−Removed: We founded CrowdStrike in 2011 to reinvent security for the cloud era.
−Removed: When we started the company, cyberattackers had a decided, asymmetric advantage over existing security products.
−Removed: We turned the tables on the adversaries by taking a fundamentally new approach that leverages the network effects of crowdsourced data applied to modern technologies such as AI, cloud computing, and graph databases.
−Removed: Realizing that the nature of cybersecurity problems had changed but the solutions had not, we built our CrowdStrike Falcon platform to detect threats and stop breaches.
−Removed: We believe we are defining a new category called the Security Cloud, with the power to transform the security industry much the same way the cloud has transformed the customer relationship management, human resources, and service management industries.
−Removed: With our Falcon platform, we created the first multi-tenant, cloud native, intelligent security solution capable of protecting workloads across on-premise, virtualized, and cloud-based environments running on a variety of endpoints such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices.
−Removed: Our Falcon platform is composed of two tightly integrated proprietary technologies:
−Removed: our easily deployed intelligent lightweight agent and our cloud-based, dynamic graph database called Threat Graph.
−Removed: Our solution benefits from crowdsourcing and economies of scale, which we believe enables our AI algorithms to be uniquely effective.
+Added: Founded in 2011, CrowdStrike reinvented cybersecurity for the cloud era and transformed the way cybersecurity is delivered and experienced by customers.
+Added: When we started CrowdStrike, cyberattackers had an asymmetric advantage over legacy cybersecurity products that could not keep pace with the rapid changes in adversary tactics.
+Added: We took a fundamentally different approach to solve this problem with the CrowdStrike Falcon platform – the first, true cloud-native platform capable of harnessing vast amounts of security and enterprise data to deliver highly modular solutions through a single lightweight agent.
+Added: Our pioneering platform approach keeps customers ahead of attackers by automatically detecting and preventing threats to stop breaches.
+Added: We believe our approach has defined a new category called the Security Cloud, which has the power to transform the cybersecurity industry the same way the cloud has transformed the customer relationship management, human resources, and service management industries.
+Added: Using cloud-scale AI, our Security Cloud enriches and correlates trillions of cybersecurity events per week with indicators of attack, threat intelligence and enterprise data (including data from across endpoints, workloads, identities, DevOps, IT assets and configurations) to create actionable data, identify shifts in adversary tactics and automatically prevent threats in real-time across our customer base.
+Added: The more data that is fed into our Falcon platform, the more intelligent our Security Cloud becomes, and the more our customers benefit, creating a powerful network effect that increases the overall value we provide.
+Added: The Architectural Purpose Behind the Platform
+Added: Our Falcon platform was purpose-built in the cloud to harness the power of our Security Cloud to deliver the next generation of automated protection and provide threat hunters with the intelligence required to stop sophisticated attacks, including non-malware based attacks.
+Added: This approach has made CrowdStrike an industry leader in endpoint and cloud workload protection (capable of protecting workloads across on-premise, virtualized, and cloud-based environments running on a variety of endpoints such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices) and enables us to rapidly scale this best in class protection across new and emerging areas of enterprise risk.
+Added: Today, we offer 22 cloud modules on our Falcon platform via a SaaS subscription-based model that spans multiple large markets, including corporate workload security, security and vulnerability management, managed security services, IT operations management, threat intelligence services, identity protection, and log management.
+Added: Our Falcon platform is composed of tightly integrated, proprietary technologies that enable us to deliver superior protection and performance, while reducing customer complexity.
+Added: Our Falcon platform consists of our easily deployed, intelligent lightweight agent, and our groundbreaking graph technology.
+Added: Our single, lightweight-agent approach has changed how organizations experience cybersecurity, delivering protection without impacting the user, resources or productivity.
+Added: With the lightweight agent installed on each endpoint or cloud workload, our Falcon platform automates detection and prevention capabilities in real time across our entire global customer base.
+Added: This also enables our Falcon platform to intelligently ingest and stream high fidelity data back into the Security Cloud to continuously improve our Falcon platform’s AI algorithms and make its real-time decision-making faster and smarter to keep customers ahead of changing adversary tactics.
+Added: Our graph technology correlates and contextualizes the vast data of our Security Cloud so we can collect data once and reuse it repeatedly to deliver solutions that solve our customers’ biggest problems.
+Added: Our Threat Graph uses a combination of AI and behavioral pattern-matching techniques to correlate and analyze trillions of cybersecurity events, enriched with threat intelligence, and third-party data to identify and link threat activity together to automatically prevent threats in real time across CrowdStrike’s global customer base.
+Added: This also provides customers with increased visibility of attacks for proactive threat hunting and timely detection and remediation of novel threats.
+Added: The Falcon platform was purpose-built with the foresight that the future of cybersecurity would need to be cloud-native and AI-driven.
+Added: While AI is revolutionizing many technology fields, including cybersecurity solutions, to be truly effective,
+Added: algorithms that enable AI depend on the quality and volume of data that trains them and the selection of the right differentiating features from that data.
+Added: This is why we believe our Security Cloud and our cloud-native architecture creates a fundamental differentiator from our competitors.
+Added: The expansive amount of high fidelity data crowdsourced and captured in our Security Cloud enables the continuous training of our algorithms.
We call this cloud-scale AI.
−Removed: Our single lightweight agent is installed on each endpoint or the cloud workload and provides local detection and prevention capabilities while also intelligently collecting and streaming high fidelity data to our platform for real-time decision-making.
−Removed: Our Threat Graph processes, correlates, and analyzes this data in the cloud using a combination of AI and behavioral pattern-matching techniques.
−Removed: By analyzing and correlating information across our massive, crowdsourced dataset, we are able to deploy our AI algorithms at cloud-scale and build a more intelligent, effective solution to detect threats and stop breaches that on-premise or single instance cloud products cannot match.
