Intrusion Inc Stock price
Is Intrusion Inc a Top Scorer Stock based on the Dividend, High-Growth-Investing or Leverman Strategy?
As a Free StocksGuide user, you can view scores for all 9,134 stocks worldwide.
StocksGuide Premium
StocksGuide Unlimited
Key metrics
📘 Market Capitalization
📈 What is it?
Market capitalization shows how much a company is currently worth on the stock market.
🧮 How is it calculated?
🏛️ Why is it important?
It helps classify companies by size (Large, Mid, Small Cap) and indicates their market presence and relative stability.
🧮 Calculation
🎯 What does this mean for investors?
- Large-cap companies tend to be more stable, often pay dividends, but may grow more slowly.
- Smaller firms may offer higher growth potential but come with more volatility.
- Market capitalization is a useful indicator of company size — but not a measure of whether a stock is undervalued or overvalued.
📘 Enterprise Value (EV)
📈 What is it?
Enterprise Value represents the total cost to acquire a company — including its debt and excluding its cash reserves.
🧮 How is it calculated?
(= Market Cap + Net Debt)
🏛️ Why is it important?
EV gives a more complete picture of a company's value than market cap alone and is used in key valuation ratios like EV/FCF or EV/Sales.
🧮 Calculation
🎯 What does this mean for investors?
- Enterprise Value shows the true cost of buying a company, including all financial obligations.
- It is more accurate than just looking at market cap, especially when comparing companies with different levels of debt or cash.
- Professional investors prefer EV-based multiples because they better reflect the company’s full financial footprint.
📘 Net Debt
📈 What is it?
Net Debt shows how much debt remains after subtracting a company’s available cash reserves.
🧮 How is it calculated?
🏛️ Why is it important?
It indicates how dependent a company is on borrowed money and how easily it can service its debt in the short term.
🧮 Calculation
🎯 What does this mean for investors?
- Low or negative net debt signals financial strength and flexibility.
- Companies with strong cash positions are better positioned in crises.
- High net debt increases financial risk — especially in environments with rising interest rates or economic downturns.
📘 Cash
📈 What is it?
Cash represents all liquid assets a company can access immediately — including cash, bank deposits, and short-term investments.
🧮 How is it calculated?
🏛️ Why is it important?
It reflects a company’s financial flexibility and resilience — enabling investments, buybacks, or buffer in downturns.
🧮 Calculation
🎯 What does this mean for investors?
- A strong cash position means greater room for maneuver and crisis resistance.
- Cash-rich companies can invest, pay down debt, or repurchase shares.
- But excess idle cash might indicate a lack of growth opportunities.
📘 Shares Outstanding
📈 What is it?
Shares outstanding represent the total number of a company’s shares currently held by investors — excluding treasury stock.
🧮 How is it calculated?
🏛️ Why is it important?
It’s the basis for key metrics like Earnings Per Share (EPS), Market Capitalization, or the Price/Earnings ratio (P/E).
🧮 Calculation
🎯 What does this mean for investors?
- Fewer shares in circulation typically increase earnings per share — making each share more valuable.
- Share buybacks reduce the number of shares and boost per-share metrics.
- Issuing new shares does the opposite — diluting shareholder value and lowering per-share figures.
📘 Price-to-Earnings Ratio (P/E)
📈 What is it?
The P/E ratio shows how many times a company's earnings per share are reflected in its current share price — in other words, how "expensive" the stock appears relative to its profits.
🧮 How is it calculated?
🏛️ Why is it important?
The P/E ratio is one of the most widely used valuation metrics. It helps investors assess whether a stock appears cheap or expensive compared to its earnings power.
🧮 Calculation
📊 P/E (TTM) = Based on earnings from the last 12 months (Trailing Twelve Months):🎯 What does this mean for investors?
- A low P/E may indicate undervaluation — or signal underlying issues.
- A high P/E may reflect strong growth expectations — or an overvalued stock.
📘 Price-to-Sales Ratio (P/S)
📈 What is it?
The P/S ratio shows how much investors are paying for $1 of the company’s revenue – regardless of profitability.
🧮 How is it calculated?
🏛️ Why is it important?
P/S is especially useful for evaluating growth companies or businesses not yet profitable. It reflects how the market values the company’s sales.
🧮 Calculation
Market Cap = $14.95m | Revenue (TTM) = $5.79m
Market Cap = $14.95m | Estimated Revenue = $9.00m
🎯 What does this mean for investors?
- A low P/S may indicate undervaluation — or low profitability.
- A high P/S can reflect strong growth expectations — or excessive optimism.
- Especially helpful when evaluating companies where profits are low, volatile, or negative.
📘 Enterprise Value to Sales (EV/Sales)
📈 What is it?
EV/Sales shows how much investors are paying for $1 of revenue — considering not just equity, but also debt and cash. It’s the capital structure–adjusted version of the P/S ratio.
🧮 How is it calculated?
🏛️ Why is it important?
It’s ideal for comparing companies with different levels of debt. It reflects a company's true cost relative to its revenue.
🧮 Calculation
Enterprise Value = $18.14m | Revenue (TTM) = $5.79m
Enterprise Value = $18.14m | Forward Revenue = $9.00m
🎯 What does this mean for investors?
- EV/Sales allows for capital structure–neutral company comparisons.
- A lower ratio may indicate undervaluation; a higher one may signal strong growth expectations or overvaluation.
- Especially helpful when evaluating high-growth companies with low or negative earnings.
📘 Enterprise Value to Free Cash Flow (EV/FCF)
📈 What is it?
EV/FCF shows how many years it would take for a company to "pay back" its enterprise value using its free cash flow.
🧮 How is it calculated?
🏛️ Why is it important?
It focuses on real cash generation, ignoring accounting noise — ideal for assessing profitability and value based on liquidity, not earnings.
🧮 Calculation
🎯 What does this mean for investors?
- A low EV/FCF may signal undervaluation and strong cash generation.
- A high EV/FCF might reflect weak recent cash flow or aggressive growth expectations.
- Best suited for stable, mature businesses with predictable free cash flows.
📘 Price-to-Book Ratio (P/B)
📈 What is it?
The P/B ratio compares a company’s market value to its book value — showing how much investors are paying for each dollar of net assets.
🧮 How is it calculated?
🏛️ Why is it important?
P/B is commonly used for asset-heavy industries like banks or industrials. It helps assess whether a stock is trading above or below its net asset value.
🧮 Calculation
🎯 What does this mean for investors?
- A P/B below 1 may signal undervaluation — or weak profitability.
- A P/B above 1 implies the market expects future value creation (e.g., brand, IP, growth).
- Best used for companies with tangible assets and strong balance sheets.
📘 Equity Ratio
📈 What is it?
The equity ratio indicates what portion of a company’s total assets is financed by shareholders’ equity – in other words, how much it relies on its own capital.
🧮 How is it calculated?
🏛️ Why is it important?
A high equity ratio reflects financial strength and stability, especially during downturns. It’s a key indicator of a company’s solvency and long-term risk profile.
🧮 Calculation
🎯 What does this mean for investors?
- Companies with high equity ratios are generally more resilient and less dependent on external debt.
- Low equity ratios can signal higher risk or aggressive financial strategies.
- Important: Always assess the equity ratio in combination with the return on equity (ROE). This shows not just how stable the company is – but also how efficiently it uses shareholder capital.
📘 Return on Equity (ROE)
📈 What is it?
Return on equity (ROE) shows how efficiently a company uses its shareholders’ equity to generate profit. In other words: how much net income is earned per dollar of equity.
🧮 How is it calculated?
🏛️ Why is it important?
ROE is a core profitability metric. It helps investors understand whether a company delivers attractive returns on the capital provided by its shareholders.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROE indicates that the company is using its capital efficiently and profitably.
- It’s especially meaningful for capital-intensive businesses or firms with high equity bases.
- Important: A very high ROE can also result from high debt levels – always interpret it alongside the equity ratio to assess financial health.
📘 Return on Capital Employed (ROCE)
📈 What is it?
ROCE measures how efficiently a company generates profits from its total capital – including both equity and interest-bearing debt.
🧮 How is it calculated?
It evaluates the return on all capital employed, regardless of how it’s financed.
🏛️ Why is it important?
ROCE is ideal for comparing companies with different financing structures. It shows how well management uses capital to create value for both shareholders and creditors.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROCE means the company uses its capital efficiently – regardless of whether it's funded by debt or equity.
- The higher the ROCE compared to peers, the more value the company creates with its invested capital.
- Especially relevant for capital-intensive sectors like industrials, energy, or infrastructure.
📘 Return on Invested Capital (ROIC)
📈 What is it?
ROIC measures how efficiently a company generates returns from the capital invested in its core operations – regardless of whether the capital comes from equity or debt.
🧮 How is it calculated?
- NOPAT = Net Operating Profit After Taxes
- Invested Capital = Operating assets minus non-interest-bearing liabilities
🏛️ Why is it important?
ROIC is one of the most accurate indicators of capital efficiency. Unlike return on equity, it is not distorted by leverage and shows how much value is created for all capital providers.
🎯 What does this mean for investors?
- A high ROIC shows how effectively a company uses the capital that is truly invested in its core operations.
- Unlike ROCE, ROIC focuses only on the capital that is actively used to run the business – and that requires a return (i.e. interest-bearing).
- Especially useful when comparing companies with large amounts of excess cash or non-interest-bearing liabilities – giving a more realistic picture of capital efficiency.
📘 Leverage Ratio (Debt-to-Equity)
📈 What is it?
The leverage ratio indicates how much a company relies on interest-bearing debt (such as loans and bonds) relative to its shareholders’ equity.
🧮 How is it calculated?
🏛️ Why is it important?
This ratio helps assess a company’s financial structure and risk profile. High leverage can enhance returns – but also increases exposure to interest rate changes and financial stress.
🧮 Calculation
🎯 What does this mean for investors?
- A low leverage ratio signals financial strength and independence.
- A higher ratio can improve returns in good times but increases risk during downturns or rising interest rate periods.
- 👉 Always interpret in the context of industry, capital intensity, and interest rate environment.
📘 Revenue
📈 What is it?
Revenue shows how much a company earns in total from selling its products and services – the gross income before any costs are deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Revenue is one of the key figures to assess a company’s size, market position, and growth potential.
🧮 Calculation
🎯 What does this mean for investors?
- Growing revenue indicates rising demand and can be an early signal of future earnings growth.
- Comparing actual and expected revenue reveals trends in the market environment and analyst sentiment.
- Note: Strong revenue alone isn’t enough – margins and profitability matter just as much.
📘 EBITDA
📈 What is it?
EBITDA stands for “Earnings Before Interest, Taxes, Depreciation, and Amortization.” It reflects a company’s operating profit before the effects of financing, taxes, and accounting depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
EBITDA is widely used to evaluate a company’s operating performance – especially across capital-intensive sectors or international comparisons.
🧮 Calculation
🎯 What does this mean for investors?
- A high or growing EBITDA indicates strong operational profitability – independent of taxes, interest, or accounting methods.
- It’s especially useful for comparing companies across sectors or geographies.
- Important: EBITDA is not a net income figure – it excludes key costs like depreciation and interest.
📘 EBIT
📈 What is it?
EBIT stands for “Earnings Before Interest and Taxes.” It reflects a company’s operating profit after depreciation, but before interest and tax expenses.
🧮 How is it calculated?
🏛️ Why is it important?
EBIT is a core profitability metric that shows how well the company performs in its main business operations – independent of capital structure and tax environment.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT indicates strong profitability from the company’s core business – before financial and tax effects.
- It allows better comparison between companies with different debt levels or tax structures.
- Compared to EBITDA, EBIT already accounts for depreciation and reflects capital intensity more clearly.
📘 Net Income
📈 What is it?
Net income is the company’s total profit – the amount left after all expenses, taxes, interest, and depreciation have been deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Net income is the most comprehensive measure of a company’s profitability – showing how much actual profit remains after all business and financing costs.
🧮 Calculation
🎯 What does this mean for investors?
- Growing net income indicates that the company is managing all of its costs efficiently.
- It directly influences valuation metrics like P/E ratio and the company’s dividend capacity.
- Over time, net income trends reveal how resilient and profitable the business model really is.
📘 Free Cash Flow (FCF)
📈 What is it?
Free Cash Flow shows how much actual cash remains after a company covers its operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
FCF reflects a company’s real financial strength – regardless of accounting profits. It shows how much flexibility a company has for dividends, share buybacks, or debt reduction.
🧮 Calculation
🎯 What does this mean for investors?
- High free cash flow means the company generates real, usable cash – independent of reported net income.
- It’s often the most reliable base for sustainable dividends and buybacks.
- Declining FCF can be an early warning sign – even when profits appear stable.
📘 Revenue Growth
📈 What is it?
Revenue growth shows how much a company’s sales have changed compared to the previous year – both on a trailing basis (TTM) and based on forward projections.
🧮 How is it calculated?
Forward = (Expected revenue ÷ Revenue in prior year − 1) × 100
Forward growth is based on analyst estimates for the current fiscal year.
🏛️ Why is it important?
Rising revenue signals growing demand, business expansion, and market share gains – especially important for growth-oriented companies.
🧮 Calculation
🎯 What does this mean for investors?
- Growth is the engine of long-term value creation – especially in tech and growth sectors.
- What matters is not just current growth, but its sustainability.
- Forward projections reflect whether analysts expect continued momentum – or a slowdown.
📘 EBITDA Growth
📈 What is it?
EBITDA growth shows how much a company’s operating profit (before interest, taxes, depreciation, and amortization) has increased or decreased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBITDA ÷ EBITDA from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
Growing EBITDA indicates improving operational profitability – regardless of financing or accounting effects.
🧮 Calculation
🎯 What does this mean for investors?
- Strong EBITDA growth signals operational efficiency and scalability – especially during growth phases.
- EBITDA growth can be an early indicator of margin and earnings expansion – but should be assessed alongside revenue and EBIT.
📘 EBIT Growth
📈 What is it?
EBIT growth shows how much a company’s operating profit (after depreciation, but before interest and taxes) has increased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBIT ÷ EBIT from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
EBIT growth is a direct indicator of a company’s business performance – taking into account capital intensity through depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- Rising EBIT signals improving operating profitability – even after accounting for depreciation.
- It’s especially important for evaluating companies with significant capital expenditures.
- Combined with revenue and EBITDA growth, EBIT growth provides a well-rounded view of operational progress.
📘 Net Income Growth
📈 What is it?
Net income growth shows how much a company’s bottom-line profit has increased or decreased compared to the previous year – both on a trailing basis (TTM) and based on analyst projections.
🧮 How is it calculated?
Forward = (Expected net income ÷ Net income from prior year − 1) × 100
The forward estimate reflects analysts’ expectations for the current fiscal year.
🏛️ Why is it important?
Net income is the ultimate measure of profitability. Growing net income signals stronger efficiency, cost control, and sustainable earnings power.
🧮 Calculation
🎯 What does this mean for investors?
- Stronger net income boosts valuation, dividend potential, and investor confidence.
- If profits stall while revenue grows, it may signal margin pressure.
📘 Free Cash Flow Growth
📈 What is it?
Free cash flow (FCF) growth shows how a company’s available cash – after covering operating expenses and capital expenditures – has changed compared to the previous year.
🧮 How is it calculated?
🏛️ Why is it important?
Free cash flow reflects real financial strength. Growing FCF indicates more flexibility for dividends, share buybacks, and reinvestment.
🧮 Calculation
🎯 What does this mean for investors?
- Declining FCF may point to rising investments, increasing costs, or weaker operating performance.
- Especially for dividend investors, FCF growth is critical – since dividends are paid from actual available cash.
- A negative trend isn't always bad, but it deserves closer attention.
📘 Gross Margin
📈 What is it?
Gross margin shows how much of a company’s revenue remains after deducting the direct costs of goods sold (like materials and production). It represents the company’s “raw profit” before fixed costs, taxes, and interest.
🧮 How is it calculated?
Or simply: Gross Margin = Gross Profit ÷ Revenue × 100
🏛️ Why is it important?
Gross margin indicates how efficiently a company can produce or procure what it sells. It is a key measure of product-level profitability and pricing power.
🧮 Calculation
🎯 What does this mean for investors?
- A high gross margin suggests strong pricing power and efficient production.
- Falling margins may signal rising input costs or competitive pressure.
- Compared to peers, gross margin offers insights into the quality of a business model.
📘 EBITDA Margin
📈 What is it?
The EBITDA margin shows how much of a company’s revenue remains as operating profit before interest, taxes, depreciation, and amortization.It reflects operating efficiency without being distorted by financing or accounting factors.
🧮 How is it calculated?
🏛️ Why is it important?
The EBITDA margin reveals how much operating income a company generates per dollar of revenue – independent of capital structure and tax effects.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBITDA margin reflects strong core profitability – before accounting distortions.
- It allows for effective comparisons across companies and sectors.
- A stable or growing margin signals efficient cost control and business scalability.
📘 EBIT Margin
📈 What is it?
The EBIT margin shows what percentage of revenue remains as operating profit after depreciation but before interest and taxes.
🧮 How is it calculated?
🏛️ Why is it important?
