Yubico Aktienkurs
Ist Yubico eine Topscorer-Aktie nach der Dividenden-, High-Growth-Investing- oder Levermann-Strategie?
Als kostenloser aktien.guide Basis-Nutzer kannst Du die Scores zu allen 9.127 weltweiten Aktien einsehen.
aktien.guide Premium
aktien.guide Unlimited
Kennzahlen
📘 Marktkapitalisierung
📈 Was ist das?
Die Marktkapitalisierung zeigt, wie viel ein Unternehmen laut Börse aktuell wert ist.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Sie hilft Unternehmen in Größenklassen (Large, Mid, Small Cap) einzuordnen und gibt Hinweise auf Marktmacht und Stabilität.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Große Unternehmen gelten als stabiler, zahlen oft Dividenden, wachsen aber langsamer.
- Kleine Firmen können stärker wachsen, sind aber schwankungsanfälliger.
- Die Marktkapitalisierung ist ein guter Indikator für Unternehmensgröße, aber kein Maß für Unter- oder Überbewertung.
📘 Enterprise Value (Unternehmenswert)
📈 Was ist das?
Der Enterprise Value (EV) zeigt, was ein Unternehmen tatsächlich kostet, wenn man es komplett übernehmen würde – inklusive Schulden und abzüglich Cash.
🧮 Wie wird es berechnet?
(= Marktkapitalisierung + Nettoverschuldung)
🏛️ Wofür ist es wichtig?
Der EV ist eine realistischere Bewertungsbasis als die Marktkapitalisierung, da er die Kapitalstruktur berücksichtigt. Er ist Grundlage für Kennzahlen wie EV/FCF oder EV/Sales.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Der Enterprise Value zeigt, was ein Unternehmen tatsächlich wert ist – unabhängig davon, wie es finanziert ist.
- Er ist besonders wichtig für professionelle Investoren, da er eine objektivere Grundlage für Bewertungsvergleiche bietet als die Marktkapitalisierung allein.
- Ein Unternehmen mit hoher Verschuldung erscheint im EV teurer, eines mit viel Cash günstiger – auch wenn sie an der Börse gleich viel wert sind.
📘 Nettoverschuldung
📈 Was ist das?
Die Nettoverschuldung zeigt, wie viele Schulden nach Abzug des verfügbaren Cashs tatsächlich verbleiben.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Sie zeigt, wie stark ein Unternehmen von Fremdkapital abhängig ist – und wie gut es in der Lage ist, seine Schulden kurzfristig zu bedienen.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Eine niedrige oder negative Nettoverschuldung bedeutet hohe finanzielle Stabilität.
- Unternehmen mit viel Cash und geringer Verschuldung sind besser gerüstet für Krisen.
- Eine hohe Nettoverschuldung erhöht das Risiko – besonders bei steigenden Zinsen oder konjunkturellen Schwächen.
📘 Cash
📈 Was ist das?
Der Cashbestand zeigt, wie viele liquide Mittel einem Unternehmen sofort zur Verfügung stehen.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Er gibt Auskunft über die finanzielle Flexibilität: Ein hoher Cashbestand ermöglicht Investitionen, Rückkäufe oder Krisenresistenz.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein hoher Cashbestand zeigt finanzielle Stärke und Handlungsspielraum.
- Cash kann für Investitionen, Schuldentilgung oder Aktienrückkäufe genutzt werden.
- Allerdings: Zu viel ungenutztes Kapital kann auch auf mangelnde Investitionsideen hinweisen.
📘 Anzahl ausstehender Aktien
📈 Was ist das?
Die Anzahl ausstehender Aktien gibt an, wie viele Aktien eines Unternehmens aktuell im Umlauf sind und von Investoren gehalten werden.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Sie ist die Grundlage für viele Kennzahlen wie Gewinn je Aktie (EPS), Marktkapitalisierung oder KGV.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Je weniger Aktien im Umlauf sind, desto höher fällt z. B. der Gewinn je Aktie aus – wichtig für Bewertung und Dividendenrendite.
- Aktienrückkäufe verringern die Anzahl ausstehender Aktien – und steigern den Wert je Aktie.
- Kapitalerhöhungen haben den gegenteiligen Effekt: mehr Aktien → Verwässerung der bestehenden Anteile.
📘 Kurs-Gewinn-Verhältnis (KGV)
📈 Was ist das?
Das KGV zeigt, wie oft der Gewinn pro Aktie im aktuellen Aktienkurs enthalten ist – also wie „teuer“ eine Aktie im Verhältnis zum Gewinn ist.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Das KGV gehört zu den bekanntesten Bewertungskennzahlen. Es hilft Anlegern einzuschätzen, ob eine Aktie im Vergleich zu ihrem Gewinn eher günstig oder teuer erscheint.
🧮 Berechnung
📊 KGV (TTM) = bezogen auf den Gewinn der letzten 12 Monate (Trailing Twelve Months):🎯 Was bedeutet das für Anleger?
- Ein niedriges KGV kann auf eine günstige Bewertung hindeuten – oder auf Probleme im Geschäftsmodell.
- Ein hohes KGV kann Wachstumserwartungen widerspiegeln – oder eine überbewertete Aktie.
📘 Kurs-Umsatz-Verhältnis (KUV)
📈 Was ist das?
Das KUV zeigt, wie viel Anleger für 1 € Umsatz eines Unternehmens zahlen – unabhängig vom Gewinn.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Das KUV ist besonders bei wachstumsstarken oder noch nicht profitablen Unternehmen hilfreich. Es zeigt, wie hoch der Umsatz an der Börse bewertet wird.
🧮 Berechnung
Marktkapitalisierung = 8,31 Mrd. kr | Umsatz (TTM) = 2,12 Mrd. kr
Marktkapitalisierung = 8,31 Mrd. kr | Umsatz erwartet = 2,20 Mrd. kr
🎯 Was bedeutet das für Anleger?
- Ein niedriges KUV kann auf Unterbewertung hindeuten – oder auf schwache Margen.
- Ein hohes KUV kann hohe Erwartungen widerspiegeln – oder übermäßigen Optimismus.
- Besonders sinnvoll bei Wachstumsunternehmen, bei denen der Gewinn oder Free Cashflow (noch) keine Aussagekraft hat.
📘 Unternehmenswert zu Umsatz (EV/Sales)
📈 Was ist das?
EV/Sales zeigt, wie viel Anleger für 1 € Umsatz eines Unternehmens zahlen, wenn man auch Schulden und Cash berücksichtigt – es ist eine kapitalstrukturbereinigte Version des KUV.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Diese Kennzahl eignet sich besonders für den Vergleich von Unternehmen mit unterschiedlicher Verschuldung – sie zeigt, wie teuer ein Unternehmen tatsächlich im Verhältnis zum Umsatz ist.
🧮 Berechnung
Enterprise Value = 7,32 Mrd. kr | Umsatz (TTM) = 2,12 Mrd. kr
Enterprise Value = 7,32 Mrd. kr | Umsatz erwartet = 2,20 Mrd. kr
🎯 Was bedeutet das für Anleger?
- EV/Sales ist neutral gegenüber der Kapitalstruktur und eignet sich gut für Unternehmensvergleiche.
- Ein niedriges Verhältnis kann auf eine günstig bewertete Aktie hindeuten – ein hohes Verhältnis auf hohe Erwartungen oder Überbewertung.
- Besonders nützlich bei wachstumsstarken, noch nicht profitablen Firmen.
📘 Unternehmenswert zu Free Cashflow (EV/FCF)
📈 Was ist das?
EV/FCF zeigt, wie viele Jahre es dauern würde, bis ein Unternehmen seinen Unternehmenswert durch freien Cashflow „zurückverdient”.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Diese Kennzahl hilft, Unternehmen auf Basis ihrer tatsächlichen Cash-Erträge zu bewerten – unabhängig von Bilanzierungsregeln oder buchhalterischem Gewinn.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein niedriges EV/FCF deutet auf eine günstige Bewertung bei starker Cashgenerierung hin.
- Ein hohes EV/FCF kann entweder auf Optimismus oder auf temporär schwachen Cashflow hindeuten.
- Besonders hilfreich bei reifen, profitablen Unternehmen mit stabilen Cashflows.
📘 Kurs-Buchwert-Verhältnis (KBV)
📈 Was ist das?
Das KBV zeigt, wie hoch der Marktwert eines Unternehmens im Verhältnis zu seinem bilanziellen Eigenkapital ist.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Das KBV ist besonders bei Substanzwerten (z. B. Banken, Industrie) relevant. Es hilft Anlegern zu erkennen, ob ein Unternehmen unter oder über seinem buchhalterischen Vermögen bewertet ist.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein KBV unter 1 kann auf Unterbewertung oder schwache Rentabilität hindeuten.
- Ein KBV über 1 zeigt, dass der Markt dem Unternehmen Mehrwert über den Buchwert hinaus zuschreibt (z. B. Marken, Patente, Wachstum).
- Das KBV eignet sich besonders gut für Unternehmen mit stabilen, materiellen Vermögenswerten.
📘 Eigenkapitalquote
📈 Was ist das?
Die Eigenkapitalquote zeigt, wie hoch der Anteil des Eigenkapitals an der Bilanzsumme eines Unternehmens ist – also wie stark es sich aus eigenen Mitteln finanziert.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Eine hohe Eigenkapitalquote steht für finanzielle Stabilität, Krisenfestigkeit und gute Bonität. Sie ist besonders relevant bei der Beurteilung der Verschuldung.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Eine hohe Eigenkapitalquote signalisiert finanzielle Stabilität – besonders in Krisenzeiten.
- Ein niedriger Wert kann auf ein höheres Risiko oder eine aggressive Verschuldung hinweisen.
- Wichtig: Die Eigenkapitalquote sollte immer gemeinsam mit der Eigenkapitalrendite betrachtet werden. Nur so lässt sich beurteilen, ob ein Unternehmen nicht nur solide, sondern auch effizient wirtschaftet.
📘 Eigenkapitalrendite (ROE)
📈 Was ist das?
Die Eigenkapitalrendite zeigt, wie effizient ein Unternehmen mit dem Kapital seiner Aktionäre arbeitet – also wie viel Gewinn es pro Euro Eigenkapital erwirtschaftet.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Die Eigenkapitalrendite ist eine zentrale Rentabilitätskennzahl. Sie hilft Anlegern zu erkennen, ob das Unternehmen eine attraktive Verzinsung auf das eingesetzte Eigenkapital erwirtschaftet.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Eine hohe Eigenkapitalrendite spricht für ein starkes, effizientes Geschäftsmodell.
- Besonders interessant ist sie bei kapitalintensiven Firmen oder solchen mit hoher Eigenkapitalquote.
- Wichtig: Ein sehr hoher ROE kann auch auf hohe Schulden hinweisen – daher sollte sie immer im Kontext mit der Eigenkapitalquote betrachtet werden.
📘 Return on Capital Employed (ROCE)
📈 Was ist das?
ROCE misst die Gesamtrentabilität eines Unternehmens – also wie effizient es das eingesetzte Kapital (Eigen- und Fremdkapital) zur Gewinnerzielung nutzt.
🧮 Wie wird es berechnet?
Das eingesetzte Kapital ist das gesamte betriebsnotwendige Kapital, unabhängig von der Finanzierungsquelle.
🏛️ Wofür ist es wichtig?
ROCE eignet sich besonders gut für den Vergleich unterschiedlich finanzierter Unternehmen. Es zeigt, wie effektiv ein Unternehmen Kapital investiert – unabhängig von der Kapitalstruktur.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein hoher ROCE zeigt, dass ein Unternehmen sein Kapital effizient einsetzt – unabhängig davon, ob es durch Eigen- oder Fremdkapital finanziert ist.
- Je höher der ROCE im Vergleich zu ähnlichen Unternehmen, desto mehr Wert schafft das Unternehmen mit seinem investierten Kapital.
- Besonders wichtig ist der ROCE bei Firmen mit hohen Investitionen – z. B. in Industrie, Energie oder Infrastruktur.
📘 Return on Invested Capital (ROIC)
📈 Was ist das?
ROIC zeigt, wie effizient ein Unternehmen das Kapital investiert, das langfristig im operativen Geschäft gebunden ist – unabhängig davon, ob es aus Eigen- oder Fremdkapital stammt.
🧮 Wie wird es berechnet?
- NOPAT = „Net Operating Profit After Taxes“
- Investiertes Kapital = operatives Vermögen abzüglich nicht-verzinster Schulden
🏛️ Wofür ist es wichtig?
ROIC ist eine der präzisesten Kennzahlen zur Bewertung der Kapitalrendite – besonders im Vergleich zur Eigenkapitalrendite, weil es Verzerrungen durch Schulden vermeidet. Er zeigt, ob ein Unternehmen Mehrwert für alle Kapitalgeber schafft.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein hoher ROIC zeigt, wie gut ein Unternehmen mit dem tatsächlich investierten (betriebsnotwendigen) Kapital wirtschaftet.
- Im Unterschied zu ROCE wird nur Kapital betrachtet, das wirklich zur Finanzierung operativer Aktivitäten dient – und verzinst werden muss.
- Besonders hilfreich, um die Kapitalrendite von Unternehmen mit viel „überschüssigem“ Kapital oder zinsfreien Verbindlichkeiten realistisch zu vergleichen.
📘 Verschuldungsgrad (Leverage Ratio)
📈 Was ist das?
Der Verschuldungsgrad zeigt, wie stark ein Unternehmen durch verzinsliche Schulden (z. B. Kredite und Anleihen) im Verhältnis zum Eigenkapital finanziert ist.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Die Kennzahl hilft, das finanzielle Risiko und die Abhängigkeit von Fremdkapital zu beurteilen. Ein hoher Verschuldungsgrad kann die Eigenkapitalrendite steigern – birgt aber auch erhöhte Risiken bei Zinsanstiegen oder Liquiditätsengpässen.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein niedriger Verschuldungsgrad steht für finanzielle Stabilität und Unabhängigkeit.
- Ein hoher Wert kann auf erhöhte Risiken hinweisen – insbesondere bei schwankenden Zinsen oder konjunkturellen Schwächen.
- Wichtig: Immer im Kontext zur Branche und Kapitalintensität bewerten.
📘 Umsatz
📈 Was ist das?
Der Umsatz zeigt, wie viel ein Unternehmen insgesamt mit seinen Produkten und Dienstleistungen verdient – also den Bruttoerlös vor Abzug von Kosten.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Der Umsatz ist eine der zentralen Kennzahlen zur Einschätzung der Unternehmensgröße, Marktstellung und Wachstumskraft.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein wachsender Umsatz zeigt eine steigende Nachfrage und kann ein guter Frühindikator für Gewinnsteigerungen sein.
- Vergleiche von aktuellem und erwartetem Umsatz geben Hinweise auf das Marktumfeld und Analystenerwartungen.
- Wichtig: Starker Umsatz allein genügt nicht – auch Margen und Profitabilität zählen.
📘 EBITDA
📈 Was ist das?
EBITDA steht für „Earnings Before Interest, Taxes, Depreciation and Amortization“ – also Gewinn vor Zinsen, Steuern und Abschreibungen. Es zeigt das operative Ergebnis eines Unternehmens, bereinigt um bilanztechnische und finanzierungsbedingte Effekte.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
EBITDA ist eine verbreitete Kennzahl zur Beurteilung der operativen Leistungsfähigkeit – insbesondere bei kapitalintensiven Unternehmen oder im internationalen Vergleich.
🎯 Was bedeutet das für Anleger?
- Ein hohes oder wachsendes EBITDA spricht für starke operative Erträge – unabhängig von Bilanzierung oder Steuerlast.
- EBITDA ist besonders nützlich, um Unternehmen branchenübergreifend zu vergleichen.
- Wichtig: EBITDA ist keine offizielle Gewinnkennzahl – Abschreibungen und Finanzierungskosten werden ausgeklammert.
📘 EBIT
📈 Was ist das?
EBIT steht für „Earnings Before Interest and Taxes“ – also Gewinn vor Zinsen und Steuern. Es zeigt das operative Ergebnis eines Unternehmens nach Abschreibungen, aber vor Finanzierungs- und Steueraufwand.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
EBIT ist eine zentrale Kennzahl zur Beurteilung der Profitabilität aus dem Kerngeschäft – unabhängig von Kapitalstruktur oder Steuersystem.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein hohes EBIT deutet auf ein profitables Kerngeschäft hin – vor Zinslasten oder steuerlichen Effekten.
- Es erlaubt objektivere Vergleiche zwischen Unternehmen mit unterschiedlicher Finanzierung.
- Im Vergleich mit EBITDA zeigt EBIT bereits den Einfluss von Abschreibungen auf das operative Ergebnis.
📘 Nettogewinn
📈 Was ist das?
Der Nettogewinn ist der verbleibende Jahresüberschuss (oder -fehlbetrag) eines Unternehmens – nach Abzug aller Kosten, Steuern, Zinsen und Abschreibungen
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Der Nettogewinn ist die zentrale Erfolgskennzahl – er zeigt, wie profitabel ein Unternehmen nach allen Kosten tatsächlich arbeitet.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein steigender Nettogewinn zeigt, dass das Unternehmen effizient wirtschaftet – trotz aller Kosten.
- Die Entwicklung des Gewinns beeinflusst z. B. direkt das KGV und weitere Kennzahlen.
- Im Zeitverlauf lässt sich ablesen, wie stabil und profitabel ein Geschäftsmodell wirklich ist.
📘 Free Cashflow (FCF)
📈 Was ist das?
Der Free Cashflow gibt Aufschluss über die echte finanzielle Stärke eines Unternehmens – unabhängig von Bilanzierungsregeln. Er zeigt, wie viel Spielraum für Dividenden, Aktienrückkäufe oder Schuldenabbau besteht.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
FCF reflects a company’s real financial strength – regardless of accounting profits. It shows how much flexibility a company has for dividends, share buybacks, or debt reduction.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein hoher Free Cashflow bedeutet, dass ein Unternehmen echte Finanzkraft besitzt – unabhängig vom bilanzierten Gewinn.
- Er ist oft die solideste Grundlage für nachhaltige Dividenden und Aktienrückkäufe.
- Sinkender FCF kann ein Warnsignal sein – auch wenn der Gewinn stabil aussieht.
📘 Umsatzwachstum
📈 Was ist das?
Das Umsatzwachstum zeigt, wie stark sich die Erlöse eines Unternehmens im Vergleich zum Vorjahr verändert haben – tatsächlich (TTM) und auf Prognosebasis (erwartet).
🧮 Wie wird es berechnet?
Erwartet = (Umsatz erwartet ÷ Umsatz Vorjahr − 1) × 100
Erwartetes Wachstum basiert auf Analystenschätzungen für das laufende Geschäftsjahr.
🏛️ Wofür ist es wichtig?
Ein wachsender Umsatz ist ein zentrales Signal für steigende Nachfrage, Geschäftsausweitung und Marktanteilsgewinne – besonders bei Wachstumsunternehmen.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Wachstum ist der Motor langfristiger Wertsteigerung – besonders bei Technologie- und Wachstumsaktien.
- Wichtig ist nicht nur das aktuelle Wachstum, sondern auch dessen Nachhaltigkeit.
- Prognosen zeigen, ob Analysten weiteres Potenzial erwarten – oder eine Verlangsamung.
📘 EBITDA-Wachstum
📈 Was ist das?
Das EBITDA-Wachstum zeigt, wie stark das operative Ergebnis eines Unternehmens vor Zinsen, Steuern und Abschreibungen im Vergleich zum Vorjahr gestiegen oder gesunken ist.
🧮 Wie wird es berechnet?
Erwartet = (erwartetes EBITDA ÷ EBITDA Vorjahr − 1) × 100
Erwartetes Wachstum basiert auf Analystenschätzungen für das laufende Geschäftsjahr.
🏛️ Wofür ist es wichtig?
Ein steigendes EBITDA ist ein Zeichen für verbesserte operative Ertragskraft – unabhängig von Finanzierungsstruktur oder Abschreibungen.
🎯 Was bedeutet das für Anleger?
- Starkes EBITDA-Wachstum signalisiert operative Effizienz und Skalierung – besonders relevant in Wachstumsphasen.
- EBITDA-Wachstum ist ein Frühindikator für Margen- und Gewinnentwicklung – sollte aber stets im Zusammenhang mit Umsatz und EBIT betrachtet werden.
📘 EBIT Wachstum
📈 Was ist das?
Das EBIT-Wachstum zeigt, wie stark das operative Ergebnis eines Unternehmens (nach Abschreibungen, aber vor Zinsen und Steuern) im Vergleich zum Vorjahr gewachsen ist.
🧮 Wie wird es berechnet?
Erwartet = (erwartetes EBIT ÷ EBIT Vorjahr − 1) × 100
Erwartetes Wachstum basiert auf Analystenschätzungen für das laufende Geschäftsjahr.
🏛️ Wofür ist es wichtig?
Das EBIT-Wachstum ist ein direkter Indikator für die wirtschaftliche Entwicklung des operativen Geschäfts – unter Berücksichtigung der Kapitalintensität (Abschreibungen).
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Steigendes EBIT signalisiert wachsende operative Rentabilität – auch unter Berücksichtigung von Abschreibungen.
- Das EBIT-Wachstum ist ein wichtiges Maß zur Beurteilung von Geschäftsmodellen mit hohen Investitionskosten.
- Im Zusammenspiel mit Umsatz- und EBITDA-Wachstum ergibt sich ein umfassendes Bild zur operativen Entwicklung.
📘 Nettogewinn-Wachstum
📈 Was ist das?
Das Nettogewinn-Wachstum zeigt, wie stark der Jahresüberschuss eines Unternehmens gegenüber dem Vorjahr gestiegen oder gesunken ist – sowohl tatsächlich (TTM) als auch auf Basis von Prognosen (erwartet).
🧮 Wie wird es berechnet?
Erwartet = (erwarteter Nettogewinn ÷ Nettogewinn Vorjahr − 1) × 100
Der erwartete Wert basiert auf Analystenschätzungen für das laufende Geschäftsjahr.
🏛️ Wofür ist es wichtig?
Der Gewinn ist die entscheidende Ergebnisgröße für ein Unternehmen. Ein wachsender Nettogewinn deutet auf steigende Effizienz, stabile Kostenkontrolle und nachhaltige Ertragskraft hin.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Wachsender Nettogewinn stärkt die Bewertung, Dividendenfähigkeit und Kursfantasie.
- Stagnierender oder rückläufiger Gewinn trotz Umsatzwachstum kann auf Margendruck hinweisen.
📘 Free Cashflow-Wachstum
📈 Was ist das?
Das Free-Cashflow-Wachstum zeigt, wie sich der freie Mittelzufluss eines Unternehmens im Vergleich zum Vorjahr verändert hat – also der Betrag, der nach allen operativen Ausgaben und Investitionen übrig bleibt.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Free Cashflow ist der echte, verfügbare Geldzufluss. Wachstum in diesem Bereich ist ein Zeichen für finanzielle Stärke und steigende Flexibilität bei Dividenden, Rückkäufen oder Investitionen.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Sinkender Free Cashflow kann auf steigende Investitionen, höhere Kosten oder stagnierende operative Erträge hindeuten.
- Besonders bei Dividendenwerten ist das FCF-Wachstum wichtig – denn Dividenden werden letztlich aus dem verfügbaren Cash gezahlt.
- Ein negativer Trend sollte genauer analysiert werden – er ist nicht zwangsläufig schlecht, aber potenziell ein Warnsignal.
📘 Bruttomarge
📈 Was ist das?
Die Bruttomarge zeigt, wie viel vom Umsatz nach Abzug der direkten Herstellungskosten (Material, Produktion) als Bruttogewinn übrig bleibt – also der „Rohgewinn“ eines Unternehmens.
🧮 Wie wird es berechnet?
Auch: Bruttomarge = Bruttogewinn ÷ Umsatz × 100
🏛️ Wofür ist es wichtig?
Die Bruttomarge gibt Aufschluss über die Profitabilität eines Produkts oder Geschäftsmodells vor Fixkosten, Steuern und Zinsen. Sie zeigt, wie effizient ein Unternehmen produzieren oder einkaufen kann.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Eine hohe Bruttomarge deutet auf starke Preissetzungsmacht und effiziente Herstellung hin.
- Sinkende Bruttomargen können auf Kostensteigerungen oder Preisdruck hindeuten.
- Besonders im Vergleich zu Wettbewerbern liefert die Bruttomarge wertvolle Einblicke in die Geschäftsqualität.
📘 EBITDA-Marge
📈 Was ist das?
Die EBITDA-Marge zeigt, wie viel vom Umsatz als operativer Gewinn vor Zinsen, Steuern und Abschreibungen (EBITDA) übrig bleibt. Sie misst die operative Effizienz – ohne Verzerrungen durch Finanzierung oder Buchwerte.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Die EBITDA-Marge hilft zu verstehen, wie viel operativer Gewinn ein Unternehmen aus jedem Euro Umsatz erzielt – unabhängig von Kapitalstruktur oder steuerlichem Umfeld.
🎯 Was bedeutet das für Anleger?
- Eine hohe EBITDA-Marge zeigt starke operative Ertragskraft – unabhängig von Bilanzierungseffekten.
- Die Marge ermöglicht gute Vergleiche zwischen Unternehmen und Branchen.
- Ein stabiler oder wachsender Wert kann auf effiziente Kostenkontrolle und Skalierbarkeit hindeuten.
📘 EBIT-Marge
📈 Was ist das?
Die EBIT-Marge zeigt, wie viel Prozent des Umsatzes als operativer Gewinn nach Abschreibungen, aber vor Zinsen und Steuern übrig bleiben.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Die EBIT-Marge misst die operative Ertragskraft eines Unternehmens unter Berücksichtigung der Kapitalintensität (z. B. Maschinen, Anlagen). Sie eignet sich gut zum Vergleich von Geschäftsmodellen mit unterschiedlich hohen Abschreibungen.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Eine hohe EBIT-Marge zeigt, dass ein Unternehmen auch nach Abschreibungen effizient arbeitet.
- Sie ist besonders relevant in kapitalintensiven Branchen.
- Langfristig stabile oder steigende Margen sind ein Zeichen wirtschaftlicher Stärke und Preissetzungsmacht.
📘 Nettomarge
📈 Was ist das?
Die Nettomarge zeigt, wie viel vom Umsatz am Ende als „Reingewinn“ übrig bleibt – also nach Abzug aller Kosten, Zinsen, Steuern und Abschreibungen.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Die Nettomarge gibt an, wie effizient ein Unternehmen über alle Stufen hinweg wirtschaftet. Sie zeigt, wie viel Gewinn tatsächlich je Euro Umsatz übrig bleibt.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Eine hohe Nettomarge zeigt, dass ein Unternehmen nicht nur operativ stark ist, sondern auch seine Finanzierung und Steuerbelastung im Griff hat.
- Vergleiche mit Wettbewerbern geben Einblicke in die wirtschaftliche Qualität.
- Sinkende Nettomargen trotz Umsatzwachstum können ein Warnsignal sein – etwa für steigende Kosten oder sinkende Effizienz.
📘 Free Cashflow Marge
📈 Was ist das?
Die Free-Cashflow-Marge zeigt, wie viel vom Umsatz nach Abzug aller operativen Ausgaben und Investitionen tatsächlich als freier Mittelzufluss übrig bleibt.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Diese Marge misst die echte Liquidität, die ein Unternehmen erwirtschaftet – unabhängig von Bilanzierungsregeln oder Abschreibungen. Sie ist besonders relevant für Dividenden, Rückkäufe und Investitionen.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Eine hohe Free-Cashflow-Marge zeigt, dass ein Unternehmen nachhaltig liquide Mittel erwirtschaftet.
- Sie ist ein starkes Signal für finanzielle Stabilität und Ausschüttungspotenzial.
- Wichtig ist der langfristige Trend – sinkende Werte können auf steigende Investitionen oder rückläufige operative Effizienz hindeuten.
📘 Ergebnis je Aktie (EPS)
📈 Was ist das?
Das Ergebnis je Aktie (EPS) zeigt, wie viel Gewinn auf eine einzelne Aktie entfällt – und ist eine der wichtigsten Kennzahlen zur Bewertung von Unternehmen.
🧮 Wie wird es berechnet?
Die verwässerte Aktienanzahl berücksichtigt auch potenzielle neue Aktien, etwa durch Optionen, Wandelanleihen oder andere Umtauschrechte.
🏛️ Wofür ist es wichtig?
EPS bildet die Basis für viele Bewertungskennzahlen wie KGV, PEG oder Payout Ratio. Es macht den Gewinn für Aktionäre vergleichbar – unabhängig von der Unternehmensgröße.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- EPS hilft, die Profitabilität pro Aktie zu erfassen – und ist besonders wichtig im Zeitvergleich oder im Vergleich mit Analystenschätzungen.
- Steigendes EPS kann ein Zeichen für stabiles Wachstum oder Aktienrückkäufe sein.
- Wichtig: Verwende verwässertes EPS für realistische Bewertungen – besonders bei stark aktienbasierten Vergütungssystemen.
📘 Free Cashflow je Aktie (FCF je Aktie)
📈 Was ist das?
Der Free Cashflow je Aktie zeigt, wie viel freier Mittelzufluss einem Unternehmen pro Aktie zur Verfügung steht – nach Investitionen, aber vor Dividenden oder Schuldentilgung.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Der FCF je Aktie zeigt, wie viel liquide Mittel pro Aktie tatsächlich im Unternehmen verbleiben – wichtig für Dividenden, Aktienrückkäufe oder Schuldentilgung. Im Gegensatz zum Gewinn ist er schwerer manipulierbar und daher besonders aussagekräftig.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein hoher Free Cashflow je Aktie ist ein Zeichen für hohe finanzielle Flexibilität.
- Er zeigt, wie viel Kapital ein Unternehmen effektiv einsetzen oder ausschütten kann.
- Besonders relevant für dividendenstarke Unternehmen oder solche mit starker Kapitalrendite.
📘 Short Interest
📈 Was ist das?
Short Interest zeigt, wie viele Aktien eines Unternehmens aktuell leerverkauft wurden – also von Investoren geliehen und verkauft, in der Erwartung fallender Kurse.
🧮 Wie wird es berechnet?
Der Wert zeigt den Anteil der Aktien, der aktuell auf fallende Kurse spekuliert wird.
🏛️ Wofür ist es wichtig?
Short Interest dient als Stimmungsindikator: Ein hoher Wert deutet auf Skepsis oder negative Erwartungen gegenüber dem Unternehmen hin – kann aber auch zu einem „Short Squeeze“ führen, wenn der Kurs plötzlich steigt.
🎯 Was bedeutet das für Anleger?
- Ein niedriger Short Interest deutet auf Vertrauen in das Unternehmen hin.
- Ein hoher Wert kann ein Warnsignal sein – oder eine Chance, wenn sich die Stimmung dreht.
- Besonders spannend in volatilen Märkten oder vor wichtigen Quartalszahlen.
📘 Employees
📈 Was ist das?
Die Mitarbeiteranzahl zeigt, wie viele Personen ein Unternehmen weltweit beschäftigt – ein Indikator für Größe, Struktur und Geschäftsmodell.
🧮 Wie wird es berechnet?
🏛️ Wofür ist es wichtig?
Sie hilft bei der Einschätzung von Skaleneffekten, Effizienz und Personalkosten. Zusammen mit Umsatz und Gewinn lassen sich Kennzahlen wie Produktivität je Mitarbeiter ableiten.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Viele Mitarbeiter bedeuten große operative Komplexität – aber auch hohes Umsatzpotenzial.
- Produktivität je Mitarbeiter ist ein wichtiger Indikator für Effizienz.
- Besonders spannend bei stark wachsenden Tech- oder Industrieunternehmen.
📘 Umsatz je Mitarbeiter
📈 Was ist das?
Der Umsatz je Mitarbeiter zeigt, wie viel Erlös ein Unternehmen durchschnittlich pro Beschäftigtem erwirtschaftet – eine Kennzahl für Effizienz und Produktivität.
🧮 Wie wird es berechnet?
Die Mitarbeiterzahl stammt in der Regel aus dem letzten verfügbaren Jahresbericht.
🏛️ Wofür ist es wichtig?
Diese Kennzahl hilft, Geschäftsmodelle zu vergleichen – insbesondere zwischen arbeitsintensiven und technologiegetriebenen Unternehmen. Ein hoher Wert deutet auf Automatisierung, Effizienz oder hohen Wertschöpfungsanteil hin.
🧮 Berechnung
🎯 Was bedeutet das für Anleger?
- Ein hoher Umsatz je Mitarbeiter spricht für ein skalierbares und margenstarkes Geschäftsmodell.
- Ein niedriger Wert kann auf arbeitsintensive Prozesse oder geringere Wertschöpfung hinweisen.
- Besonders hilfreich beim Vergleich von Tech- vs. Industrieunternehmen.
Yubico Aktie Analyse
Analystenmeinungen
9 Analysten haben eine Yubico Prognose abgegeben:
Analystenmeinungen
9 Analysten haben eine Yubico Prognose abgegeben:
Yubico Events
🇩🇪 Neu: Alle Transkripte jetzt auch auf Deutsch verfügbar!
Abonniere Premium, um Transkripte und KI-Zusammenfassungen auf Deutsch zu lesen.
Vergangene Events
|
AUG
6
Q2 2026 Earnings Call
vor etwa 2 Monaten
|
|
MAI
5
Q1 2026 Earnings Call
vor 5 Monaten
|
|
FEB
12
Q4 2025 Earnings Call
vor 8 Monaten
|
|
NOV
19
Analyst/Investor Day - Yubico AB
vor 10 Monaten
|
|
NOV
12
Q3 2025 Earnings Call
vor 11 Monaten
|
aktien.guide Basis
Yubico — Q2 2026 Earnings Call
1. Management Discussion
Welcome to Yubico Q2 2026 Report Presentation. [Operator Instructions]
Now, I will hand the conference over to acting CEO, Jerrod Chong; and CFO, Snejana Koleva. Please go ahead.
Hi, everyone. Thanks for joining us. We will walk through the agenda and we'll give you our key highlights. And I'll hand over to Snejana to give you the details on the financial details. For those who are joining us and not familiar with Yubico, we are a very innovative cybersecurity organization that continues to innovate and produce products that help companies around the world be phishing-resistant and prevent account takeovers.
We are very excited to share our report, but we do have a good, strong list of our customers around the world. We've been around for more than 20 years and with a very strong direction to continue our global expansion and serve many more customers over the next few years.
I want to take a step back and provide an update on how we look at our industry, the trends that we see and the type of news that we are also part of in terms of cyber activities, both on the positive side as well as the threat landscape that we see customers and organizations around the world face.
With AI being much more powerful with all the new models, we definitely see that the attacks are not just much larger in scale. We see that they are much more sophisticated. Many of you are aware that even these models have known to attack organizations without the controls that we expect some of them to have. So that is just what we know. And we know that there is a side that many organizations are faced with that is increasing.
The good side of that is that we believe that access to these very powerful models must be protected, so that the accounts do not get taken over and the attackers use these very powerful models to attack organizations. So we really believe that this trend will continue to happen. And we continue to help protect organizations from not having their accounts taken over.
The other area that we are very much in tune with the industry is how the post-quantum evolution is happening. A quantum computer would break a lot of the -- pretty much all of the existing technology stacks that we use for cryptography. So what that means is that you need a technology that is post-quantum ready and we are part of that journey. So we will talk a little bit more about that type of innovation as we bring a YubiKey that will have post-quantum capabilities.
The other trend that we see is that as we continue to see weaknesses of how the software supply chain is being impacted, governments around the world are doing 2 things. They want to make sure that any product has been properly reviewed. And that these products as well as a maturity in how companies build them. And so we continue to invest in making sure our products are compliant with all the new regulation. We also help set some of these new regulations for the authentication industry. But that just gives a disciplined way to build products. And so we are very much in line with how industry should continue to close these loopholes when they build products, so that we don't introduce new risk to companies deploying products in general.
