In case you missed it from this earnings season:

Table of Contents

a. CrowdStrike 101

CrowdStrike is a cloud-native endpoint cybersecurity company. It competes directly with SentinelOne, Microsoft Defender and Palo Alto. Its bread-and-butter is called endpoint detection and response (EDR), which replaces legacy anti-virus (AV). Beyond EDR, it offers applications in cloud security, log management, forensics, identity, data protection and more — rounding out its “Falcon Platform.” Falcon’s edge is in its ability to digest near-endless amounts of data to automate and uplift breach protection. CrowdStrike uses its large and diverse dataset to constantly improve Falcon’s efficacy and use cases… all with a single console and single agent to ensure superior interoperability. It can recycle this same data over and over again to efficiently develop new products for a single interface.

Important Endpoint Security Acronyms:

  • Endpoint detection and response (EDR) provides end-to-end visibility, constant monitoring and full protection of endpoints (like an iPhone). It unveils, prioritizes and responds to threats.

  • Managed detection and response (MDR) encompasses CrowdStrike’s team of threat hunters to augment EDR with human touch when needed.

  • Extended detection and response (XDR) is EDR with 3rd-party, non-endpoint data sources infused. The incremental data sharpens breach protection and extends it beyond the endpoint.

Important Log Management Ideas & Acronyms:

CrowdStrike’s security data lake is a vital complement to every single product it offers. It uses log scale to ingest, logarithmically organize and store data. Broader data ingestion means better breach protection, as Falcon’s products are fmore properly trained on larger sets of relevant insight. This allows for ingestion with more scale and faster time to value… while customers enjoy lower costs as well.

  • As an important aside, log scale is a key ingredient for Falcon XDR. It is instrumental in XDR being able to onboard needed data sources in a scalable and efficient manner.

  • Security Information and Event Management (SIEM) aggregates security logs/data to help organizations uncover and remediate threats faster. Log scale is closely related to SIEM, as log scale is what actually collects data from various sources to be utilized here.

Important Cloud Security Acronyms (alphabet soup, I know):

  • Cloud Security & Posture Management (CSPM) tells you about your vulnerabilities and misconfigurations.

  • Cloud Infrastructure Entitlement Management (CIEM) tells you who is entering a software environment. It tells you if these entrants are allowed and exactly what they can do.

  • Cloud Workload Protection (CWP) is a preventative measure to observe if anything bad is being done by entrants. This sounds the alarm bell while preventing and remediating cloud infrastructure attacks. It’s closely related to CSPM and CIEM.

  • Application Security Posture Management (ASPM) locates and facilitates the safe control of cloud apps.

  • Cloud Native Application Protection Platform (CNAPP) is the overall suite tying all of these cloud products together.

In the realm of GenAI, Charlotte AI is CrowdStrike’s security copilot. It levels up the capabilities of security analysts by actively detecting anomalies, orchestrating remediation and fixing issues in an automated fashion. It’s a force multiplier for efficiency gains in a world where most companies are starved for more security resources and talent. All of this pushes beginner-level security analysts to much higher levels of capability.

Falcon Flex:

Falcon Flex is CrowdStrike’s selling program to bolster customer “flex”ibility over product purchases. It allows clients to pay for only the modules they need as they need them. There are no preset commitments and no mandated usage; they can run through credits at their leisure. This will be the firm’s main go-to-market strategy going forward, as it has shown to lower cross-selling friction, raise deal size and create stickier customers.

Security Operations Center:

CrowdStrike’s wonderfully broad product suite gives it a fantastic opportunity to cross-sell more solutions and become the main security operator for its clients. This positioning is often called the “Security Operations Center” (SOC), where a client’s asset hygiene and protection happen under a main, interoperable, digital roof. Flex making product uptake more seamless is helping, alongside impactful product innovation across endpoint, cloud, identity, exposure management and data. Charlotte AI is also an “SOC’s best friend,” with impactful layers of incremental, actionable automation.

  • SOC-level adoption means more vendor consolidation and higher retention.

b. July 2024 Outage Reminder

Last July, a software update error led to a global outage caused by the company. That fostered considerable blowback against CRWD and the creation of its “Customer Commitment Packages” (CCPs). CCPs offer temporary contractual concessions to customers, such as discounting, extended free trials, comped modules and free professional services help. It’s their apology. CrowdStrike wanted customers to choose more products over extended free trials. Why? Their best-in-class customer service scores and product efficacy (as measured by 3rd parties) make them exceedingly confident in free modules turning into more paid adoption when CCPs expire later this year. 

