Tenable Holdings, Inc. Stock price
📊 Peer Group
📈 What is it?
The peer group consists of the companies with the most similar business model. They serve as a benchmark for putting a stock into context.
🧮 How is it selected?
Based on similarity of business model, meaning companies from the same industry with comparable products and a similar customer base. That's the only way to compare apples to apples.
🏛️ Why does it matter?
Whether a stock is cheap or expensive is best judged by comparison. A P/E of 18 or an EV/FCF of 20 can look cheap or expensive depending on the yardstick. The peer group gives you the most accurate one: companies with a similar business model that operate under the same conditions.
🎯 What does it mean for investors?
When a metric sits below the peer average, the stock is valued more cheaply relative to its competitors, and above the average more expensively. A discount to the peer group can be an opportunity, but it can also have a reason (for example lower growth). The comparison is a starting point, not a verdict.
AI Insights on Tenable Holdings, Inc.
Insights
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Invest better with AI
StocksGuide Unlimited – full access to AI analyses
👉 More detailed insights
👉 Exclusive perspectives on opportunities & risks
👉 Clear answers to your questions
Is Tenable Holdings, Inc. a Top Scorer Stock based on the Dividend, High-Growth-Investing or Leverman Strategy?
As a Free StocksGuide user, you can view scores for all 9,127 stocks worldwide.
StocksGuide Premium
StocksGuide Unlimited
Key metrics
📘 Market Capitalization
📈 What is it?
Market capitalization shows how much a company is currently worth on the stock market.
🧮 How is it calculated?
🏛️ Why is it important?
It helps classify companies by size (Large, Mid, Small Cap) and indicates their market presence and relative stability.
🧮 Calculation
🎯 What does this mean for investors?
- Large-cap companies tend to be more stable, often pay dividends, but may grow more slowly.
- Smaller firms may offer higher growth potential but come with more volatility.
- Market capitalization is a useful indicator of company size — but not a measure of whether a stock is undervalued or overvalued.
📘 Enterprise Value (EV)
📈 What is it?
Enterprise Value represents the total cost to acquire a company — including its debt and excluding its cash reserves.
🧮 How is it calculated?
(= Market Cap + Net Debt)
🏛️ Why is it important?
EV gives a more complete picture of a company's value than market cap alone and is used in key valuation ratios like EV/FCF or EV/Sales.
🧮 Calculation
🎯 What does this mean for investors?
- Enterprise Value shows the true cost of buying a company, including all financial obligations.
- It is more accurate than just looking at market cap, especially when comparing companies with different levels of debt or cash.
- Professional investors prefer EV-based multiples because they better reflect the company’s full financial footprint.
📘 Net Debt
📈 What is it?
Net Debt shows how much debt remains after subtracting a company’s available cash reserves.
🧮 How is it calculated?
🏛️ Why is it important?
It indicates how dependent a company is on borrowed money and how easily it can service its debt in the short term.
🧮 Calculation
🎯 What does this mean for investors?
- Low or negative net debt signals financial strength and flexibility.
- Companies with strong cash positions are better positioned in crises.
- High net debt increases financial risk — especially in environments with rising interest rates or economic downturns.
📘 Cash
📈 What is it?
Cash represents all liquid assets a company can access immediately — including cash, bank deposits, and short-term investments.
🧮 How is it calculated?
🏛️ Why is it important?
It reflects a company’s financial flexibility and resilience — enabling investments, buybacks, or buffer in downturns.
🧮 Calculation
🎯 What does this mean for investors?
- A strong cash position means greater room for maneuver and crisis resistance.
- Cash-rich companies can invest, pay down debt, or repurchase shares.
- But excess idle cash might indicate a lack of growth opportunities.
📘 Shares Outstanding
📈 What is it?
Shares outstanding represent the total number of a company’s shares currently held by investors — excluding treasury stock.
🧮 How is it calculated?
🏛️ Why is it important?
It’s the basis for key metrics like Earnings Per Share (EPS), Market Capitalization, or the Price/Earnings ratio (P/E).
🧮 Calculation
🎯 What does this mean for investors?
- Fewer shares in circulation typically increase earnings per share — making each share more valuable.
- Share buybacks reduce the number of shares and boost per-share metrics.
- Issuing new shares does the opposite — diluting shareholder value and lowering per-share figures.
📘 Price-to-Earnings Ratio (P/E)
📈 What is it?
The P/E ratio shows how many times a company's earnings per share are reflected in its current share price — in other words, how "expensive" the stock appears relative to its profits.
🧮 How is it calculated?
🏛️ Why is it important?
The P/E ratio is one of the most widely used valuation metrics. It helps investors assess whether a stock appears cheap or expensive compared to its earnings power.
🧮 Calculation
📊 P/E (TTM) = Based on earnings from the last 12 months (Trailing Twelve Months):🎯 What does this mean for investors?
- A low P/E may indicate undervaluation — or signal underlying issues.
- A high P/E may reflect strong growth expectations — or an overvalued stock.
📘 Price-to-Sales Ratio (P/S)
📈 What is it?
The P/S ratio shows how much investors are paying for $1 of the company’s revenue – regardless of profitability.
🧮 How is it calculated?
🏛️ Why is it important?
P/S is especially useful for evaluating growth companies or businesses not yet profitable. It reflects how the market values the company’s sales.
🧮 Calculation
Market Cap = $3.69b | Revenue (TTM) = $1.04b
Market Cap = $3.69b | Estimated Revenue = $1.10b
🎯 What does this mean for investors?
- A low P/S may indicate undervaluation — or low profitability.
- A high P/S can reflect strong growth expectations — or excessive optimism.
- Especially helpful when evaluating companies where profits are low, volatile, or negative.
📘 Enterprise Value to Sales (EV/Sales)
📈 What is it?
EV/Sales shows how much investors are paying for $1 of revenue — considering not just equity, but also debt and cash. It’s the capital structure–adjusted version of the P/S ratio.
🧮 How is it calculated?
🏛️ Why is it important?
It’s ideal for comparing companies with different levels of debt. It reflects a company's true cost relative to its revenue.
🧮 Calculation
Enterprise Value = $3.75b | Revenue (TTM) = $1.04b
Enterprise Value = $3.75b | Forward Revenue = $1.10b
🎯 What does this mean for investors?
- EV/Sales allows for capital structure–neutral company comparisons.
- A lower ratio may indicate undervaluation; a higher one may signal strong growth expectations or overvaluation.
- Especially helpful when evaluating high-growth companies with low or negative earnings.
📘 Enterprise Value to Free Cash Flow (EV/FCF)
📈 What is it?
EV/FCF shows how many years it would take for a company to "pay back" its enterprise value using its free cash flow.
🧮 How is it calculated?
🏛️ Why is it important?
It focuses on real cash generation, ignoring accounting noise — ideal for assessing profitability and value based on liquidity, not earnings.
🧮 Calculation
🎯 What does this mean for investors?
- A low EV/FCF may signal undervaluation and strong cash generation.
- A high EV/FCF might reflect weak recent cash flow or aggressive growth expectations.
- Best suited for stable, mature businesses with predictable free cash flows.
📘 Price-to-Book Ratio (P/B)
📈 What is it?
The P/B ratio compares a company’s market value to its book value — showing how much investors are paying for each dollar of net assets.
🧮 How is it calculated?
🏛️ Why is it important?
P/B is commonly used for asset-heavy industries like banks or industrials. It helps assess whether a stock is trading above or below its net asset value.
🧮 Calculation
🎯 What does this mean for investors?
- A P/B below 1 may signal undervaluation — or weak profitability.
- A P/B above 1 implies the market expects future value creation (e.g., brand, IP, growth).
- Best used for companies with tangible assets and strong balance sheets.
📘 Equity Ratio
📈 What is it?
The equity ratio indicates what portion of a company’s total assets is financed by shareholders’ equity – in other words, how much it relies on its own capital.
🧮 How is it calculated?
🏛️ Why is it important?
A high equity ratio reflects financial strength and stability, especially during downturns. It’s a key indicator of a company’s solvency and long-term risk profile.
🧮 Calculation
🎯 What does this mean for investors?
- Companies with high equity ratios are generally more resilient and less dependent on external debt.
- Low equity ratios can signal higher risk or aggressive financial strategies.
- Important: Always assess the equity ratio in combination with the return on equity (ROE). This shows not just how stable the company is – but also how efficiently it uses shareholder capital.
📘 Return on Equity (ROE)
📈 What is it?
Return on equity (ROE) shows how efficiently a company uses its shareholders’ equity to generate profit. In other words: how much net income is earned per dollar of equity.
🧮 How is it calculated?
🏛️ Why is it important?
ROE is a core profitability metric. It helps investors understand whether a company delivers attractive returns on the capital provided by its shareholders.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROE indicates that the company is using its capital efficiently and profitably.
- It’s especially meaningful for capital-intensive businesses or firms with high equity bases.
- Important: A very high ROE can also result from high debt levels – always interpret it alongside the equity ratio to assess financial health.
📘 Return on Capital Employed (ROCE)
📈 What is it?
ROCE measures how efficiently a company generates profits from its total capital – including both equity and interest-bearing debt.
🧮 How is it calculated?
It evaluates the return on all capital employed, regardless of how it’s financed.
🏛️ Why is it important?
ROCE is ideal for comparing companies with different financing structures. It shows how well management uses capital to create value for both shareholders and creditors.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROCE means the company uses its capital efficiently – regardless of whether it's funded by debt or equity.
- The higher the ROCE compared to peers, the more value the company creates with its invested capital.
- Especially relevant for capital-intensive sectors like industrials, energy, or infrastructure.
📘 Return on Invested Capital (ROIC)
📈 What is it?
ROIC measures how efficiently a company generates returns from the capital invested in its core operations – regardless of whether the capital comes from equity or debt.
🧮 How is it calculated?
- NOPAT = Net Operating Profit After Taxes
- Invested Capital = Operating assets minus non-interest-bearing liabilities
🏛️ Why is it important?
ROIC is one of the most accurate indicators of capital efficiency. Unlike return on equity, it is not distorted by leverage and shows how much value is created for all capital providers.
🧮 Calculation
🎯 What does this mean for investors?
- A high ROIC shows how effectively a company uses the capital that is truly invested in its core operations.
- Unlike ROCE, ROIC focuses only on the capital that is actively used to run the business – and that requires a return (i.e. interest-bearing).
- Especially useful when comparing companies with large amounts of excess cash or non-interest-bearing liabilities – giving a more realistic picture of capital efficiency.
📘 Leverage Ratio (Debt-to-Equity)
📈 What is it?
The leverage ratio indicates how much a company relies on interest-bearing debt (such as loans and bonds) relative to its shareholders’ equity.
🧮 How is it calculated?
🏛️ Why is it important?
This ratio helps assess a company’s financial structure and risk profile. High leverage can enhance returns – but also increases exposure to interest rate changes and financial stress.
🧮 Calculation
🎯 What does this mean for investors?
- A low leverage ratio signals financial strength and independence.
- A higher ratio can improve returns in good times but increases risk during downturns or rising interest rate periods.
- 👉 Always interpret in the context of industry, capital intensity, and interest rate environment.
📘 Revenue
📈 What is it?
Revenue shows how much a company earns in total from selling its products and services – the gross income before any costs are deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Revenue is one of the key figures to assess a company’s size, market position, and growth potential.
🧮 Calculation
🎯 What does this mean for investors?
- Growing revenue indicates rising demand and can be an early signal of future earnings growth.
- Comparing actual and expected revenue reveals trends in the market environment and analyst sentiment.
- Note: Strong revenue alone isn’t enough – margins and profitability matter just as much.
📘 EBITDA
📈 What is it?
EBITDA stands for “Earnings Before Interest, Taxes, Depreciation, and Amortization.” It reflects a company’s operating profit before the effects of financing, taxes, and accounting depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
EBITDA is widely used to evaluate a company’s operating performance – especially across capital-intensive sectors or international comparisons.
🧮 Calculation
🎯 What does this mean for investors?
- A high or growing EBITDA indicates strong operational profitability – independent of taxes, interest, or accounting methods.
- It’s especially useful for comparing companies across sectors or geographies.
- Important: EBITDA is not a net income figure – it excludes key costs like depreciation and interest.
📘 EBIT
📈 What is it?
EBIT stands for “Earnings Before Interest and Taxes.” It reflects a company’s operating profit after depreciation, but before interest and tax expenses.
🧮 How is it calculated?
🏛️ Why is it important?
EBIT is a core profitability metric that shows how well the company performs in its main business operations – independent of capital structure and tax environment.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT indicates strong profitability from the company’s core business – before financial and tax effects.
- It allows better comparison between companies with different debt levels or tax structures.
- Compared to EBITDA, EBIT already accounts for depreciation and reflects capital intensity more clearly.
📘 Net Income
📈 What is it?
Net income is the company’s total profit – the amount left after all expenses, taxes, interest, and depreciation have been deducted.
🧮 How is it calculated?
🏛️ Why is it important?
Net income is the most comprehensive measure of a company’s profitability – showing how much actual profit remains after all business and financing costs.
🧮 Calculation
🎯 What does this mean for investors?
- Growing net income indicates that the company is managing all of its costs efficiently.
- It directly influences valuation metrics like P/E ratio and the company’s dividend capacity.
- Over time, net income trends reveal how resilient and profitable the business model really is.
📘 Free Cash Flow (FCF)
📈 What is it?
Free Cash Flow shows how much actual cash remains after a company covers its operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
FCF reflects a company’s real financial strength – regardless of accounting profits. It shows how much flexibility a company has for dividends, share buybacks, or debt reduction.
🧮 Calculation
🎯 What does this mean for investors?
- High free cash flow means the company generates real, usable cash – independent of reported net income.
- It’s often the most reliable base for sustainable dividends and buybacks.
- Declining FCF can be an early warning sign – even when profits appear stable.
📘 Revenue Growth
📈 What is it?
Revenue growth shows how much a company’s sales have changed compared to the previous year – both on a trailing basis (TTM) and based on forward projections.
🧮 How is it calculated?
Forward = (Expected revenue ÷ Revenue in prior year − 1) × 100
Forward growth is based on analyst estimates for the current fiscal year.
🏛️ Why is it important?
Rising revenue signals growing demand, business expansion, and market share gains – especially important for growth-oriented companies.
🧮 Calculation
🎯 What does this mean for investors?
- Growth is the engine of long-term value creation – especially in tech and growth sectors.
- What matters is not just current growth, but its sustainability.
- Forward projections reflect whether analysts expect continued momentum – or a slowdown.
📘 EBITDA Growth
📈 What is it?
EBITDA growth shows how much a company’s operating profit (before interest, taxes, depreciation, and amortization) has increased or decreased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBITDA ÷ EBITDA from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
Growing EBITDA indicates improving operational profitability – regardless of financing or accounting effects.
🧮 Calculation
🎯 What does this mean for investors?
- Strong EBITDA growth signals operational efficiency and scalability – especially during growth phases.
- EBITDA growth can be an early indicator of margin and earnings expansion – but should be assessed alongside revenue and EBIT.
📘 EBIT Growth
📈 What is it?
EBIT growth shows how much a company’s operating profit (after depreciation, but before interest and taxes) has increased compared to the previous year.
🧮 How is it calculated?
Forward = (Expected EBIT ÷ EBIT from prior year − 1) × 100
The forward estimate is based on analyst projections for the current fiscal year.
🏛️ Why is it important?
EBIT growth is a direct indicator of a company’s business performance – taking into account capital intensity through depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- Rising EBIT signals improving operating profitability – even after accounting for depreciation.
- It’s especially important for evaluating companies with significant capital expenditures.
- Combined with revenue and EBITDA growth, EBIT growth provides a well-rounded view of operational progress.
📘 Net Income Growth
📈 What is it?
Net income growth shows how much a company’s bottom-line profit has increased or decreased compared to the previous year – both on a trailing basis (TTM) and based on analyst projections.
🧮 How is it calculated?
Forward = (Expected net income ÷ Net income from prior year − 1) × 100
The forward estimate reflects analysts’ expectations for the current fiscal year.
🏛️ Why is it important?
Net income is the ultimate measure of profitability. Growing net income signals stronger efficiency, cost control, and sustainable earnings power.
🧮 Calculation
🎯 What does this mean for investors?
- Stronger net income boosts valuation, dividend potential, and investor confidence.
- If profits stall while revenue grows, it may signal margin pressure.
📘 Free Cash Flow Growth
📈 What is it?
Free cash flow (FCF) growth shows how a company’s available cash – after covering operating expenses and capital expenditures – has changed compared to the previous year.
🧮 How is it calculated?
🏛️ Why is it important?
Free cash flow reflects real financial strength. Growing FCF indicates more flexibility for dividends, share buybacks, and reinvestment.
🧮 Calculation
🎯 What does this mean for investors?
- Declining FCF may point to rising investments, increasing costs, or weaker operating performance.
- Especially for dividend investors, FCF growth is critical – since dividends are paid from actual available cash.
- A negative trend isn't always bad, but it deserves closer attention.
📘 Gross Margin
📈 What is it?
Gross margin shows how much of a company’s revenue remains after deducting the direct costs of goods sold (like materials and production). It represents the company’s “raw profit” before fixed costs, taxes, and interest.
🧮 How is it calculated?
Or simply: Gross Margin = Gross Profit ÷ Revenue × 100
🏛️ Why is it important?
Gross margin indicates how efficiently a company can produce or procure what it sells. It is a key measure of product-level profitability and pricing power.
🧮 Calculation
🎯 What does this mean for investors?
- A high gross margin suggests strong pricing power and efficient production.
- Falling margins may signal rising input costs or competitive pressure.
- Compared to peers, gross margin offers insights into the quality of a business model.
📘 EBITDA Margin
📈 What is it?
The EBITDA margin shows how much of a company’s revenue remains as operating profit before interest, taxes, depreciation, and amortization.It reflects operating efficiency without being distorted by financing or accounting factors.
🧮 How is it calculated?
🏛️ Why is it important?
The EBITDA margin reveals how much operating income a company generates per dollar of revenue – independent of capital structure and tax effects.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBITDA margin reflects strong core profitability – before accounting distortions.
- It allows for effective comparisons across companies and sectors.
- A stable or growing margin signals efficient cost control and business scalability.
📘 EBIT Margin
📈 What is it?
The EBIT margin shows what percentage of revenue remains as operating profit after depreciation but before interest and taxes.
🧮 How is it calculated?
🏛️ Why is it important?
The EBIT margin reflects a company’s core profitability while accounting for capital intensity (e.g. machinery, infrastructure). It’s especially useful for comparing businesses with different levels of depreciation.
🧮 Calculation
🎯 What does this mean for investors?
- A high EBIT margin shows that the company remains efficient even after factoring in depreciation.
- It’s especially relevant for capital-intensive industries.
- Stable or rising EBIT margins over time are a strong indicator of pricing power and business quality.
📘 Net margin
📈 What is it?
Net margin shows how much of a company’s revenue remains as bottom-line profit after deducting all costs, interest, taxes, and depreciation.
🧮 How is it calculated?
🏛️ Why is it important?
Net margin reflects a company’s overall efficiency – across operations, financing, and taxation. It shows how much actual profit is generated from each dollar of revenue.
🧮 Calculation
🎯 What does this mean for investors?
- A high net margin means the company is not only strong operationally but also manages financing and taxes efficiently.
- Peer comparisons reveal business quality and competitiveness.
- Declining margins despite revenue growth can be a red flag for rising costs or inefficiencies.
📘 Free cash flow margin
📈 What is it?
The free cash flow (FCF) margin shows how much of a company’s revenue remains as actual free cash after covering all operating expenses and capital expenditures.
🧮 How is it calculated?
🏛️ Why is it important?
This margin reflects the true liquidity generated by the business – independent of accounting rules or depreciation. It’s especially relevant for dividends, buybacks, and reinvestment decisions.
🧮 Calculation
🎯 What does this mean for investors?
- A high FCF margin means a company consistently generates strong cash flow.
- It’s a positive signal for financial stability and shareholder returns.
- The long-term trend is key – a declining margin may indicate rising investments or weakening operating efficiency.
📘 Earnings per share (EPS)
📈 What is it?
Earnings per Share (EPS) shows how much profit is attributable to a single share – and is one of the most important metrics for evaluating a company's performance.
🧮 How is it calculated?
The diluted share count reflects potential new shares that could be issued through options, convertible bonds, or other rights.
🏛️ Why is it important?
EPS is the basis for many key valuation metrics like P/E ratio, PEG ratio, or payout ratio. It enables comparisons of profitability across companies, regardless of their size.
🧮 Calculation
🎯 What does this mean for investors?
- EPS captures per-share profitability and is especially useful for comparisons over time or with analyst estimates.
- Rising EPS may signal consistent growth or share buybacks.
- Important: Always use diluted EPS for more realistic valuations – especially in companies with stock-based compensation.
📘 Free cash flow per share (FCF per share)
📈 What is it?
Free Cash Flow per Share shows how much free cash flow a company generates per outstanding share – after investments, but before dividends or debt repayments.
🧮 How is it calculated?
Free cash flow is calculated as operating cash flow minus capital expenditures (CapEx).
🏛️ Why is it important?
FCF per Share reveals how much real cash is available per share – useful for dividends, buybacks, or reducing debt. Unlike net income, free cash flow is harder to manipulate and often seen as a more reliable metric.
🧮 Calculation
🎯 What does this mean for investors?
- High FCF per share signals strong financial flexibility.
- It shows how much capital the company can effectively reinvest or return to shareholders.
- Particularly relevant for dividend payers and capital-efficient businesses.
📘 Short interest
📈 What is it?
Short interest indicates how many shares of a company are currently sold short – that is, borrowed and sold by investors who expect the price to decline.
🧮 How is it calculated?
It reflects the percentage of a company’s shares that are being shorted relative to the total shares available.
🏛️ Why is it important?
Short interest serves as a sentiment indicator: A high value may signal skepticism or bearish expectations – but also increases the potential for a short squeeze if prices rise unexpectedly.
🧮 Calculation
🎯 What does this mean for investors?
- Low short interest usually indicates market confidence in the company.
- High short interest can be a warning sign – or an opportunity if sentiment shifts.
- Especially relevant in volatile markets or ahead of key earnings releases.
📘 Employees
📈 What is it?
The employee count shows how many people a company employs worldwide – offering insights into its size, structure, and business model.
🧮 How is it calculated?
🏛️ Why is it important?
It helps assess operational scale, labor intensity, and cost structure. Combined with revenue and profit, it enables key metrics like revenue per employee or productivity.
🧮 Calculation
🎯 What does this mean for investors?
- A high headcount can signal operational complexity – but also significant growth capacity.
- Revenue per employee is a key indicator of efficiency.
- Especially useful for comparing tech, industrial, or service-heavy companies.
📘 Turnover per employee
📈 What is it?
Revenue per employee indicates how much revenue a company generates on average per employee – a key measure of efficiency and productivity.
🧮 How is it calculated?
The employee count is typically taken from the most recent annual report.
🏛️ Why is it important?
This metric helps compare business models – especially between labor-intensive and technology-driven companies. A high value suggests automation, operational efficiency, or strong value creation per head.
🧮 Calculation
🎯 What does this mean for investors?
- A high revenue per employee indicates a scalable and margin-strong business model.
- A low figure may reflect labor-intensive operations or lower value-add.
- Especially helpful when comparing tech companies to industrial or service sectors.
Tenable Holdings, Inc. Stock Analysis
Analyst Opinions
30 Analysts have issued a Tenable Holdings, Inc. forecast:
Analyst Opinions
30 Analysts have issued a Tenable Holdings, Inc. forecast:
Tenable Holdings, Inc. Events
Past Events
|
JUL
29
Q2 2026 Earnings Call
about 2 months ago
|
|
MAY
21
Analyst/Investor Day - Tenable Holdings, Inc.
4 months ago
|
|
MAY
19
J.P. Morgan 54th Annual Global Technology
4 months ago
|
|
APR
29
Q1 2026 Earnings Call
5 months ago
|
|
MAR
3
Morgan Stanley Technology
7 months ago
|
|
FEB
4
Q4 2025 Earnings Call
8 months ago
|
|
DEC
10
Barclays 23rd Annual Global Technology Conference
10 months ago
|
|
DEC
2
UBS Global Technology and AI Conference 2025
10 months ago
|
|
OCT
29
Q3 2025 Earnings Call
11 months ago
|
StocksGuide Free
Tenable Holdings, Inc. — Q2 2026 Earnings Call
1. Management Discussion
Greetings, and welcome to the Tenable Q2 2026 Earnings Conference Call. [Operator Instructions] As a reminder, this conference is being recorded. It is now my pleasure to introduce your host, Erin Karney, Vice President, Investor Relations. Thank you. You may begin.
Thank you, operator, and thank you all for joining us on today's conference call to discuss Tenable's second quarter financial results.
With me on the call today are Co-Chief Executive Officers, Steve Vintz and Mark Thurmond; and Chief Financial Officer, Matt Brown.
Prior to this call, we issued a press release announcing our financial results for the quarter. You can find the press release on our IR website at tenable.com.
We will make forward-looking statements during the course of this call, including statements relating to our guidance and expectations for the third quarter and full year 2026, growth and drivers in our business, changes in the threat landscape in the security industry, particularly regarding AI security, the expected impact of Frontier AI models and accelerated vulnerability discovery and the shift to preemptive security, our competitive position in the market, growth in customer demand for and adoption of our solutions, including the impact of new pricing and packaging models, the expansion of Tenable One, including agentic AI security orchestration through Hexa AI and planned AI exposure coverage across third-party models, the expected benefits of our strategic partnerships with Frontier AI Labs, our ongoing research and development investments, our capital allocation strategy, including share repurchases and our future results of operations and financial position.
These forward-looking statements involve risks and uncertainties, some of which are beyond our control, which could cause actual results to differ materially from those anticipated by these statements.
You should not rely upon forward-looking statements as a prediction of future events. Forward-looking statements represent our beliefs and assumptions only as of today and should not be considered representative of our views as of any subsequent date, and we disclaim any obligation to update any forward-looking statements or outlook.
For a further discussion of the material risks and other important factors that could affect our actual results, please refer to those contained in our most recent annual report on Form 10-K and subsequent reports that we file with the SEC. Today's discussion includes non-GAAP financial measures.
These non-GAAP financial measures are in addition to and not a substitute for or superior to measures of financial performance prepared in accordance with GAAP. There are a number of limitations related to the use of these non-GAAP financial measures versus their closest GAAP equivalents.
Additionally, please see our press release for reconciliations of GAAP to non-GAAP financial measures that we discuss today. I will now turn the call over to Steve.
Thanks, Erin. We're very pleased with our results in the quarter as we exceeded all of our guided metrics and are raising our outlook for the year.
Tenable One was a record 50% of new business this quarter, continuing its strong upward trajectory. Earlier this year, we launched new pricing and packaging for Tenable One, introducing Tenable One Foundation and Tenable One Advanced.
Notably, we are seeing greater-than-anticipated adoption of Tenable One Advanced, which reflects growing customer demand given the evolving AI threat landscape.
Accordingly, larger land and expansion deals with Tenable One helped drive average deal sizes higher this quarter, and it also helped increase our net dollar expansion rate to 106%.
This is the first acceleration in our expansion rate in many quarters. The takeaway here is that our results are a clear validation of our strategy and the opportunity in front of us.
As AI reshapes the attack surface faster than most organizations can respond, we believe customers are increasingly choosing Tenable One as the platform that turns complexity into clear, actionable insight to reduce risk.
And that differentiation is what's resulting in higher deal sizes, faster expansion and durable leadership in this category. In fact, we believe it is becoming increasingly clear that companies who lead in this market will need 3 core capabilities to survive in the agentic era.
First, the ability to understand every exposure across the enterprise; next, the ability to prioritize tasks that matter most and then translate that intelligence into action. I'll discuss each of these 3 capabilities in a bit more detail.
First, organizations must understand exposure holistically across the enterprise. AI is accelerating vulnerability discovery and increasing the volume of issues requiring attention. But vulnerabilities are only part of the attack surface. Misconfigurations, compromised identities and other non-CVE weaknesses represent more than 60% of potential breach entry points, and we capture both CVE and non-CVE risk.
As attackers operate with greater speed and scale, organizations need a unified view of all of the conditions that create business risk, not simply a longer list of vulnerabilities.
Second, more findings make effective prioritization essential. Tenable combines broad exposure intelligence, deep contextual data and decades of security research to help customers distinguish the exposures that create meaningful business risk from those that do not.
This allows security teams to concentrate their resources on the relatively small number of actions capable of producing the greatest reduction in risk. And third, prioritization is only as valuable as the action it enables. As AI models become more broadly available, the key to agentic security is not the model itself. It's what sits between the model and the customer's environment, ensuring that agents operate safely and accurately with human oversight and an audit trail.
We call that the harness. Built into Tenable One, our harness draws on decades of exposure data, research and our trusted sensor layer. Hexa, our agentic engine for Tenable One, operates within this harness to orchestrate the right fixes deterministically for customers.
Digging a little further into Hexa, we continue to expand what Hexa can do. Just yesterday, we announced new capabilities that equip security teams with a coordinated fleet of agents capable of operating continuously, executing multistep security tasks and orchestrating remediation across the exposure management life cycle. Together, the Tenable One Harness and Hexa's agentic capabilities move exposure management from periodic analysis and manual intervention towards a continuous always-on defense.
As frontier models become more widely available, we believe this combination will become an increasingly important and durable differentiator for Tenable. In addition to the exciting AI capabilities we're building into our platform, we're also helping our customers secure their use of AI.
With Tenable's AI exposure, we're extending coverage to include Gemini alongside Claude, ChatGPT, Copilot as well as major MCP deployments and AI native development tools.
Together, these capabilities give security teams a more complete view of where AI is used, the risk it creates and where action is needed. As part of Tenable One, AI Exposure and Hexa are highly complementary, helping security teams secure their organization's use of AI while harnessing AI to improve operational efficiency.
And finally, we're deepening our relationships with the 2 leading Frontier AI labs, Anthropic through Project Glasswing and OpenAI through their Daybreak program. These partnerships are deep and broad working collaborations. We have access to nonpublic models. We're participating in joint research.
We have early insight into how the attack landscape is evolving before these capabilities are broadly available in the market. More specifically, our testing as a part of Glasswing demonstrated that Frontier AI can dramatically increase the speed and scale of vulnerability discovery, but it also reinforced that discovering more potential vulnerabilities does not by itself tell an organization where it is truly exposed or what it should fix first.
The output requires a trust letter to validate and provide context to determine if an exposure is reachable and exploitable and whether existing controls can mitigate the risk. This is the direction the market is moving, and it's the direction we've been building toward.
Customers need more than just another stand-alone AI feature. They're looking for an integrated platform that can act with the speed and context this moment demands. And that's exactly what we're seeing show up in how our customers are buying today.
Mark will walk you through what that looks like in practice because it says a lot about where this shift is taking us.
Thanks, Steve. The market dynamics surrounding AI that Steve described are increasingly translating into customer action and stronger commercial outcomes for Tenable.
We are now seeing customer conversations convert into action, which we believe points to the early stages of ongoing tailwinds to the business. Customers are moving beyond education to investing in broader, more sophisticated exposure management programs.
They recognize that addressing this new environment requires a unified view of exposure across the enterprise, the intelligence to identify what creates the greatest risk and the ability to take actions before the attackers do.
As Steve noted, Tenable One sales accounted for 50% of new business, a really exciting record for us. We believe 2 factors are contributing to this momentum. First, the pricing and packaging changes we introduced earlier this year have made the path to Tenable One clearer and easier for customers. The new model gives organizations the flexibility to start where they are, expand over time and move seamlessly across asset types and the attack surface with predictable spend, simplified procurement and faster time to value.
Second, the AI-driven threat environment is accelerating customer demand for exposure management. Tenable is meeting that demand with capabilities such as Tenable Hexa and AI Exposure, which are making the value of the broader platform more immediate and tangible.
We are already seeing encouraging signs in how customers engage with Hexa. More than 80% of customers who open Hexa submit a prompt and nearly half are using it to take action rather than simply consuming information. Hexa users are also engaging with an average of 6 Tenable One tools, indicating that the agentic engine can help customers discover and use more of the platform while freeing security teams to focus on higher-value work.
For one customer, Hexa connected fragmented data across systems, workflows and geographies to identify a single patch that could neutralize 53 potential attack paths.
This illustrates the efficiency opportunity Hexa creates, focusing resources on the action that reduce the most risk, accelerating remediation and enabling security teams to accomplish more with their existing resources.
These early indicators reinforce our belief that Hexa can become an important driver of Tenable One adoption and expansion over time. Customers are also seeing the benefits of Tenable One AI exposure, which helps customers discover, govern and secure the rapidly growing use of AI platforms and agents across their organizations.
Together, as part of Tenable One, these highly complementary capabilities help security teams secure their organization's use of AI while using the power of AI to create operational efficiencies. This results in a very powerful preemptive security strategy.
Our position in this evolving market is also receiving external recognition. In June 2026 report, Gartner named Tenable the company to be in AI-powered exposure assessment, noting that Tenable's long-standing dominance in vulnerability assessment, its strong asset and attack surface discovery capabilities and its ability to execute on its AI strategy make it the frontrunner in an AI-powered exposure assessment.
We believe this recognition validates the strength of our position today and our strategy for where the market is heading. Let me bring these trends to life through 3 customer examples from the quarter. First, a global manufacturing services company selected Tenable One Advanced, resulting in a 6-figure deal, replacing a legacy vulnerability management provider.
The deployment brings together multiple asset types to both consolidate and give the customer a more unified view of exposures across its environment. This is another example of a large enterprise moving away from fragmented tools to consolidate on Tenable One.
Second, a leading financial services company significantly expanded its relationship with Tenable in our largest transaction of the quarter. An existing Tenable customer, the company made a 3-year 7-figure commitment to Tenable One, including services.
This expansion demonstrates our ability to deepen relationships with some of the world's largest and most sophisticated organizations and establish Tenable One as the foundation for their exposure management programs. Finally, we also displaced a major competitor who had a long-standing relationship at a large European postal service.
Once again, this customer saw the need to move beyond traditional VM to Tenable One for full exposure management. The win was supported by the region's largest cybersecurity service provider and provides a strong foundation for broader collaboration and additional opportunities in the region.
This was a strategically important win that demonstrates our ability to disrupt established competitive relationships in key international markets. Together, these wins illustrate the broader trends we saw during the quarter. First, increased customer demand for exposure management, driven by the Frontier AI Labs, specifically Mythos.
Second, very strong competitive displacements. Third, increasing adoption of Tenable One Advanced; and fourth, meaningful expansion within our installed base.
In addition to these exciting customer wins, we also achieved FedRAMP high authorization for Tenable One cloud exposure during the quarter, one of the most rigorous security authorizations in the U.S. federal government.
This expands our opportunity in the federal market and reinforces the trust that mission-critical organizations place in our platform. With that, I'll turn the call over to Matt to discuss our financial results.
Thanks, Mark. We delivered excellent results in the second quarter, underscored by our highest ever adoption of the Tenable One platform, which reflects the early success of the new pricing and packaging introduced in the quarter.
Growth in the platform and meaningful operating leverage drove second quarter results above the high end of the range for every metric we guided to for the quarter, and we are once again raising our full year outlook across the board, reflecting the growing momentum we're seeing in the business. Let's dive into the details.
Revenue for the quarter was $268.5 million, representing growth of 8.6% year-over-year. The year-over-year growth in revenue for the quarter as well as outperformance relative to guidance was driven by strong expansion within existing accounts and underpinned by continued strength in renewals.
Professional services, which are often attached to our larger Tenable One deals, also contributed ahead of expectations. Despite the strength in professional services, our percentage of recurring revenue remained high at 95% for the quarter.
We had a record quarter for Tenable One with 50% of new business coming from the platform, a new milestone, up from 41% in the prior quarter and 40% in Q2 of last year. We believe this growing adoption reflects the increasing conviction customers have in leveraging the platform, including Hexa AI to manage risk across their entire attack surface.
Importantly, while adoption of the platform was at an all-time high, we're also seeing an increase in average deal sizes within the platform, reflecting customer preferences for our Tenable One advanced offering, which boasts a more robust feature set and price point compared with Tenable One Foundation.
We added 381 new enterprise customers in the quarter and added 32 net new 6-figure accounts. But my favorite metric of the quarter was our net dollar expansion rate, which improved to 106%, up from 105% in the prior quarter. This is the first quarter since Q1 2022, more than 4 years ago that we have seen a percentage point quarter-over-quarter increase in the net dollar expansion rate.
The growth here was driven by strong expansion and renewals business and reflects important stabilization of our growth rate. Non-GAAP gross margin was 81.4% for the quarter compared to 82.0% in Q2 2025 and within our typical historical range of 81% to 82% over the last couple of years.
Non-GAAP income from operations for the quarter was $66.2 million or 24.7% of revenue compared to $47.7 million in Q2 2025, an increase of 38.8%. We're continuing to benefit from the efficiencies that I highlighted last quarter, while rotating spend into the opportunities for growth in product development and sales capacity.
We expect to continue investing in the second half while still meeting our profitability targets for the year. Non-GAAP earnings per share for the quarter was $0.51 compared to $0.34 in Q2 2025, an increase of 50%. The improvement year-over-year reflects the increase in profitability combined with a decrease in diluted shares outstanding, driven by our share repurchase program.
Turning to the balance sheet. Cash and short-term investments totaled $298.2 million. We generated $45.3 million in unlevered free cash flow during the quarter compared to $44.3 million in Q2 2025.
During the second quarter, we repurchased 5.2 million shares for $100 million and have $108 million remaining on our current share repurchase authorization as of the end of the quarter.
So far this year, we've repurchased 11.4 million shares for approximately $230 million, reflecting an average repurchase price of $20.23. Our repurchase program remains an active pillar of our capital allocation strategy, reflecting our view that returning capital to shareholders through buybacks represents an effective use of our free cash flow, given the underlying strength of the business.
We are realizing the benefits of these share repurchases as our weighted average diluted shares outstanding for the quarter is now the lowest it has been since Q4 2020, more than 5 years ago.
Turning to the financial outlook for Q3 and full year 2026. For Q3, we expect revenue to be in the range of $270 million to $273 million, representing a year-over-year increase of 7.6% at the midpoint. Given the strength we've seen in the first half of the year and our expectations for continued momentum into the second half, for full year 2026, we are raising our guidance range for revenue to $1.075 billion to $1.081 billion, representing a year-over-year increase of 7.9% at the midpoint.
We expect non-GAAP income from operations for Q3 to be in the range of $66 million to $69 million or 24.9% of revenue at the midpoint. For full year 2026, we are raising our guidance range for non-GAAP operating income to $258 million to $264 million or 24.2% of revenue at the midpoint, representing a year-over-year increase of 230 basis points.
We expect non-GAAP net income for Q3 to be in the range of $58 million to $61 million, representing a year-over-year increase of 15.8% at the midpoint.
For full year 2026, we are raising our guidance range for non-GAAP net income to $228 million to $234 million, representing a year-over-year increase of 18.8% at the midpoint. We expect non-GAAP earnings per share for Q3 to be in the range of $0.49 to $0.52 per share, representing a year-over-year increase of 20.2% at the midpoint.
For full year 2026, we are raising our guidance range for non-GAAP earnings per share to $1.95 to $2 per share, representing a year-over-year increase of 24.2% at the midpoint.
We are also raising our unlevered free cash flow outlook at the midpoint and now expect a range of $289 million to $295 million or 27.1% of revenue at the midpoint.
Before I open it up to Q&A, I want to thank the entire Tenable team for another strong quarter of execution. We are really excited by the momentum we're seeing in the business and expect that to continue into the second half. We look forward to seeing you all at the upcoming Stifel and Piper Sandler conferences. With that, we are happy to open up the call for questions. Operator?
[Operator Instructions] The first question is from Rob Owens from Piper Sandler.
2. Question Answer
Great to see the DBNER reverse course here at points. Do you think we've hit the low watermark? Or could we see continued volatility? And secondarily, what are you guys seeing from a new customer perspective, especially given all the noise that's been created in the post-Mythos environment?
Rob, this is Matt. I'll take the first part of your question, and then I'll pass it over to Mark and Steve to answer the second part. Yes, we were really pleased to see the net dollar expansion rate increase quarter-on-quarter.
And as I mentioned in my prepared remarks, the first time we've seen that in quite some time, and it was ahead of expectations. So seeing that strength come through and in particular, seeing that strength continue on now into the second half, that gives us confidence that, that rate holds steady at 106, that's our expectation for the rest of the year, and that's the expectation that we've built into our guidance.
Yes. And I'll kind of hit on some of the customer demand. I mean, as we kind of talked about a little bit in regard to some of the investor conversations, this has definitely been -- when you look at Mythos and some of the Frontier AI labs, this has been a tailwind without a doubt.
So we are seeing strong demand from our customers around exposure management, specifically based on what they've seen and some of the feedback they've been getting from the research that's been done with the AI Frontier labs, again, highlighted with Mythos.
We saw a significant uptick in our competitive displacements of customers that might be on old school standard VM wanting to move to an exposure management platform, moving from competition to us. So that was a very strong highlight in Q2.
And with the new pricing and packaging we've highlighted, we've now been able to streamline and make it much easier and simpler for customers to move into either foundation or advanced, and we saw a higher percentage move to advanced, which was great.
And we're continuing to see the momentum. The last thing is our expansion. We saw some phenomenal expansion. I highlighted one of the accounts in the remarks. We are seeing great expansion opportunity within the installed base. So very strong demand, very happy with what we saw in Q2, and we're going to continue with the momentum.
The next question is from Mike Cikos from Needham & Company.
This is Matt Calitri on for Mike Cikos over at Needham. Wondering if you guys could give some more color on how customers are responding to flex pricing and packaging.
I know you noted greater-than-expected adoption of Advance, which is obviously great to hear. But just curious if there's anything you could share on if customers are in any way rationalizing certain asset types in favor of others? Or if there are any leading indicators in terms of what the actual uplift looks like?
Yes. Well, as Mark commented earlier, we're very pleased with our expansion this quarter and our new lamps. Something that we talked about earlier, but one of the big takeaways from the quarter are higher average selling prices.
I couldn't be more pleased. And pricing and packaging is playing a big role. More customers opted for Advanced, which has a notably higher selling price in comparison to stand-alone VM. We added a healthy number of net new 6-figure customers, but the big takeaway was the number of net new 7-figure customers, which more than double than what we typically do with one of our best net new 7-figure customers adds in nearly 2 years.
Customers -- and what drove that is really 2 things. Number one, customers migrating from stand-alone products into the platform at a greater rate.
And then number two is the customers that are in Tenable One that are expanding where we're doubling and increasing the selling price there dramatically. And things just feel different since April in a post Mythos world. I think customers recognize they need unified visibility. They need unified insights and they need to be able to take action deterministically.
And that's exactly what the platform does. That's what Hexa AI does. And things feel different, and we feel really good about the setup for the second half of the year and have confidence in our ability to continue to execute here.
The next question is from Patrick Colville from Scotiabank.
This is Conner Weed calling in for Patrick. And we were just wondering what the initial feedback on Hexa was looking like from customers? And if you could remind us of what the average selling price kind of uplift looks like for customers moving from VM to Hexa. And if there is a scenario where customer spend goes up to remediate a lot of vulnerabilities that we're seeing kind of currently, but then customer spend kind of falls back as well.
Yes. Just I'll comment a bit on kind of what we're seeing from a demand perspective. So Hexa, we launched in Q2 has actually picked up to a very, very high level in regard to customer adoption.
So we now have hundreds of Tenable One customers using Hexa. And as we highlighted, they're not just using Hexa to go get more information and content. They're actually taking prompts, they're taking actions. They're automating significant parts of how and what they do around automated remediation.
Some of the use cases that we're starting to see is they're creating dashboards for certain exposure scores. They're identifying and updating different findings, now doing this autonomously. They're being able to manage their tagging environment and managing and scanning workflows from servers and workstations.
So the adoption that we have seen has been fantastic. To give you a bit of sense, we actually created a new SKU for incremental tokens for overages from the customers because customers with significant percentages were over on their tokens. So we actually created a SKU to sell them incremental tokens because of the overages.
So all of the signs that we've seen since we've launched. And again, early days, there's going to be some great announcements coming out of Black Hat next week, but super happy and the customer feedback has been phenomenal in regard to what they're actually doing with Hexa.
And I'll just add one thing, too. Hexa, as you know, is only available in the platform. And so that was a major driver of customers adopting the platform in the quarter.
As you know, there's a significant price uplift going from stand-alone VM into Tenable One. And we think a big driver of the record adoption that we had in new business in Tenable One is 50% this quarter was due to some of the improvements that we've made and really a lot of the robust features that Hexa delivers.
The next question is from Rudy Kessinger from D.A. Davidson.
Congrats on the nice results here. You guys mentioned that the uptake of Advanced was higher than your expectations versus Foundation. Could you share any more color on what kind of that split looks like for new logos who are taking Tenable One in terms of what percent are taking Foundation versus what percent are taking Advance?
Yes. So Advanced -- this is Matt. Thanks for your question. Advanced this quarter benefited at a ratio of something like 2:1 versus Foundation. So it was a meaningful percentage higher than what we had seen in Foundation for the quarter.
And the only thing I'll piggyback on that is what we saw with the customers and why we are seeing this significant adoption on Advanced compared to foundation is there are some things with foundation you get. There's some specific cloud CNAPP capability that you get in Advanced that was a very big driver. We're seeing strong demand for cloud security.
You get some advanced capabilities around attack path analysis and some scoring within Advanced, which was a big differentiator.
You also get a significantly more amount of tokens when you go with Advanced. So some of these customers that want to be able to leverage Hexa are getting a significant incremental amount of tokens in Advanced compared to Foundation.
And they just have more domains, more assets that can actually go in different types of assets. So we were extremely pleased with that motion and what we saw. And I think it's one of the reasons that you're now seeing 50% of our new business coming in from Tenable One. I think the pricing and packaging had a lot to do with it and our sellers and our partners are getting just more comfortable talking to our installed base and our competitive opportunities about it.
Great. And then for my follow-up, it sounds like you've got really some good early momentum following Mythos. You talked about NRR kind of being stable at 106%.
I know there's some noise of volatility in both CCB and cRPO. And so with revenue, I guess, being the best indicator of the business for the time being, when might we see some of this momentum you're seeing translate into accelerated revenue growth?
Yes. So some of that we're seeing already. So like we've talked about before, that first step to inflecting growth higher is really to stabilize our top line growth rate.
And the good news is we're seeing early signs of that. We saw that this quarter. So pipeline, super strong this quarter. Competitive win rates, very strong this quarter. We had one of the strongest quarters in expansion that we've had, expansion growth that we've had in quite some time.
And so what that enabled us to do is to raise guidance by $5 million at the midpoint for the full year, which is great. You saw our 106% NDRR rate, which was excellent also.
And then one of the things, when we started the year, we talked about CCB being roughly in line with consensus expectations. And as we sit here today, we think that, that's probably $8 million to $10 million higher than where we started the year with the majority of that benefiting the back half just based on the strength and the momentum that we've seen so far.
The next question is from Jonathan Ho from William Blair.
With your existing AI solutions, what's been sort of the customer feedback? This is the non-Hexa solution? And can you talk a little bit about maybe what that means from an asset coverage standpoint? Is that potentially growing as well as people start to look at the existing solutions that you have?
Yes, Jonathan. First, just some color on Hexa. I think Mark talked about the kind of the commercial traction that we're getting, but it's worth adding a little more color. We're off to a terrific start with Hexa AI.
We see it in Q2, more than 80% of the users in Hexa, summit prompts and use it to take action.
And over 90% of the actions that Hexa recommends are accepted by customers. We're continuing to innovate there. We introduced recently advanced multistep reasoning and automated remediation workflows.
And now we have Hexa that's always on, orchestrating like a continuous autonomous defense without needing humans to reprompt.
So we're getting great traction there. I think you asked about our non-Hexa capabilities as well. And that would take us really to exposure AI, AI exposure, which is important because it addresses a couple of key use cases. And we do really 3 things, right? And if you think about Hexa AI is the ability to take action within the platform deterministically with trust, what AI exposure does, it helps customers understand AI as a threat vector, which is one of the biggest blind spots in all of security today.
And look, it starts with visibility, and we do 3 things. Number one, visibility, and we help discover what's running in a customer's environment, shadow AI agents, browser plug-ins, APIs, things like that.
The second thing we do is we provide infra protection, infrastructure protection related to AI models, workloads and agents themselves. We can discover agents. But more importantly, we understand when agents are connected to and what they have access to and whether it's exposed to the Internet and what kind of permissions kind of surround agents and if there's identity weaknesses.
And the third thing, we monitor customers' use of prompts across a wide range of models and ties back to security policy. So both on the front end, helping customers understand their posture and helping them secure their use of AI as well as AI infrastructure and also helping them take action deterministically with trust on the back end and the platform so they can reduce their risk.
