Home / Transcripts / Intercede Group plc (IGP) · June 20, 2024

Intercede Group plc (IGP) Earnings Call Transcript

June 20, 2024

London Stock Exchange GB Information Technology Software earnings 59 min

Earnings Call Speaker Segments

Lily Kushner executive
#1

Good afternoon and welcome to the Intercede Group PLC Investor Presentation. [Operator Instructions] Before we begin, I'd like to submit the following poll. And I'd now like to hand you over to Klaas van der Leest, CEO. Good afternoon, sir.

Klaas van der Leest executive
#2

Good afternoon, Lily. Good afternoon, everyone. My name is Klaas van der Leest. I'm the CEO for Intercede. I would like to welcome both existing investors as well as potential new private investors to this session, in which will cover our interim results presentation for the period 1st of April until the end of March 2024. During this presentation, I'm joined by Nitil Patel, who is our CFO, and Allen Storey, who is our Chief Product Officer. Whilst this presentation is us presenting to you, we do look forward to your questions, but also your feedback after the session. So, without further ado, let's start with the presentation, which will provide us with a financial update, as well as an insight into the markets we operate in and how we're expanding our target account markets through additional features and functionality in the MyID platform, which now consists of 3 product lines. So, let's start. Introduction wise, very quick intro of the 3 of us. We do progress report, product strategy, summary and outlook. There's a few slides in the appendices which we do not aim to cover, unless they are being raised in the Q&A towards the end of this session. So 3 of us, on my left hand side, I see Allen Storey. Allen is Chief Product Officer. He's been with the company over 20 years. He's a specialist in our area, understands our markets, our customers and prospects as well as channel partners incredibly well. For his sins, he also runs the marketing team. Nitil joined just over 2 years ago, does a phenomenal job on the financial side and keeps us all on the right page. I joined Intercede just over 6 years ago as part of a turnaround play, which is well under way now. And we look forward to take you through the presentation. So, what does Intercede do? 30,000-feet-high level. Intercede protects its clients against data breach. Why data breach? It's something we see pretty much day in, day out on the news now. For those of you following the news more actively, NHS clearly is being held to ransom in certain parts. And I think there's a ransom demand for $50 million dollars, being touted around at the moment. So, how do we protect our customers? And again, in simple terms, we try and make sure that our customers don't use passwords anymore where possible and bring them up to a higher level of authentication or, as we call it, strong authentication. We do that simply, we do that securely, and we do it at scale. What we mean with simply is it's standard off-the-shelf software. So, it's easy to implement. It's easy to upgrade. It's easy to maintain. Secondly, it's secure. As some of you will know, we work with some of the most security-conscious organizations globally who test our software inside out before it goes into production. So we know this software is secure. And finally, we can do it at scale. With scale, we mean anything from hundreds of licenses to thousands of licenses to many millions of licenses. Our largest clients use between 6 million and 7 million licenses. So, what in effect our software is? It's business-critical software. What business-critical software is, this is probably something that will not be turned off, even though the economic or the financial climate may be harsh. This is something -- the software they use is to basically protect their crown jewels. What we focus on is employee identity. So, it's not consumer identity. We protect employee identity. So, employees, colleagues like ourselves, who need to be protected from a security perspective. We work with around 150 high-profile clients. And again, for a small company, we always say, hey, we're small, but we punch well above our weight when it comes to our client base. We're around 105, 106 colleagues who are split between 2 countries. And the majority of our staff are indeed based in the U.K., with head offices in Lutterworth. And we have a second office in Bracknell through acquisition. And our U.S. colleagues are based just outside of Reston, so they can serve the U.S., U.S. federal market. We've issued many, many millions of credentials, which in effect is many millions of licenses. And we particularly focus on our channels. So, we hardly do any direct sales, which we'll focus on later on. But what's our North Star? Our North Star is really customer requirements. Once we understand customer requirements, then the rest will fall into place. It's also reflected in our Net Promoter Score. Our Net Promoter Score is 50, which is nearly double of what it used to be 2 years ago. We're quite happy that it is 50. But, of course, we always want to push this further forward. Once we understand the requirements, we know what we need to do from a product perspective, what we need to invest in. We do around GBP 3.5 million in terms of R&D investment. But that also makes sure that we have market-leading product. And that's obviously something that Allen and his team work very, very hard on. Of course, we can't do this without our colleagues. Our colleagues are incredibly valuable, and it's the biggest asset we have. Without our colleagues, we can't develop the code. We can't serve our customers. So what we've done over the years is recruit significantly. We're bringing in lots of bright people into the organization. Last year alone, we had 13 net new colleagues, which also underpins what we want to do going forward. And we'll continue to recruit, but recruit in a balanced way. I already talked about our go-to-market strategy. In the past, Intercede sometimes was direct, sometimes was indirect. But 6 years ago, we decided to go indirect, go-to-market model, go through distribution, go through channel, go through resellers. Over 95% of our new business is transacted through distribution and channels. Pricing wise, we're offering fully flexible pricing, both perpetual as well as subscription, which is new, because traditionally, we've been a perpetual pricing model. And finally, M&A as the last piece in the puzzle. We started our M&A journey just over 3 years ago, made our first acquisition just under 2 years ago. We'll provide a bit more color on our M&A journey as we go through this slide deck. Market sizing, I'm not going to go and spend a lot of time on this, but 2 main points on this slide. Point #1 is 2 years ago, the only market segment we could cover is the [ top segment or ] the PKI market. Since our acquisition, we also moved into the MFA and the Password Security Management layer. Second point I want to make is that all 3 markets show very good double-digit growth, which aligns with our stated ambition to drive strong, solid, double-digit growth from an organic perspective. So, we have good markets that we can operate in. Of course, as a small company, we can't address or serve the entire market. We're quite specialists in what we do. We focus on the addressable market, we then focus on the served market, and then ultimately, we grind it down to the actual market we operate in, and what Allen will do in his slides on product management, he will focus on how we position the 3 product lines in the markets we're operating in. But we see ourselves as specialists, and we're being recognized as specialists in the markets we operate in. But what is clear compared to 3, 4, 5 years ago, the target account market that we operate in today is materially bigger than the market we were in when we were just focusing on the PKI part of the industry. So, what's our growth strategy? Our growth strategy is based on 2 pillars. The 4 blocks on the left-hand side is all organic. The 3 on the right-hand side is inorganic. So what do we focus on? We focus on landing and expanding. We target our prospects and customers quite heavily. Once we get in, we may sign the first set of licenses, which could be 20,000, 30,000 licenses. And then we do up- and cross-sells. So, basically, we'll try and increase the number of use cases within that client, so over time, the client buys more and more licenses. Through acquisition, we can also now do vertical land and expand because we know a lot of our customers don't just use PKI or our CMS product, but they also use multifactor authentication elsewhere in the organization. They may even use Password Security Management. So we can expand both horizontally in extended license use across 1 product line, but we can also expand vertically across the multiple product lines we now have. Of course, we're always looking for new features, and we're very good in launching new software every quarter into the market. We're also looking for new geographies. We've moved into Asia Pac more extensively. We've moved into Brazil, but also look at new specific market segments. And again, we'll provide a bit more color on that. But again, to be clear, our main ambition here is to drive organic growth. We are not a buy-and-build, but as and when we find interesting IP that we can acquire, then clearly we'll do that as we did in the case of Authlogics, which, again, had proven IP, had some good recurring revenue, was close to profitability, and actually brought us real good traction into the Middle East. At this point, I'll hand over to Nitil, who will talk about progress report and financial results. Nitil, over to you.

