Yubico AB (YUBICO) Earnings Call Transcript
November 19, 2025
Earnings Call Speaker Segments
So welcome, everyone, to Yubico's Investor Day. My name is Alexandra Barganowski, and I'm the Investor Relations at Yubico. And I'll also be your moderator for the Q&A sessions later today. Just for some practicalities, this presentation is live streamed, but it will be available afterwards on our Investor Relations website and as well the material. And the presentation is largely split into 3 parts. We will have a Q&A session after each section. So if you have any questions for the speakers, please hold your your questions until then. And now I'd like to welcome Mattias Danielsson up on stage to kick off the day and talk us through the agenda. Welcome, Mattias.
Thank you, Alexandra. Can you hear me all right? Great. So before diving into today's agenda, I'd like to make 2 observations. First one is, you saw from the heading here that this is talking about building safe digital identities for future generations. So we'll take a very high-level look at the market, the product, the company, to explain what precision we're in. And then we'll talk about some of the things that we're seeing happening in the market and how we want to position to make sure that we're relevant in that emerging new world. So we will be high level talking about our view of the market and our strategies. We are aware that we released the Q3 report last week. So we'll, of course, be happy to take questions on that, too, but we'll focus primarily on long-term trends and strategies. The other kind of obvious observation is that I'm trying to speak English. Yubico was started in Sweden, and we're proud of that. But the reason for speaking English is that we have a very diverse and international crowd and a very diverse and international company. I think you'll notice that with today's presenters, it's only Stina and I who grew up speaking Swedish. If you feel more comfortable asking questions in Swedish language, we'll be happy to take them in Swedish, translate them and respond back in English as best we can. And with that, I'll dive straight into the agenda. So we'll start by explaining how we see the market today and the position that we've built. And Jerrod will start with that, talking about it from the product and technology perspective. And then Yubico's CRO, Carl Helle, will take us through some customer journeys. And we're very excited and proud to have 2 fantastic representatives of major customers of ours who will be talking about their journey and where you can ask unfiltered questions, of course. And so that is the Q&A session. There will be a short break, and then we'll do more of a deep dive into technology. So Yubico's CTO, Chief Product and Technology Officer, Albert, will take us through that part. And then [Audio Gap] to kind of summarize the position we're in today. Snejana, Yubico's CFO, will walk us through the numbers, how to interpret the business models that we have, how to map that. So we won't be sharing any new financial numbers, but we'll hopefully provide some color and some detail for you to better analyze the position that we're in. And that will actually also go for the more forward-looking sessions that we'll then continue with. We won't be sharing -- sorry, we won't be sharing any new product news or any new targets today, but hopefully, we'll be able to provide a little bit more color on where we're heading. So we'll start with -- I'll start that session with talking about our go-to-market, how we get from the position that we're in today and how we can build on that foundation to reach new customers and solve new use cases. Of course, the foundation for all of that will be our product offering. So again, Jerrod will join me on stage to talk about -- a little bit about the -- what we're seeing happening in the market. And then Albert will follow up to see what's our response to that? What's our strategy to what we're seeing in the market. And we're then fortunate enough to have one of Yubico's co-founders, Stina, join us on stage to talk a little bit about the partnership we have with the new entity that she has set up, which is a -- the SIROS foundation. So that's going to be exciting. We'll end that session 2 with Q&A and then we'll wrap it up. So far, we're pretty much on time. So with that, I'd like to hand over to Jerrod, who's been my colleague for the last 12 or 13 years, and will take about -- take us through the market.
Thank you so much, Mattias. Thank you. Today, I'm going to give you a quick overview on how we look at the cyber landscape. As Mattias mentioned, we are a global company. So we see these trends not just in one country or one region, but we see this everywhere. And the good news is that we see this everywhere. They're not so good news is that it's the same problem that everyone has. This is a snapshot of news that you see all the time. This slide that we created was just the first 2 weeks of October this year. We say to customers and -- how should we think about cybersecurity and attacks? There are 2 camps. A company that has been breached and are working to protect themselves and a company that doesn't know they've been breached and will have to protect themselves. And it's an interesting fundamental change, which is you have to assume the organization is breached and what are you going to do about it. And the #1 way that the companies get breached today, organizations get breached is through an account takeover. And the #1 way that you do an account takeover is a phishing attack. And we've seen this rapid acceleration over the last 5 years, but it has been happening steadily over the last decade. And it's just going to be increasing because of new techniques and the thing we call AI. I wanted to walk through a little bit of what that means today with some of the techniques that we've seen, a little bit of audience participation, 2 e-mails, one written by a human and one written by AI. Take a few seconds to read it. How many think that example B was written by a human. Example A was written by human. 30% got it right. Example B was written by AI. The fact that anyone even raised their hand for example B means AI is doing its job, right? Because all it takes is one person to compromise an organization. And so the lines are really getting very blurred. The phishing attacks that you see today are just the tip of the iceberg. And I'll go through a little bit about how advanced some of these things are going to be. But it's clear, asking a human to figure this out is an impossible task. There's no amount of training that will get you there. So I want to take a step back a little bit. What is all these phishing attacks all about? We've got -- we've been using technologies to log into systems more than 3 decades now. And the industry has used different techniques over time to try to prevent some of these attacks. But let's just take a quick look at what is happening behind the scenes. So I've just mentioned, AI can generate a lot of phishing e-mails with just a click of a button. And what they typically do is to get you to click on a link and redirect you to a fake website, which looks exactly like the real website, bank website, government website, your doctor's website, anything that you do today, in a legitimate way can be turned around and we used to attack you. So you put in your login, user name and password, which is the most common form of log-in authentication. And the AI agent or in this case, the human will just take those credentials. They will then use those same credentials and log into the real website. So at this point, you said, well, what can I do about it? Over the last decades, there are many different types of additional authentication vectors that people use. One of the most common is SMS. So at this point, you said, aha, no worries. I get my password, but you still didn't get my OTP credentials or the SMS code that came into my phone. But at this point, the new -- the system is expecting the SMS OTP code. So it will send out the SMS OTP code to the user. And the user is, okay, great, I've got my code now. Now you cannot get in still. But in this same situation, because you're on the fake website, you actually type in the real SMS code to the fake website. And that's how the attackers get in. So because of the way this is set up, and you are already believing the fake website is a real website. You would do everything that you would normally do on a real website. And that's how the attackers get you. And so this technique, when I first presented this scenario here, this was actually back in 2016, same diagram without the AI pictures, but 2016, I presented at one of the hacker conference, Black Hat, nothing has changed. Nothing has changed. The big thing that's changed is the scale, the speed and the accuracy of these attacks. I want to show you something really quick, not necessarily to scare you, but to just give you a sense of how the techniques have evolved rapidly over the last 1.5 years or 2 years with both generative AI as well as soon, you'll see a lot more agentic AI in the picture. This is a tool that we actually found at the same conference, Black Hat conference this year. And it's open source, anybody can use it. People use it to test their readiness, but you can be assured that the attackers are using some version of this to actually do real attacks. So we try to trick ourselves, Yubico, we try this tool. We put in our company name, and it will check whether this is a real company, Yubico is a real company. And then it checks online, various systems, who are the people working there, and we have our employees. We've got permission from them to use their names. And what it is doing today is -- or this sequence is that it's grabbing their LinkedIn profile and everything to do with who they are online. So this is all public information. The tool then passes out all the information about the individual, professional development, professional information. And it creates 2 different types of e-mail. One is generating feedback on maybe something that they care about. And the second one is to have another e-mail to persuade them to share something. And so when we get this pretext e-mail from the AI, it knows right away. It writes Daniel, it's actually from Latin America. You can see Latin America there. He works with a lot of different companies there. And the AI just generates everything based on the LinkedIn profile, so it's relevant for Daniel. Bettina, who works in channel marketing or channel sales has something similar. David, who works in our customer advocacy program has something relevant for what he wants to know. The time I've used to explain this to all of you, the tool can generate millions of e-mails to employees, customers, suppliers and so on and so forth without us doing anything. They use the same techniques that we use for productivity. So they actually -- this tool actually use one of the top AI engines for free to generate these e-mails. So as you look ahead, it's not a great scenario for what we call the defenders, right? A lot of us are on defending our organization, or helping our customers defend the organization. But the good news is that there's actually a solution to this. And so I'll change a little bit of the perspective on how we look at the market because what we've identified in terms of these attacks actually has been solved. We've been working on this thing and now we call it Passkeys, I'll explain that a little bit. We're working on this technology that fundamentally changed this attacker and defender paradigm, which is to eliminate this industry problem. The origins of passkeys was the work that we've done with Google almost now more than a decade ago. And this case study was -- is really remarkable because when Google wrote this case study, it's not just impressive stats that we've realized. These are stats that are unheard of. And the number that you want to key in on is 0. And so why is it that we have this technology for more than a decade, but yet we have still all these breaches. Maturity, right? Maturity of the technology takes time for people to understand and learn and then implement and adopt. But this has been existing for more than a decade to solve all the things you just saw in terms of the attacks that Yubico actually co-created. So what is this passkey conversation that a lot of you ask. It is the FIDO standard that Yubico co-created. It is the version 2 of the FIDO standard, implementing passwordless authentication. Unfortunately, the industry didn't do a great job trying to help educate all these names that the tech keys create, right? We had FIDO1, which was FIDO we called it U2 universal second factor. Then we had web authentication, then we had FIDO2 and then now we have passkeys. So we didn't do a good job trying to educate. But it's the same fundamental technologies that can eliminate phishing attacks and prevent account takeovers. Now today, passkeys exist in various devices. And this is intentional. This is not because we said, okay, this is a way that this is to work, and it only has to work in one way. On the bottom left, the three basic types of devices that we all as users use to passkeys. A purpose-built device like a YubiKey, purpose-built, which is all it does is security. A general purpose device like a laptop or a phone. And the way you unlock using the passkey credential is something that you remember like a PIN or who you are like a biometrics. So this is pretty well established in the market for many customers that have been using the technology this way. Now how does this actually prevent what we just talked about in terms of the attacks. So same phishing attack, you go to the fake login page, you put in a credential. They take your credential. But before they can actually move forward, this technology requires you to show that you have this device in your possession. There's no typing of codes. There's no codes involved. And so if you don't have this device, whether it's the YubiKeys or the phone you have, you're not getting in. So it essentially stops it at its tracks. And the way this technology works as well is that it knows the difference between a real website and a fake website. There's no user training. So it works out of the box. And that's the whole point. You don't want the users to think about which website to click and which website not to click. And to go further, possession of this device requires a human presence. So you can't ask an agentic AI, agent to go and like touch your device on your behalf. What we call human verification is part of this technology that we created or the protocol, what we call the standard we have created, and that was way before any AI agents ever existed. And today, the way that a lot of our customers is actually together. You actually need a very strong foundational piece of purpose of device to anchor all the other devices. The reason we say that is if you don't have a password, how do you get back -- how do you reset anything? Like there's nobody to call to reset anything. You just have a device. And so you actually use the trusted device to then what we call bootstrap the devices. And this is a very fundamental conversation, which is if you bought a house and you've got a car key -- a house key, you don't just have one. You have one that you can then use and then you've got a backup one. So it's very, very -- we live in a physical world. And these concepts are very much the same when you apply these techniques to the logical world on the Internet and when you try to apply it to log in. One other area of maybe putting some color to what we do at Yubico is to drive an entire industry around this. As I've mentioned before, we co-created FIDO with Google, and it was 2012. And you noticed over this period of a decade, we actually had to have 2 other big technology giants as part of the standard. Why? If all of us are using devices to get Internet to do something there are only 3 big players in the whole world today that are the gateways to the Internet. Google and all their Google Android phones, Microsoft and all their Microsoft operating system, laptops and tablets and Apple and all their devices. So actually, in 2022, Apple made full support for FIDO within their ecosystem, which means the 3 big players implemented the technology that we co-created. And again, this is intentional because they have to support everybody in the world. Our goal at Yubico was to make sure that we could create the type of protection that can be applied for everyone on Internet, which is one of our missions, which is our mission to protect all users on the Internet. But it wasn't just that we got the standard and we got the 3 tech giants to embrace and use the technology. We had to push the entire ecosystem. Everybody else that use the systems and more services had to also implement the standard. So this is just a glimpse that we have hundreds of thousands of services obviously implemented FIDO today. Obviously, all of them can leverage the operating systems and the devices that is already built in by Google, Microsoft and Apple. But the other thing that we also did was to make sure that corporations and businesses understood the difference between the different types of category of using FIDO. But also the industry analysts accepted this technology that we created. So this is a report from Gartner, one of the industry analysts to talk about authentication and digital identities. And you can see on the very, very far right. FIDO security keys, which is industry term for YubiKeys are the very highest type of authenticators to use. And then all the other types of FIDO authenticators on the phone or the software comes before that. So we work really very hard to make sure that the industry analysts recognize the standard that is out there. And that's why you see a huge proliferation of technology. It took a decade. The last point I wanted to help shape some of the views what Yubico does was it wasn't enough to build the standard, drive the ecosystem, convince the industry analysts. We also had to drive policy because many businesses will say, this is a great technology, just great. But until the government says I have to use it, I'm not going to use it. Or until the government says, okay, and I may get fine, then I'll do it. And so we've been driving policies and regulation in the entire world for FIDO to be accepted as a gold standard for authentication. Actually started back around the time I presented to Black Hat in 2016, where we talked to some of the individuals in the standards bodies in the U.S. And of course, that has grown significantly over the last, I would say, 2 years, huge uptick in the Asia Pacific region, which is mandating FIDO, mandating phishing-resistant technology as part of just hygiene, right? Citizen hygiene, you see this word, which is good hygiene at home really helps create protections for corporations and for that matter, nations. I'll leave you with a video of how a YubiKeys works because I've been talking a lot of things that Yubico is doing and a lot of things that would help shape the ecosystem. I want to share with you how it all works. [Presentation]
So this is a quick overview of what we've been doing with industry and what we've been doing behind the scenes to drive the open standards. With that, I wanted to hand over to my colleague, who is going to tell you a little bit how we accelerate our go-to-market motions.
