Home / Transcripts / Intercede Group plc (IGP) · May 23, 2024

Intercede Group plc (IGP) Earnings Call Transcript

May 23, 2024

London Stock Exchange GB Information Technology Software investor_day 153 min

Earnings Call Speaker Segments

Operator operator
#1

Good afternoon, ladies and gentlemen, and welcome to the Intercede Group plc Capital Markets Day. [Operator Instructions] I'd now like to hand over to CEO, Klaas van der Leest.

Klaas van der Leest executive
#2

Thank you, Mark, and welcome, everybody in the room here. It's really nice to see so many of you showing up for what is our first Capital Markets Day. So that's what we tried hard to make something interesting out of it, but we're always willing to learn. So we happily take your feedback afterwards. Also very much welcome to those who've dialed in online. We had very high sign up online. We clearly can't see you, but hopefully, you can see what's going on the screen. We'll take you through the presentation today. And I'm joined here with a number of colleagues, which I will -- and partners, who I will introduce very, very shortly. So agenda-wise, Nitil, who's the CFO and myself, will very quickly talk you through bit of the background on the company, how we position a little bit about the numbers, but just to be absolutely clear, there is no new financial data. We report back in June, third week in June. So the data that today presented, particularly on the financial side, is information that's already in the public domain, so no new technical information. Far more important what we are going to talk about is how we position, how we see the market. We have Allen Storey, our Chief Product Officer, talk about the product line, how we're evolving the product line, how we're positioning. We then have one of our partners, Stefan from company called CRYPTAS who is on recording Bob. He's been a long-standing partner. He will be introduced by one of my colleagues at the back of the room, Siobhan. We don't take that a step further and said, "Hey, we actually know quite a lot about you as individuals, U.S. companies domain names about what's out on the dark web. So James Westgate here, one of our design authorities, but he's got a special role after working hours. He will actually use and show you how that information can be used, actually log into our -- hack into your business. And that's really the starting point for how we position the products going forward because we then go into product mode and say, "Hey, if these are the threats that are out there, what do some of our customers do with their [indiscernible] case studies. We'll use some real-life case studies. We'll also show you some life product demonstrations, so you can actually see how our different products actually work. Then really pleased to have Cara here, Cara McFadden from Guidehouse. She's flown in from the U.S., those who have been following us for a while will recall that we do quite a lot of work with Guidehouse especially in the U.S. federal market. I asked Cara for a favor. I said, hey, can you do us a little speech and said, yes, that's fine. Then I realized you never been in London. So I said, okay, we'll fly you across. And obviously, I said, hey, it's always nice weather out here. So you'd be perfectly fine. Clearly, I have forget about yesterday when it rang 24 hours, look, it is what it is. And then we'll close off and summary, obviously, have some room for Q&A. So without further ado, these are the headline speakers, some of that will recognize, but we also give you a bit of a broader view as to who else is in the room. Normally, the first three on the left, you'll see us on the road shows. Cara, as I said, has joined us from Guidehouse, I have somebody calling me at the moment. So I don't have to try to get into the building down says, we'll leave that for later on. Siobhan is our Head of Sales and partners in what we call rest of world. So we have our U.S. arm. We have our Rest Of World arm, Jamie Solution Architect based in the U.K., Jamie being with the company in 15 years, quite a long time, sits in Siobhan's team, James Westgate design authority for both MFA and PSM. So the two products we acquired through Authlogics is part of Allen Storey's and units. And then Stefan is the CEO for CRYPTAS. It's an Austrian reseller. We've had a very long relationship with. So hopefully, that positions a little bit. What we really want to try and do is provide you a bit more insight into what we think is the investment case. And I won't go through all the three blocks right now, but we'll circle back towards the end. We'll particularly focus today about business and market. Like I said, there are no new financials out in the market, but Nitil will do a little bit of a recap as to where we are. But at this stage, I think the main thing to bear in mind here is we sell in the market that's clearly growing at the moment. It's the widest cybersecurity market. We're all on the Fed, whether that's individually or as companies, we are constantly on the threat. Every minute of the day, we're under threat. So we think we're in a very interesting market. First point here, this is not discretionary software. This is business-critical software. You can see it in our results, we see very little attrition. It's extremely sticky kind of software that we sell into those markets. and we have clients for 10, 15, 20 years. Ms. McFadden will also talk about playing the long game, and we're in this for the long game. So a little bit about how we position in effect at the very highest level, what we do is we protect companies against data breach. How do we do that? In fact, we use and replace weak credentials with much stronger authentication and you'll see in the products what we do. And we do that simply, we do that securely. We do it at scale, simply meaning it's standard off-the-shelf software. So we sell same product time and time again, which actually works very well for us because -- we can turn it around very, very quickly. We can recognize revenue and profits very, very quickly. We do it securely. We work with some of the most security-conscious organizations out there who test this software right to the hill. So we know our software is secure. Final point is we can do it at scale. Scale means not just we can do hundreds and thousands, we can do hundreds of thousands and millions of user licenses. So overall, I think we're pretty, pretty well positioned into the market, and we know our platform scales out. But then data breach. Data breach is interesting. 5, 10 years ago, data breaches were quite unique. Today it's been normalized. Every day of the week, every day of the week, we see the announcements about data breach. And this is probably how companies feel yes. This is how they feel. They feel anxious. It's an interesting kind of painting. Well, guess what's the name of the painting, the screen? Who is it by? Very good, and good, Monk. There are some really interesting facts about this painting, which is why I'm bringing this up. There's two really interesting facts. Anybody who wants to have a guess? And Graham, you can't because I think you've heard this one before. But two interesting facts about this painting. There are multiple versions of the same painting. So in effect, there's multiple identities as an effect, there's multiple credentials. There's another interesting fact about this painting. It got stolen twice, stolen twice got recovered twice. So what do I have now? I have in fact stolen painting with credentials and that also turns out to be the #1 reason for data breaches. Stolen credentials, stolen passwords are the #1 cause for data breach. This is Verizon Research. This is IBM Research. There are plenty of reports available every couple of -- well, every year, these reports get launched. And basically, the majority of breaches are happening because of compromised user credentials, compromised passwords. But we don't use passwords. Do we or do we? Because we actually know a lot more about your password use. So we're going to have a little poll and I need a little bit of participation here. And we need to be honest with each other because remember, I know a lot about more about you and your companies and you may want me to. We also run the pole online because otherwise, it becomes very one directional, but Mark from IMC will run the poll in a minute, but I need a quick show of hands, who's using password for personal use? Well, that's all of us, that's interesting. Who's using passwords at work? Quite a few. Who has reuse passwords between private use and work use? Don't be shy because I know a lot more about you come on. Yes, we all do. Who's using passwords longer than 12 characters. You see Royston, our Chairman, he's actually quite good because he listened to this story before. Now let me quickly check what's happening online. Are you using passwords at home? Yes, nearly 44%. You passwords at work? Yes, again, a large number. Have you reused passwords? 23%. That's a bit skinny, but looks at it. I'm not sure if everybody is open and honest, and we have 10% using passwords longer than 12 characters. So that's really interesting information. So how do we use this going forward? We actually looked at what's happening in this room. So we looked at all the companies who registered. We looked at your domain names. We looked at our breach database and said, okay, what information can we find about this? We had 25 companies that got passed on to us of the 25, we could find exposed credentials for 22 of you. So that's 22 out of 25. I'm not a mathematician, but it's 88%. That actually is quite high. More worryingly, 9,710 exposed credentials. What's even more worrying. All of these are clear text credentials. So they are clear passwords. They are not hashed. They are available on the dark web in clear text format. We then had James and his team as ethical hackers do a bit more. There were about 400-ish cash credentials, one of James' team work on it. He cracked another 49, I think 49 in little or no time. This is just compute power. The more compute power we throw it, the more we can break. So lots of exposed breach credentials available. The reason why I asked about, are you reusing passwords? Well, we can see from our database that actually quite a few of you are reusing passwords. Not particularly good hygiene, you should not be doing that. Moving on to the types of passwords we see. Well, you're quite an inventive bunch. You use wealth and secret and some simple numbers and this is quite unique to this community. We know this is unique to this community. We don't understand why, but you obviously use those kind of passwords, relatively weak passwords as well because a lot of these are less than eight characters. Eight character passwords as James will say or update can be hacked in absolute no time with a little bit of compute power, we can hack those down. A lot of them only use lower case. We shouldn't be doing that. Only 18% is using special characters, again, not particularly inventive. So what we can't see at this moment, whether the passwords we have in our database, the passwords that in effect exists on the dark web are currently used one. We can easily change this. If we engage with you as individuals or engage with your companies, we can check in less than half an hour. Where do your staff members are using those passwords or not. It's a simple audit, half an hour, James and his team will run this very, very cleanly. So we then look at some of the breaches. There are 189 breaches that we've picked data from. So it's not just the LinkedIn breach that's pretty well known. We found three breaches that are particularly interesting. Evite is an interesting one. Evite got breached in 2013, but they only admitted it in 2019. So for 6 years, this data was happily out there on the dark web and being used. The same for Zacks. I thought, well, who the heck is Zacks? Zacks is an investment research platform, that particularly shows up in this community, they had a hack a leak of 8.8 million passwords, yes. Shows up in this database. So there is clearly stuff going on that. We should be aware of. We need to protect ourselves against and that's exactly what we do as a company. We protect our companies that we work with against data breach. The last one, I'll leave for James to talk about the malware. Malware is something that will be put on your desktop, your laptop, your mobile and it will just harvest your credentials, it will just harvest your password, make it very, very easy and then automatically reuse that. So this is quite interesting. It's a bit of a wake-up call, but obviously, we started off with, well, we don't reuse passwords. Do we? So that is in mind. So then very high level, who's Intercede. We're headquartered in Lutterworth Junction 20 M1. We have two offices in the U.K., one in Lutterworth one in Bracknell through acquisition. And then our second office is in Washington, Washington, for a very good reason. A lot of our business is U.S. Federal. So we're right in the area there. What do we do? Business-critical software. So this is not discretionary software, is business-critical and we focus on employee identity. So we focus on protecting the credentials that we all use as employees within companies. Just to be clear, we do not focus on consumer identity. Yes, consumer identity is a very different part of the market. We have around 150 high-profile clients. I always say we're a small company, but we're a client base to die for. By the time you look at the logos. We work with the partners we work with. And the many clients we work with that we can't put on our website because we're not allowed to, but picky in the U.S. You can think about interesting shape buildings. You can think about three-letter acronyms agencies, you get the gest of what's going on. We're around 105 staff, but they're all subject matter experts. They are highly skilled coders, developers, design authorities as you hopefully will see some of them today. We have issued millions and millions of credentials. So again, this scalability. If you look at the Q18 national ID scheme, we have issued north of GBP 6 million, GBP 6.5 million credentials. So this is a platform that will scale. Last one is our reach into market is through channel. We decided 6 years ago, no more direct sales. I think Nitil will correct me if I'm wrong, but around 95% of our new business nowadays goes through channel. It means we have much broader reach. So if we then look at the business principles, I go back 6 years when I was appointed as CEO, the first thing we did is we said, look, we're going to focus on the customer. I don't care if we don't understand what the customer wants and needs and requirements are we aren't going to go anywhere. We use that information to invest in product. We invest over GBP 3.5 million a year in R&D. So we're investing a large part of our money into R&D to guarantee market leadership. Clearly, we can't do that without investing in our colleagues. The 105 staff we have and we added 17 in the last 12 months. So we're growing very, very nicely and we're pushing quite hard. In order to get that into the market, our go-to-market model, as I said, is very much distribution, resell and channel. Pricing wise, we've morphed our pricing over the years. Traditionally, it's always been perpetual. We're now offering both perpetual and subscription. We do it for a very good reason because some of our clients do not want to buy subscription, particularly on the high ends. They very quickly calculate what's cheaper on a 5- or a 10-year TCO model, and we need to be flexible on both sides. Final one is M&A. We've got our in-house corporate development. We are actively looking at the market. We clearly have made our first acquisition, successfully integrated that acquisition. We're on the lookout for more as and when we can share more information, we will. So then looking at the market, we always get questions about, okay, what markets are you operating in? We're operating in three distinct kind of markets, the top end of our product is also the top end of this slide. It's the PKI Public Key Infrastructure market. It's a good-sized market with good double-digit growth. Through acquisition, we've added the middle layer multifactor authentication, password security management. Clearly, these are big numbers, but we're not operating across this entire market. So trying growing this down a little bit. When we look at what we address, we shrink the market a little bit. We focus on enterprise government sorry, we focus on federal government enterprise. We focus on the three product lines we have. And very specific, we focus on anything that's not multi-tenanted. So we're very much on the on-prem side. There are plenty of use cases out there where customers do not want to buy full cloud, full multi-tenanted, and that's where we differentiate. If we then look at the markets we serve, geographical markets, we're very strong in the U.S. Over 80% of our revenue is North America. Obviously, in EMEA, Continental Europe, Interestingly, we also see growth now in the U.K., particularly since the invasion in Ukraine. We've seen U.K. government investing in the high-end product, the PKI product, which is good for us. Again, that's going through partners. Finally, APAC was starting to open up the market in APAC. WeChat in Singapore. We've got multiple live platforms in Singapore, and we're hoping to expand that going forward. And we also got our first client now in Brazil. So if we then look at our actual markets, we grind the whole thing down, very high end, high assurance. We position our CMS product. And again, we'll provide more color about what CMS actually stands for. Mid-market MFA. Again, regulation will drive that bottom end password security management, you need to start with the basics. If we compare this against 5 years ago, we had one offering. The only thing we could offer was PKI at the top end of the market, and that was the market we're operating in. We've added functionality. We'll get to the pyramid. Some of you have been following us, you will recognize the authentication pyramid. We've come down that pyramid, partially by building functionality but also through buying functionality, buying IP through acquisition but our market has grown at least 5x to 10x compared to where we started before. So where is this growth going to come from multiple angles of both organic and inorganic? First of all, land and expand. It's something we're doing. We're pretty good at. We sell 10,000 licenses to a client in year one. We find a new use case, the client buys 2,000 more CMS licenses a year later or 2 years later. So that's relatively straightforward. It's the same for MFA. It's the same for PSM. It was an interesting use case in Germany recently. We had a German hospital that was using password security management for their high-end users, that hospital got breached, Guess what? They need more licenses. Breach sometimes got an upside, we will upsell. Why is it called land and expand square? Because one of the examples I've used is all about horizontal land and expand. But through the products we've acquired through Authlogics, we can now do vertical land and expand. So a customer who's got CMS can also buy licenses from an MFA and a PSM perspective since we've integrated the full product set. Clearly, we charge for new functionality. That's pretty common. We're opening up new markets. I talked about Singapore, talking about Brazil. There's plenty of other markets we're opening up. New market segments is interesting. I know there's particularly one listener online who wasn't feeling very well, but he knows who I'm talking about. He's always asking us, well, class, what do you do in the middle end and the bottom end of the market? Why are you not positioning that? Traditionally, from a PKI perspective, we didn't have the product. But now that we have MFA and PSM, we do have the product to really come down the pyramid to really drive down at the bottom end of the SME market. The opportunity I referred to here is in Germany, we've signed an agreement with a company called River [indiscernible]. River [indiscernible] is a remote monitoring and management platform. And they focus exclusively on SMB. They focus on the bottom end of the market. But what they manage is the operating system. They make sure it's safe to run. They do backups. They do AVG. They've now added MFA to their platforms. They have millions of users on their platform, and now we're trying to cross and upsell our MFA solution into that. It's a very different market to what we're traditionally in. But because we have route to market, their route to market is through MSPs or MSSPs, managed service providers or many security service providers. They have that channel into the market. So that's a market we will actively pursue. That's obviously aligned with the new distribution model, new channel. We are constantly growing that. [indiscernible] who's in the back of the room, he's got a real background in channel and distribution. And we have [indiscernible] counterpart in the U.S. who basically drives that from the North American angle. Hosted offerings, we don't host our own offerings. Yes, we get our clients to host sorry, our partners to host the platforms for us. So that also enables us to address different parts of the market. So we have a partner in the U.S. called Whitepoint, NASDAQ-listed company. They particularly offer hosted PKIs. So that's the more complex end to lower-end customers who can't afford to run their own infrastructure. But they have a fully shrink-wrap offering. It's a very, very nice entirely. Our sales effort is very, very low because they sell it. We just take the license orders as and when they come in. And obviously, we focus on new products. Inorganic, as referred to, we've done our first acquisition. Fully integrated. We'll provide more color on that. We're always on the lookout for new IP, whether it's new revenue. We're looking at new geographic markets, new market segments that we can move into. Clearly, there's very little I can disclose, but we'll finish off today with our pyramid. And once we've gone through the presentation, you'll recognize the purpose of the pyramid. And I'll provide a little bit of color on the areas that we will explore further as we go along. At this stage, I'll hand over to Nitil, who is our CFO.

