SC

CrowdStrike

A sensor reporting to the cloud showed security teams the attacks their antivirus missed, and once it sat on every machine CrowdStrike could sell the rest of the security stack through it.

How CrowdStrike won

  1. 1 · 2011–14Cloud-only light sensor, installed beside antivirusNo server for the customer to run and no on-premises build; sold in 2013 as an addition to antivirus.Managed Service
  2. 2 · 2012–16Breach response as the tip of the spearAn incident-response practice under ex-FBI Shawn Henry came before the product; response customers became subscribers.Professional Services
  3. 3 · 2013–19Every endpoint's activity in one cloud recordAll sensors fed the Threat Graph, over a trillion events a week by 2019, and later modules reused it.Data Gravity
  4. 4 · 2017–21Full scope on one agent: antivirus replacement, then modulesCylance's marketing opened antivirus replacement; Falcon Prevent shipped on the installed sensor, and modules followed with nothing to deploy.Platformization
  5. 5 · 2019–Scope economies locked in by switching costs147% net retention in 2019; half of customers on six or more modules by 2026; retention held through the 2024 outage.Scope economies

Versus Cylance: Cylance convinced buyers to rip out antivirus with a single prevention product CS2 CY1. CrowdStrike was already on their machines with a cloud sensor, so it supplied the replacement and then sold everything after it through the same agent.

Arena: Market Conditions Before CrowdStrike

Security teams at large enterprises and government agencies · 2012 · United States first, then global

Changing technical requirementsHigh setup and upkeep costs

A security team protecting thousands of Windows machines ran antivirus that compared files against a catalogue of known malware, with management servers and consoles it operated on its own premises. Attacks written for a single target were not in the catalogue. In breaches investigated during 2012, intruders went unnoticed for a median of 243 days, and in 69% of confirmed breaches someone outside the victim found them first CS10 CS9. Each added defence meant another agent on every machine and another console to watch, and the agents carried their own risk: one signature update in April 2010 sent Windows XP machines around the world into reboot loops CS8.

How each step happened

Step 1 of 5 · 2011–14

Cloud-only light sensor, installed beside antivirus

Both founders came from McAfee: George Kurtz as chief technology officer, Dmitri Alperovitch as head of threat research CS3 CS35. They framed the purchase as defence against an adversary, not against malware. A light sensor recorded what happened on each machine and sent it to CrowdStrike's cloud for analysis, with no scheduled scans for users to feel and no management server for the customer to run CS1 CS4 CS35. The design needed every customer's data in one place, so the founders refused to build an on-premises version or to support Windows XP, and lost deals over both CS2.

McAfee could not follow. Kurtz says he proposed the idea there and it declined: its sales force and their pay were built around an antivirus product, and the company was being sold CS35. CrowdStrike had no antivirus business to protect, and did not ask buyers to give theirs up. At the June 2013 launch Alperovitch called the product additive, since antivirus was good for run-of-the-mill threats CS5; Kurtz says the first sale was visibility, installed beside whatever antivirus the customer already ran CS35. Falcon Host added prevention in November 2014, pitched as one sensor in place of the several agents a team had collected CS7. A sensor that asked the buyer to remove nothing got onto machines early, and every later step ran through it.

Rivals Cylance built CylancePROTECT, a machine-learning model that classified files before they ran, and sold it as a replacement for McAfee and Symantec, a harder first sale CY1 CS2. Symantec's own security executive had said antivirus stopped only about 45% of attacks CS11.

Managed ServiceDrop-In AdoptionCounter-positioningFounder Domain Expertise

Step 2 of 5 · 2012–16

Breach response as the tip of the spear

The response business started before the product and ran beside it. In April 2012, fourteen months before the sensor shipped, CrowdStrike hired Shawn Henry, who had run the FBI's criminal, cyber, response and services branch, to lead CrowdStrike Services CS6. Kurtz calls services the tip of the spear, and says he knew from his earlier company that in security a trusted services relationship turns into software sales CS35. The 2020 annual report agreed: incident response was a strong lead generation engine, and many response customers became subscription customers CS15.

Naming attackers made the same skill visible to buyers who never called. CrowdStrike named the groups it tracked, bears for Russian activity and pandas for Chinese, and showed breached executives who was on the other end CS35. In June 2016 it published its investigation of the Democratic National Committee network, naming two state-linked groups CS12. A buyer cannot test a security supplier's competence in advance. Watching it work through a breach is the closest substitute, and it put the sensor in front of buyers who had just been hurt.