Thank you, Jerrod. I appreciate it and nice overview. Good afternoon to everyone in the room. I appreciate you all being here and to all those online, welcome. My name is Carl Helle. I'm the CRO for Yubico. And I've been in this business over 25 years now. I know I don't look it, but believe me, I've been here a while. So today, I'm going to talk to you a little bit about the economic impact of what's happening in the market. I think Jerrod did a really nice job painting the picture of how it happens. But I'm going to talk to you a little bit about the economic impact, customers' challenges, why they would choose Yubico, and then we're going to take you down the customer journey. So let's get started. So this slide just illustrates that bad actors are not letting up. Over the course of time, these numbers continue to rise. And at this point, industry analysts say that it's over a $9.5 trillion problem across the world. That is massive. And it's going up roughly 15%. To combat that, of course, companies, organizations, government, you name it, have to continue to spend on technologies, applications, people, and that's also rising at roughly 15% . And this trend has been going on since I've been in the business. What is interesting is Proofpoint actually illustrates in their study that the CISOs, the top-level security person in the organization and the Board of Directors, along with CEOs and CFOs are now becoming more aligned to fight these issues. So there's more conversations than ever before to understand what's happening and what the organization is doing about it. So there's a lot of pressure on the individual security teams and staff to answer the question of what are we doing to protect ourselves. Breaches from stolen credentials is at an all-time high. And when those breaches happen, believe me, the bad actor doesn't stop there. They find their way in many times, they'll rest for long periods of time, sometimes even months. And they'll just watch the traffic move within the organization and then find their path to move laterally in that organization. So they might breach a staff accountant that wouldn't appear to be a critical spot in the organization. But because they breach that person, they move laterally into higher levels of the organization to systems and data, data centers and applications that host the most sensitive data within the organization. That's where the problems really begin. The increase of cyber attacks is going way, way up. And the average impact in 2025 is over $5 million per breach. If you think about that, most medium to small businesses are unable to sustain even one attack. Studies report that 6 months after an attack, that small business is out of business. The stakes are really high. It's important that -- you all can understand that. The bad actors, as you saw from Jerrod's presentation, they don't break in. There's nobody brute forcing systems anymore. I mean they might, but that's very old technology or old way of breaking in. They just log in. They just simply steal your credentials and log in as you. And when that happens, they're easily able to migrate to other areas of the organization. Companies are pouring billions of dollars into trying to stop these type of attacks. So it's really time to rethink security and identity security. And it's an imperative that companies try to protect these 3 elements. One is business continuity. And for large organizations, a breach may only take down a portion of it. We see it in the news all the time. Jerrod showed you some articles around on that. But business continuity has a major impact because if one end of the business is down, it affects the overall business, sometimes the economy. Brand protection is super important. As we all know, some organizations have a bigger brand than they do at revenue. Super important to them, and they want to protect that. And last, of course, as Jerrod mentioned, achieving compliance. Because there's a hesitation to spend more unless there's a result at the end. And sometimes those result in fines and other things that are requirements based on the industry that the organization might be in. So how are the companies keeping up today? Well, this is the arc of kind of how they've been trying to keep up. Way back in the day, we just logged in. We just put in our name and company, and we'd log into our systems. Then passwords became really relevant. We all put little yellow sticky notes, put a password up there, so we wouldn't forget. Anyone in here ever do that. Over time, it became SMS codes and authentication devices, authentication apps and now biometrics all become part of this. But they don't work. As you saw with Jerrod's presentation, they can all be intercepted through the power of AI tools, all of those ways can be intercepted. Imagine if you run a 20,000-person company, and you're counting on every person every day, doing the right thing every time. It is a huge burden on your employees and your staff, and there's just no way to combat it with that. As Jerrod said, all the training in the world won't solve that problem. So it results in partial protection around some of the people, some of the time. And there's compliance gaps throughout the organization of any size. So there's a new world. There's a new world think about how we do this, how we come to try to solve for these issues. And it starts with unburdening the user. We have to have user-friendly security. Easy security gets used, difficult security gets worked around. We need protection for all. We need compliance that's built in. We need purpose-built passwordless security, and we need proactive prevention. Those are the elements that must take place. And so that sets up Yubico to be a really great strategic partner. Based on what we've done for years and years, we've demonstrated market leadership. We have worldwide distribution, and we have scale in production and delivery. It's evidenced by the number of customers we have and certainly by the thousands of proven technology alliances that we've created over the journey of Yubico. We've been delivering on that promise for years. It's time to rethink identity security and how to go about it. And that's what we're doing every day at Yubico. It's too common to have these kind of messages end up in your inbox. A few weeks ago, I traveled to London, and I got this message shortly after. And it basically was from my airline that said, hey, by the way, the Dublin Airport may not have lost some of your data. They may or may not have some of your information on your flights. And of course, I think, well, what else do they have? That happens all the time for individuals and people and companies are sick and tired of being sick and tired. So they're starting to do things proactively to put measures in place so these kind of things don't happen. Every user is a privileged user. As I said, anybody can be -- their credentials can be stolen and they migrate. And 7 to 10 years ago, when we were building keys for companies that were very interested in our technology, it was a bit complex. Many of the keys were custom keys. What that results in today is we easily do custom keys because we had to back in the day. Today, with FIDO2 with Fast Identity Online, that's what that stands for. That standard has boosted the standardizations within the industry so that others can follow the same standard. It's a rule book, if you will, of how the technology should and could work. Back in the day, we sold individual use cases to organizations, talk to them about their particular needs in the organization and built keys, many times custom-built keys for that organization. Today, that's changed quite a bit. I'll get back to that in a little bit. There's really 2 scenarios that organizations purchase YubiKeys. There's the planned event, which is organizations, both small and large, know that they have a situation and they know they have a need, and we do the typical sales process. We do some discovery. We meet with the customer. We bring our teams in. We architect a solution with YubiKeys and sometimes our alliance partners. Eventually, we have a purchase. For large customers, that can be anywhere from 18 to 36 months, sometimes even longer. For smaller customers, that's usually 3 to 6 months to go through that process. In the unplanned scenario, it's a little bit different. The hair is on fire. There's indicators within their systems that say, "Hey, something is going on, does it look right, doesn't feel right? We may or may not have a breach." In those cases, there's an escalated approach to this. Everybody is online. It's very urgent. And they really look at it from a damage control and environment analysis. What's going on, what's been affected, what can we do? Many times, Yubico gets a call in these situations, and we get asked for help. Through all of that, we've developed a rapid response program that we implement where we get keys to customers very, very quickly. In cases where it's a relatively small customer, a few thousand people, those keys are out in a few days. In other cases, large customers, it even might take a few months before they really get their arms around what's happening. But either way, there's usually a purchase at the end. So let me give you a couple of examples of how this kind of unfolds. We have a very large financial institution that we worked with in the United States, you would know their name. And they were very interested in enhanced biometric solution. We have biometrics, but they wanted the advanced pieces parts, and we had to work with a lot of alliance partners. Our teams went in, did all the planning things, did the discovery, worked with alliance partners and with many of our own in-house product and engineering teams to build a custom key for them. That process was a good process for both and all entities, and it turned into a $7 million purchase of keys for 150,000 employees, a great win on Yubico's statute. In another case, a financial institution, real estate company started seeing those indicators through their Splunk environment and brought forth the request to secure some of their most critical assets. In this case, keys were out 9 days to solve for that problem, began to secure the company, letting them go buy new computers so that they'd knew they had a secure environment to do some analysis. Both of these end up being very, very relevant in terms of how people purchase YubiKeys. But don't let me just tell you, I'm going to turn it over to Brian Bell here. And Brian is with T-Mobile, and he's going to share his story and his journey with you all.
Thanks, everybody. I have a story to tell, but I feel like you guys already told it for me. So there's going to be a lot of repeat information here. So as Carl said, I am a principal cybersecurity architect at T-Mobile. I've been there for multiple years now, 25 years. Hopefully, I don't look as well. And we struggled with the same battle that everybody has been talking about here today. T-Mobile is seeing account takeovers at a climbing, climbing rate, 100-plus a week. We were losing employee data, which resulted in customer impacts. SIM swaps were happening, accounts were being taken over. This was at business scale as well as individual customers. It's a huge issue for us. One that we needed to solve quickly. We decided to make a cultural change at that point, and that's really what it took. In 2023, we brought in a new CISO, decided that account takeovers had to go from the hundreds to 0, something we had to stop immediately. We went through the process of strategy around this and said, what can we do? We needed a phish-resistant solution. Our passwords weren't working, our MFA standards that we had weren't working, and we needed a partner to be able to get us there, and we started looking and we found Yubico. We decided that we needed to have something quickly. It wasn't something we could wait on. So we did a little bit of an escalation on that. I wouldn't say we were in the hair on fire situation, but we wanted to do something quickly. We started in May of -- or sorry, March of 2023 reviewing our processes, saying what is it we wanted to do. By May, we had orders in place. By July, we started our deployment. Within 4 months, we had 170,000 keys deployed to users, registered users, clearing out all their authentication factors that they had and starting from scratch, rebuilding every single person up. By February of 2024, we completed our deployment to over 200,000 accounts and continued to do that today, refining as we go, making things stronger and better. It didn't come easily though. That was something, as I said, was a cultural change for us. The new CISO came in, and we made this a pillar of our standards for the year. We said, "Hey, security has to come first. We can no longer be something that comes up as a hindrance or just a compliance piece. We need to be working together with all of our teams to build this out and to know that every employee knows that security comes first," and that's really what it took. As we went through looking at what it was that was going to make Yubico the user or the provider for us, we said, "Hey, how can you get us there? And they delivered. That strategy that we had to deliver that in the keys was going to take a provider that could be there for us. They could help us with deploying not only locally. We took to our corporate offices. We had 46 regional business offices. We had users out in the field in the U.S. and globally. And we deployed every single one of them. This is our full-time employees, our contractors to our organization, service partners. We made it part of our contracts to say, "Hey, you have to have this. Yubico will be your standard. You will buy these keys. It will be part of your agreement with us." And everybody was kind of taken it back, right? It's a new thing to say, "Hey, I'm changing the standard on you." And it has made a leaps and bounds change though, about how they're able to access, how it makes their experience better with us at this point in time now. Getting to a passwordless standard has not only simplified the business for us, but it simplified the business for them in the long run. So it's something that culturally once that took hold, made all the difference in the world. That velocity was huge. So as I said, Yubico came to the table with us. They worked with our VARs. We had deployments of 15,000 keys to 50,000 at a time, and they met every single goal for us coming through. That allowed us to meet that global distribution. When we say that we deployed in that strategy, it was also very short windows. We would give our groups 24 hours and say, "Hey, your key is coming. Tomorrow, you need to register that key." That's the precision that we did this on and it was just that Yubico was able to deliver it for us. So this is the kind of partnership that we need to be able to not only get that out, but then sustain long term. As more use cases came up and more items came to the table, Yubico has been there with us along the way to say, "Hey, how can we help solve this?" If it's a remote access piece, whatever it may be, they were there with us in the trenches working through the technology details and making sure they can supply us what's needed. The form factor availability is also a big key for us. As we talked about, we're accessing on every type of endpoint. There's your virtual systems. These are mobile devices, part of our business. These are going to be laptops, desktops, whatever it may be. Yubico had something to fit every single one of those for us and make sure that legacy systems that we had to handle had the right type of access and made sure that all the new systems were there. And that standard as phones and devices things have evolved, we've been able to evolve what products we're bringing in and making sure we have that up to speed as well. This resulted in us being able to do that elimination of account takeovers. T-Mobile is now at a 0 account takeover status. It is not something we see anymore. It's not something that we worry about. We went from being ones that were in the news for the bad things happening to us to the ones in the news saying, "Hey, bring it on, what do you got? We're not really afraid of you anymore." It's a weird place to be, but it's something that we pride ourselves on. And that took that change and it took a partnership like that to get us there. It also has made it better for our employees. I talked a little bit about the user experience. Going passwordless has been huge. Internally, it cuts down our costs, our service department cost for having to do password resets has dropped dramatically. And that's huge piece for both the employee as well as the end user that's our -- person that's helping out on the technician side. Our ability to streamline how you log in is nice. I mean you can go in there and if you've never done this experience with a key, it's fantastic. You don't have to enter anything and there's no e-mail. There's no password. You just say, I want to choose my identity and you're off to the races and going. So it makes things a lot smoother for that. The bootstrapping process has become more streamlined as well. We've got endpoints from iPads in retail stores to those machines coming online, and we use the YubiKeys as the first portion for that. Regardless of any other factors you may use along the way, Yubico is our standard for everyone. Our security key is the cornerstone of them setting up for everything, and they can use that to bootstrap and bring other things online. So if they want to use the passkey or Windows Hello for business, they can. But this is the piece we want everybody to have and know that it's going to be and it's going to work every single time for every single use case that we have. This has also helped us with our business pieces. So I talked a little bit about account takeovers and the impacts that, that had. I look at our T-Mobile for business as a portion of our organization that was really hesitant about this. They used to say, "Hey you know what, we can't have anything that's going to take us down, anything that's going to slow us down." But by the time we started implementing this and came through it, they were the first ones to come back to the table and say, "Hey, you know what, we've got this now. Our account takeover rates are going down. I can go out and sell to customers." These large-scale organizations that know that they can come to T-Mobile and no longer be afraid that they're going to see the news heading that T-Mobile has been breached that their information is out there, that their account got taken over all of a sudden and now millions of dollars are at risk. And the benefits of that have been huge. It allows our organization to grow, allows us to be innovative and continue to move forward, knowing we will always have security front of mind, and we'll be good wherever we go to. I would say also that the -- sorry, lost my thought. I apologize, long flight yesterday. The acceleration to this with passwordless verification is great for us to be able to move on in a -- I apologize, guys. I lost my wording. I'll just dump to the end here. I will say that the partnership with Yubico is the strongest thing that we've had in moving forward with our enterprise standards. If you're a small business enterprise-level company, having a partner in business is what's going to take you and go places. It's not something we can do by ourselves. And we know that Yubico is what's been able to help us deliver this new cultural change. It's helped us move forward and know that we could be secure in a climate that's always out to get you and something that we value more than anything else we can say. So we appreciate Yubico. I appreciate the opportunity to be here. Sorry, I stumbled a little bit there. But hopefully, this is helpful and looking forward to the questions and kind of talking about our journey with you going forward.
You can see that customers count on Yubico. And the reason they count on us is because they trust us. We've earned that right over the many years of work we've done in the industry and what we put forth as a company. And today, we continue to grow our relationships and our partnerships with both alliance partners and our end user customers in a really relevant significant way. And that will prove to be a winning proposition. We also know that there's a lot of other companies out there that trust our brand. And this is just a small sampling of approved companies that allow us to put us up, but there's many, many more. You'll notice a few of the key customers up here, others that are in identity security as well, Okta, Ping, Microsoft all using YubiKeys as part of their solution to secure the environment. Those are significant mile markers where we partner with them, not to compete, but to partner for a better, safer Internet. And we find that when we sell to a really relevant company or any company that has a good experience, that experience travels with them in their next location and their next job. Since I'm in charge of revenue, it's kind of important to have that as part of my go-to-market. So here is a customer that wasn't able to attend today, but he wanted to share his experience. [Presentation]
I think Derek illustrates it well how the technology moved with him from Google to now Cloudflare, one of the most significant Internet providers for websites. I showed you this slide before because there's really 7 use cases that kind of apply to all organizations that we talk to. And what companies have transitioned to is instead of just protecting on a particular use case, many times, it was the one on the far left, which was privileged access, the people that are in the most sensitive data in the data centers, accessing forms and information about employees. It's really moved to understanding that all their users are on the attack surface. And because all users are in the attack surface, companies must protect all those users. So it's changing very, very rapidly. Derek in the video kind of precursored this idea of what they're looking for in modern-day security requirements. They're looking for the protection for everyone in a simplified budgeting process with the highest level of identity security that's a simplified order process and that the rollout goes quickly and efficiently for their organization. You heard from Brian how quickly they rolled out over 200,000 users within T-Mobile. And as a company, we started to understand that not only is our security technology important because if someone buys a key, they have a product. But if they engage with Yubico and with our Yubico as a Service, it becomes a solution. So wrapped around our technology and the good work that's been done for years and years, we have spent a massive amount of time, energy and effort to make this rollout of YubiKeys that much easier. We provided organizations with a lower cost of entry, flexibility of choice of what form, factor or key they would like to have for what type of computer or what type of phone, we've created a way for faster deployment for -- through our Yubico Enterprise Delivery organization, and we're able to achieve that compliance company-wide much, much quicker. So again, these are the kind of things that Yubico is developing. It's not only the technology, but it's the process, procedure and the change management required by all of our organizations to roll keys out and deliver back to their end users that high-level protection. So once again, I'm going to step aside, and I'm going to let Joe talk a little bit about his journey with Yubico as a 3-time CISO and former Head of Identity and Access for Bank of New York. Joe?
Thank you all. So I had the fortunate benefit of doing planned deployments across 3 times, right? So 3 different employers to go through and have planned not fire burning episodes where we had phishing-resistant MFA coming through. I've deployed YubiKey 4s, and that's usually the precursor to YubiKey 5 and the FIDO standard that is now, right? So there's a transition of -- like the ease of deployment has become easier and easier, whereas before we were doing U2F deployments and smartcard authentication deployments that meant deploying those is a little bit more technically challenging. And you had to bootstrap a lot of that with some of the ykman command prompt capabilities that Yubico provided as a community. But as we started looking at this, I started looking at a line of business that I worked for -- at BNY. We started with a smaller deployment to prove that out. So I was a CISO for their analytics division and that's where we made our first purchase of YubiKeys 5 series for that line of business. We protected all the employees within that line of business and bootstrapped it to their identity platform and everywhere was integrated. Some of the legacy systems that didn't go through the IDP itself had deployment directly in the ecosystem that is supported by Yubico itself. So having a wide breadth of vendors supporting YubiKeys is great for me as a practitioner because I know that if it can't centrally deploy using an IP, there's a very good chance that the YubiKeys will be used and integrated well within the tool of choice. Going forward in the corporate deployment across the whole workforce, we started to look at the flexibility of YubiKeys as a Service. YubiKeys as a Service was interesting for me because we had the opportunity to look at the whole workforce and not make a deployment straight out across all 70,000. We started to look at how are we going to ramp the deployment and which particular audiences we'd want to achieve first. And with YubiKeys as a Service, we're able to look at how do we do that ramp, how do we deploy and then also cater to the different use cases that folks have. They mentioned privileged access, mobile users, all of those use cases have their preference as to which form factor. We also worked with our help desk teams to look at, well, what computers are out in the fleet and where are they in the tech refresh cycles. So we would be scheduling the YubiKeys deployments with what tech refreshes we would have. So if it's going to be USB-C versus USB-A form factor versus a micro form factor within. So that all helped us out, and we were able to essentially schedule and track that within the portal itself. When it comes to some of the challenges that we had not necessarily with YubiKeys and deployment of YubiKeys, but more so about what prompted us to look at YubiKeys well, it's compliance. The financial services market is highly regulated and global. And so you have all regions in the world deploying their own policies and standards. Luckily for us, NIST and the major standards bodies agree with the alliance and FIDO and we moved forward with deploying based on that assertion and the services as well. We've looked at opportunities where you continue to advance the technologies that you have in place, so 2-factor authentication is great. And I think everybody should be using that already, and there's many form factors to do that, OTP, SMS, but now the standards are also deprecating some of those because the attackers continue to advance. And so you'll see that SMS is a deprecated standard for channel of OTP. And so you continue to future-proof yourself by using technologies like passkeys and YubiKeys in that instance where in the end as policies deprecate what used to be good solutions, now all of a sudden you'll be ahead of the game. This also allowed us to move towards a passwordless capability across our workforce. And so this was one of the core pieces of technology that we provided across the workforce for passwordless authentication. We deployed biometrics with Windows Hello for Business and others, and we gave users a preference to look, but the gold standard was the YubiKeys for authenticating into all of our systems. And I'm more than happy to discuss any technical implementation details as well, but the YubiKeys as a Service platform and the flexibility it offered us was nice to have because you had a schedule that was fluctuating with time and the audience of where you'd want to deploy was also fluctuating. And so that gave us the agility to carve a nice path to deploy within a given time frame. Thank you.
