Item 1. Business
Item 1. Business
Overview
We founded CrowdStrike in 2011 to reinvent security for the cloud era. When we started the company, cyberattackers had a decided, asymmetric advantage over existing security products. We turned the tables on the adversaries by taking a fundamentally new approach that leverages the network effects of crowdsourced data applied to modern technologies such as AI, cloud computing, and graph databases. Realizing that the nature of cybersecurity problems had changed but the solutions had not, we built our CrowdStrike Falcon platform to detect threats and stop breaches.
We believe we are defining a new category called the Security Cloud, with the power to transform the security industry much the same way the cloud has transformed the customer relationship management, human resources, and service management industries. With our Falcon platform, we created the first multi-tenant, cloud native, intelligent security solution capable of protecting workloads across on-premise, virtualized, and cloud-based environments running on a variety of endpoints such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices. Our Falcon platform is composed of two tightly integrated proprietary technologies: our easily deployed intelligent lightweight agent and our cloud-based, dynamic graph database called Threat Graph. Our solution benefits from crowdsourcing and economies of scale, which we believe enables our AI algorithms to be uniquely effective. We call this cloud-scale AI. Our single lightweight agent is installed on each endpoint or the cloud workload and provides local detection and prevention capabilities while also intelligently collecting and streaming high fidelity data to our platform for real-time decision-making. Our Threat Graph processes, correlates, and analyzes this data in the cloud using a combination of AI and behavioral pattern-matching techniques. By analyzing and correlating information across our massive, crowdsourced dataset, we are able to deploy our AI algorithms at cloud-scale and build a more intelligent, effective solution to detect threats and stop breaches that on-premise or single instance cloud products cannot match. Today, we offer 19 cloud modules and our Falcon platform via a SaaS subscription-based model that spans multiple large markets, including corporate workload security, security and vulnerability management, managed security services, IT operations management, threat intelligence services, identity protection and log management.
Organizations everywhere are becoming more distributed as they adopt the cloud, increase workforce mobility, and grow their number of connected devices. They are adding more workloads to a myriad of different endpoints beyond the traditional security perimeter, exposing an increasingly broad attack surface to adversaries. In addition, the sophistication of cyberattacks has increased, often coming from nation-states, well-funded criminal organizations, and hackers using advanced, easily obtained methods of attack. On a number of occasions, adversaries have launched devastating, destructive attacks that have caused significant business disruption and billions of dollars in cumulative losses. The architectural limitations of legacy security products, coupled with a dynamic and intensifying threat landscape, are creating the need for a fundamentally new approach to security.
Our pioneering approach starts with our single intelligent lightweight agent that enables frictionless deployment of our platform at scale. Our customers can rapidly adopt our technology across any type of workload running on a variety of endpoints. Our lightweight agent offloads computationally intensive tasks to the cloud, while retaining local detection and prevention capabilities that are necessary on the endpoint. The agent is nonintrusive to the end user and continues to protect the endpoint and track activity even when offline. The agent recommences transmitting data to our Falcon platform when the connection to the cloud has been reestablished. By utilizing CrowdStrike’s single agent, customers are able to leverage the capabilities of our platform without burdening the endpoint with multiple agents.
Our lightweight agent intelligently streams high fidelity endpoint data to the cloud where Threat Graph provides a simple, flexible, and scalable way to model highly interconnected data sets. Threat Graph processes, correlates, and analyzes over five trillion endpoint-related events per week in real time and maintains an index of these events for future use. Threat Graph continuously looks for malicious activity by applying graph analytics and AI algorithms to the data streamed from the endpoints. Our multi-tenant architecture allows us to collect a broad array of high fidelity data about both potential attacks and benign behavioral patterns across our entire customer base, continuously enhancing our AI algorithms. This significantly increases the efficacy of our solution to stop breaches while reducing false positives.
3
Table of Contents
We founded our company on the principle that the future of security would be driven by AI and that a cloud-native architecture would enable the collection of high fidelity data and scalability necessary for an effective solution. From the beginning, our strategy was focused on collecting data at scale, centrally storing such data in a singular model, and training our algorithms on these vast amounts of high fidelity data, which we believe is a fundamental differentiator from our competitors. Our cloud-scale AI means that the more data that is fed into our Falcon platform, the more intelligent Threat Graph becomes and the more our customers benefit, creating a powerful network effect that increases the overall value we provide. AI is revolutionizing many technology fields, including security solutions. To be truly effective, algorithms that enable AI depend on the quality and volume of data that trains them and the selection of the right differentiating features from that data. Our proprietary algorithms in Threat Graph identify events that may or may not be directly related, but together could indicate a threat that could otherwise remain undetected. We are uniquely effective because we not only have a massive amount of high fidelity data to train our AI models but also because of our deep security expertise to guide our feature selection—all resulting in industry-leading efficacy and low false positives. Our rich set of continuously collected high fidelity endpoint data feeding our algorithms also enables us to use an active learning approach, where the models are continuously updated to fill in gaps identified in initial models and their performance is validated with this data prior to production use.
By leveraging a multi-tenant, cloud native solution, the data we analyze to stop breaches is both larger and more meaningful than the data from on-premise or single instance private cloud products. If Threat Graph discovers something in one customer environment, all customers benefit automatically and in real time. Taken together, our platform enables intelligent, dynamic automation at scale to detect threats and stop breaches.
We designed our Falcon platform with an open, interoperable, and highly extensible architecture. Because of our single data model, we only need to collect high fidelity endpoint data once from our agent, which we can use repeatedly for multiple use cases. Therefore, we can rapidly innovate, build, and deploy highly integrated modules to access additional market opportunities. Additionally, via the CrowdStrike Store, customers can discover, try, buy and deploy trusted partner applications that extend their investment in the CrowdStrike Falcon platform. We also built a rich set of APIs that allows us to ingest third-party data into our Falcon platform and allows our customers to expand the functionality of their existing security systems by writing their own programs and accessing the data on our platform.
Our Falcon platform includes our OverWatch threat hunting cloud module that combines the human intelligence of our elite security experts with the power of Threat Graph. Because our world class team can see potential attacks across our entire customer base, their expertise is enhanced by their constant visibility into the threat landscape. We are able to keep this team lean and scalable by leveraging automation and our Threat Graph. OverWatch is a force multiplier that extends the capabilities and improves the productivity of our customers’ security teams.
We offer our customers compelling business value that includes ease of adoption, rapid time-to-value, superior efficacy rates in detecting threats and preventing breaches, and reduced total cost of ownership by consolidating legacy, siloed security products in a single solution. We also allow thinly-stretched security organizations to automate previously manual tasks, freeing them to focus on their most important objectives. With the Falcon platform, organizations can transform how they combat threats, from slow, manual, and reactionary to fast, automated, and predictive, providing visibility across the entire threat lifecycle.
