SC

Cylance

Cylance convinced enterprise buyers that antivirus was broken and sold them one machine-learning product to replace it, but kept its data on each machine, so CrowdStrike, already installed beside antivirus with a cloud sensor, supplied the replacement and everything that followed.

Why Cylance lost to CrowdStrike

  1. 1 · 2012–16A model on the device, sold to replace antivirusCylancePROTECT judged files before they ran, and buyers had to take McAfee or Symantec out to use it.Product Leadership
  2. 2 · 2013–16Sold a prevention claim, not breach responseDemonstrations and heavy marketing persuaded buyers that antivirus was broken; response work stayed a side line.How to win
  3. 3 · 2016–17Detection data kept on each machineCylanceOPTICS arrived in May 2017 and worked without the cloud, so no shared record built up across customers.Multi-Product
  4. 4 · 2017–19Opened antivirus replacement for CrowdStrikeFalcon Prevent shipped on CrowdStrike's installed sensor; Cylance had two products and $130M revenue when it sold for $1.4B.
  5. 5 · 2019–24Flat under BlackBerry, resold for $160MRevenue barely grew in fiscal 2020 against a 25–30% plan; Arctic Wolf bought the business in 2024.

Versus CrowdStrike: CrowdStrike put a sensor beside antivirus that sent every machine's activity to its cloud, then switched on prevention and later products through that same agent CS5 CS13 CS3. Cylance sold one prevention model that ran on the device, and its later detection product kept the data on each machine CY1 CSX-2.

Arena: Market Conditions Before Cylance

Security teams protecting employee computers and servers · 2012 · United States and global enterprises

Changing technical requirementsEntrenched systems

In 2012 security teams protecting employee computers and servers relied on antivirus, most often from McAfee or Symantec, which compared each file with the signatures of malware already catalogued CY1 CS2. New malware and fast-changing variants outran the catalog, so attacks the signatures had not seen got through, and teams spent their effort investigating compromises afterward CY1. The products could also misfire: in 2010 a faulty McAfee update flagged a core Windows file as malicious and locked up Windows XP machines CS8. Replacing the incumbent was still a hard sell; Dmitri Alperovitch, who had come out of McAfee, compares it to IBM, which no one was fired for buying CS2. Teams wanted protection that stopped new threats before they ran, without blocking legitimate software or burying them in alerts CY1.

How each step happened

Step 1 of 5 · 2012–16

A model on the device, sold to replace antivirus

Prevention as the whole product

Stuart McClure founded Cylance in 2012 on a claim most of the industry had dismissed: that malware could be stopped before it ran, including files no vendor had seen before CY1. Signature tools could not do that. Cylance trained a machine-learning model to classify executable files from their mathematical properties instead of matching them against a catalog, and ran it on each device as CylancePROTECT CY1 CY2. The product went straight at the weakness customers could see in antivirus: its dependence on a constant stream of signature updates CY1.

The same choice set the first sale. A prevention product does the job the antivirus already on the machine claims to do, so Cylance asked buyers to take McAfee or Symantec out. Alperovitch, CrowdStrike's co-founder, says his company judged that replacing those vendors would take "an enormous amount of effort" and put it off CS2. Cylance took on that harder sale from the start, and in each customer's environment it had to show that the model blocked attacks without blocking legitimate software CY1.

Rivals CrowdStrike launched in June 2013 with a sensor that recorded activity and sent it to its cloud, sold beside antivirus; Alperovitch called it "additive" CS4 CS5. Its founders refused Windows XP support and on-premises builds and lost deals over both CS2.

Product Leadership

Step 2 of 5 · 2013–16

Sold a prevention claim, not breach response

Cylance's buyers had heard "better AV" pitches before CY1. Cylance answered with demonstrations: in controlled tests its model stopped files it had never seen, and a short prevention message made that technical difference clear to executives as well as security teams CY1. Alperovitch credits Cylance with spending "enormous amounts of money on marketing, sort of convincing people that AV was broken", which he calls "what you had to do" before a buyer would consider replacing McAfee or Symantec CS2.

It worked. By mid-2016 Cylance had more than 1,000 customers and a valuation of about $1 billion after a $100 million round, and both it and CrowdStrike projected about $100 million of sales for the year CSX-7 CSX-1. McClure said Cylance was beating CrowdStrike because CrowdStrike did nothing for prevention; Kurtz gave the credit to Cylance's marketing department and said most security companies already used machine learning CSX-1. That was the weakness of the pitch: it sold a category, and any vendor could adopt the same prevention language. Cylance also did breach response, cleaning up after the OPM breach, but it never made response the way it entered customers CSX-1.

