LastPass Has ‘Cleared A Lot Of Hurdles,’ Strong AI Growth Ahead: CEO Karim Toubba

In an interview with CRN, Toubba discusses LastPass’s security overhaul and strong customer retention—as well as its expanding AI opportunity following the addition of new capabilities to its Business Max offering.

LastPass is seeing numerous signs of increasing momentum—suggesting that it has taken the right steps in the wake of a pair of security incidents in 2022—and is positioned to build on its expansion beyond password management as customers and partners embrace AI, LastPass CEO Karim Toubba told CRN.

“On the B2B side, I think we've cleared a lot of hurdles in terms of the work that we've done, the investment that we've made and the re-architecture,” Toubba said in an interview.

[Related: ‘Generational’ Shifts In AI And Quantum Are Coming For Cybersecurity. Can The Channel Get Customers Ready In Time?]

The response to the incidents at LastPass entailed a “multi-year, multi-million-dollar investment” and resulted in a wide range of major improvements—going well beyond what was immediately necessary for security following the incidents, according to Toubba.

“Beyond all the security work that we did in people, process and technology—we went back and looked at all the experiences our customers had, and made a meaningful set of investments in the user experience, both for end users and administrators, on how to onboard them better and more fluidly,” he said.

Enhancements to boost engagement, meanwhile, have likewise “really driven up our gross renewal rates,” Toubba said.

“Our renewal rate, which is the lifeblood of any SaaS company, is now actually higher than it was prior to the incident—which is a big deal,” he said.

As another indicator, LastPass has also stopped even tracking instances where a deal was lost in connection with the security incidents, according to Toubba. “The volume is so far down that we don't even track it anymore,” he said.

At the same time, LastPass is capitalizing on its key position within businesses to help enable customers with pressing needs around securing the adoption and usage of AI, Toubba said.

LastPass announced Tuesday that it is expanding its Business Max offering, with newly added capabilities for monitoring and securing the use of AI tools and websites.

On the channel front, LastPass is looking to deepen key partnerships with solution and service providers while continuing to expand its MSP business, according to Toubba.

All in all, for LastPass looking ahead, “we are clearly in what we believe is a very strong position—because not only are we growing, but the fundamentals of our business as a SaaS business are really strong,” Toubba said.

What follows is more of CRN’s interview with Toubba.

Given the security incidents you had in 2022, what have been the biggest advantages that you’ve been able to leverage to remain competitive?

The two biggest advantages for us are the amalgamation of both the credential and authentication piece, coupled with the access layer of AI. Most of the people that are coming at the AI space are not coming at it through the credential and authentication mechanism. They're coming at it through ZTNA and the network or the EDR, XDR side. They either had an agent or footprint in the network, like the CASB vendors. The challenge with that is they don't have visibility into who the user is, which informs the policy. The other big strategic advantage is our footprint. We have 100,000 B2B customers with many users inside of each of them, plus consumers. That footprint means that I can go to somebody and provide them the value without installing any additional software. That's a huge advantage. I don't have to deploy an agent. I don't have to deploy a network. I don't have to deploy and agentic harness. As it relates to the cyber side, I was talking to somebody yesterday—they asked me, “Does the incident come up?” I would say now it comes up a very small percentage of the time, maybe single-digit percentage of when we talk to a prospect—because it's been quite a while, and obviously we've done a lot of things. It still periodically comes up. Do we have to work extra hard at it? On the B2B side, I think we've cleared a lot of hurdles in terms of the work that we've done, the investment that we've made and the re-architecture. We've been very vocal in many forums about the work that we've done.

How often do prospective customers still raise the incident?

I’d be lying if I told you we still don't get questions about it. But the volume is so far down that we don't even track it anymore. We used to track how many questions [we’d] get on security after the incident—how often is the deal lost due to the security incident. That was a legitimate thing in ’22 and ’23, even in ’24. But [it’s not anymore] in ’25 and ’26.

Have business customers responded differently from consumers?