Thank you. Again, just another testimonial to some of the work that's been done over the many years at Yubico, and I think it's really beginning to pay off for organizations of large and small. So I'm going to leave you with these 3 key takeaways. Organizations must protect all their users. I think we've beat that to death. You're going to hear a lot more about Yubico as a Service in future presentations this afternoon, and you're going to hear a little bit more about where we're headed with all that. Customer speed and propensity to act is accelerating. With the standard being so well adopted now and other organizations coming alongside of that, we're seeing a lot of interest around the FIDO2 standard, again, Fast Identity Online standard. And Yubico is absolutely focused on surpassing the expectations and the needs of our customers. We've built trust with our customers. We've built trust in the industry, and they look to us to fulfill that in the future and continue to grow as a company. Thank you very much. Appreciate it.
Thank you so much, Carl, and our speakers. This concludes actually the first session or the first part of the presentation. So I'd like to welcome the speakers back up on stage, including Mattias, to open up for our first Q&A session.
There should be a mic going around the room. If there are any questions in the room, just raise your hand and the microphone will come to you. But I have a couple of questions actually from the web as well. So maybe just to warm up the room, I should start with those. So Carl, to start with you, how repeatable are deals like T-Mobile and Bank of New York? Are they outliers? Or do they rule, would you say?
Well, we focus a lot on the Global 2000 accounts. And there's areas that we don't sell to the Global 2000s, but there's about 1,600 Global 2000 accounts that we put a lot of focus on. Each one of those accounts represents unbelievable opportunity for the company and for Yubico. I think getting to them all is never easy, but we certainly are pursuing that every day. And many of those companies have deployed some keys over the period of time. So we're always after expanding that footprint.
And a follow-up question to that. How long does it typically take from an initial engagement to a signed contract?
Yes. It depends on the organization. There's the planned and the unplanned. In the case of the planned, for a large organization, it's anywhere from a year to 3 years. I mean you can pick a time. It depends how developed their team is. It depends how far down the path they are. In a small organization, it can be 3 to 6 months. If it's unplanned, hair is on fire, you got to act quickly. Those time frames get reduced significantly.
Thank you, Carl. And a question for Jerrod. Could you actually go back to the concept of passkeys and how that fits into Yubico's solution?
Yes. I think -- again, the industry didn't do a good job explaining passkeys and its relevance overall and how does it fit to the overall ecosystem from what the previous work was. You can think of passkeys as a way to login passwordless. And you can do this with YubiKey as well. You can log in passwordless with YubiKey. And you can also login passwordless to something like an iPhone, right? But it's not so much about the passwordless experience, it's the technology behind the passwordless standard. For example, what we've known to be passwordless is what we call the magic link, where sometimes you go to travel site that says, you want to log in, go click the link. There are no passwords, right? It's just a link and you just click and you get in. So it matters more about the technology behind the passwordless authentication. And the reason we say that is that this particular passwordless authentication, passkeys, FIDO is a proven, mature standard that interoperates between different operating systems. So you get a consistent experience using this particular form of passwordless authentication, which is really important. And why do we know that? Because we at Yubico created it. So it's not just passwordless authentication, it's standardized passwordless authentication that has been deployed at scale.
And then a follow-up question, why do customers pay for hardware when software passkeys are free?
When we always look at the word free, it comes with a whole set of expectations and assumptions. It's never free. You always pay for something. And if you look at the technology behind passkeys, you are storing it -- you are storing that credential, that element for you to log in somewhere. And so you have to think about more than just the hardware because the phone is also a hardware. The question becomes what happens when you get a new phone? What is your process? What is your backup strategy? What is your recovery strategy? Do you buy 3 phones to back each other up? I mean some people can. But that's not a good expectation if you want to solve this at global scale. So I think the way that we think about the technology isn't so much about YubiKeys or phone, and I've described this a bit earlier, you kind of need both. Because anything with one is a problem. Because if you lost it, you broke it, you upgrade it and doesn't work anymore, it's a huge problem. What we bring to the table is a consistent experience using a YubiKey, right? Because Apple would have one way, Google will have another way, Microsoft has another way. So using a YubiKey creates a consistent experience, but also is a consistent security model. And I think testament to some of the companies that have described it.
I can even give you user examples, if you want, how it's benefited us, right? So in T-Mobile, I'll give you 2. Our retail organization, as I said earlier, uses iPads. So, it's our primary selling methodology. They're out in the floor, they're talking to customers face-to-face. It looks very poor if the customer is there and all of a sudden, the employees is pulling out their phone and trying to interact with that iPad. It may look like they're taking a picture, sensitive information or something that seems unrealistic or something they shouldn't really be doing there. Having a key that's meant for that purpose takes away that whole conversation. It actually looks more secure to the customer. It makes everybody feel a little easier about the whole situation. Another piece would be call centers. We handle customer data in the call centers they're global or as well as United States based. In those organizations, don't allow cell phones on the Salesforce for them just to make sure they can't have a way to take data out and make it unsafe for the customer. So we have to have a key-based solution for them to be able to complete those log-ins where a passkey that's on a phone is just not viable.
And just from my experience also for an enterprise deployment, software keys or sinkable keys, you have to look at that key, that private material that usually sits on a hardware-bound device is now going to be living somewhere within an ecosystem of either Apple, Google or Microsoft or IDP provider, whereas if you have a hardware bound device passkey, then that private key is stored locally on a device similar to the YubiKey itself. So sinkable, software, passkey versus hardware, you actually know where the key material is, that is the root of the trust of that interchange.
We have a question in the room.
A question for Jerrod, and from a customer perspective. How many customers get away with kind of a standard FIDO2 key? And how many customers leverage like particular proprietary feature on top of FIDO or some embedded software aspect to solve for an enterprise solution? Not talking about the company with 10 customers or 10 employees.
I can say from T-Mobile's experience, we did not go with anything customized. We are using an out of box, not even the highest range 5 Series keys, and it works for the majority of our workforce. Certain use cases, we do have different keys that we use in areas depending on the form factor needed or other options that might be used for that user. But I will say from an enterprise perspective, we deployed a standard NFC USB-C key and it has worked for the majority of our use cases.
For me, I just had with the example of YubiKey 4, we did smartcard authentication. So like the YubiKey 5 has multiple protocols that could be deployed, FIDO, smartcard and so FIDO is the easier option of deployment across a wide broad use case. And so YubiKey 5s, for the most part are for our implementation were FIDO-based that map back up to either an IDP that we had across our workforce. So smartcard authentication is still available for YubiKey 5. We just didn't deploy it.
And just to give some color. So we talked a lot about FIDO on the YubiKey, but the YubiKey also supports other authentication protocols. And there was definitely a time many years ago where FIDO was not so mature. So companies had to use other technologies on the YubiKey to log in. But we've always provided the next-generation authentication protocol. And a lot of our customers, when they started the journey with us, evolved with that. So when the FIDO technology became more mature with the systems that they use, applications they use, they started to migrate, which is really a fantastic way to look at. Don't -- you don't have to -- the keyword for enterprise, you don't have to rip and replace, right? Because it's a very expensive process to just change all the systems to work because I need to do with FIDO. And so companies can take this journey over a period of time, as Joe talked about, as they upgrades systems, it's the same YubiKey that support many different systems over a period of many years. So it really creates this great partnership of them working with us, changing the technology stack, but the user experience really remaining consistent and really a great experience.
And the adoption has been easier to a fee with FIDO keys, whereas smartcard authentication, you typically have PKI infrastructure, public key infrastructure, that has to be maintained within the environment for any organization, enterprise that maintains it. And so by moving towards FIDO and the latest generation of YubiKey 5s, you lessen the burden on current infrastructure shift to maintain and deploy with the PKI infrastructures.
We had a question here in the front. Do you want to take that?
Ramil Koria, Danske Bank. I'll show my complete subpar understanding of the business here by asking you about sort of the app ecosystem surrounding the YubiKey. How much of that is sort of bilateral in a sense? And how much stems from you operating within the bounds of the various protocols that you do have? And then a follow-up to that to the customers on stage, you said that it covers the majority of your use cases. How important is it that it extends the entirety of the use cases? Like what are the second standard deviation use cases? How important are they to be covered here?
Yes, I could start off with just the legacy systems like mainframes, right? z/OS, IBM mainframes, things that have not evolved along with the modern authentication flows for passwordless, YubiKey fits directly into those. There's modules specifically designed to have 2-factor authentication into legacy systems with YubiKeys, fully supported.
Very good. We have time for one last question, and I'll take it to -- sorry. Do you want to take it from room first?
Yes, please. Thank you.
To you, gentlemen, do you feel like you got a lot of security for what you paid? Do you pay just right or a little too much? Because based on your customer cases, you have -- it sounds like you get a lot of value. So how do you think of all these projects in relation to the costs?
Yes. I can take that. I think the cost of not being in the news and not having a breach and what it means to our brand has far surpassed anything that we paid for our keys and our deployments that go along with that. I mean, looking at it, there is a cost involved to it, and it will be for any business that goes into this. But the peace of mind that we get out of it and what that has meant to us has paid for itself leaps and bounds over.
If I could speak from a CISO perspective, right, running security programs in general. You tackle the biggest problem being the identity problem. So now you have all the other problems in the security space to deal with. So at that point, you've already tackled a big elephant in the room by identity with a golden standard like YubiKeys to have your team now focused on other threats that are in the ecosystem.
And then maybe just a quick follow-up. I don't know if this is to Mattias or to Jerrod, but how often do you think that either T-Mobile or Bank of New York should replace these keys to keep this high security posture?
We'll cover a little bit of that in terms of the evolving landscape for what we call cryptography. I think a testament to the design of our device and the standards we create. Well, we're looking at it from 2 angles. The first angle is that if you want to use the YubiKey with a system that hasn't changed, you should have the right to use the YubiKey. Like that shouldn't change it. We can't break people's way of working when it works, right? But the other angle as well is that there are things changing around the standards. And what we mean, Albert is going to cover a little bit of that is that there's a whole new cast of technology advancement, just like AI. In the world of security, there's this word call post-quantum cryptography that changes the dynamics of how you need to create protections and products. So independent of like Yubico's leadership, and things around completely in cyber, cyber has a lot of technicalities when that whole evolution change as a market, Yubico needs to be #1 in terms of leading that change. So as all our customer says, you're only as good as the next big threat coming to the industry. And rest assured, attackers are not going to slow down. So we at Yubico look for those signs of change and shifts in technologies, AI included, to make sure that we can protect our customers.
If I can add a little bit more, less technical color to it. One of the things driving why we think YubiKey as a Service and the service and subscription model that we offer is superior to both parties is that, that really forms that partnership. We work with the customers on what's most important to them, what they're seeing in the threat landscape and make sure that we're the partner there to protect them, whether it's new threats or new regulation coming up.
Even from an experience for me, going from YubiKey 4 to YubiKey 5, right, you had a technical evolution and innovation with YubiKey and Yubico's where they went and supported FIDO versus the U2F protocol, legacy protocol. So you still had U2F and you had smartcard authentication with YubiKey 4, and that was the golden standard and did the job at the time, and we get speed there. But what compelled to go to YubiKey 5 was the support and broad support for FIDO authentication going forward. So the evolution in the product line forces customers or it compels customers go that way.
So now maybe to the last question to our customers. Would you say that your employees typically use YubiKey to protect specific accounts? Or is it wider systems?
I can say this like there -- it's a 1:1 ratio, of course, every user has their account tied to that. And then they're accessing a wide range of customer accounts and things of that nature. So they're protecting everything at that point in time once you're logging into those systems. But that is the foundational piece. If it's them getting into their system and logging into their computer or their iPad and then getting into the tools with tenets, it's all done with our YubiKey.
And it's not only for the workforce, right? So you have the workforce supportability, but also now when it comes to authentication mechanisms for clients, right? There's opportunities to open up passkey support for client interactions and client portals to authenticate as well, using YubiKeys or using other passkeys within the ecosystem as well, call that Bring Your Own Passkey, right? At the end of the day, we're not supplying passkeys directly to clients as of today, but those are opportunities where now clients because they're using it in their personal lives, they have a YubiKey or they have other hardware-bound passkeys could easily bring to the platform and authenticate it to the platform with a passkey.
Thank you so much to all the speakers. This concludes the first part of our presentation, and now we'll take a short break for about 10 minutes. Thank you. [Break]
So welcome back. We're going to start the second part of our presentation. And now I'd like to welcome Albert Biketi. [indiscernible].
