Qualys, Inc. (QLYS) 2026 Q2 法說會逐字稿

完整原文

使用警語:中文譯文來源為 AI 翻譯,僅供參考,實際內容請以英文原文為主

  • Operator

    Operator

  • Ladies and gentlemen, thank you for standing by. Welcome to Qualys' second quarter 2026 investor call. (Operator Instructions) Please be advised that today's conference is being recorded.

    各位女士、先生,感謝您耐心等候。歡迎參加 Qualys 2026 會計年度第二季投資人電話會議。(接線員指示) 請注意,今天的會議將被錄音。

  • I would like now to turn the conference over to Blair King, Investor Relations. Please go ahead.

    現在我想將會議交給投資人關係部的 Blair King。請開始。

  • Blair King - Investor Relations

    Blair King - Investor Relations

  • Thank you, Michelle. Good afternoon, and welcome to Qualys' second quarter 2026 earnings call. Joining me today to discuss our results are Sumedh Thakar, our President and CEO; and Joo Mi Kim, our CFO. Before we get started, I would like to remind you that our remarks today will include forward-looking statements that generally relate to product capabilities, future events or future financial or operating performance. Actual results may differ materially from these statements.

    謝謝你,Michelle。各位下午好,歡迎參加 Qualys 2026 會計年度第二季財報電話會議。今天與我一同討論業績的有:我們的總裁暨執行長 Sumedh Thakar,以及我們的財務長 Joo Mi Kim。在開始之前,我想提醒各位,我們今天的發言將包含前瞻性陳述,通常涉及產品能力、未來事件或未來的財務或營運表現。實際結果可能與這些陳述有重大差異。

  • Factors that could cause results to differ materially are set forth in today's press release and our filings with the SEC, including our latest Form 10-Q and 10-K. Any forward-looking statements that we make on this call are based on assumptions as of today, and we undertake no obligation to update these statements as a result of new information or future events. During this call, we will present both GAAP and non-GAAP financial measures. A reconciliation of GAAP to non-GAAP measures is included in today's press release. And as a reminder, the press release, prepared remarks and investor presentation are all available on the Investor Relations section of our website.

    可能導致結果出現重大差異的因素,已載於今日新聞稿以及我們向美國證券交易委員會(SEC)提交的文件中,包括我們最新的 Form 10-Q 與 10-K。我們在本次電話會議中所做的任何前瞻性陳述,均基於截至今日的假設;因新資訊或未來事件而更新這些陳述,我們不承擔任何義務。在本次電話會議中,我們將同時呈現 GAAP 與非 GAAP 財務衡量指標。GAAP 與非 GAAP 指標之間的調節表已包含在今日新聞稿中。並提醒各位,新聞稿、事先準備的講稿與投資人簡報,皆可於我們網站的投資人關係專區取得。

  • With that, I'd like to turn the call over to Sumedh.

    接下來,我想把電話交給 Sumedh。

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Thank you, Blair, and welcome to our second quarter earnings call. The adversaries playbook has been fundamentally re-return by AI, collapsing exploit time lines and making one thing undeniably clear. Durable pre-breach risk management increasingly requires a vendor-neutral agentic AI fabric that moves beyond theoretical exposure to autonomous quantification of actual exploitable risk and remediation. Demonstrating this conviction, we delivered another quarter of strong revenue growth and profitability. The urgency behind that conviction continues to intensify.

    謝謝你,Blair,也歡迎各位參加我們的第二季財報電話會議。對手的攻擊手冊已被 AI 從根本上改寫,將漏洞利用的時間軸大幅壓縮,並讓一件事無可否認地清楚:要建立可長期維持的事前(pre-breach)風險管理,愈來愈需要一個供應商中立、具代理式(agentic)的 AI 架構(fabric),超越理論性的曝險,走向對實際可被利用風險與修復的自主量化。基於這項信念,我們再度交出一季強勁的營收成長與獲利表現。而支撐這項信念的急迫性仍在持續升高。

  • Frontier and open source AI models are capable of discovering and recognizing vulnerabilities faster than any human team can triage them, compressing exploit time lines to hours and in some cases, turning disclosure into compromise before a patch even exists. AI is simultaneously becoming the greatest force multiplier and the most formidable challenge cybersecurity has ever faced.

    前沿與開源 AI 模型能以遠快於任何人類團隊分流處理(triage)的速度發現並辨識弱點,將漏洞利用時間軸壓縮到數小時;在某些情況下,甚至在修補程式尚未出現之前,就可能從揭露直接演變為入侵。AI 同時正成為資安史上最大的力量倍增器,也是最嚴峻的挑戰。

  • Where we part ways with the continuous threat exposure management, CTEM solutions is how we respond to it. CTEM solutions today respond by generating more findings, more theoretical risk scores and more dashboards and then pass along these findings off to siloed solutions that collect data and do the patching while losing critical time at every handoff. That approach was already failing before AI accelerated the threat landscape, and it is fundamentally inadequate now.

    我們與持續性威脅曝險管理(CTEM)解決方案的分歧,在於我們如何回應這個現實。當今的 CTEM 解決方案通常以產生更多發現項目、更多理論性的風險分數與更多儀表板來回應,接著再把這些發現交給各自為政的孤島式解決方案去收集資料與進行修補,而每一次交接都會流失關鍵時間。在 AI 加速威脅態勢之前,這種做法就已經失靈;而現在更是根本不足以應對。

  • We believe the defenders who win in this new era of AI will not be the ones who simply detect more and more vulnerabilities and produce to dashboard TruRisk. They will be the ones who can autonomously detect vulnerabilities at AI speed, validate actual exploitability in production, quantify that risk in dollar terms remediated and then prove the exposure is closed in multi-vendor environments, all before an adversary gets there first.

    我們相信,在這個 AI 新時代能勝出的防禦者,不會是那些只是偵測到越來越多弱點、並在儀表板上產出 TruRisk 的人。他們將是能以 AI 速度自主偵測弱點、在生產環境中驗證實際可被利用性、以美元金額量化並修復該風險,並在多供應商環境中證明曝險已被關閉的人——而且要在對手搶先之前完成。

  • That is the design outcome of the AI-native risk operations that are powered by our Enterprise TruRisk Management, ETM solution and it is where nearly every customer conversation we are having is heading. Against this backdrop, I'm pleased to announce major new capabilities on the platform will showcase at Black Hat later this week, spanning both AI for security and security for AI to address the post Mythos credit landscape head on. First, with respect to AI for security, we're pleased to introduce InstaScan, powered by Agent Insta the newest addition to our agent AI marketplace and ETM solution for AI speed detection that is continuous instantaneous and scanless.

    這正是由我們的 Enterprise TruRisk Management(ETM)解決方案所驅動的 AI 原生風險營運(risk operations)之設計成果,也是我們幾乎每一場客戶對話所指向的方向。在此背景下,我很高興宣布:本週稍晚我們將在 Black Hat 展示平台上的多項重大新能力,涵蓋「以 AI 強化資安(AI for security)」與「為 AI 提供資安(security for AI)」,以正面迎戰後 Mythos 信用(credit)態勢。首先,就 AI for security 而言,我們很高興推出 InstaScan,由 Agent Insta 驅動——這是我們代理式 AI 市集與 ETM 解決方案中的最新成員,可實現 AI 速度的偵測:持續、即時、且免掃描(scanless)。

  • Today, when a new vulnerability advisory release, it takes 24 hours to one week for organizations to detect it through traditional scan cycles, while adversaries recognize the same vulnerability in minutes. Agent Insta is designed to collapse that time line. By converting the asset inventory software patch and threat intelligence, our customers already collect with Qualys sensors into high confidence exposure findings without a scan new detections appear within minutes of disclosure and no risk can require and no agent disruption.

    今天,當新的弱點公告發布時,組織透過傳統掃描週期偵測到它通常需要 24 小時到一週;而對手在幾分鐘內就能辨識同一個弱點。Agent Insta 的設計目的就是要壓縮這條時間軸。透過將我們客戶已使用 Qualys 感測器收集的資產盤點、軟體修補與威脅情報加以轉換,在不需掃描的情況下產生高信心的曝險發現;新的偵測可在揭露後數分鐘內出現,且不需要風險性變更,也不會造成代理程式干擾。

  • The finding is then handed to Agent Val for instant explore valuation and the risk impact is determined and quantified immediately. While competitors are still processing and advisory writing signatures and waiting for a scan to complete, our customers already know whether they are exposed and are taking action before a vendor patch exists.

    接著,該發現會交由 Agent Val 進行即時的可利用性評估(exploit valuation),並立即判定與量化風險影響。當競爭對手仍在處理公告、撰寫特徵碼並等待掃描完成時,我們的客戶已經知道自己是否曝險,並在供應商修補程式尚未出現之前就開始採取行動。

  • Because the finding flows straight into validation and remediation detection is not a report. It is the first step of a continuous closed loop with last quarter's launch of TruConfirm, an Agent Val, safely validating actual exploitability across chain attack paths in live production environment and hyper prioritizing millions of finding to the fewer than 1% that require immediate action. The bottleneck is now shifting from identifying what to fix to actually fix it before our diversities can act.

    由於該發現會直接流入驗證與修復流程,偵測不再只是報告。它是持續閉環的第一步;搭配我們上季推出的 TruConfirm(由 Agent Val 驅動),可在即時生產環境中安全驗證跨鏈式攻擊路徑的實際可利用性,並將數百萬筆發現超優先排序(hyper-prioritize)到需要立即處置的不到 1%。瓶頸正從「找出該修什麼」轉移到「在對手行動前真正把它修好」。

  • This leads me to the next phase of our TruRisk eliminate agenda, autonomous zero-day remediation at scale. Through AI scored autonomous remediation waves, the AI-native ROC now itemizes the right action for every asset in multi-vendor environments, deploying a patch, staging a control rolled out where caution is warranted or applying a completely control where operational risk demands it.

    這也引出我們 TruRisk 消除(eliminate)議程的下一階段:大規模自主零日修復。透過 AI 評分的自主修復波次(remediation waves),AI 原生 ROC 現在能在多供應商環境中,為每一項資產逐一列出正確動作:部署修補程式、在需要謹慎時分階段推出控制措施,或在營運風險要求時套用補償性控制。

  • Every action is gated by our AI-driven patch reliability score and resiliency snapshots, delivering rollback rates below 1.5%, below half of 1%. The most critical assets remain human in the loop oversight while the platform autonomously remediates the rest. Orchestrating the cycle is Agent Sara, who prioritize exportable risk, quantifies it in dollar terms, sequence continuous waves and revalidates closure with Agent Val, all without proportional headcount.

    每一項動作都會由我們 AI 驅動的修補可靠度分數與韌性快照(resiliency snapshots)把關,使回滾率低於 1.5%,甚至低於 0.5%。最關鍵的資產仍維持人員在迴路(human-in-the-loop)的監督,而平台則自主修復其餘部分。負責協調整個循環的是 Agent Sara:它會優先處理可被利用的風險、以美元金額量化、編排連續波次,並透過 Agent Val 重新驗證關閉狀態,全程不需要按比例增加人力編制。

  • Furthermore, with the introduction of peer-to-peer patching, we are accelerating the delivery across distributed environments while removing the dependency on centralized infrastructure. Put simply, these newest innovations make autonomous zero-day remediation wave-driven vendor-agnostic, safe and approvable.