I would tell you, we saw a little difference in the B2C versus B2B side. The B2C seems to have a longer memory and [is] more vocal, especially because they're oftentimes sitting behind keyboards on things like Reddit. The B2B side, I don't know if it's more forgiving. It's just more aware—because they use so many different vendors that have so many different issues. And they, I think, judge you less by the incident and more by the response. And so we took the time—and it took a while—to explain to the market the work that we've done. When you have a crisis—which this was, no doubt about it—you ask yourself, OK, what's my goal? Am I trying to spin this, or am I going to use this as a forcing function for change? We obviously did the latter. We did a multi-year, multi-million-dollar investment. I often tell customers, it's easier for me to explain what changed than what didn’t. And I think once you get that out there, you get the benefit of that in that regard.

What are the biggest ways you have expanded your offerings at LastPass?

The company historically was primarily password management, and we started to build a bunch of capabilities. We've expanded quite a bit beyond password management. About a year ago, we broadened the platform to effectively build full visibility. We realized that that footprint is really valuable real estate. We've got millions of consumers and over 100,000 B2B companies. And so we've got this big footprint. It turns out that the extension sees all the flow mapped to the user, but also the application. So we built a full SaaS visibility and control platform as part of the deployment without any new software—because we already had the real estate of the footprint. And so, a lot of that was really about getting that into the hands of businesses—of which we have, I think, close to 7,000 customers who are now using that capability. We're still early days of penetration, but it's propelling the growth for us. And then we've got a bunch of things that we did in the AI space—largely because there's so much pressure on organizations to deploy AI. And visibility, control and governance seems to be an afterthought. As one of our customers so eloquently stated, the security team of “no” doesn't survive the AI era. It's just a totally different mindset.

What differentiates your approach to AI security?

There's a ton of investment happening in and around AI security and governance. And there seem to be two markets: AI security—how can I secure your AI deployment?—versus governance, which is, how can I provide visibility and align it maybe to some statutory mandates? This for us is kind of like the first foray [into a] convergence of the two—because you can control what people are doing, but provide visibility and then provide policy on top of that.

What's differentiated for us is, because we're in the browser, we do something technically called parsing the DOM. It's what allows 1Password to autofill your password. So we could see the user plus the AI utilization. And what that allows me to do is do things like say, a user can use Claude with their work email, but if they try to log in with their personal email account, they can’t—because their personal email has different policy controls. And the data that you upload with your personal Claude account will be shared with the model to train it. Whereas data, in our instance, when I log in with my LastPass Anthropic account—any data that I share is contained to us and is not shared with the broader model. That's just one of several examples that allow us to marry the access of AI coupled with the credentials, which we already manage anyway for companies.

What are your top channel priorities?

Our larger B2B deals will go through our sellers or our channel partners. We, like most organizations, have multi-tiered. We have direct channel partners in North America, EMEA and in APAC, but also we go through distribution. We also have a really healthy and growing MSP business—because for what we do, oftentimes our capabilities are deployed through MSP. And then we'll go through distribution for MSP, like a Pax8. In terms of what we're looking to do moving forward from a channel perspective, I think particularly in North America, we're looking to go deeper with a smaller number of strategic partners. People like SHI would be an example. Obviously they're big—so being strategic to them means that you have to do quite a bit of revenue. There's multiple ones where we've been doing a fair bit of business, and we see a lot of growth [looking ahead] as well.

Overall, where do things stand for LastPass now that you have cleared a number of hurdles following the security incidents?

We are clearly in what we believe is a very strong position—because not only are we growing, but the fundamentals of our business as a SaaS business are really strong. We don't publish any of our numbers, but our renewal rate, which is the lifeblood of any SaaS company, is now actually higher than it was prior to the incident—which is a big deal. A big portion of that is because of two reasons. No. 1, beyond all the security work that we did in people, process and technology—we went back and looked at all the experiences our customers had, and made a meaningful set of investments in the user experience, both for end users and administrators, on how to onboard them better and more fluidly. The other thing that we did is we're big users of data—meaning that we know what customers are doing in the application itself, and how to send them timely messages based on their utilization of the application, so that it increases engagement and adds more value for you as a user—whether you're a consumer or whether you're a business user. That's been really important, because engagement has really driven up our gross renewal rates and allowed us to get to near best-in-class renewal numbers, which didn't exist before.