That process has already begun to play out as hoped. Clients are predominantly opting into Falcon modules and positioning the company for easy up-selling as we move towards FY Q3 & Q4 2026. This is when the company will finish working through existing CCPs; it ended new CCP issuance last quarter. 

A lot of the CCP success can be seen within Falcon Flex, which is the mechanism CrowdStrike offered CCPs through. Customers seem to be loving this means of buying, as most of them are comfortably ahead of consumption plans in their given contracts. That should mean more usage-based revenue and larger deals in the future.

c. Key Points

  • No issues from worsening macro… cough cough SentinelOne.

  • Heightened confidence in previous financial forecasts.

  • Flex is thriving.

  • AI innovation is moving the financial needle.

d. Demand

There’s a strange item to note (related to CCPs) for FY 2026. The incentives CRWD offered entailed offering very little existing product discounting and instead offering its apologies through more products at better terms. Again, that was the goal. They have “seeded” their client base with highly popular and sticky tools, which is why the team is so upbeat on future financial performance (more later). At the same time, this means recognized subscription revenue and ARR aren’t as correlated as they’ve been to date. That will be temporary, as these incentives will go away and recognized revenue will mirror normalized run-rate. Still, that lowered subscription revenue by $11M during this quarter, and will do so by $10M-$15M during Q2, Q3 and Q4 of this year.

  • Slightly missed revenue estimate by 0.2% & slightly missed guidance by 0.1%.

  • Beat annual recurring revenue (ARR) estimate by 0.6%; beat net new ARR (NNARR) estimates by 10.9% ($194M vs. $175M expected).

    • NNARR also beat internal CrowdStrike expectations by more than 5.4%.

  • Beat remaining performance obligation (RPO) estimate by 10.0%.

Leadership called this a record quarter for large deal volume and managed security service provider (MSSP) momentum.

Competitive win rates are rising, per the team.

CrowdStrike incurs virtually all client costs when it onboards its first module with a new customer. Subsequent model purchases are essentially pure margin for it. As the trends above remain positive, the margin trends below will too. That’s not currently happening because of contractual concessions related to the July 2024 outage, but this is temporary (as laid out in the guidance section).

e. Profits & Margins

Note that contractual concessions from CCPs are still heavily impacting GAAP and FCF margins.

  • Slightly beat subscription gross profit margin (GPM) estimate by 10 basis points (bps; 1 basis point = 0.01%). Missed 77.8% GAAP GPM estimate by 4 points.

  • Missed -$87M GAAP EBIT estimate by $37M.

  • Beat EBIT estimate by 13% & beat guidance by 13.9%.

  • Beat FCF estimate by 8.3%.

    • FCF margin ex-outage charges was 30.9%.

  • Beat $0.65 EPS estimate by $0.07 & beat guidance by $0.08.

  • Missed -$0.33 GAAP EPS estimate by $0.11.

    • This includes a $40M charge from the July outage and CCPs. Without this, net loss would have been -$0.28 vs. -$0.33 expected.

f. Balance Sheet

  • $4.61B in cash & equivalents.

  • $744M in total debt.

  • Diluted share count rose by 1.8% Y/Y. Announced a new $1B buyback.

g. Guidance & Valuation

  • Reiterated annual revenue guidance, which slightly missed estimates by 0.3%.

    • Q2 revenue guidance missed estimates by 1%.

  • Guided to at least 6% Q/Q growth in NNARR or $205M.

  • Raised annual EBIT guidance by 2.7%, which beat estimates by 2.1%.

    • Q2 EBIT guidance beat estimates by 1.8%.

  • Raised $3.39 EPS guidance by $0.11, which beat estimates by $0.05.

    • $0.83 Q2 EPS guidance beat estimates by $0.02.

  • Q2 FCF will face a $29M headwind from the July outage headwinds.

As impacts from the July outage and CCPs begin to wane (following the ending of new CCPs offered), CrowdStrike is gaining more confidence not only faster NNARR growth in FY 2027, but also ramping growth throughout FY 2026.

CrowdStrike reiterated its path to $10B in ARR by FY 2031. Finally, it improved its margin recovery schedule. This was due to layoffs announced last month, as AI changes headcount needs in some areas and augments efficiency. That decision raised its FY 2027 EBIT margin target from 23%+ to 24%+ and its FCF margin target from 30% to 30%+.  It still expects to exit FY 2026 at a 27% FCF margin.

