CrowdStrike Holdings, Inc. (CRWD)
NASDAQ: CRWD · Real-Time Price · USD
206.74
-2.12 (-1.02%)
At close: Sep 11, 2026, 4:00 PM EDT
206.41
-0.33 (-0.16%)
After-hours: Sep 11, 2026, 7:59 PM EDT
← View all transcripts

Goldman Sachs Communacopia + Technology Conference 2026

Sep 10, 2026

Summary

Major product launches included SafeMind for continuous pen testing and Guardian for AI agent security, both leveraging proprietary data and advanced AI models. Security budgets are rising as enterprises accelerate AI adoption, with modernization and compliance driving demand for next-gen solutions. Deep partnerships and a strong data moat underpin technology differentiation.

Gabriela Borges
Analyst, Goldman Sachs

Hey, good afternoon. For those of us who have been at the conference for the last couple of days, the number of thought leaders in AI on this stage who have talked about cybersecurity, we're pretty much batting 10 out of 10. Really excited to have George Kurtz, CEO and Co-Founder of CrowdStrike, on stage with me. George, thank you for being here.

George Kurtz
CEO and Co-Founder, CrowdStrike

Great to be here.

Gabriela Borges
Analyst, Goldman Sachs

George, I want to start off with some of the most exciting announcements at Fal.Con From last week, because as far as industry conferences go, the combination of having Jensen, thought leaders from Anthropic, OpenAI, all of the enterprise customers in one place, along with, I think it was 11,000 customers.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

It was really a different level of conference than what we've seen before. I want to start with one very specific announcement that you announced, which was SafeMind.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

To bring the audience up to speed, SafeMind is CrowdStrike taking Nemotron and applying it to very specific proprietary CrowdStrike data to create a continuous penetration testing loop. George, maybe I'll turn it over to you. Tell us a little bit about the evolution of this idea and why it's important.

George Kurtz
CEO and Co-Founder, CrowdStrike

Sure. It was a fantastic event. We had over 10,000 customers. It became really an industry conference, and we were lucky enough to have Jensen and Lip-Bu Tan and Brockman there, and others. It was great from that standpoint. I think when you look at SafeMind, it goes well beyond the models, right. We think about it as really an agentic system, which consists of the models and the harness. It's very important to put those together. If I was to distill it down into three areas, you have a red model, which is the offensive model, Red Tempest, and you have a blue model, Blue Solano, which is our defensive model, and then you have a harness that works in combination with that.

I would say, I don't know, maybe six-plus months ago, I sat down with Jensen, and we were talking about security and really the conversation was, we need to do something to provide defenders with what they were lacking and give them sort of a fighting shot in the agentic world that we live in today. They're great partners, and part of what we did was we started the Cyber Superintelligence Lab led by Bartley Richardson, who came from NVIDIA, so that kind of helped. The whole idea was how do we work in tandem with NVIDIA to leverage the Nemotron models, these multiple ones, but Nemotron 3 Ultra, and basically create something that was bespoke for CrowdStrike and its rich data set and its history of collecting all this data.

The whole idea, just to summarize, and we'll get back to the questions here, is with the harness and with the red and the blue models, you have this continuous loop where the defense is always learning from the offense. One of the things, and Jensen was insistent on it, which was like, we need to have a digital twin because we talked about all the other areas in technology driving robotics that have digital twins so that we can very quickly simulate this environment. It can run in a digital twin or it can run in the real world.

Gabriela Borges
Analyst, Goldman Sachs

I want to put two potential bottlenecks in front of you on SafeMind adoption going exponential.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yeah.

Gabriela Borges
Analyst, Goldman Sachs

The first is CISOs are a pretty conservative bunch.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

We've been talking about automating the SOC for a really long time, it's still like pulling teeth. How do you get CISOs comfortable with something as important as pen testing being automated in a continuous loop?

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, I think it starts with we were on the system, so we already know what the systems are. We already know the identities. We already know the exposures, the patch levels, the vulnerability management aspect of it. We built an incredible digital twin. Sometimes you call it a digital cousin. Everything's not exact, but basically it allows us to very quickly simulate what that environment looks like. I think that's the first part in getting people comfortable with these sort of technologies. Now, if you want to leverage this internally or you want to leverage it externally and you want to just consume the models directly, you're going to be able to do that for companies that are part of our Project QuiltWorks trusted access program.

