← Back to list
Colossus (Invest Like the Best / Business Breakdowns)Podcast1 Sep 2022Source: joincolossus.comHost: Colossus

CrowdStrike: Cyber SaaS - [Business Breakdowns, EP. 72]

In plain words

This piece explains how CrowdStrike grew from a latecomer into a cybersecurity platform. The guest believes CrowdStrike is transforming from endpoint security to a next-gen cloud security platform, with success driven not by tech leadership but by a lightweight single-agent architecture covering all devices and a cross-customer threat graph. Key holdings: CrowdStrike (revenue up 61%, high retention); Microsoft (main competitor, offers free endpoint protection); SentinelOne (also a competitor).

AI SummaryAI-generated · may contain errors · verify against the original

CrowdStrike is a cybersecurity company founded in 2011 by former McAfee CTO George Kurtz. Its core innovation lies in building a platform that proactively predicts threats, as opposed to the passive defense model of traditional firewalls and anti-malware software. As of the report's publication, Cro

~15 min full read · 9 sections
Deep Analysis

This Issue at a Glance

Guest: Roneal Desai, a seasoned public market investor specializing in enterprise software. Main Theme: How CrowdStrike, through its cloud-native architecture and intelligent endpoint agent, grew from a late entrant into a platform-level cybersecurity company. Core Thesis: Roneal Desai believes that CrowdStrike is transitioning from a "best-in-class" endpoint security vendor into a next-generation cloud security platform. Its success hinges not on technological superiority but on architectural decisions—using a lightweight, dynamically upgradeable single agent to cover all endpoints, and building a cross-customer, cross-product threat graph on that foundation.


1. From Passive Defense to Active Prediction: CrowdStrike Redefines Endpoint Security

Roneal Desai argues that CrowdStrike's core innovation lies in upgrading endpoint security from a "static blacklist" model to a "behavioral analysis + real-time learning" model.

Traditional endpoint security (e.g., McAfee firewalls) operates by pre-loading a list of known malware and only blocking threats on that list. Once an attacker uses an unknown method to enter the system, the firewall is powerless. Desai uses a vivid analogy: "McAfee is like airport security—once you pass the checkpoint, no one watches you anymore. CrowdStrike is like a casino—after you enter, they continuously monitor your behavior patterns."

CrowdStrike's architecture consists of two core components:

1. Next-Generation Antivirus (NGAV): Connects to the cloud in real time, continuously updating threat intelligence—"As soon as an attack occurs at another customer, they add the new signature to the list."

2. Endpoint Detection and Response (EDR): Monitors behavioral anomalies on devices—"If your application suddenly requests permissions it has never asked for before, the system flags it."

The 2016 DNC hack is a classic case of CrowdStrike's capabilities. After deploying agents on DNC devices, CrowdStrike discovered multiple applications sending data to Russian servers without user knowledge. By cross-referencing IP addresses and data transmission methods, they traced the activity to a Russian hacking group known as "Cozy Bear" and reverse-engineered the infiltration path the hackers had completed before CrowdStrike's intervention.

Key data: CrowdStrike's next-generation antivirus + EDR combination is priced at $16 per endpoint per month, while traditional vendors (e.g., Symantec) charge only $1 per endpoint per month. Even after accounting for discounts, the price gap remains 5–10 times.


2. TAM Severely Underestimated: A Three-Year Leap from $10B to $18.5B

Desai points out that the market's estimation of the total addressable market (TAM) for endpoint security is severely lagging, with the core reason being the underestimation of "spend per customer" rather than "number of customers."

IDC data illustrates this shift:

  • June 2020: Forecasted the endpoint market in 2025 at $10B
  • June 2021: 2025 forecast revised up to $13B
  • 2022 (at the time of the report): 2025 forecast had risen to $18.5B

Desai argues that the expansion of TAM is driven by three layers:

1. Upgrade from Antivirus to EDR: Per-endpoint spending jumps from $1/month to $10–16/month

2. Addition of Managed Services: Customers can pay CrowdStrike to monitor and respond on their behalf, adding $6–22/month per endpoint

3. Expansion of Coverage: Traditional endpoint products were only installed on employee computers, but now they can be deployed on servers and cloud instances—"You wouldn't have installed a McAfee firewall on an AWS server before."

Competitive Landscape: Legacy vendors (Symantec, McAfee/Trellix, Trend Micro) still account for 60% of market spending, but CrowdStrike is rapidly eating away at their share. After Symantec was acquired by Broadcom, its market share fell from approximately 15% to around 5%. Desai believes Palo Alto Networks is not a direct competitor to CrowdStrike—Palo Alto's Traps product, acquired in the endpoint security space, "has never reached the quality level of its core firewall." The real competitors are Microsoft (whose E5 license includes free endpoint protection) and SentinelOne.


