and inventory, building a real platform and doing all There is no magic here. You have to do the hard work. You have to use agents, you have to use scanners, you have to use active scanners, and collect all this data, and then start to show that visibility, and then provide remedial capabilities. Once you have good, solid, up-to-date visibility, then you can start to take those actions. That's what we have been focusing on from the product perspective and with our own expansion and some of the acquisitions that we have done. Thank you very much.

Melissa Fisher
CFO, Qualys

Thank you, Sumedh. Today, I'm going to follow on based on what Sumedh said and talk about the cloud platform model from a business model perspective. Specifically, how we are expanding our TAM, driving accelerated multi-product adoption, increased stickiness, as well as how the model provides operating leverage and delivers profitable growth. We've significantly expanded our TAM. We estimate our TAM today to be $11.6 billion, growing to $20.7 billion in 2021, and we've expanded it by adding solutions that Sumedh talked about, such as passive scanning, ITS management, and cloud security. At the same time, our revenue has grown faster than the market, and we're in some of the fastest-growing security markets. What enables this is the platform. You can see platform adoption accelerating across enterprise customers with 2, 3 or more, and 4 or more solutions.

We see strong increases in penetration of our enterprise customers with five-plus solutions as well. This is in part due to adoption of the cloud agent. The cloud agent enables us to deliver many new applications at only a marginal additional cost. Multi-product adoption drives meaningfully higher revenues for us, with enterprise customers with four-plus solutions at five times the amount of a one-product customer, and enterprise customers with five-plus solutions at seven times the amount of a one-product customer. Oh, it's going the other way. Okay. This impacts retention rate as well. Enterprise customers with two solutions have a gross dollar retention rate of 92%, but multi-product adoption increases stickiness, with enterprise customers with four solutions at a best-in-class retention rate of 99%. Our land and expand strategy is one contributor to why we enjoy industry-leading margins.

Our platform model has significant efficiencies in R&D and sales and marketing. On the R&D front, as Sumedh spoke about, all of our solutions are integrated into one platform, and we have reusable product modules that enable us to deliver solutions effectively from a time perspective and a cost perspective. We continue to grow our large base of talent in Pune, which gives us significant cost leverage. As an example, if all of our R&D in India in 2017 had been in the U.S., we estimate that our margins would have been more than a third lower. As you can see, our R&D as a % of revenues in 2017 would have gone from 16% to 29%.

On the sales and marketing front, we leverage our platform as a distribution channel, enabling prospects to try and buy, generating sales at a low cost, and the incremental cost of additional revenues from our existing customers is very little. All this exemplified in a top-tier LTV to CAC ratio. Our platform approach, which is driving accelerated multi-product adoption, results in strong and consistent revenue growth, a 20% compound annual growth rate over the last three years. Our revenue growth has been organic. Our M&A to date has been focused on acquihires and technology to accelerate our time to market, not to buy revenue growth. Because of our platform model, our revenue growth drives profitability and increases our margins.

As we shared with you in June, with the momentum that we have, we believe we can sustain low twenties revenue growth in 2021, and we see a path to revenue growth of mid-twenties. The delta between the two will be driven both by the expansion of revenue from existing customers, as well as the contribution from new customers. We continue to balance growth and profitability, and we expect to see EBITDA margins of between 40% and 42%. In summary, we believe Qualys is a unique investment opportunity because of our leading position in cloud security, our multiple levers of revenue growth, and our highly profitable operational model resulting in industry-leading profitability. With all the additional solutions we have, we believe we're in the early stages of building a highly profitable billion-dollar revenue-plus company.

With that, I would like to bring up Sumedh and Philippe for questions, and we'll entertain questions from the audience now.

Speaker 8

Okay. We have a mic here. No. Let's see if we can get another mic. It's coming. This one working? No? Okay.

Melissa Fisher
CFO, Qualys

Gives people time to think about their questions.

Speaker 8

Exactly. All right, there you go. Okay. It's working?

Speaker 6

Okay, here's one.

Speaker 8

It is one seven. Do I have a button someplace?

Speaker 6

Were you going first?

Speaker 8

Oh

Philippe Courtot
Chairman and CEO, Qualys

Very good. Thank you very much. Okay. Do we have the mic here for the first question here?

Speaker 8

Eric has it.

Philippe Courtot
Chairman and CEO, Qualys

Oh, Eric. Okay. You stole the mic.

Speaker 7

All right, Eric.

Philippe Courtot
Chairman and CEO, Qualys

You stole the mic. Okay.

Speaker 7

Eric from JMP.

Philippe Courtot
Chairman and CEO, Qualys

Okay.

Speaker 7

For Sumedh, the demo was impressive. Curious, the network traffic that you're collecting data on, what type of sensors are you collecting a lot of that data? It wouldn't be coming from your traditional scanning sensors or the endpoint agents. Where is a lot of that data coming from? Can you give us a little bit of contrast how that product might compare to what Tanium, I think is doing?

Sumedh Thakar
Chief Product Officer, Qualys

Yeah. Very good question. As you rightly pointed out, the traditional scanner is the active scanner. It goes and reaches out to the host, then the agent, of course, is on the specific devices. The network sensor is part of the acquisition we did with Nevis, which is a sniffer on the network that passively listens to the traffic by connecting to your tap port of a switch at a router. Basically, it sees the entire traffic go back and forth, it is just recording and listening to that traffic.

Based on the analysis of the traffic on the platform side, it can actually identify the devices that you see on the network, be able to look at the traffic, for example, to say, "I see this device communicating." You'll see as part of the device, it is communicating in a way that is very consistent with iPhone 12.x, or maybe it has a user agent string in the browser that helps us identify. That is the technology that we use for that. Relative to Tanium, as far as I know, I don't think that Tanium has the ability to sniff the traffic on the network at the switch level, where you can see the entire traffic of that network going through the single point so that you don't miss anything.

Philippe Courtot
Chairman and CEO, Qualys

Yeah. Let me maybe add two more things here. One is that the secret source of our passive scanning is the fingerprinting. The analogy that we have here is the way, if you look at what Google did with their cars, they have essentially mapped every street in the planet. Today, we've embarked into a huge project of essentially fingerprinting every device on the planet. Sniffing the traffic network, analyzing what it is, this is a very well-known technology, which has been used for years and years and years. That ability, then if you don't fingerprint, then you don't really know what connects. That's where the big secret source is, which is a huge undertaking that we have already taken.

We have a lot of customers, like a very large manufacturing car companies in Germany, which essentially we're starting to map all of their industrial devices as well with them, and we are doing the same thing with the other companies as well. That's a big undertaking. The second thing I would like to add about Tanium is that Tanium, albeit their concept was fantastic, and they did a very good job that selling at the CIO level, that 15 or 22nd visibility, and the fact that you could see on your endpoints, essentially have a lot of information and even react on these endpoint. The problem is that albeit the vision was fantastic, the architecture was flawed or is flawed because they use peer-to-peer, so they have to install a 72.5 MB agent. Everything you've got to do is to query.

You have to query that agent to get the information back. Where do you put that information back? You need to have a back end like Splunk to put that data on and do the analysis, which of course is not very real-time. On the second, it's limited to the endpoints, to your traditionals. They don't have a solution yet for, of course, the cloud and for these other on-premise-

Containers

and for the containers and for all of that. Today, people are tired of these one solutions that do maybe a good job at that, but then miss a lot of things. That's where we were very patient. We were telling you that when we went public, if you recall, that don't expect Qualys to see significant growth because we want to invest, what I call in fake growth, but not sustainable growth. We're building the platform. It's a huge task. When we have the platform, then we're going to be able to integrate all of that and become extremely disruptive. This is the day that's come, and that's why at that user conference, we really unveil where we are, and there is even more to come. That's the big difference.

The other thing about Tanium, which is also a very big weakness, is because, in fact, you have to query the agent. When that device, that laptop leaves the network, they have no visibility anymore. With our architecture, which is again, a small agent that beams up changes, even when that laptop has left the network, the agent continues to monitor what's going on that device. As soon as that device reconnect anywhere on the planet onto the Internet, immediately the agent beams up all the changes so we know what has happened. We can essentially use all that information to quarantine the device even before that device comes in, into the network. As mentioned, as Sumedh mentioned, the old NAC concept is too black and white.

We have introduced that notion of secure access control, so we could really absolutely start to really quarantine that device on a much more granular basis.

Speaker 7

Just a quick follow-up.

Philippe Courtot
Chairman and CEO, Qualys

Please.

Speaker 7

The Nevis sensor that you're talking about, is that very broadly adopted by the customer base?

Philippe Courtot
Chairman and CEO, Qualys

This is an old technology. NetWitness or the passive scanning is again, you had company like

Lancope.

Lancope, all of that. This is an old technology, very well known, deep packet inspections. It's essentially, a sensor you put on the tap port. What is also very unique with Qualys is that the sensor is like everything we do. It is centrally managed and self-updating. You install it once and forget about it. Like today, we have 50,000 appliances worldwide distributed. We have some that are 15 years old. We totally forgot that's

Still works.

It still works. The customers, they don't have to worry about the infrastructure. We are truly an infrastructure as a service in that sense.

And the-

That's the other big difference.

Sumedh Thakar
Chief Product Officer, Qualys

Specifically, the Nevis sensor is actually deployed at multiple banks, large banks in India in the production environment. It's fairly battle-tested. It's been about integrating that into our platform. More importantly, adding the fingerprinting and the machine learning around that to be able to identify the devices. The sniffing technology itself is not a huge deal.

Philippe Courtot
Chairman and CEO, Qualys

Okay. Madison, you had a question?

Speaker 6

We've talked a lot about consolidation and building out the platform, and you have a lot that's coming out in 2019. Do you feel like we'll be approaching a point to which you feel like you have the full platform, or should we assume that the cadence that we've been seeing of R&D releases will continue? Then how do you make the determination of what you feel like you need to build or buy yourself versus what you want to partner with?

Philippe Courtot
Chairman and CEO, Qualys

I would say, but Sumedh will add.

Sumedh Thakar
Chief Product Officer, Qualys

Yeah

Philippe Courtot
Chairman and CEO, Qualys

This is the discussion that we have.

I.

We don't have these MBAs which analyze where we should go everywhere. We listen to our customers. That's the first thing we do. We look at use cases. In fact, one of the things that our customers appreciate very much is that we connect our engineers with the customers. The engineers can have an idea of the use case instead of having people translating in between. That's one of the very unique things of Qualys our customers appreciate. We have fantastic customers. They have so much knowledge today. The days when the manufacturer were the one knowing things and delivering, We were connected with the guard of technology, bringing that to the masses are over. A lot of our customers, they know more than we do, and they have also the use case, and they have the pressure of the business.

We embark them in everything that we do. That allows us more to absolutely understand what's important, what's not important. Second, we don't have that culture of invented here at Qualys. We have a culture where our engineers essentially are very curious of the new technology. Also ourself, as Sumedh did in this presentation, we are eating our own dog food. We've got to evolve. We have learned how to change the platform, which is very hard to do because it's like changing, the analogy I give is when you want to upgrade your eight-cylinder engine to a 12 cylinders on the highway, you can't stop the car. You have to do that as you continue delivering the service. We have learned that very well. We've absolutely done that. Maybe Sumedh.

Sumedh Thakar
Chief Product Officer, Qualys

Yeah. I will say, I guess start at the beginning, we're completely tied to IT. What we do, what we are on the platform. Apart from that, I hope we continue to evolve the platform from a job security perspective.