    此外,隨著點對點(peer-to-peer)修補的導入,我們在分散式環境中加速交付,同時移除對集中式基礎設施的依賴。簡而言之,這些最新創新讓自主零日修復以波次驅動的方式,變得供應商無關、安全且可核准。

  • In live benchmarking, this collapsed the window of exposure from 21 days to minutes and auto patch 60% of the vulnerabilities. This is not incremental. It turns a massive surge in exploitable vulnerability volume from an impossible backlog into a continuously clear queue at the speed of modern attacks. You cannot solve a minute's problem with a month log solution. And that's the gap the AI native ROC was designed to solve with Agent Insta providing AI speed detections, Agent Val hyper prioritizing validated exposures, and Agent Sara that are performing autonomous remediation in a continuous close look.

    在即時基準測試中,這將曝險窗口從 21 天縮短到數分鐘,並自動修補 60% 的弱點。這不是漸進式改良。它把可被利用弱點數量的大幅激增,從不可能清理的積壓,轉變為能以現代攻擊速度持續清空的佇列。你無法用「一個月的待辦清單」去解決「一分鐘的問題」。而這正是 AI 原生 ROC 所要解決的落差:由 Agent Insta 提供 AI 速度偵測、Agent Val 對已驗證曝險進行超優先排序,以及 Agent Sara 在持續閉環中執行自主修復。

  • Turning to security for AI. As enterprises raise AI workloads and production, the AI infrastructure they are building is already the next attack surface. With the introduction of TotalAI 2.0, organizations can now see their full AI estate from workforce to workload and from code to run time through new sensors that see activity at both the employee and workload level security teams can now discover shadow wire activity across the organization from what employees are doing with AI to which models endpoints and services are running in production across hybrid multi-cloud environments.

    接著談 security for AI。隨著企業將 AI 工作負載提升並投入生產,他們正在建置的 AI 基礎設施已經成為下一個攻擊面。透過推出 TotalAI 2.0,組織如今可從員工到工作負載、從程式碼到執行階段,全面看見其 AI 資產版圖;藉由可在員工與工作負載層級觀測活動的新感測器,資安團隊現在能在整個組織中發現影子(shadow)使用活動——從員工如何使用 AI,到哪些模型、端點與服務正在混合式多雲環境的生產中運行。

  • We have also extended our partial management coverage to SaaS platforms, including Anthropic and OpenAI to help organizations enforce security and compliance policies across the AI platforms that teams are already using. Additionally, they can now identify security gaps in code before deployment remediate with the guardrails at runtime and test model context, MCP to exploits across over 50 adversary scenarios.

    我們也將部分管理覆蓋範圍延伸至 SaaS 平台,包括 Anthropic 與 OpenAI,以協助組織在團隊已在使用的 AI 平台上落實安全與合規政策。此外,他們現在也能在部署前識別程式碼中的安全缺口,並透過執行階段的防護欄(guardrails)進行補救,同時測試模型情境(context),以及 MCP 在超過 50 種對抗情境下的可被利用性。

  • And of equal importance, every AI risk across the entire stack from GPU to infrastructure to supply chain to the newest prompt injection attacks is not scored and prioritized through the same TruRisk engine that powers the Risk Operation Center. For organizations seeking to secure the infrastructure, powering the AR future, these new innovations become an increasingly strong differentiator for Qualys.

    同樣重要的是,從 GPU、基礎設施、供應鏈到最新的提示注入(prompt injection)攻擊,整個堆疊中的每一項 AI 風險,都會透過同一套為風險營運中心(Risk Operation Center)提供動力的 TruRisk 引擎進行評分與優先排序。對於希望保護支撐 AR 未來之基礎設施的組織而言,這些新創新正成為 Qualys 日益強勁的差異化優勢。

  • As ROC adoption accelerates and these capabilities continue to compound, we remain laser-focused on driving ETM adoption throughout our VMDR customer base and positioning Qualys for larger upsell opportunities over time. Moving to our business update with customers spending $50,000 or more with us growing 8% from one year ago to 229. Let me share a couple of recent wins, which illustrate why organizations are turning to Qualys to help unify their security stack and operationalize the ROC.

    隨著 ROC 採用加速、這些能力持續疊加,我們仍高度聚焦於推動 ETM 在我們 VMDR 客戶群中的採用,並隨時間推進為 Qualys 創造更大型的加購(upsell)機會。接著進入業務更新:與我們合作支出達 50,000 美元或以上的客戶數,較一年前成長 8% 至 229 家。我分享幾個近期的成功案例,說明為何組織正轉向 Qualys,以協助整合其安全技術堆疊並將 ROC 落地運作。

  • The first is with an existing Global 300 customer managing a complex data-intensive environment spanning on-prem, multi-cloud and rapidly growing LLM in production. As the volume and velocity of vulnerabilities across the environment accelerated their teams recognized that prioritization based on theoretical risk scores couldn't deliver the business context needed to act decisively with fragmented telemetry disconnected tools and little automation.

    第一個案例是一家既有的 Global 300 客戶,管理著跨越地端(on-prem)、多雲(multi-cloud)以及在生產環境中快速成長的 LLM 的複雜、資料密集型環境。隨著整體環境中的弱點數量與出現速度加快,他們的團隊意識到:僅依賴理論風險分數的優先排序,無法提供果斷行動所需的業務情境;再加上遙測資料零散、工具彼此脫節且自動化不足。

  • Their teams are spending more time documenting risk than reducing it, while unpack assets and shadow IT were silently extending exposure windows by one. As a result, the customer chose Qualys to operationalize their ROC, adopting VMDR ATM TruRisk Eliminate and total AI alongside several other modules in a low seven-figure QFlex annual upsell. My consolidating Qualys and third-party data into Unified Risk Fabric customer has aligned risk reporting to the board's tolerance level, shifted remediation from manual processes to autonomous workflows and reduce its exposure window from months to hours while flattening the hiring curve and delivering better security outcomes.

    他們的團隊花在記錄風險上的時間比降低風險還多,而未受管理的資產與影子 IT 也在不知不覺中延長了暴露窗口。因此,該客戶選擇 Qualys 來將其 ROC 落地運作,採用 VMDR、ATM、TruRisk Eliminate 與 TotalAI 等多個模組,並透過 QFlex 進行低七位數美元的年度加購。透過將 Qualys 與第三方資料整合至 Unified Risk Fabric,該客戶已將風險報告對齊董事會的容忍度門檻,將修補從人工流程轉為自主化工作流程,並把暴露窗口從數月縮短至數小時,同時放緩增聘人力的需求曲線並帶來更佳的安全成果。

  • This is also an outstanding example of how we are leveraging our channel partners to activate the ROC with new to win new business. The second is with a European health care company that has been all existing scan on behalf of Qualys customer but was relying on a managed service provider to run the broader vulnerability program across more than 140 locations. That model delivered people and process, but not autonomy. Scan operations prioritization and remediation guidance all flow through the providers team on the provider's time line, leaving the customer dependent on external resources to understand and act on its own risk. As this environment grew more complex and vulnerability volume serves the limitation of that dependency became unsustainable.

    這也是一個極佳的例子,展現我們如何運用通路夥伴來啟動 ROC,並贏得新的業務。第二個案例是一家歐洲醫療保健公司,先前一直是 Qualys 的既有掃描客戶,但其在超過 140 個據點的整體弱點管理計畫,仍仰賴受管服務供應商(MSP)來執行。該模式提供了人力與流程,但缺乏自主性。掃描作業、優先排序與修補建議都必須透過供應商團隊、依其時程推進,使客戶必須依賴外部資源才能理解並處置自身風險。隨著環境日益複雜、弱點量激增,這種依賴的限制變得難以為繼。

  • Cost for blowing remediation cycles for the customer had limited visibility into the very data driving the decisions made on its behalf. This customer chose Qualys consolidating its stack into the TruRisk platform by adopting VMDR ETM and TruRisk Eliminate in a 6-figure QFlex upsell. ROC automation was the entry point and remediation was the immediate proof for value. by unifying detection prioritization and autonomous remediation into a single AI-native workflow. This customer has replaced a manual people and process dependency with a platform that delivers significantly lower cost less complexity, full control and peace of mind or CISO.

    修補週期成本不斷攀升,且客戶對於驅動他人代其決策的關鍵資料能見度有限。該客戶選擇 Qualys,透過採用 VMDR、ETM 與 TruRisk Eliminate,將其技術堆疊整合至 TruRisk 平台,並以六位數美元的 QFlex 加購完成。ROC 自動化是切入點,而修補則是立即的價值驗證:把偵測、優先排序與自主修補整合為單一 AI 原生工作流程。該客戶已以平台取代對人工與流程的依賴,顯著降低成本、減少複雜度、取得完整控制權,並為 CISO 帶來安心。

  • These wins reflect the broader ETM momentum we are starting to see as more and more customers recognize the efficiencies and scale of AI-native ROC automation. Further supporting our growth trajectory, QFlex continues to gain traction as another strategic lever for accelerating ETM adoption. As we put in the customer wins I described earlier, QFlex played a direct role in enabling significant upsells for Qualys by giving these customers the flexibility to commit broadly across the platform, while preserving the ability to shift investments as their needs evolve.

    這些成功案例反映出我們開始看到更廣泛的 ETM 動能:越來越多客戶認知到 AI 原生 ROC 自動化所帶來的效率與規模化能力。進一步支撐我們的成長軌跡,QFlex 也持續獲得市場牽引,成為加速 ETM 採用的另一項策略槓桿。如同我先前提到的客戶勝利案例,QFlex 直接促成 Qualys 的顯著加購,讓客戶能以更大範圍承諾採用平台,同時保留隨需求演進而調整投資配置的彈性。

  • This precisely the value position of QFlex model was designed to deliver. Building on strong results from our initial rollout, we have now taken QFlex life for enterprise customers looking to expand with Qualys and believe it can become an increasingly important driver of platform expansion over time.

    這正是 QFlex 模式所設計要交付的價值主張。在初期推行取得強勁成果的基礎上,我們現已將 QFlex 正式上線(live)提供給希望擴大採用 Qualys 的企業客戶,並相信它將隨時間推進成為平台擴張日益重要的驅動力。

  • Turning to our executive team. With the recent departure of our CEO and General Manager of our ETM business, I want to address how we are positioning for continuity and acceleration to lead product strategy and our ETM business going forward I have appointed Shailesh Athalye as our Chief Product Solutions Officer, a nearly 14-year Qualys veteran who has served as our SVP of Products for the last five years.

    接著談我們的高階管理團隊。隨著近期我們 ETM 業務的 CEO 與總經理離任,我想說明我們如何在未來定位以確保延續性並加速前進:為了領導產品策略與 ETM 業務,我已任命在 Qualys 服務近 14 年、過去五年擔任產品資深副總裁(SVP of Products)的 Shailesh Athalye 出任首席產品解決方案長(Chief Product Solutions Officer)。

  • Shailesh was instrumental in shaping many of the platform innovations we discussed today. and his deep institutional knowledge of our technology, our customers and our road map makes him the natural leader to drive the next phase of ETM adoption and our customer-led growth strategy. Additionally, I'm pleased to welcome Nathan Smolenski as our new Chief Information Security Officer.

    Shailesh 在塑造我們今天討論的多項平台創新上扮演關鍵角色;他對我們技術、客戶與產品路線圖的深厚內部知識,使他成為推動下一階段 ETM 採用與以客戶為導向成長策略的自然領導者。此外,我也很高興歡迎 Nathan Smolenski 加入,擔任我們新的首席資訊安全長(CISO)。

  • Nathan is a seasoned cybersecurity executive with over 24 years of experience driving security transformations across financial services, insurance and high-power high-growth SaaS environments, most recently serving as the global CISO at Cyera. We are excited to have both Shailesh and Nathan in these critical roles as we continue to scale our platform and accelerate ROC adoption.