Nitil Patel executive
#3

So investment cash flow [Technical Difficulty] our organic and inorganic. So we believe our capital structure is in a good position. We continue to invest in our product and our people. Why do we do that? Well, because it gives us the competitive advantage to then generate the revenues which gives us the profits. It's a prudent capital structure. As we've mentioned, there's no debt in the group. We have a very tight working capital document and cash [Technical Difficulty]. So we're cautious in our M&A approach. And why are we cautious? We know that if you get this wrong, it has an impact. We liked our M&A play on Authlogics. We learned a lot on that. And the key one here is the integration of the company products and how we go about that. That's a fundamental document that we always use to approach an M&A. How are we going to integrate? How are we going to make it better? What does it do with our stack, especially our IP stack. And then focusing on recurring revenues, as all of you like, recurring revenues means that it continually pays. S&M is really important to us. The reason S&M is really important to us is because it covers a big chunk of our operating cost. If it covers a big 80% to 90%, that means that our license income is highly, highly accretive to the bottom line. So continued investment in our product is really important. The good news is that all our expenditure is in the United Kingdom. Therefore, we are entitled to the tax credit, slightly less [indiscernible] going forward. but we're also producing more functionality and modules in the future of our product. What does that mean? It means that potentially in the future, we can potentially capitalize that element of that development if we have revenue streams against it. something we'll look at going forward. At the moment, we expense all our R&D into our income statement. I think one of the few software companies does that. Cash generation is a key KPI. Why is that a key KPI because it enables us to go back to the original, invest in our product, invest in our marketing, invest in our people, enables us to be competitive advantage in our product, which helps us to do more sales. There's an exceptional for 2024, if people have been following us know that we had a big sale in December with a federal agency. And that helped our cash balance to go to 17.2% as of 31st March 2024. Just wanted to show you how the group revenue is going through the double-digit growth in the last 6 years. You'll see the forecast that this year, we're coming in at GBP 20 million, and next year, it's going to be GBP 16.1 million. But we wanted to show you what without the exceptional , if you look at the orange, the oranges MFA, PSM revenue and the gray is the CMS revenue. We were looking to do GBP 13 million of CMS. Obviously, we've done better than that. But if you look at the trajectory, it's all double-digit growth, and we believe that we can achieve that in the coming years. And finally, what does all that mean? A good share price for us means that we can do a larger M&A, integrate it and therefore, increase shareholder value. We've got a good strong balance sheet to do that. We're forecasting cash generation in the coming years, but also it means as a listed company, we have access to the capital markets to do an acquisition that we believe will enhance shareholder value in the future. On that basis, I'm going to pass you over to Storey.