The EBIT margin reflects a company’s core profitability while accounting for capital intensity (e.g. machinery, infrastructure). It’s especially useful for comparing businesses with different levels of depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT margin shows that the company remains efficient even after factoring in depreciation.
- It’s especially relevant for capital-intensive industries.
- Stable or rising EBIT margins over time are a strong indicator of pricing power and business quality.
📘 Net margin
📈 What is it?
Net margin shows how much of a company’s revenue remains as bottom-line profit after deducting all costs, interest, taxes, and depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
Net margin reflects a company’s overall efficiency – across operations, financing, and taxation. It shows how much actual profit is generated from each dollar of revenue.
🧮 Calculation
🎯 What does this mean for investors?
- A high net margin means the company is not only strong operationally but also manages financing and taxes efficiently.
- Peer comparisons reveal business quality and competitiveness.
- Declining margins despite revenue growth can be a red flag for rising costs or inefficiencies.
📘 Free cash flow margin
📈 What is it?
The free cash flow (FCF) margin shows how much of a company’s revenue remains as actual free cash after covering all operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
This margin reflects the true liquidity generated by the business – independent of accounting rules or depreciation. It’s especially relevant for dividends, buybacks, and reinvestment decisions.
🧮 Calculation
🎯 What does this mean for investors?
- A high FCF margin means a company consistently generates strong cash flow.
- It’s a positive signal for financial stability and shareholder returns.
- The long-term trend is key – a declining margin may indicate rising investments or weakening operating efficiency.
📘 Earnings per share (EPS)
📈 What is it?
Earnings per Share (EPS) shows how much profit is attributable to a single share – and is one of the most important metrics for evaluating a company's performance.
🧮 How is it calculated?
The diluted share count reflects potential new shares that could be issued through options, convertible bonds, or other rights.
🏛️ Why is it important?
EPS is the basis for many key valuation metrics like P/E ratio, PEG ratio, or payout ratio. It enables comparisons of profitability across companies, regardless of their size.
🧮 Calculation
🎯 What does this mean for investors?
- EPS captures per-share profitability and is especially useful for comparisons over time or with analyst estimates.
- Rising EPS may signal consistent growth or share buybacks.
- Important: Always use diluted EPS for more realistic valuations – especially in companies with stock-based compensation.
📘 Free cash flow per share (FCF per share)
📈 What is it?
Free Cash Flow per Share shows how much free cash flow a company generates per outstanding share – after investments, but before dividends or debt repayments.
🧮 How is it calculated?
Free cash flow is calculated as operating cash flow minus capital expenditures (CapEx).
🏛️ Why is it important?
FCF per Share reveals how much real cash is available per share – useful for dividends, buybacks, or reducing debt. Unlike net income, free cash flow is harder to manipulate and often seen as a more reliable metric.
🧮 Calculation
🎯 What does this mean for investors?
- High FCF per share signals strong financial flexibility.
- It shows how much capital the company can effectively reinvest or return to shareholders.
- Particularly relevant for dividend payers and capital-efficient businesses.
📘 Short interest
📈 What is it?
Short interest indicates how many shares of a company are currently sold short – that is, borrowed and sold by investors who expect the price to decline.
🧮 How is it calculated?
It reflects the percentage of a company’s shares that are being shorted relative to the total shares available.
🏛️ Why is it important?
Short interest serves as a sentiment indicator: A high value may signal skepticism or bearish expectations – but also increases the potential for a short squeeze if prices rise unexpectedly.
🧮 Calculation
🎯 What does this mean for investors?
- Low short interest usually indicates market confidence in the company.
- High short interest can be a warning sign – or an opportunity if sentiment shifts.
- Especially relevant in volatile markets or ahead of key earnings releases.
📘 Employees
📈 What is it?
The employee count shows how many people a company employs worldwide – offering insights into its size, structure, and business model.
🧮 How is it calculated?
🏛️ Why is it important?
It helps assess operational scale, labor intensity, and cost structure. Combined with revenue and profit, it enables key metrics like revenue per employee or productivity.
🧮 Calculation
🎯 What does this mean for investors?
- A high headcount can signal operational complexity – but also significant growth capacity.
- Revenue per employee is a key indicator of efficiency.
- Especially useful for comparing tech, industrial, or service-heavy companies.
📘 Turnover per employee
📈 What is it?
Revenue per employee indicates how much revenue a company generates on average per employee – a key measure of efficiency and productivity.
🧮 How is it calculated?
The employee count is typically taken from the most recent annual report.
🏛️ Why is it important?
This metric helps compare business models – especially between labor-intensive and technology-driven companies. A high value suggests automation, operational efficiency, or strong value creation per head.
🧮 Calculation
🎯 What does this mean for investors?
- A high revenue per employee indicates a scalable and margin-strong business model.
- A low figure may reflect labor-intensive operations or lower value-add.
- Especially helpful when comparing tech companies to industrial or service sectors.
Intrusion Inc Stock Analysis
Analyst Opinions
8 Analysts have issued a Intrusion Inc forecast:
Analyst Opinions
8 Analysts have issued a Intrusion Inc forecast:
Intrusion Inc Events
Past Events
|
AUG
11
Q2 2026 Earnings Call
about one month ago
|
|
JUL
22
Shareholder/Analyst Call - Intrusion Inc.
about 2 months ago
|
|
JUN
30
Intrusion Inc., VigilAigent Corp. - M&A Call
3 months ago
|
|
MAY
14
Q1 2026 Earnings Call
4 months ago
|
|
MAR
24
Q4 2025 Earnings Call
6 months ago
|
|
NOV
11
Q3 2025 Earnings Call
10 months ago
|
StocksGuide Free
Intrusion Inc — Q2 2026 Earnings Call
1. Management Discussion
Welcome to Intrusion, Inc.'s Second Quarter 2026 Earnings Conference Call and Webcast. [Operator Instructions] Please note, this conference call is being recorded. An audio replay of the conference call will be available on the company's website within a few hours after this call.
I would now like to turn the call over to Josh Carroll with Investor Relations.
Thank you, and welcome. Joining me today are Tony Scott, President and Chief Executive Officer; and Kimberly Pinson, Chief Financial Officer. This call is being webcast and will be archived on the Investor Relations section of our website.
Before I turn the call over to Tony, I'd like to remind everyone that the statements made during this conference call relating to the company's expected future performance, future business prospects, future events or plans may include forward-looking statements as defined under the Private Securities Litigation Reform Act of 1995. Please refer to our SEC filings for more information on the specific risk factors that could cause our actual results to differ materially from the projections described in today's conference call. Any forward-looking statements that we make on this call are based upon information that we believe as of today, and we undertake no obligation to update these statements as a result of new information or future events.
In addition to U.S. GAAP reporting, we report certain financial measures that do not conform to generally accepted accounting principles. During the call, we may use non-GAAP measures if we believe it is useful to investors or if we believe it will help investors better understand our performance or business trends.
With that, let me now turn the call over to Tony for a few opening remarks.
Well, thank you, Josh, and good afternoon, and thank you all for joining us today. The second quarter was a pivotal period for Intrusion. Our revenue increased 64% sequentially, restoring the quarterly revenue run rate that we achieved prior to the ongoing delay associated with the Department of War contract extension, which we've previously discussed on our earnings call for the first quarter. And I'll cover that in more detail in a few moments. Behind that headline, we took the single most significant step in our growth strategy to date, the acquisition of VigilAigent, and we're already seeing that decision translate into tangible progress.
But before I dive into this progress and what it means for our future, I'd first like to provide a brief update on the Department of War matter that I just mentioned. The timing of this contract extension remains subject to the currently unpredictable federal funding and procurement process of the federal government, which has impacted us and many other companies providing services and capabilities to the Department of War. As previously discussed, the situation is compounded by the ongoing geopolitical situation related to the conflict with Iran.
And throughout this period, we've continued to support the critical infrastructure technology that we've already deployed, and we remain optimistic that a meaningful portion of the associated revenue will be recognized in future periods, subject to final award timing and funding approvals. And we also continue to see room to expand our solution across additional locations within the Department of War's jurisdiction. So given that the situation in the Middle East continues to remain fluid, we believe the timing of this opportunity has shifted rather than diminished, and we expect the activity to resume once the situation begins to normalize.
In the meantime, we've entered into contractual agreements with the local agencies that were the beneficiaries of our solution to provide ongoing support and maintenance. These agreements cover our ongoing cost for support, do not include additional expansion or added capabilities.
In addition, as you've no doubt read in the news, water and other local utility systems across the Continental U.S. have been attacked and compromised by nation-state adversaries. And our solution is specifically and ideally suited to protect these facilities from compromise. We are actively engaging with the appropriate agencies and authorities to raise awareness for our solution and demonstrate how we can help address their needs.
Now turning to a more recent win that shows that our growth strategy is working. As we discussed on our last earnings call, we were able to secure a $4 million annual contract to deliver our cyber threat intelligence and critical infrastructure protection product to the State of Texas. This contract win was a direct result of our efforts to enhance our federal, state and local sales efforts and our broader go-to-market strategy. Revenue from this contract started to be recognized during the second quarter and will continue through the remainder of this fiscal year and into fiscal year 2027.
Through our initial work with the State of Texas, we've identified additional opportunities for Intrusion technology and consulting services that we expect will generate additional revenue beyond the current contract levels. And based on our success in Texas, we are using the framework from this engagement to secure additional contracts across other U.S. states and territories.
Our P.O.S.S.E Program delivered through our partnership with PortNexus also continued to gain some well-received exposure during the quarter. I personally attended one law enforcement trade show here in Texas, where we jointly presented the MyFlare Alert and Intrusion solution, and I personally saw the enthusiasm in the attendees' responses. We jointly presented this solution at many other events over the quarter, and we saw similar levels of enthusiasm. We view this program as an important high-margin channel into the public safety market. And while there wasn't significant revenue in Q2, we expect its contribution to build over the coming quarters.
And just yesterday, PortNexus announced its partnership and integration work with a computer-aided dispatch solution that is already installed in hundreds of law enforcement agencies in the Midwest, furthering our opportunities to serve this community and the schools within their jurisdiction. And while it's a complex sales process, I still see strong potential for this solution in the long run.
Now finally, I'd like to address our recent acquisition of VigilAigent. But first, let me provide some context. Cybersecurity is undergoing one of the most significant transformations in its history. AI is dramatically reshaping both offense and defense and poses significant internal risks for most organizations related to the protection of sensitive data, privacy and trade secrets. Organizations today face increasingly sophisticated AI-driven threats while simultaneously confronting growing complexity, limited cybersecurity talent and rising demands to protect critical data and operations.
As a result, customers are looking beyond stand-alone security products towards integrated platforms that combine artificial intelligence, leading-edge threat intelligence, managed services and trusted long-term partners capable of delivering measurable security outcomes. It's our belief that these industry trends are reshaping the cybersecurity market, and they've also shaped the strategic decisions we've made at Intrusion. Our objective is not simply to participate in this changing market, but to build a stronger company positioned to compete and create long-term value as the industry evolves.
With that objective in mind, we announced the acquisition of VigilAigent, a managed security service provider, to create an AI-native cybersecurity platform. The acquisition of VigilAigent is a significant step forward for Intrusion and a natural evolution of our growth strategy. The addition of VigilAigent adds significant shareholder value as the business immediately adds approximately $3.5 million of annual recurring revenue that is supported by a diversified base of multiyear customer contracts.
Building recurring revenue has been a strategic priority for Intrusion over the past year, and this acquisition immediately accelerates our strategy and gives us access to an expanded ecosystem of customers and channel partners that we previously did not have access to.
The acquisition also brings together complementary technologies, experienced cybersecurity professionals, proprietary threat intelligence and managed detection and response capabilities. Most importantly, the VigilAigent and Intrusion technical teams are working together and have created some exciting brand-new capabilities to detect, manage and remediate threats associated with the use of AI by insiders as well as malevolent actors. This is the new battle space, and it is the most important area of focus in the foreseeable future, and we intend to be on the leading edge of that fight.
Now as we noted on our M&A call a few weeks ago, we plan to market and sell the Intrusion Shield platform through VigilAigent's commercially oriented organization. As a result, you'll see some changes in how we bring Shield and our other technologies to market. Intrusion will continue to serve the U.S. federal government and large institutional partners, including public federal, state and local institutions and provide those customers with its customized and highly tailored technology and consulting services, while VigilAigent will operate as a dedicated business unit within the intrusion organization. VigilAigent's focus will be on the commercial market space. We think this segmentation will accelerate our growth and allow for more effective sales and marketing efforts in these businesses.
In fact, we've already begun to see the acquisition yield positive results since being acquired a few short weeks ago. This progress includes securing over $350,000 in annualized new business and customer renewals, signing several new strategic MSP partners, each with the potential to generate more than $1 million in annual recurring revenue as deployments ramp. We've identified more than $3 million in annualized cost synergies through integration and operational efficiencies. We've expanded our strategic foundation with enhanced AI capabilities, managed security expertise and a much broader commercial platform.
These accomplishments are only the beginning. Our objective is not simply to integrate 2 organizations. It's to build a platform that can innovate faster, serve customers more effectively and create durable value over the long term and achieve our goal of transitioning Intrusion to profitability in 2027. We're extremely excited about this acquisition, but we recognize that transformations require disciplined execution, accountability and sustained performance. And these principles will continue to guide every single decision we make.
Now before I turn the call over to Kim, I'd like to remind our shareholders of our upcoming Annual Meeting on August 27. This year's meeting matters more than most as it includes several important matters, including Proposal 3, which asks shareholders to approve the potential issuance of Intrusion common stock above NASDAQ's 19.9% threshold pursuant to the membership interest purchase agreement involving VigilAigent. I encourage you all to please review the definitive proxy statement, vote every eligible account that you own and submit your voting instructions as early as possible. The Board of Directors unanimously recommends that shareholders vote for each director nominee and for Proposals 2, 3 and 4. We thank you for your support and your participation.
And with that, I would now like to turn it over to Kim for a more detailed review of our second quarter financial results. Kim?
Thanks, Tony, and good afternoon, everyone. Second quarter 2026 revenue was $1.5 million, up 64% sequentially and down 22% from the prior year quarter. The year-over-year decline primarily reflects the continued delay in the Department of War contract funding, while the sequential improvement included revenue from the new contract with the State of Texas.
We anticipate continued improvement in our revenue performance throughout the remainder of 2026, driven by the sales of our critical infrastructure solution to additional U.S. government agencies and commercial markets, further expansion of our partnership with PortNexus, revenue recognition from our recently awarded contract to provide cyber threat intelligence and critical infrastructure protection to the State of Texas, the addition of recurring revenue from the VigilAigent acquisition, increasing commercial subscription revenue as newly signed channel and strategic partners roll out our solution across their end-user customer base, and opportunities to extend our cyber threat intelligence and critical infrastructure protection offerings to other states that have established and funded cyber commands.
Second quarter gross profit margin was 66% compared to 76% from the prior year period. The decrease was primarily attributable to changes in revenue and product mix. Operating expenses in the second quarter of 2026 totaled $3.4 million, a decrease of $0.8 million sequentially and an increase of $0.1 million year-over-year. The decrease when compared to the first quarter relates primarily to the timing of audit fees, increased allocation of costs to cost of sales for work performed under the new State of Texas contract, and increased software development costs. The second quarter increase on a year-over-year basis reflects stepped-up investment in sales and sales support personnel, trade shows and enhanced brand and product marketing initiatives.
Net loss for the second quarter of 2026 was $2.6 million or $0.13 per share compared to a net loss of $2 million or $0.10 per share for the second quarter of 2025. The increased net loss in the 2026 period was driven by a decline in revenues, primarily due to the delay in incremental funding under the DOW contract.
Turning to the balance sheet. From a liquidity perspective, on June 30, 2026, we had cash and cash equivalents of $0.2 million. During the quarter, we entered into 2 separate note purchase agreements with Streeterville, pursuant to which we sold notes payable with an aggregate original principal amount of $3.7 million for cash proceeds of $3.3 million. The financing was undertaken to support ongoing operations and address short-term liquidity needs resulting from a delayed payment from a long-term government customer as well as increased operating losses associated with the delay in funding on the DOW contract. Looking ahead, we plan to continue to pursue additional capital through public or private financings, including the use of our at-the-market, or ATM, program.
With that, I'd now like to turn the call back over to Tony for a few closing comments. Tony?
Thank you, Kim. The second quarter of '26 will, I think, stand out as an inflection point for Intrusion. We entered the year focused on building recurring revenue, broadening our commercial reach and staying at the front edge of AI-driven cybersecurity. And with VigilAigent now part of the company, we've taken a real step towards all 3.
We're building a stronger platform that serves customers across both commercial and government markets at a time when the threat landscape is expanding very quickly. The early results give us confidence in the strategic rationale, and our focus going forward will continue to remain on disciplined execution as we transition toward profitability and create value for our shareholders.
And I'll close where I began by asking those of you who held shares as of the June 30 record date to vote your proxy ahead of our August 27 Annual Meeting. Your participation matters to this company's next chapter.
And with that, I'll now turn the call over to the operator for Q&A.
[Operator Instructions] Our first question is from Edward Woo with Ascendiant Capital.
