Submind YouTube summaries
Thumbnail for Dan Danielli, CrowdStrike & Robb Mayeski, Kroll | CrowdStrike 2026

Dan Danielli, CrowdStrike & Robb Mayeski, Kroll | CrowdStrike 2026

Watch on YouTube

Video summary

The discussion centers on the strategic partnership between CrowdStrike and Kroll, highlighting a significant shift where Kroll has transitioned its entire managed services portfolio to be powered by CrowdStrike's Falcon Complete platform. This collaboration leverages CrowdStrike's position as an operating system for cybersecurity to enable massive scale, allowing partners like Kroll to extend their reach beyond simple endpoint security into comprehensive risk management and agent-based defense. The core of this partnership involves using CrowdStrike's technology not just to secure assets, but to wrap it with high-level consultative services that guide customers through complex transformations, effectively lowering operational costs while elevating security outcomes for enterprise clients. A major theme of the conversation is the practical application of Frontier AI and the "Charlotte" AI agent within the Falcon Foundry environment to solve the challenge of prioritizing vast amounts of data. The speakers illustrate how traditional methods of assessing millions of vulnerabilities or attack paths are labor-intensive and slow, whereas AI agents can distill massive datasets—such as 40 million vulnerabilities—down to a critical few high-risk items in minutes rather than months. However, they emphasize that automation is not a blanket solution; human expertise remains essential for adjudicating business context, determining compensating controls versus remediation, and ensuring that the AI's outputs align with specific organizational goals and financial realities, preventing organizations from becoming the "Department of No." The dialogue also addresses the concept of sovereignty in the age of AI, defining it not just as legal or territorial but as operational and financial control over one's tech stack. The speakers argue that while vendors can provide tools to enhance security and efficiency, customers must ultimately own their risk decisions and manage costs to maintain financial sovereignty, citing examples of companies facing unexpected token budget overruns. By integrating AI into governance, risk, and compliance workflows, organizations can move from a defensive posture to an enabling one, where security teams act as accelerators for business innovation rather than bottlenecks, thereby unlocking economic gains while maintaining a single version of the truth across fragmented enterprise silos. Looking toward the future, both Dan Danielli and Robb Mayeski express confidence that defenders will soon move faster than adversaries through the use of purpose-built security models and evolved processes designed for machine speed. They envision a future where deterministic software logic and stochastic AI capabilities merge to dissolve data silos and create a unified view of truth across an organization. The ultimate goal is to redesign business processes to be "agent-ready," allowing organizations to capture tacit human knowledge and continuously improve their AI systems through human validation, ensuring that as technology advances, the ecosystem remains agile, cost-effective, and capable of delivering measurable security outcomes at scale.
Read the full video transcript
Hi everyone, we're wrapping up day three of Falcon 2026 here at the Mandalay Bay. You can see the the hall is empty, but the cube is still going. We're still doing the bringing you the the the signal extra- extracting the signal from the noise. My name is Dave Vellante. Rebecca Knight has just left trying to catch her plane. Uh we've been wall-to-wall all week. Uh this ecosystem is just exploding. Great keynote by George Kurtz, Mike Sentoni today. We had Adam Myers on just a wall-to-wall guests. It's been amazing. Dan Daniele is here. He's the vice president for global scale partnerships at CrowdStrike CrowdStrike scale is the operative word there. And Rob Majeski, who's the global head of engineered defense in CrowdStrike services portfolio owner at Kroll. You got you guys manage risk. I guess you both manage risk. It's kind of what your business is, right? A little bit. Yeah. All right. So, as I said, I got I got some little topics right before and I had just ran them through AI. So, let's see how AI did. I said, "Give me a little summary of what we're going to talk about. Tell me how how it came out." It says, "Most security organizations have no shortage of AI ideas." We know this is true. The harder problem is deciding which use cases justify the investment and moving the best ones into production and then proving that they improve security and operating economics. Kroll Apex combines Kroll's frontline expertise with CrowdStrike's Charlotte AI, something we haven't talked a lot about this week. Love to talk to more. Charlotte AI agent works in Falcon Foundry to create a more disciplined path from AI opportunity to measurable outcome for your clients. How was that? How does that sound? >> That that is >> It is AI, right? >> Yeah. >> All right. Well, so it's AI is getting pretty good. >> Thank you, my AI friend. All right. So, let's let's unpack