And the last area that we see is organizations are definitely concerned with identity, digital identity. We see that they are being attacked by all types of different hackers around the world, mostly because they -- it's much easier and it's much cheaper. But what the attackers are focused on is to downgrade the way that the users authenticate to be able to social-engineer their way into compromising the user accounts. So rather than just focused on the login to an account, a lot of companies are paying attention to how the users recover or get access back to the account when they have a recovery option. So recovery options are typically very weak. And that's where the attackers are focusing their efforts to compromise the accounts.
In the next slide, I wanted to give a highlight on where Yubico has been in the last quarter, but more collectively, what we see are the continued investments for our growth. Product innovation takes center stage in the way that we look at our business. We are very focused with delivering products and innovation that solves our customers' problem, namely in the first half and in Q2, releasing 2 types of YubiKeys. One focused on the regulated industries, particularly as we described, companies want to be compliant. We've released our FIPS-validated devices, which is relevant in a lot of markets around the world.
And then, we've also released a YubiKey that extends capabilities beyond just authentication to being able to perform authorization. And authorization is really important in the concept where it's not just who you are to be able to identify that you can log in. But do you have the right to do something besides just authenticating? And do you have -- are you the right person that is authorized to access the right system? So authorization plays a very important part of this evolution, particularly in the AI realm where you need to know who you authorized to use what and what agent was authorized to take action on your behalf.
From the commercial side, we continue to partner very closely with OpenAI in terms of how they view our technology as part of their defense strategy against account takeovers. And as I mentioned, the goal is to make sure that when you provide the companies with access to the most powerful models that you can add a very high amount of assurance, ensure that it is actually the right user that is accessing those models.
And other news, we continue to expand the support for different operating systems and browsers to make the YubiKey and the standard, the FIDO standard, more easy to use. So there's a huge focus on usability. A good security or great security can only be adopted at scale when it's easy to use.
From an internal perspective, we continue to make the necessary adjustments for how we view growth in areas that we see huge opportunities. So we continue to rebalance our portfolio of resources and investments to areas where we strongly believe are needed to grow the organization, which also means that we would reallocate resources to those areas. So that is reflected in some of the adjustments for our reduction in force and to really organize our organization for scale and efficiency. We see some of the results in this quarter or in the last quarter.
Finally, just to highlight, we continue to want to share details of how we grow. And we are going to have a Capital Markets Day in November. So stay tuned. We look forward to seeing a lot of you there.
A summary on top focused verticals that we have invested in and we'll continue to invest in. You can see a significant growth in the key industries over time. We continue to see this trend be fairly stable. The growth areas in the last quarter has focused on high tech and public sector, and public sector includes the defense industrial base. And the reason we see that is part of the evolution of newer threats, and these type of organizations want to be ahead of it. Technology include a lot of our organizations investing in AI. So they certainly want to get ahead of the cyberattack trends, so that they can defend against that.
We also continue to expand our relationship with our ecosystem partners, which are also our customers, but they also provide a lot of joint integrations for our customers around the world. For example, companies like IBM, for example, companies like Okta, which is our partners that deliver end-to-end capabilities for protecting user identities.
Key figures for Q2. Overall, the numbers are in line with the direction that we're going. The investments that we made to really be efficient affected clearly, obviously, our profitability. But it does also -- when you have a more efficient organization, you also affect our net sales to be able to realize those bookings in the way that we can reflect in the revenue.
And from a bookings perspective, it is lower compared to last year. Part of that journey for us is to make sure that we built resilience for differences in how companies buy, the buying cycle. So what we'll explain a little bit more is how that resilience is showing up if you get to the details.
So for example, we don't just depend on 1 or 2 deals to hit our targets. We are really looking towards making sure resilience means that we have a portfolio of companies that we can sell and make products to in all segments throughout the world in both small, medium and large. So we'll get to the detail of that. And I think we are positive in the way that we have made those adjustments to provide resilience and scale to our business.
With that, I'll hand over to Snejana for the details.
Thank you, Jerrod. So if we take a closer look at the quarter-on-quarter development versus last year, we continue to have a somewhat negative impact from the currency. But this impact is starting to subside as the exchange rates are now kind of more similar to what they were at this time last year.
So order bookings, organic development, minus 5%. Net sales perspective, we have 12% organic development, very positive growth. On EBIT, we continue to have negative impact from currency of SEK 10 million. But we have also increased quite substantially the EBIT and the profitability as compared to Q2 2025. So we've added 12 percentage points to the margin this quarter.
From an order size point of view, as Jerrod mentioned, the resilience -- the work on resilience continues and it's evident in this quarter. The small and midsized bookings developed very strongly with 18% growth. In Q2 2025, we've had a large multiyear subscription order. And this quarter, we have primarily smaller and midsized bookings, but very good growth in this segment.
Also, what I would like to mention is that we have a very strong EMEA growth. We are expanding and working very closely with our channel ecosystem and that is evident in the EMEA growth. YubiKey as a Service, our subscription offering, represent a 24% of the total bookings.
Let's zoom in on the perpetual first. The perpetual bookings grew with 7%, again, primarily deals below $3 million. And from a revenue perspective, we grew the net sales with 9%, excluding the currency impact. As Jerrod mentioned, public sector remains our largest contributor in the perpetual bookings for this quarter. Part of this is defense. And we also have very strong performance in the high-tech sector.
When it comes to YaaS bookings or Yubico as a Service bookings, as I mentioned, we had a very large booking last year with a multiyear subscription contract. This year, it's primarily small and midsize bookings orders, and the growth there is very healthy. From a subscription net sales, we continue to see very favorable development, 27% growth versus quarter 2 last year. And that is a reflection of our growing annual recurring revenue.
The annual recurring revenue bridge, if we compare year-to-date, it has grown 12%. And the growth comes primarily from expansions of our current base. So these are customers that either expand with more licenses or they might be upgrading also to a higher tier of subscription. But we also have new contracts that also drive growth. What we are very proud is that our nonrenewal rate or churn rate is quite low for the industry. So gross retention rate is 98 and the net retention rate is actually 107, driven by the expansions of our customer base.
When it comes to profitability, both gross profit and EBIT performed very, very strongly. And in both metrics, the net sales have a high impact. Even in gross profit, we do have a portion of fixed costs for the teams that work with our supply chain and logistics. So a strong sales quarter also supports a strong gross profit margin. So the gross profit of 80% is within the guided range on the higher end of the guided range.
From an EBIT perspective, we see the impact, of course, of the cost savings program and the net sales, the good quarter of net sales. So we have reached -- we have reported SEK 79 million of EBIT and 14.4%.
The cash flow for the quarter. So strong cash flow from operating activities before working capital changes, of course, driven by the high profitability. We had a negative development in working capital. That was primarily driven by higher current receivables, again, driven by net sales. While the inventory actually continues to decrease and had a positive impact on the cash flow.
The investing activities, SEK 19 million. The majority of that is related to capitalized development costs for our R&D activities. Financing activities is primarily lease obligations. So a bit weaker cash flow for the period of SEK 29 million, primarily due to the change in working capital. But we remain with a very healthy and strong cash position of SEK 1.02 billion.
And with that, I'll give the word to Jerrod to summarize.
We are driving towards the key areas that we've set out to do since we've communicated to the market earlier this year and also from the last Investor Day, really focusing on the strategic pillars, we call them. And the first 3 of them are very much about product innovation and product execution. So we continue to really focus on driving that really hard, so that we deliver the next-generation products that will help protect the organization from the next-generation threats. That's the way that we look at it.
And with that, we have the things we care about, which is the hardware. We care about the hardware. We care about the services that make organizations around adopt the hardware as quickly and effectively as possible. And that's the #2 pillar, and where we are going for the #3 pillar, which is really focusing on not just that hardware, but focusing on the user using their hardware, which is really protecting the user using the hardware.
So that if they are -- if they need a recovery solution, if they need to what we consider reenroll because of new things and new threats, they can safely identify themselves to be able to reuse and get access to the systems they need to get to. So thinking of a resilient organization. So those are the services that we want to bring to the table to help the organization be resilient as whatever new threats comes to the organization to protect the individual user, particularly obviously, the digital user identities as they navigate the new digital world.
The last 2 pillars are really about driving towards -- this should be consistent throughout the world where we continue to expand both our sales operations, but also our fulfillment operations, so that we can get to customers around the world.
And finally, we must focus on making it easy to experience working with Yubico and experience using the technology. The way to simplify to make sure that usability is top of mind to make sure that we take care of our customers in a very holistic way. So those are the key focus areas. We'll certainly dive into all the details when we get to our Capital Markets Day. So I look forward to seeing many of you there while we provide a very deep dive in all these 5 areas.
With that, I think we're going to open it up for questions and answers.
[Operator Instructions] The next question comes from Simon Granath from ABG.
2. Question Answer
Many of your peers have seen a significant share price surge in light of the Mythos moment and some talked about this giving them imminent sales tailwinds, while other anticipate the narrative to give better effects midterm. How would you describe the impact on Yubico so far? Have you seen any changes in demand over the past few months that is trickling into orders? Or is this so far only at an awareness stage? That's my first question and then I have a follow-up.
Yes. In terms of the cyber landscape, we are part of the cyber landscape. We are part of how organizations use technology to both defend and increase productivity in this particular case with the Mythos scenario, which is about how do we equip defenders with the best technology to defend the organization.
We're certainly part of that, whether it translates into exactly how things are aligned with the other cyber companies. From our perspective, a lot of the cyber companies themselves use our technology. So really is about a broader adoption of the relevance of the product globally, so not just concentrated in one market.
I would say that the way we look at that is there's 2 areas. The first area is we're part of cyber organizations or cybersecurity portfolio of products. But we continue to make sure that our technology can be available everywhere in the world. And sometimes that poses some challenges, right? We have a physical product. We have to make sure that these physical products make it to the users in all locations around. So sometimes we see that there are logistical things that we got to solve. And part of the conversation was that why do we see a lot of smaller orders and what are the conversations with regards to the larger orders.
And because of some of the geopolitics, we have a realization that large organizations, some of them do buy locally to move faster, right? So that is part of some of the impact to the physicality of the product, but also because there are geopolitics and tariffs around the world. So it changes the buying pattern. That's what we're trying to say. So demand is not -- demand continues to be strong. But how they actually get the technology can sometimes take certain detours.
In terms of the second thing that I would say about the cybersecurity is that we also have to work towards activating beyond the Mythos conversation, which is what is the new threats in terms of the -- what we call the cryptography, which is about the ways technology is built on top of the fundamental cryptography. And that is related to the quantum computing, right?
So we think about quantum computing as a next-generation of technology that would further accelerate development of all new products around the world because quantum computer can do a lot more things than, what we consider, a classical computer can do. And because of that, these conversations we're having with our customers that are in the leading edge, right? And we see that they are concerned, the market is concerned, the governments are concerned. So it will ultimately translate into customers wanting to get the latest generation of product. But there's a lot more buildup that will happen as we continue to push on that new front as well. So the long and short of it is we see demand. And -- but we don't always control every single cycle that the organizations are adapting to the new world order of adopting technology.
That is helpful. And on cost levels going forward, you have, of course, recently completed the cost savings program. But demand is now looking to improve with further tailwinds into H2 like the OpenAI mandate that you mentioned in the report. Does that improving backdrop mean that you'll start recruiting again? Or do you see enough capacity in the current cost base to capture this growth without adding more headcount?
I think we want to have disciplined growth. So what we -- we don't want to have knee-jerk reactions to everything. So what we've done internally is to really focus on where we need to invest. So we just have a disciplined approach now to think about investments and how we measure return on investments. Some of it will translate into headcount for sure. But you will see Yubico focusing on areas where it may not always be headcount, right? So we will invest. That's the story there. And some of those investments will translate into headcount.
The next question comes from Predrag Savinovic from DNB Carnegie.
I want to dive a little bit deeper in the comment around the post-quantum key, which is quite interesting. And if you could elaborate a bit further. You say you engage with some key stakeholders around this long-term migration strategy and usage, and you say that this has increased as well. What does this mean in practice? Are they translating to any commitments? It sounds very significant to us, but is it significant?
It is very significant from a technology evolution perspective for the entire world. And we are part of standardizing a lot of the algorithms or implementation of the algorithms into different technology that we created. For example, FIDO, we want to make sure that the FIDO technology, some of you may know the Passkey technology is quantum ready. So we are very much part of that.
In terms of discussions, yes, absolutely. We are working with -- you can think about the hyperscalers that are certainly concerned with this risk. Because if you think about what it means, all infrastructure that is provided online in the digital world will be impacted, right? So any type of product services that is online, whether you do compute, whether you do storage, whether you do analysis, whether you do financial transactions, like every system that is digitally bound will be impacted by a quantum computer.
So the folks that are spending the most time on this area are the folks that have the most digital assets and the most digital presence and most of them are infrastructure organizations, right? So we work with them. And it's not like Yubico can solve everything. We are part of the bigger puzzle. But by leading the way, we help bring together these ecosystems to discuss and collaborate at scale. And certainly, when those we consider them integrations happen, then we are at having the front seat to the adoption curve.
That sounds very interesting. Do you expect large orders to return? Or do you expect the medium order trend is sustained and that even large customers become more distributed in their purchasing, even one of your large tech companies that they don't buy 200,000 keys. But they get 20 and 20 and 20 again, which seems to have been the trend recently.
Yes. I think -- so the trend, I think it's a larger conversation, right? I would consider the larger conversation to be the state of the wall. And so if you collectively look at the state of the wall and then if you have protectionistic approaches, then you will see some of that happen.
But what you also see is that attacks don't really stop. It just continues to expand. And so sometimes there's an inefficiency to buy locally. And I can provide a glimpse that different companies have different strategies when that happens. Some may say, "We'll still take the local approach, which is distributed." But some become like, "We can't really do that because of the way that we model risk." And then they would then anticipate, "I want a central buy."
So I do think that the macroeconomics actually affects the way that our customers buy. There are customers at the end of the day, where our focus is to grow our business and protect more users. I would say that there are signs that customers are like deciding that sometimes distributed buys are not as effective or efficient.
So we are -- we will see that mix change over time. And I think it's really hard to predict really quarter-by-quarter. But over a long period of time, we will absolutely have large deals. This is just the reality of how if you look at our way that the companies buy in the last 4, 5 years, it's been like that. There are like certain trends of how organizations think about risk and then how do they make purchasing decisions.
So I don't want to say when. I don't want to -- but because these are large organizations with a lot of risk implications to how they adopt technology. And then we're not certainly the only company in this type of scenario. But if you look at our trending overall, yes, large deals are part of our strategy to grow.
Okay. Brilliant. And then finally, do you have confidence in that this recovery trajectory for the organic growth as you saw now in the second quarter can be sustained for the remainder of 2026?
As long as we deliver on the products that we've committed to and add the value that we believe that we can achieve, then the numbers would follow accordingly. So I -- and I've said it in the past briefings as well, and presentations, watch for our product announcements because that's the indication of our growth, right? So when we add new products that have new capabilities that solve customer problems. And we have a very strong base. These customers would invest in Yubico. So as long as we do that in a consistent way, in a scalable way, in a quality-driven way, we will absolutely grow.
The next question comes from Erik Lindholm-Rojestal from SEB.
You mentioned e-commerce as a driver to growth in the report. I mean, has there been any changes in activity from consumers after the announcement of the OpenAI partnership? And how much activity do you see from that specific channel in itself? I'll come back with another question.
Yes, mass market is definitely one of our bright spots as we grow the business for Yubico. And it does 2 major things. The first thing, it's a fantastic way for our customers to try the product without -- it's both efficient because it's -- a lot of our customers buy it at the list price, right? So it's very beneficial from our perspective.
But the more important thing about the mass market, it drives awareness because those are things that we can see immediate trends to how the growth are. And I would consider mass market not just about the end users. There are a lot of even large enterprises that buy through these mass market channels.
And we've also launched the retail business, right, in U.S., we are launching it in Europe as well. We want to make the technology available to customers how they want to buy. Because when you get attacked, you really don't sometimes want the inefficiencies to go through a certain process to get a product. You need to get going right away, right, in certain scenarios or you want to try it out in a certain way.
So we want to meet the customers where they are. But the exciting thing about the mass market itself is it really generates the -- I consider the self-awareness within an industry because people can talk about it in forums and it's available. And what we want to continue to invest, particularly in the mass market is to make more venues where users can buy easily, low friction and then help them curate the stories, which means a lot more education and how to set it up and how to use it type of approach, which is self-service.
So when we get a self-service engine going -- and I consider product-led growth here. Once we get into some of these product-led growth capabilities, we will really see that engine actually help significantly also in our enterprise business or large deals. So it's hand-in-hand. It's not a separate type of motion. We consider it the Yubico motion. In some ways, the tip of the spear, our indication of the future or whether there's a market, there's a customer base, there's a certain trending. We get a lot of that feedback from the mass market numbers. So that's very encouraging for sure.
All right. That's encouraging, as you say. I mean you have spoken about post-quantum readiness at length in this call. But I guess this is mainly an eventual feature of the YubiKey 6 perhaps. And I mean, what does the time line look for an eventual -- how does the time line look for an eventual release of the YubiKey 6?
Stay tuned at Capital Markets Day.
All right. I'll be there. Exciting. I guess also on that topic, I mean, Anthropic stated that they have found some weaknesses in some of the proposed post-quantum cryptographic algorithms. I think HAWK was the one that they found some weakness in using Mythos. I mean, does this imply any changes to your plans for post-quantum security? And how do you think about achieving post-quantum security in a world with advanced AI models?
Yes. So again, it's double-edged sword. I mean, we will use these models for creating better defenses. And these models can also be used to also attack. So it's always double-edged sword for very powerful models. It doesn't change the fundamentals of Yubico being the need to deliver a YubiKey with post-quantum capabilities, right? So we are committed to that. That's definitely part of our -- I guess I described our Pillar 1, which is our hardware root of trust. We must deliver that.
In terms of what this particular thing means is that when we build products, we must be -- we consider crypto-agile. We must be able to implement new crypto standards as it evolves. Nobody can guarantee that any cryptography is safe forever, right, particularly with these capable models that can break down the cryptography itself.
Our goal is to make sure that we work with the ecosystem. And then if the ecosystem and the standards bodies agree, we are first to implement it. That's our commitment. So just like before, I mean, before Mythos, right, we had weaknesses in the previous type of algorithms. The RSA algorithm had weaknesses. We had -- again, when computers become more powerful, they will break everything that was created in the past. So this is not a new situation. But the difference is that the speed of finding these things are much faster and much more efficient. So then we can also use the same powerful models to create better cryptographic modules as well.
So I think it works hand in hand. It doesn't change the way that Yubico looks at our future on delivering the most innovative hardware. It does require us to work more efficiently with both Yubico internally, but also with our partners around the world. So it's just a call to action to work more closely with all the other cyber companies around the world.
Great. Just a final question perhaps. Perpetual bookings looked strong in the quarter. Was most of this shipped already now in Q2? Or are you entering the second half here with some order backlog?
No, not everything was shipped from Q2. So we do have some backlog. The good net sales were, of course, both supported by the good perpetual bookings, but we also had backlog from before. So we do have some backlog for the coming quarters, or from the coming quarter.
The next question comes from Thomas Nilsson from Nordea.
I'm wondering if you can comment on the size and quality of your enterprise sales pipeline today? Are you seeing larger deployments, shorter sales cycles or higher win rates now as compared with a year ago?
From a large opportunities perspective, we always continue to pursue that. I think that hasn't changed since I've been at Yubico, we've always been a focused with a passionate organization, very focused to ensure that we have the engagement with the most -- the largest companies in the world. So that will always be part of it.
In terms of your question is kind of why now, why or where this is going to happen more? As I've described before, like, buying a large amount of technology has a certain cycle. And so if you look all the way into -- back into 2023 or all the way back to the pandemic where there were -- like there's a lag and then there's like changes and then people buy in big amounts. So we will continue to see this cycle. And we believe that sometimes the way that we've described it in the bookings doesn't really fully reflect like what's happening behind the scenes.
So my -- our comment on this is that we haven't changed our go-to-market strategy necessarily. We haven't changed the way that we approach these large organizations. What typically is happening is that there are different buying cycles that don't lend to how any company report the numbers. So large deals sometimes can happen really fast because of an incident or ecosystem problem. And people want to move very, very quickly or sometimes they kind of take a while because they just don't have the same type of urgency. But the demand is always there. It's just the buying cycle changes depending on a number of factors here. But part of it is internal, part of it is macroeconomics, part of it is just headline news of attacks.
So it's a very complicated way that some of these customers buy or make -- sorry, complicated way that they make large purchasing decisions. But certainly, it's in our portfolio of companies that have buy. And we believe we'll continue to do this pattern, just not sometimes the time that we want them to buy.
Okay. And a final question from me. With regards to the OpenAI collaboration, would you be prepared to state like any tangible effects you're seeing on demand for YubiKeys from this? Are there any growth numbers you can share that relate to that OpenAI collaboration?
No, we don't have any numbers just specifically with that, and I will give you kind of insight with that. There is a specific package that we have offered with OpenAI, which is very, very geared towards like individuals. So like think of an individual that wants to protect their ChatGPT account, which is a little bit different than an enterprise, right? Enterprise has a different set of requirements that they want to protect their employees or maybe their supply chain.
And so what we see is that there's a lot of spillover. What that means is that customers engage us because they want something else besides the default package that was provided and they want some special thing that is very unique to the enterprise.
So what the real effect on for this partnership is really create the right focus on security of protecting an organization, which is the awareness and the relevance and the endorsement. And we see that translated into a lot more enterprise conversations about what it means to protect themselves.
From an overall perspective, we also see sometimes people buy the products on our other e-commerce platform because the promotion is actually not global. And so one of the things that we are planning to do is make it more available to users around the world, which will help get it where it needs to go. So we've only launched it in the U.S. and parts of Europe, but there's a lot of demand, for example, in Asia and we actually don't have this type of promotion in those regions. So we hope to continue to evolve where we can help customers get it. But again, the short story there is we want to invest in global coverage wherever the users are.
There are no more phone questions at this time. So I hand the conference back to the speakers for any written questions and closing comments.
We have 2 written questions. The first one is well done on the quarter. Please, can you remind us of the revenue recognition policies for both subscription and perpetual revenue streams?
Yes, of course. When we sell our perpetual, then we recognized the revenue at shipment and delivery. So the revenue recognition depends very much on the shipment schedule and delivery schedule. Small orders, typically, we are able and the customer is able to receive them very -- in a short time frame when they place the purchase order. When we have large enterprise perpetual order bookings, the shipment schedules might be over several months, depending on the deployment schedule of the customer.
When it comes to subscription, the subscription is an obligation over the duration of the contract. So when we negotiate a 3-year or 5-year duration of a contract, we're reporting the order bookings, the total contract value over this period. But when we recognize the revenue, we recognize it over these 3 or 5 years. So the subscription order bookings and the subscription revenue is very different. We always need to think about the order bookings is a total contract value, while the subscription net sales is the revenue recognized in the period.
And I always sort of tend to encourage analysts and investors and people that are interested to look also at our annual recurring revenue for subscription because this is truly our 12-month forward-looking indicator of what our net sales in subscription -- how the net sales in subscription is developing. I hope that was clear.
There's more -- we still keep the -- last year in the Investor Day presentation and the material there. There's been quite a comprehensive walk-through in our revenue recognition policies.
Very clear. And the next question is, can you say anything about the reception so far of the new product, 5.8 and the new FIPS released in May?
The reception is positive from the customers that care about these type of capabilities. And so the FIPS devices are very focused on our public sector customers or customers serving the public sector. So definitely, there's been a lot of movement in terms of continued interest and adoption of the new products there.
In terms of the 5.8, it's really seeding the ecosystem for new use cases, which is very important for us. So 5.8 has some new capabilities that it enables developers to build new things. So in our perspective, demand will continue to accelerate when the YubiKey works with more things, more use cases, more services. So we consider the build phase of our portfolio. And sometimes the keys solve a specific market problem that is needed. But sometimes devices that we release are to seed new use cases, which is solving new problems for the ecosystem, which is what is going to build new pipeline. So we always deliver on products that have these type of goals in mind, where one is seeding, one is execution, one is seeding, one is execution, right? So it's a bit of that going on.
What is very different is that for Yubico this year, it's been a huge velocity, which I've mentioned to a number of you already that that's my goal to deliver on these products at a higher cadence with a high velocity with higher quality, which is what we're focused on because typically, we release like 1 YubiKey every 2 years. So the scale of our operations and execution, I believe, is moving in the right direction. And that would continue -- if we do that, we'll continue to translate into business growth.
Thank you. There are no more written questions.
Thank you, everyone, for joining us. We look forward to seeing all of you or if not most of you at our Capital Markets Day or our next report. Thank you.
Thank you.
Transkripte auf Deutsch freischalten
- Alle Event Transkripte auf Deutsch
- Sofortige Übersetzung
- KI-Zusammenfassungen für die wichtigsten Insights
Yubico — Q2 2026 Earnings Call
Yubico — Q1 2026 Earnings Call
1. Management Discussion
Welcome to Yubico Q1 2026 Report Presentation. [Operator Instructions]
Now I will hand the conference over to CEO, Jerrod Chong; and CFO, Snejana Koleva. Please go ahead.
Hi, everyone. Thank you for joining us for our Q1 2026 briefing. I am Jerrod Chong, the CEO of Yubico, and with me is Snejana. We are going to walk through the agenda. I'll give a quick recap of our company overview. I'll talk through our Q1 highlights. Snejana will focus on the financial overview and deeper insights to the business. I will then close up with our remarks, and we'll be opening up for questions and answers.
Quick overview. I think most of you are aware we are expanding our organization. We made adjustments to our workforce to be more efficient as reflected in numbers. We want to really commit to the investors that our growth trajectory is priority, and we also want to make sure we are paying attention to our gross margin as well as our EBIT.
Quick market update trends. I think most of you are very familiar with what we've announced 3 days ago with OpenAI and the partnership. What we see is clearly in terms of how the AI-enabled world is impacting the cybersecurity world. We can see that attacks are being much more scaled and precise in the way they are targeting accounts and how they take over accounts. What we also see is that while there's great tools for a lot of organizations to be able to defend themselves, what we see is that the tools are not even, which means the attacker actually have the advantage of the tools versus defenders. And the reason we say that is that when you identify a problem, it usually takes the attacker (sic) [ attacked ] much longer time to find a solution and fix it rather than attackers, who can just attack right away.
So what this means is that we are going to see or we are seeing a massive amount of increase in attacks, specifically very, very targeted and scaled phishing attacks. And we believe that with the announcement, not just about the partnership, but clear message from OpenAI that they themselves are using our technology. It is really clear that the foundation for how companies need to protect themselves and defend against attack is with our technology.
Highlights from the quarter. I think it's always important to talk about development as it pertains to how we grow our business from the perspective of product innovation and product capabilities that we provide to the market and key partnerships as we accelerate the business. As discussed, we have already announced the OpenAI partnership, and isn't just about, again, the program itself, it is a long-term commitment with OpenAI to protect more users in this fast-changing AI world. We've also announced other partnerships with big organizations like IBM and Auth0, which is part of Okta, in terms of how we work with the broader ecosystem to protect more enterprise users.
We've also made some operational efficiency decisions. We have to take accountability for the investments we made in '25, not as successful as we intended, making the corrections to be much more effective and efficient as we scale the organization to produce capable new products and penetrating new markets. And finally, I'm very proud to be appointed as the Chief Executive Officer in the permanent role, but also very excited to have Poupak Enbom, who joins us as the new Chief Marketing Officer to really help us expand and accelerate our go-to-market activities.
A quick 1-year look back. As I've described in a previous briefing, my focus is to really deepen relationship with customers. I think Yubico's foundation for the future of how we protect many organizations starts with our strong customer base, and I'm very proud that we're building very strong customer deeper relationships as evident by the OpenAI partnership. But beyond that, we're also very excited to continue to launch more new products. And it isn't just about launching new products to launch a product. It is about adding a lot of new capabilities that our customers want from Yubico to make sure that they can protect their organization and their users much, much more effectively and accelerate the adoption of the technology with as little friction as possible.
So you can see in the milestones wherever the word YaaS, which is Yubico (sic) [ YubiKey ] as a Service, that is a huge expansion of the ability to reduce friction to adopt the technology. And what you also see is that we've established additional capabilities to be very relevant for certain markets where they need something specific for regulation and compliance. We've launched the CCN product series, specifically for the Spanish market in Europe. Europe is a huge opportunity for growth for Yubico's 2026 ambition, so we are providing capabilities that are very relevant to that market.
And finally, we've continued to expand on our broader ecosystem for channel and distribution so that we can cover and expand globally with not just effective more troops on the ground, but more effective enablement where they can understand the value proposition of our products in the field.
Q1 saw a huge uptick in our public sector. There is a war that we are facing in several parts of the world, and this has increased defense spending and we see some of that investments in that sector. We continue to see a strong pipeline in the public sector and defense sector as things continue to get very heightened because of cyberattacks as part of overall warfare.
So we are very much invested to make sure that the defense sector and governments and militaries all over the world can successfully use our technology. Obviously, there's no indication of not investing in the other industries and areas of growth. We still see very strong demand in finance and technology with retail and manufacturing flow -- following very closely behind.
Some of the figures here for Q1. We continue to invest in YubiKey as a Service, and that is evident in our growth in ARR. We continue to be much more refined in the way that we produce products and go to market as what we try to focus and build upon on what we've stated before, which is to bring our gross profit in line with our expectation. And the profitability itself continues to be an area that we want to focus to do better.
Overall, with the announcement of OpenAI, it gives us really the product relevance for not just with the top AI companies, but every company that is going to invest in AI has to pay attention to what the most influential companies in the world are using to protect their workforce and their users.
So we're very excited to continue the partnership and also continue to work with new partnerships that we will announce as well throughout the year to accelerate and bring awareness to our technology.
With that, I'll hand it over to Snejana.
Thank you, Jerrod. So let's deep dive a bit further into the financial results for the quarter. I'll start with sort of quarter-on-quarter development of our order booking, net sales and EBIT.
As we saw in the key figures slide, the negative currency impact continues this quarter as well, both on order bookings and net sales. The organic change in order bookings is 14% down and net sales is 10% negative organic change. When it comes to EBIT, we have in the quarter SEK 14.9 million or 3.1%. If we compare to the Q1 2025, we have a negative currency impact of SEK 26.5 million and the cost for the reorganization program of SEK 21 million. So the like-for-like change organically in the EBIT is negative SEK 30 million or 5 percentage points we are missing.
If we look into the order bookings, this quarter Q1, we still see the small and midsized transactions are the majority of our order bookings. The larger enterprise deals are taking still longer time to close and we don't have large deals above SEK 3 million in this quarter. On the positive side, EMEA has developed very strongly, delivered solid bookings and YubiKey as a Service represents now 12% of the total bookings.
One step deeper to look into the perpetual bookings. The perpetual bookings are 15% down versus Q1 last year. You see again continued trend of small and midsized transactions in perpetual orders. We see in these orders strong growth actually in e-commerce and EMEA as well performed well, while the large enterprise deals in Americas were -- take longer time.
The sales follow closely the perpetual bookings. And we're happy to see also that the repeat purchases from existing customers are representing roughly 80% of the perpetual enterprise order bookings. This is clearly sort of an evidence or testimony of our strong customer relationships and deepening these relationships, as Jerrod already discussed.
If we look into our business model with subscriptions, the subscriptions bookings are more volatile. And in Q1, it's typically a bit of a slower quarter for subscriptions as customers are sort of taking multiyear commitments. So we see -- in this quarter, also, we don't have like big subscription orders above SEK 3 million, but we do have midsized between SEK 1 million and SEK 3 million in subscriptions.
It's very worth mentioning that SEK 22 million of the SEK 47 million bookings is renewals, which we are very proud and satisfied. That means that our customers continue to renew their subscriptions on a multiyear basis. The quarterly net sales from subscription actually has increased with 29%, excluding the currency impact. And this is very much driven by our increase of annual recurring revenue that we have booked or that we have reported during the previous quarters.
So if we look at the annual recurring revenue development versus the last quarter Q4 2025 and adjusting for the currency impact, on a like-for-like basis, we are growing with 4%. We have a gross retention rate of 99.1% and a net retention rate above 100% at 102.6%, which is great in terms of kind of securing that we continue growing in our subscription sales going forward.
And I will add one comment on this part. So it's really important as we -- the reason for such a strong retention rate is the capabilities that we're delivering with the product. As you saw earlier -- I described a new -- almost every quarter, we're delivering something with our subscription. So it really isn't subscription necessarily. It's the value that we add to the product that then translate into customers not just wanting to renew, but then also expand their deployment. So for us, the value creation is much more important from a product launch and release perspective, obviously, than just saying subscription or ARR.
So that's why we see that strong focus on the growth, very, very low churn and the continued expansion. Obviously, our focus now is to make sure that this capability is available throughout all the markets that we do business. And that's been one of the gaps that happened in '25, this capability of product offering was not available everywhere. So we're really expanding to all -- a lot more markets where customers can realize the value of the product.
Thank you, Jerrod. Moving to our profitability, gross profit and EBIT. Gross profit has been fairly stable, and this quarter, it is within the expected range of 75% to 80%, at 76.8%. We do have some fixed costs in the gross profit. So it is impacted a bit downwards when we have lower sales. The expenses below gross profit, if we compare, if we look quarter-over-quarter, they developed favorably, especially if we sort of take into consideration that we have SEK 21 million costs related to the reorganization program. The reorganization program is expected to deliver gross savings of about SEK 95 million on an annualized basis, and we expect these savings to start already in Q2 2026.
EBIT, as I started with, it's SEK 14.9 million, 3.1%. It is impacted by the lower sales volume, of course, on an organic basis, but also SEK 26 million in negative currency impact and SEK 21 million cost for the reorganization program. So sort of on a drop-through from sales volume, it shows kind of the a bit favorable development on the expenses side.
Cash flow. From a cash flow perspective, we had actually quite a strong cash flow generation of SEK 70 million in this quarter, very much supported by the changes in working capital. Both inventory releases and accounts receivables are reduced as compared to the previous period, and hence, the strong cash generation. The investing activities include R&D development costs for our R&D, very prominent projects. And we continue to have very strong cash position.
With that, I will hand over to Jerrod.
We are very focused on the key areas of growth for us as described in the -- since last year, we had an Investor Day. This year, we have focused on how to really get the position on delivering on all the things that we've communicated.
A quick recap on the 5 areas that we are really, really doubling down on. The first pillar is about the YubiKey. The YubiKey and everything that is making, delivering, creating is our core for how Yubico continues to grow. We are investing heavily in our next-generation product. You will hear much more about that as we get towards the second half of the year. But with that also, we invest in certifications, which is relevant to different markets where it requires specific validation. As I've described, the CCN certification is specifically for the Spanish market, and we'll continue to do certifications to be relevant for compliance-driven customers for purchasing.
The next pillar and strategic area is the YubiKey as a Service. You see that abbreviated in the presentation as YaaS, Y-a-a-S. That is our offering to reduce the friction for receiving, managing and delivering on the hardware security key, YubiKey, in terms of how to adopt faster. There's a lot of friction sometimes when customers are wanting to deploy the technology around the world, and this specific capability is to reduce the friction all over the organization for easy adoption.
Area #3, which we are very excited as well, which we will provide much more color and description as we move into the second half is our digital identity services, a part of the Yubico ID solution which is more focused towards how do we protect users and provide them capabilities beyond just the YubiKey and technology itself, which is about digital identities, digital wallets and digital identity verification. So I'm very excited to invest more in this area, and we'll share more in upcoming briefings.
The fourth area, which is where we have also started to invest very heavily as announced, we have a new Chief Marketing Officer to really focus on educating the market, bringing in awareness and also reeducating in certain areas so that everybody understands the value of the technology and relevance, especially now with more phishing attacks throughout the world.
And 5 is really very dear to me. I've spent a lot of time with customers and hear about their pains and I hear about their challenges and how they want Yubico to help. So for me personally, it's about working closely with companies like OpenAI, companies that have huge, huge user base, huge internal workforce and providing them with solutions. But also when we solve some of these big challenges for them, they are our strongest advocates and strongest champions, so they understand and help other organizations be protected.
With that, we will open it up to questions from everyone.
