Sumedh Thakar
Analyst · Scotiabank
Thanks, Blair, and welcome to our first quarter earnings call. I'm pleased to report we delivered another quarter of strong revenue growth and profitability. With the accelerated progress of new frontier models, discovering vulnerabilities and writing experts autonomously, the number of detections is going to go up significantly while the exploit window is going to shrink dramatically. The need for organizations to know their true risk to effectively prioritize and auto-remediate riskiest vulnerabilities in less than a day has never been greater. This is why we innovated with the ETM enterprise tourist management platform, which implements an AI rock risk operation center so customers can get the risks remediated instead of relying on dashboard tourism with siloed products that increase their exposure. Given our #1 rating in the GigaOM Patch Management radar with over 150 million patches deployed and over 40 million of these delivered autonomously in the last year with a Six Sigma accuracy organizations are turning to Qualys as the trusted solution to help them move from current broken manual remediation processes to high-impact, low-risk autonomous remediation workflow at scale that go beyond patch management. And that's exactly where we are focused. With exploitable vulnerability volumes surging 6.5x and average time to expect collapsing to under a day as adversaries weaponized vulnerabilities before Patches even exists, security teams focus on theoretical exposure are overwhelmed. Just finding more and more vulnerabilities doesn't equal risk. Real risk is determined by whether an adversity can successfully execute and explore path in an organization's live environment. That's why I'm pleased to report that our most recent addition to our agent AI marketplace agent Vail is now generally available, powered by TruConfirm within our ATM solution agent well delivers closed-loop exploit validation and autonomous remediation directly to the rock. Using autonomous exploit validation at scale, we remove the guest work for customers by running safe exploits over the network to confirm whether attackers will succeed in their breach attempts while enabling security and IT teams to focus on the less than 1% of threats actually exploitable in their production environment. In doing so, we have closed the gap between theoretical and actual exposure and believe set a new adoption standard in the industry, while traditional ETM solutions take days to pull scan telemetry from scanning tools and rely on theoretical risk scores ignoring, mitigating security controls, ETM and its agentic AI workforce takes a fundamental different approach. Inside a continuously functioning loop, it detects vulnerabilities, validates exploit, quantifies real risk, automate remediation and revalidate the exploit, optimize and integrated with leading LLM and SLM this end-to-end approach empowers organizations to be laser-focused on prioritizing only exploitable threats for the next logical step, which is autonomous remediation, leveraging agent era and TruRisk eliminate. Underpinning our risk eliminated solution is our new AI-powered batch reliability score, a model trained our own proprietary data set of hundreds of millions of deployed patches, which predict patch induced outages before they happen, giving customers the confidence to deploy with certainty or positive purpose while setting a new standard for predictive operationally aware patch management. With an umbrella of remediation solutions, including matching and other competing controls, with less than 10% rollback rate. The AI native rock accelerates streamlines and demoralizer security outcomes, so transforming from, we think, to know it's being fixed at machine speed. In the context of the newest frontier AI models giving attackers the ability to soon discover diverse -- zero-day vulnerabilities, generate exploits in near real time and develop autonomous attack agents, unlike anything the industry has seen, the feedback to our get it fixed in our approach from many of the CISOs I met at our decent [ Rocco ] EMEA event in London has been very positive. They shared their excitement about the rapid pace of new capabilities we are delivering their deployment agenda and their ability to now autonomously monitor, measure and confidently remediate actual risk in multi-vendor environment in an era where just generating visibility dashboards is increasingly unacceptable. Our industry-leading capabilities are gaining broader recognition among our customers, partners and third-party analysts. Specifically, our total cloud solution was recognized as a leader in CNAPP in the Q1 2026 Forrester Wave report, and subsequently won the 2026 SC Award for the Best Cloud Security Management solution. Both underscore our capabilities in delivering unified visibility with real-time detection and response at run time across hybrid environments. It was also positioned as a leader in 2026 GigaOM report for cloud and entity and title management and following our dual pan awards late last year, our third research unit has again demonstrated its impact with the discovery of Track Armor uncovering critical app armor vulnerabilities that can lead to root-level compromise and container escape across millions of Linux systems worldwide. This, alongside with our recently released research on the broken physics of remediation further demonstrate Qualys' commitment to fortified security operations and raising the bar on adversaries. The net result is that we have distinctly unified CTM exploit validation cyber risk quantification and remediation into a single AI-driven risk fabric that continuously senses alerts reasons and acts across hybrid environments on with these capabilities and growing rock momentum that will soon autonomously trigger ITSM workflows. We remain laser-focused on accelerating ETM adoption throughout our vulnerability management and detection response