2. Question Answer
Yes. Congratulations on the acquisition. My question is, is the team fully integrated? I know you mentioned that you guys are already developing products and you guys are already doing -- making sales pitch. Have you feel that the integration is pretty complete?
Well, yes, let me describe what I mean by integration. So in terms of our commercial customers, what we sold prior to the acquisition was just Shield. And now what we can do and have done in a couple of cases is offer our customers not only Shield, but also the services and capability that VigilAigent has traditionally offered. And in a few of those cases, that additional capabilities mattered both for renewal or, in some cases, for a new contract. So the teams have been working together in that regard. And the combined offering is a pretty compelling offer at this particular point.
As I said, though, on the call, we're going to operate VigilAigent as the commercial front end and go-to-market for our capabilities. So VigilAigent will include -- their offerings will include some aspects of Shield where it's relevant to their market. And for these larger government sort of custom consulting projects that involve things beyond Shield or beyond the capabilities of existing VigilAigent technology, we'll sell and market that through our traditional Intrusion sales force and channels and so on. So you should think of it as sort of commercial and then on the other hand, the customized, highly tailored larger contract kinds of modes.
Have you worked with VigilAigent before the acquisition?
We hadn't worked directly with them, but we did look around as we were considering the opportunities in the market. And what impressed me was their skill set that they had already built in terms of AI capabilities. They're, what I would call, an AI-native managed service security provider. They're not a company that has an old set of stuff that they're trying to add AI on to. They've started with a bias towards artificial intelligence right from the get-go, and that provides a whole bunch of strategic advantages. So we're pretty excited about that sort of positioning, if nothing else.
That sounds good. And my last question is on future M&As. Should we be expecting you to be possibly announcing future acquisitions?
Well, that is part of the strategy. We think in the market space that VigilAigent operates in, which is the managed service security provider space, there's already signs of massive consolidation going on. And because of their speed and cost advantages and efficacy advantages because of their approach, there's many, many, many opportunities for inorganic growth, but we also expect to grow organically. So it's a combination of the 2.
The next question is from Howard Brous with Wellington Shields.
Tony, can you discuss PortNexus and where you stand? And what are the opportunities?
Sure. So we're deployed in, let's see, 1, 2, 3, 4, 5 counties in Texas, 2 in Iowa, and 1 in Missouri during Q2. And as I mentioned on the call, we've been doing a ton of trade shows in Q2 and early Q3. And as I said on the call, the enthusiasm level of the trade shows is super high. So we had great exposure in Iowa to nearly half of the sheriffs' departments and school districts in the state and tons of leads that we're pursuing. So I'm pretty excited about the future for it, but it is a complex process, as I mentioned, because in every location, you got to get agreement between the school district and the sheriff to support the solution, and that usually takes multiple conversations.
As I mentioned on the call, one of the accelerants is going to be an arrangement that PortNexus just made with a computer-aided dispatch software company that has hundreds of deployments in the Midwest part of the U.S. And so it will be a simpler add-on kind of capability with that arrangement versus having to start from scratch. So that, I think, is a very positive development just announced earlier this week. And I expect there'll be more of that kind of thing where we'll have further integrations that should speed up our deployment and widen the opportunities here.
We're both pretty small companies. So covering every school district and every county and every sheriff's department in the country is a monumental task. But with some of these partners, we think we can accelerate faster. So pretty excited about that.
Can you give us a sense of the opportunity, say, for 2027 in terms of PortNexus?
Hard to dimensionalize exactly, Howard, because it all depends on decisions that the school districts and sheriffs' departments make. But I expect that in '27, it should start to contribute meaningful revenue that we can talk about. That would be how I would dimensionalize it. Right now, it's not that interesting to talk about for Q2, but more later this year.
[Operator Instructions] The next question is from [Jerry Yanowitz], private investor.
Tony, you mentioned several times combining the offerings, integrating the 2 firms. In terms of the increase in the ARR, the $6 million and subsequent increases in annual recurring revenue or cash flow, given your combination of the companies, how do you plan to differentiate what's due exclusively due to the VigilAigent? And what was due to the traditional Intrusion side of the company in terms of qualifying the...?
Yes. Both are recurring revenue subscription-based activities. So it's pretty easy for us to track. The only tricky part will be if we do a combined offering or if we embed some Intrusion technology directly into the VigilAigent agent offering versus a stand-alone line item, if you will. And we'll just have to have some internal transfer pricing for that kind of sale. But it's not a huge challenge in that regard. Well within our capabilities.
You did mention combined offerings in your presentation. That's why I was asking.
Right. Yes. No, we expect that we'll have that as well.
All right. And my second question is the unregistered shares that VigilAigent agent is getting. When are those shares going to be registered and eligible for sale?
They will be eligible for sale after holding 6 months. So that's pursuant to Section 144. They need to hold them for 6 months, and then they can be sold.
And you haven't put any additional requirements on those shares internally?
There are no additional requirements on those shares. No.
All right. And Tony, you've talked about in the past being cash flow positive by the fourth quarter. Do you anticipate being cash flow positive every quarter next year?
I would say at this point, in '27, I can't tell you exactly the week in the quarter, but we expect to be cash flow positive in '27. And I think I'm thinking earlier rather than later.
So you're not committing to be cash flow positive in the first or second quarter of next year?
Well, it depends on whether you're talking about run rate or for the full quarter, and that's a much more detailed discussion. So -- but we're definitely headed in the right direction there.
Am I not correct that previously, you said the run rate by the fourth quarter would be cash flow positive?
We're still aiming for that, but it won't be cash flow positive for the fourth quarter, more than likely.
So do you want to commit to a quarter when you will be cash flow positive?
Well, I don't want to commit. But my goal is Q1.
At this time, there are no other questions in the queue. I'll turn the call back over to your host, Mr. Tony Scott, for closing remarks.
All right. Well, thanks, everybody, for your participation. As I mentioned during our call earlier, it's very important to vote your shares. This transformation and vote will enable us to carry on the mission to achieve the goals that we've talked about.
I'd also like to just mention that the work done by our teams, both on the VigilAigent side and on the Intrusion side, has been stellar over the last week and months, hope to get the deal done. And then once the agreement was signed, everybody has leaned in heavily and well, and the teams are working extremely well together. So from that perspective, I couldn't be happier.
We recognize we've got a bunch of work to do, and we're working hard at it. But I did want to acknowledge that our teams have just really stepped up and leaned in and helped us get to where we are, and that gives me great confidence for where we're going. So thanks for everyone's help, and we'll talk to you next quarter.
This concludes today's conference, and you may disconnect your lines at this time. Thank you for your participation.
Intrusion Inc — Shareholder/Analyst Call - Intrusion Inc.
1. Management Discussion
Well, hello, and welcome to our webinar today. I'm pleased to share with you a preview of things to come as well as the results of some of the work that we've already done with the team from VigilAigent, our recently announced acquisition. Please see the forward-looking statement message now displayed on the screen. I'll spare you the reading of this statement in the interest of time.
Joining me today is Mark Porter, President of VigilAigent, a key member of our Intrusion management team. And you'll hear a lot more from Mark in a moment. And also on the call with me is Blake Dumas, our VP of Engineering.
Now just a bit of a preview of our go-forward business plan. In terms of addressing the commercial market, we will market, sell and support our commercially oriented Shield offerings primarily through the VigilAigent team and brand. And we'll also integrate selected Shield capabilities into existing VigilAigent technologies to enhance the effectiveness, speed to alert resolution and reduction of false positives.
This latter issue being one that plagues nearly every cybersecurity team. And the VigilAigent team is already very good at this, and the inclusion of Intrusion technology will help make this even better. And finally, we've been working hard to take advantage of some synergistic opportunities that naturally occur in situations like this.
And I'm pleased to report that we've identified and have implemented nearly $3 million in annual cost of doing business savings between the two organizations that we'll take advantage of going forward. And on that, we'll say more about that -- those efforts in our Q2 earnings call. Now let me turn it over to Mark for a peek at some of VigilAigent's technology offerings, business strategy and why these things matter in today's cybersecurity space.
Mark, over to you.
Thank you, Tony. Thanks to everybody for attending. We appreciate your time, and we're going to try to make this as useful as possible for you and get you some useful information and get over to the question-and-answers section as quickly as we can. And as I said, make it really as much as possible about you. Just a quick word on what is VigilAigent. VigilAigent is really about the combination of human vigilance with agentic AI and what virtual agents can do.
As we go forward, as Tony mentioned, our commercial go-to-market strategy will be built around the VigilAigent brand and leveraging all of the strengths of what we've built with the Shield technology and some of the capabilities that it brings. We are a truly agentic AI-native cybersecurity solution. And what we've really built now is the security fabric for enterprise that allows for any customer anywhere to plug into an open ecosystem that will be able to be built upon as their cybersecurity strategy and really as part of their business strategy as they move forward.
I'm going to talk a little bit about how the market is changing and a little bit about why we're doing what we're doing. What we see time and time again and what we hear from partners and customers is they want more visibility. They want fewer tools. They want an integrated ecosystem. And when you look at the attacks that are out there that have been driven by AI, and there's a couple of big ones in the news in the last 24, 48 hours, they understand how the tools work and they do everything they can to defeat existing security tools. So we must be more vigilant as we go forward.
We must be more focused on eliminating gaps and cracks between the tools. And that's why we're doing what we're doing. We'll talk a little bit about how it works later. A little bit about the concept of the Security Fabric for enterprise. We really believe that data is absolutely essential and taking telemetry from every element of the attack surface is more critical than ever. All of that said, as we look at the future and stop solving for all of the problems of the last 15 years and start looking at the problems of the next 15 years, there's a couple that are really on everyone's mind right now and really challenging problems.
At the end of the day, this call is about why the rationale for this business and what we're doing to go forward that's going to give us leverage and give us business advantages. When you parlay the security fabric that we've built with the Shield capabilities and you start looking at how we can detect use of artificial intelligence, not just in attacks from the outside, but how we can detect against it from use on the inside.
The major problems that are plaguing clients are that these virtual agents, these automated agents can do things at a pace that is not even close, can't be matched at all by humans. They can take massive amounts of data. They can jailbreak. You're hearing about all of these things. So we need to be able to know when AI is present in both authorized fashions know what it's being used for and then understand when it's not being used normally and when it's accessing things that it can't normally access.
We also need to know when shadow AI is being used, simply employees putting your information into browsers, into apps, into all sorts of ways that they're using company information and leaking it out there into the ether or training other people's models on your intellectual property. So these solutions are going to present -- these challenges are going to present a need for more complex solutions. And with the Shield technology, we gain massive amounts of enrichment.
So it's really critical. We've already demonstrated capabilities of being able to detect these sorts of things and demonstrated capabilities to be able to put them into the common back end of our system, which will allow for scalability and ongoing cost reductions around the management of the integrations of these solutions.
So as we look forward, the single biggest piece that we see collectively is that we're going to be able to help our clients, our partners and their clients see around the corner, so to speak. We're going to be able to detect things that others can't and provide increased value. Now we're going to shift and talk a little bit about the Oracle. I'm going to actually show you the Oracle at work in a little bit. The Oracle is the core of our digital fully agentic workforce.
The Oracle is able to go beyond what the traditional security solution providers can do, which is they can see things and they can create alerts. We're able to see -- we see over 1 billion events a day at this point. We've trained the Oracle on all of this data. It's been up and running for about a year now. It's been in production for almost that long. It's able to see things, it's able to make decisions, and it's able to act.
That action could be escalating to a human, that action could be response capabilities that there's a ton of actions as we move to a world where cybersecurity requires virtually immediate action -- the shortest mean time to conclusion and the shortest mean time to detection and response is absolutely critical.
About two months ago, CrowdStrike came out with their annual survey that showed a mean time to breakout, the time at which the bad actor decides to go from working in the environment to taking action has decreased to under 30 minutes. It's around 27 or 28 minutes, and the fastest they saw was 24 seconds. We do not stand a chance with human beings at 24 seconds. We barely stand a chance at 24 minutes. So we must get to conclusion very quickly, we must take action.
Now beyond the cybersecurity piece of it, this is where our competitive advantage starts to take hold. The Oracle gives us a 99% cost and reduction per alert. It gives us scalability without being linear in terms of adding humans for every dollar of revenue. As our business scales, as we generate more revenue, we do not need to add humans in the security operations center in the way that traditional SOCs do. Because we moved quickly and swiftly starting about 18 months ago to start making this happen, we are now in a position where we have gained a competitive advantage, a technology advantage, a training advantage in terms of what our AI can do.
And as we look at the world today, while there may be a reckoning coming in the AI market in general, it's really important to understand that the AI market is segmented into 4 or 5 different types of companies that are leveraging it. And we're in a scenario where a reckoning around the high end, around the token model and the collapse of that market actually benefits us and will further reduce our cost as we go forward as opposed to creating increased costs for us.
We're going to jump quickly into the technology and show you a couple of things about how it works. I want you to understand, I'll give you kind of a quick overview of what you're going to see. We're going to show you how signals come into the systems. We're going to show you what it would take for an analyst to look at all of this data. It's really overwhelming. And we're going to show you how we move from that detection to a decision very quickly.
And we're going to show you what an analyst actually sees, and then we're going to show you how an analyst can actually leverage the Oracle even after it's made a preliminary decision and how we can not eliminate human beings in the security operations center, but make our staff, our team the best human beings and how one individual can do the work of 10 to 20 individuals by leveraging the technology and the competitive edge it brings. A couple of pieces about what you're going to see.
We've been very, very clear with our partners and our clients, and it's really, really critical that we are fully transparent with them on how it all works, that we have very, very detailed security logging on all of this, audit trails for everything that happens and the ability to go and look at everything that's going on, on every single alert they do because the security provider role in their organization is about the most trusted role in all of this. I'm going to stop sharing here, and we'll come back to that in a moment and switch over to the tech second for the lag there.
Okay. So it looks like my screen is properly displaying. What you are looking at is what a security alert looks like in a tool that we've built called our OMNIQ. We believe it is absolutely essential to bring all of the information from all of the systems when an alert has fired and correlate it against everything possible to give our team the best fighting chance to create an outcome for the customer that's a positive outcome. So when you look at what's happening, you'll see that all the details related to a ticket from every system in our ecosystem have been brought across. This is called raw JSON.
And I'm only showing you this because it's difficult to read, difficult to understand, and that's what the humans have to look at. We've created our audit trail right here, so you can see that everything that's happened on this alert has been looked at. And I'm going to show you a couple of key statistics here. This time to first action, absolutely critical. This is the first human action in 9 minutes on a relatively modest alert, very common place.
The entire investigation and that action took 15 minutes and all of the details related to it are tracked below. This was for a false positive. So we spent all that time on something that was not even real. We present -- actually, I take it back. It was real. It's an anomaly. The question is whether it's benign or malicious.
And we determined that it's benign. We bring all related alerts in the last 30 days, all the customer details, which I'll skip over, all tickets related to the customer in the last 30 days and the Oracle decision engine, which this is for our tracking, which would show why it sent it to the security operations center or not and what the rationale was. And this is all done so that we can continue to improve its learning and its capabilities.
And here, we give the analysts all of the capabilities that they would need to respond by pressing one of these buttons to some of the most common processes. All of that has really created some tremendous efficiencies for us on the backside of this and is allowing us some key business drivers that we'll discuss after this. But the real magic is what happens here. I showed you that the Oracle has already scored.
It looks at every single alert has already scored it, made a decision as to whether to send it to the SOC or not. If I were an analyst, I would know exactly what to ask the Oracle, but I'm not. I don't know what most of that JSON means. So I'm going to ask the Oracle simply what should I do? Typically, in about 4 to 6 seconds, the Oracle will give me step-by-step instructions on how I should handle this specific incident. It will recap what happened and what its decision was. It's already closed.
So in this case, it tells me that I don't have to do anything right this second, but it walks me through what happened. This is a particular issue, and it gives me the rationale as to why it was dismissed. Now at this point, the Oracle is looking not just inside the organization, it can be looking outside the organization for enrichment from other sources.
Each Oracle consists of about 5 to 7 sub- Oracles that run specific processes, use large language models specific to the task and then verification agents that actually verify the answers and if they like it, allow it to pass, if they dislike it, make it go rework the action. It is then put back together and put into the notes for an analyst, which we'll go back over here. So there is both a customer view and an analyst view that is provided, and they see all of this right upfront and all the detailed work that it already did before I asked it that question of what should I do?
So if you'll notice over here, it's asking me if I need to verify or take action. and it will often give me suggestions and say it's closed, and none is required. Now it's asking me if I'd like to search for related alerts or check the history of the rule. I'll ask it to search for related alerts, which is what an analyst might do while they are looking at this and before it's been marked false positive.
And now it's going to take the knowledge of those 1 billion events per day that we're seeing and all the history that's logged in the data lake, and it's going to look back on that and have not only the benefit of all the machine learning and AI applied by every one of the tools, but it's going to have the real-life knowledge of all the humans and what we did with it. And you can see the amount of information that it's given me in this look back. It's found alerts for the user. It's found alerts related to the IP address.
It's found alerts related to the rule. So it's looked across all of the data lake of all the nearly 1,000 customers, all of the feeds that it's getting, all of the information -- and then it's asking me, would I like to pull the analyst notes from a true positive alert to see what indicators made it malicious. Simply give it a yes.