that. Um Talk about the partnership. Why don't we start with Kroll? How you guys work together? What each of you does. >> Sure. So, we we've been partners for many years now, but the last year we actually flipped our entire managed services book of business to be powered by CrowdStrike and CrowdStrike Falcon Complete. And we've been building on the power of the crowd uh on top of that. Now, not only securing endpoints, but now securing agents uh and helping prioritize uh clients' risks and things like quilt works and vulnerabilities and developing capabilities. >> So, Dan, we had Thank you for that. Tim, we had uh DB on a couple of times >> Awesome. >> We've been watching. We first did uh Falcon in 2022. You had little tiny ecosystem. We said, "Okay, guys, you got to work on that ecosystem thing. You got to scale it." Well, little did we know uh how the the pace of that scale. It's in your title. So, talk about sort of how you have enabled this ecosystem to grow generally and specifically the relationship with Kroll. >> Well, look, I I I think it all starts with CrowdStrike being the the operating system of cybersecurity and you you look around this this showroom floor and uh there are so many different partner types that are that are leveraging uh CrowdStrike and and the Falcon platform to get customers the the outcomes that they need most. Uh for me, the the the operative word is scale. CrowdStrike can't be in every single conversation and every single corner of the globe uh at all times and and we need partners who are uh not just taking the platform to market, but wrapping it with the services to take customers through the transformation. Again, getting to to the outcomes that they need most and the the partnership with Kroll has been a special one. They're not just CrowdStrike first, they're Falcon Complete first. They're leveraging our MDR offerings. They're lowering their operating costs in in how they're taking their services to to market, but then bringing a ton of consultative advice to to customers and they're helping them through how they go and get themselves Frontier AI ready. >> So, Rob, walk us through sort of your approach, the methodology. I mean, how do you assess a customer's environment? How do you turn sort of that you know, estate into something that you can actually get your arms around and prioritize and score? How How do you approach that? >> Well, first and foremost, it it starts with understanding the tech and understanding where clients are within their their current capabilities. Lighting up all the capabilities within the Falcon platform, but then also marrying that with what processes that they have and what processes they're focusing on. And actually going through and scoring them inside of our Crow Apex solution that's built in CrowdStrike Foundry. And then making recommendations to say, should this be an automated process? Should this be an AI agent that gets created? And stack ranking those to say, "Hey, here's where we're going to actually go and build based on value and do it inside of the CrowdStrike platform so that you're not just doing it with technology, you're really and truly agentifying your workforce." >> What's an example of something that that you found that shouldn't be automated? >> We've had a lot of people that want to do something that's a report that they run once a month, once every couple months. It only takes less than an hour because when you build an agent, there's development time in an agent to go build and everybody wants to go and say, "Yes, let's let's agentify everything." But agents cost money. They cost credits. They cost tokens. And so, you still have to weigh the the cost of development and the cost to run that agent versus how much time and efficiency is it actually going to save you and how secure it's going to help you be. >> Thank you. So, Daniel, we I guess I we haven't talked much about Charlotte. >> Yeah. >> And take us through Charlotte AI agent works, Falcon Foundry. How does that allow, you know, Kroll to sort of move from identifying an opportunity to sort of actually getting into production and and operating it on Falcon? >> Yeah, well, I'll I'll take even one step back and and start with Kroll Works. Uh we launched the Kroll Works coalition a couple of quarters ago. Um we really need to to reclaim um the direction of the narrative around how Frontier AI was not just a huge opportunity for the world at large, but also how some of the challenges at Frontier AI were bringing could be solved for by the by the cybersecurity community. We recognized that it wasn't going to be one organization, one technology that was going to be the panacea or silver bullet to to go and solve for that. And we need to bring a coalition of all the right partners, the tech ecosystem, uh service providers like Kroll's so that we could get customers to the outcomes that they needed. We developed a very simple framework of how we needed to get customers to those elevated outcomes. It started with the assessments that Rob took you through. Uh once you've got those assessments, we're able to discover not just thousands, but millions. Uh we had uh one Kroll Works partner with a Fortune 100 customer that surfaced well over 40 million vulnerabilities. So, the the prioritization