    Nathan 是資深資安高階主管,擁有超過 24 年經驗,曾在金融服務、保險以及高強度、高成長的 SaaS 環境中推動安全轉型;最近一職為 Cyera 的全球 CISO。我們很高興 Shailesh 與 Nathan 在這些關鍵職務上加入,協助我們持續擴大平台規模並加速 ROC 採用。

  • In summary, Qualys continued innovation spanning both AI for security and security for growing AI-native ROC adoption powered by our ETM solution, a growing federal pipeline for new business opportunities, strong partner-led execution and promising early QFlex engagement continue to reinforce the demand we're seeing for a unified risk management platform that honestly moves beyond theoretical exposure to validated, quantified and remediated risk at the speed of modern attacks in multi-vendor environments.

    總結而言,Qualys 持續創新,涵蓋「用 AI 強化安全」以及「為 AI 提供安全」,並由我們的 ETM 解決方案驅動 AI 原生 ROC 採用的成長;同時,聯邦市場的新商機管線持續擴大、夥伴主導的執行力強勁,以及 QFlex 早期互動展現的良好前景,都持續強化市場對統一風險管理平台的需求——該平台能在多供應商環境中,以現代攻擊的速度,將風險從理論暴露推進到已驗證、可量化且可修補的風險。

  • We believe these achievements not only advance our strong competitive differentiation, but also sharpen the market opportunity ahead of us and bolster our confidence in reaccelerating long-term growth in the business.

    我們相信,這些成果不僅推進了我們強勁的競爭差異化,也進一步凸顯我們面前的市場機會,並增強我們對於推動業務長期成長重新加速的信心。

  • With that, I will turn the call over to Joo Mi to further discuss our second quarter results and outlook for the third quarter and full year 2026.

    接下來,我將把電話會議交給 Joo Mi,進一步說明我們第二季的業績與第三季及 2026 全年的展望。

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Thanks, Sumedh. Good afternoon. Before I start, I'd like to note that except for revenue, all financial figures are non-GAAP and growth rates are based on comparisons to the prior year period unless stated otherwise. Turning to second quarter results. revenues grew 11% to $182.2 million as a result of a strategic emphasis on leveraging our partner ecosystem to drive growth.

    謝謝,Sumedh。各位下午好。在開始之前,我想先說明:除營收外,所有財務數字皆為非 GAAP;且除非另有說明,成長率皆以與去年同期比較為基礎。接著看第二季業績:在策略性強調運用我們的夥伴生態系以推動成長之下,營收成長 11% 至 1.822 億美元。

  • The channel continued to increase its contribution, making up 54% of total revenues compared to 49% a year ago. Revenues from channel partners grew 22% with revenues from direct remaining largely unchanged from Q2 of last year. IGO, 15% growth outside the US was ahead of our domestic business, which grew 8%. The US and international revenue mix was 55% and 45%, respectively.

    通路持續提高其貢獻度,占總營收 54%,高於一年前的 49%。通路夥伴營收成長 22%,而直銷營收相較去年第二季大致持平。美國以外地區的成長為 15%,高於我們國內業務的 8% 成長。美國與國際營收占比分別為 55% 與 45%。

  • In Q2, overall upsell execution improved with our net dollar expansion rate at 105%, up from 104% last quarter. The net dollar expansion made of customers with prior year purchase of ETM or CTEM subscriptions in Q2 was 107%, consistent to last quarter. Moving on to product mix. Our differentiated new products continue to drive growth.

    在第二季,整體加購執行有所改善,淨美元擴張率(net dollar expansion rate)為 105%,高於上季的 104%。第二季中,前一年購買 ETM 或 CTEM 訂閱的客戶所帶來的淨美元擴張率為 107%,與上季一致。接著看產品組合。我們具差異化的新產品持續帶動成長。

  • First, ETM CSAM combined made up 12% of total bookings and 14% of new bookings on an LTM basis in Q2. We up from last year's 9% and 10%, respectively. Next, Patch Management made up 9% of total bookings and 16% of new bookings on an LTM basis in Q2. This compares to 7% and 16%, respectively, in Q2 of last year. Lastly, TotalCloud made up 5% of total LTM bookings in Q2, unchanged from a year ago.

    首先,ETM 與 CSAM 合計在第二季以 LTM(過去十二個月)基礎計,占總訂單金額的 12%,占新增訂單的 14%。相較去年分別為 9% 與 10%,我們有所提升。其次,修補程式管理(Patch Management)在第二季以 LTM 基礎計,占總訂單金額的 9%,占新增訂單的 16%。這與去年第二季分別為 7% 與 16% 相比。最後,TotalCloud 在第二季占 LTM 總訂單金額的 5%,與一年前持平。

  • We believe that these differentiated products, combined with increased contribution to bookings in 2026, given our opportunity to increase market share and maximize share of wallet. Reflecting our scalable and sustainable business model adjusted EBITDA for the second quarter of 2026 was $83.8 million, representing a 46% margin compared to 45% last year.

    我們相信,這些具差異化的產品,加上在 2026 年對訂單貢獻的提升,鑑於我們有機會提高市占並最大化客戶錢包份額(share of wallet)。反映我們可擴展且可持續的商業模式,2026 年第二季調整後 EBITDA 為 8,380 萬美元,利潤率為 46%,相較去年為 45%。

  • Operating expenses in Q2 increased by 8% to $73.2 million, driven by investments in sales and marketing, which grew 14%. With the strong performance, EPS for the second quarter 2026 was $1.98 per diluted share and our free cash flow was $55.9 million, representing a 31% margin compared to 20% in the prior year due to fluctuations in working capital. Normalizing for this first half of 2026 margin was 42% compared to 43% in the prior year.

    第二季營業費用增加 8% 至 7,320 萬美元,主要由銷售與行銷投資帶動,該項費用成長 14%。在強勁表現下,2026 年第二季稀釋後每股盈餘(EPS)為每股 1.98 美元,自由現金流為 5,590 萬美元,利潤率為 31%,相較前一年為 20%,主要因營運資金波動所致。若將此因素正常化,2026 年上半年利潤率為 42%,相較前一年為 43%。

  • In Q2, we continue to invest the cash we generated from operations back into Qualys, including $3.7 million in capital expenditures and $76.8 million to repurchase of our $797,000 outstanding shares. As of the end of the quarter, we had $229.8 million remaining in our share repurchase program. With that let us turn to guidance, starting with revenue. For the full year 2026, we now expect revenues to be in the range of $732 million to $738 million, which represents a growth rate of 9% to 10%. This compares to prior guidance of $721 million to $727 million.

    第二季,我們持續將營運所產生的現金再投資於 Qualys,包括 370 萬美元的資本支出,以及 7,680 萬美元用於回購我們 797,000 股流通在外股份。截至季末,我們的股票回購計畫尚餘 2.298 億美元額度。接下來我們轉向財測指引,先從營收開始。2026 全年,我們目前預期營收將落在 7.32 億至 7.38 億美元區間,代表 9% 至 10% 的成長率。這與先前指引的 7.21 億至 7.27 億美元相比有所上調。

  • For the third quarter of 2026, we expect revenues to be in the range of $185.5 million to $187.5 million, representing a growth rate of 9% to 10%. This guidance assumes our net dollar expansion rate remains at current levels with moderate growth contribution from new business in 2026. Shifting to profitability guidance for the full year 2026, we expect EBITDA margin to be in the mid-40s with a low teens increase in operating expenses and free cash flow in the low 40s. We expect full year EPS to be in the range of $7.74 to $7.88, up from the prior range of $7.44 to $7.65. For the third quarter of 2026, we expect EPS to be in the range of $1.91 to $1.98.

    2026 年第三季,我們預期營收將落在 1.855 億至 1.875 億美元區間,代表 9% 至 10% 的成長率。此指引假設我們的淨美元擴張率維持在目前水準,且 2026 年新業務對成長的貢獻為溫和增長。轉向 2026 全年獲利能力指引,我們預期 EBITDA 利潤率在 40% 中段,營業費用增幅為低十位數百分比,自由現金流利潤率在 40% 初段。我們預期全年 EPS 將落在 7.74 至 7.88 美元區間,高於先前的 7.44 至 7.65 美元區間。2026 年第三季,我們預期 EPS 將落在 1.91 至 1.98 美元區間。

  • Our planned capital expenditures in 2026 are expected to be in the range of $8 million to $12 million, and for the third quarter of 2026 in the range of $1 million to $2.5 million.

    我們規劃的 2026 年資本支出預期將落在 800 萬至 1,200 萬美元區間;2026 年第三季則預期在 100 萬至 250 萬美元區間。

  • With that, Sumedh, I would be happy to answer any of your questions.

    以上,Sumedh,我很樂意回答你的任何問題。

  • Operator

    Operator

  • (Operator Instructions)

    (接線員指示)

  • Kingsley Crane, Canaccord.

    Kingsley Crane,Canaccord。

  • Kingsley Crane - Analyst

    Kingsley Crane - Analyst

  • Congrats on amazing results. Sumedh, the volume of AI-generated vulnerabilities, it's a clear reason why customers need InstaScan in the ROC. Can you just double-click again on how this is showing up in pipeline, how this is showing up in urgency? And then if CBE volumes were to double again, how could you capture that in your asset pricing models?

    恭喜取得驚人的成果。Sumedh,AI 生成的弱點數量,顯然是客戶在 ROC(風險營運中心)需要 InstaScan 的原因之一。你能否再深入說明一下,這在銷售管線中如何呈現、在緊迫性上如何呈現?另外,如果 CBE 的量再翻倍,你們要如何在資產定價模型中捕捉這一點?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Yeah, that's a great question. And I think even though the disclosure findings are increasing, I think the organization's ability to remediate is what is currently being looked at it, and that's really where our focus has been on helping these customers with autonomous remediation because at a very high level, you cannot go and tell your management as a security leader that you're going to respond to autonomous AI exploits with more manual tools that are e-mailing each other and what need to be fixed, et cetera.

    是的,這是個很好的問題。我認為即使揭露的發現(findings)在增加,目前大家更關注的是組織的修復能力;而我們的重點一直是透過自主修復來協助客戶。因為從高層次來看,作為資安主管,你不可能去跟管理層說:你要用更多人工工具、彼此用電子郵件往來、告訴對方要修什麼等等,來回應自主式 AI 攻擊。

  • And so if you look at sort of the risk operation center and what we are focused on is Agent Sara is already helping with the autonomous remediation piece. But to do a great job with that and with high confidence, you need to significantly hyper prioritized findings, and that's where Agent Val on the risk operation center platform is helping run actual exploits to reduce the number of findings that need to be auto remediated that actually matter to the business.

    因此,如果你看風險營運中心(risk operation center)以及我們的重點,Agent Sara 已經在協助自主修復這一塊。但要把這件事做得很好、且具高度信心,你需要大幅度地進行超優先排序(hyper prioritized)各項發現;這正是風險營運中心平台上的 Agent Val 所在做的:執行實際攻擊利用(exploits),以降低需要自動修復、且真正對業務重要的發現數量。

  • And then now our latest announcement yesterday of Agent Insta, which is the ability to scan instantaneously whenever new advisory comes out now shrinks the time line from the advisory coming to the time line when the advisory -- the vulnerability went detected in the customer environment. And so with all three of these on the ETM platform, you now actually have a real path to get something that is important and exploitable in your business, remediated within the first 24 hours with minimal human intervention.