Now it's able to go and pull notes without having to look up tickets, without having to look up past incidents in two prompts, I've gotten to a place where I can look and I can either improve my own skills or I can be 100% certain that this is a false positive. So you'll see here, it's starting to tell me key takeaways. It's a legitimate tool. It's a backup admin granted broad permissions as expected behavior. It's integrated with Azure AD.
Now -- the specific case referenced above shows that the rule does catch real threats when all of these conditions are met. The current alert is safe in three prompts in about 15, 20 seconds, which would have been faster if I wasn't narrating, it has basically told me definitively that this is true. If I wanted to tune the rule, I could ask it to tune the rule or create filters, and it would give me all of the details that I would need, which I could then send off to the dev team to QC and put into production if it needed to be -- needed to be tuned. It may actually tell me in this case that it doesn't.
We'll see what it says and then we're going to move on. So -- you'll see here, it actually tell me to whitelist the app and here's how to do it. It gives me all the scripts that I would need to do it. So exclude verified integrated apps as the highest impact. So now I could gain an efficiency in the SOC and create higher customer satisfaction because as Tony alluded to, false alerts are the bane of security operations team's existence as well as something that customers view as our job to eliminate.
Now I'm going to show you some other functionality of the tool very quickly. Actually, I'm going to click over here, and I want to show you -- as we alluded to in the slide, I want to show you some real-life statistics. We have 2 minutes and 37 seconds is the average time it takes for a decision to be rendered by the Oracle. It's run 4,436 jobs in the last 7 days for $276. The rough equivalent in human terms would cost at least $24,000, more likely closer to $50,000 in human cost to get this done, depending on the time it takes.
We have full governance over the back end. We can see any jobs in flight here. You see it says there are running, you can see them actually processing. And then when we go down the jobs that have already processed, I can look at any individual job, I can pull it up, and I can look at every single process that was run down to the millisecond. I can look at the number of tokens used and the amount of cost associated the decision engine.
And as you saw in multiple different views, this is where the customer-facing and the analyst facing is made. And when the analyst is working in this, they actually score this if they see the alert, thumbs up, thumbs down. If they thumbs down it, they will write notes as to why they disagree. So we're actually able to tune and continually improve the decision-making of the Oracle.
Finally, I'll show you the last piece of this. I've actually started this process here. If an analyst, I showed you where an analyst would be able to hit a response action. The beauty of a fully agentic system and being native in everything that we do is that there are two ways that an agentic agent can take response actions. We can take response actions directly into certain tools or we can build workflows for them.
We might have to teach and train it and create hooks and ways for it to tie into different systems. In this case, I've asked it to build a workflow to disable a user from Microsoft Entra ID when it sees 15 failed attempts, followed by one successful attempt to log in. You may ask why, just for little knowledge, I don't really care about the 15 failed. I only care if they get in. We've got tools and devices that are out there to block these things.
If they've gotten in the network, I wanted to do that, then I wanted to create a ticket and notify the partner as well. So we've taken -- in that case, we would have taken action, we would have created a notification to the partner, the client whoever needs to be notified. Now you'll see that it's asking me that it needs clarification on how it would -- how I would like it to connect to certain things.
I'm going to give it some answers, hopefully, the right ones. Let's do that one. And we'll see if I got the answers to the quiz right here. If it likes what I have done and understands what I now need, it will tell me what it wants to build and ask me if I want it to build this workflow. This process, it apparently does like it. So I'm going to hit apply to changes. And I've now built a workflow to do those things. This would have taken hours, days, weeks, depending on the complexity and the scenario.
We had workbooks that were up to 3,800 steps. If I looked and said, I like this, but I want to run an AI agent in here. I can actually connect that into the workflow. I had one gentleman asked me, how do I know this isn't just a bunch of pretty boxes because the code is fully built over here and you can review it and edit.
Now I wouldn't put this into production myself if I were an analyst, I would send this off to our dev team for quality control and testing, which in case you didn't notice or the window is too small, down here at the bottom, it actually suggests the test, and I can run the test from here.
In this case, our QC team would do this and deliver on that. Get out of the tech, flip back here real quick. Okay. I want to recap and shift back to the business side of this and talk about the drivers as we go forward as we see them. We're very excited about what's happening. We've had really, really tremendous response from both the Intrusion partners and the VigilAigent partners.
We've seen extremely high interest in inbound demand for licensing the digital workforce as a platform. We are currently moving to test this with a third-party solution, Google SecOps, a little known company called Google. We will integrate the digital workforce directly with SecOps as a second stage of this potential partnership with a legal tech company. It's a very exciting opportunity for us. We've seen a number of others that have asked us to integrate with their platforms as well.
So that takes everything that we've capitalized on the technology side and moves us into a completely different kind of revenue stream of licensing the digital workforce and the capabilities and supporting them without the full managed detect and response. So we're excited about that. We've seen expanded revenue opportunities from existing partners and customers. And I talked earlier about this, but I can't stress enough.
The newest frontier in cybersecurity is going to be an AI-agnostic detection capability across enterprise for both inbound attacks as well as legitimate use. legitimate tools being used for malicious purposes is one of the most complicated products. With the Shield solution as part of our VigilAigent solution, we now have technology for what we call the religion of the agentless, all those IoT devices, critical infrastructure.
We've really bolstered our solution capability set around that. AI is very, very hard to detect what is happening to your data. We're going to be able to do that because we get a tremendous amount of visibility into network traffic now that we didn't have before or we couldn't look at in the same ways. And we're going to be able to help customers see around the corner.
All of these things are looking -- are really leading to tremendous opportunities in organic growth on the commercial sector, tremendous opportunities in the inorganic mode because we can get a fast ROI as we ingest whatever tools a target may have, bring in their tools, bring in their data, we don't necessarily need to expand the footprint of our human resources in those security operations.
So these things, all of this technology at the end of the day, we feel very strongly gives us competitive advantages to our sales team, competitive advantages to our biz dev team that's going to be looking to inorganic growth, as we've stated before, and really positions us well as the AI market creates tremendous opportunity for disruption. What I like to talk to our partners about and our team about is in a brave new world where the tools are going to be free, nearly free or very custom where you can build your own operating system for your own business as opposed to the 80% software rules.
In that sort of world, teams that are agile and quick and wield those tools better than others and find new novel ways to monetize those capabilities are going to be the winners. We have our distribution network in place. We are expanding that distribution network. We've signed multiple new partnerships, and we're seeing really significant growth opportunities with new licensing opportunities, not just of the workforce, but the data as well.
With that, I will turn it over for questions to you guys.
All right. And we're happy to take questions. So -- yes. Just a second, while that happens.
In the meantime, there should be a Q&A button if you'd like to submit it or any, Q&A button at the top of your screen.
All right. Everyone should be able to unmute themselves and turn your cameras on if they would like.
Yes, please raise your hand if you have a question, hit the raise hand button.
It may take people a moment to find button or where to unmute.
I know I didn't do a good enough job explaining it all. So I can't believe there's no questions out there, but yes.
Question at the top of your screen but -- well, Mark, I think you did a phenomenal job because there's no questions. But if you have some after this is over, feel free to contact us. I'm [email protected]. Mark, your e-mail address?
[email protected], that's V-I-G-I-L-A-I-G-E-N-T. Please feel free to copy us both and questions are really genuinely welcomed. So thank you very much for your time.
All right. Let me just summarize to wrap up. I think what you've seen from the VigilAigent team is a really cool demonstration of using AI to do the necessary work that happens every day in a security operations center very fast, very accurately with a lot more information that enables just a lot better decisions and quicker response.
The other thing that excited me when I first met the VigilAigent team was the visibility that you get as to cost and also what the AI agents are doing. In many cases, AI is just a black box. You sort of put things in and you get an answer back and you have no idea how it's working. And I think the VigilAigent team has done a great job of not only using AI, but using it to explain to a human what it's actually doing and how it works.
And then as you saw in Mark's demo, the ability to make constant improvements and corrections as new information is discovered or better methods are determined. So I think all of those combined together make this a brave new world for both cybersecurity in general, but certainly for Intrusion and our VigilAigent team combined.
So I want to thank everybody for joining with us today, and you can look forward to more in the next few weeks. We'll share more in our Q2 earnings call in a couple of weeks. Thanks, everybody.
Intrusion Inc — Intrusion Inc., VigilAigent Corp. - M&A Call
1. Management Discussion
Welcome to Intrusion, Inc.'s Special Update Call. [Operator Instructions] Please note, this conference call is being recorded. An audio replay of the conference call will be available on the company's website within a few hours after this call. I would now like to turn the call over to Josh Carroll with Investor Relations.
Thank you, and welcome. Joining me today are Tony Scott, President and Chief Executive Officer of Intrusion; Kimberly Pinson, Chief Financial of Intrusion; Bobby Mikkelsen, Chief Executive AI Agent of VigilAigent; and Mark Porter, Chief Revenue Officer of VigilAigent. This call is being webcast and will be archived on the Investor Relations section of our website.
Before I turn the call over to Tony, I'd like to remind everyone that statements made during this conference call relating to the company's expected future performance, future business prospects, future events or plans may include forward-looking statements as defined under the Private Securities Litigation Reform Act of 1995. Please refer to our SEC filings for more information on the specific risk factors that could cause our actual results to differ materially from the projections described in today's conference call.
Any forward-looking statements that we make on this call are based upon information that we believe as of today, and we make no undertaking or no obligation to update these statements as a result of new information or future events. In addition to U.S. GAAP reporting, we report certain financial measures that do not conform to generally accepted accounting principles.
During the call, we may use non-GAAP measures if we believe it is useful to investors or if we believe it will help investors better understand our performance or business trends. With that, let me now turn the call over to Tony.
Thank you, Josh. And I wanted to say, first of all, welcome Bobby Mikkelsen, Mark Porter and Kim with me here on the call today. We've been working with the VigilAigent team for a couple of months now. And as we've gotten to know them and also the technology that they have put together, we've gotten more and more excited about the possibilities of these two teams working together. So as you saw from our press release last night, we've completed the acquisition of VigilAigent, which is a cybersecurity managed service security provider from Tego Cyber.
It's a done deal. It's not pending, although we'll have a -- we acquired 60%, and we'll acquire the remaining 40% later in August, pending shareholder approval of a proposal that we'll have for our annual meeting. You might want to know why this and why now. What I would tell you is that AI is completely reshaping the cybersecurity landscape.
It's lowered the cost, the expertise and the time needed to launch sophisticated, scalable attacks by the bad guys, and we're seeing it every single day. And customers need solutions that get ahead of those threats. And with this acquisition, we will deliver to the market exactly that capability. The same things that are helping the threat actors be more quick and responsive are tools that we can use in our defensive capabilities.
And so all of this is a natural evolution and a meaningful step for both attackers and also those who are defending. In terms of the deal, it immediately adds about $3.5 million in annual recurring revenue from a diversified base of multi-year customer contracts. This is recurring, not contract revenue and not one-time. And as I think our long-term shareholders know, we've been trying to build that ARR now for more than a year with, in our case, somewhat limited success, but this gives us a brand-new vehicle for reaching a whole bunch of new customers that we've not been able to reach before.
They also bring an established commercial network, 80-plus reseller partners and 1,000 customers. So it's an instant expansion of our commercial reach and distribution. And because the deal is closed, the benefits are immediate. Top line contribution and reach begins day 1. And we also plan to, for commercial purposes, take all of the Intrusion Shield assets and sell those through the VigilAigent team and reach and marketing.
So you'll see some reconfiguration of how we go to market with our commercial efforts for Shield. We will still continue to deal with the U.S. federal government and our consulting work that we do through Intrusion, but both organizations, both VigilAigent and Intrusion will benefit from this combination. And I should say we're planning on VigilAigent operating as a unit, a business unit within the Intrusion framework.
The technology story, I think, is exciting. As Mark will explain in a lot more detail, their Agentic AI engine called The Oracle is now going to be integrated with our TraceCop database. We've done some preliminary work already, and we're really excited about what that can bring to customers of VigilAigent. Each of these are built on years of research and development. One of the benefits of the Oracle that VigilAigent brings is that it automates a high daily volume of threat activity. And then TraceCop adds historical intelligence on the 8.5 billion IP addresses and the information that we have about who the actors are on the internet.
And so the bottom line is faster detection, deeper visibility, more actionable protection and a stronger combined offering than either of us could have delivered alone. And not to mention new revenue streams and cross-sell across our expanded network. So I'm really excited about this. Bobby Mikkelsen and Mark Porter are just fantastic additions to our senior management team, and they'll contribute to our strategy and actions as an organization going forward.
They've already been chock full of just great ideas, and we can't wait to begin execution of those. So the enthusiasm that I have, I can't explain how excited I am about this combination. Let me turn it over to Mark for a little more detail on VigilAigent and the scene from his view. So Mark, over to you.
Thank you, Tony. Appreciate it and appreciate everybody's time here. Very excited to talk about what we're doing. And a little bit. I'm going to keep the technology as high level as possible to try to explain exactly what we're doing while also hitting on how we differentiate ourselves in the market and going forward, what the opportunity looks like. So this is a pivotal point for us as an organization as we look at the future, what started out as very much a me-too managed detect and respond business a number of years ago has evolved over the last 18 months into what is today's current VigilAigent, which is not just a managed and detect business using other people's technology, but a business that has evolved and what we've created is our own security fabric, if you will.
And that security fabric allows us to collect data across customer environments in very meaningful ways with very deep levels of insight. And then more importantly, format that data into the data lake. So as we evolved into that strategy, it means that as we see these events, we see over 1 billion events per day at this point.
As we see these events, that data comes in and is useful to us not just for detecting and responding, but has been really critical in training the Oracle, our Agentic AI solution to understand and analyze events and more importantly, as we tilt forward and leverage the data that we're getting from TraceCop and the Shield technologies that will all be very quickly merged into the OmniViz solution, which is what we call the security fabric, it will give us a level of visibility and usability on that data that starts to allow us to see around corners. As Tony mentioned, Agentic AI and AI in general has changed the landscape in cybersecurity. The legitimate use of artificial intelligence in businesses is no longer an option. It's not people experimenting. People are making multibillion-dollar investments.
Even small businesses are investing in AI. This brings a whole host of new problems, and we can no longer continue to tilt at solving the problems of 10 years ago. We have to solve for the current day problems, which is how to make sure that AI utilization in the business has the proper governance, has the proper detection capabilities, and that requires massive amounts of data and it requires action at machine speed.
So what we have really developed is a solution that allows us to do the detect and response, but our digital workforce technology around the Oracle and a suite of tools that we've built around this fabric from an operator perspective out, we're now fielding inbound demand for that technology for licensing for other purposes for very large enterprises. Other parts of the world have reached out in the last 2 weeks, which leads us beyond that managed detect and response into a more SaaS model or a more licensing-oriented model for that product.
So that's when we talk about the pivot point and the pivotal point we are at, that is one of the key elements. The other thing that's happening here because of the use of Agentic AI and because of what we've leaned into, we find ourselves in a situation where small teams are capable of winning small teams are capable of moving very quickly and developing software at a pace that nobody has been able to do in our lifetimes for sure, and it continues to evolve week over week over week.
So as we look to the future, we look to continue to capitalize on that agility. This gives us a scalability advantage. We don't need nearly the number of people, and we are not talking about -- in our security operations, we're not talking about a humanless security operations center. We're talking -- we talk about [connecting] the humans that we have and making them infinitely more capable.
We look at how to bring revenue to the table faster because each incremental dollar of revenue will now be more profitable as we don't have to scale our headcount linearly. We give you some current examples. We're running right now roughly 10,000 alerts per week that get fully analyzed by the Oracle that costs roughly $700. The rough equivalent in human terms would be $50,000 to $200,000 depending on the time it takes those alerts. We're doing it in under 3 minutes.
We're also then putting that information in a data lake and now able to use every decision made by every tool that we manage and monitor, every tool that we log and every decision made by a human being in our SOC is now indexed back into that data lake. So we're able to do it faster. We're able to do it cheaper. And when we meld the intrusion technologies into the platform, we're going to be able to look at the network layer in a way that nobody else is, and we're going to be able to do a greater degree of network traffic analysis.
We're going to be able to stop more before it gets into the detection mode, which is critical. And all of that context and inference between the 1 billion events a day that we see and the 8.5 billion database, DNS resolutions and IP addresses in that database using historical and real-time is going to allow us to morph that into a large language model that is faster and more accurate and ultimately starts to identify trends in the risk so we can find these things before they happen, find misconfigurations and traffic patterns and look around the corner for our customers because the modern architecture of cybersecurity demands that you identify risk and that you stop it before detection and response.
The use of AI by the adversaries has made the breakout time so short. It's virtually impossible to rely solely on detect and respond. So we're going to continue to evolve those technologies, and we're going to move very quickly. As Tony indicated, we've already done pretty extensive testing, and we're going to move very quickly to minimize the cost of development because we're already doing a lot -- there's already a lot of overlap in where we're going on the technology on the Shield side. We're going to be able to move quickly to bring some of that dev cost down,
increase the cycles, the speed at which we're doing the cycles and move that to market as part of a comprehensive solution, which could help us on both sides of the table, bring our solution, this combined solution to all the existing Intrusion customers outside of FedGov. It's not exactly a FedGov solution. And then conversely do some additive things as we look at AI detection modules and things like that increase our average revenue per seat as we go forward. With that, I will turn it back to Tony.