process needed to be very acute so that you get to the things that were most important. Then there's remediation and mitigation services that need to be driven. And then finally getting the the customers into a stable state meant that we could now start to think about the transformation programs. So, back to your question around Charlotte and Agent Works and how does that all come to pass? Well, those first two chapters are very labor-intensive. The consultative process would have required hundreds of of analysts compiling information in large enterprise organizations to to try and come up with those plans. And then how to figure out how to go through all the prioritization of 40 million vulner- That's a that's a difficult. And so, we've managed to leverage Charlotte, we've leveraged Agent Works, we've built applications in foundry that reside now inside the the Falcon console. Um that uh capability is called Falcon IQ. It's available to our CrowdStrike partners, and it's it's taking what would have been days and weeks and months of work at the click of a button highly contextualizing correlated. Um uh these reports being executed within the Falcon platform. Um it's incredible with the the the speed at which these agents can operate. >> What do you find being with a degree of accuracy in terms of, you know, when you when you check it? Maybe you have humans check it. Probably doing a lot of reinforcement learning. How accurate have you found this or do you expect it to be? >> Well, we're putting it into the hands of the the biggest GSIs and and the the the strongest consultants in the market. So, not only have we got the the the machine control and speed and and efficacy that's coming with it, we've also got the the years of expertise that these consultants are bringing in. Their services catalogs are integrated into the Falcon IQ platform, and that's what's driving the the suggested outcomes. So, we're seeing a high degree of efficacy in that. >> And Rob, you guys are obviously part of CrowdStrike, right? So, that means that you get My understanding from talking to to George this morning is Blue Solana and Red Tempest and Safe Mine are going to go through the project CrowdStrike community first. >> Yep. >> Right? And then it's I guess embedded into the Falcon platform. So, that's going to be how is that going to affect your business? I mean, now you're going to be identifying I mean, would you say 40 million vulnerabilities? I mean, wow. That's incredible. But now you're going to be building digital twins for your customers, cycling it through that infinite loop that George showed, red teaming, blue teaming. Okay. Remediate, remediate, remediate until you knuckle it down to safety zone, and then you deploy it. Is that kind of how we should think about this? >> So, you have to think about it in a little bit different way. You're You're still thinking of the human speed. >> Yeah. >> We're actually we need to rethink that at AI and at machine speed. Right. Where you think of the the knuckling down where it, you know, that sounds like it's a laborious process. That sounds like it's going to take time. We're still talking hours >> Right. >> minutes where these things are running through computes that we haven't even thought of and we can't even fathom in in that sense where where you are taking 40 million vulnerabilities, distilling it down, continuing to run through all those quilt works capabilities now with Red Teampest, right? And and understanding that and say, "Okay, what really matters?" >> Mhm. >> You know, Dan Dan and I worked on something and we actually took a client's number of attack paths, right, from those those millions of vulnerabilities from 614 various attack paths down to five. The five that really matter. Because when you remediate those five, that 40 million vulnerabilities shrinks by roughly 84%. >> Yes, sir. >> So, okay. Make sure I understand. I got a couple questions from that. So, you're saying that that infinite loop that George showed that is going to take, let's say, minutes, maybe hours. Um it you won't necessarily remediate it all. Is that right? Or will you? Why wouldn't you? Is there a cost to that remediation that you don't necessarily want to incur because the risk is not there? Am I >> You have to think about the the business risk. There are things where you may want to accept or you may want to put a compensating control in versus actually fixing a vulnerability or or Uh we actually have had other clients where they're saying, "If you turn this down or if we we actually try to make this change, we could be out tens of millions of dollars per minute." And so, you have to still weigh the risk and the reward of turning down money and the the business objectives with being secure. So, you may not fix everything immediately, but you're prioritizing the things that matter the most and understanding the business context with it, which is always the hardest. >> So, I think you just answered my second question was what's the role of the humans? >> Yeah. >> It's like the human ultimately has to adjudicate whether or not it makes, you know, business sense cuz they know their business better than any of you, right? >> Yeah. >> Yeah. The the human intelligence is is going to continue to be be