Allen Storey executive
#4

So I'm going to take a look at our solutions and what we've actually got in the portfolio. I'm going to do that breaking it over to three. Starting off with where we came from, where we are today, then more importantly look at where we're actually going. So a lot of you have seen this pyramid before. We've used this to describe how strong is your authentication, weaker authentication towards the bottom, passwords easily guessed, often reused, stolen. Moving up to the middle, one-time passwords, I'm sure we've all used these to log on to our bank. We've received a code on our phone with actual type in to a certain application. And they're moving all the way up to the top of the pyramid, PKI and FIDOs, we're really talking about cryptography-based authentication. Historically, we played very much at the top of this pyramid. PKI is where we've been. That's the market for federal government, aerospace and defense, that sort of organization, intelligence agencies. It's an interesting place to be. Those people tend to keep your product for a long time. They also tend to pay well for that product. But it's -- like the pyramid, it's the smallest part of the market. As you come down the market, you get less secure, but more people will use onetime passwords, multifactor authentication and pretty much everybody, as we learned from earlier on, is still using passwords. So there's more of the market as we move down this pyramid. So we, as an organization looked at how do we address that market? Do we build it? Do we buy it? Do we partner? Came to the conclusion that acquisition was the best strategy for us. So we acquired a company called Authlogics. Happen to be based in the U.K. that we looked at people in the U.S., we looked at people in Europe could have been anywhere. The reason we chose them is we thought that the product was very credible. Multifactor authentication is a very strong product, and we thought the people were very credible to have some real expertise in what they did. But they also had an added bonus for us, and that was the fact that not only did they cover the middle part of the pyramid, the multifactor authentication, they also have password security management so that interestingly allowed us to be able to cover the whole pyramid. And that's unique. There are people that play at the top end. There are people at play at the bottom end, but there's nobody who plays across the entire pyramid other than Intercede. So very briefly, what did we do the acquisition. This was my first acquisition on this side of it. I've been acquired before. This first one I've been involved in where I have acquired much more from this way around. Can we let you know that. So the first thing we did is to understand. We didn't change anything fundamentally. We made sure we understood the product, the code, the business processes, the go-to-market. We've got out there. We got on the planes. We met the partners. We met the customers, really start to understand the business. We did an enhancement to the product based on what customers were asking for. So this was a push notification. A lot of drive for people wanting to use their mobile phone for strong authentication. So you don't have to carry around a special device, a key or a smart card or something. So that's what we put in the product. So it will now push to you and say, "Hey, Allen, somebody is trying to log on, is it really you?" Yes, it's my face, I did use my fingerprint. So I get a very good user experience. So we put that in the product, but at that point wasn't rebranded. It was still kept of logic as a branding. And then as per our strategy, we really moved on and we integrated the solutions together. So not just integrated as a business. So we've got joint sales team, customer support, et cetera, but from a product level as well. So we've now got joint development teams, testing teams, technical author teams, et cetera. This allows us as a product team to look at where do we place our investment, where do we get the loss bank for our book. So we did a complete rebrand. So the product is now rebranded MyID MFA, MyID PSM, multifactor authentication and password security management. That allows us to sell a much simpler story to our customers and partners is the authentication pyramid. We cover all of it. But it also allowed us to capitalize on the credibility we have from some of our very high-end names on the CMS side into the world of MFA and PSM. So we introduced some new features into the product. We brought FIDO Passkeys into the product. At the very top end of the pyramid is PKI. There is an argument to say that FIDO is as secure as PKI. FIDO came in from the consumer world. We're probably -- some of us are using it to log onto our banks today, but it's kind of under the hold. We don't see it. But it is then, it's very secure. It's based on the cryptography. So this was an ability to bring some of the skills and knowledge from the CMS world into that mid-market MFA world. And that's important to us because it allows us to differentiate that mid-market and multifactor authentication. It's a very competitive space. So we need to be able to differentiate, and this is one of the ways we can do that. So now the story is we cover the whole authentication pyramid. One way of saying this is to go to a customer, how secure do you need to be. Not everybody needs to be at the absolute top of the pyramid, but everybody is looking at how they want to improve their security. So we can help them wherever they are on that journey. And it is a journey, 10, 15, even 20 years ago, we were involved in conversations about when will the password die as the password gone. But we're all still using them. They're all still out there. So the story here is very much secure yourself from day one. You're still using passwords. We get it, let's make those secure as they can possibly be. If you want to move up to multifactor authentication, we can support you on that. If some are all of your users need to be at the absolute top end of security, we can also help you there. So this gives our customers an advantage that they don't need to go to three different vendors for the different parts of the solution. They can come to us. We think the flexibility to improve their security over time as they need to. And again, that's unique. There's nobody else could do that across the whole stack. So just one slide on each of the actual products here. We can actually going to show you these live later on. So this is password security management. And at the heart of that is that password breach database. So this is what we were looking into for the companies looking in the room at the moment to see what do the bad actors know about you? So we have a small team of ethical hackers who look out there on the dark web. Whenever there's a data breach, Marriott, some of the platforms Klaas was mentioning there, those used names and passwords will go into that dark web people will then steal those and they'll start trying to break into systems with them. So we do exactly the same apart from we don't break into systems with them. If we try to do that, James will be in jail at the moment. I'm glad to say he's not in jail. So we stop at that point, but all of that's public information. So we take that information and we put it into our password breach database, and we help our customers with that information. So first thing we can do is we can audit that, what do the bad actors know about your business? Is there information on the dark web that they could use to try and break into your business? Then we can actually do the on-premise, on-premise old it. So Klaas mentioned this earlier. Information in that database monthly update. It might be that you've changed your passwords. It might be you've moved on to multifactor authentication. But we can find that out with the on-premise audit. We can have a look at your passwords and say, "Are you using passwords now that are out there? And are you at risk? And if you do, the password security management product, PSM, we can install that and that will verify your passwords. It will check them for you. So at that point, if you're using a compromised commercial, it will force you to change it. You don't have to wait 30 days, 60 days, 90 days. MFA, So this is multifactor authentication. This is everything in between passwords at the bottom and PKI at the top of the pyramid. There are some significant benefits we really like in the solution, which is why we acquired it. It works on and off-line. A lot of solutions don't do that. It also protects the Windows logger. So lots of applications. We'll only protect cloud resources, but the reality is pretty much organization out there. Everybody's got something in the cloud. They've still got some legacy applications on-premise, particularly some of our customers in defense, in healthcare. There's a lot of applications that have been developed over time. So this application can protect all of that on-premise in the cloud on and offline. By bringing FIDO into the application there as well. We now have the ability to issue a very high level of assurance but for something that's very simple to use. One of the things we learned from talking to the customers and partners about this product set in this particular market, that mid-market is ease of use is vital. It almost trumps security. People want to be secure, but if it's not simple to use, people want to deploy it. They don't have the IT teams and skills that some of our government customers have. So mid-market product, now with that high level of security but very easy deploy, very easy to use. And our traditional credential management system. I hope the word traditional doesn't sound wrong because it's still a growing market. There's still very good business in that market for us and the credential management and we are absolutely the market leader in this space. I know I'm biased because it's my product, but [indiscernible] other people, Gartner say that this is the best product on the market from a credential management system. And that's all about making sure that the right people get, the right credentials and handing all of that complexity and technology and key management from the end customers. Put simply, there's no point me having a credential that says I'm Bill Gates, if I'm not Bill Gates. So we need to make sure the right -- people get the right credentials. There's a lot of integration in that solution. Importantly, also provides registration and identification of a person before we issue them a credential. We'll show you some of that when we talk about one of our customers. So it's making sure that person really is who they claim to be at the highest level of assurance before we issue the credential that let them into the air traffic control tower. So where are we going next? What are we doing with the road map? There are three general drivers for our road map. And these each take about 1/3 of our resources. So you could put 1/3 of our people into each of these areas on the left. The first one is support and maintenance. It's not a bad thing. It's a very good thing for us because that funds are support and maintenance revenue, and that's annual recurring revenue. It's very repeatable. It's very reliable revenue. Our government, aerospace, defense, military customers, they want to have that support and maintenance. It's a security product. If there's a security event, something happens, they want to make sure they're the latest, greatest the patch up to the latest level. So that takes that. We then have customer funded. All of our intellectual property remains our own, but we're quite often a vocations where a particular customer wants something accelerated on our road map and are willing to fund that. So that's great for us. That means we can get that work funded and our road map, but we always maintain the intellectual property. The strategic, the interesting one is areas we think we can enhance in the product. So that could be a new feature. It could be a new product. It could be a new module within a product. Looking back at financial figures there, the important thing from my perspective is as the person who looks at where we go with the product is that the first two are pretty fixed. There's a level of support and maintenance, the level of customer funded are pretty fixed in terms of the people we have each year. Therefore, any new head count we have in goes straight to that strategic bottom line. So 100% of that new person will go into where can we take the product, what can we do with it. So what's going on in the market? What's driving us to make decisions on product or the next acquisition, et cetera? The first one is that the level of cyber attack is increasing. Be that criminal, be that state sponsor, be that for what's happening in the Middle East, what's happening in Ukraine, we can see increasing levels of cyber attack, and that's leading to increased levels of cyber spending, particularly around governance and people who believe themselves to be a threat. So we're starting to see people demanding more security. We're seeing a trend from bespoke solutions to COTS commercial off-the-shelf solutions. There's a term government called COTS government off-the-shelf. So that's why the government actually pays for the work to be done. They own the intellectual property at that point, and the solution does exactly what they need because it's been built exactly to their requirements. The problem is 3 years, 5 years, 10 years down the line, the world's moved on. There are new technologies, biometrics, AI, post-quantum, FIDO, all the new technologies coming in, and that solution stayed pretty static. So we've had a lot of government customers wanting to move away from those bespoke solutions towards more commercial off-the-shelf solutions, therefore, they get the upgrades, they get the new technology. And part of that is avoiding vendor locking as well. There's lots of different technologies out there, the flexibility to jump between different PKI vendors, card vendors, biometric vendors is important to them. And that's always been a key strategy for us to keep technology independent. I mentioned the shift to mobile devices, doing some very interesting things with NEC on police digital warrant cards, doing some interesting things in the U.S. on a access for nonmilitary personnel to bases where they can currently getting with the plastic card, which is not great, looking to move that on to a mobile phone, but you see some of the mobile driving license standards so we can have cryptoglaphically verifier identities on a mobile device. But the big driver for our business has always been regulation. Regulation drives people to use our particular type of technology. So there's more regulation coming out of the U.S. NIST published the standards there. The rest of the world tends to follow NIST standards as they're the best funded cybersecurity administration. That's pushing people to use more fishing resistance. James will talk about that in a bit more detail. It's also pushing people to use multifactor authentication everywhere. So that's all employees and down the supply chain. Very interesting change for us is in the AU. There's a piece of legislation called NIS2. That's now being passed at the AU level, which was by the end of 2014, each member state must have enacted its own cybersecurity legislation. So 2024, good point plus, yes. [indiscernible] been doing this a long time, '24, thank you. By the end of 2024, they have to have acted cybersecurity legislation. And that's really interesting for us because the U.S. legislation has really driven our business, but there's been a lack of direct legislation around authentication and security in Europe, but that's coming. Even on our own turf in the U.K. now, our own organization of [indiscernible] cybersecurity regulation standards and cybersecurity rules. They're saying that multifactor authentication is the base level, and we're starting to see people not getting cyber insurance unless they're at least at that base level. So there's a huge amount of drivers towards more and better, stronger authentication. So the road map. So today, on Password Security Management, we have the breach database. We think that's a great asset. We can sell access to that our KPIs. We can do audits against it, and we have the software that you can actually install the premise to check those passwords. So the first thing we're doing is extending that outside of Active Directory. Active Directory is the primary password that most people use, but there are others, we're extending that to cover those. And the second one is simply marketing. And Authlogics, we think, have a fantastic product set that didn't really have the arms and legs to take that to market. So with an expanded organization, we're now taking that through our channel and our customer base. But the main thing we're looking at is turning this into an enterprise password manager. I'll explain what I mean by that in the next couple of slides. And finally, on the right-hand side here, where they've got dot, dot, dot, this is very much research and development items we're looking at. So FIDO, one of the advantages with FIDO is that I can sync my pass case from my phone to my iPad, which is very interesting because I go back up, but that tends to happen in my own personal apple account or my Google account. So we think there's an opportunity in the market there for somebody to actually do that back up, but on behalf of the organization. So they own the keys. Multi-factor authentication very capable product, works on-premise, supports cloud log on, now supports FIDO. First thing we're looking at that is national ID connectors. So some organizations, Singapore, Sing pass UAE, UAE pass have nationally issued ID credentials that we can then use to protect local resources. So how could I use my UAE pass to protect resources within my organization, we think is interesting. But what we're really doing is extending this towards more access control and single sign-on. I'll explain what I mean by that on the next slide. And on the right-hand side, again, research and development areas, we're looking at ongoing authorization. This is something that's been us for more and more, Sam logged on 10 minutes ago. Is it still Sam? Have they suddenly changed IP address from Europe to China? Is that an impossible travel situation? Are they holding the phone in the right way? Are they typing at the right speed? So it's a constant game of almost [indiscernible] where you have to hit security threat down and then another one pops up. That's what the security will like. And AI as well, artificial intelligence, we're seeing it used more and more for attacks. Phishing campaigns are virtually impossible to spot from ones that humans are generated? And how can we bring that into the product? How can we start making security decisions. So really, what we're doing is looking at bringing those two product lines together, MFA, password security management to give an access control solution for the enterprise. Now we're not unrealistic. We know there are huge players that are up that are paying them the Microsoft of this world. They tend to work at the very, very high levels. We're not fighting those. There's a lack in the market of a mid-market product that gives you that solution. So a lot of companies out there can't afford to go for the optics of things. They're just too expensive. So what this will do is on the left-hand side, we have somebody authenticating into my desktop. So that gives me the windows log on. That could be a credential we've issued. It could be their national ID credential. Once they've hit that log on, then they're presented with applications they're allowed to access. Many of those applications and modern applications so I can use things like OpenID Connect or [indiscernible] just simply pass an authentication ticket in and give people a single sign-on experience. However, there are lots of applications out there that still use passwords, again, particularly in the NHS, particularly in defense. So here, what we'll be doing is combining that with our enterprise password management, where we will learn the password for that application. We will create a huge complicated password that the end user doesn't even know. We will check against the password breach database that, that isn't a password that somebody else has already cracked. So it's safe. And with that strong authentication, we will play that password at that end application. So this gives people a journey. It gives them the ability to move towards stronger authentication over time, but it gives that full solution in the mid-market, and we can't see anybody else who's doing that in that mid-market space at the moment. So particularly relevant for things like NIS2, where there's a lot of smaller organizations. CMS road map, again, I believe it's the most capable product on the market today, but some of the key things we're looking at there is how do we play with those big players. So pass key registration with an identity provider, what does that mean? It means we issue the FIDO keys with all of the rules and control that our customers expect, but we then pass them into a Microsoft or we pass them into an Optum platform. So we can work with very much a strategy because we need to work with those big players. So that's that part. The other one on the second place here is the flexibility and configuration around the product. So sometimes, we end up configuring or customizing the product for an end customer but we're moving away from that now. We're moving towards keeping the core product absolutely pure and allowing customers to do their own configuration. So this is more toolkit around the product where customers can configure the system. They can integrate it themselves without having to come back to us to do that for them. I very much like our developers to be working on core product enhancements that enhances in the market as opposed to an individual customer. And again, other areas we're looking at artificial intelligence, how can we use that to bring in to make risk-based decisions on is this the right person? Post quantum, at the moment, a lot of cryptography is based on it's incredibly difficult to actually try and crack the keys and work out what the private key is. As computing power increases, it gets more likely to do that. So we work closely with NIS2 to set the standards in this area. We're working with the [indiscernible] manufacturers to make sure that we're up to speed and ahead of the game there. Thank you.

Siobhan Morey-Millington executive
#5

I'm Siobhan Morey-Millington, I'm Sales Director, looking after our Rest of World customers. I just wanted to briefly introduce you to one of our European partners. Unfortunately, they're not in the room today, but they have recorded a video that I can share with you. [indiscernible] are a PKI specialist based in Austria, serving the DAC and Nordic markets. They're a long-standing partner of Intercede for much more than a decade now. They resell deliver and deploy our MyID solutions, and they have also integrated their own software with MyID CMS. We've got some 20-plus customers together into the banking and finance sector, government and defense and high-end corporate enterprises. In the last year alone, we added a further three customers. We really value this partnership with CRYPTAS and we have Stefan Bumerl CEO and Founder to answer a few questions that we could share with you.

Unknown Executive executive
#6

My name is Stefan Bumerl. I'm founder, owner, CEO of CRYPTAS that for already really more than 2 years now. I -- personally, I am a tech guy. So I have a very strong technical background, so working with market since the late '90s. And CRYPTAS was always introduced to deliver impact, the positive impact to our customers. And that's what we still do today. We delivered trust to our customers. That means they need to establish their primary security goals, which are providing authenticity, integrity, confidentiality and of course, also the availability is important today. And these security goals can be solved in the best way by using cryptography. And what CRYPTAS is doing is using that someone complex technology, building complete services to our customers. and try to make that complex technology as simple as possible to consume. That means we've been having a long journey to transform ourselves from really pure tech driven to get more in easy to consume, easy to work with organizations to deliver green check boxes to our customers. So the combination of good technology, focusing on usability of users and also the operational teams in our customers' organization together with proper economics sites, deliver impact. That's what we promised to our customers and Intercede is in that scenario with a very important part. Trust is our currency. And that means that customers really fully rely on us and on our services for a long, as we said, on a long period of time. And that means that it's important to be there reliably. New is not always good. So being there for a reliable long term, that is a quality. And my idea is in that fact phase, a really rock solid software. It has been proven to be reliable for years in many organizations, is the backbone of the security architecture and still meeting the bridge -- bridging the gap between convenience on the one hand and the security on the other hand. And that is something that, for that period of time, not a lot of products and organizations can claim to deliver to their customers. And we also -- like the technologies, we have our own software products as well, as I said, we are also still tech people, even if we sell green checkboxes, still we have [indiscernible] market technologies, [indiscernible] market technologies. And they all need a proper back-end to be integrated and orchestrated with other things. And what we've been choosing to integrate these things into is MyID because of it's reliable robust technology. It's impressing how well they are able to manage a really complex technology and a complex product, which is integrating in so many external systems. And that complexity is also the orchestration of the security. And it's important to note that security is not just a matter of technology. It's a matter of quality. And the matter of quality is going the hardware game, going the extra mile and MyID and Intercede has proven to have proper documentation, well thought solutions to real market problems, and that's what we like and what we believe that Intercede's key strength is. It's not always the largest wins that are the most surprising or impressing ones. Sometimes, there are rather small ones, like one reason was a Swiss military organization where we thought, well, Switzerland, military, they try to have their own suppliers sitting close to each other. But however, we said it's fitting to what we do. Let's do a good job. And what was really impressing and surprising is how straightforward and quick and how perfect the feedback on our offering was. So it was an easy win, although we thought that might be lost time to still offer there. And that means we should -- we seem to have a good proposal to our customers. Well I'm in this market for more than 25 years, so long. And it was always a very slow and small one effectively compared to what the total potential would be. And now in Europe, there is a big change, full set of new regulatory standards came along, so including the NIS2 and DORA for the banking or for the financial industry. And this is not just yet another set of requirements that are imposed by a regulatory authority. It is a big change to the whole industry. And even the draft of the German law calls it, it's a turning point in history. Why? Because it's going to drive not just a few organizations to implement security means. It's going to change the overall market to implement and to deliver maturity, and maturity is key for security and for resilience of our whole society. So the European -- in Europe, the set of standards that already are issued, and they will be amended by further ones coming in the soon future is really changing almost everything because you need to get as an organization -- as an effective organization and you're easily an affected organization. So also us, CRYPTAS, we are affected by 3 different means because one, we are in qualified trust service provider. Second, we are delivering managed services and managed security services as well. And third, we are delivering to a lot of critical infrastructure suppliers, which means we are also indirectly affected. And what we said before with the green checkboxes, that's actually what their problems are. And the market is not doubling. It's a matter of multiplied by 20 or something like that, what the impact is. So the take-up will take some time. That's what we expect. But it's full, it's complete -- a complete change to the overall setup. And I think if you look into other industries, such kind of maturity implementation phases or however you want to call it, took decades and this is now happening to the IT industry, especially in a really short period of time. And I think that's a good opportunity for organizations with proper offers and the proper mindset. And I think we are well positioned here together. Yes. CRYPTAS is a qualified trust service provider, and we managed to get that highest technical standard in the broad market. So we are delivering in that specific market already today, millions of transactions every day with thousands of digital or electronic onboardings on the highest security level that is possible to, I think, more than 165 nations. What I want to tell, even higher security is possible to be delivered for individuals or small organizations. And what we are planning for the future is to take that technology, which was made for the major leading organizations, be consumable as a trust service like the qualified trust service for corporate trust service to the markets, which we -- where we can offer a full service like we do it today already on the qualified level. And that's, of course, one aspect where my IT product should be part of it.

