NYSE AMERICAN: CTEK
CYNERGISTEK
I N V E S T O R P R E S E N TAT I O N
CYNERGISTEK I N V E S T O R P R E S E N TAT I O N NYSE AMERICAN: - - PowerPoint PPT Presentation
CYNERGISTEK I N V E S T O R P R E S E N TAT I O N NYSE AMERICAN: CTEK SAFE HARBOR STATEMENTS This presentation contains, and our officers and representatives may from time to time make, forward - looking statements within the meaning of
NYSE AMERICAN: CTEK
I N V E S T O R P R E S E N TAT I O N
2
This presentation contains, and our officers and representatives may from time to time make, “forward-looking statements” within the meaning of the safe harbor provisions of the U.S. Private Securities Litigation Reform Act of 1995. Forward-looking statements can be identified by words such as: “anticipate,” “intend,” “plan,” “goal,” “seek,” “believe,” “project,” “estimate,” “expect,” “strategy,” “future,” “likely,” “may,” “should,” “will” and similar references to future periods. Examples of forward-looking statements include, among others, statements we make (herein or otherwise) regarding the size of the potential market for our services; the number of potential customers/clients for our services; plans and strategies of CynergisTek and its subsidiaries for future growth and performance; market acceptance of our business model; our ability to integrate acquisitions and merged companies; and timelines relating to growth, milestones, and strategic focus. Forward-looking statements are neither historical facts nor assurances of future performance. Instead, they are based only on management’s current beliefs, expectations and assumptions regarding the future of our business, future plans and strategies, projections, anticipated events and trends, the economy and other future conditions. Because forward-looking statements relate to the future, they are subject to inherent uncertainties, risks and changes in circumstances that are difficult to predict and many of which are outside of our control. Our actual results and financial condition may differ materially from those indicated in the forward-looking statements. Therefore, you should not rely on any of these forward-looking
looking statements include, among others, the risk factors discussed throughout Part II, Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations, and in Part I, Item 1A. Risk Factors of our Annual Report on Form 10-K for the year ended December 31, 2019; and throughout Part I, Item 2. Management’s Discussion and Analysis of Financial Condition and Results of Operations of our Quarterly Reports on Form 10-Q for the quarters ending March, June and September 31. Any forward-looking statement made by us in this presentation is based only on information currently available to us and speaks only as of the date on which it is made. We expressly disclaim any obligation to publicly update any forward-looking statement, whether written or oral, that may be made from time to time, whether as a result of new information, future developments, or otherwise.
3
▪ Unrivaled industry expertise in healthcare, covering 1,000+ healthcare provider locations and business associates, and partnered with 2 of the 10 largest health systems in the US; a top medical device manufacturer; and 4 Electronic Health Records Companies ▪ Revenue is packaged as a recurring managed service with significant upsell opportunity for re-occurring consulting and professional services ▪ Trusted advisor enabling clients to protect and support patient safety and care operations ▪ Leadership team with experience across the security and healthcare industry including former auditors, Healthcare CIO’s and leaders at Symantec, Cylance and IBM Security
CynergisTek is the premier provider of cybersecurity managed services and security & compliance consulting to healthcare and other regulated industries
Founded in 2004
Est.
115 Employees Continued YoY Growth in Managed Services Revenue
$
$21.4M 2019A Revenue
What makes us unique? Industry Accolades: Top Performing Services
KLAS
2018Cybersecurity
KLAS
2018HIT Advisory
KLAS
2018Tech Services
CYNERGISTEK AT A GLANCE
24%
Of managed service clients have 2
85%+
2019 Managed Service Renewal Rate
~61%
Revenue driven by recurring Managed Services segment in 2019E
$
~39%
Revenue driven by re-occurring Consulting Segment, and Professional Services
330 Customers Nationwide 1k+ Healthcare Locations 50%+
Of clients using 2 or more service
145
Managed Services Clients
4
Top 10
Most likely industry to be attacked
329 Days
Time to Identify and Contain a Breach
2x Cost
Healthcare data breaches are nearly double the cost of the average
$7.13M
Average cost of Healthcare data breach
59%
Of attacks in Healthcare come from the inside
32M
Healthcare Records Breached in First Half of 2019
$14.4B
Anticipated Healthcare Cybersecurity Market by 2024
118%
Increase in Ransomware attacks during the first quarter of 2019
10.5%
Annual Increase in Data Breach Cost Increasing Skill and Resource Gap Increasing Volume and Cost of Attacks Exponential Risk Immature Cybersecurity Adoption in Healthcare
5
Proven client growth strategy through trusted advisor relationships Potential to leverage engagement insights to be positioned for future
Codified best practices and deep reservoir of experience drives efficiencies of engagements Teams led by nationally recognized experts in their field Unique Combination of Cybersecurity, Privacy, and Compliance knowledge with Healthcare and Regulated industry experience
CynergisTek brings expertise that is both Cybersecurity & Compliance specific to healthcare & other regulated industries
6
Managed Services, 56% Professional and Consulting, 44%
COMPLETE SERVICE OFFERING Vendor Security Management Medical Device Security Management Patient Privacy Monitoring Service Risk Assessments Services
Managed Services Professional & Consulting Services