Nitil Patel executive
#3

Thanks, Klaas. Hello, everyone. So, on the left-hand side is progress report on FY '24 and then some key highlights, especially Contract 1 and Contract 2, which we announced during the year. It has been a record revenue for the group. We recognized GBP 20 million in revenues during the year. And that's been a good feed into the bottom line of that profit of GBP 6 million. And that's converted very nicely into cash. Our operating cash generated from operating activities was GBP 9.6 million. We ended up with a cash balance of GBP 17.2 million at year end with no debt. And as of 31st May, we got about GBP 18.5 million. So, we continue to concentrate on revenue and cash conversion and a strong balance sheet, and we'll tell you why we're doing that. And it's not just about deployments. We've had 17 of them in the year, again, a good number for the group. We've also been investing. And Allen will explain later on, where we're strategically increasing our headcount, planned increases in development and testing, to increase our advantages on the CMS and bring our advantages into the MFA PSM product. And we've also done some really good numbers for [ PS ] this year. We've done 30 projects for the group across our client base, and, again, that's reflected in the revenues we recognized in the year. As mentioned on the right-hand side, we wanted to highlight 2 major contract wins. The first contract, I think most of you know, was a large order from a large federal agency in December. It was a perpetual order. They ordered 6.6 million of licenses, which had to be recognized immediately because of the points of sale and responsibilities of passing across. But we also had an associated support and maintenance element of that of 1.4 million, which we call recurring, and I'll come to that later to explain why that's an important number for us. The very interesting one is Contract 2. We introduced subscription pricing for our perpetual product during the year FY '24, and this is the first time a large federal agency has taken a hybrid approach to this. They came to us saying that they wanted to buy some licenses in perpetual with certain licenses on our subscription, and that we were able to accommodate this. And we see this as a benefit for us, not just from a pricing strategy, but hopefully from an acceptance from our clients that they can either choose to be more flexible with their pricing and subscription, obviously, with the recurring elements that institutions value is beneficial for the group as a whole. Not all about CMS. It's also about MFA. We're investing heavily in the product, as Allen will describe later, but we've had some good wins, especially in the Middle East, and we'll continue to invest in that area as we expand out. But we're also into Europe and America. And we just wanted to highlight one POC that we're doing at the moment with a large federal, unusual dynamics of this federal agency. They've decided to go down the POC route. We're happy to do so. We've got, at the moment, a 12- to 18-month window, and if successful, we'll see some benefits coming out of the potential POC being successful here. We'll see how that pans out. Financial highlights, just wanted to show you the in 4 screens, how the results for FY '24 were. If you look at the top left, revenue breakdown. And this is really important for us, and we're showing you here the support and maintenance, the professional services, and the license income. Why are the first 2 really important to the group? S&M, what we call recurring revenues, continually comes through. We can have the ability to increase our S&M by circa 3% to 5%, depending on the client and the professional services that I mentioned previously, the 30 deployments, the constant upgrading every quarter of our CMS product, bringing the cadence of MFA, PSM into that process gives us the ability to bank on that recurring and repeatable revenue. Why is that important? Because if we can cover 90% to 95% of our operating expenses, then our license income is highly, highly accretive. And as you can see in FY '24, this GBP 7.7 million converted into GBP 6 million net profit. That's a good result for this group. On the right-hand side, regional revenue. United States dominates, and yes, we've obviously had an outlier in that exceptional contract. But the rest of the world is growing. And although it's slow in the United Kingdom and it's slow in Europe, we're seeing traction, and we see growth coming through, especially with the concept of what's happening in the Middle East and what's happening in Ukraine, and we're seeing some really good opportunities feeding through at the moment, which we hope to convert in FY '25 and FY '26. The last 2 slides at the bottom on the left, adjusted EBITDA and net profit for the year. Why do we want to highlight this? We want to show you that the difference between the 2 is not a lot. And why is that? It's because we, as a company, expense our R&D expenditure into our income statement. And therefore, the adjustments that we make from adjusted EBITDA to net profit