key in in all of this. And you know, like I said earlier, it's the the the ecosystem coming together at large here. It's it's not just a a single a single technology. And and what we've seen overwhelmingly here at Falcon is the the ecosystem is is voting in favor of the the Falcon platform, which is phenomenal. >> I like the term compensating controls. I know you didn't just invent it, but it it makes me think about sovereignty. That's a big topic now. And when people hear sovereignty, they think about territorial sovereignty. And it's I'm not talking about territorial or legal. I'm talking about um your sovereignty over your tech stack. Your operational sovereignty and really importantly your financial sovereignty, probably the most important version. And it seems to me that that you you CrowdStrike or any vendor, hyperscalers, they can't confer Scroll can't confer sovereignty to me as a customer. I am responsible for my sovereignty. I can work with partners like you to determine that, but I have to determine the risks, what risks I'm willing to take. Am I willing to let risk you know, getting locked in to CrowdStrike? Yes, I am because the benefits are okay, great. I understand that and and I have compensated controls that if that happens, I've got this competitive market or whatever it is. I'm accepting that risk. So, how much of a conversation is this within your customer base? This sounds like it's your business helping people you know, determine their own sovereignty, but yet you see examples all the time. Uber blew through its token its annual token budget in one quarter. Canva had a reset its its growth expectations be- because um it it was token matching for for freemium users. And th- those are two examples where they got they got an invoice and it was like, uh-oh, we didn't have, you know, financial sovereignty. So, how much of a discussion is this with your customers and and and how are you helping? >> It's it's a it's a key to a lot of the the topics that we have with our customers. As we've actually gone through that that MDR migration with Falcon Complete, it's great because it actually unlocks the entire platform to them. We've actually had customers that are reducing their total cost of ownership by moving to the Falcon platform by up to 30%. So, now not only is my tech cost less, my operational costs are less, I don't need as many people. I can reallocate people that I that I had in other areas. And what does that mean? That means that the business is even more healthy. And that means that not only is the business more healthy, I'm also more secure at the same way and security moves from Mr. No to Mr. Yes and and yes, we can. So, Dan, any anything to add on that? >> Uh look, I I think the the conversations we're getting ourselves into now where it's not just a back office governance risk and compliance conversation and uh the cybersecurity teams are becoming the foundation of how AI gets unlocked across the enterprise is probably the most exciting time for for us um knowing that we've got a a big role to play in the the economic gains. So, you talk about sovereignty from the perspective of protecting risk, but there's there's also this enormous opportunity to to unlock all of these operational gains from from AI and and how organizations can adopt that. >> Well, it's to the point um you don't want to be the Department of No. No. You actually want to be an enabler. So, to the extent that you can uh this this is to me the real benefit of having a platform. If you've got the platform and it's it's you know, the whomever is in charge throws holy water on it, go. You don't have to get permission to deploy because it's it's it's approved. And and so, that's going to be an accelerator for your business. How is that changing the role of of of of you as a as a service partner? >> Well, it's it's now not thinking about the GRCs anymore. The the governance, the risk, the compliance pieces. It's thinking about how do you actually help companies transform their business and think in an automated think about machine speedway because they can't take and put an agent in a human process. You have to help them redesign their processes that are agentic, that are agent ready. And that's where we've shifted our business to is to help them think about what are the agents that they need to build, but how do you change your process to make sure that it's ready for an agent? >> Where are we at with that because when I talk to chief AI officers, I I they'll share with me that listen, if it's data intensive, if it's it you know, manual data entry or cleaning up your CRM, that AI is like really showing a lot of promise there. What seems harder is sort of the maybe it's the next wave we're getting into. Love your feedback on this is that capturing that tacit human knowledge, you know, the tribal knowledge, um learning from the reasoning traces of the human, so the agents, you know, next time when there's an exception can handle it themselves. That's sort of you know, early days. Is that what you're experiencing and >> That's that's a lot of what we're experiencing. We we had a a saying when it was just automation before all the AI came in. You can't automate a process that doesn't exist. >> Mhm. >> And it's the same with AI. When