SentinelOne: Profitability Concerns Are Overblown (NYSE:S)



SentinelOne’s stock (NYSE:S) has had a tricky time since itemizing in 2021, regardless of the corporate performing quiet nicely. This has been as a result of a excessive preliminary valuation, quickly rising low cost charges and rising concern over the corporate’s losses. While SentinelOne’s working bills are excessive, the corporate is realizing speedy progress and margins are bettering with scale. SentinelOne is not probably the most environment friendly group, however their giant R&D investments are making the earnings assertion look worse than it truly is. A decline in inflation will probably decrease strain on unprofitable corporations, and supplied SentinelOne’s progress stays sturdy the stock may do nicely from present ranges.


Cybercrime is reportedly a $6 trillion business and attackers might be giant networks of well-resourced people and even nation state actors. Attackers are leveraging more and more subtle methods, which signifies that organizations want more and more subtle defenses.

The rise of the hybrid work atmosphere, ongoing digital transformation initiatives and an evolving menace panorama are driving the endpoint safety market. This is a big market, which continues to develop, and the penetration of next-gen options is just simply starting.

The assault floor of most organizations is rising as a result of tendencies like distant work, convey your personal system and the rise of IoT units. There will likely be an estimated 41 billion IoT units on-line in 2025, lots of which could have little to no built-in safety capabilities. Visibility throughout related units and steady evaluation of their danger profile has develop into a prime precedence for organizations.

Legacy antivirus options depend on signatures to establish malware, which is ineffective and reactive. Human-powered EDR is a next-gen method the place individuals drive detection and response. Human-powered EDR goals to detect an attack in one minute, examine in 10 minutes and reply inside an hour. This method is probably problematic although as an assault might solely take milliseconds. Legacy antivirus and human-powered EDR each depend on linear human effort to defend in opposition to the exponential progress of cyber threats. SentinelOne characterizes CrowdStrike (CRWD) as a human-powered EDR platform and their very own answer as an autonomous EDR platform, because it doesn’t depend on human intervention.

It is estimated that an extra three million professionals are required to adequately defend organizations in opposition to cyberattacks worldwide. A scalable method is subsequently wanted which doesn’t depend on human intervention to stop, detect, and remediate cyber threats.

Some next-gen instruments additionally battle to deal with the quantity, selection and velocity of knowledge that have to be ingested and analyzed. Many of those instruments generate a considerable amount of noise and require human intervention to extract helpful alerts. Existing EDR instruments may additionally be unable to retailer giant historic information units value effectively, a necessity when investigating previous assaults.

At the time of their IPO, SentinelOne estimated that their addressable market can be roughly $29 billion in 2021. This estimate was up to date to $50 billion in 2022, because of the enlargement of SentinelOne’s Singularity XDR platform into areas like id. SentinelOne additionally believes that there are alternatives in adjoining markets like Threat Intelligence and Data Loss Prevention.

The endpoint safety market is rising because of the breadth of companies supplied by next-gen distributors. Next-gen distributors can probably cost extra per endpoint for managed sort companies and are more likely to be defending a far larger variety of endpoints/workloads (PCs, servers, cloud workloads, Kubernetes, cell units and IoT units).

Sentinel Total Addressable Market 2021

Table 1: Sentinel Total Addressable Market 2021 (supply: Created by writer utilizing information from SentinelOne)


SentinelOne is a cybersecurity firm that was based in 2013. Their platform delivers capabilities throughout endpoint, cell, IoT and cloud safety and information analytics.

SentinelOne’s focus is on using AI to make cybersecurity really autonomous and so they imagine that this differentiates them from legacy safety options and next-gen options which depend on crowd-powered safety. This has the potential to cut back the burden on cybersecurity personnel, however has confronted criticism for producing overly noisy outcomes. An autonomous method additionally permits larger pace and scale, and probably larger accuracy than potential from an individual or crowd.