are mainly to do with depreciation, amortization, the normal stuff you'd expect from EBITDA to net profit. And also on the right-hand side, research and development, we expended GBP 3.5 million in the year. That went through the income statement. But because all the money is spent in United Kingdom, we benefit from the U.K. tax system on R&D. So, we used to previously claim in arrears cash because we wanted the cash. Due to the strength of the cash balance on the balance sheet and the strength of the capital structure of the group, we've decided to elect not to do that going forward. And as we're forecasting profits for FY '25 and '26, we're going to generate the tax losses on R&D tax credits and shield them from our profits going forward. The reason we're doing that is simple. The arbitrage on the tax rates, 25% corporation tax versus a 14% tax credit on R&D [ for the 11th ]. Income statement, it's a very simple income statement. We report the top half. The bottom half is just for presentation purposes, mainly for institutions. As expected, revenue is a key element of focus for us. Why is that so? Because obviously with the control of operating expenses, we can then feed that into the bottom line. Operating expenses increased, not surprising, 80% of our costs are people. But also, there's a variable element to it. So depending on the revenue streams that we deliver in the year, sales commission and bonuses are attached to that. As you can see, the net finance income was strong. Again, that reflects the strong cash balances that we have on the balance sheet. And taxation, again, that's reflecting the tax credit for last year. We'll see in the notes when the annual report comes out that we had brought forward losses of circa GBP 9.5 million [indiscernible] losses. We utilized GBP 6.2 million of that. We've got circa GBP 3.7 million going forward. And now going forward, as I mentioned previously, we'll use R&D tax losses to shield us against the corporation tax rate. One thing we do want to highlight is that we've been asked a few times in the last few months to consider developing a module out of our core product. And we're looking at the feasibility and the economics of doing so. If we decide to do so, we may take an element of core product out and charge that and sell that separately. And to develop that, there may be an identifiable separable asset that we've created with separate revenue streams. And if that's the case, we may have to capitalize. We're not talking a huge amount of money here. The core investment of R&D still continues to be in MyID platform and that'll continue to be expensed. It's just a highlight. Depending on how the contracts are struck and how the core development versus the module development occurs, we may have to apply the accounting standard. Then moving on to the financial position. Again, a very, very simple balance sheet, a clean balance sheet. The big movements here are mainly to do with working capital, which is what we like. Trade and other receivables, cash, and deferred income. We focus on these 3 things because they're really good for building strong foundations to do what Klaas mentioned, the business principles: listen to the customer, invest in the product, invest in the people, deliver on our execution and growth strategies. And we'll continue to do that. And that's fed very nicely into a strong cash generation. Cash generated from operating activities has been GBP 9.6 million, and that's a strong indication of how good our clients are. They pay us on time, it's within the 45-, 60-day procurements with big corporates and government, and we convert that very quickly. And that's good news. What does that mean for our capital structure? I'll come to that in the next slide. It means the group is in a strong position to then continue doing what it wants to do, which is to utilize its structure for investing in our product, growing it, growing its capability in a controlled manner. We're not going to go and do, what, 4 or 5 years, 6 or 7 years ago prior to when Klaas joined the team was to go and build something that we see no economic benefit for, hence why the North Star of the client is so important to us. But we've got a prudent capital structure. We've got a new treasury policy, we've taken a de-risk the element of concentrating our cash in 1 institution in the U.K. We've spread that across 3 institutions. We're looking at how we increase our interest income while we wait to see what happens on the acquisition play. It's a controlled M&A approach. We have a strict criteria that we adopt. If it doesn't fit in, we're quite happy to walk away. We had 3 LOIs last year, and we walked away from all 3 deals because it just didn't stack up for us. But the focus on M&A and the focus for the organic is all about recurring revenue, increasing that recurring revenue, creating an environment that gives us the capability of selling more license income, creating more profits, cash, and therefore shareholder return. On that basis, I'm going to pass you over to Allen to describe where he's going to spend the money.

