325 | Breaking Analysis | CrowdStrike’s Post-Mythos Surge: Moat, Momentum and the Blast-Radius Test
Watch on YouTubeVideo summary
CrowdStrike's recent financial performance demonstrates a dramatic shift in how artificial intelligence security is perceived within the enterprise, transforming it from a future concern into an immediate necessity driven by events like the Mythos incident. This urgency has directly fueled record-breaking growth, with the company delivering $333 million in net new Annual Recurring Revenue (ARR) and accelerating its trajectory toward a $10 billion ARR target originally set for 2031. The data reveals that while specific products like Falcon Flex and AI detection modules contribute significantly, the broader platform is successfully converting this heightened demand into sustained momentum across diverse business units, including cloud security, identity management, and next-generation SIEM, effectively proving that CrowdStrike is evolving from a simple endpoint vendor into a comprehensive 33-module security ecosystem.
The core of CrowdStrike's competitive advantage lies in its unique closed-loop system, which integrates a lightweight agent with proprietary threat intelligence, an enterprise graph, and advanced reasoning capabilities to create a moat that is difficult for competitors to replicate. Unlike standalone AI models or generic SaaS offerings, CrowdStrike leverages decades of accumulated attack and mitigation data specific to its installed base, allowing its agents to operate with superior context and accuracy. This system not only enhances detection and response but also drives operational efficiency by consolidating multiple security tools into a single agent, thereby reducing complexity and improving unit economics for customers who value simplicity and faster deployment over fragmented toolsets.
However, this consolidation and expansion of AI authority introduce a critical challenge known as the "blast radius" test, which defines the new frontier of operational, technical, and financial sovereignty in the AI era. As the platform manages more automated actions across endpoints, clouds, and identities, the potential impact of a single error, bad policy, or compromised agent increases significantly, requiring robust controls for independent rollback and failure isolation. While microsegmentation helps contain lateral movement, it cannot fully mitigate risks arising from privileged updates or trusted automated actions gone wrong, making it essential for customers to retain ultimate control over their security estate rather than relying solely on vendor authority.
Ultimately, the analysis concludes that while CrowdStrike's momentum is undeniable and its financial health is robust, the company must now prove the durability of its platform under the scrutiny of autonomous AI agents. The upcoming Falcon conference will be pivotal in addressing questions regarding the absolute ARR numbers for new modules, the specifics of blast radius containment strategies, and whether the growth driven by post-Mythos fear is sustainable beyond initial market reactions. As CrowdStrike continues to expand its ecosystem and leverage recent acquisitions, the focus shifts from mere platform adoption to ensuring that customers maintain sovereignty over their security operations, balancing the immense benefits of consolidation with the rigorous need for explainable, controllable, and reversible AI actions.
Read the full video transcript
This is Breaking Analysis with Dave
Vellante.
>> CrowdStrike's most recent earnings print
shows that Mythos transformed AI
security from something CISOs needed to
worry about sometime down the road into
an immediate buying event.
CrowdStrike's entrenched position in
endpoint, along with its single
lightweight agent, proprietary
intelligence, and a rapidly expanding
portfolio of modules have converted
Mythos urgency into record new logo
momentum, record new ARR, and what we
see is likely a compressed time frame to
hit $10 billion in annual recurring
revenue. That's a target that
CrowdStrike set for fiscal year 2031 at
last year's Investor Day.
Falcon Flex is one of the key mechanisms
driving commercial adoption, but buyer
research from Qualitait shows that
customers value lower complexity, faster
deployment, and improved unit economics
more than just the contracting vehicle
itself. The one caution we put forth for
CrowdStrike customers is that while
every step in your consolidation journey
gives Falcon more context and better
data, it also gives it more AI
authority, which raises the importance
of resilience and controlling the AI to
contain the potential risks of an
expanded blast radius.
Nonetheless, the numbers from
CrowdStrike's quarter speak for
themselves. Mythos and other models are
proving to be a significant tailwind for
CrowdStrike. Welcome to episode 325 of
Breaking Analysis. We've titled it
CrowdStrike's post-Mythos surge, moat,
momentum, and the blast radius test. And
in this Breaking Analysis, we'll dig
into how CrowdStrike and Falcon are
converting AI urgency into platform
expansion. We'll introduce data from a
new data intelligence firm named
Qualitait, which has conducted many
thousands of buyer surveys on
CrowdStrike and other firms, will also
discuss why containing the new blast
radius is a key to operational,
technical, and financial sovereignty in
this AI era.