Rivals Mandiant ran the larger response practice; Kurtz says big breaches are "pretty much us and Mandiant" CSX-3, yet Mandiant built no comparable endpoint subscription business CS10 CS11. Cylance also did response work, cleaning up after the OPM breach, but sold itself on a prevention claim backed by heavy marketing CSX-1 CS2.

Professional ServicesServices-Led EntryTrust

Step 3 of 5 · 2013–19

Every endpoint's activity in one cloud record

Because every sensor reported to one cloud, CrowdStrike held a single record of activity on all its customers' machines. The Threat Graph, a cloud graph database, processed over one trillion endpoint events a week by the 2019 listing and kept an index of them for later use CS3. Kurtz says the order was deliberate: "step one was to get data, as opposed to many of our competitors that were focused on prevention first" CSX-3. In Alperovitch's words, every customer contributes threat data to the cloud and all are protected as a result CS2.

The record paid off in what came next. The sensor already captured every process, file and network event, so a new capability could read data already collected. Falcon Discover, launched in February 2017, inventoried application use across a company from that data CS13. "We already have the data," Kurtz says CSX-3. Each customer's detections and history also built up in CrowdStrike's systems, which matters again in step 5.

Rivals Cylance started from prevention, with a machine-learning antivirus CS2. Its detection and response product, CylanceOPTICS, arrived in May 2017 and kept data on each endpoint, working "without requiring cloud connectivity", so there was no shared record to build later products on CSX-2.

Data Gravity

Step 4 of 5 · 2017–21

Full scope on one agent: antivirus replacement, then modules

Cylance created the replacement sale. Alperovitch says it "spent enormous amounts of money on marketing" convincing buyers that antivirus was broken, and CrowdStrike then got its own antivirus product out "in record time" CS2. Falcon Prevent shipped in February 2017 as its own module, with machine learning moved onto the sensor for offline protection, so one agent handled antivirus replacement, detection and response, and intelligence CS13. The subscription now took over a budget line the customer already paid. "We had kind of the full scope solution," Alperovitch says, and "that really just allowed us to take off" CS2.

After that the platform grew by switching on modules for customers already running the sensor. When CrowdStrike adds a capability, Kurtz says, the customer has to "sign a PO. There's nothing to deploy" CSX-3. The 2019 prospectus described this land-and-expand model: customers start with any number of cloud modules, ten at the listing, and CrowdStrike activates more on the same agent CS3. Some modules were bought; Humio's log management, acquired in 2021, was delivered through the same Falcon platform CS28. There were 32 modules by January 2026 CS16.

The Humio purchase closed in March 2021. CrowdStrike paid about $352 million in cash, net of acquired cash, plus $40 million in stock and options subject to vesting. The acquired technology added log ingestion and analysis across CrowdStrike and third-party data to support its expansion into extended detection and response CSMA-1.

Rivals Cylance scored well in a 2017 NSS Labs test that CrowdStrike tried to block in court CS14, but by 2020 CrowdStrike's filing listed BlackBerry Cylance among "point products based on malware-only" techniques CS15.

PlatformizationMulti-ProductLand and ExpandM&A Strategy

Step 5 of 5 · 2019–

Scope economies locked in by switching costs

The modules from step 4 made each new product cheap to sell, and the sensor from step 1 made the whole set hard to remove. For the customer, the next product needed no new agent, deployment or vendor review; for CrowdStrike, no new distribution CS3 CSX-3. Half of customers had four or more modules in July 2019, and by January 2026 half had six or more and a third seven or more CS29 CS17. Net retention, the growth of existing customers' subscriptions over twelve months, was 147% at the listing and 115% in January 2026 CS3 CS16. Annual recurring revenue (ARR) rose from $312.7 million in January 2019 to $5.25 billion in January 2026 CS3 CS17.

The July 2024 outage tested how hard the agent was to remove. A faulty content update to the Windows sensor, which ran inside the Windows kernel, crashed about 8.5 million machines CS19 CS33. In the first full quarter afterwards CrowdStrike reported gross retention above 97%, down less than half a point, while offering renewing customers extensions and discounts CS23 CS16. Leaving means a fleet-wide project that abandons detections, integrations and history, run while the organisation is less protected. That cost exists because of step 1: the light agent installed beside antivirus became the one thing on every machine.