The only thing that I would-

I would say that, sorry, just so if you had asked me a year ago, about KubeFed, and two years ago about Lambda, we would have no idea about that. We don't know as IT is innovating at a very fast pace, more and more things will come, in IT that security will need to respond. The advantage like we have is with the platform and the engineering team, we have been able to respond to that. Next year, there will be more things that will come that we will be responding to.

Philippe Courtot
Chairman and CEO, Qualys

The other thing that I will say with in acquisition, we're also very, first of all, we are absolutely, we look at the architecture. That's the number thing that drive us. If the architecture is not the architecture that we believe is the right architecture for that use case, and second, that we will also analyze the effort it will take us to essentially integrate that architecture into our platform. That's what guide us. The second thing which guide us is that when I look at these acquisitions today, the price that people are paying, it's absolutely insane. It doesn't make any sense. We look, for example, the example I give, we look at Evident.io, like when it was about two years ago. We look at the technology, the VCs wanted to put them in the block, and we're going to see more of that.

I mean, today, I used to say we are kissing a frog.

Two frogs a week.

Two frogs a week. I mean, it is absolutely, they've got, of course, beautiful slides and the growth and the this and the that. When we look at Evident.io, we look at the architecture and say, "Okay. Nothing.

Point solution.

Yeah, point solution. Nothing really fantastic, but not bad. We start discussing about the valuation, and this is our, "What's the valuation?" "How much you" "Tell us what the valuation, how much you want?" "$150 million." "Okay." We politely say, "We're not a very rich company, so that's too much for us." After that, a few months later, Palo Alto Networks acquired them for $302 million. We build absolutely all the functionalities of Evident.io with six engineers in India in a year and a half. That's the other element that we look is.

Sumedh Thakar
Chief Product Officer, Qualys

Did you say?

Philippe Courtot
Chairman and CEO, Qualys

I'm sorry?

Sumedh Thakar
Chief Product Officer, Qualys

Eight months.

Philippe Courtot
Chairman and CEO, Qualys

Yeah, eight, sorry.

Speaker 6

Eight months.

Philippe Courtot
Chairman and CEO, Qualys

You said a year and a half.

So-

Sumedh Thakar
Chief Product Officer, Qualys

Eight months.

Philippe Courtot
Chairman and CEO, Qualys

Yeah. In eight months. Yes, eight months. For us, when we acquire a company, we look also at that, okay, should we build it or should we buy it? The quality of the team becomes very important. One of the things that we do also very well, and now that you have been able to see, we really empower the people that we acquire. We're just not there to take their technology. No. They continue driving, and you saw that in the presentation of Rohit, of 1Mobility and other presentations. They're really driving. This is their baby. The only thing we ask them to do is to essentially make all the effort to really integrate that as best as possible, the best possible in the platform.

At the end of the day, what makes us disruptive is exactly what makes disruptive, the Azure, et cetera. The platform is the delivery channel, is the delivery model. When we build something, it's immediately, instantly available to all of our customers. We're building also more automation into that so customers could self-provision all these new solutions, et cetera. The world has changed, and I think, again, the platform is really the key. Many people speak about platform today. I have yet to see, except this big platform that I talk about in the security industry, companies which have really built a real platform. I think we have, I don't think there's that many others that I know of. Please.

Speaker 6

I don't need a mic.

Philippe Courtot
Chairman and CEO, Qualys

Okay, very good. Go for it.

Speaker 6

Anyways, congratulations. This has been a great conference so far. Yesterday, with the product demo, I was blown away. I think you put the pieces really well together.

Philippe Courtot
Chairman and CEO, Qualys

Thank you.

Speaker 6

The energy from customers was very high. From a financial perspective, clearly the company's very well run. My comment is about capital allocation, which is something that Eric brought up earlier. Why not go more aggressive? I know you have a share buyback because you could quote the number, but why not be more aggressive and actually decrease the share count meaningfully considering that you're not likely to do a large acquisition given your strategy?

Philippe Courtot
Chairman and CEO, Qualys

That's a very good point. We're very sensitive to that as well. In fact, we started to do the share repurchase, not at all to pump up the stock, but because our large investors essentially were telling us, "You have so much cash. What do you do with that cash? What you should do." They gave us the idea of why don't you essentially try to minimize the dilution that we create because we acquire companies, because we have stock option and other issues, et cetera.

The reason why today we're not more aggressive, I would tell you, is because we still are building that war chest, because I do believe that the time, and I've done that in past industries, that's what we did when we sold Signio to VeriSign, then we could acquire the competitors who are so disruptive that I see in a not so distant future competitors that today we're going to acquire a few cents of the dollar for the customer base because now we can suddenly replace all of this old technology that they have. We're trying to keep a little bit continuing building the share. That's what's behind my mind. Now, when is that? The acquisition will be bigger. I will give you, for example, things that I could think of.

If you look at what we have with file integrity monitoring, there's other solution out there which are so expensive to manage and to deploy because you need servers, you need to update all the agents on every version of Windows, et cetera. It's going to be a point in time, and that's, for example. These competitors are not growing anymore. In the old good days, you could keep a technology and then by stopping investing fundamentally in R&D, still continue to generate cash. You had more of a tendency to keep these companies because they were becoming cash generator. These days are gone. Today with the change of technology coming so fast that you see when you start to go flat and then start to go down in revenue, guess what? At some point in time, shoof, you just go vertically down.

That's the time when we can suddenly say, "By the way, okay guys, how much are you doing in maintenance? You're doing, let's say, $50 million in maintenance, $100 in maintenance. We buy you the maintenance. I give you $100 million. We take all these contracts, of course we're going to replace." That's the reason why we're not more aggressive.

Speaker 6

Thanks for taking the time to address us today. The demos have been very impressive.

It's great to see the product momentum. I have a couple of questions I hope you'll indulge me in. The first one is, Philippe, you mentioned when you were talking that you were thinking of the Global IT Asset Inventory management-

as kind of the new center of the-

Philippe Courtot
Chairman and CEO, Qualys

Correct

Speaker 6

platform. I wanted to ask if that's the case, it feels to me like that kind of maybe changes your competitive dynamic a little bit in terms of not just working purely in the security space, but potentially going against ServiceNow or EMC or a whole bunch of other competitors that are already doing general IT asset management. Is that intentional on your part and how do you think that competitive dynamic changes?

Philippe Courtot
Chairman and CEO, Qualys

Yeah, no, this is a very good question, in fact. You're absolutely right, but I would say it's changing drastically. Today if I take, for example, ServiceNow, I see ServiceNow much more as a real partner where They have some discovery capabilities for the inventory. Today we synchronize with our CMDB two-way synchronization. I've already about 70 customers. We have a lot of joint customers. We see ServiceNow specifically much more as potential very big partners where we could have a very strong alliance because we're never going to go into the CMDB business. This is not our business. Essentially, our vision is to unify IT security and compliance into one solution, which is what we're doing, but around the data that we collect. Of course, we can build the application on the top of it.

We see ServiceNow as a significant partner. Today, what is interesting, I've been, of course, starting to connect with CIOs. In fact, I was with a CIO about a year ago of a French bank, in fact the largest French bank, which is Qualys customers, and the CIO is a wonderful lady. I was starting to test and essentially say, "Okay, do you have a good view of your global IT asset inventory?" "Oh, we don't," et cetera. Of course, the security people say, "We cannot secure what we don't know." I explained to her what we're doing and she told me, "Philippe, as soon as you have it, please come and show it to me." We have it very in a few weeks we're going to show it to her. That allows us to have a real dialogue with the CIOs.

Today you're going to see more and I've done tested that with many other CIOs of our customer base. I was in Les Assises de la sécurité in France, in Monaco, not for the casino there, but because I was a keynote speaker there, I had companies like AXA, Allianz, Société Générale, others coming to me. They are seeing that we've become strategic. Strategic for two reasons, very simply, because they have to consolidate the stack. Absolutely. They don't even have the people to manage all of that. When you look at the cost, look at the cost it takes you to essentially bring all that data into a Splunk operate all of that, Splunk charges you by the data you index.

You have seen that we have essentially indexed, by the end of the year, we'll have indexed a trillion data points on Elasticsearch clusters. We know how to index data. The market is now coming to us that way. When in the past we were selling bottom-up, with the technical people, vulnerability management, web application scanning for integrity monitoring. Now today, we really have the opportunity to sell from the top, which is much quicker, obviously. Our model is a very straightforward model, which they like. We never increase the price on our customers since the beginning. Our model is very simple. If we can have our customers renewing, and you saw that the more application they use, the most naturally sticky we become.

Of course, if we renew our customers, we can live forever, we just need to manage our expenses. If we can sell them additional services, we can grow forever and grow profitably. Everybody wins in our model. That is because essentially we adopted that model many years ago. I remember always the old good days, when I went in 2002 or 2003, I don't remember, to see Marc Benioff. Because I said, "Marc, you guys are flying and we have so much resistance. What are you doing?" Marc, as you know, is a pretty big guy, tall. Looks at me and says, "Oh, Philippe, this is pretty simple." I say, "Okay." "Yes, please tell me." He said, "Look, Philippe, the IT people, they don't like us because they believe we take their jobs away.

They have nothing anymore to install. The security people don't want to talk with us because we take their data away." These were our customers. We had, in my life, I've never had so much resistance to fight against. We knew ultimately that the model was the right model. The changes we're talking today are absolutely fascinating. I mean, this is absolutely incredible. We're very close to what Amazon, Azure, Google, et cetera, Alibaba, we just met with them recently, are doing, because this cloud platform already changing the world, and we want to be there. We know that our role there is to essentially help them build security into the platform.

We did a fantastic integration with Azure, whereby today, if you are an Azure customer, you go to the Azure security center, you click, you have few immediately on the top, you have the view of all your resources. You click another button, courtesy of Qualys, you have the view of the vulnerabilities of all of your environment. You click on another button, that's not us, but this is Microsoft. Now you can remediate. Click, click, done. That's where the world is going, I think we're extremely well positioned. Please.

Speaker 6

Let me make one more comment.

Correct me if I'm wrong, but you also get growth from new customers. I know it's less.

Philippe Courtot
Chairman and CEO, Qualys

Yes

Speaker 6

existing customers adding solutions, but you make it sound like you're not growing from new customers. You obviously are.

Philippe Courtot
Chairman and CEO, Qualys

Yes, correct. That's very true.

Speaker 6

By my count, you've significantly increased the number of customers over the last five years.

Philippe Courtot
Chairman and CEO, Qualys

Yes

Speaker 6

It's been pretty recurring growth, so I would emphasize that.

Philippe Courtot
Chairman and CEO, Qualys

Correct. No, you're absolutely right. In fact, the reason why we don't emphasize that is because in terms of dollars, the percentage is not that big as compared to our revenues, because first of all, we have a huge customer base. Plus, we do a lot of upsells now. As a percentage, it's not much. In the past, it's changing now, though, we were essentially starting with customers small, and then we're growing them. Today, because we have more solutions, we start to see customers coming to us because, okay, we become strategic from the get-go. We didn't have to go through, okay, start with VM and then move into the web application scanning and move into compliance. Now today, we can sell again from the top.

Even on our new business, we can see today our deals becoming a little bit bigger as well.

Speaker 6

Can I just follow up on that?

Philippe Courtot
Chairman and CEO, Qualys

Yes, please. Yes.