3. Architectural Advantage: Single Agent + Cross-Customer Threat Graph

Desai emphasizes that CrowdStrike's most enduring moat is not the technology itself, but its architectural decision—covering all endpoints with a single lightweight, upgradable agent, and building a cross-customer, cross-product threat graph on that foundation.

The background of CrowdStrike's founding team provides key insights:

  • CEO George Kurtz: Former McAfee CTO; his security company founded in the 1990s was acquired by McAfee.
  • CTO Dimitri Alperovic: Former McAfee VP of Threat Research; father of the "Trusted Source Reputation System" (a widely used security protocol).
  • Sean Henry: Former No. 2 at the FBI (overseeing all criminal and cyber investigations); leads the incident response team.

The founding team deliberately slowed product development to focus on getting the agent right—"You download the CrowdStrike app once, it runs in the background, and you never notice it again. They were very focused on making the agent lightweight, upgradable, and capable of doing anything they wanted it to do over time."

The cross-customer threat graph is a unique advantage for CrowdStrike over competitors like Microsoft: Microsoft can only see behavior patterns within a single organization, while CrowdStrike can cross-reference data from 18,000 customers—"If we all work at Los Angeles Airport, Microsoft can see behavior among us. But CrowdStrike can see behavior patterns at Los Angeles Airport, Houston Airport, and New York Airport."

Key historical milestones:

  • 2014: Sony was hacked; CrowdStrike deployed agents on 40,000 endpoints in one day and confirmed North Korea's involvement the next day.
  • 2015: Discovered Chinese hackers infiltrating U.S. medical companies; made the front page of The New York Times.
  • 2016: DNC incident; confirmed Russian hackers; brand awareness exploded.
  • 2019: Two major next-generation competitors (Silence acquired by BlackBerry, Carbon Black acquired by VMware) and Symantec (acquired by Broadcom) were all acquired simultaneously, clearing the competitive landscape overnight.
  • 2020: COVID-19 pandemic drove remote work; the traditional "VPN back to the office" security architecture collapsed.

4. Product Expansion: From Endpoint to Platform, Modular Growth Flywheel

Desai believes that CrowdStrike is transitioning from an "endpoint security company" to a "security platform," with its product expansion strategy following the principle of "single agent, multiple modules."

The number of product modules has grown from 10 at the time of its 2019 IPO to 22 currently. The proportion of customers adopting multiple modules has been steadily increasing:

  • End of 2017: 30% of customers used more than 3 modules
  • End of 2019: 50%
  • 2022 (at the time of the report): 70%
  • Average customer uses nearly 5 modules
  • Customers spending over $1 million annually use an average of 7 modules

Desai categorizes CrowdStrike's product lines into four buckets:

1. Traditional Endpoint: NGAV + EDR + Managed Services + Threat Intelligence

2. Identity Security: Acquired in September 2020 for $80M, with an ARR of only $6M at the time; ARR has now reached $50M, with quarter-over-quarter growth of 30%

3. Extended Detection and Response (XDR): Through the acquisition of Humio (a low-cost cloud log platform), CrowdStrike can now integrate data from partners such as Cloudflare, Zscaler, Okta, Proofpoint, and ServiceNow to build a unified security view

4. Cloud Workload Protection: Deploying the CrowdStrike agent on AWS servers to monitor cloud environment security

Desai particularly emphasizes the strategic significance of XDR: "This is the first time someone has been able to unify the view of the entire security environment in this way. CrowdStrike doesn't need to control your systems—they just need your data to know when you are under attack. If they detect malware entering via email in Proofpoint data, they can directly shut down that laptop."


5. Financial Characteristics: High Growth, High Retention, and Unique Channel Economics

Desai notes that CrowdStrike’s financial model exhibits a rare combination: maintaining 60%+ growth at a $2B ARR scale, while achieving a 77% subscription gross margin and approximately 2% customer churn.

Growth Comparison (when other SaaS giants were at $2B ARR):

Company Growth Rate at the Time
CrowdStrike (Current) 61%
ServiceNow High 30-40%
Workday High 30-40%
Salesforce High 30-40%

Desai points out: "Historically, aside from Snowflake, no other SaaS company has grown at this pace at this scale."

Uniqueness of the Channel Model: The cybersecurity industry relies on channel partners (VARs, MSSPs) for sales. CrowdStrike offers channel partners a wholesale discount (approximately 10%) that is significantly lower than competitors (approximately 25%). However, because CrowdStrike’s ASP is about 20% higher, implementation is faster, and cross-selling opportunities are greater, channel partners still prefer to promote CrowdStrike. This has created a flywheel effect: channel partners have even begun competing among themselves—"they undercut each other’s wholesale margins to win customers, and CrowdStrike has almost become a 'loss leader' for channel partners."

