MAAT INDEX

CLAIM #65901 · Qualys Inc (QLYS) · 2025Q3 earnings call · Nov 4, 2025 · due Dec 31, 2026

For context, we anticipate ETM can yield up to a 100% increase for every $1 of VMDR, now that ETM also encompasses Cybersecurity Asset Management and additional ETM feature enhancements discussed earlier, along with third-party data ingestion.

Sumedh Thakar · CEO

PENDING
graded after results covering Dec 31, 2026 are reported

In context

Sumedh Thakar (CEO): Thank you, Blair, and welcome to our third quarter earnings call. As threat actors continue to swiftly exploit vulnerabilities, the future of cybersecurity is shifting from attack surface management to risk surface management through Agentic AI-driven proactive risk management that quantifies business impact and automates remediation. In this context, we have performed well in Q3, reflected by another strong quarter of revenue growth and profitability. Over the past few years, I've had the opportunity to speak with hundreds of CISOs, CIOs, and security leaders globally. A common theme from these discussions is the necessity to translate cyber risk management into business terms to ensure budget allocation aligns with business risk. CISOs seek a practical approach to consolidate tools when achievable and empower their teams to utilize the best solutions where appropriate. They desire a seamless integration of their security toolset into a centralized risk framework, allowing for the effective management of multiple risk vectors to accurately assess, communicate, and eventually mitigate the organization's risk exposure. The Risk Operations Center, ROC, powered by Qualys ETM, fulfills this need. At our recently held Risk Operations Conference in Houston, where we highlighted the business risk dialogue with a specialized CFO and Board track, our customers supported this strategy. The agenda expansion for ROCon resulted in a 20% increase in attendance compared to last year's QSC event. While traditional security operations centers work to identify breaches post-occurrence, Qualys is leading the creation of the first Agentic AI Risk Operations Center, ROC, which aims to centralize an organization's threat response before any business impact occurs. Utilizing our ETM solution, the ROC processes several petabytes of high-quality data daily, standardizes and correlates information from both Qualys and non-Qualys sources, and enables AI and humans to collaborate in real-time to detect and respond to threats at unprecedented speed. This initiative focuses not on generating more alerts but on taking actions that eliminate vulnerabilities before attackers can take advantage. In contrast to conventional continuous threat exposure management tools that merely highlight vulnerabilities without sufficient remediation capabilities, our unique ETM solution integrates CRQ, CTEM, and native remediation operations to rapidly address the most critical risks at scale. By aligning security and IT strategies with business priorities, we provide organizations with measurable proactive risk reductions that are valued by Boards and customers alike. Early adopters are already supporting the model as POCs transition to commercial deployments, highlighting both the significance of this opportunity and its similarities to the early stages of VMDR. We are committed to maintaining this momentum. Our R&D team is continuously generating innovations, expanding our platform, and positioning Qualys for wider upsell prospects. We are also integrating several established module capabilities into ETM, enabling organizations to utilize them across their entire attack surface. By making trillions of security risks from Qualys and third-party tools, like vulnerabilities, misconfigurations, and identities, accessible through our ETM solution, we are creating an advanced predictive platform. This leverages our Qualys TruRisk framework, TruLens threat management features, and a ready-to-operate Agentic AI workforce that autonomously manages risks from discovery to remediation, fully integrated with IT service management. This distinctive set of capabilities identifies emerging threats in real-time, compares threats with peers, evaluates organizational impacts, and quantifies risks in actionable, business-relevant terms. Consequently, security and IT teams can effectively prioritize tasks and address threats based on the organization’s risk linked to new vulnerabilities, focusing on specific industries, asset types, and identities. We believe these latest enhancements to our ETM solutions strengthen our position in the market, improve security operations, and significantly speed up results for our clients. Next in line for our ETM solution, I am particularly excited about a new groundbreaking feature, TruConfirm. This feature harnesses the power of our platform to validate whether vulnerabilities are exploitable before customers face a breach. Through automated large-scale validation, we eliminate uncertainty for customers by executing safe exploits on the network to confirm if attackers could succeed in their attempts, thus bridging the gap between theoretical and actual vulnerabilities. This method enables customers to concentrate on prioritizing only exploitable risks for the next step—automated remediation with TruRisk Eliminate. Our leading-edge capabilities are increasingly acknowledged by our customers, partners, and independent analysts. Notably, at Black Hat, Qualys won two Pwnie Awards for our significant contributions to threat research, driven by our strong expertise in threat intelligence and triage. Additionally, GigaOm recognized Qualys as the leader in Patch Management, a sector we pioneered, having deployed over 140 million patches in the last year alone. While some competitors are still beginning to embrace this strategy, Qualys has far surpassed traditional patching. TruRisk Eliminate addresses the unpatchable dilemma, allowing IT and security teams to automate various compensatory controls for patches that are too risky to implement or simply unavailable. As adversaries increasingly exploit vulnerabilities at rapid AI speeds, our suite of AI-driven automated remediation solutions has developed into a significant adoption layer, creating a unique competitive edge and opening new market avenues for Qualys. Moving on to our business update, we have seen a 5% increase in customers spending $500,000 or more with us, now totaling 211. Allow me to share a couple of recent successes that illustrate why organizations focused on centralizing cyber risk responses are partnering with Qualys to unify their security solutions, assess, and mitigate risks in their environments, strengthening their security operations. In Q3, a notable win involved a Global 700 customer that had initially only engaged Qualys for PCI scanning. Like many organizations, they were overwhelmed with fragmented data, manual processes, and disconnected tools. With minimal automation in place, their teams found themselves spending more time on documentation than on risk reduction, burdened by an influx of compliance audits. This customer opted for Qualys to transform disparate risk signals from code repositories, endpoints, identities, cloud containers, and network assets into an integrated real-time risk management solution by consolidating both Qualys and non-Qualys data. This included replacing their existing vulnerability management vendor and acquiring three additional Qualys modules, including ETM, to start operationalizing the Risk Operations Center with integrated third-party data, which resulted in a mid-six-figure annual upsell. By merging these data sources into the Qualys platform, we are providing this customer a vendor-neutral orchestration layer offering complete visibility of their risk and attack surfaces, centralized risk management and prioritization, and effective remediation, while facilitating operational efficiencies in security stack consolidation tailored to manageable risk parameters for the business. With our innovative technology, unprecedented platform effects, and commitment to minimizing risk and friction, this example highlights Qualys' ability to surpass outdated siloed solutions and strengthen our industry leadership. It also exemplifies our collaboration with preferred managed risk operation partners to activate the Risk Operations Center with new business opportunities. In the next phase, this customer is considering our TotalCloud native CNAPP solution and TruRisk Eliminate as they also integrate more third-party tools into the Qualys platform, representing a significant upsell opportunity. Further leveraging our managed risk operation partner ecosystem has led to a new six-figure deal with a major airline in the Middle East. This customer selected Qualys for our unified risk detection and remediation capabilities through TruRisk Eliminate. Nearly nine months after launching the ETM solution and witnessing over 28 POCs transition to commercial success, we've garnered valuable insights regarding ETM pricing and packaging. For context, we anticipate ETM can yield up to a 100% increase for every $1 of VMDR, now that ETM also encompasses Cybersecurity Asset Management and additional ETM feature enhancements discussed earlier, along with third-party data ingestion. Consequently, starting with our Q1 2026 earnings call, we will shift from reporting cybersecurity asset management long-term bookings to ETM customer penetration, as we believe ETM will become a crucial growth pillar for Qualys in the coming years. Regarding our federal business, we achieved a significant six-figure upsell with a large government agency. This customer had been utilizing multiple legacy and next-gen tools for a range of risk management needs across their security, IT, and DevOps teams. Alongside the complications of managing numerous point solutions, the government agency expressed frustrations with rising costs associated with traditional on-premise deployments, the inefficiencies of siloed systems, and drawn-out remediation processes. Facing a clear need to transition several monolithic workloads to micro applications across its hybrid environment using a FedRAMP high solution, this customer moved quickly to consolidate their security stack with over 17 Qualys modules, including VMDR, Cybersecurity Asset Management, TotalAppSec, TotalCloud, TruRisk Eliminate, and TotalAI. Currently, this customer benefits from a unified dashboard providing greater insight and automation than any competitive products they reviewed, taking full advantage of the agility and scalability of a cloud-native platform. Alongside a major seven-figure win at the state level, this highlights the strength and long-term growth potential we see in our federal, state, and local government business. Additionally, we are increasingly leveraging our partner ecosystem. In Q3, partner-led deal registrations rose, showcasing the effectiveness of our partner-first sales strategy. We have also certified nearly a dozen partners actively launching managed risk operation services, using ETM to enable centralized automated risk management before breaches occur. Momentum is building towards a global ROC alliance, and we anticipate certifying additional strategic partners in the forthcoming months who are dedicated to promoting Qualys as their managed risk operation partner of choice. Our flexible platform pricing model, Q-Flex, contributes to our platform growth efforts. We beta tested Q-Flex in Q3 to accelerate customer adoption of the Qualys Enterprise TruRisk platform. In less than a quarter post-introduction, we have seen notable customer interest and significant success. For instance, an existing Global 10 customer made a multi-year commitment under our Q-Flex program, boosting their annual bookings by over 50% while adding new modules to their subscription count with Qualys. This win demonstrates our growing proficiency in risk management, and we expect Q-Flex's contribution to continue increasing. In summary, our persistent innovation, early ROC deployments, strategic gains in federal markets, momentum in partner-led initiatives, and early adoption of Q-Flex collectively highlight Qualys' strength in integrating risk management workflows, easing operational complexities for customers, and tackling today's most demanding security challenges. We believe these accomplishments validate our ongoing investments and position Qualys as a trusted leader in pre-breach risk management, setting the foundation for lasting growth and long-term success. Now, I will hand over the call to Joo Mi to discuss our third-quarter results and outlook for the fourth quarter and the full year 2025.

Verify independently

SEC filings for QLYS · Claim quote is verbatim from the 2025Q3 earnings call.