But within the technology itself, there will be some guardrails around it, but the digital twin will serve as a way to really very quickly simulate what could happen, and that is very exciting and important for customers.

Gabriela Borges
Analyst, Goldman Sachs

The other pushback that we have heard just in the last week or so is, okay, well, if you look at the publicly available Nemotron benchmarks, they are not on the frontier. There is a progression that will happen over time here, but why does that not matter for CrowdStrike to have an incredibly performant frontier model solution or a cyber frontier model?

George Kurtz
CEO and Co-Founder, CrowdStrike

We are not trying to solve the millennium math problems, right? We are trying to solve is the hardest security problems, and Nemotron is very good for our purposes. The key, as I mentioned, is the training, the data with the harness. Even if you take our harness and you apply it to any of the frontier models, we actually get better results. When you put those in combination and you actually spend the time to do the training and really adjust it for what we wanted, you get fantastic results for the security use case. I think you have been a big proponent of these sort of verticalized type models that you have written about in the past, and I think there is a lot of opportunity. Open weight, I think is really part of the future. Now for customers, they will have choice.

We have got partnerships I know we will talk about with Anthropic and OpenAI. That will be available through the platform. You want to use our models, fantastic. But you can consume it through our harness or you can consume it through MCP. Obviously we have got a monetization strategy around tokens to be able to do that. If you look at the benchmarks that we put out, we have not tested it against Astra, but we were getting as good or better performance for a much, much lower price. What we talked about was a remediation in a frontier model was about $10 for that remediation activity, and in ours it was $0.03 with the same results because of the way we have built it and the way we can operate it.

I do think open weight will have a massive impact on the entire AI industry, and one of the reasons why we're proponents, and I know Jensen was up here earlier, but when he came to our conference, he basically said we are the poster child for why they built Nemotron and sort of the partnership with NVIDIA to get it to the place. We shortcutted a lot of time because of the relationships and understanding how their models work, where we didn't have to figure it all out from scratch. They provided what we needed.

Gabriela Borges
Analyst, Goldman Sachs

Jensen earlier, he was incredibly bullish on the CrowdStrike opportunity. But one other thing he said that I want to pick your brain on is he talked about the commercial opportunity for frontier labs in security. I know that that can be via partnership, as you just alluded to. How do you think about the risks that the frontier model swim lane converges with the security swim lane over the medium term?

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, there's always going to be a role, and I think you have to look at where these models are really good and where it all kind of interplays with security. First, when you look at these models, they've come a long way. They're incredible just from January to where we are today and what they can do. And there will always be a role and success for both frontier and for companies like CrowdStrike. I had dinner with Marco, your CIO at Goldman last night. A very sharp guy. I think he might have been around on stage, I'm not sure, but incredibly sharp.

We talked about the roles and being a Formula One guy, he sort of said, "Look, if I need Formula One sort of results in the most critical areas of alpha, and I don't care about the money I spend, I'm going to go to the frontier." But his comment was, for all the other things, I'm going to leverage these sort of open weight models, and that makes a lot of sense to me. When you look at Frontier Labs, and again, they're partners of ours, they're very good at obviously finding these sort of If they can write code, they can understand vulnerabilities, and they can create patches, and they can sift through lots of data. But these things are not in line, and they're not taking action in real time.

While there's a tremendous amount of benefit, there is a massive opportunity for companies like CrowdStrike who have all the data. We're the system of record. We're in line. We're a net data creator, 7 trillion events per day. All of the models that we train on are our data. There is no Reddit of CrowdStrike security data that somebody can just train on. I think working together and giving customers choice is a great outcome.

Gabriela Borges
Analyst, Goldman Sachs

There is one other architectural question that I think is relevant here. When you and the team founded CrowdStrike 10 + years ago now.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

There was an architectural change in endpoint such that the incumbents in endpoint, when they tried to address it, they really struggled.

George Kurtz
CEO and Co-Founder, CrowdStrike

Right.

Gabriela Borges
Analyst, Goldman Sachs

CrowdStrike was able to out-innovate with next-generation EDR and all of the modules that followed. How do you think about the risk that AI creates an architectural shift such that all of the domain experience of the last 10 + years is not the same domain experience that can be applied to the next 10?