Siobhan Morey-Millington executive
#7

That's is what from Stefan.

Klaas van der Leest executive
#8

Yes. So the one thing I've learned from Stefan is that we always talk about how complex it is. He makes it quite simple. We deliver green tick boxes for our clients, and that's what we do and that's obviously what CRYPTAS does. So the next session is James Westgate -- next slide. James has joined the team Intercede through acquisition. Now he's going to take a completely different view on what we do. So go back to the breach data that we've shown, 25 companies, 22 companies, 9,701 breached unhoused credentials. James will show you what he could do as an ethical hacker to break into your company domains. He clearly won't, but he will show you what a hacker will do, might do, could do in order to utilize the data, this data is widely available. So James, over to you.

James Westgate attendee
#9

Thank you, Klaas. Okay. So how would I hack into a business? So let's first qualify by what I mean by hack. So what I'm going to do is get hold of one or more user credentials. I am going to get into your network. And I'm going to do things like find your IP, perhaps some going to impersonate one of more of your employees, get them to do things like pay invoices, et cetera. And I could also install some malware, get more credentials, encrypt your data, et cetera. So hack is a very destructive process. And then who am I to say I could do this. Well, I'm a design authority here at Intercede on the MFA and PSM products. That's a very technical role. But I'm also an ethical hacker, specializing in password cracking. I'm a member of the Hashmob Pro password cracking team, and we go to conferences and things like Defcon, and we'll take part in password cracking competitions. And our goal really is to prove that passwords by themselves, especially how we use them, are not very secure. So to understand password cracking, let's briefly and I'll promise you this is as technical as I'll get today. Let's discuss how we store those passwords. So typically, if you go to a website, such as this LinkedIn and you sign-up, that site will take that password, but I wanted to actually store that in plain text. They'll still that uses something called a hash. Hash is a one-way function. And all you need to know about a hash is, if I put the same text into that, no matter what that text is, I'm going to get a string of bites back out called a hash. That's always going to be the same. So same text in, same hash out, but it's a one-way function. So if I'm looking at that hash, I can't tell you the text that you put into that function. So how does this work in practice? You come back to LinkedIn, you enter your user name and you type in your password. And what that site is going to do is they're going to take the password you just entered. They're going to hash it again, and then you're going to compare that hash in the database. And if those hashes match, we know you've entered the right password. So we don't know what password it is, but we know you've entered the right password. So that's a really elegant mechanism. And on the surface of it, that sounds like quite a good implementation, but there are a few problems. So the first thing, as Klaas was saying, it turns out these databases get breached all the time. For instance, that one on the screen there, that's motherboard breaches about January this year. And there was a whole lot of breaches, including LinkedIn, some other big companies there. And how do these breaches happen? Well, a few things. So the first thing is something called a SQL injection attack and that's really where people are using that front end into the database in ways they shouldn't be to get more data out of that database than just what the front end wants. And quite often, those databases are just configured as well or easy to access, again, get all the data out of that database. And something we're seeing quite often as well is people administrators will need to back up, move the databases around, and they'll need some way to put a large amount of data, they'll put it somewhere in the cloud, they'll forget about it. They won't protect that resource. And weeks or months later, other people will come across these backups. And finally, you might just have a careless or disgruntled employees sharing this data in some way. So that's not truly [Technical Difficulty], right? Because that password is hashed, and no one can tell what it is. But here's the interesting part. So as a hacker, if I take, for instance, just take the most common passwords in the U.K. last year, those are the most common passwords. And I have this off-line data, I could use this data as much as -- as I like. I can start hashing those passwords and I can compare them to the database. And you can see here, I've chosen a really, really bad password, password one and those 2 hashes match. So we say I've cracked the password. So that now means that I have credentials to access LinkedIn, I could go into LinkedIn using those credentials. Interestingly, the point when I access LinkedIn is the point that, that becomes illegal. So up to then, cracking perfectly legal. As soon as I access that resource, that's where we cross the line. Most of what are -- the rest of the things I'm going to talk about today, all illegal by the way, wouldn't actually do that. And -- so obviously, I think we can see that the more chances [Technical Difficulty] to have of finding out passwords. So we could start just by opening up a browser, anyone can do this. It could drop some plain text into that and generate the hash and compare that manually. And let's say, that's cracking at 10 hashes per minute. But I can install just a little bit of software, any regular machine, the flat top would do really well. And I could take it from 10 per minute to 50 million hashes per second. So I can really, really increase the number of guesses I'm having at that password. And to put that in perspective of possible passwords, upper case, lower case, special characters, up to 5 characters in about 5 minutes. Taking that one step further, here's some hardware I built, off-the-shelf hardware, anyone can get hold of this. That's actually a bitcoin mining motherboard and some gaming graphics cards [Technical Difficulty]. It does actually go bang market at sometimes if you're not careful. But really, what we're doing now is exponentially cracking at a higher rate. So after roughly 324 million hashes per second, suggest many, many, many guesses. And again, all of those passwords pass up to 8 captors in about 6 hours on this kind of hash. And taking that to the logical conclusion, [Technical Difficulty], you've got pretty much unlimited hardware. We estimate -- we think that they could go after any password up to about 11 characters in hours or maybe a small number of days. And how do we work that out? Well, we think that's about 95 raised to the 11th power, so 11 characters. Where does the 95 come from? If you look on to your keyboard, you're setting a password, there are about 95 different characters that you can choose on your keyboard. So that's the heuristic news there. So that's obviously very problematic. So I'll take my hacker hat off for a moment and say, okay, well, how can we improve the situation? Well, actually, [Technical Difficulty] types by default are probably not suited to storing password. So we can use stronger hashes. So hashes specifically designed to slow hackers like me down, technical term is [ we ] are going to script. And then we go all the way back down to about 3,000 hashes a second per one of those GPUs that I showed you. So all the way back down to a very, very small number of guesses. So what you can see here is -- so actually, within the password-cracking community, we get a [Technical Difficulty] will eventually crack about 97% of all those passwords [Technical Difficulty] weak hash if it's a poorly chosen hash. But what's really much more interesting here is that we'll also crack [Technical Difficulty] all the passwords with a really strong hash. And it doesn't matter how strong that hash is. Those are still the numbers we're going to achieve. And how you'll, of course, wonder how are we going to -- how is it possible to achieve that. And really, it's because at this point, as hackers we're going beyond brute force, we're going beyond like purely a technical exercise, and we're thinking more about human behavior. And we know that people tend to share passwords or similar passwords between accounts. So what we're going to do is we're going to take those passwords from the easy to crack breach. When we take your e-mail, we can take those passwords over to the really, really hard hash, and we're going to try those against the hard hash. So again, we're back to tens or hundreds of guesses, and that's how we get to this number of 15% to 20%. So that's interesting, James, but how is this a threat to my business? Well, we noticed when we log into LinkedIn, I am -- I'm most likely going to use my company e-mail accounts, it's LinkedIn. And I'm going to enter that password. But we know that we're sharing passwords. So we know your employees are going to be logging into these various sites. And it's highly likely they're going to use the same credentials. So no matter how good your internal security is, if you're using a password, you can't -- you don't have any control over the poor implementation of password security outside of your organization. You're going to get compromised because of the password-sharing problem. And does this happen in the real world? Absolutely. So in the last few months, we've seen that this has happened to Microsoft, an Asian state has found some kind of exposed endpoint. And they've managed to use a breach password, a breach credential and gain access to the e-mail accounts of all the senior executives in Microsoft. So -- and this happens all the time. And if you read through these articles, the interesting thing that people bring up over and over again is this is a legacy account, it was hacked because it had no MFA. So even in an organization like Microsoft have still got the ability to access these endpoints only using password security. So let's talk briefly about MFA. So a good way of explaining MFA is there's multiple factors, but these factors are something you know. So that will be a knowledge factor normally a password, but it can also be a pattern of some sort. And it's going to be something you have, so a device or a token of some type. And more recently, something you are, so biometric, a fingerprint, something like that. So we combine these factors together in our authentication process to add multiple checks to make things more secure. So quickly, just looking at something you have. So we probably all use our mobile devices for MFA. It's a good option. But we can also have dedicated devices. So you may have used an RSA token in the past or you may have a YubiKey. So these devices typically look like this. This is a nice one, it's got a fingerprint reader on it as well. Or there might be a smart card. It's something we're very familiar with at Intercede. So that's something we have. And how do these work? So typically, if it's your mobile device and you set up MFA on something like LinkedIn, LinkedIn know your mobile number. They're going to generate any kind of random code, send it to your mobile device, you should be in control of your number. You're going to get that message. You're going to type that random code back in the website, and that website knows that is you and not someone else. So that's SMS. So I mean, a little bit more complicated or we can pair your phone cryptographically with the server, establish a secret. And then typically over 30 seconds or a minute, we'll be generating a new code view. And because there's a shared secret, those codes should match. And when we challenge you, you can enter the code, we can recalculate that. And again, we know it's you because we established that shared secret when you were verified. This is attractive because it works off-line. So you don't need to be able to receive SMSs. And then finally, for your sort of gold standard of MFA, you'll have something that's plugged directly into the device that you're actually using to access the resource. And then that determination of you've got that factor happens at the protocol level through some kind of cryptographic process. So that's something you have. But we also have something you are factor and that's generally biometrics. And I call Apple out here because they're really driven biometrics in the consumer space and made it something that we're all familiar with. So Touch ID first came out on iPhone 5, first use of fingerprint technology for consumers followed up with Face ID in 2017. And I thought I'd just briefly mention Optic ID, which is brand new. And that's a retina scan-based authentication. It's really interesting. If you're wondering what that is, that's come out in new Apple Vision Pro that's the VR headset, if you haven't seen it. What I find really interesting about this is that's scanning a retina whilst you're using the device. So that's something Apple call spatial computing. What's interesting here is that you're authenticating inside that device without even realizing it. There's very, very little friction there for users. And that's important because I'll get back to that later. So that's MFA. So obviously, as a hacker, we're going to want to bypass that. And the first example would be how just one [ commonly ] bypassed the SMS implementations. So what we have here, if you can see on the screen, is the math of the U.K. I've taken a representative of a mobile phone provider that's 337 stores, but your threat model here is that one either disgruntled employee that will take a bribe or perhaps have been placed there by a criminal gang. And all that person has to do is issue a sim card with your mobile number to anyone who's paying for that. And they can now receive those SMS messages. So that's called sim swap. And I had a quick look online, and we could really find that 68 million in losses in 2021, and I'm sure that number is much higher now. So that's an SMS bypass. And really, when we talk about bypassing MFA when you talk about phishing. So the interesting fact here is that as we add more technology to the authentication process and we try to put more technical barriers in the way, as hackers we're going to step back and say, okay, what's the weakest link in this process? And that turns out to be the human being. So instead of hacking the device with the technology, we're just going to hack the human instead. And that's basically what phishing is. So some examples here. The first one I'd like to call authenticate the scammer. So I'm the scammer, I called you up, I'm trying to get into your bank account. This actually happened with Chase in the U.S. I call you up [ and keep around ] the phone while my [indiscernible] phones the bank. Now the bank need to verify the accomplice. So the bank sends an in-app alert to me. I'm on to the target. Target's on the phone to me, they're going to confirm that MFA request doesn't really matter what it is. And you let the scanner in. And I'm on the phone to you, I say, thank you very much, problem solved. And I now have access to your accounts. And probably the first thing I'm going to do is change the phone number or add another mobile device. So without really having to have a high level of technical expertise or just bypass all the technology that's been put in place by the bank. Another variation is a pushed fatigue attack, and this happened with Uber and an external contractor. So around September 2022, hacking group, Lapsus$, they obtained some credentials. So they already obtained some of those breached password credentials. And they took a BPM external access points. And what they did is they just started raising MFA requests over and over again. And those appeared as push requests on that external contractors device. They probably chose late at night or on a weekend. And eventually, what happened was that contractor said, I just want these messages to go away and they pushed to accept and they authenticated the hackers and the hackers got access to Uber's internal systems and did a lot of damage. So again, just using the technologies that's there, very low tech attack and exploiting human behavior. And the final attack, I'd like to talk about here quickly is person in the middle, you may have heard of that as man in the middle. So what we have here is 2 websites. On the right, we have HSBC. And on the left, we have a site that looks very much like HSBC, it actually functions in exactly the same way, but it's running on hsbcdirect.code U.K. difference being that's the site I control. This is an actual URL by the way. And it works something like this, I'll phone you up and say, hey, there's some problem with your account, a couple of thousand pounds has disappeared. And you should do something about it. But don't trust me, here's a link, click on this link, and take a look at yourself. You'll go onto the site that I control, you enter your username, your password, and I'll replay that onto the actual session. And that session will raise the MFA requests, whatever process is in place. And I'll gain access to the bank again. And on the site that I'm showing you, I'll just say, oh, there's a technical problem. Please come back later. So again, a slightly more technical implementation. But again, I've bypassed the extra mitigations that have been put in place by using a phishing attack. So what's the solution here, taking my hacker hat off again. So really, when we think about MFA, we're assuming that the resource we're accessing and the device we're using to do that is co-located with that factor being a phone typically, and those are in the same place. But most of the time, that actually -- it actually doesn't work like that. So mobile phone network, that phone could be anywhere on that network. And with an app generating codes, that app, again, doesn't have to be co-located. So if we use something like smart card or USB, Bluetooth, et cetera, those protocols guarantee that those 2 devices are in the same place. So even better what we can do is at a cryptographic level, at a very technical level, when we set up that credential, we combine that credential to the domain of that website. So that authentication will only ever succeed if you are actually visiting that domain in the browser. And what I've just described to you basically is the basis of FIDO and passkeys, which you heard earlier. So that goes a long way to solving a lot of these fishing problems. So I just want to briefly talk about emerging threats and where I see this landscape going. So the first thing is something I'd like to call malware-based credential theft, and Klaas mentioned this earlier. So if you've ever logged into something like Facebook or your LinkedIn account, you've authenticated, but then you've closed the browser and you've gone away and you've come back the next day. You open the browser again. It doesn't ask you to authenticate again. You're already logged in. So as long as you're on that particular device, those authentication credentials are stored on that device. So that's done for convenience. Generally, that's put into something called a cookie. But as a hacker, that's really, really attractive to me. So if I can get some -- if I can get you to install any small amount of malware on your device, I'm going to get all those authentication cookies. So now instead of having to phish you or hack you or in each one of those separate sites, that's going to scoop up all those cookies and we're going to gain access to all of those sites. And that site may include your password manager or it may include your Gmail accould, your e-mail accounts. And that's very attractive to me. Why? Because if I control your e-mail accounts, I can go to any website and click on the forgot password link and it's going to send me a password reset message to the e-mail account that I now control. So that's very, very much something on our radar within the product team. The next one is really interesting. So AI generates content deep fakes, a very relevant and topical. So we're probably also familiar with those e-mails, you get from time to time the so-called Nigerian print scam, promising you a large amount of money. But generally, they've been pretty easy to spot, right? The grammar hasn't quite been correct. The English language is structurally or sometimes not so structurally right. But with large language models and AI generated content, pretty much anyone with a browser can now generate really, really convincing e-mail and really, really convincing copy in that e-mail. And taking that a little step further, start integrating personal details about yourself and write that into these phishing mails book on an automated basis. And just the last few weeks, we're starting to hear about, for instance, there was a U.K. engineering company, big engineering company. Financial Controller was contacted, said, please get on to a video conference call and they go on to video conference call, senior leadership team, and the leadership team said, please transfer GBP 20 million to this account. The thing being that the people on this call were not actually the senior leadership, they were deep fakes generated in AI. So predicting the future always a little bit risky, a little bit hard. But I think we could see 2 ways that we're going to start addressing this. So first thing is we're not going to authenticate you when you log into -- just when you log into your network, we're going to need to authenticate you all the time. So when you're doing anything [ important ], signing on to a video conference, sending an e-mail, we're going to re-authenticate you. And that's why I said something like retina scanning, even though that's very early days where the user was not -- has got no impediment to completing that authentication process a very, very easy process. Once we have that, we can start authenticating you all the time, and there's not going to be a pushback from your user base. The other thing with AI generated content in deep fakes is, we're going to have to start identifying you, where did that content come from, and we're also going to start signing the actual content as well. So if that video came from Klaas, I need to know, did that really come from Klaas. And also, can I trust that, that content was created by Klaas. And to do that, we signed that, we already know how to do that and to sign things, you need PKI. So that's very promising. We already know how to do that. So again, early days there, but potential avenues for R&D. So last slide, which is good. It's getting very hot. Summarize how would I hack into your business. So I'm going to check for those endpoints and users where there's no additional MFA. I'm going to use breach credentials. So we're -- in Intercede, we have over 8 billion credentials. So that's one credential for everyone on the planet. Bad actors are going to have access to that data as well. So if that's not possible, but maybe the target is slightly higher value, I'm going to start looking at your weak MFA credentials, and I'm probably going to use some kind of social engineering attack against you. And then when you've got really high assurance, so at the top of that pyramid that Allen was talking about, I'm going to just bypass that technology completely. I'm going to use some kind of phishing attack, I'm using some kind of AI generated content, faked e-mail, faked voice is very -- is becoming more and more common or perhaps even a fake video. So that's all I have to you. Thank you very much, and I believe that's the coffee break.