Speaker 6

I personally agree that it sounds like the upselling and cross-selling of your already substantial customer base is important to financial performance.

I think we need the mic for the webcast, actually.

Philippe Courtot
Chairman and CEO, Qualys

Oh, that's true. Yes. Okay. Sorry.

Speaker 6

Sorry, just to repeat, it does seem like being able to really upsell your customers and increase the percentages in those 2 plus, 3 plus, 5 plus tiers is really significant, for the long-term financial growth path. The one thing that I have been wondering is just, Sumedh, I think you showed that the chart that now has all the different apps on it, right? And there's like 3 dozen little boxes with acronyms on there, right? To me, when I see that, I'm not a CISO or IT manager, but it feels pretty overwhelming, right? There's a lot up there. There's a lot of different applications, and it sounds like there's quite a few more to come. Is that a concern in terms of being able to get people on board with all those things?

There's almost too much that it's overwhelming to them and how does your sales model account for that to try and get people

Philippe Courtot
Chairman and CEO, Qualys

Yeah, not at all. It's exactly the opposite. It's exactly the opposite because first of all, yes, our customers, they are already challenged with that plethora of application. The only problem for them is that they require a specialist on each of them. They need to integrate them together. They need to put that into a SIEM or into a Splunk. When there is this today, they see, and you're going to see more and more-Everything unified, that as you saw on the Sumedh demo, all of these things, all of these apps that you see today are, in fact, now absolutely in that single pane of view. It becomes pretty easy for you. At some point in time, that's what I made that reference to WeChat. You don't care. You just do whatever you need to do, click, click.

I need to do this, I need to do that. All these apps that you see today, which appears to you effectively overwhelming, they will fuse. They are fusing everything.

Sumedh Thakar
Chief Product Officer, Qualys

Yeah. If I can add to that is today, this is how the buyers look at, "Oh, I need file integrity monitoring. I need this." There are different teams within the organization who are buying that. That's today how it goes. Again, to that analogy of the car, at some point, you just say, "I have a security package," and not, "I have a seat belt, I have this, I have that." I think that's what the buyers and everybody has to still do the transition. Today, they have the ability, and the value we will bring is once all these things start to connect with each other and provide that ultimate value, which is detection overall, then the specific apps are not going to be that important.

Philippe Courtot
Chairman and CEO, Qualys

One more point that I can make today. We see from our large customers today, they come to us and they say, we had quite a few example of that. "We like essentially instead of buying application one by one as we need, why we don't do a kind of an overall, all-you-can-eat type of application?" Our answer is interestingly enough, today, is as follow. Oh, we absolutely agree with that. However, there is a prerequisite. The prerequisite is that you have to now deploy and have the good view of your Global IT Asset Inventory.

Once we know that, and once you know that, then we can now sit down at the table, essentially say, "Okay, so now this is exactly all your scope, and now let's discuss about how you think you're going to deploy and implement." We can agree fundamentally on the deployment plan across three years or even five years and then say, "Okay, so this is what we're going to do. We do a three-year contract and year one you pay that much, year two you pay just $3, and we can also see your progress in that deployment. If you have deployed much faster, good for you.

If you have deployed not as fast, good for us because we have less cost, we will readjust. That also give me, as you realize, the opportunity to essentially have that discussion at a higher level and say Global IT Asset Inventory. Because once we become the source of truth, we are there. The history of the Global IT Asset Inventory I will give you, it's absolutely fascinating. Just to tell you, this is not something we've just done recently, a few months or a few years ago. We saw that opportunity about 10 or 12 years ago when we saw Goldman Sachs using the result of our scans to audit their CMDB, which was Tivoli. I say, "Wow, that's interesting," because that was not anymore security. We thought naively at the time that we could then, therefore, do that.

I went, in fact, to IBM, I went to see other people, they say, "Oh, no, CMDB this is none of your business, blah, blah." We realized pretty quickly that the scans was not enough data that we could really gather. We had the agent technology. We thought, "Oh, that's it. We've got it made. We can make that now Global IT Asset Inventory." Of course, we realized that now with the known we can do it. Of course, there is the unknown, and the unknown is as important than the known. Now today with a passive standing. It took us that many years to get to that point. This was not a walk in the park. By the way, nobody has ever done that.

It tells you, because if it was that easy, we already would have a lot of people having done that already.

Sumedh Thakar
Chief Product Officer, Qualys

It's going to continue to grow because next thing is going to be, I want to see all my Lambda functions as my inventory, after that, it's going to be, I want to see all my SaaS applications as my inventory. Today there is nothing, no view that gives you that. Next question. You have a question.

Philippe Courtot
Chairman and CEO, Qualys

We need to wait for the mic, yeah.

Sumedh Thakar
Chief Product Officer, Qualys

He has the mic, yeah.

Philippe Courtot
Chairman and CEO, Qualys

Yeah.

Speaker 6

I've got another coming.

Speaker 7

Coming back to you.

Philippe Courtot
Chairman and CEO, Qualys

Okay.

Speaker 7

Two questions. One, in light of the breadth of products that you have, and I think you've been talking about getting to a point where you have the critical mass on the new products, why wouldn't you either accelerate your spending on the sales and marketing, or is hiring the people the limiting factor there? Then I've got a second question after that.

Philippe Courtot
Chairman and CEO, Qualys

Okay. Not really. In fact, we are hiring and expanding. Again, what people don't realize, because they are still in the old model, that in order for you to sell, you need an army of our managed suit sales guys that knock on doors. You have to realize that the platform is the distribution channel. We have also already significant partners already today that now we are going to empower to do more. All the engine outsourcers are Qualys customers and Qualys partners. Ernst & Young Managed Security Services, which is a brand new, is with us, et cetera. We have all of that already there. It's the only thing is for them to adopt the new solution that we bring to market, which are taking some time, and so it's already happening as we speak.

Now, we are expanding our sales force as well, but again, within measure. No need to send an army of salespeople today, again, because of the model. We want to prioritize into the free services that we launch, which are absolutely very cost-effective lead generation machine. Again, it's about the cloud. Look at Amazon. Do they have a lot of army suit sales guys to sell their things? Not really. The platform is the distribution channel.

Speaker 6

Yeah.

Philippe Courtot
Chairman and CEO, Qualys

In doing so, we eliminate a lot of cost, both for us and as well, fundamentally, for the partners as well, because they can follow on our model. Again, as long as they renew and they can sell additional services, more and more integrated, they essentially grow the revenues very naturally, and of course the profitability follows.

Melissa Fisher
CFO, Qualys

Just to add on, this is what I was covering in my presentation. If you remember in June at our online investor and analyst event, we gave a couple of specific examples of customers who'd started with us, a few thousand dollars and gone to become multimillion-dollar customers. We don't need to multiply the number of salespeople to achieve that additional dollars. The same salesperson is still capable of selling those additional solutions, and that's again, because remember, we use a technical sales force as opposed to generalists, so they're able to pick up the adjacencies pretty well.

Philippe Courtot
Chairman and CEO, Qualys

We did another thing also in that expansion of our sales force, we have now introduced the notion of major account solution architects. We have now some of our best technical account managers, who have both the depth and breadth of technology, and they know how to really move up and speak to a higher level. They are now managing more strategic and bigger accounts, and they've got much fewer of them, about four or five. That allows us then, it's going to allow us to grow our large customers even bigger. Today we have large customers being multimillion dollars in annual recurrent revenues. If I look today, our largest customers, it's more than $5 million. We can see ourselves having $10 million a year, with these large customers being managed by essentially one person managing four or five accounts.

That's $50 million for one person.

Speaker 7

Okay. Second question. Your contribution from your newer products, it was around 14%, 15% for a while, then last quarter it popped up to 23%, but that was a little bit of an anomaly because of the big Cloud Agent deal that you did. Where do you see that normalizing in the near term? Then if you look out three years, where would you envision that that contribution could be?

Melissa Fisher
CFO, Qualys

A couple things. Actually, Dan has been waiting, we should go to him next. To answer your question, the percent of bookings from new products actually would've jumped, even without that deal. In terms of how we see the future unveiling from a product perspective, remember one of the things I've talked about is we continue to innovate, both in new solutions, but as well as in VM. Just as Cloud Agent for VM is a solution related to VM, such as ThreatPROTECT. Those today are the biggest portions of the new products. We would expect, obviously with the additional applications that we've just gone over to see that proportion increase, but it's hard to say exactly what it is because people are still increasing their expansion of VM. They're not fully deployed in their environments.

We're only beginning to see deployments at the endpoints.

Philippe Courtot
Chairman and CEO, Qualys

Just to add to what Melissa said. A question that most of you have been always asking, "Who is your major contributor?" I was always saying, we don't really have a multiple. The Cloud Agent obviously is significant, but I can tell you today that I really believe that that Global IT Asset Inventory, because of the large number of assets that our large customers have, could really become that new contributor. The way we charge is interesting. This is the way we're bringing our cloud inventory to market. If you want, if you have for the search, in other words, the ability for you or the IT people to search, you can deploy our agent free of charge.

We don't charge you as long as you have AssetView, as long as you're a Qualys customers, no charge because of course we want that agent to be deployed everywhere because once we have the agent deployed, then we can add these additional services. Now if you want to have the IT asset inventory application that Sumedh shows, then we'll charge you per IP per year with of course volume discounts plus additional few dollars for the synchronization with your CMDB. When you look at the sheer volumes of assets that companies have and that they want now to put their hands on, it's huge. I was discussing with the CIO of Wells Fargo, when was that? Six months ago. Nine months ago. 50 million assets. Hello. Why? Because you have so many, the cameras, the this, the that, it's absolutely incredible.

You're speaking of millions of assets and already I have some customers which are already looking at deploying our Global IT Asset Inventory as we mentioned, we have 30 beta users to millions of assets. You start to realize that even at $1 per asset per year, if you have 1 million assets, not bad at all. I could not answer the question before, but today to that question I can answer. I really believe that the Global IT Asset Inventory is the game changer and is going to be the biggest contributor of new product revenues.

Speaker 6

Yeah, thanks. To that point, when you talk about proliferation of assets, just the move to the cloud, you're seeing it when you talk to CIOs all the time. When you think about what's happening on the cloud between AWS, Azure, Baba, GCP, whatever, how do you as a company navigate that in terms of trying to make sure that you're aligned with the players that ultimately, whether it's geographically, internationally, or domestically, that you're there for those sales cycles?

Philippe Courtot
Chairman and CEO, Qualys

I'm not so sure if

Sumedh Thakar
Chief Product Officer, Qualys

Aligning with AWS and the way they are selling.

Philippe Courtot
Chairman and CEO, Qualys

We are now. We are now starting, effectively, because of course, first of all, it's easy to virtualize one of our solutions and put that in their cloud and in their marketplace. That easy. That's not the approach that we have taken. The approach is we have taken is first do the engineering effort till you are totally integrated, essentially, now we're starting to have more and more discussion with AWS, which again, are our customers as well as already. Now we are essentially bringing more and more of our solution to market, but in a very, very integrated way.

Sumedh Thakar
Chief Product Officer, Qualys

If I can add to that, there is still going to be, like I said, the digital transformation is still going to have the hybrid overview that the customers need. That's where we are well integrated, like the example of Azure, where go to our Azure marketplace, I have a bunch of stuff in Azure. I click Qualys Agent is already deployed behind the scene. I see all my visibility in Azure. Great, helps me with that. That information gets piped back into Qualys, my overall global asset view that I get, I see everything together in one place. We are well aligning with them in terms of, okay, you want to spin up some stuff there? You click, you get it. We still have that global view that they still need because their tablets don't show up in Azure.

