Table of Contents

1. Dell & Workday — Brief Earnings Snapshots

a. Dell

Results:

  • Missed revenue estimate by 1.2% & missed guidance by 0.4%.

  • Beat $2.00 EPS estimate & beat identical guidance by $0.15 each.

  • Missed $1.40 GAAP EPS estimate by $0.18.

  • Missed $1.3 billion free cash flow (FCF) estimate by about $600 million.

  • Missed 22.3% gross profit margin (GPM) estimates by 50 basis points (bps; 1 basis point = 0.01%).

ISG = Infrastructure Solutions Group; CSG = Client Solutions Group

ISG = Infrastructure Solutions Group; CSG = Client Solutions Group

Balance Sheet:

  • $6.6 billion in cash & equivalents.

  • $25 billion in total debt.

  • Stock comp dollars fell 13% Y/Y. Guided to about 0.2% Q/Q dilution.

  • Dividends rose 17% Y/Y.

Guidance & Valuation:

Q4 revenue guidance missed by 2.8% while $2.50 Q4 EPS guidance missed by $0.14. It lowered annual growth forecasts from 10% Y/Y to 9% Y/Y. It raised its annual EPS guidance by a penny due to the Q3 beat.

EPS is expected to compound at a 16% clip over the next two years.

b. Workday

Results:

  • Slightly beat subscription revenue guidance by 0.2%.

  • Beat revenue estimates by 1.4%.

  • Beat 25.5% EBIT margin estimates by 80 bps & beat 25.3% EBIT margin guidance by about 100 bps.

  • Beat $1.76 EPS estimates by $0.13.

  • Missed $508 million operating cash flow (OCF) estimates by about $100 million. This metric is very lumpy on a quarterly basis.

Balance Sheet:

  • $6.2B in cash & equivalents.

  • $3 billion in debt.

  • Diluted share count rose by 0.8% Y/Y.

Guidance & Valuation:

  • Lowered Q4 subscription revenue guidance by 0.8%, which represents a slight lowering of annual revenue guidance.

  • Slightly lowered Q4 EBIT margin guidance, but reiterated full year margin expectations.

EPS is expected to compound at a 19% clip for the next two years.

2. CrowdStrike (CRWD) – Detailed Earnings Review

a. CrowdStrike 101

CrowdStrike is a next-gen, cloud-native endpoint cybersecurity company. It competes directly with SentinelOne, Microsoft Defender and Palo Alto. Its bread-and-butter is called endpoint detection and response (EDR), which replaces legacy anti-virus (AV). Beyond EDR, it offers applications in cloud security, log management, forensics, identity, data protection etc. to round out its “Falcon Platform.” Falcon’s edge is in its ability to digest near-endless amounts of data to automate and uplift breach protection. CrowdStrike uses its large and diverse dataset to constantly improve Falcon’s efficacy and use cases… all with a single console and single agent to ensure superior interoperability. It can recycle this same data over and over again to efficiently develop new products for a single interface. More utility without adding complexity or cost.

Important Endpoint Security Acronyms:

  • Endpoint detection and response (EDR) provides end-to-end visibility, constant monitoring and full protection of endpoints (like a company iPhone). It unveils, prioritizes and responds to over-served threats.

  • Managed detection and response (MDR) encompasses CrowdStrike’s team of threat hunters to augment EDR with human touch when needed.

  • Extended detection and response (XDR) is EDR with 3rd party, non-endpoint data sources infused. The incremental data sharpens breach protection and extends it beyond the endpoint.

Important Log Management Ideas & Acronyms:

CrowdStrike’s security data lake is a vital complement to every single product it offers. It uses log scale to ingest, logarithmically organize and store data. Broader data ingestion means better breach protection, as Falcon’s products are more properly trained on larger sets of relevant insight. CrowdStrike also says customers get lower cost and faster querying speeds with it. This allows for ingestion with more scale and faster time to value.

