Hello everyone,
small correction: The aforementioned hyperinflation of assets is of course taking place everywhere except in my bank account.
My portfolio statement reads like a list of dead bodies of a bygone economic era. Unfortunately, high-performance coins and chips are missing, instead the little money is in underperformers of the real economy. However, the former technology leaders of the empire will certainly soon wake up from their Sleeping Beauty grandmother once the AI infusion has an effect.
The net is upset about the data theft in Berlin and the stupid German children (context?), while my colleague at the next table gets rich with swing trades. The insider tips come from a legendary Discord community. But I’m unwelcome as an onlooker, my starting capital too low, my age too high, my eternal skepticism too annoying.
Maybe we can pool our security and stock market know-how together and then make the financial breakthrough.
In this issue, I make a push forward and hope that the financial professionals of the Cybersec crowd will consider me and us in possible insider trades.
Cyber resilience has always been important and becomes even more important when the likelihood of a breach increases.
A CISO told me in an interview yesterday that his ideal next career move would be the position of “Chief Resilience Officer“.
Can you also benefit from this trend as a small investor? Let’s take a look at the providers of backup and recovery solutions .
Changing the recovery system causes extremely high effort due to the numerous integrations, so the lock-in effect is high and the price elasticity of demand comparatively low.
Too bad for the customers, pleasing for us as the up-and-coming investors.
Key figure | Unit | Category | Commvault | Backblaze | NetApp | Nutanix | Veeam | Cohesity | Acronis |
Revenue | Mio. USD | 1300 | 1200 | 150 | 7000 | 2850 | 1800 | 1700 | 450 |
Sales growth YoY | Percent | 48% | 19% | 14% | 5% | 12% |
|
|
|
Free Cashflow | Mio. USD | 150 | 240 | 20 | 1300 | 840 |
|
|
|
EBITDA Margin | Percent | -25% | 10% | -4% | 27% | 14% | 30% | 28% | ? |
Market capitalization | Mio. USD | 19000 | 5700 | 800 | 36000 | 18000 |
|
|
|
Price / Sales | # | 15 | 5 | 5 | 5 | 6 |
|
|
|
Price / FCF | # | 127 | 24 | 40 | 28 | 21 |
|
|
|
Disclaimer: I’ll save IBM, Dell, Microsoft and HP here, the numbers in the 10k and the further prospects of success probably have little to do with backup / recovery.
Veeam, Acronis and Cohesity are not listed on the stock exchange, and reliable figures are hard to come by.
Also, the fiscal years and the definitions of ARR are of course individual, so please don’t compare decimal places.
I have included NetApp and Nutanix as storage players somewhat arbitrarily, after all, recovery is listed as a core business area.
Probably no one knows Backblaze , is a smaller US provider. Here, shareholders have been pretty diluted by stock-based compensation (SBC) in the last few years – basically an issue for most tech companies, of course, especially for Rubrik due to the IPO.
Overall, it turns out that you can apparently earn good money with backup & recovery. Almost as much as with firewalls. Based on this shallow amateur mini-analysis, I would say that Nutanix ‘s rating seems to me to be the most sympathetic at the moment, followed by Commvault.
As an alternative to the VMWare hypervisor, Nutanix also benefits from the fact that many customers would like to migrate away from Broadcom as quickly as possible (in an iX comparison of 14 solutions, Nutanix was included in the tech stack of 4 providers).
Commvault is buying back a lot of shares and could perhaps also become a takeover candidate for the crowdstrikes and palo altos of this world .
Other perspectives? In any case, I have been a dwarf shareholder in both companies since this week.
Speaking of firewalls. The research for an undiscovered cash calf has also produced something. A blunt company name from the buzzword lexicon, P/E ratio of around 20, profitable, sales (~30 million EUR) is growing faster than the market, net cash position, price 80% below the peak, microscopically small compared to the US giants (200 MA) and completely unknown to analysts: This is Cyber Security Cloud, the local WAF market leader from Japan.
Cherry on top: The marketing + sales quota is only ~10%. The position vis-à-vis AWS, MS, Cloudflare, Akamai etc. is apparently being expanded via managed services. Someone has to write and maintain all the rules, and they don’t get any less with AI applications. Of course, there has also been an AI Gateway with AI Guardrails and AISPM for a few weeks now. The corresponding press release alone would be worth at least 100 million for US VCs, which is about the current market value.
I like it. It could be that I’ll get a few bills there. I just hope that my buy order is not the death knell for the share price as usual.
In all the hype and the multibillions, of course, it stands out all the more when a large security company has financial problems.