Philippe Courtot
Chairman and CEO, Qualys

The same thing plays now with APIs. That's why we made the investment in 42Crunch, because today everything is more and more via API. You ask the question to a CIO or do you know how many APIs do you have? Nobody knows. Do you know really what they do? Nobody really knows. None of that is properly documented, and they are becoming absolutely crucial because you have more and more machine-to-machine communications, et cetera, and then you communicate to this web application via API. That's another totally new frontier. These cloud providers, you need to get to them, and there's a lot of more APIs and more APIs and more APIs, and we're extremely good at that as well.

Speaker 6

Moises, just on growth, because obviously it's been a big discussion, just that strong growth rate next few years, low to mid 20% growth. There's a perception of some wrongly that it's new customer, new application focus. That's what you're betting on. If I guess, Philippe and Moises, it's really your install base. Right now, you look at your penetration.

Philippe Courtot
Chairman and CEO, Qualys

Yes.

Speaker 6

You look and you're like, "If we're even correct on 30%," I'm just throwing out numbers, "This is where we go." It's not like you're betting on the new applications to get to that growth. I just want to get this out there.

Philippe Courtot
Chairman and CEO, Qualys

You're absolutely right. I can even do, I'm a brilliant mathematician, as you are going to realize.

Speaker 6

I know you are.

Philippe Courtot
Chairman and CEO, Qualys

We'll see how brilliant I am. Let's assume that $100 of renewals. That's the base. Let's assume we renew at 95%. Okay. That's $95. Then let's assume that we do 5% new business on that. That's $100. Now I'm back, okay. Then if I do 30% upsell, I'm at 130% growth. That's absolutely the model of Qualys. We don't need this big deal. The reason why we are cost effective with the private enterprise software is that that's why they need this army of our managed sales guys driving their poor SE by the hand because every quarter, once they have sold, they need to find another one and knock on that door to sell that same amount of more dollars.

That's why at the end of the day, you saw fundamentally McAfee under the day they were all going essentially trying to sell the all you can eat to try to be very predator to Symantec by dropping their price and doing a very sweet deal to take all my application. Give me a $50 million check. As I told you before, we don't play that game. That's why we go to our customers. It's a partnership we have with our customers. I'm not there to take money out of their pockets. I'm there to provide them services. We need to earn their trust. If they renew, we can live forever. If we can sell them more services, we can grow forever. That's what I want to sell them first, the Global Asset Inventory, so we know exactly what they have.

We are fundamentally a consumption-based, if you prefer, philosophy in terms of pricing. Even today with the Azure and with the Microsoft and with the Amazon, we're now starting to look into charging by the hour as they do. We have that luxury that not many company has to be able to move from our current pricing model, which is essentially you pay, it's a consumption-based deal, but you pay in advance, a year in advance to you pay by the hour. For us to change that to that model is not difficult because it doesn't impact the revenues at all. It just, of course, will impact the cash. Today, cash is not a problem that we have fundamentally. That's again, the reason why we're so well positioned, but you're absolutely right.

I don't think the industry understand that because of course, they are still in that old model. Even those who say we're perpetual, look at their model, most of them, they are hybrid. They still do perpetual license and plus some recurrent. Not since day one, that's the way we started the model back in 1999.

Melissa Fisher
CFO, Qualys

I think we're almost over. Why don't we take questions from Rob and then Brown?

Speaker 6

Okay. I actually have two. The first one will be quick. Just out of curiosity, given your historical business of VM is not new, why does it make sense now versus before to marry VM and Patch? What is the customer asking for versus why didn't they ask for this five, 10 years ago?

Philippe Courtot
Chairman and CEO, Qualys

That's an interesting question. Sumedh could add.

Speaker 6

If it's too long of a debate, I can take it offline.

Philippe Courtot
Chairman and CEO, Qualys

Yeah.

Speaker 6

I'm just curious.

Philippe Courtot
Chairman and CEO, Qualys

No, no. The market was not resistant. You had the silos. The enemies of Qualys has been in for the silos, the people doing the patch management, and this and this and that, very complicated.

Melissa Fisher
CFO, Qualys

They had the time to take the time to patch.

Philippe Courtot
Chairman and CEO, Qualys

We're competing in the early days against the patch management solution, which said, "Oh, you don't need to do that vulnerability management. You could just need to patch." Now today, the fact that patch, things like Struts, et cetera, the urgency of patching is what is changing the game. Now today with Qualys, you push a button, you can patch everything. It's going to take some time, however, for company to adopt that new model because it's a bit revolutionary. That's what needs to be done. It's a very good question.

Speaker 6

Back on Eric's question of kind of managing growth versus margin. It was back in 2015, you guys at the analyst day introduced the whole concept of the Qualys platform, and there were actually 12 bubbles at that time.

18 now. Your highest growth rate was in 2015 at the mid-20s, and we haven't seen it re-accelerate to that kind of level. Based on Melissa's slide, you're about 2.5% market share. Why not invest more in trying to capture more share at this point, versus kind of-

Philippe Courtot
Chairman and CEO, Qualys

Again, you know, it's-

Speaker 6

the growth margin profile that you have?

Philippe Courtot
Chairman and CEO, Qualys

Our philosophy was, no, it's not about the growth. The growth margin is the byproduct of our model, fundamentally. The reason why we didn't invest in growth is because we needed to build the platform, and that's where we put our money. We had the patience to understand that it's not worth for us to buy a company, for example, to accelerate our top-line growth, which would be pretty easy. I take the revenue, then what do we do with the solution or the architecture? We're very disciplined about that. The VM marketplace was not big enough for us to really invest in that growth. Today, again, we have the platform. I don't need to put this on money suit. You want to see us doing more free services, more this, more that, of course we are going to invest.

I don't need to make the investment that an enterprise software solution does. I've always been absolutely amazed to see how much Salesforce.com invest in sales and marketing. See, that I think is probably because they came from Oracle. I think they didn't need to do that. They did a fantastic job, don't get me wrong. When I look at their matrix, I said, "Hmm, that sounds strange." You look at other companies today, they are not investing that much. As when you're cloud, the platform is the delivery, fundamentally, and that's eliminated a lot of costs. Maybe we have a last question.

Speaker 6

Yeah. I just wanted to ask about Global Asset Inventory, and if you think it's, I assume the answer is yes, but do you think it's applicable to your entire install base of customers?

Philippe Courtot
Chairman and CEO, Qualys

Absolutely.

Speaker 6

The second part of that is, what would you expect adoption to be over the next few years, given it sounds like a relatively new product that there's not really a market for?

Philippe Courtot
Chairman and CEO, Qualys

We could hire an MBA and give you beautiful curves and so forth of adoption. We just don't look at the business like that. I can tell you one thing, we have a huge demand for it. We see that. We have these 30 customers that are all absolutely fascinating. I think the adoption could be pretty big. Again, you have the budget, you have this. I only start to project when I've got enough data points on the curve. That's what we're showing, for example, this adoption. I can tell you one thing, if you look at customer who have acquired two or more solution, it's 69% of our customer base. I can tell you that our customer base will adopt all of our products. We should see 70% adoption, fundamentally of every solution that we have.

At some point in time, again, the UI will fuse all of that. We probably will go into a pricing model. We should consolidate more, it's not going to change much. Then the adoption will be even easier because suddenly I look at ThreatPROTECT, for example, which today is a separate service. At some point in time, we're going to bundle that with VM. That doesn't mean that we're going to reduce the price because we bundle. No. It means that it's going to be totally fused because that's what makes sense.

Melissa Fisher
CFO, Qualys

Just one last thing I'd like to add to the discussion that we had over the last few questions. Remember, unlike other companies, we don't incent our sales force by product because we don't want them pushing product on our customers that they're just gonna churn. I always say I give credit to Philippe for being very visionary about managing a subscription business. It's very different than managing a perpetual license business where you are dependent on the renewals every year. We are very customer-focused. Because though our roadmap is developed based on the continuous dialogue with customers, we know the demand is there, then it's a question of the timing of adoption.

Philippe Courtot
Chairman and CEO, Qualys

Exactly. Okay. Thank you very much. Thank you, a real pleasure to be here with you. Thank you.

Melissa Fisher
CFO, Qualys

We'll take a few minute break, then we're gonna have our customer speaker

Philippe Courtot
Chairman and CEO, Qualys

Yeah

Melissa Fisher
CFO, Qualys

from Experian.

Philippe Courtot
Chairman and CEO, Qualys

Okay. It's Sumedh. Sumedh, I think. Okay. Is your presentation right after?

Peeyush Patel
VP Information Security, Experian

I am trying to find it. I think I was told it was going to be loaded.

Philippe Courtot
Chairman and CEO, Qualys

It should be. No.

Speaker 8

It's not on the drive.

Philippe Courtot
Chairman and CEO, Qualys

Okay.

Peeyush Patel
VP Information Security, Experian

Okay.

Philippe Courtot
Chairman and CEO, Qualys

Okay. Please take your seats, and I'm really happy now today is not Qualys speaking about what we do. It's about our customers, and by the way, quite candidly, this is what we prefer. We like more having our customer telling about their experience with our solution and expressing the challenges that they have. We all become essentially smarter at understanding what needs to be done. With that, I'm really happy to introduce Peeyush. Peeyush, which has been an important person at Experian, as you will see. We don't do big introduction at Qualys because we believe that introduction is yourself. It's what you do and what you say. Correct, Peeyush?

Peeyush Patel
VP Information Security, Experian

Fair enough. Thanks, Philippe.

Philippe Courtot
Chairman and CEO, Qualys

Here you go.

Peeyush Patel
VP Information Security, Experian

Thank you, everyone. I caught a little bit of latter part of the initial conversation right before this. I'll try and address some of those things as well and why we partnered with Qualys to address some of the questions which were asked in the earlier session as well, and why we chose Qualys over some of the other folks, if you would. A little bit about myself, Peeyush Patel. I'm the regional CISO for Experian. I look over North America, which is more than 50% of our revenue, and I also have a lot of global programs. I run multiple global programs, sort of product security, data protection, offensive security, and other areas, and threat management, of course, where vulnerability management sits. That's a little bit more about what I do at Experian. I'll also talk briefly about me as a person.

Because it's quite important as to why we went through the journey we did, and I think it will give you a bit more color about why we chose the platform itself. I started out long time as a developer, and then I ran operations, and then I ran security operations, and then also was a head of audit for a couple of years. I'm sure you guys must have heard, Experian had a minor breach in 2015. As a result, there was a management refresh at Experian, and I came on as part of that refresh. I work with Tom King, who's our global CISO for Experian. The reason that those things are important is because, as you can imagine, the world is changing, right? No longer there is on-prem infrastructure, sort of premise and then cloud or software.

The lines are becoming blurry. It's becoming more and more democratized. The developers are more democratized now. They can go and just download something and try it out and then implement it. Right? More and more teams are coming to me and saying, "Peeyush, we found this great product. We tried it on, it works, and now we should go and buy the licenses." Most of the products we have implemented in last few weeks or last few years have been more from bottoms up rather than from sales guys making sales calls to us. That's a big difference, and that's played a big role into where we got to. Now, how many people know about Experian? Or I could just skip this slide. It's the other E. It's not the one that got breached.

