Tenable Holdings, Inc. (TENB)
NASDAQ: TENB · Real-Time Price · USD
36.06
-0.31 (-0.85%)
At close: Sep 17, 2026, 4:00 PM EDT
36.28
+0.22 (0.61%)
After-hours: Sep 17, 2026, 7:59 PM EDT
← View all transcripts

Piper Sandler 5th Annual Growth Frontiers Conference

Sep 16, 2026

Summary

Q2 saw record revenue, strong customer growth, and a rising expansion rate, driven by Tenable One and the launch of Hexa. Integration of advanced AI models and new pricing strategies are fueling innovation, while public sector demand and regulatory engagement remain robust.

Rob Owens
Head of Technology Research, Piper Sandler

Good afternoon, everyone. I'm Rob Owens, pardon me, with Piper. I head up our technology research group and cover the cybersecurity and infrastructure software universe. Happy to welcome our next management team, Steve Vintz, Co-CEO of Tenable.

Steve Vintz
Co-CEO, Tenable

Thank you, Rob. Great to be here.

Rob Owens
Head of Technology Research, Piper Sandler

Steve, welcome. Thanks for coming to Nashville.

Steve Vintz
Co-CEO, Tenable

We always enjoy ourselves when we come to conference.

Rob Owens
Head of Technology Research, Piper Sandler

Yeah. That's good. Should we start with football games over the weekend? You had probably a pretty good weekend there.

Steve Vintz
Co-CEO, Tenable

I don't think this is the time or place to talk about how good the Ravens will be this year. That's a topic of another conversation.

Rob Owens
Head of Technology Research, Piper Sandler

They looked very good. Unfortunately, my Chargers did not, and I'm out of my suicide pool right away week one. Maybe talk a little bit about the second quarter and net dollar expansion rate ticking up for the first time in several years, and just speak to the puts and takes around retention, expansion, and the opportunity for this to be sustained moving forward or potentially an accelerant.

Steve Vintz
Co-CEO, Tenable

Sure. Good question here. Just a quick recap on the quarter. Basically, over-deliver on the top line and the bottom line and raise our outlook for the year for both revenue and earnings per share, and gave a very strong free cash flow guide. I think $268 million in revenue, so almost $270 million, over $1 billion for the year. That makes us one of the largest security companies in the world, I think one of the ten largest pure play cybersecurity companies. The other thing I'll say here is we delivered over 300 new enterprise customers, and one of the things we talked about on the call, even though we don't guide to CCB, we understand directionally that CCB is directionally a corollary to what we sell.

We said that our CCB is tracking better than expected since the beginning of the year when we provided an initial estimate of CCB of where we would land for the full year. We said on the last earnings call that CCB so far is tracking $8 million-$10 million better. The expansion rate was higher in the quarter. It was the first time the expansion rate ticked up since 2022. Why is that? Mythos was released in April, so during the course of the quarter. While we acknowledge that the demand signals are really strong from customers in a post-Mythos world, both at the top of the funnel and bottom of the funnel. We had one of our best quarters for net new six-figure customers.

We said that, look, the first tell on accelerating growth, because Mark and I have been very adamant and very public about our ability to inflect growth higher here. Said the first tell will be in CCB, so revenue's more of a lagging indicator. With regard to CCB, the early leading indicator will be an inflection in the expansion rate. So pleased to see the expansion rate tick higher. We have confidence in our ability to continue to drive that higher as customers look to expand. I think it's also fair to say that Mythos is one of the biggest demand catalysts that exposure management, the category, will ever see here. We like how we're positioned, and we have a big role to play here as well.

Rob Owens
Head of Technology Research, Piper Sandler

Unpack that expansion and that acceleration within the customer base in terms of, is this them moving to Tenable One, allowing them broader exposure and so the uplift in there is it's sticking with what they have and just having more assets? Are they adding more capabilities on top? Kind of sack rank for us.

Steve Vintz
Co-CEO, Tenable

Yeah. Within the quarter, Tenable One, which is our exposure management platform, was 50% of new sales, which was an all-time high for us. We said in terms of total sales, we acknowledge, but by the end of the year, we expect Tenable One as a percent of total sales to approach 40%. So very pleased with what we saw in the quarter. One of the reasons we had one of our best quarters ever for net new six-figure customers is because of Tenable One. Selling prices are higher, close rates are higher, the highest renewal rates. One of the big reasons why is because it covers a wide range of domains. So yes, asset expansion. We have an asset-centric model.

As customers deploy more agents, more applications, more AI infrastructure into their environment, they increasingly turn to us to not only expand, but also to secure more of that. Asset expansion is a part of that. We have a number of products that are integrated into the exposure management platform. Yes, there's some core VM capability in there, but it's also OT. It's also things like cloud security, identity, ASM, historically have been sold in the market as standalone point products. But to say that customers are migrating to Tenable One because of consolidation really undersells the value. Tenable One, and specifically Exposure Management, solves a much, much bigger problem here in the agentic era. It's about unified visibility.