So we're certainly at the forefront of AI and security and we have a big role here to play, and you're starting to see some really good traction on it.
Excellent. And just as a quick follow-up, you talked a little bit about your harness advantages relative to other exposure management providers. Can you talk a little bit about what you have that's unique there? And are you concerned at all about the LLM providers maybe trying to move more upstream into your area? Can you just talk about the barriers to entry there?
Sure. And it's something we talked about at Investor Day. I mean look, the moat here, we're likely starting to see the commoditization of the intelligence layer.
I think models will continue to get infantly good, and that's important. There's also open weight models that give enterprises flexibility and control to effectively deploy AI in their own environment.
Again, the best model today may not be the best model tomorrow or 6 months or even a year from now. But with that, the real moat, we think will be above the model and below the model.
The real moat will be the application layer, which provides the context and trust to run these models safely and securely and deterministically in your environment. And Hexa was built with this in mind. Hexa routes the right task to the right model, frontier or otherwise and allows customers to take action in near real time with confidence.
And also moat is below the model, which is the extensive sensor layer and the ability to deploy agents and scanners and sensors on a wide range of domains to be able to collect data.
We have one of the largest data fabrics in all the security, one of the largest customer bases. We're deeply embedded behind the firewall. It's proprietary. It's unique to us. And now with our harness, which is the scaffolding around the model and orchestrates the workflow and allows us to take action and to reduce risk with customers deterministically. That's an important part of the value add. It's one of the reasons why customers are increasingly choosing Tenable One. It's one of the reasons why 50% of all of our new business is coming from the platform. And we feel really good about differentiation in them.
The next question is from Brian Essex from JPMorgan.
I guess -- I would love to follow up and get your feel, and I apologize if I missed it, we're bouncing around between a few calls.
But the one thing that resonated throughout this quarter across the last quarter across most of the companies that reported in this quarter across most of the partners that we spoke with is that CFOs or CIOs are freaking out about Mythos.
And it's leading to an elevated threat environment, and there's an emphasis to push to get the most updated software operating systems, hardware into those enterprise networks. And I just want to kind of take a step back in terms of what you've commented on in terms of pipeline acceleration, how companies are engaging with you to address those concerns and how an elevated pipeline might convert to revenue as you kind of walk through the year, how much visibility you might have on that?
Yes. So let me take a shot at that one because there's a couple of different parts of it. So first and foremost, right, the Mythos kind of AI lab discussion is still omnipresent, right? So it's still happening. It's still going on. There's still an enormous amount of interest from customers on, a, what we've learned as a cybersecurity company and the pressure they're getting from the Board of Directors and from the CEO.
And so it is definitely creating this demand. It is creating sense of urgency. So when you're talking to CISOs and they're saying, "Hey, we know that there's going to be this massive influx of vulnerabilities and all of these other potential risks coming down the road." We know that one of the most productive things we can do is have a preventative and proactive exposure management platform so we can actually get ahead of it and understand what's happening and get true visibility across the entire attack surface.
And so we are going in having those discussions, and that's why you're seeing Tenable One hit that 50% of new business because customers want to get RPM. They want to get all the benefits of exposure management, and they are doing it with more urgency.
So you're definitely seeing that. That's why Matt commented, we are seeing accelerated pipeline. Obviously, we feel great about what we achieved in Q2 and the guide that we gave for Q3 and Q4. There is a significant amount of momentum in this business right now and in exposure management.
And so that is definitely a tailwind without a doubt. From a budgeting perspective, it isn't -- you're not seeing this massive incremental flow of budgets saying we're going to increase the cyber budget by 10%, 15%, 20%.
What you are seeing is this consolidation story happen at a very rapid pace. They do not want to have the number of tools. They want to consolidate. They want to do more, right, with fewer vendors and have platforms.
And so you're seeing these exposure management projects happen at a faster pace, and that's why you're seeing kind of the positivity and some of the momentum we're seeing in our business because that's what's happening at the customer level.
And is that permeating through like the network scanning exposure that you might have? In other words, are they scanning more of their estate? Or are they just taking what they have and then focusing on the analytics aspect of it?
No, it's a great question. It's both, but we did see a very significant pickup in our expansion business in Q2. So we absolutely saw our installed base customers expand the asset coverage to, again, get better visibility on what's happening in the environment.
So we absolutely saw that. And we saw them look at incremental different types of assets. So we had a very strong OT quarter. Very strong OT quarter around the globe, especially in the federal government. It was outstanding. We saw strong cloud demand for that asset type. And so it's both expanding overall coverage within their environment, their infrastructure environment, but then also looking at incremental asset types.
The next question is from Meta Marshall from Morgan Stanley Investment Management.
This is Abhishek Murli on for Meta Marshall. Could you talk us through some of the dynamics you're having with customers as they are looking to move towards automated remediation? I understand there was some press release in intra-quarter as well on this, but I would love to hear what you're hearing on the ground. And then I have a follow-up.
Yes. I think Mark talked about the momentum that we have with customers. This is a quarter where we added over 300 new customers, a healthy number of new lands.
This is a quarter where we added a healthy number of new 6-figure customers. The big takeaway was really the expansion within the customer base and the higher selling prices and packaging and pricing plays a big role in that.
And with that, there's really 2 core use cases around our pricing and packaging. Number one, Foundation, which is all about unified asset visibility with discovering and continuously inventorying assets across a wide range of domains.
But as Mark called out, the reason why customers are choosing overwhelmingly advanced where the selling prices are notably higher, which is having an impact not only on the results for the quarter, but gives us confidence to have a really good raise for the full year is really because of the ability to take action and measure risk for customers.
So the orchestrator remediation comes in advance. Risk measurement and benchmarking and scoring, that comes in advance. That's a big problem, and that's the problem we're here to solve. That's the critical asset in the AI and the agentic era, and that's the moat we have.
So things, as I mentioned before, feel different. Customer conversations feel different. Obviously, all of this has to go through procurement and sales cycles. But we feel really good about what we're seeing in the business, and there's some good early signs of strong momentum here. And that's the takeaway.
Super helpful. Maybe as a follow-up, you also laid out in the Analyst Day that the Tenable One platform could be around half of revenue in 2029.
I guess given the traction you're seeing across the portfolio, is there a potential that to happen sooner?
We're definitely seeing progress towards that goal. I think at the time of Analyst Day, we called out Tenable One making up roughly 1/3 of our total business.
That number is increasing. We hope to get it up to 40% by the time we get to the end of the year, and we've made some progress against that goal already. So having a quarter like we had in Q2 where we had a record amount of new business coming into the platform certainly helps.
But we've increased from 1/3, and we're on our way to 40% and hope that, that's where we get to by the end of this year.
The next question is from Joseph Gallo from Jefferies.
This is Grant Darling on for Joe Gallo. I wanted to circle back real quick on competition as I think it's certainly clear that exposure management is increasingly important in an AI world, which puts you in a great position.
But I wanted to ask, has there been any changes in competitive dynamics with regard to some of these larger platform vendors, especially with them trying to embed some of these LLM technologies and what you're seeing there?
Yes. I mean, listen, we commented on a couple of the customer examples that we gave and in some of the commentary. This is one of the best competitive quarters we have had.
Our compete level in regard to the deals of [indiscernible] and replacing incumbent players was unbelievably strong with very specific programs, which grew double digits in Q2.
So we're super happy to see that. And it was a very strong quarter in regard to some of the larger players that have pricing and packaging where they talk to a customer and want to give away free capabilities as part of their pricing and packaging, we had a very strong quarter there.
There are certain things when you look at Tenable One and exposure management about visibility, right, in the entire environment that we see that these players simply do not see. We've got massive advantage around our accuracy and finding significantly more vulnerabilities in some of these free solutions bundled in.
We also -- when you look at just the coverage, the amount of coverage we have around [indiscernible] coverage is exponentially more than that.
So when we deal with CISOs and lay out the technical differentiation we have, we have an extremely high win rate and compete level. And we saw that without a doubt in Q2.
The next question is from Jonathan Ruykhaver from Cantor Fitzgerald.
So I'd like to just talk about the importance you see of identities within exposure management. It would just seem to me at least from a high-level view that including a view of [indiscernible] that includes exposure risk related to identities kind of broadens out an exposure management view.
And I know you have the Tenable identity exposure solution in the market. We haven't heard much in terms of adoption. But just where are customers around that vision of including identity risk Path? And what do you expect to see out of that solution looking out the next couple of quarters?
So what we're seeing is you're 100% right in regards to the importance of identity. And where we have really taken the identity technology that we've had, we've very much from an engineering perspective, been focused on embedding it seamlessly into Tenable One.
And so instead of selling it as an independent identity solution, it's about how do we get leverage within the Tenable One platform. So when you hear us talk about one of the big differentiators, which is our attack path analysis, that is a huge play from an identity perspective, where we're able to differentiate and get insight into certain areas around the attack path that other platforms simply cannot do.
So it is definitely -- when you look at kind of decision criteria being created for exposure management platform, it's one of the areas that we differentiate. We've got a long history in the identity business. And now it is embedded into Tenable One, and it's allowing us to get leverage based on the advanced feature set and capabilities and monetization of identities also.
So is it more about driving that attach across Hexa and exposure management or compared to the monetization opportunity, just explain that.
Yes. This is Steve. And just what Mark said, it's really an important contextualized feed in the platform itself. And so the ability to first identify flaws and exposures.
And if you look at our data fabric, a substantial percentage of what we have is non-CVE related. So understanding critical vulnerabilities and exposures, understanding where they exist across what asset systems, devices, workloads, models and then more importantly, understanding if those laws and exposures are on those systems that have sensitive data for the contextualization.
All of that feeds into and is scored with regard to risk. And so prioritization becomes critical where the identity is an important aspect to that because we need to look at the access and entitlements.
So in order to identify attack paths, you need to basically aggregate and change together all of these different exposures. You need to understand prioritization and contextualization, which we're able to do leveraging our harness and therefore, be able to take action.
So access and entitlements are important here. You have to understand in the event that there's an incident or attack, what is the blast radius, who owns which assets, which systems.
So it's an area we're going to continue to focus on. But it's one of the reasons why customers continue to buy the platform. It's an important part of the value add when it comes to attack path analysis.
The next question is from Joshua Tilton from Wolfe Research.
This is [ Yvon ] here on the line for Josh. Maybe one more on the competitive side. Microsoft announced a VM program a couple of days ago. So I just wanted to get your thoughts on how -- what are you thinking about that? And how do you see Tenable's positioned in this context?
Yes. I mean, listen, we feel very, very strong. As I said, a lot of the points that I brought up earlier fall into that category in regard to when we're discussing Tenable One and we're discussing exposure management, they're really -- right now, especially with some of the front AI labs and the heightened threat landscape and some of the things you're seeing around some of the state-sponsored attacks that happened, for instance, in Minneapolis, people and CISOs are looking for best-of-breed from an exposure management perspective.
So we feel, again, very, very confident about our compete level against Microsoft and what was launched. And we just will keep on working with our CISOs and walking them through the value prop of what we do from a Tenable One perspective.
The next question is from Kingsley Crane from Canaccord Genuity.
So I appreciated the comments on differentiation above and below the model.
At the Investor Day, you talked about part of that differentiation coming from 300,000 plug-ins built over time, producing around 100 new plug-ins per week. So if AI is reducing time to exploit and then with what we've seen with some of these more novel agentic attacks, I'm just wondering if there's room to accelerate the new plug-ins per week with AI-enabled threat discovery, tying into your deep partnerships with OpenAI and Anthropic or even using some of those open weight models. Just kind of curious your thoughts there.
Yes. The short answer is we are. So I think the point we made at Investor Day is that humans in the loop still matter, humans doing research. Providing plug-ins and coverage for 0 days well before even a cab is published.
But we're also leveraging AI in a way to create plug-ins and automate the process. You still need a humans in the loop to exercise judgment.
But look, threat actors have the ability to weaponize AI and move at machine speed. And so our goal here with the platform and exposure management is to be able to put capability in the hands of defenders so they can move even faster.
Mean time to exploit here, I think, has compressed over the year from 30 days down to 1.6 days. If you look at the average SLA for applying a patch, that's like 30-plus days. So we have to do better. That imbalance right there creates the risk. It's one of the reasons why in a post-Mythos world, customers are increasingly choosing the platform.
Our goal is to not build a bigger telescope here. Our goal is to tie vulnerabilities and exposures to fixes and to fix things to shrink the attack surface, to take action, change configurations.
So what you mentioned here is exactly how we're applying AI. We're applying AI only in the product, but also on the back end on the plug-ins and the coverage, and it's one of the reasons why the number -- our coverage in our database continues to grow.
And we have one of the largest data fabrics in the market, and it's driving the actions that we can take deterministically with Hexa.
The next question is from Shaul Eyal from TD Cowen.
Steve, a very simple question. What are your hiring plans into the second half of this year? Or maybe in other words, how do they build on the first half of 2026, given the success you're seeing out there?
Yes, great question. We saw -- some of the highest levels of productivity in sales that we've seen in a few years here. We are going to add capacity in the second half of the year.
More capacity in the second half than we've added really over the last 2 years. So we have confidence to go out and invest. We have confidence that we'll generate return. Mark and I spent a lot of time on this. And we're going to continue to invest and balance growth with profitability. So we see a big opportunity here, and we're pleased with the productivity levels and the achievement rates against quota, and we're leaning in.
The next question is from Richard Poland from Wells Fargo.
So I just wanted to get an understanding of -- it sounds like there's a lot of excitement around just the value proposition that Tenable is able to deliver, the activity that's kind of going on, whether it's actually converting to pipeline or not.
But I guess like I think one of the things investors are going to struggle with is when you just look at kind of what's implied in Q4 revenue growth and just the back half guidance, it's still not perking up to the tune of exactly what we've been hearing in the whole call.
So I guess just to level set, help us bridge kind of the excitement or activity you're seeing in the market, some of the competitive displacement with just kind of where numbers are headed.
Sure. Yes, I can take that. I think just to level set, right, we are in a better spot today than we were 90 days ago with respect to the second half and pretty meaningfully.
And as you know, revenue is a lagging indicator, right? It takes a while for -- when you book a deal, of course, to recognize that over the course of the contract because we're recognizing that revenue ratably.
So we took the guidance up for the full year by $5 million at the midpoint. And of course, a portion of that is in the second half. But then importantly, and I mentioned this earlier in response to your question, our expectations with respect to CCB that we laid out at the beginning of the year have improved by $8 million to $10 million, and the majority of that is coming into the second half.
And so I think that's important. When you break down the kind of Q3, Q4 dynamics with revenue, that's -- there's a little bit of timing going on there with expectations when we think professional services are going to come in.
But the key takeaway is that the second half is better for revenue and meaningfully better when you look at our short-term billings.
This concludes the question-and-answer session as well as today's teleconference. You may disconnect your lines at this time. Thank you for your participation.
Tenable Holdings, Inc. — Q2 2026 Earnings Call
Tenable Holdings, Inc. — Q2 2026 Earnings Call
Tenable beat Q2 guidance, with record Tenable One adoption, Hexa AI traction, a guidance raise, and continued share buybacks.
📊 Quarter at a Glance
- Revenue: $268.5M (+8.6% YoY)
- Net expansion: Dollar-Based Net Expansion Rate (DBNER) 106%, up from 105% and first QoQ increase since Q1 2022
- Gross margin: Non-GAAP gross margin 81.4% (vs 82.0% prior year)
- EPS: Non-GAAP EPS $0.51 (+50% YoY)
- Recurring: Recurring revenue ~95%; repurchased 5.2M shares for $100M
🎯 What Management Says
- Platform push: Tenable One (now sold as Foundation and Advanced) drove 50% of new business; Advanced adoption was higher-than-expected, lifting average deal sizes
- Agentic remediation: Hexa is positioned as an agentic engine inside a "harness" that routes actions to models and enforces human oversight, audit trails and deterministic fixes
- AI coverage & partners: AI Exposure expands coverage (Gemini, Claude, ChatGPT, Copilot) and deep partnerships with Anthropic and OpenAI give early visibility into frontier-model threats
🔭 Outlook & Guidance
- Q3 revenue: $270M–$273M (midpoint +7.6% YoY)
- FY revenue: $1.075B–$1.081B (midpoint +7.9% YoY); non-GAAP operating income raised to $258M–$264M (24.2% of revenue at midpoint)
- EPS & cash: FY non-GAAP EPS $1.95–$2.00; unlevered free cash flow $289M–$295M (~27.1% of revenue midpoint). Risks include timing of professional services, billing/revenue recognition lag, and evolving AI threat volatility
❓ Analyst Q&A
- Expansion durability: Management expects DBNER to hold at 106% for the year and built that into guidance, signaling confidence in renewal/expansion momentum
- Hexa traction: Hundreds of Tenable One customers on Hexa, >80% submit prompts, ~90% recommended actions accepted; token overages led to a new SKU—Hexa is accelerating platform adoption
- Competition & pipeline: Strong competitive displacements reported (including legacy VM vendors); pipeline acceleration cited but revenue recognition is ratable so near-term revenue lags observed activity
⚡ Bottom Line
- Investor take: Q2 validates Tenable's platform and AI-led strategy—record Tenable One uptake, Hexa momentum and a modest guidance raise show stabilization and upside potential, though conversion timing and competitive pressure remain execution risks.
Tenable Holdings, Inc. — Analyst/Investor Day - Tenable Holdings, Inc.
1. Management Discussion
[Audio Gap]
I'm going to actually spend a few minutes talking about the world we're actually living in today. And a lot of what you're going to hear are the themes that we actually heard over the last 2.5 days coming out of our incredible Exposure 2026 conference.
I'll talk about the trends that are impacting the attacker defended dynamic and how AI is changing that dynamic and ultimately, how this sets us up for an exceptional opportunity for exposure management and especially towards Tenable One and when Steve comes back on stage, he's really going to walk you through a bunch of detail on how we see that playing out.
So for 2 decades, right, we're talking a long time for 2 decades, the cybersecurity world kind of operated in this cyclical cycle, right? We would go through and we would look and find vulnerabilities, right? We would then fix those vulnerabilities, and then it was all about reducing risk after you did those first 2 steps.
During that period, however, the assumption was that the volume of critical exposures would remain within what humans could actually handle. Tenable evolved significantly through each stage of that market transition. So you think about Nessus, looking at and solving the visibility problem, you then look at VM, which solve the prioritization challenges and now exposure management.
And exposure management has emerged because cyber risk became interconnected across the entire attack surface. Think of OT, cloud, right? SaaS applications, totally transformed. And now with AI that is accelerating that interconnected risk at machine speed.
And it has actually changed the economics entirely, right? CDs grew from roughly 18,000 in 2020 to more than 48,000 in 2025. And keep in mind, these numbers do not include the impact that the Frontier AI labs will have on those numbers, right? The question no longer is can we find those vulnerabilities right? That's not the big strategic question.
The question now becomes, can we reduce the risk at machine speed before the attackers before the bad guys. So this is why exposure management in Tenable One it literally is no longer just the best practice, and we heard it in this conference is literally becoming a nonnegotiable platform in this AI era. So let's talk a little bit about that.
Okay. AI is increasing cybersecurity pressure from 2 directions simultaneously, right? First, AI is creating more exposures. Right? AI is dramatically accelerating how software is written, deployed and interconnected, right? 84% of organizations are already using or planning to use AI in their software development process.
Think about how fast 84% of these organizations, how fast that has happened over the last 18 to 24 months. Most security teams, though, still lack the visibility into how and where AI is being used across the SDLC. This problem and all these issues about having insecure apps entering production faster than the security team can actually govern them.
So the guardrails simply were not there yet. Most organizations still lack the visibility into where AI code, AI agents, AI apps are operating across the entire enterprise in their environments. The second big area, right, is around discovery. Frontier models now analyze massive code bases and accelerate vulnerability discovery at machine speed. When once required weeks or months, specialized effort that manual effort is no longer scalable.
Recent research, and this is some crazy stats are going to start throwing at you guys in a second. But recent research from Google found early evidence that attackers are beginning to use AI to discover vulnerabilities to support these exploitation activities at scale. And we actually heard some rumblings of this week here at this conference.
So the window between exposure creation, discovery and exploitation continues to compress at lightning speed. All right. So let me kind of go deep on some of these numbers to put some context to it, so you can kind of understand the ramifications and what we're going to be working with.
The disclosure to exploit window has effectively collapsed, right? If we take a look at 2021, the median time from a vulnerability disclosure to a known exploit was 771 days, right? You look at it moving forward and look at where we are today, it's 1.6 days. Right?
In February, entropic OPUS 4.6 found more than 500 days in open source code, which is an order of magnitude increase than anything we've seen before, right? And on April 7, when anthropic-released mythos, it discovered thousands of software vulnerabilities that went as far back as 1999. And according to Anthropic, which we had here at our conference this week, which was awesome, 99% of those disclosures still remained in patch.
So the reality is the attackers can find these old vulnerabilities with the power of AI to create sophisticated attacks. That is one of the ways we have not seen yet before. So this is a consequence of everything we've been talking about at this conference and over the last 15 to 18 months, right?
AI is increasing the number of exposures entering our customers' environments. The result is an explosion of findings, but more findings don't automatically make the organization safer. In fact, the customers -- our customers are actually already overwhelmed with the amount of information they're getting.
Last year, this stat is significant. Last year, more than 60% of organizations, right, that had a breach or a ransomware attack, they actually had a patch available on the known vulnerability that was exploited, but they weren't able to put it into production. Right? That's an unbelievable stat because it tells you the problem isn't simply finding vulnerabilities. The problem is understanding which exposures actually matter at reducing risk before the bad guys can operationalize them.
Again, this is the trend that I think a lot of governments, a lot of organizations are going to start kind of going through. More findings, more noise actually brings less clarity for our customers. Okay. So the answer is not going to be solved by AI alone, right?
And it is true that front to AI models are dramatically accelerating vulnerability discovery but as we said, discovery alone does not reduce risk. Organizations still need to -- let me run through this list. They need to understand what assets exist. They need to assess their exposure and every organization is different prioritize what truly matters, coordinate remediation and validate that risk was actually reduced.
That is the difference between vulnerability discovery and exposure management. So even when teams know where there's exposures, where they could be impacted, acting on it fast enough is absolutely the challenge. Remediation still requires coordination across the teams, the tools and the environment. And most of the processes remain fragmented and manual. Again, this was a huge theme we heard the last few days, right?
So the customers are really demanding a shift, right? They're not asking for more tools -- that's why when Steve and I and Matt talked to the Street, we always talk about how consolidation is 1 of the biggest drivers out there, right? They're asking for systems or platforms that help understand risk and that could actually take action.
That is the opportunity. And literally, that's exactly what we built Tenable One for, right? AI, when you take a look at it, AI is in a temporary disruption, right? This is a secular shift and how security operates. This is not a onetime event like Log for Shell. This is how business is going to be run moving forward.
As the speed of both discovery and exploitation is accelerating a fundamental shift is absolutely required, right? And it will be defined, but what we view as 3 transitions from discovery to taking action from manual workflows to orchestrated fixes and from isolated tools to an integrated platform and 1 of a system of action that requires a platform to be capable of understanding risk across the entire attack surface and coordinating action fast enough to keep pace at machine speed.
And again, that's why we focused and centered an engineered tenable 1 to do. And with that, I'm going to hand it back to Steve, right? And Steve will be able to walk you guys through more detail on how we're putting this plan into action. Thank you very much.
Okay. Hello again. What Mark just described is not a temporary disruption. It is a secular shift, a major secular shift to security and how it operates, and it's a shift towards exposure management. And speaking of the platform. Investors often ask us what makes Tenable and is platform defensible? Not just now, but over the long term. And the answer is that Tenable One is built on 3 critical layers.
Each one is a moat in its own right, but together, they compound. The first is our sensor layer. It's the data collection, infrastructure inside of a customer's environment that the rest of the platform sits on. The second is our exposure data fabric. It's where raw telemetry data becomes a unified model of risk and how it forms. And the third is HEXA, our Agentic agent. It's where knowing within an environment becomes action with human oversight, built in, and that's important. Each layer is hard to build. All 3 together, we believe, are nearly impossible to replicate. And together, they're the foundation of how security gets done in the agentic era.
So let's spend a little more time today going through each one. Okay. Everything starts with data because how and where you collect that data is important. How and where you collect that data, determines what you can see. And we believe we can see more inside a customer's environment than anyone.
We have scanners operating in enterprise environments. We have agents on endpoint and workload. We have passive network monitoring on OT networks. We have cloud configuration and workload analysis. We have identity telemetry, both on-prem and in the cloud, by the way, and we have external attack surface discovery and now visibility into the signals around AI applications, agents and systems.
In short, we're a data aggregator. We're a data compounder. We have one of the broadest sensor and telemetry networks in the industry hands down. It's infrastructure. It's sticky, and it's a hard one, and it's nearly impossible to replicate. So that's what Tenable does directly to assess exposure. And while it's comprehensive, we recognize that no 1 security company can assess exposure across the attack surface.
The market is far too fragmented for that. That is why having an open architecture to ingest data from other security providers is important. We have 300-plus integrations. And today, we just announced an open connector.
So organizations themselves can ingest data. from almost any source. It doesn't matter if you have an API or a connector, they have the power to do that. We connect with it, we transform it and we make it actionable because in a world where the attack surface is expanding the ability to unify data, normalize it, decorate it and deduped is critical and it's foundational. Okay. But data even great data at scale does not create clarity. In fact, it can create more noise for security practitioners and it often does.
That is why our exposure data fabric is so important. It creates insights from action. And it's not separate data feeds sitting next to 1 another in silos. Instead, it's a unified model of how various domains interact with vulnerabilities and configurations and it's how risk forms around them. And that model, it's not powered by telemetry alone. It's enriched by the efforts of our Tenable research team.
Yes, humans still matter. It's important because our tenable research team helped us understand emerging threats, Help us understand exploits and help us understand the exploitability of vulnerabilities and exposures. Now all of this intelligence becomes part of the reasonable layer of the platform. which our partnership with anthropic helps us accelerate. We'll talk about that momentarily.
But the important takeaway here is here with our data fabric, customers understand which combinations of exposure are most important and they understand how to prioritize those exposures because prioritization in the genetic era is not optional. It's critical. So it's also the foundational layer of how customers can take action and take it deterministically with confidence, which takes us to PEXA, Agentic engine.
Yesterday, we announced the general availability of Hexa, our gentic engine, which is powered by anthropics latest models. Hexa sits on top of our exposure data fabric and turns what it knows into action. It orchestrates the steps required to identify the fix and then closes it and validates that the fix has been done. Now we do this all through a series and a fleet of coordinated agents that sits on top of 1 unified model, all operating with humans in the loop. And customers can also build their own agents.
So instead of handing teams and enumerated list of vulnerabilities and say, "Here you go, PEXA can identify attack pass, can make recommendations, the best recommendations about the actions to take and can orchestrate those fixes.
You're going to hear directly from Eric momentarily. We'll show you some incredible things about what Hexa can do. And you're going to hear from customers today about how they're using Hexa to solve some really important problems.
Okay. Now we realize that not every customer is ready for autonomous action, at least not now, okay? That's coming, but not now. environments are complex, governance models vary and trust, trust and automation happens over time. So that's why -- Am I missing a slide here. Yes, I think I am missing a slide. Okay. That's why we think about remediation as a continuum, right? It's a continuum. -- based on the size, the sophistication, the maturity and the risk tolerance of the customer.
On one end of a continuum is manual remediation. That's where customers identify risk, they figure out what actions they take.
And then they go out and take those actions manually. That's where the market is today. That doesn't scale in the agentic era. You need to match machine speed threats with machine speed action. The second phase in the continuum is assisted remediation -- that's where AI prioritizes the risk. That's where AI accelerates the decision-making.
And that's where AI orchestrates the fix with humans in the loop. You've heard that a couple of times now. It's really important. And the third phase is really autonomous remediation, okay? And we're not talking about every workflow or every action, but we're talking about autonomous remediation where customers have guardrails where there's a repeatable process and where the action is well understood.
And we're not there yet, but that's where the market is going. And Hexa is meant to address the latter 2 phases assisted remediation and autonomous remediation. But directionally, that's where the market is going, Hexa is leading the way. And now more than ever, if that is important.
So let's kind of bring this home here. Our work with the Frontier AI models companies are strategically important. Before I describe how we're working with them. I want to answer another question that we also get from investors because it's an important one.
And the question often goes like this. What happens if one of the frontier model companies decides to compete with tenable. It's a fair question. And the answer to that question becomes well understood, want to understand what they're trying to build and what they're not because there is a clear mandate with entropic and others.
They are racing to build the most capable, the most efficient intelligence layer. In the world, and we're big fans. It's extraordinary, the reasoning engine. The Frontier model companies, though, are not in the business because I made that very clear today. of deploying scanners in a data center, a dropping sensors on an OT network running on a power grid on municipal water supply on an oil refinery.
They're not in the business of auditing cloud configurations at 3:00 in the morning and then taking the support call. They're not in the business of scanning a container image before it ships. And they haven't earned the right, not yet, and I don't -- and I say this in a very loving way, but they haven't earned the right, not yet to be deployed on a domain controller at a Fortune 500 company.
We have. It takes years of trust to build. That is infrastructure, and the infrastructure layer is what matters in the Agentic era. The LOMs are only as good as the data, they're reasoning over. They require a data fabric and a trusted sensor layer underneath. And all of our data is proprietary.
We're running behind the firewall. And are not able to publicly train on our data. And that's why we're partnering with them. And that's why they want to partner with us, okay? Because no model is designed to do security autonomously.
Instead, we're here to help deploy AI safely and operationalize it. Okay? And yesterday, we announced -- you may have noticed a strategic partnership with Enthropa to help advance the next era of agentic exposure management. Anthropic brings the resin engine, Tenables the exposure intelligence, the operational context and the infrastructure layer required to safely deploy those capabilities inside complex enterprise environments.
And through this partnership, we're not only leveraging Quad to help power tenable. But instead, we're collaborating closely. Hexa and Tenable, we're collaborating closely on joint research. We have access to nonpublic models and we're advancing a Agentic workflows, and that's really important. Together, we're building the systems capable of understanding attack pass determining the smallest set of actions that have the biggest impact on risk.
And together, we're helping orchestrate the right fixes. So defenders can move with confidence deterministically and ensure that risk has been reduced. This is a fundamentally different operating model than other security tolling, okay?
We're moving from isolated systems, two, an integrated system of action and one system to help customers reduce risk. So in a world where the attack surface is expanding, we will see a proliferation of CVEs and caps right? We're going to see more vulnerabilities, new vulnerabilities than ever before by 10 or 20x. This is how we win. This is how we grow. And this is how we help our customers solve the most important problems in security today.
So thank you. With that, I'm going to turn it over to Vlad, our CTO.
Right. Good afternoon. It's a pleasure to be here. So as Aaron mentioned, I'm fairly new to the company. So I genes 5 months ago as the CEO for Tenable, I also lead Tenable research and managed Tenables R&D center in Israel. .
Before that, I spent 11 years at Microsoft working on security as their corporate VP for cloud and AI products Working alongside Eric, actually, that was the previous time, we did a bunch of things together, building products like Defender Cloud, Defender, the micro security graph, MicroSet and a bunch of others.
So we're here today to talk about exposure management, but I also want to start by showing what drives the pressing need. And why, as an example, a month ago, the U.S. Federal Reserve Chair and the U.S. Treasury Secretary have convened an emergency meeting in Washington, D.C. with the CEOs of the U.S. major banks. Bank of America, Citigroup, Morgan Stanley and a few others.
They were there to discuss a single AI model that was [indiscernible] Metros preview and the significant risks it might create. Now Mythos was, of course, designed for defense, for software engineering, for security. But it also had capabilities that could flatten the stability of financial systems if it was to fall into the wrong hands.
The CEOs were directed to treat that as a top threat to their institutions. Allow me to zoom out into a slightly global point of view. Now 2 weeks ago, I have attended the World Economic Forum's Annual Meeting on cybersecurity in Geneva.
The goals of the cybersecurity center of the forum is to coordinate the global several defense across the ecosystem to partner in the fight against cyber crime and ransomware and overall to strengthen the cybersecurity and several resilience of critical infrastructures and businesses worldwide.
The event was attended by about 150 of the top CISOs, CTOs and CEOs across the private sector, government ministries heads of national cyber defense agencies and many others. At the closing session of that 3-day event, the participants were presented with this question. what will define cyber risk in 2027?
The answer was clear, with 46% of the votes going to AI as a threat multiplier. Now a slightly distant second place went to the response of geopolitical escalations that could target critical infrastructures. Now I think it is quite clear that AI in the hands of attackers is both a bad idea, but it is also a global concern in 2027, but for sure, it is also our current reality today.
There's almost like a shift of mindset came up across every panel and every workshop at the forum. And that is traditional patching cycle is no longer relevant. AI in the genetic economy is the next greatest vector of global risk. And that also needs a new operating model. And I think that's the model we are also building our platform around.
Let's take another look from the eyes of the overture this time. Now [indiscernible] have been tracking attacker speed for about 15 years. Looking at this chart that shows time to exploit. In fact, it presents the average number of days between patch availability and the first time we have observed exploitation of that vulnerability in the wild.
Now you can see on the left-hand side, the slide starts at about 2018, you see 63 days, then goes down to 44 days, 32 days in 2022, it's kind of a linear reduction. Something happened in 2023. It broke the trend. The time to exploit collapsed from 32 days to just 5 days. In 2024, it went negative 1. And Google [ Mandiant's ] report from last month puts that number at a negative 7%.
Now the moment that line has crossed 0, that's a yellow dotted line. That's the moment patch the patch cycle basically stopped working. It means that adversaries today are exploiting vulnerabilities on average, a full week before a patch is even available.
Now this also shows that it's not a snapshot of a point-in-time situation. It's a curve, it's a trend, and it's quite clear where this is going. Now I've been doing cybersecurity for about 25 years, and the rhythm was roughly the same.
And Mark and Steve touched upon this as well. Somebody usually human security researcher finds an issue in code, find the security vulnerability. They then traditionally use responsible disclosure to disclose it to the vendor who then goes and tries to fix the software.
Eventually issuing a patch or a new version. Adversaries have operated on a similar cycle, although they're not in the habit of disclosing that to the vendors, but they also look for issues and code. Sometimes they get the patch and the dereverse engineering to recognize it and use it in the wild.
That window between discovery, patch availability and active exploitation used to be measured in months. Now traditional patching takes days. The last data point we have from Verizon report released earlier this week was that on average, security teams take about 43 days to patch.
It was actually better last year -- but it was largely fine because you had the time. The best teams today, by the way, can probably pull it off in anywhere between 5 to 8 days. It's a big improvement, but it is still fairly off mark. Now that compression of time is driven by 1 thing.
And that is that AI today can do in hours, minutes, sometimes seconds, what it takes humans weeks and months. Now we've heard it here, we saw it in the news, we were living it with [indiscernible] 6 in February, finding vulnerabilities that have survived decades of one review. Later methods came along, it found a bunch of vulnerabilities as well.
But more so, it has changed logical flows. It has found lower severity issues and chain them together in a way that previously only humans could do into critical vulnerabilities. It has also built autonomously working exploits of those security issues.
Now about 11 years ago, we actually saw a similar watershed moment with AI. That was when Google deep mined AI, AlphaGo has successfully defeated the human master go player. Now for a very long time, GOL was considered the ultimate challenge for AI. It's a gain that was played for over 2,500 years and experts believe that computers were still decades away from being successful at that game.
The thing is the game of Go has more possible board configurations than ATMs in the observable universe. -- that stand to the power of 170. And to that point, AI used basically bot force to beat games like chest, which is a simple game and brute force was basically enumerating all the possible moves, all the possible possibilities with Go that was unfeasible.
So Google's deep mind at the time has proved that neural networks can master human intuition. They can manage extremely complex domains without relying on human knowledge without using brute-force methods, and also to self-improve exponentially basically by playing millions of games against itself.
Now that was a huge moment about 11 years ago. Now if you go back to 2026. The frankly, mind blowing realization that the frontier LMs today can run a 32-step-reasoning chain to complete end-to-end simulated breach of a corporate network is astonishing. It also means the reactive security cycles, we all have seen for the last 2 or 3 decades are absolute.
Now to be clear, this is not a single AI company story. I think this is actually a new rhythm of our industry. All the labs are racing on the same capability curve. Every model becomes better at finding vulnerabilities, doing so faster than ever in more sophisticated ways. We are seeing today that the volume of non-vulnerabilities is having a step change.
And I think that's going to keep happening at least in the foreseeable future. The speed of exploitation is compressing. And the unpatentability is, the misconfigurations, the over privileged identities, the shadow, AI agents, the AI infrastructure all of those are already running in every enterprise environment in the world.
And that's actually fuel that's going to ignite faster then the current operating model can probably handle of the model that the security teams have today. Now I'm a strong believer that security is a team sport and AI labs are definitely not the adversary. In fact, AI and frontier LMs are the best new tools the defenders ever had.
We just have to start using them much more in the right ways. Now let's connect all of this back to Tenable. What I wanted to do is to go one level deeper, a bit more technical on 3 things. The first one is why our architecture is a structural moat and why it's also the right platform for exposure management with AI.
The second, where AI and cybersecurity goes next and why I believe that every step in that direction actually expands our opportunity. And last, what we're doing in Tenable as an AI native company to become an AI native company and what that actually means for our ability to deliver.
Now if I had to summarize in 1 sentence, what I've heard in Geneva 2 weeks ago, what I'm hearing from the industry, what we heard from Antropic being on stage at exposure conference earlier today. I think I would say and compress it into this kind of 1 sentence that basically represents the core of our moat.
That the defenders edge in the AI era is not the model. It's the data, it's the context the harness and the guardrails that you need to build around it. Now let me break it down layer by layer. The layer surfaces and signals that Steve has mentioned, is the basic data collection on which everything is built.
Now I'll add just one example to build on Steve's point. So a model, we've all seen that through OPUS and others model can successfully find vulnerability in the Linux [indiscernible] source code, for example. But it can't really go and figure out which 1 of 50,000 or so Linux oats running in the corporate network, which one of those is actually running the affected version, whether it's, in fact, effectively network which will or maybe it has a compensating control in place. rendering that vulnerability, irrelevant for the moment.
Now answering those questions can only be done through sensors that are deployed within the live customer environment. We have those sensors. That's basically a huge part of that layer. In fact, we have over 300,000 of the sensors. We call them plug-ins. And they are deployed across more than 40,000 of our customer base.
Now the way to think about that, they basically represent the qualified knowledge and the deep expertise of our research teams, and they've been doing that for 2 decades. And this is a way for us to understand and see the real world enterprise environment across the full surface, everything we need to protect.
Data centers, IoT devices, OT infrastructure, cloud identities, AI apps, everything a company has. Of these pains actually operate using nonintrusive techniques because you don't want to bring down production simply by checking if something is up or down or what's the version. As we generate today about 100 new plugins every week to keep pace with the evolving threat landscape.
Now our platform basically checks if an asset in the customer environment, whatever it may be, is vulnerable to whatever the latest thing is -- it checks the configuration, it checks all those things and delivers a [indiscernible] answer with high precision.
Now that precision effectively underpins the downstream actions and decisions that go all the way up to Hexa AI. Before that, what our executive team had to do is things like open a ticket, calling your IT team to take a system of flying. Filed a report or got format schedule a patch window.
Now with Hexa, you'll hear more from Eric who goes right after me. Today, these actions can be done with AI agents part of the Hexa harness working for defenders. The second layer is the exposure data fabric. It is essentially taking 1.7 trillion security findings from all these sources across all the customer base we have, these are deterministic measurements of real configurations, real environments, real assets, including historical data, for sure.
And that serves as the base for the Agentic workflows we have with Hexa. Now HEXA is using that data to orchestrate action, providing it the right harness the right guardrails for trusted and safe action what's allowed and what's not. Things like role-based access, permission management, it has to have an audit trail and other enterprise requirements.
Now we know this and AI labs have been saying this as well that AI agents without the right harness won't be able to complete the more complex security workflows. Actually, things might get even worse because AI agents have the tendency to go off rails, doing things they shouldn't be doing. -- and this is happening as well.
Now across the 3 layers, every action Hexa takes is grounded in observable and measurable data. It has an audit trail, it gives defenders the levels of autonomy they need to protect their enterprise, both at machine speed, but with human control.
Now as Steve mentioned, these layers, they compound and they create the structural boundary that we're talking about. The second thing going to leave you with is what Tenable is doing to become a native company. Now, during my time with Microsoft and specifically for the last 3 or 4 years, I've been part of the company's had transformation at scale. And in a sentence, that's basically the playbook we are running here.
Now today, 100% of our global R&D team is using AI tools day-to-day. We have built the right scaffolding, the checks and balances. We have usage, -- we have token economy, and we've even added AI fluency, if you will, as a performance criteria. We have also established new AI native operational structures.
We call them accelerations quads. These are essentially small cross-functional teams operating on a startup like cadence cutting across the company. And we're using that model to aggressively close the gap between experimenting with AI to actually running the company on AI.
We are treating the agents as a new type of an internal software developer persona. We are adapting our product interfaces to be used by agents as well as humans, what's called a headless design, which is essentially decoupling the back end, the data, the logic, the APIs from the front end, the user experience and the presentation layer.
When the consumer of the client becomes an agent rather than a human, the product, in fact, needs to be consumable by both humans and the AI agents. Now we are not voting on the eye on to legacy stack. What we're doing, we're evolving ourselves, our product stack, our architecture our team and our platform with AI.
Last but shortly not the least, thanks to our partnership on topic as well as being part of open AI's trusted access for cyber program. We gain access to their early models that we're using both internally as part of our research teams as well as within our product through things like Hexa.
We also have the privilege of working with the AI labs engineers and their technical staff to really fine-tune the LLMs to what we need within our product and our research team. Now the AI transformation we've driven internally is basically it's a program that's structured across 4 themes, 14 work streams -- it goes across the work we're doing with our teams and talent, the tools we're using and how we have them grounded on the data in our specific company, in our enterprise.
We've also built metrics and ways to measure value -- this is an ongoing process. And of course, we have the governance for responsible and safe AI adoption and security in our CECO team. We are seeing some early productivity gains that I can share. We are seeing actually great improvements across velocity of delivery. Throughput per single human engineer went more than 2x.
And the overall efficiency of every single person in the R&D organization has improved significantly. Now to small step back. I think probably every product or manufacturing company in existence roughly does these 4 things. They build something, they sell it for a profit. They support it with their customers and they support their enterprise functions, things like finance, legal, HR and other departments.
To break it down even further, product creation goes usually across this process of creation and distribution. You find the problem you want to solve, you write requirements, you architect a system, you design an interface, you develop it, you test it, you document it, release it, and then you work with our marketing and sales and operation teams.
To get it in the hands of customers and make a profit. Now these steps essentially remain the same, almost the same with or without AI. However, there are a few things that do change. And I believe that, that's something is speed, efficiency or productivity, if you will, and the division of work. Now we're seeing that paradigm shift. We're seeing that across the industry, but also from our own personal experience at tenable and what I have seen happen at Microsoft a few years ago as well.
The first change is that our workforce, in fact, now is hybrid. It has both humans and AI agents. Humans take the role of defining directing or supervising with AI taking more and more of the execution cycle at machine speed. Now you can't only focus on cold -- so we're also working to streamline the process end-to-end left to right.
Some of these steps also need to evolve, such as the headers design I've talked about where the consumer is no longer only biological. We know the product will be used more and more by agents along with humans, and we need to adjust the design and the interface to that.
We need to have the right guardrails in the release cycle. We need to run the AI models within the right harness and invest in adopting the tooling to our specific needs. The last thing, and this is, I think, the holy grail that we're on track to achieve is when this process, this cycle becomes autonomous and fully agentive.
What that means is that we have successfully orchestrated agent to agent communication and agent to agent workflows. They can then go and iterate through these steps while preserved in the context the shared memory, if you will, which is not a simple challenge, the human intuition and the intent of the creator with humans in the loop for direction, control and supervision.
The last thing I want to touch on is where I think we are going next. Now for me, there were a couple of sessions that really were eye opening at the [indiscernible] form. One of them was securing the Agentic economy. I think it also provides a glimpse into where the market is going. And I kind of broken it down across 5 trajectories.
And I think every 1 of those talks to the expanded opportunity we have. First, we're all seeing that the LLM capability floor keeps dropping. So we are already seeing autonomous packages going mainstream, OPUS cyber, they show the trend, but others follow closely.
So what that means is that the Frontier will become baseline quite fast. And that means there's a major shift that's happening. When [ Mitas ] came along and topic predicted that others will catch up within 6 to 12 months. The reality was that it kind of happened in 30 days. So with GPT 55 being almost as good on many of the existing cybersecurity benchmarks. The second thing that's happening is that Agentic AI becomes table stakes for both sides, both the adversaries that are way ahead, actually.
They're early adopters, these guys. They're moving super fast, but also for defenders. If you go to something like a hacker 1 leader board today, you'll see a bunch of names, some of them, maybe most of them will be AI agents or humans heavily augmented by AI.
This is sort of our line of sight into that capability curve. There's also an interesting implication on regulation. Now 1 example I've heard was the European Union's AI Act next enforcement phase takes a tax effect on August 2, 2026, in about 2 months.
And there's a discussion of what it actually means where things like audit, compliance, insurance, they all require reproducible, auditable [indiscernible] output. What I see that means is that LLM have to be part of a workflow in a way that ensures determinism as well. So it needs a harness, it means that wrapper.
The agenetic economy is definitely the new attack surface. Our own cloud on a security report we've released a few months ago, shows things like 70% of enterprises today have AI artifacts, such as NCP servers or applications without proper security oversight. Eric is going to share some data points that are even carrier of what we're seeing from customers today.
And last, the contextual value, for tenable, that context is realized through our exposure to data fabric. And I strongly believe that becomes the most valuable real estate in the stack in this new world. I don't think success will be to the 1 who has the smartest LLM. All of us will have access to LOMs. Depends on the price, but that gets cheaper and cheaper as well.
I think success will be for those who can ground those AI agents in the right data in the right context, orchestrate them with the right harness and build and run them with the right guardrails. And I personally believe that every one of these trajectories are a tailwind for exposure management, that's actually what brought to tenable.
And that's what we're building here at Tenable. With that, thank you for your time. I'll pass it on to my friend and colleague, [indiscernible]
I'm Eric, Chief Product Officer. Been here for a little over a year. Before this, I was at Google for a couple of years, I led the [indiscernible] integration, Chronicle, Google Threat Intelligence. And before that, I was at Microsoft Security for quite a number of years with the lag. I had a funny job there. I was in addition to building security products responsible for the Azure sock and incident response for all of Microsoft.
Spoiler, I wouldn't recommend doing both of those jobs at the same time to anybody. But it did give me a unique insight into how one of the world's biggest targets is attacked every day, and that's been super helpful in my career since and what I bring to Tenable.
There's a ton of innovation that has happened in the post-breach world even before AI, but not as much in preemptive security. And that's a big part of what brought me to Tenable. I watched this pattern over and over. The reach happens, we clean it up. That was before AI.
AI changes the math. If the attackers are operating at machine speed, as Mark talked about, you can't respond your way out of that with spreadsheets. The Defenders edge has to move forward to preemption. You have to fix it now before they exploit it. And this is me, the little help from Claude, my version was longer.
So what's happening? We talked a little bit about this earlier. This is a hard problem before AI, NAI is making the attack surface way worse. You see productivity rising, of course, visibility is falling. But we've kind of seen this movie before in security. We saw with cloud, where cloud adoption outpaced security.
We saw it with SaaS, where things remember when Box and Dropbox came on the scene, all of a sudden, there's documents being shared everywhere and security teams are saying, I have no idea how to keep my hands on this. Same kind of trend, but AI is running this tape at 10x feet. And these are 2 curves moving in opposite directions. The business is sprinting.
Every business unit is shipping AI models, training data, agents, MCP. The workloads are going live faster than security can spell them. The CISO is effectively flying the plane blind. But every platform shift creates a new security category. Cloud give us Snap, the dissolving perimeter gave us 0 trust. We believe Shadow AI accelerates the trend towards exposure management. The average enterprise has 50-plus security tools.
You can't solve this problem in a siloed way. The answer isn't the 51st security tool. We think it's tenable. So how do we do it? Three steps. I'm going to go a little deeper than Stephen and Vlad here. Step one, you have to have continuous discovery you have to see everything. You can think of this like the census. You not only just have to see, you have to see, you have to hear, you have to taste, you have to smell.
You need to pull in all of that context because the enterprise is alive. It's not a static thing. It says cloud, it has devices, they have web apps. It has identity. And of course, now it has AI, AI infrastructure as a critical piece of the new attack surface.
And that whole attack surface is constantly changing, and the threat landscape is constantly changing continuously, not monthly, certainly not quarterly. And it's hard to do that at scale.