−Removed: Today, we offer 19 cloud modules and our Falcon platform via a SaaS subscription-based model that spans multiple large markets, including corporate workload security, security and vulnerability management, managed security services, IT operations management, threat intelligence services, identity protection and log management.
−Removed: Organizations everywhere are becoming more distributed as they adopt the cloud, increase workforce mobility, and grow their number of connected devices.
−Removed: They are adding more workloads to a myriad of different endpoints beyond the traditional security perimeter, exposing an increasingly broad attack surface to adversaries.
−Removed: In addition, the sophistication of cyberattacks has increased, often coming from nation-states, well-funded criminal organizations, and hackers using advanced, easily obtained methods of attack.
−Removed: On a number of occasions, adversaries have launched devastating, destructive attacks that have caused significant business disruption and billions of dollars in cumulative losses.
−Removed: The architectural limitations of legacy security products, coupled with a dynamic and intensifying threat landscape, are creating the need for a fundamentally new approach to security.
−Removed: Our pioneering approach starts with our single intelligent lightweight agent that enables frictionless deployment of our platform at scale.
−Removed: Our customers can rapidly adopt our technology across any type of workload running on a variety of endpoints.
−Removed: Our lightweight agent offloads computationally intensive tasks to the cloud, while retaining local detection and prevention capabilities that are necessary on the endpoint.
−Removed: The agent is nonintrusive to the end user and continues to protect the endpoint and track activity even when offline.
−Removed: The agent recommences transmitting data to our Falcon platform when the connection to the cloud has been reestablished.
−Removed: By utilizing CrowdStrike’s single agent, customers are able to leverage the capabilities of our platform without burdening the endpoint with multiple agents.
−Removed: Our lightweight agent intelligently streams high fidelity endpoint data to the cloud where Threat Graph provides a simple, flexible, and scalable way to model highly interconnected data sets.
−Removed: Threat Graph processes, correlates, and analyzes over five trillion endpoint-related events per week in real time and maintains an index of these events for future use.
−Removed: Threat Graph continuously looks for malicious activity by applying graph analytics and AI algorithms to the data streamed from the endpoints.
−Removed: Our multi-tenant architecture allows us to collect a broad array of high fidelity data about both potential attacks and benign behavioral patterns across our entire customer base, continuously enhancing our AI algorithms.
−Removed: This significantly increases the efficacy of our solution to stop breaches while reducing false positives.
−Removed: We founded our company on the principle that the future of security would be driven by AI and that a cloud-native architecture would enable the collection of high fidelity data and scalability necessary for an effective solution.
−Removed: From the beginning, our strategy was focused on collecting data at scale, centrally storing such data in a singular model, and training our algorithms on these vast amounts of high fidelity data, which we believe is a fundamental differentiator from our competitors.
−Removed: Our cloud-scale AI means that the more data that is fed into our Falcon platform, the more intelligent Threat Graph becomes and the more our customers benefit, creating a powerful network effect that increases the overall value we provide.
−Removed: AI is revolutionizing many technology fields, including security solutions.
−Removed: To be truly effective, algorithms that enable AI depend on the quality and volume of data that trains them and the selection of the right differentiating features from that data.
−Removed: Our proprietary algorithms in Threat Graph identify events that may or may not be directly related, but together could indicate a threat that could otherwise remain undetected.
−Removed: We are uniquely effective because we not only have a massive amount of high fidelity data to train our AI models but also because of our deep security expertise to guide our feature selection—all resulting in industry-leading efficacy and low false positives.
−Removed: Our rich set of continuously collected high fidelity endpoint data feeding our algorithms also enables us to use an active learning approach, where the models are continuously updated to fill in gaps identified in initial models and their performance is validated with this data prior to production use.
−Removed: By leveraging a multi-tenant, cloud native solution, the data we analyze to stop breaches is both larger and more meaningful than the data from on-premise or single instance private cloud products.
−Removed: If Threat Graph discovers something in one customer environment, all customers benefit automatically and in real time.
−Removed: Taken together, our platform enables intelligent, dynamic automation at scale to detect threats and stop breaches.
−Removed: We designed our Falcon platform with an open, interoperable, and highly extensible architecture.
−Removed: Because of our single data model, we only need to collect high fidelity endpoint data once from our agent, which we can use repeatedly for multiple use cases.
−Removed: Therefore, we can rapidly innovate, build, and deploy highly integrated modules to access additional market opportunities.
−Removed: Additionally, via the CrowdStrike Store, customers can discover, try, buy and deploy trusted partner applications that extend their investment in the CrowdStrike Falcon platform.
−Removed: We also built a rich set of APIs that allows us to ingest third-party data into our Falcon platform and allows our customers to expand the functionality of their existing security systems by writing their own programs and accessing the data on our platform.
−Removed: Our Falcon platform includes our OverWatch threat hunting cloud module that combines the human intelligence of our elite security experts with the power of Threat Graph.
−Removed: Because our world class team can see potential attacks across our entire customer base, their expertise is enhanced by their constant visibility into the threat landscape.
−Removed: We are able to keep this team lean and scalable by leveraging automation and our Threat Graph.
−Removed: OverWatch is a force multiplier that extends the capabilities and improves the productivity of our customers’ security teams.
−Removed: We offer our customers compelling business value that includes ease of adoption, rapid time-to-value, superior efficacy rates in detecting threats and preventing breaches, and reduced total cost of ownership by consolidating legacy, siloed security products in a single solution.
−Removed: We also allow thinly-stretched security organizations to automate previously manual tasks, freeing them to focus on their most important objectives.
−Removed: With the Falcon platform, organizations can transform how they combat threats, from slow, manual, and reactionary to fast, automated, and predictive, providing visibility across the entire threat lifecycle.