Allen Storey executive
#4

Thank you, Nitil. So let's take a quick look into the product set, the markets they serve, and where we're investing in them to capitalize on the growth we can see ahead of us in those opportunities. So as Klaas mentioned, our role really is to help protect our customers against data breach. The #1 cause of data breach is a weak credential, so a credential being something somebody logs onto a system with. We use what we call the authentication pyramid to help customers understand the different strength of different types of authentication. So, starting down the bottom of the pyramid, we have passwords, the weakest form of authentication. It's just a single factor. If I steal your password, I can log onto your system as you. We've seen examples of this in the healthcare recently in the news. So most customers are looking to move away from passwords towards something more secure. The next level up is multifactor authentication. So, that's 2 factors, a combination of something I have, such as a phone; something I am, such as a fingerprint; and something I know, such as a PIN. That typically, in effect, generates a one-time password. I'm sure we've all seen these where we've received 1 from our bank or we've typed 1 into an application, a one-time code to log onto it. So, it's like a password, but it lives for a very short time. At the very highest level of assurance here, we are using cryptography-based authentication. So, that's FIDO, which is a standard faster identity online that's coming from the consumer space and coming into the enterprise world. But the traditional strong authentication mechanism here, which is still the gold standard that's been used by governments, aerospace, defense, military, for a few years now, is PKI, public key infrastructure. So this is private/public key based. It has cryptography. And our solution set covers this whole pyramid. So the question we can ask our customers is, how secure do you want to be? Not everybody needs to be at the very top of the pyramid. Being at the mid-level is fine for some people. And we can help them on that journey. The reality is, most people are on the journey from authentication [Technical Difficulty], we can help them on that journey. So just quickly looking at each product in turn and what it actually does. First 1 is Password Security Management. We get it, most people are still using passwords somewhere in their organization. So, even if we're on a journey to get rid of them, while we've still got them, let's make them secure as they can be. The challenge with passwords is that they tend to get reused. They get leaked online. Once they appear in a data breach, LinkedIn, Marriott Hotels, for example, those usernames and passwords are in the dark web. Bad actors will steal that information and then try and break into systems with it. We do the same, but we don't break into systems with them. That would be illegal. What we do is we collate that information via a team of ethical hackers into the world's largest database of known compromised usernames and passwords. So we make that information available to our customers to help protect themselves. So, they can call into that via APIs programmatically if they're using a managed service. We can run audits with it so we can see, are you actually using passwords today that are already known to be compromised, so you should change them? And what we really want is customers deploy our Password Security Management software, which will actually tell them they're using a compromised password and force them to change it. So, if my password was absolutely fine on a Tuesday, it appears in a data breach Tuesday night, Wednesday morning I'll try and log in the system, it will say, stop, this is a compromised password. You need to change it. For customers who need more than managing the security of their passwords, we have more. So, this is a very busy market space. As we move down that pyramid away from the very top end, the number of people needing that technology expands. So, it's increased the addressable market by us moving down that space. But in this multifactor authentication space, there's actually a significant number of competitors. So we have quite a key strategy here. So, what we're doing there is at the very top end, we like to work with the likes of the Microsoft, the Oktas, the ForgeRock, [ the Ping ]. So, that's where the Credential Management System plays. In this midmarket space where our MFA product is targeted, we believe there's an opportunity for a product that is easier to deploy, cheaper to actually deploy, but still brings a high level of security. So, one of the things we've done is brought something from the top end, and that's the FIDO Passkeys capability. So, still a high level of security, but into that midmarket product. So we think it differentiates it in that particular space. At the very top end in credential management, probably the easiest way to describe what this product does is describe one of the regulations that it helps our customers comply with. And that's FIPS 201 in the U.S., Federal Information Processing Standard #201, subtitled PIV, Personal Identity Verification. So what that regulation states is that all U.S. federal government employees and people who work with government data, so that's suppliers into government, such as Lockheed Martin and Boeing and Northrop Grumman, for example, have to follow a certain set of security standards. And there's 2 parts to that. The first is we need to know who this person is, who they claim to be, before we even let them anywhere near the organization. So our software will capture fingerprints, capture facial biometrics, photos, scan documents, check passports are valid, pass that through to background checking systems, which will tell us, is this person who they claim to be. And even if they are, are they on a terrorist watchlist before we let them into the air traffic control tower. Once we've validated that identity, then we issue them a highly secure credential in the form of PKI credentials, private keys on a smart card, and we manage the entire lifecycle of that. So this helps our customers comply with that high-security regulation, and we help them do that simply, and we help them do that at scale up to hundreds of thousands and millions of users. So, looking at where we invest in the product set, we look at what's happening in the market. Key thing that we see in the market is that the level of cyberattack is increasing, the sophistication of cyberattacks is increasing, increased use of AI, artificial intelligence, to drive phishing scams that are very, very difficult to differentiate from the actual real scenario. So we're seeing that drive increased cyber spending as well. What's most important for us is regulation. So, the reason we're very strong in the U.S., we have a significant revenue stream from the U.S., is the regulation there drives customers towards our