We primarily sell our platform and cloud modules through our direct sales team that leverages our network of channel partners to maximize effectiveness and scale. We amplify our sales presence by leveraging our technology alliance partners that can deliver, embed, or build applications with data and analytics from our Falcon platform. We are also enhancing our go-to-market strategy using a low-touch, trial-to-pay approach. In December 2017, we began to employ a trial-to-pay model in which we offer 15-day free trial access to Falcon Prevent, our next-generation antivirus module, to prospective customers directly from our website. In May 2018, we began offering Falcon Prevent for trial and purchase through the AWS Marketplace and have since expanded our modules available through the AWS Marketplace. We believe this approach enables a higher velocity of new customer acquisition and expansion, and extends our reach to customers of all sizes.
We have a low friction land-and-expand sales strategy. When customers deploy our Falcon platform, they can start with any number of cloud modules and we can activate additional cloud modules in real time on the same agent already deployed on the endpoint. Once customers experience the benefits of our Falcon platform, they often expand their adoption over time by adding more endpoints or purchasing additional modules. As of January 31, 2021, subscription customers that had adopted four or more modules, five or more modules and six or more modules increased to 63%, 47%, and 24%, respectively. Our dollar
4
Table of Contents
based net retention rate, which measures expansion in existing customers’ subscriptions over a 12 month period, was 125% as of January 31, 2021, demonstrating the power of our land-and-expand strategy.
Some of the world’s largest enterprises, government organizations, and high profile brands trust CrowdStrike to protect their business. As of January 31, 2021, we had 9,896 subscription customers worldwide. We began as a large enterprise solution, but the flexibility and scalability of our Falcon platform and enhanced go-to-market approach enable us to protect customers of any size—from hundreds of thousands of endpoints to as few as one.
We have experienced significant growth, with total revenue increasing from $249.8 million for fiscal 2019 to $481.4 million for fiscal 2020, representing year-over-year growth of 93%, and from $481.4 million for fiscal 2020 to $874.4 million for fiscal 2021, representing year-over-year growth of 82%. Subscription revenue grew from $219.4 million for fiscal 2019 to $436.3 million for fiscal 2020, a 99% increase, and from $436.3 million for fiscal 2020 to $804.7 million for fiscal 2021, a 84% increase. Our annual recurring revenue, or ARR, has grown from $312.7 million as of January 31, 2019 to $600.5 million as of January 31, 2020, a 92% increase, and from $600.5 million as of January 31, 2020 to $1.1 billion as of January 31, 2021, a 75% increase. We had net losses of $92.6 million, $141.8 million, and $140.1 million in fiscal 2021, fiscal 2020 and fiscal 2019, respectively. We expect to continue to incur net losses for the foreseeable future as we continue to invest in our business, and in particular, our sales and R&D capabilities, to address our large market opportunity.
Industry Background
There are a number of key trends that are driving the need for a new approach to security.
Cybersecurity Threats are Greater than Ever
Today’s cybersecurity threat landscape is more dangerous than ever. Breaches are complex and often executed over multiple steps known in the industry as the threat lifecycle. The typical threat lifecycle starts with an initial exploit to enter a system, historically using malware, but increasingly using malware-free or fileless methods, to penetrate endpoints and establish a beachhead inside the corporate perimeter. Once inside, adversaries move laterally across the corporate environment where they collect credentials and escalate privileges enabling the typical adversary to download a larger, more destructive malware program or connect with an external control source. At this stage in the threat lifecycle, the adversary is able to encrypt, destroy, or silently exfiltrate sensitive data.
Increasingly, adversaries are well-trained, possess significant technological and human resources, and are highly deliberate and targeted in their attacks. Adversaries today range from militaries and intelligence services of well-funded nation-states to sophisticated criminal organizations who are motivated by financial gains to hackers leveraging readily available advanced techniques. These groups and individuals are responsible for many breaches that involve theft or holding hostage financial data, intellectual property, and trade secrets. These attacks are pervasive, targeting a broad range of industries including technology, transportation, healthcare, financial services, governments and political organizations, utility, retail, and public infrastructure. On a number of occasions, adversaries have launched devastating, destructive attacks that have caused significant business disruption and billions of dollars in cumulative losses.
Proliferation of Workloads Expanding the Attack Surface
The rise of digital transformation, cloud computing, workforce mobility, and growth in connected devices has created a rapid expansion of workloads across endpoints and industries. As a result, devices, applications, and data are highly distributed and diverse, challenging organizations to monitor and protect all of their workloads running on various endpoints. The adoption of many of these technologies and the resulting disappearance of the corporate perimeter have expanded the attack surface and left many organizations increasingly vulnerable to breach. Today, workloads running on endpoints, such as laptops and servers, are the primary targets in a security attack since they are vulnerable and frequently are repositories of valuable and sensitive data, including intellectual property, authentication credentials, personally identifiable information, financial information, and other digital assets. As new workloads are provisioned on emerging mobile and IoT devices, oftentimes residing outside of the corporate perimeter, increasingly more sensitive and mission critical data will be generated and stored on these endpoints as well. Attacks such as Shamoon, WannaCry and NotPetya have shown that destroying or locking data on a large portion of an enterprise’s endpoints can cause widespread business disruption.
5
Table of Contents
On-Premise Security Architectures are Constrained
On-premise products are siloed, lack integration, and have limited ability to collect, process, and analyze vast amounts of data—attributes that are required to be effective in today’s increasingly dynamic threat landscape. Legacy vendors often deploy more agents to the endpoint as they layer on a patchwork of additional point product capabilities. This approach burdens endpoints by consuming additional storage space, memory, and processor capacity, degrading end user experience without providing effective security. In addition, integrating and maintaining numerous products, data repositories, and infrastructures across highly distributed enterprise environments is a costly and resource-intensive process for already thinly-staffed security teams.
Other Existing Security Products have Limitations
Legacy Signature-based Products. Signature-based products are designed to detect attacks that are already cataloged in a repository of previously identified threats but are not capable of preventing unknown threats or stopping associated breaches. These signatures, known as Indicators of Compromise, or IOCs, represent a reactive method of tracking cyberattacks. By the time IOCs are located, all they provide is evidence of compromise or breach that may have already resulted in substantial losses to the victim. If an attack vector is even slightly modified, a signature-based approach will no longer detect the attack and will fail to stop the breach. Many significant breaches seen in the last two decades have involved the failure of a legacy signature-based antivirus product to detect a previously unknown or modified version of a previously known attack.
Malware-focused Machine Learning Products. Traditionally, organizations have focused on protecting their networks and endpoints against malware-based attacks. These attacks involve malware built for the specific purpose of performing malicious activities, stealing data, or destroying systems. A malware-centric defensive approach will leave the organization vulnerable to attacks that do not leverage malware.
Application Whitelisting Products. Application whitelisting products resort to an “always allow” or “always block” policy on an endpoint in order to allow or prevent processes from executing. Whitelisting relies in part on manually creating and maintaining a complex list of rules, burdening end users and IT organizations. In order to avoid these management challenges, IT organizations often create special exceptions to the whitelist that attackers leverage to compromise endpoints. Furthermore, fileless attacks can exploit legitimate whitelisted applications, compromising the integrity of the whitelisting product.
Network-centric Security Products. Traditional network security vendors have focused their products on perimeter-based protection. However, these approaches have decreased in relevance and effectiveness as employees and workplace devices have expanded beyond the firewall and the use of encrypted traffic has increased creating blind spots and vulnerabilities that attackers are able to exploit. As the number of endpoints proliferates, and workforces become more distributed, this layer of defense cannot adequately protect information-rich endpoints and workloads that are outside the corporate perimeter.
