
Qualys (NASDAQ:QLYS) executives said the company’s second-quarter performance reflected growing customer demand for vulnerability remediation, patch management and Enterprise TruRisk Management, or ETM, while positioning newer products as potential drivers of longer-term growth.
During an investor discussion, President and CEO Sumedh Thakar said the company remains focused on “profitable growth” through product innovation. He pointed to customer interest in remediation capabilities, including Patch Management and Qualys’ Eliminate offering, as a central factor in recent sales conversations.
ETM Adoption and Product Mix
Thakar said customers are using ETM to prioritize the vulnerabilities they need to address most urgently, while Patch Management and Eliminate support the remediation process. He said renewals and upsells during the quarter were larger than the company had anticipated at the beginning of the period, following customer discussions and increased interest in the company’s tools.
Chief Financial Officer Joo Mi Kim said ETM is expected to be Qualys’ primary growth engine in the near term, though she does not expect it to contribute materially to revenue immediately because the offering is still relatively new for customers.
Kim highlighted the net dollar expansion rate among customers that had ETM or CSAM subscriptions a year earlier. That cohort posted an expansion rate of about 107% in both the current and prior quarter, she said.
- ETM and CSAM accounted for 12% of total bookings on a last-twelve-month basis, compared with 9% a year earlier.
- Patch Management represented 9% of total bookings, up from 7% a year earlier.
- Kim said the company’s overall net dollar expansion rate has improved from 103% to 104% to 105%, with growth also supported by new customer acquisitions.
Kim said Qualys aims to return its net dollar expansion rate to above 110%, a level it has achieved previously, as ETM, Patch Management and TotalAI 2.0 gain adoption.
Remediation and AI Security
Thakar said Qualys is seeking to move customers from vulnerability management and detection toward a broader workflow that includes prioritization, validation and remediation. He described recent launches including Agent Val, designed to validate vulnerabilities, and Agent Insta, which he said can notify customers within 60 minutes of an advisory being released if they are affected.
The company also introduced TotalAI 2.0, which Thakar said is intended to help enterprises gain visibility into areas such as “Shadow AI.” He said customers are still in the early stages of assessing their AI deployments and determining what cybersecurity spending related to AI may look like.
“If there is a net new spend happening on overall AI and additional AI deployment, then customers will look at figuring out some spend that will be focused on AI security,” Thakar said, adding that it is too early to determine the ultimate scale of that spending.
Risk Operations Center Strategy
Thakar also discussed Qualys’ Risk Operations Center, or ROC, concept. He said the framework is designed to bring together risks across endpoints, cloud environments, containers, AI and eventually quantum-related security concerns. The objective is to give security leaders a business-oriented view of risk, including potential financial exposure.
Qualys has opened its platform to ingest risk data from other security tools, Thakar said. That approach could allow customers using third-party scanners or tools for functions such as mobile security or penetration testing to use Qualys for risk normalization, validation and remediation workflows.
The primary buyer for ETM remains the chief information security officer, Thakar said, though remediation projects can involve IT teams, chief technology organizations and, in some instances, chief risk officers or CFOs.
Capital Allocation and Competitive Positioning
Kim said Qualys’ guidance implies current billings growth of 9% to 10% for the year, compared with a deceleration from 13% to 9% to 8% in the prior several years. She described the second quarter as a “pivotal moment” for the company but said the pace of further acceleration will depend on execution over the next several years.
On capital allocation, Thakar said Qualys continues to balance share repurchases with potential acquisitions. He said the company is evaluating opportunities that could expand remediation options or add AI security capabilities.
Addressing competition in vulnerability management, Thakar argued that customers want fewer findings and stronger remediation rather than additional exposure dashboards. He said Qualys’ patching experience, reliability scoring and autonomous remediation capabilities differentiate the platform from vendors that are only beginning to add patch management functionality.
About Qualys (NASDAQ:QLYS)
Qualys, Inc (NASDAQ: QLYS) is a leading provider of cloud-based security and compliance solutions designed to help organizations streamline their IT security programs. Operating on a unified, modular platform, Qualys offers continuous visibility into global IT assets through a combination of lightweight cloud agents and on-premises scanner appliances. The platform supports an array of security and compliance use cases, enabling real-time detection of vulnerabilities, policy violations and misconfigurations across on-premises, cloud and hybrid environments.
The company’s flagship Qualys Cloud Platform delivers a suite of integrated applications, including vulnerability management, detection and response (VMDR), policy compliance, web application scanning, file integrity monitoring, asset inventory and container security.