SentinelOne’s platform ingests, correlates, and queries petabytes of structured and unstructured information from a variety of exterior and inner sources in real-time, permitting SentinelOne to construct wealthy context. SentinelOne’s algorithms are distributed, working each on each endpoint and cloud workload, in addition to on their cloud platform. While inferencing workloads are typically much less useful resource intensive, this method may make SentinelOne’s agent fairly useful resource intensive relative to CrowdStrike’s. Agents which can be overly useful resource intensive are a possible ache level for purchasers in the event that they impact the endpoint consumer’s expertise. This method permits SentinelOne to guard endpoints when they don’t seem to be related to the cloud although.

SentinelOne’s Static AI mannequin predicts file-based assaults, together with beforehand unknown threats. The incontrovertible fact that this course of is autonomous and happens on system additionally makes it quick. SentinelOne achieves industry-leading detection charges by rigorously growing and curating coaching information units at scale.

SentinelOne’s Behavioral AI mannequin displays and hyperlinks all behaviors on the endpoint to create contextual narratives that SentinelOne calls Storylines. Behavioral AI makes use of wealthy contextual data that’s encoded in every Storyline. As a outcome, it’s assault vector agnostic as a result of it isn’t restricted to any specific pathway utilized by attackers to penetrate a system. When an exercise is deemed a menace, the software program autonomously kills the assault and since the Storyline incorporates an entire document of modifications made throughout the assault, these modifications might be remediated. SentinelOne believes this functionality is unmatched on the market and considerably reduces the useful resource burden of remediation.

SentinelOne’s cloud platform aggregates Storylines and their Streaming AI can detect anomalies by correlating a number of information feeds with exterior and inner information. SentinelOne’s platform additionally offers a single pane for a company in order that analysts can shortly and simply examine incidents and hunt for threats.

SentinelOne provides endpoint safety, endpoint detection and response, cloud safety, IoT safety, id safety, information analytics and IT and safety operations. By deploying SentinelOne’s Singularity Platform, prospects can obtain a return on funding of 353% over three years, and a payback interval of lower than three months.

Singularity Mobile permits prospects to handle cell system safety alongside endpoint, cloud workloads and IoT units. Singularity Mobile brings behavioral AI-driven machine pace safety, detection and responds on to iOS, Android and Chrome OS units.

SentinelOne's Singularity Platform

Figure 1: SentinelOne’s Singularity Platform (supply: Created by writer)

SentinelOne additionally provides an rising variety of modules on prime of what’s bundled of their entry degree bundle. Additional modules are provided as a subscription and charged on a per agent foundation.

  • Binary Vault – Enables prospects to retailer and obtain copies of any file that has been executed of their atmosphere for forensic assessment and reverse engineering.
  • Data Retention – Offers information retention upgrades from one month to 3 years and past.
  • Cloud Funnel – Allows organizations to export their XDR information in real-time to their non-public information lakes, whether or not locally-hosted or within the cloud.
  • STAR Premium – Enables customized behavioral and IOC-based guidelines for real-time analysis, alerting, and computerized response workflows.
  • Ranger (for IoT) – Provides organization-wide stock and management of IoT units.
  • Cloud Workload Security – Extends EPP, EDR, and XDR options to supply runtime safety for servers and containerized workloads.
  • WatchTower – Delivers menace looking and insights to assist prospects perceive the character of threats, focused assaults, menace actors, and danger discount.
  • Vigilance MDR – Enables prospects to learn from world-class SOC operations with custom-made menace annotation and response.

SentinelOne's Singularity Platform

Figure 2: SentinelOne’s Singularity Platform (supply: SentinelOne)

SentinelOne has various capabilities, along with their autonomous method to endpoint safety, which they imagine additional differentiates their platform. SentinelOne’s distant script orchestration permits the execution of scripts throughout an enterprise, fairly than system by system. This permits incidence response companions and prospects to quickly reply to breaches.

SentinelOne additionally provides multi-tenancy to assist the usage of their software program as a managed service platform. Multi-tenancy is a software program structure during which a single occasion of software program runs on a server and serves a number of tenants.

Sentinel One provides IoT Security underneath the Ranger model. Ranger transforms SentinelOne’s brokers into an AI powered clever scanning mesh. Ranger discovers related units and delivers community stock and danger mapping. This contains modules to establish unprotected belongings, present details about found units and create community segments that limit entry to the company community.