−Removed: We primarily sell our platform and cloud modules through our direct sales team that leverages our network of channel partners to maximize effectiveness and scale.
−Removed: We amplify our sales presence by leveraging our technology alliance partners that can deliver, embed, or build applications with data and analytics from our Falcon platform.
−Removed: We are also enhancing our go-to-market strategy using a low-touch, trial-to-pay approach.
−Removed: In December 2017, we began to employ a trial-to-pay model in which we offer 15-day free trial access to Falcon Prevent, our next-generation antivirus module, to prospective customers directly from our website.
−Removed: In May 2018, we began offering Falcon Prevent for trial and purchase through the AWS Marketplace and have since expanded our modules available through the AWS Marketplace.
−Removed: We believe this approach enables a higher velocity of new customer acquisition and expansion, and extends our reach to customers of all sizes.
−Removed: We have a low friction land-and-expand sales strategy.
−Removed: When customers deploy our Falcon platform, they can start with any number of cloud modules and we can activate additional cloud modules in real time on the same agent already deployed on the endpoint.
−Removed: Once customers experience the benefits of our Falcon platform, they often expand their adoption over time by adding more endpoints or purchasing additional modules.
−Removed: As of January 31, 2021, subscription customers that had adopted four or more modules, five or more modules and six or more modules increased to 63%, 47%, and 24%, respectively.
−Removed: based net retention rate, which measures expansion in existing customers’ subscriptions over a 12 month period, was 125% as of January 31, 2021, demonstrating the power of our land-and-expand strategy.
−Removed: Some of the world’s largest enterprises, government organizations, and high profile brands trust CrowdStrike to protect their business.
−Removed: As of January 31, 2021, we had 9,896 subscription customers worldwide.
−Removed: We began as a large enterprise solution, but the flexibility and scalability of our Falcon platform and enhanced go-to-market approach enable us to protect customers of any size—from hundreds of thousands of endpoints to as few as one.
−Removed: We have experienced significant growth, with total revenue increasing from $249.8 million for fiscal 2019 to $481.4 million for fiscal 2020, representing year-over-year growth of 93%, and from $481.4 million for fiscal 2020 to $874.4 million for fiscal 2021, representing year-over-year growth of 82%.
−Removed: Subscription revenue grew from $219.4 million for fiscal 2019 to $436.3 million for fiscal 2020, a 99% increase, and from $436.3 million for fiscal 2020 to $804.7 million for fiscal 2021, a 84% increase.
−Removed: Our annual recurring revenue, or ARR, has grown from $312.7 million as of January 31, 2019 to $600.5 million as of January 31, 2020, a 92% increase, and from $600.5 million as of January 31, 2020 to $1.1 billion as of January 31, 2021, a 75% increase.
−Removed: We had net losses of $92.6 million, $141.8 million, and $140.1 million in fiscal 2021, fiscal 2020 and fiscal 2019, respectively.
−Removed: We expect to continue to incur net losses for the foreseeable future as we continue to invest in our business, and in particular, our sales and R&D capabilities, to address our large market opportunity.
+Added: Our technology is uniquely effective because we not only have a massive amount of high fidelity data to continuously train our AI models but also because of our deep cybersecurity expertise, which supports our industry-leading efficacy and low false positives.
+Added: By analyzing and correlating information across our massive, crowdsourced dataset, we are able to deploy our AI algorithms at cloud-scale and build a more intelligent, effective solution to detect threats and stop breaches that on-premise, cloud-hosted and hybrid products cannot match due to the inherent architectural limitations those products have with respect to data storage and analysis.
+Added: The more data that is fed into our Falcon platform, the more intelligent the Security Cloud becomes, and the more our customers benefit, creating a powerful network effect that increases the overall value we provide.
Industry Background:
−Removed: There are a number of key trends that are driving the need for a new approach to security.
−Removed: Cybersecurity Threats are Greater than Ever
−Removed: Today’s cybersecurity threat landscape is more dangerous than ever.
−Removed: Breaches are complex and often executed over multiple steps known in the industry as the threat lifecycle.
−Removed: The typical threat lifecycle starts with an initial exploit to enter a system, historically using malware, but increasingly using malware-free or fileless methods, to penetrate endpoints and establish a beachhead inside the corporate perimeter.
−Removed: Once inside, adversaries move laterally across the corporate environment where they collect credentials and escalate privileges enabling the typical adversary to download a larger, more destructive malware program or connect with an external control source.
−Removed: At this stage in the threat lifecycle, the adversary is able to encrypt, destroy, or silently exfiltrate sensitive data.
−Removed: Increasingly, adversaries are well-trained, possess significant technological and human resources, and are highly deliberate and targeted in their attacks.
−Removed: Adversaries today range from militaries and intelligence services of well-funded nation-states to sophisticated criminal organizations who are motivated by financial gains to hackers leveraging readily available advanced techniques.
−Removed: These groups and individuals are responsible for many breaches that involve theft or holding hostage financial data, intellectual property, and trade secrets.
+Added: The Trends Driving a Need for a New Approach to Security
+Added: We believe there are a number of important macro trends that drive the need for a new approach to security.
+Added: These include:
+Added: • Cybersecurity Threats are More Sophisticated and More Damaging:
+Added: The sophistication of adversaries continues to increase as militaries and intelligence services of well-funded nation-states, technically advanced criminal organizations and hackers use advanced, easily obtained methods of attack - including non-malware based attacks that exploit user identities and credentials.
These attacks are pervasive, targeting a broad range of industries including technology, transportation, healthcare, financial services, governments and political organizations, utility, retail, and public infrastructure.
−Removed: On a number of occasions, adversaries have launched devastating, destructive attacks that have caused significant business disruption and billions of dollars in cumulative losses.