I know it sounds very similar, but just to give you an idea, we have billion people's information. We do close to 9 billion transactions and authorize or verify 9 billion transactions. We have 2.3 billion people's transactional information. What does it mean? There's only 7 billion people in the world, it's almost one third. The reason that is important is the attacks we face are not just the traditional attacks where you get the traditional hackers, but we also face mostly nation-state attacks. My role is primarily, if you ask me what keeps me up at night, is more of a nation-state persistent attack. Right? They have unlimited resources. It's a bit of an asymmetrical sort of playing field, if you would.

The only way we can sort of level the playing field is by partnering a lot of vendors and other thought leaders within the industry to level set, if you would. We'll talk about. As I mentioned before, I've been through an initial breach. I came on right after the breach at Experian, our competitor got breached. I felt like I have been through two breaches in three years, that I've survived, surprisingly, to tell the story. We'll talk a bit more about that, and I think if you have questions at a personal level about what we did, I think I'm happy to answer that as well. Because I know we at Experian take that very seriously. My family's information's there, right? Is everyone else in this room, for most part. Happy to take those questions as well.

There are a lot of things which I can't put in the presentation because of legal reasons, we'll talk about that as well if you have questions. A month before the breach. After our breach in 2015, we established a four-year roadmap. It was called Security First. One of the outcomes we were looking for is how do we reduce the friction? Security has always been looked as friction, unnecessary friction. I describe security in a very different way. I think about it as. I used to work at Ford Motor Company, for example. When I went and talked to the designers, right? I asked them, "What is the most important part of the car?" They said, "Brakes." I was like, "Why?" Because if you have bigger brakes, you can go faster, right?

You have full confidence that when the time comes, you'll stop at a good stopping distance. That's what security is about, right? We are the brakes which you need when a crisis happens or when there is a breach of trust, right? How do you maintain that trust? That's sort of the model we decided to go towards, where we said, we're going to do a paradigm shift. Security is no longer going to be a friction, but it's going to be enabler to innovate and drive the market fast and get our products fast to the market. Right? That's sort of outcome we were desiring after the breach. It was not just get our security posture better, but also innovate and help business innovate and move at the speed of DevOps, if you would. Because that's another cultural change which we were undergoing internally.

There's another thing which was happening within Experian itself is, before our first breach, anytime there was a security problem, the conversation was, what is security doing about it, right? If you think about security, I'm sure you guys probably work at the banks. I was in New York for 10 years. You do the security training, they tell you security is everyone's responsibility. How are we embedding that, right? That was a control transformation also we were going through. That's sort of right before the breach, before the Equifax breach. A month before, we got this funding. We started doing the transformation. The people have been hired. The new team is in place. We are talking to a lot of the partners, the vendors to understand what other products do they have so we can jump the curve.

It almost feels like, as you see in the picture, right? It's like a shark lurking underneath the water, right? We didn't know what was going on, but we did see traffic patterns on our network. We knew something was coming. We just could not pinpoint why was this happening to us. Right? The D-Day, as we call it. This September 2017, the breach happened, and it just changed everything for us. Now, we thought we had a four-year program, which was quite robust and aggressive. That turned into a year program, right? Four years is like, how can we do it in a year? Anything that was two years was, how can you do it in 180 days? Just completely changed.

What does that mean for us as a security team, and what does that mean in terms of solutions which the vendors bring for us? That means we had to move at a rapid pace in a very complex environment. You can imagine this is what our world looked like. Everyone was coming to us. The boards and executives were saying, "What are we doing about this?" Our vendors who were Everyone we spend $1 with were knocking on our doors saying, "How can we help?" You can imagine that regulators were wondering what's going on at Experian, even though the breach was at Equifax. You can imagine there's only three of us. Naturally, there was a huge scrutiny on the industry itself. Everything we had, we had to throw it out of the window.

The four-year plan went out of the window. We said we need to do a transformation and gain back the trust of all our stakeholders, including the board, the consumers, everyone, because the industry felt like it was under attack, and we were just part of it. As I mentioned, everything was too slow. We said, how are we going to change the paradigm? How are we going to move faster? How are we going to provide a solution which manages the risk rather than talk about how we find the risk? Because our ultimate goal for us to be able to bring back the trust of our consumer was to show that we are actually addressing the risk. We are hearing them, and we are actually dialing down the risk. Not the fact that we knew about the risk. No one cares about the risks, right?

What are you doing about it? That's the question we were asked. That's where our board put together a 100-day challenge. They said, "Look, I think you guys have put together this great four-year plan. I want you to do it in 100 days." You can imagine we had to really think outside the box. We said the traditional way of doing the network scan and the agent-based, sorry, getting the report in a certain frequency, getting this information to our stakeholders at a certain frequency, which is not good enough. On top of it, as you can imagine from the breach, what the industry and everyone else realized is that the moment an exploit becomes available, it gets weaponized instantly. The world has changed. No longer do you have a month or two months to have time to do the remediation.

Now you have to do instant remediation. You saw the I think I walked in when the WannaCry slide was up.

Speaker 8

Yeah.

Peeyush Patel
VP Information Security, Experian

It was getting weaponized instantly. What happened? NSA leak happened. It got weaponized, next thing you know, your environment's impacted. If you spend days and days and days discovering your risk, it's too late. You are already infected. That's how we had to think about even our breach itself. By the time we found out, we knew we were 30 days, 60 days late. What do we need to do? These are sort of some of the realities within Experian. Like every other firm, we are highly complex. We have a hybrid model. We have a lot of dynamic assets, and these things never change. Every CISO has these challenges. The firms are getting more and more complex. They are going more and more towards the cloud because of natural reason that you can adopt the cloud in a very frictionless way.

As a result, how do you build the security to adapt to it? That's where we said, "Look, let's change our thought process, and let's adapt the security at the speed of DevOps." Said, "Let's implement the solutions and then iterate over time and improve them." That's when we started talking to Qualys. We said, "Look, we have this challenge. We have a 100-day challenge. I don't know what tools you have. I don't know what solutions you have, but this is what I want. I want to be able to go to my 40 CTOs and say, 'I want you to address the risk in 100 days.' What does that mean? Every day, I'll come back to you and say, 'This is what your risk posture looks like.' You deployed a patch. Next day, I should be able to tell you what is your risk.

Has the patch been applied? Have your risk gone down? We are in the business of risk management. Security is no longer set up for operational function. It's more about risk management and driving compliance and helping the business reduce the risk and innovate and get faster. We are evolving towards a world where security will not be running any operations. We'll be much more compliance and metrics driven. We said, how do we adapt that? How do we enable the CTOs to self-service their security? How do we make sure they have all this information at their fingertips so they can take action, and they don't have to wait for security team to do something? That's where we worked with Qualys. They were going through this transformation where they had just deployed a new platform.

Everything was in the cloud. We have 30 plus data centers like everyone else. We did not have the time or inclination to deploy those scanners everywhere to understand the risk posture. Our job was to reduce risk. Our job was not to run technology or not to run security. That's where we worked with Sumedh and the team. I remember getting on the calls on weekends. Before my Michigan game, I would call him up. Like, "Look, you have half an hour. I need this solution. These are the problems I'm having before I get on and watch my game." We went through some of that journey during that 100-day challenge.

They really stepped up, and they said, "Look, Peeyush, these are the platforms we have." We had a whole shift away from where we were doing network scans to agent-based scans, which gives you instant visibility. I could go back to my CTOs and give them real-time reporting. If they have patched something, they should be able to tell in next four or five hours whether that patch got applied and had their risk posture gone down. Same applies for on the application side. Every time they released code, they were expecting instant feedback because that's what they are doing in the marketplace today. No one is deploying perfect code. Everyone is sort of iterating.

They're deploying 10 to 15 times a day, and then they're understanding, getting feedback, instant feedback from the marketplace, and then iterating the code. We said, let's do security in a very similar way, right? Let's deploy, let's get them real-time feedback, and then iterate and see what worked, what didn't work. That enabled and empowered them to actually help us reduce the risk. We got out of the way, and we basically let the security be a more self-service function. The Qualys and the platform itself helped us enable that. That's one of the biggest reason where I had something early on. I had everyone at my doorstep, McAfee. I had every vendor you can think about, right? Every one of those vendors had an on-prem solution. I had to deploy across 30 data centers. That would never work.

None of my 30 data centers talk to each other because we are a highly acquisitive company like everyone else. In last five years, we've acquired more than 50 companies. We acquire for all kinds of same reasons like everyone else does, either we acquire for IP or for people on the platform, and we keep them running and see if that fits into our portfolio, right? We are highly fragmented. We did not have the luxury of working across all these different technology stacks we had within the firm. That's where it was seamless with our platform, because other vendors, they were much more focused on how, to be quite frank, how to get more revenue, right? They realized the purse strings are open, but they were not providing me solutions.

All the solutions which they provided, none of them were able to meet my timelines, if you would, where we were moving at the lightning speed, if you would, to kind of address the risk. The way our CEO put it, Brian Cassin put it to us is, look, if there is a third breach within the industry, we may not be in the business. There will be very heavy regulations, and we will become a utility, right? It was sort of one of those moments for us where we were on the cusp, if you would, and that's where we're looking for partners who can sort of help us address the risk, sort of jump the curve, if you would, and rethink our problems in a very different way.

Some of the lessons learned, this is more for our general public, in the sense, we sort of worked with One of the biggest differences and changes we made was, we made security everyone's responsibility. As I mentioned earlier, it's not about just the end user's responsibility, but making sure that we enable the CTOs, and we give them the tools to run their own security teams, if you would, and make the risk management decisions by themselves. We played the oversight role to make sure that There were times where there were bad actors, and we slowed those CTOs down, if you would. We said, 'Look, you have to jump through a lot more gates, right? Before you do deployment or before you're able to go to market.' There were ones which were doing really well. They bought into the whole system.

They were addressing the risk, we let them go as fast as they could because we had enough confidence. The only way we were able to do that is because of the platform. We had the telemetry into the risk, based on which we were able to make those decisions. Lessons learned, again, build partnership with the right vendors, right? Make sure they have the right platform. One of the biggest thing we learned from this whole experience was always prepare for a breach for a competitor. You will be surprised how much everyone prepares for their own breach, but no one prepares for a breach which can impact an entire industry, right? It can also provide you an opportunity where you can use the crisis to your advantage. I'm sure everyone's seen the Equifax stock is back at where it was.

We had a very short window, if you would, of 6 months to kind of really transform the security program at Experian, and we were able to do that with the right partners. With that, I will pause and open up for questions. Go ahead.

Speaker 6

You talked about how the cloud platform was key to collecting Qualys and your ability to scale, but there's other VM vendors that do have cloud solutions.

Can you maybe elaborate what key functionality it really was that Qualys was delivering that was differentiated?

Peeyush Patel
VP Information Security, Experian

Yeah.

Speaker 6

The second question is just thinking about expansion of your spend on Qualys moving forward. Are there additional modules that you're planning on adopting?

Peeyush Patel
VP Information Security, Experian

That's a very good question. Let me go back to the couple of slides, and now I'll answer the second question first and then come back to the first one. The only thing we were using first was VM module on that, right? It's only because of the power of the platform that we bought a lot of more set of modules because now, for my purposes, I didn't have to deploy any more agents. I had one agent giving me information on all these different things, policy compliance, ThreatPROTECT, file integrity monitoring. It was one agent. One of the biggest reasons, one of the biggest resistance you have within security is, I'm not sure if you have computers at work. If you look it up, there are tons and tons of security agents on there, right? We did an internal analysis, right?