  • As an important aside, Log Scale is a key ingredient for Falcon XDR. It is instrumental in XDR being able to onboard needed data sources in a scalable and efficient manner.

  • Security Information and Event Management (SIEM) aggregates security logs/data to help organizations uncover and remediate threats faster. Log Scale is closely related to SIEM, as Log Scale is what actually collects data from various sources to be utilized here.

Important Cloud Security Acronyms (alphabet soup, I know):

  • Cloud Security & Posture Management (CSPM) tells you about your vulnerabilities and misconfigurations.

  • Cloud Infrastructure Entitlement Management (CIEM) tells you who is entering a software environment. It tells you if these entrants are allowed and exactly what they’re allowed to do.

  • Cloud Workload Protection (CWP) is a preventative measure to observe if anything bad is being done by entrants. This sounds the alarm bell while preventing and remediating cloud infrastructure attacks. It’s closely related to CSPM and CIEM.

  • Application Security Posture Management (ASPM) locates and facilitates the safe control of cloud apps.

  • Cloud Native Application Protection Platform (CNAPP) is the overall suite tying all of these cloud products together.

In the realm of GenAI, Charlotte AI is CrowdStrike’s security copilot. It levels up the capabilities of security analysts by actively detecting anomalies, orchestrating remediation and fixing issues in an automated fashion. It’s a force multiplier for efficiency gains in a world where most companies are starved for more security resources and talent. All of this pushes beginner-level security analysts to much higher levels of capability.

b. Demand

CrowdStrike crossed $4 billion in annual recurring revenue (ARR) in record speed for pure-play cybersecurity companies during the quarter.

  • Beat revenue estimates by 2.8% & beat guidance by 3%.

    • Its 31.9% 2-year revenue compounded annual growth rate (CAGR) compares to 34.2% Q/Q & 37.4% 2 quarters ago.

    • Subscription revenue rose by 31% Y/Y.

  • Beat ARR estimates by 0.6%.

    • ARR was cut by $26 million due to a current federal government contract that it doesn’t think will be renewed.

  • Beat net new ARR (NNARR) estimates by 7%.

  • Beat remaining performance obligation (RPO) estimates by 8%.

  • Competitive win rates were “stable to trending up” Q/Q.

It’s great to see gross revenue retention (GRR) stay resilient following the July outage. That goes to show how sticky, beloved and valuable this platform truly is. Customers stayed with them. While it did fall a bit Q/Q and Y/Y, that’s as expected and 97.5% remains great.

c. Profits & Margins

  • Beat EBIT estimates by 3.3% & beat guidance by 4.1%. July outage concessions were a large margin headwind while more R&D and customer support investments hurt margins a tad too.

    • It remains confident in reaching margin targets by fiscal year 2029.

  • -$56 million in GAAP EBIT missed -$33 million estimates due to a $34 million charge from the July outage.

  • Met subscription gross profit margin (sub GPM) estimates.

  • Beat free cash flow (FCF) estimates by 5.6%.

  • Beat $0.81 EPS estimates & beat identical guidance by $0.12 each.

d. Balance Sheet

  • $4.26 billion in cash & equivalents.

  • $743 million in low-cost debt.

  • Diluted share count rose by 2.8% Y/Y.

e. Guidance & Valuation

Q4 Guidance:

  • Slightly beat Q4 revenue estimates & slightly beat its identical revenue guidance.

  • Slightly missed Q4 EBIT estimates & slightly beat EBIT guidance.

  • Slightly missed Q4 $0.86 EPS estimates & EPS guidance by $0.01 each. It would have beaten by a penny ex-M&A.

  • It assumed a $30 million ARR and revenue headwind from the July outage response in its Q4 guidance.

  • On track to reach its $10 billion ARR vision.

  • On track to deliver a growth re-acceleration during the second half of next year. Pipeline activity is informing this confidence… not hoping… reacting to data.