All right, let's start with what changed
between CrowdStrike's Q1 and their Q2.
In the first quarter, MITRE
wreaked havoc on SecOps teams and
quickly became agenda items at board
meetings.
The questions came at a furious pace.
What does this thing mean? How exposed
are we? What do we do about it? How do
we protect ourselves now? And as the
MITRE created all this chaos, in a Q2,
this chaos turned into cash for
CrowdStrike.
The company delivered $333 million in
net new ARR, up 51% year-over-year, and
more than 45 million above the high end
of its guidance.
Ending ARR
reached 5.84 billion, with growth
accelerating for the fourth consecutive
quarter.
New logo net new ARR hit a record. Gross
retention improved, net dollar retention
improved, and management raised its
full-year net new ARR growth outlook by
630
basis points to 34%
to the midpoint of its guide.
Yes, this was a beat and raise, but the
real news is the trajectory of the
business changed, and the stock
responded. It was up over 20%
at the close on Thursday afternoon.
Independent buyer evidence from
Qualitate supports this take. Now,
first, let me introduce you to
Qualitate. Qualitate is an AI-native
primary data intelligence platform that
automates expert interviews and market
research for investors and corporate
strategy professionals. The company has
built the world's most intelligent AI
moderator to capture expert insights at
massive scale across virtually any
industry including of course enterprise
tech which caught our interest. The firm
was founded by Sagar Kadakia who was the
head of data science and one of the
founding employees at ETR. Qualitate is
bringing non-obvious proprietary
intelligence to its clients and I am
thrilled to be sharing some of their
data with you today.
Here's just one example on this graphic.
First, CrowdStrike is very prominently
mentioned in Mythos-related conversation
within Qualitate's get this 1,249
CrowdStrike in-depth customer
conversations.
One deputy group CISO said
the organization went from some somewhat
limited concern about all this to much
greater urgency cited
right here as we show, we need to do
this. And let me actually read the the
quote from the Qualitate data.
He says, "Our strategy really changed
from what we didn't We didn't really
care about that much to we need this
because of Mythos and AI capabilities
that we expect to accelerate and
outperform any kind of vulnerability
numbers that we've ever seen before."
This is a deputy CISO at a large
financial services enterprise.
Qualitate also saw fewer buying
decisions go against CrowdStrike in its
July and August data so trending up.
Now, we're not saying that Mythos
generated every dollar of that 333
million. Falcon Flex, endpoint recovery,
SIM, what
CrowdStrike calls next-gen SIM, cloud
security, identity, exposure management
and large competitive displacements all
contributed.
What we can say is we believe the
post-Mythos demand environment was an
inflection point and it accelerated
broader platform momentum that
CrowdStrike already had in place.
The most obvious post-Mythos evidence is
CrowdStrike's $5.84 billion ARR, which
increased 25% year-on-year. So, our
belief is that Mythos heightened the
urgency, but the breadth of the Falcon
platform gave CrowdStrike multiple ways
to monetize it.
We can't pin it to any one product or
module, however. Now, Qualitate tells us
that it's seeing a major uptick in
CrowdStrike discussions mentioning AI
detection and response, AIDR, relative
to its last study. But in this next
section, we're going to try to show you
why this is not just an AIDR story.
Specifically, the data from Qualitate
highlights an important nuance that's
relevant to our findings today.
Most of Qualitate's Mythos-related buyer
comments show up in application
security. But that doesn't mean
CrowdStrike is missing from app security
or exposure management. It tells us
where the concern actually enters the
buyer journey.
Buyers want to know,
"Where are we exposed? And can an
adversary exploit those weaknesses
faster than we can patch them?" Now, the
term Patch Tuesday, you might have heard
of this, this came from firms like
Microsoft releasing patches and fixes on
the second Tuesday of the month.
The not-so-funny joke was that past
Patch Tuesday means Breach Wednesday,
implying that the hackers would pounce
before the updates were in place. Well,
the window is no longer 24 hours. In
fact, the idea of patch window
completely changes in the agentic era
from "How long do I have to implement
the fix?" to "You're now in continuous
patch deployment." where the window
becomes a series of, let's call them,
micro windows for individual services,
you essentially patching without human
intervention.