−Removed: Proliferation of Workloads Expanding the Attack Surface
−Removed: The rise of digital transformation, cloud computing, workforce mobility, and growth in connected devices has created a rapid expansion of workloads across endpoints and industries.
−Removed: As a result, devices, applications, and data are highly distributed and diverse, challenging organizations to monitor and protect all of their workloads running on various endpoints.
−Removed: The adoption of many of these technologies and the resulting disappearance of the corporate perimeter have expanded the attack surface and left many organizations increasingly vulnerable to breach.
−Removed: Today, workloads running on endpoints, such as laptops and servers, are the primary targets in a security attack since they are vulnerable and frequently are repositories of valuable and sensitive data, including intellectual property, authentication credentials, personally identifiable information, financial information, and other digital assets.
−Removed: As new workloads are provisioned on emerging mobile and IoT devices, oftentimes residing outside of the corporate perimeter, increasingly more sensitive and mission critical data will be generated and stored on these endpoints as well.
−Removed: Attacks such as Shamoon, WannaCry and NotPetya have shown that destroying or locking data on a large portion of an enterprise’s endpoints can cause widespread business disruption.
−Removed: On-Premise Security Architectures are Constrained
+Added: The number and scale of attacks continue to increase.
+Added: The typical attack cycle starts with attackers attempting to penetrate endpoints to establish a beachhead.
+Added: Once inside, adversaries steal and exploit legitimate credentials to escalate privileges, move laterally and progress and attack, often downloading malware or ransomware.
+Added: At this stage in the threat lifecycle, the adversary is able to encrypt, destroy, or silently exfiltrate sensitive data.
+Added: In 2021 alone, adversaries launched multiple, destructive attacks that disrupted business and resulted in significant cumulative losses.
+Added: • Hybrid, Remote Workforces and the Proliferation of Workloads Expands the Attack Surface:
+Added: Organizations everywhere are embracing digital transformation and are becoming more distributed as they adopt the cloud, increase workforce mobility, and grow their number of connected devices.
+Added: They are adding more workloads to a myriad of different endpoints beyond the traditional cybersecurity perimeter, exposing an increasingly broad attack surface to adversaries.
+Added: This existing trend was accelerated significantly with the need to support an increasingly remote workforce in 2020 due to the COVID-19 pandemic and we believe this trend continues today.
+Added: In addition, technologies like Cloud and Containers are being adopted quickly, but rather than becoming full-scale replacements, they are often being used as supplements to existing on-premise, bare metal, and virtualized workloads.
+Added: • Growing Cyber Skills Gap:
+Added: Trained cybersecurity professionals are in high demand, and organizations continue to face a dire shortage of talent to fill much needed cybersecurity positions.
+Added: As a result, existing cybersecurity teams are often overwhelmed by the velocity of cyberattacks.
+Added: Adversaries exploit this vacuum by continuing to accelerate their sophisticated attacks.
+Added: Competitive Market:
+Added: Existing Security Solutions Are Limited and Exacerbate Ongoing Trends:
+Added: We believe the aforementioned trends are exacerbated by the architectural limitations of legacy cybersecurity products, which include:
+Added: • On-Premise Security and Bolt-On Cloud Products Lead to Constrained and Impacted Users :
On-premise products are siloed, lack integration, and have limited ability to collect, process, and analyze vast amounts of data—attributes that are required to be effective in today’s increasingly dynamic threat landscape.
−Removed: Legacy vendors often deploy more agents to the endpoint as they layer on a patchwork of additional point product capabilities.
−Removed: This approach burdens endpoints by consuming additional storage space, memory, and processor capacity, degrading end user experience without providing effective security.
−Removed: In addition, integrating and maintaining numerous products, data repositories, and infrastructures across highly distributed enterprise environments is a costly and resource-intensive process for already thinly-staffed security teams.
−Removed: Other Existing Security Products have Limitations
−Removed: Legacy Signature-based Products.
−Removed: Signature-based products are designed to detect attacks that are already cataloged in a repository of previously identified threats but are not capable of preventing unknown threats or stopping associated breaches.
−Removed: These signatures, known as Indicators of Compromise, or IOCs, represent a reactive method of tracking cyberattacks.
−Removed: By the time IOCs are located, all they provide is evidence of compromise or breach that may have already resulted in substantial losses to the victim.
−Removed: If an attack vector is even slightly modified, a signature-based approach will no longer detect the attack and will fail to stop the breach.
+Added: Meanwhile, these solutions often require more agents on the endpoint as new capabilities are patchworked together, which can have a dramatic negative impact on user performance.
+Added: Many on-premise vendors have since tried to solve this problem by simply extending on-premise products to the cloud.
+Added: Since their products were not purpose built to run in the cloud, the traditional on-premise issues - complex to deploy, siloed nature, lack of integration, limited ability to scale, costly to maintain - continue to manifest.
+Added: We believe that any product that was originally designed for on-premise deployments and migrated to the cloud cannot by definition be a cloud native solution.
+Added: • Legacy Signature-Based Products Are Not Effective Against Unknown Threats :
+Added: Signature-based products are designed to detect attacks that are already cataloged as previously identified threats.
+Added: As a result, such products are fundamentally unable to prevent unknown threats resulting from shifts in attacker tradecraft.
+Added: It often only takes a slight modification on the part of the attacker to bypass signatures.
Many significant breaches seen in the last two decades have involved the failure of a legacy signature-based antivirus product to detect a previously unknown or modified version of a previously known attack.
−Removed: Malware-focused Machine Learning Products.
+Added: • Malware-Focused Machine Learning Products Miss Sophisticated Attacks:
Traditionally, organizations have focused on protecting their networks and endpoints against malware-based attacks.