[Operator Instructions] The next question comes from Simon Granath from ABG.
2. Question Answer
Congrats, Jerrod, to the permanent CEO role. Could we initially just touch again on the subject on how AI is impacting demand for your products, especially in light of recent industry discussions around models such as Claude Mythos? Have you seen any changes in the customer dialogue since this Mythos discussion started about 1 month ago?
Yes. Thanks for bringing that up. If you have noticed the OpenAI announcement, which is about the Advanced Account Security, you will notice one specific callout, which I think a lot of media did not pick up, and I will explain that to you. As part of this account Advanced Security -- or Advanced Account Security, they have announced that in their Trusted Access for Cyber, which is OpenAI's equivalent to Mythos, they are mandating that every account accepted to the Trusted Access for Cyber must be using the Advanced Account Security.
And obviously, we are the recommended solution if those customers use the hardware security key. So we are part of this Trusted Access for Cyber program, which is OpenAI's equivalent to Mythos.
And I can tell you that there's a lot of buzz in the industry because the current access for Mythos is not, we believe, at the highest level for access. And that is not where the industry needs to be. Because if you think about access to these very, very capable tools and if an attacker got access to that tool and become you, they would -- can do some very serious damage to an organization.
So we believe that OpenAI's approach to really lock down access to these very powerful models for cyber defenders is very critical. We call that security by default setting that industry needs to follow.
Appreciate it. And then I had the question on the cost base following the ongoing reorganization. Could you do more cost adjustments if demand does not pick up? Or would that then impact the long-term position of the company?
So I think we've done -- in quarter 1, we've done quite a sizable reorganization to make us both more sort of efficient cost-wise, but also efficient execution-wise. I think it's part of our sort of management oversight to continuously be very mindful of our cost base development. But I think for the time being, it is -- the reorganization is what we have executed. We need to land in the new organization. And we, of course, continuously monitor our costs.
Okay. And just a final one from me, if you don't mind. You have now started to see some signs of recovery from the U.S. public sector. How far have we come? And do you expect this trajectory to continue?
I think nobody can predict how the administration would continue to work through their approach. What we can say is that the customers that we have in the public sector are very well aware of the gaps when you underinvest. In terms of the funding, we cannot give any comments because we actually don't know. Obviously, there are some areas that have moved faster and have positive movement there. But it's very hard to say in terms of like is this the direction every month, every quarter. But we know for sure that our customers have felt the impact of underinvesting in cybersecurity. And that is one of the things that can impact national security, which then helps reprioritize funding when it's available.
The next question comes from Erik Lindholm-Rojestal from SEB.
A couple of questions from me. So just circling back to maybe Simon's question, but I mean AI as a threat really is happening right now and really increasing the volume of attacks as we speak. I mean, given this, why do you think that customers are postponing their purchasing decisions? Shouldn't there sort of be a sense of urgency? And also maybe on that point, I mean do you feel confident that you're not losing any deals to competition and that customers will come back to you?
Yes, in terms of urgency, I think customer voice is much more impactful than Yubico's voice. So the impact of the announcement isn't just about the announcement itself, it's really to show relevance of the technology. And that the foundational piece of AI that OpenAI has created is such an impactful global phenomenon and the fact that they are using our technology to protect their own workforce and supply chain is evident that everybody needs to pay attention.
In terms of how overall the market is perceiving it, I think there's still a lot of considerations for good enough. And that's -- to some extent, whether you consider a competitor or not -- I mean, good enough means just I don't really want to do anything unless I have to do something. And sometimes they're just using not very good technology. So the call to action is, again, not so much about we can say this as a vendor all the time, but our goal is to make sure that we amplify our customers' voices and why they're doing it.
And so you can start to see some of these customers coming out to really talk very positively about why they do it. And so this is evidence on how we can get other organizations and companies to invest and not wait, which is usually the status quo.
All right. Great. I had a follow-up on the OpenAI partnership. Could you perhaps shed some more light just on exactly how this works? I mean, do they get any cut from the YubiKey that customers buy when they use the link on their platform? And also perhaps if you can elaborate a bit on what your hopes are in terms of sales from the partnership. That would be great.
Yes. The first comment I have is this is not just a launch and then we are all moving our separate ways. So there's a continued conversation on additional use cases with OpenAI. But more importantly, I'm working with their stakeholders as a longer-term partnership to help protect more users.
We won't comment exactly on how all the mechanics works in the commercial teams, but I can assure you that expanding the use of the technology to protect more users is the best interest for both companies. And for that matter, it's more than OpenAI. I think the industry has realized that just using the not-so-good current solutions to log in for many, many different services like SMS is not a good solution.
So being able to push phishing-resistant technology, specifically with hardware security keys like YubiKeys are the most impactful, most secure option available. So I would say stay tuned. We will continue to work with more organizations, but also with OpenAI specifically, more use cases that we will announce.
Okay. Great. And then just cost -- on the cost savings program, it would just be great if you could elaborate on which areas this is targeting? And then perhaps -- I mean, is it reasonable to think that this will have a full effect already from Q2? Or is it more so a H2 impact?
We have taken a look and actions basically across the organization. So there is -- all departments have to look into their sort of needs, resources, et cetera. So it is not only one department. It is across the board. The processes or the program as such is largely completed. So the savings should be realized already from Q2.
The next question comes from Predrag Savinovic from DNB Carnegie.
And also congrats to Jerrod for -- on your new role. And on bookings, so what do you think it takes to see bookings on an aggregate level return to double-digit organic growth rates? Is it the market improving? Is it the launch of new products? Is it your selling execution? What do you think is the most important factor here?
I think it's all that. I think you hit it. So thank you for your congratulation note. We look at it as multipronged to grow the business. You must have a strong customer base, because if you don't have a strong customer base, then they won't invest with more products you deliver. You have to deliver on new products because there are new growing threats that you have to address and reduce the friction of adopting the technology. And sales execution has to be more precise, being able to provide the information in a way that customers can understand and adopt and deliver around the world.
And then finally, I think the broader ecosystem is necessary to support our strong growth ambitions. So one of the things that I reflect a lot is we should be in certain markets much more than where we are today. So we also have -- again, we've opened up our Singapore HQ as we discussed in the last briefing. And then being able to support the region in a much more intimate way has always been our goal. So we need to really realize the investment for the region and expand our business. So I do believe it's all things that we've communicated and then being able to deliver very, very precisely on all the things that we have committed to the community.
That's very clear. And with the launches for new products like the Quantum Key, for example, what does that mean for your chip supply inventory level as an overall level? Is there any effect we should be aware of on COGS, gross margins improving or same level, lower? What can you say there?
A very good question. The new key is going to be on a different platform, which means that we will -- the plan is to start ramping up manufacturing during the second half of the year, including buying the new chips. So from that perspective, we'll be ramping up on that level. But at the same time, the idea is that we are reducing the inventory on the previous while we're ramping up on the new platform. From a COGS perspective, we don't expect a major difference basically.
Okay. And then back to bookings again. In Q1, has there been some deal slippage? And what was the size of it? And can you discuss somehow how Q2 so far has started, if it's on the kind of same trend as the last few quarters, above trend, under? Any general comments there?
A general comment is that the Q1 had one of the sizable deals slipped to the next quarter, and then it did close shortly after. In terms of the overall trending, I think from a pre-OpenAI announcement to the post-OpenAI announcement, activities are slightly different. But in terms of how we look at the business, certainly, what we see is activities happening in terms of volume. But of course, that is not reflective of obviously closing. But we are confident about the relevance, which is really, really important, and then the realization to not just settle for good enough. So we see that interest peaking for sure, given the recent announcement.
The next question comes from Thomas Nilsson from Nordea.
You have a very substantial net cash position. Do you see any interesting opportunities to expand your product and service offering through M&A? And what could be of interest to you in terms of adjacent product and service opportunities?
Yes, we are aware of our strong cash position. We are exploring different options as an organization. And then I would call attention to the Item #3 in our discussion of strategic areas. In terms of like what type of companies, we're not at liberty to share, but you can infer that the item -- strategic Area #3 is where we see areas of new growth and new markets where we can add value. We see that clearly because our customers have -- existing customers' installed base has indicated a strong interest in our expansion.
Okay. And a final question from me. The booking decline was most pronounced in Americas. And was this mostly timing, macro hesitation or a structural change in enterprise demand? And what evidence do you see that larger enterprise activity can recover in Americas in the second half of this year?
I think from an overall growth perspective, what we see in Americas is a very strong demand for YubiKey as a Service. And strong demand for YubiKey as a Service creates different way of interpreting what we measure because from the perspective of YubiKey as a Service, the contract cycle to review is longer, but also the way of investing is also a little bit different.
What we can say is that the type of pipeline that we are seeing from Americas has now surpassed 50%, which means there's a very high interest in that technology and that product offering in a, what we consider, maturing significantly market. Whereas, in Europe, I think it's getting started. So strong evidence that the value that we're creating for the subscription or YubiKey as a Service and companies buying the offering through subscription is a huge driver.
The next question comes from Georg Attling from Pareto Securities.
I was just wondering about -- I mean, we have the YubiKey 6 coming up for the new platform, whatever you're going to call it. Do you feel in any way that, that upcoming launch is holding back enterprises from placing large orders on the current platform?
And then second question related to that, when you do launch a new line of keys, a new platform, so to speak, what do you typically see from your existing customer base in terms of replacement rate? Do they all buy the new product? Or are they usually happy with the one they already have?
So the answer the first question. So one of the key benefits of the YubiKey as a Service is the ability to upgrade to the new platform, and, obviously, not all tiers, but the highest tier. So we are seeing that customers are -- we are moving our customers to go to the higher tier as they want to realize the benefit.
In terms of how our customers view the new technology, I think there's variations in how our customers view transition. So one of the key focus areas for us is to make sure that when they do want to transition, that they have the ability -- that we can help them with the ability for the transition. And it's not just about buying the new platform because the deployment is as important as the new platform devices. So we are -- obviously, we haven't finally released the name yet, but we can think about YubiKey 6. It's not just about I have the YubiKey 6 in my company, but how are you going to get that new product in the hands of all the users around the world. So what we want to do is to make sure we really accelerate that friction -- or reduce the friction to adopt the technology.
Yes. That's good color. And on order bookings, I mean, you again state that conversations are taking longer. Are these the same conversations that you've had with the same customers for, what, a year or so now? Or those old discussions didn't they render any deals and what you're talking about now is new discussions, let's say?
I think there's always new discussion with new customers and existing customers that want to get more value with new things. So as long as we keep on releasing new products, then we keep on getting more conversations about expansion. So I will say it's new prospects as well as existing customers.
Okay. Are there any of those prior conversations that have ended without an order? Or do you feel like most discussions that you had are still ongoing without the decision?
Most conversations are still ongoing.
Okay. And on the visibility in terms of order bookings, how good is that? I mean I expect it's quite difficult to predict when they're actually going to place the orders. But do you have any feel for timing of those larger orders coming back? Are we talking first half, second half this year? Or impossible to say?
I think we're not going to comment on it right now. Everyone will know when we have those orders. Again, I think one thing to take away is that the demand is very strong and our customers are engaged.
Yes. Just a final question on Yubico ID. I mean you talk about this a lot. How should we think of the timing of the scale up? Is it also something that we should expect in coming months? Yes, any color here would be great.
We will provide more information when we announce the product line.
There are no more phone questions at this time. So I hand the conference back to the speakers for closing comments.
I want to thank everyone for joining us today's Q1 briefing. We want to close out by saying that we're very excited with what we are offering to the market with some new focus on our company based on the OpenAI announcement, and we will continue to invest in the product and the capabilities so that more users and customers around the world can adopt it. Thank you, everyone.
Transkripte auf Deutsch freischalten
- Alle Event Transkripte auf Deutsch
- Sofortige Übersetzung
- KI-Zusammenfassungen für die wichtigsten Insights
Yubico — Q1 2026 Earnings Call
Yubico — Q4 2025 Earnings Call
1. Management Discussion
Welcome to Yubico's Q4 2025 Report Presentation. [Operator Instructions]
Now I will hand the conference over to acting CEO, Jerrod Chong; and CFO, Snejana Koleva. Please go ahead.
Hello, everyone. Thank you for joining for our Q4 2025 presentation. I'm Jerrod Chong, the acting CEO of Yubico. And with me, I have Snejana Koleva, who is our Chief Financial Officer.
Good morning.
We want to cover a few topics here on the agenda. A brief quick overview of the company, our Q4 '25 highlights, a bit of the financial deeper dive, and then I'll provide a set of concluding remarks, and we'll have the Q&A session open to the floor.
I'll start first with a quick glance of our company. We have been in business for 19 years. And one of the things that we are very proud of is our customer base. As you can see, we have over 4,500 business customers and millions of consumers around the world. We are also really proud of being able to grow our business. We have our net sales last 12 months at SEK 2.2 billion. We see a strong continued growth over a period of time with our CAGR at 30%.
We also are growing rapidly our ARR. Our subscription business is really growing by adding more value and services around our subscription business. We see that growing very significantly over the last 4, 5 years. And really, I'm really proud to talk about the technology where we protect millions of users around the world with the open standard we created, FIDO open standard, and a lot of you might know it as passkeys. We are the co-creator of that technology and that standard, and it's really a remarkable standard because it really creates a very strong phishing-resistant organization and reduces account takeovers significantly.
Next slide, I wanted to give a quick view on where we are and where we're going. We play in the advanced authentication market. We have the YubiKey, which is our flagship product that is a hardware security device. We have been building this product line for many years. We are in the fifth generation. We'll be getting our sixth generation product by later this year.
And with that, we are also expanding our product portfolio into -- expanding into digital identities. Advanced authentication is part of the identity and access management ecosystem, and we see a lot of momentum that our customers want us to provide products as we expand protecting digital identities, and we want to offer more products as we move into the digital identity space.
In this picture, you can see on the left side, a picture of the YubiKey in black with the gold disk that is our flagship product. And we have a variety of different form factors from very small devices that sit neatly into your laptop and you don't even know you're using it. But one thing that is very, very clear, this is the highest level of protection that a user and an organization can use to protect against various phishing attacks that we see very widespread, particularly now with a lot of AI attacks. And this is a clear need to have these type of technologies to prevent some of the most sophisticated attacks in the market today.
On the right side, as we created the open standards, we work with many, many different technology partners and applications. And you can see this is just a swath of the applications that works out of the box. And it's really important when you think about enterprise adoption, they don't want to spend time configuring things and like installing different agents and things like that. They just wanted to work. We wanted to work with the things that they have every day. So we're really proud of all the different integrations, business applications, consumer applications alike to be able to protect them out of the box.
This slide, we're really proud when we look at our overall portfolio of where we have a presence. We see a much more balanced portfolio of industries that adopt the technology, particularly if you look at from the '25 portfolio perspective, really seeing a balanced portfolio from financial sectors, the governments of the world, high-tech sectors, including cybersecurity companies and AI companies that adopt the technology. And we also see a good growth in the manufacturing side of it in terms of manufacturing and the retail side of the business. So a very balanced portfolio, really excited to be able to diversify our portfolio from what when I joined 12 years ago was pretty much only one sector of the business, which is the tech sector. So really, really excited to see that progression continues as we move into 2026.
A quick glimpse of our Hall of Fame, and it's certainly not all of them, but certainly, you can see a reflection of the different industries reflected here in terms of both very large organizations, international business as well as a swath of smaller but also very impactful companies that we've helped protect and they continue the journey with our company as we grow and scale our product line.
Let's get to the meat on the highlights of Q4 2025. I take a step back. And when you look at Q4 2025, one thing that really stands out is that this is our best bookings quarter ever at Yubico. If you remove the currency headwinds, it's really important to recognize this milestone, cutting through the noise, getting it done in Q4 '25 is a really important milestone for us.
Well, if you peel back the layers a little bit and what is going behind the scenes, we know that we have strong subscription and ARR growth. And this is important because it not just sets us up for like the current quarter, it sets us up for the entire next 12 months. It's a really important indicator of some of the longer-term growth that we want.
One of the key highlights of that strong growth was a big subscription deal that we closed in India, which is a new market for us or we invested -- it's a fairly new market for us, and we invested some boots in the ground, and we see these results when we invest in the region with the people and the amplification of what we do to the market.
Also reflected here, we talk about generally what we're going to do as we get to 2026. We want to make sure that we are accelerating our product offerings. There are many things that we are planning to do. I'll call out one of the products that we announced or released 2 days ago, a very specific capability for the Spanish market. And that is a very important deliverable that we need to do to make sure that, that market is meeting the requirements or meeting the requirements of the market. So we're going to continue to see a lot of product velocity with scale and quality as we head towards the rest of the year. One thing that's not reflected here, and I'll call it out is we see a strong base of our small and medium businesses as we grow the overall pipeline as well as the execution of our go-to-market strategies.
A bit of self-reflection of where we are right now. I took over this on December 18 to lead the organization. I've been at the company though for 12 years, and I spent an enormous amount of time with our customers, and I plan to continue to do that. I think it's important to make sure we understand or I understand where they're going, what pains they have and how can we develop products and capabilities to help them mitigate some of the new risks that they are seeing.
Very focused on product innovation, as I've described and be able to bring that out to the market so that our customers can realize and protect themselves better. Of course, I want to make sure I focus on the customers, but more specifically, we actually have a very strong customer base. And one of the things that we start to see is that we want them to be very proud of using our technology and come out and talk about not about the product necessarily, but about the partnership that they have developed with us over the years and why do they continue to use our products. I think that's really important for us. And obviously, the new customers as well, we are very excited to talk about their use cases when they deploy our product.
And finally, I think it's really important given that I've been at Yubico for some time that while I make adjustments to execute on our strategy, I keep a focus on making sure we retain the best talent of the company, being focused on the mission, keeping that really North Star, how we built the company that we will bring that into the next era of our growth trajectory.
Finally, I'll give a quick highlights here and talked about the bookings already. I think if you look at the numbers here with FX, we ended up lower. But if you take away the currency effects, it's a growth for us. It's really important that we recognize this milestone. A lot of the bookings did happen towards the end of the quarter. And so that has also an effect on the net sales because there are 2 elements to that.
The first element is we have a subscription business. And so that entire revenue is recognized over the duration of the contract. So we sign a 5-year deal, then revenue is spread over the 5 years. And the other thing about bookings converted to net sales, we have perpetual deals and nobody wants to be receiving keys during Christmas Day if you made a good booking the day before. So there is a bit of the effect on deliveries tied to deployment schedules and how they run to deploy the technology with the teams ready to receive the YubiKeys.
We've shown the ARR growth. I think this is a clear sweet spot for us to continue that. But of course, we see some pressures also with the gross profit from FX, but we even see even much, much more -- and we acknowledge that in terms of the EBIT itself with some of the investments that we made and also the pressures from the FX. And so we definitely recognize that, and we're working as a team to make sure that we are an efficient organization.
With that, I want to hand it over to Snejana to talk through and deep dive a little bit more.
Thank you, Jerrod. So let's deep dive into some of our key metrics. I'll start with the order bookings. And Jerrod mentioned that in fixed currency, this is the largest quarter for Yubico ever in the history, which it's indeed a big milestone. However, we are very exposed to the USD FX rate as 70% of our business approximately is in the U.S. So nominally, we see a decline in the order bookings, but in -- excluding the currency, it is a healthy growth of 4.6% versus a very strong Q4 last year.
In Q4 2025, we have a very, very healthy underlying activity with demand from various industries, financial services, technology, retail, the public sector. Jerrod showed as well kind of how we have diversified our industry portfolio. So that's really good. In terms of geographies, Americas were the ones that mostly were impacted by a lower number of large orders, while EMEA and Asia Pacific, we delivered solid momentum there.
The other factor that we are very proud of is that the subscription bookings are increasing continuously. The subscriptions are very important for us as this provides kind of deeper commitment, deeper partnership with the customers, but it also provides a stable recurring revenue base. The renewals represented SEK 96 million, so approximately half of the subscription orders.
If we deep dive into the order sizes, last year, in Q4 2024, we've had a very sizable big orders of SEK 197 million. And this year, we have less than that. But what we are -- what is very good is that our small and mid-sized orders are continuing to grow. And that again provides more diversified customer base and fuels our growth going forward. When we look into the sales numbers, again, it is very impacted by the FX rates. In -- excluding the FX impact, it's more or less flat, minus 1% decline versus last year. We continue to grow the share of subscription sales. So that increased to 26% versus the quarter last year and now represents 70% of net sales. And again, this continues to strengthen our recurring revenue base.
Just as a reminder, when we book subscription orders, we book the total contract value and then the revenue recognition happens over time of the contract duration, while perpetuals when we book the order value more or less it flows as per delivery schedule in the net sales.
From a geography perspective, Americas continue to have the highest share currently at 63% almost. They were at 67% last year. EMEA is stable and Asia Pacific is having a good growth momentum and now it represents 9% of the net sales, primarily driven by growth in India. India is a very big market for us, and we are very happy to have this big order that we announced in Q4.
If we look into ARR or annual recurring revenue, we see a very healthy growth between the quarters, year-over-year growing with 21%. And this is even higher if we clean out the FX impact. We have net retention rates that are above 100% renewal rates, as I mentioned, very healthy. So all of that is very positive. And ARR is a forward-looking indicator. This represents our next 12 months of booked annual recurring revenue. So that indicates basically continued growth in our net sales going forward from subscriptions.
Now to the more difficult part. The EBIT and the profitability took a hit in Q4 with 1% EBIT margin. It was driven by 2 main factors. First of all, our gross profit decreased significantly, corresponding to a gross margin of 75%, 76% versus last year of 84%. The majority of that impact is driven by currency headwinds. The reason of these currency headwinds, again, we have a very negative impact on the top line from currency. At the same time, our product cost is a mix of USD and SEK. So it gets more sort of expensive in U.S. So the margins in the U.S. are somewhat pressured. We expect this gross margin to be in the range of 75% to 80% during 2026. We are taking active measures to offset partially with -- working with pricing structures and managing tightly the entire supply chain.
The second part of the EBIT decline was caused by increase in overhead costs below gross profit. We have deliberately invested during 2025 in our sales and marketing and go-to-market organization. And this is visible in our quarterly figures. We do have a negative currency impact of SEK 22 million in EBIT and nonrecurring expenses of SEK 6.6 million. So that is basically explaining the EBIT hit or turn down during the quarter.
If I go into the cash flow, the cash flow was positive despite the lower cash flow from operating activities. The positive change is in the working capital. This is primarily driven by inventory reduction, driven by our careful planning of sourcing and manufacturing volumes, and this has continued to -- expected to continue during 2026 as we are, again, very carefully planning. We have a lot of inventory. We plan carefully where do we source, what do we manufacture, so we have the right products at the right time.
CapEx or cash flow from investing activities includes investments in some machinery equipment for our supply chain and production, but also capitalized R&D of SEK 6.6 million. We continue to have a very strong cash balance in the balance sheet, which will continue to support our growth ambitions in 2026.
And with that, I'll give the word back to Jerrod.
Thank you, Snejana. I want to close it out with looking at our plans, not just for '26, but really the long-term goals that we want to hit. It is really about continue to invest in -- I consider a very strong part of the entire ecosystem, our YubiKey, which is a really, really secure root of trust, and we have many organizations around the world that this is their backbone, the security backbone that keeps them in business. So we want to continue to advance with the state of art to get the best YubiKeys out there. We have described a next-generation version, the sixth generation YubiKeys that we are planning to roll out later this year. It's really important that we bring those new innovations to the market.
The second area of the product line that is really important for us is to make sure that the services to adopt YubiKeys really, really help the organizations deploy. What do we mean by that? If the YubiKey is sitting on the shelf and they're not being used because they couldn't be delivered to the user, that is not very useful. So by providing services to deliver, improve the adoption and usage, which is a better customer experience and user experience, these really accelerate the adoption. And when you accelerate adoption, then obviously, the customers see the value and they continue to invest in our product portfolio.
The #3 area, which is what we described also in the Investor Day, we're moving into new services around digital identities that we want to bring to the market. I described earlier in the total addressable market where we want to head if we offer new services and products in this ecosystem, we will see growth coming from a new direction.
And fourth is to make sure that we refine our go-to-market investments. As Snejana mentioned, we have had some cost overhead in sales and marketing, which is necessary to grow the business internationally and globally. But what we also want to do is to make sure that we can realize these investments in '26. But what we also want to do is to make sure that we can leverage some of the business partnerships we have to be part of larger deals, larger projects.
And finally, I think for us, it's a no-brainer to make sure that everything we do is a smooth and wonderful experience as our customers work with us. Many of our customers are long-time customers over many, many years, and they continue to work with us because they trust us as the market leader for the technology that we provide.
With that, we'll go into the Q&A section of the presentation.
[Operator Instructions] The next question comes from Simon Granath from ABG.
2. Question Answer
I think last quarter, we talked about you having very limited visibility with the public U.S. customers. Has that visibility increased? And if so, what are you currently seeing with them?
The U.S. public customers, we are definitely seeing some adjustments in the way that they interact with the commercial companies. From our perspective, we haven't seen major movements in terms of how they change their pattern. But what we are focused on and to make sure that we are focused on the ones that have adjusted the way that they do the budgets and have been working with us for a while. So we want to make sure that we make every effort to see those conversations and opportunity materialize.
So from our perspective, we are not like removing investments in the area, but we are really refining where the conversations are happening and creating the outcomes that we want.
And on the gross margin guidance into 2026, the 75% to 80% range it's relatively wide. But at the same time, you are not expecting a decline from the Q4 level of 75.5%. Can you talk a bit about the moving parts into that range? And would you expect Q4 to mark the trough? Or could it come down even more into Q1 and then gradually improve given the changes you are making, as you mentioned during the presentation? I think that would be very helpful to understand.
Yes. I can comment on that. So the moving pieces in the gross profit, if I start with the currency impact is the share of business that we do in the U.S. If we grow more in EMEA and Asia Pacific, then the currency impacts are a bit more limited. But in the U.S., they are more prominent. The other moving piece is the share of subscriptions. I think I went through the logic during the Investor Day that especially in the initial stages of subscriptions, the gross profit is lower as we deliver keys while we're recognizing revenue on a bit more gradual basis.
So that is the other moving piece that can impact -- we're seeing an increased share of bookings. It will gradually go into -- will impact the revenue, of course. But it is a rolling effect. What I mean by that is that initially in the subscriptions, the gross profit is somewhat lower. But as we are building the subscription kind of tenure, then the gross profit actually becomes higher once we have recognized the cost of the product. So these are the moving pieces within the gross profit. And we are very much kind of managing both on the supply chain side, as I mentioned, on the pricing side as well so that we can -- that this is kind of -- the Q4 is the bottom, so to say.
Very colorful answer. And then I had a question on the recent progress in APAC, particularly in India. Is this a market we will hear you talk more about going forward? And if this is a potential growth market, is this supporting or diluting the margins, i.e., will this require more costs?
So India as a market is a big market, and let me give some color to that. And one of the reasons why it's a big market before we even had boots on the ground is that we have a lot of U.S. customers that have BPOs in the region. So this market has been slowly adopting the technology independent of whether we had the boots in the ground, right? But of course, that those are segmented industries. If you look at just how the business was growing. And so we made a very conscious decision to invest more with our team in India.
And I think the results are very impressive for the short amount of time that we've got the team in place. What we know from a historical perspective is that focus gives us the result. So when the team is comfortable talking to customers at this level for large deals, then clearly, there's a path and a trajectory for opportunities to continue to expand and grow in the region.
That said, I think every region in Asia is very different. We can't make all the investments we wanted, right? Because you have to be very deliberate in where the investments go because it does take up overhead cost to be in that specific country, for example. But what we're doing though is that we are setting up headquarters for Asia Pacific and Singapore. I've discussed this with you. I'm going to be flying there to open that hub in 3 weeks. And it's really exciting because it sends a signal to the region that we are open for business. It's hard to do that if you don't have a base in the region. And so that's a clear signal that we want to work with our customers, build up our relationships in the region. And I think that's the results would follow and we have to focus.
The next question comes from Erik Lindholm-Rojestal from SEB.
Sorry, it appears I was muted. I hope you can hear me now. So yes, I wanted to ask you on the ARR dynamics to start with. Your subscription bookings number was encouraging. But I guess ARR is being held back by FX. But is there any degree of churn as well impacting ARR in the quarter here? I'll start there.
So there is always some small churn, but it was sort of our renewal rates are very healthy. And as I mentioned, our net retention rate, so expansions plus renewals minus the churn is positive. It's about 100%. If that answers your question?
Yes, definitely. And then just you mentioned converting a significant share of bookings -- sorry, getting a significant share of bookings in at the end of the quarter, which has not yet converted into sales. I mean, is it possible to quantify sort of how much you feel that this impacted the net sales in Q4 here?
We monitor this very closely. We are not disclosing the shipments or the fulfillment rates. But we do have some backlog that we will invoice during Q1.
Okay. And then just a final question here. Jerrod, I wanted to ask you, I mean, looking into '26, you spoke about small and mid-sized orders being solid here, but what are sort of the key things that you think you need to get right to start getting those larger orders again here in '26?
Yes. There are 2 very fundamental things that gets us back on track with the large deals. First is to build products that adds more value. And again, it's more than just YubiKey, right, providing new capabilities, new use cases that we solve. Being really focused with the additional services and products that the customers will want to invest in the entire portfolio of our product base.
Second, it's really important that we continue to establish the business relationship. So what we know a lot of times when we go into a customer with a large project, we always end up really at the top when it comes to the technical win. But that doesn't always translate to the large deal. And so we need to build stronger relationship from the business side of it.
And it's really a focused effort, right, being able to find where these decisions are -- makers are, connect with them, build the relationship, build the trust. So they are going to be willing to invest in our company and our product portfolio. So it's really 2 things that need to happen to really get to a lot more of the large deals. It's being very, very focused with that type of effort.
The next question comes from Thomas Nilsson from Nordea.
First, you saw record Q4 bookings. Does this reflect some fundamental improvement in demand? Or was it a closing of large-scale enterprise deals behind this? And how sustainable is the momentum in order bookings going into the first half of 2026?
I'll answer that. If you give back the layers, we saw the chart that Snejana showed previously, we really see the strong base of the small, medium deals. Maybe we can go back. We just show that again. I think super useful to...
I can move it.
Yes. So if you really look at this super carefully, we didn't have that many large deals as we described it. So the question we had asked previously was like what are we doing about it, right? So we're going to do something about that. But if you just look at this chart a little bit and look at the kind of the growth numbers where we are with the deals below $1 million, it's really a strong growth there. And to us, this is what's going to continue because if you look back again, if you look at the chart, look back and you can even go back even to 2022 and further, right? This is a strong indicator of the growth trajectory.
In fact, we also see, of course, some of the $1 million to $3 million deals starting to pick up a little bit. But again, fundamentally, we're missing -- this is what we call the mega deals. And that as I described, we have to really invest in that at a different level to build a relationship. So trending, the data shows it. We don't see any fundamental difference in terms of the trend lines for the $1 million deals, it's going in this direction, going up. But the large deals, right, it's very lumpy today. And so it gives us the volatility, and we don't want that.
And the way that we can smooth it out as well is to think of a longer-term contract, which helps smoothen out some of these conversations and then obviously build more pipeline for the large deals with the relevant stakeholders.
Okay. And a final question, if I may. You have a very strong cash position at Yubico. Are there any opportunities for acquisitions? And what does your M&A pipeline look like? And what type of acquisition could be of interest for Yubico to make?
Jerrod, do you want to comment on that?
Yes. So what we -- if we look at where we're going, this is the pillars that we have. If you look at the buckets that we have on #3, there is some opportunities we're looking to expand our portfolio. We're not going to comment on our pipeline. It's something that we don't want to review too much, not necessarily because we don't want to talk about it, but it gives other people some indication even with our peers and things like that. But if you look at 3, there is a directional piece for us to be able to expand into the digital identity ecosystem and that particular market. And so we will look for ways to be able to accelerate our deliverables and execution.
[Operator Instructions] There are no more phone questions at this time. So I hand the conference back to the speakers for any written questions and closing comments.
So now let's go to the written questions. And the first one is for you, Jerrod. How long does it generally take for a newly hired account executives to become productive and reach baseline sales?
The sales executive in terms of where they are hired has a different trajectory. So for example, when we look at some of our sellers that are selling to super large enterprises, there is usually a longer ramp-up time. The sellers that are focused on the small and medium deals, they generally ramp up faster and also because it's more transactional, right, that kind of the volume matters. But the ones that are -- the large deals that we just talked about, they -- it's solution selling, right? Solution selling is complex sales. So they need some level of competence with our product lines, our messaging, our portfolio to be comfortable talking to customers that have obviously multimillion dollar deal opportunities for large contracts. So it does vary with our teams. But generally, most team members as a range between 6 months to a year.
And next question, how does demand from the biggest tech customers look if you think about Microsoft, Google, Amazon, et cetera? Are you seeing increasing penetration among those?
Increasing penetration. I think that is an interesting question. Some of these organizations have passed what we believe as their internal employee count. But what we do know is that these companies, we want to protect the end-to-end organization, but also a number of them protect their supply chain. So that is an additional growth area for us as they expand their business and protect their supply chain. In terms of where we are heading, they still continue to be a large part of our portfolio. We've seen the industry side. I think we bring it back to that again. The industry side, we're not seeing them disappear. I mean they just continue to be part of our portfolio, but balancing out our overall strategy. So they're still a big part of how we grow the business.
Next question. Small orders are increasing. How much of this is due to the larger orders becoming smaller? In other words, are you down selling on your bigger customers?
From the perspective of transactions, there's definitely much more transactions. So it would not make sense to then equate therefore, the large company bought a lot of many small orders. I mean sometimes it does happen. But in general, because we also see volume increases in the number of transactions, that does indicate to us that it's not just big orders becoming small orders, right? From what we obviously understand, we also have a mass market business. So that also means that the transactions are faster, going through different channels. As some of you may know, we launched an in-store retail product in the U.S. for Best Buy, which is one of the top consumer electronic retail stores.
So we do see this groundswell where people are buying where they're comfortable with in different marketplaces. But what is really important and exciting is that these customers, a lot of them are also businesses that they can try out without necessarily having a long sales cycle. So it gets really rapid to just get the product in hand and use it. And then they become leads to the enterprise team because when they buy at a certain volume, they say, you know what, I think I need to go talk to someone because I want to get better discounts than just paying some of these prices that they see.
So we see this as a good fuel and lead to the enterprise business. So in general, some of it does happen that way, but I would say just the volume of transaction does not indicate that is the trending.
And next question, you said India is a very big market for you. Can you indicate how big it is? What type of customers are they? How does the growth look like there?
We're not going to give the comments on the growth numbers for the region. But what we can say is I've explained the awareness of the technology has been building for several years now. And the difference in the numbers are because we've actually put boots on the ground to build the local relationship with other businesses, and they are partnering with us to then commit to long-term contracts.
We also built a strong channel partner ecosystem in India. And so that's also paying off because we need to work with a lot of the local partners to bring the scale of delivering all the products to all the different customers. And so we continue to see that development happening in the markets where we invest in the people and the resources to give it the full amplification of the results.
And a question to you, Snejana. Could you repeat how you think about converting bookings into sales quickly?
Depending on what quickly signifies. But a quick comment. The subscription order bookings, we recognize or we report them as total contract value as perpetual, by the way. But the subscription total contract value then is spread out over the course of the duration of the contract. So meaning if we book SEK 90 million, let's say, subscription order, then each year, we will -- and it's a 3 year order. Each year, we will recognize SEK 30 million of sales.
Perpetual is booked as total contract value. It's typically linked or entails a shipment schedule, especially if it's a big order. And then there, we recognize the revenue over the duration of the shipment. But typically, the shipments are within a quarter or max 2. So that's kind of the quick. If the quickly meant, are we able to recognize revenue quicker, then it all depends on the agreement with the customer on the shipment schedules for perpetual orders. For subscriptions, it's typically we start -- once the contract is signed, it's very typical that we start recognizing the revenue more or less from the quarter after.
Next question, back to you, Jerrod. Could you elaborate more on the U.S. public customers? There was talk of delayed orders in previous quarters. Have you received those? Are they still delayed? Or do you expect them not to come?