- Some of you may know Optiv from the cybersecurity landscape, which we also included in the first pitch decks of CyberCompare. Otherwise, Optiv is primarily active in North America – originally essentially a reseller, now as one of the largest MSSPs, and in the meantime probably even the largest pure security service provider in the USA
- Approx. 700 million USD revenue (roughly 50% share through VAR reselling of approx. 400 security vendors, the rest services, mainly MDR/MSOC), ~5500 customers, ~2000 employees
- Owner KKR, acquired by Blackstone in 2017, emerged from a merger of FishNet Security and Accuvant in 2015.FishNet was founded in 1996 and sold for USD 380 million, so a fabulous success story for its time
- Since the purchase of KKR, operating profit has shrunk to the point where debt (~$1 billion) is 20 times EBITDA (= creditors get their money back in 2046 and have to forego interest payments until then)
- The decline in sales is attributed to cuts in sales staff, changes to the bonus system and increases in prices (or fewer discounts for customers), among other things
- The consulting business (~500 employees) was passed on to a new PE investor in June
Once again, it turns out that the classic private equity playbook with extremely high debt is a gamble. If revenues fluctuate, the balance sheet immediately takes a hit.
Last but not least, a reference to the handout on penetration tests of the German IT Security Association, which contains, for example, a comprehensive catalog of criteria for inquiries of common tasks. The OWASP Testing Guides, to which reference is made, are even more detailed. In this category, a Babylonian confusion of terms can still be observed, especially among SMEs, and pure vulnerability scans are still declared as pen tests.
M&A Headlines:
- PAN buys Console (ITSM, of course with Agentic workflows) => addition Cortex SOAR and presumably an attack on ServiceNow
- Clickhouse (Observability) kauft RunReveal (SIEM). Told you so.
- Spin.AI (SSPM, Browser Sec, SaaS Backup) buys competitor DoControl
- NetSPI (BAS / Human Pen Tests) merged with US competitor Synack, together resulting in sales of USD 200 million
- Adelis (PE from Sweden) takes over the German MSP/VAR Plenticon (~400 employees)
- Infravia (French PE) buys a majority stake in Nexis (IAM + GRC from D)
- At Saviynt (IGA), another 250 million USD of new capital will be injected, and MA will be bought out in secondaries, if I understood the PR announcement correctly. Meanwhile ~300 million USD ARR and already valued at 3 billion in the last round. Symptom of the trend that successful companies are making an IPO less and less often / later.
- Upwind (CNAPP) receives another USD 300 million
- Hiddenlayer (“AI Discovery, AI Supply Chain Security, AI Attack Simulation, AI Runtime Security”) erhält weitere100 Mio. USD Funding
- Xorlab (Digital Sovereign Email Sec from Switzerland) receives EUR 5 million
- Update on the Crowdstrike / XM Cyber Deal: SafeMind is probably partly based on the XM technique (thanks, Wolfgang!), but of course there is also a lot of CS know-how about attack paths and remediation in it
Quick notes from vendor conversations:
Vivid:
- Israeli start-up for comprehensive recovery management, i.e. large companies with multiple systems, still in the early stages
- Integrations with popular backup providers such as VEEAM, Rubrik, Cohesity, Commvault, AWS…
- First check the backup configurations against good practices
- After that, the dependencies are checked for a successful recovery
- Auf Roadmap: Kontinuierliche Recovery Tests in Sandbox
Censys (Update):
- Search engine for Internet-connected assets / Attack Surface Mgmt, is probably known to many readers as an alternative to Shodan, Recyber, Bitsight: Daily scans of 250 million IPv4 and IPv6 hosts each as well as ~3.3 billion services across all 65k ports
- Paying reference customers include BSI and Airbus (of course there is also the free community version)
- Customer-specific alerting in the event of relevant new vulnerabilities / exploits
- Darknet information not taken into account by default so far
- Excitingly, Censys also offers cyber insurance companies, for example, the complete data so that they can better calculate the risks for customers
Cato Networks:
- SASE/ZTNA/SD-WAN complete package from Israel/USA, of course also with and for AI (we already bought an AI Sec specialist with Aim 1 year ago)
- Customers in the EU include Vitesco, Carlsberg, Swissport
- In the identical architecture / data lake / range of functions supposedly also usable for locations in China
- Good approach: Integration with the EDR/XDR solution (Bitdefender, Crowdstrike, Defender, SentinelOne) for direct coupling of device status and enforcement of policies. In addition, own response options
- Baselining for the initial generation of permissions => Smart to get started with Zero Trust. Nevertheless, there is no getting around a thorough review of all access rights found in this way
- OT/IoT management: No agent on devices, but a VPN gateway / edge device per site
- Feel free to take a look at projects, sympathetic DACH team
TransferChain:
- File exchange, shared storage and PW management from Switzerland (development personnel mainly in Turkey)
- Approx. 100 corporate customers, e.g. some asset management companies
- Zero Knowledge Encryption with random distribution of files
- Object storage is quantum-safe, HIPAA + FINRA compliant
As always, nothing here is AI-generated. Questions, suggestions, comments, experience reports, topic requests and also opposing opinions or corrections are welcome by email. Ditto for unsubscribing from the mailing list.
For the people who have received the market commentary for the first time: Here you can register if you are interested or convert the archive into a message board using AI agents and thus take over the world.
Best regards,
Jannis Stemmann