Bolt-on Cloud Products. Many on-premise vendors have introduced cloud offerings by putting their on-premise products in the cloud. Such single-tenant products were not designed to run in the cloud and therefore continue to be siloed, lack integration, and possess limited scalability to identify threats across their customer base in real time. In addition, such products are complex to deploy, difficult to scale, brittle to maintain, costly to own, and can be ineffective in stopping breaches. Any product that was originally designed for on-premise deployments and migrated to the cloud cannot by definition be a cloud native solution.
Creation of the Security Cloud
Over the last 17 years, cloud computing has revolutionized many industries in enterprise software and created significant shifts in market share away from incumbents with on-premise or single instance cloud offerings. The cloud has enabled organizations to cost-efficiently scale their compute and storage resources, accelerate innovation, eliminate ongoing maintenance and administrative costs, and consolidate previously disparate and siloed products. During this period, new data technologies also emerged leveraging the cloud to enable more data collection, improve data analysis, and share key insights to drive better business outcomes and make more informed decisions.
The purpose-built, cloud native leaders that began from scratch with multi-tenant architectures, single data models, and SaaS business models have defined entirely new categories such as CRM Cloud, HR Cloud, and Service Management Cloud. We believe we are doing the same for security.
6
Table of Contents
An effective solution to address the modern cybersecurity threat landscape should combine multiple methods into an integrated, data-driven, and automated cloud-based platform in order to provide comprehensive breach protection across the entire threat lifecycle. Such a platform requires collecting, processing, analyzing, and correlating vast amounts of high fidelity endpoint events in the cloud. This platform needs to operate at web-scale, process events in real time, and benefit from the network effects of crowdsourced data to understand attacks that happen across millions of endpoints. We believe only a cloud native approach can address today’s threat landscape.
We believe we are defining a new category called the Security Cloud.
Our Solution
With our Falcon platform, we created the first multi-tenant, cloud native, intelligent security solution capable of protecting workloads across on-premise, virtualized, and cloud-based environments running on a variety of endpoints such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices. Our solution consists of our single intelligent lightweight agent and our powerful and dynamic cloud-based database Threat Graph. These two tightly integrated proprietary technologies continually collect, process, analyze and correlate vast amounts of high fidelity data across the entire threat lifecycle using a combination of AI and behavioral pattern-matching techniques to stop breaches. We implement this approach by crowdsourcing data across our entire customer base and taking advantage of economies of scale, which we believe enables our AI algorithms to be uniquely effective. The benefits of our cloud-based AI are automatically shared with customers across our community in real time. We combine multiple methods of detection, prevention, and response to known and unknown threats as well as malware and malware-free techniques across the threat lifecycle.
Our Falcon platform supports 19 cloud modules via a SaaS subscription-based model that spans multiple large markets, including corporate workload security, security and vulnerability management, managed security services, IT operations management, threat intelligence services, identity protection and log management. Our single data model and open cloud architecture enable us and third-party partners to rapidly innovate, build, and deploy new cloud modules to provide our customers with additional functionality across a myriad of use cases.
We designed our platform to be rapidly deployable, easy to use, and extensible, with the ability to consolidate point security products that have historically led to data silos and agent sprawl, into one comprehensive and integrated solution. Our platform allows our customers’ thinly-staffed security organizations to spend less time and fewer resources provisioning hardware, configuring supporting software systems, and performing ongoing maintenance work, freeing them to focus on their most important objectives. We aim to transform how organizations combat threats from slow, manual, and reactionary to fast, automated, and predictive.
Key Benefits of Our Solution
• The Power of the Crowd. Our crowdsourced data enables all of our customers to benefit from contributing to Threat Graph. As more high fidelity data is fed into our Falcon platform, there is more data to train our AI models with, increasing the overall efficacy of our Falcon platform. This benefits our customers and supports our efforts to gain more customers, creating a powerful network effect. Threat Graph can then learn and identify warning signs once and rapidly deliver protection to every customer in our community. Further, our AI algorithms are more effective because they are trained on such a broad and representative set of data that captures information about potential attacks throughout the entire threat lifecycle across our customer base.
• High Efficacy with Low False Positives. Our Falcon platform collects, processes, correlates, and analyzes high fidelity data on both real-world attacks and benign behavioral patterns to continually train and enhance our algorithms resulting in industry-leading threat detection and low false positive rates.
• Consolidation of Siloed Products. Integrating and maintaining numerous products, data and infrastructures across highly distributed enterprise environments leaves blind spots that hackers can exploit and is a costly and resource-intensive process. Our integrated platform unifies cloud modules addressing cloud workload security, next-generation antivirus, endpoint detection and response (EDR), device control, host firewall management, vulnerability management, forensic analysis, IT hygiene, threat hunting, and automated threat intelligence. Our platform enables our customers to reduce or streamline their siloed and layered security products, simplifying operations while providing a comprehensive solution.
7
Table of Contents
• Consolidation of Agents. We provide robust and diverse functionality through a single intelligent lightweight agent. Legacy vendors’ agents were designed to be single purpose, thus they often deploy multiple agents to the endpoint as they layer additional point product capabilities on top of their initial offering. This legacy approach burdens endpoints by consuming additional storage space, memory, and processor capacity, degrading the end user experience. Our single agent approach allows customers to consolidate and remove numerous agents from their infrastructure and restore endpoint performance. Because we collect data once from our agent and use it across multiple use cases, the Falcon platform can offer a wide range of functionality without burdening the endpoint.
• Rapid Time to Value. On-premise security solutions take time to install, configure, deploy, and maintain. We streamline the deployment process by providing cloud-delivered security with protection policies that work from day one, eliminating lengthy implementation periods and professional services engagements. Moreover, once a customer deploys our lightweight agent on their endpoints, we can activate additional cloud modules in real time.
• Constant Protection Anywhere. Our cloud-based model allows us to secure customer workloads such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices. In addition, once our agent is deployed on an endpoint it continues to protect the endpoint and track activity even when offline.
• Elite Security Team as a Force Multiplier. Our OverWatch threat hunting cloud module combines world class human intelligence from our elite security experts with the power of Threat Graph. OverWatch is a force multiplier that extends the capabilities and improves the productivity of our customers’ security teams. Because our world class team can see attacks across our entire customer base, their expertise is enhanced by their constant visibility into the threat landscape.
• Bridging the Security Skills Gap through Automation. Our solution automates certain previously manual tasks, freeing up personnel to focus on their most important objectives. Our Falcon Complete module provides a turnkey solution that combines endpoint security with remediation and response capabilities.
• Lowering Total Cost of Ownership. Our cloud-based platform eliminates our customers’ need for initial or ongoing purchases of hardware and does not require their personnel to configure, implement or integrate disparate point products. Additionally, our comprehensive platform reduces overall personnel costs associated with ongoing maintenance, as well as the need for software patches and upgrades for separate products.