This sensor fabric creates a network effect, 1.7 trillion real-world findings, $113 billion on average a month, new findings per month. That's deep scanning inside the operational environment.
You've got a -- but as Steve mentioned, no one can scan every interesting piece of data in the enterprise. So the 300 data integrations we have and growing more every day, allow us to bring in context from other security tools, but just as important from the infrastructure and business systems that help create the context that allows you to know what matters.
Zooming into AI in the last 30 days alone, in our customer base, we found 457 million AI security findings, finding as a problem or a potential problem. That's across 7,000 customers in 57 countries. So this is a globally growing shadow AI problem. We're built. And if you could think about it, we've been training for 20 years to outscale the attackers.
Last year alone, we shipped 70,000 plug-ins. Vlad mentioned this, you think of this as detections for different kinds of issues that our customers have. We have hundreds of shadow AI detections to. They're live today and more shipping every day. We cover about 25% more than CESA with the known exploited vulnerabilities program.
You may have read the news that CISO is sadly scaling back some of their activities because they can't handle the increase in volume, we're scaling up. The enterprise is alive, 11 helps you discover it in near real time.
Step 2. Yes, the priority is what matters because every enterprise is different. We had about 48,000 CDs. This is the funny unique number for every unique vulnerability. Maybe we'll have 100,000 this year, maybe more. The last thing security teams need is another firehouse.
You got to bring that data in, you have to deduplicate it, you have to correlate it enrich it. decorate it. You have to make it useful because the raw data is not useful. And you have to do that synthesis at the center rather than inference at the edge because the data needs to be a graph. With this, this exposure data fabric.
We can tell you, on average, the 3.3% of those unique vulnerabilities that matter to you. And we do it faster. Again, looking at CESA, we discover exploitation about -- we overlap in about 64% of the times that CESA discovers vulnerabilities. But the median time we discover that exploitation is 7 days earlier.
The average is 37%. But you have to move beyond CDs. Because as we see from those recent Verizon data breach report, which we contributed to, about 1/3 of findings are not CDs. These are identity misconfigurations, infrastructure hygiene, exposed secrets and 2/3 of the breaches come from those non-CD issues.
So 1/3 of your risk, but 2/3 or 1/3 of your findings, 2/3 of your risk. So with our exposure data fabric, this all becomes context. In context, as Vlad mentioned, is extremely necessary for the orchestration of both humans and agents. So if the sensors are the sensors, you can think of the data fabric like the brain. But let's talk about number three. The third step is obviously fix the problems.
But unfortunately, this is where historically the industry has broken down and moved at the speed of spreadsheet, just not machine speed. Grade visibility and prioritization is obviously critical. It is necessary, but it is nowhere near sufficient to solve the problems of today.
You can see in 2025, about 26% of the worst vulnerabilities, the commonly exploited vulnerabilities or known exploited 1 real disease, we're fully remediated. 26%. You see the patch cycles, 43 days on average, flat showed that the trend line, but they're actually going in the wrong direction.
The year before, the industry average was 32%. That's terrifying. Spreadsheets can't keep up, only machine can fight the machine, and this is why we built Hexa, which went generally available yesterday. So if the sensor fabric or senses and if the exposure data fabric is the brain, ex is the body. Hexa is our genic engine. It's intenable one. We announced it at RSA a few months ago.
We've been in early access with a few dozen customers, including some in this room, for the last few months, and we went generally available yesterday. It is built on the exposure data fabric. It enables automatic patching and remediation.
You need the brain to coordinate those actions. It moves security teams for manual security to a genetic security at the speed they want to go, the speed of trust. And it orchestrates this mix, this messy mix that is security.
Why do I say it's a messy mix? Well we know humans are falable, we've always known that. You sometimes you ask them to do something. Sometimes they do it, sometimes they don't. Sometimes they close a ticket and say they fix something, sometimes they didn't.
We also know agents have problems. Agents [indiscernible] sometimes they act like bratty teenagers. You need the context in the guardrails and where you choose the explicit human in the loop interaction, to make sure that you're getting to that outcome that you want.
Skynet isn't showing up tomorrow. The real enterprise is messy. We must go 10x faster, but we have to do it deterministically. So this is the layer of Tenable One. The layers of Tenable One, continuous discovery across all of the domains in your enterprise including the business context that makes it real, the world's smartest exposure data fabric, the brain tells you what matters, avoid solution nations in real time and Hexa, the body.
The Agentic engine that gets humans and agents working at machine speed. But enough slides, I get to show you a product. And so I'm going to take you through for demos in the next 6 minutes, I think. So let's get into it. This is demo 1.
How do you get from 10,000 findings to an attack path? Remember, attack path analysis is the only way you can get from 10,000 findings to a few things that matter. This is looking at the sequence of events that get you from an exposure to something that matters.
Frontier models can't do this. They don't have the asset graph, they don't have the identity context. They don't have the brain. So here's the demo set up because it's going to go fast once I get going, okay?
Customer environment, simulated customer environment. We've got cloud identity, VM scanning applications and, of course, a bunch of AI infrastructure, just like every organization on the planet. So let's go and play the video.
So here in Tenable One, I open Hexa. I'm going to search for top attack pets. Looking across everything, thanks for a second. You can see the top 5. I could go drill into this, but I actually want to zoom into AI infrastructure. And so -- in a second, I'm going to zoom into AI infrastructure -- are we paused -- can we play -- you think a recording wouldn't have the demo gods like you. Why don't I tell you what's going to happen while we try to get the video going. We'll put it on the website.
Yes, we'll put it on the website. So what would happen if the video played is you'd see a 4-step attack path, okay? On the far right, is a fine-tuned model.
This is something the organization is using for an app in their environment, and they're training that with proprietary data. On the far left is a user. But if you look, that user doesn't have access to the model, you're probably fine, right?
Not really. In the middle is some training data. It's just in a storage location. In this example, it's in an AWS S3 bucket, the average customer has thousands or tens of thousands of these. There's no real way unless you connect all these pieces together to see that the data that's in that S3 bucket is actually the data that's used to fine-tune that model.
And this exposes you to something that we call data poisoning or model poisoning. But let's go one step deeper. You might, if you're a good security team, say, let's look at who has access to that training data. And you would find that the user in this attack path does not have access.
So you're safe, right? Not so fast. What the user has is the ability to create a policy that gives access to that bucket. So if you get a hold of that user, you can start print and access all day long, get into that training bucket and poising the model.
That's the kind of thing that adversaries love, and it's the kind of thing that siloed security. Here, now it's going. It's the kind of thing that silo security just can't help you figure out because you really have to look at the intersection of identity, you have to look at how that identity is related to the storage assets in your environment and how those storage assets are being used with the AI infrastructure that you have.
So you really need all the data plus you need the brain to find an exposure like that. But we can do more than just find stuff. So the second demo is showing you how Hexa AI helps make humans superhuman. So analysts spend a ton of time doing manual tasks in every aspect of security. We all know this.
Hexa handles the operational busy work so that analysts can focus on decisions, not clicks. So same environment or similar environment. What I'm going to use HEXA to do I'm going to set up a scheduled scan. I'm going to create a dynamic system to organize the results, also something people spend in a rangeous amount of time doing manually historically. And then I'm going to create a summary from my management team because I want to look good.
So let's go. Here I am, open up HEXA, Zoom in. So I'm going to create a scan targeting a couple of assets, Teleca, these are our finance servers. So I want this to happen regularly, please do it for me. And also we went pretty quickly, but you should have seen it said that I'm going to tag these things as they go.
Here, we ask for human in the loop because you're doing a right operation in the environment. We're going ahead and creating the scan. By the way, also you should notice, this is setting up multiple subagents in parallel. -- because Hexa is a harness that orchestrates multiple agents.
Now it's doing the work. Now it may have paused again. What I'm about to -- there it goes. All right. So we set up the weekly scan. That's great -- it is moving. I can see the -- yes, there we go. And now I'm going to say, hey, generate that executive report.
And this is pretty cool. Because it does a nice job as you'll see in a second of showing what I did, what happened, but it also flagged something. It flags that there was a patch regression.
This means you previously took an action to patch something, and it doesn't look patched anymore. Maybe the patch failed maybe something else happened. This is what the industry talks about as validation. And it's really an essential element.
It's one of those guardrails that helps make sure that when humans or agents go do things that we make sure that they get done correctly, super important part, especially in the world of AI.
Demo 3. So what about when I want Hexa to just do stuff for me. exit doesn't just tell you what's wrong. It takes action. We have in Tenable One, a number of inbox agents, and we also allow custom agents, why custom. Because a lot of our customers, especially our biggest customers have very complex workflows.
They have complicated approval flows, internal tooling, tons of custom data. In the past, the only option to do something here was to create an expensive internal development team or to bring in an expensive outside consulting firm to build custom automation that was fragile and meat and maintenance and all that kind of stuff.
Since Hexa comes with MCP, which is a fancy way of saying that it's built to interact with other tools and agents. We can enable security teams to do a lot more in a really cool way. So here's the task I'm going to set up here, and it's going to go even faster than the previous demos.
So give me a second to set it up. What I want to do here is I want to automate some patching because I'm worried about an incoming vulnerability. I have the patch, but I can't wait for a normal patch cycle. It is critical to me that we have the right human approvals because my organization requires that.
And it's also critical to me that in addition to the normal auditing that every Hexa operation always has, but we use Jira for workflow tracking. That's going to work with any tool. In this case, we wired it up to Jira.
I'm using cloud for the demo and for optics Cloud, it could be codecs or any other AI harness. So let's do it zoom in, you can see the prompt. We go ahead and do the scan. I found a few assets that have high vulnerability scores. So these are risky assets. Great. Now I'm going to go and check, do have patches for them with tenable patch manager, turns out have patches for most of them.
Great. A couple of notes. They don't need a patch. They need a registry fix, okay? That's easier. That's good. Now we've found 6 findings across a few assets. We're going to get to a place where I have human in the loop, by the way.
You don't have to have human in the loop, if you want to be fully autonomous, you can do that. That's part of the power of custom agents. Now you can see the patches were applied. It does flag there's 1 manual action you need to do.
We went ahead and updated the Jira ticket for my workflow, I signed it to the right owner so that you can get that done. It also tells me, hey, you should probably do a rescan, do you want me to do that, just to make sure that this stuff actually happened, that validation loop again. It's pretty cool.
Last demo. Patching even at machine speed isn't enough, as we talked about, 1/3 of the findings aren't CDs and won have patches ever. 2/3 of the breaches don't involve a CV at all. and AI scanning tools like Mythos and GPD55, wire is going to make this harder.
So what I'm doing in this last demo is I'm looking for high severity findings that have no owner. And if they're risky, if those identities look risky, I'm going to automatically quarantine them. I'm going to update the identity system, which in this case is Okta and just take them out of it so that there is no risk until I can go figure out what's up there and make it right.
Let's do it. Okay. Simple prompt again, it's thinking, looking for critical AES. That's the attack score effectively, the tenable users, find some assets, digs in a little bit. works around a problem, finds the owner finds 4 matches in Okta. Of course, I'm going to update Jira because that's my workflow. It's important. Have a little bit of human in the loop there.
You can see the success. I've got 4 accounts quarantined. Now I'm going to move to the final step, which is verifying the membership, updating the JIRA ticket. And I'm just quarantine those assets in under 60 seconds. There's no risk of an attack without attack vector, pretty cool stuff.
So this is a brand-new tool set for security teams. Stuff like Hexa did not exist yesterday, certainly not a year ago. If you zoom out to the Tenable One platform, we walked through how continuous discovery is essential, the senses of Tenable One, help prioritization that matters to you has to be there, that exposure data fabric the brain of Tenable 1; and Alexa, our agent engine, the body that makes the security team superhuman and automates the messy mix of humans and agents.
And I want to leave you with my favorite marketing tagline, as we were working on Hexa, I don't get to decide the marketing tag lines, I get to propose some. My favorite marketing tagline that we didn't pick, Is at Hexa, [indiscernible] one.
AI is making the attack surface, harder, the job harder. Shadow AI is everywhere, sideload security can't solve this problem. A platform that only sees some of the attack surface can't solve this problem. You need complete visibility, cross cloud, OT on-prem, IoT, Identity business context in more. Our customers have 50-plus security tools. They don't need a 51st in [indiscernible] one.
Thank you. All right. I know we're running a little behind. So I'm going to move relatively swiftly through talking about the marketing piece and then invite our customers up on stage so you could actually hear how they're using Tenable and Hexa. By way of introduction, I am Meg O'Leary. I'm the Chief Marketing Officer here at Tenable, I can't believe it, but I'm here almost 3 years. They've let me say. And I love this company. I love this team, and I think we are building something really amazing.
So let me talk just -- as you came in, you -- I'm sure, I hope saw the new tenable brand. And so this is not about marketing for marketing's sake. This is about taking the foundation of tenable and what we've built in signaling to the market that we are here and ready for the AI era.
So the future we are building required a new expression of Tenable. And so we really want the market to see us in a new way. We are very proud of our vulnerability management heritage. As companies are looking for VM, they are going to come to Tenable. They're going to come to Tenable because we are the undisputed leader in vulnerability management.
But as you've heard over and over GaN. We are ready for the next generation of what's happening around exposures. But there's so much goodness in this brand. When we spoke to when we built this brand, we spoke to over 1,000 customers.
And the #1 thing they said about why they like Tenable is because we are trusted. That is the #1 attribute that they associate with the Tenable brand. So we want to hang on to that brand, but we also want to express it in a new way. And when we all spoke to those customers, what we realize is we have something that is very, very powerful.
We take chaos and we turn it into control. So you heard from Eric and Steve and Mark, 50-something -- 50-plus tools inside their environments. 12 to 15 teams. Now the AI attack surface is coming, Agents are proliferating. It is a lot of chaos to harness. And what we learned is that, that's what customers count on us to do.
So this idea of chaos to control of giving them simple answers in black and white, that is what this brand is all about. So it's a scalable system. We think it's opinionated. We think it's sharp. And we think it stands out in the marketplace because we have something to say and we have something to show.
And I hope that you saw that in the demos and what we're telling you about 11. So you're going to see this roll out more and more, if you come to RSA, when you come to conferences, but also the first real expression that we're doing of this -- of the brand is actually a new brand campaign.
So when I say brand campaign, I'm not talking about Super Bowl ads. I'm not talking about huge billboards, we are surgical in the way that we do brand marketing. We started investing in about a year ago.
Our website traffic has more than doubled since we've started targeting customers and prospects in this way. and we just want to make sure they hear our message. So I'm just going to give you a little preview of the brand campaign that's rolling out this week.
[Presentation]
All right. Thank you. Thanks. So what we're trying to do for our customers is contrast the intenable circumstances of their jobs and what they're trying to do with the control that Tenable is bringing. And we're really leaning into the AI message because we think we're doing something very exceptional here.
And you can see it scales when the opportunity is the right to scale to the physical spaces to scale to digital spaces around trade shows and our own events and showing up in the market in a really bold way because as we are saying more and more when the world is untenable, we are tenable.
So with that, I'm going to invite our customers up so we can actually talk about what they're doing to control their chaos. So if you guys would join me on the stage here. Come on up.
All right, we'll get started without him. Don't turn on this -- and let's turn the offer comes back in the room. All right. Actually, I'm going to want to hear from Eric because he actually is doing some incredibly exciting things with Hexa and agenetic security. So let's just get started with some introductions here. No, you're okay. You're okay. Why don't we go ahead and get started? Rick, do you want to introduce yourself?
Sure. My name is Rick Vagama. I am the CECL like GEICO, Be sure to bundle your home, auto, boat. -- and motorcycle and give us 15 minutes and we'll save you 15%.
John Schram, I'm the Global Head of IT Risk and Security for Unit Re. The largest company you may not have heard of before, and I run a team of 400 security professionals across 10 countries for the world's largest reinsurer.
Hi, everybody. My name is Tarek, I hope my mic was internal, what I was -- it would have been great as you, I think you can hear, I am French. I've come from Zika, which is a cement company, which I'm telling in the very [indiscernible] I'm sure, basically, they build concrete and sell it across multiple countries around the world. them super I don't have a coal like selling you .
All right. Well, we're super happy to have you here. And let's sort of talk about the jury that you are taking to exposure management, right?
So I know you all sort of started your journey with us around vulnerability management. I know there's a lot of expansion that you've done. But can you just talk a little bit what was the breaking point or the turning point for VM that made you decide, okay, we need to move on to exposure management.
And maybe, Rick, you could start for us.
Sure. So I'm proud to say that I've been working with Tenable now for 12 years. I'm a 3-time customer, though, according to Mark and Steve, I will not get Tom Brady go status until I buy them 7 times. But anyways, so for us, it wasn't necessarily a breaking point, right?
I mean Tenable has really been helping me over the number of years that I've been working with them to pivot my journey. Certainly, from a vulnerability management perspective, there's no lack of CVEs, and part of the reason why I'm a big fan of Tenable One is, is that it's my single VM platform.
So regardless of where all these various sensors are, right? My ability to ingest all that information and then have a single brain provided by overall exposure management and oh, by the way, to take it to the next level, understand my attack exposure score is really important.
And what that really means is this, right? From a tech perspective, there's certainly no lack of vulnerabilities that we need to address. But when I go to tech leadership or when I talk about risk reduction with ELT members.
I'm really talking about risk. So when I go and say, these are the 5 things that we need to focus on because they're exploitable. All of a sudden, it changes that narrative, then instead of me going with 1,000 things and saying address that, I'm basically saying these are the 5 things you need to focus on.
Awesome. Derek, I know for Vicat. It started with VM, then it was OT and then it was [indiscernible] all the different domains an 101. But can you kind of talk about drove you to sort of bring it all together under an exposure management.
Pleasure. So Vika operates in cement and plan. So we started with OT because the sensor solution is actually the best that was on the market. Nobody else was offering that. then we went to agent with narrative management. We basically followed the product roadmap of Tenable.
And then we moved into the cloud. So we invested into the tunable Synap. And at this moment, we move to Tenable One actually we went into exposure management and the fast actually made sense because what is exposure management, like Rick said, vulnerability is. That's also what Eric said earlier, actually, 2/3 of the bridges don't come from CVs, they come from misconfiguration.
They come from stuff that are really dangerous -- also since we are among a lot of countries, we have -- it's important for us to share the same language.
So talking like in Brazil or in India, we do need to make sure that we all understand where the risk is and what needs to be fixed and exposure management give us that through the unified view, the unified Dageboards and the attack asset bases.
Like Rick said, instead of think you have 1,000 stuff to fixed, you have this one and this one to fix. It will secure the solution. And the various owners of all of the platforms to go back to their boards with something that's simple, actionable and educate measure in.
And so I'd like to add to that, like that's a great point, right, because we all have a lot of security reactive systems, right? And when I think about Tenable, it's by proactive system where I have all the information and telemetry and oh, by the way, right, we all have various EDRs. And the EDR companies are also talking about VM the last time you were able to install the EDR on a firewall.
No, right? So which is why Tenable is the right solution because regardless of what the sensor is, you can pull it all in. And now we're having a proactive conversation to go and look for things that matter where I am misconfigurations around my crown jewels.
Yes. I don't disagree with that shift has happened with the active environment and EDR and actually enable is bringing this kind of mindset that actually security teams know about, like you need to fix this right away.
And [indiscernible] everybody actually to bring that mindset to the proactive movement such we can fix at the speed of machines, every vulnerability is the risk, every exposure is a big risk. It needs to be fixed right away. So you're absolutely great point.
No, I think it's really important this capability to understand the entire attack surface of a company. Again, we have 20-plus applications. We have hundreds of thousands of devices on our networks, sprawls the globe.
We have 149 legal entities that we're governing in my central security services team. And sometimes we can't actually shut something off. We don't have a patch for it, but it's making a lot of money, so we can't turn it off.
So we need to push a fix, maybe it's a web application firewall rule. Maybe it's a rule. Maybe it's a network structure and being able to see everything that I have and where those problems are the things that I can fix to be able to fix them and the things that I can't fix to be able to do something different is very, very critical to our business.
Can you talk a little bit more about specifically why Tenable one, right? There's lots of companies, lots of platforms coming out around exposure management. What is it about Tenable One specifically that you chose that as the solution? I'll go to any of you who want to jump in.
So first of all, props to Tenable leadership, okay? They have made Tenable One incredibly easy to buy. They've simplified the SKU process made it really easy for the channels in order to be able to sell it to meet the customer.
And by the way, right, in terms of how they package all the capabilities, it's really meaningful. But for me, right, the openness of the platform and the simplicity and the real power and really, right, with Hexa, it really comes down to how creative my teams can really be.
And as all of you are out there and read constantly in the Wall Street Journal about how lots of companies are reducing head count by 5% to 15%. What does that really mean, right? Also, our budgets aren't increasing either.
So one of the things that we'll be taking a look at is how we can automate a lot of the lower-level types of work by using agents in order to take those things. So such as in the supernerd thing specifically is tagging an asset with the right sort of metadata so that we can make sure that the right scans are being approached.
Previously would have taken one of our analysts a lot of time and a lot of collaboration with a bunch of team members. Well, essentially, right, we'll be able to automate that through Hexa.
That's such a good point. First, I just want to make sure everyone in the room saw we announced new pricing and packaging a couple of weeks ago around flex pricing so that our customers can use the assets they need to use in a fluid way to match the needs of their environment.
So if you haven't seen that news, I'm sure Aaron has shared it, but just so we all have some of the context there. But then as we're talking about Hexa and what we're able to do with this genetic engine within Tenable 1, there's everything from sort of the [indiscernible], right, of the work that just takes time, tagging, what have you. And then there are things that we're doing that are next level that we really couldn't even think about doing a year ago with such speed.
Yesterday, Tarek did a breakout here at exposure to talk about what he's doing with Hexa and with a genetic security. 200 people came -- it was a dire, I think it was this room but literally a standing ovation at the end. So Tarek, I would love for you to sort of share with this group how you're using hexene of the spectrum, just helping with manual work all the way up to how it's upping your game and risk in the...
Just to go on what [indiscernible] very true. Why do we trust actually trust is the right word. Out of the big players that we've been using for quite a didn't have any kind of major issue that some others might have.
So this layer of trust that has built over all the years makes, the right decision to like bring your data into it, we do feel safe with the solution.
Also, the vision is very good. And I guess you know French people are very nosy, so I've also exchanged a lot with the technical teams. They're very good. It makes sense where they go. So there's like a keen ship of engineers that's been created.
This is something that personally like. About Hexa. So yes, I also had the pleasure to access to Hexa before the others. So I played with it for maybe the last 4 months. And what Eric was describing, like the TDS task that used to take analyst or even more senior people like me 2 or 3 days every month can be automated and actually, it then takes 20 minutes on the Monday, I can do it whenever I want, change my tags, change my scanning.
And you need to know that when you do that, this is the basis of discovery without those kinds of not very sexy task, actually, the tool doesn't work as well. So somebody has to do it, and now take a and do it so I can put value my time and reflection actually risk management, which is my job, actually where it matters, and that's for our Board, that's the labs will spend.
So this -- just for that already excise fantastic. Eric showed it to you. This one is great also, like you said, since headcount are going to be bigger. We're having less and less people. So being able to do more with the same kind of people or even less -- it's a great asset.
Now on the capability of excess, did the demonstration yesterday, that kind of look like what Eric did, but it wasn't only intenable because in my company, like he said, we do have 50 products, I think, I won't say the name, but all of the EDA over the firewalls, all of the SIM that you might imagine, we do have debt and having tunable as our source of truth and actually using the capabilities of [indiscernible] actually give an model, a new which 1 you want, actually.
Access to these kind of normalized information gives you a very good source of truth, which means that your agent can work very well. And then you can orchestrate many things quite simply.
What you said about yesterday was true. I think it worked pretty well. I think the nice thing is that everybody was able to see what you could do. It's not in the future, like elegant. It's actually you can do it right now. It's fun to do. It gives you back control over your assets, control over what you have.
And I think the underlying thing is that make that possible because it is so easy to integrate with the rest. And I think I've been tried with lots of other solutions. That's where the [indiscernible] that the forefront. The vision has been clear and they are capitalizing on years and years of sensors and data and become at the right moment, right time with the right product. And I think that's pretty rare in the landscape of cyber security.
I think also where we are with Mythos and the acceleration, the tsunami of vulnerabilities, we're going to see this an enabler for us to be able to go fast and also to enable our business to use AI processes to build out business functions.
We have a huge number of units doing things in reinsurance and underwriting and in client service on AI right now, and we want to do more of that.
So I think Tenable is one of the reasons we'll be able to manage the risk as we go down that path.
And also I wanted to add, like the work that I had an opportunity to see you do is so inspiring, okay. And so why this really batters, right? Imagine a new 0-day exploit comes out, right? And so then I can go to Hexa and be where am I vulnerable and where don't I have an EDR in place.
So Hexa will go through search. And then from there, I can say, all right, can you go quarantine those systems? Or can you go ahead and patch them, right? And historically, that would have taken hours or I might have had to run a COE process, a correction of error process, right?
We're now I got to disrupt a whole bunch of engineers this they cause a lot of drama. Right, through Hexa, I can do that. But the other cool thing about Hexa, right? I'm only eliminated by the my imagination. So picture a world that once we get this fully deployed and when I come in, in the morning, Hexa will have already found all the 0-day exploits, giving me a readout of where I'm vulnerable. And if I elect to tell it let [indiscernible] take over, then it can either quarantine or patch them or so on and so forth, right?
And it's basically saves a lot of minutia a lot of extra effort that my teams have to go through today.
Like Rick said, which is very interesting, since I had access to or the others earlier during the week, it made cybersecurity fun again. We started asking questions. Act was finding solutions so the job wasn't a dread anymore, so the noise of the disaster, we can fund again to interact with versus that's 1 part, which is great.
Another thing also that I wanted to sit so the great presentation, knowing that Tenable is going in native also actually makes sense with what our companies are doing.
So there is a convergence that's happening. And tunable offering us eMCP using AI. We are also strongly encouraged to go AI-native also. So we do have the access, GMCP not go into the technical although the technical lot. But actually, the way to plug in the AI nativeness, it's nothing I'm sorry table with our own relativeness. I think that's great.
I know we're up against time, but I -- just one question I'd love to all to give an answer to. One of the things you know this better than I, but we hear over and over again about 1 of the value that comes from exposure management is the business level reporting.
Going to the Board, going to the leadership team and sort of giving a -- letting them know how at risk you really are. So could you just talk about the value of Tenable 1 in terms of executive communications in terms of communicating at the Board level.
Yes. So historically, right, from a CECL perspective in the olden days, we would go to the Board and say, these are all our CV vulnerabilities and whether or not we're meeting SLA and the glass and they would kind of glaze over, right?
Basically not been able to change the narrative. Now I talk about exposure. Now I talk about risk reduction. So now when I go up and present a pictorial representation, I basically show what are the top 5 risks what are the level of effort. And by the way, what's the revenue impact that if we lost that system due to an exploit, right?
That then that really resonates with them because at the end of the day, right, the general managers are the ones that dictate the product on what capabilities engineering needs to work on. And historically, it's always been a tough fight from cyber working with the death or the technical teams to try and convince them. Essentially, I'm skipping them. I'm going right to ELT, and I'm saying here -- these are your 5 top risks -- you can choose to accept it. But by the way, this is what's going to be the loss of revenue due to an outage.
John, how about you?
Yes. I mean, it's core to my program, as I said, 149 legal entities, all requiring reports. I run the security services company for the group. I have to report to all of them. So that's a huge task. We have a team of people who do that. Tenable is one of the primary feeders into that reporting system for all those entities to comply with the regulations and to demonstrate their oversight of the servicing that we provide.
And Tarek, I know you talked about not actually talking about one realities, but actually you measure attack back, right? So they talk a little bit about that?
So like I said earlier, so [indiscernible] is basically France, but actually we have subsidiaries all around the world. So it's different kind of regulations, different kinds of lows and also different kinds of cyber insurance topics. For example, a 6.2% in France -- if you give us a good price with ice, we can start the business, we can talk about the business.
But yes, so there's all kinds of various steps. So in Brazil, it's not the same as in India or it's in Kazakhstan anyway. Having similar vocabulary, a similar game was 1 of the big issues that we're moving around. So having to #1, but this for more than a year, has been a game changer because we do talk about the tax at -- so they managed to put that into their insurance contract.
And so all of the countries, so it's also in 13 countries, it's 13 boards, reporting to the board. French, let's say, that I won't get into that. But all of them share the same vocabulary, they can improve on the same spot. And since we also had a wearer, I used to have to explain all of those reports everybody has its own card into exposure management. And treaty can actually ask questions on what to do and what would be the best way to actually improve that.
So I almost made myself out of the [indiscernible]
Your Rick's reporting to the Board level through Hexa, those reports they were being mines of our own engineering and product team. So super excited to sort of see that kind of use. I know we're running a little lot. Thank you so much. Thank you, Rick. John, Eric. And with that, I'll hand it over to my friend and colleague, Dino, to talk about our GTM.
Awesome. Got you. It's always nice when your customers do you're selling 4 years. So thank you, guys. That was awesome. My name is Dino [indiscernible] I'm the new Chief Revenue Officer here at Tenable and spent about 17 years, not as many as Latin Cyber. At various companies from RSA Mimecast. Most recently, I was the CEO of a mission entity company called APX. And the reason I joined Tenable is pretty simple. First of all, it's the team. So I've been welcomed extremely quickly and deeply by the executive team, the operating team I get to work with from my theater leaders, channel leaders across my entire org, customer success through to the cross-functional teams that work with every day.
So it's been an amazing 70 days so far. The second thing is the platform. When Mark and I and Steve first started talking, they walked me through sort of what momentum they had around the platform. This was re-met I didn't predict mythos, but I knew that in a world of AI, this would be the only way that you'd be able to fight machine speed attacks with a machine speed platform like Tenable One and then lastly is the timing.
Again, somewhat of the category exposure management is becoming a real category. It's becoming preemptive security, proactive security is a real thing now. And again, I think the shift in dynamics of how CISOs, like the 3 gentlemen we have on stage, think of preemptive security is changing from a decade's long sort of focus on detection and response to more of a balanced focus on preemptive security, detection and response, which I think is the only way that we're going to are against the adversaries against AI, machine attacks, machine speed attacks.
So let me jump into a few quick updates on how we see the opportunity ahead for Tenable and 101, a little bit better structure, how we go after the market and then I'll get into a little bit of the pricing packaging and positioning around the platform itself.
So first of all, you guys know you cover our stock or you invested in Tenable. We have over 40,000 customers. We're very proud of that. Mix of some high-volume business from Anesa's perspective through to some of our on-prem VM technologies like Tenable SC thought Tenable IO all the way through to Tenable.
And 1/3 of our enterprise customers already have some footprint of 101. And that tells me 2 big things: a, exposure management is real. So you're talking thousands of customers have already made this investment in our platform, and there's still a lot of cross-selling and upselling opportunities across what we've already landed with from a team perspective.
And two, we have a ton of runway just within our existing base of customers, let alone the net new acquisition that I'll touch on in a few minutes, and that opportunity to land and expand with Tenable One. We have a lot of partners. There's a lot of work that Jeff, who runs this organization for us is doing around not only mobilizing our channel partners, but enabling them to not just sell our technologies, including Tenable One but to successfully design, implement and in certain cases, manage the platform for some of our maybe less sophisticated customers or customers, like Rick mentioned, who are going through some type of headcount reduction, but still need services wrapped around this key preemptive platform.
And then lastly, similar to our footprint in Tenable one, we have a lot of big customers and no surprise. A lot of our big customers drive our biggest expansion. And we have a lot of midsized customers in the $100,000, $200,000, $300,000 range that we were starting to see a lot of engagement around driving more upsell expansion.
Again, as we land more net new, providing that fuel to drive a double-digit growth engine in ARR over the next several years. So we think about how we're organized. This probably looks quite typical. So I'm not going to spend too much time on it as it relates to an enterprise SaaS go-to-market structure.
But we've got enterprise, commercial and what we call a high velocity team as well sort of co-mingled with an e-commerce team that's supported by our world-class marketing team, again, shuttled to bag of the branding.
When our sales team is screaming from the hilltops that are brand is amazing. You've nailed something because salespeople are unfortunately, almost a skeptical to [indiscernible] no offense. So I was super impressed with how the team responded because actually, black and yellow is not purple, not red, which is sort of how A lot of the world is branding themselves in cyber.
So anyway, we've got an amazing marketing team that's helping, obviously, from a demand gen perspective, and supplementing again, a world-class channel organization and channel partners that are helping to drive demand, both for net new as well as existing customers and supported by field teams in the enterprise as well as hybrid teams in commercial and a high velocity team in what we call SMB.
And I think the key thing here is we think of AI, which we're going to touch on speed and efficiency, actually glad said it multiple times, and I say it a lot within our teams now as I'm getting my hands around the business, is a massive opportunity across all segments, but obviously, within more of our high-velocity business. do not reduce headcount but to make the headcount we have significantly more productive and efficient.
So our world-class partner ecosystem, again, pretty typical for an enterprise SaaS business. We sort of have 3 pillars. I think the one thing to call out is you shouldn't be thinking of a partner, let's say, like GuidePoint as living in one of these buckets. Many of our partners live in 2 of these sort of capabilities. And that's pretty -- again, pretty normal. I think as those businesses modernize and they look to provide more, what I'll call, round the box around the solution capabilities.
They're not only going to resell technologies, but that they're going to implement and in certain cases, manage them. And then you've got sort of more pure-play players like an IBM and Accenture, who are less, I'd say, concerned or interested in the product resale side and much more around the broader business consulting and program design or redesign for CISOs who need assistance to really start to modernize their VM programs to an exposure management program.
And lastly, you've got tech alliances. Obviously, Steve hit on the OpenAI announcements. I mean these I think are going to be table stakes for any cybersecurity vendor. It's going to allow us to move faster and stay ahead of the curve as it relates to AI-related threats, be in the know and co-partnering with them.
As well as learning from them and leveraging their technology to actually move our platform faster and stay again ahead of the adversaries that we are all concerned about as we now sort of live in this new agent world.
And then we've underpinned that with very typical Tech Alliance partnerships. One of the things I'll touch on in a few minutes is the fact that our exposure management platform is open. We have competitors that tend to want to platformatize the entire state and do everything they can to make [indiscernible] lives painful by forcing them to buy 1 size fits all.
When the reality is the journey of both CISOs are on is a heterogeneous journey. So us having partnerships with the likes of AWS, Cisco and Splunk to name another 160 or key technology partners is critical. And underpinning that, when you think about the partnerships we have across Tech alliances, we have 300 integrations.
Eric mentioned a few. So if you think of Jira, that's an integration. But Jira is a company. But they give to ServiceNow, we have multiple integrations to ServiceNow, 1 company multigenerations. So hence, why we have more integrations than partners expect that to grow significantly.
And with the advent of the MCP protocol, which is an open -- or sorry, an AI networking protocol, you're going to see more ad hoc integrations at scale, which is super exciting as it relates to the fixing side of what we're delivering on the platform.
So a little pivot. We talk a lot about machine speed attacks. We talked a little bit about AI and cyber what are we doing inside of the company as it relates to AI incentive go-to-market? We're doing a lot. So I'm going to hit just a few highlights here for you.
So when you think about sort of the customer journey, we map our sales cycles against that. And we also map our enablement, how we drive demand gen through to post-sales experience. And so I'm going to hit a few highlights that we've already started.
And Vlad hit this earlier, what we're doing inside of Tenable around trying to drive AI in our SDLC, yes, that's core to the product, but AI can drive efficiency everywhere in our business. And so we are in early innings, but we're already seeing really good gains as it relates to that in go to market.
So genetic deal coaching seeing inside of Clari, which is a platform to use maybe the questions, the trap setting questions that the seller should use versus having to think of that on the fly.
You think about click-to-chat sort of table stakes capability, but how can we use agents behind our click-to-chat platform to now streamline how our sales development reps get back to customers within machine speed where appropriate.
And here's one that you hopefully will be interested in. So we talk a lot about Hexa and you might be thinking, well, you gate it yesterday, but we've got Terra talking about these use cases he's deployed, but we had an early access program.
And I was one of the early access people as well, and I will try to Trump Eric's [indiscernible] Chief Revenue Officer can use it. So I've actually started to use Hexa in our demo environment just to become really, I'd say, astute understanding of what technical operators will leverage in this technology.
And I do think it's going to free up the customers that we have and the prospects that we're working with around the drudgery and the complexity of working through even their head list or a traditional UX front end, but we're going to provide all 3 choices to the customers.
But our solution engineers getting to the punchline are already starting demos based on the customers' top 3 top 5 pain points, either within Tenable One today, pre-ex or within other technology solutions that we're looking to augment and replace.
So it's been a game changer for us already, and it's not even GA. Well, it's GA, sorry, 2 days ago. And then in post sales, again, pretty table stakes things, how do we give people in the customer success organization, real-time telemetry and call to action plans where we've got opportunity to cross-sell and upsell or if we see account risk within our customers.
And this is all underpinned by a go-to-market operations team, again, world-class function within the business. that's helping us get insights to drive our sales leaders, SC leaders, channel leaders to the right spots to either double down or potentially invest in other areas as well as making sure our forecasts are done accurately weekly.
We understand exactly what's happening moment to moment within the business. So now let me touch on our pricing and packaging. So I think for people that have been tenable for a while, probably the simplest way to think of what we're delivering was already said by Rick from GEICO.
We're trying to drive simplicity and ubiquity with the new pricing that we've launched just earlier in late in April, so just less than a month ago. And so why we're doing that is we're trying to drive adoption of exposure management. And rather than counting multiple line items, which we become, again, fatiguing and super complex for customers, we were saying how can we simplify that buying journey and also the coverage journey for our customers.
So many of our customers and Mark hit on this are maybe not quite ready for a full loan exposure management journey. So it's important to understand that while 1011 unlocks that capability, we do have a lot of customers that say, look, I'm not quite ready for this yet, but I want to take my existing VM environment, Tenable and start at least to experiment with the capabilities in my [indiscernible] layer and then over time, start adding other capabilities that are maybe adjacent to VM, like OT, identity, et cetera.
And so when we think about the sales motion that we have, which I'll touch on the next slide, it's really trying to get siloed DM security tools. And if it's tenable, it's, let's say, [indiscernible] or SC or I/O or if it's one of our competitors, their legacy VM technology and get them to exposure management. It doesn't mean that VM goes away.
Just think of it now as a use case, a vertical use case under a horizontal capability for Eric's slide that is exposure management. And the packages, we're not getting rid of VM. We still have customers that use it needed, but the packages now our traditional security products from a VM standpoint with 2 exposure management packages, foundation and advanced and in the case of foundation, just think of all the sort of basic or standard capability of an exposure management platform and advance, we get into more sophisticated use cases.
And in the case of Hexa, both packages include Hexa -- but in the case of advanced, you get significantly more usage in that package. So the price per asset is higher. I think Matt is going to touch on sort of the economics that we're trying to deliver with the pricing and packaging. But ultimately, the advanced package is our more advanced, most advanced package and everything Eric has touched on would be included in the advanced package.
So we're trying to make it very, very civil for our customers as it relates to their journey with Tenable. And we do see that we will have customers that sort of start where they are today, move to foundation and then over time, upgrade to our advanced package. So when you think about the on-ramps into the platform, there's really 3 simple ways that I'd like to talk to our sellers about it as we've kicked off me joining the company, being a few months in.
And the first focus area, Mark and Steve hit this hard at sales kickoff. I was unfortunately not there. It was amazing, but still, it was good to sort of ride their coattails off a key focus area for the company, which was getting our existing VM base to Tenable on as fast as possible.
And we're doing that because Tenable, as Vlad mentioned, provides multiple moats so it's a bit of a protective tissue against competitors, et cetera. So there's the decentive side of why it's strategic.
But also it unlocks ridiculously valuable capability that siloed tools simply don't have. So like I said, we've already transitioned thousands of customers to Tenable One. We still have a lot of runway, over 60-some-odd percent to go. So that's a massive focus area for the sales organization and the channel organization. displacing competitors, whether it's a sophisticated Fortune 10 or 100, one of whom I spoke to yesterday that has a niche exposure management platform, a competitive VM technology, a competitive cloud technology they likely might start with 2 of those 3 use cases?
Or is it straight modernization with the future proofing of our exposure management platform, we have the flexibility, especially with the new packages to land in either fashion. And while we still have DM technology to land more and more, especially with the capabilities of the likes of Hexa and the demands we're going to see from the market on things like MCP, I expect that we will see more and more lands with our Tenable One platform, either Foundation or advanced. And then obviously, once we land, we have a litany of use cases and asset coverage to drive.
And I think it's very important to understand the simplicity of the asset coverage gives sophisticated organizations the ability to do things like double scanning. So I think we know there's a lot of endpoint detection and response vendors that have some basic VM capability.
And we have some Fortune 100 CISOs to say, you know what, we trust your scan better than anybody else, but we already have an agent on their endpoint. We're going to double scan. And the good news for that customer, they pay once. If they want to drop the competitive agent, they don't have to pay, they get to save that money off that competitive, what we call displacement.
But in the case of Tenable, they've got the coverage and they have the optionality and I think as some of the panelists said, they have the flexibility to move asset types to different use cases over time. And so that flexibility is critical as we go forward, I think, in this type of agentic world, and that's what Tenable One's platform and pricing provides.
So this is an example of a very large major telecommunications company. The good news is, I think all 3 that we use on our phones today are tenable customers. So you have a 33% chance or 33.3% chance of getting it right. And this is a customer that's been with us sitting until -- since 2017, and they started like a lot of our enterprise Tenable customers, probably back even prior to 2017, they might have been doing some very basic Nessie scanning.
In 2017, they made a big investment in Tenable SC along with our web app scanning technology. And this was, at the time, sort of modern core VM and like I mentioned earlier, you've got customers at different stages of their journey.
This particular customer, like many Fortune 500, I would argue that their credit was already doing exposure management and I call it, version negative 1.0 in that they had various sensors like ours and others, they had a single database in the back end and a power BI front end with a lot of bubble gum and tape to drive workflow to do remediation that matter days and weeks because we know that has to be collapsed now into minutes and hours.
And that's why they made sort of this journey, an accelerated journey over the last several years from what I'll call sort of very core VM use cases to a more broad-based sort of foundational almost exposure management use case, although we wouldn't have called it that in Phase II to then about a year ago, making a huge investment in Tenable to now become the brains as we like to call it, of their preemptive security posture, including everything from VM scanning Web App Scanning, cloud, identity, WAS, and we are now becoming the orchestrator of remediation for this very large Fortune 10 organization.
So just to wrap up before I hand it over to Matt, 3 focus areas that we've got our go-to-market team lined up on over the next 8 months as we finish the year, but I anticipate these are going to be similar themes, the tactics may change over time, number one, land with Tenable One; number two, migrate and expand our VM values as fast as we can from VM to Tenable One. And then lastly, how do we deliver speed, scale and efficiency in go-to-market with AI and automation.
And that's going to be, I think, a big factor as to how we continue to leverage on the income statement, still invest in sales capacity, but become smarter and smarter with how we have supporting capabilities in the business. Allow sellers to do what they do best, which is be in front of customers a position and sell Tenable One. So with that, we'll hand it over to Mr. Brown, who's going to call on stage and take us home.
All right. Thank you, Dino. Really appreciate it. our newest executive, been here only a couple of months. And as you can see, hit the ground running. So super happy to have Dino on board. You've heard a lot today. You heard a lot about how this market is changing. It's an absolutely shifting landscape. We wanted to go deep on the technical side.
And so hopefully, you got that, you're able to hear from Vlad and from Eric. And then you heard from Meg on the new brand, you heard from our customers, what I want to try to do is pull this together for you and let you know how I expect that to impact our financial results over the next few years.
First, I think it's worth taking you back to 2021 and which is the last time that we had Investor Day. Back in 2021, really exposure management was a collection of a whole bunch of different sets of tools, right? We had VM, we had web API, cloud identity. But these were all operating somewhat independently. It's pretty different today.
Today, we have a unified platform, which you've heard a lot about, that platform is looking across all of the different asset types that customers have. It's focusing on what matters most, and then it's tying it together with a agentic capabilities that help orchestrate remediation. That's a big change from 2021. We've come pretty far.
We've also come far from a financial perspective, so back in 2021, I'll go a little deeper. Steve touched on this already, but I want to drill into each of these areas a little bit. Our revenue back in 2021, $541 million. Today, at the midpoint of our guide for 2026, we've now smashed through the $1 billion threshold, growing at 15% CAGR over that period of time.
Pretty impressive growth. How about from a profitability perspective? Even better. Profitability has grown from our op income back in 2021, $51 million, 9.4% of revenue. Fast forward, 2026, midpoint of the guide, we're now expecting $257 million in operating income. That's a 24% of revenue. It's an impressive 15 percentage point growth over those 5 years, so averaging 3 percentage points per year.
With that increase in profitability comes an increase in cash. Unlevered free cash flow grew from $95 million back in 2021 to now more than triple that. We're expecting $290 million of unlevered free cash flow in 2026. That's a 25% CAGR over that period of time, more than 9 percentage points of growth. So really impressive. We've come pretty far. Today, as you heard, we've got over 40,000 customers that span 160 countries. We've got an incredible distribution network, 8,000 channel partners, many strategic partnerships, over 300 third-party connectors within our platform. So we've come a long way since 2021. But we also believe that this is really just the beginning. So we -- like I said, we drilled deep on some of these technical aspects over the last 1.5 hours.
You've heard about where we've been, where we're going, where we are going and most importantly, what we're doing to help our customers stay safe. So these are exciting times for us at Tenable. Also really exciting and challenging times for our customers.
You've heard about how AI is changing the attack surface. There's a proliferation of vulnerabilities, but these can be addressed with our Tenable One platform. As Eric laid out really nicely, Step 1 is this first layer. It's the surfaces and signals. It's continuous discovery. Step 2, it's making sense of this noise with the exposure data fabric. Step 3 is orchestrative remediation with Hexa. This is our key differentiator.
Remember, the challenge for our customers is not discovering new vulnerabilities. The challenge instead is figuring out which of those vulnerabilities pose a risk to them in their specific environments on their assets, with their configurations, it's those specific risks, then the challenge is prioritizing them and fixing them.
That's what Tenable One solves, and it's never been more important. To really lean into the opportunity, Dino touched on this with our new pricing and packaging. We knew that we needed to drastically simplify the pricing.
And he talked about and actually a customer panel did a really fantastic job as well. Discussing not just the benefits of Tenable One and Hexa, which is, by the way, only available on the platform, but also this new simplicity of the pricing. This has been a pretty significant change. It reduces friction. Very important to reduce friction, not only for new opportunities but also for expansion.
In the past, customers wanted to switch and mix and match assets in the middle of a contract term. I have to go through new approvals in the PO and procurement process. We don't want that friction. We've eliminated that. Now with it comes an uplift in price. Tenable One foundation is new. From going stand-alone VM to Tenable One foundation, it's a 6 percentage point price uplift.
Going from stand-alone VM into Ten advanced, it's a 60% price uplift. But the price uplift, a little bit like Dino touched on is really just the beginning. What we're expecting is that expansion becomes far easier once those VM customers are into Tenable One foundation, they can much more easily expand within that platform and also much more easily upgrade to Tenable One advance.
That's the goal. And importantly, Hexa AI is only available in these platforms. So while it's still pretty early, you've already heard positive feedback from some customers -- we're getting positive feedback from our customers and from our sellers.
Okay. So why does it matter if a customer migrates to Tenable One platform? Well, first and foremost, and importantly, we know that it's a better customer experience. So clearly, better for the customer, but it's also better for Tenable. And here's why.
We know that our Tenable One platform customers are our more strategic customers. They have longer contract durations with us, on average, 10% longer than non-platform customers. We know that our Tenable One platform customers spend more with us.
We have a higher ACV. Tenable One customers spend 2x to 3x the annual contract value compared to non-platform customers. We know that our platform customers have a much greater opportunity for expansion. Our Tenable One platform customers expand at double the amount of expansion compared to non-platform customers.
We know that it helps from a competitive differentiation standpoint. When we're in head-to-head bake off competitive situations, whether it's in a new situation or in a renewal deal, we have consistently higher win rates when we lead with the platform. Finally, we know, as I mentioned a minute ago, there's an attractive price uplift anywhere from 6% to go from VM to Tenable One Foundation, all the way up to 60%, again, and that's just on price alone.
So what does that mean for growth within Tenable One. Well, what that means is our Tenable -- on revenue growth is growing in the mid-teens. And this is after normalizing for platform change. What do I mean for normalizing? What I mean is, if last year, a customer was outside of the platform, spent $100,000 with us.
This year, they've migrated into the platform, and they're spending 115,000 with us. That's a 15% growth after normalizing for the platform, not 115%. But what it means is Tenable One has very strong growth. It's growing in the mid-teens. Now based on better pricing and packaging, exciting developments within the platform like Hexa AI, we believe that this growth is sustainable.