SentinelOne believes that different SIEM distributors lack automation and enforcement capabilities, and that by combining SIEM with their endpoint safety platform, they’re able to shut the loop. SentinelOne acquired Scalyr to enhance their information analytics capabilities in assist of their platform. Scalyr is now built-in into SentinelOne’s expertise backend and is reportedly performing nicely.

Scalyr is a vital a part of SentinelOne’s XDR highway map because it enhances their capacity to ingest and retailer information. Enhanced information storage capabilities permit prospects to cheaply retain giant quantities of knowledge for longer intervals of time. New prospects are already being onboarded to Scalyr and current prospects are being migrated.

On the again of the Scalyr acquisition, SentinelOne has additionally launched DataSet, an enterprise information platform for information queries, analytics, insights and information retention. DataSet is an enterprise information platform, not simply the again finish for SentinelOne’s XDR platform and addresses use instances like logging, search and real-time occasion information monitoring. DataSet eliminates information schema necessities from the ingestion course of and index limitations from querying. The availability of an index-free method allows prospects to get sooner outcomes at a fraction of the price in comparison with conventional approaches. Index free logging includes storing information in buckets that are tagged so {that a} question engine can discover related information. Indexes are appropriate for programs with low ingest charges and excessive question frequencies. This is problematic for logging because it includes excessive ingest charges and question frequency is commonly low. Index-free logging reduces ingest latency and disk house and {hardware} necessities.

SentinelOne has additionally entered the id safety market, with a $617 million acquisition of Attivo. This acquisition permits SentinelOne to guard id utilizing a zero belief framework. Misused credentials are one of many major methods utilized in breaches. A compromised endpoint can result in compromised consumer credentials, at which level an attacker can set up backdoors, exfiltrate information and alter safety insurance policies. Attivo helps organizations preserve passwords protected, admin privileges restricted and consumer id intact.

Attivo’s id safety is an agent-based answer that secures credentials and detects malicious id behaviors. It delivers real-time safety in opposition to credential theft, privilege escalation and lateral motion. Attivo additionally provides id infrastructure evaluation, identity-based vulnerability scanning and administration for enterprise infrastructure. Attivo’s scanner offers instantaneous visibility of lively listing misconfigurations, suspicious password modifications and unauthorized entry. Attivo additionally has a deception answer that makes attackers reveal themselves, their strategies and targets via misdirection.

Identity is an estimated $4 billion alternative and Attivo is capturing share inside that market, rising its ARR at over 50% yearly. At the top of 2021 Attivo’s ARR was roughly $30 million, and income in 2022 was forecast to be $40 million. Attivo has over 300 prospects, from Fortune 500 enterprises to authorities entities. The acquisition opens up new buyer and cross-sell alternatives.

SentinelOne additionally provides a market the place prospects can combine purposes throughout various classes (Threat Intelligence, SIEM, Sandboxing, Analytics, and Workflow Automation) into the Singularity Platform. Singularity XDR Marketplace additionally permits safety groups to drive a unified, orchestrated response amongst safety instruments in numerous domains.

Partnerships are an more and more necessary a part of SentinelOne’s enterprise, and will drive gross sales and advertising and marketing effectivity sooner or later. Managed safety service suppliers present outsourced monitoring and administration of safety units and programs. SentinelOne’s partnerships with these organizations (Enable, AT&T, Pax8, Continuum, Kroll) give them mid-market and huge enterprise protection, and are an necessary supply of progress. ARR from the MSSP channel elevated by 300% YoY within the third quarter of FY22. SentinelOne’s strategic expertise and companies companions (together with MSSPs, MDRs and IR companions) have grown to over 20% of their enterprise.

SentinelOne additionally continues to construct on their incidence response partnerships (Mandiant, KPMG, Kroll, RSA), and have been growing persevering with training programs to enhance their accreditation applications. These programs preserve companions up-to-date on new capabilities and modules.


SentinelOne faces various rivals, together with:

  • CrowdStrike
  • VMware (VMW)
  • McAfee
  • Symantec (Broadcom (AVGO))
  • Microsoft (MSFT)
  • Palo Alto Networks (PANW)

CrowdStrike, Microsoft and Palo Alto are in all probability a very powerful rivals because of the breadth of their answer portfolios and the power of their choices.