Thank you so much, and I'm really glad to be in front of you today to share a little bit about Yubico's technology journey and leadership. And I will try and make this as accessible as possible to a wide audience. So if I take some of the concepts down a little bit, but I will try to make it accessible to everyone. And what I'm going to try and cover is a couple of things. One is what it is that Yubico is building? And why we care so much about the way we build it, the way we are building it. And a little bit about our journey on innovation. I'll talk about what's currently being built and how it's built and why that matters. And at the end of the discussion, hopefully, it starts to be clear to everyone the foundation that we've laid for all the future innovations that we do for our customers because we are building our customer base because we want to give them even more innovation. And so we look at -- this as a very long-term journey that we're on. All right. So by focusing on what it is we're building and the -- why that hardware architecture is such a winning combination for high-assurance identity, hopefully, you'll be able to see that trajectory. And bear in mind, this is a long, long-term journey in terms of just understanding all the layers that build on top of each other. All right. So if you remember anything from this slide, it's that Yubico doesn't just follow standards. We contributed substantially in writing those standards. And then we built and shipped the authenticators, the hardware that makes these standards real and at scale. So when we look at the landscape and see everything that is changing, we have an eye to what that standardization looks like also into the future because Yubico's uniqueness comes from this combination of a very strong innovation ethos combined with the standardization that creates the potential for mass adoption. So we co-lead in FIDO, the fast identity online, in Open ID in WPC all these groups that defined collectively this massive move away from passwords to passwordless. And we're continuing to define that journey for continuous authentication. And so when you see something that says FIDO or WebAuthn, compliant, you're actually looking at something or dealing with something that has a little bit of what we made possible and we made it -- part of that invention possible. And this is important because this is all open standards, the folks who control a lot of how the web works. So think about Apple, Google, Microsoft, are all able to interoperate cleanly because of some of these standards that we set. But the way to think about it is Yubico is actually this hub that allows you to abstract away from those platforms as well and own your identity and own the route material for your authentication inside a key that you possess. And this will become important later because there's big trends in the world around decentralization, particularly here in Europe. And so you'd appreciate why it's important to actually own that piece of your identity. All right. I don't know if anybody here was born in May. Can I get a show of hands? May? Okay. We've got a couple of folks. So now if you're very interested in passwordless, the first Thursday of May used to be World Password Day. And for safety reasons, they changed that to World Passkey Day. And that's because this shift away from passwords is real, it's deep, and it has a lot of things around it that are fundamentally important. So if we just look at where we are today, if I was standing here 13, 14 years ago, I would be telling you there's going to be billions of people using passkeys. And except for the people who really truly believed and understood the path that Yubico was paving at the time, people would say, well, I don't know what you're talking about. But if there's going to be perspective that you're able to take about what it takes to build things that have massive, massive adoption, that's the journey, and that's the vision. It was very, very clear that far back that passwordless adoption was going to grow to become this big. So to give you an example, just from 2023 to 2024, the adoption of passkeys in online accounts doubled to 15 billion, it's probably going to grow at about that trend for a significant period of time. Now what's changing underneath all of this that gives us confidence that this is happening. One of them is password -- platform readiness. The second is top site adoption. So if I look at the top 100 sites today on the Internet, about 20% of them support passkeys. If you look at the top 250, about 12% of them supported, including Apple, Google, Microsoft, Amazon, PayPal, Tiktok, et cetera. So there's massive adoption going on and a lot of conversion happening. So this is a fundamental mega brand, and it's important to understand it in that kind of context. Then consumer awareness and use is also going up. And so just looking at some of the statistics that we look at, something like about 40% in 2022 had awareness. It's now doubled to about 60%, and that trend continues. And we're also seeing the data that we see this in the proof of behavioral changes and other things that support it. So the conclusion, I hope you all draw is that this is very well supported in user behavior, and it's not hard to intuit why. It's because it's easier and it's safer. And those 2 things in combination are magical for security because every time you build security that is an obstacle to getting to what it is you want to do on the other side, people find lots of ways to bypass it and it's magic for the hackers. So making security easier to adopt is one of the fundamental roles of the passwordless movement, and it's been something that has been very, very successful. All right. Jerrod talked a little bit about this earlier. And the power of the developer ecosystem that you've been able to build around FIDO, and actually goes to a question that was addressed earlier, which is how much of this is one-to-one versus how much of this is because of the standard. So if you're building with FIDO and FIDO compatibility, you're able to tap into a massive ecosystem. And so this is kind of the logical approach. And so there's going to be always support for a lot of legacy complicated things in the technology. But the fundamental goal here is to make security easy and widely adopted in ways that you have a challenged response that gives you a high assurance of secure authentication without phishing. And so U2F was the web-scale protocol that actually led a single hardware key be used across hundreds of relying parties. And relying parties, you can think of them as the folks who have a website that is going to be the real website that you don't want a phishing attack to impersonate. And so this relationship between relying parties and the relying party infrastructure and the YubiKey is a fundamental one. But one of the things that start a neat innovation about it is you're able to have this key that can connect with all these relying parties, and none of them have to know anything else about any other other place you authenticate. And this was a really key piece of innovation about the way we did this. When you combine this with a very simple API for developers write to, that's what turns this into a key that unlocks so many different services. So again, really important to understand that this mega trend and massive multibillion user adoption is inevitable, and it is driven by foundations that are extremely strong and well supported, right? Then this is something Jerrod showed also a little bit earlier that I'd like to emphasize. I hope you can still hear me clearly. Okay, good because the sound changed. But what this slide shows is an independent assessment by Gartner that shows where on the continuum from very, very low reliability from a security perspective, to very, very high. And I mean, just go back 3, 4, 5 years, for a lot of things. The password is so so familiar that when we show this slide, people are surprised just how low it ranks in terms of giving people high assurance of security. What this slide should make people feel is the urgency to get away and move as high as possible. But that journey is not linear and it's not easy, and there are a lot of things that Yubico is doing to make that journey and that transition easier. When Brian and Joe stood up here and explained to you the journey, there are many organizations where over time, we found the missionaries who are interested in making this journey work. What the missionaries do is they open it up to more people in the enterprise. And our job really and what I'll show you is how we take that and convert it into a much more scalable service to help people through. And that combines both the physical and the logical delivery of that value. But what does it mean to be at the very high end of this? It means you either have a FIDO2 security key or that X.509 hardware token is basically the equivalent of like, for example, what's used in the U.S. federal government around kind of PKI-based credentials that are strongly linked to a physical device that will be called [indiscernible] in the federal government in the United States. But really, YubiKey is basically are able to give you this across a variety of environments. And what we know is that in very, very high assurance and basically, in any use case where you really, really care that you're going to be the right person doing the right thing that YubiKeys are always going to be one of the solutions that is preferred for giving you that high assurance of indication. All right. I'm going to take you through the insights of the YubiKey for a bit. But as I do that, I just want you to understand this magical device on how to think about it. So this is a small device. I have one right here on my key chain. The framing that I'd like you to have as you think about a YubiKey is that, this is a piece of critical infrastructure. I say that again. It's a piece of critical infrastructure. Why do I say that? It's a piece of critical infrastructure because we are deployed in places where our customers are dealing with nation-state adversaries on a daily basis. In other words, somebody is trying to make sure that nothing works. And this key sometimes sits in between that and the provision of normal services, it might be energy, it might be some other reliable thing that you need. But even in high conflict zones where people need cyber defense as part of defense, these keys are proving to be part of that high critical infrastructure. So the reason why that's important is because we built them to behave like infrastructure. So if you look at the inside of the YubiKey, it has this chip -- single chip design and it's designed to be extremely resilient with a secure element that actually meets extremely high valuation. Our supply chain is all based in Western countries with a supply chain that is very carefully selected with very secure manufacturing. We do write our own firmware. So everything on the YubiKey in terms of the firmware, [ at the station chain ] is written by our internal engineering team. It's tested extremely well. And -- you recall mission that it has a touch sensor that makes sure that you can't impersonate touching it. It needs to be touched by a human in order for that authentication event to be complete. It has a whole host of certifications with it. It's built with a unique blend glass and plastic around it so that it's tamper evident. And it's actually sealed and has no moving parts of batteries. So it doesn't actually need to have a power source built in it. It generates power from what it's connected to either over wireless or over a USB connection in order to work. And that's fundamentally important because these things actually survive wash, rinse, dry cycles in dishwashers and washing machines and people use them for years. They're highly, highly reliable devices. And we have this variety of form factors. I just mentioned the one right at the end, it's called the Nano, and this is a typical YubiKey deployment that you'd find attached to computers. And so it basically stays constantly plugged in. And every time you have an authentication event, you just touch it. Once I plug one in -- I worked at Google before I joined Yubico, it's always plugged, you just touch it. And that's part of the authentication chain. Now we have our manufacturing and -- secure manufacturing here in Sweden, in actually Norland and Småland, and this is -- I've been to the factories, a couple of different factories and kind of had a good look at what the capabilities look like. I'm going to play a short video. It's about a minute long for you to get a sense for what that manufacturing process looks like. [Presentation]
Right. So that just gives you a breakdown of why we build, what we've built and why we care about it so much. We think about -- our mission every day is providing critical infrastructure because when people take over credentials, bad things can happen. Now in the spirit of talking about big things that change in the world. I'll shift and talk a little bit about what it means to go from classical to quantum safe computing. So this can be a very dense and complicated topic. So I was trying to think about a way to explain it that everybody understands. Today, we live in a world of classical computing. In classical computing, you have the concept of bits and bytes, a 1 and 0. In the quantum sense, you have this world where you have a super position where a bit or an object can't be either 0 or 1 simultaneously. And that creates enormous power from a computing perspective but it comes with a lot of problems. So the best mathematical explanation I can give for why classical encryption algorithms break, it's because of a time architecture problem. So the way classical encryption works involves factoring very, very large numbers and figuring out exactly what the solution is in them. It just happens to be something called a quantum Fourier transform that can take even an extremely large number and figure out the mathematical pattern around exactly when you peaks in certain ways that, that number of patent forms. And so this makes the entire foundation of encryption we depend on vulnerable to basically breaking and being replaced by capabilities that quantum computers can do. And so we had to think about a way to actually create new encryption algorithms to replace this. And almost everything we know today in encryption will have to go through this transition to become quantum safe. And so there's current attacks that you hear about, like gather all the inflation now, store it somewhere and then decrypt it later. And it's just a -- it's kind of -- it's going to be a big journey for people to go around in the next several years, this term called Q-Day, which kind of talks about what that looks like. And we're not waiting around for that. We are solving that in terms of what an authenticator needs to look like and operate in this post-quantum world. And so actually, the leader of the team that built that post-quantum YubiKey is here. I don't know if Alessio is here. Just wave, everybody can see him. Yes, there he is. So I'm incredibly proud about the fact that a month ago at the FIDO Authenticate conference, we showed what we are doing in this area. And you're just going to see a short video, but I'll explain something about the -- what this technology does in order to kind of stay ahead of this quantum resistance. You basically have algorithms called module lattice algorithms that make it incredibly hard for quantum computers to break. And in the break or a follow-up, I can kind of give you a simple explanation for how they work. But you can think about it as making it impossible to guess how many things you could buy in a grocery store, that has like 1,000 dimensions. Like that's the simplest explanation I can give. But this is a big deal because all of computing is going to change because of it, and Yubico is at the forefront of making this safer in terms of authentication. So here he goes. [Presentation]
So earlier, 2 of our esteemed customers shared with you what this journey looks like. I'll just touch on 2 parts of this journey, and it's the user enrollment and delivery. And think about that as the logical and physical delivery. It's very, very important that the right YubiKey arrive in the right customer's hands. And creating this life cycle is actually pretty difficult for a superhero or a missionary inside an enterprise because the typical person that you'll find will say, well, I'm running an identity and access management program, I want to move to passwordless. I have 5,000 employees in 33 locations. Well, am I going to attach this to the rollout of phones? Like what am I going to attach it to? So what YubiKey as a service is we created basically the capability to run this all in a way that feels seamless. But you should think about the fact that we're doing physical analogical delivery as the first step in building a foundation for what comes next. And so what YubiKey-as a Service then looks like is all of these capabilities, being able to deliver value over multiple years, you can have provisioning for loss of keys and replacements of keys, you have flexibility of form factors that you can procure. You have faster deployment. We work with you to understand exactly the challenges of what your deployment looks like. We'll have a look to see that you're actually truly phishing resistant because there's many places that you can implement this that end up not being -- you can leave open doors and you can lock one door with YubiKey and leave other places open. And -- so we want to help people do that so that they truly achieve compliance. And so this YubiKey as a Service serves as the foundation for us to be able to go out and serve a lot of our customers, and I'll let you watch a short video of what looks like. [Presentation]
So we do this over 100 countries, but that's like the physical side. What this diagram shows and I promise this is the most complicated thing I'm going to show is, how there is an interaction between the customer environment and the Yubico environment to either deliver a remotely preregistered key, so that's one touch, it works or a physically pre-enrolled key where the programming is done in the factory. So when the key arrives and the key is for Mattias Danielsson, it is the correct key and it works just for him. So being able to do that and deliver that reliably sets us up with an incredible foundation for what we're going to do next. So today, we are penetrated in about 30% of the Global 2000, about 5,000 enterprise customers and continue to grow. But all of this actually sets us up because this is a user base that is increasingly moving to subscription because they see the value of what we're doing and they want an ongoing relationship with us. They want to see that innovation come through. But what this then sets us up to do is once we start to eliminate these risks that our customers are facing and reduce that deployment friction and provide this turnkey solution, it ends up being the foundation for something really magical for our subscribing customers because we can come back and offer them what the future holds, because passkeys are just the foundation. Passwordless is just the foundation for future innovation that we're going to show. And so our customers are basically walking that journey with us. So in order to explain how the magic works and how the financial model works around what we're doing, I'm happy to have Snejana, our CFO, come.
Yes. Definitely, Albert deserves a lot of applause. Hi. Great to be here. So let me try to give you some of the basics of how the business models actually works in our financials. But before that, I would actually like first to start with how we have developed since we went public financially. So taking a little bit of a longer-term perspective since 2022. And then we deep dive into the business models overview. So we went public, not that a long time ago, and we've had some fair challenges, like in the Q3 now that we reported last week. But if we take a little bit of a longer term, we have seen actually quite good long-term growth, both in order bookings and net sales. We do face some volatility quarter-over-quarter in our bookings, which is primarily driven by the timing of closing large orders. As Carl said, some of these large orders might take years to close from the start of the opportunity until we actually close it. But we do have a very nicely accelerating YubiKey as a Service, both bookings and annual recurring revenue, which I will zoom in further. We have a very stable gross profit of about 80% over time. We see our operational expenses are growing with -- as we are growing. We expect them to kind of scale going forward. And our EBIT has really improved since 2022. We are challenged as we reported by a little bit of lower net sales growth in the latest quarters. Still, we are generating positive cash flow since -- in the last 3 years, and it's been going very well. So just, again, to take a bit longer term, bookings are growing with 15% CAGR on average since 2022. What we see is that really the YaaS bookings, the YubiKey as a Service is growing very -- in a very accelerated way with 27% CAGR, but we have a bit of volatility quarter-over-quarter in the order bookings. Why is that? If we look into our -- actually, the deal size breakdown, and I'll pause a little bit on that. You see that we have the large orders that are above SEK 3 million, they take longer time to close, there will be volatility quarter-over-quarter, whether we actually close -- some of these big orders or they kind of go into the next quarter. However, our small-sized deals or small, small, there kind of the majority of our deals being under the SEK 1 million, they are fairly stable. They grow very nicely over time. So it's the volatility quarter-over-quarter is very much driven by the large orders. If we look into the long term for the net sales growth, it's also growing with 14% CAGR. And again, here, we see a very, very good acceleration in the YubiKey as a Service sales. It is growing with 33% CAGR since 2022, and it now represents 16% of total net sales. And to remind, our long-term net sales target our growth target is 25% over the next 5 years. Our gross profit margin is very stable. It's about 80% over time. Again, going back to what Albert showed, we have long-term standing partners and vendors. We work very closely with them. They are in Europe and Sweden, and it's been a stable gross profit over the last -- over the quarters. There is one note -- one thing to note is that since our partners are primarily in Europe, our vendors are primarily in Europe and Sweden, while the majority of our revenue is in USD, we do have a bit of currently negative currency impact. And when we look into the OpEx or the operational expenses, the majority of our operational expense is actually the cost of our teams. And in 2024, when we had a very successful sales year, we see that [indiscernible] of the operational expenses are scaling. We do expect this scaling to continue forward as we grow going forward. One thing to note as well is that we have 2/3 of our employees in U.S. -- in the U.S. So currently, as the SEK is strengthening or has strengthened versus 2024. We do have some positive impact on the cost. So if we compare year-on-year, the cost, you could see that that some of our employee cost is decreasing, but that's not because we are decreasing teams. It's more of the currency impact. And with that, basically to recap, the EBIT has improved really from when -- 2022 from minus 3%. Now we have reached some quarters of 18%, 19%. Currently, it is the -- the LTM is 14%. It's really -- EBIT is impacted by our net sales number because gross profit is very stable. Our operational expenses are also very stable. We expect them to, again, scale forward looking forward as we grow further in our net sales, which will drive, of course, EBIT going up. And lastly, just to kind of pause on the cash flow. We have generated positive cash flow since 2022 and really improve 2023 and onwards. If we look into our cash flow from operating activities, it's as well very, very positive. We have had some -- we have had outlays or negative change in inventory. I just want to remind, though, why that is. In 2022, we had a capacity constraint of one of the major components of the secure element that, again, we showed in the previous videos. Then we had only 11% of inventory of the sales for the year. And this was very, very critical moment for us because it basically was a matter of business continuity and whether we would be able to deliver keys to our customers. So at that time, we have actually secured capacity with our vendors for the next 3 years. And we are aiming to maintain inventory of about 12 to 15 months of sales. In Q3, as we have also discussed in last week, we have received the last shipment of this capacity. We do have a little bit of higher inventory as of today. But going forward, we are having our secured vendors or our vendors that we work with. So we will see some movement there. But still, our cash flow, basically net cash flow or both cash flow from operating activities and cash flow from net cash flow is very positive. So that's on our kind of long-term financial performance. So let's now deep dive into the business models that we have. We have 2 business models: the perpetual business model and the YubiKey as-a-Service business model. And these 2 business models differ in how we provide the product and how we provide the service but also how we recognize the revenue and how our financials work in these 2 business models. The perpetual model is basically the customer orders case. And more or less, they take care of the entire deployment with very limited support from our side. In the YubiKey as a Service model, Carl talked about it. Albert talked about it, but it's basically, we provide -- we are the technical and the solution partner to the customer in this model. So the perpetual model was the original model that YubiKey -- or Yubico launched with in 2007. In 2020, we launched the YubiKey as a Service model. And this was really driven by customer demand for having good support, technical support, service and basically be with the customer throughout the journey. So how does it work? Just illustrative for example. Perpetual model is very straightforward. We get an order, we report the order value as we get it. Typically, we are able to ship the keys more or less within a very short time frame. We recognize the cost. We recognize the gross profit. Typically, our payment terms are within 30 days, so we collect the cash. So from order to cash, it's a very straightforward, order, revenue, gross profit, cash. Of course, this is the illustrative and kind of the ideal example. Real life is a little bit more tricky. There are a lot of factors that impact when we recognize the revenue. When do you see the drop-down from order booking into revenue. For example, timing of the order. If the order comes on 30th, we don't have time to ship it on the 30th, so we will report the order booking in the quarterly report, but the revenue will come in the next quarter. The deal size, some of our deals that are -- especially the ones that are above $1 million, it involves a lot of keys to be shipped. It might involve a lot of addresses to be reached in a lot of countries. So the larger the order typically means also a little bit more complex logistics. And since you recognize the revenue when we have actually delivered the key. So the timing of delivery will determine when we recognize the revenue. Again, typically smaller orders, we are able to ship in -- quite quickly. Large orders might have some complexities in terms of logistics. Not only that, some customers might want actually a phased approach and have different deployment choices. So again, kind of the time of delivery will determine our revenue recognition. But in general, as a concept, it's a very straightforward model. From order to cash, it's a linear sort of for drop down very -- in a very logical way. When it comes to the YubiKey as a Service model, again, very illustrative example, let's assume that we get a service order or an order of SEK 20 million or SEK 21 million for the simplicity of calculations. This is an order for 3 years. So this is a contract where 3 years, we will support our customer, both in terms of the deployment of the keys, but also in the entire lifetime of actually using the YubiKey during these 3 years. According to the IFRS, we recognized the revenue for this contract over the lifetime of the contract. So every year, SEK 7 million being recognized. Typically, we will deliver the keys during the first year and recognize the direct cost of these keys during the first year, which means that the gross profit then is a little bit lower, but then the second and the third year when the physical keys are already delivered or the majority of them, then the gross profit is much higher. From a cash collection point of view, from payment, typically, we -- the invoice is issued or is done 1 year in advance. So from a cash collection point of view, it follows more or less the revenue recognition. Again, this is a very sort of illustrative and straightforward example. There are other factors that impact the timing. For example, their ramp-ups, some clients or some customers will start with a pilot, will move into kind of next phase and third phase, and that will impact how we kind of plan or plan the revenue recognition. The contract duration typically is between 1 to 5 years. The majority is 3 years, but there are, of course, cases going up to 5 years. So that will impact how we recognize the revenue. From customer delivery choices point of view as well, this impacts how we recognize the financials, more so from a direct cost recognition rather than revenue. Typically, when we have activated users, even if the customer has different delivery choices, the revenue recognition starts from activating the users. So that are the fundamentals of the 2 business models. I would like to zoom in a little bit more into the subscription model of the YubiKey as a Service model and specifically on our annual recurring revenue. We have seen a very, very good growth of 23% in our annual recurring revenue since 2022. And I would like just to pause a little bit here and read what is our definition of annual recurring revenue. So this is the total contract value at the time of the reporting or the end of the reporting period of contracts that have started and then we divide them this total contract value by the remaining duration of the contract. By definition, this makes the -- our annual recurring revenue, actually a forward-looking metric, and forward-looking metrics for our next 12 months of subscription sales. So actually, if you put together a chart of our annual recurring revenue, as we have reported it every quarter since 2022, and our next 12-month subscription sales, you see almost 1:1 correlation. Of course, there is a small difference here and there in the quarters, primarily, it is from kind of changes that are coming into the ARR and some currency fluctuations. But since our base is quite large, basically, ARR is a forward-looking metric for our next 12 months of sales. And this might be very simple, but kind of just to set the scene, our growth drivers in the annual recurring revenue is both growth of existing customers, but also adding new customers to the model. And the growth of existing customers, you can break it down into renewals, expansions. So customers that have already a contract, but they expand their user base. And the negative part is if we don't manage to renew contract, which is churn. The net reaction rate would be -- or the net retention then would be the sum of these. So the renewals plus the expansions minus the churn and the rate would be the change period over period. The new growth is consisting of when we convert perpetual customers into subscription. And of course, of new customers or new orders. So if we look into our 23% growth of ARR, we started with SEK 207 million. We have retained SEK 23 million of ARR and the rest comes from new growth. There's one thing to kind of to just be aware of is that retained ARR is based on this space. Of course, within this new ARR, we retain this as well during -- in between the periods. And on the left-hand side, yes, our net retention rate has been consistently over the years, above 100%, which means that our customer stays with us and they renew and they extend. So to recap, let's compare back -- or let's go back to comparing the 2 business models and especially the pricing models. The perpetual is a onetime purchase. Typically, we have a price per key. We do have some additional or there could be services or like shipping services and things like that. But the model is a price per key. In the subscription model, it's price per user. We have services included in that, of course, could be -- it is everything from technical support, dedicated customer success manager, the enrollment suite for onboarding and all that. So how does the same scope of protected users would look like. If we take like, again, the same scope and I'm taking at least pricing, how would it look like? When we get an order booking for perpetual, we recognize it or we report it immediately. For subscription or for YaaS, we will report the total contract value. So it will be typically a little bit higher. But if we take it over the 3 years, a perpetual customer typically has repurchases, expanding or replacing keys, et cetera. So over the 3 years, typically, what we see is that a subscription value in the orders is about 20% higher than for the same scope of a perpetual customer. The net sales, they follow through, just the profile is different. In a perpetual, we would recognize the revenue immediately. More or less [ 1:1 ] as the order booking. For subscription, we will recognize the revenue over the contract term. So in this case, over the 3 years, it's 1/3 a year. From a direct cost COGS perspective, so the cost of the keys. Since in this example, I'm taking kind of the same scope, so same number of keys, the cost is the same, which means that as a percent of revenue since the pricing is higher in the YaaS, it's -- the cost is -- the direct COGS as a percent of revenue is lower and then the gross profit is respectively higher. So -- and that's not a -- it's not a coincidence of course. We provide more value, more services, and that's natural that kind of from a pricing perspective as well, the subscription model generates more revenue, more profit over time. Now we often get the question, how does -- how transition to more subscription would impact our financials? And especially like if we take it in a bit of a longer term, how does it relate to our financial target, et cetera. So I've shown that the YaaS model basically created by definition, higher revenue. And it does so because the solution that we are providing has like bigger value for the customer with all the technical support and all the services around it. If we continue to gradually increase our subscription share, which is the dark green scenario, we will see also that the sales growth will gradually -- will be kind of matching gradual growth. If we are a bit more aggressive with the subscription sales and we go more aggressively towards a higher share of subscriptions, we will see that revenue growth will be lagging somewhat as compared to the order booking growth. And that's natural because again, we recognize the revenue over the period of the contract. But both directions will -- as we grow kind of order bookings, we will get to the same place. It's just the time or the path will be somewhat different. So with that, I would like to reiterate that we are staying committed to our long-term financial targets, which are the 25% net sales growth and 20% EBIT margin and that we are primarily reinvesting our cash flow into growing our teams and investing in all the great things that my colleagues are describing. So thank you.