you think about it, AI has to learn from something. It can learn from data, but it can also learn from processes. It can learn from how many times did I do this? What was the outcome? And that's why humans are still important is that validation to then help the AI continue to learn and get better of did it do it right? Did it do it wrong? How do we how do we change that and how do we make sure that humans are helping the the agents get better and learn? >> It was interesting to see Mark Benioff on TV with Dario the other day, um talking about something that we've been talking about for a while, which is you've got deterministic software and you've got the stochastic probabilistic, you know, capability with with frontier models. Those have to come together in order to actually achieve outcomes. Um And and and and and so but determinism is kind of it it lives within departments, I would say, you know, the financial department has their view of the world and logistics, you know, on and on and on. And and the promise of AI is those those fragmented silos get dissolved and there is a single finally, a single version of the truth, you know, data warehousing didn't give it to us and big data didn't give it to us, but maybe AI will deliver that. So, how do you think about that? Are you you know, having those conversations with customers? Obviously, security. If I can wrap security around all of that and be the department of yes, that's a major checkbox and then I can attack some of these other, you know, challenges. You don't have to go to IT and security every time I want to deploy something. How how are we you thinking about and your customers in the conversations around sort of the that silo busting, if you will? >> Well, this is where what what Dan mentioned of Project Quilt Works because it's not a product, it's a coalition, it's a fabric, it's thinking about the technology, thinking about the data layer, thinking about the process, bringing it all together as a coalition, but also as a set of of capabilities like a quilt to actually go in and make those determinations and and help clients really understand by using a framework, using a set of common capabilities. We put our our Quilt Works capability into 10 questions. 10 questions that a CFO can understand, that a board member can understand, that a vulnerability management analyst can understand to really help make a determination based on the data of where do I need to build my agents, where do I need to focus my time, right? And then how do I govern that? And then what does that mean for the outcomes for my business? >> Okay, so it's not a skew, but but there's a lot of product thinking going into they're kind of productizing, you know, Quilt Works. So not again, not as a skew, but but as something that can be much more easily deployed and and adopted. All right, last question. We're getting We're getting beep beep beeped out of here, but we we love the cube loves to go all day all night. Last question for each of you. We're here at uh let's say uh Falcon uh 2027. What do you want to be able to say each of you that you can't say that then that you can't say today? Start with you, Dan. >> Gosh, uh that we're moving faster than the speed of the adversary. I think that's that's got to be absolutely core everything that that we're driving. I think what George announced on uh on on Monday um on Tuesday rather was was really exciting. Uh you know, we we we heard uh a lot of scary things when when the mythos moment hit, uh but what we heard on Tuesday is that the defenders have got purpose-built models that are focused on security outcomes that are going to be able to be delivered at a cost basis that allows us to to really start to elevate the the cost of an attack for the adversary, which is exactly where we need to be. So, I'm I'm confident that we're going to be in that position and and we're going to be moving faster than the speed of the adversary and driving the right outcomes. >> Hey Dave, how about you, Rob? >> I would say something similar, but I would say I want us to rethink what we're doing in terms of the technology to marry with that speed. And the processes can't be the same processes that we've had for 20 years. The processes have to evolve to make up for that machine speed. So, when we are using the things that that we talked about this week for all the new innovations at speed at scale, that we do stand a chance. >> Guys, thanks so much for helping me close out Falcon 2026. You know, the Cube's coverage, really appreciate your time and uh congratulations on all the good work and thank you. >> Absolutely. Thanks for having us. >> Hey, thank you for watching. That wraps up the 2026 Falcon event, the Cube's coverage. Check out the cube.net. All these videos are available on demand. They're up within minutes. Siliconangle.com has all the news. We covered the the the whole Falcon news portfolio. The cuberesearch.com has all the deep research. And go to the cubeai.com. Ask it, you know, what were the top takeaways in Falcon 2026. You'll get that. I'm Dave Vellante. September is a huge month for the Cube. We're back out here for a number of shows. We're in Moscone, we're out of the NYSE Wired studio. Check it out. Thanks for watching, and we'll see you next time.