Dan Danielli, CrowdStrike & Robb Mayeski, Kroll | CrowdStrike 2026
Watch on YouTubeVideo summary
The discussion centers on the strategic partnership between CrowdStrike and Kroll, highlighting a significant shift where Kroll has transitioned its entire managed services portfolio to be powered by CrowdStrike's Falcon Complete platform. This collaboration leverages CrowdStrike's position as an operating system for cybersecurity to enable massive scale, allowing partners like Kroll to extend their reach beyond simple endpoint security into comprehensive risk management and agent-based defense. The core of this partnership involves using CrowdStrike's technology not just to secure assets, but to wrap it with high-level consultative services that guide customers through complex transformations, effectively lowering operational costs while elevating security outcomes for enterprise clients.
A major theme of the conversation is the practical application of Frontier AI and the "Charlotte" AI agent within the Falcon Foundry environment to solve the challenge of prioritizing vast amounts of data. The speakers illustrate how traditional methods of assessing millions of vulnerabilities or attack paths are labor-intensive and slow, whereas AI agents can distill massive datasets—such as 40 million vulnerabilities—down to a critical few high-risk items in minutes rather than months. However, they emphasize that automation is not a blanket solution; human expertise remains essential for adjudicating business context, determining compensating controls versus remediation, and ensuring that the AI's outputs align with specific organizational goals and financial realities, preventing organizations from becoming the "Department of No."
The dialogue also addresses the concept of sovereignty in the age of AI, defining it not just as legal or territorial but as operational and financial control over one's tech stack. The speakers argue that while vendors can provide tools to enhance security and efficiency, customers must ultimately own their risk decisions and manage costs to maintain financial sovereignty, citing examples of companies facing unexpected token budget overruns. By integrating AI into governance, risk, and compliance workflows, organizations can move from a defensive posture to an enabling one, where security teams act as accelerators for business innovation rather than bottlenecks, thereby unlocking economic gains while maintaining a single version of the truth across fragmented enterprise silos.
Looking toward the future, both Dan Danielli and Robb Mayeski express confidence that defenders will soon move faster than adversaries through the use of purpose-built security models and evolved processes designed for machine speed. They envision a future where deterministic software logic and stochastic AI capabilities merge to dissolve data silos and create a unified view of truth across an organization. The ultimate goal is to redesign business processes to be "agent-ready," allowing organizations to capture tacit human knowledge and continuously improve their AI systems through human validation, ensuring that as technology advances, the ecosystem remains agile, cost-effective, and capable of delivering measurable security outcomes at scale.
Read the full video transcript
Hi everyone, we're wrapping up day three
of Falcon 2026 here at the Mandalay Bay.
You can see the the hall is empty, but
the cube is still going. We're still
doing the bringing you the the the
signal extra- extracting the signal from
the noise. My name is Dave Vellante.
Rebecca Knight has just left trying to
catch her plane.
Uh we've been wall-to-wall all week. Uh
this ecosystem is just exploding. Great
keynote by George Kurtz, Mike Sentoni
today. We had Adam Myers on just a
wall-to-wall guests. It's been amazing.
Dan Daniele is here. He's the vice
president for global scale partnerships
at CrowdStrike CrowdStrike scale is the
operative word there. And Rob Majeski,
who's the global head of engineered
defense in CrowdStrike services
portfolio owner at Kroll. You got you
guys manage risk. I guess you both
manage risk. It's kind of what your
business is, right? A little bit. Yeah.
All right. So, as I said, I got I got
some little topics right before and I
had just ran them through AI. So, let's
see how AI did. I said, "Give me a
little summary of what we're going to
talk about. Tell me how how it came
out." It says, "Most security
organizations have no shortage of AI
ideas." We know this is true. The harder
problem is deciding which use cases
justify the investment and moving the
best ones into production and then
proving that they improve security and
operating economics. Kroll Apex combines
Kroll's frontline expertise with
CrowdStrike's Charlotte AI, something we
haven't talked a lot about this week.
Love to talk to more. Charlotte AI agent
works in Falcon Foundry to create a more
disciplined path from AI opportunity to
measurable outcome for your clients. How
was that? How does that sound?
>> That that is
>> It is AI, right?
>> Yeah.
>> All right. Well, so it's AI is getting
pretty good.
>> Thank you, my AI friend. All right. So,
let's let's unpack that. Um
Talk about the partnership. Why don't we
start with Kroll? How you guys work
together?
What each of you does.