George Kurtz
CEO and Co-Founder, CrowdStrike

I actually think it becomes even more important because it starts with the data. You do not have AI without the training data, like period. If you train it on garbage or your synthetic data is not where it needs to be, you are going to get substandard outcomes. When we think about these architectural shifts, it actually plays into our hands because we have all this data. Sometimes the old saying, it is better to be lucky than good. We actually had annotated this data for the last 10 years. We started doing this before there was GenAI. That data is basically in a format for the most part, there is always curation we have to do, that it was incredible for training. That creates a moat.

This data moat that we have creates a barrier for, I think, others, and it plays into our hands in terms of this inflection point that we see in AI today. We see the results of it based upon what we have just built. The good news is we are an AI company from the beginning. It started machine learning, and obviously now we have got many opportunities in front of us with agentic AI.

Gabriela Borges
Analyst, Goldman Sachs

I know it has only been a handful of business days since all of the product releases at Fal.Con.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yeah.

Gabriela Borges
Analyst, Goldman Sachs

The reality is you would not have put these types of products in front of customers if you did not think they were going to be hugely popular.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yeah.

Gabriela Borges
Analyst, Goldman Sachs

My question for you is what surprised you in the feedback, is there anything, were there asks that came down the pipe that made you think, huh, that should really be on the product roadmap?

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, we'll take Guardian as an example. This is one that I announced, and we shipped that day. From a Guardian perspective, this really falls under the category of AIDR, AI Detection and Response. What that means is we've basically moved from just EDR of protecting a human and a computer or a cloud workload to protecting the agent, everything the agent does, everything the agent touches. We think it's a bigger opportunity potentially than EDR because on average, at least the math is, there'll be 90 AI agents per human. Obviously, I think it'd be unlimited, it doesn't mean why can't you have 1,000 or what have you. We actually worked on that, it's a great story because we had so much feedback from customers in what they wanted. We bought Pangea, which really did prompt inspection.

Then we had our customers saying, "Well, we don't know where all these AI agents are." It's AI agents run amok, the CEO on down and the board is saying, we have to deploy AI agents. But we can't go fast enough because of the security issues. They told us this, every customer was saying this, and we had a piece of it. What we did is we created a tiger team internally about six months ago, this is a great example of how you have to operate today. I said, "Okay, we're going to put a tiger team in place, and we're going to start." I had a kickoff meeting, it was a smaller group, but then 200 people show up. Everybody wanted to be part of the tiger team.

I'm like, "This is not a tiger team." I disinvited 200 people, then I re-invited, and I handpicked the best all-stars from CrowdStrike. It was a privilege to be in this team. Then we ran three meetings a week that I was on, three status meetings. To be honest, it was no different than when I started the company. It was like, "Here's what we want. Here's what we're going to build. Change that, move that. I don't like the color." It was that level of detail. It's incredible because the good news is with the platform, 80% of this stuff is built. We don't have to build agents and workflows. We create a new workflow, but we don't have to build the architecture around it.

With a very short period of time with a small team and leveraging AI, we got an incredible product out, so that when I got on stage, I was able to announce Guardian GA. It went live while I spoke, and then our customers were turning it on and using it in their workshops in the afternoon. That one is super exciting, and I think it's going to be a total home run for us.

Gabriela Borges
Analyst, Goldman Sachs

When they turn it on, it consumes Flex credits?

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, if you license it through Flex, it consumes Flex credits. It really consumes tokens, which again, are made available through Flex. Part of Flex, as you probably saw in the last quarter, we did 935 Flex. We're at $2.3 billion, we're the total Flex contracts. We've gone to a Flex-first selling motion, which means if you wanted to sell something that wasn't Flex, you'd have to get it approved up through probably the head of sales, president of the company. Not to say that some of them don't get through for whatever reason, but at the end of the day, we tripled the amount of Flex deals last quarter than we've done.

Gabriela Borges
Analyst, Goldman Sachs

There are a lot of technical decisions made early on in CrowdStrike with the lightweight sensor that you have and the knowledge graph and all that good stuff, Threat Graph. My question for you is, if you think about the pace of agentic attacks, for lack of a better word.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

Is there a scalability upgrade that has to happen? I guess we can take it in two ways. One, internally for your own architecture, did you have to upgrade to be able to meet the pace and speed of agentic attacks? Then two, we can talk about customers.