You do have a complete inventory of your entire digital footprint, whether it's on the network, in the cloud, on the factory floor, to be able to take all of that data, enrich it with ownership data, asset criticality, external threats, to identify your most important exposures, is not optional to survival in this area. Then more importantly, Hexa is our agentic engine to help orchestrate fixes. In short, the value prop of Tenable has evolved quite a bit historically here from the find a company, the visibility company, to the fix a company, and Hexa and AI plays a very important role.

Rob Owens
Head of Technology Research, Piper Sandler

Maybe drill down on Hexa and the ability to close the loop quicker. I think the world is changing rapidly relative to the tools the bad guys have. In effect, I think the bad guys are actually somewhat ahead of the good guys, putting you in that good guy camp, just from the standpoint of friction in traditional processes and things of that nature within organizations. Talk about what Hexa brings to the table. Talk about Tenable's ability to close the loop more quickly, which I'm sure is what customers are starting to ask for.

Steve Vintz
Co-CEO, Tenable

Yeah. Well, Hexa, in short, is our agentic engine. It's part of our harness, and it orchestrates autonomous defense. We live in a world where it took 26 years for there to be 300,000 CVEs. That was the number of CVEs at the beginning of the year, which is basically errors in software. This year alone, year to date, post-Mythos, there's been nearly 60,000 new CVEs. There's 12,000 new CVEs just in August alone. We live in a world where there's a proliferation of applications and agents and infrastructure here, so the attack surface expands. There's more exposures and vulnerabilities. By the way, we're not in the vulnerability discovery business. We are in the orchestrated remediation business. We can tell you if those CVEs and non-CVE risks exist inside your environment. Security defenders are overwhelmed with workloads. You can't patch everything.

You can't change configurations on everything. So that's where the visibility, the prioritization, the ability to match machine speed threats with machine speed action is absolutely critical, and you have to do that deterministically. Hexa helps customers either apply patches, change configurations, determine the existence or the absence of compensating controls, and quarantine an asset or isolate an asset. It's also model agnostic. If customers want that routed through a frontier model, we can do that. If they want open-weight models, and there's a lot of concerns about enterprise sovereignty here, give customers the ability to download a fully parametered file on their infrastructure. It's cheaper, it's more flexible. We can do that as well, all through Hexa.

The right way to think about Tenable in the context of the security continuum is, look, for years, the market has spent a lot of money, a disproportionate amount is spent on detect and respond. Arguably, that's really about response, not necessarily security, but that's an important job. Runtime, detecting, responding. We're on the proactive security side, and so we live in a world where you can't patch everything. You can't secure what you don't see. To be able to take actions deterministically, the right actions with the right fix, the fewest actions that have the biggest impact on risk, it's going to be important. The last thing I would say here, Hexa plays a big role in all of that. We just released it in Q2.

It's part of our foundation and our advanced packages, which are new pricing and packaging, which we just launched a few months ago. 80% of all customers are choosing the advanced package, by the way, which has a 60% uplift in comparison to standalone Tenable One and VM. The last point here would be, we are working very closely with the frontier model companies to integrate their models into the platform. Yes, we're a part of Daybreak. Yes, we're a part of Glasswing. Glasswing means we can take Mythos 5 and scan our own code base. We're one of 150+ companies that has been vetted to do so. But investors can do their own research.

To my knowledge, I'm not aware of any security company, anyone on the planet that has been given permission by the White House, by Anthropic, to be able to integrate a frontier model, Mythos 5, the most advanced model, into a live product, into Tenable One, which is what we announced last week. Frontier model companies, even open-weight models, will help us solve an even bigger problem in security and help customers move from reactive and respond technologies to this proactive mindset.

Rob Owens
Head of Technology Research, Piper Sandler

New pricing, new packaging. What about a consumptive element? You mentioned in the last, where are we, five months now, you've had 20% of the all-time CVEs discovered. I guess it'd be one-sixth, so 18% or so. How do you attach to that? Because there's got to be an opportunity beyond where you're at from a pricing, packaging standpoint. What do you have now? But help investors kind of dream the dream a little bit in terms of this dynamic, because obviously we're going to see more CVEs, we're going to see more day zeros, and we would love to see your model more so attached to that opportunity.

Steve Vintz
Co-CEO, Tenable

Well, there's two ways, and we're doing exactly that, Rob, and that's a good point. There are consumptive aspects to our pricing and packaging. We do that in two ways. Number one is Hexa. We talked about the customers we announced in the second quarter, that we have hundreds of customers already out of the gate that are going in, prompting, taking an action prompting, and then 90% of all actions that Hexa recommends, customers accept. So we sell tokenized packs for Hexa. We sell that in foundation, more so in advance. So if customers want to be able to fix, change configurations, compensating controls, apply patching, whatever the case may be, you can buy tokenized packs for that. So that is an add-on SKU that we just made available here, I think a few weeks ago. The second thing is we launched Adversary View.