technology. That regulation, FIPS 201, is starting to expand, so it's driving more use of stronger authentication down the entire organization and also down the supply chain. So, there's some significant growth opportunities there for us in the U.S. Probably a bigger change for us is in the EU. So, there's been a lack of cybersecurity regulation that drive people towards a particular type of technology for a long time in the EU, but that's changing. There's a regulation called NIS2, an information security directive, which affects about 50% of the companies in the EU. That's now being passed at the EU level as legislation, and that states that by October 2024, each member state must have enacted its own cybersecurity regulation, i.e., law. So, that's starting to drive people, and they will have a time to comply with that, but everybody's starting to look at this and how do I need to be compliant? So that, we believe, will drive the market in Europe towards a higher level of authentication, and that's one of the reasons we've brought that high security element, FIDO Passkeys, into that midmarket product. So, looking at where we're investing. I won't go through all of these. I'll just pick some key elements on here. So the slide in front of you is showing our planned roadmap for each of the products in turn. This one's Password Security Management. On the left-hand slide, we have where we are now, so what do we have today? Password breach database, software to help protect people. On the right-hand side with the dot-dot-dot, these are elements we're investigating as research and development. We continue to invest in that we will bring into the product at the appropriate time. And in the middle, we have the first half of the financial year, second half, where we're investing to cover new opportunities. So, the key one I'll pick out on password management here is enterprise password management. So it's not just looking after the security. Is this a secure password? It's being able to provide password management and single sign-on experiences into applications. So we'll learn the password. We will scramble that password within the workplace, and we will replay that application to give somebody a single sign-on experience. I'll come back and show what that looks like in a couple of slides' time. On the multifactor authentication piece, we're really turning this into an access control solution. So, we are deliberately not trying to compete with the likes of Microsoft or Okta who provide these capabilities for very large organizations. There we work with them and we have connectors to them. We add value to them by providing the credential management. But there's a significant population, particularly in Europe, where there are smaller organizations who don't have the IT skills in house and to deploy something as complex as an Entra ID or an Okta. So, we believe working with the likes of the Gartner analysts, looking at what the competition does in this space, there's a gap for a product that brings that capability down to the midmarket. So, I'll explain on the next slide what we mean by access control. So, this is really taking the product we acquired, we've now rebranded, and are taking to market as part of the MyID family, but adding value to it, so we can upsell into existing customers' new capabilities, new modules, but we can also target net new opportunities with it. So, on the left-hand side of the slide, we have somebody accessing the system with strong authentication. Typically, in a midmarket, that will be their own phone because it avoids having to buy expensive hardware tokens. But we can do that with our FIDO Passkey, so that brings that level of stronger authentication and phishing resistance. Once they've logged onto the machine, they're then presented with the applications they're allowed to access. So, this isn't just authentication. Is it really, Sam? This is authorization. What can Sam do? With modern applications, on the top right of the slide, they support protocols called Federation, so that means sharing identity between system. So, for those, we can simply provide a single sign on logon experience to those applications, strongly authenticate once, we can let you into the other applications. The reality is, though, particularly in healthcare, finance, and some military as well, there are some legacy applications that still use passwords. So, what we will be able to do there is for those applications, we will have scrambled that password, we will have learned it, we will play it into the application to let that people sign on, but only once they've strongly authenticated into the system. So, this, we believe, combines capabilities of modern authentication and password management in a single compelling application very much aimed at that midmarket who need high levels of security. For the credential management system, what's key for us is keeping it at the top of the tree as the best product on the market. I realize I'm biased thinking it's the best product on the market, but luckily, we've had independent analysts such as KuppingerCole publishing reports on this, conversations with Gartner we have, and some of the significant wins we've had in the U.S., we believe, give us very credible evidence. [Technical Difficulty]. A lot of our large customers who buy this product tend to look ahead. So, they're looking 5 or 10 years ahead. And what's really important to them is that they're working with a vendor who's still going to be investing in this space in the future. Just picking a couple of recent examples. One of the large contracts we won with the U.S. federal agency, as part of their request for proposal, they were looking at mobile identity, so mobile identity documents, and then we're looking at FIDO, how can I bring that into the enterprise space with those FIDO Passkeys? Because we continue to invest in the product, through our prime contractors, we were able to demonstrate this to the end customer. So, we weren't showing PowerPoint slides on how this work, we were actually showing this working in the product. And that's really important to the customers. [Technical Difficulty] they're concerned about artificial intelligence and how it's being used to create deepfakes and scams, they're concerned over post-quantum where you can have more powerful computers that could potentially crack cryptic keys. We're already working on those. So, we're working with partners to look at how we bring that into the product and bring that protection to our system ahead of when our customers need it. So, we continue to invest. So, hopefully that gave you a quick overview of where we are with the products. But to summarize, we've got a strategy at the top end of working with the very large players. On the mid end, we have a strategy of providing a cheaper, easier to deploy alternative. And down the very bottom of the market, we have a strategy with partners, but I'll let Klaas talk about that.