Thank you so much, Snejana. I'd like to welcome back Albert Biketi and Mattias on stage and open up for our second Q&A session. Welcome back. And again, maybe start with a question from the web, so the room can get a little warmer. Albert, first question is for you. Is hardware a long-term strategy or a temporary bridge until software reaches parity?
Hardware is absolutely a long-term strategy. And the reason it's a hardware -- it's a long-term strategy is because having a second factor for authentication that provides high assurance is fundamental. You can't -- if you have a phone as the primary device that you're interfacing with to the external web or a computer, high assurance means that, that phone can't touch itself. That phone can't prove that it is being controlled by a human. And so there's always going to be scenarios where you need a second factor. And second factor authentication is just fundamental. So yes, it is an absolute long term. It's not a bridge. There is a place for software-backed keys with -- there is a place for convenience for cloud sinkable keys. But if you want high assurance, you're always going to go with a strong second factor.
And if that's the case, why hasn't security key adoption reached mass scale yet?
It hasn't reached mass scale yet because the journey there requires big transitions for people. People have gone very, very used to passwords as a way to authenticate. And this is just -- it's just the way it is. Change is actually much more difficult than it sounds. And we're now at the pace of change where we have enough of a community that people really see the value of this and people can see the pioneers before them have done this. It's a magical place to be. In a lot of the conversations that I have with our customers, people who aren't yet ready to go on the journey are able to listen to other customers who've been on the journey and seen what that looks like, the mistakes, the challenges along the way. You put yourself in the position of a bank, for example, that has everybody on user name and password. Today, the scenario they face might be that they have a certain amount, percentage of revenue that is being lost to fraud, account takeovers and the like. And so they have to do this calculation where they look at that and they look at what the complexity of change might look like. And the fact that as they take people from passwords to passkeys, and passkeys to strong second factor authentication. The promise planned is to get to a place where there's 0 account takeovers. The middle ground is figuring out how to help people with transition. People don't have the same phones, they don't have this. They don't have that. So that's the journey. It's always a bit of a complex journey to get there. But the momentum, as I said earlier in my presentation is unstoppable. The foundation for this has been set. The standards are reliable, highly scalable. So I'm just confident it's a matter of time.
And a question for both you and Mattias. What is Yubico's R&D focus right now? And what will you focus on over the next 18 months?
In terms of focus, I think Albert will share some of that in the next session. So not to steal your thunder.
So I will share some of that in the next session. But I think the key takeaway that is a bridge from this session to that is we're establishing this base of subscription customers because there's more value to give them that the strong authenticator and the foundation that we've already built. And so that's the way we should be thinking about the value of the customer base we've built on value that we continue to give them. So our innovation focus on the additional value that we can bring when you start to solve the basic authentication problem.
And now to Snejana. Do your financial targets still hold if subscription adoption accelerates faster?
As I've shown, they should hold. It's just the path would be a bit different from a net sales growth perspective.
Will you work with pricing to incentivize the different models?
Our pricing is set so that kind of reflects the value that we provide to the customers already. So I think we are -- every customer case, of course, is different, and we take the value that we bring in creating the specific pricing for -- quote for our customer.
And then what about volatility? How do you see that it will persist as the mix changes? Perhaps a question for both you and Mattias.
And to Carl as well. Volatility in the large orders, in particular is -- it very much is driven by the time it takes for large organizations to take these decisions. I mean, large organizations don't take necessarily sort of very quickly decisions to invest $3-plus million.
So the volatility for those of you who had a chance to look real quickly at the chart that Snejana showed, 3 things really stand out there if you ask me. One is the big volatility of the large orders in between quarters. And then you can see a seasonal pattern if you look real closely seeing that Q4 is typically a really strong quarter historically. But those 2 aside, if you look at the orders sub-$1 million, there's a pretty consistent pattern there over time. And that's what makes me more reassured about the fact that we're on the right trajectory and that even if you see the short-term swings, we remain committed to the financial targets that we have. As Snejana and I discussed this before, we had this day, and we decided to only focus on the numbers that we have been made public since -- publicize -- since we went public, so in '22 onwards. If you take an even longer perspective, I've been around quite a long time. If we take for the last 5 or 7 years, the average annual growth rate has been about 40%. However, year-by-year, I think it's varied between minus 17% and plus 102%. Of course, there are no guarantees for the future, but I've seen this volatility long enough. And as long as I see that underlying trend of run rate business, nothing bad with that, but orders below $1 million that makes me confident in the long-term viability for sales growth.
Yes. I think one more point, as we are growing our subscription customer base, our order book will always be sort of -- we will have volatility, but our net sales will become more predictable because we have the annual recurring revenue. We have contracts. We work very diligently in renewals of our contracts. So I think as the share of subscriptions is increasing, our net sales will become more predictable as well.
Just our order intake, not...
Order intake.
We have a question in the room. So let's take that.
Yes. [indiscernible] question for Albert. So if you compare YubiKey to a competing vendor selling a plain vanilla FIDO2 key, do you have anything in the firmware or any features on top of FIDO that's important for enterprise customers?
Yes, a ton. So I could spend the next 7 minutes talking about it, but I'll keep it to 1. So one is -- the fact that we build our firmware and test it and have done that in a robust way over 6 generations is incredibly important. Many of our competitors are in the first or second generation of doing anything in this space and do not have the long history that we've had with extremely demanding enterprise customers, holding our feet to the fire. Second thing is we are focused on delivering a life cycle of value around our enterprise relationships. So we're not comparing a key to another key. You're comparing a key with a bundle of value that comes around that, including a very robust way of delivering both the physical key and the logical credentials around it so that, that whole process is phishing resistant. So for a lot of our customers, the choices that they make are about having a strategic partner that can walk this journey with them and having a strategic partner that can think through the implications of doing this classic to hybrid to post-quantum transition as well. So for us, we feel very comfortable that we are able to differentiate that value in the market.
And just a follow-up on that. If you have a proprietary feature like touch design, how decide if you want to add it to FIDO2 to make it easier to roll out or have it more proprietary secret sauce so you actually differentiate and build great interest to value over time?
So for us, there's always a trade-off between running with the standard and building extensions on top of it. And the way FIDO is constructed actually allows us the latitude to do both of those things. I think for us, our heart is always going to be in the place where we want to make digital identity safer for everyone. And so there's a lot of focus in innovating in a way that is consistent with the standard because that's what will get you billions of users. And so for us, that's always been the North Star for how it is we can co-create, but always stay ahead of the innovation curve in terms of the ability to bring those features to our enterprise customers and our consumer base because we do serve both.
We have another question in the front.
Erik Lindholm-Rojestal from SEB here. So you mentioned having a replacement rate of about 25% in the perpetual business. So just 2 questions about this. I mean, do you have any sense as to what share of revenues comes from sort of pure replacement business today? And then I also was wondering, we saw that smaller orders have grown over the last couple of years. I mean, do you think this is an effect of a sort of larger replacement business base to stand on? And does that create lower volatility?
Really good questions. When we talk about 25% replacement rate, that's excluding expansion, just to say kind of on an installed base, what would typically be the replacement. And that's primarily driven actually by employee attrition and frankly, people losing their keys. So that's a typical customer. I would say it ranges between 15% and 25%, but it's closer to 25% depending on the type of customers. Interesting story there, depending on the recovery methods, because customers typically see very different replacement rates. If it's very cumbersome to recover if you lost your YubiKey, people hang on to them more tightly than if it's easier to recover back, but that's a side note. I would agree that, that fact that we have a larger installed base drives more run rate business. And it's definitely part of that more predictability and that increasing number of smaller deals or run rate business.
Just a follow-up. Do you have any sense of what the installed base is today?
Yes. I mean, again, with the exception of...
5,000 Enterprise customers.
But with the exception of -- the caveat here is that -- and keep me real now, Albert, with the exception of those running OTP, a legacy authentication method on Yubi OTP, i.e., something that we host ourselves, we cannot track usage -- actual usage of the keys. So that's all based on estimates and working with customers. But we have shipped and delivered some 40 million keys, quite a big chunk of those over the last 5 years. So rule of thumb installed base being used currently, probably in the 20 million range.
Another question in the room?
Daniel Thorsson from ABG. A question to both Albert and Mattias. I guess that there are a fraction of the customer base that you only see adoption among the IT department still and not the full organizational rollout. So on the tech and product side, is it anything you are working on, on the future products to kind of accelerate the full organizational rollout? And also on the commercial side from Mattias, what can you do to see this pace accelerating? And also, what are the key triggers for organizations to go full rollout?
Yes. So I think that the ad age in security is that you're only as strong as your weakest link. And so we see sometimes a pattern where people say, well, I'm going to deploy this for my privileged users. We have big like powerful integrations with privileged access management, for example. But my perspective is that organizations just begin there gradually start to expand their scope because they start to understand that you can't just have a phishing-resistant implementation that fits only a small bill. And so there's a security argument that is compelling for a lot of enterprises to start somewhere, learn the lessons and then expand. And we're very optimistic that, that's something that will continue because it's just grounded in good security sense that you want to expand your phishing resistance until it covers 100% of your population.
So I'll add to Albert's comment on one of the key features of YubiKey as a Service, reducing the thresholds, making it less difficult to do a broader rollout, whether it's enrollment or such a simple thing as getting it into 50 different locations in 30 different countries. So there's a lot of groundwork being done there. What we do on the go-to-market side, I'll ask for a little patience, and we'll cover that in the next session and happy to follow up after that.
Yes. And then I have a financial question as well. When I looked at the first year numbers you gave for the subscription business model, you showed around SEK 7 million in sales and SEK 5 million in gross profit over the first year in this illustrative example. Does it mean that the gross margin in the first quarter? Some of us in the room are quite shortsighted here. Does it mean that, that could theoretically be 0% gross margin in the first quarter?
Theoretically, it could happen, yes, depending on when we ship the keys because we recognize the revenue, let's say, on a linear basis in the quarter, so 1/12 of the order. If you assume that we ship all the keys in the same quarter, it could happen. Yes.
But that's typically not the case...
That's typically not the case, kind of the worst case scenario.
And also worth noting is that we have -- quite a substantial part of our subscription customers have actually converted and they've already deployed perpetual keys. And despite that, they elect to go for our YubiKey as a Service.
Yes. The flip side is that in the next quarters, we don't have direct cost. So then it becomes quite a high gross profit.
Another question in the room.
Just brief on -- you showed us the NRR bridge on subscription revenues per end of 2024 until today, 10% up roughly speaking, ever since. But given this land and expand model that you just spoke about and the fact that you've gone from like privileged access users to a broader spectrum of users internally, could you say anything about like the flip side, what are you losing? What's the churn rate? Anything to add on the other side of that spectrum?
So the key message here is that the net retention rate is positive. We do have some churn, but it is lower than what we expand and renew. We are not right now kind of able or ready to share that. But in the bridge that I showed, in particular, by definition, the net retention is only on the base that we start with. So within -- in these 2, 3 years that I showed from 2022 to 2025, even in the new customers there, when we add them, then we expand and we retain, et cetera. So I think that's kind of the -- how you should look at it. Year-over-year, it's above 100% net retention rate.
Isn't that partly a function of the average contract being 3 years as well, so you haven't reached the tail end of a lot of the contracts signed ever since. So the 2022 cohort is more representative.
I wouldn't say so.
I don't quite make the bridge there. Maybe it's me not being able to calculate it fast enough. Of course, it's only 2022 ones that would typically have expired and where you have a renewal and then you can calculate net retention rates. You did the calculation here. I don't think that was the key factor.
No, I don't think so, if I understand your question correctly.
We'll take it offline.
We're running out of time a little bit. But just last question, would you consider changing the guidance framework?
The short-term guidance framework, you mean, or the person...
The overall, I guess. The simple answer is it's above my pay grade. But we -- I mean, one of the benefits of issuing long-term guidance, well, one of the constraints there is you shouldn't change the structure too often than the guidance becomes meaningless. We have done, however, since we went public, made one alteration based on feedback that we got. So we expressed the long-term growth target, 25% still, but we moved from order bookings to net sales because we wanted something that was more consumable for analysts and investors. And of course, that opens up for the question that Snejana got earlier. So if there's a faster transition to subscription, doesn't that have a negative impact on revenue growth in the short term. And definitely, that's correct, but it shouldn't have a major impact.