    接著,我們昨天最新宣布的 Agent Insta,具備在每當新的安全公告(advisory)發布時即可即時掃描的能力,現在能把從公告發布到在客戶環境中偵測到該弱點的時間軸大幅縮短。因此,當這三者都在 ETM 平台上時,你就真正有一條路徑,能在最少人為介入下,於前 24 小時內把對你業務重要且可被利用的問題完成修復。

  • And that is the conversation that everybody is having is that they need to go have conversations internally to say how are we going to move towards a road map that allows us a feasible autonomous remediation plan and the ETM is enabling that.

    而大家正在討論的就是:他們需要在內部展開對話,去說明要如何朝向一個可行的自主修復計畫路線圖前進,而 ETM 正在促成這件事。

  • And so we have been ahead of this, as you know, for the last few years with creating autonomous emulation capabilities. And so we already had a few customers in the pipeline who were discussing with this. We saw this beforehand. And so the conversation with post-Mythos is helping -- helped us accelerate a couple of these opportunities. However, there's a large number of customers that are very, very curious now about what they are -- what they can do and what is the art of the possible with this kind of autonomous remediation.

    因此,如你所知,過去幾年我們在這方面一直走在前面,打造自主模擬(autonomous emulation)能力。所以我們在管線中已經有一些客戶在討論這件事。我們之前就看到了這個趨勢。因此,Mythos 之後的對話正在幫助——也確實幫助我們加速了其中幾個機會。不過,現在有大量客戶對於他們能做什麼、以及這種自主修復能達到的可能性邊界(art of the possible)感到非常、非常好奇。

  • And so we're very excited to see that pipeline in terms of the conversations in terms of POCs is looking good, and we're happy with that. And of course, we have to move forward, get the POCs done look at the budgets when they were closed, et cetera. But I would say with all the innovation and the investment that we have made, we're pretty excited to see the current conversations that were happening.

    所以我們很興奮看到,無論是對話的熱度或是 POC(概念驗證)的推進,管線看起來都不錯,我們也對此感到滿意。當然,我們還需要繼續往前推進,把 POC 做完、在結案時檢視預算等等。但我會說,以我們所做的所有創新與投資而言,我們對目前正在進行的對話感到相當振奮。

  • Kingsley Crane - Analyst

    Kingsley Crane - Analyst

  • Great. And then just a follow-up for either Sumedh or Joo Mi, building off of that, billings grew 16%. It was a really sizable race. On top of a broad-based beat. We're now talking about reaccelerating long-term growth. Is it that the conviction in the business hasn't changed and the market has come towards you this quarter? Or just could you help us understand just how much more bullish you are on the business today than you were three months ago?

    很好。接著想追問 Sumedh 或 Joo Mi:在此基礎上,帳單金額(billings)成長了 16%。這是相當顯著的加速。而且是在全面超預期之上。我們現在在談長期成長重新加速。是因為你們對業務的信心其實沒有改變,而市場在本季向你們靠攏?或者你能否幫我們理解,相較三個月前,你們今天對業務的看多程度究竟提高了多少?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Look, I think we always sort of were ahead of this with remediation, et cetera. And so the conviction that this is what that the market is going to need and the investments that we put in before that has always been there. I think right now, with the advent of AI, it's just accelerated what we are sort of being seeing was going to happen at some point.

    你看,我認為我們在修復等方面一直都算是走在前面。因此,對於市場將需要什麼、以及我們事前投入的投資,這份信念一直都在。我認為現在,隨著 AI 的出現,只是加速了我們先前所看到、遲早會發生的事情。

  • And so that's sort of driving -- the conversations are driving us to feel like because of the investment we put in the platform, these are solutions that actually can help customers right now in what they are looking for to set up as auto remediation capabilities for the future. So I mean, I will say that a lot of that goes to us being able to see where the industry is going to go and putting the investment behind it and now positive conversations with the customers are kind of helping us get through to ensuring that we can actually work through to see how these opportunities can close.

    因此,這某種程度上正在推動——這些對話正驅使我們覺得,因為我們在平台上投入了投資,這些解決方案其實能在客戶目前所尋找的方向上立即提供協助,並為未來建立自動化修復能力。所以我的意思是,我會說其中很大一部分在於我們能看見產業將往哪裡走,並在其背後投入資源;而現在與客戶的正向對話也在某種程度上幫助我們推進,確保我們確實能把這些機會一路推動到最終成交。

  • Operator

    Operator

  • Jonathan Ho, William Blair.

    Jonathan Ho,William Blair。

  • Jonathan Ho - Analyst

    Jonathan Ho - Analyst

  • Congratulations on the strong quarter. I wanted to understand a little bit better. When you talk to your customers about sort of the change in the exposure risk management process, can you maybe help us understand how much of this is that they need to cover more assets versus the fundamental patch management process changing versus having sort of the ROC part of this on the managed side. Can you just maybe unpack that for us a little bit in terms of what they're buying and also what they intend to buy over time.

    恭喜本季表現強勁。我想更深入了解一點。當你們和客戶談到曝險風險管理流程的變化時,能否幫我們理解:其中有多少是因為他們需要涵蓋更多資產,多少是因為基礎的修補程式管理流程正在改變,或是其中有一部分是把這個 ROC 的部分放在託管端來做。你能否就他們現在在買什麼、以及隨時間推移他們打算買什麼,幫我們稍微拆解說明一下?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Great question. I think at the end, what they are focusing on is can I remediate the thing that actually matters to my environment as fast as possible, right? And that includes all assets in their environment, but that doesn't necessarily mean that they don't have other products that might be helping them get some visibility through acquisitions, this and that. And I think that's why if you look at our strategy around ETM and what we have done with the concept of a ROC is that the ROC is a multi-vendor solution. So it gives us the ability for the customers who are leveraging Qualys to have capabilities like InstaScan, where we can instantaneously detect things.

    好問題。我認為歸根結底,他們關注的是:我能否以最快速度修復對我的環境真正重要的問題,對吧?這包含他們環境中的所有資產,但這不一定表示他們沒有其他產品——可能透過併購等等——在幫他們取得一些可視性。我想這也是為什麼,如果你看我們圍繞 ETM 的策略,以及我們在 ROC 概念上所做的事情,ROC 是一個多廠商(multi-vendor)的解決方案。因此,它讓使用 Qualys 的客戶能具備像 InstaScan 這樣的能力,我們可以即時偵測問題。

  • We could do the same on data collecting from other scan-only products that are just throwing a bunch of CVs. So we are seeing with ETM that it is allowing us to expand the licenses in the early POCs that we have with some of these customers and early purchases, they are also bringing data on other tools from outside of Qualys into the ETM solutions, so that they can get a holistic view across multiple tools and prioritize the ones that really matter, run the exploits and then get to the remediation piece.

    我們也可以對其他僅掃描(scan-only)的產品所收集的資料做同樣的事,那些產品只是丟出一堆 CV。因此我們看到,透過 ETM,在與部分客戶進行早期 POC 以及早期採購時,它讓我們得以擴大授權數;同時,他們也把 Qualys 以外、來自其他工具的資料帶入 ETM 解決方案,讓他們能跨多種工具取得整體視角,並優先處理真正重要的項目、執行 exploit,然後進入修復環節。

  • So I think it's the focus on adding on the Patch Management elemented capabilities is one aspect. And then with ETM broadening the coverage of -- with how many assets that they should look at to make sure the remediation succeeds is helping us that even if they have some other scan-only CBI detection tool, which is producing a lot of false positives, we can all still bring that license as part of the Qualys team solution.

    所以我認為,聚焦於加入 Patch Management 的能力是一個面向。另外,ETM 也在擴大覆蓋範圍——就他們應該檢視多少資產以確保修復成功而言——這也在幫助我們:即便他們有其他僅掃描的 CBI 偵測工具,而那個工具產生大量誤報,我們仍然可以把那個授權納入 Qualys 的整體解決方案中。

  • Jonathan Ho - Analyst

    Jonathan Ho - Analyst

  • Excellent. And just given the relative proximity of Mythos, when do you think the bulk of the spending will start to materialize? I'm guessing we haven't seen it yet. I just wanted to get your sense for how you think this is developing with the pipeline.

    很好。另外,考量到 Mythos 發生的時間相對接近,你認為大部分支出何時會開始反映出來?我猜我們還沒看到。我只是想聽聽你對這在管線中如何發展的看法。

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Yeah. I think we -- it's the same that we had talked about when Log4j came out and solar winds stuff. Look, our customers typically tend to be enterprises organizations that are more thinking of long-term changes in their security programs and less about the new jerk reaction of immediate spending, and that's kind of what we're seeing right now as well a lot of these conversations are CISOs looking at the ways to use this post-Mythos threat landscape to make the point to the team's internal stakeholders on long-term sustainable changes that they can make to their security program, where it's not that -- you do this one thing for the one month.

    是的。我想我們——這和我們在 Log4j 出來以及 SolarWinds 事件時談到的是一樣的。你看,我們的客戶通常是企業型組織,他們更傾向於思考其資安計畫的長期變革,而不是對新事件的短期、立刻的衝動式支出;而這也正是我們現在看到的情況。很多這類對話都是 CISO 在思考如何利用 Mythos 之後的威脅態勢,向團隊內部的利害關係人說明:他們可以對資安計畫做出長期且可持續的改變,而不是——你只為了某一個月做某一件事。

  • For companies to roll out a program that allows them to do autonomous remediation, that's where they need to think through work with different stakeholders and then look at the budget. Does it come from an existing solution that they can get rid of? Does this is something that they need to add on, et cetera. So I think we are early on. We feel like in these conversations, and we will see at the next few quarter goes to see what meaningful signals come in terms of when these budgets might be leverage otherwise. But so far, right now, it's a lot more of positive conversations and pipeline building.

    要讓公司推行一個能夠進行自主修復(autonomous remediation)的計畫,他們需要與不同的利害關係人一起把事情想清楚,然後再看預算。這筆預算是來自他們可以淘汰的既有解決方案嗎?還是這是他們需要額外新增的項目,等等。所以我認為我們還在早期。我們覺得在這些對話中,我們會在接下來幾個季度觀察,看看有哪些有意義的訊號,能反映這些預算何時可能被動用或重新配置。但到目前為止,現在更多是正向對話與管線建立。

  • Operator

    Operator

  • Patrick Colville, Scotiabank.

    Patrick Colville,Scotiabank。

  • Patrick Colville - Equity Analyst

    Patrick Colville - Equity Analyst

  • I guess, let me just ask Sumedh a question first, and then Joo Mi, I'd like to ask you one if possible. Great to see guide to fiscal year guide being raised from 8% to 10%. And then in your prepared remarks, talking about re-exciting growth in the long term. I guess, as one question is like, I think that's new disclosure, I don't think you've said that before. Can you just clarify that, that is new? And then what gives you confidence, if it is new to say that now? Is it stuff you're seeing or just conversations or just kind of help provide some color on that?