Klaas van der Leest executive
#10

Perfect. Ladies and gentlemen, thank you very much. [Break]

Allen Storey executive
#11

[ Rick and Ernie, ] you can probably work out which one of us is which, but we'll look at that. And just before we kick off, James would like to point out that he absolutely didn't disappear and [ stalk ] into any of your systems, that didn't happen. Okay. So we're going to show you some product, but we're going to try and make it a little bit more interesting. We're going to take 3 customers and what problem did they have and how they actually used our product. So just taking some sample customers to give you a feeling for our customers. On the left-hand side, government customers, very much driven by regulation. This is just a sample that's probably over 150 customers in total. But the pattern is they all tend to have something to protect. That's either driven by regulation or it's driven by a lot of intellectual properties such as BASF, T-Mobile, they have to protect customer data; and patient data, the NHS, for example; or financial transactions. So all of our customers have something they need to protect. On the left-hand side, we have government, so very strong in U.S. federal government because there's that regulation saying we absolutely need to know who our people are and who's authenticating to our systems. We're also strong outside the U.S. So we've got Singapore, we've got the U.K., we've got the Netherlands, we've got the Kuwait government, for example. And then the second one in that aerospace and defense tends to be suppliers into government. As Klaas also mentioned, we've got lots of interesting logos. We're not allowed to put on this slide as well, which we'd loved to, but we just can't. And then we're into the more finance health care industry. So these are more generic sectors where people have realized they've got something to protect. So what we're going to do is we're going to pick one of each that represents use of the password security management, multifactor authentication and the credential management system and describe that customer and what they needed. So the first one we're going to look at is BeyondTrust. So these are a U.S.-based company, over 1,500 employees, got about 20,000 customers around the world, multiple countries. They provide identity and access security, software consulting systems to multiple end clients, a significant number of them in the finance industry. I'll be surprised if you weren't a customer of these, at least some of you have been probably a customer of these. So the problem they have is that they were concerned that passwords were being used for online work services, but those were also being used for online services. So the problem that we've described here before, if your organization does what it can to protect its passwords, if that password is also used for [indiscernible] mobilestuff.com or Marriott or LinkedIn or anybody else, it's probably going to end up online, and they were absolutely right to be concerned about this. So this is something that genuinely happens. So they were concerned that data breach was recurring and their employees will be using passwords. Bad actors would then take those passwords and try and break into the organization. But they also wanted to try and follow best practice. So NIST pushed out rules on what is best password practice. And if it's a CSO, if it's a CTO, you're following best practice, you're far less likely to get fined or lose your job if you can point back at the standards you're following. So standards, yes, they have a real benefit in terms of saying, I am secure because I'm following these standards. But from an organizational point of view, they also point to the fact that you're taking this seriously and you're doing the right thing. So that's the problem they have. So what we actually deployed was a combination of access into our password breach database. So that's in the cloud. That doesn't go on the customer site. That's our database that we keep populating. When password breaches happen on the dark web, they go into that password breach database. That's then available to Intercede. It's available to our partners. They can look into that portal and say, what does the bad actors know about this firm? Next one down then is the [indiscernible] Password Security Manager product. So this is the software that gets on installed on the organization site. And that will do 2 things. It will check, are you using good quality passwords? But importantly, it will check they're not actually known to be compromised. So I hand over to my colleague, Jamie, who's actually good to show you what experience the end user had with the product.

Jamie Smith attendee
#12

Yes, my name is Jamie Smith. I'm a Solution Architect/Presales Consultant for Intercede. To put that easily, I work with the [indiscernible] to protect you from the James'. So I deal with our customers. I put the solutions together as well for them. So a key issue that our customers have is understanding the reality of their position at the moment. So like BeyondTrust, what passwords have been compromised, where do I need to look. And this is where our password security portal comes in. It's handy for that purpose. Another purpose we have is when I work with our partners, our systems integrators. When they're talking to new customers, we can actually use this. So we can say, look, this is already known about you. This is what the bad actors know about you. So that's a huge bit of kudos you can get, that's really popular with them when they go in and they talk to their customers. And it just gives that a whole range of information. So if we can play the first video. So I've chosen a company called acme.com, not one of the 23 breached ones in the audience today. But this is an example of the portal. Here, we can see the different -- the domain. And you can see all the different breaches. Each little dot on that line is a breach that, that company has been involved in. So data from that has come in. This is good for them to know. We were talking around malware incidents. We're getting a lot of calls these days from companies that have a malware incident. And this will tell you what information has been leaked on that malware incident that's available on the dark web. So very good information. We also can look at the different users. So here, we can see a user with the most compromised passwords. It's quite interesting when you actually look at the passwords. You can see the password evolving over time. They may add an extra character, they may put the month of the year in or whatever. All that stuff is guessable. So here, we can see not only that user and their password, but also other systems that have also had a password breach. So I may be Jamie Smith at inducy.com, I maybe Jamie Smith at playstation.com. And if my PlayStation password has been hacked, you can bring that back, and you can see that same password has been -- is available out there and it's on the rainbow table, it's very easy for people to guess. So this -- that's our security portal. If you want to have a look, by the way, talk to us, and we can actually run a search for you as well. So we won't tell anyone, but come and have a talk if we can actually show you the information that's available for different companies that's there. So once -- what tends to happen from that is when I talk to customers, they look at that, it moves into what we're talking about earlier, which is an audit stage. So that doesn't actually touch the customer's network at all. This is just start web information. What we can then do is go to audit, look at what's on their active directory, look at their password database and then securely compare that against our breach database. We can do that on-premise as well. So the customer -- again, this is really good information. So you can see not only the breach passwords, but you can see if a password has been shared. So you may have an administrator who's giving the same password out to every new user and telling them to change it. And when they don't change it, it's there. Or we've seen with the Microsoft account, you've got accounts that haven't been used for ages, and you've got passwords in there that have sat there for a long period of time. Here, what is a black box of what the passwords are in your organization. We actually put levels of control on it. We do risk analysis of it. And you can have that as an audit that we put in our password security manager, set up some corrective measures, run that audit again, and you've got actual demonstrable controls there that your organization is putting in better password security policy, that which is great to all these accreditations. So here if we look at our next video. So here, we're going to see user change their password. This is our portal. We also intercept any password changes. So it can be password changes when the Windows log on or whatever. And you can see here, there are actually the little green lights are coming on when they're taking the various checkboxes that we've set up. This is a very complex password. But it's giving very clear information back to that user, what they have met, what they haven't met in real time, [indiscernible] IT desk being hassled. And there's a little line at the bottom there with the date going across. What you can say is if they've got a 12 character password, that's okay for a month, if they start bringing that to a 16 character that we can maybe have 3 months or make it so that, that password never expires. Now never expire sounds really odd, but this is being checked against our password breach database. So if it's -- if they've got a password that's not known by anybody, why change it? And it's not being repeated in your network, you've got that level of control, make the actual end user happy, keep them using that password. We're looking now at sort of past phrases. So taking 3 words -- 3 rounded words, putting them together, something you remember, it's sufficiently long. It's not been breached, and you've got that level of control. If it does get breached, that again, our password security manager is aware of that. So password that was good yesterday might not be good today. We can automatically make that user change their password online. We could actually hold their account until they actually do a password change. So that level of control takes the -- as BeyondTrust had found, takes what is a black box of password management within an organization into actually something that you can demonstratively control. Over to you.