George Kurtz
CEO and Co-Founder, CrowdStrike

The good news is that we've built the technology and the platform to be scalable. When we think about these attacks and we think about agentic attacks, there's two things that you have to really keep in mind. Number one is things happen faster and more of them happen. This is the simple explanation. The agents haven't figured out some new miraculous way or class of attack that have never been seen before that we're not covering for. Okay? You have more attacks, and they come faster. That's the big piece. Obviously these agentic attacks are good because they can string so many different vulnerabilities together, really esoteric things that a human couldn't keep track of to be able to find an access path in. We've all heard and read the Hugging Face examples.

From that standpoint, we have the technologies, and we've understood what was happening. We talk about this breakout time. It used to be days, then hours, then minutes. It was 27 minutes last year, with 27 seconds we saw in some cases. Part of what I talked about at Fal.Con is this window has now collapsed to zero because of the new apex predator is the agent state, not the nation state. Now everyone can operate with nation state capability. We of course keep adapting. But the big part is making sure that you've got the right AI internally with the right speed and the platform to keep up with what the adversary's doing.

Gabriela Borges
Analyst, Goldman Sachs

This leads to the modernization question. I think about your share in even classic endpoint, for example, let alone your share in next generation SIEM, which is going to be—

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

—benchmarking below what endpoint is because it is newer. There is a lot of heavy lifting that customers still have to do from a modernization standpoint.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

Talk to us about some of those conversations. When enterprises call you in and say, "Look, we haven't historically been a CrowdStrike customer," how do you walk them through legacy to next-gen across the key pillars?

George Kurtz
CEO and Co-Founder, CrowdStrike

I think we just want to start with, well, what are you trying to solve? We have a lot of customers that I think we're looking. Sometimes legacy technology is just, there's inertia, right? Hey, we'll get around to it whenever we get around to it. Half the market is still legacy. We got massive customers, but half the market is still legacy, so plenty head room in front of us. I think with this Mythos moment, what we're seeing now is customers going, "Hey, maybe legacy's not good enough. Maybe it's time to make a change." There are always these technology inflection points that people go, "Wait a minute, we got to do something different." I think AIDR or Guardian is the product, will actually spur more activity around what we had is not going to work, and how do we modernize this?

Some of the companies that we've won, and we've got a great amount of net new logos. You would look at those. If you knew the names, you go, "I can't believe for 15 years you've been on legacy technology." But they still are, and we're happy to have them over. But it's taking them on the journey. Let's solve what you have today. Maybe you want AIDR. Your SIEM is outdated. You're spending too much money. You've got one of every tool and two of everything else. How do we get rid of this stuff? That's really the conversation which leads to Flex, and also the demand planning that we do year-over-year, which has been great in having customers actually consume more Flex sooner.

Gabriela Borges
Analyst, Goldman Sachs

What about in terms of budget? One of the industry conversations that we've been having is CISOs generally have more of a carte blanche than they did a year ago—

George Kurtz
CEO and Co-Founder, CrowdStrike

Yeah.

Gabriela Borges
Analyst, Goldman Sachs

—because enterprises are so determined to make AI a reality. When they get that carte blanche, how do they then map it to specific security products? I guess it depends very much on the problem they're trying to solve. Maybe just give us some high-level commentary on what you're seeing at a budgetary level.

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, from a budgetary level, it really starts with what problem are they trying to solve? One of our largest customers, one of the hyperscalers, work with us as a design partner for Guardian. They came to us, and they said, "We want these things." Great. It was unbelievable to have them as design partner. I said, "Okay, well, what does success look like? When this thing pops out the other end, what does it look like? What are you looking for?" It wasn't a feature, it wasn't a technology sort of widget that they wanted as success. The number one thing was, "We want to go faster in AI deployment.

The CEO wants us to go faster, and we can't go fast enough." When you have that level of support at the CEO level down, what we're seeing is that basically security is hitting the gas pedal for the first time for IT rather than hitting the brake pedal. This, I think we talked about this before we got on stage, is really the first time I've seen hitting the gas pedal in security rather than hitting the brakes. That gives you additional budget where it's the CTO, the Chief Data Officer, whatever it might be, saying, "We got to go faster. We need security to be part of it."

