Intercede Group plc (IGP) Earnings Call Transcript
November 26, 2024
Earnings Call Speaker Segments
Good afternoon, ladies and gentlemen, and welcome to the Intercede Group plc half year results investor presentation. [Operator Instructions] The company may not be in a position to answer every question it receives during the meeting itself. However, the company can review all questions submitted today and will publish those responses where it's appropriate to do so. Before we begin, as usual, we would just like to submit the following poll. And if you could give that your kind attention, I'm sure the company would be most grateful. And I would now like to hand you over to the executive management team from Intercede Group plc. Klaas, good afternoon, sir. [Voting]
Good afternoon, [ Jake ]. Good afternoon, everyone. My name is Klaas van der Leest. I'm the CEO for Intercede. I would like to welcome both existing investors as well as potentially new private investors to this session which will cover our first half, being 1st of April until the end of September, 2024. I'm joined by Allen Storey, who is our CPO; and Nitil Patel, who is the CFO. And whilst this presentation is us presenting to you, we do look forward to your questions but also your feedback after the session, so without further ado, let us start with the presentation, which we'll update -- which we will provide an update into and insight into the markets we operate in and how we position through both additional features but also through new products like MyID SecureVault. So let's start. So if we look at company introduction, I know this is a difficult one because we're presenting into a black hole and we don't know whether you're an existing investor or whether a new investor and how much background you have, so I'm going to pick out a few salient points here. Intercede is a software company based out of Lutterworth. We've got 2 offices in the U.K., main office in Lutterworth. And through acquisition, we're also based out of Bracknell. We're about 108, 109 staff; just over 94, 95 in the U.K. And the rest of our colleagues are based just outside of Washington; Washington, for a very good reason because we're heavily geared towards the U.S. federal market. So we need to be near clients and prospects. So we're a software company. What does the company do? Ultimately, at 30,000 feet, we help our customers to protect themselves against data breach. Data breach 5 years, 10 years ago was something which was sporadic in the news. Nowadays, it's daily, if not hourly. Only yesterday, one of the NHS trusts was hit and completely rendered ineffective, so this is something that's very, very real. So we help and protect our customers against data breach. How do we do that? We basically replace weak credentials such as passwords with much stronger authentication. Allen will pick that up in his part of the presentation. And we do that simply. We do it securely and we do it at scale. What do we mean with simply? It's standard off-the-shelf software. This is easy to implement, easy to integrate with and easy to maintain. We do that securely. If you look at our client base -- and there are some samples of our clients in the appendix, but also you can find some logos on our website. You will find that these clients are very recognizable. And they tend to test our software rigorously before it comes into production, particularly in the U.S. A lot of our U.S. federal clients need to have an authority to operate, and they can only do so if the software has been tested. So we know it's secure. Final point is it scales. We tend to position in the market at mid-level, upwards. Lowest number of licenses we probably sell is in the high hundreds, and then we scale to millions. The largest one we've probably got out there is the Kuwaiti national ID scheme, [ who have ] probably issued between 6.5 million and 7 million licenses by now, so we know the platform scales. It's also business-critical software, so this is not the kind of software that will get turned off because there is an economic downturn. Basically our clients are protecting their crown jewels with the software that they have purchased, and therefore, it's regarded as business critical. It's also very much positioned within the wider cybersecurity market. And depending on which analysts you read, that market is still growing very much at double digit. If we then move to the box on the left. From a business perspective, it is very much a scalable business. We've proven that over the last couple of years. And there are 3 main revenue streams: recurring revenue, our support and maintenance. We have then our repeatable revenue, which is typically our professional services; and then on top of that, the licenses. The good news nowadays is that the majority of our costs, and a lot of that is labor, is actually covered by the revenue we get from both the recurring revenue as well as the professional services. And therefore, as and when we sell licenses, it becomes highly accretive. And a lot of that will drop to the bottom line. Operating model is very much proven. I talked about the Tier 1 client base. Some of the logos are on our website. Other clients, we simply can't talk about, but think about interesting shape buildings in and around Washington. Think about intelligence agencies. And by the way, not all intelligence agencies have [ 3-letter acronyms. There -- I think there are ] in the low 20s in the U.S., and we're dealing with a number of them. Management team is established. Obviously, I brought Allen and Nitil with me here, but we also have COO and CTO as part of the team. The growth pillars are very much defined. We position ourselves as an organic growth business. The objective is always to drive double-digit growth. And clearly we came off of the back of a very strong full year, but also, in this first half, we're showing again that we can drive very solid double-digit growth in the mid- to low 20s. The second growth pillar is acquisition as and when we can find the right acquisition. And we focus particularly on IP. Then we will layer that into the business. We've completed our first acquisition. That's been fully integrated and we're on the lookout for more acquisitions. Market-wise, we're very much recognized; not just recognized by clients and partners but also by industry analysts like KuppingerCole, who've written very favorably about our products in the market. If we look at the pipeline. Our pipeline has developed very, very nicely, compared to comparable period last year, not just in terms of absolute value but also in terms of geo diversification. What do I mean with that? Those who have been following us for a while will know that the majority of our revenue, typically 80%, 85%, is U.S., but what we've actually seen: that our pipeline outside of the U.S., which is what we classify as rest of world, has grown very, very nicely. And that's not just focused on a single region. It's pretty much broad brush. We see opportunity in the U.K. We see opportunity in Continental Europe, Middle East as well as Asia Pac, so that's really good to see, that our pipeline is balancing more out. What I'm not saying is that our pipeline in the U.S. is not growing. That's absolutely not the case, but we're actually seeing more number of opportunities appearing in rest-of-world region than we've seen for a little while. The second point about the pipeline is actually the weighted pipeline. And we've described it as materially ahead of where we were last year, so what does that mean? We have more opportunities in the pipeline that sit on the right-hand side with heavier weighting, so closer to the procurement stage. Competitively, we can very much defend, protect and defend, our moat. Whilst we are quite niche, we're very much regarded in the space we operate in. And we've seen very little revenue attrition. Our revenue attrition in terms of revenue is significantly below 2.5%; and has been so for many, many years. Allen will talk about the authentication pyramid, which is a very good reflection of the journey we've been on over the last 5 years, but it's also a good picture to highlight where we want to take the business next. Final point in the central box is regulation. We love regulation. Again Allen will talk more about regulation in the U.S., but we also see more regulation now appearing in Continental Europe within the EU, where NIS2 is very much coming into force. And we fully expect in the next 2 to 3 years that companies will have to work hard to comply with the new laws that will appear in each individual country. Financials. Nitil will talk about the KPIs and how they've grown over a period of time. Main thing I want to stress here is the share buyback we've commenced, 2 main reasons for that. First of all, we've got some EMI options coming up next year. We haven't got enough shares in treasury, so we're actually buying shares for treasury to fulfill that potential requirement. Secondly, each one of us knows on this call there's been a lot of instability, leading up to the new budget, around AIM and IHT. We have a small exposure, relatively small exposure, to AIM, IHT, so we wanted to make sure we had an instrument in the market that we can actually deal with. As most of you, I'm sure, will realize, share buybacks have to be approved by Board. There is and there are some mechanics we have to take in place, so we want to make sure that, before the budget was announced, we [ actually had an ] instrument in the market that could deal with any adverse reactions to what was going on in the budget. So that's very much a high-level introduction. At this point, I hand over to Nitil, who will talk you through the numbers.
