The Penny Share Letter #031 February 2018

Originally published under Growth Stock Network on 2nd February 2018.

Click here to download this issue as a PDF

There’s a cyber security boom, and these salesmen are cashing in 

Sean Keyes

The internet security company Symantec was the first to identify the group in 2008.

Symantec labelled them Advanced Persistent Threat 29, or ATP29. In time they would pick up other names: Office Monkeys, The Dukes, CozyDuke. Now though, they’re best known as Cozy Bear.

Their M.O. is to go after big targets by compromising ordinary employees. In this way Cozy Bear has hacked governments, militaries, embassies, telecoms and energy companies.

They’re particularly keen on attacking adversaries of the Russian government. Cozy Bear has gone after the militaries and governments of the United States, Uzbekistan and South Korea.

Now, everyone in the business knew Cozy Bear were Russian. And everyone strongly suspected they were part of the Putin regime. But nobody was able to confirm exactly how close they were to Putin. American, Israeli, and British intelligence agencies had been on their case for years without much luck.

Then one day in 2015, America’s FBI got an unexpected phone call from the Dutch.

The Dutch security service, which is called the AIVD, had hacked the network of a university building near Red Square in Moscow in 2014. They were poking around, not sure what they might find. The hack gave them access to everything in the building from outgoing traffic to security cameras.

One year later, the AIVD noticed some strange goings-on at their Moscow University building. None other than the Cosy Bear crew had set up shop.

The AIVD could see everything. They could see who Cozy Bear was attacking, who they were planning to attack and how they were planning to do it. Through security cameras, they could see the faces of the hackers, and the faces of Russian intelligence officers who were working alongside them.

With the AIVD, the NSA and FBI watching, Cozy Bear tried to hack the US State Department, the White House, and then the Democratic National Committee.

By hacking the Hilary Clinton campaign’s emails, later released via Wikileaks (with a little help from the Trump campaign, perhaps), the Cozy Bear hackers changed history. But that’s another story.

Last year I was following the Russia hacking story like everybody else. But it took a letter in the post last July to get me to take internet security seriously. The letter came from a financial institution I’d had dealings with in the past.

It went something along the lines of “We lost your data. Hackers stole it. Sorry.”

The letter told me to change all my passwords immediately, check my bank accounts, and consider freezing my credit cards.

Turns out a couple of my friends got similar letters over the past year. Each of our details were lost by a different incompetent company.

I used to think internet security was for people like Hillary Clinton or Lloyd Blankfein. The types of people Cozy Bear went after.

It took the letter to get it through my thick skull that cyber crime isn’t something that just happens to Hillary Clinton. It’s something I need to take control of.

I’ve lived online for twenty years now. In that whole time, I hardly bothered changing my passwords. I didn’t use two-factor authentication. I figured even if I were to be hacked, I didn’t have a whole lot of useful information online anyway.

But that has gradually changed. Now, everything about me is online. With a few passwords, hackers could easily steal my identity and rob me blind.

It’s hard to get reliable data on how many people are hacked every year. The police don’t gather data in a joined-up way, and lots of people don’t report cybercrime anyway. But if me and a bunch of my close friends have been hacked, it has to be everywhere.

The best information I can find comes from a study last year by Accenture, a consultancy. Accenture found that a) cybercrime is a huge problem and b) it’s growing very, very quickly. It found that the costs of cyber crime went up by more than 22% in 2017. Of the 254 companies it studied, internet security and crime cost an average of £8.3m.

Those numbers are a guess at what’s going on in the cyber security market. Whether or not these numbers are perfectly accurate, the trend is clear. It’s gone from being a “big company” problem to an “every company” problem, to an “every person” problem.

An “every person problem” is just another way of saying “a huge market”. Ordinary people are starting to protect themselves properly online. There’s big money to be made here.

In 2016, this month’s recommendation made a huge bet on the consumer internet security market. Their bet is about to pay off in a big way.

The pivot

Crossrider (AIM: CROS) started out life as an online marketing system. Companies which wanted to sell online would go to Crossrider; it would sell the products on their behalf. Crossrider was good at finding potential customers, then converting them into a sale, then cross selling them to other products.

This “sales funnel” is the way companies sell things to retail customers these days. It’s a big talent in itself, and potentially very lucrative. Companies need to know where to place their online ads, how much to pay for them, how to convert ad clicks into sales, and how to increase sales to existing customers.