Growth Strategy
Key elements of our growth strategy include:
• Growing Our Customer Base by Replacing Legacy and Other Endpoint Security Products. Given the limitations of existing legacy and other endpoint security products, many organizations are replacing their existing legacy and other endpoint security products with our Falcon platform. We grew our subscription customer base by 4,465 customers from 5,431 at January 31, 2020, to 9,896 at January 31, 2021, representing an 82% increase. We will continue to invest in customer acquisition programs, including our channel partnerships and new programs, like our free trial program of Falcon Prevent that is easily downloaded from our website and AWS Marketplace.
• Further Penetrating Existing Customers. Our growth will depend in part on our ability to continue to expand our relationships with our customers by deploying on additional endpoints in their environment and cross selling more cloud modules. When customers deploy our lightweight agent, they can easily add additional cloud modules. We also offer in-application trial usage of additional modules to cross-sell to existing customers. While some new customers initially deploy our Falcon platform broadly across the organization, others elect to deploy only in selected business units and later deploy on additional endpoints and subscribe to additional modules. Over time, we seek to deploy our solution enterprise wide for all customers. The power of our land-and-expand strategy is evidenced by our 125% dollar-based net retention rate as of January 31, 2021.
• Leveraging Our Falcon Platform to Enter New Markets. Because we leverage a single data model and open cloud architecture, we are uniquely positioned to continue innovating and rapidly deploying new cloud modules on our platform. For example, Falcon Discover includes use cases outside of security, such as application license management, AWS spend analysis, and asset inventory. Because our lightweight agent collects diverse endpoint data
8
Table of Contents
once for repeated use, we can expand our addressable market by rapidly adding new cloud modules that leverage this data. We intend to continue to develop new cloud modules for broader endpoint use cases.
• Broadening Our Reach into New Customer Segments. While we initially targeted large sophisticated enterprises, we have expanded our go-to-market efforts to include customers of all sizes with a dedicated inside sales team focused on smaller organizations. We also released Falcon Complete in 2018, our turnkey solution that combines the most popular cloud modules of our Falcon platform with our remediation and response capabilities, to create a solution for customers with limited or no internal security expertise. As a result, we can sell our Falcon platform to the largest enterprises or smallest businesses with any level of security sophistication and budget. We continue to look for new ways to broaden our reach into new customer segments.
• Extending Our Falcon Platform and Ecosystem. We designed our architecture to be open, interoperable, and highly extensible. We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity, which provides an ecosystem of trusted partners and applications for our customers. In the future we plan to continue investing in the CrowdStrike Store to empower our partners by making it easier to build applications and to enable our customers to more easily discover, try, and purchase additional cloud modules from both trusted partners and us.
• Broadening Our Reach into the U.S. Federal Government Vertical. We are investing in the acquisition of customers in the U.S. federal government vertical. Our platform is authorized by several federal agencies via the Federal Risk and Authorization Management Program (“FedRAMP”). To further meet the compliance demands of the federal government, customers can elect to deploy the Falcon platform in the AWS GovCloud. We have also successfully been embedded into several strategic government-wide cybersecurity programs and contracts, such as the Department of Homeland Security’s Continuous Diagnostics and Mitigation Approved Products List, which serves to provide federal agencies with innovative security tools.
• Expanding Our International Footprint. We are expanding our international operations and intend to invest globally to broaden our international footprint. We grew our international revenue from $124.9 million for fiscal 2020, to $247.0 million for fiscal 2021, representing an increase of 98%. We intend to grow our international customer base by increasing our investments in our overseas operations, including adding headcount in Europe, the Middle East, Asia-Pacific, and Japan and establishing overseas data centers.
Falcon Platform
Our Falcon platform is composed of two tightly integrated proprietary technologies: our lightweight agent and Threat Graph. The Falcon platform offers a unified set of cloud-delivered technologies that power a wide range of modules including next-generation antivirus, EDR, device control, host firewall management, managed threat hunting, IT hygiene, vulnerability management, and threat intelligence. The Falcon platform also encompasses recently acquired technologies where integration may be ongoing. We can rapidly and cost effectively develop and deliver additional cloud modules on our Falcon platform, and are expanding options for our new customers to test modules on a trial basis and in-application trials for existing customers. Our expanding set of open APIs allows customers and partners to build their own capabilities on top of the Falcon platform. With our Falcon platform, we can crowdsource data and deliver a variety of cloud modules to detect and stop breaches.
Our Cloud Modules
Our cloud modules integrate seamlessly with the Falcon platform to provide functionality in the endpoint security, security and IT operations (including vulnerability management), and threat intelligence markets. Today, our cloud modules include:
Cloud Security
Falcon Cloud Workload Protection—Cloud Runtime Protection. Falcon Cloud Workload Protection provides comprehensive breach protection at run-time for workloads and containers as well as detecting vulnerabilities before services and images are deployed. Falcon Cloud Workload Protection reduces the attack surface by automatically detecting vulnerabilities, hidden malware, secrets, keys, and more, enabling customers to build, run, and deploy secure applications with speed and confidence.
9
Table of Contents
Falcon Horizon—Cloud Security Posture Management. Falcon Horizon delivers unified visibility, threat detection and continuous monitoring and compliance for multi-cloud environments. Falcon Horizon automates the process to detect cloud related misconfigurations, vulnerabilities, and identity-based risks, providing step-by-step remediation and giving developers guardrails to avoid costly mistakes.
Discover for Cloud and Containers—Cloud Service Discovery. Discover for Cloud and Containers delivers comprehensive visibility of cloud assets, security configurations, workloads and containers across multi-cloud environments so customers can mitigate risks and reduce the attack surface.
Endpoint Security
Falcon Prevent—Next-Generation Antivirus . Falcon Prevent provides next-generation antivirus capabilities to customers, delivering comprehensive protection to defend customers against both malware and fileless attacks.
Falcon Insight—Endpoint Detection and Response. Falcon Insight provides EDR capabilities to customers, allowing for continuous and comprehensive visibility to notify our customers what is happening on their endpoints in real time.
Falcon Device Control—Device Control. Falcon Device Control provides administrators with a high degree of visibility and granular control of USB peripheral devices.
Falcon Firewall Management—Host Firewall Management. Falcon Firewall Management provides centralized management of the firewall capabilities native to the host operating system, allowing customers to create, enforce, and maintain host firewall policies.
Security and IT Operations
Falcon Discover—IT Hygiene. Falcon Discover identifies rogue systems and applications in our customers’ networks, and monitors the use of privileged user accounts anywhere in a customer’s environments. The module also enables use cases outside of security, such as application license management, AWS spend analysis, and asset inventory.
Falcon Spotlight—Vulnerability Management. Falcon Spotlight identifies vulnerabilities in real time that exist across our customer endpoints. The module does not depend on scanning systems for vulnerabilities, a process that can often take days or weeks for an enterprise, and instead leverages data already collected by our agent to provide instant and accurate real-time visibility into an enterprise’s vulnerability exposure.
Falcon Forensics—Forensic Data for Analysis of Cybersecurity Incidents. Falcon Forensics streamlines the collection of point-in-time and historic forensic triage data for robust analysis of cybersecurity incidents, enabling responders to quickly identify relevant data with preset dashboards and rapidly investigate.