Thanks, Klaas. Hopefully, everyone has read the RNS we released on Tuesday. I'll start on the left-hand side and the progress report. And then I'll just highlight some of the key revenue streams that we've had in H1. Revenues have grown by 22% to GBP 8.54 million and 29% on a constant currency basis, which is a good result for us, as Klaas has mentioned, coming off on FY '24's exceptional results that we had. Profit before tax is GBP 1.7 million, again a really good number for us in H1, 55% higher than the comparative last year. And the reason for this is because our product is so good and we continue to invest in our product. And Allen will explain what we're doing with our flagship MyID CMS later in the deck; and also what we've done with our acquisition since we bought it, what have we integrated, how we've gone to the market and what we're looking to do with it. And that's version 5.06. And again I will explain more about that, but this week also, we've launched our new product called MyID SecureVault. It's a separable stand-alone product, subscription-based pricing only. And again Allen will explain more why we're doing this and what we see in the marketplace for this product. We've taken a different approach to R&D tax credit. It's a technical tax adjustment policy, and there's a slide later in the deck. And I'll explain what we're doing with that, but you'll see an impact on the income statement because of that. And just as Klaas has mentioned, professional services have grown quite well this year, in H1, as a comparative. And this is mainly because of our 3 either deployed, deploying or just deployed and potential POC that we're doing with 3 large federal agencies; 1 we can name, the Department of State. 4 years ago, we won it; 2.5 years ago, went live. We're continuing to help them maintain and operate that and manage that, and they're constantly using our services for that. And we like that because it's a good revenue stream, a repeatable revenue stream for us; and it embeds our staff in that environment. Last year, we had a really good strong order, in December, $8 million. And that was with a new federal agency which we can't be -- unfortunately we can't name yet, but they had an aggressive time line to go live. The good news is they have gone live. They've used a lot of our professional services and they continue to use our professional services going forward, and we don't see that tailing off. And as we've highlighted, we're in the process of doing a POC for another large U.S. federal that's taking a longer period of time to test it. We're happy with that at the moment. We normally don't do this unless there's a license order attached to it, but because of the opportunity, we decided to allow 2 of our staff to be embedded into the POC world in this agency. So that's why PS is looking good this H1. [ This license income is ] slightly behind schedule, but we will come to an explanation of why that is the case and what we're seeing in H2. Just the highlights on the right-hand side. Yes, we do have a lot of good federal revenue, but we're also seeing movement in ROW and through that, as Klaas has explained about our pipeline and the weighting of that pipeline. And [ MyIDs in MFA and PSM ] is also getting good traction. And the release of 5.06; and the potential of what we're trying to achieve in a new marketplace, which Allen will explain, have some good prospects for us in the future. Again financial highlights [ vectorially ]. If you look on the right hand -- sorry, left-hand side, top, revenue streams by analysis of support and maintenance, our recurring element; our PS, our repeatable element; and our license income. As you know, we're normally perpetual. We've obviously, [ in last ] few years, introduced subscription. We'll see how that develops. Our MFA, PSM products are all subscription, as is our new product, my SecureVault (sic) [ MyID SecureVault ]. If you look at this year, [ 4.7, 2.7 ]. That's a really good number for us. Why? Because as Klaas has mentioned, it covers a large percentage of our operating expenses. So any license sales that we do, less commission, are going to be highly, highly accretive to us. And we're focusing that and looking to convert a chunk of our pipeline in H2 into license income. Revenue by region. As you know, Americas continues to be the largest and will continue to be the largest in the foreseeable future purely because it's got bigger budget. It's well funded. It's got more agencies that are securing -- or abiding with regulations like the existing in United States, but there is traction in ROW. And we will look to see that [ RO ] segment grow over the coming H2 and into next financial year. Adjusted EBITDA and profit before tax is a good metric, again, that we focus on. Why? Because we'd like to see them close enough to each other. As we can see, in H1, it's GBP 1.8 million versus GBP 1.7 million. Again there's a reason for that, and I'll explain that later in the income statement. And then on the bottom right, you see the movement of cash. Good cash generation gives us the capability of secure foundations to continue to invest in our products and also gives us room to maneuver in -- regarding M&A activity or share buybacks that we have to do this year -- and equities and -- going in the right direction as well. Income statement. We have a very clean statutory income statement. That's the top half. And the bottom half is just an illustration of where the adjusted EBITDA and the adjustments look like. So if you look, then you'll see the 2 main changes here are the net finance income. It's larger than last year, again a reflection of our cash balances. We spread that money across 3 U.K. banks, A+ rates, A rated or A+ rated. And we hold it to the maximum of 3 months to abide with accounting standards. And then you can see the taxation. We have not received a tax credit this year. We've elected not to take it. Again there's a later slide on why we are looking to do that. You'll note at the bottom that we've got carried losses of GBP 3.9 million. We probably