>> Sure. So, we we've been partners for
many years now, but the last year we
actually flipped our entire managed
services book of business to be powered
by CrowdStrike and CrowdStrike Falcon
Complete. And we've been building on the
power of the crowd
uh on top of that. Now, not only
securing endpoints, but now securing
agents
uh and helping prioritize uh clients'
risks and things like quilt works and
vulnerabilities and developing
capabilities.
>> So, Dan, we had Thank you for that. Tim,
we had uh DB on a couple of times
>> Awesome.
>> We've been watching. We first did uh
Falcon in 2022.
You had little tiny ecosystem. We said,
"Okay, guys, you got to work on that
ecosystem thing. You got to scale it."
Well, little did we know uh how the the
pace of that scale. It's in your title.
So, talk about sort of how you have
enabled this ecosystem to grow generally
and specifically the relationship with
Kroll.
>> Well, look, I I I think it all starts
with CrowdStrike being the the operating
system of cybersecurity and you you look
around this this showroom floor and uh
there are so many different partner
types that are that are leveraging
uh CrowdStrike and and the Falcon
platform to get customers the the
outcomes that they need most. Uh for me,
the the the operative word is scale.
CrowdStrike can't be in every single
conversation and every single corner of
the globe uh at all times and and we
need partners who are uh not just taking
the platform to market, but wrapping it
with the services to take customers
through the transformation. Again,
getting to to the outcomes that they
need most and the the partnership with
Kroll has been a special one. They're
not just CrowdStrike first, they're
Falcon Complete first. They're
leveraging our MDR offerings. They're
lowering their operating costs in in how
they're taking their services to to
market, but then bringing a ton of
consultative advice to to customers and
they're helping them through how they go
and get themselves Frontier AI ready.
>> So, Rob, walk us through sort of your
approach, the methodology. I mean, how
do you assess a customer's environment?
How do you turn sort of that
you know, estate into something that you
can actually get your arms around and
prioritize and score? How How do you
approach that?
>> Well, first and foremost, it it starts
with understanding the tech and
understanding where clients are
within their their current capabilities.
Lighting up all the capabilities within
the Falcon platform, but then also
marrying that with what processes that
they have and what processes they're
focusing on. And actually going through
and scoring them inside of our Crow Apex
solution that's built in CrowdStrike
Foundry. And then making recommendations
to say, should this be an automated
process? Should this be an AI agent that
gets created? And stack ranking those to
say, "Hey, here's where we're going to
actually go and build based on value and
do it inside of the CrowdStrike platform
so that you're not just doing it with
technology, you're really and truly
agentifying your workforce."
>> What's an example of something that that
you found that shouldn't be automated?
>> We've had a lot of people that want to
do something that's a report that they
run once a month,
once every couple months. It only takes
less than an hour because when you build
an agent, there's development time in an
agent to go build and everybody wants to
go and say,
"Yes, let's let's agentify everything."
But agents cost money. They cost
credits. They cost tokens. And so, you
still have to weigh the the cost of
development and the cost to run that
agent versus how much time and
efficiency is it actually going to save
you and how secure it's going to help
you be.
>> Thank you. So, Daniel, we I guess I we
haven't talked much about Charlotte.
>> Yeah.
>> And
take us through Charlotte AI agent
works, Falcon Foundry. How does that
allow, you know, Kroll to sort of move
from identifying an opportunity to sort
of actually getting into production and
and operating it on Falcon?
>> Yeah, well, I'll I'll take even one step
back and and start with Kroll Works. Uh
we launched the Kroll Works coalition a
couple of quarters ago. Um we really
need to to reclaim
um the direction of the narrative around
how Frontier AI was not just a huge
opportunity for the world at large, but
also how some of the challenges at
Frontier AI were bringing could be
solved for by the by the cybersecurity
community. We recognized that it wasn't
going to be one organization, one
technology that was going to be the
panacea or silver bullet to to go and
solve for that. And we need to bring a
coalition of all the right partners, the
tech ecosystem, uh service providers
like Kroll's so that we could get
customers to the outcomes that they
needed. We developed a very simple
framework of how we needed to get
customers to those elevated outcomes. It
started with the assessments that Rob
took you through. Uh once you've got
those assessments, we're able to
discover not just thousands, but
millions. Uh we had uh one Kroll Works
partner with a Fortune 100 customer that
surfaced well over 40 million
vulnerabilities. So, the the
prioritization process needed to be very
acute so that you get to the things that
were most important. Then there's
remediation and mitigation services that
need to be driven. And then finally
getting the the customers into a stable
state meant that we could now start to
think about the transformation programs.