That was last week as a part of our partnership with Anthropic, where we're integrating Mythos 5 into the platform. And what does Adversary View do here? When we assess a device or a machine or whatever the case may be, or a system, there's a lot we learn about it. Yes, we can identify the existence of CVEs. We can determine misconfigurations. We can identify access and entitlements. But we also pick up and collect in our raw telemetry data a lot of low signal exposure data. It could be a mid-level CVE on an internal host. It could be a stale service account that has admin rights. Individually, maybe not significant, doesn't make it into our prioritization and risk scores, but when you run it through a Mythos-like model, it delivers and chains together incredible insights.

That's what we're first in market to deliver last week for a partnership. And those are tokenized scans and assessments that customers will be able to do. They're a little more expensive than your traditional scan, but you can buy tokenized packs. It delivers greater insights. So customers have a choice. Obviously, there's a consumptive element to it, and we expect it to have an impact on the selling prices.

Rob Owens
Head of Technology Research, Piper Sandler

Without a doubt, the criticality of exposure management's increased significantly, be that Mythos or what we've seen with Hugging Face, what we've seen over the weekend with, whoa, we don't know where these models are going. But that also invites a lot of competition and a lot of noise. You now see OpenAI talking about their new system, CrowdStrike showing an autonomous capability of red teaming attacking and then blocking. How do you think about the evolution of the space and the defensibility of where you guys sit currently?

Steve Vintz
Co-CEO, Tenable

As I look at it, I think there's two types. There's a convergence coming. You have build time capabilities on the left, and you have runtime capabilities on the right. I believe you'll see a convergence. I think you'll see runtime companies shifting left and build time companies shifting right. So it's important to be able to block, stop or kill agents. I think you're going to see legislation from the USG that talks about having these kill switches in some of these frontier models. I think that's more enforcement at the plumbing. I don't think that's a feature. But I do think it's going to be important. So you'll be able to block, stop or kill maybe through Salesforce Agentforce, maybe through the frontier model companies. There'll be a number of ways in which you can do that.

But to be able to take the right action, orchestrate the right fix, what's important here is the context. The exposure graph is absolutely going to be critical. The exposure graph is a graph of all of your exposures, all of your agents, all of your identities. To be able to correlate that, deliver visibility so you understand the right fixes at the right time is essential. I think that's an important aspect for the runtime players. I think the ability to take action will be important for the build time companies such as Tenable. We're not the visibility company. We're not in the ability just to identify risk. We're in the fix-it business. Not find it, but fix it.

Hexa is our engine to be able to integrate with the tooling, the block, stop, kill, to take an action on an endpoint, to be able to change the configuration, to be able to add a compensating control. All that's going to be important. I see the convergence of those two markets, and I think it makes security better. I think it makes customers safer. I think there's a big role to play here by each. I don't think there's a winner takes all and one security company will prevail in this market.

Rob Owens
Head of Technology Research, Piper Sandler

Fair enough. It has been an interesting year having been through SaaSpocalypse, and we are going to get disrupted everywhere to, oh my God, maybe cybersecurity truly is the real enabler or the bottleneck, however you want to think about it. Maybe lend some perspective to where you see potential disruption and where you see potential augmentation with what is going on with the frontier models. I know through the new partnerships and things of that nature. Help investors kind of what are the puts and takes around this opportunity in terms of pitfalls they should avoid and how this looks for cyber?

Steve Vintz
Co-CEO, Tenable

Well, I would say this. If you look over the last 40 years, every major technology shift has demanded more security. Not sometimes, but all the time. Look at the PC era. With the operating system, I do not think anyone relied on Microsoft to say that they were secure. It gave way to a whole host of new security companies and categories. The shift to the internet. Obviously, we saw things like firewalls and vulnerability management. The shift to cloud, CSPM, CNAPP, and a whole host of acronyms in cloud security that would be too long of a list to name every one.

Rob Owens
Head of Technology Research, Piper Sandler

Yeah.

Steve Vintz
Co-CEO, Tenable

AI is that next big shift. Right now the focus and the spend is on building out infrastructure, and rightfully so, but eventually it will turn to security. I know if you look at in the case of the frontier model companies, their aspirations are to be the intelligence hyperscaler. Well, you look at the hyperscalers today, you look at Microsoft, you look at Google, you look at AWS.

There has always been this need for independent assessments. There has always been this demand for security companies to secure part of that infrastructure, part of those compute environments. I do not think frontier model companies, who knows what the S-1 will say and what they will eventually do, but right now what they are offering in market today is the ability to identify and automate the discovery of vulnerabilities at the source code layer. A lot of this is publicly available.