Crossrider has built every part of its sales funnel (apart from payments, which is highly regulated). This has allowed it to optimise the hell out of the sales process through constant testing, tweaking and improvement. It’s also good at what digital marketers call organic sales – its website gets tonnes of traffic from the likes of Google. The website for one of its products is the 230th ranked website globally, higher than ESPN, The Washington Post and Forbes.

By 2016 it was clear that Crossrider could sell stuff online. But it was missing a trick. If actually selling the product is the hard part, why was Crossrider only getting a small cut of the sale? The company realised it could make more money if it sold its own products, as opposed to those of other companies.

It came up with a strategy. It would focus on the most promising market it sold into – the one with a proven sales funnel and the greatest growth potential. Then it would buy in products it knew would sell. It would cut costs at its new acquisitions by leveraging its existing marketing resources. And finally it would cross sell customers onto other products in the same space.

The market Crossrider landed on was internet security. It knew from past experience that its sales model worked in this space. And it knew the overall market for internet security was growing quickly, because ordinary people were starting to put money into it.

Crossrider’s first acquisition was called Reimage. Reimage is a tool for disinfecting hacked and damaged computers. It keeps a database of “snapshots” of Microsoft operating systems, then compares the user’s operating system to the snapshots. If there are differences they’re automatically spotted and repaired, so the user’s operating system is kept clean. The product is licensed by Microsoft.

Crossrider’s next acquisition was called DriverAgent. DriverAgent is a bit like Reimage – it scans a user’s computer to make sure all drivers are up to date, then fixes and replace the old ones. (What’s a driver? A driver is a little bit of software that allows your computer to communicate with other hardware, such as printers and scanners.) Crossrider bought DriverAgent because it knew it would sell. Crossrider had already more than doubled DriverAgent’s revenue and gross profit since it started selling it on its digital marketing platform.

Last year Crossrider made its biggest acquisition so far. It paid £8.2m for a German internet security business called Cyberghost. Cyberghost is a VPN (virtual private network) company. VPNs let people browse the web anonymously. Let’s say you don’t want advertising companies following you around online; or you don’t want to share your browsing history with the coffee shop whose wifi network you’re using; or your government blocks you from accessing news sites. A VPN solves all those problems.

Cyberghost was a good fit for Crossrider, and vice versa. Within five weeks of putting Crossrider’s sales funnel to work, Cyberghost saw a 30% improvement in sales.

The addressable market for VPN and internet security solutions is mind-boggling. A study found that 41% of Americans, for example, used a VPN. Another study found $16bn annually was lost to fraud.

It’s only this year that Crossrider has fully crossed over. It’s left its old business-to-business, online marketing business model behind. It’s now a proper business-to-consumer internet security business. And a successful one at that.

Investors love quality

CEOs like to talk about the quality of their earnings. What they mean by this is how predictable their company’s earnings are. This matters because investors love predictability. Predictable earnings are less risky, and investors are happy to pay more for them.

Now, there are two ways a software company can make money. It can either charge its customers a one-off licence fee to install the software, or it can charge an ongoing monthly service fee. This subscription model is known as “software as a service” (SaaS).

The SaaS model has proven to be much more lucrative than the old one-off-fee model. By asking customers to pay little and often, SaaS companies tend to make much more money in the long run. That’s because, provided the product is up to snuff, customers don’t often cancel their subscriptions.

Crossrider is in the middle of switching over to a subscription-based model. The Cyberghost acquisition helped with that: Cyberghost has used that model for years, and it showed Crossrider how to transition its existing products over to that model. In its latest trading update from January, Crossrider notes that recurring revenue is up 70% on the previous year.

I wrote about this business model recently in Microcap Millionaires, my top-tier newsletter which trades the smallest companies on the public markets. Recommending a microcap SaaS company, I cited the Harvard Business Review, which calls this “the best business model in the world”:

“If you can find a business that has highly repeatable revenues… and if you can keep your CAPEX to, say, less than 10%, then you probably have a winner… This is not necessarily a cheap investment but if you get it right, you create a defensible moat based on the IP created. From that point on, so long as on-going research and development and CAPEX can be managed, there is tremendous leverage in this model.”

In this respect Crossrider is like a couple of my biggest successes at The Penny Share Letter. Blue Prism (PRSM) and IMI Mobile (IMO) are in the same game. They sell an important IT service, then charge for it on a monthly recurring basis.

Microsoft’s former CEO Steve Ballmer – who’s generally thought of as a bit of an idiot – deserves credit for turning Microsoft into a subscription-revenue-based cash cow. He was very good at entangling Microsoft’s clients in long term deals, up selling and cross selling them onto other products, and generally making Microsoft totally indispensable to their IT infrastructure.