want to utilize those into this financial year and then utilize the R&D loss -- tax losses. And again I'll explain that later, why we're doing that. Financial position of the group. Again we have a very clean balance sheet. We don't expense our R&D expenditure. The 3.5 million, 3.6 million that goes through the income statement will continue to go through the income statement but a slight tweak on MyID SecureVault. Again I'll explain why we're probably going to have to capitalize that, but the amounts we are talking are not material. The movement in other, property and plant and equipment and right-of-use assets, is mainly because, one, we've got a new office in Reston. And that reflects the 7-year lease. And also we've invested heavily this H1 in upgrading our back-end infrastructure, not just physical servers but also moving into Azure, but all staff has received new laptops, especially the development and testing staff, to get new specs and capabilities and functionality so they can increase boundaries, increase productivity and get ready for the next 3 to 4 years of, hopefully, increased activity. The other part of our balance sheet that we focus on quite heavily is trade and receivables, cash and deferred income. I should have highlighted the deferred income, [ a little greater than 1 year ]. Reason for this, pure working capital management. It's good to have deferred income. It gives you good visibility or good visibility into the future. And if you've got even longer noncurrent liabilities, that shows you that you're selling either 2- or 3-year contracts, either licenses under MFA, PSM; and also maybe as people are doing longer-term S&M subordinated contracts with us and locks in the price now without the inflationary increases that we apply if you don't -- if you renew every year. Trade and receivables is higher than last year. We just had late orders in September. We're under procurement rules with our big corporates and our government agencies. We get paid, but you have to be in that system. We're in the system. It takes 50 to 60 days to get paid. Most of that money has now been collected. [ It hasn't had ] an impact on the cash flow. It's just a negative outflow, but that's a comparable to the 31st March as a working capital adjustment. We had a large debtor at 31st March on renewal, a large renewal of subscription that we had every year. And that's just a comparative. The cash used in investing activities, as I've mentioned, is all to do with the fixed assets. And there's no tax credit. Last year, we got 450,000 in tax. Obviously, this year, we didn't. Again, we've elected not to receive that. Well, we've got a good, strong cash balance. And we expect that to turn around in H2. So I just wanted to give some additional notes I've mentioned on the updates from the financial section. The capitalization of MyID SecureVault: There's a slight change potentially on the policy. And this has got to be audited, but because it's a separable asset with a standalone -- can be sold without the MyID CMS attached to it, has its own pricing and can -- has identifiable costs associated with it and future revenue streams. Then the standard [indiscernible] kind of gives guidance on you should be able -- you should be capitalizing this because you're matching future revenues with the costs element of the development of the product. We don't see this as material. We don't see this as a significant change in policy, but it's one thing that we will be probably doing so at year-end. I just wanted to highlight that to our investor community: not a material change and impact on the income statement and no change on our flagship MyID CMS which also now incorporates MFA and PSM. The other technical change we're doing is on R&D tax credits. We've normally, in the previous years, taken cash because we wanted it and it was good to have the cash. And we could invest it in the product. As we are [ cash rich ] at the moment, we've decided not to take the tax credit for this year. And we've also gone back and opened last year's tax comp. And that's you'll see a cash outflow in H2 of circa 0.5 million. That's 450,000 that we got from HMRC and plus interests flowing out of us. Actually it's flown out of us in H2. The reason we're doing this is purely tax arbitrage rates. We get a blended tax cash credit of circa 12% to 14%. And the corporation tax is now at 25%. And going forward, it's better for us to [ utilize ] R&D tax losses against future corporation tax liabilities. It just makes sense to have that arbitrage, and that's what we were doing. And that's why we've opened up last year's tax comp and why we're paying it back and also why we haven't got a credit for this year. Share buyback. As Klaas has mentioned, we decided to do one in the beginning of November, getting ready just for the budget on 30th of October, with an end date of 31st of December. We'll see that flow through. You will see the statement RNSes coming out from [indiscernible] coming [indiscernible]. And we'll see how that progresses through, but we're anticipating a 1.5 million cash outflow in H2 mainly to do with the share buyback and the R&D tax credit I just mentioned. And you see [indiscernible] moving us down from 18.5 million to 17 million, purely to do with this 1.5 million cash outflow that we've described just now. We also wanted to show you that -- from a like-for-like basis, if you took the exceptional out of the equation, where has this company been going in the last 4 or 5 years? Klaas and I were talking. 3 years ago, 3.5 years ago, we reported GBP 9 million, GBP 9.5 million for the full year. And we're now reporting GBP 8.5 million in H1. CAGR, for us, it's great in the sense it's [ now 21% to 21.4% ]. We'd like to continue that. And you can see that -- the progress we're making. So the emphasis on the pipeline, the conversion of the pipeline is really important to us. And we'll be focusing on that going forward in the coming years -- or months and years. On that basis, I'm going to pass you over to Allen, who's going to talk more about product.