But there needs to be a window in time
in case something goes awry, and you got
to roll back. In this graphic, you can
see the momentum across several of
CrowdStrike's businesses.
Let's call out exposure management
specifically because it is now front and
center.
CrowdStrike participates directly with
Falcon exposure management, which
accelerated sequentially in Q2.
Project Quilt Works was launched by
CrowdStrike in April of this year. It's
an industry-wide coalition to help
organizations find, prioritize, and fix
software vulnerabilities
discovered by AI AI models.
Quilt Works extends CrowdStrike sales
motions across an ecosystem using Falcon
and Frontier models to discover, to
prioritize, and to remediate
vulnerabilities. And CrowdStrike says
the initiative now includes more than 25
partners with nearly 400 million in
total contract value pipeline.
But the commercial opportunity doesn't
stop there.
Look at endpoint ARR accelerated for a
fourth consecutive quarter, and this is
important because endpoint is
increasingly where agentic work is
consumed. And you know, and runtime is
the most obvious place to stop the
breach.
AIDR is an incremental module on the
same Falcon agent, and its its ending
ARR nearly tripled sequentially. And we
don't know exactly what that number is,
we'll come back to that, but uh
CrowdStrike's sharing, you know, growth
rates, not absolute ARR numbers.
So but the customer doesn't have to
deploy another sensor or create another
data silo to add AI visibility and
response. So this was key in
post-mythos.
And then the momentum continues across
the platform. Look at next-gen SIEM, it
passed 695 million in ARR. Identity
exceeded 585 million. Falcon Shield was
up more than 185% Privilege Account
Security grew more than 35-fold year
over year.
These are importantly indicators around
the rise of non-human identities.
Look at cloud security, it exceeded 905
million in ARR.
Collectively, SIM, identity, and cloud
produce record Q2 net new ARR. So, the
fact that Mythos often enters through
app sec is not necessarily a problem for
CrowdStrike. It's a top of a funnel
indicator that leads to sales of other
modules.
Mythos may have opened the door for
exposure management. However,
CrowdStrike is monetizing risk
mitigation across the entire Falcon
platform. And that breadth underscores
that CrowdStrike should not be viewed as
an endpoint company
with with a bunch of collection of
add-ons.
The headline on this slide deliberately
states the obvious. CrowdStrike
CrowdStrike is no longer an endpoint
company.
For quite some time, we've said
CrowdStrike's history and endpoint
remains a powerful anchor, but there's
much more to the story.
CrowdStrike now presents Falcon as a
33-module platform built around a single
lightweight sensor that spans
10 control points: endpoint, cloud,
identity, SIM, threat intelligence, data
protection, exposure management, and the
data pipeline
at AI security and browser security.
Now, the financials tell the story, and
it's very impressive.
Cloud security, as we said, passed 905
million of ARR. Next-gen SIM, 695.
Next-gen identity, uh
585
a million. And in and of themselves,
these could be pre-IPO companies if they
were stand-alone entities. They would be
ready for a IPO. Not quite, but on their
way.
Combined, these exceed 2.18 billion of
ARR and are growing above 39% year over
year. So, if you do some
back-of-the-napkin calculation, if you
just assume the minimum growth rates
here, that puts roughly 37%
of CrowdStrike's
total ARR.
So, Falcon may start with endpoint, but
a meaningful share of the business now
comes from other areas.
CrowdStrike's investor deck this quarter
says that 149 bill is is estimates a 149
billion dollar TAM in calendar 2026, and
they think that's going to rise to 325
billion by 2030. And regard regardless
of what you think about TAM figures,
there's no shortage of market here. The
more important point is that the company
has built
entries in many adjacent security
businesses.
This is also where blast radius comes
into play. It becomes more important cuz
consolidation can reduce tool sprawl and
complexity. That's wonderful,
but as endpoint, identity, and SIM, and
cloud, and posture, and AIDR
consolidate,
the risk domain grows.
Bad update, a a a bad policy, or an
overzealous agent can propagate across
more of the security estate. And that's
where sovereignty enters. Sovereignty
does not mean rejecting a strategic
platform or consolidation like Falcon.
It means retaining the operational and
technological control
to bind authority, override it if it's
necessary, and isolate failure and
recovery independently.