Rivals Cylance had revenue above $130 million when BlackBerry agreed to buy it for $1.4 billion in 2018 CSX-4 CY2; its revenue was only slightly up in fiscal 2020 against a 25-30% growth plan CSX-5, and BlackBerry sold it to Arctic Wolf in 2024 for $160 million plus stock CSX-6. Microsoft is the harder test: it sells endpoint protection inside licences enterprises already hold and reported the largest share of IDC's modern endpoint category for 2024, 28.6% CS22.

Scope economiesSwitching costs

Key dates

  1. 2011-08Incorporated by two former McAfee executives CS3
  2. 2012-02Leaves stealth: an adversary problem, not a malware problem CS1
  3. 2012-04Incident-response practice under Shawn Henry CS6
  4. 2013-06Falcon cloud sensor ships, sold beside antivirus CS4 CS5
  5. 2014-11Falcon Host adds prevention: one sensor instead of several CS7
  6. 2016-06Publishes its Democratic National Committee investigation CS12
  7. 2017-02Falcon Prevent replaces antivirus on the same sensor CS13
  8. 2019-01$312.7M ARR January 31, 2019, +121% year over year; net retention 147%; 2,516 subscription customers CS3
  9. 2019-06IPO on Nasdaq with ten cloud modules CS15 CS3
  10. 2019-07Half of subscription customers on four or more modules CS29
  11. 2020-01$600.5M ARR January 31, 2020, +92% year over year CS15
  12. 2021-02Buys Humio for log management, delivered through the same platform CS28
  13. 2024-07Faulty update crashes about 8.5 million Windows machines CS19 CS33
  14. 2024-11Gross retention above 97% in the first full quarter after the outage CS23
  15. 2025-01$4.2B ARR January 31, 2025, +23% year over year CS16
  16. 2025-06Microsoft starts moving security products out of the Windows kernel CS21
  17. 2026-01$5.25B ARR January 31, 2026, +24% year over year; 32 modules; net retention 115% CS17 CS16

Sources

Oldest first.