70% of our compute was being used for activity like processing, and close to 20% of our compute was being used by security agents, right? You can imagine all the agents we are loading on. At one point, we had 22 agents on an endpoint, right? It was creating a lot of friction with our technology teams. One of the differences, the reason we went with the Qualys agent is it has a very small footprint, right? The same agent can be used for multiple things, right? The reason it can do that is it does the scanning of the endpoint and does all the processing in the cloud, so the endpoint does not take on most of the load. As a result, your CIO can actually use the compute which he's invested in for what it is truly meant for delivering services. Right?

Security workload moves onto the cloud. Qualys platform itself does all the analytics for you to be able to give you the telemetry of risk. That was one of the biggest reasons. For us, one of the biggest drivers was the same agent could do multiple things. We did not have to deploy a single more agent. My stakeholders loved it. It has a small footprint, and I haven't had not a single complaint from them. I can name all the vendors who they have complained about. They start with M, they start with T, they start with S. Every one of my technology guys hates it because all the processing happens on the endpoint and they take up the compute. The world is changing. Right? If you go to Amazon, you're paying by compute. Right? Why would you want to pay for that?

Why can't you let a vendor pick up the cost? Does that answer your question?

Speaker 6

Yes.

Peeyush Patel
VP Information Security, Experian

Any other thoughts, questions?

Philippe Courtot
Chairman and CEO, Qualys

Okay, thank you. Oh, there's a question.

Peeyush Patel
VP Information Security, Experian

There's one there.

Speaker 6

I mean, first, I'm just interested, first off, internally at the company, just going through, was it the 60 Minutes and where was that like, "Oh my God" moment, this is different? I'm just curious.

Peeyush Patel
VP Information Security, Experian

The way the sequence of events happened is our CIO got notified like an hour before. Where is that slide? An hour before the thing was going to go public. It was oh my God moment. At that point you had to realize when this happened, we did not know the size of the breach. Just like us, they have billion people's information or a little bit less, more like $750 million. Right? We did not know it was $750 million or was it $140 million. Right? In security, you had to assume the worst, right? You had to plan for the worst and hope for the best. The next question was, for us was a similar question.

You can imagine that the first question after that was, excuse me, how does our posture look like? Do we have those controls in place and are we breached? Right? We spent a week assuring our board and our stakeholders that, look, the ways, we are in a much better place because we had a better controls and we had better telemetry into the risk. We'd been like six months into the journey because we had our breach two years ago. As you know, as a blessing and a curse, right? The blessing was that it was just small enough where it was a wake-up call for us, and we kind of shifted and invested very heavily into security. Right? We are in a much better place, but at that moment, that hour, that phone call came in, it was all hands on deck.

It was a crisis protocol, right? Everyone was on the con calls. We had to give assurances to the clients. It was surreal.

Speaker 6

With Qualys, was their speed just-

so impressed in terms of like, you're talking to the board.

Peeyush Patel
VP Information Security, Experian

Yeah

Speaker 6

you're on the other call, you're calling them, and right away, like SWAT team, they're in, versus other guys, like, "Yeah, we could get there in a few weeks.

Peeyush Patel
VP Information Security, Experian

Yeah, I could call, Sumedh was on my speed dial. Right? That's the difference. Right? I could not get to the other product managers in the other places. To give you perspective, we were just using, as I mentioned, the VM scan. We had network scans, right? Across 30 days. I deployed agents across close to 200,000 assets, I think, after all is said and done, in less than 30 days. That's the speed at which we had to move, because you can imagine, I cannot tell people what their risk posture looks like if I cannot deploy the agent and give them telemetry into their risk. Right? That was to me, was the game changer for us. We were able to do it with very little effort. Go on.

Speaker 6

Thanks for presenting this. I think it's pretty interesting perspective. One question that I have, you made that comment about how you kind of had this six-month window after the thing happened where you could take advantage of the crisis, essentially.

Peeyush Patel
VP Information Security, Experian

Yeah

Speaker 6

to kind of promote the investment in these products and these solutions to help you improve your posture.

Peeyush Patel
VP Information Security, Experian

Yeah.

Speaker 6

I'm wondering about industries or companies who maybe haven't experienced something quite so drastic.

Peeyush Patel
VP Information Security, Experian

Yeah.

Speaker 6

They don't have that ability to use the crisis as a motivation, right?

Peeyush Patel
VP Information Security, Experian

Yeah.

Speaker 6

Like how do you justify if you wanted to.

expand to additional products or things like that, how would you think about kind of justifying that cost if you were sort of-

Peeyush Patel
VP Information Security, Experian

Yeah

Speaker 6

in peacetime scenario?

Peeyush Patel
VP Information Security, Experian

You can imagine every firm has a lot of compliance requirements, whether it's SOX or whether it's GDPR or other areas, right? Privacy is becoming more and more important. Right? As a result, you'll see in a lot of the privacy regulations, there are a lot of security requirements which are built in. I can imagine, I haven't come across any CISO who hasn't implemented all the things I mentioned on this slide. The question is, which vendor can displace and do this seamlessly. Where did that slide go? All these things. Policy compliance, I have to do it. It's because we are a global company across 24 countries, right? Same with the VM. Right? And same with indicators of compromise and ThreatPROTECT and other things. File integrity monitoring is required by PCI. Very few firms are not impacted by SOX or PCI, which requires file integrity monitoring.

Today, they are doing it with someone. The question is, who can provide a seamless, frictionless experience which you can adopt, right? Security teams are going away from running operations. If you look at the world two or three years from now, because everything's moving in the cloud, the platforms are doing it for you. That's what Qualys is doing it actually for you as well, right? Just like what AWS and Azure are doing. Most of the security operations is actually done by the platform for you. Security as a profession is evolving more into a compliance profession, where we are more around understanding the risk which the firm is taking on, and managing the risk and helping the business reduce the risk. That's where it's moving towards. What's happened traditionally is most of the CISOs you're dealing with.

I have a unique background. I come from a development background. That's where I guarantee you the next 10 years of CISOs are going to be from the development background, because AWS and Azure and everything else, you need to have that background where you are relying on the platform itself. Software is eating the world, and it's true. Right? Traditionally what's happened is, most of the CISOs have come from the networking background, because that you had on-prem solutions. More and more, what I'm seeing is where the CISOs have started to recognize that your job is not to run security operations, but to help manage the risk for the firm. More and more CISOs are adopting this kind of model, where you let the platform do the work for you, and you're managing the risk. Does that answer your question?

That's the transformation which will drive.

Speaker 6

It certainly helps. If I can follow up just briefly.

Peeyush Patel
VP Information Security, Experian

Yeah

Speaker 6

on several of these areas. I think Qualys has long been regarded as VM is like bread and butter, right?

Peeyush Patel
VP Information Security, Experian

Yeah.

Speaker 6

Certainly in a couple of these other areas, there's other players that I think a lot of people recognize as best of breed or whatever.

Peeyush Patel
VP Information Security, Experian

Yeah

Speaker 6

like CyberArk and PAM.

Peeyush Patel
VP Information Security, Experian

Yeah

Speaker 6

Varonis and DLP or something like that. When you were in this situation, how were you thinking about those options versus going.

Peeyush Patel
VP Information Security, Experian

Yeah

Speaker 6

with something that was more.

Peeyush Patel
VP Information Security, Experian

Yeah

Speaker 6

consolidated?

Peeyush Patel
VP Information Security, Experian

No, you're right. Let's talk about file integrity monitoring over there, right? We obviously have the McAfee solution, right? It was the speed of deployment, and it was the speed at which I can get to my primary role, which is managing the risk, right? If I were to go with some of these vendors, right? It takes me forever to deploy and get the buy-in from the solution. If a product works 90% of the time, I'll take it hands down, because I know that the world we are living in, I can iterate over time. I can work with the right partners and get it to the point where I need it to be. Right?

Also, another thing which is changing is because the platform provides a lot of this functionality for you, with APIs and other things, you're able to build those customizations on top of it, right? Because of APIs, your customizations don't go away. Previously, you had to build it in on-prem, and every time you moved a server, you had to take it with you. You don't have to do that anymore, right? Now, most of my engineers are actually application developers who I have trained to be security experts. They are not coming from network background. Going back to your question, anyone who's going to be able to help transform and move at the speed of DevOps are the vendors who are going to survive.

The only way you can do that is you take away all the work that a CISO has to do in terms of running operations and building all the platforms, right? Take that on and go back to the work they're hired to do, is to manage the risk.

Speaker 6

Yep.

Philippe Courtot
Chairman and CEO, Qualys

Okay.

Peeyush Patel
VP Information Security, Experian

Any other thoughts?

Philippe Courtot
Chairman and CEO, Qualys

No more questions. Okay. Thank you, Peeyush, very much.

Peeyush Patel
VP Information Security, Experian

No, thank you.

Philippe Courtot
Chairman and CEO, Qualys

Now is the view from an industry analyst from The 451 Group. I propose that we do a little change in the agenda, if that's okay with you. Scott has about a 30-40 minute max presentation. The lunch is next door. I suggest, and for some reason, that was not really connected there because we don't have the screen there. What I suggest we do, so what about we go through his presentation without the lunch interruption, and then after that, you could go for lunch. Is that okay with you? Okay, very good. Scott-

Scott Crawford
Research Director, 451 Research

Very good

Philippe Courtot
Chairman and CEO, Qualys

It's going to be all yours.

Scott Crawford
Research Director, 451 Research

All right. Thank you. Yeah. Very briefly, I'm an industry analyst with 451 Research, and I think a lot of you working on the investment side of things may be familiar with 451. If you're not, I am not a sell-side analyst, nor do I play one on TV, but I do bring a practitioner background to covering the space. I'm a former CISO myself, having worked for an NGO, a UN-affiliated group, the Nuclear Test Ban Treaty Organization. That's the kind of experience on the syndicated research side of things we bring to bear on the market, and we tend to follow innovation and disruption in technology. My team's focus is on InfoSec. We also have a survey-based research group, so I will share you some of the findings that we've done in our studies over the course of the last year or so.

We'll start with some of the top takeaways for you. We will see to the point of it was discussed that Experian and compliance definitely setting an agenda for practitioners these days. We'll also take a look at the impact of the cloud, kind of elaborating on that same theme. We'll look at some of the aspects of shared responsibility for the management of IT assets and security. We'll take a look at the people and the process aspect of security, which is another dimension of security management, and one aspect of that has been overlooked in some of the more recent and high-profile trends. Let's get started with some of the top takeaways.

Of course, security spending continues to increase, one of the interesting things that we've been seeing over the last couple of years is that two years ago, when we saw the number of organizations where the number that reported no change in their InfoSec spend compared to those who said it was going to grow, that share has really expanded into the numbers that are increasing their spend in InfoSec. Our survey for this year is in the field right now, I expect to see that trend continue going into 2019. As was suggested by our friends at Experian, compliance is the top driver for information security projects this year. It's right up there with user behavior, security awareness initiatives. If you think about that, what's the relationship to vulnerability management, for example? What's the largest attack surface in an enterprise? It's their people.