Gabriela Borges
Analyst, Goldman Sachs

This is the durability of growth question. Are we hitting the gas pedal for two to four quarters until we are up to a higher level of security, and then we come back down to 40 mph ? Or is this a period of time where we are staying at 200 mph and perhaps even going higher?

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, the world we live in today is if you went on vacation for a week, you are outdated. Come back, and what happened? The whole world has changed in a week. It is a much different pace. I always say to my folks, we are looking at a watch, not a calendar. We have to go. That is kind of the pace we are in. I actually do not see that changing. My simple math on this is, do I think there is more AI in a year, three years, or five years? For me, absolutely. Do I think the technology is going to change even faster? Absolutely. Has security paralleled the slope of the technology curve for the last how long I have been in it? Yes.

What we did at Investor Day, you were there, we plotted the adoption of the cloud, and you can plot the revenue stream over the last 10 years, and you can kind of see it go like this, and security goes along with it. If you just take the main labs and you look at how fast, never been seen before, the revenue growth, it goes like this. I think the inflection point for security is going to be a lot sooner and a lot steeper than what we saw with the cloud, just because of what I said. You cannot really roll this stuff out unless you have security. I think it is going to be durable. I think it is a long tailwind. Honestly, we are going to look back.

I hope to be back in five years, every year with you, but in five years, we go, "Man, that was kind of Mickey Mouse with all the stuff that we saw in 2026 compared to what we are going to see." It is just going to change that fast.

Gabriela Borges
Analyst, Goldman Sachs

Let me ask you about a couple of product cycles. You already touched on AIDR and the frontier model inflection, followed by what is pretty much happening real-time in security. How do we think about AIDR in terms of an attach rate or a token allocation? Give us some clues as to how that product cycle or market develops over time.

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, if you just look at the AI spend, I think today it's like $2.7 trillion going to almost $6 trillion in 2030. Those are the stats that we gave at our Investor Day. If you took an attach rate of 1%-8%, pick whatever math you want, these are massive numbers that are in front of us. As I said, there's not going to be a company that doesn't have some level of AIDR. Just like we would go, "That's crazy you don't have antivirus. That's crazy you don't have EDR." Well, it wasn't crazy in 2011 when I started the company. Nobody even knew what this stuff was. In 2026, you can go to any company, they don't have AIDR, right? That's the opportunity in front of us. The attach rate, I'm a simple math guy.

Pick whatever percent you want in a massive TAM. You have to buy into the fact that it is going to be needed and it's going to be mandated. I think given the level of compliance that's out there, 100%, it's going to be mandated. How can it not in these regulated industries? How can anyone go back to the regulators? Take what you guys do. How can you go back to regulators? We don't know what our agent did. It did something. That's not going to fly. So having visibility, having full traceability of the life cycle of that agent, tying it together with identity as a control plane is going to be critical, and that's going to be, again, a massive TAM opportunity for us.

Gabriela Borges
Analyst, Goldman Sachs

Let's go to the identity control plane.

George Kurtz
CEO and Co-Founder, CrowdStrike

Okay.

Gabriela Borges
Analyst, Goldman Sachs

Over the last several years, the world has thought about privileged access, identity access, identity governance, and you've had these three pillars. What's unique about agentic identity is fundamentally it's more ephemeral. I think that's probably the best—

George Kurtz
CEO and Co-Founder, CrowdStrike

Yeah.

Gabriela Borges
Analyst, Goldman Sachs

—way to describe old versus new. Then we see the types of products that CrowdStrike is releasing, which we can debate whether they're overlay technologies or you could actually do full displacement over time.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yeah.

Gabriela Borges
Analyst, Goldman Sachs

Talk to us about how the construct of identity is changing and why CrowdStrike addresses that as opposed to the classic pillar of guides.

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, there's multiple areas of identity, and one of the first areas that we got into was ITDR, identity detection response. That basically was, do you have your directories configured right? Can they be abused? Things like lateral movement when an adversary gets in, and we got into that in 2020. We saw identity as going to be important to stopping breaches. Now where we are today, essentially is this model of PAM, privileged account management, was really born in the late 1990s, early 2000s, where I have all these Windows administrator credentials, and I got to put them somewhere, and I want to make sure they're secure. Then cloud came about, and it was like, well, I have all these cloud accounts, I got to put them somewhere, and I got to make sure they're secure.