CFO Burt Podbere offered extremely rare commentary on sell-side analyst forecasts for Q4. He never does this. He hinted at these estimates being too high, and needing to bake in more prudence. While that’s never great to hear, I think this is solely a matter of CRWD leaning overly cautious in the wake of uncertainty. It always guides conservatively and this summer’s event makes doing so a lot more appealing. Customer commitment packages (CCP) (more later) are creating up-selling and revenue retention headwinds and overall revenue visibility remains limited. While it’s very encouraged by how customers are reacting to CCP (going with more product over free trials), CrowdStrike did not want to assume this would continue in Q4. It’s essentially baking in a sharp negative divergence in customer behavior with no data-driven reason for doing so. Meaning? I think it’s just setting itself up for another quarter of large outperformance.

EPS is expected to compound at an 18% clip for the next two years. This is one of the most expensive names in markets, but that’s largely related to the July 2024 outage greatly holding back results through most of next year. EPS growth is expected to accelerate back towards 25%-30% Y/Y thereafter (so still expensive).

f. Call & Release Highlights

Outage Aftermath — Qualitative:

  • Falcon Flex: CrowdStrike’s selling program to bolster customer “flex”ibility over product purchase design. It allows these customers to pay for only the modules they need as they need them. There are no pre-set commitments and customers are not locked into product usage.

    • As an aside, the mixing-and-matching make-up of Flex means customers don’t need to wait for competing vendor contracts to expire to embrace CRWD. They can simply use whatever modules they want and shift (or add) Flex dollars to Falcon later on.

  • Customer Commitment Packages (CCP) Definition: This uses Falcon’s traditional module selling process, but incorporates Flex’s pricing and contractual flexibility too. It offers a diverse series of bundles (with some comped services) and the ability for customers to lock in favorable pricing on a multi-year basis.”

    • CCP perks include straight discounting, extended free trials and temporarily comped modules.

So far, the Flex and CCP responses to the July 19th outage are working exactly as planned. Again, customers are choosing more product over extended free trials. This is so immensely important. Why? It means CrowdStrike is becoming an even stickier, more leaned-on vendor for these companies, which will be great for retention, lifetime value and every piece of its financial statements. Its post-July approach is accelerating vendor consolidation and its overarching platform push by incentivizing customers with more favorable per-product terms. Over the long haul, these favorable terms will fade away, while we’re left with an even more mission-critical cybersecurity platform doing more revenue per client.

It’s hard to overstate how well leadership handled the large blunder from this past summer. CrowdStrike shaped its concessions in a way that turned this into the most positive thing it could possibly be. The accountable response is night and day compared to how others like MSFT and Okta handled issues in the past. CrowdStrike’s c-suite is full of stars who made customers feel supported and taken care of. It’s no coincidence that these customers now feel inspired to take care of CrowdStrike and do even more with them.

“We saw incredible success with our customer commitment packages as customers embraced the program and chose to deepen their relationship with CrowdStrike.”

CFO Burt Podbere

Outage Aftermath — Quantitative:

Quantitatively speaking, the CCP hit to net new ARR was $25 million as expected, while 50%+ of the deals that were delayed from the July blunder have now been closed. Total deal value (TDV) from Flex rose from $700 million to over $1.3 billion Q/Q as CCP accelerated deal velocity.

And we have more evidence of CCP and Flex working as planned to create more reliant CRWD customers and a larger long-term opportunity. An average Flex customer uses 9 modules, which is over 2x the rate of an average customer. Relatedly, the flexible bundle solutions across endpoint, cloud, identity etc. are materially expanding wallet share. Favorable customer terms are pushing enterprises to race to adopt more CRWD products while these terms remain in place. And again, discounts will eventually disappear… the clients won’t.

  • Considering all of this discounting context, the very modest 30 bps GPM decline Y/Y is notably positive.