SentinelOne has talked about win charges at or above 70%, together with in opposition to their closest friends. SentinelOne has additionally pointed to excessive and bettering win charges for offers value over $1 million and over $100,000, that are typically in opposition to different next-gen rivals.

From a contest perspective, there are a selection of present developments that might permit SentinelOne to select up market share. Kaspersky is a Russian cybersecurity vendor that’s probably offering tailwinds to rivals because of the warfare in Ukraine. SentinelOne is at the moment seeing a sizeable motion away from Kaspersky, both by mandate or as a result of prospects need a greater safety platform.

Broadcom’s acquisition of VMware is one other potential tailwind for competing options. According to market share experiences, there was a big shift to next-gen distributors from Symantec after they had been acquired by Broadcom. The identical scenario will probably play out with Carbon Black, benefitting corporations like CrowdStrike and SentinelOne.

Financial Analysis

SentinelOne continues to counsel that demand stays sturdy, though administration seems to have develop into barely much less bullish in latest quarters. In the latest quarter administration urged that gross sales cycles had develop into marginally longer and required extra budgetary approvals. Cybersecurity is a prime IT spending precedence, and administration believes that the macro atmosphere has not impacted that. The penalties of not being protected by a number one cybersecurity answer are too nice for purchasers to chop spending.

Cloud safety is SentinelOne’s quickest rising phase, with greater than 10% of SentinelOne’s endpoints being servers or within the cloud. SentinelOne expects that cloud will proceed to increase and sooner or later will likely be comparable in measurement to the endpoint market. Customers are selecting Singularity cloud along side endpoints and on a stand-alone foundation. SentinelOne can be seeing increasingly cloud solely offers. The scale of cloud footprint in early deal sizes point out a a lot bigger future potential.

SentinelOne expects natural progress to be mid-80% going ahead, a powerful determine given the corporate’s measurement. This would proceed to position SentinelOne’s progress broadly inline with CrowdStrike’s on the identical measurement.

SentinelOne Revenue Growth

Figure 3: SentinelOne Revenue Growth (supply: Created by writer utilizing information from firm experiences)

SentinelOne’s progress has been pushed by sturdy adoption of their next-gen endpoint answer, together with the introduction of latest options (MDR, EDR, cloud workload safety, Scalyr) and FedRamp certification. Emerging merchandise like Ranger IoT, cloud workload safety and information capabilities are all rising at triple-digit charges.

SentinelOne ARR

Figure 4: SentinelOne ARR (supply: SentinelOne)

SentinelOne’s buyer base continues to develop quickly, though it’s at the moment nonetheless pretty small. Revenue per buyer can be rising as a result of SentinelOne attracting bigger new prospects and increasing inside current prospects. Revenue per buyer can be comparatively low and has vital room for enlargement as SentinelOne continues to introduce performance to their platform and defend extra endpoints/workloads.

SentinelOne Customers

Figure 5: SentinelOne Customers (supply: Created by writer utilizing information from SentinelOne)

As of January 31, 2021, SentinelOne’s dollar-based gross retention rate was 97%, which is fairly excessive and supportive of bettering margins because the enterprise scales. Gross retention can be probably to enhance over time as SentinelOne introduces extra modules and an rising variety of prospects standardize on their platform. SentinelOne’s internet retention fee can be sturdy and has been bettering as prospects undertake extra modules.

SentinelOne Dollar Based Net Retention Rate

Figure 6: SentinelOne Dollar Based Net Retention Rate (supply: Created by writer utilizing information from SentinelOne)

SentinelOne’s gross margins are comparatively low given the character of their platform, however have been slowly bettering. There have been recommendations that SentinelOne is prepared to undercut rivals on value to achieve market share, which can be contributing to decrease gross margins. The migration of current prospects to SentinelOne’s DataSet again finish has additionally resulted in quickly larger prices. SentinelOne are focusing on gross margins of 75-80% within the long-term. This needs to be achievable as SentinelOne earns excessive incremental margins when prospects undertake a number of modules.