Allen Storey executive
#13

Thank you, Jamie. So what did BeyondTrust get from that? They're protected against password reuse. If people are reusing passwords, this system will spot that and it will force them to change their password. They get verification of those real time, so they don't have to wait 30 days, 60 days, 90 days for that to actually appear. They can tell them straight away. But they're also following best password policy guidelines now. So if they get audited, they can point to the NIST rules and they say, we've implemented it within the software. But importantly, it gives the users more help as well. So the end users get more help to set better passwords. So it's actually improved the user experience. Second one, we're going to look at is multifactor stronger authentication. So this is Liverpool Heart and Chest Hospital, NHS Foundation Trust. During the pandemic, they started working from many different locations, and they actually found some benefits to that. They found that they could perform better if they let people do things like X-ray reviews, procurement, various business processes from home, from a different location without having to come back to specific offices to do this. Some things you obviously have to do in the building like health operations, for example. Lots of other things they could do very efficiently at home. They also have a bring-your-own device policy. So they didn't issue lots of corporate devices to individuals outside the hospitals. They want people to use their own devices. So that was the background. The problem they have is that they started using the VPN, virtual private network, sure lots of us use this. This is secure remote access into the hospital network, but it was a horrendous user experience. They had a combination of a device generating a code, a password and a user name and it just got really, really complicated for people. So security was a barrier. It was getting in the way of them being able to do their jobs on a day-to-day basis. They also -- it was costly. They forgot the token. They needed to deploy software. They have limited IT resources in the hospital. And when they did have IT resources, they wanted to be focusing on keeping the hospital systems running, not end user authentication. So they basically wanted something that was more secure, but was much simpler. So we deployed multifactor authentication solution that worked with the hospital VPN so they didn't have to change their infrastructure, that working with what's there important to us. We actually used a pattern grid for authentication, which I'll let Jamie explain that. But basically, what we're doing now is, as we're authenticating into that VPN, that's handed over to the MyID multifactor authentication server which is making sure that person is -- are they who they claim to be before we actually let them log in to the system.

Jamie Smith executive
#14

Okay. Next Slide, please. Yes. One of the major problems is we deal with human beings and human beings don't like remembering things and they don't like remembering complex numbers, et cetera. But what they do like and what they can do, and I'm [indiscernible] to anyone is remember patterns. So what we do is we present a pattern grid, which is -- as we see here, a grid of numbers. These numbers are repeating. And the user actually remembers a pattern. So here, we're seeing the -- from the diagonal pattern going across. And so the user's code there would be, in this case, 224154. Now what happens is every time the user logs on, so that would be a website being VPN and the NHS side or even Windows authentication and this also works over mobile as well is a random set of pattern of numbers come up. So if the -- so every time they log on, it would be a different onetime code, but it will be from that patent. One of the great benefits of this for the NHS and what we're seeing as well for managed service providers is you can give this up. There's no additional footprint for the end user. You're not giving them -- you're not giving them -- and I like these things, but we're not giving them a $10 smart card, we're not giving them $40 Yubikey. This is a 0 cost device effectively to authenticate and as well give a onetime password. This is why it's been popular with Riverbed, which we're running -- at the moment, which we as a managed service provider -- to their managed service providers actually giving their users, this is a second form of authentication as well without them actually having to deal with that end devices. So just to show that an action, we can play with it. So yes, here we have, yes, outlook web access. We entered the user name. Microsoft recognizes that's part of our domain, brings up the pattern patent grid. The user can then enter the -- enters their password. So we're actually having this as an additional factor. You can just have it as the grid, but we're actually having this as an additional level of security. So then they put -- type in. They remember their code which -- they remember their code and they enter that. We have a desktop client as well. So if you're looking into windows, for example, again, you can have your password and then you can enter your code, which there would be 114230. And if you can guess the pattern from that, you'd be doing very well because that's an example of how, with the repeating numbers even if your shoulder surfing, if you see what they type, you won't be able to guess that pattern. And that's a straightforward log into windows. Very quick demonstration because it's a very simple technology, but that is able to be replicated at extremely low cost out to customers. And that's pattern grid.

Allen Storey executive
#15

Thank you, Jamie. So the benefits they get from that, they maintain the strong authentication, but they did that with a much, much simpler user experience. So the end user didn't have to carry things around with them. They didn't have to remember things. They also saw reduction in calls to the help desk. As Jamie mentioned, people tend to remember patents, and they don't tend longer complex passwords, particularly if they don't use them all the time. So the help desk costs went down. It worked with the existing VPN, so they didn't have to swap out any additional technology and its support of that bring your own device environment because this is absolutely zero footprint, you don't have to deploy anything out to the endpoint device, so you don't get all of those complex help desk calls coming in saying, my computer is not working. Finally, what we're going to look at is the Federal Aviation Administration. So this is climbing up the pyramid to the top to PKI at the highest levels of authentication. So FAA is part of the Department of Transportation. They're responsible for all civil and space aviation. So when the billionaires get on their rockets and they fly over now, it's actually the FAA that's responsible for the safety flying into space. Very safety focused over 100,000 people. The problem they had is that they needed to comply with the NIST guidelines. FIPS 201 is the name of the standard PIV, Personal Identity Verification is the subtitle. That basically means every single federal government employee, we need to know who they are. We need to do background checks on them. We need to issue them a highly assured strong credential. So they have to comply with that. They had to comply with identity enrollment, so they have to capture information about the people, biometrics, documents, et cetera, before they could do that, and they have to issue high assurance PKI credentials. So you need to do both of those 2 things, check the person and issued a high insurance credential. But if you ask the FAA, where are they based, they kind of point that map and say, "We're based there." Every single state, they've got multiple locations, some of them really dispersed. I'm not quite sure why Alaska has dropped down to where it is, but you get the idea. So literally, some of their locations are a very small building with about 3 people in Alaska. As part of the enrollment process for the FIPS 201, you have to see the person face-to-face to do the enrollment. But the last thing they wanted to do is to get them back in the office again whenever they needed to do anything such as collector card, up data card, solve the problem. So they have that hugely dispersed environment they needed to cope with. And they also have some enrollment data in place, but not everything. So they wanted to add to that data to actually get to the level they needed for FIPS 201, but without throwing everything away. So here, we deployed our MyID credential management system. So what that did is it took data from the existing systems, working with that, what's there is a big thing for us. There's lots of APIs to get data in, pass data out, et cetera. We work with a certificate authority. We work with the card production bureau. So these are people -- the same sort of people who make your credit cards. So generally here, they are geared up for sending cards out to a physical location and they can deal with that distribution part, which made it easier for the FAA, so they didn't have to get everybody into a central office, and we'll explain how that secure later. But we're also using MyID to capture additional enrollment data of fingerprint, facial biometrics, documents, et cetera. And we put in place a secure self-service activation process, so we can actually get the credentials out to the people in a dispersed environment.

Jamie Smith executive
#16

Okay. And firstly, I'd like to apologize for the model used in this demonstration you're about to see. Yes. So we're now heading into the realm of -- so this is really smart card. This is PIV devices, the ultra-secure area. And part of this is user onboarding. And what we're doing here is we're using our operator client, which is a rest react interface, which is run -- is a very simple user interface, we'll see the second. And that just allows the initial collection of the data, but also integration with things like [ LDAPs ] or any other data source the customer has for that individual. So if we play the vid. Thanks, Mark. Yes. So here we have it. It's very simple. As I say, rest react, all this functionality can be externally driven. So you might have an HR system that actually says, "Oh, Jamie is a new starter, I would like a new card for Jamie." Somebody a human being will then authorize that request. Here, we're looking for Delcie. I, as an operator, can only see users that I can see. So part of my scope, part of my team. We have some information from Delcie from the active directory, but we pulled that data in. But we have a strong binding here between our data source now and that user, and we've requested a device for Delcie. So what's going to happen now is we're going to collect the data for Delcie, and that includes reaching out to things like photographic capture and fingerprint capture using federally approved devices, and that's all run from MyID. So if we get next video, please. So here, I'm -- imagine me as a registrar, Jamie sat in front of me and I'm going to collect is biometric data, I enter some details about him. And you'll see -- and you'll see this wonderful human being turning up. So we just connect to that. So we're collecting to an external camera here. And we have this person, that is not a federally compliant image. He's smiling, he's got glare. You can see on the right, the information here. So we've now -- the system has waited until that is FIPS compliant. It could also be ICAO compliant, which is passport based civil aviation. And of course, it's [ Icandy ] compliant already. So there we go. So it collected the image. We're not going to do the fingerprint. This is reaching out to [indiscernible], these are the super expensive readers you see when you go into -- whenever you go into America and it's collecting fingerprints and thumbprints. We're rating those fingerprints. As Allen said, you don't want these people coming back. You want to make sure you've got good ones. So there, we can see there's one that's not discussed -- we'd ask that person to reregister that fingerprint. But that stops him coming back for a second time. And here's an example of just using those devices. So there we go, it captures 4 fingers at once and then 2 thumbs. But this is all different from MyID, reaching out to these federally compliant devices. Literally, systems that have this up and running registered millions of users, part of it, things like transport workers in America, et cetera. We can collect that in from various different sites. Yes. So then what happens is we've got that data. That gets sent off to the -- that gets sent off to a card production bureau, and they produce a card like this. But this is something you don't want to give out to anybody. You don't want to intercept it in the mail. This is a secure way for somebody to authorize themselves as a federal Officer. So what you do is they look at cryptographically. So if it was ever picked up, intercepted in the mail, nobody can actually access this card. The only thing available to it is a serial number. No data on this card is available. So we get that sent to Delcie, but how does Delcie authorize. You can see on the left there, it's a single fingerprint reader. This is the nice and cheap fingerprint reader with a card in the slot. So we take Delcie's fingerprint. You can't read it from the card check if we've written it to the card, but we can do it against our server data. So we're doing a match on server check here. Is this really Delcie? Is this the card, we've issued to Delcie? Yes, it is. So we just go and check that. We check with initial fingerprint. And then we can say, yes, Delcie what pin do you want for your card? And these cards we're looking at now, you can do things like match on card fingerprint from that moving forward. You can use this in FIPS physical access, you can use this against different [indiscernible]. You can use it against different government offices, et cetera. So here, we've got a fully working card. The whole data collection. The whole talking to the Federal Bridge here, which is the American government standard PKI. And the whole issuance process is to FIPS standards. We know because we help them produce those standards originally. And they have a fully working card. And that's been out there working to millions of American federal offices. So there we go.

Allen Storey executive
#17

Thank you, Jamie. So FAA, every year, they get audited, they have to hit what's called an authority to operate, so they have to secure it all day, every year. MyID helps them comply with that security audit. So that's a big part of what they do there. But they also get that remote self-service, not just for activation of the card. If they've locked it. If they lost it, they need to replace it. We can enable all that securely by -- that self-service in those remote locations. So hopefully, that gives you a feeling for some of our customers and how they actually use our technologies.