Now, the next section we're we're going
to dig into how CrowdStrike's land and
expand and consolidate engine
is working.
So, let's look at the mechanics behind
CrowdStrike's platform
expansion. So, at the top of this
graphic is, you know, the product. It's
evidence. I mean, look at it. Among
subscription customers, 51% now use six
or more Falcon modules, 35% use seven or
more, and 26% use eight or more.
That tells us that a big portion of the
install base is standardizing across
multiple security control points.
Falcon Flex is the lever that turns that
product breath into a repeatable
expansion
expansive sales motion.
CrowdStrike added more than 935 Flex
accounts in Q2, more than it added in
the prior three quarters combined.
Ending ARR from accounts that have
adopted Flex reached 2.29 billion.
That's up 101% year-over-year or
approximately 39% of CrowdStrike total
ARR.
And the expansion math is sick.
Flex new logo ARR contributed 34% of Q2
net new ARR. And customers moving from
standard subscriptions to Flex produced
more than a 40% average ending ARR
uptick.
Wow.
Their first reflex
added another 25% on average on top of
that from and from that new baseline.
And customers that have reflexed at
least twice were 53%
above their initial Flex starting point.
So, you see this flywheel that we're
showing here. CrowdStrike get get the
sensor in that activates modules
that moves into Flex. It reflexes as
their their needs expand and CrowdStrike
expands its capabilities.
And it gives Falcon more context, so
better data, more context can make
better decisions, higher quality, better
outcomes that reinforce the next
expansion.
But we need to read that 2.29 billion a
little bit carefully. It's It's It's ARR
from accounts that have adopted Flex.
It's not the same as committed Flex
capacity, modules already consumed or
ARR generated beyond the endpoint.
The conclusion is that Flex is
increasingly associated with
CrowdStrike's largest and fastest
expanding accounts. Not that every
dollar in those accounts was created by
Flex.
George Kurtz said, "Flex is the
commercial harness,
but to us, customer value is what
matters most. So, let's dig into that
next."
On the earnings call, CrowdStrike talked
about Falcon Flex constantly. By our
count, roughly 50 mentions.
The emphasis is, you can understand it,
Flex is fundamental to the go-to-market
motion associated with that two 2.2 time
2.29 billion of ARR and strong new logo
expansion
uh economics. But, what stood out in the
Qualtrics survey is interesting. Across
1,250 discussions with CrowdStrike
customers, only three proactively
mentioned Flex by name.
Buyers instead described the benefits of
Flex in very different language. They
talked about fewer tools, faster
deployment, lower complexity, and better
economics.
So, it doesn't mean
Flex is failing or CrowdStrike is
hyping. We believe it means that Flex is
working behind the scenes as a
commercial contracting mechanism, while
buyers experience the result
in the terms of simplification. As we're
showing here based on the Qualtrics
surveys, customers talk about one Falcon
agent supporting EDR,
data protection, AI, and identity. They
talk about turning on capabilities
without having another agent. And they
talk about consolidating point tools and
reducing investigation and operations
work, and improving both manpower
efficiency and unit price.
By the way, in speaking with the
Qualtrics data team, they're seeing
clear indications that CrowdStrike is
increasingly being viewed as more
cost-effective,
and it's likely that Flex is part of
that reason. In Qualtrics first half
research, CrowdStrike ranked ahead of
Palo Alto Networks, Wiz, and Zscaler on
economics.
Buyers cited built-in services, easy
activation, and lower logging ingestion
costs relative to products such as
Splunk and Google Chronicle as showing
here.
CrowdStrike ultimately made essentially
the same point on the call. At the end
of the day,
it is the platform sale, better
outcomes, and lower costs that really
matter.
And the stickiness is equally
impressive.
Of 217 CrowdStrike customers that
Qualitate polled since early July, not a
single one voiced an intent to churn.
Now, there is one caution we saw in the
data.
One satisfied Flex customer called the
recurring ACV escalation an OEM tax and
said, "Buyers still need continual
diligence so the platform can lower
total costs while
increasing CrowdStrike's commercial
average contract values." Let Let me
actually read this verbatim so you have
the context.
This person said, "The CrowdStrike
component of increased spending is the
OEM tax that happens every year where
the bill goes up.
It's built into our 3-year contract of
CrowdStrike
uh CrowdStrike Flex right now as well.
We're happy with them.