Red/Purple Teaming Ransomware Assessment Cloud Security Assessment GDPR/Data Privacy Compliance Security Control Validation EPCS Services IT Audit Services Endpoint Security 20+ Others Incident Response Readiness Exercise
7
Compliance Assist Partner Program
Annual Assessments ▪ Annual Review to identify security gaps through several assessments & analyses Internal and External Assessment ▪ External: Quarterly ▪ Internal: Bi-Annually
Patient Privacy Monitoring Medical Device Security
Experienced professionals review documents, processes, and procedures impacting research, and identify possible gaps against HIPAA requirements ▪ Annual review to identify security gaps through several assessments & analyses ▪ Regularly review user activity within designated ePHI applications Medical Device Security Technical Assessment ▪ Comprehensive inventory of networked devices and associated vulnerabilities Medical Device Security Assessment ▪ Evaluation of security controls & an identification of gaps or vulnerabilities Medical Device Security Management Strategy ▪ Strategy articulating different risk categories and remediation roadmap
Vendor Security Management Managed Security Services*
Evaluate and monitor vendors on a regular and ongoing basis ▪ Comprehensive assessments ▪ Status Updates on vendor participation and escalation of issues ▪ Quarterly Program Report covering high- level of the vendor program, including recommendations Complete security monitoring solution and strategic security partnership ▪ Cloud, Endpoint, SaaS, and Network ▪ 24x7 detection and response with trained cyber experts ▪ Assessment and remediation support
*Currently serviced via referral
8 Electronic Prescription and Control Substances Audits
Assess an organization’s cyber resilience to identify if the security controls in place are effective and working. This service identifies gaps or oversights in security technology and process. Validating your security investment, if your organization has outsourced part
Emphasis on the simulation of attacks that happen every day in corporate
variety of tools and comprehensive manual analysis. Followed by precise targeted attacks against the services identified as potential vulnerabilities.
PROFESSIONAL & CONSULTING SERVICES SNAPSHOT*
Slide
Experts on-staff deliver high-end, high margin services to both large organizations and SMEs
Pen Test & Red/Purple Teaming Security Control Validation Ransomware Assessment Endpoint Security
Using predictive modeling, we identify and prevent threats – both known and unknown. Our team of security analysts then takes this threat data and creates actionable insights for your internal team. Certifies EPCS software vendor’s solutions, and ensures compliance
Data Privacy
Privacy Impact Assessments, GDPR Compliance Assessments, Social Median Governance, and
IT Audit Services
Third Party Risk Assessments, Medical Device Security, ERP Security, Security Architecture, Cloud Security
Cloud Security Assessments
* Not all services shown Helps organizations build strong security and response practices to better prepare for a ransomware-related incident. This includes a thorough review of existing controls and practices that provide protection against, reduce the spread of, and increase the speed to respond and recover from a ransomware attack. Determine the levels of cyber risk, potential loss, disruption, or exposure of your cloud-based assets to better understand your cyber risk posture; building a roadmap for risk reduction.
9
TRUSTED NATIONAL BUSINESS ACROSS DIVERSE INDUSTRIES**
*Covered entities are defined in the Health Insurance Portability and Accountability Act (HIPAA) rules as (1) health plans, (2) health care clearinghouses, and (3) health care providers who electronically transmit any health information in connection with transactions for which the department of Health and Human Services (HHS) has adopted standards. **Does not include addition of recent acquisition of Backbone Consultants
Health Care Information Technology Consumer Discretionary Financials Other
Current Client Mix by Industry
military experience
are remote covering 31 states
are women
10
RELATED COMPANIES Revenue* Healthcare Focus CynergisTek $21M Healthcare Deloitte $46B** None KPMG $29B* None HCI Group $160M* Healthcare EY $36B** None Secure Digital Solutions N/A None IBM $80B* None Atos $13B* Healthcare^ Impact Advisors $84M* Healthcare
*Estimated 2018 Revenues in US Dollars **Estimated 2019 Revenues in US Dollars ^Atos does not exclusively focus in healthcare, active in 21 industries KLAS Research is a healthcare IT data and insights company providing the industry with accurate, honest, and impartial research on the software and services used by providers and payers worldwide
Black Book Market Research 2019 CynergisTek Named Top Performer Cybersecurity Advisors and Consultants
11
12
Sophisticated & Faster Threat Attackers Rapidly Changing Business Model
healthcare come from the inside
ransomware attacks during the 1st half of 2019
their healthcare records breached last year
GDPR, CMS)
Consolidation
data sharing (cloud, APIs, etc.)
changed and Healthcare is a prime target
journey and not a destination
New Market Conditions
13
COMPANY TICKER NYSE: CTEK UNITS: USD Price (as of 8/14/2020) $1.62 FD Shares Outstanding* 10.6M Market Cap $17.2M LTM Revenue* $20.2M Cash* $5.4M Long- and Short-Term Debt* $4.4M**
*Data as of Q2 2020 and incudes 2020 negative impact from COVID-19. **Includes $2.8M PPP loan with majority expected to be forgiven
2018 2019 Q2 YTD 2019 Q2 YTD 2020
Managed Services Professional & Consulting Services
52% 39% 53% 61% $21.4M $10.8M $9.6M
Financial Highlights ($Millions) – Expanding New Revenue Lines to Focus on Growth
$21.3M
14 InvestorRelations@cynergistek.com cynergistek.com
NYSE AMERICA: CTEK