Klaas van der Leest executive
#18

I think there's a flip side to this as well, whilst we hear the side from Cara, I think it's also important to hear aside from our perspective because as Cara said, Department of State, we were nobody in the market, and we were very grateful that Cara and team chose to bid with us. But so we were exclusive. Subsequently, we've been nonexclusive and nonexclusive for a very good reason, even though initially when we had the conversation that wasn't well appreciated because I take a simple view there are 5 primes that are bidding, 5 system integrators, Guidehouse is one of them. If we are exclusive with Guidehouse and we bid with nobody else, then there are 4 competitive tenders out there that carry different products and that was initially within Guidehouse, Cara got that very, very quick. But some of the colleagues were less appreciative because you should be exclusive. And we said, "No, no, no. I understand it from my perspective," we provide the same solution to 3 or 4 of the bidders, yes? So what the client will see is 3 or 4 bids that include MyID. So there is no argument about who the market leader is in this space. Then the client will make a decision about who they think is the best system integrator. This is where Guidehouse skills come into play. This is where the other system integrate -- you play it your strength, you're good at risk good mitigation. You're good at lifting and shifting from a goth's product, older style product onto a modern platform. You're good program management, you're good at national rollout. That's not what we do. We're just a simple software provider. We just hack code together. And we do it pretty well. But we deliver the same code. And subsequently, that's been very much accepted that we embed ourselves in multiple bids. So one of the ones that Cara was referring to, and I'm quite shocked about this because we typically don't declare who the young clients is where Cara is very happy to declare. But even the last one that we announced in December last year, there were 2 final parties bidding or short selected, both of them carried MyID, okay? Good for us. So we knew we were in a very good space. We clearly had a preference maybe for a party that might win. But that's how we get to the end game. That's how we invest. And the difference we see with Guidehouse is more often than not, the software vendors are treated like second or third rate, were the ones that -- yes, just give us your data, and we'll take care of everything. With Guidehouse we sit on the same side of the table, we work together. And these guys are machines, believe me, they are machines. Guidehouse is a professional services organization. It's all about utilization. So they work the team during the day and then 5:00 afternoon onwards, we start with the bid cycle. That's the way it works. They get the billable hours out of the way and then they start bidding. And we basically are an extended part of their team. We work with the team. We sit there until 10, 11 at night. We worked during the weekends. We set up labs, State was an interesting one. We actually did the demo in our offices. Some of the others we've subsequently won, we have to demonstrate at client's side, yes, with no net external network capacity or access. So and in fact, we have to create our own network, Guidehouse invests a lot of money in hardware and software to basically set up a complete rig and then we demonstrate together the number of hours that are burned on these bids are phenomenal from both sides. But because we sit on the same time in the table. We enjoy working with them because we're treated like we're like an extended employee. So that really works well. The other thing that came up is a point about the exclusivity, talked about how we work again and how we roll out together. And we try and be responsive. And it goes back to your point, customer first. We start with our customer. And in this case, Cara is my customer, but Cara is also my partner. So I need to look after her. So that's absolutely critical in the work we do. So hopefully, with Cara's input and what we heard earlier on from Stefan at Cryptas. On both sides, Stefan also talks about regulation is to DORA in Continental Europe, in the U.S., it's all about regulation. That's why we build our business. So trying to wrap up, and we're trying to stay on time. So how many minutes have we got left. I've literally got 5 minutes left. So where do we start today? We talk about the company, how we position ultimately what we try to do. But today was not just about numbers, numbers are easily accessible to all of you, today was all about how do we position in the market, where do we see the market drivers? What sort of problems, we're trying to solve. We brought James in as our ethical hacker said, okay, what -- would somebody who's on the dark side, do to access your system. We've shown you a lot of data available collectively about you. Clearly, we'll never show individual data, but we thought it was quite a good fun to demonstrate that actually we can collect loads of data that's available free available on the dark web. Yes, we know how to get it, we know how to analyze it. We know how to crack passwords very, very well. We've got some interesting rigs. And when these rigs are on, we don't need any heating on in the office. So there's lots going on. We've looked at some of the case studies. We talked about BeyondTrust. It's another cybersecurity company, but it's using our technology, talk about NHS in the U.K. We talked about the FAA. And then clearly, with Cara, we're actively working with the other companies. So hopefully, that's given you a good view as to who we are. It's our first CMD. We'd love feedback. We're trying to put this together. In addition to the day role, we are busy, which is good. Lots of people flying around a lot of late nights. Hopefully, you found that if we go back to where we started we started about this pyramid, and we frequently get the question okay class, but this is all nice and well. But yes, we know where you started 5 years ago on the top and then you built some more functionality and then you added some more functionality for acquisition, but what's happening with this pyramid. And of course, the parameters flat face in this case. But actually, the good news is we all know if we go to Egypt, there are multiple sites to this pyramid. So clearly, what we've been working on over the last couple of years is to understand where else can we take into scene. We've gone from an absolute niche company at the top to being far more broad-based? And what we're seeing here, the front phase of this pyramid is all about employee identity. We don't do consumer, we don't do machine. This is employee identity. So what have we done on the last couple of years also from an M&A perspective, where are we looking around? I can't tell you which companies, of course, we're looking at, what I can tell you, roughly, the kind of things we're looking at. If this face is about employee identity, we clearly have a lot of skills and knowledge here about how to manage certificates, how to manage credentials. So that's not too far away from what we call nonperson entity. So that's about machine. It's -- and with machines, I need to be clear. We're talking about routes. We talk about service. We talk about WiFi access points. So that's kind of interesting. So we're starting to look at that. U.S. whole new security paradigm with Zero Trust. Mr. Biden has said, look, as the U.S. federal government, we need to become far more secure in what we do. And Zero Trust is a really broad spectrum of things. The good news is there are multiple pillars within Zero Trust. Pillar #1 is employee or entity. Well, actually, I know a company that does employ identity very, very well. But we're starting to look at the other pillars of Zero Trust and say, is there anything we can buy? Is there anything we can partner with? Is there anything we can build? So again, potentially a different side, again, if I was able to twist that pyramid one more time, I talked about can we access different markets. We've always been in the top end. I always say we are a tin-pot outfit based [indiscernible] is really, really interesting, but it's junction 20 on the M1 -- but we've got a client base to die for. When we say small company, you look at our client list, Cara has lifted the lid up for some of the other ones that are not even highlighted on our website. But we are capable of doing real good business with some really high-profile clients. But that's one side of the business. I think there is another side of the business, which is the one I referred to earlier on, is in Germany, we're working with this company called Riverbed. They have actually reskinned our MFA solution, they call it [ Twin Verify ] and they're offering Twin Verify into the SMB market. SMB market, you think of all 5 users, 8 users, 10 users, 12 users. That's not our core business. Nobody like the licenses because if they come in volume, volume, volume, it starts adding up. It's all subscription-based. So we're now starting to pursue different market segments. We got a partner in Germany, I know Siobhan had dialogue with a partner here in the U.K. So we're looking at different sides of this pyramid. So coming back to the growth story, the growth story is all about what can we drive organically with what we've got what can we drive inorganically. And just to be clear, I don't see ourselves, and I repeat, I do not see ourselves as a buy and build. I see ourselves as a company that will grow organically double digit. And as and when we can and as and when we find the right kind of target like we did with Authlogics, we will absolutely do that. We've got more cash in the bank, as Nitil said, so we can probably look a little bit bigger than we did 2 or 3 years ago, but that's a really interesting play. So then coming back to the business case, what do we see as the investment case. Hopefully, we can at least agree that we provide business-critical software in an interesting market. The cybersecurity market is really, really interesting. It's growing a good double-digit speed. We have a scalable business model. Our costs are very much covered by our recurring revenue. And if we look at our repeatable revenue, we know that if we sell licenses, it's highly accretive as we've shown over the last couple of years. Our operating model is clear. We're a software company. We know how to target the market. Tier 1 client base, I don't think anybody can argue about who we have as clients and whether that's credible. And as Allen has said earlier on, there are many, many clients we can't put on there simply because we're not allowed to, whether our partners do, that's up to them, but we're quite cautious. But again, in the U.S., here in the U.K. as well, we do increasingly more work in the U.K., but again, we can't talk about it. The other interesting thing is Net Promoter Score. Again, coming back to these business principles, customer-first, our Net Promoter Score is 50, 5-0. For a software company, 50 is a pretty good Net Promoter Score. I'd like to push it a little bit higher. I'd like to get in the 60s, but Net Promoter Score is ruthless. You find a few more -- you track this and suddenly your score will tank. I think as a management team, I think we're reasonably credible. We've proven over the last couple of years that from what originally was a turnaround business is now a business that's motoring very, very nicely. We're showing good growth. And we talked about is inorganic versus organic, but the starting point is organic. Market-wise, we think we're a market leader. We believe we're a market leader, but it's not just us, companies like -- partners like Guidehouse, they assessed the market earlier on when they chose 2019 to approach us. They were, of course, talking to other parties, but it's not just the partners. It's the clients who are choosing this technology. It's the clients who are choosing to stay on platform for 10, 15, 20 years, or longer serving clients think as in the U.K. is either 21 or 22 years now, and it's a bank. Competitive advantage, we know and feel we can expand that moat we can really defend it well. Our attrition is extremely low. Our attrition is below 2.5% in terms of revenue. We hardly lose any clients. We talked about that pyramid not just the front face of the pyramid, but also the multi-dimensions of that pyramid, which allows us to grow that target account market, not just from a product perspective, from a geography but also go to market, we will continue to invest in that distribution model in that reseller model. We have a relatively small sales scheme, but we can actually work with our partners. We have one of our channel managers currently in Oman. He's based here in the U.K. match is probably spending 2 weeks and months nearly in the Middle East out there. I was in Dubai a couple of weeks ago, at GISEC, one of the largest cyber security shows. We get very, very good interest. And of course, in a market, we love regulation. Yes, regulation is good for us. Regulation in the U.S. has established our business. We now see regulation taking whole foothold in Continental Europe, and we are chasing that business with partners like Cryptas, but also the whole Riverbed conversation with [ Twin Verify ], that's again driving companies in -- particularly in Continental Europe, who have to do something, they have to start using MFA. So we're on that bandwagon. Finally, financials, we've had a couple of very good years. Our KPIs are growing quite nicely. Really good cash flow generation. We have more cash in the bank than we ever had. I go back to 2018 when we were nearly out of cash. And it was a very different story with nearly a [ GBP 5 million ] convertible hanging down, which we retired early. And then since then, we've been growing the cash pile. Debt-free, clean balance sheet, good profitability. We talked about the attrition. We see very little attrition. This is pretty sticky stuff. Once a customer is on platform, they'll stay on platform. We're trading pretty solidly, and we've seen some good share price momentum over definitely the last 12 months, and we think there is significant growth for us in the market. We're working hard. I can't control the share price. I always say to the team, the only thing we can control is how we respond as a company. [indiscernible] we'll do what we do well, and we'll hang on to the coattails of our partners, whether that's in the U.S. or anywhere else, and we continue to drive that out. And I think that concludes the day and I think 6 minutes over.

Operator operator
#19

No problem at all, Klaas. Thank you very much indeed to Allen, Jamie and Cara. Ladies and gentlemen, we'll take some questions. So if you could just raise your hand, I'll pass you the microphone and then perhaps you can hand it out to Klaas as appropriate to do so.

Hai Thang Liao analyst
#20

It's Bob Liao at Zeus. Just wanted to ask a question on competition and just one finance question. But on the competition, just if you could provide a bit more insight into who you mostly see in the market. And when you talk about how competitive you are and confidence in your moat, but what are the key sort of strengths you have against those particular competitors? And then secondly, on the financials and talk a lot about scalability in the software model. Maybe just a little bit more insight into how scalable it is from an operational gearing perspective. And what sort of drop-through you might get in terms of revenues over the next couple of years and where margins might get to in that situation.

Klaas van der Leest executive
#21

So let's start with question number one.

Allen Storey executive
#22

Okay. So on the competitive side, it depends on the product set. On the credential management system, I genuinely believe we've got the best products on the market. We do see others. So we see some people being combined into a PKI. Nexus, for example, Active Identity used to do some [ Extech ] used to be a competitor, but seems to be losing everything at the moment. So on CMS one, I think we're in a very, very strong position. As we move down the pyramid MFA is much more competitive. There are some very large players in that space, Okta, Ping Identity, Microsoft themselves, RSA, Thales, et cetera. So the key there is not to fight them the keys to try and differentiate from them and have that mid-market product in that MFA side. Also bringing [ fine tuning ] into the product allows us to bring that higher assurance into that space. On the password security management, really, the area there is probably some of what we got told by an opportunity recently, which is I love the security that you guys bring what can you do for the rest of the passwords in the organization. So that's why we're looking at coming into competition with more people like Specops, Dashlane, people like that who have enterprise password style management solutions. So combining the security management with the enterprise and password management, but also bringing that in with the MFA. So we've got more of that larger set of capabilities for the mid-market and for the large opportunities with -- it's working with the likes of Microsoft, Okta Ping, how do we add value to those on the CMS side. So more than happy to have a longer conversation. There's a lot I could go into there. But I think we're very familiar with our competition.

Klaas van der Leest executive
#23

Nitil, you want to take...

Nitil Patel executive
#24

[indiscernible] bearing is that we're roughly -- with [indiscernible], we did 17 employees last year. We've got 5 or 6 forecasted for FY '25. We don't see that growing too much. The variable in that operating is now sales commission. And so as our sales increase, we'll see that, as we said, is that the license income for us is highly, highly accretive and it feeds very nicely down to the bottom line. I think one of the graphs we showed you is that 2 or 3 years ago, we were forecasting GBP 1 million of EBITDA and then growth was going at 10% and that was feeding through at about GBP 1.3 million, GBP 1.4 million. I mean that we shifted that to GBP 3 million -- GBP 3.2 million, GBP 3.5 million going forward. And the reason for that is because, again, as we sell the licenses, our recurring income from our support and maintenance is continuing to grow because that's a 20% fee from that license sale. And also because our product is -- our new product is brought out every version is every quarter as our clients upgrade, they're using more of our repeatable professional services, and that's growing and that's now covering 90% to 95% of our operating expenses going forward.

Unknown Analyst analyst
#25

It's Kai from Canaccord. Just had a quick question on the U.S. market, I guess, at the federal level, have you had a guess at your market share in the software of CID space, as a 10% at 50%. Just wondering where do you think that can get to? And then I guess, linked into that is how about the state level, is that interesting to use obviously a lot less seats and licenses presumably, it's also a pretty sizable market. Just wondering how you're thinking about those 2.

Klaas van der Leest executive
#26

Okay. So on the first question, particularly on the CMS side, which is the U.S. business, there is no active market data available. So I can't go to a Gartner over to get market data. There is plenty of scope in that market for licenses for us as we've shown over the last couple of years. I don't know, Allen, you want to have a guess, but...

Allen Storey executive
#27

2025 will be my good feel that we have at the moment with some of the recent wins. I'm guessing it's just -- the data is just not there.

Klaas van der Leest executive
#28

I think there is a lot of space for us to grow into. Your second question, state local, absolutely. As I explained, and you will -- they tend to be smaller, and they may not want to buy a PKI solution on its own, but we have partners who offer fully managed services. So a company like WidePoint in the U.S., NASDAQ listed they offer a fully wrapped servers. So that's actually quite good for the smaller opportunities, but also talking to a very large distributor in the U.S. who's got a very strong foothold in state and local [ slat ] or state local education and taking up the lingo. So we definitely can see a lot of opportunity for growth. And that's the CMS side, but also because we've uplifted the MFA product into the cryptographic side with passkeys FIDO, we can see real good opportunity now going forward. We've lifted the functionality in the product. We've got a much wider market to sell into.