All right. Well, thanks, Mark. And I've been very impressed. I wish there was a way that we could all do a demo of the VigilAigent technology for all of you. But a couple of things really impressed me. One was the ability to show the operators and even customers how the AI agents are working. So in a lot of cases, people think of AI as sort of this black box that you put something in and then you get something out and you never have any idea how it actually worked. One of the impressive things that the VigilAigent team has done is create some visibility and transparency in terms of what the AI is actually doing and what the costs are.
And I think ultimately, that's going to be important for customers. But probably even more importantly, if you can understand what the AI is doing, you can also correct it when you see mistakes being made. And that's one of the opportunities in the AI space today is having a rich feedback loop. And I think Mark hinted at that so that you can just dramatically improve quality over time with the right kind of feedback.
So really impressive stuff, and we'll love the opportunity to show this to all of you at some point in the future. Let me close my opening remarks here with a couple of points, and then we'll take questions. First of all, I think there's tremendous shareholder value in this deal. It's immediate recurring revenue. It broadens our commercial footprint in a big way, and I think will make a big splash in our target marketplace.
I think anybody who looks at it will see a very differentiated AI platform that we've talked about at some length now and a whole bunch of great cross-sell opportunities and runway going forward. It also puts us on the trajectory for the best opportunity in the future, sustainable growth and long-term profitability. With the tools that VigilAigent brings, we can see a clear path to growth, both organically and inorganically, and we really look forward to that. I think when we have our demo opportunities for customers, they're going to be wowed by the capabilities of the united platform.
And I can't wait to share some of those successes with you on future calls. So I want to thank both Bobby and Mark and the whole VigilAigent team and their investors and our investors on their deep enthusiasm and also help in making this a success. So we'll post this on our website for anybody who wants a replay, but I'm ready to open it up for questions at this particular point. So thank you.
[Operator Instructions]
Your first question for today is from Walter Schenker with MAZ Partners.
2. Question Answer
Two questions actually. If I understood correctly, Bobby and Mark will be, not regardless of title, in charge of the non-big government opportunities for Intrusion, i.e., Guam or Texas, et cetera. They're going to run or hopefully grow the rest of Intrusion.
Yes. I think the way to think about it, Walter, is our business really falls into sort of two big groups, if you think about it today. One is the commercial space where we have MSPs and MSSPs who are using Intrusion technology, and that's clearly the space where VigilAigent plays a much bigger role than our footprint today. And so I think it makes sense for us to rationalize our offerings in the commercial space and market that and sell that through the VigilAigent sales team and so on.
So we'll reformat our marketing and even our engineering to give us the best opportunity to address the commercial space. On the other side, we have these big consulting contracts like we did in Guam or we're doing for Texas Cyber and so on. And there will be opportunities, obviously, in federal, state and local that are relevant for the VigilAigent team. But most of the government contracting we do are very tailored to specific needs that those specific agencies have and so on. So those will largely remain in Intrusion's hands.
So we've got some work to do to sort out which customers and so on will go with each team. But in general, that's our approach that the commercial stuff, even if it's a state and local government, for example, that's looking for commercial type solutions, we'll tend to want to have that managed by the VigilAigent team. So I hope that answers your question. But there's a lot of detail we got to work out over the next couple of weeks as we do a deep dive on customers and other technology synergies and so on. But that's our general approach.
And second question for Bobby and Mark, since I was unfamiliar with the parent company, can you give us just some sense of the type of growth you've had historically? And if you're not making a forecast and not expecting a forecast, but some sense as to how you look at the opportunity because $3.5 million is still less than nothing in $1 trillion, maybe multi-trillion-dollar cybersecurity market. Now combining with Intrusion and having more access, do you have any sort of broad sense is this, eventually, hopefully going to be a $10 million, $20 million? I'm just trying to get a sense of how you look at your opportunity.
Very optimistically right now, actually, given where the market is at, and thank you for the question. So as you did indicate, we're not going to give any forward-looking guidance, but we do feel like we're extremely well positioned. One of the challenges that we've had is resource constraints. And as we look to not just capital resources, but personnel resources and we look across the combined organizations, we reap the benefit of a lot of really smart people and hope to bring some agility to that as well.
So leveraging a combination of some of the intellectual firepower, a lot of the relationships that are here and present and some of the ability to do some more aggressive marketing, we're expecting pretty significant organic growth, having the Nasdaq vehicle, as Tony alluded to, gives us the opportunity to be inorganic, which when you get deep into the weeds on why that makes sense, revenue growth without adding human beings or the ability when we talk about the fabric, the security fabric that we've developed gives us the ability to ingest not just tools and data, but other organizations very quickly without having to scale the human costs in the security operations center.
If we can continue -- and we've got pretty substantial data to back, both our ability to act quickly and to scale. So we know what it looks like in terms of adding revenue versus people. It is very nonlinear. So once we move through the back half of the year and validate more of this with growth, the margins start to lever up very quickly on that recurring revenue business. And in the licensing side, where we're fielding these inbound requests now, those are extremely margin rich because we're leveraging all of the technology resources and all the things we put into growing the managed detect and response business and now seeing demand from others.
There's actually a third stream in there, which is the data and the use of that data and the monetization of that data, which is, again, minus your cost of sales, is extremely lucrative. So we're very excited about what that looks like. And as we push forward, growth is going to be key. And I think as Tony alluded to, that's what this transaction is really all about is accelerating the growth and looking to go faster from here.
Yes. Walter, if I were to summarize, I would say the advantage the VigilAigent team brings is speed, which Mark alluded to, a very significant cost advantage and a very significant quality advantage. And those 3 elements, I think, are going to be very, very attractive in the market in terms of accelerating growth.
Your next question for today is from [Andrew Brandstetter] with ABL Investments.
I was just wondering if you could briefly discuss the growth strategy. And do you see any acquisitions on the horizon that could further enhance your product offerings?
Yes. I think we see both, as I mentioned, both organic and inorganic growth. What we see happening in the marketplace right now is there's tremendous consolidation going on in the MSSP, MSP space. PE firms are jumping in. I mean everybody is in there trying to consolidate and grow market share. And with these three elements that I've talked about, speed, cost and quality, I think we have a great opportunity to do some acquisitions to grow inorganically, but also just feet on the street, shoe-leather grow organically because of the attractiveness of this proposition. We don't have a specific target in mind right at the moment, but I think that's certainly within our framework in terms of going forward. So the answer is yes.
Tony, if I could just add on to that. When you look at one other -- there's one other factor in there that I think is really important when you look at the technology, which is maturity. When we present to very technical audiences and get deep in the weeds, what they talk about is how far ahead we are. We started on this journey to what it looks like today almost 18 months ago.
So it's seen massive amounts of data, which is really important to the training of the models and the training of the virtual agents. And so the maturity of it is really a huge enabler for us as we go forward, Andrew, in terms of being able to act quickly and move to scale.
That's great. As a follow-up question, when all the cost efficiencies are taken into account, how does the EBITDA margins look as a percentage of gross revenues?
I don't think we have an accurate answer to that at the moment, but some of the modeling we've done suggests that there's great opportunities in that space. But I'd be hesitant to give you a number at this particular point because there's a lot of variables in that at the moment. It has a lot to do with product mix, volume assumptions and so on. But traditionally, in the Intrusion space, we've been in the mid-70% margins, and I wouldn't expect significant deviation from that overall in the combined entities when all said and done.
Okay. Wonderful. Well, congratulations guys, and keep up the great work.
[Operator Instructions]
At this time, there are no other questions in the queue. I'll turn the call back over to our host, Mr. Tony Scott, for any closing remarks.
All right. Well, thank you, everyone, for jumping on the call today. And I appreciate everybody paying attention to this. We've obviously attracted some attention in the market today, which is welcome. And I just wanted to publicly thank Mark and Bobby and the VigilAigent team for their hard work.
Our team, working with Doug and Kim and our Investor Relations people and so on, has done a lot of hard work over the last couple of months to make this happen, and we really look forward to the next couple of months, our shareholder meeting. We'll seek approval of the 40% so that we can conclude the second half of this. And you'll hear from us again at our earnings call, if not before. So thanks very much, everybody, and we'll talk to you soon.
This concludes today's conference, and you may disconnect your lines at this time. Thank you for your participation.
Intrusion Inc — Q1 2026 Earnings Call
1. Management Discussion
Good day, ladies and gentlemen, and welcome to Intrusion, Inc.'s First Quarter 2026 Earnings Conference Call and webcast. [Operator Instructions] Please note, this conference call is being recorded. An audio replay of the conference call will be available on the company's website within a few hours after this call.
I would now like to turn the call over to Mr. Josh Carroll with Investor Relations. Josh, the floor is yours.
Thank you, and welcome. Joining me today are Tony Scott, President and Chief Executive Officer; and Kimberly Pinson, Chief Financial Officer. This call is being webcast and will be archived on the Investor Relations section of our website.
Before I turn the call over to Tony, I'd like to remind everyone that statements made during this conference call relating to the company's expected future performance, future business prospects, future events or plans may include forward-looking statements as defined under the Private Securities Litigation Reform Act of 1995. Please refer to our SEC filings for more information on the specific risk factors that could cause our actual results to differ materially from the projections described in today's conference call.
Any forward-looking statements that we make on this call are based upon information that we believe as of today, and we undertake no obligation to update these statements as a result of new information or future events.
In addition to U.S. GAAP reporting, we report certain financial measures that do not conform to generally accepted accounting principles. During the call, we may use non-GAAP measures if we believe it is useful to investors or if we believe it will help investors better understand our performance or business trends.
With that, let me now turn the call to Tony for a few opening remarks.
Thank you, Josh, and good afternoon, and thank you all for joining us today. Our first quarter results reflect the negative impact of the previously disclosed delay in an anticipated contract extension with the Department of War, and I'll discuss that in more detail in a moment. But while these short-term headwinds to our financial results have been challenging, we remain optimistic that our financial results will see an improvement throughout the remainder of the fiscal year. This is supported by strengthening sales momentum that's already visible in the second quarter, including broader adoption of the P.O.S.S.E Program through our partnership with PortNexus and growth in our Shield installed base.
As I mentioned during our fourth quarter earnings call, we have been enhancing our federal, state and local sales efforts and broader go-to-market strategy, and we're beginning to see the early signs of these efforts paying off.
Last week, we signed a significant new customer contract, a $4 million annual contract to deliver our cyber threat intelligence and critical infrastructure protection to the state of Texas. The contract was awarded in recognition of Intrusion's unique capabilities and reflects the growing demand for our intelligence-driven approach to cybersecurity. The performance period for this contract is 12 months, during which we will work closely with the customer to deliver high standards of cybersecurity protection and operational responsiveness. Importantly, we believe that this engagement establishes a strong framework that can be replicated across other U.S. states and territories.
Now I'd like to address the delayed contract extension of our critical infrastructure technology with the Department of War. Our revenues during the first quarter were once again impacted by delays in finalizing an expected contract extension with the Department of War. And as noted on our fourth quarter earnings call, these delays were driven by operational and administrative constraints stemming from the U.S. government shutdown, which limited agencies' ability to initiate and process contract actions as well as ongoing geopolitical developments related to the conflict with Iran. Despite this delay in funding, we've continued to support the already deployed critical infrastructure technology, which is reflected in our operating expenses.
We expect to recognize revenue from this effort in a future quarter and remain confident in expanding our solution across additional regions with the Department of War throughout 2026. And while the Department of War is heavily focused on the war in Iran, the threats in the Asia-Pac region have not gone away, and we believe the situation will normalize in the next few months.
Now I'd like to address some of the other opportunities that will help support future financial growth for Intrusion. The expansion of our Shield cloud solution on both the AWS Marketplace and the Microsoft Azure platform have begun to show some promising signs in helping us expand our customer pipeline. While both expansion efforts are still in the early stages, we believe that we will see an uptick in revenue contribution from having our solution available on these 2 platforms over the next several quarters.
As you may recall, we also expanded our partnership with PortNexus in February with the launch of the P.O.S.S.E Program, which leverages our Shield on-premise technology to help protect law enforcement from cyber threats. The program continues to progress well with ongoing deployments and strong engagement across Texas, Missouri, Oklahoma and Iowa. And we expect to see further adoption as additional law enforcement agencies recognize the value of Intrusion's Shield technology in identifying and stopping active cyber threats. We're beginning to see the benefit of this partnership reflected in our second quarter results, and we anticipate that we'll see further financial growth from this program over the next few quarters.
As I've discussed on previous earnings calls and with many of you during our one-on-one meetings, AI is rapidly reshaping the cybersecurity landscape. Its growing adoption has significantly reduced the cost, the technical expertise and the time required to develop and execute highly sophisticated and scalable attacks. At the same time, customers are seeking cybersecurity solutions capable of keeping pace with these rapidly evolving threats. And that's where our AI-assisted platform comes in, which can help catch malicious actors before they can cause any harm.
As we enter the commercial space in a meaningful way, we believe this AI-assisted platform will help support our customer base, expansion efforts and further improve our top line growth.
Now briefly on to our financials for the quarter. Total revenues for the first quarter was $0.9 million, a decrease of 40% sequentially, which was directly the result of the delay in the incremental funding of the Department of War contract that I noted earlier on in our call. Our operating expenses also saw a slight increase during both the quarter and as compared to last quarter. This increase in our expense reflects deliberate strategic investments to strengthen our business and position us to achieve our goal of creating sustainable growth and long-term profitability as well as the costs associated with the critical infrastructure deployment and operation.
With that, I'd like to now turn the call over to Kim for a more detailed review of our first quarter 2026. Kim?
Thanks, Tony. First quarter 2026 revenue was $0.9 million, down 40% sequentially and 50% year-over-year. As Tony mentioned, results continue to be impacted by delays in the award of a key U.S. government contract, contributing to an unusually low reported revenue level. We remain optimistic that a meaningful portion of the associated revenue will be realized in future periods.
Consulting revenues totaled $0.8 million in the first quarter compared to $1.1 million in the prior quarter and $1.4 million in the prior year quarter. Shield revenues totaled $0.1 million in the first quarter compared to $0.4 million in the prior quarter and $0.4 million in the first quarter of 2025. We anticipate that these results will improve throughout the remainder of 2026, driven by the sales of our OT Defender solution to additional U.S. government departments and commercial customers, further growth of our partnership with PortNexus and the recognition of revenue from the new contract to deliver our cyber threat intelligence and critical infrastructure protection technology that Tony outlined earlier in the call.
First quarter gross profit margin was 74%, down slightly from the prior year period. Operating expenses in the first quarter of 2026 totaled $4.2 million, an increase of $0.3 million sequentially and $0.8 million year-over-year. The first quarter increase both sequentially and year-over-year reflects stepped-up investment in commercial activities, particularly through expanded trade show presence and enhanced brand and product marketing initiatives.
Net loss for the first quarter of 2026 was $3.6 million or $0.18 per share compared to a net loss of $2.1 million for the first quarter of 2025. The increased net loss in the first quarter was driven by a decline in revenues, primarily due to delays in incremental funding under a government contract. This was further impacted by higher operating expenses during the period.
Turning to the balance sheet. From a liquidity perspective, on March 31, 2026, we had cash and cash equivalents of $1.4 million. As we discussed during our fourth quarter call, we had begun the process of seeking a small debt financing. In early April, we entered into a $3 million secured financing agreement, strengthening our liquidity position and supporting our near-term operating priorities. The facility provides us with additional flexibility as we continue to execute on our strategic initiatives.
With that, I'd like to turn the call back over to Tony for a few closing comments. Tony?
Well, thank you, Kim. As I noted earlier in the call, as we move beyond the headwinds of the past 2 quarters, we're very optimistic that our financial performance will begin to improve through the remainder of fiscal year 2026. The teams worked diligently over the past several quarters to position the business for growth, and we're beginning to see evidence of those efforts taking hold, and it's evident by the continued growth of our critical infrastructure technology, our expanding partnership programs and sales pipeline and our ability to stay at the forefront of technology and cybersecurity, especially when it comes to AI that will help provide our customers with a more enhanced product offering. We still have a lot of hard work ahead of us, but we continue to remain on track to transition Intrusion to profitability by the end of the fiscal year and create value for our shareholders.
And with that, I'll now turn the call over to the operator for Q&A. Operator?
[Operator Instructions] Our first question today is coming from Ed Woo with Ascendiant Capital.
2. Question Answer
My question is on the Department of War contract that has been delayed. Are you still providing services on that? And when it does get approved, will all the revenues that you have, will it be recognized all at once? Or is it just kind of extend out the contract from when it's actually approved going forward?
Yes. Thanks for the question, Ed. We are still providing services. The government actually can't retroactively pay for things that weren't contracted for. So the revenue will come in or the contract will come in, and we'll bill forward from that particular point, but we wouldn't be able to reverse recognize revenue, I don't think, in that particular case. So -- but I think this is an important capability. The customer there is very happy with the solution, and we look forward to getting this resolved.