Klaas van der Leest executive
#5

Thank you, Allen. So if we then try and wrap up and summarize the reporting period. Clearly, as Allen has indicated, there are some real solid market drivers that point towards the use of our type of technology, whether that's U.S. regulation, whether that's newly-formed European legislation that really works well and is favorable for our software offering and particularly our partners and channels are taking that to market. Second point is we've clearly been expanding our product portfolio. Again, 2 years ago we had a single product line. We now have 3 product lines. The product lines are fully integrated, and we're bringing high-end functionality available in mid-market product by adding FIDO Passkeys into our MFA offering. Pricing-wise, we're offering now full flexibility in terms of perpetual as well as subscription, which gives not just us flexibility, it gives the partners flexibility, but also the end client flexibility. We tend to get a lot of questions on this about can't you just drive one or the other? Ultimately we take the view that the customer requirements come first. If the customer has got a strong preference for a CapEx model, they will probably go down a perpetual route. However, if the customer has got a strong preference for an OpEx model or a combination of the 2, we can now offer the full flexibility from the pricing perspective. Fourth point, revenue, margin, and profitability focus, that's something which was extremely high on the agenda when I joined 6 years ago because we were pretty much running out of cash. We were loss making the year before. Good news is, over the last 6 years we've been profitable, we've been steadily growing. Clearly last year has been exceptional year in terms of revenue growth, and we also have good plans to continue to drive that. Cash conversion again has been strong, particularly in the last year, but if I go back 6 years we were well below GBP 2 million of cash. We had a GBP 5 million convertible out there. Today, I think, Nitil reported end of May GBP 18.5 million cash, we've got no more convertible, and we've done an acquisition, which again we paid through cash, so ultimately our cash position has materially improved compared to 2018-2019 and that's also the final point on here that our balance sheet is very clean, very tidy, very unleveraged, and obviously that gives us more firepower, particularly on the back of the cash we have. So, we've made good progress. We had exceptional performance in the last 12 months, but we also feel we got momentum, it's not just momentum in the last 12 months, but we've carried that momentum that we had in the prior year into last year, and we're carrying that momentum going forward. So the other question we tend to get a lot is, okay, you've got a lot of cash in the bank. What are you going to do with that cash? And we want to be clear on this, that part of that cash will be ringfenced for M&A. Now if we start on the left-hand side, that's the pyramid we've basically been talking about for the last probably 3 to 4 years by now, where we started initially only covering the PKI side, we then built functionality, FIDO Passkey functionality into our CMS offering, and then we said, hey, this pyramid is also a very good reflection of relative market size. Clearly, the top is a lot thinner than the middle and the bottom end of this pyramid. So we then had lots of conversation at management team level and also with the Board and said what do we do, because we can see there is a market there, we can see our clients are using MFA, our clients are using Password Security Management solutions, but what will it take to build? So, questions you continue to ask yourself, do you partner, do you build, do you buy? When we looked at the MFA side, we said, look, it will take us 2 to 3 years to build a credible MFA offering into the MyID portfolio, but at the same time we knew that the regulations that Allen was talking about in the U.S., FIPS 201 and now NIS2 in European Union, they were moving a lot faster than we can actually physically build net new products, so we decided to go down the acquisition route. So, what this pyramid is actually reflecting is person identity, employee identity, as I referenced in my initial slides. But, as we all know, pyramids have got different sides. So, from an acquisition perspective, we want to look at what are the other sides of the pyramid. And some of the areas we're looking at, for instance, nonperson entities, we're good on the person side, but there are also certificates being used on WiFi router service, et cetera So, that's an interesting play. It also plays very, very closely to what we do, because even some of our existing customers already use MyID CMS, for instance, to manage nonperson entities. We turn the pyramid one more time, we get to an area particularly in the U.S. where President Biden has announced a new cybersecurity framework, which is called Zero Trust. Zero Trust is more of a concept. It's not a single product, but it's an approach, and the federal agencies will have to comply with that over the next 3 to 5 years. It's not a single shot, it's not a single solution, but it's a combination of multiple products. There are 5 pillars within the Zero Trust framework. Pillar #1 is person identity. Well, that's the pyramid on the left, we understand that one. Second pillar is devices. Well, devices is the nonperson entities I talked about. Third pillar is application. Fourth pillar is network access. Final pillar is data. Data is probably less tightly aligned with what we do in absolute terms, but in relative terms we clearly deal with a lot of data as an application. And then underneath those 5 pillars, the framework talks about orchestration. Orchestration is something again we're very, very familiar with on the top end of this pyramid in our CMS product. So, on each and every angle of this pyramid, we will evaluate whether we partner, whether we build, whether we buy. One of the partnering opportunities that we're pursuing at the moment is the SMB part of the market, which is clearly an area based on our client base we've never been particularly active in, but we're in active dialogue with partners. We've got a first partner in Germany who is pursuing this, who is actually serving the SMB market in a managed service model or MSP model or managed security service provider model. So that's quite good for us because the partner takes care of the entire sales engine and the support engine. The only thing we do is provide code. So, we're clearly quite clear on what we want to do from an acquisition perspective, but at the same time, I repeat what I said earlier on. I do not see Intercede as a buy and build. I see Intercede as a company that's pushing for organic growth, double-digit organic growth, and as and when we find the right acquisition, we will try and bolt it on based on the paradigm we've just discussed here. So, if we then look at outlook, we clearly had an exceptional year, and we believe we're very well positioned to maintain strong traction going forward. At the same time, we need to invest. We continue to invest in colleagues. Last year we had 13 net new colleagues. We're heavily investing in our internal IT infrastructure, we're heavily investing in product development, and we're spending significantly more money on marketing. On the marketing side a lot of that is driven towards events at the moment. A couple of weeks ago, 3, 4 weeks ago, I was in Dubai attending the largest cybersecurity show called GISEC out there. Again, we are participating on 1 of our distributors called Shifra, who had a very nice well-developed stand and, as we all know, in the Middle East relationships are absolutely key. It's very difficult for a company like Intercede to build its own relationships out there, so we use distribution partners who have existing relationships, who have the contacts with the reseller community, and we had a very successful event, and we are pursuing multiple opportunities on the back of that. I've already talked about the pricing strategy. We can now offer full hybrid pricing. Interesting in that approach is that we're pursuing some opportunities at the moment where multiple system integrators are bidding the Intercede solution. Some of the integrators choose to go down the perpetual route, others choose to go down the subscription route, and ultimately the client will decide what's best for them in terms of budget. Final couple of points here is we have good visibility in the pipeline. Our investments are all planned out, and the balance sheet again as highlighted earlier on, we've got very strong cash flow, and we got real strong growing recurring revenues. Acquisition was the previous slide. I believe we've got a very strong strategy that we're pursuing. But as Nitil referenced earlier on, we're very balanced on that, and we're also quite cautious in that approach. We have issued a number of LOIs in the last 12 to 15 months, but we decided not to pursue them as we went through due diligence. And final point, we believe we're exceedingly well positioned to deliver on the medium- and long-term aims of the company. We have a stated ambition to double the revenues based on 2023, and we believe we're well on track to achieve that. At that point, I think I'm going to hand over to Lily if I'm correct or if we go straight to Q&A. Lily, please advise.

Lily Kushner executive
#6

Klaas, Nitil, Allen, thank you very much for your presentation this afternoon. Ladies and gentlemen, please do continue to submit your questions just by using the Q&A tab situated on the top-right-hand corner of your screen. Just while the company take a few moments to review those questions submitted today, I'd like to remind you that a recording of this presentation along with a copy of the slides and the published Q&A can be accessed via your Investor dashboard. As you can see, we have received a number of questions throughout today's presentation. Can I please ask you to read out the questions and give responses where appropriate to do so, and I'll pick up from you at the end.

