Sumedh Thakar
Analyst · Canaccord
Thank you, Blair, and welcome to our second quarter earnings call. The adversary's playbook has been fundamentally rewritten by AI, collapsing exploit time lines and making one thing undeniably clear. Durable pre-breach risk management increasingly requires a vendor-neutral agentic AI fabric that moves beyond theoretical exposure to autonomous quantification of actual exploitable risk and remediation. Demonstrating this conviction, we delivered another quarter of strong revenue growth and profitability. The urgency behind that conviction continues to intensify. Frontier and open source AI models are capable of discovering and weaponizing vulnerabilities faster than any human team can triage them, compressing exploit time lines to hours and in some cases, turning disclosure into compromise before a patch even exists. AI is simultaneously becoming the greatest force multiplier and the most formidable challenge cybersecurity has ever faced. Where we part ways with the continuous threat exposure management, CTEM, solutions, is how we respond to it. CTEM solutions today respond by generating more findings, more theoretical risk scores and more dashboards and then pass along these findings off to siloed solutions that collect data and do the patching while losing critical time at every handoff. That approach was already failing before AI accelerated the threat landscape, and it is fundamentally inadequate now. We believe the defenders who win in this new era of AI will not be the ones who simply detect more and more vulnerabilities and produce dashboard tourism. They will be the ones who can autonomously detect vulnerabilities at AI speed, validate actual exploitability in production, quantify that risk in dollar terms, remediate it and then prove the exposure is closed in multi-vendor environments, all before an adversary gets there first. That is the design outcome of the AI-native risk operations powered by our Enterprise TruRisk Management, ETM, solution, and it is where nearly every customer conversation we are having is heading. Against this backdrop, I'm pleased to announce major new capabilities on the platform we will showcase at Black Hat later this week, spanning both AI for security and security for AI to address the post-Mythos threat landscape head on. First, with respect to AI for security, we're pleased to introduce InstaScan, powered by Agent Insta, the newest addition to our agentic AI marketplace and ETM solution for AI speed detection that is continuous, instantaneous and scanless. Today, when a new vulnerability advisory is released, it takes 24 hours to a week for organizations to detect it through traditional scan cycles, while adversaries weaponize the same vulnerability in minutes. Agent Insta is designed to collapse that time line. By converting the asset inventory, software patch and threat intelligence our customers already collect with Qualys sensors into high confidence exposure findings without a scan, new detections appear within minutes of disclosure and no rescan required and no agent disruption. The finding is then handed to Agent Val for instant exploit validation and the risk impact is determined and quantified immediately. While competitors are still processing an advisory writing signatures and waiting for a scan to complete, our customers already know whether they are exposed and are taking action before a vendor patch exists. Because the finding flows straight into validation and remediation, detection is not a report. It is the first step of a continuous closed loop. With last quarter's launch of TruConfirm and Agent Val safely validating actual exploitability across chained attack paths in live production environments and hyperprioritization using millions of findings to the fewer than 1% that require immediate action, the bottleneck is now shifting from identifying what to fix to actually fixing it before adversaries can act. This leads me to the next phase of our TruRisk Eliminate agenda, autonomous zero-day remediation at scale. Through AI scored autonomous remediation waves, the AI-native ROC now determines the right action for every asset in multi-vendor environment, deploying a patch [indiscernible], staging a control rolled out where caution is warranted or applying a compensatory control where operational risk demands it. Every action is gated by our AI-driven patch reliability score and resiliency snapshots, delivering rollback rates below 1.5%, below half of 1%. The most critical assets remain human-in-the-loop oversight while the platform autonomously remediates the rest. Orchestrating the cycle is Agent Sara, who prioritizes exploitable risk, quantifies it in dollar terms, sequence continuous waves and revalidates closure with Agent Val, all without proportional headcount. Furthermore, with the introduction of peer-to-peer patching, we are accelerating the delivery across distributed environments while removing the dependency on centralized infrastructure. Put simply, these newest innovations make autonomous zero-day remediation wave-driven vendor-agnostic, safe and provable. In live benchmarking, this collapsed the window of exposure from 21 days to minutes and auto patch 60% of the vulnerabilities. This is not incremental. It turns a massive surge in exploitable vulnerability volume from an impossible backlog into a continuously clear queue at the speed of modern attacks. You cannot solve a minutes problem with a month-long solution. And that's the gap the AI-native ROC was designed to solve with Agent Insta, providing AI speed detections, Agent Val hyperprioritizing validated exposures, and Agent Sara performing autonomous remediation in a continuous closed loop. Turning to security for AI. As enterprises raise AI workloads into production, the AI infrastructure they are building is already the next attack surface. With the introduction of TotalAI 2.0, organizations can now see their full AI estate from workforce to workload and from code to run time. Through new sensors that see AI activity at both the employee and workload level, security teams can now discover shadow AI activity across the organization, from what employees are doing with AI to which models, endpoints and services are running in production across hybrid multi-cloud environments. We have also extended our posture management coverage to SaaS platforms, including Anthropic and OpenAI to help organizations enforce security and compliance policies across the AI platforms their teams are already using. Additionally, they can now identify