Thank you, Nitil. So let's start to take a look into the product and what we're doing with it to try and drive that revenue. So as Klaas mentioned and what we do is we help protect our customers against data breach. We use that by taking weak credentials, typically passwords and onetime passwords, and replacing them with stronger credentials. We use what we call the authentication pyramid to describe the strength of those credentials. So passwords at the bottom; multifactor authentication and onetime passwords in the middle; and moving up to the top of the pyramid, PKI. So this is authentication based on public, private keys; and cryptography. Historically, we've only played at the top of that pyramid. So that's the gold standard of security. It's used by governments, aerospace and defense, for example. Strategically, we wanted to move down the pyramid to address a wider market, so that's why we made an acquisition a couple of years ago of a company that had multifactor authentication and password security management. We've now completed the rebrand of those products and we take those to market as MyID solutions, so MyID has now become a product family. And we're a multiproduct company. The next 3 slides really talk through each of those products in a little bit more detail. Conscious of time, I won't leave those there, but those will be in the deck. And you can use those as a little bit more reference on what each product does. What I'm going to do is really focus on where we're taking those products. So this is how we're positioning them into the market today. The first one is aimed at the very top of the market. So this is our existing customer base and type of customer, federal government agencies, aerospace, defense contractors who have to comply with the legislation called PIV, personal identity verification, which states that you have to issue strong credentials to known people in your organization. So that's the legislation people have to comply with. To comply with that legislation, they've issued fairly complicated systems out there that integrate lots of components together, so this is how customers today are using our system in that federal government market. So on the left-hand side of the slide: We're onboarding people. We're capturing fingerprints, facial biometrics. We're placing documents such as passports or driving licenses on scanners, making sure they're not faked. They're not -- known to be tampered with. Then we pass that information up to background-checking systems. Do these fingerprints match anybody else in the system who's enrolled before? This person is enrolled. They are who they claim to be, but are they on a terrorists no-fly list? Before we actually let them into the air traffic control tower. So a lot of this is about is it the right person and is it a good person. Once we've done that, then we issue them a high-assurance digital credential. So that takes the form of a PKI certificate with keys on a smart card, USB token or phone. To do that, again we're integrating lots of technologies together, the PKIs that provide the certificates, mobile device management systems looking after mobile security, physical access control systems, et cetera. So this is what customers have deployed in that high-assurance environment today, and that allows us then to comply with those federal government regulations. There's a change to the regulations coming out the executive office of the President that states that organizations now need to deploy stronger authentication to the maximum extent possible. That means everybody in the organization and down the supply chain. It's quite hard to deploy PKI down the supply chain because the organization to do that has a complex system like this setup, but they're not in control of the supply chain's IT infrastructure. So it's quite difficult to implement. There's another technology that's used in the consumer space called FIDO, now called FIDO passkeys, still based in cryptography, which is potentially easier to deploy because you don't need as much infrastructure in place to deploy it. It's built into operating systems, for example. Now what customers wanted to do is to be able to deploy and manage this in the same way as they could PKI with their credential management system, but until recently, they couldn't do that. They could either issue the FIDO passkeys with Microsoft Entra, which is Microsoft's rebranded name for their identity and access management suite, but then they couldn't do it to the policy. They couldn't comply with the federal government policy rules. Or they could issue them with a credential management system that complies with the federal government rules, but they wouldn't work with Entra. So Microsoft realize this. Our customers realize this. We've been on conversations with Microsoft, with some of those customers asking Microsoft to give the ability to issue passkeys that it could work with from a third-party system. So we've been working with Microsoft as an early adopter in this space. There's -- a small number of vendors were invited to work with them on that scheme. We've worked with them on that scheme. What that allows us to do is then issue and manage those FIDO passkeys in exactly the same way as customers today issue their PKI. So they use our system and they get all of that compliance with policy, but then they work within the Microsoft Entra environment, so what that means is the customer can keep meeting the guidelines and they can deploy those stronger credentials. From our perspective, that's simply more licenses into our existing customer base. So whenever they issue a PKI smart card, that consumes a license. If we issue a FIDO passkey or something like a YubiKey, that also consumes a license. Moving down to the absolute opposite end of the scale now. So one market customer size Intercede hasn't addressed in the past is the very small customer. So 5, 10, 15, 20 users, for example. Even our multifactor authentication product, our mid-market products, typically starts around the 250-users-plus environment. So these customers are very difficult to deploy to because they typically don't have their own IT departments. And they outsource their IT to a service provider. So we were approached by a organization called Riverbird based in Germany. What they do is they have a platform, so a cloud SaaS platform, that multiple managed service providers use to satisfy multiple end customers. So that Riverbird platform is used by around 400 managed service providers. And those 400 managed service providers in turn manage multiple end customers, and they've got millions of devices under management. So partly because of the increase in the level of cyber attack, the geopolitical climate, partly because of the upcoming NIS2 legislation in Europe which drives organizations to set their own cybersecurity standards, Riverbird said, "Can we have stronger authentication as part of this platform?" so we took the product we'd acquired, rebranded it as MyID MFA server; and we made 2 major enhancements to it. The first one is the ability to manage multiple end customers within a single instance of that server environment so, that way, we can deploy this into the Riverbird cloud, into their SaaS cloud environment. We don't have to deploy it at the end customer side. We don't even have to deploy it into each managed service provider. The second thing we did is we enhanced the APIs around the product to allow it to be completely automated. That way, if an end customer ticks the box saying, "I want strong authentication," the deployment of any software is absolutely automated down to their clients so no human being has to get involved. The point where they start using that and they start getting billed, again, nobody has to [ run report ]. All of that is completely automated. So I'm personally very keen on this for a couple of reasons. One is that it allows Intercede to address a customer base that doesn't cannibalize our existing revenue. We've not gotten near these customers before, so these are brand-new types of customers for us. The second one is that it allows us to tap into that pure-cloud SaaS model that gives us scalability without having to actually run that SaaS environment ourselves. So by tapping into an existing platform that's out there and widely used, it gives us those scalability benefits. So this is currently in production. We've been working with Riverbird for a few months on pilot customers. It's