Klaas van der Leest executive
#7

Thanks very much, Lily. Right, we've got quite a few questions, so let's go through them. First question is from [ Ellen W. ]. Thanks for your good work over the last 12 months. Your outlook statement seems to be a literal copy and paste from last year, which suggests it's not a nuanced reflection of the current state of play. Could you please give some color on how you feel versus this time last year, particularly with respect to the pipeline of opportunities, where you can, please quantify the weighted pipeline, average opportunity size, or at least sizes of the above relative to 12 months ago? Not sure I completely agree that it is a complete copy and paste because it'd be very difficult to do a copy and paste based on record revenues of GBP 20 million. But I do get your point clearly that there will always be some repetition. With regards to pipeline, we do not disclose pipeline or pipeline growth or weighted values into the public domain, but what I can say is that we got extremely good visibility in the pipeline, and we believe there is enough value in the pipeline, both in terms of absolute as well as weighted volume to deliver the budget. Just to provide a bit of extra color on that. I manage the sales engine myself. Every Monday, we have a sales review with both sales teams here in the U.K. and in North America. And if anything, I know because of my cautious nature that the value of the pipeline is understated. So, hopefully that provides you a bit more color, [ Ellen W. ] [ Gary B. ], next question. How do you plan [Technical Difficulty] cash generated from operating activities? Nitil, one for you.

Nitil Patel executive
#8

Thank you, Klaas. I think hopefully this slide on capital structure told you what we're doing. One of the things I forgot to mention on that slide was that we have a strict internal working capital policy where we ringfence 6 months of operating expenses, the bulk of that being payroll and lease commitments, just to give us the buffer and the ability to continue investing and having no debt has, I believe, the comfort zone for us. It does mean we have excess cash. We're not saying we don't. We're looking to do an M&A strategy. We're looking to see how that pans out. We have a head of corporate, internal head of corporate, who's got a very long list, 200, 300 targets, which is shortened down to a 25 targeted list of which we focus on that. It's not easy. We are looking at that. We are looking internally, obviously, at some of the things that Klaas mentioned on the growth pillars, whether we're going to buy, build, or partner. If we're going to build, what is that going to look like, how that's going to pan out. Are we going to do a -- I assume the question is implying on a dividend policy. At the moment, the Board are not planning to do a dividend policy at all. We're looking at investing continuously into our product, ringfencing, being cautious about how we approach the future, but also looking for an M&A in a controlled environment, and putting our cash as we see fit in U.K. institutions, which are giving hopefully 4%, 4.5% of interest income in the coming year. I hope that answers your question.

Klaas van der Leest executive
#9

Next question is from [ Gary B. ] How do you plan to utilize this -- sorry, we've just done that one. Sorry, that was [ Gary ]. Next one is Roger. Do you have regular increases in support and maintenance prices, at least in line with inflation? Generally speaking, the answer to that is positive, other than where there may be contractual restrictions where we can't do it. But generally speaking, we're pretty, pretty firm with applying inflation on the support and maintenance revenue stream. [ Ignatius ], fantastic performance. Congratulations. How big can the company grow without any acquisitions in future years? Secondly, what areas are you looking for acquisitions? I think the second part of that question, we indicated what we're doing. The stated ambition, again, this is in the public domain. Step #1 is we want to double the size of this business based on 2023. And to be honest, I don't see any real restrictions. I always use internally the example of a company called [ Cerillion ]. They have managed to find a breakout. I do not see any reason why Intercede couldn't pursue the same trajectory and significantly grow beyond its current shape and size. Says [ Ignatius ]. Mike P, what opportunities or threats, if any, have been identified in respect of AI? Well, I think Allen has been very patient.

Allen Storey executive
#10

So no problem. So, in terms of threats, it's fundamentally increased use of AI to create phishing scams or spear phishing, which is particularly aimed at an individual that are very difficult to spot. So, you may have received an email saying hey, could you please click this link and review this document for me? It's now [ de-skilling ] cyberattacks so that somebody could send me an email saying, hey, Allen, it's Klaas. Can you review this document from Natil? And no person has had to go in and get that information. AI can get that from social media, get that from websites. It can craft very difficult to spot phishing attacks. I'm on a company website. I'm trying to log in. I put my 1 time code in. Incorrect. Please try again. It looks like I'm on the same site where I've actually been taken to a site that's just a replica of it. And it looks identical. So AI is out there doing that. Even some deep fakes video with people looking like people that they're not really. They're artificially created. So the effect that has is to drive people up that security pyramid towards stronger authentication, where I can't accidentally provide my 1 time code or my password to somebody. So, it's driving people up towards Fido, and it's driving people up towards PKI. From an opportunities' perspective, there are some interesting security organizations out there starting to use AI to predict behavior and track behavioral biometrics. How am I holding the phone? How am I typing? So we're looking at potentially bringing that in as an additional forms of authentication about the person.

Klaas van der Leest executive
#11

Thank you, Allen. Next question is from Ian H. I've read a white paper article on your website. This was a collaboration with device authority about IoT and the healthcare sector. Is this still ongoing? And if so, do you expect to form some partnership with device authority? Allen, do you want to answer that?