Not on the long term.
Very good. So now it's time for another break. We're going to take a 10-minute break and resume for the third and last session in 10 minutes. Thank you so much. [Break]
So welcome back once again, and we're going to initiate our third and final part of the presentation where we'll go through [Technical Difficulty].
Thank you, Alexandra. So I'll talk a little bit about our strategic direction when it comes to [Technical Difficulty] existing customers, the ones that have agreed to being public references for situations like this. And it doesn't include all the other companies that feel more comfortable with sharing it in a one-to-one setting that they're using our technology. And -- but even from this subset, you can see that some of the most attacked and security-conscious organizations in the world are trusting us. So we've built what I feel is a unique position in terms of credibility of being that combination of the highest level of security with good usability. This is another illustration that some of you has come across before. We are very focused and where we've seen success so far has been primarily working with the world's largest companies, largest companies and largest public organizations. And we've seen a steady inflow of new customers, landing new customers. So as Carl mentioned, there are certain markets that we don't serve, People's Republic of China being one of them. But in spite of that, we're already at a point where we have some 30% or 29% of the back in '24 of the Global 2000 companies as our customers. However, in the vast majority of cases, we're only deployed within a subset of their employees, starting with privileged access users or one of the initial use cases that Carl referred back to. What's comforting or very nice to see is that this -- we took -- before we introduced the YubiKey as a Service model or a subscription model, we try to keep a close eye on, okay, so what can we say about customer retention and repurchase rates. So this statistics is based on the sample of customers that we had before we introduced YubiKey as a Service. If you took a look at our 25 biggest customers back in 2019, these were perpetual customers only. What did their average annual repurchase rate look like. And consistently, when we've done these measurements, it's landed above 100% per year. Erik asked earlier about the typical renewal rates or repurchase rate on an installed base. Well, it's probably 15% to 25% on average. So if you get above 115 -- if you get to 115%, it's not that people lose their YubiKeys left and right, it's that land and expand motion where our customers are loyal in the sense that they come back to us despite that they haven't made any commitment to do so, but they come back to us as they deploy it to a larger user audience. We are able to be sticky with our customers. And finally, no secret, we started out with the high-tech companies because they were pretty much the only ones we could work with way back when because they had that pull to be able to use one way to authenticate across all of their systems before open standards were adopted, and they were also very happy to talk to us engineer to engineer before Carl and his team joined the company. So the market we're in, the current market that we serve is a subset of the identity access market. It's what called advanced authentication. And the best estimate that we've seen of that market is that currently is about $5.2 billion a year. And I think these are 2024 numbers actually, and that it's expected to grow with on average 14% per year. So we "only" have a 5% market share of that, give and take, about $250 million of sales, $5.2 billion being the total market. And as I think someone alluded to earlier, well, who are the biggest players in advanced authentication today? Well, it's still the smart card vendors that has the biggest chunk of the market, even if it's not a growing technology today. And this is the final piece of statistics that I'll show about the current position that we have. If you look 5 years back, and it actually holds true even today, we were optimistic about the relevance of our technology because we saw that 9 out of the 10 biggest tech companies, at that time, they were all American, were using our technology. So they who really understood the threat landscape out there, they were using YubiKeys to protect themselves. Take a snapshot today. We did so recently and have a look at, okay, what about the largest AI companies. This time, we looked at it define the largest as in terms of market size, but -- sorry, in market cap, but I think you can apply pretty much any definition. And what's interesting to note there is that 18 out of the 20 largest AI companies today rely on YubiKeys to protect their organizations. And if anyone is aware of the types of attacks which will be scalable in the brave new AI world, my guess would be that it's probably these organizations who are very much aware of the need for a hardware root of trust in a world where pretty much any type of attacks can scale massively because of AI. So this is the position that the go-to-market team, Carl's team with sales and the great marketing team we have at Yubico has put us in. We're recognized as a market leader and as a thought leader among those who really understand technology. How do we scale there? How do we scale to users that are perhaps not quite as tech advanced and how do we get the message out there to a broader audience? Well, the answer is, of course, by good execution on the go-to-market side, and we'll talk a little bit about some of the activities that we've got going in this space over the next couple of slides. So this is a summary, and I'll deep dive on these different initiatives that we'll talk about as we expand our reach and as we go deeper with existing customers. So it's pretty simple. It's about landing new customers and then expanding within those. So we don't end up in just a subset of the relevant users using YubiKeys to authenticate. And the 5 different motions that I'd like to talk about is increasing coverage, scaling through the reseller channel or I should say, reseller and disti channel, more traditional channel partners, leveraging the partner ecosystem. And then once we have our foot in the door, how can we be more efficient in expanding. And there are 2 motions I'd like to talk about there, driving adoption and renewal and expanding beyond workforce. So what do we mean by that? The footprint that we have. We started out pretty much in the U.S. We're now growing rapidly in Europe. And as you may have noticed on the slide that Jerrod shows, there's a lot of activity going on when it comes to up-leveling the security in Southeast Asia these days. To meet that demand and the fact that there's now regulation coming out in a lot of different Asian countries requiring strong MFA, we're -- as we announced in the Q3 report, we're shortly setting up an office in Singapore. It's not just a sales office. It's a fully operational office where we'll be able to do the final steps of programming. We can even invite customers in -- we'll even be able to invite customers in Singapore, much like we've done in Santa Clara and Stockholm, if you're really paranoid about security to program their own keys. So it's really setting up that functional model that we have running in Santa Clara and Stockholm to service the local market. And it's important for a number of reasons. One is that we want to, of course, be in touch with the customers, but it's also important for credibility. We are facing a situation today where European customers are concerned about moving all of their assets to a non-European company and vice versa in the U.S., and we're also seeing some of that in Asia. So it's important to -- for us to be local in the markets. I think this open up a huge opportunity for us because the need is definitely there and the market readiness is there. Broaden industry coverage. You still see a lot of our business coming from high-tech companies from financial services and public sector. The need is much broader than that. We'll be investing in making sure that our technology is out there and being tested and then easy to scale within a broader set of sections. I've highlighted this before, but one of the favorites there is really the health care industry, especially health care providers because they're sitting on so much sensitive data and we read about breaches pretty much every day. So we want to be part of putting that industry at the forefront of modern technology rather than at the forefront of hacker attacks. More to come there, but it's really important that we can get to a broader set of customers even within the geographies that we currently serve. Channel partners, distis and resellers. To this point, we've been very reliant on a one-to-one sales model where our account executives work directly with the largest companies and public organizations in the world to generate demand. We want to make sure that we enable channel better. We have a representative for that effort in the room, Stina, and I'm sure she'll be happy to talk to you later. But it's really about getting that global reach. We can't be local in all the different geographies where we serve customers. We need distis and reseller to do the work there. And we want to make sure that we get more channel-generated sales. We work with channel partners to a very large extent today when it comes to servicing all the existing customers, making sure that delivery happens, making sure that they get serviced locally in the right language. But when it comes to demand generation, there's lots that can be done. One of the important parts that we have there is that it is about training the trainers, i.e., training our channel partners so that they understand our technology, what benefits it brings compared to other technologies, what are the typical reservations that you need from customers and perhaps even more importantly, how do you make sure that you support the customer through successful implementation. That part is critical, not just for customer success, but also for the kind of channel partners that, to a large extent, have their business based on working in a service model with these end customers. It's not rocket science, but it's a long-term effort, building the credibility so that channel partners trust you, that you won't take the business that they've generated in a direct motion or switch to another channel partner. And I think we're building an important basis there that will serve us long term, seeing more channel-generated sales. I just -- even if consumer is not a big part of our business, especially for really security-conscious consumers, there's already some buying online our keys either from our store or Amazon presence. And we've also started working with consumer distribution partners. One of the first ones that we started working with was Best Buy, a large U.S. retailer. They saw a lot of demand actually on their homepage for our products. And it's primarily 2 types of users, cryptocurrency enthusiasts and password -- people that use password managers and want to protect their vault. That's what we see in every survey that we make out of these consumers. So it's not really something for everyone yet. We hope to get there. But for these 2 markets, that in itself is something which is interesting in generating demand. So together with Best Buy, we've now taken the step of moving into the brick-and-mortar stores with a new set of packaging and some simple instructions for how to use it. This is the new packaging reason for that. I think you may be even able to order something afterwards. We'll get back to that. So this is one illustration of how we can make our technology more accessible to a wider audience working through partners, even if this is not a big part of our business today. Finally, when it comes to the land motion, it actually works in expand too, but we're seeing it primarily as a land motion is strategic alliances. I'd highlight 2 strategic alliance types. One is global system integrators or GSIs, where we today have started working with a few of the leading GSIs on a more tactical basis, where we're essentially running large projects together with them. And we're hopeful or optimistic that we'll be able to announce a more formalized partnership with at least one of the largest GSIs shortly. And that will be important in getting into the Board conversations, executive level conversations. We always have our biggest friends and supporters in the basement, so to speak, the one who are really techy. But to up level our conversations within the organization, GSIs or global system integrators could play a really big part. On the technology alliances, one thing that I'll -- that we talked a little bit about as an example is the partnership that we have with Okta. It's not a coincidence that we run Okta internally because they have a great identity access management platform and a very nice integration with YubiKeys, they do the very same within their organization. So that's kind of eating your own dog food and then taking it out to the customers. So far, we've launched it for a very limited set of users, but it provides a really good user experience. So we're optimistic that with Okta and other technology partners, we can reach audiences that are already captured on those platforms. Turning over to expand, and this is an area where we perhaps haven't spent enough resources and attention in the past. One critical step that we made there was that as we introduced YubiKey as a Service, we said that, well, it's one thing to drop ship keys at someone's loading bay. It's a whole different thing to make sure that they have a successful implementation. We probably want to dedicate customer success managers to all of our largest YubiKey as a Service customers. Honestly, that shouldn't be limited to YubiKey as a Service. 80% of our business is still perpetual business, and we see a very high repurchase rate there. So we're now also introducing customer success managers for our largest perpetual accounts. What does that mean? Well, it means that we support the customer. We work with them in assessing their needs, provide manuals for how successful deployments can work that are relevant to them in their industries, in their geographies. We are with them as a plan, as they plan the rollout. Then we assist them as they deploy, whether it's with practical questions or user adoption or whether it's with technical questions, okay, this wasn't implemented right in that system. So we need to go through this process. We've seen this before, again, train the trainers within the customers. Then there's that ongoing engagement with the customer. And as we get more data points, we're better able to predict how we can best support our customers. And then we can be more proactive. Okay, you've protected these types of users. Do you know that a customer in a similar situation then went through these next steps? This is the experience that they've had, monitor their data and support them with relevant experience so that they can be more quick and more successful, as they deploy it to the wider organization. And then finally, making sure that we have the right incentives for people to continuously upsell within the organization, i.e., identifying new use cases and making sure that renewals or repurchases happen. This is a relatively new function within our company, but I'm really excited about this because this is, frankly, the fastest way to growing revenue for us. It's great, and we need to add new customers, but upselling and renewing on existing accounts is a much quicker way to revenue. Finally, and this is really tied to a lot of the things that Jerrod and Albert will talk about as we talk about the product road map. This is about extending security beyond use within a large enterprise or public organizations -- public organization. The -- and we've seen successful deployments in the past, but they have all been based on bespoke development, where we work with specific banks to protect a subset of their customers to make sure that they don't experience account takeovers or where we work with a large manufacturing company to make sure that their supply chain is protected. With some of the initiatives that we're now preparing within product, this will be then we don't need to reinvent the wheel every time. It can scale more quickly beyond the limits of the organization without us having to find out the right solution for every customer one by one. So I'm really excited about that. And then, of course, that opens up a whole new set of users for us without us being at the forefront in generating that demand because, as we mentioned, our biggest customers serve billions of users that need protection. So in short, what has formed this foundation for our success to date is primarily a direct sales motion to the largest companies and public organizations in the world. And of course, we need to continue doing that, and we need to excel at expanding within that type of customers. However, we're now investing in a number of initiatives when it comes to land and expand, which will permit us to reach to new customer segments. We'll be able to work more closely with the customer and therefore, deepen the relationship with them. And if we're smart about working with tech partners and GSI, we can leverage their vast sales resources and reach within other organizations. And with that, I'd like to hand over to Jerrod, who will talk about some of the things that we'll put in a position to scale better in the future.
Thank you. Thank you, Mattias. I wanted to step back a little bit to give everyone a view of the mission that we've been on. Stina is actually here, so kudos to her. The reason I joined Yubico and the reason I'm still here really relates to this mission. The mission was to make a safer place for everyone. And one of the things that we've done is to make secure login easy. We talked about the FIDO technology. We talked about passkeys. And if you look into the future, it's not just about the authentication, it is the user interacting with this digital world. When I first joined Yubico, I had the opportunity to train a group of journalists, and I was raving up all the great things they can do with the YubiKey, being so naive to know actually what they do, I start to emphasize on things that can protect the social accounts, the banks and the governments and they say, hold on, Jerrod, you don't understand if my digital identity is compromised, you will not see me tomorrow. So I take this mission very seriously. I take the way that we orchestrate our company to build the products to make an impact to the world. And I do believe that a lot of our customers believe in this as well, and they're with us in this journey. So what is happening today is that we've established a very good baseline, the foundation of authentication. But what's happening is the attackers are kind of going around authentication. And we hear this straight from our customers. They just said, I've lost all my authentication device, whether it's a phone, a laptop or a YubiKey, please let me in. And then people generally say, how do I know it's you? And there's so many ways that people create fake documents. Now with again, generative AI, it's so much easier to create fake documents, fake voice, fake pictures, you name it. And then whoever it is that helps this individual lets them back in. So who cares about passkeys? And so this is a huge problem. The users didn't have control of their digital identity. They may have control of the authentication, but they don't have control with this digital identity that they now put themselves out there. And this is -- we saw the headlines with attacks. We're starting to see the actual problems of digital identities now. So the attackers are kind of moving around and evolving their attacks. So there's this huge paradigm shift in digital identities. And it's actually happening -- epicenter of the change is actually happening in Europe. There's so many activities and so much regulations coming and standardization coming, how do we create national IDs and how do we create all these citizen IDs and all these great innovation is happening right in front of us. But I'll take a little step back. This also pertains to the growing market that the analysts believe is the next big thing. So if you look at authentication, you look at identity access management, but digital identity is a huge, huge, bigger type of opportunity in the market. And today is very fragmented. A lot of companies trying to solve this problem, no standardization, everybody doing their own thing, the proprietary thing again, right? But that's just a snapshot of 2024. We anticipate this space to expand and accelerate at rates of close to doubling their size in the next 5 years. And for the reasons I just told you why, it's a big problem. I want to take a step back to say what's the difference? Like you solved authentication, you're the best, and we'll continue to invest in that space. Absolutely, we will. A lot of people don't use strong authentication today. But it actually is in parallel where it needs to coexist in terms of digital identities because you issue a strong authentication to the digital identity that you've just proven. Here's the difference between the two. The authentication, you are trying to authenticate to that one service, right? The log on to your Google is Google. You set a password and you set up a vital security for Google and then you log into Google, the same entity. In digital identity, it is different, slightly different in terms of the way that things are orchestrated, but it's vastly different in the way that who gives you the digital identity and how you use it. The government gives you a passport, but you use the passport to enter to security and get to your airline. They are 2 different entities. So that complexity alone requires coordination at scale. And today, it's not coordinated at scale. That's the challenge. That's why you have so many companies trying to solve this problem. And no one has solved it at scale. I'll take a quick example and both Stina and Albert will give you a little bit of a glimpse of what we're actually trying to do. I'll set some baselines. So this is a national ID from Finland, physical card, smart, there is a chip in it. And today, you can create a digital version of that from a physical card, so today can be on an app, can be on a web application. And what you want to do is that you want to prove certain aspects of yourself to the service that you're trying to do in activity. Certain sites required to be a certain age to do something. And so in this case, in a digital identity form, you can actually only control and share what you want to share. I'm over 13, please let me use the site. And so you can present in a way that you selectively disclose, which is great. You want to control, right? You want to control. You don't want to say, now I'm over a certain age, you have my address, you know where I'm born, like you know all these other things that you shouldn't need to know for most of the time. And so when we look at the digital identity ecosystem, it becomes complicated because there's an issuer, like I said, like a government issues you a digital credential and then you have a verifier, which may not be the same person that issues it. And the holder is holding these really important attributes of themselves, their age, their birth date, sometimes even family members. There are things that you do professional credentials, you work for a company. And in that case, the user in our term for the digital ecosystem, we call this user holding a wallet and the wallet has different things that you hold in it. And so because of this complexity, there is a lot of players in the mix. In this new world, the standardization is much more complicated than just trying to standardize authentication like FIDO or passkeys. But if we get this right, you actually protect the user. So a quick example on how this actually works is some of the early works that we've done with our teams, with other organizations, including the organization that Stina found SIROS Foundation to give a glimpse of what is possible. So this is the same ID, but now we're trying to present this credential to a service to prove an age. So we want to show this site that this individual is over a certain age only, and we don't want to review anything else. We don't review the name. We don't review where they live, anything else. And in this case, the way to unlock that sharing is with the YubiKey. So without using the YubiKey, the user is not releasing anything about themselves to the service, which means the identity of the individual is locked to this hardware that you can control, and you can decide which service is allowed to see what attribute of yourself. This is not just a video. We actually have a working prototype, which we also actually showed at the same FIDO Authenticate conference that we showed our post-quantum cryptographic YubiKey. With that, I want to introduce back -- and bring back Albert back on stage to tell you a little bit about what Yubico is going to do with this great scenarios.