All in all, Flex customers are delivering a couple million in ARR, which is roughly 10x larger than its overall customer base. Management is confident in Flex growth accelerating, which supports its optimism in a back half of calendar 2025 ARR re-acceleration.

Still, there are negative impacts from the outage to discuss. GRR fell from roughly 98% to 97.5% while net revenue retention (NRR) continues to be below its 120% target, with a 115% result this quarter. Both are directly impacted by discounting, free trials and a 15% Y/Y sales cycle elongation stemming from the July event.

  • Its new Adaptive Shield purchase (more later) immediately prompted customers to ask if their Falcon Flex credits can be used for its products. They can be. Just another example of Falcon’s platform and go-to-market approach turbo-charging enterprise adoption for all of its products… organically developed and externally purchased.

  • The remaining CCP deals for affected clients will conclude over the next couple quarters.

  • Flex helped make this CRWD’s largest quarter ever for $1 million+ deals.

Adaptive Shield M&A:

CrowdStrike bought Adaptive Shield to expand its identity security suite. Falcon is comprehensive in on-premise identity-based security and active directory, but perhaps a bit less advanced in SaaS-level identity security. This gives them that SaaS muscle to provide what it calls the “only platform to unify Cloud & ID security with integrated SaaS protection. Specifically, Adaptive Shield provides SaaS Security Posture Management (SSPM) to identify improper hygiene and misconfigurations for cloud-based software. CrowdStrike’s willingness to spend $300 million indicates more confidence that the residual liability of the July outage is manageable.

Adaptive Shield’s SSPM “leadership” is also expected to augment endpoint protection, and its CNAPP suite. Specifically, leadership thinks this gives them the “broadest cloud security coverage” in the market. From cloud-native code to data and apps, CrowdStrike now offers a holistic cloud suite that doesn’t just help with hygiene and configuration (like many do), but actual runtime protection (a lot more rare today). Many of the needed integrations from this purchase have already taken place.

CrowdStrike Financial Service (CFS):

CFS is CrowdStrike’s internal financing division. It closed $49 million in deal value and contributed multiple 8 figure deals as well. One of these deals was for SIEM and carried a seven-year term as a direct result of CFS. This product is helping CrowdStrike “align with CFOs” more tightly than ever before. CFOs love minimizing cash outlays, like financing helps to accomplish.

  • The program has a minimal impact on FCF generation, with most of the quarterly weakness there stemming from CCP.

(Agentic) AI and Cybersecurity:

While CrowdStrike isn’t using the “Agentic AI” term like every other peer is, it thinks it set the trend and innovation curve here. Charlotte AI is “not just a chat bot.” It’s fully able to take complex, multi-step remediation action on behalf of security analysts. It’s equipped to do this in an autonomous, goal-oriented way that requires virtually no customer coding or concrete instruction. This capability is guided by CrowdStrike’s gigantic threat graph and the trillions of security events in that system of record to train Charlotte AI and drive genuine model inference. Just tell it what you want… and it will deliver. As a needed caveat, these use cases are still somewhat limited but continue to rapidly proliferate.

For one customer, Charlotte AI cut time to create security reports from 48 hours to 1 hour. That helps explain why Charlotte AI continues to enjoy 100%+ Y/Y growth (still probably a small revenue base).

As announced at Fal.Con, CrowdStrike debuted AI-generated parsers for data log management. AI parsers pull from GenAI models to automate data extraction and pattern creation from raw logs as data is ingested. Insights lead to new parser creation and parser enrichment from previous findings. This all means the process of data ingestion, processing and analysis is constantly improving and allows companies to find extremely subtle issues missed by analysts. In turn, that lowers false positive rates and helps mightily in threat detection, software performance optimization etc. This up-levels a customer’s ability to seamlessly use their data in the Falcon environment, or, as Kurtz puts it, just makes ingestion “easier and better.”

  • AI Investigator is its tool to expedite “analyst learning curves.”