I think the market continues to evolve in the U.S. public sector. I wouldn't say they're gone. I think it's -- the delays will be still present in certain parts of the adjustments. And they think that the entire ecosystem of public sector is adjusting to a new normal. But what we can say is that we have very close conversation with all the customers, right? So those that are -- that we have our customers continue to invest in us. And also, if we look at the overall sector, our brand and our recognition of our product line is really, really very clear. For example, we have the guidance coming out from the U.S., I guess, Department of War, Department of Defense, whatever the guidelines continue to change, calling out YubiKeys by product name in the report.
So the awareness is really, really high within the public sector and the government in the military space in the U.S. We continue to focus on that because we actually are a recognized brand in that space. But of course, there are budgeting scenarios that they have to work through with the current administration that they need to get sorted out. So we continue to be very closely aligned with how that develops.
And next question, Yubico chose to move to a subscription model, yet this is now blamed for the poor reported growth. Was moving to a subscription model a mistake? Why did you do it?
Maybe I can start, Jerrod. We definitely don't blame the subscription for a poor reported growth. We just need to call out kind of the dynamics of that. The subscription model, again, provides a deep partnership with the customers. It provides stable, predictable recurring revenue. And from a profitability profile perspective, over the long-term, as we add actually and provide to the customers value-added services, the profitability profile of a subscription over the long-term is more favorable. Jerrod, maybe you can continue on that.
No, I agree with you. I mean we're not blaming that for sure. And we don't actually look at it as a negative. I think -- and also we shouldn't just look at the subscription. Like what are we trying to do here? What we are trying to do is to help our customers protect the organization for a very consistent period of time. So the service that we provide, we want to future protect them, right? So for example, if the customer -- one of the benefits of the subscription model is that they have some employee churn. And so in the modeling, they will get the additional keys they need to protect the customers. Now they don't have to take all of the entitlements, but that is a benefit.
So they want to work with us because they see the value. So it isn't about like all subscription is good or bad. What value do we provide to the customers? And customers buy the product subscription because they see the value. And the other thing with the subscription is we also accelerate a number of things that help deliver products to the customer. And they also look at it at how do you can help me enroll the users to use the YubiKeys. So these are additional capabilities.
And then without it, the customer has to invest somewhere else to go solve this problem. And so I wouldn't look at it as just a black and white like subscription is causing this effect on the profitability. This is a thing that the customers see value. And when you see the customers see the value in the product, they will continue to invest more as we release more products.
And Snejana, can you give any color on your thoughts on headcount? Will the low double-digit growth we have seen for long time trend downwards if sales do not pick up sufficiently?
Yes. So we have indeed invested in our people during 2025. During 2026, we will be much more selective on the headcount growth. We think we have an organization in place now that will deliver on our priorities. So we will continue primarily investing in R&D resources to deliver on our accelerated product and services road map.
And the next question to you, Jerrod. If you expand into digital identity services, are you at all worried about cannibalization?
I think there's always a possibility. But the way that I look at it and the team looks at it is that we don't do this, then we're going to be [indiscernible] by somebody else. So again, if the customer wants a certain set of products that we can deliver, we need to deliver it. Otherwise, it's just going to go somewhere else.
And last question, how big is the average order in the less than $1 million category?
I think it's a very big variety in this category as we have mass market in there, Amazon sales. So it could be anything from people buying 1, 2 keys to actually small and medium enterprises buying below $1 million. It's a very big range.
But what we can say, though, is that the deal sizes in general is trending up. If you notice one of the things that we've done in the release of the product line in the Best Buy, we have a 2 pack now, right, 2 YubiKeys. So the average cart size is growing because of the way that we are positioning -- actually, you need 2 keys because you -- a lot of the customers complain, what was if I lost my YubiKey, I would say, you get 2 of them. So the overall movement is to be able to bring up the average deal size for each segment of our buyer.
That concludes the written questions.
All right. Thank you very much.
Thank you, everyone, for joining us, and have a great rest of the day.
Thank you.
Transkripte auf Deutsch freischalten
- Alle Event Transkripte auf Deutsch
- Sofortige Übersetzung
- KI-Zusammenfassungen für die wichtigsten Insights
Yubico — Q4 2025 Earnings Call
Yubico — Analyst/Investor Day - Yubico AB
1. Management Discussion
So welcome, everyone, to Yubico's Investor Day. My name is Alexandra Barganowski, and I'm the Investor Relations at Yubico. And I'll also be your moderator for the Q&A sessions later today. Just for some practicalities, this presentation is live streamed, but it will be available afterwards on our Investor Relations website and as well the material. And the presentation is largely split into 3 parts. We will have a Q&A session after each section. So if you have any questions for the speakers, please hold your your questions until then.
And now I'd like to welcome Mattias Danielsson up on stage to kick off the day and talk us through the agenda. Welcome, Mattias.
Thank you, Alexandra. Can you hear me all right? Great. So before diving into today's agenda, I'd like to make 2 observations. First one is, you saw from the heading here that this is talking about building safe digital identities for future generations. So we'll take a very high-level look at the market, the product, the company, to explain what precision we're in.
And then we'll talk about some of the things that we're seeing happening in the market and how we want to position to make sure that we're relevant in that emerging new world. So we will be high level talking about our view of the market and our strategies. We are aware that we released the Q3 report last week. So we'll, of course, be happy to take questions on that, too, but we'll focus primarily on long-term trends and strategies.
The other kind of obvious observation is that I'm trying to speak English. Yubico was started in Sweden, and we're proud of that. But the reason for speaking English is that we have a very diverse and international crowd and a very diverse and international company. I think you'll notice that with today's presenters, it's only Stina and I who grew up speaking Swedish. If you feel more comfortable asking questions in Swedish language, we'll be happy to take them in Swedish, translate them and respond back in English as best we can.
And with that, I'll dive straight into the agenda. So we'll start by explaining how we see the market today and the position that we've built. And Jerrod will start with that, talking about it from the product and technology perspective. And then Yubico's CRO, Carl Helle, will take us through some customer journeys. And we're very excited and proud to have 2 fantastic representatives of major customers of ours who will be talking about their journey and where you can ask unfiltered questions, of course. And so that is the Q&A session. There will be a short break, and then we'll do more of a deep dive into technology.
So Yubico's CTO, Chief Product and Technology Officer, Albert, will take us through that part. And then [Audio Gap] to kind of summarize the position we're in today. Snejana, Yubico's CFO, will walk us through the numbers, how to interpret the business models that we have, how to map that. So we won't be sharing any new financial numbers, but we'll hopefully provide some color and some detail for you to better analyze the position that we're in. And that will actually also go for the more forward-looking sessions that we'll then continue with. We won't be sharing -- sorry, we won't be sharing any new product news or any new targets today, but hopefully, we'll be able to provide a little bit more color on where we're heading.
So we'll start with -- I'll start that session with talking about our go-to-market, how we get from the position that we're in today and how we can build on that foundation to reach new customers and solve new use cases. Of course, the foundation for all of that will be our product offering. So again, Jerrod will join me on stage to talk about -- a little bit about the -- what we're seeing happening in the market. And then Albert will follow up to see what's our response to that? What's our strategy to what we're seeing in the market.
And we're then fortunate enough to have one of Yubico's co-founders, Stina, join us on stage to talk a little bit about the partnership we have with the new entity that she has set up, which is a -- the SIROS foundation. So that's going to be exciting. We'll end that session 2 with Q&A and then we'll wrap it up. So far, we're pretty much on time.
So with that, I'd like to hand over to Jerrod, who's been my colleague for the last 12 or 13 years, and will take about -- take us through the market.
Thank you so much, Mattias. Thank you. Today, I'm going to give you a quick overview on how we look at the cyber landscape. As Mattias mentioned, we are a global company. So we see these trends not just in one country or one region, but we see this everywhere. And the good news is that we see this everywhere. They're not so good news is that it's the same problem that everyone has. This is a snapshot of news that you see all the time. This slide that we created was just the first 2 weeks of October this year.
We say to customers and -- how should we think about cybersecurity and attacks? There are 2 camps. A company that has been breached and are working to protect themselves and a company that doesn't know they've been breached and will have to protect themselves. And it's an interesting fundamental change, which is you have to assume the organization is breached and what are you going to do about it. And the #1 way that the companies get breached today, organizations get breached is through an account takeover. And the #1 way that you do an account takeover is a phishing attack.
And we've seen this rapid acceleration over the last 5 years, but it has been happening steadily over the last decade. And it's just going to be increasing because of new techniques and the thing we call AI. I wanted to walk through a little bit of what that means today with some of the techniques that we've seen, a little bit of audience participation, 2 e-mails, one written by a human and one written by AI. Take a few seconds to read it. How many think that example B was written by a human. Example A was written by human. 30% got it right. Example B was written by AI.
The fact that anyone even raised their hand for example B means AI is doing its job, right? Because all it takes is one person to compromise an organization. And so the lines are really getting very blurred. The phishing attacks that you see today are just the tip of the iceberg. And I'll go through a little bit about how advanced some of these things are going to be. But it's clear, asking a human to figure this out is an impossible task. There's no amount of training that will get you there.
So I want to take a step back a little bit. What is all these phishing attacks all about? We've got -- we've been using technologies to log into systems more than 3 decades now. And the industry has used different techniques over time to try to prevent some of these attacks. But let's just take a quick look at what is happening behind the scenes. So I've just mentioned, AI can generate a lot of phishing e-mails with just a click of a button. And what they typically do is to get you to click on a link and redirect you to a fake website, which looks exactly like the real website, bank website, government website, your doctor's website, anything that you do today, in a legitimate way can be turned around and we used to attack you. So you put in your login, user name and password, which is the most common form of log-in authentication. And the AI agent or in this case, the human will just take those credentials. They will then use those same credentials and log into the real website.
So at this point, you said, well, what can I do about it? Over the last decades, there are many different types of additional authentication vectors that people use. One of the most common is SMS. So at this point, you said, aha, no worries. I get my password, but you still didn't get my OTP credentials or the SMS code that came into my phone. But at this point, the new -- the system is expecting the SMS OTP code. So it will send out the SMS OTP code to the user. And the user is, okay, great, I've got my code now. Now you cannot get in still. But in this same situation, because you're on the fake website, you actually type in the real SMS code to the fake website. And that's how the attackers get in.
So because of the way this is set up, and you are already believing the fake website is a real website. You would do everything that you would normally do on a real website. And that's how the attackers get you. And so this technique, when I first presented this scenario here, this was actually back in 2016, same diagram without the AI pictures, but 2016, I presented at one of the hacker conference, Black Hat, nothing has changed. Nothing has changed. The big thing that's changed is the scale, the speed and the accuracy of these attacks.
I want to show you something really quick, not necessarily to scare you, but to just give you a sense of how the techniques have evolved rapidly over the last 1.5 years or 2 years with both generative AI as well as soon, you'll see a lot more agentic AI in the picture. This is a tool that we actually found at the same conference, Black Hat conference this year. And it's open source, anybody can use it. People use it to test their readiness, but you can be assured that the attackers are using some version of this to actually do real attacks.
So we try to trick ourselves, Yubico, we try this tool. We put in our company name, and it will check whether this is a real company, Yubico is a real company. And then it checks online, various systems, who are the people working there, and we have our employees. We've got permission from them to use their names. And what it is doing today is -- or this sequence is that it's grabbing their LinkedIn profile and everything to do with who they are online. So this is all public information. The tool then passes out all the information about the individual, professional development, professional information.
And it creates 2 different types of e-mail. One is generating feedback on maybe something that they care about. And the second one is to have another e-mail to persuade them to share something. And so when we get this pretext e-mail from the AI, it knows right away. It writes Daniel, it's actually from Latin America. You can see Latin America there. He works with a lot of different companies there. And the AI just generates everything based on the LinkedIn profile, so it's relevant for Daniel.
Bettina, who works in channel marketing or channel sales has something similar. David, who works in our customer advocacy program has something relevant for what he wants to know. The time I've used to explain this to all of you, the tool can generate millions of e-mails to employees, customers, suppliers and so on and so forth without us doing anything. They use the same techniques that we use for productivity. So they actually -- this tool actually use one of the top AI engines for free to generate these e-mails.
So as you look ahead, it's not a great scenario for what we call the defenders, right? A lot of us are on defending our organization, or helping our customers defend the organization. But the good news is that there's actually a solution to this. And so I'll change a little bit of the perspective on how we look at the market because what we've identified in terms of these attacks actually has been solved.
We've been working on this thing and now we call it Passkeys, I'll explain that a little bit. We're working on this technology that fundamentally changed this attacker and defender paradigm, which is to eliminate this industry problem. The origins of passkeys was the work that we've done with Google almost now more than a decade ago. And this case study was -- is really remarkable because when Google wrote this case study, it's not just impressive stats that we've realized. These are stats that are unheard of. And the number that you want to key in on is 0.
And so why is it that we have this technology for more than a decade, but yet we have still all these breaches. Maturity, right? Maturity of the technology takes time for people to understand and learn and then implement and adopt. But this has been existing for more than a decade to solve all the things you just saw in terms of the attacks that Yubico actually co-created. So what is this passkey conversation that a lot of you ask. It is the FIDO standard that Yubico co-created. It is the version 2 of the FIDO standard, implementing passwordless authentication.
Unfortunately, the industry didn't do a great job trying to help educate all these names that the tech keys create, right? We had FIDO1, which was FIDO we called it U2 universal second factor. Then we had web authentication, then we had FIDO2 and then now we have passkeys. So we didn't do a good job trying to educate. But it's the same fundamental technologies that can eliminate phishing attacks and prevent account takeovers. Now today, passkeys exist in various devices. And this is intentional. This is not because we said, okay, this is a way that this is to work, and it only has to work in one way. On the bottom left, the three basic types of devices that we all as users use to passkeys. A purpose-built device like a YubiKey, purpose-built, which is all it does is security. A general purpose device like a laptop or a phone.
And the way you unlock using the passkey credential is something that you remember like a PIN or who you are like a biometrics. So this is pretty well established in the market for many customers that have been using the technology this way. Now how does this actually prevent what we just talked about in terms of the attacks. So same phishing attack, you go to the fake login page, you put in a credential. They take your credential. But before they can actually move forward, this technology requires you to show that you have this device in your possession.
There's no typing of codes. There's no codes involved. And so if you don't have this device, whether it's the YubiKeys or the phone you have, you're not getting in. So it essentially stops it at its tracks. And the way this technology works as well is that it knows the difference between a real website and a fake website. There's no user training. So it works out of the box. And that's the whole point. You don't want the users to think about which website to click and which website not to click.
And to go further, possession of this device requires a human presence. So you can't ask an agentic AI, agent to go and like touch your device on your behalf. What we call human verification is part of this technology that we created or the protocol, what we call the standard we have created, and that was way before any AI agents ever existed. And today, the way that a lot of our customers is actually together. You actually need a very strong foundational piece of purpose of device to anchor all the other devices.
The reason we say that is if you don't have a password, how do you get back -- how do you reset anything? Like there's nobody to call to reset anything. You just have a device. And so you actually use the trusted device to then what we call bootstrap the devices. And this is a very fundamental conversation, which is if you bought a house and you've got a car key -- a house key, you don't just have one. You have one that you can then use and then you've got a backup one. So it's very, very -- we live in a physical world.
And these concepts are very much the same when you apply these techniques to the logical world on the Internet and when you try to apply it to log in. One other area of maybe putting some color to what we do at Yubico is to drive an entire industry around this. As I've mentioned before, we co-created FIDO with Google, and it was 2012. And you noticed over this period of a decade, we actually had to have 2 other big technology giants as part of the standard. Why? If all of us are using devices to get Internet to do something there are only 3 big players in the whole world today that are the gateways to the Internet.
Google and all their Google Android phones, Microsoft and all their Microsoft operating system, laptops and tablets and Apple and all their devices. So actually, in 2022, Apple made full support for FIDO within their ecosystem, which means the 3 big players implemented the technology that we co-created. And again, this is intentional because they have to support everybody in the world. Our goal at Yubico was to make sure that we could create the type of protection that can be applied for everyone on Internet, which is one of our missions, which is our mission to protect all users on the Internet.
But it wasn't just that we got the standard and we got the 3 tech giants to embrace and use the technology. We had to push the entire ecosystem. Everybody else that use the systems and more services had to also implement the standard. So this is just a glimpse that we have hundreds of thousands of services obviously implemented FIDO today. Obviously, all of them can leverage the operating systems and the devices that is already built in by Google, Microsoft and Apple. But the other thing that we also did was to make sure that corporations and businesses understood the difference between the different types of category of using FIDO.
But also the industry analysts accepted this technology that we created. So this is a report from Gartner, one of the industry analysts to talk about authentication and digital identities. And you can see on the very, very far right. FIDO security keys, which is industry term for YubiKeys are the very highest type of authenticators to use. And then all the other types of FIDO authenticators on the phone or the software comes before that. So we work really very hard to make sure that the industry analysts recognize the standard that is out there.
And that's why you see a huge proliferation of technology. It took a decade. The last point I wanted to help shape some of the views what Yubico does was it wasn't enough to build the standard, drive the ecosystem, convince the industry analysts. We also had to drive policy because many businesses will say, this is a great technology, just great. But until the government says I have to use it, I'm not going to use it. Or until the government says, okay, and I may get fine, then I'll do it. And so we've been driving policies and regulation in the entire world for FIDO to be accepted as a gold standard for authentication.
Actually started back around the time I presented to Black Hat in 2016, where we talked to some of the individuals in the standards bodies in the U.S. And of course, that has grown significantly over the last, I would say, 2 years, huge uptick in the Asia Pacific region, which is mandating FIDO, mandating phishing-resistant technology as part of just hygiene, right? Citizen hygiene, you see this word, which is good hygiene at home really helps create protections for corporations and for that matter, nations.
I'll leave you with a video of how a YubiKeys works because I've been talking a lot of things that Yubico is doing and a lot of things that would help shape the ecosystem. I want to share with you how it all works.
[Presentation]
So this is a quick overview of what we've been doing with industry and what we've been doing behind the scenes to drive the open standards.
With that, I wanted to hand over to my colleague, who is going to tell you a little bit how we accelerate our go-to-market motions.
Thank you, Jerrod. I appreciate it and nice overview. Good afternoon to everyone in the room. I appreciate you all being here and to all those online, welcome. My name is Carl Helle. I'm the CRO for Yubico. And I've been in this business over 25 years now. I know I don't look it, but believe me, I've been here a while.
So today, I'm going to talk to you a little bit about the economic impact of what's happening in the market. I think Jerrod did a really nice job painting the picture of how it happens. But I'm going to talk to you a little bit about the economic impact, customers' challenges, why they would choose Yubico, and then we're going to take you down the customer journey.
So let's get started. So this slide just illustrates that bad actors are not letting up. Over the course of time, these numbers continue to rise. And at this point, industry analysts say that it's over a $9.5 trillion problem across the world. That is massive. And it's going up roughly 15%. To combat that, of course, companies, organizations, government, you name it, have to continue to spend on technologies, applications, people, and that's also rising at roughly 15% . And this trend has been going on since I've been in the business.
What is interesting is Proofpoint actually illustrates in their study that the CISOs, the top-level security person in the organization and the Board of Directors, along with CEOs and CFOs are now becoming more aligned to fight these issues. So there's more conversations than ever before to understand what's happening and what the organization is doing about it. So there's a lot of pressure on the individual security teams and staff to answer the question of what are we doing to protect ourselves.
Breaches from stolen credentials is at an all-time high. And when those breaches happen, believe me, the bad actor doesn't stop there. They find their way in many times, they'll rest for long periods of time, sometimes even months. And they'll just watch the traffic move within the organization and then find their path to move laterally in that organization. So they might breach a staff accountant that wouldn't appear to be a critical spot in the organization. But because they breach that person, they move laterally into higher levels of the organization to systems and data, data centers and applications that host the most sensitive data within the organization.
That's where the problems really begin. The increase of cyber attacks is going way, way up. And the average impact in 2025 is over $5 million per breach. If you think about that, most medium to small businesses are unable to sustain even one attack. Studies report that 6 months after an attack, that small business is out of business. The stakes are really high. It's important that -- you all can understand that. The bad actors, as you saw from Jerrod's presentation, they don't break in. There's nobody brute forcing systems anymore.
I mean they might, but that's very old technology or old way of breaking in. They just log in. They just simply steal your credentials and log in as you. And when that happens, they're easily able to migrate to other areas of the organization. Companies are pouring billions of dollars into trying to stop these type of attacks. So it's really time to rethink security and identity security. And it's an imperative that companies try to protect these 3 elements.
One is business continuity. And for large organizations, a breach may only take down a portion of it. We see it in the news all the time. Jerrod showed you some articles around on that. But business continuity has a major impact because if one end of the business is down, it affects the overall business, sometimes the economy. Brand protection is super important. As we all know, some organizations have a bigger brand than they do at revenue. Super important to them, and they want to protect that.
And last, of course, as Jerrod mentioned, achieving compliance. Because there's a hesitation to spend more unless there's a result at the end. And sometimes those result in fines and other things that are requirements based on the industry that the organization might be in. So how are the companies keeping up today? Well, this is the arc of kind of how they've been trying to keep up. Way back in the day, we just logged in. We just put in our name and company, and we'd log into our systems. Then passwords became really relevant. We all put little yellow sticky notes, put a password up there, so we wouldn't forget. Anyone in here ever do that. Over time, it became SMS codes and authentication devices, authentication apps and now biometrics all become part of this. But they don't work.
As you saw with Jerrod's presentation, they can all be intercepted through the power of AI tools, all of those ways can be intercepted. Imagine if you run a 20,000-person company, and you're counting on every person every day, doing the right thing every time. It is a huge burden on your employees and your staff, and there's just no way to combat it with that. As Jerrod said, all the training in the world won't solve that problem. So it results in partial protection around some of the people, some of the time. And there's compliance gaps throughout the organization of any size.
So there's a new world. There's a new world think about how we do this, how we come to try to solve for these issues. And it starts with unburdening the user. We have to have user-friendly security. Easy security gets used, difficult security gets worked around. We need protection for all. We need compliance that's built in. We need purpose-built passwordless security, and we need proactive prevention. Those are the elements that must take place. And so that sets up Yubico to be a really great strategic partner.
Based on what we've done for years and years, we've demonstrated market leadership. We have worldwide distribution, and we have scale in production and delivery. It's evidenced by the number of customers we have and certainly by the thousands of proven technology alliances that we've created over the journey of Yubico. We've been delivering on that promise for years. It's time to rethink identity security and how to go about it. And that's what we're doing every day at Yubico. It's too common to have these kind of messages end up in your inbox.
A few weeks ago, I traveled to London, and I got this message shortly after. And it basically was from my airline that said, hey, by the way, the Dublin Airport may not have lost some of your data. They may or may not have some of your information on your flights. And of course, I think, well, what else do they have? That happens all the time for individuals and people and companies are sick and tired of being sick and tired. So they're starting to do things proactively to put measures in place so these kind of things don't happen.
Every user is a privileged user. As I said, anybody can be -- their credentials can be stolen and they migrate. And 7 to 10 years ago, when we were building keys for companies that were very interested in our technology, it was a bit complex. Many of the keys were custom keys. What that results in today is we easily do custom keys because we had to back in the day. Today, with FIDO2 with Fast Identity Online, that's what that stands for. That standard has boosted the standardizations within the industry so that others can follow the same standard.
It's a rule book, if you will, of how the technology should and could work. Back in the day, we sold individual use cases to organizations, talk to them about their particular needs in the organization and built keys, many times custom-built keys for that organization. Today, that's changed quite a bit. I'll get back to that in a little bit. There's really 2 scenarios that organizations purchase YubiKeys.
There's the planned event, which is organizations, both small and large, know that they have a situation and they know they have a need, and we do the typical sales process. We do some discovery. We meet with the customer. We bring our teams in. We architect a solution with YubiKeys and sometimes our alliance partners. Eventually, we have a purchase. For large customers, that can be anywhere from 18 to 36 months, sometimes even longer. For smaller customers, that's usually 3 to 6 months to go through that process.
In the unplanned scenario, it's a little bit different. The hair is on fire. There's indicators within their systems that say, "Hey, something is going on, does it look right, doesn't feel right? We may or may not have a breach." In those cases, there's an escalated approach to this. Everybody is online. It's very urgent. And they really look at it from a damage control and environment analysis. What's going on, what's been affected, what can we do? Many times, Yubico gets a call in these situations, and we get asked for help.
Through all of that, we've developed a rapid response program that we implement where we get keys to customers very, very quickly. In cases where it's a relatively small customer, a few thousand people, those keys are out in a few days. In other cases, large customers, it even might take a few months before they really get their arms around what's happening. But either way, there's usually a purchase at the end.
So let me give you a couple of examples of how this kind of unfolds. We have a very large financial institution that we worked with in the United States, you would know their name. And they were very interested in enhanced biometric solution. We have biometrics, but they wanted the advanced pieces parts, and we had to work with a lot of alliance partners. Our teams went in, did all the planning things, did the discovery, worked with alliance partners and with many of our own in-house product and engineering teams to build a custom key for them. That process was a good process for both and all entities, and it turned into a $7 million purchase of keys for 150,000 employees, a great win on Yubico's statute.
In another case, a financial institution, real estate company started seeing those indicators through their Splunk environment and brought forth the request to secure some of their most critical assets. In this case, keys were out 9 days to solve for that problem, began to secure the company, letting them go buy new computers so that they'd knew they had a secure environment to do some analysis. Both of these end up being very, very relevant in terms of how people purchase YubiKeys.
But don't let me just tell you, I'm going to turn it over to Brian Bell here. And Brian is with T-Mobile, and he's going to share his story and his journey with you all.
Thanks, everybody. I have a story to tell, but I feel like you guys already told it for me. So there's going to be a lot of repeat information here. So as Carl said, I am a principal cybersecurity architect at T-Mobile. I've been there for multiple years now, 25 years. Hopefully, I don't look as well. And we struggled with the same battle that everybody has been talking about here today. T-Mobile is seeing account takeovers at a climbing, climbing rate, 100-plus a week. We were losing employee data, which resulted in customer impacts. SIM swaps were happening, accounts were being taken over. This was at business scale as well as individual customers.
It's a huge issue for us. One that we needed to solve quickly. We decided to make a cultural change at that point, and that's really what it took. In 2023, we brought in a new CISO, decided that account takeovers had to go from the hundreds to 0, something we had to stop immediately. We went through the process of strategy around this and said, what can we do? We needed a phish-resistant solution.
Our passwords weren't working, our MFA standards that we had weren't working, and we needed a partner to be able to get us there, and we started looking and we found Yubico. We decided that we needed to have something quickly. It wasn't something we could wait on. So we did a little bit of an escalation on that. I wouldn't say we were in the hair on fire situation, but we wanted to do something quickly. We started in May of -- or sorry, March of 2023 reviewing our processes, saying what is it we wanted to do. By May, we had orders in place. By July, we started our deployment.
Within 4 months, we had 170,000 keys deployed to users, registered users, clearing out all their authentication factors that they had and starting from scratch, rebuilding every single person up. By February of 2024, we completed our deployment to over 200,000 accounts and continued to do that today, refining as we go, making things stronger and better. It didn't come easily though. That was something, as I said, was a cultural change for us.
The new CISO came in, and we made this a pillar of our standards for the year. We said, "Hey, security has to come first. We can no longer be something that comes up as a hindrance or just a compliance piece. We need to be working together with all of our teams to build this out and to know that every employee knows that security comes first," and that's really what it took. As we went through looking at what it was that was going to make Yubico the user or the provider for us, we said, "Hey, how can you get us there? And they delivered. That strategy that we had to deliver that in the keys was going to take a provider that could be there for us.
They could help us with deploying not only locally. We took to our corporate offices. We had 46 regional business offices. We had users out in the field in the U.S. and globally. And we deployed every single one of them. This is our full-time employees, our contractors to our organization, service partners. We made it part of our contracts to say, "Hey, you have to have this. Yubico will be your standard. You will buy these keys. It will be part of your agreement with us." And everybody was kind of taken it back, right? It's a new thing to say, "Hey, I'm changing the standard on you."
And it has made a leaps and bounds change though, about how they're able to access, how it makes their experience better with us at this point in time now. Getting to a passwordless standard has not only simplified the business for us, but it simplified the business for them in the long run. So it's something that culturally once that took hold, made all the difference in the world. That velocity was huge. So as I said, Yubico came to the table with us. They worked with our VARs. We had deployments of 15,000 keys to 50,000 at a time, and they met every single goal for us coming through. That allowed us to meet that global distribution.
When we say that we deployed in that strategy, it was also very short windows. We would give our groups 24 hours and say, "Hey, your key is coming. Tomorrow, you need to register that key." That's the precision that we did this on and it was just that Yubico was able to deliver it for us. So this is the kind of partnership that we need to be able to not only get that out, but then sustain long term. As more use cases came up and more items came to the table, Yubico has been there with us along the way to say, "Hey, how can we help solve this?" If it's a remote access piece, whatever it may be, they were there with us in the trenches working through the technology details and making sure they can supply us what's needed.
The form factor availability is also a big key for us. As we talked about, we're accessing on every type of endpoint. There's your virtual systems. These are mobile devices, part of our business. These are going to be laptops, desktops, whatever it may be. Yubico had something to fit every single one of those for us and make sure that legacy systems that we had to handle had the right type of access and made sure that all the new systems were there. And that standard as phones and devices things have evolved, we've been able to evolve what products we're bringing in and making sure we have that up to speed as well.
This resulted in us being able to do that elimination of account takeovers. T-Mobile is now at a 0 account takeover status. It is not something we see anymore. It's not something that we worry about. We went from being ones that were in the news for the bad things happening to us to the ones in the news saying, "Hey, bring it on, what do you got? We're not really afraid of you anymore." It's a weird place to be, but it's something that we pride ourselves on. And that took that change and it took a partnership like that to get us there. It also has made it better for our employees.
I talked a little bit about the user experience. Going passwordless has been huge. Internally, it cuts down our costs, our service department cost for having to do password resets has dropped dramatically. And that's huge piece for both the employee as well as the end user that's our -- person that's helping out on the technician side. Our ability to streamline how you log in is nice. I mean you can go in there and if you've never done this experience with a key, it's fantastic. You don't have to enter anything and there's no e-mail. There's no password. You just say, I want to choose my identity and you're off to the races and going.
So it makes things a lot smoother for that. The bootstrapping process has become more streamlined as well. We've got endpoints from iPads in retail stores to those machines coming online, and we use the YubiKeys as the first portion for that. Regardless of any other factors you may use along the way, Yubico is our standard for everyone. Our security key is the cornerstone of them setting up for everything, and they can use that to bootstrap and bring other things online. So if they want to use the passkey or Windows Hello for business, they can.
But this is the piece we want everybody to have and know that it's going to be and it's going to work every single time for every single use case that we have. This has also helped us with our business pieces. So I talked a little bit about account takeovers and the impacts that, that had. I look at our T-Mobile for business as a portion of our organization that was really hesitant about this. They used to say, "Hey you know what, we can't have anything that's going to take us down, anything that's going to slow us down."
But by the time we started implementing this and came through it, they were the first ones to come back to the table and say, "Hey, you know what, we've got this now. Our account takeover rates are going down. I can go out and sell to customers." These large-scale organizations that know that they can come to T-Mobile and no longer be afraid that they're going to see the news heading that T-Mobile has been breached that their information is out there, that their account got taken over all of a sudden and now millions of dollars are at risk.
And the benefits of that have been huge. It allows our organization to grow, allows us to be innovative and continue to move forward, knowing we will always have security front of mind, and we'll be good wherever we go to. I would say also that the -- sorry, lost my thought. I apologize, long flight yesterday. The acceleration to this with passwordless verification is great for us to be able to move on in a -- I apologize, guys. I lost my wording. I'll just dump to the end here.
I will say that the partnership with Yubico is the strongest thing that we've had in moving forward with our enterprise standards. If you're a small business enterprise-level company, having a partner in business is what's going to take you and go places. It's not something we can do by ourselves. And we know that Yubico is what's been able to help us deliver this new cultural change. It's helped us move forward and know that we could be secure in a climate that's always out to get you and something that we value more than anything else we can say. So we appreciate Yubico. I appreciate the opportunity to be here. Sorry, I stumbled a little bit there. But hopefully, this is helpful and looking forward to the questions and kind of talking about our journey with you going forward.
You can see that customers count on Yubico. And the reason they count on us is because they trust us. We've earned that right over the many years of work we've done in the industry and what we put forth as a company. And today, we continue to grow our relationships and our partnerships with both alliance partners and our end user customers in a really relevant significant way. And that will prove to be a winning proposition. We also know that there's a lot of other companies out there that trust our brand.
And this is just a small sampling of approved companies that allow us to put us up, but there's many, many more. You'll notice a few of the key customers up here, others that are in identity security as well, Okta, Ping, Microsoft all using YubiKeys as part of their solution to secure the environment. Those are significant mile markers where we partner with them, not to compete, but to partner for a better, safer Internet.
And we find that when we sell to a really relevant company or any company that has a good experience, that experience travels with them in their next location and their next job. Since I'm in charge of revenue, it's kind of important to have that as part of my go-to-market. So here is a customer that wasn't able to attend today, but he wanted to share his experience.
[Presentation]
I think Derek illustrates it well how the technology moved with him from Google to now Cloudflare, one of the most significant Internet providers for websites. I showed you this slide before because there's really 7 use cases that kind of apply to all organizations that we talk to. And what companies have transitioned to is instead of just protecting on a particular use case, many times, it was the one on the far left, which was privileged access, the people that are in the most sensitive data in the data centers, accessing forms and information about employees.
It's really moved to understanding that all their users are on the attack surface. And because all users are in the attack surface, companies must protect all those users. So it's changing very, very rapidly. Derek in the video kind of precursored this idea of what they're looking for in modern-day security requirements. They're looking for the protection for everyone in a simplified budgeting process with the highest level of identity security that's a simplified order process and that the rollout goes quickly and efficiently for their organization. You heard from Brian how quickly they rolled out over 200,000 users within T-Mobile.
And as a company, we started to understand that not only is our security technology important because if someone buys a key, they have a product. But if they engage with Yubico and with our Yubico as a Service, it becomes a solution. So wrapped around our technology and the good work that's been done for years and years, we have spent a massive amount of time, energy and effort to make this rollout of YubiKeys that much easier.
We provided organizations with a lower cost of entry, flexibility of choice of what form, factor or key they would like to have for what type of computer or what type of phone, we've created a way for faster deployment for -- through our Yubico Enterprise Delivery organization, and we're able to achieve that compliance company-wide much, much quicker.
So again, these are the kind of things that Yubico is developing. It's not only the technology, but it's the process, procedure and the change management required by all of our organizations to roll keys out and deliver back to their end users that high-level protection. So once again, I'm going to step aside, and I'm going to let Joe talk a little bit about his journey with Yubico as a 3-time CISO and former Head of Identity and Access for Bank of New York. Joe?
Thank you all. So I had the fortunate benefit of doing planned deployments across 3 times, right? So 3 different employers to go through and have planned not fire burning episodes where we had phishing-resistant MFA coming through. I've deployed YubiKey 4s, and that's usually the precursor to YubiKey 5 and the FIDO standard that is now, right? So there's a transition of -- like the ease of deployment has become easier and easier, whereas before we were doing U2F deployments and smartcard authentication deployments that meant deploying those is a little bit more technically challenging.
And you had to bootstrap a lot of that with some of the ykman command prompt capabilities that Yubico provided as a community. But as we started looking at this, I started looking at a line of business that I worked for -- at BNY. We started with a smaller deployment to prove that out. So I was a CISO for their analytics division and that's where we made our first purchase of YubiKeys 5 series for that line of business. We protected all the employees within that line of business and bootstrapped it to their identity platform and everywhere was integrated.
Some of the legacy systems that didn't go through the IDP itself had deployment directly in the ecosystem that is supported by Yubico itself. So having a wide breadth of vendors supporting YubiKeys is great for me as a practitioner because I know that if it can't centrally deploy using an IP, there's a very good chance that the YubiKeys will be used and integrated well within the tool of choice. Going forward in the corporate deployment across the whole workforce, we started to look at the flexibility of YubiKeys as a Service.