early days, so we're up to the first few hundreds of end users at the moment. We're now monitoring that and working with them to look at what the attachment rate is. How many of those end customers will start stepping up to stronger authentication? And if that's successful, we intend to take that model through to other managed service providers in other regions. Talking now about a new product, MyID SecureVault. So part of the security of PKI is that there is a private key. And you need access to that private key to read an e-mail that somebody sent you, if it was encrypted, or open a file that was encrypted. When I get a new device, I might lose my smart card or get a new one. Or I'll buy a new phone. I need to get those private keys onto that device to be able to continue to read the e-mail or open that file. Now traditionally customers have managed those keys within the PKI infrastructure. Those keys are placed in a -- what's known as a secure vault or a secure archive within that PKI infrastructure. And they use our product, the credential management system, to help them recover them and write them down securely to the new device, but this causes our customers a problem. So we had a customer approach us, saying, "The problem this causes me is, whenever I move PKI provider," which they do regularly, often -- so they may move between DigiCert or Entrust or Verizon as a PKI provider. "I'm kind of locked into that vendor because my private keys are in that vendor's environment. And I need to move them from that vendor to another vendor." That's costly. It's time consuming. It's very risky, so the customer approached us and said, "Intercede, you understand keys and security. Could you build a secure vault to store these private keys but one that gives us independence from the PKI provider?" so we built it. The good news is that we had a lot of code and skills and knowledge in our existing product. And that allows us to build this product relatively quickly, but we've built it as a stand-alone product, so it's not part of the credential management system. It's a completely stand-alone product, partly for security purposes so the customer can deploy it in a different environment but partly so we can sell it integrated with the credential management or completely standalone so it could work with somebody else's credential management system. So what this does is it gives customers the ability to store and manage those private keys completely independent from the PKI infrastructure. Because it's a new product, we are only providing it on a subscription pricing basis. So there's no perpetual licensing here for this product. The way the license is, is for the number of keys held within the system. The more keys, the lower price per key. Most organizations, [ when ] people use this, they have around 5 keys per person because the keys change over time. And there's also a requirement to hold onto historical keys, typically for around 7 years. So for example, with one of our customers, Federal Aviation Administration, they need to hold them for 7 years due to government guidelines. So if somebody like the FBI or the CIA came in to investigate somebody, they'd need to have access to those keys so they could read the e-mails, so that's why they need to keep it for 7 years. So brand-new product. This is focused on our top-end customer base and where the CMS plays initially on PKI keys. As we continue our M&A journey and start to look at other areas where we can add value, there are potential future uses for this. So for example, in nonperson entity, secrets management, API keys, device keys, for example. Moving on to innovation, so what research activities we're undertaking to try and add ongoing value to our customers. The first one is quantum cryptography. So this is probably the thing that keeps our customers awake at night at the moment: The idea behind public-private key cryptography-based security is there's a private key and a public key. I can sign something or authenticate with a private key. I can verify that with the public key, but I can't get back to that private key. That remains secret. The theory is, with quantum cryptography and quantum computing, you can have a computer that is so powerful and so fast. It can perform billions of what-if calculations per second. So theoretically, with the public key and only the public key, you could work out what the private key is. That means it undermines the security of public-private key cryptography. So the good news is that NIST, who set all the standards in the U.S. around cryptography, are well aware of this and they're already working on it, so they've recently published the first 3 quantum-resistant algorithms. What that means is, even if a nation-state has a incredibly powerful quantum computer, because of the way the maths is calculated, you still can't get back to the private key, if you know the public key. So I was at NIST last week, with people who are setting these standards, talking to them. They are running early adopter schemes for vendors to prove you can work with these algorithms and deploy them. We will be part of those schemes, so as those algorithms become available on hardware devices such as smart cards and hardware security modules, we will be working with them in the NIST labs, proving to our customers we can actually deploy that cryptography when they need it. So it's probably 2 to 3 years before customers need to start deploying these quantum-resistant algorithms, but we will be there before they need it, demonstrating that to them. And we will also help them migrate from the old cryptography to the new cryptography, so that's an important part of our product value. Second one here is artificial intelligence. So we've been looking at artificial intelligence and how it can add value to our product set. It's no secret that artificial intelligence is being used by hackers. So there's lots of examples of deepfakes of people reading video out that look like real people, the e-mails we all used to receive from the "Nigerian princes" that are obviously fake. It's very, very difficult to spot a phishing e-mail these days when it's generated by AI because it looks very, very realistic. And it has context in there. The good news for us is that drives people towards stronger authentication, which is FIDO passkeys or PKIs. So it drives people [ to our sort of ] technology, but we've been looking at where we can add value to our product set using AI. Our view of our particular product is we don't think it will replace the people using it, but it does add value and help those people. So that's probably why Microsoft call AI co-pilot, as opposed to pilot. So the 2 areas we're looking at initially. The first one is our system is connected to lots of other systems. There are lots of log files and audit files that come out from those systems. And we have an online knowledge base. So AI with machine learning is very good at spotting patterns. If we can spot patterns ahead of an incident occurring, we can help those customers. So it could be, for example, this particular person has been logging on an abnormal number of times. You might want to investigate that. It could be, when we've seen this pattern happening in the log before, we're starting to see a network slowdown. Therefore, you might want to go investigate a particular area. So proactive AI analysis of logs, we think, can help people maintain their systems. The second one on here is, a while ago, we put our documentation online. Some people aren't comfortable with that because it means competitors can look at it. We are comfortable with it because we believe we should focus on being the best product and making that available and stand behind it, so I'm very pleased we did that. The documentation is online. The knowledge base is online, so customers can search that easily. And they like that, but you still need a degree of knowledge to know where to look. What this can do is act as a -- more of a conversational-style engine to help you find what you're looking for. How do I change the color of a card layout? How do I actually swap from an old crypto algorithm to a new one? So AI with machine learning, again, is quite useful at pulling together that information from different places and presenting it to the end customer. So these are just 2 of the areas we're looking at in bringing AI usage in to add value to our product set, okay? With that, I'm going to hand back to Klaas.