SentinelOne Gross Profit Margins

Figure 7: SentinelOne Gross Profit Margins (supply: Created by writer utilizing information from firm experiences)

SentinelOne’s working revenue margins are much more regarding than their gross margins, because of the firm’s excessive working bills. While margins are bettering with scale, SentinelOne’s working losses are giant for a corporation its measurement.

SentinelOne Operating Profit Margins

Figure 8: SentinelOne Operating Profit Margins (supply: Created by writer utilizing information from firm experiences)

SentinelOne Operating Leverage

Figure 9: SentinelOne Operating Leverage (supply: Created by writer utilizing information from firm experiences)

This seems to be extra the results of heavy investments in R&D than inefficient gross sales and advertising and marketing. SentinelOne is much from being a lean group although, as exemplified by their excessive common and administrative bills.

SentinelOne Operating Expenses

Figure 10: SentinelOne Operating Expenses (supply: Created by writer utilizing information from SentinelOne)

As of April 30, 2021, 35% of SentinelOne’s employees labored of their R&D group. The burden of R&D bills is declining, and supplied that the corporate continues to introduce performance that drives progress, R&D prices should not a significant concern.

SentinelOne R&D Expenses

Figure 11: SentinelOne R&D Expenses (supply: Created by writer utilizing information from firm experiences)

SentinelOne’s gross sales and advertising and marketing bills are comparable in magnitude to CrowdStrike’s at an identical measurement. SentinelOne might be able to enhance the effectivity of their gross sales and advertising and marketing group as their partnerships mature and develop in relative significance.

SentinelOne Sales and Marketing Expenses

Figure 12: SentinelOne Sales and Marketing Expenses (supply: Created by writer utilizing information from firm experiences)

SentinelOne has elevated its headcount quickly since going public, and continues to rent aggressively in assist of progress. There is little indication in SentinelOne’s hiring information up to now that they’re dealing with a requirement slowdown that’s regarding administration. They are additionally within the means of globalizing their expertise pool into new areas just like the Czech Republic and India, which ought to assist to manage prices.

SentinelOne Job Openings

Figure 13: SentinelOne Job Openings (supply:

SentinelOne’s administration has urged that they’re focusing on working margins of over 20% within the long-run, which appears cheap based mostly on their present trajectory. Their monetary efficiency is at the moment a good distance from best-in-class firm’s like CrowdStrike, however gross margins will enhance and the burden of R&D will decline. Importantly, SentinelOne will understand economies of scale and scope over time and churn ought to decline.

By capitalizing a portion of SentinelOne’s working bills to account for investments in intangible belongings and adjusting margins for scale to account for working leverage, a clearer image of SentinelOne’s profitability might be ascertained. Depending on how giant SentinelOne in the end turns into, and whether or not they can preserve their low churn and excessive enlargement, it might not be unreasonable to anticipate working revenue margins of round 20-25% at scale with normalized progress.

SentinelOne Growth and Scale Adjusted Operating Profit Margins

Figure 14: SentinelOne Growth and Scale Adjusted Operating Profit Margins (supply: Created by writer utilizing information from firm experiences)


Investor time horizons have compressed considerably over the previous 18 months, with buyers now much less involved about an organization’s long-term capacity to generate free money stream and extra involved about subsequent quarter’s income. For corporations like SentinelOne, this has brought about a big decline in share value as they’ve gone from buying and selling at a premium based mostly on progress, to buying and selling at a reduction based mostly on profitability. Looking ahead 5-10 years, SentinelOne ought to provide buyers sturdy returns if the corporate can preserve its aggressive place. In the present market atmosphere this issues little although, and with out present income there isn’t any actual ground for the stock value.

SentinelOne Relative Valuation

Figure 15: SentinelOne Relative Valuation (supply: Created by writer utilizing information from Seeking Alpha)


SentinelOne has been rising quickly in a robust demand atmosphere for cybersecurity software program. The stock seems attractively priced if SentinelOne can proceed progressing in direction of profitability, supplied that progress doesn’t deteriorate an excessive amount of going ahead.

Source link


Please enter your comment!
Please enter your name here