YubiKeys as a Service was interesting for me because we had the opportunity to look at the whole workforce and not make a deployment straight out across all 70,000. We started to look at how are we going to ramp the deployment and which particular audiences we'd want to achieve first. And with YubiKeys as a Service, we're able to look at how do we do that ramp, how do we deploy and then also cater to the different use cases that folks have. They mentioned privileged access, mobile users, all of those use cases have their preference as to which form factor.
We also worked with our help desk teams to look at, well, what computers are out in the fleet and where are they in the tech refresh cycles. So we would be scheduling the YubiKeys deployments with what tech refreshes we would have. So if it's going to be USB-C versus USB-A form factor versus a micro form factor within. So that all helped us out, and we were able to essentially schedule and track that within the portal itself. When it comes to some of the challenges that we had not necessarily with YubiKeys and deployment of YubiKeys, but more so about what prompted us to look at YubiKeys well, it's compliance. The financial services market is highly regulated and global.
And so you have all regions in the world deploying their own policies and standards. Luckily for us, NIST and the major standards bodies agree with the alliance and FIDO and we moved forward with deploying based on that assertion and the services as well. We've looked at opportunities where you continue to advance the technologies that you have in place, so 2-factor authentication is great. And I think everybody should be using that already, and there's many form factors to do that, OTP, SMS, but now the standards are also deprecating some of those because the attackers continue to advance.
And so you'll see that SMS is a deprecated standard for channel of OTP. And so you continue to future-proof yourself by using technologies like passkeys and YubiKeys in that instance where in the end as policies deprecate what used to be good solutions, now all of a sudden you'll be ahead of the game. This also allowed us to move towards a passwordless capability across our workforce. And so this was one of the core pieces of technology that we provided across the workforce for passwordless authentication.
We deployed biometrics with Windows Hello for Business and others, and we gave users a preference to look, but the gold standard was the YubiKeys for authenticating into all of our systems. And I'm more than happy to discuss any technical implementation details as well, but the YubiKeys as a Service platform and the flexibility it offered us was nice to have because you had a schedule that was fluctuating with time and the audience of where you'd want to deploy was also fluctuating. And so that gave us the agility to carve a nice path to deploy within a given time frame. Thank you.
Thank you. Again, just another testimonial to some of the work that's been done over the many years at Yubico, and I think it's really beginning to pay off for organizations of large and small. So I'm going to leave you with these 3 key takeaways. Organizations must protect all their users. I think we've beat that to death. You're going to hear a lot more about Yubico as a Service in future presentations this afternoon, and you're going to hear a little bit more about where we're headed with all that.
Customer speed and propensity to act is accelerating. With the standard being so well adopted now and other organizations coming alongside of that, we're seeing a lot of interest around the FIDO2 standard, again, Fast Identity Online standard. And Yubico is absolutely focused on surpassing the expectations and the needs of our customers. We've built trust with our customers. We've built trust in the industry, and they look to us to fulfill that in the future and continue to grow as a company. Thank you very much. Appreciate it.
Thank you so much, Carl, and our speakers. This concludes actually the first session or the first part of the presentation. So I'd like to welcome the speakers back up on stage, including Mattias, to open up for our first Q&A session.
There should be a mic going around the room. If there are any questions in the room, just raise your hand and the microphone will come to you. But I have a couple of questions actually from the web as well. So maybe just to warm up the room, I should start with those. So Carl, to start with you, how repeatable are deals like T-Mobile and Bank of New York? Are they outliers? Or do they rule, would you say?
Well, we focus a lot on the Global 2000 accounts. And there's areas that we don't sell to the Global 2000s, but there's about 1,600 Global 2000 accounts that we put a lot of focus on. Each one of those accounts represents unbelievable opportunity for the company and for Yubico. I think getting to them all is never easy, but we certainly are pursuing that every day. And many of those companies have deployed some keys over the period of time. So we're always after expanding that footprint.
And a follow-up question to that. How long does it typically take from an initial engagement to a signed contract?
Yes. It depends on the organization. There's the planned and the unplanned. In the case of the planned, for a large organization, it's anywhere from a year to 3 years. I mean you can pick a time. It depends how developed their team is. It depends how far down the path they are. In a small organization, it can be 3 to 6 months. If it's unplanned, hair is on fire, you got to act quickly. Those time frames get reduced significantly.
Thank you, Carl. And a question for Jerrod. Could you actually go back to the concept of passkeys and how that fits into Yubico's solution?
Yes. I think -- again, the industry didn't do a good job explaining passkeys and its relevance overall and how does it fit to the overall ecosystem from what the previous work was. You can think of passkeys as a way to login passwordless. And you can do this with YubiKey as well. You can log in passwordless with YubiKey. And you can also login passwordless to something like an iPhone, right? But it's not so much about the passwordless experience, it's the technology behind the passwordless standard.
For example, what we've known to be passwordless is what we call the magic link, where sometimes you go to travel site that says, you want to log in, go click the link. There are no passwords, right? It's just a link and you just click and you get in. So it matters more about the technology behind the passwordless authentication.
And the reason we say that is that this particular passwordless authentication, passkeys, FIDO is a proven, mature standard that interoperates between different operating systems. So you get a consistent experience using this particular form of passwordless authentication, which is really important. And why do we know that? Because we at Yubico created it. So it's not just passwordless authentication, it's standardized passwordless authentication that has been deployed at scale.
And then a follow-up question, why do customers pay for hardware when software passkeys are free?
When we always look at the word free, it comes with a whole set of expectations and assumptions. It's never free. You always pay for something. And if you look at the technology behind passkeys, you are storing it -- you are storing that credential, that element for you to log in somewhere. And so you have to think about more than just the hardware because the phone is also a hardware. The question becomes what happens when you get a new phone? What is your process? What is your backup strategy? What is your recovery strategy? Do you buy 3 phones to back each other up? I mean some people can.
But that's not a good expectation if you want to solve this at global scale. So I think the way that we think about the technology isn't so much about YubiKeys or phone, and I've described this a bit earlier, you kind of need both. Because anything with one is a problem. Because if you lost it, you broke it, you upgrade it and doesn't work anymore, it's a huge problem. What we bring to the table is a consistent experience using a YubiKey, right? Because Apple would have one way, Google will have another way, Microsoft has another way. So using a YubiKey creates a consistent experience, but also is a consistent security model. And I think testament to some of the companies that have described it.
I can even give you user examples, if you want, how it's benefited us, right? So in T-Mobile, I'll give you 2. Our retail organization, as I said earlier, uses iPads. So, it's our primary selling methodology. They're out in the floor, they're talking to customers face-to-face. It looks very poor if the customer is there and all of a sudden, the employees is pulling out their phone and trying to interact with that iPad. It may look like they're taking a picture, sensitive information or something that seems unrealistic or something they shouldn't really be doing there.
Having a key that's meant for that purpose takes away that whole conversation. It actually looks more secure to the customer. It makes everybody feel a little easier about the whole situation. Another piece would be call centers. We handle customer data in the call centers they're global or as well as United States based. In those organizations, don't allow cell phones on the Salesforce for them just to make sure they can't have a way to take data out and make it unsafe for the customer. So we have to have a key-based solution for them to be able to complete those log-ins where a passkey that's on a phone is just not viable.
And just from my experience also for an enterprise deployment, software keys or sinkable keys, you have to look at that key, that private material that usually sits on a hardware-bound device is now going to be living somewhere within an ecosystem of either Apple, Google or Microsoft or IDP provider, whereas if you have a hardware bound device passkey, then that private key is stored locally on a device similar to the YubiKey itself. So sinkable, software, passkey versus hardware, you actually know where the key material is, that is the root of the trust of that interchange.
We have a question in the room.
2. Question Answer
A question for Jerrod, and from a customer perspective. How many customers get away with kind of a standard FIDO2 key? And how many customers leverage like particular proprietary feature on top of FIDO or some embedded software aspect to solve for an enterprise solution? Not talking about the company with 10 customers or 10 employees.
I can say from T-Mobile's experience, we did not go with anything customized. We are using an out of box, not even the highest range 5 Series keys, and it works for the majority of our workforce. Certain use cases, we do have different keys that we use in areas depending on the form factor needed or other options that might be used for that user. But I will say from an enterprise perspective, we deployed a standard NFC USB-C key and it has worked for the majority of our use cases.
For me, I just had with the example of YubiKey 4, we did smartcard authentication. So like the YubiKey 5 has multiple protocols that could be deployed, FIDO, smartcard and so FIDO is the easier option of deployment across a wide broad use case. And so YubiKey 5s, for the most part are for our implementation were FIDO-based that map back up to either an IDP that we had across our workforce. So smartcard authentication is still available for YubiKey 5. We just didn't deploy it.
And just to give some color. So we talked a lot about FIDO on the YubiKey, but the YubiKey also supports other authentication protocols. And there was definitely a time many years ago where FIDO was not so mature. So companies had to use other technologies on the YubiKey to log in. But we've always provided the next-generation authentication protocol. And a lot of our customers, when they started the journey with us, evolved with that. So when the FIDO technology became more mature with the systems that they use, applications they use, they started to migrate, which is really a fantastic way to look at.
Don't -- you don't have to -- the keyword for enterprise, you don't have to rip and replace, right? Because it's a very expensive process to just change all the systems to work because I need to do with FIDO. And so companies can take this journey over a period of time, as Joe talked about, as they upgrades systems, it's the same YubiKey that support many different systems over a period of many years. So it really creates this great partnership of them working with us, changing the technology stack, but the user experience really remaining consistent and really a great experience.
And the adoption has been easier to a fee with FIDO keys, whereas smartcard authentication, you typically have PKI infrastructure, public key infrastructure, that has to be maintained within the environment for any organization, enterprise that maintains it. And so by moving towards FIDO and the latest generation of YubiKey 5s, you lessen the burden on current infrastructure shift to maintain and deploy with the PKI infrastructures.
We had a question here in the front. Do you want to take that?
Ramil Koria, Danske Bank. I'll show my complete subpar understanding of the business here by asking you about sort of the app ecosystem surrounding the YubiKey. How much of that is sort of bilateral in a sense? And how much stems from you operating within the bounds of the various protocols that you do have? And then a follow-up to that to the customers on stage, you said that it covers the majority of your use cases. How important is it that it extends the entirety of the use cases? Like what are the second standard deviation use cases? How important are they to be covered here?
Yes, I could start off with just the legacy systems like mainframes, right? z/OS, IBM mainframes, things that have not evolved along with the modern authentication flows for passwordless, YubiKey fits directly into those. There's modules specifically designed to have 2-factor authentication into legacy systems with YubiKeys, fully supported.
Very good. We have time for one last question, and I'll take it to -- sorry. Do you want to take it from room first?
Yes, please. Thank you.
To you, gentlemen, do you feel like you got a lot of security for what you paid? Do you pay just right or a little too much? Because based on your customer cases, you have -- it sounds like you get a lot of value. So how do you think of all these projects in relation to the costs?
Yes. I can take that. I think the cost of not being in the news and not having a breach and what it means to our brand has far surpassed anything that we paid for our keys and our deployments that go along with that. I mean, looking at it, there is a cost involved to it, and it will be for any business that goes into this. But the peace of mind that we get out of it and what that has meant to us has paid for itself leaps and bounds over.
If I could speak from a CISO perspective, right, running security programs in general. You tackle the biggest problem being the identity problem. So now you have all the other problems in the security space to deal with. So at that point, you've already tackled a big elephant in the room by identity with a golden standard like YubiKeys to have your team now focused on other threats that are in the ecosystem.
And then maybe just a quick follow-up. I don't know if this is to Mattias or to Jerrod, but how often do you think that either T-Mobile or Bank of New York should replace these keys to keep this high security posture?
We'll cover a little bit of that in terms of the evolving landscape for what we call cryptography. I think a testament to the design of our device and the standards we create. Well, we're looking at it from 2 angles. The first angle is that if you want to use the YubiKey with a system that hasn't changed, you should have the right to use the YubiKey. Like that shouldn't change it. We can't break people's way of working when it works, right?
But the other angle as well is that there are things changing around the standards. And what we mean, Albert is going to cover a little bit of that is that there's a whole new cast of technology advancement, just like AI. In the world of security, there's this word call post-quantum cryptography that changes the dynamics of how you need to create protections and products.
So independent of like Yubico's leadership, and things around completely in cyber, cyber has a lot of technicalities when that whole evolution change as a market, Yubico needs to be #1 in terms of leading that change. So as all our customer says, you're only as good as the next big threat coming to the industry. And rest assured, attackers are not going to slow down. So we at Yubico look for those signs of change and shifts in technologies, AI included, to make sure that we can protect our customers.
If I can add a little bit more, less technical color to it. One of the things driving why we think YubiKey as a Service and the service and subscription model that we offer is superior to both parties is that, that really forms that partnership. We work with the customers on what's most important to them, what they're seeing in the threat landscape and make sure that we're the partner there to protect them, whether it's new threats or new regulation coming up.
Even from an experience for me, going from YubiKey 4 to YubiKey 5, right, you had a technical evolution and innovation with YubiKey and Yubico's where they went and supported FIDO versus the U2F protocol, legacy protocol. So you still had U2F and you had smartcard authentication with YubiKey 4, and that was the golden standard and did the job at the time, and we get speed there. But what compelled to go to YubiKey 5 was the support and broad support for FIDO authentication going forward. So the evolution in the product line forces customers or it compels customers go that way.
So now maybe to the last question to our customers. Would you say that your employees typically use YubiKey to protect specific accounts? Or is it wider systems?
I can say this like there -- it's a 1:1 ratio, of course, every user has their account tied to that. And then they're accessing a wide range of customer accounts and things of that nature. So they're protecting everything at that point in time once you're logging into those systems. But that is the foundational piece. If it's them getting into their system and logging into their computer or their iPad and then getting into the tools with tenets, it's all done with our YubiKey.
And it's not only for the workforce, right? So you have the workforce supportability, but also now when it comes to authentication mechanisms for clients, right? There's opportunities to open up passkey support for client interactions and client portals to authenticate as well, using YubiKeys or using other passkeys within the ecosystem as well, call that Bring Your Own Passkey, right?
At the end of the day, we're not supplying passkeys directly to clients as of today, but those are opportunities where now clients because they're using it in their personal lives, they have a YubiKey or they have other hardware-bound passkeys could easily bring to the platform and authenticate it to the platform with a passkey.
Thank you so much to all the speakers. This concludes the first part of our presentation, and now we'll take a short break for about 10 minutes. Thank you.
[Break]
So welcome back. We're going to start the second part of our presentation. And now I'd like to welcome Albert Biketi. [indiscernible].
Thank you so much, and I'm really glad to be in front of you today to share a little bit about Yubico's technology journey and leadership. And I will try and make this as accessible as possible to a wide audience. So if I take some of the concepts down a little bit, but I will try to make it accessible to everyone. And what I'm going to try and cover is a couple of things. One is what it is that Yubico is building? And why we care so much about the way we build it, the way we are building it. And a little bit about our journey on innovation. I'll talk about what's currently being built and how it's built and why that matters. And at the end of the discussion, hopefully, it starts to be clear to everyone the foundation that we've laid for all the future innovations that we do for our customers because we are building our customer base because we want to give them even more innovation. And so we look at -- this as a very long-term journey that we're on.
All right. So by focusing on what it is we're building and the -- why that hardware architecture is such a winning combination for high-assurance identity, hopefully, you'll be able to see that trajectory. And bear in mind, this is a long, long-term journey in terms of just understanding all the layers that build on top of each other.
All right. So if you remember anything from this slide, it's that Yubico doesn't just follow standards. We contributed substantially in writing those standards. And then we built and shipped the authenticators, the hardware that makes these standards real and at scale. So when we look at the landscape and see everything that is changing, we have an eye to what that standardization looks like also into the future because Yubico's uniqueness comes from this combination of a very strong innovation ethos combined with the standardization that creates the potential for mass adoption.
So we co-lead in FIDO, the fast identity online, in Open ID in WPC all these groups that defined collectively this massive move away from passwords to passwordless. And we're continuing to define that journey for continuous authentication. And so when you see something that says FIDO or WebAuthn, compliant, you're actually looking at something or dealing with something that has a little bit of what we made possible and we made it -- part of that invention possible. And this is important because this is all open standards, the folks who control a lot of how the web works. So think about Apple, Google, Microsoft, are all able to interoperate cleanly because of some of these standards that we set. But the way to think about it is Yubico is actually this hub that allows you to abstract away from those platforms as well and own your identity and own the route material for your authentication inside a key that you possess. And this will become important later because there's big trends in the world around decentralization, particularly here in Europe. And so you'd appreciate why it's important to actually own that piece of your identity.
All right. I don't know if anybody here was born in May. Can I get a show of hands? May? Okay. We've got a couple of folks. So now if you're very interested in passwordless, the first Thursday of May used to be World Password Day. And for safety reasons, they changed that to World Passkey Day. And that's because this shift away from passwords is real, it's deep, and it has a lot of things around it that are fundamentally important. So if we just look at where we are today, if I was standing here 13, 14 years ago, I would be telling you there's going to be billions of people using passkeys. And except for the people who really truly believed and understood the path that Yubico was paving at the time, people would say, well, I don't know what you're talking about. But if there's going to be perspective that you're able to take about what it takes to build things that have massive, massive adoption, that's the journey, and that's the vision. It was very, very clear that far back that passwordless adoption was going to grow to become this big. So to give you an example, just from 2023 to 2024, the adoption of passkeys in online accounts doubled to 15 billion, it's probably going to grow at about that trend for a significant period of time. Now what's changing underneath all of this that gives us confidence that this is happening. One of them is password -- platform readiness. The second is top site adoption. So if I look at the top 100 sites today on the Internet, about 20% of them support passkeys. If you look at the top 250, about 12% of them supported, including Apple, Google, Microsoft, Amazon, PayPal, Tiktok, et cetera. So there's massive adoption going on and a lot of conversion happening. So this is a fundamental mega brand, and it's important to understand it in that kind of context. Then consumer awareness and use is also going up. And so just looking at some of the statistics that we look at, something like about 40% in 2022 had awareness. It's now doubled to about 60%, and that trend continues. And we're also seeing the data that we see this in the proof of behavioral changes and other things that support it. So the conclusion, I hope you all draw is that this is very well supported in user behavior, and it's not hard to intuit why. It's because it's easier and it's safer. And those 2 things in combination are magical for security because every time you build security that is an obstacle to getting to what it is you want to do on the other side, people find lots of ways to bypass it and it's magic for the hackers. So making security easier to adopt is one of the fundamental roles of the passwordless movement, and it's been something that has been very, very successful.
All right. Jerrod talked a little bit about this earlier. And the power of the developer ecosystem that you've been able to build around FIDO, and actually goes to a question that was addressed earlier, which is how much of this is one-to-one versus how much of this is because of the standard. So if you're building with FIDO and FIDO compatibility, you're able to tap into a massive ecosystem. And so this is kind of the logical approach. And so there's going to be always support for a lot of legacy complicated things in the technology. But the fundamental goal here is to make security easy and widely adopted in ways that you have a challenged response that gives you a high assurance of secure authentication without phishing. And so U2F was the web-scale protocol that actually led a single hardware key be used across hundreds of relying parties. And relying parties, you can think of them as the folks who have a website that is going to be the real website that you don't want a phishing attack to impersonate. And so this relationship between relying parties and the relying party infrastructure and the YubiKey is a fundamental one. But one of the things that start a neat innovation about it is you're able to have this key that can connect with all these relying parties, and none of them have to know anything else about any other other place you authenticate. And this was a really key piece of innovation about the way we did this. When you combine this with a very simple API for developers write to, that's what turns this into a key that unlocks so many different services. So again, really important to understand that this mega trend and massive multibillion user adoption is inevitable, and it is driven by foundations that are extremely strong and well supported, right?
Then this is something Jerrod showed also a little bit earlier that I'd like to emphasize. I hope you can still hear me clearly. Okay, good because the sound changed. But what this slide shows is an independent assessment by Gartner that shows where on the continuum from very, very low reliability from a security perspective, to very, very high. And I mean, just go back 3, 4, 5 years, for a lot of things. The password is so so familiar that when we show this slide, people are surprised just how low it ranks in terms of giving people high assurance of security. What this slide should make people feel is the urgency to get away and move as high as possible. But that journey is not linear and it's not easy, and there are a lot of things that Yubico is doing to make that journey and that transition easier. When Brian and Joe stood up here and explained to you the journey, there are many organizations where over time, we found the missionaries who are interested in making this journey work. What the missionaries do is they open it up to more people in the enterprise. And our job really and what I'll show you is how we take that and convert it into a much more scalable service to help people through. And that combines both the physical and the logical delivery of that value. But what does it mean to be at the very high end of this? It means you either have a FIDO2 security key or that X.509 hardware token is basically the equivalent of like, for example, what's used in the U.S. federal government around kind of PKI-based credentials that are strongly linked to a physical device that will be called [indiscernible] in the federal government in the United States. But really, YubiKey is basically are able to give you this across a variety of environments. And what we know is that in very, very high assurance and basically, in any use case where you really, really care that you're going to be the right person doing the right thing that YubiKeys are always going to be one of the solutions that is preferred for giving you that high assurance of indication.
All right. I'm going to take you through the insights of the YubiKey for a bit. But as I do that, I just want you to understand this magical device on how to think about it. So this is a small device. I have one right here on my key chain. The framing that I'd like you to have as you think about a YubiKey is that, this is a piece of critical infrastructure. I say that again. It's a piece of critical infrastructure. Why do I say that? It's a piece of critical infrastructure because we are deployed in places where our customers are dealing with nation-state adversaries on a daily basis. In other words, somebody is trying to make sure that nothing works. And this key sometimes sits in between that and the provision of normal services, it might be energy, it might be some other reliable thing that you need. But even in high conflict zones where people need cyber defense as part of defense, these keys are proving to be part of that high critical infrastructure. So the reason why that's important is because we built them to behave like infrastructure. So if you look at the inside of the YubiKey, it has this chip -- single chip design and it's designed to be extremely resilient with a secure element that actually meets extremely high valuation. Our supply chain is all based in Western countries with a supply chain that is very carefully selected with very secure manufacturing. We do write our own firmware. So everything on the YubiKey in terms of the firmware, [ at the station chain ] is written by our internal engineering team. It's tested extremely well. And -- you recall mission that it has a touch sensor that makes sure that you can't impersonate touching it. It needs to be touched by a human in order for that authentication event to be complete. It has a whole host of certifications with it. It's built with a unique blend glass and plastic around it so that it's tamper evident. And it's actually sealed and has no moving parts of batteries. So it doesn't actually need to have a power source built in it. It generates power from what it's connected to either over wireless or over a USB connection in order to work. And that's fundamentally important because these things actually survive wash, rinse, dry cycles in dishwashers and washing machines and people use them for years. They're highly, highly reliable devices. And we have this variety of form factors. I just mentioned the one right at the end, it's called the Nano, and this is a typical YubiKey deployment that you'd find attached to computers. And so it basically stays constantly plugged in. And every time you have an authentication event, you just touch it. Once I plug one in -- I worked at Google before I joined Yubico, it's always plugged, you just touch it. And that's part of the authentication chain.
Now we have our manufacturing and -- secure manufacturing here in Sweden, in actually Norland and Småland, and this is -- I've been to the factories, a couple of different factories and kind of had a good look at what the capabilities look like. I'm going to play a short video. It's about a minute long for you to get a sense for what that manufacturing process looks like.
[Presentation]
Right. So that just gives you a breakdown of why we build, what we've built and why we care about it so much. We think about -- our mission every day is providing critical infrastructure because when people take over credentials, bad things can happen. Now in the spirit of talking about big things that change in the world. I'll shift and talk a little bit about what it means to go from classical to quantum safe computing. So this can be a very dense and complicated topic. So I was trying to think about a way to explain it that everybody understands. Today, we live in a world of classical computing. In classical computing, you have the concept of bits and bytes, a 1 and 0. In the quantum sense, you have this world where you have a super position where a bit or an object can't be either 0 or 1 simultaneously. And that creates enormous power from a computing perspective but it comes with a lot of problems. So the best mathematical explanation I can give for why classical encryption algorithms break, it's because of a time architecture problem. So the way classical encryption works involves factoring very, very large numbers and figuring out exactly what the solution is in them. It just happens to be something called a quantum Fourier transform that can take even an extremely large number and figure out the mathematical pattern around exactly when you peaks in certain ways that, that number of patent forms. And so this makes the entire foundation of encryption we depend on vulnerable to basically breaking and being replaced by capabilities that quantum computers can do. And so we had to think about a way to actually create new encryption algorithms to replace this. And almost everything we know today in encryption will have to go through this transition to become quantum safe. And so there's current attacks that you hear about, like gather all the inflation now, store it somewhere and then decrypt it later. And it's just a -- it's kind of -- it's going to be a big journey for people to go around in the next several years, this term called Q-Day, which kind of talks about what that looks like. And we're not waiting around for that. We are solving that in terms of what an authenticator needs to look like and operate in this post-quantum world. And so actually, the leader of the team that built that post-quantum YubiKey is here. I don't know if Alessio is here. Just wave, everybody can see him. Yes, there he is. So I'm incredibly proud about the fact that a month ago at the FIDO Authenticate conference, we showed what we are doing in this area. And you're just going to see a short video, but I'll explain something about the -- what this technology does in order to kind of stay ahead of this quantum resistance. You basically have algorithms called module lattice algorithms that make it incredibly hard for quantum computers to break. And in the break or a follow-up, I can kind of give you a simple explanation for how they work. But you can think about it as making it impossible to guess how many things you could buy in a grocery store, that has like 1,000 dimensions. Like that's the simplest explanation I can give. But this is a big deal because all of computing is going to change because of it, and Yubico is at the forefront of making this safer in terms of authentication. So here he goes.
[Presentation]
So earlier, 2 of our esteemed customers shared with you what this journey looks like. I'll just touch on 2 parts of this journey, and it's the user enrollment and delivery. And think about that as the logical and physical delivery. It's very, very important that the right YubiKey arrive in the right customer's hands. And creating this life cycle is actually pretty difficult for a superhero or a missionary inside an enterprise because the typical person that you'll find will say, well, I'm running an identity and access management program, I want to move to passwordless. I have 5,000 employees in 33 locations. Well, am I going to attach this to the rollout of phones? Like what am I going to attach it to? So what YubiKey as a service is we created basically the capability to run this all in a way that feels seamless. But you should think about the fact that we're doing physical analogical delivery as the first step in building a foundation for what comes next. And so what YubiKey-as a Service then looks like is all of these capabilities, being able to deliver value over multiple years, you can have provisioning for loss of keys and replacements of keys, you have flexibility of form factors that you can procure. You have faster deployment. We work with you to understand exactly the challenges of what your deployment looks like. We'll have a look to see that you're actually truly phishing resistant because there's many places that you can implement this that end up not being -- you can leave open doors and you can lock one door with YubiKey and leave other places open. And -- so we want to help people do that so that they truly achieve compliance. And so this YubiKey as a Service serves as the foundation for us to be able to go out and serve a lot of our customers, and I'll let you watch a short video of what looks like.
[Presentation]
So we do this over 100 countries, but that's like the physical side. What this diagram shows and I promise this is the most complicated thing I'm going to show is, how there is an interaction between the customer environment and the Yubico environment to either deliver a remotely preregistered key, so that's one touch, it works or a physically pre-enrolled key where the programming is done in the factory. So when the key arrives and the key is for Mattias Danielsson, it is the correct key and it works just for him. So being able to do that and deliver that reliably sets us up with an incredible foundation for what we're going to do next. So today, we are penetrated in about 30% of the Global 2000, about 5,000 enterprise customers and continue to grow. But all of this actually sets us up because this is a user base that is increasingly moving to subscription because they see the value of what we're doing and they want an ongoing relationship with us. They want to see that innovation come through. But what this then sets us up to do is once we start to eliminate these risks that our customers are facing and reduce that deployment friction and provide this turnkey solution, it ends up being the foundation for something really magical for our subscribing customers because we can come back and offer them what the future holds, because passkeys are just the foundation. Passwordless is just the foundation for future innovation that we're going to show. And so our customers are basically walking that journey with us.
So in order to explain how the magic works and how the financial model works around what we're doing, I'm happy to have Snejana, our CFO, come.
Yes. Definitely, Albert deserves a lot of applause. Hi. Great to be here. So let me try to give you some of the basics of how the business models actually works in our financials. But before that, I would actually like first to start with how we have developed since we went public financially. So taking a little bit of a longer-term perspective since 2022. And then we deep dive into the business models overview. So we went public, not that a long time ago, and we've had some fair challenges, like in the Q3 now that we reported last week. But if we take a little bit of a longer term, we have seen actually quite good long-term growth, both in order bookings and net sales. We do face some volatility quarter-over-quarter in our bookings, which is primarily driven by the timing of closing large orders. As Carl said, some of these large orders might take years to close from the start of the opportunity until we actually close it. But we do have a very nicely accelerating YubiKey as a Service, both bookings and annual recurring revenue, which I will zoom in further.
We have a very stable gross profit of about 80% over time. We see our operational expenses are growing with -- as we are growing. We expect them to kind of scale going forward. And our EBIT has really improved since 2022. We are challenged as we reported by a little bit of lower net sales growth in the latest quarters. Still, we are generating positive cash flow since -- in the last 3 years, and it's been going very well. So just, again, to take a bit longer term, bookings are growing with 15% CAGR on average since 2022. What we see is that really the YaaS bookings, the YubiKey as a Service is growing very -- in a very accelerated way with 27% CAGR, but we have a bit of volatility quarter-over-quarter in the order bookings. Why is that? If we look into our -- actually, the deal size breakdown, and I'll pause a little bit on that. You see that we have the large orders that are above SEK 3 million, they take longer time to close, there will be volatility quarter-over-quarter, whether we actually close -- some of these big orders or they kind of go into the next quarter. However, our small-sized deals or small, small, there kind of the majority of our deals being under the SEK 1 million, they are fairly stable. They grow very nicely over time. So it's the volatility quarter-over-quarter is very much driven by the large orders.
If we look into the long term for the net sales growth, it's also growing with 14% CAGR. And again, here, we see a very, very good acceleration in the YubiKey as a Service sales. It is growing with 33% CAGR since 2022, and it now represents 16% of total net sales. And to remind, our long-term net sales target our growth target is 25% over the next 5 years.
Our gross profit margin is very stable. It's about 80% over time. Again, going back to what Albert showed, we have long-term standing partners and vendors. We work very closely with them. They are in Europe and Sweden, and it's been a stable gross profit over the last -- over the quarters. There is one note -- one thing to note is that since our partners are primarily in Europe, our vendors are primarily in Europe and Sweden, while the majority of our revenue is in USD, we do have a bit of currently negative currency impact.
And when we look into the OpEx or the operational expenses, the majority of our operational expense is actually the cost of our teams. And in 2024, when we had a very successful sales year, we see that [indiscernible] of the operational expenses are scaling. We do expect this scaling to continue forward as we grow going forward.
One thing to note as well is that we have 2/3 of our employees in U.S. -- in the U.S. So currently, as the SEK is strengthening or has strengthened versus 2024. We do have some positive impact on the cost. So if we compare year-on-year, the cost, you could see that that some of our employee cost is decreasing, but that's not because we are decreasing teams. It's more of the currency impact.
And with that, basically to recap, the EBIT has improved really from when -- 2022 from minus 3%. Now we have reached some quarters of 18%, 19%. Currently, it is the -- the LTM is 14%. It's really -- EBIT is impacted by our net sales number because gross profit is very stable. Our operational expenses are also very stable. We expect them to, again, scale forward looking forward as we grow further in our net sales, which will drive, of course, EBIT going up.
And lastly, just to kind of pause on the cash flow. We have generated positive cash flow since 2022 and really improve 2023 and onwards. If we look into our cash flow from operating activities, it's as well very, very positive. We have had some -- we have had outlays or negative change in inventory. I just want to remind, though, why that is. In 2022, we had a capacity constraint of one of the major components of the secure element that, again, we showed in the previous videos. Then we had only 11% of inventory of the sales for the year. And this was very, very critical moment for us because it basically was a matter of business continuity and whether we would be able to deliver keys to our customers. So at that time, we have actually secured capacity with our vendors for the next 3 years. And we are aiming to maintain inventory of about 12 to 15 months of sales.
In Q3, as we have also discussed in last week, we have received the last shipment of this capacity. We do have a little bit of higher inventory as of today. But going forward, we are having our secured vendors or our vendors that we work with. So we will see some movement there. But still, our cash flow, basically net cash flow or both cash flow from operating activities and cash flow from net cash flow is very positive. So that's on our kind of long-term financial performance.
So let's now deep dive into the business models that we have. We have 2 business models: the perpetual business model and the YubiKey as-a-Service business model. And these 2 business models differ in how we provide the product and how we provide the service but also how we recognize the revenue and how our financials work in these 2 business models. The perpetual model is basically the customer orders case. And more or less, they take care of the entire deployment with very limited support from our side. In the YubiKey as a Service model, Carl talked about it. Albert talked about it, but it's basically, we provide -- we are the technical and the solution partner to the customer in this model.
So the perpetual model was the original model that YubiKey -- or Yubico launched with in 2007. In 2020, we launched the YubiKey as a Service model. And this was really driven by customer demand for having good support, technical support, service and basically be with the customer throughout the journey. So how does it work? Just illustrative for example. Perpetual model is very straightforward. We get an order, we report the order value as we get it. Typically, we are able to ship the keys more or less within a very short time frame. We recognize the cost. We recognize the gross profit. Typically, our payment terms are within 30 days, so we collect the cash. So from order to cash, it's a very straightforward, order, revenue, gross profit, cash. Of course, this is the illustrative and kind of the ideal example. Real life is a little bit more tricky. There are a lot of factors that impact when we recognize the revenue. When do you see the drop-down from order booking into revenue. For example, timing of the order. If the order comes on 30th, we don't have time to ship it on the 30th, so we will report the order booking in the quarterly report, but the revenue will come in the next quarter.
The deal size, some of our deals that are -- especially the ones that are above $1 million, it involves a lot of keys to be shipped. It might involve a lot of addresses to be reached in a lot of countries. So the larger the order typically means also a little bit more complex logistics. And since you recognize the revenue when we have actually delivered the key. So the timing of delivery will determine when we recognize the revenue. Again, typically smaller orders, we are able to ship in -- quite quickly. Large orders might have some complexities in terms of logistics. Not only that, some customers might want actually a phased approach and have different deployment choices. So again, kind of the time of delivery will determine our revenue recognition. But in general, as a concept, it's a very straightforward model. From order to cash, it's a linear sort of for drop down very -- in a very logical way.
When it comes to the YubiKey as a Service model, again, very illustrative example, let's assume that we get a service order or an order of SEK 20 million or SEK 21 million for the simplicity of calculations. This is an order for 3 years. So this is a contract where 3 years, we will support our customer, both in terms of the deployment of the keys, but also in the entire lifetime of actually using the YubiKey during these 3 years. According to the IFRS, we recognized the revenue for this contract over the lifetime of the contract. So every year, SEK 7 million being recognized. Typically, we will deliver the keys during the first year and recognize the direct cost of these keys during the first year, which means that the gross profit then is a little bit lower, but then the second and the third year when the physical keys are already delivered or the majority of them, then the gross profit is much higher. From a cash collection point of view, from payment, typically, we -- the invoice is issued or is done 1 year in advance. So from a cash collection point of view, it follows more or less the revenue recognition. Again, this is a very sort of illustrative and straightforward example. There are other factors that impact the timing. For example, their ramp-ups, some clients or some customers will start with a pilot, will move into kind of next phase and third phase, and that will impact how we kind of plan or plan the revenue recognition. The contract duration typically is between 1 to 5 years. The majority is 3 years, but there are, of course, cases going up to 5 years. So that will impact how we recognize the revenue.
From customer delivery choices point of view as well, this impacts how we recognize the financials, more so from a direct cost recognition rather than revenue. Typically, when we have activated users, even if the customer has different delivery choices, the revenue recognition starts from activating the users.