With a software as a service business there are a few things you’re looking for. You want to see a high level of recurring revenues as a proportion of overall revenues. You want to see high customer retention. You want to see high gross margins, which indicates that additional customers contribute strongly to the bottom line.

The beauty of a company like this is that profits ratchet up over time as revenue from new customers is added to revenue from existing customers. Gross margins are high because software is cheap to roll out.

As Crossrider’s CEO Ido Erlichman is keen to point out, the subscription model will mean more recurring revenue, which will mean predictable high-quality earnings, which will mean a higher rating, which will mean more money in investors’ pockets.

The risks

You can look at Crossrider two ways. One is as a consumer internet security company; the other is as a digital marketer. Without the marketing expertise the internet security products don’t sell; without the internet security products there’s nothing to sell.

There are risks on both sides. First, the sales channel. Digital marketing and adtech is a tough business. All things being equal, digital marketing companies fetch a lower multiple than other businesses because investors don’t trust that their business is sustainable. The fear is that a change in technology or customer shopping habits could wipe out the adtech company’s business overnight.

How can Crossrider quieten those doubts? If its next few results show earnings growing at a stable predictable rate, markets should lighten up on Crossrider and give it a higher multiple. The shift from licensing to SaaS will help in that regard.

Then there are the risks around the internet security market. I think it’s a safe bet that internet security spending will go up and up over the next few years. But what about Crossrider’s specific products? Reimage and DriverAgent are focused on the Windows PC market. Windows PC might not be the centre of people’s technological lives the way they used to be, but they’re still everywhere. They still sell in the hundreds of millions every year. For a tiny company like Crossrider, there’s still an unimaginably huge addressable market to sell into.

Crossrider has £69m of cash at hand. It’s planning on another acquisition – something in the high growth cyber security area, something to expand its user base. This could be great: another acquisition like Cyberghost is exactly what Crossrider needs. But growth-through-acquisition can be risky. When you zoom out and look at all mergers and acquisitions deals, on average, they tend to destroy value. So Crossrider is swimming upstream to an extent.

Having said all that… Crossrider is the right kind of business for this strategy. It has a proven sales channel. It knows what kind of products it can sell. So it just needs to acquire the right products at the right price.

The final risk is the familiar one over forex. Crossrider makes 94% of its money overseas, with about two thirds coming from the USA and Europe. That means it’s vulnerable if the pound strengthens because a stronger pound means overseas earnings aren’t worth as much. By now you know how this might come about – a softer Brexit would do the trick.

The triggers

So Crossrider is a small, stable business. It’s generating £1.9m in free cash every year, which is 90% of EBITDA. It has £69m on its balance sheet. And it’s been consistently generating cash for years.

That’s a good start. But what’s going to send Crossrider higher from here? The first place to start is, as I’ve mentioned, earnings quality.

If Crossrider moves more customers to an SaaS model, that’ll make earnings more predictable, which in turn could lead to a re-rating.

The next is acquisitions. Crossrider’s sales funnel will kick into a higher gear if it has a suite of complementary products to offer customers. That way it can cross-sell and up-sell more effectively. This is the Keywords Studios strategy.

The next is organic growth. The company has R&D labs in Israel and in Germany. They’re developing a comprehensive security system, which will build on the strengths of Crossrider’s existing products. And they’re continually moving more customers onto the SaaS model, which will grow earnings.

The bottom line

Between the surging internet security business, the digital marketing platform, and the switch to a subscription model, Crossrider is just surging ahead.

Revenue is growing at a healthy 20% per year. Last year, the company lost 3.5m in EBITDA; next year it’s forecast to make close to £5m. And as I’ve said, 90% of that comes through as free cash.

My bet is this: Crossrider spends its £69m wisely, and acquires more customers. It gradually transfers more of its existing customers to a subscription model.

It cross-sells existing customers to its new products, bringing up average revenue per user.

And when the market gets wind of what’s going on in this formerly-unpredictable adtech business, it gets a re-rating. BUY Crossrider at 73p.

New Recommendation – BUY Crossrider PLC 

Ticker: CROS 

Price (31.01.2018): 73.00p

52 week low/high: 45.00/86.40p

Market Cap: £103.50M GBP

Performance Data: Full 5 year data is not available 2015 -49.55% | 2016 -38.74% | 2017 +92.65% | 2018 +11.45%

Don’t look down: how to invest at market highs

Sean Keyes

Looking at your portfolio of penny shares, you might be feeling pretty pleased with yourself.