It's increasing. We like the Flex
package that CrowdStrike has, but as
part of your due diligence, you got to
be constantly reviewing what you've got
out there." So, he's saying it was makes
sense, right? It makes sure you're
getting value out of this if the
average contract values are going up.
So, that is a tension to watch, but the
key takeaway is this. Quote George
Kurtz,
"Flex is the commercial harness to
enable customer success in the agentic
era." To that, we would say, "Customer
success is measured in fewer tools, less
friction, and better unit economics.
While Street hears Flex. Customers are
buying simplification.
Now, again, this is sort of a dissonance
between how
CrowdStrike is communicating to Wall
Street and how how customers think about
the benefits of Flex
uh because they can certainly add more
another module a lot faster than they
can onboard,
you know, a new vendor. So, this is
where the language needs to be
translated. Now, the next slide, we're
going to show that customer value where
it comes from, which is a system-level
moat. It's not an LLM feature that a
competitor can easily copy. And we bring
that up because there was a lot of
kerfuffle in the in the business where
people were taking where investors were
grouping
uh SaaS companies, if you will, like
CrowdStrike with the SaaS-pocalypse. So,
let's get to where we believe
CrowdStrike's sustainable moat is.
It's not just Charlotte AI. It's not
just AI-DR. It's not any single module
or or a model. Those products, they're
very important. It's where the
innovation is.
CrowdStrike's a product company, but
features can be copied. The
harder-to-match asset is the closed-loop
system that we're showing here.
Falcon starts with a sensor that's
deployed. It's a lightweight agent. It
generates first-party telemetry. It's a
real-time data pipeline that combines
endpoint, identity, cloud, and even
third-party telemetry.
So, then you have an enterprise graph.
It I uh uh
CrowdStrike's been using graph
uh databases for a long, long time.
That adds asset, threat, and risk
context. CrowdStrike's threat
intelligence is world-class, and that
helps with prioritization.
You know, Charlotte AI, by the way,
which has received very high marks in
the Qualtrics surveys,
then you bring in agent works and AI-DR,
and they reason over that context. Then
you've got trusted and governed actions
that lead to outcomes, and those
outcomes feed the next decision. So, the
system is constantly learning and
updating itself. CrowdStrike describes
Charlotte as the reasoning engine across
Falcon and agent works as a way for
security agents to operate natively on
Falcon data.
This is why Frontier Labs don't
automatically commoditize Falcon like
the street was afraid of a while back.
Anthropic and Open Open AI or any other
model provider, they write great code
and they can improve reasoning and they
can perform threat analysis, but they
don't possess CrowdStrike's
installed endpoint estate or proprietary
attack and response data. They don't
have customer specific conste- context
and so forth. CrowdStrike claims it has
spent 15 years building threat, attack,
and mitigation data that is specifically
trained and labeled, and much of this
data is unavailable outside
CrowdStrike's walls.
Barclays Saket Chalia made a similar
point in his in that his analysis of the
quarter, i.e., that proprietary security
data is critical when thinking about the
potential risk
disruption risk, he means, from Frontier
Labs.
Now, a feedback loop is not
automatically a moat. It still must
demonstrate that broader telemetry
produces better detection,
less analyst fatigue, and faster
containment.
And as AI begins to act, the standard of
excellent, bar associated with that
standard, rises. Because actions have to
be explainable, they got to be
controlled, you got to be able to
observe them, and you got to undo them.
There's got to be an undo button if
necessary. Otherwise, the same agents
that create advantages become potential
liabilities. So, the model can
commoditize the deployed feedback system
and the trusted authority to act, those
are strategic assets.
And that leads directly to the paradox
that we're going to talk about in the
next section,
the architecture it cements the moat,
but it also expands the blast radius.
So, let's get to the crux of the
conundrum at the center of this breaking
analysis.
The same architecture that builds
Falcon's moat also creates three
distinct blast domains. First is the
update plane. Yes, the customer gets
fast protection throughout, but remember
that remember the 2024 uh patch update
incident showed
that that that the inverse that you had
a defective
content or software update designed to
protect can actually
propagate through a privileged estate.
And the tests that should be in place
are things like phase rollouts,
hold periods, version control, automatic
rollback. We learned a lot from that
incident.
Second is the platform plane. The
customers get shared telemetry and
consistent policy with consolidation.