  • AI alert triage fully automates and sharpens risk prioritization.

  • CrowdStrike is now actively testing large language models to “reduce exposure, weaknesses and data leakage risk.”

“We do AI for security and security for AI… Much like peer companies such as ServiceNow and Salesforce, we're using advanced AI models to deliver proactive and autonomous outcomes.”

Founder/CEO George Kurtz

Customer Wins:

  • 8 figure deal with an AI Unicorn for its endpoint suite and CNAPP. Falcon’s broad, unified, utility-building suite was the deciding factor.

  • Fortune 50 retailer expanded its Falcon usage with a new 8 figure deal for cloud security (already an endpoint customer). Its runtime protection prowess was the difference-maker.

  • Identity protection was credited for another Fortune 500 win, to offer evidence of this product being a capable top-of-funnel tool.

  • SIEM is emerging as another powerful top-of-funnel winner. It netted an 8 figure deal with a healthcare provider.

  • 8 figure new customer win with a global technology manufacturer leader. It was already “all in” on CrowdStrike endpoint and its MDR product. Now it’s using CRWD for SIEM and replaced 4 point solution vendors during the process of migrating.

  • Flex + CFS led to a $15 million upsell for an existing client.

  • This was CRWD’s best ever selling quarter for customers with 2,5000 or fewer employees.

Partnerships:

70% of all net new ARR this quarter was partner-sourced. Its work with global system integrators (GSIs) and cloud titans like AWS is working quite well. Specifically, AWS deal value rose by over 100% Y/Y. It has done $1 billion in total deal value through AWS since inception of this partnership, so the revenue base here is not that small.

It also announced a new partnership with Fortinet to combine that firm’s firewall-based network security approach with CrowdStrike’s endpoint suite. Fortinet is likely feeling the need to match product expansion from other firewall vendors like Palo Alto. This is an easy way to do that for them, and has already yielded more deal inclusion for both new partners. While software and zero trust are replacing a firewall hardware-based approach for network security, there is still revenue to be enjoyed from this aging technology. Finally, its managed security service provider (MSSP) program enjoyed 100%+ Y/Y growth. SHI (IT service provider) became its 4th MSSP to cross $1 billion in deal volume.

  • Deepened its AWS and Nvidia partnership to support a secure GenAI technological boom.

  • Extended its 1Password partnership.

  • Added a new partnership with Omnissa to cover real-time threat detection and automated remediation for both virtual and physical desktop endpoints.

Final Notes:

  • First $1 billion revenue quarter.

  • SIEM net new ARR accelerated to 150% Y/Y as this product reached $200 million+ in scale.

  • Accolades this quarter included Gartner endpoint recognition, where it was ranked first in vision and execution (just like last year). Frost Radar named it a CWP leader for the second straight year; GigaOm named it a CNAPP leader; Forrester Wave named it an Attack Surface Management leader; IDC names it an SIEM “major player.”

g. Take

All things considered, I thought this quarter was admirable. Despite CrowdStrike’s elite technology (the outage wasn’t a security breach) and go-to-market engine, July could have turned into something far worse. It could have been a massive balance sheet drain… it could have permanently diminished company trust… it could have durably impacted CrowdStrike’s world-class financial engine. But none of that is happening. Why? George Kurtz and Burt Podbere (and the whole team) are fantastic at their jobs. As I said earlier, they took a terrible situation and made the absolute best of it. They took spoiled lemons and made decent-tasting lemonade.

As I said in the portfolio earnings preview, I was quite cautious heading into this quarter. The outage does hurt visibility and near term results, yet the multiple had already raced back to multi-year highs. I am eager to add back more shares that I sold near $400 in June (lucky timing and a reaction to multiple expansion) and near $300 in July. This remains one of my biggest winners since inception; I’d love to again own a lot more of this special company at more reasonable multiples. It isn’t there today.

Reply

Avatar

or to participate