security gaps in code before deployment, remediate with guardrails at run time and test model context MCP tool exploits across over 50 adversarial scenarios. And of equal importance, every AI risk across the entire stack from GPU to infrastructure to supply chain to the newest prompt injection attacks is now scored and prioritized through the same true TruRisk that powers the risk operations center. For organizations seeking to secure the infrastructure, powering their AI future, these new innovations become an increasingly strong differentiator for Qualys. As ROC adoption accelerates and these capabilities continue to compound, we remain laser-focused on driving ETM adoption throughout our VMDR customer base and positioning Qualys for larger upsell opportunities over time. Moving to our business update with customers spending $500,000 or more with us growing 8% from a year ago to 229. Let me share a couple of recent wins, which illustrate why organizations are turning to Qualys to help unify their security stack and operationalize the ROC. The first is with an existing Global 300 customer managing a complex data-intensive environment spanning on-prem, multi-cloud and rapidly growing LLMs in production. As the volume and velocity of vulnerabilities across the environment accelerated, their teams recognized that prioritization based on theoretical risk scores couldn't deliver the business context needed to act decisively. With fragmented telemetry, disconnected tools and little automation, their teams were spending more time documenting risk than reducing it, while unpatched assets and shadow IT were silently extending exposure windows by months. As a result, the customer chose Qualys to operationalize their ROC, adopting VMDR, ETM, TruRisk Eliminate and TotalAI alongside several other modules in a low seven-figure QFlex annual upsell. By consolidating Qualys and third-party data into unified risk fabric, this customer has aligned risk reporting to the Board's tolerance level, shifted remediation from manual processes to autonomous workflows and reduced its exposure window from months to hours while flattening the hiring curve and delivering better security outcomes. This is also an outstanding example of how we are leveraging our channel partners to activate the ROC with new -- to win new business. The second is with a European health care company that has been a small existing scan on behalf of Qualys customer, but was relying on a managed service provider to run the broader vulnerability program across more than 140 locations. That model delivered people and process, but not autonomy. Scan operations prioritization and remediation guidance all flowed through the provider's team on the provider's time line, leaving the customer dependent on external resources to understand and act on its own risk. As this environment grew more complex and vulnerability volume surge, the limitation of that dependency became unsustainable. Costs for ballooning remediation cycles were [indiscernible], the customer had limited visibility into the very data driving the decisions made on its behalf. This customer chose Qualys consolidating its stack into the Qualys platform by adopting VMDR, ETM and TruRisk Eliminate in a six-figure QFlex upsell. ROC automation was the entry point and remediation was the immediate proof of value. By unifying detection prioritization and autonomous remediation into a single AI-native workflow, this customer has replaced a manual people and process dependency with a platform that delivers significantly lower cost, less complexity, full control and peace of mind for the CISO. These wins reflect the broader ETM momentum we are starting to see as more and more customers recognize the efficiencies and scale of AI-native ROC automation. Further supporting our growth trajectory, QFlex continues to gain traction as another strategic lever for accelerating ETM adoption. As we heard in the customer wins I described earlier, QFlex played a direct role in enabling significant upsells for Qualys by giving these customers the flexibility to commit broadly across the platform while preserving the ability to shift investments as their needs evolve. This precisely the value proposition of QFlex model was designed to deliver. Building on strong results from our initial rollout, we have now taken QFlex live for enterprise customers looking to expand with Qualys and believe it can become an increasingly important driver of platform expansion over time. Turning to our executive team. With the recent departure of our CISO and General Manager of our ETM business, I want to address how we are positioning for continuity and acceleration. To lead product strategy and our ETM business going forward, I have appointed Shailesh Athalye as our Chief Product Solutions Officer, a nearly 14-year Qualys veteran who has served as our SVP of Products for the last 5 years. Shailesh has been instrumental in shaping many of the platform innovations we discussed today, and his deep institutional knowledge of our technology, our customers and our road map makes him the natural leader to drive the next phase of ETM adoption and our customer-led growth strategy. Additionally, I'm pleased to welcome Nathan Smolenski as our new Chief Information Security Officer. Nathan is a seasoned cybersecurity executive with over 25 -- 24 years of experience driving security transformations across financial services, insurance and high-power -- high-growth SaaS environments, most recently serving as the global CISO at Cyera. We are excited to have both Shailesh and Nathan in these critical roles as we continue to scale our platform and accelerate ROC adoption. In summary, Qualys' continued innovation spanning both AI for security and security for AI, growing AI-native ROC adoption powered by our ETM solution, a growing federal pipeline for new business opportunities, strong partner-led execution and promising early QFlex engagement continue to reinforce the demand we're seeing for a unified risk management platform that autonomously moves beyond theoretical exposure to validated, quantified and remediated risk at the speed of modern attacks in multi-vendor environments. We believe these achievements not only advance our strong competitive differentiation, but also sharpen the market opportunity ahead of us and bolster our confidence in reaccelerating long-term growth in the business. With that, I will turn the call over to Joo Mi to further discuss our second quarter results and outlook for the third quarter and full year 2026.