Awesome, that's great. But, as endpoint
identity, SIM, cloud, posture, and AI
policy come together on a common set of
data and controls, one error can
propagate failure across all the
modules.
The test is whether services fail
independently and whether recovery
systems are available and whether they
work when something goes wrong
at the primary control plane.
The third is agentic action, that plane.
The benefit, of course, is you're going
at machine speed.
Um
that's the upside uh for the
containment, but lots can go wrong when
there are 100 x more agents than there
are humans. A security agent could be
compromised and go rogue, or bad policy
can cut across the system at machine
speed before you can react.
The controls that need to be in place
should focus on agentic identities,
approval processes, and independent kill
switch, and the like. We've seen more of
that out in the market and we hope to
see more. A CrowdStrike offers a
credible story for containing its
customers' AI agents. On the Q2 call,
George Kurtz described a non-human
identity control plane.
Data protection, runtime visibility,
exposure awareness, and visibility into
where agents are calling out and
guardrails around identity, data,
execution, and network connectivity.
Now, we heard much less about how
uh CrowdStrike contains a failure that
originates inside of Falcon itself. And
we hope to hear more about this at
Falcon next week. We would expect
CrowdStrike to have deeper answers, of
course, for customers than they would on
an earnings call.
Think of this as more research is
needed. This is not necessarily a
deficiency in in CrowdStrike's, uh you
know, portfolio or product features. We
don't know for sure yet, but it's a fair
question for a platform that's gaining
both context and authority.
Now, things like microsegmentation, we
hear about that a lot. They can help,
but it's not the complete answer because
microsegmentation, it contains
east-west, you know, movement. It does
not automatically stop a rogue or
privileged sensor update or a trusted
automated action that's gone bad. Those
can travel through the very channels
that the architecture is designed to
allow.
So, this is where blast radius also
becomes a sovereignty issue. It's not a
territorial sovereignty issue, but it's
operational, it's technological, and
potentially financial.
Operational sovereignty means binding
and interrupting authority if necessary.
Technological sovereignty means
retaining an independent recovery
process.
And then financial sovereignty means
avoiding an emergency re-platform on
someone else's timetable because
something went wrong or you drastically
exceeded your token budget.
So, the old question used to be, how
widely can a bad update propagate? The
new question
is, how widely can a trusted automated
decision act, and what happens if
something goes wrong. We believe
customers should absolutely take
advantage of the benefits of
consolidation, whether it's from
CrowdStrike and its partners or Palo
Alto or Microsoft, etc.
But they should also keep things simple
and practical. For example, as Falcon is
trusted to do more, buyers should ask
three basic questions.
What can the system do on its own?
How far could a mistake spread?
Thirdly, how quickly can we stop it and
recover?
This isn't a criticism of consolidation
or a negative on so-called
platformization.
It's a common sense strategy for any
AI-powered security platform. In our
view, sovereignty in this context simply
means that the customer, not the
software
vendor,
the tech stack, the customer retains
ultimate ultimate control.
So, let's close with one of the score
cards that we've been doing,
building these with the help of our AI
friends. We'll call this our post-mythos
scorecard, what the quarter and what the
qualitative buyer data tell us and what
still requires better evidence.
Look, it's hard not to rate
CrowdStrike's momentum green given its
record-breaking quarter.
CrowdStrike delivered at 333 million as
we said in net new ARR of 51%,
ending ARR accelerated for the fourth
consecutive quarter in the fiscal year
2027 net new ARR outlook
rose to 34% growth.
The quality of CrowdStrike's financials
are clearly green with a 26% free cash
flow margin and a 25% non-GAAP operating
margin as I recall. Those are both
improving in the guidance. We'll hear
more next week at the at the analyst
event and and with the the analyst day
at Falcon.
They can look at platform expansion.
That's green as well. Cloud, next-gen
SIM, and identity now exceed, as we
said,
$2 billion of combined ARR.
And customer module depth continues to
rise. It's impressive.
Customer value may be the most important
green signal in our view, and Qualtate
buyers describe
uh one agent covering EDR, data
protection, AI, and identity with
benefits in reduction in manpower,
better operating efficiency, and better
unit economics.
AI perception is also strong.
CrowdStrike scored 89% favorable in
Qualtate's uh latest work, placing it
among the leading vendors along with
Palo Alto and Wiz.