    我想先問 Sumedh 一個問題,然後如果可以的話,Joo Mi 我也想問你一個。很高興看到你們把財年的指引從 8% 上調到 10%。另外在你們的事先準備發言中,提到長期重新加速成長。我想,這算是一個問題:我覺得這是新的揭露,我不認為你們以前說過。你能否澄清一下,這是新的嗎?如果是新的,你們現在這樣說的信心來源是什麼?是你們看到的現象、或只是對話,或能否提供一些背景說明?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Yeah. I wouldn't say it's new, Patrick. I think we always talked about investing and innovating in the platform and our belief that what we're doing and helping with the focus on remediation is something that we've been working on strategically along with a focus on federal and along with focus on working with our partners to focus on that acceleration of growth in the long term, getting into long-term double-digit growth has been a focus for us.

    是的。我不會說這是新的,Patrick。我想我們一直都在談對平台的投資與創新,以及我們相信我們正在做的事情——協助把重點放在修復——是我們一直在策略性推動的方向;同時也聚焦於聯邦市場,並與合作夥伴合作,著眼於長期的成長加速。回到長期的雙位數成長一直是我們的重點。

  • So I think that is not new, so to say. I would say that given the current conversations that are happening, it just gives us an opportunity, again, to talk about what we've already built and the innovations that we have already done and see how this maps to the current focus that market has in terms of -- look, at the end of the day, the CISOs to be able to go tell their Board and management somehow that they're going to adopt some form of autonomous remediation.

    所以我認為這並不算新。我會說,鑑於目前正在發生的對話,這只是再次給我們一個機會,去談我們已經打造的東西與已經完成的創新,並看看這如何對應到市場當前的關注點——你看,歸根結底,CISO 必須能以某種方式向董事會與管理層說明,他們將採用某種形式的自主修復。

  • And so they're going to have to figure out how they will do that. And if you look in the market, with Qualys having 150 million patches developed in the last 12 months, 40 million of those already being deployed autonomously that gives us an interesting conversation point to build confidence for them when they're looking at these things. And so right now, it's the same sort of what we have always talked about and focused on is working towards innovating and investing to create long-term growth and double-digit revenue growth is what we have always been looking at. And so this is just continuing on that momentum.

    因此他們必須想清楚要如何做到。而如果你看市場面,Qualys 在過去 12 個月開發了 1.5 億個修補程式,其中 4,000 萬個已經以自主方式部署,這給了我們一個很有意思的對話切入點,能在他們評估這些事情時建立信心。所以現在,這仍然是我們一直以來談論並聚焦的方向:透過創新與投資來創造長期成長,而雙位數的營收成長一直是我們追求的目標。因此這只是延續那股動能。

  • Patrick Colville - Equity Analyst

    Patrick Colville - Equity Analyst

  • Okay. Very helpful, Sumedh. And Joo Mi, if I may, the disclosure about new bookings, so 14% of new bookings were from ETM and CSAM, which if my model is correct, that's the same as last quarter. And then 15% of new bookings from patch in 2Q. Again, if my model is correct, that's the same as last quarter. So I guess, totally on hand or the kind of quality of the commentary around ETM and patch, shouldn't -- like how come is not starting up more clearly in that new booking number? And should we expect that portion of new bookings to ETM and CSAM and patch to increase as we look towards kind of 3Q and 4Q?

    好的。非常有幫助,Sumedh。另外 Joo Mi,如果可以的話,關於新訂單(new bookings)的揭露:ETM 和 CSAM 佔新訂單的 14%,如果我的模型沒錯,這和上季一樣。而第二季 patch 佔新訂單的 15%。同樣地,如果我的模型沒錯,這也和上季一樣。所以我想,整體而言,基於你們對 ETM 和 patch 的評論品質,為什麼在新訂單數字上沒有更明顯地開始上升?而當我們展望第三季與第四季時,是否應該預期 ETM、CSAM 與 patch 在新訂單中的占比會提高?

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Yeah. In terms of the percent contribution to bookings from your customers, you do anticipate fluctuations. We're not too surprised whether it goes up or down. So if you take a look at the percentage that made from patch management, last quarter was 15%, this quarter 16%. You're right, on the ETM side, our ETM CSAM it's 14% same as last quarter.

    是的。就來自客戶對預訂(bookings)的百分比貢獻而言,您確實預期會有波動。無論上升或下降,我們都不會太意外。所以如果您看一下來自修補程式管理(Patch Management)的占比,上季是15%,本季是16%。您說得對,在ETM方面,我們的ETM CSAM是14%,與上季相同。

  • We're not too surprised by it because they really depends more on the customers we're onboarding at that point in time what they end up starting off way. So for example, if we have a new prospect that decide to purchase more of that or spend more of that budget on MDR or versus ETM versus Patch Management. We want to make sure that the customer is set up to succeed and grow with us.

    我們不會太意外,因為這更取決於我們在那個時間點正在導入(onboarding)的客戶,以及他們最終一開始採用的方式。例如,如果我們有一個新潛在客戶決定購買更多,或把更多預算花在MDR,而不是ETM或修補程式管理。我們希望確保客戶能夠成功落地,並與我們一起成長。

  • And so this percentage, it's a healthy percentage what it lends itself to -- for us it's really a validation that when we land new logos, go after the market when we're able to win, it's partly due to the fact that we were able to innovate and lead the market in terms of our continuous enhancement in our product solution set with ETM CSAM as well as patch management.

    因此,這個百分比是健康的;它對我們而言真正代表的是一種驗證:當我們拿下新客戶(new logos)、進攻市場並且能夠勝出時,部分原因在於我們能夠持續創新並引領市場,透過在產品解決方案組合上的持續強化,包括ETM CSAM以及修補程式管理。

  • Operator

    Operator

  • Rudy Kessinger, D.A. Davidson.

    Rudy Kessinger,D.A. Davidson。

  • Rudy Kessinger - Analyst

    Rudy Kessinger - Analyst

  • Congrats on the results here. I guess if I hear what you're saying, in that the Mythos stuff is more so still in the pipeline and conversation stages, and that wasn't really the driver of the quarter. It sounds like more so just better ETM execution, but certainly seeing those demand trends, I guess as you go to accelerate growth going forward, I guess, are you guys more willing to maybe utilize some of that margin and put that to work and maybe take margins down a bit further to help drive that accelerated growth? Or how should we think about the gross profitability trade-off into next year?

    恭喜本季的成果。我想如果我理解您所說的,Mythos相關的內容更多仍在管線與對話階段,並不是本季的主要驅動因素。聽起來更像是ETM執行得更好,但當然也看到了那些需求趨勢;我想在您們接下來要加速成長時,您們是否更願意動用部分毛利,把它投入運用,可能再把毛利率壓低一些,以推動加速成長?或者我們應該如何看待明年毛利能力的取捨?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Look, I think we always look at -- we've talked about this. We always look at investing in the innovation, investing in our sales and marketing, as we have been doing more recently. And I think we are -- we always focus on ROI, and we see the opportunity ahead of us. And as the opportunities move through the pipeline. It is something that we continue to evaluate. But at this point, we feel good about kind of the investments that we're making. And I think as we see the opportunity, we will continue to evaluate that to make additional investments.

    你看,我認為我們一直都在看——我們也談過這點。我們一直都在投資創新、投資銷售與行銷,最近也確實是這麼做的。而且我認為我們——我們始終聚焦投資報酬率(ROI),也看到了眼前的機會。隨著機會在管線中推進,這是我們會持續評估的事情。但就目前而言,我們對正在進行的投資感到滿意。我想當我們看到機會時,我們會持續評估並進一步追加投資。

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Right. And to double quick on that. Part of the reason why we're able to accelerate the top line growth currently without necessarily having to double dip on the investment, is the fact that we are a partner for partner-led growth momentum right now with majority of our growth, especially when it continued global acquisitions, we're working very with our partners. And we believe that we are investing appropriately at the current levels with the sales and marketing expense going up by 17% in Q1 and 14% in Q2 in the second half, we're anticipating further acceleration on the investments into sales and marketing.

    對。再補充很快一點。我們之所以能在目前加速營收成長、而不一定需要再加倍投入,部分原因是我們現在正處於與合作夥伴共同推動(partner-led)成長動能的階段;我們的大部分成長,尤其是持續的全球併購(acquisitions)帶動下,我們都與合作夥伴密切合作。我們相信以目前水準對銷售與行銷的投入是恰當的:Q1銷售與行銷費用增加17%,Q2增加14%;在下半年,我們預期對銷售與行銷的投資將進一步加速。

  • Rudy Kessinger - Analyst

    Rudy Kessinger - Analyst

  • Got it. And then for my follow-up, current calculated billings was really strong in the quarter. Anything to call out there as far as maybe early renewals or anything like that, that drove the better sequential and year over year on CCB in Q2? And then for Q3 and the full year, just any directional commentary on CCB growth expectations?

    了解。那我的追問是,本季的當期計算帳單(current calculated billings, CCB)非常強勁。這裡有什麼值得特別指出的嗎?例如提前續約之類的因素,推動了Q2的CCB在季比與年比上的更佳表現?另外,對於Q3與全年,對CCB成長預期有沒有任何方向性的評論?

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Yeah. Q2, from a current billings perspective, there's always naturally quarterly fluctuations. So I would point to that LTM which is smooth out some of the lumpiness in the current billings growth rate, which is still an acceleration. As of last quarter, it was 8.5% under LTM growth. And then this quarter, it's at 10%. We're very pleased with the growth. And because of that, we decided to increase our revenue growth guidance. In terms of the second half current billings growth, we're still anticipating for the baseline 7% to 8% and which implies a full year current billings growth in line with a revenue growth rate of 9% to 10%.

    是的。就Q2的當期帳單而言,季度之間自然總會有波動。所以我會指向LTM(過去十二個月)指標,它能平滑當期帳單成長率的一些起伏,而整體仍是在加速。截至上季,LTM成長為8.5%。而本季是10%。我們對這個成長非常滿意。也因此,我們決定上調營收成長指引。至於下半年當期帳單成長,我們仍預期基準為7%到8%,這意味著全年當期帳單成長將與9%到10%的營收成長率一致。

  • Operator

    Operator

  • Junaid Siddiqui, Truist.

    Junaid Siddiqui,Truist。

  • Junaid Siddiqui - Analyst

    Junaid Siddiqui - Analyst

  • Sumedh, can you confirm it appears to be a powerful tool for ETM by helping customers validate which wrong mobilities are actually exploitable in their environment. Is that becoming like the land motion for ETM? In other words, once customers see exploit validation reduce thousands of findings to a handful of truly exploitable risks. How often does that conversation expand into broader ETM remediation and risk quantification deployments?

    Sumedh,你能否確認:它看起來是ETM的一個強大工具,因為它能幫助客戶驗證在其環境中哪些錯誤的弱點(vulnerabilities)實際上是可被利用(exploitable)的。這是否正在成為ETM的「落地」動作(land motion)?換句話說,一旦客戶看到利用性驗證(exploit validation)能把數千項發現縮減到少數真正可被利用的風險,這樣的對話有多常會擴展到更廣泛的ETM修復(remediation)與風險量化(risk quantification)部署?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • That's a great question. I think when you look at the entire vulnerability life cycle to be successful with that, those are three buckets, right, which is detection as fast as possible, and that's where our innovation with Agent Insta, which I call, I like to call it, scanless scanning, the ability to post reflection in less than 1 hour, make it possible for you to get that visibility of what might be exposed. However, just based on what is exposed from a vulnerability perspective. It doesn't give you the confidence that this is actually exploitable and non-exploitable because you have other tools that you might have put in place. And so we definitely see that with TruConfirm, it's a differentiator.