Managed Services
Falcon Complete—Turnkey Security Solution. Falcon Complete provides comprehensive monitoring, management, response, and remediation solution to our customers and is designed to bring enterprise level security to companies that may lack enterprise level resources. It is backed by an underwritten limited warranty policy for breaches.
Falcon OverWatch—Threat Hunting. Falcon OverWatch is a threat hunting solution that consists of an elite team of dedicated security experts who work with the power of Threat Graph to proactively identify threats for our customers.
Threat Intelligence
Falcon X—Threat Intelligence. Falcon X integrates threat intelligence into endpoint protection and provides automated analysis of detected threats to provide insight into the capabilities, motivation and attribution of attacks. In addition to the standard Falcon X offering, we also offer premium options that include global threat research and reporting from our team of intelligence analysts.
10
Table of Contents
Falcon Search Engine—Malware Search. Falcon Search Engine enables customers to search in real time across approximately 2.8 petabytes of malware collected in our Falcon platform and indexed by our proprietary binary data indexing technology.
Falcon Sandbox—Malware Analysis. Falcon Sandbox allows our customers to analyze unknown files for malicious behavior by detonating them safely in virtual machines.
Falcon X Recon—Situational Awareness . Falcon X Recon allows our customers to identify and mitigate digital risks on the hidden areas of the clear, deep and dark web. These risks include digital fraud, data theft exposure, social media impersonations, and much more.
Identity Protection
Falcon Zero Trust—Zero Trust Security. Frictionless Zero Trust security with real-time threat prevention and IT policy enforcement using identity, behavioral and risk analytics.
Falcon Identity Threat Detection—Identity Threat Detection. Visibility for identity-based attacks and anomalies, comparing live traffic against behavior baselines and rules to detect attacks and lateral movement.
Log Management
Humio—Log Management. Humio is a high-performance, index-free cloud log management solution that allows customers to collect logs from any data source and to search and query streaming data in real-time.
Technology
We have designed an innovative architecture from the ground up to overcome the limitations of existing security products and deliver cloud-based solutions. The key design principles of our Falcon platform include:
Cloud Native Architecture. We built the Falcon platform entirely in and for the cloud, enabling collection and analysis of a massive, crowdsourced dataset from all of our customers to stop breaches. Our platform is designed to be redundant, resilient, and high performing. Delivering security from the cloud enables agility, ease of use, and protection for workloads on a variety of endpoints wherever they are located. As customer adoption grows, the network effect of each additional endpoint added to the Falcon platform will amplify the breadth and depth of our dataset and intelligence.
Falcon Agent. We designed an intelligent lightweight agent that is installed on each endpoint or cloud workload. These agents incorporate identification and prevention of known malware, machine learning for unknown malware, exploit blocking and advanced behavioral techniques, to protect workloads across all endpoints while capturing and recording high fidelity endpoint data. Our agents continue to protect workloads running on endpoints even when offline. The agent recommences transmitting data to our Falcon platform when the connection to the cloud has been re-established. Our lightweight agent is built to support Windows, Mac and Linux operating systems. The agent is hardened against attacks and uses a combination of kernel and user-mode modules to collect high fidelity endpoint events as they take place on a system. It correlates these events with a local situational model on the endpoint, analyzes via agent-based machine learning models and is capable of taking a variety of preventative and responsive actions on the endpoint, either automatically or via human control. Events are streamed by the agent to the cloud in real time in order to be further analyzed in the Threat Graph, where additional correlation and AI algorithms can be applied. The agent is also capable of being remotely reconfigured in real time based on analytics in our cloud platform in order to collect and analyze different events or take other actions.
Threat Graph. Threat Graph is a proprietary, powerful, and dynamic graph database. Threat Graph continually looks for malicious activity by combining AI with behavioral pattern-matching techniques to look beyond file features and track the behaviors of every software program executed on an endpoint in a customer’s network environment. By applying powerful graph analytics and AI algorithms to cybersecurity, we enrich the data collected with our proprietary and third-party threat intelligence, such as adversary capabilities, motivations, attributions, and threat indicators. The graph data model allows the AI algorithms to identify relationships between events that are not directly related but which could indicate an attack that would otherwise remain undetected. We believe that our AI algorithms are advantaged by the rich proprietary dataset that we use to
11
Table of Contents
train them. Threat Graph provides customers with complete real time and historical visibility and insight into events occurring on their endpoints for hunting and searching.
Threat Graph also provides query and hunting capability over the full set of high fidelity events collected in the graph. This correlated data, natively represented in a graph structure, enables new products and cloud modules to be created rapidly since the platform provides the visibility, collection, correlation and actions over data as reusable building blocks. This collect-once, use repeatedly approach is the reason why we have been able to deliver new cloud modules covering IT hygiene and vulnerability management quickly and enables us to continue expanding the Falcon platform rapidly in the future.
High Fidelity Data and Smart Filtering. Absent an intelligent agent, a typical endpoint generates approximately 100 gigabytes of unfiltered system event data per day. After this data is compressed, or data shaped, a typical enterprise organization with 100,000 endpoints would generate over one petabyte of endpoint events daily. The presence of a local graph model in our agent enables it to track the state of the machine in real time, perform rapid machine learning and behavioral analysis, and provide efficient event streaming to the cloud. We call this “smart filtering.” This allows us to keep performance overhead on the endpoint to a minimum, dramatically reduce the bandwidth required for agent-cloud communication, efficiently process large volumes of data, and separate the signal from the noise. The Falcon agent collects and analyzes unfiltered data with local machine learning and behavioral algorithms on the endpoint but only streams high fidelity endpoint events to the cloud to only send what is necessary for detection, prevention and investigation of attacks. This smart filtering architecture allows us to reduce network load for customers to approximately five megabytes per endpoint per day. The Falcon platform collects an array of high fidelity endpoint events, such as code execution, network, file system and user activity. This information can be used for a variety of use cases beyond security, such as IT operations and vulnerability management.
Management Interface. The Falcon platform management interface gives customers an intuitive and informative view of their complete environment, with timely alerts and detailed search capabilities. We provide real-time endpoint and cloud workload visibility to allow customers to review details and respond to threats instantly and effectively, from anywhere, and maintain an index of these events for future use.
APIs and Integrations. Our Falcon platform and architecture is built around a rich set of APIs that efficiently and effectively complement and expand a customer’s existing security infrastructure, such as security information event management, or SIEMs, and intrusion prevention systems and intrusion detection systems. The platform includes streaming, query and batch APIs allowing customers and partners to integrate a variety of solutions seamlessly. It also includes rich management and control APIs. The platform allows third parties to develop additional cloud modules and features, furthering the power of the Falcon platform. By connecting existing security systems to the Falcon platform, we allow our customers to further leverage their security investments.
Data Center Operations
We have data center co-location facilities throughout the United States and in Europe, and we also utilize AWS data centers located in the United States and Europe. Our technology infrastructure, combined with select use of AWS resources, provides us with a distributed and scalable architecture on a global scale.
Professional Services
In addition to our Falcon platform and cloud modules, we also offer incident response and forensic investigatory services, technical assessment and strategic advisory services, as well as training to assist organizations that have experienced a breach or are assessing their security posture and ability to respond to breaches.
