Rubrik, Inc. Goldman Sachs Communacopia + Technology Conference 2026
Review the key takeaways and the transcript of this earnings call.
- Rubrik reported net new ARR growth accelerating to 35% in the most recent quarter and raised its full-year guidance.
- The company has evolved from backup to cyber resilience and now focuses on security and AI operations, aiming to deliver resilience across data, identity, and AI agents.
- Rubrik's platform enables cyber recovery at machine speed, addressing the shift to continuous autonomous attacks and recovery.
- The identity business scaled to $50 million in just over a year, complementing the $100 million data security business, with strong growth potential.
- Rubrik introduced Flex, a new consumption model providing customers flexibility to buy and consume multiple products under one contract.
- The company is seeing increased demand for sovereign and self-hosted solutions due to geopolitical risks and data sovereignty concerns.
- Rubrik continues to win against legacy competitors by adding capabilities and delivering integrated platform value across on-premises and cloud environments.
- The company is engaging early with customers on its Annapurna solution, which enables AI to operate efficiently on large volumes of unstructured and semi-structured data by slicing relevant data portions.
- Rubrik emphasizes the importance of resilience over prevention and detection alone, given the rise of machine-speed AI attacks.
- The company envisions autonomous recovery with human-in-the-loop only for decisions, enabling continuous recovery and patching at machine speed.
STOCKNOW INSIGHTS
Continue with outlook and guidance.
Log in to unlock executive comments and Q&A highlights.
Log in for the full summaryStockNow uses AI to translate and summarize earnings calls. Accuracy and completeness are not guaranteed.
Transcript
Preview the first fifteen paragraphs, organized by speaker.
All right. Good morning, folks. We're going to get started in the interest of time. We have the pleasure to have Bipul Sinha, CEO of Rubrik, here this morning. Welcome back to the conference, Bipul.
Thanks, Matt. All right. Well, let's get started.
Bipul, you've called this a singularity moment for AI and cybersecurity. As enterprises become increasingly reliant on AI systems and autonomous agents, what do you think changes most about the way organizations think about risk and resilience?
We have been talking about this for the last many years, that prevention and detection is not sufficient. Folks have to really think about recovery and resilience because you can't prevent the unpreventable. What Mythos and frontier models have shown is that you can't really prevent and detect anything because these attacks are at machine speed, and at machine speed, you can't prevent. All the technologies that we have built for cyber in the last 20, 30 years was built for human operator and human attackers. We are in a completely different era. This is a new moment, and all you can do is to think about how do you patch your systems at machine speed, and how do you deliver cyber recovery at machine speed. That's what Rubrik is solving for our customers, doing a cyber recovery at machine speed.
Okay. Even over the last 2 years, I think Rubrik started with backup. You evolved into cyber resilience, and now you talk about security and AI operations. When you connect those dots, what do you ultimately want Rubrik to become? 3 years from now, what do you think customers will be buying from Rubrik that they are largely not buying today?
Our goal is to deliver resilience to every aspect of operations. What are the different things we do? Number 1 is data. We want to ensure that your data is recovered and your applications are up and running. Number 2 is identity, because we want to ensure that the data risk comes from identity, and identity systems are up and running, and they are in the correct state. Then the third piece is AI. As we know, agents assume identity and operate on sensitive data. So you need to have resilience and security for agents. How do we ensure that agents are only taking the right actions? If they do bad action, how do we rewind the action of agents? We are very clear. There are 2 major trends in the market, AI and cybersecurity. Underneath AI and cybersecurity is identity and data.
We want to deliver complete cyber resilience across data identity and agentic world.
Okay. You talked about prevention and detection alone not being enough. I think you have been very consistent in that message. If attacks are becoming increasingly autonomous and continuous, what does the security architecture ultimately look like on the other side of that shift, and where does Rubrik sit within that architecture?
In my mind, since attacks are going to be at machine speed, it will be a world of continuous attacks. Today, operations and cyber are two different teams and two different things inside any business. I believe that these two, operations and security, will merge. You will have a situation of continuous attack and continuous recovery and continuous patching. In this world of continuous attack and continuous patching, you need to have a human in the loop at the very minimum level, where the humans are making decision, but machines are implementing decisions. This is where the cyber is going to go. It is going to be a world of no human in the loop patching, mostly no human in the loop recovery.
Let us pull that into the most recent quarter. Net new ARR accelerated to 35%. You raised the full year guide. I guess a two-parter here. One is what felt different in the business this quarter. I guess if we dovetail off of the previous question, are you seeing Rubrik sort of increase in relevance within sort of the security budget more broadly? How is that shaping customer conversations today, even relative to a year ago?
If you think about this idea of Mythos and frontier AI and machine speed, businesses, particularly board and CEOs, are realizing more and more that cyber has gone from a technology discussion, whether it is endpoint network, cloud, zero trust network, all of that mumbo jumbo, to a risk discussion. That can we keep our business up and running? What is our dollar at risk should we go down for a day or two or three? Do we have a situation where my large manufacturing will come to a screeching halt just because of the ransomware attack or cyber attacks? That is the discussion now. Rubrik plays in that discussion because we are giving assurance to our customers, saying, no matter what happens, whether it is AI attack, human attack, machine speed attack, you will always be up and running because of our Preemptive Recovery Engine.
We pre-calculate a clean data state in peace time to be able to deliver a machine speed recovery. This message is resonating. Obviously, Rubrik is a considered purchase, as we are not like a Facebook app that millions of people download overnight and we run the market. There will be a process. I like that process because at the end of the day, I want us to have consistent high growth for many years. We believe that we are set up for it.
Okay. A lot of the strategy increasingly is around data, identity, and agents. You have broadened the aperture from just pure cyber resilience into some new categories. Why is it important to see all three of those together, and what can Rubrik do with that combination that customers cannot get from separate point solutions?
Let us just take agents. If you think about agentic security and governance, there are many pieces to it. You need to have visibility into all your agents, sanctioned or unsanctioned. Second piece is, can you do identity-based, just-in-time regulation on activity of these agents? That is the number two. So that is an identity-based MCP server level, which database, which entity these guys can update. The third one is runtime security, and this is where the intent understanding of agents are important. What happened in the OpenAI Hugging Face is these agents to get to a goal, they actually circumvented the guardrails that was built for them. So you need to understand the intent of the agent and check the intent on every interaction of the agent to be able to stop the agentic action on runtime at the point of action.
Then finally, the rewind piece, that if the agent still does something that is not desirable, how do you undo it? Folks are now buying observability from one vendor, identity from a different vendor, runtime security intent from third vendor, and agent rewind or recovery from a fourth vendor. We believe that businesses need a consistent, fully integrated agentic security and governance platform, and Rubrik has the vision and the path to deliver that.
FULL TRANSCRIPT
Continue the full translated transcript in StockNow.
Log in to unlock every statement, the English original, and speaker-by-speaker history.
Log in for the full transcriptCall participants
2 people spoke on this call — only 1 are shown here.
PARTICIPANT LIST
View participant details in StockNow.
Log in to see executives and analysts, their roles, and complete speaking history.
Log in to view all participantsKeep exploring