We think that's an outdated model, which is one of the reasons why we acquired SGNL.ai. The founders all came from Google. They built their identity stack for Google Cloud through an acquisition, and super smart bunch. The whole idea is the world needs to move to human and non-human, needs to move to zero standing privileges. Essentially, you can think about a hotel. Let me just give you an analogy. You check into this hotel here, you get a card key. You can go wherever you want. You want to go to the gym, you go. You want to go to the rooftop, you just click it, right? That's standing privileges. Zero standing privileges, you get access, and you only get into the room, and as soon as you get into the room, your access is turned off.

You move and you want to go to the gym, everything else is turned off, and you just go to the gym, but you know you're going to the gym. You want to go to the restaurant, you go to the restaurant, but everything else is turned off. By the way, if you lose the card, nobody has access to anything. That's the simple analogy of zero standing privileges, and this is what's needed in an agentic world. When the agent runs, you don't want to load the agent up with every entitlement to do whatever it wants, because guess what? It figures out a way to do things you don't want, and that's part of the problem.

It literally steals tokens and credentials and all kinds of crazy stuff that you've read about, and this is why what we released we're so excited about, because it becomes a control plane. In addition to runtime, we now have the identity control plane with non-human identities and SGNL.ai, which is now our next-gen identity solution.

Gabriela Borges
Analyst, Goldman Sachs

Do you need visibility into the network or a network control point for the platform to be complete?

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, it is interesting you say that. So one of the things we announced at Fal.Con is AI Gateway, which is coming out in September, and that is for things that we may not run on. But also, what is interesting is we actually have a transparent proxy on the agent. So we actually see all the agentic traffic before it ever hits a gateway, as long as you are running our agent. So we will be able to cover, obviously, our agent, plus if you are not running an agent doing something else, or we are not covered in the whole environment, we will be able to see that through our gateway. No problem, there are plenty of gateways that are out there. We actually integrate with most of all the big AI gateways, and we actually can implement control points from those gateways as well.

Gabriela Borges
Analyst, Goldman Sachs

You have alluded a little bit to why agentic security is hard. How did you all solve the problem of visibility, given that we hear about things, for example, like agent session management or life cycle agent management, where it does not have the same parameters that a human would have had or machine identity would have had a year ago. How did you think about addressing that visibility question?

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, the good news is we have sort of architected for this in the human world, and it applies into the agentic world at super scale. You probably have seen this in your own world. You are using ChatGPT or Claude, and you get called to dinner, and you come back to your session, or you close the computer for the night and you boot it up and you take over from where you left. Well, all of that is you have to track the state, and you have to understand when it started and what it did.

We have always had that concept of not losing the state in a process or a human world, and we have that in the agentic world, and that was part of our Threat Graph and all of the graphs that we built, and this is why it is so important to be able to understand the context across a long horizon of what someone or something is doing. So we had that concept. We have actually extended it out for the agentic world, but it allows us to track these things over long periods of time because you might have a short-running agent, or you may have a much longer running agent, and you have to put it all together.

The other piece of that which is important is you have to tie together, say, the prompt layer with the runtime layer because you can have a prompt that sort of passes the smell test of "I'm going to run this prompt, and it looks good." But underneath, if you don't have the technology to understand AV identity, but also runtime, what it's doing, you're not going to know if the prompt actually did something bad. We're in a unique position to tie together the prompt itself, the identity, and actually what it did, which is very unique in the industry.

Gabriela Borges
Analyst, Goldman Sachs

Let's talk about SIEM.

George Kurtz
CEO and Co-Founder, CrowdStrike

Let's talk about it.

Gabriela Borges
Analyst, Goldman Sachs

There has been what I would call a big gap in intelligence in the industry because customers don't put all their data in the SIEM—

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

—and then once it's in the SIEM, it's either expensive, or they don't have the right security domain experience to know what to do with it.

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

So you get all of the stories of the burned-out SOC analyst trying to find a needle in a haystack. How is the upgrade cycle in SIEM going? I would have loved to have seen it happen faster and earlier, but the reality is these things take time.