Thanks, Jerrod. I'll ask you all to wish me luck that my glasses don't fall down in the middle of this. So all right. So in explaining what this means, I think it's just important to go back to something that I said and a couple of folks have said, it's subtle, but it's really important. We have a very long-term perspective. And so there was a time long before I joined Yubico that somebody stood on the stage and said, passkeys are going to be adopted by billions of users. It's true today. And that same long-term perspective actually has been applied to lots of other things that we really need to think about as a society. And I'll talk a little bit about what this means in this context because it will then give you a sense for what we're investing in and why. And hopefully, that gets some people grounded. So what does it mean for AI to be in the mix? I mean 2, 3, 4 years ago, people are working on artificial intelligence for a long time. There was a long AI winter, and there's other companies that were really grinding up the mill because they knew that this was going to become something big and great, and this is the moment. But if you look at what identity means in the age of AI, it's actually a perilous question when computers are able to impersonate so well, it just opens up a lot of big questions. Without creating a lot of parade of horrors, I want to focus on the way we're thinking about it, as AI is actually a new supply chain input. What does that mean? It means you have labor. You now have this boundless intelligence that you can insert into lots of different things and you have to trust it, especially when AI is going to be acting on behalf of a human in terms of verifying something or authorizing something. You're going to need verifiable inputs at the heart of what it is that you're presenting in order for people to feel some trust that the telemetry that's coming from that or the software bill of materials that you're signing or all the other things that enterprises are now beginning to do with artificial intelligence can be trusted. You are going to need roots of trust that come back to humans. And fundamentally, that's going to be something that as systems start to work and act on our behalf, we have to have that trusted. So almost every device you have in your hand is going to be infused with intelligence and there will be times when you need to separate what that device is doing from the human who authorized it. And that's a key role that we will continue to play. And I want you to look at this chart because what this shows you is a 20-year journey from where we were with 99% of any kind of authentication coming from passwords to passkeys, which now have a multibillion user and multibillion account adoption trajectory that is very, very strong, built on open standards and foundations that give us this ability to have adoption at scale. So you ask them what does that journey look like? I mentioned earlier that some of the necessary innovation we have to have will require that this foundation of encryption we have has to be rebuilt on quantum safe capabilities. And so in the United States and around the world, there have been competitions and contests to establish the correct white box cryptography that will be allowed for post quantum cryptography. We have incorporated the algorithms that have been chosen by NIST as finalists. NIST is the National Institute of Standards and Technology. It plays a big role in determining which encryption technologies will be the correct foundations for what we do because all of these things have to be interoperable. So that's a very necessary bridge. And then I'll tie this back to what Jerrod just talked about, which is verified credentials, meaning something that you own that you tie to your identity that you might need to prove to somebody else. The interesting thing about verified credentials is that they are as powerful for what you allow them to do for you as what you can disallow, meaning you can actually create a privacy container and a security container around a piece of information and attribute about yourself and enforce that it may or may not be shared depending on what you, the owner of that identity decide. This is a big deal because this is a complete flip of the privacy model we've lived under for the last however many years. And what I'm really excited about is the fact that, again, Yubico and its founders have been visionary about thinking about what this future holds. And so I'm incredibly excited to have Stina, our Co-Founder, come up on stage and talk about what this means.
Thank you, Albert. Wow, one of the biggest challenge on the planet, every second, 3 fake identities are created on LinkedIn. Today, there are more fake identities and bots on the internet than real humans and we have a solution. Okay. So this is about 2.5 years ago, about the same time I stepped aside as the CEO for Yubico. We were approached by a research organization here in Europe, who invited us to be part of a very cool, bold vision that the European Union had set up. And you've heard Jerrod and Albert sort of talk about this in other terms, but it's actually a vision for EU. I think EU is -- for the first time, I think EU is much cooler than Silicon Valley. Yes, credentials, user information is transferred from your passport digital identity app to this identity wallet that is controlled by the user. You share whatever information is needed for the service that you want to share. And this is the coolest part. You can be verified, but anonymous, which means that you can share that you're a real person and not a bot. And do you understand what this means for the world's democracy and free speech and peace and human rights? It's a revolution. So of course, we want to be part of this. We did not only engage with the first research organization, we engaged with 2 others, Greece, Holland and Sweden. And we created an open source, open standard prototype research project that is actually the one that Jerrod shared. The challenge is it was sort of a shared ownership. It was a project -- an open source project on GitHub. There was no real leadership. It was just like, hey, we, as a group, want these things to happen. And did you know what we did? We actually solved the fundamental problems with universal digital identity. And I am absolutely sure that we are now building a new next-generation secure Internet on these pieces. So by routing it as a web-based application and not a centralized solution that's owned and controlled by an identity provider where you tie to a phone or a smart card, we have a solution that is web-based. You can share it, you can use computers, you can use phones, you can delegate to others. Families can have a shared computer. I mean there are families who may have an even a shared phone to access the system. And you can even delegate to a legal person. No one has solved this before us. It is the highest level of security because all the reasons we have talked about today. Passkeys, security keys and YubiKeys is the best. It's smarter and more secure than your Swedish hard bank ID or bank authentication tokens or name it. And because it's not a centralized service, and it doesn't collect data. And we delegated security to users. And these users do not just share everything about everything, but actually the only thing that they need to share. There is no oversharing. There's less data that will be hacked and it's the highest level of privacy. And because there was no ownership of this amazing project, I knew now it was time for me to step into a leadership position again. And I created the nonprofits as a partner to Yubico. I'm now the Executive Director and Founder of this little sister to Yubico. And we are on a good path into making this into a global standard. Here are things we started. We are the most tested, most interoperable of all the European Union digital identity wallet projects today. We won a German competition, an innovation competition that Germany put out and said, hey, innovators, pick giants, anyone, help us create the next-generation identity system for Germany. And our solution kicked out both Google and Samsung because we are cooler and more privacy preserving. And then after that, when Germany said, hey, we like this, Canada and France said, we also want to be part of this. And Canada is not even part of Europe, but they like Europe now a little more than a year ago. So now we're starting a pilot there. And this is a project we're doing with Sweden actually showing that you have legal ID wallets, and there may actually be some kind of press release out there where this business -- this idea of business ID wallets is coming where you can delegate -- for example, Mattias can delegate the authorization of signing documents to other members of the Yubico team. You can't do that with your phone, but you can do that with the YubiKey. Singapore also wanted to be part of Europe or at least its initiatives. So we're making a pilot between Sweden and Singapore. And this is the coolest part. There is this group of investigative journalists. We all were very touched when Jerrod named the importance of protecting free press and the people who protect us. If there is no free press, there is no security. So there's this group of investigative journalists, who are developing a new digital press pass for the Internet. And they said and asked us at SIROS Foundation if they can root that in this digital identity standard. And we've already started the first phase of that, sending them all YubiKeys. And then there is an international research organization and the list goes on. Every week, there's someone new, a new country, a new government agency, a new company that want part of this global initiative. And people have asked me, why couldn't Yubico lead this? Why did I have to create a nonprofit? And it is because this is -- this -- we now need to engage with governments and policymakers and nonprofits and have a neutral platform. Just like Ericsson, when they created GSM and wanted that to be a global standard, they couldn't -- it had to be the GSM consortium that sort of took the pieces of GSM and moved it forward. And of course, Ericsson had a very vital and important voice in the room. And that is sort of the relationship between the little sister SIROS Foundation with just a dozen people, I funded it with money that I was grateful to receive when Yubico went public. It's my way of giving back. And now we're also being encouraged to get funding from other resources. We partner with Yubico because Yubico is the established credible player, is the leading inventor behind passkeys, and it's actually a really good synergy between us. So we meet up every week, and we sort of conquer and divide where can SIROS be of use and where and what was Yubico need to do to make this into one global digital identity standard for all on our same mission, making the internet safer for everyone. Thank you.
This is exciting. And hopefully, you start to see a glimpse of something that we'll talk about more and more as elegant as this sounds, there is a lot of -- there's a saying in the United States, there's a lot of wood to chop. There's an incredible amount of cryptography and coordination and mad science that you have to get right for this to work really well. And so that's the job that our customers are going to trust us with. That's the job that we are going to work in a way that has been consistent with the way Yubico has always worked before, which is a pairing of standards and standards-based innovation together with excellence and building that foundation of trust. But I want you all to look at this slide and kind of recognize what these layers tell us. This is a very simplified diagram that shows what the -- kind of what the relationship looks like across the layers. But you can think about Yubico as being this root of trust, well established, global passkey adoption is a great foundation. In addition to that, we have this enormous base of thousands of enterprise customers, at least 1/3 of the Fortune -- of the Global 2000 that we're already working with that give us this amazing innovation factory to go back and think about what it means to have this new sense of identity start to go. We have this interoperability layer that starts to bring the right kind of open standards that you'll need in order to drive billion user adoption eventually. And then you've got the kind of engagement that you need at the user experience layer that's a sophisticated interplay of both the open standards and the root of trust. And we need to obviously have a way of making this measurable because if you're not making this measurable, you can't transmit the proofs that people need in order to trust the ecosystem. And so we're thinking about all these problems. I'm really, really excited about the investments that we are making here. And there'll be more to come over time. And just to give you a couple of examples of what this could look like. I'll tell you a little bit of a story here. Initially, we had an example that kind of lived in the health care field, but that's one of the places where the United States and Europe are highly, highly contrasted because in the United States, if you give a health care example, you're giving a private sector example. In Europe, when you give a health care example, you're mostly giving a public sector example. And so you wanted to give something that was a little bit more distinct. But I'll just give the -- I'll give one of the examples that we had, which is it does take a while for a doctor who works for one hospital system to sometimes just transfer to work in a different hospital system or to work in the same hospital system in a different jurisdiction in the United States. And if that takes 6 weeks, that's 6 weeks in which somebody can't make an appointment with, I don't know, a doctor who looks after people who have complications from diabetes and they have a leg that is suffering, and so they wait 6 weeks longer to get something. If you could have a system where you're verifying those credentials nearly instantaneously, that is real value add in a way that cascades into things that people feel viscerally. It's about how well you can get quicker because you get better care. But that's just one example that kind of links back to the medical side. But then there's this whole web of things that you can do all the way from how people do background checks effectively in a workforce, how people do loyalty programs, what it is that you can do to prove that you have certain qualifications in order to take on a task, how quickly you can onboard if you're a consultant working in one company and then being deployed to another. There's just so many things that you can do once trust becomes a programmable artifact that the sky is really the limit. And we're very, very confident that this is a race that we are going to run really hard at because the world needs this. So if you think about what I've talked about, there's a possibility of actually bringing identity back into the control of the user. So user-controlled identity with verified credentials, which are as powerful for what it is that they allow you to do as what they allow you to prevent from happening. So you start to have identity that travels with privacy attributes that work as a container that you control cryptographically with your YubiKey. And then secondly, you have all these great use cases that you can start to show to industry, starting with our 5,000 enterprise customers and growing beyond. And then third, if we do this the way we are, we are committed to doing this in a way that's really about open standards. So it means that the value of this actually increases with greater adoption. And then we're doing this with the context that has been set with widespread passkey adoption. So this is not a cold start problem where you're going to have to create the logic that then allows people to do this. You could never do this without first trying to solve authentication. What that tells you is that this company has an incredibly long-term vision about how the world will change for the better. We're committed to doing this in a way that's very much about open standards, and we're really excited about what the future holds. So with that, these are the 2 takeaways that I want you to have about what our innovation path looks like and why we're investing the way we are. What passkey adoption is doing is it's setting the foundation for digital identity that protects users beyond login. And I think we've painted that picture really clearly, and you're beginning to see how it comes together. And Yubico will sit at that decentralized root of trust for what this next generation is going to be. So that's, I think, what brings us to Q&A. So I'll call up Mattias, I think, to wrap.
I think we can welcome back all speakers from the last session, Jerrod, Mattias, Stina and Albert. So this concludes the third and final session, and this will be the third and final Q&A. So let me start with the first question. And the first question is for Mattias. Which factors do you believe are most crucial for Yubico's success? And how do you ensure the whole organization focuses on them?
Well, it comes in 2 different parts. Fundamentally, we need to stay ahead of not just competition, but also the hackers in terms of providing that secure hardware root of trust. So the work that Albert and his team is doing in both making sure that our core stays ahead of the game and then expanding to what our customers are looking to solve in terms of problems when it comes to digital identities are both critical for our success long term. If you look more short term, the quickest way to make sure that we meet our financial targets is about that expansion within the existing customer base. But that doesn't mean that we can let go of the land ambitions that we have and look at more ways to adding new customers and get more leverage in our sales model. So it's a combination of the two. And of course, if we don't have the leading product, well, it doesn't matter if we have the best go-to-market in the world. That's kind of a shortsighted approach.
And then to Albert and Jerrod, can you elaborate on the focus for digital identity? And do you view it as diluting focus?
So it doesn't dilute focus because it's actually building on the foundation that we have. And the customers that get the value out of the YubiKey today are the ones who are setting themselves up for that future. So we see this very much as what that evolution will need to be.
Yes, I'll just add to one practical scenario at a company. Albert talked a lot about delivery of YubiKeys and enabling them to be onboard really quickly. One of the key challenges today that customers have is the recovery. How do I know it's you before I give you the YubiKey? And just that statement alone, we have to solve the identity part of the equation. It's not just authentication. So in some ways, whatever we have envisioned for the future of Yubico, it's also solving a real problem that the customers have today, particularly as companies employ and have users everywhere globally and growing and not just employees, but their customers and their suppliers, how do I actually know that you should be getting YubiKey because I don't really know who you are. And we need to solve the problem to solve the bigger ecosystem challenges.
So following that, how do you see the revenue model for identity verification?
I'll take that one. This, to me, is one of the reasons why I'm so happy that we introduced the service and subscription model some time ago. For most applications, at least enterprise applications, the logical way to sell this service is in a subscription mode. Of course, we're going to have customers who would want to separate the two, and we're not going to stop that. But I think this is one of the accelerators that we're seeing for customers making sure that we have that long-term partnership and a commitment, which the YubiKey as a Service framework provides.
And to now both Stina and Mattias. Can you just elaborate a little on the collaboration between SIROS Foundation and Yubico? And is there a scenario where the solutions are competing with each other?
I think I made it fairly clear. SIROS is like Linux for online identities. And Yubico is the red hat that builds value-added commercial service on top of the same platform on top of the same code and Yubico will develop more advanced service. Well, we, at SIROS will continue to drive the open source project oversee it, ensure that it's certified, ensure that it goes to every country on the planet and ensure that we actually engage with the Linux Foundations of the world to put it into the central pieces of the internet. And for that, you need to be a nonprofit long-term sort of neutral player. We, at SIROS -- because I represent both. I am a major shareholder in Yubico. I own 10% of this company. I'm the co-founder and I mean the Board. So I -- of course, I have literally only 1 hat today, but I have 2 hats. My hats are to ensure that Yubico is successful and SIROS is successful. And we -- at SIROS, we realize that when all these governments want to come and try this open source platform, we set up a -- that we're going to launch shortly just a reference wallet platform where people like the test bed. And we say, hey, this is for free. If you want to do something more advanced, we will charge some very minimum just to not start losing too much money. It's basically that is sort of the revenue model.
And I only wear one hat, even though I'm not wearing it today. I'll add to Stina's description there by saying we're actually very happy to be working with one of the leaders, now SIROS, in this space because this is actually a center of expertise and knowledge, and we learn a lot about getting our heads around this interesting market and defining our product offering where we can make money in this emerging -- with this emerging technology.
Initially, I thought it would be mainly YubiKeys but there are more commercial services tied to the YubiKeys that Yubico can make.
And a question to Mattias. Can you talk more about the new office opening in Singapore? Why Singapore? And when will we see material revenue coming from that region?
So today, the APJ region represents about 10% of our revenue, but it's growing quite rapidly. And as we talked about earlier, it used to be that most of our revenue from that region actually came from American and European companies operating in the region. That's now changing. We're seeing locally generated demand. We have a sales team in place, and we're seeing a lot of activity on both the government side and on the private side, recognizing the need for strong MFA. So it's definitely a rapidly growing market. And as I mentioned, it is critical for us to be local as we do business. We literally have customers who wouldn't take delivery of the product unless they know that it's programmed in a location that they feel confident about. Even if those are really large and very security-conscious companies, having that local base is important. Why we chose Singapore is because it's a great place to do business. I'm not going to lie about that. It provides a very stable framework and a long-term perspective, and we're getting great support locally for our ambitions there. Fundamentally, it's driven by customer demand that we're seeing this hub as a natural place to expand our footprint in the region.