The real moat is data. We are deeply embedded in runtime infrastructure behind the garden firewall, and we have the largest data fabric that is non-public in the market. So data will be the new moat. It will be above the intelligence layer at the application layer. Where you can take actions deterministically. Hexa is part of our harness there. It will be below the intelligence layer, which is the infrastructure, which is our vast network of sensors. So sensors on domain controllers for Fortune 500 companies.

We do passive network monitoring for water utilities and electrical grid companies. We are on telecommunication networks. We have agents on endpoints. We do cloud workload analysis and identify misconfigs with an audit trail. So all that is sticky, hard-won, years to create, and that is what feeds really the data fabric. So data is the new moat. I think frontier model companies will help us accelerate and deliver more innovation and solve bigger problems.

Rob Owens
Head of Technology Research, Piper Sandler

Out there in the public sector, being the fiscal fourth quarter, I think you mentioned a strong public sector last quarter, if I remember correctly, just how things are shaping up on that front. Obviously, there's been a lot of disruption in the federal government over the last couple of years, which I think is causing some friction out there, but would just love your perspective.

Steve Vintz
Co-CEO, Tenable

Well, this year, the demand environment is much healthier and more stable in comparison to last year. We saw doves and there was disruptions in procurement at the broadest level, not just security. We have a better spending environment, which is great. We talked about a sizable OT win on our last earnings call in our public sector business. What we have also seen here over the last couple of months is a huge wave of new AI security policy from the U.S. government coming from Sean Cairncross, the National Cybersecurity Director in his office, the NCD. We're talking about establishing Gold Eagle, which is a national vulnerability clearinghouse that spans both public and private agencies.

We're also talking about things like binding operational directives, which is U.S. government wants to be able to provide these dynamic risk-based frameworks to be able to harden federal systems, protect critical infrastructure, focus on state and local matters. We have leadership in public sector. We are one of a small number of companies working closely, directly. I've had personal conversations with the National Cybersecurity Director, but one of a small number of companies, part of these task force, part of securing critical infrastructure, part of helping them solve these problems that the agentic era presents.

Rob Owens
Head of Technology Research, Piper Sandler

Great. Questions? Aiden.

Speaker 3

[audio distortion]

Steve Vintz
Co-CEO, Tenable

The use cases are different. We have Foundation, we have Advanced. Foundation is a 6% uplift. Advanced is a bigger step up at 60%. Overwhelmed with the response from customers who are choosing the Advanced package. Keep in mind, we launched these new packages last quarter. So of the cohort of customers that have selected or are buying this new package, they are choosing, obviously, the Advanced package. I am not sure if it will continue to play out that way, but we are certainly pleased. It is one of the reasons why the net new six-figure customers has been one of the best over the last five years. The use cases are different. Foundation is more about visibility. So there are capabilities in there, for example, where we AI Aware, which we can discover all of your AI applications, your browser plugins, your models.

The big focus here is visibility, unified insight. Whereas the Advanced package comes with broader CNAPP offerings, more agentic capabilities. Hexa is prominently featured there with much higher usage limits, which is the action ability. So the ability to automate a workflow, the ability to take an action either with a human in the loop or autonomously is the big value add for the Advanced package.

So it is really this evolution from find it, which is what Foundation can help you do much better than standalone VM because it is cross-domain. But it is also this evolution into fix it, which is Advanced, which is cross-domain visibility and remediation, which Hexa plays a big role in all that.

Speaker 3

[audio distortion]

Steve Vintz
Co-CEO, Tenable

It is a good question, and we have a great relationship with the frontier model companies. I think they recognize it is hard to have a conversation about AI adoption without having a conversation about security.

They recognize that the security community is really important to them. We have access to non-public models. Mythos is a good example. Mythos 5 is a great example of that. We are doing joint R&D research together. We just launched, speaking of Hexa, which comes with a fleet of agents that you can use out of the box that take specific actions. But also we have an agent exchange where customers who are creating agents in Hexa can push them out on the exchange. We have partnered with OpenAI in that regard, where they are helping secure those agents in that exchange. So I think they recognize that there is a big role here, security, and Tenable in particular, has a big role to play here. This notion that you cannot possibly detect and triage every alert, every incident.

This realization that we have to shift our thinking, have to shift our focus, have to shift our budgets from detect and respond to proactive security. They believe Tenable has a big role to play here. We are the leader, unequivocal leader, we believe, in exposure management. I think they are picking market-leading companies to help solve some of these problems, which in turn could help drive more AI deployments. They need the security community, and they need some of the established players, the leaders here.

Rob Owens
Head of Technology Research, Piper Sandler

All right. We have time for one last quick question, if there is. All right. Steve, thank you very much.

Steve Vintz
Co-CEO, Tenable

Thank you, Rob. Appreciate it.