    這是個很好的問題。我認為如果你看整個弱點生命週期,要把它做好可分成三個部分,對吧:第一是盡可能快地偵測;這也是我們在Agent Insta上的創新——我喜歡稱之為「無掃描的掃描(scanless scanning)」——能在不到1小時內提供結果,使你能看見哪些地方可能暴露。然而,僅僅基於弱點層面所暴露的內容,並不能讓你有信心判斷它到底是可利用還是不可利用,因為你可能已經部署了其他工具。因此我們確實看到,TruConfirm是一個差異化因素。

  • There are a lot of CTEM solutions that are just aggregating findings and giving you a theoretical score, but that theoretical score doesn't necessarily tell you whether it is actually going to be exportable or not. So when we are able to tell the customer, look, the ETM solution will help you theoretically reduce your findings to the 1% that matter.

    市面上有很多CTEM解決方案只是彙整發現並給你一個理論分數,但那個理論分數不一定能告訴你它是否真的可被利用。所以當我們能告訴客戶:你看,ETM解決方案可以在理論上把你的發現縮減到真正重要的那1%。

  • And then additionally, you can run these lightweight exploits to further reduce the number of filings that actually will work in your environment that becomes a very interesting conversation because why is that interesting because now that you have reduced the number of findings it makes autonomous remediation, which is the next thing that we are selling to them really plausible. If you tell somebody that you're going to fix 1 million vulnerabilities autonomously. That's a very hard conversation.

    此外,你還可以執行這些輕量化的利用測試(exploits),進一步把在你環境中實際可行的發現數量再降低;這會帶來一個非常有意思的對話。為什麼有意思?因為當你已經把發現數量降下來之後,自主修復(autonomous remediation)——也就是我們接下來要賣給他們的東西——就變得非常可行。如果你告訴某人你要自動修復100萬個弱點,那會是一個非常難談的對話。

  • But if you can show to them that highly validated 70 vulnerabilities are the ones that we are going to fix with automation because they are confirmed exitable, and we cannot wait for attackers to explore them that conversation becomes a lot better. And so TruConfirm is definitely a key part of the conversation, especially with our existing VMDR customers, who are just getting great scanning. Now the ability to upgrade to ETM and then run the validation, which then encourages them to look for the eliminate, which is remediation kind of fits and makes all these pieces work together really well. And so it is an important piece of every conversation we are having with existing customers.

    但如果你能向他們展示:經高度驗證的70個弱點,才是我們要用自動化去修復的,因為它們已被確認可被利用(exploitable),而我們不能等攻擊者去利用它們——那這個對話就會好很多。因此TruConfirm絕對是對話中的關鍵部分,特別是對我們既有的VMDR客戶而言,他們已經享有很好的掃描能力。現在他們可以升級到ETM並進行驗證,進而促使他們去看「消除」(也就是修復)——這讓所有環節能很好地串在一起運作。所以這是我們與既有客戶進行的每一場對話中都很重要的一部分。

  • Junaid Siddiqui - Analyst

    Junaid Siddiqui - Analyst

  • Great. And just as a follow-up, could you just help us understand the behavior of those customers that have not yet adopted ETM like those VMDR are only customers are you still experiencing a high amount of churn there? And is that kind of like still the primary source of any pressure on your overall and the dollar retention rate.

    很好。再追問一下,你能否幫我們理解那些尚未採用ETM的客戶行為——例如僅使用VMDR的客戶——你們那邊是否仍然看到較高的流失(churn)?而這是否仍是你們整體留存率與美元留存率(dollar retention rate)承壓的主要來源?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • I think nothing to call out. We're pleased with the overall momentum of the business, and it's -- we look at that as a great opportunity for us to talk to our existing VMDR customers because all of them are going to have to answer to their management and Board, what they are doing to find a way for autonomous remediation.

    我認為沒有什麼特別需要點出的。我們對整體業務動能感到滿意,而且——我們把這視為一個很好的機會,去和我們現有的 VMDR 客戶溝通,因為他們所有人都必須向管理層與董事會交代,他們正在做什麼來找到自主修復的方法。

  • And so the conversation of upgrading to ETM and the conversation of upgrading and adding on eliminate, we look at that VMDR customer base as a big base that we have where we can actually create growth opportunities because almost everybody is going to need some sort of a prioritization and remediation solution moving forward after the post-Mythos era. So that's actually a pretty good way for us to look at it as I think less and less customers -- I mean, more and more customers, I would say would want to look at a solution that's not just scanning, but also giving them remediation, and that's what we're seeing in conversations right now.

    因此,升級到 ETM 的對話,以及升級並加購 eliminate 的對話,我們把這個 VMDR 客戶群視為一個龐大的基礎;我們確實可以在這裡創造成長機會,因為在後 Mythos 時代之後,幾乎每個人都會需要某種形式的優先排序與修復解決方案。所以我認為,這其實是我們看待它的一個相當好的方式——客戶越來越少——我是說,越來越多的客戶會希望看到的不只是掃描的解決方案,而是也能提供修復能力的方案,而這正是我們目前在對話中看到的趨勢。

  • Operator

    Operator

  • Joseph Gallo, Jefferies.

    Joseph Gallo,Jefferies。

  • Grant Darling - Analyst

    Grant Darling - Analyst

  • This is Grant Darling on for Joe Gallo. I wanted to ask first, have you seen anything different competitively post-Mythos release? It seems like we're hearing more chatter from a variety of players who are signaling more interest in the space. So your results certainly signal strength, but just curious if you're seeing or expecting any change in competitive dynamics? And also if there's any difference in the frequency of competitive displacements to call out?

    我是代替 Joe Gallo 的 Grant Darling。我想先問一下,在 Mythos 發布之後,你們在競爭面上有看到任何不同嗎?感覺我們聽到來自各式各樣玩家更多的討論聲量,他們似乎在釋放對這個領域更感興趣的訊號。所以你們的結果當然顯示出強勁,但我只是好奇,你們是否看到或預期競爭態勢會有任何變化?另外,是否有任何競品替換(competitive displacement)的頻率變化值得特別提及?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Well, I think the problem the customers have is the charter, right? There's too many solutions that are just throwing more and more CVEs and which is kind of something they're focusing on, and that creates a lot of chatter and noise for customers that they have to read through. And so where we are seeing success is not just the traditional let's find 1 million CVE findings, where we are differentiating and why we are seeing that different ship is things like TruConfirm, right?

    我認為客戶面臨的問題是「雜訊」對吧?有太多解決方案只是丟出越來越多的 CVE,這也是他們關注的重點之一,結果為客戶帶來大量討論聲量與噪音,客戶必須花時間去閱讀與篩選。因此,我們看到成功的地方不只是傳統那種「找出 100 萬個 CVE 發現項」;我們的差異化、以及我們看到那艘船(趨勢)不同的原因,是像 TruConfirm 這類能力,對吧?

  • Where we're basically able to not just tell you the CVE is there, but actually have the ability to find a way to give you confidence in its exploitability by actually exploiting it in some cases, giving you additional information in other cases. Our autonomous remediation, while there's a lot of tools that are throwing out CVEs and tools that were saying that they can find something and then they will e-mail the patching solution what they need to fix.

    我們基本上不只是告訴你 CVE 存在,還能在某些情況下實際利用(exploit)它,或在其他情況下提供額外資訊,讓你對其可被利用性更有信心。我們的自主修復也是如此;市面上有很多工具在丟出 CVE,也有工具宣稱能找到問題,然後再用電子郵件通知修補(patching)解決方案需要修什麼。

  • We're actually natively patching that in a matter of hours. And so the interest is more to say, oh wait, there is a solution that can actually allow me to fix and exploit it expose vulnerability in 4 hours from the release versus I'm going to have a hotchpotch of these different solutions, that is not actually going to work in the environment. And so I think that's really kind of what's driving the conversations right now, and that's what we're excited about.

    我們則是在原生平台內於數小時內完成修補。因此,市場的興趣更多是在說:等等,原來有一個解決方案能讓我在發布後 4 小時內就修復並處理已暴露的可利用漏洞,而不是我得拼湊一堆不同的解決方案,最後在環境中其實行不通。所以我認為這正是目前推動對話的核心,也是我們感到興奮的地方。

  • Grant Darling - Analyst

    Grant Darling - Analyst

  • Got it. And then maybe for my follow-up, you've referenced the growing federal pipeline a few times. I guess just any way to quantify the size of that business today? And then just any more detail that you could provide regarding your thoughts about that opportunity and maybe you're right to win there going forward.

    了解。那我追問一下,你們多次提到聯邦(政府)管線正在成長。能否用任何方式量化一下目前這塊業務的規模?另外,能否再多提供一些細節,談談你們對這個機會的看法,以及未來你們在那裡的勝出條件(right to win)?

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • It is right now not a big part of the business, but that is where the opportunity lies right now. I think if you look at the focus of the current administration, if you look at the new CISA BODs, very interesting that the new CISA BODs talks about fast detection, exploit validation and quick remediation. I've heard this somewhere for the last two years, right? So we've focused on building this and being ready for this. And so the federal government is also very, very focused on ensuring that they are seeing outcomes, which are CISOs new requirement of remediating in 72 hours, okay?

    目前它還不是業務中很大的一部分,但機會就在這裡。我想如果你看現任政府的重點、再看新的 CISA BODs,很有意思的是,新的 CISA BODs 談到快速偵測、利用性驗證(exploit validation)以及快速修復。我過去兩年好像一直聽到這些,對吧?所以我們一直專注於打造這些能力並為此做好準備。而且聯邦政府也非常、非常重視確保他們看到可衡量的成果,這也是 CISO 的新要求:在 72 小時內完成修復,好嗎?

  • How are you going to remediate something if your scan is taking two days? That's where InstaScan is going to help you find the issue in the first 60 minutes giving you a realistic chance to meet the Board requirement. And so that is creating very positive conversations at the -- with the federal customers that we are engaged with. A lot of them have very old school traditional on-prem solutions for scanning, different solutions for patching. They've been trying to patch those together for a while.

    如果你的掃描要花兩天,你要怎麼修復?這就是 InstaScan 能在前 60 分鐘內幫你找出問題,讓你有一個現實的機會去滿足董事會要求的地方。因此,這在我們正在接觸的聯邦客戶之間,帶來非常正面的對話。他們很多人仍使用非常老派、傳統的地端(on-prem)掃描方案,以及不同的修補方案。他們嘗試把這些拼在一起已經有一段時間了。

  • And now these bods and the focus on the administration is giving them an opportunity to look at something that is more modern and something that is really helping them give an outcome that is measurable. And so now with Qualys having a FedRAMP High platform that actually is the only platform that can do both the detection and the patching as a FedRAMP High solution.

    而現在這些 BODs 以及政府的重點,讓他們有機會去看更現代化的東西,並且真正幫助他們交付可衡量的成果。因此,Qualys 現在擁有 FedRAMP High 平台,而且實際上是唯一一個能以 FedRAMP High 解決方案同時做到偵測與修補的平台。

  • And our modern approach with agentic AI capabilities built in with these three different agents versus sort of having one generic agent that is just talking to -- in the back end to Anthropic or something like that, it creates a big differentiation in our mind. And I think that gives us the opportunity to go out and the right to have these conversations and work towards winning some of these opportunities that are coming our way. And so for us, given that right now, it's not a big material part of the business is where we see the big opportunity moving forward. And we're excited about the conversations and the investments that we're putting behind that.