So that are the fundamentals of the 2 business models. I would like to zoom in a little bit more into the subscription model of the YubiKey as a Service model and specifically on our annual recurring revenue. We have seen a very, very good growth of 23% in our annual recurring revenue since 2022. And I would like just to pause a little bit here and read what is our definition of annual recurring revenue. So this is the total contract value at the time of the reporting or the end of the reporting period of contracts that have started and then we divide them this total contract value by the remaining duration of the contract. By definition, this makes the -- our annual recurring revenue, actually a forward-looking metric, and forward-looking metrics for our next 12 months of subscription sales. So actually, if you put together a chart of our annual recurring revenue, as we have reported it every quarter since 2022, and our next 12-month subscription sales, you see almost 1:1 correlation. Of course, there is a small difference here and there in the quarters, primarily, it is from kind of changes that are coming into the ARR and some currency fluctuations. But since our base is quite large, basically, ARR is a forward-looking metric for our next 12 months of sales. And this might be very simple, but kind of just to set the scene, our growth drivers in the annual recurring revenue is both growth of existing customers, but also adding new customers to the model. And the growth of existing customers, you can break it down into renewals, expansions. So customers that have already a contract, but they expand their user base. And the negative part is if we don't manage to renew contract, which is churn. The net reaction rate would be -- or the net retention then would be the sum of these. So the renewals plus the expansions minus the churn and the rate would be the change period over period. The new growth is consisting of when we convert perpetual customers into subscription. And of course, of new customers or new orders.
So if we look into our 23% growth of ARR, we started with SEK 207 million. We have retained SEK 23 million of ARR and the rest comes from new growth. There's one thing to kind of to just be aware of is that retained ARR is based on this space. Of course, within this new ARR, we retain this as well during -- in between the periods. And on the left-hand side, yes, our net retention rate has been consistently over the years, above 100%, which means that our customer stays with us and they renew and they extend.
So to recap, let's compare back -- or let's go back to comparing the 2 business models and especially the pricing models. The perpetual is a onetime purchase. Typically, we have a price per key. We do have some additional or there could be services or like shipping services and things like that. But the model is a price per key. In the subscription model, it's price per user. We have services included in that, of course, could be -- it is everything from technical support, dedicated customer success manager, the enrollment suite for onboarding and all that.
So how does the same scope of protected users would look like. If we take like, again, the same scope and I'm taking at least pricing, how would it look like? When we get an order booking for perpetual, we recognize it or we report it immediately. For subscription or for YaaS, we will report the total contract value. So it will be typically a little bit higher. But if we take it over the 3 years, a perpetual customer typically has repurchases, expanding or replacing keys, et cetera. So over the 3 years, typically, what we see is that a subscription value in the orders is about 20% higher than for the same scope of a perpetual customer. The net sales, they follow through, just the profile is different. In a perpetual, we would recognize the revenue immediately. More or less [ 1:1 ] as the order booking. For subscription, we will recognize the revenue over the contract term. So in this case, over the 3 years, it's 1/3 a year.
From a direct cost COGS perspective, so the cost of the keys. Since in this example, I'm taking kind of the same scope, so same number of keys, the cost is the same, which means that as a percent of revenue since the pricing is higher in the YaaS, it's -- the cost is -- the direct COGS as a percent of revenue is lower and then the gross profit is respectively higher. So -- and that's not a -- it's not a coincidence of course. We provide more value, more services, and that's natural that kind of from a pricing perspective as well, the subscription model generates more revenue, more profit over time. Now we often get the question, how does -- how transition to more subscription would impact our financials? And especially like if we take it in a bit of a longer term, how does it relate to our financial target, et cetera. So I've shown that the YaaS model basically created by definition, higher revenue. And it does so because the solution that we are providing has like bigger value for the customer with all the technical support and all the services around it. If we continue to gradually increase our subscription share, which is the dark green scenario, we will see also that the sales growth will gradually -- will be kind of matching gradual growth. If we are a bit more aggressive with the subscription sales and we go more aggressively towards a higher share of subscriptions, we will see that revenue growth will be lagging somewhat as compared to the order booking growth. And that's natural because again, we recognize the revenue over the period of the contract. But both directions will -- as we grow kind of order bookings, we will get to the same place. It's just the time or the path will be somewhat different.
So with that, I would like to reiterate that we are staying committed to our long-term financial targets, which are the 25% net sales growth and 20% EBIT margin and that we are primarily reinvesting our cash flow into growing our teams and investing in all the great things that my colleagues are describing. So thank you.
Thank you so much, Snejana. I'd like to welcome back Albert Biketi and Mattias on stage and open up for our second Q&A session. Welcome back.
And again, maybe start with a question from the web, so the room can get a little warmer. Albert, first question is for you. Is hardware a long-term strategy or a temporary bridge until software reaches parity?
Hardware is absolutely a long-term strategy. And the reason it's a hardware -- it's a long-term strategy is because having a second factor for authentication that provides high assurance is fundamental. You can't -- if you have a phone as the primary device that you're interfacing with to the external web or a computer, high assurance means that, that phone can't touch itself. That phone can't prove that it is being controlled by a human. And so there's always going to be scenarios where you need a second factor. And second factor authentication is just fundamental. So yes, it is an absolute long term. It's not a bridge. There is a place for software-backed keys with -- there is a place for convenience for cloud sinkable keys. But if you want high assurance, you're always going to go with a strong second factor.
And if that's the case, why hasn't security key adoption reached mass scale yet?
It hasn't reached mass scale yet because the journey there requires big transitions for people. People have gone very, very used to passwords as a way to authenticate. And this is just -- it's just the way it is. Change is actually much more difficult than it sounds. And we're now at the pace of change where we have enough of a community that people really see the value of this and people can see the pioneers before them have done this. It's a magical place to be. In a lot of the conversations that I have with our customers, people who aren't yet ready to go on the journey are able to listen to other customers who've been on the journey and seen what that looks like, the mistakes, the challenges along the way. You put yourself in the position of a bank, for example, that has everybody on user name and password. Today, the scenario they face might be that they have a certain amount, percentage of revenue that is being lost to fraud, account takeovers and the like. And so they have to do this calculation where they look at that and they look at what the complexity of change might look like. And the fact that as they take people from passwords to passkeys, and passkeys to strong second factor authentication. The promise planned is to get to a place where there's 0 account takeovers. The middle ground is figuring out how to help people with transition. People don't have the same phones, they don't have this. They don't have that. So that's the journey. It's always a bit of a complex journey to get there. But the momentum, as I said earlier in my presentation is unstoppable. The foundation for this has been set. The standards are reliable, highly scalable. So I'm just confident it's a matter of time.
And a question for both you and Mattias. What is Yubico's R&D focus right now? And what will you focus on over the next 18 months?
In terms of focus, I think Albert will share some of that in the next session. So not to steal your thunder.
So I will share some of that in the next session. But I think the key takeaway that is a bridge from this session to that is we're establishing this base of subscription customers because there's more value to give them that the strong authenticator and the foundation that we've already built. And so that's the way we should be thinking about the value of the customer base we've built on value that we continue to give them. So our innovation focus on the additional value that we can bring when you start to solve the basic authentication problem.
And now to Snejana. Do your financial targets still hold if subscription adoption accelerates faster?
As I've shown, they should hold. It's just the path would be a bit different from a net sales growth perspective.
Will you work with pricing to incentivize the different models?
Our pricing is set so that kind of reflects the value that we provide to the customers already. So I think we are -- every customer case, of course, is different, and we take the value that we bring in creating the specific pricing for -- quote for our customer.
And then what about volatility? How do you see that it will persist as the mix changes? Perhaps a question for both you and Mattias.
And to Carl as well. Volatility in the large orders, in particular is -- it very much is driven by the time it takes for large organizations to take these decisions. I mean, large organizations don't take necessarily sort of very quickly decisions to invest $3-plus million.
So the volatility for those of you who had a chance to look real quickly at the chart that Snejana showed, 3 things really stand out there if you ask me. One is the big volatility of the large orders in between quarters. And then you can see a seasonal pattern if you look real closely seeing that Q4 is typically a really strong quarter historically. But those 2 aside, if you look at the orders sub-$1 million, there's a pretty consistent pattern there over time. And that's what makes me more reassured about the fact that we're on the right trajectory and that even if you see the short-term swings, we remain committed to the financial targets that we have.
As Snejana and I discussed this before, we had this day, and we decided to only focus on the numbers that we have been made public since -- publicize -- since we went public, so in '22 onwards. If you take an even longer perspective, I've been around quite a long time. If we take for the last 5 or 7 years, the average annual growth rate has been about 40%. However, year-by-year, I think it's varied between minus 17% and plus 102%. Of course, there are no guarantees for the future, but I've seen this volatility long enough. And as long as I see that underlying trend of run rate business, nothing bad with that, but orders below $1 million that makes me confident in the long-term viability for sales growth.
Yes. I think one more point, as we are growing our subscription customer base, our order book will always be sort of -- we will have volatility, but our net sales will become more predictable because we have the annual recurring revenue. We have contracts. We work very diligently in renewals of our contracts. So I think as the share of subscriptions is increasing, our net sales will become more predictable as well.
Just our order intake, not...
Order intake.
We have a question in the room. So let's take that.
Yes. [indiscernible] question for Albert. So if you compare YubiKey to a competing vendor selling a plain vanilla FIDO2 key, do you have anything in the firmware or any features on top of FIDO that's important for enterprise customers?
Yes, a ton. So I could spend the next 7 minutes talking about it, but I'll keep it to 1. So one is -- the fact that we build our firmware and test it and have done that in a robust way over 6 generations is incredibly important. Many of our competitors are in the first or second generation of doing anything in this space and do not have the long history that we've had with extremely demanding enterprise customers, holding our feet to the fire.
Second thing is we are focused on delivering a life cycle of value around our enterprise relationships. So we're not comparing a key to another key. You're comparing a key with a bundle of value that comes around that, including a very robust way of delivering both the physical key and the logical credentials around it so that, that whole process is phishing resistant. So for a lot of our customers, the choices that they make are about having a strategic partner that can walk this journey with them and having a strategic partner that can think through the implications of doing this classic to hybrid to post-quantum transition as well. So for us, we feel very comfortable that we are able to differentiate that value in the market.
And just a follow-up on that. If you have a proprietary feature like touch design, how decide if you want to add it to FIDO2 to make it easier to roll out or have it more proprietary secret sauce so you actually differentiate and build great interest to value over time?
So for us, there's always a trade-off between running with the standard and building extensions on top of it. And the way FIDO is constructed actually allows us the latitude to do both of those things. I think for us, our heart is always going to be in the place where we want to make digital identity safer for everyone. And so there's a lot of focus in innovating in a way that is consistent with the standard because that's what will get you billions of users.
And so for us, that's always been the North Star for how it is we can co-create, but always stay ahead of the innovation curve in terms of the ability to bring those features to our enterprise customers and our consumer base because we do serve both.
We have another question in the front.
Erik Lindholm-Rojestal from SEB here. So you mentioned having a replacement rate of about 25% in the perpetual business. So just 2 questions about this. I mean, do you have any sense as to what share of revenues comes from sort of pure replacement business today? And then I also was wondering, we saw that smaller orders have grown over the last couple of years. I mean, do you think this is an effect of a sort of larger replacement business base to stand on? And does that create lower volatility?
Really good questions. When we talk about 25% replacement rate, that's excluding expansion, just to say kind of on an installed base, what would typically be the replacement. And that's primarily driven actually by employee attrition and frankly, people losing their keys. So that's a typical customer. I would say it ranges between 15% and 25%, but it's closer to 25% depending on the type of customers.
Interesting story there, depending on the recovery methods, because customers typically see very different replacement rates. If it's very cumbersome to recover if you lost your YubiKey, people hang on to them more tightly than if it's easier to recover back, but that's a side note. I would agree that, that fact that we have a larger installed base drives more run rate business. And it's definitely part of that more predictability and that increasing number of smaller deals or run rate business.
Just a follow-up. Do you have any sense of what the installed base is today?
Yes. I mean, again, with the exception of...
5,000 Enterprise customers.
But with the exception of -- the caveat here is that -- and keep me real now, Albert, with the exception of those running OTP, a legacy authentication method on Yubi OTP, i.e., something that we host ourselves, we cannot track usage -- actual usage of the keys. So that's all based on estimates and working with customers. But we have shipped and delivered some 40 million keys, quite a big chunk of those over the last 5 years. So rule of thumb installed base being used currently, probably in the 20 million range.
Another question in the room?
Daniel Thorsson from ABG. A question to both Albert and Mattias. I guess that there are a fraction of the customer base that you only see adoption among the IT department still and not the full organizational rollout. So on the tech and product side, is it anything you are working on, on the future products to kind of accelerate the full organizational rollout? And also on the commercial side from Mattias, what can you do to see this pace accelerating? And also, what are the key triggers for organizations to go full rollout?
Yes. So I think that the ad age in security is that you're only as strong as your weakest link. And so we see sometimes a pattern where people say, well, I'm going to deploy this for my privileged users. We have big like powerful integrations with privileged access management, for example. But my perspective is that organizations just begin there gradually start to expand their scope because they start to understand that you can't just have a phishing-resistant implementation that fits only a small bill.
And so there's a security argument that is compelling for a lot of enterprises to start somewhere, learn the lessons and then expand. And we're very optimistic that, that's something that will continue because it's just grounded in good security sense that you want to expand your phishing resistance until it covers 100% of your population.
So I'll add to Albert's comment on one of the key features of YubiKey as a Service, reducing the thresholds, making it less difficult to do a broader rollout, whether it's enrollment or such a simple thing as getting it into 50 different locations in 30 different countries. So there's a lot of groundwork being done there. What we do on the go-to-market side, I'll ask for a little patience, and we'll cover that in the next session and happy to follow up after that.
Yes. And then I have a financial question as well. When I looked at the first year numbers you gave for the subscription business model, you showed around SEK 7 million in sales and SEK 5 million in gross profit over the first year in this illustrative example. Does it mean that the gross margin in the first quarter? Some of us in the room are quite shortsighted here. Does it mean that, that could theoretically be 0% gross margin in the first quarter?
Theoretically, it could happen, yes, depending on when we ship the keys because we recognize the revenue, let's say, on a linear basis in the quarter, so 1/12 of the order. If you assume that we ship all the keys in the same quarter, it could happen. Yes.
But that's typically not the case...
That's typically not the case, kind of the worst case scenario.
And also worth noting is that we have -- quite a substantial part of our subscription customers have actually converted and they've already deployed perpetual keys. And despite that, they elect to go for our YubiKey as a Service.
Yes. The flip side is that in the next quarters, we don't have direct cost. So then it becomes quite a high gross profit.
Another question in the room.
Just brief on -- you showed us the NRR bridge on subscription revenues per end of 2024 until today, 10% up roughly speaking, ever since. But given this land and expand model that you just spoke about and the fact that you've gone from like privileged access users to a broader spectrum of users internally, could you say anything about like the flip side, what are you losing? What's the churn rate? Anything to add on the other side of that spectrum?
So the key message here is that the net retention rate is positive. We do have some churn, but it is lower than what we expand and renew. We are not right now kind of able or ready to share that. But in the bridge that I showed, in particular, by definition, the net retention is only on the base that we start with. So within -- in these 2, 3 years that I showed from 2022 to 2025, even in the new customers there, when we add them, then we expand and we retain, et cetera. So I think that's kind of the -- how you should look at it. Year-over-year, it's above 100% net retention rate.
Isn't that partly a function of the average contract being 3 years as well, so you haven't reached the tail end of a lot of the contracts signed ever since. So the 2022 cohort is more representative.
I wouldn't say so.
I don't quite make the bridge there. Maybe it's me not being able to calculate it fast enough. Of course, it's only 2022 ones that would typically have expired and where you have a renewal and then you can calculate net retention rates. You did the calculation here. I don't think that was the key factor.
No, I don't think so, if I understand your question correctly.
We'll take it offline.
We're running out of time a little bit. But just last question, would you consider changing the guidance framework?
The short-term guidance framework, you mean, or the person...
The overall, I guess. The simple answer is it's above my pay grade. But we -- I mean, one of the benefits of issuing long-term guidance, well, one of the constraints there is you shouldn't change the structure too often than the guidance becomes meaningless. We have done, however, since we went public, made one alteration based on feedback that we got. So we expressed the long-term growth target, 25% still, but we moved from order bookings to net sales because we wanted something that was more consumable for analysts and investors. And of course, that opens up for the question that Snejana got earlier. So if there's a faster transition to subscription, doesn't that have a negative impact on revenue growth in the short term. And definitely, that's correct, but it shouldn't have a major impact.
Not on the long term.
Very good. So now it's time for another break. We're going to take a 10-minute break and resume for the third and last session in 10 minutes. Thank you so much.
[Break]
So welcome back once again, and we're going to initiate our third and final part of the presentation where we'll go through [Technical Difficulty].
Thank you, Alexandra. So I'll talk a little bit about our strategic direction when it comes to [Technical Difficulty] existing customers, the ones that have agreed to being public references for situations like this. And it doesn't include all the other companies that feel more comfortable with sharing it in a one-to-one setting that they're using our technology. And -- but even from this subset, you can see that some of the most attacked and security-conscious organizations in the world are trusting us.
So we've built what I feel is a unique position in terms of credibility of being that combination of the highest level of security with good usability. This is another illustration that some of you has come across before. We are very focused and where we've seen success so far has been primarily working with the world's largest companies, largest companies and largest public organizations. And we've seen a steady inflow of new customers, landing new customers. So as Carl mentioned, there are certain markets that we don't serve, People's Republic of China being one of them. But in spite of that, we're already at a point where we have some 30% or 29% of the back in '24 of the Global 2000 companies as our customers. However, in the vast majority of cases, we're only deployed within a subset of their employees, starting with privileged access users or one of the initial use cases that Carl referred back to.
What's comforting or very nice to see is that this -- we took -- before we introduced the YubiKey as a Service model or a subscription model, we try to keep a close eye on, okay, so what can we say about customer retention and repurchase rates. So this statistics is based on the sample of customers that we had before we introduced YubiKey as a Service. If you took a look at our 25 biggest customers back in 2019, these were perpetual customers only. What did their average annual repurchase rate look like.
And consistently, when we've done these measurements, it's landed above 100% per year. Erik asked earlier about the typical renewal rates or repurchase rate on an installed base. Well, it's probably 15% to 25% on average. So if you get above 115 -- if you get to 115%, it's not that people lose their YubiKeys left and right, it's that land and expand motion where our customers are loyal in the sense that they come back to us despite that they haven't made any commitment to do so, but they come back to us as they deploy it to a larger user audience. We are able to be sticky with our customers.
And finally, no secret, we started out with the high-tech companies because they were pretty much the only ones we could work with way back when because they had that pull to be able to use one way to authenticate across all of their systems before open standards were adopted, and they were also very happy to talk to us engineer to engineer before Carl and his team joined the company. So the market we're in, the current market that we serve is a subset of the identity access market. It's what called advanced authentication.
And the best estimate that we've seen of that market is that currently is about $5.2 billion a year. And I think these are 2024 numbers actually, and that it's expected to grow with on average 14% per year. So we "only" have a 5% market share of that, give and take, about $250 million of sales, $5.2 billion being the total market. And as I think someone alluded to earlier, well, who are the biggest players in advanced authentication today? Well, it's still the smart card vendors that has the biggest chunk of the market, even if it's not a growing technology today. And this is the final piece of statistics that I'll show about the current position that we have.
If you look 5 years back, and it actually holds true even today, we were optimistic about the relevance of our technology because we saw that 9 out of the 10 biggest tech companies, at that time, they were all American, were using our technology. So they who really understood the threat landscape out there, they were using YubiKeys to protect themselves. Take a snapshot today. We did so recently and have a look at, okay, what about the largest AI companies. This time, we looked at it define the largest as in terms of market size, but -- sorry, in market cap, but I think you can apply pretty much any definition.
And what's interesting to note there is that 18 out of the 20 largest AI companies today rely on YubiKeys to protect their organizations. And if anyone is aware of the types of attacks which will be scalable in the brave new AI world, my guess would be that it's probably these organizations who are very much aware of the need for a hardware root of trust in a world where pretty much any type of attacks can scale massively because of AI. So this is the position that the go-to-market team, Carl's team with sales and the great marketing team we have at Yubico has put us in. We're recognized as a market leader and as a thought leader among those who really understand technology. How do we scale there? How do we scale to users that are perhaps not quite as tech advanced and how do we get the message out there to a broader audience?
Well, the answer is, of course, by good execution on the go-to-market side, and we'll talk a little bit about some of the activities that we've got going in this space over the next couple of slides. So this is a summary, and I'll deep dive on these different initiatives that we'll talk about as we expand our reach and as we go deeper with existing customers. So it's pretty simple. It's about landing new customers and then expanding within those. So we don't end up in just a subset of the relevant users using YubiKeys to authenticate. And the 5 different motions that I'd like to talk about is increasing coverage, scaling through the reseller channel or I should say, reseller and disti channel, more traditional channel partners, leveraging the partner ecosystem. And then once we have our foot in the door, how can we be more efficient in expanding.
And there are 2 motions I'd like to talk about there, driving adoption and renewal and expanding beyond workforce. So what do we mean by that? The footprint that we have. We started out pretty much in the U.S. We're now growing rapidly in Europe. And as you may have noticed on the slide that Jerrod shows, there's a lot of activity going on when it comes to up-leveling the security in Southeast Asia these days.
To meet that demand and the fact that there's now regulation coming out in a lot of different Asian countries requiring strong MFA, we're -- as we announced in the Q3 report, we're shortly setting up an office in Singapore. It's not just a sales office. It's a fully operational office where we'll be able to do the final steps of programming. We can even invite customers in -- we'll even be able to invite customers in Singapore, much like we've done in Santa Clara and Stockholm, if you're really paranoid about security to program their own keys. So it's really setting up that functional model that we have running in Santa Clara and Stockholm to service the local market.
And it's important for a number of reasons. One is that we want to, of course, be in touch with the customers, but it's also important for credibility. We are facing a situation today where European customers are concerned about moving all of their assets to a non-European company and vice versa in the U.S., and we're also seeing some of that in Asia. So it's important to -- for us to be local in the markets. I think this open up a huge opportunity for us because the need is definitely there and the market readiness is there. Broaden industry coverage. You still see a lot of our business coming from high-tech companies from financial services and public sector. The need is much broader than that.
We'll be investing in making sure that our technology is out there and being tested and then easy to scale within a broader set of sections. I've highlighted this before, but one of the favorites there is really the health care industry, especially health care providers because they're sitting on so much sensitive data and we read about breaches pretty much every day. So we want to be part of putting that industry at the forefront of modern technology rather than at the forefront of hacker attacks. More to come there, but it's really important that we can get to a broader set of customers even within the geographies that we currently serve.
Channel partners, distis and resellers. To this point, we've been very reliant on a one-to-one sales model where our account executives work directly with the largest companies and public organizations in the world to generate demand. We want to make sure that we enable channel better. We have a representative for that effort in the room, Stina, and I'm sure she'll be happy to talk to you later. But it's really about getting that global reach. We can't be local in all the different geographies where we serve customers.
We need distis and reseller to do the work there. And we want to make sure that we get more channel-generated sales. We work with channel partners to a very large extent today when it comes to servicing all the existing customers, making sure that delivery happens, making sure that they get serviced locally in the right language. But when it comes to demand generation, there's lots that can be done.
One of the important parts that we have there is that it is about training the trainers, i.e., training our channel partners so that they understand our technology, what benefits it brings compared to other technologies, what are the typical reservations that you need from customers and perhaps even more importantly, how do you make sure that you support the customer through successful implementation. That part is critical, not just for customer success, but also for the kind of channel partners that, to a large extent, have their business based on working in a service model with these end customers. It's not rocket science, but it's a long-term effort, building the credibility so that channel partners trust you, that you won't take the business that they've generated in a direct motion or switch to another channel partner.
And I think we're building an important basis there that will serve us long term, seeing more channel-generated sales. I just -- even if consumer is not a big part of our business, especially for really security-conscious consumers, there's already some buying online our keys either from our store or Amazon presence. And we've also started working with consumer distribution partners. One of the first ones that we started working with was Best Buy, a large U.S. retailer. They saw a lot of demand actually on their homepage for our products. And it's primarily 2 types of users, cryptocurrency enthusiasts and password -- people that use password managers and want to protect their vault.
That's what we see in every survey that we make out of these consumers. So it's not really something for everyone yet. We hope to get there. But for these 2 markets, that in itself is something which is interesting in generating demand. So together with Best Buy, we've now taken the step of moving into the brick-and-mortar stores with a new set of packaging and some simple instructions for how to use it. This is the new packaging reason for that. I think you may be even able to order something afterwards. We'll get back to that. So this is one illustration of how we can make our technology more accessible to a wider audience working through partners, even if this is not a big part of our business today.
Finally, when it comes to the land motion, it actually works in expand too, but we're seeing it primarily as a land motion is strategic alliances. I'd highlight 2 strategic alliance types. One is global system integrators or GSIs, where we today have started working with a few of the leading GSIs on a more tactical basis, where we're essentially running large projects together with them. And we're hopeful or optimistic that we'll be able to announce a more formalized partnership with at least one of the largest GSIs shortly. And that will be important in getting into the Board conversations, executive level conversations.
We always have our biggest friends and supporters in the basement, so to speak, the one who are really techy. But to up level our conversations within the organization, GSIs or global system integrators could play a really big part. On the technology alliances, one thing that I'll -- that we talked a little bit about as an example is the partnership that we have with Okta. It's not a coincidence that we run Okta internally because they have a great identity access management platform and a very nice integration with YubiKeys, they do the very same within their organization. So that's kind of eating your own dog food and then taking it out to the customers. So far, we've launched it for a very limited set of users, but it provides a really good user experience. So we're optimistic that with Okta and other technology partners, we can reach audiences that are already captured on those platforms.
Turning over to expand, and this is an area where we perhaps haven't spent enough resources and attention in the past. One critical step that we made there was that as we introduced YubiKey as a Service, we said that, well, it's one thing to drop ship keys at someone's loading bay. It's a whole different thing to make sure that they have a successful implementation. We probably want to dedicate customer success managers to all of our largest YubiKey as a Service customers. Honestly, that shouldn't be limited to YubiKey as a Service.
80% of our business is still perpetual business, and we see a very high repurchase rate there. So we're now also introducing customer success managers for our largest perpetual accounts. What does that mean? Well, it means that we support the customer. We work with them in assessing their needs, provide manuals for how successful deployments can work that are relevant to them in their industries, in their geographies. We are with them as a plan, as they plan the rollout. Then we assist them as they deploy, whether it's with practical questions or user adoption or whether it's with technical questions, okay, this wasn't implemented right in that system. So we need to go through this process. We've seen this before, again, train the trainers within the customers.
Then there's that ongoing engagement with the customer. And as we get more data points, we're better able to predict how we can best support our customers. And then we can be more proactive. Okay, you've protected these types of users. Do you know that a customer in a similar situation then went through these next steps? This is the experience that they've had, monitor their data and support them with relevant experience so that they can be more quick and more successful, as they deploy it to the wider organization.
And then finally, making sure that we have the right incentives for people to continuously upsell within the organization, i.e., identifying new use cases and making sure that renewals or repurchases happen. This is a relatively new function within our company, but I'm really excited about this because this is, frankly, the fastest way to growing revenue for us. It's great, and we need to add new customers, but upselling and renewing on existing accounts is a much quicker way to revenue.
Finally, and this is really tied to a lot of the things that Jerrod and Albert will talk about as we talk about the product road map. This is about extending security beyond use within a large enterprise or public organizations -- public organization. The -- and we've seen successful deployments in the past, but they have all been based on bespoke development, where we work with specific banks to protect a subset of their customers to make sure that they don't experience account takeovers or where we work with a large manufacturing company to make sure that their supply chain is protected.
With some of the initiatives that we're now preparing within product, this will be then we don't need to reinvent the wheel every time. It can scale more quickly beyond the limits of the organization without us having to find out the right solution for every customer one by one. So I'm really excited about that. And then, of course, that opens up a whole new set of users for us without us being at the forefront in generating that demand because, as we mentioned, our biggest customers serve billions of users that need protection.
So in short, what has formed this foundation for our success to date is primarily a direct sales motion to the largest companies and public organizations in the world. And of course, we need to continue doing that, and we need to excel at expanding within that type of customers. However, we're now investing in a number of initiatives when it comes to land and expand, which will permit us to reach to new customer segments. We'll be able to work more closely with the customer and therefore, deepen the relationship with them. And if we're smart about working with tech partners and GSI, we can leverage their vast sales resources and reach within other organizations.
And with that, I'd like to hand over to Jerrod, who will talk about some of the things that we'll put in a position to scale better in the future.
Thank you. Thank you, Mattias. I wanted to step back a little bit to give everyone a view of the mission that we've been on. Stina is actually here, so kudos to her. The reason I joined Yubico and the reason I'm still here really relates to this mission. The mission was to make a safer place for everyone. And one of the things that we've done is to make secure login easy. We talked about the FIDO technology. We talked about passkeys. And if you look into the future, it's not just about the authentication, it is the user interacting with this digital world.
When I first joined Yubico, I had the opportunity to train a group of journalists, and I was raving up all the great things they can do with the YubiKey, being so naive to know actually what they do, I start to emphasize on things that can protect the social accounts, the banks and the governments and they say, hold on, Jerrod, you don't understand if my digital identity is compromised, you will not see me tomorrow. So I take this mission very seriously. I take the way that we orchestrate our company to build the products to make an impact to the world. And I do believe that a lot of our customers believe in this as well, and they're with us in this journey.
So what is happening today is that we've established a very good baseline, the foundation of authentication. But what's happening is the attackers are kind of going around authentication. And we hear this straight from our customers. They just said, I've lost all my authentication device, whether it's a phone, a laptop or a YubiKey, please let me in. And then people generally say, how do I know it's you? And there's so many ways that people create fake documents. Now with again, generative AI, it's so much easier to create fake documents, fake voice, fake pictures, you name it.
And then whoever it is that helps this individual lets them back in. So who cares about passkeys? And so this is a huge problem. The users didn't have control of their digital identity. They may have control of the authentication, but they don't have control with this digital identity that they now put themselves out there. And this is -- we saw the headlines with attacks. We're starting to see the actual problems of digital identities now. So the attackers are kind of moving around and evolving their attacks.
So there's this huge paradigm shift in digital identities. And it's actually happening -- epicenter of the change is actually happening in Europe. There's so many activities and so much regulations coming and standardization coming, how do we create national IDs and how do we create all these citizen IDs and all these great innovation is happening right in front of us. But I'll take a little step back. This also pertains to the growing market that the analysts believe is the next big thing.
So if you look at authentication, you look at identity access management, but digital identity is a huge, huge, bigger type of opportunity in the market. And today is very fragmented. A lot of companies trying to solve this problem, no standardization, everybody doing their own thing, the proprietary thing again, right? But that's just a snapshot of 2024. We anticipate this space to expand and accelerate at rates of close to doubling their size in the next 5 years. And for the reasons I just told you why, it's a big problem. I want to take a step back to say what's the difference? Like you solved authentication, you're the best, and we'll continue to invest in that space. Absolutely, we will. A lot of people don't use strong authentication today.
But it actually is in parallel where it needs to coexist in terms of digital identities because you issue a strong authentication to the digital identity that you've just proven. Here's the difference between the two. The authentication, you are trying to authenticate to that one service, right? The log on to your Google is Google. You set a password and you set up a vital security for Google and then you log into Google, the same entity. In digital identity, it is different, slightly different in terms of the way that things are orchestrated, but it's vastly different in the way that who gives you the digital identity and how you use it.
The government gives you a passport, but you use the passport to enter to security and get to your airline. They are 2 different entities. So that complexity alone requires coordination at scale. And today, it's not coordinated at scale. That's the challenge. That's why you have so many companies trying to solve this problem. And no one has solved it at scale. I'll take a quick example and both Stina and Albert will give you a little bit of a glimpse of what we're actually trying to do. I'll set some baselines. So this is a national ID from Finland, physical card, smart, there is a chip in it. And today, you can create a digital version of that from a physical card, so today can be on an app, can be on a web application.
And what you want to do is that you want to prove certain aspects of yourself to the service that you're trying to do in activity. Certain sites required to be a certain age to do something. And so in this case, in a digital identity form, you can actually only control and share what you want to share. I'm over 13, please let me use the site. And so you can present in a way that you selectively disclose, which is great. You want to control, right? You want to control. You don't want to say, now I'm over a certain age, you have my address, you know where I'm born, like you know all these other things that you shouldn't need to know for most of the time.
And so when we look at the digital identity ecosystem, it becomes complicated because there's an issuer, like I said, like a government issues you a digital credential and then you have a verifier, which may not be the same person that issues it. And the holder is holding these really important attributes of themselves, their age, their birth date, sometimes even family members. There are things that you do professional credentials, you work for a company. And in that case, the user in our term for the digital ecosystem, we call this user holding a wallet and the wallet has different things that you hold in it.
And so because of this complexity, there is a lot of players in the mix. In this new world, the standardization is much more complicated than just trying to standardize authentication like FIDO or passkeys. But if we get this right, you actually protect the user. So a quick example on how this actually works is some of the early works that we've done with our teams, with other organizations, including the organization that Stina found SIROS Foundation to give a glimpse of what is possible. So this is the same ID, but now we're trying to present this credential to a service to prove an age. So we want to show this site that this individual is over a certain age only, and we don't want to review anything else. We don't review the name. We don't review where they live, anything else. And in this case, the way to unlock that sharing is with the YubiKey. So without using the YubiKey, the user is not releasing anything about themselves to the service, which means the identity of the individual is locked to this hardware that you can control, and you can decide which service is allowed to see what attribute of yourself.
This is not just a video. We actually have a working prototype, which we also actually showed at the same FIDO Authenticate conference that we showed our post-quantum cryptographic YubiKey. With that, I want to introduce back -- and bring back Albert back on stage to tell you a little bit about what Yubico is going to do with this great scenarios.
Thanks, Jerrod. I'll ask you all to wish me luck that my glasses don't fall down in the middle of this. So all right. So in explaining what this means, I think it's just important to go back to something that I said and a couple of folks have said, it's subtle, but it's really important. We have a very long-term perspective. And so there was a time long before I joined Yubico that somebody stood on the stage and said, passkeys are going to be adopted by billions of users. It's true today.
And that same long-term perspective actually has been applied to lots of other things that we really need to think about as a society. And I'll talk a little bit about what this means in this context because it will then give you a sense for what we're investing in and why. And hopefully, that gets some people grounded. So what does it mean for AI to be in the mix? I mean 2, 3, 4 years ago, people are working on artificial intelligence for a long time. There was a long AI winter, and there's other companies that were really grinding up the mill because they knew that this was going to become something big and great, and this is the moment.
But if you look at what identity means in the age of AI, it's actually a perilous question when computers are able to impersonate so well, it just opens up a lot of big questions. Without creating a lot of parade of horrors, I want to focus on the way we're thinking about it, as AI is actually a new supply chain input. What does that mean? It means you have labor. You now have this boundless intelligence that you can insert into lots of different things and you have to trust it, especially when AI is going to be acting on behalf of a human in terms of verifying something or authorizing something. You're going to need verifiable inputs at the heart of what it is that you're presenting in order for people to feel some trust that the telemetry that's coming from that or the software bill of materials that you're signing or all the other things that enterprises are now beginning to do with artificial intelligence can be trusted. You are going to need roots of trust that come back to humans.
And fundamentally, that's going to be something that as systems start to work and act on our behalf, we have to have that trusted. So almost every device you have in your hand is going to be infused with intelligence and there will be times when you need to separate what that device is doing from the human who authorized it. And that's a key role that we will continue to play. And I want you to look at this chart because what this shows you is a 20-year journey from where we were with 99% of any kind of authentication coming from passwords to passkeys, which now have a multibillion user and multibillion account adoption trajectory that is very, very strong, built on open standards and foundations that give us this ability to have adoption at scale.