1 unchanged sentence
A malware-centric defensive approach will leave the organization vulnerable to attacks that do not leverage malware.
−Removed: Application Whitelisting Products.
+Added: • Application Whitelisting Products Are Ineffective:
Application whitelisting products resort to an “always allow” or “always block” policy on an endpoint in order to allow or prevent processes from executing.
Whitelisting relies in part on manually creating and maintaining a complex list of rules, burdening end users and IT organizations.
−Removed: In order to avoid these management challenges, IT organizations often create special exceptions to the whitelist that attackers leverage to compromise endpoints.
−Removed: Furthermore, fileless attacks can exploit legitimate whitelisted applications, compromising the integrity of the whitelisting product.
−Removed: Network-centric Security Products.
−Removed: Traditional network security vendors have focused their products on perimeter-based protection.
−Removed: However, these approaches have decreased in relevance and effectiveness as employees and workplace devices have expanded beyond the firewall and the use of encrypted traffic has increased creating blind spots and vulnerabilities that attackers are able to exploit.
−Removed: As the number of endpoints proliferates, and workforces become more distributed, this layer of defense cannot adequately protect information-rich endpoints and workloads that are outside the corporate perimeter.
−Removed: Bolt-on Cloud Products.
−Removed: Many on-premise vendors have introduced cloud offerings by putting their on-premise products in the cloud.
−Removed: Such single-tenant products were not designed to run in the cloud and therefore continue to be siloed, lack integration, and possess limited scalability to identify threats across their customer base in real time.
−Removed: In addition, such products are complex to deploy, difficult to scale, brittle to maintain, costly to own, and can be ineffective in stopping breaches.
−Removed: Any product that was originally designed for on-premise deployments and migrated to the cloud cannot by definition be a cloud native solution.
−Removed: Creation of the Security Cloud
−Removed: Over the last 17 years, cloud computing has revolutionized many industries in enterprise software and created significant shifts in market share away from incumbents with on-premise or single instance cloud offerings.
−Removed: The cloud has enabled organizations to cost-efficiently scale their compute and storage resources, accelerate innovation, eliminate ongoing maintenance and administrative costs, and consolidate previously disparate and siloed products.
−Removed: During this period, new data technologies also emerged leveraging the cloud to enable more data collection, improve data analysis, and share key insights to drive better business outcomes and make more informed decisions.
−Removed: The purpose-built, cloud native leaders that began from scratch with multi-tenant architectures, single data models, and SaaS business models have defined entirely new categories such as CRM Cloud, HR Cloud, and Service Management Cloud.
−Removed: We believe we are doing the same for security.
−Removed: An effective solution to address the modern cybersecurity threat landscape should combine multiple methods into an integrated, data-driven, and automated cloud-based platform in order to provide comprehensive breach protection across the entire threat lifecycle.
−Removed: Such a platform requires collecting, processing, analyzing, and correlating vast amounts of high fidelity endpoint events in the cloud.
−Removed: This platform needs to operate at web-scale, process events in real time, and benefit from the network effects of crowdsourced data to understand attacks that happen across millions of endpoints.
−Removed: We believe only a cloud native approach can address today’s threat landscape.
−Removed: We believe we are defining a new category called the Security Cloud.
−Removed: With our Falcon platform, we created the first multi-tenant, cloud native, intelligent security solution capable of protecting workloads across on-premise, virtualized, and cloud-based environments running on a variety of endpoints such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices.
−Removed: Our solution consists of our single intelligent lightweight agent and our powerful and dynamic cloud-based database Threat Graph.
−Removed: These two tightly integrated proprietary technologies continually collect, process, analyze and correlate vast amounts of high fidelity data across the entire threat lifecycle using a combination of AI and behavioral pattern-matching techniques to stop breaches.
−Removed: We implement this approach by crowdsourcing data across our entire customer base and taking advantage of economies of scale, which we believe enables our AI algorithms to be uniquely effective.
−Removed: The benefits of our cloud-based AI are automatically shared with customers across our community in real time.
−Removed: We combine multiple methods of detection, prevention, and response to known and unknown threats as well as malware and malware-free techniques across the threat lifecycle.
−Removed: Our Falcon platform supports 19 cloud modules via a SaaS subscription-based model that spans multiple large markets, including corporate workload security, security and vulnerability management, managed security services, IT operations management, threat intelligence services, identity protection and log management.
−Removed: Our single data model and open cloud architecture enable us and third-party partners to rapidly innovate, build, and deploy new cloud modules to provide our customers with additional functionality across a myriad of use cases.
−Removed: We designed our platform to be rapidly deployable, easy to use, and extensible, with the ability to consolidate point security products that have historically led to data silos and agent sprawl, into one comprehensive and integrated solution.
−Removed: Our platform allows our customers’ thinly-staffed security organizations to spend less time and fewer resources provisioning hardware, configuring supporting software systems, and performing ongoing maintenance work, freeing them to focus on their most important objectives.
−Removed: We aim to transform how organizations combat threats from slow, manual, and reactionary to fast, automated, and predictive.
−Removed: Key Benefits of Our Solution
+Added: This does not prevent fileless attacks from exploiting legitimate whitelisted applications, compromising the integrity of the whitelisting product.
+Added: Built for This Moment and the Future
+Added: We believe that the cloud-native architecture of the Falcon platform and Security Cloud provides a sustainable advantage in addressing the needs of our customers as their business and the threat landscape continues to evolve.
+Added: We offer our customers compelling business value that includes ease of adoption, rapid time-to-value, superior efficacy rates in detecting threats and preventing breaches, and reduced total cost of ownership by consolidating legacy, siloed security products in a single solution.
+Added: We also allow thinly-stretched security organizations to automate previously manual tasks, freeing them to focus on their most important objectives.