customer base and positioning Qualys for larger upsell opportunities over time. Turning to our business update. We have established a long history of converting operational challenges into strong competitive advantages demonstrated by customers spending $500,000 or more growing 9% from a year ago to 2021 -- [ 2020 ] months. That's why one of my favorite wins in Q1 was with an existing global 1,500 customer despite strong foundational visibility that teams struggled to operationalize risk reduction across the growing mix of on-prem multi-cloud environment, silo tools fragmented telemetry, a growing population of LLM and millions of vulnerabilities with limited business contacts. This customer recognized the traditional severity-based prioritizing methods were not long -- are no longer sufficient and launched a strategic initiative to unify risk signals across their environment and operationalize the rock. Leveraging AI for security and security for AI, they expanded the Qualys footprint by adopting ETM and total AI in a mid-6-figure annual upsell. By consolidating disparate signals into the Qualys platform, this customer now has a unified orchestration layer that delivers end-to-end visibility across the attack surface, including deep scans on their assets across binaries, open source libraries and dependencies with centralized risk quantification, prioritize remediation workflows and measurable outcomes aligned with business risk tolerance. This win reflects broader ETM momentum as more and more customers turn to Qualys for evidence-based export validation and remediation while benefiting from the efficiency and scale of AI-native -- automation. Partners remain a key pillar for our growth agenda. In addition to a growing list of nearly 2 dozen certified MRO partners beginning to actively launch new services we are seeing momentum build across all geographic theaters with a strong focus on AI and native rock. For example, one of our largest MRO partners is now in the process of bringing the case-ready AI-native rock to market powered by our ETM and automated remediation solutions. Additionally, to our strategic alliances initiatives, we continue to drive deep technology integrations, co-selling opportunities and demand generation programs. to drive innovation in security research through the latest -- models. We have partnered with open AI in their crystal access for cyber program and anthropic in their cyber verification program to advance our vulnerability and threat intelligence and allow customers to ingest these findings into ETM for further detection and remediation. On the cyber insurance side, we are also pleased to announce a new strategic partnership with Converge Insurance, leveraging the quality team solution to help their customers demonstrate strong security hygiene and qualify for meaningful premium reduction, advancing our vision of tying cybersecurity to business outcome for CECL. Further supporting our growth trajectory in Q1, we continue to expand data testing of Flex designed to help customers accelerate and broaden their adoption of the Qualys TTM platform. Based on strong early engagement and positive feedback we're planning to build on this momentum by proactively identifying opportunities to extend [ Keflex ] to select customers and partners with a go-live date planned for later this year. And finally, as the federal government seeks to garnish greater efficiency and replace outdated and costly on-prem deployments from years past with modern cloud-native risk management solutions we are especially excited to host our third annual [ Pedro ] conference in Washington, D.C. towards the end of this month. We have made good progress growing our federal business and advancing our fed ramp high status with large federal agencies, and we continue to believe this market will fuel a new leg of growth for the company over time. In summary, we are pioneering a new category in pre-breach risk management by bringing autonomous exploit validation, risk quantification and zero-day remediation together within a single AI-driven risk fabric that redefines how enterprises operational as cyber risk. Complementing frontier model discover vulnerabilities. Our platform leverages proprietary domain data, real-time telemetry and deep operational context using sensors and agents behind the firewall to continuously discover assets, validate exposures, quantify risks, remediate threats and enforce company-specific policies, which are unavailable in the public domain. This is driven by our 2 decades of processing petrabytes of structured telemetry, combined with industry-leading threat intelligence in a closed-loop system that compounds across thousands of customer environment every day. printer models are powerful and accelerated back path analysis and triage. However, they need to be paired with a highly reliable control plane to consistently enforce accurate policy and compliance outcomes across live hybrid environments. This is where the unique value proposition for Qualys customers live, and it requires deterministic auditable, repeatable and trusted execution with effectively zero tolerance for error with attacks moving and machine speed and increasingly requiring defenses start to learn and respond in real-time closed-loop agents orchestration, driven policy and harness by flexible model choice act as a force multiplier further enabling precise risk quantification, safe remediation and even faster and more doministic outcomes at scale. For Qualys, this means our massive data context, LLM and SLM integration and trusted execution serve as the system of record for pre-beach cyber risk management and translate AI into a packaged Rock automation platform that delivers customers measurable risk reduction, zero-day remediation, government outcomes and immediate ROI. With that, I will turn the call over to Joo Mi to further discuss our first quarter results and outlook for the second quarter and full year 2026.