Rivals CrowdStrike sold breach response first: Shawn Henry, after more than 20 years at the FBI, joined in April 2012 to run CrowdStrike Services CS6. Its response engagements began by installing its agent, and CrowdStrike says many response customers became subscribers CS15.

How to win

Step 3 of 5 · 2016–17

Detection data kept on each machine

Customers came to want more than a verdict on each file: they wanted to see what had happened on a machine and act on it CY3. Cylance added detection and response in May 2017 with CylanceOPTICS, sold as an extension of PROTECT CSX-2 CY2. It kept the data on each endpoint and did its forensic collection there, working independently of the cloud instead of streaming events to Cylance CSX-2.

The design followed from where Cylance started: a model that judged files on the device never needed a central record. The cost was that Cylance never gathered activity from all its customers' machines in one place. Kurtz describes CrowdStrike's order as the reverse: collect the data first, unlike competitors that started with prevention and, in his view, had to compromise on architecture as a result CSX-3. Cylance's later products had no shared record to start from.

Rivals CrowdStrike's sensors fed every customer's endpoint events into its Threat Graph, which by 2019 processed more than one trillion events a week CS3.

Multi-Product

Step 4 of 5 · 2017–19

Opened antivirus replacement for CrowdStrike

Cylance's marketing created the buying moment, and CrowdStrike was placed to take it. Alperovitch says that once CrowdStrike saw Cylance create the opportunity, it pushed its own antivirus product out "in record time" and then had "the full scope solution": antivirus plus what is now called endpoint detection and response CS2. In February 2017 CrowdStrike made Falcon Prevent, its antivirus replacement, a separate module on the agent that customers were already running beside antivirus CS13. A customer Cylance had persuaded to remove McAfee could get the replacement from a vendor already on its machines, together with detection.

Cylance still led on tests. In NSS Labs' February 2017 comparison it scored 99.69%, while CrowdStrike, which had sued to stop publication, scored 74.17% on an incomplete run CS14. But buyers were no longer choosing on one score. Cylance's line was PROTECT and OPTICS plus services CY2, and CrowdStrike's 2020 annual report grouped BlackBerry Cylance with "point products based on malware-only or application whitelisting techniques" CS15.

In November 2018 Cylance agreed to sell to BlackBerry for $1.4 billion in cash. It had raised nearly $300 million, reported more than $130 million of revenue for fiscal 2018, up more than 90%, and had over 4,000 customers CSX-4. The deal closed in February 2019 CY2. It ended the independent test of whether Cylance could grow from one prevention product into the broader set CrowdStrike was already selling.

Rivals CrowdStrike's annual recurring revenue (ARR) grew from $58.8 million in January 2017 to $312.7 million in January 2019 CS3.

Step 5 of 5 · 2019–24

Flat under BlackBerry, resold for $160M

Under BlackBerry, Cylance's first quarter brought $51 million of non-GAAP revenue, 30.8% more than the $39 million Cylance had recorded a year earlier CY2. Growth then stalled. Management had projected 25–30% growth for fiscal 2020; BlackBerry's chief executive, John Chen, described the year's revenue as only slightly up and the latest quarter as flat CSX-5. In the same period CrowdStrike grew quarterly revenue 84% to $199 million CSX-5.

The choices in steps 1 and 3 explain the stall. A product that judged files on each device, with its detection data kept there too, left Cylance nothing already installed and already collecting through which to sell the next product. CrowdStrike, whose agent already sent every event to its cloud, could switch a new module on without a new deployment, and its dollar-based net retention was 147% at the start of 2019 CSX-3 CS3. In December 2024 BlackBerry sold Cylance to Arctic Wolf for $160 million in cash plus about 5.5 million Arctic Wolf shares, to be folded into Arctic Wolf's Aurora platform CSX-6. The prevention model that made Cylance's name now serves as one part of another company's platform.

Rivals CrowdStrike kept adding products to the same agent; Kurtz says a new capability needs only a purchase order, with nothing to deploy CSX-3. Arctic Wolf bought Cylance to add endpoint protection to its own platform CSX-6.