• Incident Response/ Forensics Services. Our incident response services typically begin by deploying our lightweight agent to a customer’s endpoints to provide comprehensive visibility and determine if an attacker is currently in the environment, what assets have been compromised, and how much damage has been done. We also provide customized remediation planning by providing a strategy to eject attackers out of the network, lock down credentials from further use, and ensure adversaries stay out. In addition to providing valuable breach remediation to our customers, our incident response services also act as a strong lead generation engine for our Falcon platform and cloud modules. After experiencing the benefits of our platform firsthand, many of our incident response customers become subscription customers. Among organizations who first became a customer after February 1, 2019, for each $1.00 spent by those
12
Table of Contents
customers on their initial engagement for our incident response or proactive services, as of January 31, 2021, we derived an average of $5.51 in ARR from those subscription contracts.
• Technical Assessment and Strategic Advisory Services. Our proactive security services include technical assessment services designed to help organizations understand their cyber maturity levels. These services include cybersecurity maturity assessments, security program in-depth assessments, service organization control assessments, cloud security assessments, IT hygiene assessments and active directory security assessments. We also advise customers on readiness and preparation through the execution of table-top exercises, live fire exercises, red team/blue team assessments and advanced adversary emulation exercises. These services are designed to evaluate our customers’ security profile so they can identify areas of vulnerability, secure their network and improve their response if their defenses are breached.
• Training. We offer training and certification services to customers and partners on CrowdStrike technologies and cybersecurity topics to facilitate the adoption of CrowdStrike and to broaden and deepen their skills. CrowdStrike University is an online learning management system that organizes all CrowdStrike e-learning, instructor-led training and certification in one place, providing a personalized learning experience for individuals who have an active training subscription. Beginning the first quarter of fiscal year 2022 CrowdStrike University plans to offer proctored exam certifications through industry leading training partner Pearson Vue for its Falcon Administration, Incident Response, and Threat Hunting training programs.
Customers
Some of the world’s largest enterprises, government organizations, and high profile brands trust us to protect their business. As of January 31, 2021, we had 9,896 subscription customers worldwide. Historically, we and our channel partners have primarily sold to large organizations, but have increasingly focused on selling to small and medium-sized businesses, particularly through our trial-to-pay model. We engage our customers through our global customer and technical advisory boards in which we solicit feedback from our customers on a regular basis allowing us to understand their evolving needs. We have used this feedback to develop new cloud modules, such as Falcon Insight, and we intend to continue to develop new cloud modules based on our customer’s feedback. Our business is not dependent on any particular end customer.
Sales and Marketing
Our sales and marketing organizations work together closely to drive market awareness, build a strong sales pipeline and cultivate customer relationships to drive revenue growth.
Sales
We primarily sell subscriptions to our Falcon platform and cloud modules through our direct sales team, which is comprised of field sales and inside sales professionals who are segmented by a customer’s number of endpoints. Our sales team also leverages our network of channel partners. We also use our sales team to identify current customers who may be interested in free trials of additional cloud modules, which serves as a powerful driver of our land and expand model. By segmenting our sales teams, we can deploy a low-touch sales model that efficiently identifies prospective customers.
Marketing
Our marketing organization is focused on building our brand reputation, increasing the awareness and reputation of our platform, and driving customer demand. As part of these efforts, we deliver targeted content to demonstrate thought leadership in the security industry, including speaking engagements with the security industry’s foremost organizations to provide expert advice, issuing regular reports on the state of the industry, educating the public about the cybersecurity threats, and identifying and naming adversary groups. We also engage in paid media, web marketing, industry and trade conferences (including our annual Fal.Con conference), analyst engagements, whitepaper development, demand generation via digital and web, and targeted displacement campaigns. We employ a wide range of digital programs, including search engine marketing, online and social media initiatives, and content syndication to increase traffic to our website and encourage new customers to sign up for a 15-day free trial of the Falcon platform. Additionally, we engage in joint marketing activities with our channel and technology alliance partners. In December 2017, we began to employ a trial-to-pay model in which we offer 15-day free trial access to Falcon Prevent to prospective customers directly from our website, a program that has continued to grow over time. In May 2018, we announced that Falcon Prevent was available for trial and purchase from the AWS Marketplace and have since
13
Table of Contents
expanded our modules available through the AWS Marketplace. In February 2019, we launched the CrowdStrike Store, a marketplace platform that enables customers access to third-party applications and add-on capabilities to extend the value of the Falcon platform. In 2020, we significantly expanded our technical and go-to-market alliances, including new partnerships with identity providers and business consulting firms in addition to launching new capabilities in the identity protection space.
Partnership Ecosystem
We work with a number of technology alliance partners to design go-to-market strategies that combine our platform with products or services provided by our technology alliance partners. These partner integrations deliver more secure solutions and an improved end user experience to their customers. Our technology alliance partnerships focus on security analytics, network and infrastructure security, threat platforms and orchestration, and automation. We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity and the industry’s first unified security cloud ecosystem of trusted third-party applications. In addition, we recently announced the launch of Falcon for Amazon Web Services (AWS). Available in the AWS Marketplace, Falcon for AWS allows customers to easily purchase and take advantage of the metered billing (pay-as-you-go) pricing option to scale their consumption as their business needs change.
Research and Development
Our research and development organization is responsible for the design, architecture, operation and quality of our cloud native Falcon platform. In addition, the research and development organization works closely with our customer success teams to ensure customer satisfaction is the top priority.
Our success is a result of our continuous drive for innovation. Our internal team of security experts, researchers, intelligence analysts, and threat hunters continuously analyzes the evolving global threat landscape to develop products that defend against today’s most sophisticated and stealthy attacks and reports on emerging security issues. We invest substantial resources in research and development to enhance our Falcon platform, and develop new cloud modules, features and functionality. We believe timely development of new, and enhancement of our, products, services, and features is essential to maintaining our competitive position. We work closely with our customers and channel partners to gain valuable insight into their security management practices to assist us in designing new cloud modules and features that extend the capability of our platform. Our technical staff monitors and tests our software on a regular basis, and we also make our Falcon platform available for third-party validation. We also maintain a regular release process to update and enhance our existing solutions. In addition, we engage security consulting firms to perform periodic vulnerability analysis of our solutions.
Our research and development leadership team is located in Seattle, Washington and Sunnyvale, California. We also maintain research and development centers in Irvine, California, and Israel. We employ subject matter experts in a number of jurisdictions around the world. We plan to continue to dedicate significant resources to research and development.
Competition
The market for our services is intensely competitive and characterized by rapid changes in technology, customer requirements, and industry standards and by frequent new product and service offerings and improvements. We compete with an array of established and emerging security solution vendors. Conditions in our market could change rapidly and significantly as a result of technological advancements, partnerships, or acquisitions by our competitors or continuing market consolidation. With the introduction of new technologies and market entrants, we expect the competitive environment to remain intense. Our competitors include the following by general category:
• legacy antivirus product providers, such as McAfee, LLC, Broadcom Inc.’s Symantec Enterprise division, and Microsoft Corporation, who offer a broad range of approaches and solutions with traditional antivirus and signature-based protection;
• alternative endpoint security providers, such as BlackBerry Cylance, VMware Carbon Black and SentinelOne, who offer point products based on malware-only or application whitelisting techniques; and
• network security vendors, such as Palo Alto Networks, Inc. and FireEye, Inc., who are supplementing their core perimeter-based offerings with endpoint security solutions.