It's how people interact with technology. Where do you first see the evidence of that compromise? You typically see it in the endpoints and the systems that people interact with directly. There is a direct relationship between vulnerability and asset management and user behavior and efforts by the enterprise to get a better handle on securing the organization and taking advantage of people as their first line of defense. We see some of the chronic and ongoing issues with information security staffing up at the top too, but we also see as far as investment in the environment, cloud security, specifically for cloud infrastructure, being the top architectural priority in the organization. Not too surprising considering the remarks that we've just heard.

There's one note here about, we note that security information and event management and, I should say, security analytics as coming in at number 4 among the top security projects. That needs some elaboration. This isn't all about SIEM, and it isn't all about a security operations center platform. It's about new ways to understand analytics that are relevant to security, such as your total exposure in your IT estate. What users are actually doing, the ability to distinguish malicious behavior from non-malicious behavior. It's not just to get a handle on the insider threat. It's actually more common in a lot more cases to have visibility into when the credentials of legitimate, well-meaning users are captured and compromised and used by an attacker to move laterally in the organization.

Of course, vulnerability assessment remains among the top projects in organizations, but that compliance number stands head and shoulders above. It's not just because of GDPR, which of course is certainly having an impact around the world. In fact, almost half of organizations that we surveyed in EMEA are feeling this pressure. A fourth to a third of all organizations cite compliance in various manifestations as a top priority for their InfoSec projects. In fact, we've seen, if you look at the key determinants for approving top InfoSec projects, risk assessment is going to come out on top in most cases for obvious reasons. That's our business in InfoSec. Compliance edges it out just slightly. Again, following on the Experian talk, compliance gives you a way to qualify your information security objectives.

In fact, compliance gets a bad rep among InfoSec practitioners as being, well, it's a detractor from achieving real security priorities. Well, our respondents don't really tell us that that's the case. In fact, twice as many tell us, over the next most common relationship between security and compliance, that compliance actually sets a baseline set of controls for their security program. That's fairly intuitive as well too, if you think about industries where the business is not highly motivated to influence security as a strategic priority. It's a cost center for most organizations. Yes, it can be a differentiator for those who have to deal with highly sensitive information or tangible assets.

For others, it's typically a cost center, and even in those cases where they deal with tangible assets, they may not be real quick to respond, as we saw in the case of the Equifax breach, or may not have the most or best informed response. Compliance helps security practitioners point to a requirement that the organization has to meet and helps them tie that to their own priorities. It does help them prioritize their spend. Another issue with compliance is just the sheer complexity of the estate. We have so many different manifestations of the cloud and cloud functionality. We have so many different manifestations of enterprise IT in the data center. We have burgeoning numbers of increasingly connected endpoints.

That the challenge of maintaining adherence with security priorities across this varied and diverse estate becomes a real headache for organizations where things like data privacy is an issue, and data goes through a lot of hands in the enterprise, through IT, once it comes into the custody of any organization that's handling it. That's the relationship there, and we've seen compliance be a primary driver for organizations this year. What about the cloud? I mentioned that cloud infrastructure security is one of the top priorities, and stepping back a little bit to the backstory, we had a little bit of illustration of this, again, from Equifax. What we've seen in the last few years is this increasing abstraction of infrastructure away from the traditional physical environment.

We've seen this change evolve over the last decade or more, actually, beginning with virtualization, which turned physical infrastructure into software and made it a lot more portable, made it a lot more elastic and scalable as a result. From there, we've gone on to evolutions like containers. Really where containers began was to make it easier for application development to move from development to test, to staging, to production, because you package all the dependencies of that application with you when you put them in a container. It's a much more granular, much more modular way to effectively virtualize the IT environment. We're moving now towards trends to serverless architecture. Essentially what that means is service providers have figured out that the customer really doesn't have to be concerned about managing the security of the underlying environment.

Their approach is, look, we'll put everything below the event horizon for you. We'll handle the security of the underlying infrastructure, provisioning, availability, all of that enterprises used to have to handle, even with their own virtual machines. All you need do is give us your application logic. We'll make it available for execution. In fact, we're not even going to charge you for housing it full time. We'll only charge you when it's actually used. This event-driven model is characterizing serverless computing, and it fits in overall architectures in combination with all these services, to the extent we're now starting to see trends toward integration of these services and concepts called service meshes, which will imply another level of management to tie these together in a coherent and consistent manner. Keep an eye on areas like API security, for example.

As Sumedh illustrated yesterday when talking about containers, the portability and ease of movement of containers also makes it possible that we may see something in the nature of really well-orchestrated arbitrage, if you will, across cloud platforms. The example that Sumedh used yesterday is, let's say a hyperscaler offers a sale on compute. Goes on this limited time only. If you have intelligent enough container orchestration systems that can move those environments fluidly from one provider to another, why not arbitrage those platforms and get the most out of your investment? This is helping to serve to drive the cost of individual cloud computing resources down, making it more of a commodity. These are all complexities that enter into the security manager's challenge. How do you get a handle on all these innovations and all these developments?

We see that the investment in cloud infrastructure security is the area where we expect to see greatest changes in spending in InfoSec techs in the next 12 months. In fact, of the four areas where we see the majority of our respondents indicating that they will increase their spend, cloud infrastructure security remains at the top, and that's kind of our overall categorization of embracing cloud security in all of the manifestations that I just described. Managed security services is number two, and that's not terribly surprising. If you look at that diversity of the IT estate and the ways to implement and deploy IT, coupled with the ongoing shortage of skilled expertise in security. It's not that the field doesn't have appeal to new people coming into it.

It's finding the people with the right level of experience to handle security strategy intelligently and respond to things like sophisticated threats. Great opportunity for service providers. In fact, we've seen segments within security services that experience a boom because emerging technologies, there's no one with the expertise in those technologies. The service providers have a motivation to invest and capitalize on areas like next generation endpoint security, hence the rise in managed endpoint threat detection and response, or MDR. User behavior analytics, that speaks to what I said earlier, but again, that's a sub-categorization of security analytics in a broader sense. What are analytics that gives us better visibility into the estate to give us the ability to be more proactive, more prepared for dealing with the types of threats that we deal with today, beyond just simple security operations? Automation of security tasks.

There are a ton of repetitive tasks in security. Some of them are created by the technologies we use, like SIEM. Because of the breadth and complexity of the estate, we do need a lot more automation of things like a routine response, if you will, to an emerging threat or a threat that's correlated to a specific vulnerability. How do you automate response? How do you up the ante on defense to improve the resilience of the environment? Because as Philippe mentioned in his keynote yesterday, you will be compromised at some point. The objective post compromise is how well can you contain that threat? How well can you respond to it? How resilient is your business against that threat? Automation plays an increasing role on a number of different levels.

For all the investment in the cloud and for all as much as it looks like the future of IT as well as InfoSec, it's still worth noting that non-cloud environments aren't simply disappearing. In fact, we note that while the majority of organizations still maintain, just a bare majority, maintain an investment in non-cloud environments, that's quickly changing. Last year, we actually saw that more than half of our respondents indicated that they were willing to move business-critical applications to the public cloud. At the same time, we see an interesting phenomenon going on. Nearly half of respondents to our studies this year indicated that they plan to take an on-premises modernization in place approach to their missing- critical legacy applications. Is that a paradox? Is that a conflict? Did we do bad research? What's really going on there? It's not that unusual an anomaly.

If you look at what the expectations of organizations are when they get involved in their cloud investment initially, cost rises to the top for obvious reasons. Reduce the total capital expenditure, shift it to OpEx, reduce the total outlay when you don't have to invest in your own infrastructure, and all the benefits that come with that resource, scalability, agility, time to market, and so on. When organizations pull back from the public cloud, and we've seen 25% of respondents this year indicate that they were willing to move their public cloud investment to a private cloud, hosted or on-premises or a non-cloud environment, we ask them why. Performance is part of it. If you have more direct control over the environment, if you're willing to make the investment and shoulder that burden, then you can get some performance gains for specific applications that need it.

Cost, still up there. Number two, the same that was number one in moving to the public cloud. What's really going on here? What we see at 451 Research, and we take our name from Ray Bradbury's book "Fahrenheit 451," we tend to use literary references when we do our analysis. We're seeing this sort of getting past the first phase of cloud adoption, and part of the issue here is that it's been so easy to move to the public cloud. In some cases, all you need is a credit card. It's very easy to get invested.

It's very easy to not have to go through dealing with whatever processes you have to deal with IT in order to get access to a very high degree of capability and compute. We experience this on a personal level when, let's say, you sign up for an audio streaming service, it's only $5 or $6 a month, right? Only $5 or $6 a month to manage several gigabytes of your photos. Only $5 or $6 a month to have access to all kinds of sports in any market, until you get your bank statement at the end of the month, and where did your disposable income go? Similar sort of issue playing out in some cases in the enterprise, where organizations are seeing what their outlay is. In some cases, it's redundant.

In some cases, they have assets that they're paying for, they don't even remember or know why, because the people who bought them have left, or the assets that are at issue have just plain disappeared or are of no use to the enterprise anymore. We see organizations wanting to take a more strategic approach to their cloud investment, get a better handle on the investment for the benefit of the whole organization, and not have so much redundancy and cost outlay so they can avoid what's been called the Jevons paradox. Which is the barrier to entry is so low that you keep adding on to your investment to the point where total costs actually are higher than they used to be in the past. It's not that people are retreating from the cloud. Far from it.

As Experian made clear, the investment in the way that IT is done in modern cloud environments is setting the pace for the future not only of IT, but for InfoSec as well too. Organizations are reaching that second phase where they have to be more mature and more strategic about their investments, and we'll see that in other areas as well too. Part of the reason is it's just plain resource sprawl. There's so many choices to choose from. Not just in the cloud in the way that IT is deployed, but in the way that IT is built and rolled into production. In DevOps pipelines, where continuous integration and continuous deployment is the rule, you have developers working very closely in concert with IT operations, thanks to the advancement in the fact that infrastructure is now software. That makes it programmable, so infrastructure is effectively code.

That gets developers more directly involved in defining the environment. By the way, that also means that security gets more directly involved with developers in defining the environment. One of the things was illustrated very well in the last talk that will define the future of InfoSec professionals is how strong is their background in development. If you think that's bad news for the enterprise, it's kind of along the lines of, we need data scientists, but we need people who are expert in security as well too. Well, good luck finding people who are affordable in either one of those fronts. Similar sort of situation with development.

We will need to find InfoSec professionals that have skills in development, understand modern development pipelines and processes and tools, because InfoSec increasingly has to interact with and interoperate and be knowledgeable about those tools and about these development practices and processes. Today, most InfoSec professionals have come up through the ranks of dealing with infrastructure, and a lot of them cut their teeth in IT operations. That's changing now. At the operational end of the spectrum, again, the diversity in the ways that technology can be deployed in the cloud. There's no lack of choices, and this leads to sprawl in the investment, in the IT estate. That's something that InfoSec professionals have been familiar with for quite some time.

Many of you are familiar with this chart from what was Momentum Partners, now Momentum Cyber, thanks to Dave DeWalt, in part, becoming part of their team. This is something that they track every year. This is their logo slide. It's roughly 2,000 security vendors. I don't think they have them all here. That jives pretty well with our count of the total number of vendors in the InfoSec space, this has been a problem for information security professionals for some time. A frequently cited case in point is the number of endpoint security products, given the trends and the evolution of the endpoint security market today. Most organizations have between two and, in some cases, more than a dozen endpoint security products. Why is it necessary to have multiple products that solve one problem?