Unit Economics: Desai estimates that CrowdStrike’s cost to acquire $1 of ARR is approximately $0.90, with an incremental profit margin of 30%. Given a 2% customer churn rate, the incremental ROIC is approximately 40%. Under his adjusted methodology (reclassifying growth investments from OPEX to CAPEX), CrowdStrike’s LTM EBIT margin is approximately 24%.


6. Risks and Outlook: Uncertainty on the Path to Platformization

Desai believes CrowdStrike's greatest opportunity lies in becoming the "next-generation security platform," but it faces three key risks.

Platformization Logic: Desai draws on Clay Christensen's theory of "interdependence and modularity." In the client-server era, integration costs resided at the application layer, giving rise to application suites like Oracle and SAP. In the cloud era, integration costs have shifted to the infrastructure layer, paving the way for new platform companies. He argues that CrowdStrike and Microsoft are the two most likely candidates to become the new platforms in the security space.

Three Key Risks:

1. XDR Route Debate: CrowdStrike adopts an "open model" (integrating third-party data), while Microsoft and Palo Alto pursue a "closed model" (building all components in-house). Desai believes the open model is superior in the long run, but "this is not a settled conclusion."

2. Microsoft Threat: "You should never bet against Microsoft in software. They should always be regarded as a threat."

3. Sustainability of Product Expansion: If CrowdStrike cannot find more new security domains it can enter with its current economics, customer acquisition costs will rise, and unit economics will deteriorate.


Mentioned Positions

Position Guest View Key Data
CrowdStrike Bullish (platform potential) ARR $1.9B, growth 61% YoY; 18,000 customers; 77% subscription gross margin; ~2% customer churn rate
Microsoft Risk warning (main competitor) Free endpoint protection bundled with E5 license; second-largest and second-fastest endpoint security vendor
SentinelOne Risk warning (competitor) No specific data provided
Palo Alto Networks Neutral (not a direct competitor) 70,000 customers; no breakthrough in endpoint security
Symantec (acquired by Broadcom) Risk warning (being eroded) Market share declined from 15% to ~5%
McAfee/Trellix Risk warning (legacy vendor) Market share ~8-9% (by spending)
Trend Micro Risk warning (legacy vendor) Market share ~8-9% (by spending)

Judgments Worth Remembering

1. Roneal Desai believes that CrowdStrike’s success is not about being “first to market” but about “entering the market with the right architecture” — they were the third company to launch a next-generation endpoint product, but their single-agent architecture allows for unlimited subsequent expansion, while the first two (Silence and Carbon Black) declined after being acquired due to architectural limitations.

2. “McAfee is like airport security, CrowdStrike is like a casino” — traditional security checks only at the entry point once, while CrowdStrike continuously monitors behavioral patterns. This analogy precisely captures the paradigm shift from “static defense” to “dynamic monitoring.”

3. Desai points out that the lag in TAM estimation is the biggest blind spot for investors — IDC raised its 2025 endpoint market forecast from $10B to $18.5B within three years, because “spend per customer” rather than “number of customers” was severely underestimated. CrowdStrike’s ASP is 10–16 times that of traditional vendors.

4. The cross-customer threat graph is CrowdStrike’s unique moat relative to Microsoft — Microsoft can only see behavioral patterns within a single organization, while CrowdStrike can cross-reference data from 18,000 customers, forming “collective immunity.”

5. Desai argues that CrowdStrike’s channel economics have formed a flywheel effect — despite offering channel discounts (approximately 10%) far lower than competitors (approximately 25%), channel partners still prefer to push CrowdStrike due to higher ASP, faster implementation, and more cross-selling opportunities, even competing to lower their own margins to win customers.

6. “The security industry has historically been dominated by ‘best-of-breed,’ but that may not be the case in the future” — Desai notes that this is the easiest mistake for investors to make: extrapolating future industry structure from the past. The complexity of cloud-era infrastructure is creating demand for integration, making platform-based security companies possible.

7. Desai estimates CrowdStrike’s incremental ROIC at approximately 40% — the cost to acquire $1 of ARR is about $0.90, with an incremental margin of 30% and a customer churn rate of only 2%. Under his adjusted metrics, CrowdStrike’s LTM EBIT margin is approximately 24%.

8. The core lesson for entrepreneurs is “be patient with product architecture” — CrowdStrike was the third to market, but they took the time to get the single agent right, making it upgradeable and scalable. Desai adds: “Another key to their success is focusing on what customers truly want — not a software product, but ‘security as a service.’”