  1. CS8 McAfee false detection locks up Windows XP. Brian Krebs / KrebsOnSecurity · 2010-04-21 Trade reporting
  2. CS1 Why CrowdStrike?. George Kurtz / CrowdStrike · 2012-02-21 Primary source
  3. CS6 Former FBI exec to head CrowdStrike Services. Steve Ragan / SecurityWeek · 2012-04-23 Trade reporting
  4. CS9 2013 Data Breach Investigations Report. Verizon · 2013-04-23 Independent research
  5. CS4 CrowdStrike launches big data active defense platform. CrowdStrike / PR Newswire · 2013-06-18 Primary source
  6. CS5 Do not call it a hack back: CrowdStrike unveils Falcon platform. Paul Roberts / The Security Ledger · 2013-06-19 Trade reporting
  7. CS7 CrowdStrike delivers next-generation endpoint protection. CrowdStrike · 2014-11-18 Primary source
  8. CS11 Strategic defence in cyberspace: beyond tools and tactics. Richard Bejtlich / NATO CCD COE · 2015-12-31 Academic analysis
  9. CS12 Bears in the midst: intrusion into the Democratic National Committee. Dmitri Alperovitch / CrowdStrike · 2016-06-14 Primary source
  10. CSX-1 Duelling Unicorns: CrowdStrike Vs. Cylance In Brutal Battle To Knock Hackers Out. Forbes (Thomas Brewster) · 2016-07-06 Trade report
  11. CS13 CrowdStrike revamps Falcon security platform to replace legacy AV. Sean Michael Kerner / eWeek · 2017-02-13 Trade reporting
  12. CS14 CrowdStrike sues NSS Labs to prevent publication of test results. Kevin Townsend / SecurityWeek · 2017-02-15 Trade reporting
  13. CSX-2 Cylance Launches AI-Driven Endpoint Detection and Response with CylanceOPTICS. Dark Reading (Cylance release) · 2017-05-24 Company announcement
  14. CSX-4 BlackBerry to Acquire Cylance for $1.4 Billion in Cash. SecurityWeek · 2018-11-16 Trade report
  15. CS3 CrowdStrike Holdings Form S-1. CrowdStrike / SEC · 2019-05-14 Primary source
  16. CY2 BlackBerry acquisition of Cylance. BlackBerry / SEC · 2019-05-31 SEC filing
  17. CS34 CrowdStrike positioned as a Leader in the Gartner Magic Quadrant for Endpoint Protection Platforms. CrowdStrike · 2019-08-23 Primary source
  18. CS29 Second quarter fiscal 2020 financial results. CrowdStrike / SEC, Form 8-K Exhibit 99.1 · 2019-09-05 Primary source
  19. CS15 Annual Report on Form 10-K, fiscal year ended January 31, 2020. CrowdStrike / SEC · 2020-03-23 Primary source
  20. CSX-5 BlackBerry Cylance acquisition performance (Motley Fool analysis). The Motley Fool (Herve Blandin) · 2020-09-29 Analyst article
  21. CS28 CrowdStrike to acquire Humio. CrowdStrike · 2021-02-18 Primary source
  22. CSMA-1 CrowdStrike Completes Acquisition of Humio. CrowdStrike · 2021-03-05 Company announcement
  23. CS10 M-Trends 2021. FireEye Mandiant · 2021-04-13 Independent research
  24. CS35 Building a $65B Company: The Thesis and Operating Principles That Built CrowdStrike — George Kurtz. The Logan Bartlett Show · 2024-01-19 Founder interview
  25. CSX-3 Platform versus Platformization: George Kurtz on why CrowdStrike is winning the platform battle. VentureBeat (Louis Columbus) · 2024-04-16 Founder interview
  26. CS2 Dmitri Alperovitch, co-founder of CrowdStrike (transcript). Inside the Network · 2024-05-02 Founder interview
  27. CS30 Decoding the MITRE Engenuity ATT&CK enterprise evaluation. Shen, Li, Burleigh, Wang and Chen / AsiaCCS 2024 · 2024-07-01 Academic analysis
  28. CS33 Microsoft says 8.5M Windows devices were affected by CrowdStrike outage. TechCrunch · 2024-07-20 Trade reporting
  29. CS19 Falcon content update preliminary post incident review. CrowdStrike · 2024-07-24 Primary source
  30. CS18 Channel File 291 incident root cause analysis. CrowdStrike · 2024-08-06 Primary source
  31. CS26 Form 8-K, Item 7.01, July 2024 operational disruption. Delta Air Lines / SEC · 2024-08-08 Primary source
  32. CS24 CrowdStrike: the consequences of the IT outage for German companies. BSI and Bitkom · 2024-09-19 Independent research
  33. CS20 Written testimony of Adam Meyers before the Subcommittee on Cybersecurity and Infrastructure Protection. US House Committee on Homeland Security · 2024-09-24 Congressional record
  34. CS23 Third quarter fiscal 2025 earnings call transcript. CrowdStrike / The Motley Fool · 2024-11-26 Earnings transcript
  35. CSX-6 Arctic Wolf Buys Cylance for $160M Plus Stock From BlackBerry, Which Bought It for $1.4B. SecurityWeek (Eduard Kovacs) · 2024-12-16 Trade report
  36. CS25 Judge allows Delta lawsuit against CrowdStrike to proceed. The Register · 2025-05-21 Trade reporting
  37. CS21 The Windows Resiliency Initiative. Microsoft / Windows Experience Blog · 2025-06-26 Primary source
  38. CS22 Microsoft ranked number one in modern endpoint security market share. Microsoft · 2025-08-27 Vendor claim
  39. CS17 Fourth quarter and fiscal year 2026 financial results. CrowdStrike / SEC, Form 8-K Exhibit 99.1 · 2026-03-03 Primary source
  40. CS16 Annual Report on Form 10-K, fiscal year ended January 31, 2026. CrowdStrike / SEC · 2026-03-05 Primary source
  41. CS27 Quarterly Report on Form 10-Q, quarter ended April 30, 2026. CrowdStrike / SEC · 2026-06-04 Primary source
  42. CY1 Entrepreneur interview: Stuart McClure, Cylance. DFJ Growth / Stuart McClure · Undated Founder interview
  43. CSX-8 CrowdStrike case study. Warburg Pincus · undated Investor account