The PSL portfolio has more than doubled in two years. Aim is up 22% in a year. The FTSE is at all time highs. Around the world, markets are humming.

God is in his heaven, and all is right in the world…

But – I know – human psychology doesn’t work like that. We’re skittish, nervous creatures. Contentment doesn’t come easily.

Even when you’ve made all the right moves – careful research, bold and decisive action, patience – you probably find it hard to credit yourself and enjoy the moment. If you’re anything like me you find it hard to savour your successes.

You might hear an insistent voice from deep in your brain:

This can’t last… 

What if it all crashed tomorrow?

Get out while you still can!

There’s no getting away from it. On any given day the market could crash like a stone. You could wake up much poorer tomorrow.

Of course I worry about it, and I know you do too because I get emails about it all the time. Take this one from last Thursday, from Zana J:

I would really appreciate hearing your views on the widely anticipated market crash that is being discussed in the specialist financial media and to what extent the Penny Share portfolio would be affected by such a crash? I hope to hear your thoughts.

Today I want to answer Zana’s question. I want to tell you what you need to know about market crashes, and what you should do about it.

Fear is not your friend

Fear is one of the two fundamental emotions that drives our investing decisions.

(The other? Greed, of course.)

Fear has a seat at the table for every investing decision you make. And it’s not shy of letting its voice be heard.

There was probably a time when fear was a great man to have at the table. It would’ve kept you safe from rats, serpents, tigers and the like.

But for a modern person trying to decide how to allocate capital, fear is not helpful. More often than not fear talks you into making bad decisions.

In fact, a study from Geoffrey Friesen and Travis Sapp showed that fear costs the average investor a third of their wealth. A third!

A third of an ordinary person’s wealth might be several hundred thousand pounds. How many years of work goes into accumulating a couple of hundred grand?

Fear costs people all that money by spooking them into making poor decisions.

The study looked at the difference between the amount an average investor actually realises from investments in index funds (i.e. the overall market), and the actual performance of index funds. It turned out the average investor makes a third less than the index itself.

What’s going on? What happens is that, when markets are riding high, investors tend to get spooked and sell their stocks. They think record-high markets mean a crash must be coming soon.

The problem with selling your stocks in the hope of buying them back more cheaply is that it’s very difficult to buy them back more cheaply. If the market rises, you won’t want to get back in because you’ll be guaranteed a loss. And if the market keeps falling you won’t want to get back in because, well, the market is falling.

That’s how fear makes you poorer. It makes you afraid of ghosts. Fear of losing money causes people to buy high and sell low.

Psychologists wouldn’t be surprised by this. They call it “loss aversion” – the tendency of people to hate losing much more than they like winning.

It’s much easier to visualise – and care about – money you have in your account right now, as opposed to notional extra money you might have in the future. So you sell, and miss out on gains coming down the track.

Know your stuff

So there’s a part of our brain that’s reflexively scared of risk. It wants to protect what you have at any cost. And that instinct ends up costing you money.

How do you stop that from happening?

You stop it from happening by knowing your stuff. If you properly understand why it’s not smart to sell, you’ll be less inclined to do so in a stressful moment.

The basic reason why it’s not smart to sell your stocks is that markets go up far more than they do go down.

Markets don’t swing from boom to bust like a wave. They go up most years, punctuated by the odd bad year.

Since 1947, the S&P 500 rose in 80% of calendar years. And it rose by an average of 202% in every ten year period.

If you sell all your stocks during a crisis, there’s no way of knowing whether things are about to get worse or about to get better. That’s unknowable. The only thing you can know for certain is that stocks tend to go up over time. By taking your money out of the stock market, you don’t get to benefit from that.

Okay, you might say, but what about times like now when the market is at an all-time high?

The thing about all-time highs is, they’re not a very good indicator of an impending crash. In fact, all-time highs are quite a good sign that the market is going to keep rising. In the 1980s, the S&P500 hit 162 all-time highs; in the 1990s it hit 312; in the 2000s it hit 60; and in the 2010s it’s hit 123.

All of which is not to say that bear markets don’t matter. A severe bear market might knock one-third off share prices. So if you’re going to need to cash in your stocks soon to pay for retirement, education or whatever, it makes sense to reduce your overall exposure to stocks. When you’re sure you’ll need the cash soon, it’s better to play it safe.

If you’re not in that position, the best thing you can do is conquer your fear. Sit tight. And trust the long term trend.

“How much should I invest in each stock?”