Well, InfoSec pros have long been known for their preference for best of breed and their willingness to take risks and invest in emerging technologies. That's not uncommon, and one of the things that fuels all the venture investment in the space. At the same time, at least almost half of those that we survey say that it's somewhat to very difficult to manage the sheer number of vendors that they have to deal with. As IT grows more complex, we expect to see even more pressure to choose strategic vendors, not just in cloud technologies but in security technologies as well too. In fact, Jeff Moss, the founder of Black Hat, made a comment this year, and I think, Philippe, you might have actually been on the panel where this statement came up.

Where he said that, "I'm guessing that maybe 20 companies in the world are in a position to actually do something about raising the level of security and resilience for everybody." Now implied there are Facebook, Google, Amazon, and its reach in the cloud. Microsoft and its reach not only in the cloud but in the enterprise. It's also true that if you're responsible for InfoSec budget and you have this fragmented and complex landscape to deal with, you are going to want to do what Experian illustrated. You're going to want to make your investment in areas where you can have the most advantage from your spend and gain visibility across silos.

One of the things about that fragmented security market is that we tend to concentrate capability and insight in these silos, which don't talk to each other to the point where it becomes difficult to put together a cohesive and integrated defense when you have that going on. Overcoming those limitations is one of the things that's driven the emergence of what we think of as the P word in covering InfoSec, which means we've seen a lot of vendors that want to say that they're a platform. In some cases, that's a survival strategy. If you look at the sheer number of logos on that logo slide, how many vendors can be sustained in a market? We have some markets where there are a number of vendors where the market itself is somewhat drying up. Threat intelligence platforms, for example.

There are one or maybe two vendors with a real play there in the enterprise these days, and several more that are kind of looking for relevance in the face of advances in security operations. For them, for everybody, they want to be a platform, but there aren't that many true platforms in InfoSec. And enterprises are aware of this. They're going to want to make their investments in the ones that truly do give them more of a platform strategy to attacking their most serious problems across this environment of both the data center, across applications and services, across their highly varied and increasingly burgeoning estate of highly compute-capable and networked endpoints that give them visibility across the entire environment, on-premises and off-premises for both legacy and new IT. Talk a little bit about shared responsibility with IT and IT ops for InfoSec.

This has been going on for a while. We feel it particularly among Qualys' customer base because of the issue at hand. Considering the legacy and heritage that Qualys has in terms of vulnerability management, we're talking about securing vulnerabilities primarily in IT assets. Remediation of those vulnerabilities also been a shared responsibility with IT. It's interesting to know when our survey respondents tell us who is the primary user of security technologies. You'd think the security team primarily owns these, and they may have influence over spend, but a lot of times, in the case of endpoint security, the desktop team. They're responsible for deploying it. They're responsible for coordinating endpoint security with things like endpoint vulnerability remediation, patching, and systems management. Not that unusual. When we ask which team is primarily responsible for InfoSec products and services procurement, IT department. Again, much the same reason.

Who's most influential in making the investment in InfoSec? It's IT leadership. As we see this continued integration of development and IT operations and the deployment of technology directly from developers through automated pipelines into production in DevOps environments, we're going to see security become more of an advisor, setting guardrails. The business is not going to tolerate security putting roadblocks in the way of agile development and deployment. One of the worst things you can do, we've seen this in the application security testing space, one of the worst things you can do is fail a build unless you've got a really good reason for doing so, because those builds have to proceed towards specific business objectives.

Putting up guardrails, if you will, around what are good security practices in development and deployment is one of the objectives of working more cooperatively with IT teams and finding ways where, in those cases, you don't have to necessarily fail a build. Let's say in the case of incorporating open source software into a project. There may be a vulnerability in a project, but is it actually exposed in the development that you're putting into production? Well, if not, do you necessarily have to fail the build? There are better ways to solve problems, and we have to be more cooperative with IT as security professionals in solving them. Lastly, let's take a look at some of the recent evolutions in people and process, and an aspect that's often overlooked in some of these trends.

I'm thinking specifically of something that's been at issue here just in the last few months. We heard just a few minutes ago that security op centers may be decreasing, which is true if you have an increasing dependence on cloud infrastructure and cloud providers that do a lot of the security heavy lifting for you. What we see in most of the enterprises that we survey is that they're actually increasing their investment in security operations. Part of the reason for that is the increasing complexity of the endpoint environment, the increasing diversity of the IT investment, and the fact that a lot of organizations are still dealing with their legacy tools for managing security operations, which again feeds into the security talent shortage. It's not just in finding personnel, which remains pretty consistent. Two-thirds of organizations tell us they have problems finding personnel.

80% tell us they have a problem retaining their personnel because they become valuable, and that becomes even more pronounced in the larger organizations. We've seen an adoption of security automation and orchestration to try and solve some of these problems because we've historically had people doing a lot of these tasks for event escalation or pulling together the context of intelligence around a threat or an incident to get a handle on are we penetrated, and if so, how bad is it? We've seen developments like the ATT&CK framework, which is an initiative largely moved forward by MITRE.

It's a successor to things like STIX and TAXII, which is a way to make threat intelligence machine-readable and characterize it in ways that security tools can consume directly, which is in turn inherited from some of the impetus, the way behind the definition of CVE and CVSS and vulnerability definition, for example. Now we see this logic applied to threat intelligence in ways that can modularly, if that's a word, describe adversary attributes, specific techniques, and tactics, so you can correlate an adversary to their known techniques. You can correlate specific techniques and tactics to known adversary groups. You can get a better understanding of the threat that you face. You can elaborate on this. You can include in a specific scenario the type of software you use.

For example, in the case of what Mandiant refers to APT28, what CrowdStrike calls Fancy Bear, basically a threat actor group acting in the Russian interest, uses Mimikatz, which is a well-known credential dumping tool to pull credentials from memory in some cases, to gather credentials and use them to gain access to resources, attack and penetrate the enterprise, and move laterally from there. What's missing in this scenario? This is all about the threat as far as this has been elaborated up to this point. What about the target? What is needed in organizations is a way to characterize the target in just as sophisticated and just as contextual a manner so that organizations can build a complete view, not just of the attack and of the adversary, but of the targeted environment.

When you first see the impact of an adversary, typically, you'll see it at the endpoint. What's changed about the endpoint? Do you know what endpoints you have in your environment? Do you know what makes for evidence of a threat at that endpoint? Do you know when they've contacted a gateway? Is that gateway vulnerable to exploit? When they gain access to the back-end server or service, how vulnerable is that server or service? How would you know if it's been compromised? They gain access to an application, to the application data. How do you know to build the scenario of what the likely outcome of an attack is likely to be? You can't stop at intelligence about the adversary. You have to elaborate on that to understand the target as well, too. It gets even better because we already have tools that are moving in that direction.

In fact, if we look at taking those organizations that have taken advantage of the ATT&CK framework, they're already starting to build an inventory of this information that's shareable in a public repository. This is significant because this is what John Lambert of Microsoft has called the Githubification of security. The ability to pool this type of information together in a machine-readable manner and managing it in a GitHub repo, GitHub repository, that anyone subscribing to the repository can then pull that information, I should say, pull that information into their own environment and use to inform their systems, and anyone can contribute to it. The same sort of community involvement and development that's gone into creating the boom in open source software is going to create a similar boom in security operations.

By the way, speaking of open source software, there's other aspects to Githubification that you should keep your eye on as investors as well. One of them. I touched on open source. If you're going to be incorporating open source software into your projects, wouldn't it be good to know if that software has a known vulnerability in it before you start building a production environment on it? There are ways to do that. Qualys is investing in those now through software composition analysis. There's another aspect of that to keep an eye on, and that's the fact that when software is pushed into, or it's actually called pulled into a repository in GitHub, what a great time that would be to perform some automated checks on that software, including for security.

That's not the only type of operation that can be done when software is pulled into a repository. Using pull requests as a point of execution for all kinds of processes, including security, is going to become a matter of increasing focus for development as well as operations teams. This notion of GitOps, if you will, operations that revolve around GitHub-type processes will become more of a factor in IT as well as in security in the not-too-distant future.

Again, getting back to the point at hand here, how well prepared is the enterprise in terms of its investments in strategic providers that can give them this visibility across this very diverse estate, and that can see into each aspect of these processes and give them the information they need to understand the progress of a threat, and even before that, to build a more resilient environment, once a threat appears in the environment, to give them the context they need to perform efficient and effective response and remediation? These are objectives we expect to see more of in the enterprise going forward. With that, I don't want to keep you much further from your lunch, I will take questions if you have any. Well, it's always good. Okay, go ahead.

Speaker 6

Just had a question about your comment about the target.

In your case, it was an application. Do you feel that most of the attacks that happen have a known target in advance, or do you think a lot of them are just we're trying to penetrate and depending on where we penetrate how, then we decide what the target will be, whether it's to take information or disrupt the company?

Scott Crawford
Research Director, 451 Research

It's pretty diverse, which makes prioritization based on threat model a real challenge for organizations. On the one end of the spectrum, they have to deal with these industrialized threats, if you will, where you have someone that's looking pretty openly for vulnerabilities, and we saw that in a very extreme way with NotPetya and WannaCry. There's that end of the industrialized spectrum, which is very opportunistic. There's another end of the spectrum that is more strategic, and they have specific assets in mind. In the case of Equifax, in the Equifax breach, for example, they clearly had an idea of what kind of information is available there. They also knew that there was an Apache Struts vulnerability in the applications that exposed that data to public networks.

Put two and two together, it's not too hard to follow the thread, and that feeds into a third trend, which is as soon as vulnerabilities are made available, they are capitalized on by adversaries very quickly, to the point that zero days, which was a big deal a few years ago. This move to capitalize quickly on vulnerabilities being very opportunistic is really setting the pace for the more sophisticated adversaries. It's really across the spectrum, and it depends on the adversary, which makes the defender's dilemma all that much more difficult. They have limited resources to spread across the entire estate. The adversary can focus on what they want to. Being prepared for that more sophisticated future behooves organizations all the more to have a more strategic approach to defense. Anyone else?

Philippe Courtot
Chairman and CEO, Qualys

Okay.

Speaker 6

Just one question. When you got the survey back that you did on cloud, what was the thing that surprised you the most? You had a pretty good sample size, when you went through it. Just you personally, when you saw that.

Scott Crawford
Research Director, 451 Research

Which ones?

Speaker 6

In terms of the survey, in terms of moving to the cloud, and why everyone was moving to the cloud in terms of the survey. What was the thing you thought was most different than you expected before you did it?

Scott Crawford
Research Director, 451 Research

The one that really stood out was the on-premises modernization in place. Because of the responsibility you're taking on for managing your own assets on an ongoing basis, there has to be something really compelling for that. The advantage that means for a strategic vendor in security is that if you cover those bases from the cloud to on-premise, then you have a better footing for dealing with those enterprises. Immaterial to you whether they make the investment on-prem, off-prem, modern, legacy, or whatever. That did surprise me because primarily the cost factor of moving to the cloud. It's a lot more efficient. You need a lot fewer personnel to manage it. The provider themselves does a lot of the security management for you. We see it linking back to that Jevons paradox.

Total spend has gotten to a point where we need to be more selective about our strategic investments in the cloud and prioritize accordingly. On-prem and legacy isn't going away.

Philippe Courtot
Chairman and CEO, Qualys

No more questions. Thank you very much. I think now we have lunch, which is served next door. Again, thank you for coming, and we can continue our discussion there. Thank you very much indeed.