Key dates

  1. 2012Cylance founded on a prevention thesis CY1
  2. 2012-04CrowdStrike Services opens under Shawn Henry CS6
  3. 2013Demonstrations against files the model had never seen CY1
  4. 2013-06CrowdStrike's cloud sensor launches beside antivirus CS4
  5. 2015Cleans up after the OPM breach CSX-1
  6. 2016-061,000 customers $100M round; valued at about $1 billion CSX-7 CSX-1
  7. 2016-07Both companies project about $100M of sales CSX-1
  8. 2017-02CrowdStrike ships Falcon Prevent to replace antivirus CS13
  9. 2017-02NSS Labs test: Cylance 99.69%, CrowdStrike 74.17% CS14
  10. 2017-05CylanceOPTICS keeps detection data on the endpoint CSX-2
  11. 2018-11$130M+ revenue Fiscal 2018, up 90%; 4,000+ customers CSX-4
  12. 2018-11Agrees to sell to BlackBerry for $1.4 billion CSX-4
  13. 2019-02BlackBerry completes the acquisition CY2
  14. 2019-05$51M quarterly revenue First quarter under BlackBerry (non-GAAP), +30.8% year over year CY2
  15. 2020Revenue slightly up against a 25–30% growth plan CSX-5
  16. 2024-12$160M plus stock Sold by BlackBerry to Arctic Wolf CSX-6

Sources

Oldest first.

  1. CS8 McAfee false detection locks up Windows XP. Brian Krebs / KrebsOnSecurity · 2010-04-21 Trade reporting
  2. CS6 Former FBI exec to head CrowdStrike Services. Steve Ragan / SecurityWeek · 2012-04-23 Trade reporting
  3. CS4 CrowdStrike launches big data active defense platform. CrowdStrike / PR Newswire · 2013-06-18 Primary source
  4. CS5 Do not call it a hack back: CrowdStrike unveils Falcon platform. Paul Roberts / The Security Ledger · 2013-06-19 Trade reporting
  5. CSX-7 Cylance raises $100 million to bring more A.I. smarts to cybersecurity. VentureBeat (Paul Sawers) · 2016-06-08 Trade report
  6. CSX-1 Duelling Unicorns: CrowdStrike Vs. Cylance In Brutal Battle To Knock Hackers Out. Forbes (Thomas Brewster) · 2016-07-06 Trade report
  7. CS13 CrowdStrike revamps Falcon security platform to replace legacy AV. Sean Michael Kerner / eWeek · 2017-02-13 Trade reporting
  8. CS14 CrowdStrike sues NSS Labs to prevent publication of test results. Kevin Townsend / SecurityWeek · 2017-02-15 Trade reporting
  9. CSX-2 Cylance Launches AI-Driven Endpoint Detection and Response with CylanceOPTICS. Dark Reading (Cylance release) · 2017-05-24 Company announcement
  10. CSX-4 BlackBerry to Acquire Cylance for $1.4 Billion in Cash. SecurityWeek · 2018-11-16 Trade report
  11. CY3 BlackBerry to acquire Cylance. BlackBerry · 2018-11-16 Investor presentation
  12. CS3 CrowdStrike Holdings Form S-1. CrowdStrike / SEC · 2019-05-14 Primary source
  13. CY2 BlackBerry acquisition of Cylance. BlackBerry / SEC · 2019-05-31 SEC filing
  14. CS15 Annual Report on Form 10-K, fiscal year ended January 31, 2020. CrowdStrike / SEC · 2020-03-23 Primary source
  15. CSX-5 BlackBerry Cylance acquisition performance (Motley Fool analysis). The Motley Fool (Herve Blandin) · 2020-09-29 Analyst article
  16. CSX-3 Platform versus Platformization: George Kurtz on why CrowdStrike is winning the platform battle. VentureBeat (Louis Columbus) · 2024-04-16 Founder interview
  17. CS2 Dmitri Alperovitch, co-founder of CrowdStrike (transcript). Inside the Network · 2024-05-02 Founder interview
  18. CSX-6 Arctic Wolf Buys Cylance for $160M Plus Stock From BlackBerry, Which Bought It for $1.4B. SecurityWeek (Eduard Kovacs) · 2024-12-16 Trade report
  19. CY1 Entrepreneur interview: Stuart McClure, Cylance. DFJ Growth / Stuart McClure · Undated Founder interview