So you ask them what does that journey look like? I mentioned earlier that some of the necessary innovation we have to have will require that this foundation of encryption we have has to be rebuilt on quantum safe capabilities. And so in the United States and around the world, there have been competitions and contests to establish the correct white box cryptography that will be allowed for post quantum cryptography. We have incorporated the algorithms that have been chosen by NIST as finalists. NIST is the National Institute of Standards and Technology. It plays a big role in determining which encryption technologies will be the correct foundations for what we do because all of these things have to be interoperable. So that's a very necessary bridge.
And then I'll tie this back to what Jerrod just talked about, which is verified credentials, meaning something that you own that you tie to your identity that you might need to prove to somebody else. The interesting thing about verified credentials is that they are as powerful for what you allow them to do for you as what you can disallow, meaning you can actually create a privacy container and a security container around a piece of information and attribute about yourself and enforce that it may or may not be shared depending on what you, the owner of that identity decide.
This is a big deal because this is a complete flip of the privacy model we've lived under for the last however many years. And what I'm really excited about is the fact that, again, Yubico and its founders have been visionary about thinking about what this future holds. And so I'm incredibly excited to have Stina, our Co-Founder, come up on stage and talk about what this means.
Thank you, Albert. Wow, one of the biggest challenge on the planet, every second, 3 fake identities are created on LinkedIn. Today, there are more fake identities and bots on the internet than real humans and we have a solution. Okay. So this is about 2.5 years ago, about the same time I stepped aside as the CEO for Yubico. We were approached by a research organization here in Europe, who invited us to be part of a very cool, bold vision that the European Union had set up.
And you've heard Jerrod and Albert sort of talk about this in other terms, but it's actually a vision for EU. I think EU is -- for the first time, I think EU is much cooler than Silicon Valley. Yes, credentials, user information is transferred from your passport digital identity app to this identity wallet that is controlled by the user. You share whatever information is needed for the service that you want to share. And this is the coolest part. You can be verified, but anonymous, which means that you can share that you're a real person and not a bot. And do you understand what this means for the world's democracy and free speech and peace and human rights? It's a revolution.
So of course, we want to be part of this. We did not only engage with the first research organization, we engaged with 2 others, Greece, Holland and Sweden. And we created an open source, open standard prototype research project that is actually the one that Jerrod shared. The challenge is it was sort of a shared ownership. It was a project -- an open source project on GitHub. There was no real leadership. It was just like, hey, we, as a group, want these things to happen. And did you know what we did? We actually solved the fundamental problems with universal digital identity.
And I am absolutely sure that we are now building a new next-generation secure Internet on these pieces. So by routing it as a web-based application and not a centralized solution that's owned and controlled by an identity provider where you tie to a phone or a smart card, we have a solution that is web-based. You can share it, you can use computers, you can use phones, you can delegate to others. Families can have a shared computer. I mean there are families who may have an even a shared phone to access the system. And you can even delegate to a legal person. No one has solved this before us.
It is the highest level of security because all the reasons we have talked about today. Passkeys, security keys and YubiKeys is the best. It's smarter and more secure than your Swedish hard bank ID or bank authentication tokens or name it. And because it's not a centralized service, and it doesn't collect data. And we delegated security to users. And these users do not just share everything about everything, but actually the only thing that they need to share. There is no oversharing. There's less data that will be hacked and it's the highest level of privacy.
And because there was no ownership of this amazing project, I knew now it was time for me to step into a leadership position again. And I created the nonprofits as a partner to Yubico. I'm now the Executive Director and Founder of this little sister to Yubico. And we are on a good path into making this into a global standard. Here are things we started. We are the most tested, most interoperable of all the European Union digital identity wallet projects today.
We won a German competition, an innovation competition that Germany put out and said, hey, innovators, pick giants, anyone, help us create the next-generation identity system for Germany. And our solution kicked out both Google and Samsung because we are cooler and more privacy preserving. And then after that, when Germany said, hey, we like this, Canada and France said, we also want to be part of this. And Canada is not even part of Europe, but they like Europe now a little more than a year ago.
So now we're starting a pilot there. And this is a project we're doing with Sweden actually showing that you have legal ID wallets, and there may actually be some kind of press release out there where this business -- this idea of business ID wallets is coming where you can delegate -- for example, Mattias can delegate the authorization of signing documents to other members of the Yubico team. You can't do that with your phone, but you can do that with the YubiKey. Singapore also wanted to be part of Europe or at least its initiatives. So we're making a pilot between Sweden and Singapore. And this is the coolest part.
There is this group of investigative journalists. We all were very touched when Jerrod named the importance of protecting free press and the people who protect us. If there is no free press, there is no security. So there's this group of investigative journalists, who are developing a new digital press pass for the Internet. And they said and asked us at SIROS Foundation if they can root that in this digital identity standard. And we've already started the first phase of that, sending them all YubiKeys. And then there is an international research organization and the list goes on.
Every week, there's someone new, a new country, a new government agency, a new company that want part of this global initiative. And people have asked me, why couldn't Yubico lead this? Why did I have to create a nonprofit? And it is because this is -- this -- we now need to engage with governments and policymakers and nonprofits and have a neutral platform. Just like Ericsson, when they created GSM and wanted that to be a global standard, they couldn't -- it had to be the GSM consortium that sort of took the pieces of GSM and moved it forward.
And of course, Ericsson had a very vital and important voice in the room. And that is sort of the relationship between the little sister SIROS Foundation with just a dozen people, I funded it with money that I was grateful to receive when Yubico went public. It's my way of giving back. And now we're also being encouraged to get funding from other resources. We partner with Yubico because Yubico is the established credible player, is the leading inventor behind passkeys, and it's actually a really good synergy between us.
So we meet up every week, and we sort of conquer and divide where can SIROS be of use and where and what was Yubico need to do to make this into one global digital identity standard for all on our same mission, making the internet safer for everyone. Thank you.
This is exciting. And hopefully, you start to see a glimpse of something that we'll talk about more and more as elegant as this sounds, there is a lot of -- there's a saying in the United States, there's a lot of wood to chop. There's an incredible amount of cryptography and coordination and mad science that you have to get right for this to work really well. And so that's the job that our customers are going to trust us with. That's the job that we are going to work in a way that has been consistent with the way Yubico has always worked before, which is a pairing of standards and standards-based innovation together with excellence and building that foundation of trust.
But I want you all to look at this slide and kind of recognize what these layers tell us. This is a very simplified diagram that shows what the -- kind of what the relationship looks like across the layers. But you can think about Yubico as being this root of trust, well established, global passkey adoption is a great foundation. In addition to that, we have this enormous base of thousands of enterprise customers, at least 1/3 of the Fortune -- of the Global 2000 that we're already working with that give us this amazing innovation factory to go back and think about what it means to have this new sense of identity start to go.
We have this interoperability layer that starts to bring the right kind of open standards that you'll need in order to drive billion user adoption eventually. And then you've got the kind of engagement that you need at the user experience layer that's a sophisticated interplay of both the open standards and the root of trust. And we need to obviously have a way of making this measurable because if you're not making this measurable, you can't transmit the proofs that people need in order to trust the ecosystem.
And so we're thinking about all these problems. I'm really, really excited about the investments that we are making here. And there'll be more to come over time. And just to give you a couple of examples of what this could look like. I'll tell you a little bit of a story here. Initially, we had an example that kind of lived in the health care field, but that's one of the places where the United States and Europe are highly, highly contrasted because in the United States, if you give a health care example, you're giving a private sector example. In Europe, when you give a health care example, you're mostly giving a public sector example. And so you wanted to give something that was a little bit more distinct.
But I'll just give the -- I'll give one of the examples that we had, which is it does take a while for a doctor who works for one hospital system to sometimes just transfer to work in a different hospital system or to work in the same hospital system in a different jurisdiction in the United States. And if that takes 6 weeks, that's 6 weeks in which somebody can't make an appointment with, I don't know, a doctor who looks after people who have complications from diabetes and they have a leg that is suffering, and so they wait 6 weeks longer to get something. If you could have a system where you're verifying those credentials nearly instantaneously, that is real value add in a way that cascades into things that people feel viscerally. It's about how well you can get quicker because you get better care.
But that's just one example that kind of links back to the medical side. But then there's this whole web of things that you can do all the way from how people do background checks effectively in a workforce, how people do loyalty programs, what it is that you can do to prove that you have certain qualifications in order to take on a task, how quickly you can onboard if you're a consultant working in one company and then being deployed to another. There's just so many things that you can do once trust becomes a programmable artifact that the sky is really the limit. And we're very, very confident that this is a race that we are going to run really hard at because the world needs this.
So if you think about what I've talked about, there's a possibility of actually bringing identity back into the control of the user. So user-controlled identity with verified credentials, which are as powerful for what it is that they allow you to do as what they allow you to prevent from happening. So you start to have identity that travels with privacy attributes that work as a container that you control cryptographically with your YubiKey. And then secondly, you have all these great use cases that you can start to show to industry, starting with our 5,000 enterprise customers and growing beyond. And then third, if we do this the way we are, we are committed to doing this in a way that's really about open standards. So it means that the value of this actually increases with greater adoption.
And then we're doing this with the context that has been set with widespread passkey adoption. So this is not a cold start problem where you're going to have to create the logic that then allows people to do this. You could never do this without first trying to solve authentication. What that tells you is that this company has an incredibly long-term vision about how the world will change for the better. We're committed to doing this in a way that's very much about open standards, and we're really excited about what the future holds.
So with that, these are the 2 takeaways that I want you to have about what our innovation path looks like and why we're investing the way we are. What passkey adoption is doing is it's setting the foundation for digital identity that protects users beyond login. And I think we've painted that picture really clearly, and you're beginning to see how it comes together. And Yubico will sit at that decentralized root of trust for what this next generation is going to be. So that's, I think, what brings us to Q&A. So I'll call up Mattias, I think, to wrap.
I think we can welcome back all speakers from the last session, Jerrod, Mattias, Stina and Albert. So this concludes the third and final session, and this will be the third and final Q&A. So let me start with the first question. And the first question is for Mattias. Which factors do you believe are most crucial for Yubico's success? And how do you ensure the whole organization focuses on them?
Well, it comes in 2 different parts. Fundamentally, we need to stay ahead of not just competition, but also the hackers in terms of providing that secure hardware root of trust. So the work that Albert and his team is doing in both making sure that our core stays ahead of the game and then expanding to what our customers are looking to solve in terms of problems when it comes to digital identities are both critical for our success long term.
If you look more short term, the quickest way to make sure that we meet our financial targets is about that expansion within the existing customer base. But that doesn't mean that we can let go of the land ambitions that we have and look at more ways to adding new customers and get more leverage in our sales model. So it's a combination of the two. And of course, if we don't have the leading product, well, it doesn't matter if we have the best go-to-market in the world. That's kind of a shortsighted approach.
And then to Albert and Jerrod, can you elaborate on the focus for digital identity? And do you view it as diluting focus?
So it doesn't dilute focus because it's actually building on the foundation that we have. And the customers that get the value out of the YubiKey today are the ones who are setting themselves up for that future. So we see this very much as what that evolution will need to be.
Yes, I'll just add to one practical scenario at a company. Albert talked a lot about delivery of YubiKeys and enabling them to be onboard really quickly. One of the key challenges today that customers have is the recovery. How do I know it's you before I give you the YubiKey? And just that statement alone, we have to solve the identity part of the equation. It's not just authentication. So in some ways, whatever we have envisioned for the future of Yubico, it's also solving a real problem that the customers have today, particularly as companies employ and have users everywhere globally and growing and not just employees, but their customers and their suppliers, how do I actually know that you should be getting YubiKey because I don't really know who you are. And we need to solve the problem to solve the bigger ecosystem challenges.
So following that, how do you see the revenue model for identity verification?
I'll take that one. This, to me, is one of the reasons why I'm so happy that we introduced the service and subscription model some time ago. For most applications, at least enterprise applications, the logical way to sell this service is in a subscription mode. Of course, we're going to have customers who would want to separate the two, and we're not going to stop that. But I think this is one of the accelerators that we're seeing for customers making sure that we have that long-term partnership and a commitment, which the YubiKey as a Service framework provides.
And to now both Stina and Mattias. Can you just elaborate a little on the collaboration between SIROS Foundation and Yubico? And is there a scenario where the solutions are competing with each other?
I think I made it fairly clear. SIROS is like Linux for online identities. And Yubico is the red hat that builds value-added commercial service on top of the same platform on top of the same code and Yubico will develop more advanced service. Well, we, at SIROS will continue to drive the open source project oversee it, ensure that it's certified, ensure that it goes to every country on the planet and ensure that we actually engage with the Linux Foundations of the world to put it into the central pieces of the internet. And for that, you need to be a nonprofit long-term sort of neutral player.
We, at SIROS -- because I represent both. I am a major shareholder in Yubico. I own 10% of this company. I'm the co-founder and I mean the Board. So I -- of course, I have literally only 1 hat today, but I have 2 hats. My hats are to ensure that Yubico is successful and SIROS is successful. And we -- at SIROS, we realize that when all these governments want to come and try this open source platform, we set up a -- that we're going to launch shortly just a reference wallet platform where people like the test bed. And we say, hey, this is for free. If you want to do something more advanced, we will charge some very minimum just to not start losing too much money. It's basically that is sort of the revenue model.
And I only wear one hat, even though I'm not wearing it today. I'll add to Stina's description there by saying we're actually very happy to be working with one of the leaders, now SIROS, in this space because this is actually a center of expertise and knowledge, and we learn a lot about getting our heads around this interesting market and defining our product offering where we can make money in this emerging -- with this emerging technology.
Initially, I thought it would be mainly YubiKeys but there are more commercial services tied to the YubiKeys that Yubico can make.
And a question to Mattias. Can you talk more about the new office opening in Singapore? Why Singapore? And when will we see material revenue coming from that region?
So today, the APJ region represents about 10% of our revenue, but it's growing quite rapidly. And as we talked about earlier, it used to be that most of our revenue from that region actually came from American and European companies operating in the region. That's now changing. We're seeing locally generated demand. We have a sales team in place, and we're seeing a lot of activity on both the government side and on the private side, recognizing the need for strong MFA. So it's definitely a rapidly growing market.
And as I mentioned, it is critical for us to be local as we do business. We literally have customers who wouldn't take delivery of the product unless they know that it's programmed in a location that they feel confident about. Even if those are really large and very security-conscious companies, having that local base is important.
Why we chose Singapore is because it's a great place to do business. I'm not going to lie about that. It provides a very stable framework and a long-term perspective, and we're getting great support locally for our ambitions there. Fundamentally, it's driven by customer demand that we're seeing this hub as a natural place to expand our footprint in the region.
And a question for you, Albert. You talked a little bit about how Yubico is preparing for the era of quantum computing. When do you anticipate that quantum-resistant authentication will be required?
We think that for some use cases, quantum-resistant or quantum-safe authentication will be required as early as the end of the coming year. And we think that that's only going to grow. Where we are right now is in an intense testing phase with partners. And so we have really opened up at the authenticate conference an invitation to folks to work with us on that because these are not small projects. Essentially, what you have to do to get your organization ready for a quantum-safe transition involves doing a cryptography audit of every dependency that you might have in your environment and then going on from there.
So from the date you start, you're starting off on a multiyear project. And a lot of enterprises, a lot of the CISOs and identity folks we speak to are beginning to kind of bring that into view or setting up post-quantum working groups. And so the time for the engagement is right now.
And what cadence of product releases is Yubico aiming for?
Is that in the post-quantum context?
Both.
We have kind of 2 cadences for our product releases. So the simplest answer I can give is our services are releasing monthly or something on a much more frequent cadence, and that will continue. And on the hardware where you have firmware trains, customers typically don't want to consume too much change. They want kind of stability around that because these keys are deployed for a long time. So the cadence is there a lot longer where we'll take some time, get something up and then kind of move from there. So those are the 2 cadences we have. And in order to support our subscription businesses and the services that we continue to offer that add value, we'll continue to intensify the release trains there accordingly.
Thank you. We have a question in the room.
Yes. Daniel from ABG. You showed that you had 9 out of 10 tech companies in 2020, 18 out of 20 AI companies today. Is that just because these companies in the forefront are much more aware of cybersecurity and they buy protections from many, many more providers and doesn't really say that much about your solutions against your head-to-head competitors? Or do you see better proof in the other sectors like health care, financials that you are more an exclusive provider?
No. Sorry, to -- as I understand the question, when we looked at those statistics, we also took a closer look. So what's the level of deployment that we have within those customers? And it turns out that for our broad set of customers, our average penetration rate, if you compare the number of keys deployed with a total number of employees is like in the 10% range. In this subset, AI companies, we find that more than half of them have rolled out YubiKeys to their entire workforce. They're at the bleeding edge of understanding the threat levels, and they're very tech savvy, of course. So I think that's an indication that they're a little ahead of the curve, but I think the rest will catch up before too long.
I think that a little comment to it. For a long time, we were perceived as a Silicon Valley company. We were in the heart of Silicon Valley, Google, Microsoft, Apple were our main partners. And these AI companies have thrived mainly from Silicon Valley and these tech giants are U.S. West Coast based. So it was -- we were never like the biggest cybersecurity on the planet, but we were the biggest strong authentication organization company in Silicon Valley.
Yes, I think that the color from Joe earlier, which is a lot of these AI companies have been using this technology for more than a decade. And that's the fact. And so when you -- it's not just the technology that they're buying. So I think an earlier question, why should they buy another device. People don't buy devices, they want to trust Yubico. That's a big difference.
One thing maybe also to add. I'll just refer back to the video we saw earlier. Cloudflare, for example, is a very classic example of one of the things that we see, which is somebody who used the technology and saw the difference that it made in one job then moves to a different job and says, I would like to sponsor this to get this rolled out everywhere. And so we also have that as something that's almost like a perpetual fountain of people who experience the product, see the value in it, taking the experience from one organization and going to another one and doing a company-wide rollout.
In the early days, we had someone from Google who went to Facebook. They deployed YubiKeys and then someone from Facebook went to Uber and they deployed YubiKeys and someone from Uber went to Salesforce and they deployed YubiKeys exactly what you pointed out.
Another question from the room.
Excellent. Erik from SEB here. So just a follow-up on the identity product to Stina and Mattias perhaps or all of you. Do you -- I mean -- just so I understand, do you foresee that this is something that governments will deploy and they would send out YubiKeys to the users?
It will be a combination. They will -- some will just deploy digital identity cards that are similar to the identity cards that you get today and that you can put on your phone, and it will transfer the information and you can also through a card reader transfer information to a computer. And then you will have YubiKey as an add-on for high security, high privacy, shared delegation, shared computers, phone restricted rooms, backup.
I mean there are all these scenarios where the first card will not be enough. Then there may be -- and we have those conversations in service now in all countries to say, hey, could we replace that card and just have a YubiKey because it's more convenient. It works in all computers or phones, you put it on the key chain. I mean a card doesn't work with your computer unless you have a card reader and it's sort of a little -- so we don't know yet, to be very honest. But we know that there will be enough use cases.
And as like we said, how big can this market of digital identity be? And let's say we get 10%. 10% of 5 billion Internet users is 500 million. And to date, we only sold 45 million keys. I'm not going to sort of commit to that number in X number of years, say, like in 2 years, we will be there, but it's sort of the opportunity that's growing because before we were -- Yubico was enterprise and some consumers, and now we can be part of national ID systems. And that is the big opportunity where we need -- SIROS and Yubico need to work hand-in-hand and driving that effort.
So it's definitely expanding the addressable market. We're not betting the farm on government sponsoring YubiKeys for everyone, but it's a nice idea. But it's more about making sure that we're part of that platform, which is being provided, which is being developed right now.
Put 500 million keys in the model then. But just a follow-up, if I may. I mean, you said there's a lot of wood to chop before this is fully deployed and functional. But if you were to give a rough time line, when does this become relevant for Yubico and a big driver for Yubico.
I think it's going to go fast -- much time sort of comparison. We took 10 years before starting with Google, getting Microsoft and Apple to adopt passkeys. This will go faster. I think in 5 years, we will have -- there will be hundreds of millions of citizens that use this kind of digital identity system. And how much of this share will Yubico get? That's up to us. We need to continue to innovate. We need to -- not only with the keys, but with the services surrounding the system, just like an Ericsson or the guys preventing -- when there's a standard for WiFi or USB or whatever, whatever standard that is created, the innovators needs to be on top of it because there is competition.
I believe it's the last Q&A session. So I'll just take the opportunity to first off, thank you all for the great presentation throughout the day. But I just wanted -- you mentioned that -- I don't want to run ahead of ourselves here, but you mentioned that there's several adjacent services that could be added by Yubico in the future in this initiative. Could you elaborate a little bit on what that could be?
I think Jerrod is better at...
Yes. So I gave a glimpse of it a little bit on that earlier. Albert obviously can share more, but if you think about the identity life cycle, there are things that you need to do to verify the identity of the user. This is just one example, right? It's not like the YubiKey can't do that and they can't -- so there are things that you can offer to help prove that the user is who they say they are.
You can also think of a service where you are providing the user with the trust that they work for someone, right? We may not be a government, but we could provide a service for corporations. I think we talked a bit about the delegated scenario here, right? I delegate -- Mattias delegates to someone else to sign the paperwork, but what gives them the right to delegate and who is he's supposed to trust in the digital world. So we can offer such scenarios where professional credentials can be issued by Yubico and then they can take an action to then present it. So there's a lot of corporate scenarios, business scenarios, independent of citizen government scenarios.
So that's really our focus to really find trusted customers in this journey. And the good news, like 5,000 of them. So I think that's the difference, which both actually Stina and Albert talked about, which are [indiscernible] from 0. I mean if you like the core start problem, which is like no customers, no market, it's really hard. We have a strong foundation to build upon.
Yes. Two things to add. One is, just being transparent, I can't stand here and tell you the things that we're going to run fastest on because that would not be wise. So...
A security company can never run too fast. I don't ask us to run too fast because we cannot make mistakes.
But we're excited about where we're going to run fastest because we know that there's already a lot of customer value we can create. That's one thing. And then the second thing is it's just coming back to the fact that amongst our 5,000 customers in the enterprise and many thousands more prospects, we have conversations every day that illuminate for us just how much need there is for what it is in the direction we're going, all the way from people who want to flip their privacy model to people who want kind of easy verification for really hard things to do today because they're just inconvenient processes.
So we're just going to be very methodical about how we create value for our customers, but this is not going to be rooted in things that divert from the focus that the company has always had, which is providing that strong authentication, root of trust, hardware-backed phishing-resistant MFA as the foundation because if you don't lock that door, then you don't have identities that you can trust to do anything else. And so think about this as sort of laying that foundation has taken a while. This is a fantastic base on which to build. And when we build on that base, we're going to be rooted in real customer problems and they're just too numerous to solve. So actually what we spend a lot of time thinking about is what we're going to do.
But every existing customer struggles with this. How do I onboard people? How do I secure the identity of the user and then how do I manage the life cycle of the product. And every customer today pretty much has a different approach to it. I think it's safe to say you used to work. The Google had a very generous approach and said everyone should get at least 3 YubiKeys and make sure that, that's always the need a trust.
We -- I spoke with the German customer only a couple of weeks ago. They have a lot of discipline when it comes to someone losing their YubiKey and how they get back online or how they get access again. They literally demand the delinquent to show up on site and then to have 2 of their managers on location, verifying that person's identity using their YubiKeys and then new credentials can be issued. That's an example of a customer with a very low attrition rate, let's put it that way, because you don't want to go through that process. And we want to make sure that we find the right balance between security and convenience/scalability there. And I think we come from a unique position with the background that we have.
Next question.
Yes, you kind of touched upon it a little bit now, but I'm thinking of -- maybe you don't know the answer to this, but if you consider other cybersecurity companies like Cloudflare has been mentioned or CrowdStrike or Palo Alto Networks, when they roll out their services, those are also typically quite long implementations and they're painful. The implementation time for you guys compared to -- I don't know if you can say an average of other large complex implementations.
But based on what you just told us, it is this kind of recovery onboarding that is really the big pain point for you. How do you stack up versus other companies? And are they quicker at deploying? I know it's software, but it kind of ties in...
I think the question is if you took a life cycle of hardware versus the software, there are fast things and slow things in each category of technology. So you might be -- for example, let's just talk about software. You could be fast to deploy, but really struggle for maintaining the level of security because what you don't see behind the scenes of software is you actually have to maintain the patches of that phone.
Do you want to take control of how frequently we patch phones and operating systems and Windows and Google and Apple? There's a huge cost to that. So some things are fast and some things are longer. Hardware is a little bit of the reverse. It takes a longer time to establish that deployment, but then you have a very consistent flow because we're not changing anything on the hardware like the YubiKey when you get it. So there's all these measurements that we see from the reality of customers deploying. And long-term perspective, independent of whether it's software or hardware, customers choose companies that go for the marathon, not the sprint.
And so that's really the difference because you've got to really work through the pain in some ways. It's nothing to do with Yubico or the technology. Every company has complexity because I call this every large company, large is relative, as a computer history museum of stuff. And you can't like run fast in some of these things, even if you wanted to, right? Obviously, T-Mobile had a very strong leader that pushed all the way through, but that sometimes works, sometimes it doesn't work because the technology doesn't have it. The stack didn't mature enough. So I think there are a few combinations that I can't give you a straight answer whether it's faster than a Palo Alto Network-based software thing or a YubiKey thing.
I think enterprise is complicated than let alone if you think about deploying to government systems, you have even more complexity. So what we believe, though, is that the innovation that we provide accelerates the adoption. And it's two things. It's definitely about the standardization so that it works out of the box, and we spend a lot of time making sure things work out of the box. And then the second part of it is like Yubico has to do its part. He's got to innovate on this open stand to accelerate the adoption.
One quick thing to add. First of all, I think we've got 2 customers here who have been so kind with their time. They can give you unvarnished samples of how quickly they saw time to value because oftentimes, this is just a time to value question, like how quickly can I see value from deploying this. Value is often very, very quick because there are situations where when Carl talked about unplanned deployments, and unplanned deployment is usually because some kind of catastrophic compromise occurred, credentials were stolen and people show up and they say, well, we need to get -- we need to like reestablish connections to our environment that we can trust again.
And then there will be people in our facilities working until 2 in the morning to get keys to them. It happens. But if that's an indication of what time to value means for YubiKey deployments, that's the best evidence I can give you that this is something that has very rapid time to value.
Everything between a few -- couple of weeks to 7 years. I mean we've seen some customers like 7 years ago, like, oh, we started this little thing and then, oh, you know what, as you said, the reason why they then take action is -- the 2 major reasons are either compliance there's a new regulation that they need to comply with that needs this kind of high level of security or they've had a breach or they got a new CISO that had YubiKeys in his previous job.
Can I ask a quick follow-up on that? Is there a service you could provide where you promise a certain delivery time? Or would you just -- based on what the IT stack looks like in the various customers, but will you actually even further than you do with T-Mobile, et cetera, just redo the implementation for you and then charge for it.
Let me -- so most environments are Microsoft environments in enterprise. So the parts of the environment that we control the delivery of often -- like identity is such a complex stack. There's going to be many things that you're getting right in order for the YubiKey to fit in correctly and deliver the value. But you could deliver and deploy YubiKeys in a day. However, if you did that and you have vulnerability to what I call downgrade attacks, downgrade attacks, all the other places where you don't actually have true phishing resistance in your architecture, but you have ostensibly deployed something phishing resistant on the front door, but you've got an open window here.
And so we can deploy YubiKeys extremely quickly and deliver perceived time to value quickly. But all identity and access management professionals and CISOs will tell you that you have to make sure that you're doing it in a way that gives you the protection you're trying to buy.
The best we can get to today, I think, is working with a professional organization like T-Mobile saying, okay, we're going to get this done. We're going to make sure that we don't have the back door open or open windows, and we're committing them to, yes, we'll support you in that journey. It will not -- the physical access to YubiKeys at this point will not be the limitation. As we scale, yes, that's doable. I think it's more of an implementation partner opportunity than a Yubico opportunity.
Yes. And I think we're going to work with a lot more. I think Mattias talked about some of the global system integrators because a lot of it is not even technology related. It's all change management. Like a majority of these projects, besides going to on plan, they are massive change management and some of it is digital transformation as well. So we certainly don't have the expertise to do like large-scale change management. And that's why one of the leverage plays -- sales plays that we have is to work with the global system integrators, MSSPs. That's our plan to really help accelerate the adoption because those are the folks that know how to do change management and be professional about the cadence and the planning.
We have one last question.
My name is [indiscernible]. And I would like to ask you if you see company acquisition as a way to expand and how would that be?
Yes. Just some background, we've never made an acquisition. It's all been organic growth in the past. However, as we expand in the digital identity space when it comes to life cycle credentials management, when it comes to [ IBV ], those are two areas where there is -- there could be value in "not" reinventing the wheel, but identifying specific product features or specific competencies that would be a quicker time to market and a good return on investment to instead of making an acquisition. We're not quite there yet, but it's not something that will...
It's not off the table.
No.
Thank you to all the speakers. And then I'll leave it for Mattias to close things up.
So thanks, everybody. Hopefully, this was digestible. At times, I need to think really hard to follow along when Albert and Jerrod talk about things. So it takes some time to get your head around it. We're recording everything. If there are parts that you want to revisit, there's a good chance to do so and also all the presentation material will be available online.
I'd like to wrap it up by talking about what I mentioned initially. And I'm really happy about the questions that we got here. This is about how we leverage the position that we build so we can safe -- so we can protect and create safe digital identities for generations. So why are we so confident about our ability to deliver on that? Well, it comes from a few different levers. We already have established a market leadership position in a rapidly growing market, which is the foundation for managing digital identities.
So we created the passkeys protocol, co-created it, and we've built a position where we're being recognized as the world leader when it comes to hardware-based MFA. And we've also established a business model which lends itself to working with some of the largest players in this market to leverage the position we built with them within the current use case YubiKey as a Service and with emerging digital identity solutions.
We have the strongest innovative team in this market that you can find. And I think some of the examples that we've shown today is -- are testaments to the fact that we'll continue innovating and leading the market within strong MFA and beyond. And we have a solid financial position. We have had 3 quarters with lower sales growth than the long-term target, taking a longer perspective. We've had 40% growth since we went public, about 15% growth. We have a stable gross margin. We have consistently had positive cash flow, and we have a very strong balance sheet. So we're in a position where we can invest in building the next big thing.
So with that, I'd like to thank everybody for your interest in Yubico, and we'll hand it over to Alexandra to wrap things up for those that are here. For those of you that have joined online, thank you so much, and we look forward to hosting similar events in the future. Thanks.
Transkripte auf Deutsch freischalten
- Alle Event Transkripte auf Deutsch
- Sofortige Übersetzung
- KI-Zusammenfassungen für die wichtigsten Insights
Yubico — Analyst/Investor Day - Yubico AB
Yubico — Q3 2025 Earnings Call
1. Management Discussion
Welcome to Yubico's Q3 2025 Report Presentation. [Operator Instructions]
Now I will hand the conference over to CEO, Mattias Danielsson; and CFO, Snejana Koleva. Please go ahead.
Good morning, everybody, and welcome to Yubico's Q3 report call. I'm Mattias, CEO of Yubico. And with me today is Snejana Koleva, our new Chief Financial Officer, and we'll take you through the material. And several of you have probably been attending these calls before. But as always, we'll start with a quick overview of the company and before we get into news and details of the financial report. So in terms of the agenda, we'll start with the company overview.
So Yubico is a proud hardware company, and our core product is the YubiKey. And what we typically like to stress when we talk about our growth today is the fact that we are the world leader in modern multifactor authentication. And our customers who have deployed our keys and a modern protocols on the keys have experienced 0 account takeovers. And of course, we want to keep that way. So that's the basis of our success. We're a hardware company. But in spite of that, we've been able to maintain healthy gross margins pretty consistently in the 80% range over the past number of years.
Second thing we'd like to brag about is the customers that we're working with. We've been selling to about 5,000 different business customers, but our focus has been on selling into the largest companies in the world. And as we get back to, we cover almost 30% of the Global 2000, so almost 30% of the Global 2000 companies are existing customer of ours. In most cases, they've only deployed YubiKeys to a subset of their employees. And of course, our journey is to make sure that they protect all of their users using YubiKeys.
We've been growing at a pretty consistent rate. Our average growth rate over the past 5 years has been 4% a year, but it's been variable year-by-year, but we've experienced a healthy long-term growth. Since the start of the company, we've sold and deployed about 40 million YubiKeys. And today, and last 12 months' sales amount to about SEK 2.3 billion. And today, there are approximately 520 people working for Yubico, about 2/3 of them in the U.S., about 1/4 in Stockholm or in Sweden, and the remainder in different sales positions across the world. So that's Yubico in a snapshot.
Okay. I mentioned very briefly the market we're in, which is multifactor authentication. What does that mean? Well, the most common way to access any online service or system, or device is still using a password, where the password is the identity and the -- sorry, where the user name is the identity and the password is how you authenticate that you're the user. And everyone knows that username and password is not a safe way to authenticate. So what you want to have is MFA, multifactor authentication, not just something you know a password, but something that you are, biometrics, something that you have, like an app or a device. And we're in the most advanced form of MFA, the highest level of authentication. And that market for multifactor authentication is estimated to amount to about $5 billion per year.
How can we claim that we're the leader in that market? Well, we're the leader when it comes to modern advanced authentication. There are -- is a lot of legacy technology out there, but gradually, modern forms of MFA is taking over, and we're the market leader in that segment. This market of advanced authentication is estimated to grow at about 14% per year over the next couple of years. So it's a big market where we have only so far a very limited market share, and it's growing quite rapidly.
What the UK has as its unique features is a unique combination of achieving the highest level of security together with its being very easy for user to use, which sets it apart from other ways, which are much more cumbersome when it comes to advanced authentication. And another key feature, pun intended of the YubiKey is that it's a key that fits into all the relevant locks. Fundamentally, what we're selling is a key, the YubiKey, and it's only as usable as the number of locks where it fits. And we've invested a lot in making sure that we have this Swiss Army-type of key that fits into all the relevant locks. It used to be us doing all the heavy lifting in terms of building support for different systems, but now increasingly, instead systems realizing that their customers want to authenticate in the most safe way and therefore, provide support for YubiKeys.
Part of it is the software that goes on the key, and part of it is how it gets integrated into different environments, which is something we'll have a reason to get back to later in the presentation. Now talking then a little bit about customers.
As I mentioned, we're actually in excess of 30% of G2000 companies in terms of coverage today. So if you look 6 years back, we worked with 14% of the Global 2000. Now we're at the full 32%. So that's growing. We're adding new customers continuously. What's also very encouraging is that we see a very high loyalty and repurchase rate from our customers. We have 2 different business models, one, which is an outright sale of YubiKey, and the other one is a subscription model where you instead sign up for the use of YubiKey to ensure that your users are protected with the best technology, and then you instead pay on a recurring annual basis.
No matter the business model, we see a very high repurchase rate. We've been measuring this over different periods of time, but you typically would see an annual repurchase rate among our biggest customers in excess of 100%. How can it be that high? Well, a lot of it is about the fact that we typically land and expand with customers. We win a new customer, and it's typically a limited set of users within that enterprise or government organization that use our keys. And then as people realize that it offers the best protection, it's also very convenient for the user. That's when we start a conversation about expanding into more groups so that the entire organization gets protected.
We started out within tech, and it's still a very important sector for us, but now we have a pretty diverse customer base working across a lot of different geographies and a lot of different industries. So on a very high level, our sales strategy is to land accounts and then to expand within those accounts.
That was it for kind of the overview. Some highlights for the quarter.
As we reported, as we released early, or what's called an early press release or profit warning, we see -- we saw softness in terms of order bookings. So year-over-year, we saw a decline in order bookings by 17%, 9% of that -- 8% of that was attributable to FX, but an underlying order booking decline of about 9%. A little comment on that. What we see and what we highlighted in the quarter was that we saw a decline when it came to the larger orders. We saw good -- continued good momentum and winning new customers, and doing smaller sales. So small and midsized orders grew quite nicely, but the large orders, which are important for making sure that we meet our numbers, we saw softness there.