That sounds good. And then going back to the pipeline, have you noticed any change in terms of -- I know there's some geopolitical issues, but it seems like at least on the AI front, a lot of Chief Technology Officers are still putting the gas on the pedal to spend. Have you seen any change in the last couple of months in terms of people -- enterprises or government spending on IT, specifically on cybersecurity?
Yes, it looks to us like the spend is still going up slightly. I think one of the things that we've talked about before is AI is sort of creating a little bit of concern in terms of how easy it is to conceive of an attack and actually launch it. And I think that's put a little extra oomph into people's desire to have more advanced solutions. And so I don't expect that to change much in the rest of 2026. So we're -- we think we should get our fair share of that.
Our next question is coming from Howard Brous with Wellington Shields.
So let me focus on PortNexus and see if I can get a better understanding of how big an opportunity this is. So where are you deploying it? And what size as this gets deployed? And what's the opportunity near term and longer term?
Yes. So I'll give you a couple of examples. We did a demonstration of the MyFlare Alert with the majority of the counties in Iowa. This is probably 2 months or so ago. And we now have 4 active deployments in Iowa with several more scheduled over the next few months. And we're replicating that sales motion in some of the other states that I mentioned on the call earlier. So the enthusiasm level is high. One of the things that this is subject to is the budget cycle for -- this is primarily counties and school districts. So -- we've heard lots of comments from both schools and counties that they love the solution, but -- and would put in requests in their budget packages. And then it's a question of whether those budget packages get approved at the local level. And that's going to vary across the country and across various states. But I'm optimistic because of the reception that we get whenever we show this to either school or the sheriffs or law enforcement officials.
I hope at the end of the day, we're in every county in this country because it's such a grand and cost-effective solution to that problem of situational awareness when there's an incident in a place like a school where some of our most precious assets are every day.
How is it possible that a school board can say no when you're talking about a methodology of protecting your children or your grandchildren? That I don't understand.
Yes. I think that goes to the level of enthusiasm that we've seen. I think the problem is not there. It's not with the school administrators or with the police force and so on. It's squeezing it into a budget that I do know is very tight in most cases. The schools are not flush with cash in a lot of situations. But we're also working at the state level and federal level to hopefully make sure that there's some grant money and other kinds of things available so that schools, even if they can't afford it in their own fiscal budget could take advantage of this solution. So a lot of different ways to skin that cat. But I agree with you. I don't know why anybody would ever say no.
How difficult is it to deploy in each facility? Does it take a month, a week, 6 months?
It's 1 day or 2 max in the vast majority of cases. It's a very quick lightweight install.
So from your perspective, what kind of margins, if you can comment on it, what kind of margins could you look at?
Well, for Intrusion, we license our network protection technology to PortNexus. And so it's nearly 100% margin for us because PortNexus does the install. Our only direct costs are marketing assistance, and we do go to trade shows and other events and explain the network protection part of this. In the case of sheriffs, we also put in an appliance, one of our Shield boxes, and that has the same margin as our other Shield business. So it's in the mid-70% range when we put in hardware at the sheriff's office. So a very good business for us.
So is it fair to say that on a sequential basis, each quarter potentially could be better than the prior quarter for the next period of time?
I would certainly think so. And also word of mouth is starting to get around on this. So when we do events and so on, more and more people are saying, "Oh, I heard about this. I want to learn more or those kinds of things." So I expect that, that will help us as well.
How many schools are there, 150,000, give or take, in the United States?
Well, I don't know, Howard, it's got to be at least that, I would think. It's -- we're not talking about just public schools. There's private schools, there's grade schools and high schools and preschools and trade schools and all kinds of opportunities. This is a great solution for courtrooms or any place, sports facilities, any place we're -- there's a potential for an incident where you need situational awareness right away. And right now, we're focusing on schools and sheriff's departments, but there's nothing that would preclude any of these other kinds of venues from adopting the solution.
So let me come back to my -- basically the first question. Sequentially then you can foresee over the next several quarters, business getting better each quarter. And then does that lead to profitability?
Well, overall, we think the business will be cash flow positive at the end of 2026. And so it will be a contributor to that, but not the whole answer.
At this time, there are no other questions in the queue. So I'll turn the call back over to Mr. Tony Scott for any closing remarks.
Yes. Thanks, everyone, for being on the call today. I apologize, I'm a little hoarse. I don't know if it's allergies or what. But I do want to reiterate that I'm very enthusiastic about the remainder of the year. This win that we announced today is the first of what I expect are going to be several big wins for us over the coming months. And the team that we put together to go after these is highly skilled, highly experienced and can help us in areas where we have not had that much success in the past. As some of you long-term followers know, we were deep in the places we were in, but almost nonexistent in other places in the federal government and even in DoD, in particular. And our team now has the skills and the ability and the history of doing good things and big things in places where we're not currently present. So I'm very excited about those.
When they get done like the one we announced, they come in big chunks. And we've got a whole bunch of other tricks up our sleeves for the remainder of the year. So stay tuned. We're pretty excited and everybody here is working really, really hard to make sure that '26 takes us in a new direction from where we've been. So I appreciate the support, and we'll talk to you by next quarter, but probably a few times in between. And thank you.
Thank you. Ladies and gentlemen, this concludes today's call, and you may disconnect your lines at this time, and we thank you for your participation.
Intrusion Inc — Q4 2025 Earnings Call
1. Management Discussion
Welcome to Intrusion Inc.'s Fourth Quarter and Full Year 2025 Earnings Conference Call and Webcast. [Operator Instructions] Please note this conference call is being recorded. An audio replay of the conference call will be available on the company's website within a few hours after this call. I would now like to turn the call over to Josh Carroll with Investor Relations.
Thank you, and welcome. Joining me today are Tony Scott, President and Chief Executive Officer; and Kimberly Pinson, Chief Financial Officer. This call is being webcast and will be archived on the Investor Relations section of our website.
Before I turn the call over to Tony, I'd like to remind everyone that the statements made during this conference call related to the company's expected future performance, future business prospects, future events or plans may include forward-looking statements as defined under the Private Securities Litigation Reform Act of 1995. Please refer to our SEC filings for more information on the specific risk factors that could cause or actual results to differ materially from the projections described in today's conference call. Any forward-looking statements that we make on this call are based upon information that we believe as of today, and we undertake no obligation to update these statements as a result of new information or future events.
In addition to U.S. GAAP reporting, we report certain financial measures that do not conform to generally accepted accounting principles. During the call, we may use non-GAAP measures if we believe it is useful to investors, or if we believe it will help investors better understand our performance or business trends.
With that, let me now turn the call over to Tony for a few opening remarks.
Well, thank you, Josh, and good afternoon, and thank you all for joining us today. Fiscal year 2025 was a year that had an unexpected beginning and an unexpected ending along with a number of significant product milestones along the way. At the beginning of the year, we improved our balance sheet by fully eliminating our then outstanding debt and Series A preferred stock. At midyear, we rolled out production of our critical infrastructure solution to help safeguard essential assets like water, power and telecom facilities. In the third and fourth quarter, we expanded our access to our Shield Cloud solution by making 2 variations of the product available on the AWS marketplace. And towards the end of the year, we announced our partnership with PortNexus to provide secure network protection for their MyFlare safety technology, which is being deployed at schools in several states.
In conjunction with PortNexus, we also launched the [indiscernible] program, which will give tariffs and other law enforcement agencies critical network protection for their public safety networks. And our pilot experience with the [indiscernible] program is encouraging with a high adoption rate so far. And finally, we ended the year with an unexpected delay in the extension of the earlier mentioned critical infrastructure contract with the Department of War. And I'll start my detailed remarks with some more insight about this unexpected end-of-year development.
Kim will provide more details on the overall number shortly, but our fourth quarter revenues decreased by 12% compared to the prior year period as a result of the delayed timing of an expected contract extension for our critical infrastructure technology. But for this delay, we had expected to show quarter-on-quarter increases in revenue, and greater year-over-year increase in revenue overall.
Now to be clear, the cost of providing the services for this critical infrastructure solution are included in our operating expenses, but the expected revenue is not and will show up in later periods when the contract is extended. The timing of this contract extension was and remains affected by the operational and administrative constraints associated with the U.S. government shutdown, which limited agency's ability to initiate and process contract actions during that period. And the situation is further impacted by the events related to the war in Iron unfolding currently. This delay in funding reflects a broader trend affecting companies with U.S. government contracts, particularly those operating within the defense sector. And while we're disappointed by this delay, we do believe that we will be able to recognize this revenue during the first half of 2026 once procurement activity normalizes, and we are continuing to support and enhance the solution that we have provided, and we look for further expansion of this solution in other regions in 2026.
We're proud of our partnership with the U.S. Department of War and the critical role we play in protecting national security through our advanced cyber capabilities. We continue to view the critical infrastructure solution that we have rolled out with the Department of War as one of the key drivers of future growth, especially as cyber threats become more frequent and more sophisticated. To convert this opportunity into future growth, we've recently taken targeted steps to enhance our sales efforts and go-to-market strategy, and I'll discuss these initiatives in more detail shortly, but they are specifically designed to expand our customer base across the private sector as well as federal state and local government markets.
Turning now to some fourth quarter developments. During the quarter, we announced the launch of our Shield Cloud offering on the AWS marketplace, expanding the opportunity for customers to access our Shield technology. Additionally, we've launched our Shield Cloud offering on Microsoft's Azure platform and it's now live. With availability across both leading cloud marketplaces, we've meaningfully expanded our sales reach, which will help enhance our customer pipeline and drive future revenue growth.
On top of this customer access expansion effort, we've also continued to strategically invest in R&D to help provide enhanced offerings to our customers. This is evident by the recent launch of Shield Stratus, a cloud-native packet filtering solution that inspects every connection and blocks known threats immediately without the complexity or rearchitecture required by traditional firewalls. Shield Stratus integrates seamlessly with AWS gateway load balancer and is a great addition to our Shield ecosystem.
Now on to some of the more recent developments during the first few months of 2026. As you may recall, we began a partnership with PortNexus in 2025, and who chose to embed our Shield endpoint solution into their MyFlare solution that helps provide enhanced security for education and law enforcement customer end points. In February, we expanded our partnership with PortNexus by launching the [indiscernible] program that utilizes our Shield on-premise technology to help protect law enforcement from cyber threats. The program achieved high levels of adoption during the initial pilot. And in the pilot program, Intrusion Shield technology identified and stopped dozens of active threats. The program is now scaling across Texas, Missouri, Oklahoma and Iowa through our partnership with PortNexus. And this partnership provides distribution access to hundreds of sheriffs' departments, schools and government facilities. So an exciting development, and we look forward to working closely with PortNexus to help expand this program and increase the adoption of our technology.
We also recently took steps to expand our business development efforts with the hiring of Valencia Reeves as our Public Sector Vice President of Sales; and Patrick Dugan Anthony Scott our Director of Channel sales and partnerships. These 2 additions to our team will help strengthen our U.S. business development efforts across the government sector and our channel partners.
Now briefly on to our financials for the quarter and the year. Total revenues for 2025 were $7.1 million, up 23% year-over-year. This top line growth was largely driven by the contract expansion with the U.S. Department of War that I touched on earlier.
Fourth quarter revenue was $1.5 million, a decrease of 25% sequentially, which was the result of the delay in the incremental funding of the Department of War contract that I previously referred to.
Our operating expenses also saw a slight increase during both the quarter and the year. This increase in our expense reflects deliberate strategic investments to strengthen our business and position us to achieve our goal of creating sustainable growth and long-term profitability as well as the costs associated with the critical infrastructure deployment and operation I mentioned before. We've made meaningful progress against our goals, and we believe we're on track to breakeven operations.
And finally, before I turn the call over to Kim, I'd like to wrap up by addressing some of the recent AI trends that we're seeing in the cybersecurity space. As I'm sure many of you are aware, the recent emergence of cloud code security has caused a bit of a shakeup in the cybersecurity space as some fear of this tool will change the industry by eliminating defects in software. However, I do not view this development as a threat to cybersecurity companies such as Intrusion, but more as a promising tailwind for the industry. While improved code quality is more than welcome, it's only one aspect of the landscape of cybersecurity vulnerabilities. And in fact, the rapid adoption of AI has materially increased cybersecurity risk as it has significantly reduced the cost, the technical expertise and the time required to develop and execute highly sophisticated and scalable attacks. As a result, this is only going to increase the need for cybersecurity solutions, such as the ones that we provide to our customers that help catch these malicious actors before they can cause harm.
With that, I'd like to turn the call over to Kim for a more detailed review of our fourth quarter and full year financial results. Kim?
Thanks, Tony, and good afternoon, everyone. Fourth quarter results totaled $1.5 million in revenue, a decrease of 25% compared to the prior quarter, and 12% when compared to the prior year period, as noted earlier on the call. This was due to the delayed incremental funding of a major U.S. government contract. The timing of this award was affected by funding and procurement constraints associated with the U.S. government shutdown and continuing resolution, which affected agency's ability to approve and initiate new contract actions during the period. We believe the delay in this contract award is primarily timing related and anticipate that a substantial portion of the delayed revenue associated with this contract will be recognized in future periods.
Consulting revenues totaled $1.1 million in the fourth quarter compared to $1.5 million in the prior quarter and $1.3 million in the prior year quarter. Shield revenues totaled $0.4 million in the fourth quarter compared to $0.5 million in the prior quarter and $0.3 million in the fourth quarter of 2024.
We anticipate that the sale of our OT Defender solution and other departments of the U.S. government as well as commercially will contribute to future growth. Additionally, during 2025, we partnered with PortNexus to integrate our Shield technology into its MyFlare Alert School Safety solution. Although sales to PortNexus did not materially impact 2025 revenues, the expanded pipeline for this offering is expected to support future Shield revenue growth.
Fourth quarter gross profit margin was 74%, which was slightly down from the prior year period. For the full year, gross profit margin was 76%, down approximately 93 basis points versus 2024.
Operating expenses in the fourth quarter of 2025 totaled $4 million, an increase of $0.3 million sequentially, and $0.8 million year-over-year. The fourth quarter increase both sequentially and compared to prior year was primarily driven by higher sales and marketing expenses reflecting increased participation in trade shows and expanded brand awareness and product marketing programs.
For the full year, operating expenses totaled $14.5 million, an increase of $1.7 million compared to 2024.
In addition to the increased sales and marketing expense, the full year increase primarily related to onetime savings realized in 2024 from the negotiation or cancellation of existing contracts, which contributed $0.5 million in savings in 2024, increased share-based compensation of $0.8 million from equity grants made in the first quarter of 2025 and cost of living and merit increases of $0.3 million.
Net loss for the fourth quarter of 2025 was $2.8 million or $0.14 per share compared to a net loss of $2 million for the fourth quarter of 2024. The increased fourth quarter net loss is the result of the reduction in revenues resulting from the delay in the incremental funding of government contract and increased operating expense.
Net loss for the full year was $9.1 million or $0.46 per share, a $1.3 million increase from the prior year.
Turning to the balance sheet. From a liquidity perspective, on December 31, 2025, we had cash and cash equivalents of $3.6 million. Looking ahead, we plan to seek a small debt financing in the near term to help further support our growth initiatives. We have already begun to have some initial discussions, and we'll provide an additional update on the debt financing during our first quarter earnings call.
With that, I'd like to turn the call back over to Tony for a few closing comments. Tony?
Thank you, Kim. 2025 was a year of meaningful progress for Intrusion from a product development standpoint and was marked by several key improvements, including new products. And while this progress was encouraging, we're not satisfied, and we realize that we have some significant work ahead of us. As we look to the remainder of '26, we will be doubling down on our sales efforts to expand our customer base and to further improve our top line growth.
We're confident that we have both the right people and the products in place that will help us achieve our goal of creating sustainable growth and long-term profitability. And before I wrap up, I want to extend my gratitude to our employees. The progress we've made this past year is a direct reflection of their dedication and hard work. And to our shareholders, we deeply appreciate your patience and steadfast support throughout this journey.
And with that, I'll now turn the call over to the operator for Q&A.
[Operator Instructions] Your first question is coming from Scott Buck from H.C. Wainright.
2. Question Answer
Tony, I'm curious, can you provide a little more granularity on the unit economics of the [indiscernible] program? Like what is the average contract value for a typical sheriff's department deployment? And what do the sales cycles look like with your partnership with PortNexus?
Sure. Well, the device that they select will depend a lot on the network bandwidth that they need at the sheriff's department. So those could range from a few thousand dollars up to tens of thousands of dollars depending on the size and bandwidth requirements of the particular sheriff.
In the case of the pilots, we used some of our lower-end appliances. So it's a few thousand dollars in terms of unit pricing on those. But what I'm encouraged by is when we -- as we've experienced everywhere else, once we show the network traffic that's getting through the traditional firewalls and other technologies they have in place and also show the outbound traffic that should be blocked that's not currently being blocked, it makes the sale pretty quickly. So we're seeing a high adoption rate and we're going to expand into these other states, as I mentioned on the call. And the way it works is we loan them a unit, it goes in for a week to 10 days. We do a report and show them the traffic that we see and would have blocked if we've been in place, and they love it. So we're doubling down on that. We're increasing the number of POC units, and we'll see where it takes us. So that's kind of the way it works.