Charlotte AI has well as drawn
consistently positive buyer citations
and AIDR nearly tripled sequentially.
The next proof point to watch is
durability.
Q3 conversion, adjacent growth relative
to endpoint, and sustained customer
outcomes at renewal are things to watch.
Now to the yellow and some of the open
areas.
Flex is a yellow. It's not because the
commercial motion is not working or is
weak. It's actually very strong.
The uplift in reflex behavior prove
that.
The questions are around consumption
versus commitment, renewal economics,
and CrowdStrike's pricing leverage.
As we said, that one satisfied buyer
described the recurring escalation as an
OEM tax.
How much of that flex momentum is
related to myth of fear, and how much is
durable? As competitors copy the flex
model, will CrowdStrike's first mover
advantage and that differentiation be
challenged?
Or will procurement part the
departments, you know, hold them up
against the to make make more column
fodder and get better discounts? We'll
see. AIDR has similar disclosure
asterisk. The percentage growth is
exceptional, but CrowdStrike has yet to
disclose absolute ARR.
Waiting for that.
Autonomous authority is also yellow, if
only because it's early.
The product ingredients are emerging,
but customers still need evidence on bad
action rates and approval gates and
rollback times and
with the scope of things that are
affected, etc. Blast radius containment
remains open
because the earnings call didn't provide
any details, nor does the qualitative
data uncover any insight here.
So, we're left with our own reasoning
and knowledge from speaking with SecOps
pros and customers.
In fairness, this is a research gap.
It's not a negative call against
CrowdStrike. It's one of the items that
we'll be digging into next week at
Falcon.
By the way, this is also an operational
sovereignty test. Can the customer bind
or interrupt and recover from an agent's
action on its own terms?
Then comes the the the Falcon
checkpoint, the conference.
Barclays sees a plausible path to move
the $10 billion ARR milestone from
fiscal 2031
to fiscal 29.
Now,
big reason probably why the stock was up
20% today.
That is a street scenario. It's not a
CrowdStrike guidance.
The conference Falcon can
hopefully show us whether pipeline
durability, product innovation, support
is accelerating while still imposing
those technical controls.
So, where do we arrive in this analysis?
Clearly, momentum is there and it's
validated.
The trust test is open, so let's give it
some time to prove that out.
Post mythos momentum is real. There's no
question about that. The moat is
strengthening, but as Falcon becomes
more central to the AI SOC, the trust
bar rises
with it
and it's too early to claim a definitive
mission accomplished statement. Now, one
thing we haven't touched on is
ecosystem. CrowdStrike's ecosystem is
exploding as we predicted at our first
Falcon conference in 2022,
we said
that was our first year. They need
We predicted that their their ecosystem
we we we compared it to the early days
of 2013 ecosystem of of ServiceNow,
which also exploded. And then last year
we said, "CrowdStrike, they need a
bigger boat." And so they're moving into
the Mandalay Bay.
You know, under the leadership of of
DB, his nickname is DB, Daniel Bernard.
He's I call him the ecosystem uh the
partner alpha.
He's the chief commercial officer at
CrowdStrike. The ecosystem has become a
key part of the CrowdStrike flywheel.
And we'll be watching for which key
players in the network are leaning into
that story. We'll also be watching for
new product innovations. You always get
that at Falcon and how CrowdStrike is
leveraging some of its recent
acquisitions.
Really curious to see what they do with
Pangea and Signal, Signal SGNL, which is
a continuous identity and real-time
access control platform. It was acquired
in January of this year. Obviously very
relevant to the blast radius discussion
that we've been having today. So, the
Cube is going to be at Falcon. Stop by
and see us. We're going to be
broadcasting for 3 days this year,
kicking off Monday evening with the Cube
after dark, which is a great tradition.
We're super excited to be part of the
the opening evening events. And we're
going to go wall-to-wall through the
week at Mandalay Bay. Myself, Rebecca
Knight, and Krista Case is going to be
there on site. We're going to be
broadcasting and in the endless program.
So, stop by, see us, check out
siliconangle.com for all the news, the
cuberesearch.com
for all the the deep research, and of
course the cube.net. That's where we'll
be broadcasting live, and check out the
QBAi.com
and find out, you know, what's happening
around the world. Thank you for
watching. I'm Dave Alonte. We'll see you
next time on Breaking Analysis.