High level, it should be noted that we saw some currency headwinds. We had year-over-year about 10% appreciation of Swedish krona, which is our reporting currency, compared to the U.S. dollar, which is the currency where we conclude the vast majority of our deals, about 80% and the remainder is in euro, where we also see an increase in the Swedish krona.
Another thing that we highlight is the fact that we are making steady progress when it comes to our product road map, and that was made even more specific as we released new functionalities, which are planned to be released at Authenticate in California in mid-October. One is targeting digital signatures, making sure that you can sign transactions using YubiKey, not just use it for authentication. And the other one, which is a little bit more long-term, so it won't be released next quarter or anything, is the ability to run post-quantum cryptography on the YubiKey, which is important as we want to make sure that we have the most resilient authentication solution even when quantum computers are a reality.
So high level, we continue to expand our market reach, expanding new geographies, setting up a new office in Singapore, and continuing focusing on recurring revenue through our subscription model. And we feel that this and the underlying growth in small and mid-sized deals puts us in a good position to continue growing this market and delivering long-term sustainable growth.
One thing that we could highlight in particular is the fact that we've now -- we've been available on Best Buy online stores in the past. But in Q3 -- sorry, at the start of Q4, I think, we announced that we're now actually even in the physical stores of Best Buy, which means that we can get access to a new set of consumer uses with a different set of packaging and simplifying that they can protect the digital sales using YubiKeys. However, the vast majority of our sales goes into large companies and government organizations, and that remains unchanged. So that forms the basis of our revenue base still.
With that, I'll hand it over to Snejana, who will talk more about the numbers for the quarter. Over to you.
Thank you, Mattias. Let's start first with the key figures for the quarter. So net sales nominally declined with 7%, but the entire change was actually driven by negative currency impact, as Mattias mentioned. 80% of our sales are in dollars, the rest is in euro, and the SEK, our reporting currency, has depreciated year-over-year. So excluding currency effect, our sales are flat versus last year, and our subscription sales are actually growing very nicely. Gross profit nominally has decreased with 10%, but gross profit margin is relatively stable. It has some effect from currency as well.
Looking at the EBIT, it has decreased with 4 percentage points versus last year Q3, primarily as our gross margin is relatively stable, then the rest of the sort of the decline in the EBIT margin comes from increased expenses, as our growth ambition, we are increasing somewhat our headcount to meet and deliver on our growth ambitions. ARR is increasing very nicely, 32% versus last quarter or last year's quarter. very much driven by adding new customers in subscription in our subscription model and renewing our existing installed base. Also, it shows that there is an increasing demand and adoption of our subscription model. So the pages are moving a little bit.
Now let's take a look at -- a little bit closer look at the bookings. The bookings declined 17% year-over-year, whereof 9% was the -- actually the underlying change, and the rest was a negative currency impact. It came -- the order bookings came a bit short of expectations, which we have as well announced in our earlier communications. We've seen fewer high-value perpetual bookings. We had a very strong Q3 2024, where we have multiple large public sector contracts, which we didn't see coming to fruition in Q3 2025. Subscription bookings, however, develop well. We see a decline -- nominal decline of 3.2% versus Q3 2024, very much driven by currency. Now it corresponds to a larger share of the bookings, 17% versus 15% in Q3 2024.
We see that the overall subscription activity and demand and adoption continues to increase. So we see that reflected in both the bookings and then further on in the net sales. From a net sales perspective, as I mentioned, 7% nominal, but actually flat in -- if we disregard the currency impact, increasing share of subscription sales, now it's 16% of the total net sales for the quarter versus 12% in Q3 2024, total SEK 87 million of subscription sales in the quarter. From a geographical perspective, Americas is now 64%, while EMEA and Asia are increasing somewhat in the mix with 25% and 10%, respectively. From an ARR perspective, as I mentioned, 32% increase versus 2023, driven by good renewal rates and adding new customers to the portfolio of subscriptions.
When we look at EBIT, as I mentioned, gross profit is -- has decreased 10% nominally, margin-wise, somewhat decreased versus quarter 3 2024. Overall margin decrease is 4 percentage points versus last year. We see that the costs in the quarter are driven by higher personnel costs, reflecting our continued expansion ambition. Of course, we are very mindful how we grow, but we see that impact versus last year. The LTIP program costs this quarter were about SEK 30 million. Last year, they were SEK 23 million. And we have very small currency effects in the EBIT this quarter, only SEK 0.3 million, while last quarter, it was about SEK 9 million.
From a cash flow perspective, the cash flow for the quarter from operating activities was SEK 32 million. Overall, good cash flow before the changes in working capital of SEK 105 million. The changes in working capital were about SEK 17 million. The majority of that came from changes in inventory, where we have received the last order for our security component. now in Q3. The cash and cash equivalents for -- at the end of the quarter are SEK 875 million, which is an increase versus last year. And excluding the interest-bearing liabilities, the net cash at the end of the period is SEK 835 million. Our interest-bearing liabilities are primarily leases. Inventory has increased as a percentage of the last 12 months' sales to 33%, again, primarily driven by the last shipment, as I mentioned, for our security chip in the quarter.
And with that, Mattias, back to you.
Thank you, Snejana. So just to sum it up then, we fell short of expectations when it comes to order booking in this quarter, and what fell short was really the large orders, i.e., orders in excess of $1 billion. About half of the shortfall is attributable to the U.S. public sector, where the government shutdown definitely had an impact. We saw renewals of subscriptions, but we didn't see any new orders really towards the end of the quarter. The reason why we -- and then we had a number of private sector orders.
So outside of the U.S. public sector, there were also some -- we also saw a shortfall in large orders from the private sector. There's not a common theme there, but what's promising is that with one exception, they remain in the pipeline, and it's continuous conversations about taking that expansion from a small segment of the company into a broader use case. And also combining that with the good activity that we see for small and mid-sized orders, that means that we remain optimistic about the position we have in the market.
We continue to see growth in subscription. And I think that's good because that will provide more predictability and more stable development of net sales over time. We're excited about the collaboration we have initiated with Best Buy. And I think this is a good test for us to see not just how many customers are interested in buying YubiKeys online, but going and buying it in traditional shops, where they can also get support from the local representatives in how they actually deploy the key.
We continue to invest in innovation and future growth. I think the biggest highlight there was really when it comes to our core product during the quarter, highlighting new functionality, which is in the immediate product road map. Finally, if you're interested in learning more about the company and get to learn more about our upcoming product releases, but also a run-through of our go-to-market and also understanding the difference between the 2 business model, perpetual subscription, I recommend and you're quarterly invited to attend our Investor Day, which will be held in Stockholm next week on Wednesday, starting at 3:00 p.m. local time. It will be recorded, so it will be accessible online afterwards. But if you want to be there and ask questions, you are welcome to join our Investor Day.
So I hope to see you there. And with that, we'll hand over for any questions.
[Operator Instructions] The next question comes from Erik Lindholm-Rojestal from SEB.
2. Question Answer
Just a couple of questions from me. So I want to start on the quarter here. You mentioned seeing a high share of smaller and mid-sized orders in the quarter. I mean, is it fair to say that more customers are active and ordering compared to a year ago? And is it possible to disclose sort of what growth you're seeing in the number of orders and the number of customers? I'll start there.
Thank you. So, to respond to that, yes, we did see an increased number of both new customers placing orders and existing customers doing follow-up orders. We debated some before we released this report, whether we should report order value by order size. And we conclude that if we start that, then, of course, we need to continue doing so and may add confusion on -- rather than adding clarity. I think the compromise that we'll go for is that we'll try to share at the Investor Day what the composition of orders by deal size look like because then if you look at orders below $1 million, you can see that's much more predictable, and there's a long-term positive trend there, whereas you see that big volatility when it comes to the bigger orders quarter-by-quarter and even year-by-year. So hopefully, that will add some context to understand what the order composition looks like.
And looking forward to that at the CMD. Then just on -- I mean, you speak about sort of evolving your platform to protect digital identities and not just secure log-ins. And I wanted to ask, is this more of an organic effort that you're developing and aiming to reach with partners, perhaps? Or do you think you have to make acquisitions here to sort of fully reach your goals in this area?
It's more a matter of speed, honestly. It's a very good question, but I'll have to get back to you on that. But if you look at 2 of the critical areas where we need to supplement our current product offering, it's within identity verification and credentials management. And when it comes to IDB, it's a pretty complex business in itself. So it's more about providing a framework so that customers either could fall back on a solution that we offer or that there's a good integration with the IDB identity verifier that they're using. That can be developed internally, or we could seek a partnership or a merchant acquisition, but we'll have to get back to you on that.
The other one, credential management. We do have some of those pieces in place already. When it comes to expanding those, it's a matter of either of partnerships or acquisitions. I don't think you should expect -- if we go down the acquisition right, I don't think you should expect a large acquisition, which is targeting, say, market access. It's more about the critical technology that would be relevant for us.
And then just a final question. I mean, you mentioned most of these sort of large enterprise orders still being active opportunities, the public sector as well, perhaps. I mean, do you feel like there has been any changes to the competitive landscape at all? Are you losing any deals to competition?
I would say if there's one general change in the competitive landscape, is that when we looked at the biggest competition outside of using the password, say, a couple of years back, then it was different software apps, authentication apps on your cell phone. Today, we increasingly see CloudSync passkeys being deployed. And that is both a threat and an opportunity because we are one of the founders behind the Passkeys technology, and we know that technology better than arguably anyone. And analysts like Gartner agree on that CloudSync Passkeys is a giant leap from passwords, but if you want the highest level of security, highest level of security and also the biggest flexibility, then you need to go with hardware-based passkeys, which is YubiKey. So the competitive landscape is changing a little bit in terms of technology and use, but we don't see a major shift there. But that's a long-term trend that we need to explore.
The next question comes from Predrag Savinovic from Carnegie.
Let me start by the U.S. government. You did unpack a bit on the size of it. But in terms of a catch-up effect, can this be, for example, a delay where you see accelerated order momentum Q4, Q1, Q2 due to these budget shutdowns in the U.S.
So I mentioned that for all the with one exception for all the larger opportunities, they continue into Q4. Honestly, we have very little visibility into the federal conversations. There's essentially no one responding to phone calls there. So we'll have to see, as the government opens up again, what the spend mandate is and what the plans are going forward within the federal sector. And that actually has also for state and local, since they also depend on a lot of federal funding in the space. I think it's too early to tell whether there will be a catch-up from them. I think that the need is definitely there. It's more a question, will the budgets be there within the U.S. public sector?
And then another question on the competitive landscape, do you have any visibility or any expectations for how it might change in the future, considering how the capacity in new threats are increasing, becoming more complex, and software is becoming potentially slightly too fragile. Do you see or hear discussions on some of your partners in Silicon Valley and so on in terms of either partnering further with you or developing something themselves?
One trend that we see, I mean, everyone is talking about how AI will impact the threat landscape with more sophisticated attacks and more scalable and industrialized attacks based on harvesting information to make very targeted attacks attacking digital identities. And another aspect of that, when it comes to AI, is with agentic AI, then you really want to make sure that someone that if you authorize an AI to represent you in different transactions, well, then definitely you need strong authentication. I think this will be something that will work in our favor in the sense that there is an even greater need for strong authentication in securing the digital identities that are being out there, whether they're agentic AI or you doing it yourself, so to speak.
What's interesting there is that if you look at the people that are -- probably have the most insight into what this will mean, it's arguably some of the leading AI companies, and we see a very strong market share; almost all AI companies, at least in the U.S., use YubiKeys internally today. That to me is a good indication that we're offering something which is very robust when it comes to AI-enabled attacks. Of course, AI companies today are relatively small when it comes to internal use. But as that insight and as that threat becomes more pervasive, I'm optimistic that there's an ever-growing realization that you need a hardware with good trust.
Finally, in terms of inventory levels, if you can comment on what you think in absolute numbers, but also percentage of sales for 2026?
Yes. I think I've learned to be a little careful when it comes to short-term forecasts. But as Snejana mentioned, the driver between -- for the buildup in inventory in Q3 was that we took final delivery of all second half deliveries -- committed deliveries of secure elements in -- already in Q3. So that meant that there was a short-term peak. And since we don't buy any more of those in Q4, that should, by nature, mean that the inventory levels drop when it comes to components.
We're a little high now in inventory levels, and it's mostly about components where we secured enough secure elements to maintain production, and that should come down. Another thing which could be commented on is that the deliveries of secure elements that we took now in Q3 were actually the last ones of the ones that we committed already 3 years back. So now we're in a position where we can set new inventory -- sorry, purchase levels, meaning that we can reduce inventory level. How fast that will happen? I'm afraid I can't commit to that right now, but that's definitely something that will -- because we are a little too high in inventory levels, particularly when it comes to raw components right now.
The next question comes from Simon Granath from ABG.
And I'd like to continue on the inventory topic because, as you point out, cash flow was weighted by that, and there have been lots of questions on this on previous calls as well. But can you help us unpack why it's necessary to have this, at least in my view, big inventory levels? Is this a competitive edge that you see that your customers really appreciate, i.e. that you have short deliveries? Or could this change markedly over time?
There are 2 reasons for why you want to have a certain level of inventory, really. Fundamentally, it's about our -- one part is fundamentally about our ability to deliver on short notice in the different form factors to customers because even if typically, a deployment is planned and takes at least a large deployment, some quarters to do. In some cases, the customer urgently needs to have a need satisfied. And then it's -- we need to have inventories levels that are sufficient of the different versions in the different geographies that we're serving.
The other part is more about business continuity. And that's on the component side, making sure that the critical components, where we essentially have a single point of failure that we're not put in a position where we run out of stock on those. There was a scare, I think, broadly in the market when it comes to a shortage of -- it's getting later in California, I'm losing the words, of secure elements and more broadly in silicon circuits for some time. And that made us realize that we can't go for just-in-time delivery there. So we've made sure that we secured at least a year of inventory of critical components, which would, if needed, even permit us to transition over to a different technical platform. So that's more kind of a business continuity.
On that part of the inventory, we're a little too high right now because of the volumes that we secured already 3 years back, and that's something that should come down. So we think that the -- to satisfy those 2 requirements, the target inventory level should be in the 23% to 25% range measured against the last 12 months. It's not an official target we have, but that's kind of a rule of thumb we have. So that's the level we should be targeting going forward.
And then I also had a question on net recruitment because, as you highlighted, the momentum from medium-sized customers is good, while there have been slower progress with the larger customers. And does this, call it, change in dynamics? And assuming that this continues as well, incrementally require more sales resources? Or do you see scale effects kicking in here? And in connection to that, how should we think about net recruitment in 2026? Should it be in line with 2025 or slightly slower pace, given the current market dynamics and outlook?
So we're still in a situation where most of the demand is generated in a one-to-one direct sales relationship. Even though a lot of delivery happens through channel, i.e., resellers and distributors, most of the larger deals are settled in a one-to-one direct relationship where we are account executives engaged directly with the customer.
One of the ambitions and one of the big investments that we're making on the go-to-market side is making sure that we have more channel and partner-generated sales. And we're making some good progress there, but that takes time. That's an area where we'll continue to invest in, which means, again, kind of rule of thumb, we're seeing some scalability when it comes to winning orders which aren't generated by our demand generation, but by partners and channel.
At the other hand, we need to invest in building that capacity. So I don't see a big change in the spend -- sales and marketing spend compared to revenue in the short term. But longer term, we want to build more leverage in that model. So I'm not going to be able to provide good guidance for '26, but we don't anticipate any major changes there.
And a final question for me. Can you refresh us on your view around buybacks, especially now, when the share has continued to drop while the balance sheet remains very robust?
Yes. We got -- as a reminder, we got a mandate to repurchase up to 2% of the outstanding shares. Sorry, we got a mandate to -- I think the Board got a mandate from the AGM to repurchase up to 5% of the outstanding shares. And then we had a Board decision to buy up to 2% of the outstanding shares in mid-Q3, if I remember correctly. And as is reported in the interim report, we've used about half of that mandate, but there hasn't been a -- and of course, since late September, we haven't used any more of that mandate, since we then could be argued that we're leveraging inside information while purchasing shares. It's really subject to a separate board decision whether we should resume that, but we'll have to get back to you on that question. But there's still room for the mandate, both the mandate granted by the AGM and the Board decision on how much to repurchase.
The next question comes from Georg Attling from Pareto Securities.
Can we just start on the subscription bookings because most of the decline was obviously less renewals on subscription bookings this quarter? So I'm just thinking in Q4, what's the sort of the size of the upcoming renewals? Is it in line with last year? Or will this be a drag on subscription booking growth in Q4?
I'm not quite sure I got the question there. Could you repeat the first half because I missed it? Snejana, maybe you go ahead. I'm not sure I got the question.
I can just clarify. Yes. So this quarter, we had SEK 43 million of subscription renewals compared that to SEK 62 million in Q3 last year. So just wondering in Q4, if this continues to be a drag or if the size of the upcoming renewals in Q4 are roughly the similar size of Q4 '24.
I can take more sort of a general sort of comment on that. The duration of our subscriptions is on average, 3 years. So every quarter, the subscriptions that come for renewal will be basically the ones that we take 3 years back in the same quarter. So I wouldn't be able to comment kind of on the exact amount. But as we have grown out the subscription bookings lately, like if we look 3 years back, probably sort of the size of the renewals is -- will start increasing as we go forward.
On my second question, I'm just wondering about the personnel cost per employee here. So I understand that FX is moving this a little bit, but even excluding that, we see the cost per head coming down here in Q3. Just wondering if you could add some more color to why that is.
Yes. We have 2 effects in the personnel cost this quarter. One, correctly, as I say, is the FX movement, as we have quite a large share of our personnel cost in the U.S. And then on that note, then we'll have a sort of a positive impact in SEK translation. That's one. And then the other one is that we have 2 development projects that are quite advanced, and we have started this quarter, actually capitalizing part of the time that we are putting into advancing these projects. The total sort of capitalized development cost is about SEK 6 million. So these are the 2 effects.
And that capitalized expenses in personnel costs, R&D, I guess, that's down. Okay. Just final question on Q4 here. Wondering, first, what's your visibility on the larger order bookings? And then generally speaking, is Q4 more tilted towards large orders than Q3 or roughly similar?
I can talk some -- of course, we have visibility in the sense that we -- any large deal, which is expected to close in Q4 is already in our pipeline for some time, and we have visibility into how the conversations are going. So we definitely see that there's progress and activity on them. But as I mentioned before, the volatility when it comes to whether an order actually closes before or after quarter-end is very hard to predict. So that's just generally speaking. There's much more visibility, as mentioned, on small and mid-sized orders, where the velocity is typically much higher and where they're just kind of by the law of numbers, you have more predictability on the aggregate since it's thousands of orders instead of a handful of orders.
When it comes to deal composition, I can see that there's a clear trend across quarters when it comes to the deal composition. However, Q4 is typically a very, let's say, broad-based quarter where you see orders across all geographies and all types of industries. For instance, normally, Q3 is a quarter where you see low activity in Europe because of vacation, and you see high activity in the U.S. public sector because of the end of the federal fiscal year. This year, we didn't see that. We saw pretty good traction in Europe, and we saw very limited activity for U.S. federal orders. So it was a bit of an anomaly. But Q3 is -- that's how Q3 typically looks. We don't see any pattern like that in Q4 other than it being typically a strong quarter, probably because of people wanting to spend their budgets or close business before the end of the year. But nothing really in terms of deal size that can be concerned there.
There are no more questions at this time. So I hand the conference back to the speakers for any written questions and closing comments.
We'll start with a question from David. And the first one is, how does YubiKey as a Service enable faster deployment within organizations and accelerate the land and expand strategy?
Now that's one of our key selling points, really to this stage. There's, to date, relatively limited specific product functionality in the YubiKey as a Service offering. It's just about making sure that we're that partner when it comes to deployment. So I'll give 2 examples of that. One is that we actually help train the customer based on our experience working with other customers on how you execute a good rollout. So that, of course, based on our experience there, that would typically quicken up the deployment. The other one is more when it comes to the sales process because with YubiKey as a Service, the customer doesn't need to know exactly how many keys they will deploy in what location and what type and what type of YubiKey they want to have, USB-A, USB-C, Lightning and whatnot because it's commitment more on protecting the users and then they have flexibility on the form factors. And that typically speeds up -- that particular feature typically speeds up the sales process.
Those would be 2 examples of how YubiKey as a Service is an enabler for faster deployment.
Second question from David is, as past key adoption grows and syncing becomes seamless, through Apple, Google, and Microsoft ecosystems, how do you anticipate this will impact YubiKey demand among SMB and enterprise customers?
Really insightful question because as we talked about before, there are 2 types of Passkeys, one which is CloudSync, and it's typically tied -- well, it is tied to a platform like Apple or Google, or Microsoft. And then there are passkeys that are hardware bound like the ones that are on the YubiKeys. Now the market for Passkey is growing quite rapidly. And a lot of that and a lot of the effort from the platform provider is on promoting the cloud sync Passkeys. However, they're tied to that platform. And it's actually often very complicated to move it across platforms. So not only is a hardware-bound passkey more secure, but it's also more flexible, and you're not tied down to that platform.
So there are 2 different motions impacting that. One is, okay, for convenience, it could be good if you're only using one platform to use cloud-based cloud sync passkeys. However, if you want to maintain flexibility and a more robust recovery, well that you probably want to go for a hardware-bound one. So it's -- we have a very strong, of course, opinion about what would be -- what's the best solution. And ours is always hardware root of trust, even if you can use it for convenience for applications where cloud sync passkeys are deemed safe enough. But I think this is long-term central that will actually foster a type of user behavior, realizing that it's really good to have that separate hardware-bound trust.
Third question, and I'll have to ask you, Snejana, but I'll read out the question. Which LTIP program incurred the costs in the quarter?
So we have 3 active LTIP programs: 2023, the 2024, and the 2025. And all 3 of them have running costs because they are 3 years long. And the 2023 program has the lowest cost because it's a different program, but 2024 and the 2025 program incurred the higher share of the cost because they are performance-based. And according to IFRS, they are sort of different rules how we account for that. But it includes the cost of the program plus the social cost that we will be -- that we will need to pay as an employer based on this benefit.
So it's really all 3 programs that impacted the cost in the quarter, then.
Yes.
Another question for Snejana. It would be very helpful if you could, in a bit more detail, explain the journey towards a subscription model and how long this journey will take. Are we talking about a number of quarters or a large number of years or something in between? I think Q3, net sales subscription percentage was 15.8% and 9-month stage. Okay, the full 9 months. Yes, year-to-date. The optical impression is that this precision is pretty slow. Could you please develop this topic, please?
Yes. It is -- we have an ambition to -- where we think that the natural mix between perpetual and subscription is probably 50-50, but it's going to be a journey to get there. Part of that will be in terms of how we can impact that is really about functionality. We had a breakthrough we felt in Q2 when we, for the first time, saw that high-tech companies were interested in buying on a subscription basis. And then it was not so much about what we talked earlier, deployment support or implementation support, because they're long-time customers and they're pretty qualified.
There was more about commitments on our road map and our functionality, in particular when it comes to PQC, because they're pretty advanced when it comes to thinking about that and knowing what's in the plans there. So -- and for other industries, it's perhaps not either about deployment, but more about business continuity. So I think we need to work pretty much sector by sector to figure out how we have the right offering so that we support our customers, not just with a one-off delivery, but with a commitment from our end. But it is, as you say, a transition that will take a number of years.
Next question is from Alex. How locked are your bookings? Typically, how long does it take for booking to flow into revenue? I'm not sure I get the first part of the question, but how long does it typically take for bookings to flow into revenue for a perpetual sale? Actually, I'll hand this over to you, since you have excellent coverage.
Actually, I mean, how locked are your bookings? I would say pretty locked. I mean it's a contract and a sales order. So yes, it is pretty locked. Typically, how long it takes? So for larger -- for smaller orders, the shipment takes quite fast. The larger orders, it could take some time in terms of shipment, both from -- actually primarily from the customer side as they are planning the deployment. So it takes -- it can take some time, typically a few months. There are some very large perpetual orders that could take up to a year. But now we're talking about the above the large orders that Mattias is talking about, about like $1 million or $3 million.
For the subscription bookings, in the order bookings, we report the total contract value. So on subscription orders, we will see, again, typically a 3-year contract value. And then we recognize the revenue on a linear basis. So the next quarter, it will be like 1/12 of the contract value on average. So that's how it flows. I hope this gives a bit more clarity.
The next question, inventory increased 19% between September '25 versus last year, September '24. How do you see this trending? I think we commented, Mattias already as well commented, we had some final shipments of secure element, both in secure element both in Q2 and Q3 this year. Now these were the final shipments on this contract. So -- and we are a bit high, we would be working on kind of having a bit more optimal inventory. Anything else you would like to comment, Mattias?
I think you covered it. And the final question there, how do you improve cash conversion? Again, I'll ask you to comment first on that, Snejana.
Exactly, I mean from an operating point of view, we have quite good cash conversion before the changes in the working capital. I think, again, the biggest driver to improve that would be the inventory. From ARR perspective, we have quite stable percentage of revenue. So again, it's about working on the inventory.
Then we have an anonymous question. Who are your biggest competitors within hardware-based keys?
So if you talk about all types of hardware-based keys, the biggest competitors are the smart card vendors, and that's the traditional solution. And that includes companies like HID owned by ASSA ABLOY, Gemalto owned by Thales, RSA, OneSpan, I used to be called something different than another OneSpan. Those would be the biggest traditional competitors we have within hardware-based keys. When you talk about passkeys that are hardware-based security keys, it's actually the same companies that I just mentioned because they've now come to realize that this is where the market is moving in terms of strong MFA. So they've all introduced security keys that look surprisingly much like YubiKeys. And they are -- of course, they're good about security. So they're definitely competitors that we respect.
Next question is from Anders at DNB Carnegie. You mentioned AI effects earlier. Is there any other changes in the market that could change increased demand?
Well, I think the biggest thing is how the development continues when it comes to passkeys. It is a much better way than using a password. So we really encourage everyone to consider implementing passkeys to up their game when it comes to MFA. And I think when we enter the customer conversations, they're all aware of this development. And then it's more about, okay, do I want to get the highest level of security and perhaps even more importantly, do I want to have that robustness in my solution and not trust the big platform providers to depend on them on my digital identities. And then it turns into a conversation, okay, then everyone needs [indiscernible] -- do you need to use it for every type of authentication? Probably not. Do you want to use it for very sensitive transactions? Yes. Do you want to have it as the way that you switch between platforms and as effectively the hardware loop trust? Yes.
So I think that the development of passkeys is one of those bigger trends that will impact our demand. And then it's about getting that knowledge out there and, in some cases, also regulation, driving a need for deployment of strong MFA.
I think we have one more question here, circle back. Maybe you want to take this.
It's a follow-up on the LTIP cost. So let me try to explain again. The LTIP for 2023 program is based on total return for shareholders. So we have like thresholds for the share price that determines whether the RCUs will vest. However, so we take the cost basically at the time of granting. It is option-based approach for valuation. And the cost for LTIP 2023 is quite low because of this valuation method. But we take the full cost and we spread it out throughout the duration of the program. And since we have a catch-up effect in -- at the end of the program for all the programs, then we take the full cost.
For '24 and '25, we take the cost, again, at the time of granting the full cost for the full program, so 3 years ahead. But then we spread it out again throughout the months and the quarters. And again, because we have a catch-up effect in both programs when they end, basically, at this point, we calculate or we take the cost with the assumption that 100% of the shares will vest at the end of the program period. So that's really kind of what lies behind. I hope it became more clear. Basically, we take the full cost for all the 3 years, and we spread it out throughout the years.
Great. Then we have a question from Magnus. After several consecutive profit wars, do you think management now has a credibility issue around communications? I'm not sure we have several consecutive profit warrants, but to really back to take there, what happened when we released the Q1 report was that we said that we saw a drop in demand towards the end of Q1 spilling into Q2. So we provided some negative guidance there, and then we follow up when we released the Q2 report. Yes, that materialized into lower sales in Q2 as in net revenue. However, we did see a recovery towards the end of Q2, so the order bookings were unusually weighted towards the end of the quarter, and we saw strong momentum into -- going into Q3. And that's the profit warning now. That positive forecast that we made or the positive comment that I made in my CEO statement about the good velocity going into Q3 didn't actually materialize into the larger orders materializing in Q3, and hence, the profit warning.
Looking in the rearview mirror, well, even without the rearview mirror perspective, I should know -- I've taken enough econometrics to know that it's very difficult to make strong predictions based on only a handful of deals that could be correlated. So I definitely realize that I should have been even more sure before putting a positive statement like that out. So I understand if that introduces a credibility issue. It was all in earnestly, but I can understand if that means that there's some doubt on our predictability. And that's one of the reasons why we, during the Investor Day, we want to show what does a typical deal composition look like over a quarter to give some more confidence in what's predictable and what's not predictable when it comes to order bookings.
Next question, what does YubiKey do better than other hardware-based competitors?
I would put it into 2 things. One is usability, where we, as explained earlier, have invested a lot in making sure that our key actually fits in relevant that is integrated in systems. The other one is about security. And of course, we're using when it comes to PAK an open protocol, an open standard. So it's not difference there, but it's security isn't only about cryptography. It's about the integrity of the product. It's about the integrity even about of the organization. So I think we've had a very holistic perspective and a thought-through perspective when it comes to security, ranging from everything that we source our components from trusted suppliers that we only manufacture control environments in Western Europe and in Europe, and in the U.S., to the fact that we have very rigorous peer control on how new software gets deployed. And I think we have earned a recognition as having the highest level of security.
I'm not going to talk that about anything competitors do, but at least our -- the competitors that I just mentioned. But I think that, that combination of usability and security puts us at the top.
We'll have to wrap it up shortly, but we'll take 2 or 3 more questions. Do you see a threat of the other hardware-based competitors taking market share from Yubico by launching passkeys similar to YubiKeys? Well, all of them already have, and there's definitely competition out there. If there's no competition, there's no market. But because of the combination of usability and security, I feel that we have an edge. We just need to maintain that edge by launching and pursuing new product features and functionality over time.
Given that Yubico's business is largely based on USB support, how do you see the company's future prospective device manufacturers follow this example of removing physical parts as they did with the headphone jack? What is Yubico's plan B in such a scenario?
Well, I should mention that most YubiKeys, excluding those really small ones, the nanos, also support NFC. So I think we will make sure that we cover the different protocols for transmitting data that are out there. So I don't see a change in USB support, or the migration from USBA to USBC has a big impact.
And final question, which 2 to 3 parameters do you consider most insightful to evaluate when thinking about Yubico's intrinsic value?
That's a really good question. I'll have to take a minute to think about it, but let me put it like this. I think you need to get comfortable with the total addressable market and what you think about how that will evolve over time. That kind of sets the potential. And then it comes down to our product market fit, which is a little more difficult to put a number on, but I think you can find indications in terms of how well-positioned the company is by looking at what kind of users they have, what position they have within those.
And then finally, of course, parameters, of course, the financial numbers are how do we deliver on that opportunity, and that's execution.
Great. I think that actually sums up the -- both live and written questions. So with that, we'll end the Q&A. And again, repeat that you're all welcome to attend our Investor Day in Stockholm next week, Wednesday, November 19, starting at 3:00 p.m. Hoping to see as many of you as possible there. Thanks so much. Have a great day.
Transkripte auf Deutsch freischalten
- Alle Event Transkripte auf Deutsch
- Sofortige Übersetzung
- KI-Zusammenfassungen für die wichtigsten Insights
Yubico — Q3 2025 Earnings Call
Finanzdaten von Yubico
Umsatz
Der Umsatz stellt die Summe aller Einnahmen eines Unternehmens z. B. für dessen Produkte oder Dienstleistungen dar.
Umsatz (TTM) einfach erklärtDirekte Kosten
Direkte Kosten sind die Kosten, die direkt im Zusammenhang mit der Herstellung des Produkts oder der Dienstleistung entstehen.
Bruttoertrag
Der Bruttoertrag gibt an, wie viel vom Umsatz nach Abzug der direkten Herstellkosten im Unternehmen verbleibt. Berechnet man den prozentualen Anteil vom Umsatz, spricht man von der Bruttomarge (engl. Gross Margin).
Brutto Marge einfach erklärtVertriebs- und Verwaltungskosten
Die Vertriebs- & Verwaltungskosten (engl. Selling, General & Administrative expenses, kurz SG&A) beinhalten alle Aufwände für Marketing und den Verkauf sowie die allgemeine Verwaltung des Unternehmens.
Forschungs- und Entwicklungskosten
Die Forschungs- und Entwicklungskosten (engl. research & development costs, kurz R&D) geben Auskunft darüber, wie viel das Unternehmen in die Forschung und die Entwicklung seiner Produkte investiert. Vor allem prozentual vom Umsatz und im Vergleich zu direkten Wettbewerbern sind die Kosten interessant.
EBITDA
Das EBITDA (Earnings Before Interest, Taxes, Depreciation and Amortization) ist der Gewinn des Unternehmens vor Zinsen, Steuern und Abschreibungen. Berechnet man den prozentualen Anteil vom Umsatz, spricht man von der EBITDA-Marge.
Abschreibungen
Abschreibungen stellen Wertminderungen von Vermögensgegenständen des Unternehmens dar (z.B. durch Abnutzung von Maschinen).
EBIT (Operatives Ergebnis)
Das EBIT (engl. Earnings Before Interest and Taxes) ist der Gewinn des Unternehmens vor Zinsen und Steuern, das auch als operatives Ergebnis bezeichnet wird. Berechnet man den prozentualen Anteil vom Umsatz, spricht man von
der EBIT-Marge.
Nettogewinn
Der Nettogewinn stellt den Gewinn oder Verlust nach Abzug aller Kosten dar.
Nettogewinn einfach erklärtaktien.guide Premium
| Jun '26 |
+/-
%
|
||
| Umsatz | 2.119 2.119 |
9 %
9 %
100 %
|
|
| - Direkte Kosten | 471 471 |
5 %
5 %
22 %
|
|
| Bruttoertrag | 1.648 1.648 |
13 %
13 %
78 %
|
|
| - Vertriebs- und Verwaltungskosten | 1.183 1.183 |
2 %
2 %
56 %
|
|
| - Forschungs- und Entwicklungskosten | 290 290 |
18 %
18 %
14 %
|
|
| EBITDA | - - |
-
-
|
|
| - Abschreibungen | - - |
-
-
|
|
| EBIT (Operatives Ergebnis) EBIT | 180 180 |
46 %
46 %
8 %
|
|
| Nettogewinn | 151 151 |
41 %
41 %
7 %
|
|
Angaben in Millionen SEK.
Nichts mehr verpassen! Wir senden Dir alle News zur Yubico-Aktie direkt und kostenlos in Deine Mailbox.
Auf Wunsch erhältst Du jeden Morgen pünktlich zum Frühstück eine E-Mail, die alle für Dich relevanten Aktien-News enthält.
Yubico Aktie News
Firmenprofil
Yubico AB, beschäftigt sich mit dem sicheren Zugang zu Computern, mobilen Geräten, Servern, Browsern und Internetkonten. Das Unternehmen hat seinen Hauptsitz in Stockholm, Stockholm und beschäftigt derzeit 528 Vollzeitmitarbeiter. Das Unternehmen ging am 2021-03-25 an die Börse. Seine Lösungen werden von Privatpersonen, Unternehmen und Organisationen weltweit zum Schutz vor verschiedenen Arten von Cyberangriffen wie Phishing und Kontoübernahmen eingesetzt. Das Produktportfolio des Unternehmens umfasst mehrere Hardware-Produktfamilien, die durch ein Servicepaket unterstützt werden: die YubiKey 5-Serie, die YubiKey 5 FIPS-Serie, die YubiKey Bio-Serie und die Security Key-Serie. Darüber hinaus verfügt Yubico über ein umfassendes Unternehmensangebot, bestehend aus YubiEnterprise Subscription und YubiEnterprise Delivery, das die internationale Bereitstellung und Handhabung von YubiKeys vereinfacht.
aktien.guide Premium
| Hauptsitz | Schweden |
| CEO | Mr. Danielsson |
| Mitarbeiter | 514 |
| Webseite | www.yubico.com |