14
Table of Contents
We compete on the basis of a number of factors, including but not limited to our:
• ability to identify security threats and prevent security breaches;
• ability to integrate with other participants in the security ecosystem;
• time to value, price, and total cost of ownership;
• brand awareness, reputation, and trust in the provider’s services;
• strength of sales, marketing, and channel partner relationships; and
• customer support, incident response, and proactive services.
Although certain of our competitors enjoy greater resources, recognition, deeper customer relationships, larger existing customer bases, or more mature intellectual property portfolios, we believe that we compete favorably with respect to these factors and that we are well positioned as a leading provider of endpoint and workload security solutions.
Intellectual Property
We believe that our intellectual property rights are valuable and important to our business. We rely on trademarks, patents, copyrights, trade secrets, license agreements, intellectual property assignment agreements, confidentiality procedures, non-disclosure agreements, and employee non-disclosure and invention assignment agreements to establish and protect our proprietary rights. Though we rely in part upon these legal and contractual protections, we believe that factors such as the skills and ingenuity of our employees and the functionality and frequent enhancements to our solutions are larger contributors to our success in the marketplace.
As of January 31, 2021, we had 65 issued patents and 102 pending patent applications in the United States and other countries. Our issued patents expire between 2032 and 2039. These patents and patent applications seek to protect our proprietary inventions relevant to our business. We intend to pursue additional intellectual property protection to the extent we believe it would be beneficial and cost-effective. Despite our efforts to protect our intellectual property rights, they may not be respected in the future or may be invalidated, circumvented, or challenged. Our industry is characterized by the existence of a large number of patents and frequent claims and related litigation based on allegations of patent infringement or other violations of intellectual property rights. We believe that competitors will try to develop products that are similar to ours and that may infringe our intellectual property rights. Our competitors or other third-parties may also claim that our security platform and other solutions infringe their intellectual property rights. In particular, some companies in our industry have extensive patent portfolios. From time to time, third parties have in the past and may in the future assert claims of infringement, misappropriation and other violations of intellectual property rights against us or our customers, with whom our agreements may obligate us to indemnify against these claims. Successful claims of infringement by a third party could prevent us from offering certain products or features, require us to develop alternate, non-infringing technology, which could require significant time and during which we could be unable to continue to offer our affected products or solutions, require us to obtain a license, which may not be available on reasonable terms or at all, or force us to pay substantial damages, royalties, or other fees. For additional information, see the section titled “Risk Factors—Risks Related to Our Business—The success of our business depends in part on our ability to protect and enforce our intellectual property rights.”
Backlog
We enter into both single and multi-year subscription contracts for our solutions. We generally invoice the entire amount at contract signing prior to commencement of subscription period. Until such time as these amounts are invoiced, they are not recorded in deferred revenue or elsewhere in our consolidated financial statements, and are considered by us to be backlog. As of January 31, 2021, we had backlog of approximately $448.2 million . Of this amount, approximately $164.4 million is not reasonably expected to be billed in fiscal 2021. We expect backlog will change from period to period for several reasons, including the timing and duration of customer agreements, varying billing cycles of subscription agreements, and the timing and duration of customer renewals. Because revenue for any period is a function of revenue recognized from deferred revenue under contracts in existence at the beginning of the period, as well as contract renewals and new customer contracts during the period, backlog at the beginning of any period is not necessarily indicative of future revenue performance. We do not utilize backlog as a key management metric internally.
15
Table of Contents
Seasonality
Given the annual budget approval process of many of our customers, we see seasonal patterns in our business. We expect these seasonal variations to become more pronounced in future periods, with net new ARR generation being greater in the second half of the year, particularly in the fourth quarter, as compared to the first half of the year. In addition, we also experience seasonality in our operating margin, with a lower margin in the first half of our fiscal year due to a step up in costs for payroll taxes, new hires, and annual sales and marketing events. This also impacts the timing of operating cash flow and free cash flow.
Human Capital Resources
As of January 31, 2021, we had 3,394 full-time employees. We also engage temporary employees and consultants as needed to support our operations. None of our employees in the United States are represented by a labor union or subject to a collective bargaining agreement. In certain countries in which we operate, we are subject to local labor law requirements which may automatically make our employees subject to industry-wide collective bargaining agreements. We have not experienced any work stoppages, and we consider our relations with our employees to be good.
Attraction, Retention, and Talent Development
Supporting our people is a foundational value for CrowdStrike. We believe the company’s success depends on our ability to attract, develop and retain key personnel. The skills, experience and industry knowledge of key employees significantly benefit our operations and performance.
Our talent sourcing is aligned to our organizational strategy to provide the expertise and skills needed to move our mission forward. We have created a high performance talent model that pinpoints the top traits and qualities we look for in talent and that may already exist within the organization, then consistently use that model to develop interview questions, screen candidates, and make hiring decisions.
We continue to market to and recruit technical talent in diverse communities by engaging as a high-level sponsor or partner of professional conferences and organizations such as Grace Hopper, Society of Women Engineers, Blavity Afrotech World, Hire Military, Black Girls Code, Thurgood Marshall College Foundation, and others.
To attract high performers, we have a team dedicated to building and promoting our employer brand focused on creating a strong employer value proposition:
• Competitive pay and benefits
• Flexible working arrangements
• Role and task diversity
• Professional development opportunities
• Organizational reputation and culture
We provide robust compensation and benefits programs to help meet the needs of our employees. In addition to base salary, these programs (which vary by country/region) include annual bonuses, equity awards, an employee stock purchase plan, a 401(k) plan, healthcare and insurance benefits, health savings and flexible spending accounts, paid time off, family leave, family care resources, flexible work schedules, adoption and surrogacy assistance, employee assistance programs, tuition assistance and on-site services such as health and fitness centers.
We invest resources to develop the talent needed to remain a leader in cybersecurity. We deliver numerous training opportunities, provide rotational assignment opportunities, have expanded our focus on continuous learning and development, and implemented new methodologies to manage performance, provide feedback, and develop talent.
16
Table of Contents
Remote-First Distributed Workforce
For CrowdStrike, the ability to work remotely is a deliberate strategy that we believe fuels rapid innovation and attracts the best and brightest around the world. Our culture is purpose-built around a remote-first way of working, creating a competitive advantage for both the company and its customers and minimizing disruption from localized issues such as natural disasters, political events, or health emergencies like COVID-19.
CrowdStrike has had a distributed workforce since its inception. Before COVID-19, 70% of our workforce, including nearly all engineering and technology teams, worked on a remote basis. 100% of our workforce is remote in response to COVID-19 and we do not have immediate plans to return to physical offices.
Since the Company’s inception, we recognized that creating high-functioning, effective remote-first teams would require careful planning and system design to not only establish the culture but help it grow and evolve organically. We have designed our processes, systems, and teams so that people can perform their jobs without needing to be physically present in the same room or even in the same time zone. Part of supporting our remote-first culture also involves actively encouraging personal well-being through initiatives, including wellness programs, engagement programs (speaker series, employee resource groups, gift exchanges, mentorship opportunities, virtual events, etc.), community outreach activities, recognition programs, and groups to connect people, no matter where they are geographically, with similar interests, life circumstances or backgrounds.