Importantly, how does that then translate to the overall revenue growth algorithm for the company? Well, today, 2026, we know that the Tenable One platform represents a little more than 1/3 of our business. And again, growing in mid-teens. Nonplatform, roughly 2/3 of our business, and that's showing mid-single-digit growth. Now what we expect to have happen over the next several years and by 2029 is that our Tenable One platform revenue will continue to represent a greater share of the total business.
This is what we believe 2029 looks like. 2029 Tenable One platform revenue will represent more than half of our business while growing in the mid-teens, non-Tenable One, the remaining portion continuing to grow mid-single digit.
What that translates to is stabilizing growth from in 2026, where we're in high single-digit revenue growth to stabilizing growth into 2029, accelerating to high single-digit to low double-digit growth.
Okay. That's the revenue side. The other side is profitability. That's been another really impressive part of our story. First and foremost, we know that we're investing for growth. We have an enormous opportunity in front of us. heard a lot about it today.
So we're investing in sales capacity. We're investing in developing features and functionalities, particularly into the platform. But we also know that we can get some efficiencies and Dino talked about some of these on the go-to-market side. Others have touched on them. A lot of them are being driven by AI capabilities. We think we're going to be able to continue to have cloud optimization in our cost of sales. which means we'll be able to maintain gross margins of about 82%.
But also some of those AI-powered efficiencies are going to allow us to rotate into high-impact areas for hiring such as in sales capacity, such as in specialty product development, while also continuing to get a little bit of leverage in the margin.
Some of these AI-driven capabilities include automatic RFPs and quoting. It includes AI-powered SEs to help our sellers be more effective. in areas like general and administrative areas, it's things like AI-powered data clearing and aggregation.
It's the type of normal things that you would expect to get efficiencies from using these new AI tools, but it's allowing us to rotate in and spend money where we think it's most effective. What this ends up translating to is about 1.5 points of operating margin growth each year.
Okay. Moving on to capital allocation. So you can see all of that increase in profitability especially over the past several years has come with an increase in cash and a lot of it. I mentioned a few minutes ago that we'd seen our annual unlevered free cash flow more than triple from 2021 over to 2026.
In fact, since 2021, we generated more than $1 billion in cash, and it's going to continue to go up from there. What this does is it gives us a ton of flexibility. We've had a history of using cash and inorganic investments in the form of M&A. And we've also leaned into our share repurchases especially lately.
Share repurchases is represented here by the yellow bar have increased significantly over the past couple of years. The Board authorized an incremental $150 million of share repurchases at the start of the year that we've continued to lean into.
And in the first quarter, we bought 6.1 million shares for $130 million leaving a little over $200 million left on the share repurchase authorization, which is represented by the dotted line here on the screen.
We continue to believe that our stock is trading at prices that don't represent the fair value. And as a result, we've leaned heavily into share repurchases. And as you can see, the diluted share count is coming down. The weighted average shares outstanding has dropped.
And in fact, at the end of Q1, it was down 5% year-over-year, and it was at the lowest level that it had been at in over 3 years. Finally, I'm going to pull it all together and share midterm targets.
First, with 2026. This is consistent with the high -- with the midpoint of the guide, that we had given several weeks ago on our earnings call. High single-digit revenue growth, gross margin at 82%. We've got sales and marketing, R&D, G&A, at approximately 32.5%, 17% and 8.5%, respectively, operating margin at 24%, unlevered free cash flow at 27%.
But as I mentioned, as Tenable One continues to make up a greater portion of our business and is growing in the mid-teens. We expect our revenue growth rate exiting 2029 to stabilize and then inflect tire, showing revenue growth of high single to low double-digit growth.
We expect gross margins will be able to be maintained at approximately 82%. And within OpEx, we expect to get about 4 percentage points of leverage, spread out across sales and marketing, a little tiny bit in the R&D and then some in G&A as well, resulting in operating income, operating margin of about 28%, unlevered free cash flow of 31%.
And that means we hit Rule of 40 exiting 2029. This translates to about 1.5 points of margin growth, as I mentioned before, from 2025 and to exiting 2029 .
Okay. I think I made up some time. So I know that we are going to open it up for questions now. We're going to have to get set up with some chairs. So we'll go take a quick, quick 30-second pause and then we'll get Q&A invite everybody else back up here. Thank you.
We've got a lot of questions here.
2. Question Answer
Great. Rudy Kessinger, D.A. Davidson. Thank you guys for hosting. Matt, one metric you didn't touch on that I wanted to ask about was gross retention and how that's trended over the last several quarters, particularly as it relates to large platform vendors, we hear intersects all the time, CrowdStrike, et cetera, showing up in deals.
And I'm curious, as you think about going forward, what is the risk on the stand-alone VM side growing slower than that mid-single digits. Because I think on the Tenable One side, I think with everything you guys have talked about, I could actually see upside to that mid-teens growth, but I think where I see the risk and where a lot of investors would see the risk is on that standalone VM side.
Yes, great question. So gross retention has been remarkably stable. That's something that we've seen quarter after quarter. As you know, we disclosed our net expansion rate and gross retention is a component of that. .
Of course, the rest of that component is expansion. And even that rate, we are beginning to see signs of stabilization, right? Over time, that rate has been coming down. Underneath that, gross retention remarkably stable. And our expectation, as we make our way through the year is that, that rate in total, the total net expansion rate stabilizes as well.
So that's kind of first piece. Second piece, the mid-single-digit growth on non-platform has also been quite stable. So being able to understand the dynamics and the opportunity as we see it, is we feel there's a solid floor and the opportunity for us now is to really lean into that growth, particularly in the platform.
And then you're essentially shifting 20 percentage points of mix from platform in 2026 to exit in 2029, growing in that mid-teens rate to get that incremental 2 to 3 percentage points of revenue growth in that period of time.
And one last point. VM and exposure management especially is more important in the agenda era. There's more applications, more infrastructure, more identities, more agents, consequently more risk and more threats and more exploits. The number of vulnerabilities is increasing dramatically. There's 300,000, I think, since 1999. And 50,000 new CVEs added last year.
This is no longer enriching CVE data. They can't keep up with the proliferation of new vulnerabilities. We're Entering an era unlike any other. So exposure management is going to be more important. VM is absolutely foundational to that, and it will provide tailwinds to growth, and we're confident of that.
Mike Cikos from Needham. I guess the question comes to the growth versus margin debate. We'll go back to Matt for a second, but great to see the margin expansion that you guys continue to execute on. What was the thought process? And I know that you guys have been putting this together on a multi-month, multiyear journey, right?
But as far as the decision to continue to expand those margins versus potentially let's deliver stabilization of those margins and try to accelerate growth faster, right?
And then the second piece, maybe more of a strategic question here, but you guys are definitively using the carrot approach to get people to adopt Tenable. Given the seamlessness of expansion and the dollar opportunity, why not use potentially more of a stick to help that penetration and expand at a faster clip?
Yes. Great question. So when we think about margin versus growth, we've always taken a pretty balanced approach but our expectation is around 1.5 percentage points of margin growth -- we know that, that is an amount that will allow us to continue to lean into and invest in that growth, right? .
In the past, since 2021, we've grown margin 3 percentage points. This is actually a bit of a step down. The reason for that, again, is because we do see an enormous opportunity in front of us.
And so we know that we can invest heavily in that area while still continuing to get 1.5 points of margin. The carrot and stick approach is also a really good question and I'll dish it .
Yes. Let me cover this one. That's an awesome question. trust me. It's something we talk about we debate all the time. But our thought process here, and this was even before Dino joined, we are laser-focused in regard to our selling and our channel organization, upgrading that VM installed base. We pay accelerated rates to our sellers for Tenable One. We have very aggressive incentive programs to touch all of those VM customers and migrate them to Tenable One. So those motions are taking place.
And the other attribute is you can obviously see the margin improvement, right, by going to advance and going to foundation. But it's also one of those things where you've got to take the customer on the journey -- if you just automatically upgrade them instantaneously, they won't understand the benefit of the multiple assets that they could expand with. So there's some education.
So when we go in, there's a huge sense of urgency to get them on to T1, but we also have to take them through the journey, so they actually get the value and the benefits through the process. And when they do, you see some of those examples like Dino has shown where they come in and then they start spending 7x.
But I can just tell you, and it's even been more aggressive since Dino's joined, we are all over that VM installed base, moving them to T1, and we also are ultra aggressive in regard to competitive displacements. Going after our traditional competitors and nontraditional competitors. So that's another thing we spent a massive amount of time on also with T1.
Joe from Jefferies. And congrats on Hexa GA. I think you made it extremely clear why the lab vendors are friends, not foes. And I know you're embedding anthropic -- but I imagine you also have your own AI.
Can you just talk when we think through Hexa, how much is embedded Anthropic versus your own AI? And I asked that more because I imagine a lot of your exposure management competitors will also be embedding the lab vendors I'm just curious on the differentiation and the secret sauce on that side?
Yes, I can take this. So the first thing I'd say is that it'll get a little nerdy in the answer. But Hexa is a model agnostic agentic harness. So we built it to run multi-model. In fact, today, we're running on a couple of different Anthropic models in production with customers and in our labs, we're doing things with other models as well. And so the -- of course, the models themselves are quite capable, but there's quite a lot of, I'll say, IP in the tools exposed to the models, how the data is fed to the models, the context created, when you use one model versus another model, ensuring that the outcome that the customer wanted when they said, go do a thing is actually the deterministic outcome that was created.
And of course, it's early days still. So our expectation is that the foundational models will continue to get better and better and better, and the faster, the better from our perspective. But at the same time, you've got an acceleration of the complexity of tasks that customers are wanting to entrust to things like this. And so I expect that the gap of value that harness brings stays robust as far as they can see.
And some AI exposure, too. The stuff we're doing with AI exposure is pretty powerful also.
Yes, for sure. Yes, the AI security side in helping see the AI infrastructure and all the different attack paths that are there as well.
All right. Meta Marshall from Morgan Stanley. I guess a lot of your -- the conversation focused on kind of allowing customers to move at the pace that they're comfortable with. But how much of their -- is an acknowledgment by your customers that there's just going to have to be kind of more reliant on kind of automation of these systems in order to kind of protect themselves. And as you've been doing data with customers, how quickly do they kind of rely more on the automation?
I'll start and then others can kind of jump in here. We talked about certainly in the agentic era, we'll see a proliferation of vulnerabilities. And the one thing that's clear, I think Mark shared the stat is that mean time from vulnerability discovery to exploit is 1.6 days, talking to a lot of customers here today, CISO security executives. Look at the SLA time, it's not 48 hours. It's not 7 days, not 10 days, not 30 days. I think Eric mentioned, according to the Verizon breach data report is now 40-plus days. [ When it falls ] it's going like this, mean time to exploit is going like this, it's down dramatically. And this is really all about survival.
I think what was considered possibly taboo years ago, which is get tickets in the hands of humans and let them do the fix, let them identify the risk doesn't scale the agentic era. So I think customers are now, I want to say, forced to move at machine speed are willing to accept a little more risk. They don't want to blow up things downstream we're seeing the transition to assisted remediation, but we know autonomous remediation orchestration is coming, and it's where you have a repeatable process, where there's clear governance and guardrails and where you think the risk downstream is minimal. But we are on this journey, and AI is taking us there, and we're leading our customers in that direction.
Maybe just to build on that slightly. This is actually the exact reason why we have levels of autonomy within Hexa and customers can choose the right level of autonomy or automation they'd like for specific tasks and according to their kind of -- where they are in the maturity curve.
And another kind of thing to keep in mind, but right now, we're kind of talking about what's going on with vulnerabilities are coming and all that, we can actually decouple right, customers once they get going with this too remediation. We don't have to wait for yet another way of vulnerabilities. The job to be done does not change. Like the exposure -- the job to be done is exposure management spending exactly the same with customers as they keep going, I can mention a flywheel that just keeps going faster and faster and faster as things become more autonomous in the right context in the customer environment, right? And with time, customers will actually be able to get ahead of the breach fixed security hygiene regardless of whatever threat or vulnerability is going to be released next.
This is Jonathan Ho from William Blair. Just given the clearly growing importance of your platform, the significant capability gains that Hexa adds to that platform and the broad proliferation of assets that we expect. I'm just trying to understand why we can't see even faster growth than what you're talking about today. Is this just broadly conservatism? Are you looking for more visibility? I'm just trying to understand why it wouldn't be faster than sort of these growth levels. Steve is smiling.
Sure. Okay. I'll take the easy one. Look, I mean, that's absolutely our goal. I mean we're extremely optimistic in, not only where I think the market is, but where Tenable is specifically positioned in it. So clearly, a huge opportunity but also somewhat early days, right? This got the pace at which things are changing and happening really, really fast. So Hexa GA 2 days ago. Methos, preview was released on April 7, right? And so here we are in near end of May, things are happening quickly.
Clearly, though, we think we've got the right strategy. We think we have the right approach. We think we have the right products. We think we have the right team. And so I'm extremely optimistic. I think the future is very bright. I also -- I don't think we need to get ahead of ourselves on where we think it's going.
Roger Boyd with UBS. I wanted to come back to the automated response question we just talked about a second ago. How much of that toolkit do you want to own yourself? And I know you launched patch management last year, but a lot of the conversation today was around keeping up with patches becomes increasingly difficult. So how are you thinking about the broader kind of realm of remediation that includes things like configuration management, asset isolation as far as enabling that automated response?
We're definitely leaning into that pretty hard with Hexa and Hexa enables that in a bunch of new ways that would have been really hard to do a year or 2 ago. And so, I mean, again, a couple of demos we showed if you're walking -- or you have the opportunity to walk for, I guess, the course closed now. But there were a bunch of our partners showing some of those kind of those capabilities as well. You'll see more from us pushing in that direction.
It's Saket at Barclays. I want to zoom out a little bit and Steve maybe touch on what you were talking about with more vulnerabilities and whatnot, right? So one of the earlier slides kind of has you scan, you find vulnerabilities and then you patch. I want to dig into each of those from just a value perspective, right?
Scanning is something that I don't think Frontier models want to do nor do enterprises sort of trust any old model inside. So that's good, right? I think there's clear value there. But just to push a little bit to make sure the question is asked. For finding vulnerabilities is more of the value shift to the Frontier models since they're finding vulnerability faster, right? But on the other side, does more -- do you capture more value from patching, which now needs to be done at machine speed? So like there are a couple of kind of shifting values here. It feels like in the in those 3 processes that makes sense. Maybe I'm thinking about it wrong, but I'm curious how you think about that?
Yes, I'll start and others can kind of chime in here. But there is a clear distinction here. Number one, so first of all, I want to be very clear. What we do is more valuable and more important in the agentic era. And scanning becomes more important, but just to make that distinction, the Frontier AI model companies, they operate at the code layer. We find vulnerabilities in code.
By the way, a vulnerability is not just a bug in a piece of software, a vulnerability/exposure is a misconfiguration, is an overprivileged identity, is the absence of a compensating control. So we're not in a vulnerability discovery business. We never have been, yes, we've discovered 500 0 days since 2018. It's not what we do. We can tell you if those exposures exist in the environment. We can tell you if those exposures can be connected and chained together to create a lethal attack path. That's really important.
So what we do, we solve even more important. So scanning and the data collection infrastructure becomes more important. Prioritization is not optional. It's not severity scores, and it's not CDEs. It is survival in the agentic era, and we do that better than anyone. And the Frontier AI model companies will help us do better raising, better explainability of risk and enhances what we do. And then the final thing is really the ability to take action, which is what Hexa is all about today, and that's really our north star.
And if I can just pressurize the -- if you drill a level deeper, when you talk about finding a vulnerability, I think, it's important to be really precise. You basically say there's closed source. I worked at Microsoft for a long time. Microsoft last year found what? Roughly 1,100 CDEs. I don't know how many they found last year because I wasn't there last year.
In the era I was there, we usually found about 2 to 3x what we actually patched. So better capabilities to find vulnerabilities, great, that's good for the world. That will turn into more things patched from closed source, great. Tenable doesn't play in that game, never have, don't want it, right?
Then you got open source, right? Different game. There, while some open source libraries, I don't know if people read the Kearl article via a week or so ago, Kearl's one of the popular open source packages, has a particularly conscientious set of maintainers who've been actually pretty aggressive at using Frontier models over the last few years. And of course, the many cool tools that existed before they were Frontier models. They ran Methos on top of curl and found one, additional vulnerability. And that's not to say Methos isn't awesome. It's just to put in perspective kind of the difference of a really well studied code base, a really well-secured code base and then Methos is great.
The victory is a sound one, right? The challenge on the open source side is the really good maintainers and well-funded maintainers might be able to keep up, maybe with this, but a lot of the open source used in the world is not. And so they are the challenges will the patches exist at all? Or certainly, will they exist in time? No, I think it's pretty clear. And so there, you've got to really look at how you're been compensating controls, how you have layered security, how you're reducing your exposure risk when there isn't a patch.
But again, in that area, the finding of the vulnerability never part of our job, now what we want to be our job. As that explodes, you have an already hard job that as a defender, but you're trying to figure out of all those things out in the ecosystem, how many are you vulnerable to. That is the heart of what we do. And that's, as Steve mentioned, what we think will continue to have significant value and in fact, more value in the world with the tailwinds from AI.
Brian Essex from JPMorgan. I'd like to ask you a question actually. So historically, vulnerability management hasn't been at the top of the list of a lot of enterprises. But I'd love to hear your observations with those that have adopted Tenable One. What has your practice been for the percentage of assets that they scan throughout their networks? And then our view of that question is, do they share that -- do you share that exposure with maybe some of the EDR vendors that are moving into the space?
Yes. So there are a couple of points here. I think the vision of exposure management is exactly that is connecting all the dots. And one of the reasons we have 300-plus integrations is want to pull signals from tools like EDR, your cloud security products, whatever this you have across your enterprise stack, you don't have to replay and replace and only use a tenable solution, even if it's better in some cases. you can keep it. We just need the signal, right, exactly to collect those dots.
And the reason for that, right, for customers because adversaries really go as a they -- they don't attack based on your own structure. They don't go only on your on-prem databases and data share cloud. They move laterally. They start with whatever is easiest, the weakest link, might be even the human [ pros ] phishing.
And you have, I think, the latest number from Gartner, 70-plus security tools in an average enterprise and to make things slightly worse. You have different teams under the CISO running those tools, right? So it's a largely fragmented defense. So connecting those dots is super important to build things like attack path to understand, right? To go across all these signals. And out of these connect the dots to understand what's more important to me specifically right now. Tenable One or Hexa give them a better sense of urgency that they need to increase the penetration of the asset -- percentage of assets they need to scan in their networks?
Absolutely. It's both that, that comes from kind of creating that broad content, if you will. And also vulnerability management historically is a very kind of limited to specifically only do this on endpoints and the traditional cycle that used to work kind of -- there's some patch, I figure out if it's relevant for my specific server. I open up a patching window or in the process it takes like 2 months or so. I get it done, hopefully, right? But again, this is still relevant, but it's like one piece of a much bigger puzzle.
Any quantification of the lift you might see on the VM side?
Not today.
I appreciate it. Yes, I was just going to add to it, on that point that I think -- it depends on what vertical, what segment of the market we're speaking to as far as the comfort level, the speed at which their organizations are getting more broadly, deeply. So probably your organization is pretty mature. And I think what you're seeing with the Frontier AI models is people are saying like, okay, we do have to kick into gear authenticated scans, scanning everything. And I think we're going to ask similar questions like how frequently we should be looking at the speed of this. I think some of those will be driven by policy regulation and our own findings through capabilities like Hexa. So then you're going to see this moving quite rapidly over the coming weeks and months.
One last thing to add, the thing we're seeing with Hexa is kind of super cool to see. We talked earlier about the spill of trust, and this is many times of organizational processes inside the large enterprise. So if people see what Hexa can do for them, right, it allows our practitioners to actually show that thing to their management chain. And it literally opens the doors, build up more and more cycles, more and more levels of the funding. And again, that cycle is something that just keeps going.
Two more. And I know we are running late. So I appreciate everybody asking around.
Shrenik Kothari from Baird. So Steve, you started the presentation citing there's incremental TAM beyond exposure management from -- so added almost 100% over and about exposure management to AI attack. So for my first question is, are you already seeing the funding urgency and timing show up in terms of unlocking these budgets from that AI governance bucket. And part 2 is some of the broader platform players are starting to play in by leveraging their exposure workflows and aggressively leveraging Flex models to broaden [ peak ] over dollars also across modules. I know you touched upon Hexa from perspective of premium attach and up-tiering motion. Can you talk a little bit about how potentially Flex can accelerate that expansion as well?
I'll start off, and then I want to hand it over to Mark because I think you can add a lot of color here. The one thing I'll say is, if you look at -- yes, TAM has expanded significantly. First, I think the last time we updated our TAM was several years ago. So a $30 billion TAM per annum for exposure management, we said today, AI securing the threat vector of AI is an incremental $35 billion.
If you look at -- there was a Wall Street Journal article earlier this week, but the average Fortune 500 company over the next 12-plus months, will each have 150,000 agents deployed, multiply that by 500, that's 75 million agents. There's arguably 100 million, tens of millions of companies in the world, 100 million plus.
We are going to see a proliferation of agents unlike anything other. It's going to be ubiquitous. It's going to be autonomous. And it's one of the most important challenges in all of security. So I think it connects it back to go to market is, yes, customers are still wrestling with this issue. It's a very complex and challenging one. They're getting their arms around it, and it's absolutely driving more engagement. You heard that from Mark and you heard that from Meg.
Yes. A couple of things I'll add. And Matt and I and Aaron hit on this a couple of days ago in one of the investor conferences. So first and foremost, kind of anecdotally, right, since Methos and the Frontier AI models kind of explode on the scene, we have seen a dramatic increase in customer engagement. I think Steve and I mentioned on the call report in Q1, we said 100, we are literally at thousands of customer outreaches to us at very senior levels, CISO level engagement, talking to us about what and how we're dealing with it, what would be our remediation steps, what should they be doing in their environment from an exposure management perspective, right? So you're looking at some of the pipeline build that Gino and his team are all over, very, very happy and feel really strong with the signs that we're seeing.
When you look at the competitive dynamic, and I think Vlad and Eric and even our customer panel hit on it, right, Tenable is the leader, the #1 player in the exposure management category and Tenable One is the #1 platform. And it's not just our customers, and Tenable is saying it. Gartner put us as #1. Forrester put us as #1, right? IDC put us as #1.
When you were looking at building out this now mission-critical exposure management platform, it started and the genesis was it was world-class vulnerability management. And then you added those other components to get visibility on the entire tax surface with all of the native centers we now have, and now you're able to get the whole visualization, you're now able to tie in Hexa from an agentic AI perspective.
We feel unbelievably confident. I can't say it strongly enough on our compete level right now. When you talk to our sellers, you talk to our team, our compete level against our traditional competitors and any new competitors, we feel unbelievably confident going against them.
Richard Poland from Wells Fargo. So mine is on Hexa in particular. I'm curious, we talked a little bit about the 6% uplift for Tenable One foundations, 60% for the advanced. How does the Hexa monetization work? Is that usage base? Like how should we think about that as part of the monetization?
So we chose to make Hexa's functionality tied to the platform. So what that means is we have to think the 2 layers of the platform. You've got the new packaging Tenable One foundation, Tenable Advance. Hexa, there's not good Hexa and bad Hexa. It's just Hexa.
Now in advance, you have things like attack path analysis, which does not exist in foundation. So Hexa is smarter, in Advance because it has a smarter exposure graph that can do more and have more context. The way we're approaching this is we have -- you buy your license, and this is graduated based on how many assets you license, you get a certain amount of included Hexa with that, and then it's consumptive above that. So if you -- if you're particularly active, you might go a little bit over, and that's how we've approached it.
Yes. And I think it builds an opportunity again as I think originally, pre-Hexa prebidding here. We were probably thinking the Advance capabilities to Eric's point, attack path analysis is one thing you'd unlock. Well, now Hexa in a way becomes sort of an indirect upsell engine for us because they'll want to unlock some of those capabilities. So again, it's very early days, 2 days after GA, but you can tell the excitement we have. Again, we have customers that have leverage it that are validating the capabilities. But it's interesting that we have sort of this like what I call horizontal use case expansion opportunity, which is pretty easy to understand, VM infra cloud, AI exposure, et cetera, et cetera.
But then Hexa, people wanting to unblock that to say, okay, actually in full blown capabilities for remediation attack path analysis is going to be pretty interesting to track over the next couple of months.
And last thing I'll hit it from a margin perspective. So as we model this out, which we've obviously worked very closely together on this, we have a negotiated agreement with Anthropic that's in place that includes spend across our entire company. It includes what we're doing operationally. It includes what we're doing in development, also includes cost of sales from Hexa.
In building in the model we understood what would be included as part of the tiers, sort of free of charge, if you will. And the way that we've modeled it out is the incremental uplift that we will get from customers converting over more than pays for what it costs and what's included in the model.
On top of that, there's, as I mentioned, an enormous expansion opportunity as customers begin to see the utility of Hexa. We think that's great. It will continue to expand and potentially then move up even to Advance that pays for it again. And then finally, as they bump against those limits, which we would love to see, frankly, we want usage, there is a pay per token that kicks in after that.
You guys want to close it up?
Yes. I think Mark and I are going to bring it home here. First and foremost, I want to thank you for attending our first Investor Day in many years. The change in this company has been extraordinary. We're in the midst of 3 major market transitions from visibility to action, from manual workflows to orchestrate it and automated remediation, and from siloed tools to an integrated platform, and one platform for taking action and reducing risk.
The mandate has never been more important. The opportunity has never been bigger. And this team here on the stage has never been more excited. And so we're confident in what we're doing and our ability to execute.
I echo every single thing Steve just said. Hopefully, you guys can feel it. I know, Steve, myself, Matt, Erin, we spend a lot of time with you, folks. You can see this confidence level of this team right now, and especially even with new members being here at Tenable, I don't think -- I've been here for 6.5, coming up on 7 years. I don't think the confidence level as a company has never been higher, right?
The tailwinds that are coming our way in our view are built for this exposure management platform. We're getting the validation from the customers. We're getting validation from the Frontier AI lab. I mean, Anthropic and OpenAI are saying the same things to us that we're saying to you guys about how these partnerships are going to be strategic for them. And the momentum you feel when you talk to customers, you talk to our partner community and you talk to our sellers is phenomenal. So we just now are all about execution, all about driving growth, all of the metrics that Matt has laid out is what we are laser-focused on. And we appreciate you guys coming, and look forward to talking to you guys in the future. Thank you very much.
Tenable Holdings, Inc. — Analyst/Investor Day - Tenable Holdings, Inc.
Tenable Holdings, Inc. — Analyst/Investor Day - Tenable Holdings, Inc.
Tenable used its Exposure 2026/Investor Day to frame Tenable One + Hexa as the platform to counter AI-driven, machine-speed attacks.
📣 Key Message
- Takeaway: AI is compressing the window from discovery to exploit, making exposure management mandatory; Tenable positions Tenable One (sensors + unified exposure data + Hexa agentic engine) as the platform to detect, prioritize and orchestrate fixes at machine speed with humans in the loop.
🎯 Strategic Highlights
- Sensors & Scale: Tenable emphasizes its data footprint — ~300,000 plugins/sensors across 40,000+ customers, ~1.7 trillion real-world findings and 70k plugins shipped last year — plus 300+ integrations to ingest third‑party signals.
- Hexa & AI: Hexa, the agentic engine, announced generally available; built as a model‑agnostic orchestration/harness and partnered with Anthropic for nonpublic models, joint research and safer enterprise deployments.
- GTM & Pricing: New Tenable One packaging (Foundation / Advanced) and flex pricing aim to simplify buying and accelerate migration from legacy vulnerability management; Tenable One is already >1/3 of revenue.
🔭 New Information
- Announcements: Hexa GA, an open connector and a strategic Anthropic partnership (early model access, joint research), plus simplified pricing/packaging and MCP protocol support; no new near‑term financial targets were given.
❓ Analyst Q&A
- Retention & Mix: Management said gross retention is stable while platform mix is the lever to reaccelerate growth; Tenable One customers show longer durations and higher ACV.
- Growth vs Margin: Company plans modest margin expansion (~1.5 pts/year) while continuing to invest in sales capacity and platform development.
- Hexa Monetization & Safety: Hexa is sold via platform tiers with included usage and overage charges; product is a harness (model‑agnostic) with significant proprietary data/context IP and human‑in‑the‑loop controls for staged automation.
⚡ Bottom Line
- Implication: Tenable is staking its moat on data scale, integrations and an agentic remediation layer; if execution (migration of VM base, adoption of Hexa, controlled automation) proceeds, investors can expect higher ACV, deeper expansion and improved economics, while risks include execution pace, customer trust in automation, and evolving competitive dynamics.
Tenable Holdings, Inc. — J.P. Morgan 54th Annual Global Technology
1. Question Answer
All right. Good afternoon, everyone. Thank you for joining us. My name is Brian Essex. I'm JPMorgan's midcap, large-cap software analyst.
Very excited to have Tenable with us here today. We have Mark Thurmond, co-CEO of the company; and then to his right is Matt Brown, CFO.
So Mark, Matt, thank you so much for joining us.
Thank you, Brian, for having us.
Thanks for having us.
Good to be here. This is my hometown. So I'm a Boston guy, so I love when the conferences work out this way.
We'll talk more about that. I spend a lot of time here.
I love it. I love it.
Yes. Excellent.
I guess maybe to kind of start at the top, you talked a little bit on your earnings call about, I don't know if it was the word that you guys used, but a tsunami of vulnerabilities coming down the pipeline, particularly post Mythos. And you referenced the webcast you had with, I think, 1,000 people joined up in 72 hours.
Yes.
Maybe help us understand what the nature of the conversations that you're having with customers are and how much visibility you have into like the resulting demand pipeline for that.
Absolutely. So a couple of things. Yes, it's a good question. So put some context to it too. We actually are having our Exposure Management Conference this week here in Boston. So we put together what was literally the first exposure management conference, and it's actually happening tonight and tomorrow. So we've got over 650 to 700 customers that will be attending from all around the globe.
And the attendance actually spiked. And when you look at who registered at the CISO level, an executive level, over the last 5.5, 6 weeks, we think a lot of it had to do with Mythos and the announcements there.
In regard to some of the pipe build and what we're seeing in activity, we've had literally thousands -- hundreds to thousands of different individual conversations with executives. In the beginning of the announcement with Glasswing and Mythos, it was more about, "What does this mean? We hear this word vulnerability. Are you guys going to be disrupted? Can you give us an explanation what's going on?"
And so we sat down. We have a very, very specific talk track and an educational track on what it means for cybersecurity, what it means for the exposure management category. And after folks got educated and realized, okay, this is on software code, right, where they're able to find and do an incredible job at finding those vulnerabilities. We now are using exposure management, right, things behind the firewall, for all of our native sensors and all the prioritization, and all of the automated remediation, all the steps you need to take when you're going to be seeing anywhere from 5, 10, 15 to 20x increase in the amount of known vulnerabilities.
And so for us, it's been an excellent event. We now have taken a lot of that pipeline activity and it's going through what we call the sales funnel, meaning it comes in as a conversation, then gets converted to a pipeline, then gets converted to a presentation/demonstration. That then moves to a POV, proof of value, and then you negotiate an expansion or a new deal.
So great top of funnel, like super happy with what we've seen there. And now these opportunities are going through our sales process and sales funnel.
So we're very optimistic. We feel very strong about what we're seeing in the conversations. The executives, who we're now engaging with from a CISO perspective, is excellent. Sometimes when you're doing an expansion or an upgrade from VM to Tenable One, you wouldn't get access to the CISO. The CISO would say, "I'm going to trust my VM or exposure management team." The CISOs now want to meet with us, and we're able to have a broader discussion about bigger expansion opportunities, bigger, more strategic deals, and then educate them about the partnership we now have with Anthropic and OpenAI, which we can talk about also.
Sure. And what are you finding as you assess your customers' vulnerability landscape or exposure management landscape? Because you have different -- I mean, obviously, with Mythos, everyone is focused on code vulnerability. And a lot of those are attributable to packaged software. But you also have custom software, which may be more difficult, may cause refactoring. And also hardware, which you may have to replace at some point, which is longer remediation cycle. So what is the mix that you're finding within your customer base? And how does your platform help them manage exposure to each of those different segments?
Yes. So it kind of hits everything you just discussed, so kind of all of the above. But the way I'll simplify it is when you think about exposure management, right, the true value of exposure management compared to, say, traditional old-school VM, it's really built for kind of what we're dealing with today. It allows you to see all of these signals, right? We have all of these native sensors within these customers' environments looking at traditional IT assets both in the cloud and on-prem.
But then we also have tremendous visibility at the asset level looking at operational technology, looking at cloud. So think of any type of SaaS-based application or cloud infrastructure. Looking at web application scanning, looking at identities, third-party asset types, attack surface management. So think of Internet-facing assets. All of that allows you to put together what's called the modern, when you look at a modern cybersecurity attack surface.
And so now if you're a customer, this is really what you want to know. You don't want to know about one specific portion, right, of your environment. You want to know about your entire attack surface. Then once you get all that, you can think of the thousands and, in some organizations, hundreds of thousands of vulnerabilities and CVEs they get. We then allow you to look at it, prioritize it, set up certain automated remediation paths, be able to then take that automated remediation, flow down to patch management, flow down to autonomous automation at some point and level. We can talk about Hexa, our agentic AI platform that we're rolling out. And so that has been the conversation.
And so what's exciting is customers now want to look at the entire attack surface. I can give you one quick example where we're seeing some really good opportunities, in the OT space. OT was traditionally one of those asset types that would get cut off at the end of an opportunity or deal. That's why you haven't seen great growth with the private OT vendors, because it wasn't sustainable. We're now seeing really good growth in data center build-outs as the companies are building out data centers, but also wanting to get an asset view of what the risk is in these OT environments. And now with things like Tenable One and what we're doing with Hexa, we're seeing really good growth opportunities there too.
Great. And how do you find your customers, I guess, mitigating the risk that they're finding? One of the issues that we're hearing more and more frequently is your mean time to exploit is just collapsing.
Yes, it's insane.
And it takes time to like assess your platform, remediate the platform, deploy patches, right? So what does that gap look like? And what are the -- are there other adjacent types of technology that they're deploying to kind of either sandbox those incidents or remediate or air gap from exposure? Like how are they managing that?
Yes. So to your point, right, so when you actually look at from when you first figure out you have an issue and to the mean time to potential exploitation, just to put it into perspective, in 2025, 60% of breaches that occurred were on known vulnerabilities that a patch was available. So think about how scary that is. That means you knew there was a vulnerability, you actually know that there's a patch available, but you didn't have the remediation cycles. You didn't have the automated remediation to allow you to do the patch management, to turn the system down, to talk to the IT team, to actually put down the downtime.
What you're starting to see, and we're going to talk about a lot of this tomorrow when we have our Exposure Management Conference, is with Hexa, our AI agentic agent, we are seeing our customers, that use Hexa in early access, being able to build the agents to do autonomous remediation, being able to take those manual processes around remediation and around manual tasks. Think of things like tagging an asset, right? Super painful. Think about patch management. Super painful. You're able to create these agents that can actually take those manual, mundane tasks and automate them.
And we'll be publishing some customer success stories where there are certain things they did from a remediation perspective that went from weeks and months down to days and seconds. So huge kind of quantum step, quantum leap forward in regard to the way folks and customers are going to start using Tenable One.
Hexa is going to be, we think, is going to be a significant driver of getting people off base VM. We have a huge tens of thousand customers that have VM that we want to get moved to T1, and allow us to expand the T1 asset count.
How many of these -- one of the things that we've heard -- several things we've heard, but one is the noise-to-signal ratio accelerating. And the other one is other types of technology that might be able to be deployed. If you assume that you're going to get breached a lot faster, you can have adversaries in your network, so things like deception technology, because you'd want to find out, or is there someone in my network? Like where do you see the levels of opportunity as this becomes a shifting environment where it's probably likely that more networks are going to get penetrated over the next year or so?
Yes. I mean, listen, so when we take a look at it, I think right now people are still kind of in that assessment phase of understanding and getting true visibility to all of the different assets, all of the different potential toxic combinations that they have out there. I think the market, the Wall Street community and customers are getting much more educated on what these -- the power of these frontier AI models. Let me just give you a couple of examples, right?
When Mythos was launched, right, everyone saw the sell-off in cybersecurity, right, saying, "Oh my gosh, these guys are going to displace cybersecurity." I think you can see the run back up in cybersecurity where they're realizing, "Okay, there's going to be some of these cybersecurity companies," Tenable being one of them, where we'll be announcing our partnership with Anthropic tomorrow. We have the Deputy CISO of Anthropic presenting at our Exposure Management Conference tomorrow, "that are leveraging those AI frontier models to enhance and take care of that T1 installed base to automate these manual tasks and procedures."
I think you're going to see the fear from our customers. And what we're seeing is when you do get one of these adversarial attacks, either a state-sponsored attack or a ransomware attack that uses one of these very capable frontier AI models, not so much from OpenAI or Anthropic, but from like DeepSeek where you have something in China, you have something in Russia. And that is one of the big fear factors that a lot of our customers are expressing, saying, we haven't seen it yet. You can see Google and Mandiant put out a couple of different reports. We are starting to see some groundswell of potentially some of those type of very advanced, persistent threats and very sophisticated attacks.
That is -- what we're talking to our customers is like if that is going to happen, and to your point, Brian, it's inevitable, you want to have full visibility. You want to know where the toxic combinations are. What are those attack paths, right, that the bad folks could get in? And how do you become preventative, right? And how do you become proactive in your security approach?
These are all the things that we've been preaching. And we do think some of these events are going to wake customers up to say, we just can't react and respond, like that is -- can't do it. The time is too precious and too quick, fast-moving right now. You need to be more preventive and you need to be more proactive. And that's some of the messages that we've been talking with our customers about. Yes.
Great. And how have attach rates been, particularly with Tenable One, but also newly-released Hexa, over the past like a month or so...
So Hexa, just to clarify, Hexa actually gets GA-ed tomorrow. So we're announcing tomorrow. But we had 30 to 40 customers that used in early access. And we'll be publishing some of their results, like they've -- we've got a bunch of good quotes and a bunch of good feedback, where you'll be hearing tomorrow and on Thursday at our Investor Day, our CTO and our Chief Product Officer will be talking and they'll be referencing some of the benefits that these customers have already seen leveraging Hexa, which, by the way, Anthropic is one of our strategic design partners. We are using Claude in Hexa. And we'll be announcing that relationship in more detail tomorrow also.
Great. And how important is it? I mean you talk about your relationship with Anthropic, and I think OpenAI's TAC initiative is a little more open.
Yes. Without a doubt. Yes.
But how different has the impact of each of those models been on your platform? And how critical do you think it is to have the visibility of each of those models...
Yes. I'll give you a quick example. And Matt has been super-involved in kind of negotiating and working with Anthropic on the deal that we did with them. But I'll just give you a quick anecdotal feedback.
So when we saw the benefit of Opus 4.6, we shifted and upgraded literally within 24 hours to have all of our developers start coding with Claude Code and 4.6, because we actually saw the benefit. And we literally within -- I think Eric Doerr, our CPO, will be talking about it. So these models are like quantum step-ups.
And so to have a design team that wants to be able to go, I think we're on Opus 4.2 or 4.3, and for him to then want to make move, that massive, aggressive move that quick and that fast, it shows you the speed that these frontier AI labs are moving at. And I think Eric actually will give reference to that on the Analyst Day on Thursday.
Yes, it's been really fun to see how these conversations have evolved over the past 4 or 5 months. If you think back to the beginning of the year when really the topic of conversation around AI was which companies are going to be disrupted and there was quite a bit of uncertainty, the sort of SaaSpocalypse that occurred. And then to think really the velocity in which these conversations have evolved, right? Our quarter ended on March 31. Mythos preview was announced on April 7, right? Our Q1 earnings announcement was April 29. And then here we sit today. These are conversations that are happening really, really fast, that are evolving quickly.
But what I think has been super-interesting to observe is how much I think people are getting it and how much things have changed from the beginning of the year to where they are now. And I think what folks are starting to realize is these very powerful models are quite capable at finding vulnerabilities, previously undiscovered vulnerabilities, in code. And that's amazing. It's an important -- and we expect there to be this explosion of vulnerabilities that exist. I think people really get that. They intuitively understand that.
They are also now increasingly intuitively understanding that that makes vulnerability management, and even more, exposure management, that much more important. Because the difficult part now is not in discovering vulnerabilities, right? Truth is that's never really what Tenable has done. Tenable has done an excellent job of looking at, okay, let's place the context of those vulnerabilities in your specific environment based on your asset types, based on your configurations. Let's give you that visibility. Let's give you the insight. And now we have Hexa AI that sits on top to help with orchestrated remediation.
Because that's really the trick, right? The trick is these CISOs are now overwhelmed with vulnerabilities that need to be patched. What Tenable One allows our customers to do is figure out which ones are most important to them, prioritize them, and then have some automated remediation to then go patch.
Yes. What percentage -- like anything you can reference or quantify, like the number of vulnerabilities kind of back to that noise-to-signal ratio, the number of vulnerabilities that actually need to be patched versus, all right, maybe you don't use a software anymore and you remediate it by deleting, or it's one that you don't have very high exposure to, you kind of cast it aside for a little bit, I mean, how is that profile really changing?
Yes. It's changing, but the numbers are massive. And you got to think through it also, it's -- the complexity of what the vulnerabilities are, let's just say, kind of at a lower level. What you now see with these AI frontier labs is they can actually chain together what used to be in the past considered very low-level, nonthreatening vulnerabilities.
A vulnerability in isolation, unless it's been identified as being compromised, is low-level risk. However, with some of these frontier AI models, when they can actually look at some of these older vulnerabilities and see 3 or 4 different older vulnerabilities and chain them together, that then gets them access into a network, be able to move laterally, be able to compromise excessive permissions that are on the network live, that is where the danger comes in. That's where this visibility factor really becomes even more important, right?
I mean in an old world, you typically see 2% to 3% of vulnerabilities that could be exploited. That number could go up significantly because now you can use these very sophisticated frontier AI models to be able to chain together what used to be perceived as individual, stand-alone vulnerabilities or nonthreatening vulnerabilities.
So that is where, again, right, not to bring it back to why all these things are kind of a net positive for Tenable, but they are a net positive because you need to have true visibility of what your asset types are. Where are these potential vulnerabilities? How do you prioritize them based on these, what we call, attack path analysis or toxic combinations? And be able to be preemptive and proactive instead of reactive, leading to a kind of a breach or a ransomware situation. So we actually view it as a net positive from what we're doing with Tenable One.
Got it. And maybe, Matt, if I could ask you, about 1/3 of the business on Tenable One now and you have, look, I think it's ranged from 70% to 80% pricing uplift once you get a customer migrating on a Tenable One.
Yes.
At what -- does that at some point become a headwind for growth? I mean how much growth is Tenable One accounted for? And now that you have a more material portion, you're obviously lapping that lift last year, how do you think about the contribution to your platform this year from incremental Tenable One business?
Yes. It's a perfect segue into some of the changes that we've made in pricing and packaging and also a preview in that we're going to talk in even more depth and detail about this on Thursday in our Investor Day.
But to give you a little bit of a preview, our new pricing and packaging has introduced Tenable One Foundation, which for us is really important, because as you said, there's about 1/3 of our business today is not on the platform. But we need an easy on-ramp for our non-platform customers to get into the platform. And that easy on-ramp is Tenable One Foundation. So we've created Tenable One Foundation. It's a modest price uplift to get from standalone VM into Tenable One Foundation.
But then the idea is there's 2 different paths for growth from there. You can expand your asset coverage, which of course we think is a really compelling offer for our customers to just get better with their preemptive security. But also they can upgrade from there to Tenable One Advanced, and that price increase ranges anywhere from 6% to go into Foundation, up to 60% to go up to Advanced. And then it grows beyond that when you factor in expansion.
So it's a really important part of our growth story. We continue to see favorable trends in that direction. So last quarter, 41% of new customers and new business was done in the platform. That's about an 8 percentage point growth from the prior year, and we continue to see that trend going forward.
Yes. The one thing I'll piggyback on that is when you look at -- we see that, when we look at the different selling motions, we see the 2/3 of our installed base, right, that's still on VM, right? And 1/3 is already migrated over to Tenable One. That 2/3 installed base, that is a phenomenal opportunity. That's where we see this massive migration opportunity to take those VM customers with the uplifts that Matt referenced into either Foundational or Advanced.
We are not allowing customers to run Hexa on VM installation and accounts. So if you're a VM customer, you can't run Hexa. We're only building Hexa into Tenable One.
So when I think customers that are sitting on VM and want to be able to have a forcing function to upgrade, there's all the other capabilities of looking at all the incremental assets and all the other things we do, the advanced capability, but to now have Hexa where you can have agentic AI agent automate a bunch of these manual processes and mundane tasks and automate the remediation and tagging and things like that, we think -- because there's not a lot in that VM base, they don't have a lot of cyber experts, right? One of the big issues with that lower-end VM-based is they don't have a huge cybersecurity team. So if we can automate a bunch of those things, we think more customers will end up migrating to T1, and it gives us a great opportunity in the 2/3 of the installed base that are still VM.
Got it. And then on the Hexa side, you've talked about consumption tiered model with tokenized access. How do you expect the uplift from Hexa will be like incremental to Tenable One for those customers?
Yes. I think the most important uplift actually comes from upgrading into the platform. So as Mark said, Hexa is only available in Tenable One. We know that there's an immediate price uplift from non-platform customers into the platform. And so that benefit, again, it ranges anywhere from a 6% uplift to a 60% uplift. Just that upgrade ends up paying for the sort of included tokens that all of our customers get depending on the level of assets they have.
From there, as customers begin to use Hexa and lean into it, and that's absolutely what we want, they start to bump up against those thresholds, then there's a per token charge that kicks in after that.
Okay. Got it. And then from a, I guess, competitive standpoint, how do you view -- or how often do you run into some of the larger platform players that are elbowing their way into like the VM market, like a CrowdStrike or a Palo Alto? And how meaningful is that?
Yes. So when you take a look at it, we do extremely well against all of our competitors, right? But if I break it down, you look at the Rapid7 and Qualys' compete levels, literally, coming out of the quarter, have never been higher. And they continue to be at record-setting numbers in regard to our compete level there.
And in regard to kind of the CrowdStrikes and Palo, we don't really ever see Palo Alto obviously in the VM space. We see them a bit in the Prisma Cloud space, competing against our CNAPP offering. So that's where we see that. CrowdStrike, obviously, we see in regard to exposure management. And our win rates are extremely high. We feel very confident about our compete level.
A couple of different data points. A, when you look at just not Tenable, the co-CEO of Tenable and the CFO saying our compete level is great, but you look at the analyst community, right, third-party analysts. So look at Gartner, IDC and Forrester, right? Gartner created for the first time ever a Gartner Magic Quadrant for Exposure Management, and we were #1. There were, I think, 51, 52 companies that applied. They put 20 to 25 in the quadrant, and then we became #1. We're also #1 in Forrester. We're also #1 in IDC.
So when we actually explain to customers the differences, the technical differences, so you do have to do some technical selling, right? You have to explain it. Because CrowdStrike a lot of the times will go in there with their flex pricing and try to give it away for free, and say, "Hey, use this. It's free." So you always got to be careful of what free is. You get what you pay for in life. And so you got to watch out for that.
But when we go in and say, well, let's actually break down the technology stack. Let's look at why vulnerability management is the cornerstone and the bedrock of how you want to evaluate exposure management and how you want to look at these multiple asset types. You want to come from it from a VM perspective. You don't want to come from -- exposure management from the endpoint or from a firewall or from a managed SIEM. You want to come from it from a VM.
So if you look at all of the teams, right, some of the larger enterprises that are changing the name of their security organization, the vulnerability team is now being called the exposure management team. It's the VM team. It's not the endpoint team or the SIEM team or the SOC team.
And so we feel extremely confident in our compete level. We do have to get into technical evaluations, and we break it down, and we have extremely high win rates. And we think when they are T1, it's unbelievably high win rates, right? So we want to -- again, another reason why we want to get that VM base on to T1.
Got it. And then on the pricing side, flex pricing, how has that been received by the channel partners? And maybe can you walk through some of the economics there? How does that actually work?
Sure. So in the past, we had a fairly confusing pricing model where customers, depending on the asset type, would have different ratios and, in effect, then different pricing per asset. And so customers would have to first determine what types of assets they were going to cover and in what quantities, and then they would get their kind of total cost of ownership there.
What we've done now is just drastically simplified that. What we've said instead is, look, we're going to have a single price per asset. We are going to then allow customers the flexibility to set a -- set capacity, but they can then mix and match across asset types, without having to go back through procurement and legal and get additional approvals. So not only does that reduce friction on the front end, because it's a much more understandable total cost of ownership, it also reduces friction when they're midway through their subscription and they decide maybe they got the initial allocation wrong or they would like to try out scanning a different asset type, it makes it so much easier, which we believe then encourages expansion.