    再加上我們的現代化方法:內建具代理式(agentic)的 AI 能力,透過這三種不同的代理(agents),而不是只有一個通用代理在後端去跟 Anthropic 或類似服務對話——在我們看來,這形成了很大的差異化。我認為這也讓我們有機會走出去,並具備正當性去進行這些對話,朝著贏得一些迎面而來的機會努力。所以對我們而言,鑑於目前它還不是業務中很大、很具實質性的部分,這正是我們看到未來最大的機會所在。我們對這些對話以及我們投入的投資感到興奮。

  • Operator

    Operator

  • Joshua Tilton, Wolfe Research.

    Joshua Tilton,Wolfe Research。

  • Joshua Tilton - Analyst

    Joshua Tilton - Analyst

  • Awesome. I apologize for the background noise. I am in Vegas for Black Hat. Maybe just two quick clarifications. First one, Joo Mi, I think you said you still expect 7% to 8% current billings growth for the year. Can you help us understand like why that stands or is an updated from, I guess, what you expected last quarter given the strong billing growth in 2Q. Is it a conservative thing? Is it a 2Q is a blip type thing? Just help us understand why that full year outlook is left unchanged?

    太好了。抱歉有背景噪音。我人在拉斯維加斯參加 Black Hat。先做兩個快速釐清。第一個,Joo Mi,我想你說你們仍預期全年當期帳單(current billings)成長 7% 到 8%。能否幫我們理解,為什麼這個看法仍然成立,或這是否相較於上季你們的預期有所更新,畢竟 2Q 的帳單成長很強。這是保守起見嗎?還是說 2Q 只是一次性的波動?請幫我們理解為什麼全年展望維持不變?

  • And maybe I'll just -- I'll ask my second question now. Any way you could help us understand what net dollar retention rate is baked into the full year guidance since I think it's the second quarter now that has kind of picked up for us?

    那我也先把第二個問題一起問。你們能否幫我們理解,在全年指引中隱含的淨美元留存率(net dollar retention rate)是多少?因為我想這已經是第二季了,這個指標對我們來說似乎有所回升。

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Yeah. To clarify, the current billings guidance for the full year is now in line with our revenue guidance of 9% to 10%. So the 7% to 8% is for the second half current billings. So what we're assuming is for the baseline, the second half current billings will grow by 7% to 8% year over year, and that's predicated on no meaningful change to our net dollar expansion rate, which is now at 10% versus 103 that we started off the year.

    好的。釐清一下:全年當期帳單的指引現在與我們 9% 到 10% 的營收指引一致。所以 7% 到 8% 是針對下半年當期帳單。我們的假設是:以基準情境來看,下半年當期帳單將年增 7% 到 8%,而這是建立在我們的淨美元擴張率(net dollar expansion rate)沒有出現顯著變化的前提下;該比率目前是 10%,相較於我們年初的 103(即 103%)。

  • Joshua Tilton - Analyst

    Joshua Tilton - Analyst

  • So to be clear, the current billings 7% to 8% is for the second half you're saying?

    所以確認一下,你說的當期帳單 7% 到 8% 是指下半年,對嗎?

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • That's right.

    沒錯。

  • Operator

    Operator

  • Mike Cikos, Needham.

    Mike Cikos,Needham。

  • Mike Cikos - Equity Analyst

    Mike Cikos - Equity Analyst

  • If I could just pick up on where Josh was leading off there I think even earlier this year you were talking about a soft guide for that 7% to 8% CCB in calendar '26. Just given the year-to-date outperformance we've seen, why not tweak CCB that even for back half of this year at 7% to 8%. Why not take that slightly higher? Again, we're coming off this mid-teens result you just posted in Q2. It doesn't seem like there was any real fluctuations from renewals. So can you just Help us think about what your assumptions are in driving that 7% to 8% in the back half?

    如果我可以接著 Josh 剛才的話題延伸一下,我記得甚至在今年更早的時候,你們曾談到在 2026 年曆年 CCB 約 7% 到 8% 的較為保守指引。考量到我們看到的年初至今超預期表現,為什麼不把 CCB(即使只是今年下半年)調整到 7% 到 8% 呢?為什麼不把它稍微再提高一些?再說一次,我們剛看到你們在第二季公布的約中十位數(mid-teens)的結果。看起來續約並沒有出現任何明顯波動。所以能否請你們協助我們理解一下,你們對於推動下半年 7% 到 8% 的假設是什麼?

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Yeah. Quarterly current, because we don't actively manage to it, it tends to be lumpy. And so if you take a look at on an LTM basis, that's what we like to point to if you're trying to gauge the business momentum. So on the LTM current billings growth rate, last quarter, it was at 8.5%. This quarter, it's currently sitting at 10%.

    是的。季度的 current billings(當期帳單)因為我們不會主動以此作為管理目標,所以通常會比較不均勻、呈現波動。因此如果你看的是過去十二個月(LTM)的基礎,這才是我們在衡量業務動能時比較喜歡引用的指標。所以以 LTM 的 current billings 成長率來看,上季是 8.5%。這一季目前是 10%。

  • And so what we believe right now is look, it's great that we see that acceleration in the LTM current billings growth rate. And I think that, that 10% better reflects the current business momentum today. And as Sumedh commented on before, you didn't know exactly when the acceleration or heightened kind of pressure from our existing customers who are already pretty followed along the discussion of ATM adoption, we're really going to execute on those deals and Q2 is a reflection of that.

    所以我們目前的看法是:看到 LTM current billings 成長率加速,這很好。而且我認為,10% 更能反映當下的業務動能。如同 Sumedh 先前提到的,你並不確定加速或是來自既有客戶更高的壓力(他們已經相當跟進我們關於 ATM 採用的討論)究竟會在何時真正落地成交,而第二季就是這點的反映。

  • If you were to take a look at our customer base and take a look at them and split them into two different cans. There are already a smaller cohort of customers that we're pretty far along in the discussion around the ROC adoption upgrading to ETM that ended up translating into a better-than-expected results in Q2.

    如果你看我們的客戶基礎,並把他們分成兩個不同的類別。其中有一個較小的客群,我們在 ROC 採用、升級到 ETM 的討論上已經推進得相當深入,這也轉化為第二季優於預期的結果。

  • With that said, the second can of customers that are not as far along in discussion, what we're anticipating right now is we're not seeing any significant increases or acceleration in the sales cycle for the court of customers that are up for renewal in the second half. So given that, it's a data point, Q2, very strong quarter. We're not anticipating any meaningful material changes in the deal cycle in second half. And so therefore, we decided to keep the baseline at 7% to 8% for the current billings flow for the second half of this year.

    話雖如此,對於第二類、討論進度沒那麼深入的客戶,我們目前的預期是:對於下半年即將續約的那一批客戶,我們並沒有看到銷售週期出現任何顯著的縮短或加速。因此,第二季是一個數據點,是非常強勁的一季。但我們不預期下半年的成交週期會出現任何有意義、實質性的變化。所以,我們決定把今年下半年 current billings 的基準維持在 7% 到 8%。

  • Mike Cikos - Equity Analyst

    Mike Cikos - Equity Analyst

  • Understood. And maybe another one here. Just wanted to get a better sense. It was great to see the last 12 months net dollar expansion improved by a point again this quarter to 105%, especially since you have this improvement for total company. Meanwhile, the ETM and CSAM NDR was unchanged sequentially at 107%. Can you, I guess, provide any further granularity on almost like a quarterly snapshot here as far as what was driving the total company improvement from products or cohort of customers adopting or increasing spend. I'd just love to get a little bit more on that.

    了解。那我再問一個。我想更清楚理解一下。很高興看到過去 12 個月的淨美元擴張率(net dollar expansion)本季又提升了 1 個百分點到 105%,尤其是你們整體公司都有改善。同時,ETM 與 CSAM 的 NDR(淨美元留存率)則較前季持平在 107%。你能否提供更細的拆解,例如以季度快照的角度,說明是哪些產品或哪些客群的採用/增加支出,推動了整體公司層面的改善?我很希望能多了解一點。

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Yeah. If you take a look at our product mix, that will help you to kind of come with us in this journey of different product adoption. And as customers come up with renewal, where they decide to spend more on. So right now, with our ETM and CSAM currently making up 12% of total bookings, up from 9% a year ago period. That kind of tells you that that's really helping to drive the bookings growth momentum that we see in the business today. Patch Management definitely contributed to that as well. currently at 8% a year ago, it was at 7%. And then offsetting that was the VMDR contribution coming down to 49%, down from 54% a year ago.

    好的。如果你看我們的產品組合,會有助於你跟著我們一起理解不同產品採用的這段歷程。以及客戶在續約時,會決定把更多預算花在哪些地方。目前 ETM 與 CSAM 佔總訂單(bookings)的 12%,高於一年前同期的 9%。這某種程度上說明了,它們確實在推動我們目前看到的訂單成長動能。修補管理(Patch Management)也有貢獻:目前是 8%,一年前是 7%。而相對抵銷的是 VMDR 的貢獻降到 49%,低於一年前的 54%。

  • Operator

    Operator

  • Brian Essex, JPMorgan.

    Brian Essex,摩根大通(JPMorgan)。

  • Brian Essex - Analyst

    Brian Essex - Analyst

  • I guess, I have two, I think both for Joo Mi. But I guess, Joo Mi, I'd love to -- it's great to see the traction that you've got on the partner side of the business. on the indirect side. But I would love to kind of understand where you're guiding spending, particularly in sales and marketing, but for OpEx overall. I think last quarter, you talked about mid-teens growth.

    我想我有兩個問題,應該都給 Joo Mi。不過,Joo Mi,我很高興看到你們在合作夥伴端、也就是間接通路方面取得的進展。但我想更了解你們對支出的指引,特別是銷售與行銷,但也包括整體營業費用(OpEx)。我記得上季你們談到中十位數(mid-teens)的成長。

  • It seems like you're pointed in the same direction, but you've come in well under that for the first half of the year. I'd love to understand where are you seeing traction? Where might you regulate greater spend? And what might outside of performance on the top line in the back half of the year, how are you regulating spend on OpEx and sales and marketing relative to that mid-teen level when we've come in materially below that in the first half? And then I got a follow-up.

    看起來你們仍朝同一方向,但今年上半年你們的實際表現明顯低於那個水準。我想了解你們在哪裡看到成效?你們可能會在哪些地方加大支出?以及除了下半年營收端(top line)的表現之外,你們如何在 OpEx 與銷售行銷支出上進行調控,讓它相對於中十位數水準;畢竟上半年明顯低於該水準?然後我還有一個追問。

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Yeah. On the sales and marketing spend, majority of that spend increase is driven by the headcount. So if you take a look at the 17% year over year for Q1 and 14% year over year for Q2, both quarters, majority of it was basically investing back into our business, expanding our team, making sure that we have the right team members in the GTM team, whether it be sales or marketing or product all across the board that's really focused on selling our product and better positioning ourselves and working very closely with our partners.

    好的。在銷售與行銷支出方面,支出增加的大部分是由人力(headcount)所驅動。所以如果你看第一季年增 17%、第二季年增 14%,這兩季的大部分其實都是在回投資我們的業務:擴編團隊,確保我們在 GTM(go-to-market)團隊中有合適的人才,不論是銷售、行銷或產品等各個面向,重點都放在把產品賣出去、把定位做得更好,並且與合作夥伴密切合作。

  • Now with that said, we are leveraging AI back into our business as well, and that certainly helped to make sure that we're looking at the operating efficiency, making sure that its appropriate level of investment that we're spending each quarter. And so with that in mind, we're very pleased with the momentum that we see today, and we do anticipate increase in spend, whether the number one is always going to be head count for us right now for 2026, but there are other certainly investments that we're making, which is demand, making sure that we're investing that business to generate sufficient pipeline, that's quality that we can execute on for the second half of this year.