+Added: With the Falcon platform, organizations can transform how they combat threats, transforming from slow, manual, and reactionary to fast, automated, and predictive, while gaining visibility across the threat lifecycle.
+Added: Key benefits of our approach and the CrowdStrike Falcon platform include:
• The Power of the Crowd:
−Removed: Our crowdsourced data enables all of our customers to benefit from contributing to Threat Graph.
−Removed: As more high fidelity data is fed into our Falcon platform, there is more data to train our AI models with, increasing the overall efficacy of our Falcon platform.
−Removed: This benefits our customers and supports our efforts to gain more customers, creating a powerful network effect.
−Removed: Threat Graph can then learn and identify warning signs once and rapidly deliver protection to every customer in our community.
−Removed: Further, our AI algorithms are more effective because they are trained on such a broad and representative set of data that captures information about potential attacks throughout the entire threat lifecycle across our customer base.
−Removed: • High Efficacy with Low False Positives.
−Removed: Our Falcon platform collects, processes, correlates, and analyzes high fidelity data on both real-world attacks and benign behavioral patterns to continually train and enhance our algorithms resulting in industry-leading threat detection and low false positive rates.
+Added: Our crowdsourced data enables every customer to benefit from contributing to the Security Cloud.
+Added: As more high fidelity data is fed into our Security Cloud, our AI models continue to train and improve, increasing the overall efficacy of the Falcon platform.
+Added: This creates a powerful network effect that is a key differentiator in our efforts to gain more customers.
+Added: The Threat Graph is able to contextualize and turn this data into action, automatically delivering protection to every customer.
+Added: • High Efficacy, Low False Positives :
+Added: The vast telemetry of the Security Cloud and the best practices employed in continually training our AI models results in industry-leading efficacy rates and low false positives.
• Consolidation of Siloed Products :
−Removed: Integrating and maintaining numerous products, data and infrastructures across highly distributed enterprise environments leaves blind spots that hackers can exploit and is a costly and resource-intensive process.
−Removed: Our integrated platform unifies cloud modules addressing cloud workload security, next-generation antivirus, endpoint detection and response (EDR), device control, host firewall management, vulnerability management, forensic analysis, IT hygiene, threat hunting, and automated threat intelligence.
−Removed: Our platform enables our customers to reduce or streamline their siloed and layered security products, simplifying operations while providing a comprehensive solution.
−Removed: • Consolidation of Agents.
−Removed: We provide robust and diverse functionality through a single intelligent lightweight agent.
−Removed: Legacy vendors’ agents were designed to be single purpose, thus they often deploy multiple agents to the endpoint as they layer additional point product capabilities on top of their initial offering.
−Removed: This legacy approach burdens endpoints by consuming additional storage space, memory, and processor capacity, degrading the end user experience.
−Removed: Our single agent approach allows customers to consolidate and remove numerous agents from their infrastructure and restore endpoint performance.
−Removed: Because we collect data once from our agent and use it across multiple use cases, the Falcon platform can offer a wide range of functionality without burdening the endpoint.
+Added: Integrating and maintaining numerous security products creates blind spots that attackers can exploit is costly to maintain and negatively impacts user performance.
+Added: Our cloud-native platform approach gives customers a unified approach to address their most critical areas of risk seamlessly.
+Added: We empower customers to rapidly deploy and scale cloud workload security, next-generation antivirus, endpoint detection and response (“EDR”), device control, host firewall management, vulnerability management, forensic analysis, IT hygiene, threat hunting, identity protection, log management, automated threat intelligence, and Extended Detection and Response (“XDR”) from a single platform.
+Added: • Reducing Agent Bloat :
+Added: Our single intelligent lightweight agent enables frictionless deployment of our platform at scale, enabling customers to rapidly adopt our technology across any type of workload running on a variety of endpoints.
+Added: The agent is non-intrusive to the end user, requires no reboots and continues to protect the endpoint and track activity even when offline.
+Added: Through our single lightweight agent approach, customers can adopt multiple platform modules to address their critical areas of risk without burdening the endpoint with multiple agents.
+Added: Legacy approaches often require multiple agents as they layer on new capabilities.
+Added: This can severely impact user performance and create barriers to security.
• Rapid Time to Value :
−Removed: On-premise security solutions take time to install, configure, deploy, and maintain.
−Removed: We streamline the deployment process by providing cloud-delivered security with protection policies that work from day one, eliminating lengthy implementation periods and professional services engagements.
−Removed: Moreover, once a customer deploys our lightweight agent on their endpoints, we can activate additional cloud modules in real time.
−Removed: • Constant Protection Anywhere.
−Removed: Our cloud-based model allows us to secure customer workloads such as desktops, laptops, servers, virtual machines, cloud workloads, cloud containers, mobile, and IoT devices.
−Removed: In addition, once our agent is deployed on an endpoint it continues to protect the endpoint and track activity even when offline.
−Removed: • Elite Security Team as a Force Multiplier.
−Removed: Our OverWatch threat hunting cloud module combines world class human intelligence from our elite security experts with the power of Threat Graph.
+Added: Our cloud-native platform was built to rapidly scale industry leading protection across the entire enterprise, eliminating the lengthy implementation periods, and professional services engagements that next-gen and legacy competitors require.
+Added: Our single agent approach enables us to activate new modules in real time.
+Added: • Elite Security Teams as a Force Multiplier:
+Added: As adversaries continue to employ sophisticated non-malware attacks that exploit user credentials and identities, automation and autonomous security are no longer sufficient on their own.
+Added: Stopping today’s sophisticated attacks requires a combination of powerful automation and elite threat hunting.
+Added: Our OverWatch threat hunting cloud module combines world-class human intelligence from our elite security experts with the power of the Security Cloud.