Andrew Darley analyst
#29

It's Andy from Cavendish. When you -- I'm not sure if this is for Allen or Klaas, but when you are talking about your tech road map, certainly at the high level for PKI in the CMS environment, and you're dealing with such large clients. How do you make sure that you stay peer to your tech road map for the greater good of all clients as opposed to being bullied by the enormous individuals who you're trying to serve perfectly.

Klaas van der Leest executive
#30

We have a very good answer to that is every year, we're now running client advisory boards. All our clients in the U.S. are invited. The partners are invited as well. There is generally a trend of areas they want to explore, and I'm sure Allen can jump in here. We're not being bullied by a single client. As Nitil has explained, if a client wants to bring forward functionality that's on our road map, we were perfectly fine with it, but then you pay and we retain. So maybe that's the only way they can accelerate something. But other than that, our road maps are now published, we release software every quarter, which is very different from 5 years ago, 6 years ago, we have one release maybe every 12, 18 months. Now we're on a quarterly cadence. But you want to add anything to.

Allen Storey executive
#31

Yes. So what we find is our customers have common problems. So not just with the U.S. federal government, but even from outside that space. So the customer advisory board, you see the customers talking to each other, and that's really, really valuable for them, but it's also valuable for us because we get feedback of what's important to them. We then tend to put that on the road map, we put it back into the product. So we put FIDO in the product. You could say that was before customers actually needed it, but some of the very large customers, they're looking 5 or 10 years ahead. And they want to know that you're looking at post quantum, you're looking at AI, you're looking at FIDO, you're looking at mobile driving license because they're going to be there in 5, 6 years' time, and they aren't getting that from their current vendor. So I have to say it's not been a problem. And we generally find more we speak to customers, the more common problems we find and the more common solutions we can bring.

Andrew Darley analyst
#32

And then the further question is, how much can you rely on other people's tech like face scanning on iPhones. I can actually open my dad's iPhone. That probably 1 in 400 faces can open a different item. So is that something that you have to ensure yourselves against? Or is this something where you know that you're just never going to rely on that kind of third-party tech.

Allen Storey executive
#33

So it comes down to how secure you want to be, not all customers need to be at the highest level of assurance. If we're talking federal government, they will be using PIV compliant biometrics, there are rules about what level of assurance do you need to get to. So they wouldn't necessarily be allowed to use the face ID on their iPhone at the high level of assurance. They're protecting lower assurance assets they may be able to. So we've always been in the realms of trying to explain to our customers, these are the various options you've got, how secure you want to be as opposed to dictating to then you should be at this level because our customers are generally quite educated and they'll make their own choices. But that technology dependence is very important to us as again, we don't just rely on one particular technology. So the national ID of Kuwait, for example, we issued about 4 million smart cards. So they went mobile, we've issued about 2.5 million mobiles. Initially, they were exactly as you saying there, do I trust face ID. I don't know. They were comfortable with fingerprint. So the way we configured it is, where, you can -- as a customer, you can enforce a pin or you can allow it to use a fingerprint or you can allow to use face ID, but it's your choice for customer, how secure do you want to be. So that's very much the strategy we've been following.

Klaas van der Leest executive
#34

Bruce, did you have a question? Okay. Good.

Unknown Analyst analyst
#35

Just a couple of questions. I was wondering if you could just expand -- you talked about trying to not go directly against some larger competition. I was wondering if you could just expand on that, and also from a sort of go-to-market perspective, is -- are those competitions or -- are those competitors? Or can you still go direct to those whereas you can quite clearly access the sort of federal government U.S. indirectly, does that sort of indirect model lend itself to the sort of MFA market as well and the different customers that you're trying to access within that.

Klaas van der Leest executive
#36

You take the first one, I'll take the second one.

Allen Storey executive
#37

Yes. Sure. So most of our very large customers have invested very heavily in identity and access management solution. And that's typically around Microsoft or Okta or something of that. And it does more than the authentication. It does -- not just is it really [indiscernible], but what can [indiscernible] do or what are the rules around it, et cetera. So when we issue PKI credentials with Guidehouse, for example, often those customers are using them to access Microsoft protected environments. So working with those big players is very important to us. So we wouldn't try and take those head on. But as you move down to the mid-market, particularly in Europe around the [indiscernible] legislation, those systems are very expensive and they're very complex to deploy and manage. So we think there's a gap in the market for something like an Okta light for the midsized market, which doesn't really exist at the moment. So that's very much we're playing, things change over time. But as it stands today, we're very much working with I was in Redmond with Microsoft 2 weeks ago, looking at how we can work with them on deploying MFA solutions in their environment and work with them. So we're very much looking at how do we work with them. On the more -- down the mid-market size, it's a different play. We think, yes, we can compete directly there.

Klaas van der Leest executive
#38

So distribution, your second question. We very much see distribution for that mid-market. We cannot build a sales team that will cover that entire mid market. Siobhan and her team as I said, Matt, one of our channel managers is in Oman at the moment, they are working that channel and distribution very, very hard. And what we acquired with Authlogics is real good, strong distribution. So we have 2 very strong distributors, AmiViz and Shifra and they are both pushing our solution set out in that market. And in the same way as we're now using in the German market and again, the MSPs to get to the market because don't forget, again, if you look at the pyramid. The way it works is the MSPs have access to the resellers and the resellers have access to the clients, it would be impossible for us to work with all small individual resellers. We focus on those who've got access to the market and that model works. It works on the high end because we need the credibility. We need the credibility for -- from the system integrator to help that client migrate from legacy platform onto state -- modern state platform like MyID CMS. And that works really, really well, but it only -- it works in that middle market as well in that middle market distribution, as Siobhan has walked those corridors for years. If you look at the [indiscernible] -- you look at the [ HIDs ], that route to market is through distribution and channel, and we're following exactly the same. And clearly, what we have now is we started with that journey 5, 6 years ago. So we've been building our credibility up with reseller channel distribution, bringing Authlogics on board, we can utilize the existing relationships. I know Cara has got conversations within her client base about password security management. If we think that state doesn't use any passwords, believe me, I can show you, I can show in our PSP. There are an awful lot of passwords being used. But a lot of this is about timing. We need to find the right timing. We need to find the right vehicle, we need to find it by partner to work with. So hopefully, that answers your question.

Unknown Analyst analyst
#39

Mike from Equity Development. Do you see [ RFCA 784 ] as a guideline or [ approach ] of regulation towards magic key authentication? And secondly, when that cat in the screen looking at the mouse, when do you wake up one day and find out it's become a quantum cat, you got to think about what it might do?

Allen Storey executive
#40

So absolutely something our customers are looking at. So the quantum piece, particularly, a lot of our U.S. federal government customers are at the absolute cutting edge of security, nation sponsored states. We'll be trying to break into their systems. Quantum is what they're looking at. So we very much never trying to write our own cryptography. We always use NIST approved cryptography. So we're working with hardware security manufacturers, we're working with the smart card device manufacturers ahead of that to look at post-quantum and where that's going and then incorporating that into our own product. My personal view, I think authentication is less of a risk for quantum resistance because as we've done beforehand, we're quite crypto agile. You can just roll out new crypto technologies into the product to move forward. We move from RSA to ECC, from [ crypto base ] to AS. So we've done that before. I think it's likely to be more of a problem for stored encryption. So archived e-mails that are there for a long time, and you can't really easily go back and change the encryption on that without a huge key management overhead. So I think that's more of a challenge. The other interesting attack I've seen is potentially trying to attack signing certificates for installing software. So if you could fake Microsoft certificate, and you can install some malware and everybody thinks it's Microsoft, that's the bigger attack. So yes, yes, we're absolutely watching it. Yes, our customers are asking about it. From an authentication perspective, I think it's less of an issue. I think we've probably got a bit more time.

Klaas van der Leest executive
#41

There are questions on the platform, but I thought we'll deal with the questions in the room first before we go to IMC. I don't know if there's any more questions here?

Unknown Attendee attendee
#42

Any more questions from the room?

Klaas van der Leest executive
#43

The good role of reading the questions, and then I can try and dish them out as we see fit. What's your appetite for further acquisitions? This is a question from Samuel. I think what we tried to explain through the presentation, we started our acquisition journey 3 years ago, we got a full-time head of Corporate Development in-house, somebody who is really, really experienced. So we are definitely on the acquisition trail. We will only do acquisitions as and when we think it's the right fit. Before Authlogics, we had one that we walked away from. Yes, it's expensive because you're paying lawyer's fees, but it's far cheaper to walk away at that point then end up with the wrong acquisition. In total, we've walked away from 3, where we've started [ DD ] And then certainly what you find when you're on the inside, it doesn't look as pretty as when you were originally looking what -- indeed what was sold to you, yes? And we recently had our company kick off in April, and I said, I'll compare it to looking at the kitchen, I look at my kitchen and at least I know what's in my kitchen. I love looking at somebody else's kitchen. But we kiss a lot of frogs when we engage with potential acquisition parties. I tend to come back to my own kitchen sink, at least I know what's in it and I know what it looks like. So we are very cautious, as Nitil said as well, but we're not afraid to invest. So definitely, acquisition is on the road map. There's a bit of glare on the screen here. This one for you, Allen, how is AI impacting your business.

Allen Storey executive
#44

So the major thing we're seeing is phishing attacks using AI. I'll give you an example. I personally got one. So I'm a member of a rowing club, and I've got an e-mail. I'm actually -- the secretary of our rowing club got an e-mail, say, "Hey, Natalie, Stewart contacted me and they've said, we need to pay this invoice by tomorrow? Are we going to get fined? And she sent it to me so it's this legitimate" And I looked at it and went no, but it's really impressive. So this AI engine has gone there, it gathered information from the websites populated a really credible looking e-mail in a really nice PDF form and sent it on. And I looked at it and thought, I would not have looked at that and thought this is fake. So we're absolutely seeing AI videos to generate more realistic phishing campaigns, more realistic websites, bringing in real world content about the person who is sending to. So it's spearfishing. It's a direct attack on somebody. But there's no human being doing that. They're just putting the rules in and the AI is doing it for you. And more and more people are full for it. It's really spot them these days. So that's on the attack side, which is good for us because that drives people towards more fishing resistant authentication such as PKI and FIDO. But we're also starting it seem to be used in terms of cyber defense as well. So starting to look at behavior, starting to look at risk analysis, starting to look at things like some authenticated 10 minutes ago, but now he's authenticating again, and that's an impossible travel situation. So if you look into what Gartner calls shared signals, one of the big trends in the -- there is lots of systems sharing security information between them to make better security decisions and that's going to need AI in there to do that. So again, we started to look at how do we start incorporating that into our technology. So it's both a threat and an opportunity.

Klaas van der Leest executive
#45

So what Allen didn't say with regards to the rowing club, Allen from Yorkshire, so that bill would never have been paid anyway.

Allen Storey executive
#46

That's not true actually, I'm 7/8 Yorkshire, 1/8 Scottish, you can figure out yourself.

Klaas van der Leest executive
#47

Then we're definitely confirmed. What size of opportunity do you see in the U.K. in the U.K. and EU digital ID space driven by regulatory changes. Question from David, David B. I think go back to Stefan's presentation, who clearly indicated there's a step change within the EU and regulation with regards to NIS2 and DORA . It's not just a 1x or 2x change, it is a multiplier change in the market. And we're jointly pursuing that Stefan within Cryptas. He's got huge credibility, again, in the very high end, and that's exactly what we're saying because we're credible on the top end of the pyramid, nobody is asking us for referenceability. We're credible as a company because of the client base we have. So if it's credible on the top end, it's definitely credible on that middle end. But I think Stefan gave you answer, it's a force multiplier that we see in the market changing and regulation in the U.S. has been phenomenal for us. If we see the same regulatory impact in Continental Europe that could actually be really, really good for the business, not just for industry, but also the partners we work with because they typically bring their own IP to the market. And I think that's the last question, that's out there.

Operator operator
#48

That's correct. Thank you very much indeed. I don't know Klaas, whether you've got any closing comments and if not, I'll redirect, just to give you some feedback online.

Klaas van der Leest executive
#49

Yes. It's been great to see you all here has been great to prepare for this. As I said in the beginning, this is our first CMD. We want to learn, we'd love your feedback. I know that Tim and team will be on you for your feedback, and it's not just about in the [ seat ] itself, but we also love your feedback on the content of the material that we're presenting. Appreciate, it's 2.5, 3 hours of your time. You've all traveled in. So very much appreciate it. We know there are existing investors in the room that are potential investors. So -- we're always available again through Tim and the team. We're always happy to jump on a call or respond accordingly. So on that note, we have some drinks next door if you want to hang around and really appreciate your time. So thank you for coming. Thank you.

Operator operator
#50

Thanks to Allen, James, Jamie, Cara. Thank you very much indeed. If I may, just ask investors to close the session. We will now redirect you to provide your feedback. Good afternoon to you all.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Intercede Group plc transcript - plus 251,000+ transcripts from 12,000+ companies, speaker segments and full-text search - through the EarningsAPI REST API or hosted MCP server.

Get an API key View API docs →

For developers and AI pipelines

Programmatic access to Intercede Group plc earnings transcripts and 251,000+ others is available through the EarningsAPI REST API and the hosted MCP server. Quarterly plans from $105 - full transcripts, speaker segments, full-text search, and the /api/v1/transcripts/recent polling endpoint for ETL pipelines.