Thank you, Allen. So trying to summarize where we are today and a little bit more about outlook on the next slide. If you left with one thing today, other than presenting half-decent results, it's that Intercede does incredibly well in highly regulated markets. One of the reasons why we're successful in the U.S. is because it's very heavily regulated. There are other countries where there may be less regulation, but they want to follow the U.S. standards like FIPS 201 that Allen referred to. We see that, for instance, in Singapore. We now start to see that happening in Australia. And we see interest in New Zealand, which is really interesting for us, but we also see more regulation now within the EU with NIS2. NIS2 is something that's going into law pretty much now as we speak. And there is a large cohort of companies that will have to comply with NIS2 regulations. Compliance is something that typically takes time, but it does mean that they have to make investments, particularly around the cybersecurity posture. And the good news is within NIS2 there are real good drivers similar to those we've seen in the U.S., so we expect that those market drivers will be positive for a company like Intercede. We'll continue to expand our product portfolio, not just in feature enhancements but also the launch of new products. SecureVault, MyID SecureVault, is a very interesting product. We've got that to market very, very quickly. We have already initial interest. There are active quotes for this product out there and we fully expect that they will materialize in the foreseeable future. That also quite nicely builds on to point number three: We build and grow a diverse pipeline. In my introduction, I referred to a pipeline that is very solid in terms of absolute numbers but also with regards to the weighted pipeline. It's in a much better position than where we were last year, so that gives us a lot of confidence for the full year ahead. And the second point I raised on the pipeline is the fact that we see lots of opportunity arising in rest of world, so real good movement on the pipeline. Nitil, as CFO, he's got very single-mind focus on revenue, margin and profitability. And hopefully, through the numbers, you see that they really play a key part in our day-to-day business. And we're very much focused on those going forward. Liquidity is excellent. And that will continue to provide us opportunity to grow the cash pile and, hopefully, invest some of that cash into future acquisitions. We haven't focused a lot on the acquisition part in this presentation, but just to reconfirm: We have a full-time corporate head of development in house. We have a long list of around 300 companies at any point in time. We've talked to you about 5 to 10 potential targets. And that definitely takes time. As and when we have updates, we will clearly come back to the market. Balance sheet, as Nitil has talked about, is very, very clean. We used to have a convertible for 5 million. That was dealt with just over 2 years ago. And 12 out of the 13 loan note holders actually converted. So if we then wrap up towards the last slide because we do want to leave a little bit of time for Q&A. Outlook-wise, we clearly come off the back of a very successful year. It was the best year in the history of the company, with GBP 20 million revenue, but we've seen that same kind of traction continuing into half 1. And on the back of half 1, as we've clearly presented the results to you, we also see very strong traction into the second half. And it gives us a lot of confidence to deliver the full year -- numbers for the full year. We talked about SecureVault that allows us to capitalize on net new opportunities not just in the existing client base but also in potential prospect areas that we're already starting to explore. We're very close to our technology partners, our resellers, our distributors; and continue to expand. It was only last week we announced a new reseller relationship with Infinigate in the Netherlands. Clearly it's a country I know reasonably well. We visited a couple of times. Why Infinigate? They focus very, very heavily on the cybersecurity space, which is good. They're also one of the leading distributors of YubiKeys in the Netherlands. And as you may recall from earlier presentations we've done through IMC is that, when you issue or when an enterprise or a government body issues thousands of YubiKeys, you need to have a management platform. So we're very much driving that proposition jointly with Infinigate into the Dutch market, and we're already starting to see initial traction there. M&A-wise, it is extremely disciplined. Again, we've highlighted in previous updates that we have been in DD from time to time, but once you start lifting up the carpet tiles in somebody else's organization, it's not always the things that you like to find compared to what they presented to you, so in that case, yes, we incur some legal costs. And in some countries like the U.S., lawyers are expensive, but it's better to walk away from a deal that doesn't feel right or doesn't smell right than have to come back in 2 years time and say actually the acquisition we -- didn't really work out. And there are plenty of examples in the industry where acquisitions haven't worked out, and we can even stay pretty close to home for those. Final point is we -- I think we excel in delivering very good service to our clients. Allen was in the U.S. last week not just to visit NIST, the standards body, but also to run our client advisory board in the U.S. where we had over 40 attendees. So we're extremely close to our clients. We get real good feedback from them. We have an NPS at 55 which not that long ago was around 20, so we're continuing to invest quite heavily. And for those who attended the CMD: We had one of our partners, Guidehouse, talking about the importance of playing the long game. And that's exactly what we do. We play the long game with clients even if it means that there is some short-term pain, but if you take the 5- to 10-, to 15-, to 20-year view on a client, that's where the lifetime value of the client comes in. And that's very much the game we're in. So final point is, short term, we're very much focused on half 2. We're extremely busy. Nitil and I are flying to the U.S. on Saturday to spend more time not just with our colleagues but also again with clients and partners and potential prospects. Medium term, our ambitions have been very clearly outlined [ in the industry ], that we've got strong ambition to grow; and that's pretty much where we are. So [ Jake ], on that note, I'm handing back to you.
Perfect. That's great. Klaas, Allen, Nitil, thank you very much indeed for your presentation this afternoon. [Operator Instructions] Just while the company take a few moments to review those questions that were submitted already, I'd just like to remind you that a recording of this presentation, along with a copy of the slides and the published Q&A, can all be accessed via your investor dashboard. Guys, as you can see, we have received a number of questions throughout your presentation this afternoon. And thank you to all of those on the call for taking the time to submit their questions, but guys, at this point, if I may just hand back to you just to read out those questions and give your responses where it's appropriate to do so and if I pick up from you at the end, that would be great. Thank you.
Right. So we've got quite a few questions in the Q&A box. Now I'm in the very good position that I read the questions and I decide who's going to answer them, so this is actually quite good fun. So let me start with the first question from [ William C ]. "Great results." Thank you. "How much visibility do you have over half 2 license sales at this time?" [ William ], I hope that it would become clear that we've got real good confidence in our pipeline. Not just in the short term, but also medium-term pipeline is really, really good, so we have no concerns about the opportunity for license sales in the second half and indeed beyond. Next question is from [ Mark C ]. "You advise that 80%, 85% of the revenues comes from works in the U.S.A. How concerned are you about the possibility of tariffs the incoming President has threatened to impose on imports?" Yes, we obviously discussed this. And we're pretty well protected when it comes from a pricing perspective. We play in the top end of the market. If indeed there was a scenario where tariffs would be applied to our product range, then we seek to revise our pricing. And I do believe we've got the pricing power there, so I have no real concerns on those discussions around tariffs. "Sorry. Some of my questions have moved on." Other question from [ William C ]: "Your September contract RNS mentioned, $0.5 million major development order for a new government end client, with deliverables in the second half. Is this still on track?" Nitil, one for you.
Yes.
There you go. We're confident in our ability to deliver. That also comes back to the fact that we're releasing quarterly [ listeners ]. And we have a very strong cadence in our deliverables, so we wouldn't make statements on RNSes if we didn't feel we were capable of delivering. [ Marvin ], question from you. "What will be the full year impact of increased NIC on your cost base?" Nitil, one for you.