So far, education with our sellers has gone very, very well. Education with the channel, gone very, very well. It's well received by customers as well. Still very early. But across the board has been net positive.
Great. And then how do you think about -- when should we expect to see maybe some impact of flex pricing on your model?
Yes. I think -- do you mean impact in terms of like when does it show up in the numbers?
Yes.
Yes. It's part of -- it's a great question. And it's part of what we're already kind of -- some of the good signs that we're already seeing, which is building momentum around our new and expansion business, for example. So what everybody wants to know is, look, when are we going to see growth inflect higher? The very first step in seeing growth inflect higher is, first of all, stopping the decel. But that starts with growing new and expansion business. And that's what we're seeing now. So we're already beginning to see the early signs, and that's showing up. And ideally, that makes its way, of course, to increased bookings numbers and then ultimately to revenue.
That's a good segue into the next question, which is second half revenue guide implies about 6.5% growth. You guys delivered, what, 9.6% growth in Q1. So how do we put that in context? Are you feeling more bullish...
This is like the outperformance gift that keeps on giving, which is great.
So when we started the year, this is funny, we guided the year to 7% growth at the midpoint, and that was our initial full year guide. And what that meant was -- and we guided Q1 at 8.1%. And so now math just dictates that you know if you're guiding to 8.1% in Q1 and your full year guide is at 7%, the rest of the year is going to be something sub-7%, call it 6.5%.
Q1 comes along and we have a fantastic quarter and we deliver above 9% growth for the quarter. And now -- and then the question we get is, well, why the decel? And so I have to laugh because the decel was always there, right?
The takeaway from the quarter is, look, as opposed to in the years past when we've maybe had a Q1 and then had to reset guidance downward on the year, it's quite the contrary this year. This year we had a really good Q1 and we took guidance up. So yes, mathematically, there's a decel. But the way to think about it actually is that we're 1/4 of the way through the year, we're incrementally more positive for the full year, which is what allowed us to raise the full year guide. And yes, mathematically, that implies a decel, but that's no change to how we started the year. Net-net, we're better off today than we were at the beginning of the year.
Got it. And then, Mark, you mentioned your cloud, CNAPP business. How big is Ermetic now? And is it -- are you -- do you think that it could be a substantial contributor to the platform?
Yes. Absolutely.
And kind of would love to see how that kind of fits in your growth profile.
Yes. So it's definitely, when you look at asset types, it's one of the larger asset types within Tenable One. I think the shift that we've seen in the cloud business is the bulk of the business that we're now doing for CNAPP is part of Tenable One platform. So you're not seeing -- in the early days of CNAPP, you'd see a lot of customers do a stand-alone deal and buy CNAPP as stand-alone. You're not seeing many stand-alone deals.
What we're seeing in the market is a chance, and we are seeing this with Wiz now that they're owned by Google, you're seeing this disruptive motion where they're using Tenable One. They've been a Tenable One customer. They love Wiz. Wiz is a great product and great technology. But they now see it as part of Google. And you could be a big AWS shop or a big Azure shop, and you're not sure if you really trust what the road map is going to be in regard to where Wiz is going to go. And now they're going to have to take them off the AWS platform, re-platform the GCP. How does that work? How the sharing of road maps and technology work with AWS and Azure now they're a part of Google. And Wiz historically is extremely expensive, right, one of the most expensive cyber technologies in the cybersecurity stack.
So where we're starting to see some momentum is part of Tenable One, not stand-alone, but as part of Tenable One, you're seeing these opportunities to go into some of these Wiz shops and say, "Hey, you're already using Tenable. You're already using the platform. You're spending an incredible amount of money with Wiz. Let's be able to move you on to the platform for cloud security and migrate you off Wiz." And so you're starting to see that selling motion.
And so we view cloud and CNAPP, as part of T1, to be a significant differentiator. Especially when you look at our historical competitors, it really isn't even close to the capability we have compared to, say, a Wiz -- or no, sorry, compared to like a Rapid7 or a Qualys or even a Crowd.
So yes, we view it as a big competitive differentiator and we view it as a space that still has lots of growth, lots of leg room and a competitive dynamic that's being shaken up a little bit by Wiz now being part of Google.
Yes. I mean on that point too, obviously, that was one of the biggest questions that came up when Google announced they're acquiring Wiz, is if they're built on AWS, so will...
Billion-dollar customer, right? I mean one of the biggest. Yes.
So any indication of like -- that you're seeing on your side? Is there going to be a change there? Or is it something the customers are worried about?
I can't comment -- I mean, listen, anecdotally, customer conversations, they're concerned about it. I can't give you any Inside Baseball on what discussions have happened between Amazon and Google. I have no idea. But customers are concerned, especially if you're a true-blue AWS shop and you knew that A-dub and Wiz had a very tight relationship, right? Road maps would be shared 12 months previously, there was a lot of co-design and co-development with AWS. And so if you're an AWS customer, now you have a Wiz rep show up with a Google rep to talk about GCP, along with Wiz, I think there'll be some concern there.
But we stay in our lane. We focus on what we can control. And we focus on selling and positioning Tenable One, the platform. And if customers see an opportunity to simplify their cybersecurity stack and are able to remove and consolidate a CNAPP product into a platform like Tenable One, we'll work with customers all day long in those opportunities.
Got it. I think we've got a couple of minutes. I just want to reach out to the audience to see if there's any questions from the audience?
Okay. We'll follow up on this. I wanted to ask Matt about, or you, Mark, about things on the hiring front, particularly on the sales rep side. How have hiring trends been over the past few quarters? And then what's your outlook for near-term hiring on the sales rep side?
Yes. You want me to...
Yes, go ahead and I'll follow up.
And you follow up. So super fast. When we came into the year, we added quota capacity to the field. And we've seen that pay off, right? So we feel really good about where we are at. We've seen productivity levels increase.
We have deployed a lot of automation and AI technology to improve the amount of face time our sellers get with customers, meaning we've drastically reduced the time to create quotes and configurations, drastically reduced the time they have to spend with -- inside Salesforce.com, right? A lot of these things have been productivity enhancements.
When we see certain regions, like, say, for instance, the Middle East, that's seeing a spike where we might need some resources, we will add quota capacity. But right now, we are in a really, really good spot in regard to our sales rep coverage and productivity. And I'll let Matt comment on the rest of the business.
Yes. One of the things I'm probably most proud of is our ability to hire in high-impact areas, in particular, in sales capacity and in some of our engineering areas, where we're really leaning into the investment -- into the growth opportunity we see. So we're investing heavily there. But at the same time, what we're able to do is, through AI implementation, automation, we're able to reduce in other areas and pull back.
So what you'll end up seeing is from a net headcount perspective, you're going to end up seeing a headcount that is flat to down-ish actually for the whole company, while at the same time hiring into those high-impact areas and getting a little bit of leverage from -- in the form of margin growth on all of the OpEx lines. So we're managing it really well.
How much has sales headcount growth been?
So sales capacity growth, or are you talking about sales in total?
Headcount, like the total number of people.
Yes. We don't disclose that.
Yes.
Yes. But sales capacity is up 10% from what it was a year ago.
Got you. Is that -- and capacity is measured how though?
Quota-carrying sales reps.
So productive quota-carrying sales reps or just total?
No. Productive.
Yes. Productive. Yes.
Okay. With that, I think we're out of time. So Mark, Matt, thank you so much.
Thank you, Brian.
Take care.
Yes. Cheers.
Tenable Holdings, Inc. — J.P. Morgan 54th Annual Global Technology
Tenable says AI-driven vulnerability discovery is accelerating demand for its Tenable One platform and Hexa autonomous remediation, with Anthropic partnership fueling product momentum.
🎯 Key Message
- Central point: Frontier AI (e.g., Mythos) is surfacing far more vulnerabilities, driving customers to prioritize exposure management over legacy vulnerability scanning.
- Positioning: Tenable is pitching Tenable One (its unified exposure-management platform) plus Hexa (an agentic AI automation layer) as the solution to prioritize and remediate at scale.
- Market read: Strong top-of-funnel engagement, more CISO-level interactions, and a clear migration opportunity from legacy vulnerability management.
⚡ Strategic Highlights
- Hexa GA: Hexa (agentic AI for autonomous remediation and workflow automation) goes GA tomorrow; 30–40 early-access customers showed time-to-remediate improvements and quotes will be published.
- Pricing & packaging: Introduced Tenable One Foundation as a lower-cost on‑ramp from standalone vulnerability management; single-price-per-asset flex pricing simplifies procurement and encourages expansion.
- GTM & scale: ~1/3 of revenue already on Tenable One; 2/3 remain on legacy VM (vulnerability management) representing a sizable migration and upsell opportunity; sales quota-carrying capacity up ~10% year-over-year.
🆕 New Information
- Product news: Hexa GA and a more-detailed Anthropic partnership (using Claude) to be announced at Tenable's Exposure Management Conference and Investor Day.
- Commercials: Previewed Tenable One Foundation pricing and clarified tokenized Hexa consumption (included tokens with per-token overage).
- Financials: No new quarterly guidance metrics announced beyond the prior full-year raise and the second-half growth math discussed.
❓ Analyst Q&A
- Demand pipeline: Management described thousands of customer conversations post-Mythos, stronger CISO engagement, and an expanding sales funnel from demos to proofs-of-value.
- Remediation gap: Hexa's promise to automate tagging, patching and remediation was probed; management cited customer anecdotes of compressing weeks/months to days/seconds but broad metrics are still early.
- Competitive/CNAPP dynamics: Asked about competitors (CrowdStrike, Palo Alto, Wiz/Google) — Tenable points to high win rates, #1 positions in analyst reports, and CNAPP as a platform differentiator vs. point solutions.
⚡ Bottom Line
- Investor take: Tenable is leaning into an obvious market tailwind—AI-driven vulnerability discovery—and monetizing via platform migration (Tenable One), new pricing tiers, and Hexa consumption. Execution risks include speed of customer migrations, uncertain token consumption, and an evolving competitive CNAPP landscape, but management reports clear early traction and pipeline momentum.
Tenable Holdings, Inc. — Q1 2026 Earnings Call
1. Management Discussion
Greetings, and welcome to the Tenable First Quarter 2026 Earnings Conference Call. [Operator Instructions] As a reminder, this conference is being recorded.
It is now my pleasure to introduce your host, Erin Karney, Vice President, Investor Relations. Thank you. You may begin.
Thank you, operator, and thank you all for joining us on today's conference call to discuss Tenable's First Quarter and Full Year 2026 Financial Results.
With me on the call today are Co-Chief Executive Officer, Steve Vintz and Mark Thurmond, and Chief Financial Officer, Matt Brown. Prior to this call, we issued a press release announcing our financial results for the quarter. You can find the press release on our IR website at tenable.com.
We will make forward-looking statements during the course of this call, including statements relating to our guidance and expectations for the second quarter and full year 2026, growth and drivers in our business, changes in the threat landscape in the security industry, particularly regarding AI security, the expected impact of Frontier AI models like Anthropic Mythos, on accelerated vulnerability discovery and the shift to preemptive security, our competitive position in the market, growth in customer demand for and adoption of our solutions, including Tenable One, our exposure management platform, the expansion of Tenable One, including agentic AI security and orchestration through HEXA AI and OT discovery, research and development investments in Tenable One and our future results of operations and financial position.
These forward-looking statements involve risks and uncertainties, some of which are beyond our control, which could cause actual results to differ materially from those anticipated by these statements. You should not rely upon forward-looking statements as a prediction of future events. Forward-looking statements represent our beliefs and assumptions only as of today and should not be considered representative of our views as of any subsequent date and we disclaim any obligation to update any forward-looking statements or outlook.
For a further discussion of the material risks and other important factors that could affect our actual results, please refer to those contained in our most recent annual report on Form 10-K and subsequent reports that we file with the SEC.
In addition, all of the financial results we will discuss today are non-GAAP financial measures with the exception of revenue. These non-GAAP financial measures are in addition to and not a substitute for or superior to, measures of financial performance prepared in accordance with GAAP. There are a number of limitations related to the use of these non-GAAP financial measures versus their closest GAAP equivalents. Our press release includes GAAP to non-GAAP reconciliations for these measures.
I'll now turn the call over to Steve.
Thanks, Erin. In Q1, we exceeded all of our guided metrics, with 10% year-over-year revenue growth and 24% operating margin. Tenable One, our AI-powered exposure management platform was 41% of new business this quarter, an 8-point increase from Q1 last year. In addition, we added 406 new enterprise platform customers and 43 net new 6-figure customers. New customer adds and large deals with Tenable One continue to underscore our strong financial performance and balanced growth approach. The rapid advancement of Frontier AI models is having a profound impact on cybersecurity and there is understandably a lot of noise in the market.
Recent announcements, including Anthropic Mythos, have demonstrated that AI can now autonomously discover software vulnerabilities at scale and speed we have not seen before. As a result, the #1 question we are getting from investors is, what does this mean for the future of cybersecurity and what does it mean for Tenable in particular?
To start, as part of our ongoing research and development efforts, we are actively engaging with leading frontier AI model providers, including Anthropic to better understand these investments and help customers prepare for what's next in the cybersecurity industry. This is top of mind for customers as we've seen a significant increase in inbound inquiry from our customers over the past couple of weeks, which Mark will cover later on the call. Our view is this. AI models are incredibly proficient at discovering previously unknown vulnerabilities. Number two, AI is also changing low-risk evolve and software quickly and at scale. And third, -- and finally, these 2 things will lead to a proliferation of new vulnerabilities and attack paths in customers' environments, overloading operational workloads for defenders.
On that note, let me be precise about where these models operate and where we operate because the distinction matters here, frontier models like Mythos, read and reason about source code. They find vulnerabilities such as logic flaws, injection weaknesses and authentication bypasses by tracing data flows through a codebase. That is application security research at the source code layer. It is genuinely impressive, and it is 1 stage of a much longer life cycle for managing risk. Tenable operates on the other stages of that life cycle. The ones that determine whether a vulnerability actually creates risk in a real customer environment. Specifically, customers need to understand their entire digital footprint and then assesses for critical exposures.
Exposures are much broader than vulnerabilities. They include overprivileged access, misconfigurations, ScatoAI and the real-world impact of vulnerabilities as they exist in our customers' environment. From their Tenable works across all of these signals to prioritize and identify the likely and most critical path of exploit by threat actors. So let me put this in pragmatic terms. There will be a window where adversaries hold a clear advantage in the AI era because we will see more exploits due to a Tsunami of new vulnerabilities. That's exactly why the urgency for exposure management has never been higher.
Organizations need to understand what exposures exist and which ones create real, immediate risk in their environment, and then ensure those risks are remediated and verified. That is exactly what Tenable One is designed to deliver. For over 2 decades, we have built 1 of the industry's most comprehensive and proprietary data sets across IT, cloud, OT, which we have also expanded to AI infrastructure and apps and third-party data to solve the hardest problems in cybersecurity. Tenable One leverages this expansive data set of exposure intelligence to unify visibility across assets, vulnerabilities, identities and misconfigurations, then applies business context and drives prioritized remediation across the environment.
And that brings me to Tenable Hexa,AI, our new Agentic engine. -- which we announced in Q1. Hexa is designed to take the prioritized exposures we identified, primarily in runtime infrastructure and turn them into a coordinated action. It operates as an orchestration layer across the security ecosystem, automating triage and executing multi-step remediation workflows across a wide range of domains. Where Tenable One serves as the system of record for risk management, at its core Hexa serves as a system of action for proactive risk reduction, coordinating work across humans and agents autonomously. It determines what matters most in the broader security context and drives the steps required to reduce exposure. This is a critical shift.
Security teams today are not just dealing with more vulnerabilities. They are managing fragmented workloads across tools, teams and systems. Hexa brings all of that together, transforming exposure intelligence into coordinated execution at scale. Hexa is built to execute automating complex tasks and orchestrate the right fixes across the enterprise before exposures are exploited. The result is a move from reactive response where you wait for vulnerabilities to come to consistent machine speed risk reduction, enabling defenders to operate with the speed and precision required in an AI-driven threat landscape.
Now with that said, we are also continuing to broaden our capabilities across asset types. We recently announced OT discovery to secure cyberphysical systems. These systems have historically required time-consuming deployments of specialized hardware, new agents and bolt-on software to gain visibility. We've eliminated this friction by integrating OT discovery directly into our core solution inside the Tenable One platform. This is particularly important as the number of OT devices explode with AI data centers and build-outs.
And finally, before I turn the call over to Mark, I want to remind everyone, we will be hosting an Investor Day as part of our exposure 2026 Industry Conference. Investor Day will take place the afternoon of May 21 in Boston. We hope to see you there.
With that, I'll turn the call over to Mark to walk through what we are seeing with our customers.
Thanks, Steve. As Steve outlined, the cyber landscape is shifting at an unprecedented pace and the conversations we are having with customers and partners reflect that shift. We are seeing a level of urgency that is different from even a month ago not just at the practitioner level but across the C-suite and the Board. Initiatives like OpenAI's TAC program and Anthropic Mythos have triggered a surge of inbound strategic customer conversations as organizations work to understand how to prepare for a world where vulnerabilities are discovered and exploited at machine speed. And the concerns we are hearing are consistent. First, customers are preparing for a massive increase in the volume of discovered vulnerabilities. They're concerned about the real possibility that AI models like mythos, can potentially change multiple flaws into full system compromise. Second, they are realizing that their current remediation process will not scale to meet this new reality.
A recurring theme from the hundreds of customer conversations we've had since these announcements is that our customers now see an increased urgency to prioritize and remediate exposures. Importantly, this is not just our perspective. Industry leaders in cybersecurity experts have been aggressively validating these points. For example, JPMorgan Chase published a blog that highlighted that AI is compressing the time from vulnerability discovery to exploitation, while patch cycles are often exceeding organization's capacity. They also recommended that organizations need to focus effort where risk is highest rather than chasing volume indiscriminately. Additionally, a highly respected cybersecurity consulting firm recently noted that in an AI-driven world, sustainable advantage will belong to companies that own differentiated data and are embedded in mission-critical workflows. They also highlighted a shift from software that helps users do work to platforms that automate and execute that work directly.
As Steve discussed earlier, this is where we believe Tenable is uniquely positioned. Our differentiation is rooted in 4 main pillars. First, our unmatched breadth of telemetry combining native and third-party signals across the modern attack surface. Second, our proprietary exposure data fabric, which transforms fragmented signals into authoritive context. Third, our market-leading research and exposure intelligence, which continuously enriches and prioritizes the exposures that matter most. And fourth, Tenable Hexa AI within our platform, which is designed to help automate prioritization and remediation workflows to drive action at scale.
Taken together, these advantages help position Tenable to lead as the market shifts towards exposure management. We believe this creates a meaningful tailwind for Tenable. As organizations adapt to this new environment, we see evidence that many organizations are recognizing that traditional silo tools are no longer sufficient and that consolidating onto a platform that provides unified visibility, contextual prioritization and increasingly automated remediation is even more essential. We saw that play out in the quarter in several ways. First, our largest new logo of the quarter for Tenable One was a 7-figure transaction with a major financial institution in the Middle East.
In this case, the customer displaced an incumbent competitor and chose Tenable ones because they needed a more unified approach to understanding and prioritizing exposures across a large and complex environment. Second, we secured a new 6-figure Tenable One deal driven by the need to secure the company's use of AI. This organization is proactively investing to prepare for the wave of AI-driven threats and vulnerabilities that we've been discussing and to ensure they can identify and remediate AI risk faster. And third, we closed a significant 6-figure OT deal with a large public sector organization responsible for critical infrastructure.
As AI accelerates vulnerability discovery and exploitation we are seeing more organizations focused on securing operational environments where the consequences of disruption extend well beyond IT. These wins reinforce what we see as a broader market shift. Customers are moving away from tools that create more noise and toward exposure management platforms that provide context, prioritization and automated action. This is a key area of differentiation for Tenable One. Our current momentum reinforces our conviction that our strategy is aligned to where the market is going with Tenable One and HEXA AI at the forefront of this shift towards exposure management and automated action.
And finally, this week, we announced an important step forward in how customers buy and adopt Tenable One with new flexible pricing and packaging. As AI drives an explosion and vulnerability discovery and increases the urgency to prioritize and remediate exposures at scale, customers are looking for platforms that can deliver value quickly without adding complexity to procurement or budgeting. Our new Flex model continues to price per asset. However, pricing will be consistent across all asset types, which creates predictable spend and removes frictions as customers scale their exposure management program across their entire attack surface.
Ultimately, we believe this new flex pricing will help us reach more customers, accelerate adoptions and create a clear path to broader platform deployments over time.
With that, I'll turn the call over to Matt to discuss our financial results.
Thanks, Mark. Q1 was another quarter of very strong and steady execution. Revenue increased year-over-year by nearly 10% and even more impressive, we converted more than half of that increase into operating income, once again demonstrating our ability to balance growth and profitability. We were pleased to have exceeded the high end of the range on every metric we guided to for the quarter and are raising our full year outlook.
Let's dive into the details. Revenue for the quarter was $262.1 million, representing growth of 9.6% year-over-year. The year-over-year growth in revenue for the quarter as well as outperformance relative to guidance was underpinned by a solid foundation of renewal business and an increase in new business growth. Professional services also drove upside to expectations. Our percentage of recurring revenue remained high at 96% for the quarter. We're continuing to see growing momentum in Tenable One with 41% of new business coming from the platform, an increase from Q1 in the prior year. Customers are increasingly turning to our platform as their solution of choice to manage risk across their attack surface, including AI.
We added 406 new enterprise customers in the quarter, an increase of 12.5% compared to Q1 in the prior year, many of which came directly into Tenable One. We added 43 net new 6-figure deals and our net dollar expansion rate landed at 105%. Non-GAAP gross margin was 82.2% for the quarter, an increase from 81.9% in Q1 2025. Once again, we've demonstrated our ability to slowly but steadily increase non-GAAP gross margin year-over-year, while sales within the Tenable One platform continue to represent a larger share of the total.
Non-GAAP income from operations for the quarter was $61.9 million, or 23.6% of revenue compared to $48.7 million in Q1 2025, an increase of 27.1%. We are beginning to see the first signs of AI-driven operational efficiencies. As our internal use of AI capabilities expands, we're able to minimize headcount growth due to the increased productivity the technology is offering, which is a trend we expect to continue throughout the year. Non-GAAP earnings per share for the quarter was $0.47 compared to $0.36 in Q1 2025, an increase of 30.6%. The increase year-over-year reflects the increase in profitability combined with the decrease in diluted shares outstanding.
Turning to the balance sheet. Cash and short-term investments totaled $360.3 million. We generated $88.6 million of unlevered free cash flow during the quarter, which is an all-time record and represents 33.8% of revenue. During the first quarter, we repurchased 6.1 million shares for $130 million and have $207.6 million remaining on our current share repurchase authorization as of the end of the quarter. We continue to believe that our current share price trades at a discount relative to our true value and that utilizing our strong balance sheet and cash flow generation, to more aggressively repurchase shares is an effective use of capital. We are realizing the benefit of these share repurchases and as our weighted average diluted shares outstanding in Q1 decreased 5% year-over-year and is now the lowest it has been in more than 3 years.
Turning to the financial outlook for Q2 and full year 2026. For Q2, we expect revenue to be in the range of $263 million to $266 million, representing a year-over-year increase of 7.0% at the midpoint. For full year 2026, we are raising our guidance range to $1.068 billion to $1.078 billion, representing a year-over-year increase of 7.4% at the midpoint. We expect non-GAAP income from operations for Q2 and to be in the range of $61 million to $64 million or 23.6% of revenue at the midpoint. For full year 2026, we are raising our guidance range for non-GAAP operating income to $252 million to $262 million or 24.0% of revenue at the midpoint representing a year-over-year increase of 210 basis points. We expect non-GAAP net income for Q2 to be in the range of $53 million to $56 million representing a year-over-year increase of 31.5% at the midpoint. For full year 2026, we are raising our guidance range for non-GAAP net income to $222 million to $232 million, representing a year-over-year increase of 16.8% at the midpoint.
We expect non-GAAP earnings per share for Q2 to be in the range of $0.46 to $0.48 per share, representing a year-over-year increase of 38.2% at the midpoint. For full year 2026, we are raising our guidance range for non-GAAP earnings per share to $1.90 to $1.98 per share representing a year-over-year increase of 22.0% at the midpoint.
We are pleased to have been able to carry forward the momentum we saw in the second half of 2025 and into the first quarter and are excited about the growing opportunity we are seeing as customers lean into exposure management to reduce risk. Demand continues to be driven by Tenable One where we see tremendous benefits both for our customers and as a foundation to continue to drive balanced growth. We hope to see you all at Investor Day on May 21 in Boston, where we will provide even more context around the impact of AI, our road map and midterm financial expectations.
Finally, thank you to the entire Tenable team for their contribution to our strong results. With that, we are happy to open the call up for questions. Operator?
[Operator Instructions] Our first question comes from Saket Kalia with Barclays.
2. Question Answer
Okay. Great. I'll keep it to one. Steve and Mark, it's clear that the newly discovered vulnerabilities through Mythos are driving more interest and exposure management. I think that shows in a lot of your commentary. But I want to zoom out from some of your prepared remarks. I guess I'm curious how you think about frontier models longer term in the exposure management space? And maybe specifically, do you think customers are going to look to these models as alternatives to VM tools? Or do they actually heighten awareness on exposure management tools. And therefore, this is maybe more of a complement to the industry long term? Sorry, I know there's a lot there, but does that make sense?
Yes, Saket. This is Steve. I'll take a stab at this. First and foremost, AI is a massive opportunity for Tenable. I want to be very clear about that. Mark and I cannot be more excited, more energized about the opportunity that's in front of us. We are and will partner with the frontier model companies [indiscernible] our customers reduce risk at machine speed. It is not AI versus security or AI versus Tenable. It is AI enables tenable in the AI era, it's going to be more infrastructure, more identities, more applications, more agents and therefore, more speed and more exposures and that's why exposure management is more important now than ever. And so the frontier model companies make us better.
It starts with our data. It's something I talked about earlier in the call, the breadth and depth of the data we've collected over 2-plus decades is unparallel. We're deeply embedded behind the garden wall and onetime infrastructure. The data we collect is unique, it's based on domain expertise, years of trust, continuous scanning and exposure analysis. This is something that general models can't replicate. And at its core, the frontier model companies are raising engines. They're not in the business that deploying agents and sensors in your network, and they're not in the business of deploying those in your OT and industrial control systems environment or audience fakes and scanning images in a public cloud environment, but we are. And that's something that we want to make clear. And the last comment I'll say here is that we're applying AI. AI makes us better, allows us to reimagine the value that we can deliver to customers and the bigger problem that we can solve.
The data we have delivers valuable insights to the customer so they can take action deterministically to reduce risk. And from that AI at the center of what we do to not only augment human operators but also gives us the critical context to develop a deeper understanding of exposure. So we can help our customers provide and orchestrate the fixes and move that machine speed and move at the speed of trust.
Yes. And listen, I'll just add from the field perspective, literally, having hundreds of calls here over the last few weeks. This is a force multiplier for us. The amount of feedback we're getting from our customers, this is a massive opportunity. This is like a game-changing opportunity for us in the exposure management space. And as Steve discussed, it needs to be very clear. We are partnering with anthropic. And we are partnering with Open AI. We are building Claude into Hexa, right? So when you look at this partnership, it is just going to strengthen Tenable and Tenable one, and it will drive more demand, right? There is no question about that, and we're kind of seeing that in these initial conversations. And then when you take what the Frontier labs are doing and then building out and continuing to drive our innovation with Tenable One focused on the entire attack surface, focused on world-class pinpoint prioritization, because now when you're dealing with thousands or hundreds of thousands of vulnerabilities, you need to be damn accurate where you need to apply your resources and prioritization has never ever been more important in one of the massive gold standards we have here at Tenable.
You take a lot of reporting, the governance, the compliance needs you need when you get this massive tsunami of vulns coming in. the agent workflows we're now doing with Hexa, the remediation capability going into OT environments. So it's a bit long winded, but we've been dealing with this for the last few weeks with customers and I'm telling you, we feel unbelievably optimistic that this is going to be a force multiplier for the exposure management category moving forward.
That's super helpful, guys. And look forward to the Analyst Day.
Our next question comes from Brian Essex with JPMorgan.
Steve, a question for you. We're hearing a lot about security software getting access to budgets outside of traditional IT security budgets, particularly as business unit leaders slap AI on top of their budgets and get more allocation. And I think you guys alluded to it a bit last quarter. We heard it from Varonis last night, but I was wondering if you could update us to your conversations and what you're seeing, maybe the puts and takes involved? Are you getting meaningful incremental budget in -- is this a tailwind to close rates? Or are the additional stakeholders extending sales cycles. We just love just a little bit more color on that.
Sure. I think a couple of things here. Certainly, with Mythos and other frontier model companies. We have to acknowledge the [indiscernible] just got an upgrade. And I think we all know that, but our customers know that I think Boards and CEOs also realize that outside of the security community. And so consequently, it needs more vulnerabilities, more that, more exploits -- and so there's a window here where adversaries hold an early advantage, and that's exactly why the urgency around exposure management has never been higher.
I will tell you this, the threat of -- in the impending Tsunami of new vulnerabilities. We're talking about order of magnitude of 10 or 20x more than what we currently have today, there's roughly 300,000 CBEs. We're like we see $3 million, maybe $6 million over the course of time, an increase in the own caps. I think people realize that the threat is real. This is a security challenge. The Boards and CEOs are getting involved, number one. Number two, we will likely see -- this is not tied to guidance or anything like that, that we're providing today, but we will likely see sizable increases in security budgets. We'll likely see a healthy spending environment. We will likely see the acceleration of security projects, not only in the private sector but also in the public sector, we're having regular and ongoing conversations with the OMCD the Office of the National Cyber Security Director. They arguably have the best intel on entropic and some of the other frontier model companies. I think they realize what's potentially coming our way and they're moving quickly. So I think all of this creates incredible opportunity for us in exposure management. And yes, I think it's fair to say, Mark can provide more perspective here. factoring into every sales conversation.
Yes, no question. -- we highlighted it on 1 of the deals that we discussed, right? There is definitely spend, and I'll call it, there is security AI spend that is becoming clean, and you can see it when you're talking to but there's also discretionary spend, right? We saw a bunch of deals, right, where we're working with the security contacts that we have where they would then -- when we start talking about especially AI exposure, looking at discovering shadow AI looking at protecting and configurations, best practices for AI-related deployments in the cloud, governing. There was budget that they pulled in to add on to these Tenable One deals. So I think that will become more mainstream over time. It won't be so much discretionary. It will be built in and moved into the cybersecurity budget. But there's no question, as Steve said, it's every single call starts off with the AI security discussion. It's that omnipresent.
Great. That's helpful color. And Mark, I'm sure our CISO appreciates you flagging his blog, thank you on his behalf.
Very, very, very well done blocked by the way. A lot of people download phenomenal information there.
Okay. Our next question comes from Rob Owens with Piper Sandler. Rob Owens with Piper Sandler.
I apologize. I had the mute on. I think I've learned after all this time. Mark See, very bullish comments from both of you. And clearly, this could be a watershed moment for the industry overall. But I wanted to pivot a little bit towards sales capacity. And noting sales and marketing growing less than 5% year-over-year this quarter. Maybe help us understand where you guys are from a capacity standpoint as this opportunity is in front of you right now? And what are your intentions with the new CRO in place to maybe lean in a little bit in terms of that sales and marketing line as we move forward? Because I think investors would prefer point of growth over point of margin at this point in your life cycle.
Yes. No. Awesome question. And yes, no question. And as we discussed numerous times, we are laser-focused on growth, right? The number one factor here at Tenable is getting growth accelerated. Yes, super excited to have a new CRO, Dino DiMarino, who joined Tenable, our COO, Dave Feringa had retired. We did an incredible job here at Tenable, but Dino is phenomenal and has been here for a short time period, but already making an impact. And when we look at sales capacity, it's something literally we look at on a weekly basis. We made some decisions coming into 2026 to add some incremental capacity, and we're actually seeing that pay off, which is great. We are evaluating some of the faster-growing regions and countries to look at adding additional sales capacity, especially when we start seeing some of the pipeline growth and we see some of the Tenable One activity in some of these faster-growing regions. So it is something we are absolutely evaluating. We also, though, are spending a huge amount of time on productivity per seller. So we're using a bunch of AI technology to get more efficiency out of our sellers. So our sellers can produce more at a lower cost, taking away a massive amount of manual processes and tasks that slowed them down that took away from customer-facing time. We're removing those obstacles, and we're literally returning a significant amount of time back where our sellers are in front of more customers and partners on a daily basis.
So we are all over it. We're evaluating it. We made that move to add some capacity, and we're going to continue to tweak that as we see kind of the productivity improve, and we see pipeline build continue to grow.
Yes. And Rob, this is Matt. I'll just add on what Mark was saying there. You heard in some of my prepared remarks, I called out our use of AI beginning to see the impact on the efficiency we gain in there. That's exactly what Mark is talking about there, where we're able to actually increase sales capacity and quota capacity while reducing costs overall because we're rotating those dollars out of other non-quota carrying areas and that's helping. We're able to do that through the use of some AI technology.
Our next question comes from Adam Borg with Stifel.
Great. Maybe just building off the last question around some of the operational efficiencies, Matt. Maybe a follow-up is, as you continue to introduce Hexa and introduce more AI into the offering? And maybe we'll hear a lot more about this at the Analyst Day in a month. But how do we think about the flip side to the efficiencies with higher spend and the impact that could have on gross margin?
Sure. Yes. As you know, cloud costs are 1 of our largest expenditures and it's something that we focus quite a bit on optimizing. But the truth is today, we get a better trade in leaning into AI spend and compute power. There's a bigger payoff there on the extra efficiency capacity that we're able to gain. As you look in total at our P&L, that model that I laid out in terms of adding incremental margin. I think I've said this over the past couple of quarters and it holds true today. where that's going to show up is mostly in G&A, a little bit in sales and marketing, tiny bit in gross margin. And then R&D is probably going to be roughly consistent as a percentage of revenue. And we're doing that through making sure that we're optimizing our cloud costs for sure, and that gross margin remained strong, but also just optimizing some of the tools that we have at our disposal now, which is really powerful.
Our next question comes from Mike Cikos with Needham & Co.
Congrats on a strong start to the year. I just wanted to come back to the -- I know CCB is a weaker indicator here, but we've been looking obviously at the CCB versus the CRPO and that delta that's widened in recent quarters. It seemed to converge this quarter. And I just wanted to get a better sense of how CCB/CRPO played out in Q1. Should we expect this convergence to play out? Or no, we should expect a widening now over the rest of the year? Any color that would be beneficial?
Yes. I -- yes, you're going to continue to see some fluctuation there in the delta between CCB and CRPO will likely bounce around a bit because number one, seasonality plays a role. And number two, we're continuing to work through and anniversary some of the noise that we saw in both billings duration and contract duration. So it was -- it narrowed this quarter. It will likely widen again next quarter. There's not much to read into there, actually.
Having said all of that, we're happy with where our billings came in our commitment in this quarter, which gave us the confidence to not only beat revenue for the quarter, but then to take up the guidance for the full year. So we're happy with where things are coming in.
Our next question comes from Meta Marshall with Morgan Stanley.
Maybe just coming back to the influx of business that you guys are seeing for Tenable One and exposure management, just driven by the AI risk headlines customers are seeing. Do you think that they have enough knowledge of what the customers have enough knowledge of what they need or what the potential weaknesses are to speed up decision-making processes? Or are they still -- are some of these sales cycles potentially longer just as they try to evaluate kind of what the changes to the environment are? Just any reflection on sales cycle.
Yes. No, no, so. Very, very good question. A couple of points there. We are still doing a lot of education. As we hit on in the beginning of this call, we've taken hundreds of calls over the last few weeks with customers literally asking for our advice, giving them guidance getting on the phone and Zoom sessions with our CSO and getting guidance and leadership from that perspective. Just to put a small example, we're actually doing a webinar in 24 hours in regards to doing some education around the Frontier AI models, and we have over 1,000 people registered. It's 1 of the fastest thousand-person webinars we generated since the last 12 to 13 months. So incredible amount of evangelizing and education. We are sensing now that people are getting it. Like these conversations are going from less of an enablement and education saying, okay, let's come in here, let's talk about exposure management. Let's talk about Tenable One. What would be the deployment strategy, how do we get full visibility across the entire tax surface and then digging in on some of the relationships and partnerships that we've got with enthropic and open AI and building some of that capability in the product. So there's still some evangelizing indication, but customers are definitely getting smarter. And as I said before, right, we see it as a tailwind here in 2026.
Our next question comes from Jonathan Ruykhaver with Cantor Fitzgerald.
Yes. Nice execution. So I'm just curious if you could comment on the platform expansion opportunity relative to new adds. You did see a nice uptick in 6-figure customers sequentially. So how should we be thinking of that platform of customer growth versus expansion? It does seem like there's a nice opportunity as well to drive are incrementally higher as we move through the year. So how are you looking to balance those 2 growth drivers?
This is Steve, Jonathan. I would say, look, in any given quarter, there's always some variability between expansion opportunities and pipeline opportunities for new customers this quarter. The number of new customers was extraordinarily strong. It's 400-plus as 1 of our strong quotas specifically here in Q1, we're off to a great start. So we're really pleased with the ability to continue to take and win customers that we've never had a relationship with. Customers who recognize and appreciate the importance of exposure management in the Agentic era. The expense rate, Matt can provide more color about it, but played out as expected. But extension remains certainly a big opportunity for us. We have 1 of the largest customer bases in all security -- we have certainly demonstrated an ability to move customers into the exposure management platform into Tenable One to drive higher selling prices and remains certainly a focus for us going forward. .
Yes. I would just add there, we were pleased with the new business, which includes new and expansion business into Tenable One in Q1, you saw 41% of that new business coming into the platform, which is an increase year-over-year of about 8 percentage points. So it was a nice uptick there, and we expect to continue to carry that momentum forward.
Our next question comes from [indiscernible] with TD Cowen.
Congrats on the performance and a little bit in rate. Steve, on that 7-digit EMEA win, can I ask how many vendors did you displace or consolidate?
Yes. Mark here. Yes, so we consolidated 1 major player that was in there. That was an incumbent that was in this account for multiple years. This was a strategic decision that they were working on out of the Middle East, and you guys -- everyone knows all of the distractions in the geopolitical situation over there. So for them to make a move of an incumbent player, an incumbent VM player and move to Tenable, I think shows you the power that we are able to show and be able to give this customer around not just Tenable One the platform but being able to evaluate and look at all of those incremental assets that they're struggling to get visibility on, which is 1 of the biggest drivers -- and so it was a 1 vendor situation that we replaced an incumbent that was in there for multiple years. Great Tenable One Victory. .
Our next question comes from Rudy Kessinger with D.A. Davidson.
Matt, I want to ask about CROs I know the CRPO growth has actually been trending ahead of revenue growth basically for the same reason CCB has been below. But we saw that decell 3 points from 13% last quarter this quarter. So any comment there you can -- or color you can provide and just what drove the decel and how that line should trend throughout the year?
Yes. Thanks for the question. There is there is seasonality at play. So if you look at kind of growth rate quarter-on-quarter from Q4 to Q1 in any year, typically, there is a downward tick on CRPO. And so that's at play. And then there's also the normalization of some of the contract duration noise that was in that number that starts to work its way through as we anniversary some of the policy changes that we had. And so that creates some noise in there as well. I do expect that, that number is going to continue to fluctuate quarter-to-quarter throughout the year. And as I mentioned a few moments ago, the delta between CCB, let's say, and CRPO is likely to continue to fluctuate as well.
Our next question comes from Gray Powell with BTIG.
Okay. Great. Thank you very much for taking the question. So as I listen to this call, I mean, I got to say that the commentary around customer conversations and everything that you're seeing about the elevated demand for exposure management just in the last month, it sounds really good. At the same time, the second half revenue guide is at about 6.5% versus a little over 9.5% in Q1. And I get that you're normally conservative. I understand that a lot of these developments are very recent, so you probably don't want to bake it in. But I guess I'm just trying to think like how should we think of the conservatism within guidance? And then like, are there any underlying metrics we should be focused on going forward to prove out the bull case thesis. I hope that's okay.
Sure. Sure. No, I think the way to think of it is that we came in over the top of guidance for revenue in Q1, and then we're raising for the full year, which should hopefully communicate a level of conviction that we have on the rest of the year. At the midpoint, we took it up -- well, actually, across the entire range, we took up the full year revenue guide -- and the reason we're able to do that is because of a lot of the commentary that you've heard here gives us that confidence. Now of course, when you have the midpoint of the guide for revenue at 7.4%, and you have a quarter like we just did which is 9.6%. -- obviously, the averages are going to work out such that there's something less than 7.4% to get to that number. But the takeaway is, as we sit here a quarter later, net-net, we're in a better position now than we were a quarter ago. We're feeling more bullish. We're feeling more convicted on the year. And that is what has allowed us to raise the guide for the full year.
Our next question comes from Junaid Siddiqui with Truth Securities. .
You've talked about remediation as the next major chapter in exposure management and a large greenfield opportunity. With the launch of HEXA AI, how do you position Tenable as a system of action, not just insight where do you believe Tenable can establish a durable leadership position in driving measurable remediation outcomes versus other exposure management platforms?
Yes. Look, over the years, we -- this is Steve. We've evolved from helping customers understand risk to helping customers reduce it. and now the Agentic era to do that in a very deterministic way, moving at machine speed. We're not in the business of building the bigger -- to build the bigger telescope to watch the meteor hit, we're in the business of helping our customers reduce risk. And it all starts with the data, which we talked about earlier. But a little more color really on Hackel generally be available here in the second quarter. Hexa automates complex multistep workflows and leverages our exposure data and turns it into action. I mean there's a couple of types of action here and pain points that we're solving for our customers. Number one, reducing the manual toil and the drudgery as we would say, for security practitioners, but automate on a wide range of manual tasks such as grouping and tagging, things that just take extraordinary amount of time. But maybe take weeks here, days, we can do in short order even in minutes.
And more importantly, and this is really the bigger mandate for us, which is we can take action via prebuilt agents or custom agents that practitioners can build either to patch or change configs or apply compensating control to reduce risk. It's the action here that really matters and really depending on the maturity and the sophistication of the customer, we can do that autonomously with guardrails. We can do that with a human in loop to ensure that the action is taken in the right manner. But in the Agentic era, it's really the fewest actions with the biggest impact that really matters, and that's our mandate. That's been our mandate since day 1.
This is -- exposure management is a category that we've created. -- is 1 we're continuing to refine and evolve and we are the unequivocal leader here. So excited about the opportunity and what AI means for us and the ability to solve the bigger problem for our customer.
Our next question comes from Todd Weller with Stephens.
Steve, to piggyback on that question. Could you talk about how HEXA AI is packaged and price? Just trying to get a sense of kind of the monetization strategy for it?
Yes. As I mentioned earlier, we have customers that have been using it with great success, and we're getting some tremendous feedback on it. It will be generally available here in the quarter. We have launched new pricing and packaging here. We have a foundational package. We have an advanced package and Hexa will be available either in full form in the advanced model. We want customers to be able to use it, perhaps with greater tokenized access with Hex in the advanced model. But HEXA will play an important role here in helping us drive our ASPs higher and developing better engagement and creating better outcomes for our customers. and certainly solving the exposure management problem. So more to come on that, something we'll talk about really probably over the ensuing weeks, but we're excited about bringing Hexa to the market.
Our next question comes from Jonathan Ho with William Blair.
Congrats on the strong results. One thing I wanted to understand a little bit better is how are you partnering with Anthropic and Open AI today? And can you maybe help us understand how that partnership might differ from Project Glass swing or some of the other broader platform players? .
Yes. I mean, listen, I'll kind of kick it off, and Steve might have 1 or 2 comments. But listen, what we can say is we have a very good close relationship with both anthropic and with OpenAI. So we're working with these folks on a bunch of different fronts. We're obviously using their technology to actually build Tenable One and build Hexa. We're taking actually their product. We're building Claude into Hexa. So there's a great partnership opportunity there. And so this is something that we've been working on for a while. We'll continue to work and continue to expand that relationship as they continue to expand their partner program and they're partnering with different cybersecurity vendors. -- this is something that we're extremely optimistic about and the attitude that they're coming to us with where it is truly partnering, right?
It is not this combative situation that I think a lot of people have in their minds. -- that they're coming after and trying to take over all of software. I mean they are working with us, partnering with us. They've got embedded engineers that we're going to be working with, with our engineering teams. There's just a massive amount of partnering that is going to be a huge benefit to the cybersecurity industry, not just Tenable but the entire industry. So we're going to continue to drive it, and we're off to a great start with both OpenAI and Anthropic.
Yes. And the 1 thing I would add there, just to play off what Mark said, which is we can't comment on all the specifics. What I can say, as Mark mentioned, that we're in active and ongoing conversations with entropic and open AI on a wide range of initiatives that gives us access to nonpublic models. We can say we're partners of Open AI's TAC program, which is the trusted access for cyber program. So that will empower our researchers to be able to do greater -- higher levels of innovation and do that more efficiently. So the takeaway here is we're doing joint research with the frontier model companies, to help defenders leverage the most sophisticated models to fight AI with AI, and we're bringing that technology to market and our technology stack by embedding it in every layer of our platform. So certainly excited about with the opportunity to continue to work with them. .
Our next question comes from Joshua Tilton with Wolfe Research.
Thanks for sneaking me in here. Maybe just 1 on my end. I totally appreciate and understand all the commentary around the urgency you're hearing from your customers as everybody, I guess, sort of freaks out ahead of this Mythos launch. I guess -- what we're trying to reconcile and the question that we're getting from investors just help us bridge that sense of urgency and everything that you're hearing from your customers with short-term bookings growth this quarter of 0%. I think you addressed some of that around timing in an earlier question, but any incremental color that you can help us with there would be very helpful. .
Sure. Yes, Josh, I'll take that. This is Matt. The short-term bookings growth, if you're referring to CCB, that was up 9.2% this quarter year-over-year. But I think to the broader comment, around when is this going to show up in the numbers? This is still early, right? So it does take time for some of this to play out. I think the takeaway and what we're trying to communicate here is though it's early, we're seeing all the signs that point to it being a massive opportunity for us. And the takeaway is that as more vulnerabilities are exposed, exposure management becomes that much more important for our customers to be able to put those vulnerabilities in the context of their own environment, and how that impacts them and then prioritize what to fix. That's really critical. So for us, the takeaway is, look, exposure management has never been more important. It will continue to be increasingly important as some of these models continue to discover more vulnerabilities. And of course, that ultimately the idea that ultimately, that makes its way to the numbers, of course.
Any incremental color on the CRPO bookings growth?
No, nothing more than what I've said. I guess I can say, it came in line with expectations. It was not a surprise to us. It will continue to, like I said, fluctuate in the delta between CCB and -- but no, it came in line with expectations. And again, it's what gave us confidence to be able to raise the full year revenue guide. So we feel good about it.
Our next question comes from Shrenik Kothari with Robert Baird.
Yes. So really great to see the hundreds of early customer conversations around front model. were Discovery, you did announce the Flexstar pricing and how it can be central in removing procurement and budgeting friction. So just curious, how do you think about the unlock opportunity here? And -- and do you see like a clear shift in confidence from customers that they are now excited to kind of scale spending and utilization, especially in light of this AI-driven tsunami as you described, without having to sort of rebuy that budget conversation. Just any comments on that and timing wise, how do you see that unlock play out?
Sure. Yes. No. I mean we've been extremely, extremely well received. We put a press release announcing the pricing change. We've obviously have been working with our channel partners. We're 100% channel-driven company, and so we gave early access to a bunch of our partners got tremendous feedback. And yes, we absolutely view this as something that is going to allow customers to expand with us very, very easily. The way we now have taken out some of the complexity around our older pricing model and really having just 1 price per asset in a single license model we view is going to be able to drive expansion of asset types. So kind of think about it if you were just a VM customer using OT you now have a 1 license pricing model where you can easily be able to expand with not a lot of pain from procurement to add cloud to add AI to add web application scanning to add a tax surface management and be able to spin that up and down based on where you see demand.
So this was a big initiative within Tenable and this was very much a collaborative effort with our partner community and our customer base to make sure we dial this incorrectly. And so yes, we are very optimistic this will move a lot of friction and will drive expansion within the base.
Our next question comes from Roger Boyd with UBS.
I wanted to touch on the buyback, a pretty substantial step-up there. Free cash flow generation remains strong. Matt, I appreciate your commentary here, but would love for you to kind of expand on how the buyback factors in the capital allocation in the current environment and how you're thinking about that relative to M&A and other organic investment? I know Steve talked about investing in the sales force earlier as well, too. So any thoughts there would be great. .