OverWatch is a force multiplier that extends the capabilities and improves the productivity of our customers’ security teams.
Because our world-class team can see attacks across our entire customer base, their expertise is enhanced by their constant visibility into the threat landscape.
−Removed: • Bridging the Security Skills Gap through Automation.
−Removed: Our solution automates certain previously manual tasks, freeing up personnel to focus on their most important objectives.
−Removed: Our Falcon Complete module provides a turnkey solution that combines endpoint security with remediation and response capabilities.
−Removed: • Lowering Total Cost of Ownership.
−Removed: Our cloud-based platform eliminates our customers’ need for initial or ongoing purchases of hardware and does not require their personnel to configure, implement or integrate disparate point products.
+Added: Additionally, the insights of our OverWatch team can then be leveraged by the Falcon platform to further enhance its autonomous capabilities, creating a positive feedback loop for our customers.
+Added: • Alleviating the Skills Shortage through Automation :
+Added: CrowdStrike automates manual tasks to free security teams to focus on their most important job - stopping the breach.
+Added: Our Falcon Fusion module automates workflows to reduce the need to switch between different security tools and tasks, while our Falcon XDR module provides a unified solution that enables security teams to rapidly and efficiently identify, hunt, and eliminate threats across multiple security domains.
+Added: • Lower Total Cost of Ownership :
+Added: Our cloud-native platform eliminates our customers’ need for initial or ongoing purchases of hardware and does not require their personnel to configure, implement or integrate disparate point products.
Additionally, our comprehensive platform reduces overall personnel costs associated with ongoing maintenance, as well as the need for software patches and upgrades for separate products.
−Removed: Growth Strategy
−Removed: Key elements of our growth strategy include:
−Removed: • Growing Our Customer Base by Replacing Legacy and Other Endpoint Security Products.
−Removed: Given the limitations of existing legacy and other endpoint security products, many organizations are replacing their existing legacy and other endpoint security products with our Falcon platform.
−Removed: We grew our subscription customer base by 4,465 customers from 5,431 at January 31, 2020, to 9,896 at January 31, 2021, representing an 82% increase.
−Removed: We will continue to invest in customer acquisition programs, including our channel partnerships and new programs, like our free trial program of Falcon Prevent that is easily downloaded from our website and AWS Marketplace.
−Removed: • Further Penetrating Existing Customers.
−Removed: Our growth will depend in part on our ability to continue to expand our relationships with our customers by deploying on additional endpoints in their environment and cross selling more cloud modules.
−Removed: When customers deploy our lightweight agent, they can easily add additional cloud modules.
−Removed: We also offer in-application trial usage of additional modules to cross-sell to existing customers.
−Removed: While some new customers initially deploy our Falcon platform broadly across the organization, others elect to deploy only in selected business units and later deploy on additional endpoints and subscribe to additional modules.
−Removed: Over time, we seek to deploy our solution enterprise wide for all customers.
−Removed: The power of our land-and-expand strategy is evidenced by our 125% dollar-based net retention rate as of January 31, 2021.
−Removed: • Leveraging Our Falcon Platform to Enter New Markets.
−Removed: Because we leverage a single data model and open cloud architecture, we are uniquely positioned to continue innovating and rapidly deploying new cloud modules on our platform.
−Removed: For example, Falcon Discover includes use cases outside of security, such as application license management, AWS spend analysis, and asset inventory.
−Removed: Because our lightweight agent collects diverse endpoint data
−Removed: once for repeated use, we can expand our addressable market by rapidly adding new cloud modules that leverage this data.
−Removed: We intend to continue to develop new cloud modules for broader endpoint use cases.
−Removed: • Broadening Our Reach into New Customer Segments.
−Removed: While we initially targeted large sophisticated enterprises, we have expanded our go-to-market efforts to include customers of all sizes with a dedicated inside sales team focused on smaller organizations.
−Removed: We also released Falcon Complete in 2018, our turnkey solution that combines the most popular cloud modules of our Falcon platform with our remediation and response capabilities, to create a solution for customers with limited or no internal security expertise.
−Removed: As a result, we can sell our Falcon platform to the largest enterprises or smallest businesses with any level of security sophistication and budget.
−Removed: We continue to look for new ways to broaden our reach into new customer segments.
−Removed: • Extending Our Falcon Platform and Ecosystem.
−Removed: We designed our architecture to be open, interoperable, and highly extensible.
−Removed: We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity, which provides an ecosystem of trusted partners and applications for our customers.
−Removed: In the future we plan to continue investing in the CrowdStrike Store to empower our partners by making it easier to build applications and to enable our customers to more easily discover, try, and purchase additional cloud modules from both trusted partners and us.
−Removed: • Broadening Our Reach into the U.S.
−Removed: Federal Government Vertical.
−Removed: We are investing in the acquisition of customers in the U.S.
−Removed: federal government vertical.
−Removed: Our platform is authorized by several federal agencies via the Federal Risk and Authorization Management Program (“FedRAMP”).
−Removed: To further meet the compliance demands of the federal government, customers can elect to deploy the Falcon platform in the AWS GovCloud.
−Removed: We have also successfully been embedded into several strategic government-wide cybersecurity programs and contracts, such as the Department of Homeland Security’s Continuous Diagnostics and Mitigation Approved Products List, which serves to provide federal agencies with innovative security tools.
−Removed: • Expanding Our International Footprint.
−Removed: We are expanding our international operations and intend to invest globally to broaden our international footprint.
−Removed: We grew our international revenue from $124.9 million for fiscal 2020, to $247.0 million for fiscal 2021, representing an increase of 98%.
−Removed: We intend to grow our international customer base by increasing our investments in our overseas operations, including adding headcount in Europe, the Middle East, Asia-Pacific, and Japan and establishing overseas data centers.