That's very helpful. And then I wanted to clarify something in your prepared remarks. Did you say that had you not had the delay from the government contract during the quarter that we would have seen sequential revenue growth from the third quarter?
Yes. Yes. That is correct.
Okay. Perfect.
That is correct. Yes, we were expecting to report growth, both for the quarter-on-quarter and year-on-year above and beyond what we reported on the year-on-year.
Okay. So it's safe to assume that contract delay cost you at least $0.5 million in the quarter?
Yes.
Yes. Perfect. And then, Kim, I wanted to ask about sales and marketing expense. I think it's the highest quarterly level of spend maybe ever. Is this the new run rate? Or given some of the comments during the call, can we expect further investment in sales in 2026?
We will continue to invest in sales and marketing. What we saw in the first quarter approximates the run rate, but we will see some increases from here.
Scott, I'd also add, we're looking for cost efficiencies elsewhere. So it's important for us now to improve that sales and marketing muscle, and we'll look for other efficiencies elsewhere as we buttress up that capability.
Okay. So we may not see as material an increase in total operating expense because some of those dollars will.
Could be offset...
could come from other buckets?
Yes. exactly.
Your next question is coming from Ted Woo from Ascendiant Capital.
Did I hear you right that you said for the delayed contract that some of your expenses has already flown through the P&L already...
That's correct. We've taken all the expense associated with that. We just are not able to recognize the revenue at this point.
Okay. And then...
I'm sorry? What that means is when the revenue does come, it will show up in a subsequent quarter, but the expense will already have been recognized.
Okay. So that would be a 100% margin when it comes through?
Pretty nearly, yes.
Okay. And then are you seeing any -- what about the sales cycle pipeline for commercial customers? Have you seen any delays, any lengthening of sales cycle? Any concerns that you're hearing from Chief Information Officers out there?
Beyond the government sector, no real change. I think the one concern that we hear all the time is that the dwell time for threats is getting shorter and shorter and shorter, which means you have to react faster than ever, once some suspicious activity is noted. And I think that bodes well for Intrusion's technology because we don't rely on the presence of malware or other known signatures, we're heavily focused on repetition, which means that we can stop things in real time versus waiting for something bad to happen and then have to react to it and then remediate and so on. So we're currently having some discussions with MSPs and so on who are attracted to that kind of capability because it helps get out in front of these attacks versus waiting for an attack to actually happen.
Your next question is coming from Howard Brous from Wellington Shield.
A couple of questions. Tony, critical infrastructure customers that you have, can you give us a general sense of what kind of customer it is? And is he happy with the work? Is this basically expandable for that particular customer?
Yes. So this solution is protecting critical water infrastructure in the Asia-Pac region, and the customer is very happy with the solution. It's working as designed, and we continue to support it. And I think there's tremendous opportunities for this to expand beyond the region where it is now. We're doing one island right now in Asia-Pac. But as you know, there's a lot of islands that the Department of War has interest in, in that particular region. And so I think the revenue opportunity that comes from this is multiplied by the number of islands that still need this kind of protection.
And that's not to mention the domestic facilities as well, which fall under Homeland Security jurisdiction generally. And with our new sales capability that I mentioned on the call, we're targeting those places as well. And we've got great customer reference from this initial deployment. So we're pretty excited about the revenue opportunity in '26 and going forward. There's a lot of this critical infrastructure around, whether it's water or telecom or electrical grid kinds of things, and our solution is tailorable to each of those environments.
So let me take [indiscernible] for a moment and talk about school and children. You install this in a school, and my understanding it's in every school room, every class move and can be activated by a teacher. This is a potential event happening where somebody is coming into the school with a weapon. Is that fair comment?
Correct. Yes, that's the PortNexus solution that we're partners with. Yes.
Right. So you've got thousands of school districts throughout the country, why isn't everyone adopting this? It protects our children. There's nothing more important than that.
How are you going about marketing this?
Well, with PortNexus, we're attending events where school administrators look for technology. We're also marketing, as we mentioned, to the sheriff's department because -- or whoever the local law enforcement agency is that's associated with a particular school district because it takes the combination of them to really adopt the solution. The good news is it's very inexpensive. I've mentioned a couple of people. It's the kind of thing that, in many cases, the local PTA could find even if the school couldn't afford to do it. But you're right. I think once you see the demo of this capability and the situational awareness that it brings to the law enforcement of people within seconds of an event occurring, it's a why wouldn't we want to have this kind of thing. And so we're really looking forward to 2026 to expand this greatly across lots of markets in the U.
S.
And how your reception so far has been?
It's been outstanding, yes. Again, once you see it, you go, dah, why would I ever want to be without this kind of thing. And parenthetically, I'll say it could apply to other public venues as well. It doesn't necessarily only get marketed to schools. But any place where people gather and there's a potential for disruptions, whether it's active shooters or fire or any other kind of an event that might be disruptive, it's really important for law enforcement to get situational awareness as quickly as possible. And this PortNexus solution allows for multiple perspectives to get that situational awareness as well as alerting the authorities very quickly when an event happens. It shaves minutes off of that critical first few minutes when you have a potential to avert disaster. And I don't know anybody who's ever seen it that doesn't think that's a good idea so...
Anything to protect our children is a very good idea. Can you talk about...
You got it.
No doubt about that. Talk about the kind of cost? Is it per student, per class, per school?
It's per classroom. The PortNexus solution would go in to the classroom in the case of a school and attached to or become part of the smart whiteboard that's in the classroom and then school resource officers and teachers and anybody else that should be registered gets registered to that location. And then in the event of an incident, the panic button gets pushed, a text goes to all the preregistered cell phones. It turns the cell phone into lights up the camera and the microphone and the GPS signal and all of that gets fed to the law enforcement authorities along with video from the fixed cameras that usually are already installed in the school. So when an event happens, the law enforcement authorities have great situational awareness and location information from multiple perspectives, it's invaluable.
And we license to PortNexus the network protection aspect of it. So the revenue we get comes from the number of classrooms and then the number of schools within the school district.
And the margins on this are high margin...
so for us, it's very high, yes, because we don't actually have to go do any install or anything. We just license our software, PortNexus team is responsible for the installs and first-level support and so on. So it's almost pure profit for us.
This is a big deal. Anything to protect our children, That's a good thing.
You got it.
Your next question comes from James Green.
My question concerns the potential emerging technologies and the ability for your technology to interface with those things. And I'm specifically thinking about as we move forward into a day in an era where we have humanoid robots and we have autonomous cars, we have an imminent threat where if they're compromised they can be an immediate danger if someone compromises it.
Hello. I think we may have lost you, or I couldn't hear the rest of your question. Hello, can anyone hear me?
Apologies. James Greens line has disconnected.
Okay. Well, I think the question was -- I'll try to answer as best I can. Yes, there's more and more software, more and more autonomous things, whether it's robots or everything in your house, the emergence of AI and everything, I think widens the aperture for cybersecurity risk significantly. And our fundamental belief is that if you're not monitoring the network that all of these things need to operate on, if you're not monitoring it in real time packet-by-packet in multiple places in your network, you're likely to miss important things that would allow you to avert a disaster. And that's what Intrusion Shield does. We look at every packet in near real time and we make a decision about whether that packet is likely good or likely bad or unknown in some cases, and we make a decision. And I have used the analogy, it's like having continuous blood monitoring in your body. Most people get their blood drawn once a year when they go to physical exam, but some bad condition might have existed for almost a year, and you wouldn't know it until you get your blood drawn and get it tested.
In our case, we're doing the equivalent of looking at every single drop of blood in the body all the time, every time it moves through the body, and that allows us to very quickly detect when there's something untoward going on. And so I think that type of protection is what's going to be more and more and more important as things move forward, specifically with AI and more and more software in our lives. The threat landscape just got a whole lot bigger and needs to be monitored and managed.
And James Green, your line is connected and live.
Sorry, I accidentally got the line disconnected, so I missed the beginning of what you said. But since I missed the beginning, my question was, based off those emerging technologies, et cetera, is the current form factor or technology that you all utilize? Is it easily interfaced with those potential technologies? Or is there some minor alteration necessary to be able to utilize them in that?
Yes. We -- yes, so the answer to that is we can attach to the network in any form that it occurs, whether it's wired or wireless or in the cloud or in a data center or in a home for that matter. And the important thing, as I was saying in my earlier answer is to be really safe, you need to be monitoring the network each and every packet all the time and monitoring from multiple places in your network to be assured that everything that is going on in the network is desirable and necessary even in some cases. So yes, we're very flexible in that regard. And we have put the R&D effort into making sure we can handle increasingly large bandwidth as that becomes a necessity. So I think we're well prepared for the future in that regard.
Okay. And 1 other question, which is since we have all these scenarios where people are going to have local agentic things running on their own potentially private networks walking back off a cloud, the speculation that companies might be trying to have all the things working within their own system, is there a way in which the technology deals with the agentic element even internally?
Yes. I think to the degree that all of these agentic tools will use the network that allows us to monitor what that activity is. And I think you're going to see in 2026, I've made this prediction a number of times, you're going to see some pretty big accidents caused by unrestrained AI, where people loose something that got out of control somehow, whether it's privacy violation or whether it's a violation of releasing intellectual property in an unwarranted way. Who knows what it could be. But I think it's easily predictable that that's going to happen in '26. And for us, the only safeguard against that kind of thing is continuous real-time network monitoring so that the nanosecond something bad happens that you can stop it and shut off its activities. So we think we're in a good spot as all of these things come to fruition.
So like within a local network, if there's a agentic misbehavior, it can be controlled from being able to, in fact, ones outside connected potentially?
Yes. Yes. One of the characteristics of malware already today, even without AI is what's known as a call home, an infected device inside the network makes a call home to a command-and-control server externally and looks for instructions in some cases or just reports its presence in the network where it finds itself resident and then often waits for instruction and what to do next, launch a fishing campaign or launch some sort of other kind of attack. And intrusion technology is particularly good at stopping those call homes that would otherwise be very dangerous.
Now I'll say what we don't do is we don't go fix the device that had the problem. We just point you to it and say, this device over here has apparently got a problem. It's generating call homes to undesirable place. But most managed service providers and managed service security providers and institutions already have the tools to do remediation. What they lack is the early detection of that activity, and that's where Intrusion comes in.
[Operator Instructions] Your next question is coming from Jerry Wanwitz from Yanco Limited.
Tony, last quarter, you opened your comments by saying you're pleased to report that during the third quarter, we continue our path towards achieving our goal of creating sustainable growth and long-term profitability. Today, you opened by saying you're on the path to breakeven operations. My question is, in what quarter do you expect to have those breakeven operations?
Well, can you tell me when we're going to have another government shutdown or CR...
Assuming no government shutdown and no CR, what quarter would you expect that breakeven operations?
I -- well, it depends on new contracts that we signed. As I mentioned, we think this critical infrastructure solutions got pretty big legs. Our first contract for that was a $3 million roughly annual contract, and it wouldn't take too many more of those to get us to that goal. So it's all dependent on timing in '26 of when we would get those. But we think we're in a good position to land more of those in '26 than we did in '25 and whether it's 2 or 3 or whatever.
Would you be extremely disappointed if you weren't breakeven in the third quarter of this year?
Yes is the answer. I was disappointed that we weren't at breakeven right now, to be honest with you. We thought we were on a path to get there more quickly than we have been, and that's life. And there's probably some mistakes that we made that we, in retrospect, would do differently. But I think -- I still think we're on the right path, and I'm pretty optimistic that 26 is our year.
All right. So by the third quarter, we should expect to see that as shareholders?
I would hope so, yes. And I'm a shareholder so...
You have to get in the game, so I appreciate it.
Yes.
Thank you. At this time, there are no other questions in the queue. I'll turn the call back over to our host, Mr. Tony Scott for any closing remarks.
Well, as I said before, I just want to thank everybody for your interest in Intrusion. As I said at the beginning, it was a year that was unexpected in many respects. And I look forward to the progress that we can make in '26 with a little more stability and a little more predictability coming our way. We've made, I think, all the right investments in our tech. We've begun the strategic investments in our sales and marketing capability that, frankly, we've lacked over the last couple of years. If I had to look back, I probably was a little too slow in building up that muscle. But I'm very pleased with the team that we have now, and they're showing remarkable ability to get us into places that -- and talk to people that we hadn't been talking to over the last couple of years. So that gives me hope. These are experienced sales and marketing people, and it's just a pleasure to work with them and see the progress every single day.
So I'm appreciative of everyone's patience. I know it's been a along grueling road. But I remain optimistic and excited about what we can do together in. So appreciate everybody's time today, and I look forward to speaking with you at the next earnings call or maybe some announcements even before then. Thanks.
Thank you. Everyone, this concludes today's event. You may disconnect at this time, and have a wonderful day. Thank you for your participation.
Intrusion Inc — Q3 2025 Earnings Call
1. Management Discussion
Welcome to Intrusion Inc.'s Third Quarter 2025 Earnings Conference Call and Webcast. [Operator Instructions] Please note, this conference call is being recorded. An audio replay of the conference call will be available on the one's website within a few hours after this call. I would now like to turn the call over to Josh Carroll with Investor Relations.
Thank you, and welcome. Joining me today are Tony Scott, President and Chief Executive Officer; and Kimberly Pinson, Chief Financial Officer. This call is being webcast and will be archived on the Investor Relations section of our website. Before I turn the call over to Tony, I would like to remind everyone that statements made during this conference call relate to the company's expected future performance, future business prospects, future events or may include forward-looking statements as defined under the Private Securities Litigation Reform Act of 1995.
Please refer to our SEC filings for more information on the specific risk factors that could cause our actual results to differ materially from the projections described in today's conference call. Any forward-looking that we make on this call are based upon information that we believe as of today, we undertake no obligation to update these statements as a result of new information or future events.
In addition to U.S. GAAP reporting, we report certain financial measures that do not conform to generally accepted accounting principles. During the call, we may use non-GAAP measures if we believe it is useful lessors or if we believe it will help investors better understand our performance or business trends. With that, let me now turn the call over to Tony for a few opening remarks.
Thank you, Josh, and good afternoon, and thank you all for joining us today. I'm pleased to report that during the third quarter of 2025 we continue our path towards achieving our goal of creating sustainable growth and long-term profitability. And a few of our highlights of our progress in Q3 include our sixth consecutive quarter of sequential upline growth, demonstrating consistent execution and increasing demand for our products. Continued near 0 customer churn, which we view as a testament to the value of our offerings.
And the expansion of our Shield technology offering through the launch of Shield Cloud on the AWS marketplace. I'd also highlight the ongoing rollout of our critical infrastructure solutions, reinforcing the demand that we see to help protect these [indiscernible] assets from cyber threats. And finally, the strong momentum we are seeing from our solution partner, PortNexus, as they continue to deploy the MyFlare platform.
Now none of what we achieved this quarter would be possible without our incredible team, and I'm deeply grateful for the passion and the commitment our employees show every day in serving our customers and advancing our mission. I'd like to provide some additional context on a few of these highlights, all of which are aimed at positioning intrusion for sustained growth.
First, we're really excited about the launch of our Shield Cloud offering on the AWS marketplace, which we believe will help drive long-term growth for our business. By making Shield Cloud available on the AWS marketplace, we're not only expanding the opportunity for customers to access our Shield technology, but we're also positioning our cybersecurity engine directly where innovation is taking place.
Although still in the early stages, we're already seeing encouraging traction with new potential customers, which we believe will begin contributing positively to our financial results in the fourth quarter and throughout fiscal year 2026. In addition to AWS, we're also preparing for the launch of our Shield Cloud offering on Microsoft's Azure call platform later this quarter or early in the first quarter of 2026. This launch will further expand our ability to reach new potential customers.
Next, I wanted to mention that we're continuing to make progress with the rollout and adoption of our Shield critical infrastructure offering. And at the end of the third quarter, we shipped over 230 units of this critical infrastructure device as a part of our previously announced contract with the Department of Defense. And as we've previously noted, this represents a promising opportunity for intrusion, driven by the growing need to protect critical infrastructure from evolving cyber threats. We're actively pursuing additional contracts in the private sector as well at both the federal, state and local government levels, and we remain optimistic about posing new agreements in the near future.
As for our partnership with PortNexus, we're continuing to see strong demand for Shield endpoint that's embedded within their MyFlare solution. And that solution provides enhanced security for education and law enforcement customer end points. As some of you may have heard me say during recent discussions, the sales cycle for this solution has been one of the shortest I've ever seen. The demand for this solution, especially among school districts, is strong, and we anticipate that we will see further adoption of this offering in coming quarters.
Now briefly on to our financials for the quarter. Total revenues for the third quarter were $2.0 million, representing a 5% increase compared to the previous quarter and a 31% increase on a year-over-year basis. This was largely driven by the contract expansion with the Department of Defense that we previously discussed. And our operating expenses increased modestly this quarter, primarily reflecting the continued strategic investments that we're making in the business to drive growth.
As we've noted in the past, we remain committed to disciplined spending, as we invest to support our growth over the coming quarters. Now before I turn the call over to Kim, I'd like to address the current government shutdown. As you all know, the current government shutdown has impacted businesses across the board. For Intrusion, we've not yet seen any meaningful effect on our business. And it looks like the situation is on a path to resolution, thankfully. But most of the government contract conversations are still occurring. And we expect that we will be able to see additional government contracts once this situation has been resolved in Washington.