    另外,我們也把 AI 應用回到自身業務中,這確實有助於我們檢視營運效率,確保每一季的投資水準是適當的。基於此,我們對目前看到的動能非常滿意,也確實預期支出會增加;其中第一順位對我們而言仍會是人力配置,特別是針對 2026 年。

  • Brian Essex - Analyst

    Brian Essex - Analyst

  • Okay. Great. That's helpful. And maybe just how far penetrated are you into your installed base with QFlex? And how are you regulating the level of availability that customers might have for QFlex? Are you still measuring it and keeping it kind of like the high-end customers? Or could we expect maybe a broader rollout as you develop more experience with QFlex across your customer installed base?

    好的。很好。這很有幫助。另外,你們在既有安裝基礎(installed base)中,QFlex 的滲透率大概到什麼程度?你們如何調控客戶可取得 QFlex 的範圍?你們仍在衡量並把它主要保留給高端客戶嗎?或者隨著你們在客戶安裝基礎中累積更多 QFlex 的經驗,我們是否可以期待更廣泛的推廣?

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Yeah. We have rolled out QFlex it's really more intended for enterprise customers. And so now it's available -- generally available to enterprise customers, and we are having appropriate level of discussion with a set of customers that are up for renewal as well as new prospects as we discuss with them what they're looking for, is Q4 is something that's going to be advantageous to them. And really, if you think about this product, it's premium product grade. It helps the customers to really adopt a number of our solutions in a seamless way.

    是的。我們已推出 QFlex,它主要是為企業級客戶所設計。因此目前它已對企業級客戶全面可用(generally available),而且我們也會與一部分即將續約的客戶以及新的潛在客戶進行適當程度的討論,了解他們的需求,並評估 QFlex 是否會對他們有利。而且如果你從產品角度來看,這是一個高階(premium)等級的產品。它能幫助客戶以更無縫的方式採用我們多項解決方案。

  • And so they're more than willing to pay the premium price for this and the way that we think about it right now is, it's going to be right for customers who are willing to grow and for existing customers as we look to drive our net dollar expansion rate further then continue to focus on that metric as customers grow with us, it will be right for our enterprise customers who are looking for a cost-effective way to gain more value while at the same time increasing their spend with Qualys.

    因此,他們非常願意為此支付溢價;而我們目前的看法是,這將適合願意成長的客戶,以及我們在推動淨美元擴張率(NDR)進一步提升時的既有客戶,並在客戶與我們一同成長的過程中持續聚焦這項指標;同時,這也將適合我們的企業客戶,他們正在尋找一種具成本效益的方式來獲取更多價值,並在同時增加對 Qualys 的支出。

  • Operator

    Operator

  • Shrenik Kothari, Baird.

    Shrenik Kothari,Baird。

  • Shrenik Kothari - Analyst

    Shrenik Kothari - Analyst

  • Again, congrats on the great quarter. Sumedh, big picture, you did underscore that near term, there is a stronger patch margin cycle, but you believe there's a broader category reset underway around the control plan for the pre bridge risk management, as you described, exploit validation, risk quantification and autonomous remediation.

    再次恭喜這個出色的季度。Sumedh,從大方向來看,你確實強調短期內會有更強的修補(patch)需求週期,但你也認為,正如你所描述的,圍繞控制平面(control plane)的「事前(pre-breach)風險管理」正在進行更廣泛的類別重置,包括漏洞利用驗證(exploit validation)、風險量化(risk quantification)以及自主修復(autonomous remediation)。

  • Around the AI urgency, I remember last quarter, you guys did say since it's broadening the opportunity customers may extend sales cycles or pause renewals. Just can you add any finer point around these broader strategic deal conversion timing, sales cycles? How long are these evaluations taking? Are you seeing these conversion rates getting faster broadly, just directionally? And then I have a quick follow-up.

    關於 AI 的急迫性,我記得上個季度你們確實提到,因為它正在擴大機會,客戶可能會延長銷售週期或暫停續約。你能否就這些更廣泛的策略性交易轉換時點、銷售週期補充更細的觀察?這些評估大概需要多久?你是否看到整體而言這些轉換率正在變快(方向性地)?然後我有一個簡短的追問。

  • Sumedh Thakar - President, Chief Executive Officer, Director

    Sumedh Thakar - President, Chief Executive Officer, Director

  • Yeah, that's a great question. I think as I mentioned earlier too, and when we talk about the ROC, right, there is corporation center pre-breach risk management is broader than just vulnerability management. Obviously, that is a focus right now. We've talked about the use of misconfigurations as part of these attacks, the use of identities and the recent OpenAI, Hugging Face was a great example of a vulnerability misconfiguration and identity being used. And so the Risk Operation Center has been broadly built around that.

    是的,這是個很好的問題。我想如同我先前也提到的,當我們談到 ROC(Risk Operation Center,風險營運中心)時,企業級的事前風險管理其實不僅僅是漏洞管理。當然,這是目前的重點。我們也談到,這些攻擊會利用錯誤設定(misconfigurations)、身分(identities),而近期 OpenAI、Hugging Face 的事件就是一個很好的例子:漏洞、錯誤設定與身分被一併利用。因此,風險營運中心是圍繞這些面向廣泛建構的。

  • I think in terms of the way we are seeing the conversation is not about saying, can I just patch for the next one month and I'm done. I think there is a -- or the conversation with customers are really about nobody is saying that they're just going to patch now and then go back to not having regular patching cycle and autonomous matching in the future.

    我認為就我們看到的對話而言,並不是在說「我接下來一個月把補丁打完就結束了」。我想客戶的對話其實是——沒有人會說他們現在只打補丁,然後未來又回到沒有規律的修補週期、也沒有自主修補的狀態。

  • So the broad-based conversation is about how they're moving forward create a process throughout their organization that is long-lasting where they're able to -- any threat that comes out, they're able to actually respond to that threat very quickly. And so we see this more as something that is broadly being talked about and we see the opportunity for that to be something that we can focus on. And so I think right now, like with any corporation, large companies, they want to understand what the big picture road map is that they can talk to their management about while focusing on sort of phases that they can deploy.

    所以,更廣泛的對話是在談他們如何往前走,在整個組織內建立一個可長期運作的流程,使他們能夠——任何新的威脅出現時,都能非常快速地回應。因此,我們把這視為一個正在被廣泛討論的議題,也看到其中的機會,讓我們可以聚焦於此。我想目前就像任何大型企業一樣,他們希望了解整體的大方向路線圖,以便與管理層溝通,同時也會聚焦於可以分階段部署的各個階段。

  • And so the ROC conversation allows us to have a much broader strategic conversation with ETM and then the vulnerability management patch management is something more of a that they're focusing on right now to be able to have that phased approach. So overall, I think our innovation around ROC that we have been focusing on is coming to the help quite a bit for these customers to have broader conversation while the focus right now is changing their Patch Management processes and programs.

    因此,ROC 的對話讓我們能夠與 ETM 進行更廣泛、更具策略性的討論;而漏洞管理、修補管理則更像是他們目前為了採取分階段方法而聚焦的部分。總體而言,我們近來聚焦於 ROC 的創新,對於協助這些客戶進行更廣泛的對話相當有幫助;同時,他們目前的重點是在改變其修補管理流程與計畫。

  • So I do think that the opportunity or rather this is giving us an opportunity to have those broader conversations with the customer. And as Joo Mi said, of course, there were a small cohort of customers that was already in process before Mythos came out to adopt Patch Management. Just a reminder, 150 million patches already applied by Qualys.

    所以我確實認為,這個趨勢——或者說——正在給我們一個機會,讓我們能與客戶展開更廣泛的對話。而如同 Joo Mi 所說,當 Mythos 出來之前,就已經有一小群客戶正在導入修補管理的流程中。提醒一下,Qualys 已經套用(applied)了 1.5 億個補丁。

  • So some customers have been at the forefront of these. So that helped us sort of say, look, we were right. The customers were like, look, we're already in the process. We were right to focus on Patch Management. So that helps in the short term, but then there is a long cohort of customers that are having these conversations now and is going to create the opportunity for us to have sustained conversations or additional things in the ROC as we move forward and they get comfortable with auto patching.

    因此,有些客戶一直走在最前面。這也幫助我們某種程度上能說:看,我們的方向是對的。客戶也會說:看,我們本來就已經在進行中了。我們把重點放在修補管理是正確的。這在短期內有幫助;但同時也有一個更長尾的客戶群,現在正在進行這些對話,這將為我們創造機會,讓我們在未來、當他們對自動修補(auto patching)更有信心後,能在 ROC 上進行持續的對話或導入更多內容。

  • Shrenik Kothari - Analyst

    Shrenik Kothari - Analyst

  • Got it. Very helpful. And Joo Mi, just a follow-up to Mike's and Josh's question around the NDR improvement, very encouraging to see that pick up. The ETM cohort remained at 107%, I think you highlighted, is QFlex going live and you did highlight it playing a direct role and several of these large platform expansion also helping pull forward the commitment, help in bookings more than near-term use it. So is that -- what is kind of explaining these budgets shifting towards more newly urgent capabilities reflected in your sort of NDR next 12 months versus something more strategic around ETM CSAM usage will follow through? Like just or to understand if QFlex is playing a role?

    了解。非常有幫助。Joo Mi,我想就 Mike 和 Josh 關於 NDR 改善的問題再追問一下,很令人鼓舞看到它回升。你提到 ETM 客群仍維持在 107%;我想你也提到 QFlex 上線,並強調它在其中扮演直接角色,且有幾個大型平台擴張也有助於把承諾(commitment)提前,對訂單(bookings)的幫助大於短期實際使用。所以,這是否——也就是說,究竟是什麼在解釋這些預算轉向更「新近且急迫」的能力,反映在你們未來 12 個月的 NDR,而不是更偏策略性的、像是 ETM/CSAM 的使用會在之後跟上?也就是想了解 QFlex 是否在其中扮演角色?

  • Joo Mi Kim - Chief Financial Officer

    Joo Mi Kim - Chief Financial Officer

  • Yeah, QFlex is really to accommodate customers who are looking for that flexibility and who are willing to spend more with us. And so we wanted to make the selling motion. It's seamless easier for that where it creates a win-win opportunity for both customers as well as us. And so we're very pleased with us going with it broadly. It still applies to a small percentage of customers today who sign up for QFlex, it's not yet reflected in the numbers, but we believe that this will help drive the NDR for us broadly speaking.

    是的,QFlex 主要是為了滿足那些尋求彈性、並且願意在我們這裡增加支出的客戶。因此,我們希望讓銷售動作(selling motion)對這類情境而言更順暢、更容易,從而為客戶與我們雙方創造雙贏的機會。因此,我們很高興能更廣泛地推行它。目前,選擇加入 QFlex 的客戶仍只占一小部分,尚未反映在數字上,但我們相信,從整體而言,這將有助於推動我們的 NDR。

  • Operator

    Operator

  • Thank you. This will conclude today's question-and-answer session and also concludes today's conference call. Thank you so very much for participating, and you may now disconnect. Goodbye.

    謝謝。今天的問答環節到此結束,也同時結束今天的電話會議。非常感謝各位的參與,現在您可以掛線。再見。