Allen Storey executive
#12

Yes, sure. So, what we want to do, Klaas talks about the other faces of the pyramid. Device identity is 1 of those faces. But what we want to do is really understand that market before we build something and understand the opportunities. Then we make the right buy, build partner decision. So, what we found from working with the likes of Device Authority, potential working with them there, is, we believe, the best fit for us for device identity is closer to our enterprise space. So, firewalls, printers, routers, for example, servers have identities. They're based on certificate. And that's the best place for us to actually either acquire or build in IoT. Identity, we've learned, is a little different. So, yes, there's an ongoing relationship there, but that particular one is unlikely to turn into a partnership, unless the market changes. But we've learned from that experience. It's influencing where we actually acquire or build product.

Klaas van der Leest executive
#13

Next question is from [ David B. ]. Intercede has done exceptionally well in the government sector. Which other sector or sectors are you targeting? I actually think one of our slides, if I recall correctly, in the appendices, shows some of the other sectors we're operating in. So, it's not just government or U.S. federal. Broadly speaking, anybody who's got something to protect whether that's banks, whether that's healthcare companies, defense and aerospace players, companies who provide mobile networks or mobile connectivity. There's a very broad space that Intercede can offer its services in. Clearly from a PKI perspective, you're absolutely spot on. That's very much geared toward a very high end. But definitely when we look at multifactor authentication, password security management, it's a much broader field of play when it comes to client opportunities. Next question is from [ William D ]. UnitedHealthcare has suffered a very costly hack. I can see they are a client of Intercede. Does this mean this hacker somehow overcame our authentication system, or have we been brought in to help UnitedHealthcare to improve its security? Allen?

Allen Storey executive
#14

Yes. So familiar with the hack, medical data got lost. There's been no details of how the hack happened released, so there's no information on how it actually occurred. I'm absolutely positive it was not overriding any authentication technology we provided. And the reason I'm confident in that is we don't invent these standards in this security. We follow the standards that NIST publish, we follow the standards that our own security authority publish. So, we use the gold standard of authentication. We don't invent anything proprietary here, and there's no information that any of that has been compromised. But on this particular one, there's no information yet available from either the organization or the organization that hacked them on how the hack actually occurred. So, there's nothing further I can add to that at this point.

Klaas van der Leest executive
#15

We're getting close to what's the end now. Question from [ George O. ] Thanks for the presentation. Can you give information on the expansion rate from customers? Also, the industry is talking more about "platformization" of security projects. Are you seeing this? So if I take the first half, Allen, you take this second half. We're not providing any insight about expansion rate, i.e., the land and expand from existing customers. We don't provide that data. But what I can say is we are very good on the land and expand side. We have a customer success manager who basically drives the adoption rate of the software. So, this is definitely something very high on our radar screen, and we're extremely motivated and skilled to drive the adoption of our software within our client base. Allen, can you take the second one, Platformization?

Allen Storey executive
#16

Platformization is basically building security into the operating system, so it just becomes part of the platform. That's very much on the large-scale customer side. So, if you pick Microsoft Entra ID, as an example, they're building more and more security features in there. That's why we don't try and compete with them. That's why we have a works with strategy. So I was in Redmond a few weeks ago. I'll be back there again in July. FIDO Passkeys is a big thing for Microsoft. It's built into the operating system. So, where does Intercede play? Intercede play because at that higher level of authorization and security, our customers want to manage and control those passkeys. So even though Microsoft provide that capability, we can use our credential management system to allow them to comply with those high security policies, FIPS 201, and work in that environment. If you look at something like Zero Trust, there is no one product in the world that can meet Zero Trust. It has to be systems working together. So even though more and more is becoming part of the platform, there are still significant opportunities. As long as we work closely with the big players like Microsoft and work out where we add value to them, there's still significant market growth for us there.

Klaas van der Leest executive
#17

I'm just checking the board. I think we're all done. We've answered all the questions. So Lily, back to you.

Lily Kushner executive
#18

Klaas, Nitil, Allen, thank you for answering all those questions you got from investors. And of course, the company can review all questions submitted today and we'll publish those responses on the Investor Meet Company platform. Just before redirecting investors to provide you with their feedback, which I know is particularly important to yourself and the company, Klaas, could I please just ask you for a few closing comments.

Klaas van der Leest executive
#19

Yes, so a couple of final words in closing. Looking forward to continuing our progress into the current fiscal year. Our offering remains very relevant, if not more relevant than ever, as witnessed by the daily stream of data breaches. Allen has explained how we are now positioning MyID CMS, MyID MFA, and MyID PSM, and how we aim to take advantage of our enlarged target account market, which we serve through our distribution channel. We've got a highly committed and loyal team of colleagues who day after day deliver the best code in our industry. And I'm absolutely convinced that we write the best code in our part of the industry. It's witnessed by the client base we have, witnessed by the number of partners we can attract. It's also witnessed by the fact that we have very, very few support cases coming into the business once our code is being used in production. Of course, we aim to deliver continued revenue growth, both organic and inorganic, as well as profitability. And we believe we are on track to deliver that in the current fiscal year. Please do take your time for feedback on this session. We do take it very, very seriously. I'm sure you're all aware we recently had our Capital Markets Day on the 23rd of May and that recording is available on the IMC platform. Thank you again for attending. I think we're stuck within our time at 59 minutes, and we look forward to updating you all again in November. Thank you very much.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Intercede Group plc transcript - plus 251,000+ transcripts from 12,000+ companies, speaker segments and full-text search - through the EarningsAPI REST API or hosted MCP server.

Get an API key View API docs →

For developers and AI pipelines

Programmatic access to Intercede Group plc earnings transcripts and 251,000+ others is available through the EarningsAPI REST API and the hosted MCP server. Quarterly plans from $105 - full transcripts, speaker segments, full-text search, and the /api/v1/transcripts/recent polling endpoint for ETL pipelines.