Sean Keyes

I’d like to talk about a topic I hear about a lot in subscribers’ emails.

Subscribers ask how much they should allocate to each stock; or how many stocks they should own; or how to keep down dealing costs in their portfolio.

There’s one big answer to all three of those questions…

Risk vs. Costs 

When you’re deciding how to build your portfolio of penny shares, you have three goals.

The first is to return as much as possible. That one is obvious. Second, you want to minimise your risk, so that the overall value of your investments stays fairly steady and doesn’t give you heartburn. And third, you want to keep dealing costs and tax burden low.

The problem is that the last two of those goals are in tension.

It can be hard to keep dealing costs low and minimise risk at the same time (I’ve explained in a footnote precisely what the word risk means in this context).

The lower your risk the higher your dealing costs are going to be. And vice versa.

Why is that? It’s because stockbrokers charge a flat fee per transaction, among other fees. So the fewer transactions you make, the lower your dealing costs are going to be.

For example, if a broker charges £10 per trade and you decide to divide your £3000 pot into 20 shares, your dealing costs are going to be 20*10= £200. But if you put the whole £3000 into just two shares, your dealing costs will be £20.

£200 adds up to 6.66% of you the value of your portfolio, on top of spreads and whatever else you have to pay. So you’ll have to make 5-10% on your investments just to stand still. All things being equal you’ll want fewer transactions to keep costs low.

On the other hand, you can make your portfolio less risky by spreading your money across more positions. If you put your £3000 into two shares, you’re at their mercy. A bit of bad luck could seriously hurt you.

Better to spread your money into a number of shares. On average your returns won’t suffer. But you’ll have less heartburn because the overall value of your portfolio will be more stable. All things being equal, you’ll want more shares to reduce your risk.

So that’s the tension. Fewer transactions for lower costs; more shares for less risk.

So the question is, how diverse is diverse enough? The answer, basically, is 10. A portfolio of 10 shares are much less risky than a portfolio of two shares, and only a tiny bit more risky than a portfolio of say 100 shares. Around 10 is the sweet spot.

What about dealing costs? For small caps, you’d like your overall dealing costs to be 2% or less. That’s a reasonable amount to pay.

So there you have it. If you have a large amount of money to invest in small caps, buy the 10 shares you’re most excited about. And don’t pay more than 2% in fees.

If you’re just starting out with a small amount to invest, I would recommend you prioritise keeping dealing costs low. Maybe you could start out with only one or two positions and then gradually build up your portfolio over time by adding new positions. That way your dealing costs will be low, and your risk will gradually decrease.

P.S. What I mean by risk.

In this context risk means “the propensity of your portfolio to move about in value”. All things being equal, you want less risk. The more risky your portfolio is, the less sure you can be of its value in the future.

Risk has three elements:

  • How many shares you own (the more shares you own, the less risk)
  • How much they swing around (junior gold miners swing around more than British Gas)
  • The extent to which they all tend to move in the same direction at the same time (a bucket of companies in different industries is less risky than a bucket of bank stocks, for example).

All this multiplies up to something called the standard deviation of your portfolio. Standard deviation is “the risk number”. The lower the standard deviation, the better.

Assume you have one share and it has a standard deviation of 25. If you add another share – in a different sector – the standard deviation of your two-share portfolio falls to 20.2. With five shares the standard deviation is down to 16.6 and by the time you have ten the standard deviation of your portfolio falls to 15.2.

The thing is, if you have 100 shares the standard deviation falls to only 13.9 and even if you have 200 shares the figure is still 13.8.

You need not understand exactly what is meant by standard deviation. The crucial message is that after a certain point you can go on adding new shares to your portfolio, but they will make practically no difference to its ‘risk’ – in other words the extent to which it is likely to fluctuate in value from one day to the next.

You do not need to have a huge long list of shares. Just make sure that they are a good mixture, and not all for instance gold mines or house builders. Ten shares will do it. Have a few more if you really want to, but try and work with an upper limit of 20 or so. Buying a whole lot more is going to achieve nothing, except a lot of extra work and dealing costs.

 

Show Sitemap
  • Save
  • Print
  • '); mywindow.document.write(data); mywindow.document.write(''); mywindow.document.close(); // necessary for IE >= 10 var mediaQueryList = mywindow.matchMedia('print'); mediaQueryList.addEventListener('change', function(mql) { if (!mql.matches) { mywindow.close() } }); mywindow.onload = function() { // wait until all resources loaded mywindow.focus(); // necessary for IE >= 10 mywindow.print(); // change window to mywindow }; return true; }