And a question for you, Albert. You talked a little bit about how Yubico is preparing for the era of quantum computing. When do you anticipate that quantum-resistant authentication will be required?
We think that for some use cases, quantum-resistant or quantum-safe authentication will be required as early as the end of the coming year. And we think that that's only going to grow. Where we are right now is in an intense testing phase with partners. And so we have really opened up at the authenticate conference an invitation to folks to work with us on that because these are not small projects. Essentially, what you have to do to get your organization ready for a quantum-safe transition involves doing a cryptography audit of every dependency that you might have in your environment and then going on from there. So from the date you start, you're starting off on a multiyear project. And a lot of enterprises, a lot of the CISOs and identity folks we speak to are beginning to kind of bring that into view or setting up post-quantum working groups. And so the time for the engagement is right now.
And what cadence of product releases is Yubico aiming for?
Is that in the post-quantum context?
Both.
We have kind of 2 cadences for our product releases. So the simplest answer I can give is our services are releasing monthly or something on a much more frequent cadence, and that will continue. And on the hardware where you have firmware trains, customers typically don't want to consume too much change. They want kind of stability around that because these keys are deployed for a long time. So the cadence is there a lot longer where we'll take some time, get something up and then kind of move from there. So those are the 2 cadences we have. And in order to support our subscription businesses and the services that we continue to offer that add value, we'll continue to intensify the release trains there accordingly.
Thank you. We have a question in the room.
Yes. Daniel from ABG. You showed that you had 9 out of 10 tech companies in 2020, 18 out of 20 AI companies today. Is that just because these companies in the forefront are much more aware of cybersecurity and they buy protections from many, many more providers and doesn't really say that much about your solutions against your head-to-head competitors? Or do you see better proof in the other sectors like health care, financials that you are more an exclusive provider?
No. Sorry, to -- as I understand the question, when we looked at those statistics, we also took a closer look. So what's the level of deployment that we have within those customers? And it turns out that for our broad set of customers, our average penetration rate, if you compare the number of keys deployed with a total number of employees is like in the 10% range. In this subset, AI companies, we find that more than half of them have rolled out YubiKeys to their entire workforce. They're at the bleeding edge of understanding the threat levels, and they're very tech savvy, of course. So I think that's an indication that they're a little ahead of the curve, but I think the rest will catch up before too long.
I think that a little comment to it. For a long time, we were perceived as a Silicon Valley company. We were in the heart of Silicon Valley, Google, Microsoft, Apple were our main partners. And these AI companies have thrived mainly from Silicon Valley and these tech giants are U.S. West Coast based. So it was -- we were never like the biggest cybersecurity on the planet, but we were the biggest strong authentication organization company in Silicon Valley.
Yes, I think that the color from Joe earlier, which is a lot of these AI companies have been using this technology for more than a decade. And that's the fact. And so when you -- it's not just the technology that they're buying. So I think an earlier question, why should they buy another device. People don't buy devices, they want to trust Yubico. That's a big difference.
One thing maybe also to add. I'll just refer back to the video we saw earlier. Cloudflare, for example, is a very classic example of one of the things that we see, which is somebody who used the technology and saw the difference that it made in one job then moves to a different job and says, I would like to sponsor this to get this rolled out everywhere. And so we also have that as something that's almost like a perpetual fountain of people who experience the product, see the value in it, taking the experience from one organization and going to another one and doing a company-wide rollout.
In the early days, we had someone from Google who went to Facebook. They deployed YubiKeys and then someone from Facebook went to Uber and they deployed YubiKeys and someone from Uber went to Salesforce and they deployed YubiKeys exactly what you pointed out.
Another question from the room.
Excellent. Erik from SEB here. So just a follow-up on the identity product to Stina and Mattias perhaps or all of you. Do you -- I mean -- just so I understand, do you foresee that this is something that governments will deploy and they would send out YubiKeys to the users?
It will be a combination. They will -- some will just deploy digital identity cards that are similar to the identity cards that you get today and that you can put on your phone, and it will transfer the information and you can also through a card reader transfer information to a computer. And then you will have YubiKey as an add-on for high security, high privacy, shared delegation, shared computers, phone restricted rooms, backup. I mean there are all these scenarios where the first card will not be enough. Then there may be -- and we have those conversations in service now in all countries to say, hey, could we replace that card and just have a YubiKey because it's more convenient. It works in all computers or phones, you put it on the key chain. I mean a card doesn't work with your computer unless you have a card reader and it's sort of a little -- so we don't know yet, to be very honest. But we know that there will be enough use cases. And as like we said, how big can this market of digital identity be? And let's say we get 10%. 10% of 5 billion Internet users is 500 million. And to date, we only sold 45 million keys. I'm not going to sort of commit to that number in X number of years, say, like in 2 years, we will be there, but it's sort of the opportunity that's growing because before we were -- Yubico was enterprise and some consumers, and now we can be part of national ID systems. And that is the big opportunity where we need -- SIROS and Yubico need to work hand-in-hand and driving that effort.
So it's definitely expanding the addressable market. We're not betting the farm on government sponsoring YubiKeys for everyone, but it's a nice idea. But it's more about making sure that we're part of that platform, which is being provided, which is being developed right now.
Put 500 million keys in the model then. But just a follow-up, if I may. I mean, you said there's a lot of wood to chop before this is fully deployed and functional. But if you were to give a rough time line, when does this become relevant for Yubico and a big driver for Yubico.
I think it's going to go fast -- much time sort of comparison. We took 10 years before starting with Google, getting Microsoft and Apple to adopt passkeys. This will go faster. I think in 5 years, we will have -- there will be hundreds of millions of citizens that use this kind of digital identity system. And how much of this share will Yubico get? That's up to us. We need to continue to innovate. We need to -- not only with the keys, but with the services surrounding the system, just like an Ericsson or the guys preventing -- when there's a standard for WiFi or USB or whatever, whatever standard that is created, the innovators needs to be on top of it because there is competition.
I believe it's the last Q&A session. So I'll just take the opportunity to first off, thank you all for the great presentation throughout the day. But I just wanted -- you mentioned that -- I don't want to run ahead of ourselves here, but you mentioned that there's several adjacent services that could be added by Yubico in the future in this initiative. Could you elaborate a little bit on what that could be?
I think Jerrod is better at...
Yes. So I gave a glimpse of it a little bit on that earlier. Albert obviously can share more, but if you think about the identity life cycle, there are things that you need to do to verify the identity of the user. This is just one example, right? It's not like the YubiKey can't do that and they can't -- so there are things that you can offer to help prove that the user is who they say they are. You can also think of a service where you are providing the user with the trust that they work for someone, right? We may not be a government, but we could provide a service for corporations. I think we talked a bit about the delegated scenario here, right? I delegate -- Mattias delegates to someone else to sign the paperwork, but what gives them the right to delegate and who is he's supposed to trust in the digital world. So we can offer such scenarios where professional credentials can be issued by Yubico and then they can take an action to then present it. So there's a lot of corporate scenarios, business scenarios, independent of citizen government scenarios. So that's really our focus to really find trusted customers in this journey. And the good news, like 5,000 of them. So I think that's the difference, which both actually Stina and Albert talked about, which are [indiscernible] from 0. I mean if you like the core start problem, which is like no customers, no market, it's really hard. We have a strong foundation to build upon.
Yes. Two things to add. One is, just being transparent, I can't stand here and tell you the things that we're going to run fastest on because that would not be wise. So...
A security company can never run too fast. I don't ask us to run too fast because we cannot make mistakes.
But we're excited about where we're going to run fastest because we know that there's already a lot of customer value we can create. That's one thing. And then the second thing is it's just coming back to the fact that amongst our 5,000 customers in the enterprise and many thousands more prospects, we have conversations every day that illuminate for us just how much need there is for what it is in the direction we're going, all the way from people who want to flip their privacy model to people who want kind of easy verification for really hard things to do today because they're just inconvenient processes. So we're just going to be very methodical about how we create value for our customers, but this is not going to be rooted in things that divert from the focus that the company has always had, which is providing that strong authentication, root of trust, hardware-backed phishing-resistant MFA as the foundation because if you don't lock that door, then you don't have identities that you can trust to do anything else. And so think about this as sort of laying that foundation has taken a while. This is a fantastic base on which to build. And when we build on that base, we're going to be rooted in real customer problems and they're just too numerous to solve. So actually what we spend a lot of time thinking about is what we're going to do.
But every existing customer struggles with this. How do I onboard people? How do I secure the identity of the user and then how do I manage the life cycle of the product. And every customer today pretty much has a different approach to it. I think it's safe to say you used to work. The Google had a very generous approach and said everyone should get at least 3 YubiKeys and make sure that, that's always the need a trust. We -- I spoke with the German customer only a couple of weeks ago. They have a lot of discipline when it comes to someone losing their YubiKey and how they get back online or how they get access again. They literally demand the delinquent to show up on site and then to have 2 of their managers on location, verifying that person's identity using their YubiKeys and then new credentials can be issued. That's an example of a customer with a very low attrition rate, let's put it that way, because you don't want to go through that process. And we want to make sure that we find the right balance between security and convenience/scalability there. And I think we come from a unique position with the background that we have.
Next question.
Yes, you kind of touched upon it a little bit now, but I'm thinking of -- maybe you don't know the answer to this, but if you consider other cybersecurity companies like Cloudflare has been mentioned or CrowdStrike or Palo Alto Networks, when they roll out their services, those are also typically quite long implementations and they're painful. The implementation time for you guys compared to -- I don't know if you can say an average of other large complex implementations. But based on what you just told us, it is this kind of recovery onboarding that is really the big pain point for you. How do you stack up versus other companies? And are they quicker at deploying? I know it's software, but it kind of ties in...
I think the question is if you took a life cycle of hardware versus the software, there are fast things and slow things in each category of technology. So you might be -- for example, let's just talk about software. You could be fast to deploy, but really struggle for maintaining the level of security because what you don't see behind the scenes of software is you actually have to maintain the patches of that phone. Do you want to take control of how frequently we patch phones and operating systems and Windows and Google and Apple? There's a huge cost to that. So some things are fast and some things are longer. Hardware is a little bit of the reverse. It takes a longer time to establish that deployment, but then you have a very consistent flow because we're not changing anything on the hardware like the YubiKey when you get it. So there's all these measurements that we see from the reality of customers deploying. And long-term perspective, independent of whether it's software or hardware, customers choose companies that go for the marathon, not the sprint. And so that's really the difference because you've got to really work through the pain in some ways. It's nothing to do with Yubico or the technology. Every company has complexity because I call this every large company, large is relative, as a computer history museum of stuff. And you can't like run fast in some of these things, even if you wanted to, right? Obviously, T-Mobile had a very strong leader that pushed all the way through, but that sometimes works, sometimes it doesn't work because the technology doesn't have it. The stack didn't mature enough. So I think there are a few combinations that I can't give you a straight answer whether it's faster than a Palo Alto Network-based software thing or a YubiKey thing. I think enterprise is complicated than let alone if you think about deploying to government systems, you have even more complexity. So what we believe, though, is that the innovation that we provide accelerates the adoption. And it's two things. It's definitely about the standardization so that it works out of the box, and we spend a lot of time making sure things work out of the box. And then the second part of it is like Yubico has to do its part. He's got to innovate on this open stand to accelerate the adoption.
One quick thing to add. First of all, I think we've got 2 customers here who have been so kind with their time. They can give you unvarnished samples of how quickly they saw time to value because oftentimes, this is just a time to value question, like how quickly can I see value from deploying this. Value is often very, very quick because there are situations where when Carl talked about unplanned deployments, and unplanned deployment is usually because some kind of catastrophic compromise occurred, credentials were stolen and people show up and they say, well, we need to get -- we need to like reestablish connections to our environment that we can trust again. And then there will be people in our facilities working until 2 in the morning to get keys to them. It happens. But if that's an indication of what time to value means for YubiKey deployments, that's the best evidence I can give you that this is something that has very rapid time to value.
Everything between a few -- couple of weeks to 7 years. I mean we've seen some customers like 7 years ago, like, oh, we started this little thing and then, oh, you know what, as you said, the reason why they then take action is -- the 2 major reasons are either compliance there's a new regulation that they need to comply with that needs this kind of high level of security or they've had a breach or they got a new CISO that had YubiKeys in his previous job.
Can I ask a quick follow-up on that? Is there a service you could provide where you promise a certain delivery time? Or would you just -- based on what the IT stack looks like in the various customers, but will you actually even further than you do with T-Mobile, et cetera, just redo the implementation for you and then charge for it.
Let me -- so most environments are Microsoft environments in enterprise. So the parts of the environment that we control the delivery of often -- like identity is such a complex stack. There's going to be many things that you're getting right in order for the YubiKey to fit in correctly and deliver the value. But you could deliver and deploy YubiKeys in a day. However, if you did that and you have vulnerability to what I call downgrade attacks, downgrade attacks, all the other places where you don't actually have true phishing resistance in your architecture, but you have ostensibly deployed something phishing resistant on the front door, but you've got an open window here. And so we can deploy YubiKeys extremely quickly and deliver perceived time to value quickly. But all identity and access management professionals and CISOs will tell you that you have to make sure that you're doing it in a way that gives you the protection you're trying to buy.
The best we can get to today, I think, is working with a professional organization like T-Mobile saying, okay, we're going to get this done. We're going to make sure that we don't have the back door open or open windows, and we're committing them to, yes, we'll support you in that journey. It will not -- the physical access to YubiKeys at this point will not be the limitation. As we scale, yes, that's doable. I think it's more of an implementation partner opportunity than a Yubico opportunity.
Yes. And I think we're going to work with a lot more. I think Mattias talked about some of the global system integrators because a lot of it is not even technology related. It's all change management. Like a majority of these projects, besides going to on plan, they are massive change management and some of it is digital transformation as well. So we certainly don't have the expertise to do like large-scale change management. And that's why one of the leverage plays -- sales plays that we have is to work with the global system integrators, MSSPs. That's our plan to really help accelerate the adoption because those are the folks that know how to do change management and be professional about the cadence and the planning.
We have one last question.
My name is [indiscernible]. And I would like to ask you if you see company acquisition as a way to expand and how would that be?
Yes. Just some background, we've never made an acquisition. It's all been organic growth in the past. However, as we expand in the digital identity space when it comes to life cycle credentials management, when it comes to [ IBV ], those are two areas where there is -- there could be value in "not" reinventing the wheel, but identifying specific product features or specific competencies that would be a quicker time to market and a good return on investment to instead of making an acquisition. We're not quite there yet, but it's not something that will...
It's not off the table.
No.
Thank you to all the speakers. And then I'll leave it for Mattias to close things up.
So thanks, everybody. Hopefully, this was digestible. At times, I need to think really hard to follow along when Albert and Jerrod talk about things. So it takes some time to get your head around it. We're recording everything. If there are parts that you want to revisit, there's a good chance to do so and also all the presentation material will be available online. I'd like to wrap it up by talking about what I mentioned initially. And I'm really happy about the questions that we got here. This is about how we leverage the position that we build so we can safe -- so we can protect and create safe digital identities for generations. So why are we so confident about our ability to deliver on that? Well, it comes from a few different levers. We already have established a market leadership position in a rapidly growing market, which is the foundation for managing digital identities. So we created the passkeys protocol, co-created it, and we've built a position where we're being recognized as the world leader when it comes to hardware-based MFA. And we've also established a business model which lends itself to working with some of the largest players in this market to leverage the position we built with them within the current use case YubiKey as a Service and with emerging digital identity solutions. We have the strongest innovative team in this market that you can find. And I think some of the examples that we've shown today is -- are testaments to the fact that we'll continue innovating and leading the market within strong MFA and beyond. And we have a solid financial position. We have had 3 quarters with lower sales growth than the long-term target, taking a longer perspective. We've had 40% growth since we went public, about 15% growth. We have a stable gross margin. We have consistently had positive cash flow, and we have a very strong balance sheet. So we're in a position where we can invest in building the next big thing. So with that, I'd like to thank everybody for your interest in Yubico, and we'll hand it over to Alexandra to wrap things up for those that are here. For those of you that have joined online, thank you so much, and we look forward to hosting similar events in the future. Thanks.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Yubico AB transcript - plus 251,000+ transcripts from 12,000+ companies, speaker segments and full-text search - through the EarningsAPI REST API or hosted MCP server.
Get an API key View API docs →For developers and AI pipelines
Programmatic access to Yubico AB earnings transcripts and 251,000+ others is available through the
EarningsAPI REST API and the hosted MCP server.
Quarterly plans from $105 - full transcripts, speaker segments, full-text search,
and the /api/v1/transcripts/recent polling endpoint for ETL pipelines.