So, back to your question around
Charlotte and Agent Works and how does
that all come to pass? Well, those first
two chapters are very labor-intensive.
The consultative process would have
required
hundreds of of analysts compiling
information in large enterprise
organizations to to try and come up with
those plans. And then how to figure out
how to go through all the prioritization
of 40 million vulner- That's a that's a
difficult. And so, we've managed to
leverage Charlotte, we've leveraged
Agent Works, we've built applications in
foundry that reside now inside the the
Falcon console.
Um that uh capability is called Falcon
IQ. It's available to our CrowdStrike
partners, and it's it's taking what
would have been days and weeks and
months of work at the click of a button
highly contextualizing correlated. Um
uh these reports being executed within
the Falcon platform. Um it's incredible
with the the the speed at which these
agents can operate.
>> What do you find being with a degree of
accuracy in terms of, you know, when you
when you check it? Maybe you have humans
check it. Probably doing a lot of
reinforcement learning. How accurate
have you found this or do you expect it
to be?
>> Well, we're putting it into the hands of
the the biggest GSIs and and the the the
strongest consultants in the market. So,
not only have we got the the the machine
control and speed and and efficacy
that's coming with it, we've also got
the the years of expertise that these
consultants are bringing in. Their
services catalogs are integrated into
the Falcon IQ platform, and that's
what's driving the the suggested
outcomes. So, we're seeing a high degree
of efficacy in that.
>> And Rob, you guys are obviously part of
CrowdStrike, right? So, that means that
you get My understanding from talking to
to George this morning is Blue Solana
and Red Tempest and Safe Mine are going
to go through
the project CrowdStrike
community first.
>> Yep.
>> Right? And then it's I guess embedded
into the Falcon platform.
So, that's going to be how is that going
to affect
your business? I mean, now you're going
to be identifying I mean, would you say
40 million vulnerabilities? I mean,
wow. That's incredible. But now you're
going to be building digital twins for
your customers, cycling it through that
infinite loop that George showed, red
teaming, blue teaming. Okay.
Remediate, remediate, remediate until
you knuckle it down to
safety zone, and then you deploy it. Is
that kind of
how we should think about this?
>> So, you have to think about it
in a little bit different way. You're
You're still thinking of the human
speed.
>> Yeah.
>> We're actually we need to rethink that
at AI and at machine speed. Right. Where
you think of the the knuckling down
where it, you know, that sounds like
it's a laborious process. That sounds
like it's going to take time.
We're still talking
hours
>> Right.
>> minutes where these things are running
through computes that we haven't even
thought of and we can't even fathom in
in that sense where where you are taking
40 million vulnerabilities, distilling
it down, continuing to run through all
those quilt works capabilities now with
Red Teampest, right? And and
understanding that and say, "Okay, what
really matters?"
>> Mhm.
>> You know, Dan Dan and I worked on
something and we actually took a
client's number of attack paths, right,
from those those millions of
vulnerabilities from 614 various attack
paths down to five.
The five that really matter. Because
when you remediate those five, that 40
million vulnerabilities shrinks by
roughly 84%.
>> Yes, sir.
>> So, okay. Make sure I understand. I got
a couple questions from that. So, you're
saying that that infinite loop that
George showed that is going to take,
let's say, minutes, maybe hours.
Um
it you won't necessarily
remediate it all.
Is that right? Or will you? Why wouldn't
you? Is there a cost to that remediation
that you don't necessarily want to incur
because the risk is not there? Am I
>> You have to think about the the business
risk. There are things where you may
want to accept or you may want to put a
compensating control in versus actually
fixing a vulnerability or or
Uh we actually have had other clients
where they're saying, "If you turn this
down or if we we actually try to make
this change, we could be out tens of
millions of dollars per minute."
And so, you have to still weigh the risk
and the reward of
turning down money and the the business
objectives with being secure. So, you
may not fix everything immediately,
but you're prioritizing the things that
matter the most and understanding the
business context with it, which is
always the hardest.
>> So, I think you just answered my second
question was what's the role of the
humans?
>> Yeah.
>> It's like the human ultimately has to
adjudicate whether or not it makes, you
know, business sense cuz
they know their business better than any
of you, right?
>> Yeah.