Sure. Yes. Yes, we were pleased to be able to lean into the share buyback this quarter. As we announced last quarter, we had an increase to the share repurchase authorization and we've been accelerating the pace of repurchases. So in Q1, we repurchased 6.1 million shares for $130 million. And that's because we believe that the stock is trading at a price that doesn't represent true value. We continue to believe that share buybacks are a good use of capital. And so we're going to continue to repurchase shares. We maintain though the capacity for opportunistic M&A as well. We've got a very strong balance sheet. The cash position is strong. We got access to debt and so should the right thing come along, of course, we can be opportunistic there. So this in no way limits that, but we do believe that this is the best use of capital right now just simply because of where our share price is trading.
We have reached the end of our question-and-answer session, which concludes today's teleconference. You may disconnect your lines at this time. Thank you for your participation.
Tenable Holdings, Inc. — Q1 2026 Earnings Call
Tenable Holdings, Inc. — Q1 2026 Earnings Call
AI-driven exposure management momentum drives Tenable's solid Q1 results and higher guidance.
📊 Quarter at a Glance
- Revenue: $262.1M (+9.6% YoY)
- Gross margin: 82.2% (+0.3 pp YoY)
- Non-GAAP OI: $61.9M (23.6% of revenue) (+27.1% YoY)
- Tenable One share: 41% of new business (+8 pp YoY)
- New ent. customers: 406 (+12.5% YoY)
🎯 What Management Says
- Strategy: Focus on exposure management via Tenable One and Hexa AI to automate prioritization and remediation, turning insights into action at machine speed.
- Expansion: OT discovery integrated into Tenable One; Flex pricing per asset to simplify adoption across asset types.
- Partnerships: Collaborations with Anthropic and OpenAI to embed frontier models in Hexa; Investor Day May 21.
🔭 Outlook & Guidance
- Q2 Revenue: $263M–$266M (+7.0% YoY at midpoint)
- Full-year Revenue: $1.068B–$1.078B (+7.4% at midpoint)
- Non-GAAP OI: $61–$64M Q2; $252–$262M for year (about 24.0% of revenue)
- Non-GAAP Net Income: $53–$56M Q2; $222–$232M year
- Non-GAAP EPS: $0.46–$0.48 Q2; $1.90–$1.98 year
❓ Analyst Q&A
- Frontier AI impact: Models enable faster vulnerability discovery; Tenable focuses on exposure management to prioritize real risk and drive automated action.
- Budget & cycles: AI security spend rising; boards pushing funding; early deals show expansion potential despite shorter-term timing noise.
- Sales capacity: New CRO; AI-led productivity boosts; ongoing regional hiring to accelerate growth and ASP.
⚡ Bottom Line
Tenable's Q1 confirms strong demand for exposure management amid AI-enabled risk, lifting full-year guidance. The mix shift to Tenable One, Hexa AI, OT discovery, and new flexible pricing supports faster adoption and higher value realization. with a solid balance sheet and active buybacks, the stock has meaningful upside as AI-driven threats elevate the need for coordinated risk reduction.
Tenable Holdings, Inc. — Morgan Stanley Technology
1. Question Answer
I'll start with the disclosures. For important disclosures, please see the Morgan Stanley research disclosure website at morganstanley/researchdisclosures. If you have any questions, please reach out to your Morgan Stanley sales representative.
I'm Meta Marshall. I cover cybersecurity here at Morgan Stanley. We're delighted to have Tenable here with us today, Steve Vintz and Matt Brown, Co-CEO and CFO.
You guys have done a great job over the last year or so of pivoting the business towards Tenable One and exposure management over the last couple of years. Just how did you guys put yourself in position to capitalize on this transition?
I would say it really comes down to three things. Number one, it's recognizing early on that exposure management is a larger expansionary opportunity to vulnerability management. So if you look at our roots over the years, we're really strong, historically have been in discovering and assessing network-based devices. But then over the years, we've applied that core use case into other domains and other areas and brought to market an OT capability.
We also look at like cloud, both on the preproduction side, looking at misconfigurations, identity security as well as web app scanning. So over the years, we've expanded that core use case to other asset types. And now today, we also assess one of the largest threat vectors in security, which is the AI attack surface, which we can talk more about. So over the years, kind of going broader across the attack surface, a larger, more expansionary opportunity.
The second thing I would say is understanding that to be a successful EM platform, yes, you have to do VM and you have to do much more, but you also have to have an open platform and allow yourself to ingest data from other security companies, which we do. We have over 300 connectors.
And the real goal here is to be able to correlate risk to identify leaky S3 buckets that have misconfigurations with lots of entitlements and access and then go to a customer and say, "Hey, this is what you need to be able to prioritize. This is what you need to be able to focus on." So contextualization is really important. And AI will actually allow us to go even faster there.
And I think the third thing would be our North Star here is not just helping customers understand risk, but helping them reduce it. And the orchestrated remediation, tying vulnerabilities and threats and entitlements and access to risk reduction on the back end is really critical. And that means we can do bulk configuration changes in multi-cloud environments.
That means that we can spin up a fleet of agents that interact with a lot of the players on the tooling side to be able to reduce risk, whether it's applying virtual patches or taking other action. But helping customers reduce risk, remediating risk and driving higher levels of mobilization is one of our -- is a big endgame for exposure management.
Got it. So I mean that's a much broader value proposition to customers. How does that change either the sales cycle or like the proof points necessary to close?
Well, if you look over the years, we've become -- we've demonstrated ability to drive ASPs higher. So if you look at sales of our Tenable One platform, which is our flagship product, so we have a stand-alone VM offering that does traditional VM when it comes to looking at exposures on network-based devices.
But over the years, we spent a lot of time integrating a lot of these capabilities across these different domains into a single unified platform. And so that's important because more often than not, customers recognize that security is very siloed. Most large organizations or enterprises today have 80-plus vendors in their supply chain.
So to be able to develop a unified view to be able to take all the things that you assess all that data and correlate it with external third-party data and develop a single unified view of risk and your entire digital footprint is really important.
So ASPs are higher when we sell the platform. They're anywhere from 30% to 80% higher, so higher ASPs, higher selling prices, higher close rates. And the platform is now roughly 40% of our new sales. And we've become more strategically relevant to customers, and it's also recognized as one of the biggest problems in all of security.
Gartner has come on record and said, [ CTAM ] continuous threat and exposure management is one of the major spending opportunities. Today, 96% of all spend is on detect and respond. Exposure management is really about proactive security, helping customers reduce risk. So consequently, they expect outsized growth and spend in proactive security.
This notion that I'm going to look for incidents and breaches and try to detect those and then respond to those, that thinking, those resources, that investment needs to shift to proactive security, and that's what's inflecting deal sizes.
And how does -- sorry.
Yes, I was just going to add on. One of the ways that, that's showing up for us is that we are seeing this increase in the number of large multiyear strategic transactions with our customers.
So we're being elevated within our customers' security environment where we're having those higher-level strategic conversations, which, of course, is driving more loyalty where we're seeing within the platform, churn rates are lower than they are for customers that are outside of the platform. And increasingly, we're seeing more customers moving on to the platform, which is very positive.
Okay. Perfect. Before we kind of dive more into that, obviously, there's been a lot of discussion over the past few weeks around cloud security and just impacts to cybersecurity. I'm sure you might have even had many of those conversations today.
Most of this started kind of after your earnings. And so just wanted to hear from you what you see as competitive moats from AI natives. And just kind of how you think that this discussion is kind of disconnected from the reality that you're seeing?
Sure. I would say if you look at what [ Cloud Code ] does today, they announced capabilities that scans publicly available, open-source software on a preproduction basis. And if you look at where we play, so code scanning capabilities we have, a is small; and b, it's very different than what Anthropic announced.
Where we're strong is really on the data side. So we are post-production infrastructure run time, which means we're behind the firewall. And so the relationship we have with our customers that's built over the last 20 years is based on trust.
So we're able to, when we assess, detect things that others can't, no LLM can do. It's things like an inventory of all your software libraries, an inventory of the configurations of the device. It's understanding if your password is 6 digits and your policy says 9 digits.
So it's built on a level of trust. It's based on assessment and real capability that others don't see. So it's certainly very deep. And that's a little different than certainly what Anthropic plays.
Now I would say also the second thing here is the ability to be able to correlate things. That's really important based on the data that we do have and deliver insights to customers that, quite frankly, LLMs can't do. And I say that because right now, we see ourselves as the contextualized truth to be able to orchestrate fixes.
Yes, can some of the AI labs deliver enhanced capabilities and security and allow us to assess risk faster to be able to correlate risk sooner? Absolutely. But taking action unilaterally without context creates risk. And so the big opportunity for us is doing that in a very deterministic way.
A lot of the AI labs are probabilistic and they're undeterministic. And so the contextualized truth to have the confidence for customers to be able to take action to be able to reduce risk is really important.
And so AI, we believe, creates incredible opportunity for us. But we're still in a world where customers, quite frankly, don't want to deploy patching automatically. They believe it creates too much risk. They want a human in the loop.
But the capabilities that we have allows customers to take action based on their maturity where they can do things with a human still in the loop where they feel safe, they can also do it autonomously with guardrails, where it's safe, where they think the exposure is minimal. But over the course of time, more automated remediation is one of the big value props for us.
And so you kind of mentioned that seeing AI as an opportunity. How do you benefit from that kind of increased surface area? Is it what drives people to look for exposure management? Just how do you benefit from AI versus kind of what we've said is that it's not a headwind?
Well, a lot of the -- what's played out in the market over the last couple of weeks has really been on, "Okay, what risk does AI create for SaaS companies?" And certainly, there will be some levels of disruption, probably more for SaaS-based businesses that have seat-based license models or have workflow that's repeatable that possibly vibe coding can help solve or even things like businesses that are built on data models that it's publicly available. And we saw a good example of that with the scanning of open-source code.
If you look at our opportunity here, we look -- we have the ability with AI to discover shadow AI applications. So the proliferation of AI applications has been dramatic. Most customers have no idea what applications they're using in their environment, whether they're downloaded, whether they build them internally, whether they're browser plug-ins. So there's a lot of talk about [ Claude ] bot. So discovering things like use of ChatGPT, Gemini, internally developed applications is really important.
More importantly, we have the ability to monitor at the prompt level what information that's going into a lot of these LLMs. So is it sensitive customer information? Is it proprietary code? Is it financial information? And then more importantly, tie that back to use cases. So AI, we believe, is going to be a big opportunity for us. It will create tailwinds.
We actually talked about closing a 7-figure deal with a customer last quarter for their use of AI exposure where we're helping them discover shadow AI and then tie it back to governance and policy. So it's questions that Boards are increasingly asking, which is how secure are we? What's our risk with AI? And obviously, these are questions that we're able to help our customers answer with clarity.
Yes. I think I look at it as a massive opportunity because it really plays to our strength, right? If you think about what we do in exposure management, it is about getting visibility, insights and actions. And every company out there is trying to adopt AI for lots of really good reasons, more efficient and effective, and you want to get all these different operational benefits out of it. But from a risk perspective, what companies need to understand is what models are in use? How are they being used?
So the first step is visibility, and that's what Tenable One can provide. Next, okay, how do you contextualize that? How do you get insights into that visibility? And then last, of course, how do you take action?
For us, it's an opportunity because you now have a new and emerging category that we just didn't have before. And increasingly, companies are looking at, of course, how do you adopt AI to make yourself more efficient and effective. But also, they have to understand how do we secure that. That's really, really, really important, and that plays to our strengths.
Got it. Okay. I want to jump back into just kind of Tenable One. You referenced kind of an 80% ASP uplift when customers translate -- or transition from stand-alone VM to Tenable One. Just where do you think we are on that migration cycle? And just what is that gating item to kind of converting the installed base?
Yes. We're, I would say, fairly early, but far enough along that we can see that it's working. So to give you some numbers, we closed out last year in Q4 with the highest percentage of new and expansion opportunities that were closed and won in Tenable One in the platform at 45%. That's the highest in a quarter that we've seen.
And in terms of total, when you look at both new and renewal, it represents about 1/3 of our business today. And so we're seeing customers increasingly moving into the platform. And whether that's from stand-alone VM or other stand-alone EM solutions, what our customers are finding that is within the platform, they're able to have just a far more effective exposure management experience.
And so the reason I say we're fairly early is because the opportunity out there is still massive. We've got 2/3 of our enterprise customers then that are not yet on the platform. And our expectation is as those customers move over, they're going to see, yes, the price uplift, but we also know already that these are customers that are expanding more, they're churning less.
And so all of the good things that you would want to see are happening in the platform, and those are the types of things that we're seeing underneath the surface right now.
And so there's no intent to trying to force people the Tenable One or some sort of upgrade path incentive to kind of speed up that transition or...
So there's a couple of things that we're doing that are very customer-friendly. Number one, we'll very soon have pricing and packaging that makes it -- reduces quite a bit of friction for customers to go and adopt the platform. That's coming soon and is all good news for customers.
The other thing we're doing is we're incentivizing our sales force to encourage platform adoption. So there's an incentive there for our -- all of our quota-carrying sales reps to go out and encourage sales of the platform. So that's all good. We are not penalizing customers. If customers want to continue to be on their stand-alone SKU, they may continue to do that, and we don't have plans to end that.
Okay. You highlighted 300 validated integrations earlier. Just how do those integrations kind of impact win rates, time to value? And where are we in terms of where do you want to get the number of integrations?
Well, sure. Well, security is a very fragmented market. And arguably, there's probably 20,000-plus cybersecurities in the world, offering a wide range of capabilities, and most of those companies are less than $20 million of revenue.
Our view of the world is this, that if we look at the number of integrations, they pertain directly to a core customer use case. So customers may have a preference to use a certain provider for cloud, another provider for EDR. We're really strong at assessing devices across a wide range of domains, but we also recognize that we're not going to have core IP in all domains, no security company can.
So the integration is really important. We acquired a company called Vulcan early last year that not only had those integration capabilities, but also the mobilization pieces that are really important because that's kind of the downstream benefit of ingesting data is that we're able to deliver higher levels of visibility to correlate things that we previously could not, but more importantly, to be able to take action to reduce risk.
So we'll continue to add more integrations. Some of those integrations are bidirectional, and that's really important, too, because it creates a closed loop.
And so depending on the level and the maturity of the customer, some customers may want us once we ingest data and correlate it, normalize it and [ redo ] it because that's really the hard part here. ingesting data is one thing, but to be able to understand that you're ingesting data from CrowdStrike or Prisma or some of the other players that are out there and then combine that with your own exposure data and then say this is a unique asset or a duplicate asset and then to normalize it so customers understand and have an inventory of their entire digital footprint and then more importantly, tie that back to devices that may have critical data that have lots of entitlements and access; that's really important.
So it represents some of our largest deals. It's a big opportunity. It's one of the reasons why we think the expansion rate over time will continue to inflect up.
And obviously, it's a more complicated sale. It's one of the reasons why customers are also making longer-term commitments to us. If you look at the growth in long-term RPO, I think it's up 35%, 40%. So customers are buying more upfront, resulting in higher selling prices, making longer-term contractual commitments, and you can see that in the RPO growth.
Got it. You reported 500-plus net new customers in Q4 and so the platform customer adds were the best in 2 years. What has specifically changed kind of in the execution to drive that improvement? And just how should we think about the sustainability in '26?
I would say it's around a couple of key things. Number one, we're leading with the platform -- a platform-first approach. And if you look at -- I talked about the evolution of Tenable over the years where we have brought new capabilities to market, taking that core exposure use case on the network and then applying that into different assets and different domain types and then more recently, integrating a lot of those data sets into the platform.
So historically, if you kind of look at how we've gone to market, it's really with individual products. And then even in the platform, calculating different licenses for different asset types. So one is platform at the center of everything we do, and we pay higher remuneration for a platform sale because a platform sale means larger selling price, it means higher close rate. It also means higher renewal rate.
Second thing is also moving away, if you look at the innovation, shifting that innovation, not so much at the sensor level, but at the platform level. And one of the big changes that we made last year early was we used to have GMs and individual products that had their own road map that was developing capabilities around individual sensors. It could be things like grouping and tagging or role-based access, it could be more enhanced reporting.
So we want sensors to be able to assess and a lot of the capabilities. A lot of the correlation has to be at the platform level. So that was a big change that we made last year. So engineering has changed quite a bit in that regard.
And number one, go-to-market has changed, and now there's focus on things more recently where we're removing friction instead of selling individual asset types as part of the platform, we're going to be selling tokenized access to the platform to allow higher levels of utilization and adoption.
Got it. On the federal side, this has been a kind of meaningful portion of your business over the years, you implied that the '26 growth rate would be in line with the overall company. Just what are you seeing in this market? And are there opportunities for you to kind of gain share in that environment?
Sure. Yes, I think there are. As you know, before 2025, Fed was a tailwind for our overall growth. And in 2025, it was a slight headwind. And as you mentioned, in 2026, we think it will grow more or less in line.
As we look forward into the future, we expect Fed is going to continue to be a positive driver of our business. And I do think that there's opportunity where rather than being a headwind as it was in 2025, we can start to see a tailwind again. And I think that, that then, of course, improves our overall growth rate.
Got it. I mean you exited the year at 10.5% year-over-year growth. You guided to fiscal '27 to 7% at the midpoint, understanding we are very early in the year. But just how are you thinking about kind of '26 growth relative or the drivers of '26 and if they're any different than what you saw in '25?
I think the important things that we want to see that are not necessarily evident in that headline figure are things like Tenable One adoption and growth as well as expansion.
And so some of the early indicators that I think we'll want to be looking for are an increasing percentage of adoption in Tenable One, which we talk about every quarter, and we'll continue to talk about. That's a very positive sign for us. And then also looking at our net expansion rate, which has been coming down pretty steadily over the last several years.
We'll want to look to that rate as we get to the back half of 2026 as evidence that expansion is picking up because what we have seen most recently is an increasing growth rate in new and expansion, which is exactly what you want to see. Renewal rates remain intact. Churn is steady.
And so when we can begin to see an increasing growth rate in new and expansion, that will ultimately show up in the top line measure. And probably the first place it will be evident to everybody else is in that net expansion rate.
Okay. Steve, you mentioned earlier the 7-figure AI exposure deal. Just what was the core use case that made it kind of AI exposure versus kind of a traditional exposure purchase? And just kind of any context around that deal?
Sure. Well, the core use case there was shadow AI. And it's back to this notion, which is like how secure am I and what's my level of risk? And that's -- these are foundational questions, one that we're really good at answering and we've demonstrated ability to do that over time. So AI is the new threat vector, one of the biggest blind spots in security.
If you look at the use of AI, it's been obviously prolific. We've all read the data points, but 1.5 billion monthly users between Gemini and ChatGPT, yet, that's only -- what is it, arguably 20%, 15% of the world's population. Code today, depending on what you read, anywhere from 5% to 30% of all code is AI generated or AI assisted.
And so without the ability to understand your risk, understand the applications, understand the deployment in your environment and then be able to tie it back to policy and use case and governance models, it's really important.
So it really starts with visibility. And it was actually a sizable 7-figure deal. Sales cycle was very short, came in near the end of the quarter, and we're hard at work building pipeline, and we expect to continue to be successful there. So we're early in that journey. But we are monetizing capability. We have a real role to play here in the AI attack surface.
Got it. I mean with AI risk kind of being this Board-level discussion and you guys having a way to kind of give people actionable insights into those environments, just how do you determine like what KPIs are going to matter most internally? And then how do you -- just like how do you better kind of optimize deals or better capture deals like the ones you just spoke about?
Is it -- just to clarify your question, is it really, "Okay, what's our momentum and success in securing AI in this agentic world?" Or is it, "Hey, how are we using AI internally to go faster?"
It's more of the former. How do you capitalize on this large deal that you just signed and kind of the momentum that, that can bring in how to kind of more package thing to kind of be this like AI risk solution?
Well, in terms of how we measure that, I would say -- and there's different levels here of both qualitative and quantitative.
Number one would be, okay, you have to look and think early at the top of the funnel, we're creating opportunities here, our sales reps having conversations with customers about not only our ability to secure AI. But also, are they helping -- do customers understand our ability to correlate data? So a, leading with the platform; b, with a particular focus on AI exposure. That's really important.
Number two, I would say, closing deals, deals matter here. And the size of those deals matter, too. And so in software, companies can tout a lot of different capabilities, but the one thing that's undeniable are customers and referenceable customers and sizable customers. So obviously, we're going to see more momentum with customers, more close one opportunities.
And then the third thing is really is like what's the impact on overall growth. I know it's hard for investors to try to figure out who's an AI winner and who's not, who will be disrupted and who's a beneficiary. But the easy way to cut the deck here is really on growth.
And so we're focused on driving growth higher. We have the right product, right market, right strategy, and we have a big role here to play in this agentic world. And the ability to help customers not only understand risk, but reduce it is really important.
So I think it's all the usual KPIs that you would see, which is traction with the platform, utilization and the assessment with AI exposure and then obviously, on the back end to be able to help drive expansion and higher renewal rates.
Got it. Matt, you mentioned the dollar net expansion earlier. You found some kind of stabilization in the first half or talked about stabilization in the first half. Just is it as simple as more Tenable One is going to lead to a reacceleration there? Or are there other levers that we should be thinking about?
It's specific to expansion and expansion is a huge part of the Tenable One platform. Reason for that is once the customer is in the platform, it becomes easy. And particularly with our new pricing and packaging, it becomes very easy to expand and begin scanning additional asset types. And the more that customers are scanning, the better overall picture they get of their exposure. And of course, that means for us, then we're able to increase the size of that deal.
And so our expectation is with increased adoption of Tenable One, we will see increased rates of expansion, and that's obviously a big piece of that net expansion rate. The -- if you go back and just chart this rate over time, it has been coming down. But what we're beginning to see underneath the surface is increasing rates of expansion. And our expectation then is that as we get to the back half of 2026, that will start to show up in the overall rate.
Got it. We've also seen kind of some shift in the billing terms. Just how are contract duration and renewal billing behavior changing? And just anything that we should be noting there?
Yes. We talked a lot about this last quarter and even the quarter before a little bit where the push into the platform is driving larger, more strategic multiyear deals. But in many cases, customers just don't want to pay 100% upfront. They would prefer to pay in installment billings annually. which for us, we're okay with.
And so as a result, while we have been seeing contract durations increasing, the billings duration has been decreasing, which is driving this difference in CCB, which is being impacted by billings duration and CRPO, which is being impacted by contract duration.
My expectation is that we're going to continue to see contract duration continuing to expand. But where we saw a 5 percentage point difference at the end of Q4 between CCB and CRPO, my expectation is that as we make our way through 2026 and certainly into 2027, those rates will begin to normalize and converge somewhat. And all the while, we will continue to drive larger and more strategic deals in the platform.
Got it. In terms of operating margin guidance, you guided to 150 basis points kind of approximately of expansion into 2026. Where are you investing? Where are you seeing as the highest ROI investments?
And then maybe that kind of circles back to the latter part of that AI question, Steve, are there ways in which you guys are using AI internally to find efficiencies?
Yes. I'll answer the first part and then kick it over to Steve for the second.
One of the things I'm proudest of is our ability to continue to expand operating margin while at the same time, investing very heavily in R&D. And you saw that in 2025, where our R&D expense grew 23%. And in that same period of time, year-over-year, we grew our non-GAAP operating margin by 140 basis points.
That formula is the same formula we're going to be taking forward into 2026, which is we're going to continue to invest very heavily in product development. We think there's just massive opportunities that are in front of us, and it's very important that we develop and invest heavily in the product, so -- where we're pouring those investments into is exactly where you'd expect. It's within the platform in Tenable One, and it's around AI exposure.
And so where we're going to find the margin is basically everywhere else on the P&L, a little bit out of gross margin, more out of sales and marketing and more out of G&A.
I would say with regard to the latter part of that question, we look at AI as a horizontal enabling function that makes every area better. So for example, in engineering, as you can imagine, where the focus is on greater adoption of AI through the use of a series of tools. So we want to see more AI generated or assisted code. We want to see AI deeply embedded into the workflows. That's really important.
And then in terms of things like on the sales side, understanding the opportunities and looking at data and say, okay, what opportunities have a higher likelihood of close? Is it large or small customers, U.S. or outside, what products?
And then we're also leveraging AI to better support customers where only a smaller percentage of calls and escalations actually will go to a technical support engineer, the frontline defense is that we feel like AI. We're leveraging AI to be able to get information in the hands of customers depending on their specific need -- one, in need. So it's all the things that you would think.
I would say moreover, I think the margins in this business can -- and for a lot of companies like Tenable can go much higher than even anticipated. The fact that we're over $1 billion in sales, we have 40,000-plus customers, we have massive distribution and more importantly, we're able to leverage AI to be able to make our business more efficient to more productive; and I think the operating margins over the course of time will be very, very attractive, perhaps even above and beyond what we've committed to previously.
Got it. And then maybe just last question for me on capital allocation. You guys obviously increased the share repurchase authorization. But just how are you kind of balancing buybacks, M&A, organic investment as you look forward?
Yes. So as we announced in the last earnings call, our share repurchase authorization now stands at almost $340 million. And our intention is to lean heavily into that and accelerate that, the repurchase of shares because we believe fundamentally, shares are undervalued. And so we believe that's a good use of capital.
We will also continue to be opportunistic and look at M&A where it makes sense. We have plenty of capacity should we choose to do that. And so we'll continue to look at those opportunities. But right now, we're focused on going and building organically. We think we've got most of the right pieces in place. And in the meantime, at these levels, we can buy back shares.
Perfect. Well, Steve, Matt, this has been super helpful. Thanks so much.
Thank you. Appreciate it.
Tenable Holdings, Inc. — Morgan Stanley Technology
🎯 Key Message
- Core Narrative: Tenable is accelerating its Tenable One exposure management platform, expanding beyond vulnerability management to a unified platform that correlates risk across networks, cloud, OT, and the AI surface, enabling proactive remediation and higher platform-driven pricing.
🧭 Strategic Highlights
- Platform momentum: Tenable One accounts for about 40% of new sales, with platform-driven deals and higher close rates as customers migrate; 2/3 of large enterprises remain on legacy offerings, a sizeable upgrade opportunity.
- Integrations & data fabric: 300+ validated connectors; Vulcan acquisition expands data ingestion and orchestration, with bidirectional integrations enabling a closed-loop risk workflow.
- AI opportunity: Notable 7-figure AI exposure deal; helps identify shadow AI and govern data use, turning AI risk into a growth lever with governance and policy.
🆕 New Information
- Pricing/packaging: Upcoming simplifications and tokenized platform access to reduce adoption friction.
- Billing dynamics: Longer contract durations with installment billing; contracted billings (CCB) and current remaining performance obligations (CRPO) expected to converge through 2026–27.
- Growth backdrop: Fed remains a positive driver; Tenable’s adoption of Tenable One and AI exposure expansions support an in-line to accelerating growth trajectory into 2026–27.
❓ Analyst Q&A
- AI moat: Asked about AI-native competition; management stressed data-centric, behind-the-firewall assessment and deterministic, contextual risk that LLMs cannot replace.
- Migration progress: Early but progressing Tenable One adoption; pricing/packaging changes and sales incentives to accelerate platform uptake; substantial upgrade opportunity remains as 2/3 of customers are not on the platform.
- Billing & margins: Longer deals and installment billing impact CCB/CRPO dynamics; ongoing platform investments expected to support mid-to-high single-digit margin expansion over time.
⚡ Bottom Line
Ten able signals a clear shift to a platform-centric growth path with Tenable One, higher ASPs, and AI-risk monetization. The combination of broad integrations, a growing AI exposure footprint, and disciplined capital allocation suggests improving revenue growth and potential margin upside, supported by buybacks and selective opportunistic M&A.
Tenable Holdings, Inc. — Q4 2025 Earnings Call
1. Management Discussion
Greetings, and welcome to the Tenable Fourth Quarter 2025 Earnings Conference Call. [Operator Instructions] As a reminder, this conference is being recorded.
It is now my pleasure to introduce Erin Karney, Vice President, Investor Relations. Please go ahead.
Thank you, operator, and thank you all for joining us on today's conference call to discuss Tenable's fourth quarter and full year 2025 financial results.
With me on the call today are Co-Chief Executive Officer, Steve Vintz and Mark Thurmond; and Chief Financial Officer, Matt Brown. Prior to this call, we issued a press release announcing our financial results for the quarter. You can find the press release on our IR website at tenable.com.
We will make forward-looking statements during the course of this call, including statements relating to our guidance and expectations for the first quarter and full year 2026, growth and drivers in our business, changes in the threat landscape in the security industry, particularly regarding AI security and the shift to preemptive security, our competitive position in the market; growth in customer demand for and adoption of our solutions, including Tenable One, our exposure management platform; planned innovation, including Agentic AI security and orchestration capabilities, research and development, investments in Tenable One, changes in key financial metrics and our future results of operations and financial position.
These forward-looking statements involve risks and uncertainties, some of which are beyond our control, which could cause actual results to differ materially from those anticipated by these statements. You should not rely upon forward-looking statements as a prediction of future events. Forward-looking statements represent our beliefs and assumptions only as of today and should not be considered representative of our views as of any subsequent date, and we disclaim any obligation to update any forward-looking statements or outlook.
For a further discussion of the material risks and other important factors that could affect our actual results, please refer to those contained in our most recent annual report on Form 10-K and subsequent reports that we file with the SEC. In addition, all of the financial results we will discuss today are non-GAAP financial measures with the exception of revenue. These non-GAAP financial measures are in addition to and not a substitute for or superior to measures of financial performance prepared in accordance with GAAP.
There are a number of limitations related to the use of these non-GAAP financial measures versus their closest GAAP equivalents. Our press release includes GAAP to non-GAAP reconciliations for these measures.
I'll now turn the call over to Steve.
Thanks, Erin. Before we get started, I want to welcome Vlad Korsunsky to Tenable as our new CTO. He will be instrumental in advancing our AI strategy and driving innovation across our AI-powered platform, specifically advancing our argentic remediation capabilities. Vlad comes with tremendous experience building and leading Microsoft's global multi-cloud security, enterprise AI security and exposure management businesses.
With that, let's get into the quarter. In Q4, we exceeded all of our guided metrics with 11% year-over-year revenue growth and 24% operating margin. Tenable One, our AI-powered exposure management platform, was 46% of new business this quarter, an exciting record for us. During the quarter, we added over 500 new enterprise platform customers, which was our best quarter in 2 years. Strong demand for preemptive security, along with the continued validation from major industry analyst firms is driving larger deal sizes. These firms have recognized Tenable One as a leader in exposure management.
Mark will speak more about this momentarily. Now a key driver behind these wins is the complexity of the modern attack surface. AI is showing up in nearly every customer conversation. Organizations are moving quickly, but many still can't see where AI is running, what it touches, who can access it or how it connects to the rest of the environment. This creates an invisible attack surface that most teams aren't equipped to manage.
In response, many organizations have turned to AI-specific point products that focus on a narrow slice of the problem. But because they only see a part of the environment, they leave gaps across applications, identities, cloud workloads and data, which is exactly where risk grows. This is why a platform approach is needed. And for Tenable, it's a natural extension of what we've always done and why we are demonstrating early customer momentum.
Tenable One now continuously discovers AI across the entire organization, including internal and external, on-premises and cloud to deliver a complete risk-aware view of where AI operates, how it's connected and where exposure is created. From there, the platform provides the insight and context that customers want to identify the governance controls required to reduce risk. By bringing AI into the same unified exposure management model that our platform customers already rely on, Tenable One delivers the clarity and consistency organizations need in a rapidly changing landscape.
We are a platform-first company. Everything we do is about giving customers unified visibility, insight and action in a way that scales with the complexity of the attack surface. Tenable One enables security leaders to reduce operational complexity, resulting in a comprehensive single source of truth for risk. As we expand our capabilities in the platform with more third-party integrations, we are also leaning in and investing in what comes next in preemptive security, including Agentic AI security and the evolution of exposure management into advanced remediation.
Our customers are increasingly asking us to go beyond identifying risk and help them reduce it in an automated, repeatable way. We believe remediation will be a major part of the next chapter in exposure management and that Tenable is in a strong position to lead that shift into this expansive greenfield opportunity. As we enter this next phase, we see our advantages as fundamental to helping customers solve their biggest cybersecurity challenges.
We have vast amounts of exposure data from over 15,000 enterprise platform customers through our open platform and continuous scanning and exposure analysis. This helps create competitive moat and will allow us to deliver data-driven scalability, autonomy and transparency so our customers can reduce risk preemptively. We view our data's breadth, depth and quality as unmatched given the expansive ecosystem of assets, environments and signals it spans.
This differentiation matters. The accuracy of any AI model or prioritization engine depends on the strength of its underlying data. And our data is built to give customers a level of precision and context that is difficult to replicate. And with emerging capabilities, we are positioning our solutions to turn that insight into action by automating the manual repetitive tasks that slow teams down, enabling faster and more efficient remediation.
Our disciplined focus on expanding the platform and ensuring AI remains central to every innovation is driving stronger platform adoption and deeper customer engagement. We believe these priorities will be key drivers in the evolution of our growth trajectory as we move throughout 2026.
And now I'd like to turn the call over to Mark to discuss how customers and the industry are responding to the shift to exposure management and how we are positioned to lead them through this change.
Thanks, Steve. We spoke last quarter about being recognized as a leader in the exposure management category by IDC and in the unified vulnerability management category by Forrester. 2 of the industry's top analyst firms. In Q4, we were named a leader in the 2025 Gartner Magic Quadrant for Exposure Assessment platforms. We were also named as the current company to beat in the 2025 Gartner AI Vendor race. Tenable is the company to beat for AI-powered exposure assessment reporting. Tenable was also 1 of 2 vendors recognized as a customer choice alongside with Wiz in the 2025 Gartner Peer Insights, Voice of the Customer for cloud-native Application Protection Platform report. Taken together, this recognition reinforces what we are hearing from customers and partners every day.
Tenable One is emerging as the essential foundation for exposure management, helping customers turn fragmented security data into unified, actionable road map for risk reduction. Let me share a few examples of customer wins in Q4 and how they are using Tenable One as their environments grow more complex and their needs evolve.
First, let's talk about expansion momentum. A large global enterprise significantly expanded its Tenable One deployment after consolidating and simplifying multiple VM technologies. They selected Tenable because our platform gave them deeper, more accurate visibility and reduced operational overhead compared to their previous tools. They also chose Tenable One for third-party risk managements following a highly competitive and rigorous evaluation, including multiple large platform players.
This win reinforces 2 important trends we are seeing in real time. Customers want to consolidate fragmented tools, and they increasingly view Tenable One as the strategic platform that can address multiple exposure-related use cases through a single unified platform approach. Second, we are seeing strong demand driven by rapid adoption of AI. We closed our first 7-figure deal driven by AI exposure in the quarter. A major telecommunications provider selected Tenable One to gain visibility into how AI was being deployed and used throughout the organization. They had no unified way to understand which agents were being used, what data was being shared or how AI-driven activity was expanding their attack surface.
Their teams were trying to address AI exposure in silos, which left significant blind spots. Tenable One AI exposure closed that gap by giving them end-to-end visibility across their entire AI environment. With Tenable One, they can see which AI apps are being used and by which users, what data is being shared by those users and how these elements combine to create potential exposure paths. They chose Tenable because our platform delivers a complete connected view of AI activity instead of a series of isolated findings.
Third, we are seeing momentum in the public sector, a large higher education consortium selected Tenable to lead a multiphase exposure management initiative spanning more than 20 campuses as part of a statewide cybersecurity modernization effort. The program focuses on reducing systemic risk across institutions with varied levels of maturity, while establishing consistent visibility, prioritization and remediation practices. This was a highly strategic win because the customer required a unified platform that could support a diverse environment, integrate with existing tools and scale across dozens of institutions.
Tenable One met those requirements and demonstrated the ability to drive measurable risk reductions in the early phases of the project. As a result, the customer consolidated on Tenable and eliminated competitive solutions to standardize on Tenable One. Additional phases covering the remaining campuses are expected as the program expands. While these all represent clear examples of where Tenable differentiates itself from the competition, there is one other key point here. We view these customer wins as representing early steps in a much larger opportunity.
Customers are not buying Tenable for a single use case. We are seeing that they are investing in Tenable One as a long-term platform to address exposures across multiple domains in their environments. This reflects a broader shift to platform consolidation. And Tenable One is becoming the system our customers standardize on as they replace fragmented point solutions.
With that, I'll turn the call back over to Matt to dive deeper into the results for the quarter.
Thanks, Mark. We're very encouraged by the strong fourth quarter, exceeding the high end of the range on every metric we guided to for the quarter and the year. It was an outstanding finish to the year, and I'm so proud of the entire team for their execution.
Revenue for the quarter was $260.5 million, representing growth of 10.5% year-over-year and driving growth of 11.0% year-over-year on a full year basis. The year-over-year growth in revenue for the quarter as well as outperformance relative to guidance was underpinned by a solid foundation of renewal business and an increase in our new and expansion growth rates driven by Tenable One adoption. Our percentage of recurring revenue remained high at 96% for the year. We're continuing to see increasing momentum in Tenable One with an all-time high of 46% of new and expansion business coming from the platform.
As preemptive security takes center stage, customers are turning to our platform as their solution of choice to manage risk across their attack surface, including AI. We added 502 new customers in the quarter, many of which came directly into Tenable One. The strength in Tenable One drove calculated current billings, or CCB, ahead of expectations to $327.8 million in the fourth quarter, a year-over-year increase of 8.5%. Full year 2025 CCB landed at $1.049 billion, growing 8.2% year-over-year, while short-term remaining purchase obligations, or cRPO, grew 13.3%.
Changes in upfront billing patterns and increasing contract durations are causing the growth rates in CCB and CRPO to diverge, which we expect to persist in the midterm. Net dollar expansion rate came in ahead of expectations at 106%. Non-GAAP gross margin was 82.7% for the quarter, an increase from 81.7% in Q4 2024. Full year 2025 non-GAAP gross margin was 82.1% compared to 81.4% in the prior year.
We are encouraged by our ability to slowly but steadily increase non-GAAP gross margin year-over-year, both on a quarter and full year basis. Non-GAAP income from operations for the quarter was $63.7 million or 24.4% of revenue. On a full year basis, non-GAAP income from operations grew to $219.0 million or 21.9% of revenue compared to $184.1 million or 20.5% of revenue in the prior year.
I'm especially proud of our ability to steadily increase margins in 2025, growing operating margin 140 basis points compared to 2024. In a year in which we absorbed 2 acquisitions and invested significantly in product innovation as demonstrated by the year-over-year increase in research and development expenses.
We expect to continue our strong track record of delivering margin expansion, while balancing for growth, having expanded our non-GAAP operating margin by 680 basis points since the end of 2023. Non-GAAP earnings per share for the quarter was $0.48 compared to $0.41 in Q4 2024, an increase of 17.1%. Non-GAAP earnings per share for the year was $1.59 compared to $1.29 in 2024, an increase of 23.3%. The increase in Q4 and full year EPS reflects the increase in profitability combined with a decrease in diluted shares outstanding.
Turning to the balance sheet. Cash and short-term investments totaled $402.2 million. We generated $87.5 million in unlevered free cash flow during the quarter compared to $85.7 million in Q4 2024, bringing our full year 2025 unlevered free cash flow to $277.0 million, a year-over-year increase of 16.5% and now represents 27.7% of revenue. During the fourth quarter, we repurchased 2.3 million shares for $62.5 million. And through the end of 2025, we have repurchased a total of 10.6 million shares for $362.4 million since November 2023.
Today, I'm happy to announce that we recommended and the Board approved a $150 million increase to our share repurchase authorization, increasing our current total authorization to $338 million as of year-end and enabling us to accelerate repurchases under the program. We believe that our current share price trades at a discount relative to our true value and that utilizing our strong balance sheet and cash flow generation to more aggressively repurchase shares is an effective use of capital.
Turning to the financial outlook for Q1 and full year 2026. We have discussed over the past several quarters that CCV and RPO growth rates are diverging due to changes in upfront billings patterns and increasing contract durations. The increasing mix of larger strategic multiyear transactions is a desired outcome of our platform strategy and is driving an increase in overall contract duration.
At the same time, the shift to annual installment billings based on customer demand and away from 100% upfront payments on multiyear transactions is reducing overall billings durations compared to prior periods and causing a negative distortion to CCV that we believe fails to accurately represent the growth of our business.
In addition to the distortion dynamic that impacts what we disclose externally, internally, management is no longer using CCB as a component to monitor the performance of the business. Consequently, CCB is no longer a key financial metric for us, and we will not be providing a specific guidance range for CCB in 2026 and forward.
Having said that, while we will not guide to a specific CCB range in 2026, we expect full year 2026 CCB will be in line with current consensus expectations despite the anticipated billings duration headwinds. The momentum we experienced in Tenable One in the second half of 2025 and growing opportunity in AI exposure gives us confidence heading into 2026. For Q1, we expect revenue to be in the range of $257 million to $260 million, representing a year-over-year increase of 8.1% at the midpoint.
For full year 2026, we expect revenue to be in the range of $1.065 billion to $1.075 billion, exceeding the $1 billion milestone for the first time and representing a year-over-year increase of 7.1% at the midpoint. We expect non-GAAP income from operations for the first quarter to be in the range of $53 million to $56 million or 21.1% of revenue at the midpoint.
For full year 2026, we expect non-GAAP operating income to be in the range of $245 million to $255 million or 23.4% of revenue at the midpoint, representing a year-over-year increase of 150 basis points. At the end of Q4, we began an effort to realign departments across the company, stripping out redundant roles and reinvesting into innovation in the Tenable One platform and AI security.
As a result of these efforts, we incurred $3.1 million of restructuring expenses in Q4 and expect to incur approximately $5 million more in the first half of the year, all of which is expected to be paid in 2026. We expect non-GAAP net income for the first quarter to be in the range of $46 million to $49 million, representing a year-over-year increase of 7.2% at the midpoint. For full year 2026, we expect non-GAAP net income in the range of $214 million to $224 million, representing a year-over-year increase of 12.7% at the midpoint.
We expect non-GAAP earnings per share for the first quarter to be in the range of $0.39 to $0.42 per share, representing a year-over-year increase of 12.5% at the midpoint. For full year 2026, we expect non-GAAP earnings per share in the range of $1.81 to $1.90 per share, representing a year-over-year increase of 16.7% at the midpoint.
And finally, we expect unlevered free cash flow for the year to be in the range of $285 million to $295 million or 27.1% of revenue at the midpoint. While we're pleased unlevered free cash flow continues to grow year-over-year, it's worth noting that our 2026 forecast is being impacted by an estimated $24 million or approximately 220 basis points of margin due to the reduction in upfront multiyear billings and cash restructuring charges that I spoke about before.
Looking ahead to 2027 and beyond, we expect billings durations to normalize and unlevered free cash flow as a percentage of revenue will grow generally in line with growth in non-GAAP operating margin. In closing, we'd like to thank the entire Tenable team and our customers and partners for a great result. It's amazing to see the traction we're getting in Tenable One and our customers' excitement around our AI exposure management capabilities. We believe the second half of 2025 was important validation and that 2026 is setting the foundation for returning to accelerating growth, which is our #1 priority.
With that, we are happy to open up the call for questions. Operator?
[Operator Instructions] Our first question is from Rob Owens with Piper Sandler.
2. Question Answer
Great stuff on the deal size is moving up the success with Tenable One everything you're -- the successes you're seeing from an exposure management standpoint. But hoping you could square that a little bit with what you saw in the large customer cohort and the net additions of $100,000 ACV customers, as it was lower than we've seen in the past.
Rob, this is Steve. I would say 2 things. #1, new business was strong for us. As you saw, we added 500 new customers and the value of those lands are more sizable now than they have been in the past. Second thing is that expansion was good for us in the quarter. I want to make that very clear. Where we saw strength is within the cohort of customers that were -- our large customers.
So our largest customers that have adopted Tenable One, who are using Tenable One, expand it within the quarter. So we're very pleased to see the ability to land and transact new business at higher price points with the platform, but also more importantly, expand the relationships with our largest customers. And that's really the tail to take this quarter.
Great. When you talk about some of the success you're seeing in terms of AI exposure, and I think you mentioned your first 7-figure deal on that front. Just help us understand where customers are in this journey at this point? Is it a tip of spear type of item for you or something that's being followed on? And while it's conversational, how much activity you're actually seeing out of the customer base right now to move?
Yes. So it is literally coming up in every single conversation, right? There isn't a conversation that you have with the CISO where AI and AI security and how to protect their organizations does not come up. So it is unbelievably prevalence. We see it everywhere. When you look at some of the opportunities that we're going after, obviously, we commented we closed our first 7-figure deal, which was outstanding.
And when you look at some of the use cases, there's some constant themes that are coming up, where I think we're uniquely positioned to excel, right? When you look at some of the things that are coming up from the CISO around looking at and discovering AI across the entire enterprise and the company, looking for like shadow AI and the AI attack surface and the public services being used from an AI perspective, then how do they protect the AI workloads and the agents for misconfigurations and nonhuman identities, those type of things and then the governance issues that are arising in regard to deploying and using AI.
So these are constant themes that we're seeing. And we are seeing pipeline build, and we're seeing it come up in all of our conversations. So I think this will be quite a bit of tailwind for us moving forward.
Our next question is from Saket Kalia with Barclays.
Nice quarter. Steve and Mark, maybe just to start with you. I mean, Tenable One is clearly doing very well. And that really expands vulnerability management into exposure. And so maybe the question around that is what additional modules within Tenable One, are customers adopting most as you look at that growing Tenable One base? And maybe relatedly, how is that broader offering impacting your competitive win rates, if at all?
Sure. Yes. Good question, Saket. I would say a couple of things. First and foremost, as you saw this quarter, mix of new business inflected higher. 46% of our total new sales came from the platform. Customers clearly won a platform. They clearly want to be able to assess risk holistically and it really comes down to 3 things.
1, I would say visibility; 2 is insights; and 3 is action. And so one of the big areas of value for the platform is our ability to help customers understand their entire digital footprint, whether it's asset systems, devices, workloads that are either in the cloud on your network, on the factory floor. And so consequently, we have most customers who are using the platform are using us for traditional VM, but plus web app, plus cloud security, which continues to grow at a very nice rate.
And then more recently, as Mark called out, securing the AI attack surface, which is a big blind spot for our customers. So -- and then more importantly, it's the ability to correlate all those data -- all that data to deliver insights and help customers orchestrate remediation to reduce risk.
And I think the takeaway here going forward, there will be less emphasis on individual modules and individual products. And the emphasis for us and it's really selling the platform, selling it in a more cohesive way and making sure that we're giving customers access to all of the capabilities within the platform to continue to drive higher levels of utilization and continue to inflect selling prices higher.
Got it. Got it. Very helpful. Maybe for my follow-up for you, Matt. Listen, it was very clear on the call. I mean, the billings duration dynamics definitely help explain why we're no longer going to be talking about CCB. But it also sounds like the growth here in fiscal '26 on CCB shouldn't be that impacted. Can you just unpack that a little bit? I mean is the headwind from billings duration maybe smaller? Or is there just faster underlying growth in the business that enables you to sort of endorse consensus?
And maybe just philosophically, what is -- is it going to be revenue that's going to be really the basis that we should be judging the health of the business? Or anything on that on sort of new metrics that you think are going to be better reflective of the dynamics that are happening?
Yes. Thanks for the question, Saket. So really, we saw a really strong finish to 2025, which gives us quite a bit of confidence heading into 2026. We are still seeing a billings direction headwind to CCB. But we did feel like it was important to at least give that qualitative direction around where our expectations are for CCB in 2026. Beyond that, though, you could just tell from our guide, we're feeling very good about where revenue is coming in op income, and despite the fact that we also see billings duration headwinds in free cash flow, we're also able to put up a pretty good free cash flow number for the guide as well.
So generally feeling very positive, and it goes back to a lot of what we've discussed already, which is our confidence in the platform. We're seeing where that's working, that strategy is paying off and the opportunities that we're continuing to see in AI.
And despite that headwind, the one comment I would add there is that despite that headwind, we're seeing strength. If you look at the strength in our business, so I think the guide reflects the strength and the underlying momentum of the business despite the change that Matt mentioned.
So really pleased with the results for the quarter. Really pleased to be giving the guide today and demonstrates the increasing confidence in our ability to execute and deliver greater value to customers.
Our next question is from Brian Essex with JPMorgan.
I appreciate all the commentary on the quality of the data across the platform. Or maybe for either Steve or Mark, if you could maybe pull on that thread a little bit. As investors become concerned about the potential for disruption outside of the depth of visibility that you noted with Rob and Saket, could you maybe help us better understand where some of the deeper data differentiation lies, how that resonates with customers? And then also maybe how you might competitively see larger platform vendors that are innovating into the exposure management space, particularly as we see demand on the AI side?