Diversity, Equity, and Inclusion
A diverse, equitable, and inclusive culture fuels creative excellence and innovation, helping people achieve their best work. We continue to strive to advance our efforts to build an equitable workplace and formally establish it as part of CrowdStrike's mission and organization.
We strive to create an environment where everyone feels seen, heard, and empowered to succeed. Through employee resource groups, internal development programs, allyship training, speaker series, and networking opportunities, we are empowered to come together to create a workplace that reflects the diverse communities around us.
Setting a diverse workforce up for success requires a commitment to the practices of inclusion in everything we do. What a practice of inclusion means to us is that we are creating an environment and providing tools that help our people understand how to actively involve every employee’s ideas, knowledge, perspectives, approaches, and styles and how to engage all of our people via a mindful approach to organizational design and experiences that feels accessible and relevant to everyone.
Employee Resource Groups
Employee Resource Groups are an integral component of our commitment to foster community, promote a sense of belonging, facilitate organizational change, and drive a greater understanding of the diversity of perspectives we have across CrowdStrike. In addition to the Embracing Equity majority ally group, we have five official Employee Resource Groups and we are anticipate additional groups in the future:
• Women of CrowdStrike
• Veterans of CrowdStrike
• Pride Team (LGBTQ)
• Green Team (Sustainability)
• Team BELIEVE (Black employees)
Our Employee Resource Groups are employee led, self-directed, voluntary groups that align with our organizational mission, values, and goals that offer opportunities for groups to network, recommend business initiatives and process improvements, increase organizational awareness and allyship, and create opportunities for talent development. Employees who join an Employee Resource Group can:
• Network and build community with people with similar interests, life circumstances or backgrounds.
17
Table of Contents
• Serve as champions for inclusion and belonging at CrowdStrike and help identify opportunities for us to become more inclusive.
• Identify initiatives and best practices throughout the organization and make recommendations to the business to help spark and facilitate change.
Executive Officers
The following table sets forth certain information with respect to our current executive officers as of March 18, 2021:
Name: Age: Position:
George Kurtz 50 President, Chief Executive Officer and Director
Burt W. Podbere 55 Chief Financial Officer
Colin Black 57 Chief Operating Officer
Michael Carpenter 45 President, Global Sales and Field Operations
Shawn Henry 58 President, CrowdStrike Services and Chief Security Officer
There is no family relationship between any of our directors or executive officers and any other director or executive officer.
George Kurtz - President, Chief Executive Officer, and Director
Mr. Kurtz is one of our co-founders and has served as our President, Chief Executive Officer, and a member of our board of directors since November 2011. From October 2004 to October 2011, Mr. Kurtz served in executive roles at McAfee, Inc., a security technology company, including as Executive Vice President and Worldwide Chief Technology Officer from October 2009 to October 2011. In October 1999, Mr. Kurtz founded Foundstone, Inc., a security technology company, where he served as its Chief Executive Officer until it was acquired by McAfee, Inc. in October 2004. Since November 2017, he has also served as Chairman as a board member, and as President for the CrowdStrike Foundation, a nonprofit established to support the next generation of talent and research in cybersecurity and artificial intelligence through scholarships, grants, and other activities. He has also served on the board of directors of Hewlett Packard Enterprise, an enterprise information technology company, since June 2019. Mr. Kurtz holds a B.S. in Accounting from Seton Hall University. Mr. Kurtz also holds a CPA license from the State of New Jersey with an inactive status.
Burt W. Podbere - Chief Financial Officer
Mr. Podbere has served as our Chief Financial Officer since September 2015. From May 2014 to August 2015, Mr. Podbere served as Chief Financial Officer for OpenDNS, Inc. (acquired by Cisco in 2015), a cloud-delivered network security company, where he oversaw the finance function. From October 2011 to April 2014, he served as Chief Financial Officer for Net Optics, Inc. (acquired by Ixia in 2013), a manufacturer of network monitoring and intelligent access solutions for physical and virtual networks. Since November 2017, he has also served as Treasurer and as a board member for the CrowdStrike Foundation, a nonprofit established to support the next generation of talent and research in cybersecurity and artificial intelligence through scholarships, grants, and other activities. Mr. Podbere is a Chartered Accountant and holds a B.A. from McGill University.
Colin Black - Chief Operating Officer
Mr. Black has served as our Chief Operating Officer since January 2017 and as our Chief Information Officer from November 2015 to December 2017. From May 2012 to November 2015, he served as Chief Information Officer for Kratos Defense and Security Solutions. Inc., a provider of advanced engineering, security, surveillance, and information technology services. From August 2008 to May 2012, he served as Chief Information Officer for Cymer, LLC. a developer and manufacturer of lithography light sources used in the semiconductor industry. Since November 2017, he has also served as a board member, and until November 2020 as Secretary, for the CrowdStrike Foundation, a nonprofit established to support the next generation of talent and research in cybersecurity and artificial intelligence through scholarships, grants, and other activities. Mr. Black holds a B.S. in Electronics Engineering from the University of Glasgow.
18
Table of Contents
Michael Carpenter - President Global Sales and Field Operations
Mr. Carpenter has served as our President, Global Sales and Field Operations since November 2016. From February 2014 to September 2016, he served as President of Global Sales and Field Operations for Tanium Inc., an endpoint security and systems management company. From December 2012 to January 2014, Mr. Carpenter served as President. Americas Sales for Intel Security Group, a global computer security software company. Mr. Carpenter holds a B.A. in Accounting from the University of Massachusetts Lowell.
Shawn Henry - President, CrowdStrike Services and Chief Security Officer
Mr. Henry has served as President of CrowdStrike Services and our Chief Security Officer since March 2012. Mr. Henry previously worked for the FBI from 1987 through March 2012, including most recently as Executive Assistant Director of the FBI's Criminal, Cyber, Response and Services Branch. Since June 2016, Mr. Henry has served as a faculty member specializing in cybersecurity for the National Association of Corporate Directors, an organization providing training and education for private and public company directors. Since June 2015, Mr. Henry has served as a cybersecurity and national security analyst for NBC News. Mr. Henry holds a B.B.A. from Hofstra University and an M.S. in Criminal Justice from Virginia Commonwealth University.
Corporate Information
Our principal executive offices are located at 150 Mathilda Place, Suite 300, Sunnyvale, California 94086, and our telephone number is (888) 512-8906. Our website address is www.crowdstrike.com. Information contained on, or that can be accessed through, our website does not constitute part of this Annual Report on Form 10-K.
Available Information
Our Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and amendments to these reports are filed with the SEC pursuant to Sections 13(a) and 15(d) of the Exchange Act. Such reports and other information filed or furnished by us with the SEC are available free of charge on our website at https://ir.crowdstrike.com/financial-information/sec-filings, as soon as reasonably practicable after we file such material with, or furnish it to, the SEC. The SEC maintains a website that contains the materials we file with or furnish to the SEC at www.sec.gov.