CrowdStrike trades for 135x forward EPS and 100x forward FCF. Profit will be heavily challenged this year as it finishes working through financial concessions stemming from the outage. As a result, EPS is expected to fall by 12% Y/Y while FCF is expected to grow by just 11%. For the following two years, EPS is expected to compound at a 33% clip while FCF compounds at a 40% clip. Profit growth estimates will likely rise following this report, but it will remain an expensive name; that has been the case since its IPO.

h. Call & Release

Macro:

What a shocker… as expected, CrowdStrike didn’t blame worsening macro for poor results like SentinelOne did. Instead, they spoke about “evolving conditions” and their ability to cut through the uncertainty with better product efficacy, more vendor consolidation, more cost savings and more customer success. Macro is not starkly different for SentinelOne and CrowdStrike; CrowdStrike is simply more capable of overcoming imperfect conditions. This quarter is more proof.

“I think we did a great job on execution. And with the right platform and solving the problems that we're solving, you know, we powered through it… the environment had a lot of noise and we powered through it.”

Founder/CEO George Kurtz

Platform Play & Flex:

The wonderful efficiency gains that customers enjoy from heightened point solution displacement is a secret weapon. As founder/CEO George Kurtz rightfully says, CrowdStrike offers elite product quantity AND quality.

While this product breadth and value gap isn’t new, CrowdStrike’s revamped Falcon Flex go-to-market is accelerating cross-selling trends even more. Total deal value for Flex rose 31% Q/Q and 6x Y/Y to reach $3.2B across 820 customers. These customers are landing with longer, larger deals and using more products than a typical CrowdStrike client does. For context, Flex customers average 9 modules; as you can see above, less than 33% of its overall client base has 7 modules.

And impressively, 39 Flex customers have already used up all contractual commitments and re-upped (or “re-flexed”) for more. On average, the 39 companies took 5 months to run through 36-month contracts. This is direct evidence of Flex accelerating platform-level adoption, experimentation and bolstering product traction across its entire suite. It’s motivating customers to shrink module expansion cycles from years to months and making CrowdStrike’s contracts even stickier than they already were. For a compelling example, one customer moved from a 3-year, $4M per year contract to a 5-year, $20M per year contract with Flex. And? They rapidly used all of their credits with more than 80% of the term remaining. As a result, they again doubled their annual spend. The customer started with Falcon EDR, and now uses endpoint, cloud, identity, SIEM and exposure management tools.

“Seeing our customers and ecosystem embrace Falcon Flex at this speed and scale gives me confidence in improving sequential net new ARR growth next quarter and accelerating back-half net new ARR.”

Co-Founder/CEO George Kurtz

AI Innovation:

CrowdStrike launched AI Agentic Response & AI Agentic Workflows during the quarter. These are not just your dime-a-dozen chatbots. They pull from CrowdStrike models and world-class 3rd-party reasoning models to make these products far more actionable. AI Agentic Response automates troubleshooting for analysts to expedite the source of breaches. It also reduces lateral threat movement (breaching one part and freely moving through the rest thereafter) and offers preferred next steps for fixing issues. The time savings are already palpable. Charlotte AI Agentic Workflows adds agentic reasoning to its Falcon Fusion Security, Orchestration, Automation and Response (SOAR) product to vastly deepen what automated workflows it can provide. No longer are these based on static if/then statements, but instead contextualized, nuanced workflows based on specific cases.

Both products will pair very nicely with Charlotte’s automated triaging service, which ranks severity of inbound risks to prioritize where to focus. They’ll both also mean protection gets more proactive, with more prevention and less clean-up. That has a way of saving customers meaningful dollars, while the added layers of automation do too. For these reasons, CrowdStrike sees this as a “leap forward” for becoming that modern SOC for its customers. Clients need a lot of help. Clients need the help to work. Clients need to make sure that help doesn’t coincide with exploding costs. Enter Falcon.

CrowdStrike sees the explosion of AI agents as creating another massive asset class needing protection. It is quickly building out the product suite with this in mine. It wants to be the “protector of autonomous AI agents.”

  • Added new scanning for GenAI models.

Exposure Management:

Exposure management is ensuring digital architecture is configured properly with sound hygiene and things like minimum access permission. Vulnerability Management helps uncover security weak spots, scores the urgency of these specific weak spots and offers best practices for fixing them. Attack Surface Management offers a birds-eye-view of all ecosystem entrances for potential adversaries, reducing the probability of gaining impermissible entry. This includes external and unknown assets and is rapidly displacing the need for some virtual machine use cases.

Exposure Management will be added to the 101 section next quarter, as it’s quickly becoming a large piece of the business. During the quarter, CrowdStrike added vulnerability scanning for networks, which it thinks was the remaining missing piece of that offering. The debut helped it land a large financial services deal for 120,000 devices.