In the meantime, we're continuing to see our pipeline of nongovernment opportunities expand, and we remain excited about the future here at Intrusion, as the demand for our products continues to grow.
And with that, I'd now like to turn the call over to Kim for a more detailed review of our third quarter financials. Kim?
Thanks, Tony, and good afternoon, everyone. Third quarter 2025 revenue was $2 million, up 5% sequentially and 31% year-over-year. Growth was driven by expansion of work performed under the contract with the U.S. Department of Defense, which utilizes both Shield technology and consulting services. Consulting revenue of $1.5 million is up $0.1 million sequentially and $0.4 million year-over-year.
Shield revenues in the third quarter totaled $0.5 million, which was relatively flat sequentially but up approximately $0.1 million year-over-year. The increase in shield revenue primarily reflects the work performed under the previously noted DoD contracting work. As Tony mentioned, we are continuing to see strong demand for our services with both governmental and commercial customers and anticipated deeper penetration in both sectors, which will result in further changes to our customer mix.
Third quarter gross profit margin was 77%, down 58 basis points year-over-year, which is consistent with expected variability based on product and service mix. Operating expenses in the third quarter of 2025 totaled $3.6 million, an increase of $0.1 million sequentially and $0.4 million year-over-year. The increase sequentially was largely driven by an increase in sales and marketing expense related to increased participation in trade shows and programs to generate brand awareness and concise product marketing messaging.
We may continue to further increase our investment in both product development and sales and marketing to accelerate the growth of our customer base, which will result in higher operating expenses. The increase over the prior year period of $0.4 million is primarily due to higher share-based compensation from equity grants made in the first quarter, timing of merit increases and minor changes to staffing. Net loss for the third quarter of 2025 was $2.1 million or $0.10 per share compared to a net loss of $2.1 million for the third quarter of 2024.
Turning to the balance sheet. From a liquidity perspective, on September 30, 2025, we had cash and cash equivalents of $2.5 million and short-term investments in U.S. treasuries of $2 million. Subsequent to quarter end, we received $3 million in cash related to the DoD contract extension, which increased our cash position, inclusive of short-term investments to $7.5 million, which we believe is sufficient to fund operations through the remainder of 2025 and into early 2026.
With that, I'd now like to turn the call back over to Tony for peak closing comments. Tony?
Thank you, Kim. And I think the third quarter was another step in the right direction for Intrusion as we are continuing to make great progress towards achieving our goal of generating sustainable growth and long-term profitability. And while we're proud of the progress we've made, we're not satisfied with our overall financial results. We know there's still more work to do, and we're confident that we can and will deliver stronger performance over time.
Achieving this will require continued discipline and time, but we believe our ongoing investments in the business, the strength of our expanding pipeline and the improved engagement we're seeing with both customers and partners, has positioned us well to drive enhanced financial results. Now this concludes our prepared remarks. And I'll now turn the call over to the operator for Q&A.
[Operator Instructions]The first question comes from Scott Buck with H.C. Wainright.
2. Question Answer
Tony, I think you touched on it a little bit in the prepared remarks, but I wanted to kind of dig in a little bit deeper on the infrastructure work with the DoD. When do you get far enough along the process or prove yourself enough that maybe you open the door to some additional work of a similar nature with them?
Already in progress. So with this first project, it's opened the doors for us to have conversations about deployment in other locations. Right now, we're in a [ One Island ] location in the [pack ] room, but there's lots of islands there. There's also domestic opportunities for this. From a government perspective -- and then there's, we think, even more opportunities from a private sector or a commercial perspective. So I'm particularly excited about this product.
These are -- like we've seen in this particular case, it's a big dollar sale when it happens. PAUSE And we think we have an opportunity for many more of these during not only the next quarter, but next year. So it's a big area, a big opportunity for us. Now we've got to close them. We got to get government funding squared away, which as we've all experienced, is a daily up and down sort of situation. But I think the potential is big for this product.
It is our most successful product at this particular point. So we're going to bet on it and all we can.
No, that's great to hear. Now Kim, do you need to add heads or any kind of other supports to kind of press on those opportunities?
No. There's a fairly small capital investment because there is a device that goes with this infrastructure monitoring. But otherwise, we don't expect or anticipate having to add heads or increase our operating expenses to any large degree.
All right. Perfect. And then, Tony, I want to ask -- I know it hasn't been very long, right? But I'm curious what the experience has been like so far on AWS where you may be seeing some interest and any kind of initial feedback you guys are getting, I think, would be helpful.
Yes. It's -- we've gone through -- we've actually been in AWS for the bulk of the third quarter and now into the fourth quarter. And we've already done a couple of updates to make it easier to configure and install. And we have one more big update coming shortly that I think will make it even easier. And this is all based on feedback we've gotten from our initial beta customers and so on.
And I think with these changes, it will significantly make it easier for people to adopt. So a lot of excitement around it. The numbers aren't huge at the moment, but we're on our plan. We're starting to do the marketing and advertising work that I think we've talked about on prior calls. And our expectation is that, that's going to pay off.
And the lessons we've learned from this will also apply as we get into the Azure marketplace on the Microsoft platform. And so I'm expecting that the acceleration there can go even quicker than what we've experienced in the AWS environment. But very positive about it.
Good. No, that makes sense. And on Azure, it sounds like it could be end of this quarter it could be getting -- '26. What steps do you have left there to get up and active?.
Well, we created a new kind of got from scratch variant of Shield for the cloud that makes it much easier to deploy in these virtual environments. And that's the 1 that we're going to target for Azure as well. So easier -- a better build for us, easier for the customer to adopt. The current AWS 1 has -- is coupled with pfSense, the open source firewall and the new versions that will go into AWS shortly and also Azure are just yield and not coupled to pfSense, and we think that's going to attract a broader set of customers. We'll still offer the pfSense version in AWS. So we'll actually have 2 properties in AWS, 1 with pfSense and 1 stand-alone.
And probably in a you price it, Tony?
Pardon me?
Does that change the way you price it, yes.
Not a whole lot because the pfSense is open source. So there's no royalties or anything like that associated with it. But what we heard from customers is, some of them want choice around which firewall they use. And while we like our technology, they had a different choice for firewall than what we chose, which was pfSense. So this will give customers broader choice. If they don't have a firewall and want 1 and like open source, they can use that. If they want to choose something else but still want our technology, they can have that choice as well.
Okay. Perfect. Well, that's all I had, guys. I appreciate the time and congrats on the progress this quarter.
The next question comes from Ed Woo with Ascendiant Capital.
Congratulations on the progress. My question is on your channel partner, PortNexus. What are you able to do there that is able to give you the successes? And is this able to be translated to other channel partners?
Yes. So what we're providing to PortNexus is endpoint security for their solution that's deployed in classrooms and other public sort of places. And that endpoint security is important so that the devices are effectively tamper-proof and safe from hacking and so on. I'm excited about it because as we've done trade shows with PortNexus and school administrators come by and see the demo and understand the capability, they get pretty excited.
And as I kind of hinted the sales cycle, it looks like it's pretty short. The feedback is I want this now kind of thing, which with other solutions, there's a much longer conversation that ordinarily takes place. So we're in a couple of school districts already, and I think as experience with this product grows, the excitement is going to only accelerate.
We're attending all the right trade shows with PortNexus, but also word of mouth is beginning to get out that this is a pretty cool solution. So at the end of the day, we've got great expectations for this.
Can you translate these opportunities to other channel partners? Or is this very specific just to -- for Nexus?
Well, we can certainly port it to or extend it to other endpoint kinds of solutions where network security is a fair amount importance, and we are looking for those opportunities, I'd say, the success with PortNexus will certainly be a good indicator for other potential partners as well. And so yes, I think it can extend and we are looking for those kinds of opportunities.
Great. And my last question is, as you rolled out in AWS and then also on the Azure platform soon. Do you care where your customer buys it? Is there any difference in profitability and R&D costs?
No impact on R&D costs. We're only at this point, extending it to U.S. customers. We're not in the global marketplaces. So that kind of, by definition, restricts where it's for sale, but it doesn't really impact our costs one way or the other.
And you don't really care where your customer gets it because the profitability margins are about the same.
Yes. Correct.
I wish you guys good luck.
The next question comes from Howard Brous with Wellington Shields.
Tony, congratulations on the increase quarter-over-quarter-over-quarter. I have a couple of questions. Can you discuss the revenue opportunity with OT Defender as an example?
I can talk about it generally. I mean, I think the nice thing about these is as compared to our Shield or Cord Nexus deals that tend to be smaller, these tend to be bigger sales. 10,000 above kind of opportunities. And so as you get one of these, there's a more meaningful impact in terms of revenue and overall sales. So obviously, that's important in terms of the revenue opportunity. The second thing is it's pretty widely recognized at this point that the OT environment is probably the biggest area of underinvestment from cybersecurity perspective.
And it also happens to be one of the biggest targets for nation state actors who in anticipation of some sort of aggressive activity would love to take out water systems and the electrical grid and communication systems and the things that are necessary to sustain life in most places around the world. A lot of the environment in these OT spaces is old gear that over time got hooked up to networks, but we're never ever designed to fend off the kinds of attacks and threats that are just a part of our modern day world.
And the reality is we've -- as a nation and even internationally, we've been a little slow to wake up to this aspect of cybersecurity it's particular kind of threat. So we think the market opportunities are really big. And we think we have a very cost-effective and now proven solution to this particular problem, and we're going to do everything we can to let everybody know what we've got and what its capabilities are.
So I think I'm pretty bullish on this. It's going to take work. But I'm excited not just from a revenue perspective for intrusion, but I'm excited for the protection, I think this can bring to some very vulnerable environments in our cities and states and critical infrastructure generally.
And then as I mentioned on the call, it also applies to commercial environment, shop floors and other manufacturing environments and so on. And all of those are pretty vulnerable at this particular point. If you can disrupt manufacturing or disrupt the production of goods, that's got a pretty serious economic impact. And I think our technology is good to help protect those environments as well. So a pretty broad-based market or surface for us to go after.
So the second question, the same question with revenue opportunity on Port Nexus school safety offering, which I -- from my understanding, should be critical with every school in the country.
Yes. That one is probably not as big as the critical infrastructure stuff. But this is one of those things where once you see it, you can't unsee it. And as we've experienced the trade shows, the school administrators love the simplicity of it and also the sort of capability that the PortNexus solution provides. And the critical thing there is visibility in that first 1 to 5 minutes of an incident where you have really good and better situational awareness than you do with any other solution that's out there.
And the first responders call that the critical first few minutes. If you can understand what's going on and have situational awareness, you can have a much better response, and that's what the PortNexus solution provides. So we're happy to be a part of that clearly. And I think just like you've seen police departments all over have body-worn cameras. I think ultimately, this is going to be a required thing in every school classroom or at least public school classroom in the country because it's just such a good solution. So we're happy to partner with PortNexus on that journey.
So my last question -- well, let me come back to the Port Nexus. Any sense for 2026 of a revenue opportunity?
I'd be wildly guessing at this point, Howard, but our eyes are towards up and onward from a revenue perspective. So we're -- I think, genuinely excited about the opportunity. Clearly, we've got to execute. Clearly, we've got to get in front of customers make the case and go forward. But I think we have all the right things in our briefcase to go sell, and we're as excited as I've ever been about it..
My last question, then 1 comment afterwards Shield Cloud revenue opportunity?
Again, as I said on the call, that's the place where innovation is happening. And so the growth in small, medium business, they've moved to the cloud and are moving to the cloud, and that's where the economy is growing the fastest. It's probably the biggest opportunity from a tech standpoint for that part of the market. And we'll see.
Again, we've got to execute. We've got to continue to work our marketing plan and demand gen plan, but we've seen a lot of other companies do it. And we're going to be a fast follower in terms of all of the things that we've seen work in that journey. So hard to exactly predict, but we have, I would say, great expectations.
At what level -- last question, what level of revenue per contract, would you make a public announcement $100,000, $1,000,000? It's not so much like PAUSE.
It's not so much like -- well, it's not so much -- in some cases, Howard, it's not the level of the dollar amount that would determine whether we can make an announcement. We actually signed some deals in Q3 that didn't produce revenue in Q3, but it will produce revenue in Q4, that by contract, we were prohibited from announcing. So the only way you'll see them is when revenue shows up after the end of a quarter. And that's not uncommon in the cybersecurity space. we'll announce whatever we can when we can. If it's significant. I'm not going to announce a $5,000 deal or a $10,000 deal or something like that. But if it's $1,000 or $400,000 or $1 million, I'll certainly announce it if I'm allowed to.
The next question comes from Jerry Yanowitz with -- he is a private investor.
Tony, do you believe your intellectual property alone could be worth multiples of your current stock price and I'm just looking for a simple yes or no answer.
Yes.
And based on your knowledge in the cybersecurity market, do you believe your products could integrate well with a larger cybersecurities company suite of products. Yes or no.
Yes. Yes, yes, I do. It may not always be the obvious first names that come to mind. But the answer is yes. It's I think obvious that, that could be very interesting and exciting for us..
At this time, there are no other questions in the queue. I'll turn the call back over to our host, Mr. Tony Scott, for any closing remarks.
Well, thankfully, the -- it looks like the government shutdown is close to coming to an end. And I think we all breathe a sigh of relief in that regard. We're looking forward to working with our government partners as we've talked about at some length already today. This is the opportunity that's in front of us right now is doing better protection for critical infrastructure, whether it's public sector or private sector, it's the biggest cybersecurity opportunity, I think there is out there.
And so with the shutdown behind us, I think it opens the door for us to move ahead. We'll let you know is when we can and as soon as we can when anything has developed. But as I said earlier, I'm pretty excited about the opportunity and look forward to having this call with you for the next quarter in our annual results.
So thanks, everybody, for your patience. We're working hard. We've got a great team on this, and I think we're making great progress. So talk to you all soon. Thanks.
Thank you. This concludes today's conference, and you may disconnect your lines at this time. Thank you for your participation.
Financial data from Intrusion Inc
Revenue
Revenue is the sum of all sales generated by a company, e.g. for its products or services.
Revenue (TTM) metric explainedDirect Costs
Direct costs are the costs incurred directly in connection with the manufacture of the product or service.
Gross Profit
Gross Profit indicates how much of the revenue remains in the company after deducting direct production costs. If the percentage share of sales is calculated, this is referred to as the gross margin.
Gross Profit metric explainedSelling and Administrative Expenses
Selling, general and administrative expenses (SG&A) include all expenses for marketing and sales as well as the general administration of the company.
Research and Development Expense
Research and development costs (R&D) provide information on how much the company invests in the research and development of its products. The costs are particularly interesting as a percentage of revenue and in comparison to direct competitors.
EBITDA
EBITDA (Earnings Before Interest, Taxes, Depreciation and Amortization) is the company's earnings before interest, taxes, depreciation and amortization. The EBITDA margin is calculated as a percentage of sales.
Depreciation and Amortization
Depreciation represents reductions in the value of the company's assets (e.g. due to wear and tear on machinery).
EBIT (Operating Income)
EBIT (Earnings Before Interest and Taxes) is the company's profit before interest and taxes, also known as the operating income. The EBIT Margin is calculated as a percentage of sales at
.
Net Profit
Net Profit represents the profit or loss after deduction of all costs.
Net Profit metric explainedStocksGuide Premium
| Jun '26 |
+/-
%
|
||
| Revenue | 5.79 5.79 |
15%
15%
100%
|
|
| - Direct Costs | 1.56 1.56 |
5%
5%
27%
|
|
| Gross Profit | 4.23 4.23 |
18%
18%
73%
|
|
| - Selling and Administrative Expenses | 10 10 |
20%
20%
174%
|
|
| - Research and Development Expense | 5.22 5.22 |
6%
6%
90%
|
|
| EBITDA | -9.40 -9.40 |
48%
48%
-162%
|
|
| - Depreciation and Amortization | 1.65 1.65 |
6%
6%
28%
|
|
| EBIT (Operating Income) EBIT | -11 -11 |
36%
36%
-191%
|
|
| Net Profit | -11 -11 |
36%
36%
-191%
|
|
In millions USD.
Don't miss a Thing! We will send you all news about Intrusion Inc directly to your mailbox free of charge.
If you wish, we will send you an e-mail every morning with news on stocks of your portfolios.
Intrusion Inc Stock News
Company Profile
Intrusion, Inc. engages in the provision of network security solutions. It specializes in the development and marketing of entity identification, high speed data mining cybercrime and advanced persistent threat detection products. The company supports a range of customers including United States federal government entities, local government, banks, airlines, credit unions, and other financial institutions as well as hospitals, and other healthcare providers by providing products such as TraceCop for identity discovery and disclosure, and Savant for network data mining and advanced persistent threat detection. Intrusion was founded by T. Joe Head and G. Ward Paxton in September 1983 and is headquartered in Richardson, TX.
StocksGuide Premium
| Head office | United States |
| CEO | Mr. Scott |
| Employees | 54 |
| Founded | 1983 |
| Website | www.intrusion.com |