>> Yeah. The the human intelligence is is
going to continue to be be key in in all
of this. And
you know, like I said earlier, it's the
the the ecosystem coming together at
large here. It's it's not just a a
single a single technology. And and what
we've seen
overwhelmingly here at Falcon is the the
ecosystem is is voting in favor of the
the Falcon platform, which is
phenomenal.
>> I like the term compensating controls. I
know you didn't just invent it, but it
it makes me think about sovereignty.
That's a big topic now. And when people
hear sovereignty, they think about
territorial sovereignty.
And it's I'm not talking about
territorial or legal. I'm talking about
um
your sovereignty over your tech stack.
Your operational sovereignty and really
importantly your financial sovereignty,
probably the most important version.
And it seems to me that that you you
CrowdStrike or any vendor, hyperscalers,
they can't confer
Scroll can't confer sovereignty to me as
a customer. I am responsible for my
sovereignty. I can work with partners
like you to determine that, but I have
to determine the risks, what risks I'm
willing to take. Am I willing to let
risk you know, getting locked in to
CrowdStrike? Yes, I am because the
benefits are okay, great. I understand
that and and I have compensated controls
that if that happens, I've got this
competitive market or whatever it is.
I'm accepting that risk.
So,
how much of a conversation is this
within your customer base? This sounds
like it's your business helping people
you know, determine their own
sovereignty, but yet you see examples
all the time. Uber blew through its
token its annual token budget in one
quarter. Canva had a reset its its
growth expectations be- because
um it it was
token matching for for freemium users.
And th- those are two examples where
they got they got an invoice and it was
like, uh-oh, we didn't have, you know,
financial sovereignty. So, how much of a
discussion is this with your customers
and and and how are you helping?
>> It's it's a it's a key to a lot of the
the topics that we have with our
customers. As we've actually gone
through that that MDR migration with
Falcon Complete,
it's great because it actually unlocks
the entire platform to them. We've
actually had customers that are reducing
their total cost of ownership by moving
to the Falcon platform by up to 30%.
So, now not only is my tech cost less,
my operational costs are less, I don't
need as many people. I can reallocate
people that I that I had in other areas.
And what does that mean? That means that
the business is even more healthy. And
that means that not only is the business
more healthy, I'm also more secure at
the same way and security moves from Mr.
No to Mr. Yes and and yes, we can. So,
Dan, any anything to add on that?
>> Uh look, I I think the the conversations
we're getting ourselves into now where
it's not just a back office governance
risk and compliance conversation and
uh the cybersecurity teams are becoming
the foundation of how AI gets unlocked
across the enterprise is probably the
most exciting time for for us
um knowing that we've got a a big role
to play in the the economic gains. So,
you talk about sovereignty from the
perspective of protecting risk, but
there's there's also this enormous
opportunity to to unlock all of these
operational gains from from AI and and
how organizations can adopt that.
>> Well, it's to the point um
you don't want to be the Department of
No. No. You actually want to be an
enabler. So, to the extent that you can
uh this this is to me the real benefit
of having a platform. If you've got the
platform and it's it's you know, the
whomever is in charge throws holy water
on it, go. You don't have to get
permission to deploy because it's
it's it's approved. And and so, that's
going to be an accelerator for your
business. How is that changing the role
of of of of you as a as a service
partner?
>> Well, it's it's now not thinking about
the GRCs anymore. The the governance,
the risk, the compliance pieces. It's
thinking about how do you actually help
companies transform their business and
think in an automated think about
machine speedway because they can't take
and put an agent in a human process. You
have to help them redesign their
processes that are agentic, that are
agent ready. And that's where we've
shifted our business to is to help them
think about what are the agents that
they need to build, but how do you
change your process to make sure that
it's ready for an agent?
>> Where are we at with that because when I
talk to chief AI officers, I I
they'll share with me that listen, if
it's data intensive, if it's it you
know, manual data entry or cleaning up
your CRM, that AI is like really showing
a lot of promise there.
What seems harder is sort of the maybe
it's the next wave we're getting into.
Love your feedback on this is that
capturing that tacit human knowledge,
you know, the tribal knowledge, um
learning from the reasoning traces of
the human, so the agents, you know, next
time when there's an exception can
handle it themselves. That's sort of you
know, early days. Is that what you're
experiencing and
>> That's that's a lot of what we're
experiencing. We we had a a saying when
it was just automation before all the AI
came in. You can't automate a process
that doesn't exist.
>> Mhm.