Cloud Security:

NNARR growth accelerated vs. last quarter. Its ability to offer great cloud configuration and posture management tools and cloud work protection to actually stop breaches is resonating. This led to a 7-figure win with a tech company that doubled annual spend after they realized the massive difference between their old vendor just flagging an issue and Falcon actionably fixing it. It’s a lot more helpful to say “here’s the issue and we fixed it for you” than “here’s the issue go figure it out yourself.”

CrowdStrike added Falcon data protection for cloud environments and apps. This happens on the exact same sensor that its data protection tools use to protect other assets. Meaning? More coverage without more complexity or onboarding headache.

  • Recent M&A (probably Wiz and Alphabet) is emboldening CrowdStrike’s confidence in how large this business can become. 

Playing Well with Partners:

60% of deal value during the quarter was sourced from partners. MSSPs alone were 15% of total new business vs. around 5% just a couple of years ago. For a company that was once considered unwilling to play well with partners, that reputation has taken a complete 180-degree turn.

GuidePoint became CRWD’s 5th partner to cross $1B in total sales, while it launched a new MSSP program for its SIEM tool. This is also available for managed service providers.

For hyperscalers, CRWD was named the 2025 Google Cloud Security Partner of the Year, while it added Falcon Cloud Security to that marketplace. Alphabet is quickly turning into another AWS-level partner for CrowdStrike. More surprisingly, it also partnered with Microsoft to combine databases of assets and threat actors. The two are seemingly more willing to work together to help their large base of joint clients, despite Microsoft Defender being a direct competition for Falcon. They’re “working to find common ground.”

Finally, in what I think is the most impactful partner announcement of the quarter, CrowdStrike and Nvidia are tightening their relationship. Going forward, Falcon will be the “cybersecurity standard for securing Nvidia hardware and software. If it’s good enough for Jensen, it’s good enough for everyone.

  • Secured accolades from GigaOM (for XDR and Identity) and Forrester (top-ranked cloud innovation company).

Public Sector:

CrowdStrike received Federal Risk and Authorization Management Program (FedRAMP) High Authorization for the full Falcon Platform. This unlocks contracts from the Department of Defense and other highly important agencies.

They were asked about the May Bloomberg article calling out its potential involvement in a $32M Carahsoft deal for the IRS. The company has received requests for information from the DOJ and SEC regarding this and ARR recognition surrounding the July 19th outage. I do not expect this to amount to anything, as CrowdStrike and CFO Burt Podbere have pristine accounting reputations. Still, we must keep an eye on this to make sure it is a nothing burger.

More Product News:

  • Falcon debuted Privileged Access Management, which will directly compete with Okta’s offering. Falcon Privileged Access offers a minimum permission zero trust framework for granting access granularly and as needed. This displaces the need for 3rd-party integrations and led to a 7-figure deal with a foreign government.

  • Added 3rd-party data availability for managed threat hunting.

  • SIEM registered 100%+ Y/Y ARR growth and added service from its world-class threat hunting team to this product. To the team, this is a key unlock in its pursuit of SOC status with its customers.

Post July Outage Customer Sentiment:

“The customers have put it in the rearview mirror. We've moved forward, with our customers and partners… we're back to business in the areas that we've always focused on, which is really exciting for us.

i. Take

Good quarter. To me, very modest declines in Q2-Q4 revenue expectations were greatly overshadowed by fantastic ARR and RPO performances during the quarter. That shows us where this business will be once we’re through July 2024 outage noise by the end of this year. When pairing that with thriving Flex demand making it even more of a platform play in security, this company continues to execute at a special level. The faster margin recovery is important icing on the cake for this organization as it continues to profitably compound. While the CCPs will slow down FY 2026 numbers, the headwind will go away as we enter 2027 and this financial engine will magically snap back to what we’ve grown to expect. Thriving demand… thriving cross-selling momentum… massive opportunity… strong margin maintenance and expansion coming… beautiful balance sheet. And? Sky-high valuation.

I view CrowdStrike as a generational company. For this reason, I am not willing to sell the 2.1% stake I have in the company despite what I view as a valuation that’s ahead of itself. I’ve already taken considerable profits on this name already, and I have zero interest in cutting it from the portfolio. I would selfishly love for this quarter to be harshly punished so I can finally begin to add to my stake once more. We shall see.

Finally, this report and Zscaler’s quarter tell me that macro isn’t the issue hurting SentinelOne’s business. It’s execution. I will cut 40% of my SentinelOne stake tomorrow morning. Decision made. I will also cut the remaining 60% if their next quarter doesn’t look significantly better. 

Reply

Avatar

or to participate