George Kurtz
CEO and Co-Founder, CrowdStrike

They do take time because they are embedded. You have workflows. There's plenty of SIEMs that have been around and technologies that are decent. But obviously, there's a modernization cycle taking place, and it takes time because a lot of processes are built around these. So how we got in the SIEM business was we had customers saying, "Your data's incredible, your product's easy to use. Why can't you just take some third-party data in?" And they asked us this year over year until finally we said, "Okay, we're going to do that." We bought Humio, and obviously it became Next-Gen SIEM, LogScale Next-Gen SIEM. Now, what does that actually mean? Well, it means that, and where this becomes disruptive, is that customers are not charged for the first-party data that we generate. So think about what was happening.

We were generating 80% of the data that was going into their SIEM, and they were being charged by the SIEM vendor. So we said, "Well, why don't you just keep it in Falcon? We won't charge you to ingest that data." This is a very important point, and every customer actually has access and gets 10 GB for free. We won't charge you for that, but we will charge you to ingest the third-party data. So when you do the math on this, it's like, well, why would I take all the data out of Falcon, put it somewhere else, be charged to tax to put it somewhere else, and have disconnected systems? And this is why it's resonated so well. It's faster, better, and better outcomes, and then obviously cheaper to operate, better TCO.

Gabriela Borges
Analyst, Goldman Sachs

CrowdStrike strikes me as a company that has had its foot on the gas from an R&D standpoint from day one, and I don't think that's—

George Kurtz
CEO and Co-Founder, CrowdStrike

Yep.

Gabriela Borges
Analyst, Goldman Sachs

—ever really changed during the number of years that you've been public. My question for you is, does the efficient frontier of R&D change? Have you noticed anything different in the way that CrowdStrike operates over the last year because of AI productivity, for example? It sort of creates this expansive idea of all of the places that you could compete over time, essentially getting pulled in from a roadmap standpoint.

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, if you look at what is AI really just bends time. We always talk about this concept of how do you bend time. AI bends time, right? You can do more things faster. Obviously, what does that translate to? Potentially efficiencies around headcount, spend, those sort of things. What we've tried to do is be very diligent and efficient where we apply it. Whether it's in legal, we want to be more efficient in terms of getting through all this data, and AI is very good at that. We think about development. Of course, there's a crawl, walk, run because you want to apply AI in the right spots. Where do you want to write code? Where do you want to deploy code? How do you make sure that AI is to a level where it is today? It wasn't a year ago.

Just a year ago, it wasn't as good as it is today. So we've been very diligent on where we apply it, how we apply it, but overall, more and more agentic workflows and processes are taking place internally. Again, we're seeing that in many of the other customers. Really, the problems that we're solving for customers, we have to solve for ourselves. The visibility, the control, the identity, and we're doing that as customer zero. But I couldn't be more excited about just being in technology and security today because of how fast it's moving and the opportunity that's in front of us. But if you look at every area, not just coding agents, but whether it's legal, whether it's marketing, whether it's HR, all of these processes are going to be reimagined, and they're going to need security as part of that modernization.

Gabriela Borges
Analyst, Goldman Sachs

I'm curious if you're willing to share with us, has your day-to-day changed, or in what way has your day-to-day changed?

George Kurtz
CEO and Co-Founder, CrowdStrike

Well, I used to ask for a white paper, and then three months later, I would get one. Now I can write one in an hour and go, "Here it is."

Gabriela Borges
Analyst, Goldman Sachs

What was the last white paper that you wrote in an hour?

George Kurtz
CEO and Co-Founder, CrowdStrike

I can write. I need a white paper. I wrote it and then give it to the marketing people. I do this all the time. There isn't anything that I haven't really optimized. I write my own programs. I have an Apple developer license. Everything is curated, all my workflows. You spend a lot of time setting this stuff up and getting things running and playing with the models and open source, open weight technology. You got to be in this stuff, and you got to have a passion for it. My day-to-day piece has changed. Actually, now, I don't have to do white papers anymore. In the early days, I don't need to wait. I'll write one. Now, the whole company is like, "Well, how do we do this and do it better using AI technology?" For me, it's changed dramatically.

Just the speed at which I can do things. I think about AI as a little bit of like an Iron Man suit. If you put it on, you can be superhuman, but you sort of have to know what you want to get out of it, and I would say I'm pretty darn good at prompting.

Gabriela Borges
Analyst, Goldman Sachs

I believe it. I'm glad I asked the question. Please join me in thanking George Kurtz for his time. George.

George Kurtz
CEO and Co-Founder, CrowdStrike

Thank you.