Yes. We've done a quick calculation for the changes in April, circa GBP 160,000, GBP 170,000 increased costs for FY '26. What mitigation we're doing is no employee will be worse off. We were planning to increase the employer pension contributions from 6% to 7% next year. That will not happen now. And the original ideal plan was to increase the graduate intake probably by 4 to 5 people next year. We're probably going to trim that by 1 or 2 people as well just to compensate for those costs. So there is going to be an impact, but we've got mitigating factors in play to make sure that has a 0 impact overall on the income statement.
Other question from [ Marvin ]. "Do you expect the level of professional services in half 1 to be sustainable or revert back to more historic levels going forward?" I don't think they will necessarily go back to historic levels. Whether we can maintain half 1, to be seen, but what we are seeing, as Nitil has indicated, is we are getting more pulled into the very large programs we're working on because we're -- ultimately we're the subject-matter experts. So we definitely expect going forward a very solid revenue stream on professional services. We are embedded in the large programs, so we fully expect that it will be a real good run rate on PS going forward. Sorry. I just need to skim through the questions again...
There is -- one missed out is [ William C ]. Is there any particular reason...
I am sorry, [ William ]. "Is there any particular reason why half 1 license sales were weaker than the last 2 years?" Again, we tried to highlight that. It's pure a timing issue. There is nothing more sinister. This is procurement. We tried to indicate that in the RNS and in this presentation, that our pipeline is strong. Our weighted pipeline is extremely mature, so we fully expect the slight weaker half 1 license sales will be compensated in the second half, so we don't see any real concerns there. Next question is a question from [ Marvin ] again. "Can you give us a sense of the margin profile between your 3 revenue sources, licensing, PS and recurring?" Nitil, do you want to take that one?
Yes. I mean it's difficult to do recurring. Recurring is a renewal, so you've already committed the kind of development costs and the testing environment already expensed. And then you've got a commission element on it. So renewals, the sales team get an element of commission. The PS, obviously there's a cost of sale associated with that, a lot of cost of sales, shown as operating expenses on our income statement. If we're not making margins of 40% to 50% of PS, we'd be disappointed. And then on license sales, why are we focused on license sales? Because they are highly accretive to us. Again, net of commission, you're looking at 90%, 95% gross profit on those.
Quickly moving on because there are still quite a few questions and we're trying to answer as many as we can. A question from [ Scheff D ]: "How do you compare with your competition?" Allen, one for you. I don't want you to feel left out.
Yes. Thank you, Klaas. So it depends on where we are on the product set. So at the top end, the high-assurance credential management, the competition, we are best in market there. There's no doubt about it. I -- we can see that from the projects we've won over there against the competition and the independent reports such as KuppingerCole. So at that very top end, the competition tends to have been either acquired by a large agency or lost focus. Or it's a large systems integrator who builds bespoke systems. And our customer base is very much looking for commercial off-the-shelf now because they've been stunned by upgrade costs in the past. And the third option there is some of our competition deliver this via appliances, but then the end customer doesn't have an open system. They can't access the data, so we're very much an open platform there, best of breed. As you move down the pyramid, towards the mid-market, it's absolutely a more competitive space, so our technique there is to not try to compete with people who are bigger than us that we won't win against. So for example, we're not going to be -- we're going to -- don't try and compete with a Cisco Duo in that environment. So we're very much focused on how do we differentiate our product and how do we go after our sweet spots. For example, probably, the people who don't want to put their authentication in the cloud, they want to keep it closer to their own environment. We can fit very strongly there, [ places that have ] off-line environments. And again looking at the smaller market, how can we embed that into those managed service platform providers is another piece we're looking at.
Thank you, Allen. Another question from [ Marvin ], "Do you see any risk under the Trump government that the new administration wants U.S. businesses to provide authentication services to U.S. government entities going forward?" Well, I think observation number one is Mr. Trump has been in office before and it didn't have any impact. We don't really expect any impact today. It's also one of the reasons why we do not sell direct in the U.S. market. We sit behind local national, typically, system integrators, primes. And that's typically a very good position for us to be in. Another one from [ Marvin ]. "How long are your typical contracts with government entities? What are the termination periods for those contracts?" Let's keep this relatively straightforward. In the U.S., it's very much well known that they are funded on an annual basis; and therefore, our contracts are on an annual basis. That doesn't mean that we don't provide pricing for the outer-years. Typically, when we bid for contracts, we're being asked to bid for base year and option years, where option years can be option year #1, #2, #3 and #4. So it could be anything up to 5 years. Sometimes, we're being asked to price for anything up to option year #9. i.e., you're bidding base plus 9, i.e., 10 years, but you don't get the contract for 10 years. And if we look at the contracts, particularly on support and maintenance, there is no termination, in as far as these contracts are paid annually upfront. We have a question from [ Guy ] next. "Is there any reason to question the relationship with the U.S. government given the recent election? Does the product become less valuable as you sell more and people get more familiar with your approach to software security?" Hopefully, answered the first question already. The second part is does the product become less valuable. I actually think it becomes incredibly more valuable, and we've actually seen that happening in recent years. As we've won some of the real large programs within the U.S. federal agencies, that's very much the queue and the starting point for the other federal agency to say, "Actually, if they can do it, we can do it." And that's very much what we've seen after we won Department of State. Obviously we announced the deal in December last year. They were pretty much waiting for Department of State to go into production before they went. And now we're seeing a stream of other opportunities coming into the market, so actually I think it makes us more valuable rather than less valuable. Another question from [ Marvin ]. "Do you expect to be able to accelerate your sustainable revenue CAGR from historically low mid-teens to plus 20%-plus going forward while keeping and -- keeping or increasing margins?" Nitil, one for you.
Thanks, Klaas. It's a difficult one. We're cautious. As you can see, we are dependent on procurement cycles, so that's why we focus on the support and maintenance and repeatable revenues as a key KPI, because we know that we can rely on that. As licenses grow, then the support and maintenance grows. And as we shift to subscription, we'll have more visibility, so the aim is, yes, to keep the momentum going. Can we guarantee that? No, we cannot, because of the way the procurement cycle works, but the idea is to -- [ one that ] Klaas has mentioned previously. We've been a -- very much a peak [ and strong ] entity. What we're trying to do is we're taking the peaks. We want to keep them, but we're trying to fill the troughs up with smaller, more sustainable deals. And therefore, we have more sustainable revenues, as you suggest. Can we keep the 20%-plus CAGR? That's the aim that we want to keep on doing, so yes, we're trying to keep growing at that rate as we can.