>> And it's the same with AI. When you
think about it, AI has to learn from
something. It can learn from data, but
it can also learn from processes. It can
learn from how many times did I do this?
What was the outcome? And that's why
humans are still important is that
validation to then help the AI continue
to learn and get better of did it do it
right? Did it do it wrong?
How do we how do we change that and how
do we make sure that humans are helping
the the agents get better and learn?
>> It was interesting to see Mark Benioff
on TV with Dario the other day, um
talking about something that we've been
talking about for a while, which is
you've got deterministic software and
you've got the stochastic probabilistic,
you know, capability with with frontier
models. Those have to come together in
order to actually achieve outcomes. Um
And and and
and and so
but determinism is kind of
it it lives within departments, I would
say, you know, the financial department
has their view of the world and
logistics, you know, on and on and on.
And and the promise of AI is those those
fragmented silos get dissolved and there
is a single finally, a single version of
the truth, you know, data warehousing
didn't give it to us and big data didn't
give it to us, but maybe AI will deliver
that. So,
how do you think about that? Are you you
know, having those conversations with
customers? Obviously, security. If I can
wrap security around all of that and be
the department of yes,
that's a major checkbox and then I can
attack some of these other, you know,
challenges. You don't have to go to IT
and security every time I want to deploy
something.
How how are we you thinking about and
your customers in the conversations
around sort of the that silo busting, if
you will?
>> Well, this is where what what Dan
mentioned of Project Quilt Works
because it's not a product, it's a
coalition, it's a fabric, it's thinking
about the technology, thinking about the
data layer, thinking about the process,
bringing it all together
as a coalition, but also as a set of of
capabilities like a quilt to actually go
in and make those determinations and and
help clients really understand by using
a framework, using a set of common
capabilities.
We put our our Quilt Works capability
into 10 questions.
10 questions that a CFO can understand,
that a board member can understand, that
a vulnerability management analyst can
understand to really help make a
determination based on the data of where
do I need to build my agents, where do I
need to focus my time, right? And then
how do I govern that? And then what does
that mean for the outcomes for my
business?
>> Okay, so it's not a skew, but but
there's a lot of product thinking going
into they're kind of productizing, you
know, Quilt Works. So not again, not as
a skew, but but as something that can be
much more easily deployed and and
adopted. All right, last question. We're
getting We're getting beep beep beeped
out of here, but we we love the cube
loves to go all day all night. Last
question for each of you. We're here at
uh let's say uh Falcon uh 2027.
What do you want to be able to say each
of you that you can't say that then that
you can't say today?
Start with you, Dan.
>> Gosh,
uh that we're moving faster than the
speed of the adversary. I think that's
that's got to be absolutely core
everything that that we're driving. I
think what George announced on uh on on
Monday
um on Tuesday rather was was really
exciting. Uh you know, we we we heard uh
a lot of scary things when when the
mythos moment hit, uh but what we heard
on Tuesday is that the defenders have
got purpose-built models that are
focused on security outcomes that are
going to be able to be delivered at a
cost basis that allows us to to really
start to elevate the the cost of an
attack for the adversary, which is
exactly where we need to be. So, I'm I'm
confident that we're going to be in that
position and and we're going to be
moving faster than the speed of the
adversary and driving the right
outcomes.
>> Hey Dave, how about you, Rob?
>> I would say something similar, but I
would say
I want us to rethink what we're doing in
terms of the technology to marry with
that speed. And the processes can't be
the same processes that we've had for 20
years.
The processes have to evolve to make up
for that machine speed. So, when we are
using the things that that we talked
about this week for all the new
innovations at speed at scale,
that we do stand a chance.
>> Guys, thanks so much for helping me
close out Falcon
2026.
You know, the Cube's coverage, really
appreciate your time and uh
congratulations on all the good work and
thank you.
>> Absolutely. Thanks for having us.
>> Hey, thank you for watching. That wraps
up
the 2026 Falcon event, the Cube's
coverage. Check out the cube.net. All
these videos are available on demand.
They're up within minutes.
Siliconangle.com has all the news. We
covered the the the whole Falcon news
portfolio. The cuberesearch.com
has all the deep research. And go to the
cubeai.com.
Ask it, you know, what were the top
takeaways in
Falcon 2026. You'll get that. I'm Dave
Vellante. September is a huge month for
the Cube. We're back out here for a
number of shows.
We're in Moscone, we're out of the NYSE
Wired studio. Check it out. Thanks for
watching, and we'll see you next time.