Sure. First and foremost, let me say that AI is a massive opportunity for us. I want to be very clear about that. I think Mark and I are convicted in that. It makes us more relevant. It makes us more important and more importantly, it makes exposure management more critical for our customers. Mark highlighted this earlier, but we're starting to see incremental AI budget dollars flow our way to help customers secure their use of AI. But it all starts with our data, the breadth and depth of the data we've collected over 2-plus decades, we believe is absolutely unparalleled.
We talked about this earlier on the call, the data that we collect is unique. It's based on deep domain expertise and things like trusted access and years of continuous scanning telemetry and exposure analysis. And this is something that either general models or other companies can't replicate. And moreover, it's really about applying AI to leverage this data to deliver insights in a way that allow us to solve the closure gap.
And for that, AI is at the center of what we're doing, it's not only going to augment human operators. But it's going to give us like critical context and knowledge that will help our customers develop a deeper understanding about their risk. And more importantly, it will allow us to drive actionability and orchestrated remediation to reduce risk in the world of AI speed and scale.
So this data is going to allow us to continue to create a bunch of agentic workflows to get the job done in the right way. And so we're well positioned here, and it's of course, more compliant in what we can do. And the last thing I would say here would be -- I think, it's just to connect the dots. It's really about the brand, the trust customers have in us, the size of our customer base, the ability to leverage the data to reduce risk at all of these things.
Great. Super helpful. And maybe if I could do one quick follow-up for Matt. Conservatism in the guide, I mean, 1Q at the midpoint implies a sequential decline, which seems early similar to 1Q this year. You have the same philosophy? Should we think about the setup this year the same way as you have coming into 2025 and...
Yes. I think -- look, we're pretty happy with the guide certainly relative to the expectations that were already out there. We're -- I think we're ahead across the board on our guided metrics. I expect seasonality will be pretty similar to what we've seen in the past. So I would expect that to be consistent. But we're very happy about the opportunity that we've seen, not just exiting the year, but also as we look ahead to the pipeline and the deals that we have in front of us, we're feeling good about the year.
Our next question is from Joseph Gallo with Jefferies.
There was a lot of strength in pro services in the past 2 quarters. Can you just speak to that? And how we should think about that in the context of the guidance?
You bet, I'll comment on that. The reason you're starting to see that pick up, and it is a unique model that we have here at Tenable because we do 100% of our business through partners and resellers. So our partners and resellers. They also drive a significant part of their business through services. But as we now are deploying a platform at scale, you see these deployments, where they're going through and rolling out multiple different asset types.
And so we're able to go in there and as we're doing larger transactions, larger deals, we're able to go in there with our professional services organization and help them on this exposure management journey. When it was just core base VM way back in the day, there wasn't this massive demand for professional services. But now as you deploy a platform they want to do it, they want to deploy it quickly. They want to make sure that they get all of the different asset types deployed over time, and they want to get it done to drive their utilization rates as high as possible, utilizing all their licenses. So we expect that to continue, but we also expect our partner community and the GSI community to be able to drive significant service exposure management platform, Tenable One.
Awesome. That's really helpful. And then maybe just as a quick follow-up. So it was a really strong quarter and you guys spoken to prudence, it seems like in the guidance. But I just want to square away, you just grew 11%. You're guiding to 7%. So the exit rate may be below that. Like is that just a straight math equation between the baton handoff between VM and exposure management. And like at what point can we see exposure management be material enough to kind of offset that and stabilize growth?
Yes. Underneath that, what we're seeing is strength and significantly higher growth rates within Tenable One, which is exactly what we want to see. Today, though, Tenable One represents about 1/3 of our overall business. As that percent overall percentage continues to decline and continues to grow faster than non-Tenable One, we expect that, that overall growth rate then inflects higher stabilizes and then inflect higher.
The Good thing is we're seeing signs of that now. So we're seeing increased rates of adoption Tenable One. That's exactly what we want to see. We're seeing increased growth rates within new and expansion, which is also exactly what we want to see. So the early signs are there, and that gives us confidence.
Our next question is from Mike Cikos with Needham & Company.
I'll echo congratulations here. Appreciate the commentary on the shifting patterns here to annual installment billings. Matt, I guess, first question for you, but my concern is you would cited the $24 million headwind to unlevered free cash flow this year from both billings and restructuring. And the concern is that folks are still going to calculate CCB and then try to triangulate off of that $24 million to derive some sort of figure.
Can you point us in the right direction for why that and is or is not what we should be doing when thinking about normalized CCB adjusting for these different billing patterns, please? And then I have a followup.
Sure. So first off, we thought it was important to at least provide some qualitative direction around our expectations for CCB for 2026, which is why we pointed -- why we pointed out in my prepared remarks that we expected CCB to be in line with current consensus expectations. So that was important for us.
Underneath that, though, we know that's despite some of the billings headwinds. And so I think what I would point to is, yes, there is going to be this impact. But we're also providing other metrics that should be helpful. So if we talk about percentage of new and expansion business in Tenable One. We talk about additional new customers. We talk about our net expansion rate. And obviously, we're talking guide to revenue. The types of things that I would be looking at and that we are looking at are things like the net expansion rate, I think that's important. That came in ahead of expectations at 106%.
Actually expected that to drop down to 105% in Q4, but we exceeded expectations and it landed at 106%. I think that percentage very likely could bounce down to 105%, but I expect that to stabilize in the middle of the year. And I think that's a very good first sign that things overall are stabilizing. So I think there's a lot there to look at. as you point out, CCB, not only, of course, do we provide that qualitative aggression. CCB is going to be readily available for everyone to calculate, when you're looking at our financial statements. So that is going to be something that folks can continue to look at, if they so choose. But we tried our best to quantify the impact and that headwind is embedded into our expectations for 2026.
And just as a follow-up, I want to make sure I heard correctly, this probably goes back to Joe's question on the shape or what's implied for the decel through '26. But if I heard you correctly, so it sounds like the guide is underwriting net expansion rate of 105% in the back half of the year. So first, did I hear that correctly? And then secondly, just given that Tenable One today is about 1/3 of the business. At what scale does Tenable One need to be before we can actually see an inflection point?
Yes. So actually, it underwrites a net expansion rate of 105% in the first half of the year. My expectation is that, that rate stabilizes and could, in fact, inflect higher. And that really, at that point, demonstrates the stability in our overall growth rate at which point Tenable One continues to drive things higher. And in particular, as we see greater opportunities within exposure management. AI is just one example, but we're beginning to see the signs of accelerated growth beyond.
And I think that's really the important point here, which is we have confidence and our ability, we feel like we have the right strategy, our confidence in our ability to execute as we've demonstrated here not only just this quarter, but over the last few quarters, where we're demonstrating good stable growth with traction in the platform, and that is all a preposition to driving growth higher.
And so, the investments we're making around the platform, the investments we're making in AI helping our customers secure the AI attack surface. The investments we're making in the ability to monetize leverage the data to deliver insights to orchestrate remediation or we're confident in our ability to drive growth higher. And that's -- Mark and I are focused on that and the opportunities are right in front of us, and we're confident in our ability to do that.
Our next question is from Jonathan Ho with William Blair.
Could you maybe talk a little bit about -- especially the broader adoption of Tenable One maybe what the pricing uplift looks like, but also potentially how asset and coverage rates increase over time as well?
Yes, I can speak to that. This is Matt. So the great thing about the platform is we see an opportunity where customers today standalone VM customers today moving to the platform to do full exposure management, can see an uplift as much as 80% uplift when moving to the platform. But even customers that wanted to stand-alone VM today, but want to move to the platform to do VM within the platform. They're seeing an increased set of capabilities within the platform, and they get an uplift as well.
So regardless of where you're at in your exposure management journey, moving to the platform ends up being a net positive for the customer and it ends up being a net uplift for us in terms of ASP. So that's why it's important when we move customers to the platform. The thing that gets us just incredibly optimistic there is yes, you get an uplift when they move to the platform, but these are also just the customers that we want.
You have customers that are churning less. They're expanding more the deals are larger in size, they're more strategic. So this is a strategy that we're all in on and is working for us. And I think from our perspective, the best part is that we've got a pretty good on-ramp here to the platform. And with roughly 2/3 of our business not on the platform, it represents an opportunity that we're very excited about.
Got it. And then just quickly as a follow-up. When it comes to Agentic AI, we seem to be seeing a lot of interest not just in sort of visibility, but also the governance side of AI. Can you talk a little bit about how your CIEM and CNAPP products sort of play a role in governance. Why is important? And maybe what you're seeing customers invest in early on?
Yes. Well, it's all -- governance is all very important regardless of what domain, whether it's network, cloud, or even AI applications and Agentic capabilities. And I think you mentioned on the cloud side, our CNAPP offering covers broad cloud risk across configs identities and workloads. While cloud VM, as we call it, 0 in an extending traditional VM into those environments. And this is also a specific app ensuring like workloads like virtual machines and container images are monitored continuously and prioritize with contact.
So look, the problem we're helping to solve is really about helping customers discover all of their assets across multi-domains, it's about correlating a lot of this data to deliver insights. And then it's also really about the transparency and the governance behind it, so we can enforce AI security policies and force broader security policies to ensure there's the right use and deployment of this technology.
Our next question is from Shaul Eyal from TD Cowen.
Congrats on the performance and initial 2026 outlook. Steve, I know it's early days, but lots of consolidation in the exposure management arena. Do you see Tenable benefiting from customers revisiting prior relations? And maybe as my follow-up, how would you characterize the current pricing environment? Have you seen increasing ASP slightly during the quarter, maybe even during January?
Yes. And I want to make sure the connection was clear. So prioritization certainly is a big challenge for a lot of customers are talking to a lot of CISOs. What we hear time and time again is that they're overwhelmed with alerts and the starter insights. And so there's a need to be able to correlate all that data across domains, whether it's network, cloud, OT, identities. All that's really important. And our goal here is to help customers prioritize and identify the riskiest exposures on their most critical assets that have a lot of access and entitlements.
So we do that in a very visualized way that customers can consume. And that all points towards remediation. So you can't take action without delivering insights and you can't deliver insights to customers and correlate data without having the visibility. But now having 20 years plus of exposure analysis and ingesting data from others. So all of it is really important. It's all of it interconnected, and that's why we're having success selling the platform in a very integrated way.
Any view about ASPs during the quarter, maybe during January?
Yes. So Mark here. Yes, no, they were strong. I mean you could see from our margin perspective, very, very strong quarter. We're not seeing any pricing pressure, the beautiful thing that Matt already highlighted is when you are selling Tenable One on the platform. Obviously, you're getting an uplift for that, you're getting incremental capability, you're getting incremental coverage.
And so when you look at it from a competitive standpoint, when you're driving and selling Tenable One, it is really about this consolidation play. And so when you're able to go ahead and consolidate multiple other tools into the platform and get a higher asset count into Tenable One that allows you to get very, very good pricing. And so we feel very confident there. We're not seeing any pricing pressure with new logo or with our installed base.
Our next question is from Patrick Colville with Scotiabank.
I guess 1 for Matt. I just want to circle back to the guidance because lots of exciting innovation, success, but the guidance is strong. But if I look at RPO or short-term RPO, it was 13.3% in 4Q, where 2026 guidance is for 7%. It's just like a big gap between the 2. So why is short-term RPO not a good indicator of forward revenue given there's such a big gap between the 2?
Yes. I just want to make sure you're clear on this. So we don't guide CRPO. So that 2026 number that you mentioned is not an RPO number. So CRPO did come in at more than 13% for 2025. One of the things that we talked about with CRPO is that, that number continues to be driven higher in part due to contract durations becoming longer. And that contract duration is increasing as a result of us entering into more larger strategic transactions many times in the case of a Tenable One transaction.
And so it's a desired outcome is what we want to see. We want to see our contract durations going up, but it does have a byproduct effect of increasing CRPO and actually distorting that number a bit. You can see there was a tremendous growth in long-term RPO as well. So 2026, we don't guide to CRPO and actually for similar reasons as to why we're no longer guiding to CCB. Both of those metrics are somewhat distorted.
Okay. Very clear. And just focusing on another metric that you do guide to non-GAAP operating, I guess, margin, right. I'm calculating at 23.5% for 2026, which is a really -- calculated it correctly, it's a really healthy increase of about 1.5 points year-on-year. I guess can you just talk through, if I'm right in my calculations, the puts and takes there. And it seems like the Tenable is really continuing this effort to improve profitability.
Yes, that's right. So the guide for 2026 at the midpoint is 23.4%. And what I love about that number is, yes, you're right, it's an increase of about 150 basis points year-on-year. It is also while we are investing significantly in product development, in particular, in the platform and around innovations in AI, in particular. So this is something that we expect to be able to continue to drive higher. We've taken an approach, where we're balancing growth and profitability and our expectation is that we'll be able to grow in 2026 by about 150 basis points, while meeting our -- all of our investment goals as well.
Our next question is from Rudy Kessinger with D.A. Davidson.
And congrats on the quarter and solid guidance here. Just 1 for me. What are the federal assumptions for Q3 and the full year? I know we're a couple of quarters out from the big federal quarter, but the government is still a bit volatile, if you will, with almost shut down this past week. So what are the assumptions there relative to last year and just overall on a growth standpoint?
Yes. So the expectation is embedded within the guide for federal is that federal will perform more or less in line actually with the rest of the business. So we're not expecting outsized growth, and we're not expecting any particular headwinds for Fed. So again, just in line with overall company growth. But...
Yes. No, I think it's a very, very accurate feedback and we're happy, very happy with our performance in the federal space in Q4. So we're finally seeing some stability there, and we're expecting the same thing in 2026. And from a state, local sled perspective, very, very strong also. So it seems like things are getting back to normal there, which is great to see.
Our next question is from Abhishek Murli with Morgan Stanley.
This is Abhishek Murli on behalf of Marshall. And congrats on a really strong end of the year. I guess to start off, could you kind of walk us through whether you embedded government shutdown into guidance? And then kind of what you ended up seeing for the quarter in terms of the federal dynamics given the tougher backdrop?
Yes. So no, a federal government shutdown is not embedded within the guide per se. But we saw minimal impact of that in 2025 and don't expect to see any significant impact on that one way or the other. As I mentioned, Fed, our expectations for Fed in 2026 are very much in line with our expectations on growth on the rest of the business.
Just one clarification. This is Steve. So Mark talked about some of the strength in Fed in the fourth quarter, right? Other quarters were not as favorable, just given a confluence of different events in U.S. Federal this past year, and that's what's reflected in our outlook for the full year for 2026.
Got it. And then to follow up on like more of a budgetary perspective, do you see exposure management getting lumped into AI spend in budgets? And then can you kind of walk us through some of the dynamics you're seeing of where it's being allocated in cybersecurity budgets more broadly?
Yes. No, it's being added to. So when you take a look at the exposure management, when you look at like RFPs and you look at opportunities right now, you are starting to see AI being added to it. And as we highlighted in one of the big customer wins, sometimes it can be for significant budget dollars. So when you're now competing from an exposure management perspective, we are seeing an increase and RFPs and pipeline build around exposure management opportunities for Tenable One, AI is now becoming a critical part of that decision criteria.
And so you're seeing that budget from an AI perspective to be added into exposure management. And, a, it's a great differentiator for us. So it gives us a great competitive foothold and it's also one of the more pressing areas that CISOs are really driving us too and having conversations with us about.
Thank you. There are no further questions at this time. This does conclude today's conference. We thank you again for your participation. You may now disconnect your lines.
Tenable Holdings, Inc. — Q4 2025 Earnings Call
Tenable Holdings, Inc. — Barclays 23rd Annual Global Technology Conference
1. Question Answer
Excellent. Well, good afternoon, everyone. Welcome to day 1 of the Barclays Tech Conference. My name is Saket Kalia. I cover software here. I'm honored to have with us the team here from Tenable. We've got Steve Vintz, Co-CEO; as well as Matt Brown, new CFO. Also have Erin Karney, Head of Investor Relations there in the audience.
So we've got about 30 minutes together. Let's spend the first 20 or 25 minutes just going through some fireside chat with the team, which I know is going to be real fun. And then we'd love to make it interactive. If anyone's got a question, just pop up your hand, we'll get a mic out to you for the benefit of the webcast. So with that, Steve, Matt, thanks so much for being with us here today.
Happy to be here.
Thank you.
Yes, absolutely. So I think that there's so much to talk about from last quarter, right? I mean, Steve, Matt, maybe just to help us level set, can you just spend a couple of minutes kind of recapping some of the points from last quarter that you were most proud of? Maybe, Steve, you talked to us about some of the strategic points in the business that we've made some really good progress and some good things. And Matt, maybe from a financial perspective, you can highlight some of the points you want us to take away.
Sure. I'll start here, and we're pleased with the results in the third quarter. Matt can get into this a little more, but we exceeded on both the top and bottom line and gave a strong outlook for the year. That's always a good thing. But kind of numbers aside, one of the things I'm particularly proud of is the momentum and the traction that we're getting with our exposure management platform.
And just to level set exposure management in its most basic form is a unified business -- risk-based business contextualized view of your entire security program. So you understand your entire digital footprint. So whether it's assets and connected devices on the network or workloads in the cloud or even industrial control systems, these things that are on your factory floor to understand all of that, do that in a very unified way.
So you're identifying the most important vulnerabilities and exposures on your most important devices that have the most sensitive data with lots of entitlements and access, both human and machine. So you're identifying likely path of exploit for the organization. So they can look at the company through the lens of threat actors.
It's a big problem. It's one of the most important, we think, in all of security. And we had great traction this quarter with our exposure management platform. Over 300-plus new customers we added, a good number of those were new lands with the platform. We're also seeing certainly significantly higher ASPs, which is great to continue to get traction there. And one of the important attack vectors, if you look at our exposure management offering, which includes traditional -- assessing traditional network devices. It includes cloud, it includes web apps, it includes ASM and other areas of the attack surface.
But moreover, more recently, we announced over 300 integrations as part of the platform. So we're now able to ingest data from other security companies, whether it's web app, data from security companies and web application and AppSec, cloud, endpoints, whatever the case may be, ingesting that data, combining it with our own, enriching it, scoring it to be able to drive higher levels of mobilization and remediation.
So the traction there has been notable. And AI is also creating tailwinds for us, where we brought to market and announced AI exposure, where we're now able to identify as part of the platform, vulnerabilities, misconfigurations and flaws in a lot of these AI applications and the cloud environments in which they run in.
Yes, absolutely. Matt, maybe on the financial side, you could round that out.
Yes, so much to be proud of. In Q3, I was very happy that we were able to come in over the high end of the guide on all of the metrics that we guide to for the quarter, which is fantastic. And that also allowed us to guide up for full year at the midpoint on our guided metrics. So I felt really good about the solid execution there. We saw 11% revenue growth. I was super happy about the incremental margin growth that we saw.
So year-over-year, in the quarter, we saw a 350 basis point increase year-over-year for op margin, which is especially impressive given that at that same time, we increased our R&D spend by 18%. So we were able to generate that much incremental margin while still investing heavily in product development that made me very happy. So put us on solid footing for the rest of the year. It's encouraging to feel that momentum building. And yes, looking forward to continuing that trend.
Yes, absolutely. Steve, maybe back to you. I mean, the way that you talked about the business before just around sort of exposure management, that's so much of a broader category than what we've historically called VM vulnerability management. How do you think about that sort of expanding the TAM? Do you see that out there? I mean, do you think exposure management kind of expands that definition?
Well, it does. And we've been on this journey for some time now. We went public in 2018. We were not the market leader in VM, but one of the things we said is that our mandate was in short order to become the unequivocal leader in vulnerability management. And VM is really the ability to discover and identify exposures in network-based devices and service desktops and laptops. And then over the years following, we brought new capabilities to market to address other domains of the attack surface.
But one of the things that we talked about early on at the time of the IPO was the outgrowth of VM for what we call exposure management. And exposure management is a category that we've created. It got very little recognition and fanfare by the industry analysts. And we saw it as certainly a big problem given all the vendor sprawl. When I talk to CEOs, CISOs and even CIOs, one of the things they tell me is that there's not a lack of data. In fact, there's an avalanche of it, and they're having a challenge managing all of it. So they're drowning in alerts and starved for insight.
In fact, if you look at organizations today, most reasonably sophisticated organizations have over 80 different security vendors and technologies deployed across their environment. And that doesn't create clarity. It creates a lot of noise. And so given the proliferation of all these devices and systems, we need a unified way to really understand risk because cyber risk is not a technology issue, it is a business issue. And so we need to be able to quantify risk and be able to trend it in a way that -- so others can understand the impact on the organization.
So we were pleased to see Gartner release an MQ for CTEM, their first one, specifically exposure assessment platforms. We were at the top right, IDC also came out with a MarketScape report in exposure management. We were at the top right. Forrester came out with their report this quarter on UVM, which is their preposition to exposure management. We were at the top right there. So it's nice to see a category that we created kind of a market turning to us.
Gartner says -- now says one of the biggest opportunities in all of security is exposure management, is CTEM, continuous threat and exposure management, in part because a lot of the spend in the market, if you think about it over the years, has been in detect and respond technologies, actively searching for breaches and then responding to them. 96% of all spend in security today is on detect and response. Think about that. It's basically looking for fires.
What we advocate at Tenable is what we call proactive security exposure management, which is the shift from firefighting to fireproofing and it's, we think, one of the biggest opportunities in the market. So we're early on it. It's a journey. We're getting great traction with customers. And certainly, it's nice to see not only the industry analysts recognize it, but we're already to see -- starting to see other companies now talk about exposure management, which I think is healthy because certainly, it's a big opportunity, one of the largest TAMs. It's the intersection of cloud and network and identity and all these other things to help customers really understand risk.
But it's really the mobilization and the remediation pieces that I think are going to continue to create an inflection point for us, which is what do you do with all that data? How do I look at all this data in a way where I can proactively reduce my risk? Because there's no shortage of vulnerabilities in the world. There's 300,000 unique vulnerabilities today that's been identified. And according to our research, there's roughly over 500 billion of unique instances of those vulnerabilities. And AI is leading to more vulnerabilities, more threats and more breaches, and it's demanding a secular shift in security this shift to proactive, which is what exposure management is all about.
Interesting. I always love that analogy of firefighting versus fireproofing really brings it home. But maybe we'll use that as a stepping stone to talking about Tenable One a little bit. And Matt, maybe the question is for you. The way that I was viewing the mix shift in this business was that maybe VM was 80% of the business and exposure solutions was the remaining 20%. But that doesn't really tell the whole story because Tenable One, of course, includes VM. So I was curious, right, just as you come in with fresh eyes, how you sort of articulate the mix shift that's happening in the business right now?
Yes. It really does sort of start with that difference between EM and VM. And as you mentioned, there's more value in EM for the customer than there is in traditional VM. Referencing back to that Gartner Magic Quadrant, it was very interesting. One of the -- I think one of the most interesting stats that was identified in that piece talked about how companies that adopt exposure management solutions, those companies in the not-too-distant future, just in the next couple of years, will experience 30% less downtime as a result of exploited vulnerabilities compared to companies that have VM only. That just tells you the value proposition that you get from EM instead of VM.
And for us, our Tenable One platform is our exposure management platform, right? The super encouraging thing there from my point of view is there is a tremendous amount of value that customers get when they go to Tenable One. We see an uplift in price. Tenable One grows faster than the rest of our portfolio. Those customers are stickier, so retention rates are better. All of that goodness, we're seeing momentum building and moving towards that platform. And the good news is we're fairly early days still, right? There's a lot of runway ahead of us. There's roughly 1/3 of our business today of our enterprise business is in Tenable One. That means we've got 2/3 then that we still have an opportunity to go get, which is really nice.
That was going to be the next question on runway. So thank you for that. That's great context. Maybe, Steve, then this one could be for you. I think we disclosed last quarter, right? We just said, right, Tenable One is about 1/3 of the total business. And we've talked about sometimes how -- we talked about sometimes the parallels between Tenable One and Tenable.io, for example, right? And so maybe the question is, how do you compare and contrast that adoption curve of Tenable One to Tenable.io? It seems like it's steeper. It feels steeper from what I remember Tenable.io, but I'd love to hear how you compare and contrast those 2.
Yes. And so Tenable.io is our cloud-based VM offering. So historically, the roots of the company have been vulnerability assessment. We have a piece of technology called Nessus, which is one of the most ubiquitous pieces of technology in all security. It's been downloaded over 3 million times, represent -- virtually anyone who's a security professional has used it or is using it. And over the years, we've kind of built some enterprise-type capability around it and then delivered a more expansive VM capability as part of a cloud offering, which we've been in market doing for some time.
But when we went public, it was somewhat of a newer offering for us, not the subscription model, but the cloud-based version. And in short order, in 3 years, I think following the IPO, it became over 50% of our total sales. So we said it would take 5. We did it in 3. If you look today, Tenable One, as Matt talked about, highest selling prices, highest close rates, highest renewal rates of any of our products.
It's what customers -- certainly, it's how customers want to buy, and it's how we're going to market. It's roughly about 30% -- 40% of our total new sales. We think that will be 60% plus. Also look for new pricing and packaging for us to continue to evolve. We have an asset-based pricing model. So as customers place more assets in their environment, increasingly, they turn to us to help assess those. And even in terms of total sales, it's about 30% of our total sales, and we think that can more than double over the year.
So we feel really good about where we're going. One of the reasons why is what I talked about earlier, which is the shift from detect to respond reactive to more proactive security, which AI is necessitating, right? There's no shortage of vulnerabilities. There's going to be more vulnerabilities in the world. With AI, threat actors are weaponizing it. So there's been more 0 days discovered this year and more incidents and meantime for vulnerability discovery to vulnerability exploitation has shrunk dramatically. You used to have 2 weeks to be able to apply a patch. Now you have days and even seconds.
So it's important not to necessarily understand vulnerabilities and manage all of them and patch everything, but identify likely path of exploit. So that's what this is really about. So consequently, 4% today is spent on proactive security. Others have indicated -- a lot of the other industry analysts say that 4% will go over the next 5 to 10 years to 50%. That's a dramatic increase. So whether you think it's 4 going to 50% or 4 going to 20% or 25% or 30%, that's where this market is going. We're talking about a secular shift in security in terms of how we need to think about cyber risk as a whole. and certainly, exposure management and doing that in a continuous way is the epicenter of all that.
Yes, absolutely. Matt, maybe for you, just staying on Tenable One. I mean, you talked about kind of the ASP uplift that you get the additional value that a customer is receiving. Just walk us through some of the drivers of that. And what's kind of the uplift that you're able to see from some of the data that you've seen?
Yes, it's a significant uplift. And at the same time, the customer is getting significant value, too, right? And so it's quite a significant uplift when you look at a customer that is doing VM stand-alone only today into Tenable One, it can be as much as 50% to 80% of a price uplift when they're using the full breadth of the features within Tenable One, which is important. And ultimately, that's where we want them to be and where we see just this enormous opportunity.
Ideally, you're taking a stand-alone VM-only customer and helping them on their journey to a more sophisticated exposure management solution. Part of the way of getting them on that journey is to get them into that platform. So we can get them into the platform, land on the platform, expand from there. And it's a pretty significant price difference taking them from just core VM into the full breadth of our Tenable One platform.
Got it. Got it. Maybe, Matt, just to stay with you just on Tenable One because we've talked a bunch about the product and we talked about the market a little bit as well. I want to -- and this is clearly the future of the business, right? That's what's kind of coming through. But I'd love to dig into how a growing mix of Tenable One could maybe impact the model. And so one of the things that we've talked about in the last couple of calls has sort of been this growing divergence or this divergence between CRPO and CCB, right, calculated current billings. Can we just touch on that as it relates to Tenable One? If you could start us off, Matt.
Yes. What we're seeing is, increasingly, we're engaging with our customers on larger, more strategic, longer-term deals, which is exactly what we want. We love that. We've got a bigger seat at the table, and it is nice to be locked in with a customer for multiple years and frees up capacity, all sorts of reasons why we want that. At the same time, though, whereas in the past, we may have required upfront billing, say, for a multiyear agreement, we're allowing our customers to pay annually.
So what we're seeing is as more of these deals are happening, contract duration is going up, which is impacting RPO. And at the same time, billings duration is actually going down because we no longer have a policy of requiring upfront billing. When that happens, you start to see some distortion in the numbers. So CRPO is benefiting from having this outsized growth of long-term RPO, which is then feeding short term and increasing that number.
And conversely, CCB is being negatively distorted because the long-term billing portion, it's showing up in the contract, but it's not showing up in long-term deferred revenue, right? So there is this disconnect where we know that they're both being distorted somewhat. And so that's a dynamic that we wanted to make sure that folks understood because CCB is a metric that we have historically guided to and tracked, but it's something to just be aware of.
Yes, absolutely. I think that's a really important point. I mean -- and maybe we'll come back to that. But Steve, maybe for you, just to kind of stay on the economics of Tenable One because I think they're just so much more compelling. As you build up a bigger base of Tenable One customers, what's keeping a customer on Tenable One or even expanding versus moving to another solution? And maybe relatedly, Matt, I mean, you touched on this earlier, but how different are the gross and net retention rates on Tenable One versus other Tenable products? Maybe you could start us off.
Sure. And we talked about kind of our growing mix of Tenable One, higher selling prices and close rates and certainly renewal rates. Look, one of the reasons why customers are using Tenable One, it's -- you can't do -- Tenable One includes all of the individual domains that we assess, whether it's traditional VM, network-based devices, cloud security, OT, which are the industrial control systems that are now digital and all interoperable and all susceptible to exploit. We're seeing more attack there in critical infrastructure.
Think manufacturing facilities, municipal water systems, think telecommunications, all those things, right, create significant exposure. And now even AI, which is an important part of the attack surface, shadow AI that applications that are downloaded or created that employees use not maliciously, but as a means to do their job faster, but it creates real risk because they're prompting things in these public LLMs such as customer data, financial data, sensitive information around strategy. That's all part of the attack surface. We manage that. We can monitor at the prompt level and tie it back to your policy.
So -- and then now more recently, ingesting data from others. So when customers use Tenable One, selling prices are higher, it's a stickier product. And we're still very early in that journey with the customer because they don't buy and assess everything within their environment. But what they want to do is they want more insight. It's really all about unified visibility, right? Right now, visibility is fragmented with all of the vendor sprawl, and we were able to bring that together in a way where customers understand their entire digital footprint, right, by ingesting third-party data, which sounds seemingly simple, but it's more than APIs.
It's normalizing it, deduping it, it's doing a whole bunch of things with the data so we can drive higher levels of prioritization. It's about visibility, it's about insight, right, all the contextualization that goes with it. And then it's all about action, too, which is how do I reduce risk. So this has been a journey that we're on with customers. We're proud of the fact that more than 15% of our enterprise customers are now using the platform. Even within those customers, those cohort of customers, the usage there, we still think is modest in terms of our ability to grow with them over the years. So it's a journey, and we feel like it's starting to inflect higher.
Absolutely. Matt, maybe on gross or net retention rates to the extent you can comment?
Yes, there -- so we don't publish the specific breakdown, right? And I won't do it here, but it is higher, and it's higher than any individual product that we have as well. It's something that we're actually thinking about is there's a lot of interesting things when you start diving into Tenable One, and we give some Tenable One specific metrics. But certainly, as we're thinking about, CCB, maybe not as meaningful as it used to be, what are some other metrics internally that we're looking at? Some Tenable One specific metrics are certainly some of the that we're thinking about.
So boy, that's a great segue into the next question that I wanted to ask you, Matt. I mean, to your point, right, like as we change -- as the billings duration here changes, that might weigh a little bit on CCB. You still grew at 11%. But then, of course, RPO might also feel that impact of longer contract duration. So I mean, how could those focus metrics change? Like does it make sense to go to talk about other metrics? A lot of our companies talk about ARR. I mean how do you sort of think about the future of the metrics here as the business evolves? Because the economics here are improving, those metrics don't necessarily reflect it properly. So what will be a good way to think about that?
It's something that we're thinking a lot about. And there are a lot of different options, and there's pros and cons to many. ARR is something that we look at internally, but lots of folks have different definitions of what ARR is and so different ways of measuring it. So I'm not sure that that's the best either. It's absolutely top of mind.
We know that revenue is solid, right, in terms of a metric. That gets reported all the time. We know what that is. It's a GAAP definition. Everybody knows how to calculate it. And it also -- it falls right in the middle now of what I would consider your upper and lower bounds of CCB on the one end and CRP on the other, revenue is right in the middle. So that might be the best metric, but it's something that we're thinking about.
Yes, absolutely. I'm going to go back to some financial questions in a second. But Steve, maybe for you. Obviously, U.S. Fed and public sector have been nice, large, stable businesses for Tenable for years now. Is there any area within the large public sector that you and the team are particularly excited about as we head into 2026?
Yes. Well, I think it's notable that we're able to deliver good quarters despite the sizable market leadership we have in the Fed. We serve a wide range of 3-letter federal agencies. U.S. public sector is 15% of our total sales. So we have major market leadership there. And the good news is that we've been able to close deals despite somewhat of a selling environment where there's far less visibility. Like we've had to deal with everything from Doge early on at the beginning of the year, where there's disruption in personnel, even to -- we lack real leadership in security within Fed right now, like there's Sean Plankey.
Well, first of all, the CISA has been completely rightsized, right? It's back to their focus over the years in a prior administration, politics aside, has been on election security. The Trump administration now is refocusing kind of their center of gravity into critical infrastructure and network security, which is the original congressional mandate. We hear Plankey -- it's been some time. He has not been confirmed. We're told now he's out. And so we don't have leadership at CISA. I think new business has been tougher. I know new business has been tougher to transact within the government. But those are -- that's transitory stuff. That's all short-term stuff.
Public sector, major leadership. It's created tailwinds of growth for us over the years. It will create tailwinds of growth for us in the ensuing years. Right now, there's just a little less visibility. Deals are a little tougher to get across the finish line. But despite that, we're able to deliver good results, give a good outlook. And so the best days are still ahead for us in Fed, because they want to modernize, they want to consolidate. And those are all things that we do really well. And obviously, they also want to focus on things like cloud security, where we're now FedRAMP authorized. Things like exposure management, where we're now FedRAMP authorized. So look for bigger deals, more traction there.
That's great. That's great. Matt, maybe back to you. I mean, just to talk about growth headwinds, tailwinds, it's obviously very early to guide for next year. But with all the different dynamics that we've talked about, what are some puts and takes that you want us to think about for the model next year from a growth and profitability perspective?
Yes. I think -- so yes, definitely too early to guide. We're feeling really positive about, obviously, how Q3 went, our then renewed optimism for 2025, where we were able to take up the guide. So feeling like that's providing some nice momentum and stability. And we've had a history of being able to grow while continuing to expand margins. That's also something that we're going to continue to on. So look for more of that. We remain committed to making sure that we can grow with profitability and at the same time, making sure that we're investing in all of the areas where we're seeing growth out there on the horizon.
No, that's a really helpful framework. I mean, Steve, maybe last one as we wrap up here. I mean, to Matt's point just around still being able to invest, I think you specifically highlighted investments in R&D on the Q3 call. The team has just done a series of great tuck-in acquisitions over the years to really build that breadth of product right across exposure. Should we expect that to continue? Maybe open-ended question for you.
Well, security is a fragmented market. And the deals we've done in the past are used -- were used as a means to accelerate road map. And there's a lot of customer pull with respect to those. But they're also a journey. They've been a journey for us. Like, for example, we acquired a company called Apex Security early in the year and even Vulcan, which is more on the third-party data side. But with those acquisitions, they require time, they require investment. The products have to mature. We're also very focused, as you heard today, time and time again on selling and going to market with the unified platform.
And so sometimes they necessitate rewriting of technology and code into the platform. So the short answer is, yes, we'll continue to evaluate acquisitions. But we have a full plate right now. We're hard at work in bringing if you think about the growth that we've been able to deliver to date with certainly no tailwinds from Fed and historically, there have been and there will be with, quite frankly, we only have been in market with third-party data for a very short amount of time. And next year, we'll have a full year of selling that. We now have 300-plus integrations into the platform and more to come.
And more importantly, the mobilization, the remediation pieces that are now coming to the market in the fourth quarter from the Vulcan acquisition. So these are all things -- and then AI security. So these are all things that, quite frankly, we haven't gotten the benefit of this year. We've been able to transact newer business. We've been able to deliver -- get momentum with the platform. We've been able to get validation and recognition from the industry analysts as the leader in one of the most important markets or our best days are still ahead. We think we have all the capability we need to be able to drive growth to the levels that we want, and we're committed to, and that's what we're focused on for now.
I don't think I could have thought of a better way to end right there. So Steve, Matt, thanks so much. That was a really enlightening session. So thank you.
Thank you for having us. Appreciate it.
Tenable Holdings, Inc. — Barclays 23rd Annual Global Technology Conference
🎯 Key Message
- Focus: Tenable is accelerating exposure management via Tenable One, broadening beyond VM to cover cloud, network, OT, and AI-enabled risk.
- Momentum: Q3 execution was solid with revenue growth and margin expansion, supporting a higher full-year outlook.
- Scale: Tenable One accounts for about one-third of total business, with 300+ integrations, higher ASPs, and rising renewal rates.
🧭 Strategic Highlights
- Integrations: 300+ third-party integrations enable richer data ingestion and better risk prioritization.
- AI Exposure: New AI-focused exposure features help identify vulnerabilities and misconfigurations in AI apps and cloud environments.
- Platform & Gov: Acquisitions and FedRAMP authorizations broaden platform reach and public-sector traction.
🆕 New Information
- Platform Momentum: Tenable One now about one-third of business; ASP uplift when adopting full platform (~50–80% in some cases) and higher renewal rates.
- Data & Ecosystem: 300+ integrations and Vulcan/Apex acquisitions expand mobilization/remediation capabilities.
- Metrics & Billing: Longer-term deals boost RPO but distort CCB; internal focus on alternative metrics to reflect ARR/retention dynamics.
❓ Analyst Q&A
- Adoption Curve: Discussion on Tenable One versus Tenable.io, with emphasis on higher ASP, close and renewal rates as platform adoption grows.
- Metrics: Questions on CRPO/CCB distortions from annual billing and longer contracts; management highlighted internal metric considerations and ARR thinking.
- Growth Outlook: Tailwinds from AI, public sector momentum, and ongoing R&D investments; acquisitions kept under consideration to accelerate roadmap.
Bottom Line: Tenable is building a more durable growth story around exposure management via Tenable One, driving higher value, pricing, and stickiness. The Q3 beat and platform traction—300+ integrations, AI capabilities, and public-sector momentum—point to upside as adoption deepens. Watch how long-term deals and metric definitions evolve as the mix shifts toward platform-based ARR and higher retention.
Tenable Holdings, Inc. — UBS Global Technology and AI Conference 2025
1. Question Answer
All right. We will get going here. Thank you all for being here. I'm Roger Boyd, I cover cybersecurity here at UBS. Very happy to have the team from Tenable here. Matt Brown is the new CFO of the company; and Erin Karney is VP of Investor Relations. So thank you both for being here.
Thanks for having us. Appreciate it.
But I wanted to start high level and go back to a comment that Steve made on the earnings call last month. But he called out that the AI threat landscape is exposing the limits of a traditional kind of reactive approach to security. Can you just explain what that view means, this idea of more fireproofing versus firefighting? And how does that kind of align with what you've built in the exposure management category?
Sure. I'll start and Erin can fill in on some of the details as well. So what we really talk about with respect to AI is, it represents a significant amount of change, right? Everybody talking about AI. And what every Board -- you're going to hear in every Board and every management team are 3 key questions. One, how are you incorporating AI in your products to make them more competitive? -- fine. How are you leveraging AI internally to be more productive, and efficient. Great. makes sense. The third is how are you safeguarding your use of AI, right? And that last one is super important and represents brand-new opportunities for us. And so one of the ways that we are doing that is by providing visibility to our customers for what AI is being used in their environments. There are many companies that know that AI is being used in their environments, but they can't tell who's using it and which specific models are being used. And so our product AI Aware, which is incorporated into our VM products, gives companies the ability to see what models are being used and and then it informs them on how they can protect themselves. It can expand beyond that, though, right? So with our most recent acquisition with Apex, they brought a tremendous amount of AI capabilities that we are now incorporating into Tenable One, which includes really our -- more broadly speaking, AI exposure, which now not only allows companies to see the AI that's being used in their environment, but also how it's being used, the prompts that are being input, how do you safeguard the models from attempts, jailbreak attempts and other types of prompts that can try to get the AI models to do things that are not intended. And then how do you make sure that what being fed into those models as in compliance with your policy. So all of that represents brand-new opportunities now that we think Tenable is extremely positioned to go capitalize on.
Yes. I guess maybe to follow up there, how do you feel this kind of evolves as a demand environment? And I look at 3Q results, fairly strong. Do you feel like we're starting to see this? Do you need kind of additional lever to come from like regulatory angle, like the pessimistic view would be, we need to see something happen in the threat environment that kind of forces enterprise's hands? Like how do you see this kind of evolving from a budget perspective?
Yes. I think the biggest piece is companies are realizing that only detecting and responding to threats is not sufficient. And by the time there's an attack that takes place, it's -- in many cases, it's too late. It's very costly in the form of downtime and disruption and, in some cases, real financial impact. And as a result, then companies are realizing that in order to have the best practice on their security posture, they really have to take a proactive approach. And that's what we -- when we talk about fireproofing rather than firefighting, the most mature companies that have developed their exposure management programs are looking at vulnerabilities across the entire landscape and assessing where those risks are before they happen. There's various estimates out there from some third-party analysts that the amount of dollars that are being spent on detect and response, going forward, some of that is going to shift into more preemptive security measures, which is really what exposure management is all about.
Cool. Yes, I want to dive a little bit into 3Q and again, a fairly strong quarter. The net adds continue to stand out. You added almost 450 new enterprise customers. I wanted to dig a little bit deeper into what drove -- what was driving some of the momentum on a customer adds perspective? And how are you thinking about kind of sustainability of that going forward?
Yes, we were really happy with Q3, had nice new logo growth, as you mentioned. Most of that is being driven by Tenable One. So we saw 40% of that new business growth was within Tenable One, which is our exposure management platform. And that's really important for us because Tenable One represents an important opportunity for our customers and also an important opportunity for us going forward, where we're seeing more customers that are transitioning from point solutions, whether it's in VM or some of our other point exposure management solutions into the platform where they can see now holistically across their environment a much broader view into what the exposures are. Tenable One allows customers to see their vulnerabilities, but then really importantly, how do they assess those vulnerabilities from a risk ranking perspective. So you can imagine a CISO that is overwhelmed with the number of vulnerabilities that are in their environment, they have to find some way to prioritize them. And what Tenable One allows our customers to do is cast a very wide net, scan many assets across on-prem, cloud, OT/IT, AI and on, and then risk rank them, giving them business context who has access, what type of access, what data is included? What are some predicted attack path analyses? How does that all factor in order to then prioritize risks and vulnerabilities that need to be addressed now. That's what's really, really value add for our customers. And so -- and that's what they get in Tenable One. So A lot of that optimism that we're seeing, the new customer growth came from Tenable One but that's what gives us a lot of optimism as we look out to the future as well.
Yes. When you talk about the strength of Tenable One, how do you think about new logos from a greenfield, brownfield perspective? And I know all of your competitors have been moving towards this vision of exposure management, for you, it's Tenable One. Competitively, have you seen any big shifts in the landscape? And what have you seen specifically on kind of the brownfield side of new logos?
Yes. I mean it's one of the most exciting areas, actually, and I want Erin to weigh in on this too. I don't want her to getting lonely over there. So I'll kick it to you in 1 second. The greenfield -- some of the greenfield opportunities is what we touched on a minute ago with AI. I mean that's clearly greenfield. We think that's really interesting, has an opportunity then to grow so -- with some of the cloud opportunities that we have. But when we think about brownfield, there's an enormous opportunity that we have to transition our existing VM customers over to Tenable One. So yes, Erin, you can touch on that a little bit as well.
Yes. Yes, definitely. So we're seeing really strong win rates pretty consistently across the board against all the competitors. What I think when you drill in, what's really interesting is the -- what we're -- the progress we're seeing within Tenable One. So that broadens the competitors because you're dealing with cloud, OT, these other areas, but it gives us an opportunity to displace them and then be able to expand within that into those greenfield areas. So even when you're looking at the brownfield, there's a huge amount of opportunity to display some of those competitors. And third-party data helps with that, which is a recent company we acquired, that allows us to ingest that data, maybe displaced down the road. So really all starts with Tenable One and then within that, you have brownfield and greenfield.
Makes sense. And then the other side of the growth formula, net retention, it's been somewhat stable in kind of the single digits, 105%, 106%, 107% range. I recognize it's a trailing 12-month metric. But how do you think about kind of the trajectory there? And given the strength you've seen in Tenable One, 40% of new business last quarter, what's the pathway to getting that to reaccelerate here?
Yes. Eventually, it stabilizes and even inflect higher. But we know in the near term, it's going to tick down. So for example, it was at 106% this last quarter. as you mentioned, it's a trailing 12-month metric. That was as expected. And next quarter, it's very likely to be 105%, right? It's going to go down another percentage point. Well, why is that? Well, you're looking back 12 months. And when you look at Q4 of '24, that growth rate was significantly higher than what we're projecting in Q4 of '25 to be. And so that quarter rolls off, the new quarter rolls on, it's just going to end up being math. So that's not going to surprise us either. But it does stabilize from there and it starts with -- it really kind of starts and ends with Tenable One and Tenable One adoption. I mean that really is where our focus is internally on the product development side as well as go to market, we think that, that has an opportunity to really inflect higher. And importantly, we're pretty early there, and there's quite a bit of runway given the percentage of our customers and our overall book of business that is currently in Tenable One, we've got a lot of room to ramp.
That's a good segue. I think that number is close to 17% today in the high teens. Is there kind of a target you think about internally about how far Tenable One can go in the installed base?
I think it can go really far. We haven't talked about a specific target. Are we ever going to get to 100%, I doubt it, but it can certainly grow from there. 17% is the number of our enterprise customers. So we think of something like 3,000 out of 18,000 is that math. But some of those customers are our larger customers. So it skews slightly higher when you think about total amount of bookings or revenue today but we expect that number to grow. And it's going to grow in a couple of different ways. Number one, we're going to get our traditional either core VM or other point exposure management customers into the platform. That's the first way. And then the other is that once those customers are in the platform, they're actually growing faster than customers that are outside of the platform. There's higher retention rates and higher upsell and cross-sell opportunities. So both of those ways are going to grow that number higher, and we expect as that becomes a higher and larger proportion of our business, while that's growing higher, that's going to help the overall growth rate as well.
Yes. Okay. The other kind of impact, I think we've seen is customers making bigger commitments to Tenable. And I'm sure part of that is around Tenable One. I think last quarter, you mentioned the discrepancy between CCB and RPO and certainly, I think, seeing longer deals show up. Can you elaborate on that dynamic? And I see more of these big commitments. What does that mean for some of those metrics?
Yes. The first thing to point out is we really like that trend. So we want our customers to be engaging with us on larger, more strategic longer-term deals, but we're no longer requiring that they pay upfront for those transactions, right? So what that means is that we end up seeing our contract duration moving up significantly because they committed, right? But because we're no longer requiring these companies to pay upfront, we're actually allowing for annual installment billings, our billings duration has gone down. And what's interesting then is you end up with this distortion effect on CRPO, which in Q3 was 13% year-over-year. That was distorted somewhat positively. Conversely, but for the same reasons, CCB was actually impacted negatively because billings duration went down. So then the question becomes, okay, well, what's the right metric. Revenue grew at 11%. I think revenue is a great metric. And so it could just be that CCB and CRPO are both distorted and they're going to be distorted for some period of time and that revenue is the best metric.
Okay. Makes sense. I wanted to talk a little bit about cloud security. And I think there's an investor perception out there that, that's been a difficult competitive environment. We've obviously seen some transactions in that space. To what degree have you seen that change the environment for those deals? I know you called it out as an area of strength with Tenable One. And what sort of momentum have you seen with specific deals around cloud security?
I'm going to let Erin answer because I've got something going on the road and then you can come back to me.
Happy to jump on that one. So I would say the cloud space has been somewhat competitive, but I don't think anybody would be surprised that there's one competitor in particular that's been pretty strong. We see 2 things. One, we have a really strong cloud product, and we can stack it up against most, and we feel really positive about that. But we weren't necessarily getting all of the opportunities. So either there wasn't a broad RFP out there or they didn't realize Tenable had cloud. So we've really made a big effort to make sure customers know what we have to offer, that we have a strong product. And M&A, recent M&A has definitely helped customers to want to cast a wider net. So I would say it's really all of those things that are allowing us to have these opportunities where we're displacing competitors. And it isn't necessarily just one of those things, but definitely all of them is helping to contribute. And we're really happy with how cloud is growing. And then within Tenable One, it's even more compelling for our customers.
Yes, it's a strong spot for us. We highlighted a competitive win in the last earnings call that we're really proud of. The good thing about the cloud space is it's a pretty big space. And we think there's room for a couple of strong competitors there and we're one of them. So we're going to win our fair share, and it continues to be a good source of strength for us.