All right, [ we'll wrap up ] through the next few questions. Hopefully, we can get to the end. Given the -- it's a question from [ Stephen ]: "Given the possibility of increased trade barriers to the U.S., do you see benefit in a U.S. listing?" I think -- if we went for a U.S. listing, I think I would have to find a new CFO because I don't think Nitil would be up for quarterly reporting and the very high cost associated that, but on a more serious note, at this stage, I don't think that's even in the picture. We're very happy where we are at the moment. We do feel we've got enough differentiation in the market and pricing power to deal with that. [ Simon ] has got a question. "[ Tera Soft ] seems to be very busy pushing a great many companies and webinars, but I haven't seen IGP mentioned. How is the relationship developing?" Allen, do you want to answer that one?
Yes. So we are starting to appear in there now. So we were recently on a stand with them at an event. We've recently published material on their website. And we are currently planning joint webinars with them. So that is our focus in there will be increased over the coming months.
Thank you. [ Simon ], another question. "How exceptional was last year's exceptional? Could something like that happen again?" Absolutely, [ Simon ]. I don't see any reason why it wouldn't happen again. Well, I'm not going to tell you it will happen every quarter because we'll be in a very different space, but there's definitely opportunities in the market out there and we're actively positioning. [ Alastair ]. "Nitil touched on timing for the big U.S. opportunity." Could you provide -- one second. "Could you provide a bit more detail on how this is expected to pan out and when?" Well, let me answer on this one. We're not going to provide any detail around that other than we're actively involved in that POC. The POC is progressing well, but as we well know with U.S. and U.S. federal procurement, timings can be quite difficult to predict. And even if I looked into my crystal ball, I wouldn't even give an answer to my Board, so I'm not quite sure how I could you -- could give you a [ confident ] answer there. Because there is no exact answer there other than we're very well engaged. We have a question from [ John ]. "How is your own company cybersecurity process? Do you use your own product?" Very good question. "And following on, what might be the impact of a breach in a client organization relating to your product?" So let's start with number one. "Do you use your own products?" Yes, we eat our own dog food, and we are very extremely well protected. And we know that we recently had pen testing done. And they didn't really find anything worth of any note and they couldn't get through our protection. There was a second part in that question. "And following on, what might be the impact of a breach in the client organization relating to your products?" Allen, one for you.
The impact will be quite high. I'm glad to say, in the 24 years I've been here, we've never had one.
That's answered that question. [ Martin ] has got a question. "Why has your share price dropped from the peak of 200p?" To be totally honest, [ Martin ], I don't know. I don't really focus on the share price. We focus on running the business. The share price is something that's happening around us. And there is clearly institutional pressures. There's retail pressure, but the interesting [ bit ], we definitely know from the institutional side that they are very supportive in what we do, so I'm afraid I haven't got an answer for you. [ John ] has got a question. "You speak of your M&A activity, but presumably Intercede must be being looked at as a target. Are you able to comment?" [ John ], I think you know what the answer to that is. I can't comment on that. I'm not trying to be awkward, but we can only put information in the public domain that is shared with everyone else. [ Simon ]. "So will Microsoft effectively start acting as a reseller?" The answer is no to that, but as Allen has, hopefully, explained, we will be very closely technically integrated with the Entra platform, which will give us net new license opportunity through our distribution channel and resellers. And then final question, [ Chris S ]. And then we're nearly -- well, we are out of time, but, "Are there any opportunities to sell your products to the U.K. government?" Absolutely. There are opportunities to sell in the U.K. government. We are actively doing so. Unfortunately, we can't really disclose any detail around those, but I can confirm that U.K. government absolutely uses our software. And that is dealt with 24 questions in record time. [ Jake ], back to you.
Perfect, Klaas. That's great, and Allen and Nitil as well. Thank you very much indeed for being so generous of your time then addressing all of those questions that came in, but Klaas, perhaps before really just looking to redirect those on the call to provide you their feedback, which I know is particularly important to yourself and the company, if I could please just ask you for a few closing comments to wrap up with, that would be great.
Yes, will do so. Thank you, [ Jake ]. So on the back of a record year, we've maintained this momentum into the first half and believe we're in an extremely strong position to deliver the full year forecast and on the back of the strength and maturity of our current pipeline, as explained. Our offering remains very relevant, as witnessed by the daily stream of data breaches across the world. And Allen has explained how we are positioning with Microsoft for an end-to-end integration with Microsoft Entra but also highlighted how we now start to work with MSPs and MSSPs to bring strong authentication into the SMB market. So very much the low-end market that we traditionally haven't pursued. Finally, none of this is possible without our team of highly committed and loyal colleagues who, day after day, deliver the best code in our part of the industry. We aim to deliver continued revenue growth, both organically and inorganically, and profitability. And we strongly believe we are on track to deliver this for the full fiscal year. Please do take your time for your feedback on this session, as we take this very, very seriously. And finally, thank you again for attending. We look forward to updating you all again with IMC in June 2025.
Perfect, Klaas. That's great. And thank you once again for updating investors this afternoon. Could I please ask investors not to close this session? As you'll now be automatically redirected for the opportunity to provide your feedback in order that the management team can really better understand your views and expectations. This will only take a few moments to complete, but I'm sure it'll be greatly valued by the company. On behalf of the management team with Intercede Group plc, we would like to thank you for attending today's presentation. That now concludes today's session. So good afternoon to you all.
Thank you.
Thank you.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Intercede Group plc transcript - plus 251,000+ transcripts from 12,000+ companies, speaker segments and full-text search - through the EarningsAPI REST API or hosted MCP server.
Get an API key View API docs →For developers and AI pipelines
Programmatic access to Intercede Group plc earnings transcripts and 251,000+ others is available through the
EarningsAPI REST API and the hosted MCP server.
Quarterly plans from $105 - full transcripts, speaker segments, full-text search,
and the /api/v1/transcripts/recent polling endpoint for ETL pipelines.