Yes. Similar question around AI security and Apex. And I'd be curious to get your perspective. I mean, in some ways, it feels like the first place enterprises are going to turn to trying to enforce AI security is going to be around risk assessment and posture management and just getting visibility into what they have. That should set you guys up in a pretty good spot. But how do you think about that demand showing up over time? And how do you think about your right to win? We've seen a lot of companies in the space acquire into like the AI visibility, AI posture management space. What gives Tenable the right to win with kind of this broader Tenable One posture?
Yes. I mean it's a huge opportunity for us. One of the things that we did differently with Apex and Vulcan actually for that matter, is we brought both of those technologies into the platform right away rather than trying to go to market with a separate product or module. That was really important because it becomes a really unique differentiator of Tenable One and the platform. So now customers can go in -- within Tenable One, have really effective AI exposure and view that in the context of their broader security environment, which we think is huge. So that's a really big deal for us. It continues to be a bright spot, and I think it's going to be a nice source of growth for us.
I want to talk about a couple of verticals here, but the first being U.S. federal. And I think 3Q, you had performed pretty well against expectations that had come down a little bit earlier in the year around some of the uncertainty there. What's been kind of the mood within those customers? And when you think about timing around the Fed shutdown we saw in early 4Q, to what degree did that kind of influence 3Q? And how are you thinking about kind of that opportunity going forward?
Yes. So Fed for us, to just put it in context, our public sector business is roughly 15% and Fed is half that, so 7-or-so percent. And for us, we took our pain a little bit in the beginning of the year when we took down the numbers because we're staring ahead at the opportunities and seeing some of the disruption with the new administration and DOGE and ultimately, the shutdown occurs. But by that time, we had already reset expectations, and I think that was really important. And since then, Fed performed in line or even slightly better with those renewed expectations. And so actually, as it -- we get to the back half of the year here, we're not expecting to have a significant negative impact from Fed, but Erin may have more on that.
I mean I think you called it really well. The only thing I would add, and there's not necessarily a time line around this, but the Fed has always been focused on cyber, and they've been a great customer for us and continue to be. And where we see opportunity is we are now FedRAMPed with Tenable One and with cloud security. So while it's pretty noisy right now, and we're navigating through that pretty successfully, we do see areas of opportunity as we look forward and some of the noise dissipates.
Cool. Okay. And then the other vertical is -- it sounds like it doesn't get as much attention as cloud or AI, but the OT space was called out last quarter as an area of an acceleration. And I think there's something to be said about the convergence of IT and OT and CISOs being more involved in those conversations. I know Steve called out the data center market around AI as a potential interesting opportunity. How do you feel about that vertical? And what -- can you frame that opportunity going forward? And what's the differentiation there between some of the specialists in the space?
Yes. I'm glad you asked about that one. That's been a bright spot for us and I think continues to represent a really nice opportunity as these data centers are being built. It's super important now that there is security around all of the OT assets that are associated. So it's a differentiator for us because it's yet another vulnerability that companies need to get their arms around. We're providing the ability for companies to get visibility into those vulnerabilities in a really effective way within Tenable One. And so we're seeing some really, really nice traction there.
I want to touch on margins a little bit. 3Q is, I think, a pretty good EPS beat, 23% operating margin. Free cash flow is continuing to look nice despite what you called out around on the billing side. Just maybe talk about kind of your visibility there. And then just broadly, how you're thinking about kind of the trade-off of continued margin expansion versus trying to invest in a lot of these pretty fast growth areas across cloud and AI and OT.
Yes. Our margin expansion is maybe the least appreciated part of our story actually. We had -- in Q3 '25, our op margin was up 350 basis points year-on-year. And that is with an 18% growth in R&D. So pretty incredible growth investment -- reinvestment into the product, but getting much more efficient on sales and marketing and a little bit so in G&A as well. That was just for the quarter. But even when you look year-to-date through Q3, still up more than 200 basis points. So pretty confident in our ability to continue to expand margins. The other thing I would add is that's on top of absorbing a couple of acquisitions that we saw that are going to be impacting OpEx, right? So overall, I feel really good about our ability to continue to expand margins, and that's something that we're focused on.
Maybe to double-click on the sales and marketing efficiency aspect of that. Are there -- is there more room there to eke out efficiency? Is it like you look out into next year and like there's a desire to kind of grow headcount and improve capacity? Like how do you think about that?
Yes. So when you sort of double-click on where are we going to get more margin, the place we know we're going to continue to invest is in product development with -- and in particular, in the platform. So we're doing a lot of that now. What we're able to do, though, is because we switched from what had historically been a GM sort of a model with respect to acquisitions that we had in product categories. We've moved now to flatten that and have folks that are focused on the platform, still within their expertise and the domains that are within the platform, but within the platform, importantly, which has allowed us to reduce and get more efficient while still pouring investment into development. So that's really important. All that really means is a lot of the investment in R&D, we're going to be able to self-fund. And so R&D will continue to grow. But underneath the surface, it's growing even more than you would imagine. So that's important. Every other line, we're going to be able to get some efficiency from. So gross margin is going to tick up a little bit. Sales and marketing, we can continue to get more efficient on. G&A, we can get more efficient on. When we think about sales and marketing, we're a very channel-focused company, and we will continue to be. We can leverage the channel more to become even more efficient. And so what that means is you're basically going to be able to get more out of your [ quota-carrying ] sales reps. And the efficiency essentially goes up and the effectiveness of each sales rep is going to go up. And the sales and marketing as a percentage of revenue is going to continue to tick down a little bit.
Yes. Makes sense. And then maybe you mentioned R&D and product. Maybe talk about kind of the principles behind that. I mean you have all these different growth areas. How do you think about kind of dividing your R&D resources? And where does kind of continued M&A fit into that category? You've been fairly acquisitive over the past couple of years, tucking pieces into the platform. Are you at a point now where you feel like there's enough breadth of Tenable One? Or are there potential future areas where you can continue to expand?
Yes. I mean -- so we have been pretty acquisitive in the past. And I think we continue to be open-minded, right? So if we saw a company that had a particular piece of technology that we thought filled the gap and it made sense, then sure, we would do that. Having said that, I think we have what we need for the most part here. And at this point, we're concentrating on executing. So let's take what we've got, make sure that we can make it super effective. We've got a relatively new Chief Product Officer, who's come on board, is doing a lot of really great things. We're going to lean into that. And again, sure, something came along that we thought we needed to have, great, we have it. But I think the chances for some type of a large transformational M&A is probably fairly low.
Yes. maybe 2 last ones. Just any broad level thoughts about the demand environment? I think there's -- on one side of the page, a pretty healthy view that concerns around the AI threat landscape are going to continue to fund cybersecurity budgets. But you also hear about budget tightness and procurement still being difficult. How do you think about kind of customer budget, security budgets into 2026 at a high level?
Yes. I'll answer and then I want Erin to answer, too. But we're seeing really positive signs from pipeline. That's the way that I think about it is, what's our level of opportunity and pipeline look like, and we're still -- we're seeing really, really healthy pipeline. Cybersecurity continues to be a focus for companies and rightfully so. So overall, feeling pretty good.
Yes. I think it's key to be able to take advantage of the opportunities that are in front of you or those that you know are pain points for your customers, which is why we've really innovated on the AI side, the cloud side, Tenable One, exposure management as a whole to be able to take our own share of that exposure management market as it starts to accelerate. And I think beyond that, one of the things that we had seen over the past couple of years is new business was harder to transact. And one of the things that we're really focused on, as we talked about a couple of times, is getting our existing base on to Tenable One. So not only landing new there, but also getting our current customers on there and being able to expand with them. it can be pretty sticky once you get a customer there. So we also see a really good expansion opportunity moving forward with the same product.
Yes. Cool. Last question for you, Matt, because you're relatively new to the story, what was one thing that attracted you to Tenable? And now being in the seat for a little bit, what's one thing that surprised you?
Yes. What attracted me initially is still what attracts me today, which is good. I get -- I'm now I'm mindful of 30 seconds. I get super excited about exposure management as a space. I believe in it. I think it's the best way to do cybersecurity. And I think companies are moving in that direction. Once you're there, there's no doubt in my mind that Tenable is best positioned to capitalize on that market. And it's not just us saying that, it's IDC and Forrester and Gartner, all of them have us upper right. That, to me, gives me a ton of confidence and excitement about the future. So I love that. That's kind of piece number one. Piece number 2 is, we've got a super competitive management team that is focused on executing. And I love being part of that. So yes, very excited.
Cool. Well, thank you for joining for a great conversation. And thank you all for listening in.
Thank you.
Tenable Holdings, Inc. — Q3 2025 Earnings Call
1. Management Discussion
Greetings, and welcome to the Tenable Q3 2025 Earnings Conference Call. [Operator Instructions] As a reminder, this conference is being recorded. It is now my pleasure to introduce your host, Erin Karney, Vice President, Investor Relations. Thank you. You may begin.
Thank you, operator, and thank you all for joining us on today's conference call to discuss Tenable's third quarter 2025 financial results. With me on the call today are Co-Chief Executive Officer; Steve Vintz and Mark Thurmond; and Chief Financial Officer, Matt Brown.
Prior to this call, we issued a press release announcing our financial results for the quarter. You can find the press release on our IR website at tenable.com.
We will make forward-looking statements during the course of this call, including statements relating to our guidance and expectations for the fourth quarter and full year 2025 and growth and drivers in our business, changes in the threat landscape in the security industry and anticipated shift towards preemptive security approaches, our competitive position in the market, growth in customer demand for and adoption of our solutions, including Tenable One, our exposure management platform, our ability to expand integrations with third-party tools and data sources and grow our ecosystem, planned innovation, research and development investments and new product services and initiatives and our expectations regarding long-term profitability and free cash flow.
These forward-looking statements involve risks and uncertainties, some of which are beyond our control, which could cause actual results to differ materially from those anticipated by these statements. You should not rely upon forward-looking statements as a prediction of future events. Forward-looking statements represent our beliefs and assumptions only as of today and should not be considered representative of our views as of any subsequent date and we disclaim any obligation to update any forward-looking statements or outlook.
For a further discussion of the material risks and other important factors that could affect our actual results, please refer to those contained in our most recent annual report on Form 10-K and subsequent reports that we file with the SEC. In addition, all of the financial results we'll discuss today are non-GAAP financial measures with the exception of revenue.
These non-GAAP financial measures are in addition to and not a substitute for or superior to measures of financial performance prepared in accordance with GAAP. There are a number of limitations related to the use of these non-GAAP financial measures versus their closest GAAP equivalent. Our press release includes GAAP to non-GAAP reconciliations for these measures.
I'll now turn the call over to Steve.
Thanks, Erin. Before we get started, I want to welcome Matt Brown to the Tenable team. Matt comes with tremendous experience and his ground running since he joined us in August. With that, let's get into the quarter.
In Q3, we exceeded all of our guidance metrics delivering 11% year-over-year revenue growth and 23% operating margin. We continue to see strong growth from Tenable One, our exposure management platform, which represented approximately 40% of new business during the quarter. We added 437 new enterprise platform customers in the quarter, a 13% increase compared to Q3 of 2024. Notably, half of all those customers are landing with exposure solutions with strong momentum globally.
We believe our strong new platform traction reflects a fundamental shift in cybersecurity away from detection and response technologies and more toward a more preventative and preemptive approach. The reactive approach to cyber is where the tools, the budgets, compliance priorities have lived for many years, simply trying to detect breaches. In fact, more than 95% of all cyber security spend today is on post-breach technologies. So consequently, less than 5% is spent on preemptive security.
Now the good news here is that, that mix is expected to change significantly over the ensuing years, and we're starting to see signs of that shift with Tenable One. The obvious question is why is this happening now? The short answer is AI. AI is dramatically reshaping the threat landscape as attacks have become faster, more automated and more sophisticated exposing the limits of traditional reactive defenses. The takeaway here is that it's no longer just about firefighting, it's about fireproofing and exposure management is helping customers make that shift.
Market-leading exposure management starts with unified visibility, but it's more than just seeing assets, domains and systems across your environment. It demands intelligence, context, and the ability to mobilize that insight into action. It's not just about knowing that vulnerability exists, but understanding that it's on a critical asset that is actively exploited and sitting on a direct attack path to your crown jewels. It's also about using AI, not simply to find flaws but to anticipate how an adversary may move through your environment and to see your organization the way an attacker does and moreover, to mobilize before attackers do.
We believe Tenable One is uniquely positioned to win in this next phase of security in this new AI world, given our roots in our strategic direction. Our foundation in vulnerability management gives us the data the scale and credibility to lead gift toward exposure management. And we're building on that strength with focused investment and innovation. Notably, R&D is up over 20% year-to-date, reflecting significant investments in Tenable One that unified visibility, insight and action across the full attack surface.
In Q3, we launched Tenable AI Exposure, leveraging technology from APAC to Gio's visibility into and control over the risk associated with generative AI. The solution helps organizations discover AI usage across their environment, understand how it impacts their attack surface and identify potential exposure stemming from AI-enabled applications, code and user behavior. It is a powerful example of how we continue to extend Tenable One to stay ahead of emerging threats.
We also surpassed 300 validated integrations in the Tenable One platform, underscoring our progress in creating the most open and the most interconnected exposure management platform in the market. This open ecosystem is a key differentiator. These integrations go beyond technical connectivity to unify visibility insight across tools and data and teams. By breaking down silos between vulnerability management, biosecurity, identity, OT operations and the broader ecosystem of third-party tools, we are advancing how customers unify data apply contacts and orchestrate faster in a more coordinated way. As we continue advancing this vision, we are building a platform where connectivity drives action, where customers don't just see risk, they can act on it.
Finally, we advanced our vulnerability priority rating across different domains allowing for higher levels of smarter orchestration and mobilization for exposure management. This gives organizations even sharper precision in determining which risk demand immediate action. Most enterprises are flooded with findings and the challenge is not just seen vulnerabilities, but knowing which ones matter by combining real-world threat intelligence contextualized asset data and AI-driven analytics. Our enhanced VPR helps customers focus their remediation efforts on the exposures that matter most.
We believe that these innovations are cross visibility, insight and action, combined with our growing open integration ecosystem and our focused investment on ramp secured an R&D are what differentiate Tenable among the many vendors now laying claim to the exposure management space. And our core to wide customers are turning to us.
I'd now like to turn the call over to Mark to discuss how customers and the industry are responding to the shift to exposure management and how we are leading them through this change.
Thanks, Steve. We believe Tenable is leading the transformation to exposure management, and the industry is taking notice. We are recognized as a leader in exposure management by 2 of the industry's top analyst firms during Q3. In July, Tenable was named a leader in the Forrester Wave for unified vulnerability management solutions. In August, we were recognized as a leader in the IDC MarketScape for exposure management platforms. And in September, IDC again reported Tenable ranked #1 in its latest market share report.
As Steve mentioned, one of our defining strengths and what signs through in every customer story is Tenable one's ability to unify visibility, insight and action across the modern attack surface. We're now extending that power to include both tenable native and third-party data, giving customers an even more complete view of risk. But exposure management is more than a technology. It's a journey that requires a new mindset. We're listening closely to our customers by helping them chart that path step by step.
Our Exposure Management Leadership Council and our exposure management maturity model have become critical guides in that journey. The Leadership Council, which launched this quarter brings together some of the most forward-thinking CISOs and security leaders to share insights and best practices from their own exposure management transformations. Their feedback helped shape our platform road map and ensures we're focused on solving the challenges that matter most.
Our new Exposure Management Maturity Model gives organizations a framework to assess where they are today and what it will take to advance in their exposure management journey. It helps them measure progress identify gaps and prioritize the investments that will have the greatest impact. Together, our Exposure Management Leadership Council and Maturity Model are helping customers turn exposure management from an abstract goal into a disciplined strategy for the future. Through these initiatives, we're helping customers evolve their approach, from managing vulnerabilities to embracing a true preemptive security mindset.
It's how they move from reacting to risk to staying ahead of it. That's what Tenable One is designed to deliver the clarity, intelligence and context to see threats before they strike. As Steve highlighted, we're leading the way with the most comprehensive exposure management platform in the market, helping our customers build stronger, smarter defenses for the AI era.
Let me give you some real-world examples from the quarter. First, we captured a major new logo with a global commercial real estate investment services firm, displacing the top cloud security provider and an incumbent vulnerability management player to consolidate onto the Tenable One platform. Like many large enterprises, this constipates growing complexity of a hybrid environment with assets spread across on-prem infrastructure, multiple cloud providers and third-party systems.
Tenable One was selected for its superior technical capabilities across cloud security and vulnerability management. It was also chosen for its ability to unify data and context across their entire ecosystem. This consolidation immediately filled critical visibility gaps streamline operations and reduce the cost and complexity of managing risk across a fragmented landscape.
We also had another major win this quarter with a national electric utility provider in EMEA to accelerate their critical infrastructure transformation. Like many in the energy sector, this organization is navigating the growing convergence of IT and OT environments with operational technology increasingly coming under the responsibility of the CECL. They selected Tenable as their exposure management partner for our ability to integrate complex technical requirements and deliver a cohesive, scalable OT security framework across their national distribution network. By unifying visibility and context across IT and OT assets, Tenable is helping them eliminate silos and protecting critical infrastructure at a national scale.
We also secured a 6-figure expansion with a leading technology provider serving the public sector, converting them from our stand-alone crowd product onto the Tenable One platform. This is a strategic shift for the customer, driven by their need to unify visibility and control across a complex environment supporting sensitive government workloads. This multiyear agreement enables them to consolidate onto Tenable One over time; simplifying operations, reducing vendors fall and strengthening compliance across both commercial and public sector deployments.
These customer wins reinforce that our strategy is absolutely working. We are earning larger, longer-term commitments by delivering strategic value and deeper integration into our customer environments. At the same time, we believe these wins reflect the broader industry shift that is now underway from reactive post-breach defense to preemptive security. As this shift accelerates, we believe Tenable is exceptionally well positioned for sustainable growth. with exposure management becoming the foundation of modern cybersecurity programs worldwide.
With that, I'll turn the call back over to Matt to dive deeper into the results for the quarter.
Thanks, Mark. I want to thank everyone for the warm welcome, and I'm really excited to be here I look forward to seeing new and familiar faces over the next couple of months. With that, I'll jump into the results for the quarter.
We're encouraged by the strong third quarter, exceeding the high end of the range on every metric we guided to for the quarter. Revenue was $252.4 million, representing growth of 11.2% year-over-year. The year-over-year growth in revenue for the quarter as well as outperformance relative to guidance was underpinned by a solid foundation of renewal business strong tenable on adoption and better-than-expected contribution from professional services.
Our percentage of recurring revenue remained high at 95% this quarter. We're continuing to see solid momentum in Tenable One as customers are increasingly turning to our platform to bolster their preemptive security programs. The strength in new platform growth in the quarter drove calculated current billings or CCB, to $267.5 million, a year-over-year increase of 7.7%, while short-term remaining purchase obligations or CRPO, grew 12.9%. These measures are beginning to diverge due to changes in upfront billings patterns and increasing contract durations, which we expect to persist in the midterm.
Net dollar expansion rate was in line with expectations at 106%. Non-GAAP gross margin was 81.6% for the quarter, an increase from 81.4% in Q3 2024. We're encouraged by our ability to slowly but steadily increase non-GAAP gross profit year-over-year, both on a quarter and year-to-date basis. Year-to-date non-GAAP gross margin was 81.8% compared to 81.3% for the 9 months ended in the prior year.
Non-GAAP income from operations was $58.9 million or 23.3% of revenue compared to $45 million or 19.8% of revenue in Q3 2024. Although we continue to make targeted investments during the quarter, including growth of more than 18% in research and development-related expenses year-over-year, we were able to drive continued leverage in the business as a whole. Our investment in innovation is a result of our focus on delivering the most comprehensive exposure management platform to our customers. On a year-to-date basis, non-GAAP income from operations grew to $155.3 million or 21.0% of revenue, compared to $124.8 million or 18.8% of revenue in the comparable period last year.
Non-GAAP earnings per share for the quarter was $0.42, compared to $0.32 in Q3 2024, an increase of 31.3%, reflecting the increase in profitability, combined with a decrease in diluted shares outstanding.
Turning to the balance sheet. Cash and short-term investments totaled $383.6 million. We generated $58.5 million of unlevered free cash flow during the quarter. compared to $60.8 million in Q3 2024. This brings the year-to-date unlevered free cash flow to $189.6 million. a year-over-year increase of 24.7%, putting our annual guide well within reach.
During the third quarter, we repurchased 2 million shares for $60 million. In total, we have now repurchased 8.3 million shares for $300 million since November 2023 and have $250 million of repurchase authorization remaining. We intend to continue to repurchase shares, which we believe is an effective use of capital.
Turning to the financial outlook for the remainder of the year. With the results of the third quarter behind us, we've gained incremental visibility into the full year. And as a result, we are raising our full year guidance at the midpoint across most of our guided metrics. Specifically, we are increasing our full year guidance at the midpoint for CCB and now expect a range of $1.040 to $1.048 billion. representing a year-over-year increase of 7.7% at the midpoint.
We expect revenue for the fourth quarter to be in a range of $249.1 million to $253.1 million, representing a year-over-year increase of 6.5% at the midpoint. For full year 2025, we are raising our revenue guidance range to $988 million to $992 million, representing a year-over-year increase of 10.0% at the midpoint.
We expect non-GAAP income from operations for the fourth quarter to be in the range of $55.7 million to $59.7 million or 23.0% of revenue at the midpoint. For full year 2025, we are raising our non-GAAP operating income guidance at the midpoint and now expect a range of $211 million to $215 million, or 21.5% of revenue at the midpoint, representing a year-over-year increase of 100 basis points. We remain committed to balancing top line growth with a steady increase in profitability.
We expect non-GAAP net income for the fourth quarter to be in the range of $47.9 million to $51.9 million, representing a year-over-year decrease of 1.6% at the midpoint. For full year 2025, we are raising our non-GAAP net income guidance at the midpoint and now expect a range of $185 million to $189 million. representing year-over-year growth of 17.9% at the midpoint.
We expect non-GAAP earnings per share for the fourth quarter to be in the range of $0.39 to $0.43 and flat at the midpoint compared to Q4 2024. For full year 2025, we are raising our non-GAAP earnings per share guidance to $1.51 to $1.54, representing year-over-year growth of 18.2% at the midpoint.
In closing, we'd like to thank the entire Tenable team and our customers and partners for a great result. We're very pleased with the steady execution the team has delivered this quarter and our incremental optimism for the rest of the year, as reflected in the increased guidance ranges we've provided.
Mark, Steve and I thank you all for joining and we look forward to seeing you at the UBS and Barclays conferences in the coming weeks. We are happy to open the call up for questions. Operator?
[Operator Instructions] The first question is from Saket Kalia from Barclays.
2. Question Answer
Okay. Great. And welcome, Matt. I'll just keep it to 1 question. Steve and Mark, maybe for you, U.S. Federal is, of course, a really important vertical for Tenable. Can you just talk a little bit about how that performed this quarter? And given the current situation, maybe give us a little historical context of how the business has performed around prior shutdowns as we think about any potential impact going into Q4. Does that makes sense?
It does, Saket, and thank you for your question. This is Steve. We have major market leadership in public sector and U.S. federal in particular, across a wide range of 3-letter federal agencies, spanning civilian, defense and intel. And CRs are not new nor are government shutdowns. We have seen that before, and we've demonstrated an ability to execute in these environments, and we're particularly pleased with the results this quarter. Public sector, new federal in-line expectations, which is very notable given the seasonally high mix of U.S. federal business. So overall, a good result for us for the quarter.
Next question is from Brian Essex from JPMorgan. .
And Matt, congratulations on the new role for me as well. Looking forward to working with you again. And nice consistency out of the gates as well. So I certainly appreciate that. I guess maybe to follow on with Saket's question for you, Matt. I was down to D.C. last week in that basis, and it was clear that things were going to get incrementally uglier this week as agencies run out of money, particularly for central employees where CISA is focused. But would love to hear from your perspective, given that, I guess, deceleration that's baked into the 4Q, like just basically what's implied by your full year guide, the deceleration of revenue in the 4Q. What are you contemplating within guidance and what kind of scenarios might lead for upside to your expectations for the quarter and for the year?
Yes. I think the first thing to note is just the steady execution that we had in Q3 under the current environment of uncertainty. And keeping in mind, Q3 is a higher proportion of Fed for us relative to other quarters in the year. So with that backdrop, we look ahead to Q4, which seasonally is a smaller Fed quarter for us. and see relatively minimal exposure. Now of course, there's a couple of million dollars that could be at play here or there. But generally, we feel very positive about the pipeline that we see renewals continue to come in very strong. We think we've got good line of sight. So we think we're not especially exposed in this fourth quarter.
Got it. Maybe if I just sneak in a quick follow-up for Mark. Just with regard to the impact of the expiration of CISA 2015 and what that might have on CVE reporting. Any impact that you might envision for the core VM portion of your business?
Yes. Right now, based on feedback with customers and talking to a bunch of partners, and obviously, our employee base, we're not really projected to see any type of negative impact right now. as it plays out, we'll obviously be monitoring it closely. But right now, based on a lot of our conversations and contacts and relationships we've got going on in the federal government, we're not really anticipating any significant downside there.
The next question is from Mike Cikos from Needham & Co.
Great. And congratulations to you, Matt, looking forward to working together. Before I ask my second question, which is more tied to the billings, I just wanted to ask, Matt, since this is your first earnings call here with the firm, can you help us think about if there were any changes to guidance philosophy or what you're bringing to the finance function here now that you got a couple of months in the seat?
Yes. I think generally, no substantial changes to our approach to guidance. I will say I was just extremely pleased to come in and see a very high-functioning team not just within finance, but across the entire organization. I feel like we're really focused on the right things and the team is all rowing together. So I would say no major shifts in the way that we're approaching guidance.
Okay. And then the follow-up is again on that billing side. Just trying to get a better sense of the different puts and takes here, right? If we have the call it, $3 million-ish of upside this quarter versus where people were expected. We're nudging up the low end of the guide by $2 million. You guys are talking about increased visibility into year-end. Can you just discuss how you guys I thought about putting out this range and some of the different puts and takes there as it pertains to the visibility you're talking to?
Sure. I think the very brief takeaway is, as we sit here today, we're feeling incrementally more positive about the year than we were 3 months ago. That's as a result of a strong Q3, but also visibility into Q4. So it represents a small guidance increase at the midpoint for CCB of $1million but that slows down, too. So taking up the guidance to revenue and taking up the guidance in op income, all of those things are things that we're happy we're able to do, which is as a result of us feeling better about the year on balance.
The next question is from Rob Owens from Piper Sandler.
Great. And Steve, really enjoyed the discussion upfront on fireproofing versus firefighting in terms of where things are going. To that end, if I look at your enterprise adds versus your 100,000 ACV customers, maybe you can parse what's going on there? And are you just -- are you seeing more new customer additions upfront and you're starting to see just velocity increase on that front as some of these trends are changing? And if that's the case, maybe you could add some color around the 100,000 ACV customers?
Sure. Well, as you noted, like our mix of business can change from quarter-to-quarter. This quarter has higher concentrations with U.S. Federal. And as we mentioned, we were very pleased with the results there. We're also very pleased with a strong quarter for new business for us. We added 437 new enterprise platform customers, which was one of our strongest quarters, I would say, to date. And look, on a year-to-date basis, too, new lands have been strong.
We're also, as we've talked about on the prior quarters is that we've demonstrated an ability with our exposure management platform to transact larger deals, we're delivering incremental value to customers, transaction sizes and deal sizes are getting larger. On average, anywhere from 50% to 90% plus in comparison to stand-alone VM. So overall, we're pleased with the velocity of lands this quarter. We're pleased with our ability to continue to do larger deals. And there's always some interplay from one quarter to the other.
And I think it really speaks to the continued momentum of the platform and the ability to help customers sort through all of this fragmented visibility, this overwhelming noise and alerts and all this manual remediation to help them unify visibility, insights and action to reduce risk. And so it's certainly something that we're pleased to see with the continued traction of the platform.
The next question is from Meta Marshall from Morgan Stanley.
Maybe a couple for me. Just first, in terms of noted commentary on the OT market. Just wanted to know if there's efforts underway kind of either with R&D or go-to-market to kind of better take advantage of some of those opportunities? And then second, just kind of noting the 18% increase in R&D just in terms of kind of the answer to the previous question of trying to simplify kind of environment for customers. Just what are some of the other investments, whether that's professional services or go-to-market? Are you making to kind of help simplify the offering for customers?
Yes. Great question. I'll take the first part on the OT market and what we're seeing, and then I'll pass it over to Steve to talk about some of the investments from a research perspective. So we are seeing a dynamic in the market and it's been happening really all year, but it's happening, I think, at a bit of a faster pace where you're seeing this convergence of the OT market and the CISOs getting a lot more responsibility and visibility over those OT assets.
And one of the deals that we referenced in the earnings announcement was that consolidation story. So we're seeing a lot of not only our installed base customers wanting to look at and be able to ingest those OT assets into Tenable One but also new customers where they're saying, we don't want to have 2 distinct products and technologies, one looking at traditional IT assets and then another one looking at OT assets. So you're seeing that convergence and it is speeding up.
When you also look at some of the market dynamics around the AI data center build-out, that is a big area for us. We're seeing a lot of demand when companies and organizations are building out data centers. they need operational technology to monitor all of those different asset types. And we're starting to see significant pipeline growth in closing deals in that area. So we were very pleased and have been pleased all year with our OT performance, and we will continue to focus in on it from a go-to-market perspective.
I'll pass it over to Steve now to talk about some of the R&D questions.
Yes. With regard to R&D and the investments we're making, they're paired with increased confidence in our ability to execute in this big market that we call exposure management. And it's really centered around 3 things: #1 is the ability to unify visibility, and in particular, in just data from other security providers so we can help customers see any asset, whether it's on their factory floor, in their network or even in their cloud environment. And then moreover, is the ability to normalize and dedupe all of that to tie it to mobilization and orchestration on the back end so we can help customers reduce risk.
And that's -- and then last, I would say, and really important is helping customers secure their AI attack surface and leveraging AI in the way where we're able to deliver greater insights to customers. and AI adoption of applications has dramatically expanded the attack surface and certainly made us all more successful to exploit. And Tenable plays a really big role there. as we're able to discover all AI applications, whether they're internally developed or even shadow AI. And then we're able to assess those for risk, including determining vulnerabilities and scans.
And now with AI Exposure, we can go and inspect and control at the prompt level, the AI applications that enterprise use the most. So we have a lot of traction with AI, pleased with the innovation we've done to date, but there's certainly a lot more to do. And we believe principally the real winners in this new AI world will be companies that can assess a wide range of domains, ingest data from other security providers and then really combine all that proprietary exposure data with AI to anticipate tax, not simply to respond to them. And that's a foundational change in the security market, shifting away from detect and response more towards pretty active and preventative approaches.
The next question is from Jonathan Ho from William Blair.
Congratulations on the strong results. Can you give us a sense of what percentage of your total base is now on Tenable One? And it seems to me like there would be some opportunity to upsell more into the base once they've adopted the platform. So can you also talk about maybe the potential for uplift going forward on the platform?
Yes. As you know, we have roughly 40,000 customers, 3,000 plus, should I say, and approximately, we'll call it, 18,000 use one of our enterprise offerings. And of those 3,000-plus are using Tenable One. So we've got good traction to date. It's 40% of our total new sales. And so there's a significant opportunity not only to expand within of the existing customers to have adopted Tenable One, but moreover, to continue to see further traction within our customer base.
The next question is from Joseph Gallo from Jefferies.
And Matt, congrats on the new role. Looking forward to working together. It was great to hear the exposure management momentum. As we start to get ready for next year, in your combos with customers, where is the prioritization for exposure management in their budgets? And then historically, I think you gave some sense of following your billings in 3Q. Just any commentary on what billings can look like in 2016 or confidence in sustaining the current levels would be helpful.
I'll take down of the budget question from the customer perspective, from exposure management. I think 1 of the bright spots that we're really starting to see is we talked about all of the different analysts that are starting to cover the exposure management category. And coming out as the leader and the #1 player in that category has given us lots of visibility, especially at the CECL level. And so now when we're sitting down with customers, we're not actually having to educate a lot of the CISOs, what exposure management is and how it is so different from vulnerability management. They're hearing about it, they're seeing it.
And so you're starting to see budgets being allocated that way. You're starting to see budgets in regard to consolidation, which is really one of the biggest motions we have in regard to going after and talking about exposure management and justifying it is really looking at that consolidation play. So that momentum is there, and it's gaining traction, and that continues to play out in the market, not just with customers, but we're also seeing our resellers and our partner community around the globe, start to build out exposure management practices and gain visibility there.
Yes. And I can answer your second question. So we're really happy about is that there is this move, in particular, the Tenable One, roughly 1/3 of our business now is Tenable One. Increasingly, we're seeing new customers adopting 101. That's exactly what we're focused on. And we think that sets us up well for the long term in going and really capitalizing on this exposure management environment. With respect to 2026, we're really focused on 2025 and closing out and continuing to execute there. And it's just too early to talk about 2026 at this point. But importantly, we feel like we're doing all the right things to put us in the right spot.
The next question is from Patrick Colville from Scotiabank.
This is [ Joe Vandrick ] on for Patrick Colville. Steve, I think you mentioned earlier that there's a lot more to do on AI innovation. So I was hoping you could expand a bit more on that maybe talk about how you're thinking about the road map, you're planning and how you're planning to add these new AI security products or solutions, would it be organically or through M&A?
I think we would certainly consider both and successful companies pull both levers here. And I think it's centered around the fact that the threat environment that we're experiencing today is unlike anything we've seen before. adversaries are moving with incredible speed, scale, sophistication and leveraging LLM and AI to create flawless, hyperrealistic fishing e-mails that bypass both human especially and traditional e-mail filters. We're also seeing executive coming executive faces and voices for socially engineered attacks.
So certainly, bad actors are moving with incredible speed. We're seeing the weaponization of AI, which is resulting in the discovery of more vulnerabilities. And perhaps more concerning is not just more vulnerabilities in this all new digital world of AI, but it's the exploitation of those have become much faster, meantime for vulnerability discovery to vulnerability exploitation has compressed dramatically. So this necessitates a completely new approach to security, to sense on every dollar in cybersecurity spend on detect and respond technologies.
Consequently, 4% is on proactive security. Gartner estimates over the next 5 years that, that mix will change dramatically. And so we'll see a disproportionate amount of spend more towards proactive security. And the goal here is to move tenable, are well in this world is to evolve from not just providing visibility but to be able to correlate vulnerabilities with preps and exploit chatter with criticality of those assets. So we can highlight likely passive exploit so organizations can look at their enterprise to the lens of adversaries and they can identify attack paths that are most meaningful to them.
So exposure management is really at the epicenter of all of that. And it's a category that continues to grow and received recognition from IDC and some of the others that Mark talked about earlier, given our traction with exposure management and we're super excited about what's ahead for us.
The next question is from Roger Boyd from UBS.
You talked about the longer, more strategic deals, and it seems like that's been a consistent trend over the past couple of quarters. And clearly evident in the nice acceleration on ARPU on bookings this quarter. Can you just further quantify what you're seeing there, what you're doing there from a sales perspective? And with these longer contracts, what's the overlap with customers adopting Tenable One Exposure Management?
Yes, you bet. I mean it's a really phenomenal dynamic that we're seeing, right? The great part of this, and you see it in the RPO numbers, is we have customers not only new customers, but our installed base that want to get longer-term 3-year commitments, right? They're seeing the road map, they're seeing how we're evolving exposure management, right, how we're building the technology and building tenable on the platform. And when we are able to articulate that and explain from where we're headed, the customers are buying in and they're buying it aggressively and they're making long-term commitments.
And so we're very, very focused on the installed base that Steve identified, going after those 18,000 to 20,000 commercial and enterprise customers. anyone that's on VM, getting them upsold to Tenable One. That is our motion. We are driving that aggressively. And then for the new logos, one of the very cool things when we identified which is an extremely high number, 437 new logos in the quarter, a very significant portion of those customers were Tenable One, right? So that is a pretty cool trend and we'll be able to then upsell those customers over time. And so I think when you see customers willing to sign up for long-term contracts, when they understand where you're headed and you're truly building an enterprise scale platform, that's an extremely positive sign for us.
The next question is from Joshua Tilton from Wolfe Research.
And Matt, it's good to hear your voice again. Two for me. The first one, hopefully, kind of easy, more of a clarification. Is there any way you can just help us understand what the inorganic contribution to billings was in the quarter? And how we should think about the inorganic contribution to billings for the full year? And then I have a follow-up.
Yes. Very insignificant, Josh, for both the quarter and the year.
Okay. Very helpful. And then maybe just a follow-up, and I prefaced the question with not here to hold you to any numbers. But I think part of what was great about you in your previous role is you had a pretty predictable playbook on how you wanted the financial profile of the business to kind of unfold on an annual basis. And I think investors really appreciated that. So again, not here looking for numbers, but maybe how do you think about your ability to leverage some of the playbook from your previous role to kind of deliver or help deliver a more consistent message around the durability of the financial profile for Tenable going forward?
Oh man, that is quite a setup. So I mean, here's the way that I look at it. Tenable has a really incredible business and is getting only better and more strategic with our move to exposure management. So when you look at the underlying fundamentals and 95% of revenue is subscription and recurring, there is an opportunity to make sure that we can continue to grow top line while also continue to add profitability. And I think there are some spots in the P&L, where we've done that already over the past couple of years, but we'll continue to do that going forward into the future where we can continue to get more leverage out of the business. So I think there's a lot of opportunity to do some of the same things that I've done before, yes.
The next question is from Adam Borg from Stifel.
Awesome. Of course, welcome and congrats to Matt. Maybe just on the macro, we talked a lot about the Fed. It's great to see in line with expectations. Any other color you could share just demand environment overall, be it at the upper end of the market, the mid-market geography vertical? Any other color would be really great.
No. I think demand was pretty even really across the board. We talked about the seasonally high mix in U.S. Federal, and we were pleased with the results there. I talked about strength in new land and new logos, 437. And obviously, the continued traction with the platform. And I think that's really the highlight of the quarter here. The one takeaway is that the ability to close platform sales, the ability to assess a wide range of domains, the ability to unify action insight and deliver increased visibility from both the things that we assessed, assets that we assess as well as ingest data from others is resonating. It's a big market opportunity. we believe we're the clear leader there, and it's good to see the validation and recognition from our customers.
The next question is from Jonathan Ruykhuver from Cantor.
Yes. I'm curious to hear how conversations might be changing with the pending with Google deal, how much of a concern is multi-cloud support. And then just broadly looking at Tenable cloud security, how is it performing? I mean it does look like a market that is increasingly competitive but when you look at your positioning relative to the broader exposure management opportunity, it seems like that could be a differentiating factor. So maybe you could just elaborate on those 2 questions.
Yes, you bet. No, absolutely. And yes, it is definitely an active conversation without a doubt, right? So a lot of CISOs are really looking at it. And we mentioned this on a couple of previous calls once the announcement first out there, but you're really starting to see it pick up because now it's becoming a reality. Now customers are getting a true sense of how they're going to come together within Google. And we are doing a significant amount of presentations, demonstrations and POVs with accounts. When we look at Q3, we had a bunch of deals that we were able to go in and actually do displacements. One of the deals we highlighted on the call was a displacement of not just a Wiz account, but also an incumbent VM player.
So to the point that you brought up on the question, this consolidation story around a platform that centers around exposure management right, being able to ingest multiple different assets into a hybrid platform, so both on-prem and in the cloud and in OT and in identity in other areas that absolutely resonates. And so we are -- I use the term getting invited to a significant amount of more dances and we continue -- and we will continue to expect that to happen throughout Q4 and going into next year. So we are very, very optimistic about our cloud business centered around Tenable One.
The next question is from Todd Weller from Stephens.
In the past, we've talked about kind of the growth equation to drive top line acceleration. Wanted to see if you could just kind of revisit that and give us an update, continued momentum with Tenable One and exposure management. is great, and that's much higher growth and then you have like the traditional VM piece. So how are you thinking about those components? How you're thinking about the VM kind of sustainable growth and is it really just a math equation and time of the exposure piece continuing to get bigger? Or is there anything that can happen on the VM side that could drive kind of improved growth there?
Yes. I think you've hit on the main components there. So we're 100% focused on Tenable One and driving customers to Tenable One. And our belief is that once they're there, they will continue to expand. So whether they're doing pretty much as core VM there today, we're seeing opportunities where they then expand within Tenable One to take on more EM type activities. So that's encouraging.
When you zoom out from Tenable One and you look just at VM versus EM, EM is obviously today a smaller part of our business, but it is growing much faster. So our expectation is that over time, while VM is a stable grower, EM is growing much faster, and that helps drive that growth algorithm overall.
The next question is from Junaid Siddiqui from Truist.
Great. You highlighted now supporting over 300 validated integrations. How are these integrations contributing to deal velocity and deal sizes?
Yes. Well, the -- it's been around this belief that no one security company can secure all domains all assets across the attack surface. We have -- today, it's a tack surface, is us prowling the ecosystem of traditional IT devices, it's cloud environments, identities, both human and machine as well as OT industrial control systems that power on of critical infrastructure. So over the years, the attack surface has expanded, right? It's no longer about securing servers in the data center or laptops in an office.
And so we think exposure management it's really turned around this belief of any assessing things that are foundational, like traditional IT devices like cloud environments, both pre and post production like OT assets and even looking at the important context around the identities of those, but also the ability to ingest data from others. We believe in an open platform, we believe we should be able to partner for this kind of data to deliver this kind of insight to customers, all center around this notion of unified visibility and insight and action.
Those are foundations to what we do. We think the connections matter. We think it gives us certainly more breadth, the ability to deliver more insights and more importantly, the ability to help our customers mobilize and orchestrate fixes on the back end and correlate vulnerabilities with exploit chatter with asset criticality, that's really important to do that in a very cohesive way.
The next question is from Shrenik Kothari from Robert Baird.
Congrats, and welcome, Matt. Mark, you cited turn at 40% of new business, of course, improving ASPs and deal sizes. And it seems like the platform growth as percent of new business is covering in near that 40% mix. Just what do you think are going to be the biggest unlocks to further accelerate this platform as a percentage of new business? Are you thinking something along the lines of a pricing package and exploring something like flex? Are you also thinking more sort of field enablement and increased S&M investments? Just curious and then a follow-up for Matt.
Yes. So you highlighted a couple of great areas right there, right? And so those areas we're looking at. But I think one of the best things we've got in front of us is we've got the opportunity to expand in that installed base, right? So as Steve kind of highlighted the numbers, we've got phenomenal opportunity to go expand within our huge massive installed base. So that is like the #1 focus for us is getting that expansion.
When you then look at the innovation that we've done around third-party ingest, right, we're now seeing here in Q4 a bunch of quotes going out to Tenable One deals that have third-party asset types, right? So we'll be able to monetize that third-party asset type. So that will start taking off. We talked about our AI strategy and what we did with Apex and how we'll be able to start monetizing that in Q4 and especially going into 2026.
Now that is on the back of some of the things you highlighted, right? So obviously, evaluating pricing and packaging strategies and marketing strategies, those are all things that we're very much on top of. But there is very tangible specific things that we're doing today that to get the growth and the expansion within Tenable One, and we're going to continue to march down that road.
Great. Very helpful. And Matt, very quickly from your perspective in terms of what you have seen so far, like how do you plan to now kind of balance all the priorities that just laid out versus incremental operating leverage in terms of your strategy or your priorities? How should we expect 2026?
Yes. I think we expect to continue to both grow top line and add incremental margin. And so when we look at places on the P&L where we can expect to go get that margin it's a little bit like what you should have seen in this quarter's results actually, where you're going to get a little bit out of gross margin, you're going to get a little bit out of sales and marketing and G&A, and we are going to probably give a little bit back in R&D because we're continuing to invest in the platform. And we're going to -- there's going to be, obviously, no one quarter is going to be exactly like the next. We're going to continue to invest in sales capacity as well. But the point is as you grow revenue, you're able to just get a little bit more leverage.
The last question is from Gray Powell from BTIG.
Okay. Great. Thank you very much for working me in. Greatly appreciate it. A lot of good questions have been asked. Maybe I said one of my list that has not. What kind of traction are you seeing with the Apex acquisition and AI exposure? And I'm not sure if you said this, but how should we think about it impacting ASPs with Tenable One or potentially driving just incremental adoption of the platform?
Sure. So that's an acquisition that we announced, I think the last quarter, several months ago. And really the plan from an integration perspective was to natively build those capabilities in the platform. and then come to market with a more expansive AI offering, which we're pleased to see us do at Black Hat. So we did that over the summer. We brought to market AI exposure. And our exposure gives us the ability to not only discover AI applications and shadow AI, but now gives us to the ability to inspect at the prompt level usage of AI.
It is a foundational piece in our broader AI strategy, and the AI strategy is really centered around a couple of things. Number one, contextualized risk with which we've been doing for some time, and we continue to do and that's generate risk-based prioritization. That is really dynamic and constantly updated so AI acts really is this risk co-pilot. The second thing is really a journey that we've been on, which is autonomous remediation agents. And right now, we're able to integrate bidirectionally with the CMDBs and the ticketing systems. And the focus is really on generating tickets with precise remediation steps to orchestrate patch deployments and force configuration baselines.
But the goal here over the course of time is this continuous learning and adaptation and use AI as a means not only to deliver greater insight, but have customers benefit from this network effect to 40,000-plus customers at global telemetry that we've collected over the last 20 years to do safer auto remediation. And so we can not only not just respond to threats, but also anticipate them. So we're super excited about our place in this world, with AI, EM exposure management is taking on greater importance Obviously, we expect continued grow air and continued traction with the offering itself.
This concludes the question-and-answer session and today's teleconference. You may disconnect your lines at this time. Thank you for your participation.
Tenable Holdings, Inc. — Q3 2025 Earnings Call
Financial data from Tenable Holdings, Inc.
Revenue
Revenue is the sum of all sales generated by a company, e.g. for its products or services.
Revenue (TTM) metric explainedDirect Costs
Direct costs are the costs incurred directly in connection with the manufacture of the product or service.
Gross Profit
Gross Profit indicates how much of the revenue remains in the company after deducting direct production costs. If the percentage share of sales is calculated, this is referred to as the gross margin.
Gross Profit metric explainedSelling and Administrative Expenses
Selling, general and administrative expenses (SG&A) include all expenses for marketing and sales as well as the general administration of the company.
Research and Development Expense
Research and development costs (R&D) provide information on how much the company invests in the research and development of its products. The costs are particularly interesting as a percentage of revenue and in comparison to direct competitors.
EBITDA
EBITDA (Earnings Before Interest, Taxes, Depreciation and Amortization) is the company's earnings before interest, taxes, depreciation and amortization. The EBITDA margin is calculated as a percentage of sales.
Depreciation and Amortization
Depreciation represents reductions in the value of the company's assets (e.g. due to wear and tear on machinery).
EBIT (Operating Income)
EBIT (Earnings Before Interest and Taxes) is the company's profit before interest and taxes, also known as the operating income. The EBIT Margin is calculated as a percentage of sales at
.
Net Profit
Net Profit represents the profit or loss after deduction of all costs.
Net Profit metric explainedStocksGuide Premium
| Jun '26 |
+/-
%
|
||
| Revenue | 1,044 1,044 |
10%
10%
100%
|
|
| - Direct Costs | 229 229 |
10%
10%
22%
|
|
| Gross Profit | 814 814 |
10%
10%
78%
|
|
| - Selling and Administrative Expenses | 547 547 |
1%
1%
52%
|
|
| - Research and Development Expense | 224 224 |
10%
10%
21%
|
|
| EBITDA | 86 86 |
172%
172%
8%
|
|
| - Depreciation and Amortization | 42 42 |
10%
10%
4%
|
|
| EBIT (Operating Income) EBIT | 44 44 |
769%
769%
4%
|
|
| Net Profit | 6.74 6.74 |
115%
115%
1%
|
|
In millions USD.
Don't miss a Thing! We will send you all news about Tenable Holdings, Inc. directly to your mailbox free of charge.
If you wish, we will send you an e-mail every morning with news on stocks of your portfolios.
Tenable Holdings, Inc. Stock News
Company Profile
Tenable Holdings, Inc. engages in the development of security software solutions. It offers Cyber Exposure which is a discipline for managing and measuring cybersecurity risk in the digital era. Its products include tenable.io, tenable.sc, tenable.ot, and nessus professional. The firm delivers solutions in the field of application security, cloud security, compliance, energy, finance, healthcare, and retail. The company was founded by John C. Huffard, Jr. and Renaud M. Deraison in 2002 and is headquartered in Columbia, MD.
StocksGuide Premium
| Head office | United States |
| CEO | Mr. Vintz |
| Employees | 1,995 |
| Founded | 2002 |
| Website | www.tenable.com |