−Removed: Falcon Platform
+Added: The CrowdStrike Falcon Platform:
+Added: Built to Innovate and Scale
+Added: Our platform approach allows us to rapidly innovate, build, and deploy highly integrated modules that address critical customer problems and access additional market opportunities.
+Added: Our cloud modules integrate seamlessly with the Falcon platform that addresses use cases across corporate workload security, security and vulnerability management, managed security services, IT operations management, threat intelligence services, identity protection, and log management.
Our Falcon platform is composed of two tightly integrated proprietary technologies:
−Removed: our lightweight agent and Threat Graph.
+Added: our lightweight agent and our Security Cloud.
The Falcon platform offers a unified set of cloud-delivered technologies that power a wide range of modules including next-generation antivirus, EDR, device control, host firewall management, managed threat hunting, IT hygiene, vulnerability management, and threat intelligence.
The Falcon platform also encompasses recently acquired technologies where integration may be ongoing.
−Removed: We can rapidly and cost effectively develop and deliver additional cloud modules on our Falcon platform, and are expanding options for our new customers to test modules on a trial basis and in-application trials for existing customers.
+Added: We can rapidly and cost effectively develop and deliver additional cloud modules on our Falcon platform without the need for additional agents, and are expanding options for our new customers to test modules on a trial basis and in-application trials for existing customers.
Our expanding set of open APIs allows customers and partners to build their own capabilities on top of the Falcon platform.
With our Falcon platform, we can crowdsource data and deliver a variety of cloud modules to detect and stop breaches.
+Added: Our modules address the most critical areas of enterprise risk and friction.
Our Cloud Modules
19 unchanged sentences
Falcon Firewall Management provides centralized management of the firewall capabilities native to the host operating system, allowing customers to create, enforce, and maintain host firewall policies.
+Added: Extended Detection and Response
+Added: • Falcon XDR - Extended Detection and Response .
+Added: Falcon XDR extends our industry leading detection, investigation, and response capabilities by incorporating relevant third-party security data.
+Added: We correlate signals from multiple disparate technologies to deliver XDR detections across the attack surface.
+Added: We allow customers to investigate these detections and to search and hunt using data from CrowdStrike, as well as third party security sources such as email, cloud access security broker (“CASB”) network threat detection, and identity and firewall data.
+Added: The CrowdXDR Alliance offers a first-of-its-kind technology ecosystem to enable unified, threat-centric detection and response across an organization’s security and technology ecosystem.
+Added: We believe the CrowdXDR Alliance is differentiating - bringing together industry leaders and cutting-edge solutions to establish an open-source, common XDR ontology for data sharing.
+Added: Falcon XDR is designed to enhance threat correlation and speeds response times against sophisticated attacks.
Security and IT Operations
7 unchanged sentences
Falcon Forensics streamlines the collection of point-in-time and historic forensic triage data for robust analysis of cybersecurity incidents, enabling responders to quickly identify relevant data with preset dashboards and rapidly investigate.
+Added: • Falcon FileVantage—File Integrity Monitoring .
+Added: Falcon FileVantage reduces compliance complexity by building in the services an additional agent would normally provide, including being able to monitor all files on the protected systems.
+Added: This in turn provides alerts and reports to help meet various compliance requirements imposed by PCI, CIS Controls, and Sarbanes-Oxley.
Managed Services
2 unchanged sentences
It is backed by an underwritten limited warranty policy for breaches.
+Added: We also offer Falcon Cloud Workload Protection Complete and Falcon Identity Threat Protection Complete as add-ons to our Falcon Complete solution to extend its capabilities to include our cloud workload protection and identity protection modules.
• Falcon OverWatch—Threat Hunting .
10 unchanged sentences
Falcon X Recon allows our customers to identify and mitigate digital risks on the hidden areas of the clear, deep and dark web.
−Removed: These risks include digital fraud, data theft exposure, social media impersonations, and much more.
+Added: These risks include, but are not limited to, digital fraud, data theft exposure, social media impersonations.
Identity Protection
6 unchanged sentences
Humio is a high-performance, index-free cloud log management solution that allows customers to collect logs from any data source and to search and query streaming data in real-time.
+Added: Recently Acquired Technologies
+Added: • SecureCircle – Data Protection .
+Added: SecureCircle is a recently acquired technology that extends Zero Trust security to data on the endpoint.
+Added: As data security drives business value for our customers, end users operate without obstacles,
+Added: while data is continuously secured against breaches and insider threats.
+Added: Instead of relying on complex reactive measures, we believe integrating SecureCircle will help us simply secure data persistently in transit, at rest, and even in use.
+Added: Bringing CrowdStrike to the Market
+Added: We primarily sell the Falcon platform through our direct sales team that leverages our network of channel partners to maximize effectiveness and scale.
+Added: We have a low friction land-and-expand sales strategy.
+Added: Key elements of our growth strategy include:
+Added: • Growing Our Customer Base by Replacing Legacy and Other Endpoint Security Products.
+Added: Given the limitations of existing legacy and other endpoint security products, many organizations are replacing their existing legacy and other endpoint security products with our Falcon platform.
+Added: We grew our subscription customer base by 6,429 customers from 9,896 at January 31, 2021, to 16,325 at January 31, 2022, representing a 65% increase.
+Added: We will continue to invest in customer acquisition programs, including our channel partnerships and new programs, like our free trial program of Falcon Prevent that is easily downloaded from our website and AWS Marketplace.
+Added: • Further Penetrating Existing Customers.
+Added: Our growth will depend in part on our ability to continue to expand our relationships with our customers by deploying on additional endpoints in their environment and cross selling more cloud modules.
+Added: When customers deploy our lightweight agent, they can easily add additional cloud modules.
+Added: We also offer in-application trial usage of additional modules to cross-sell to existing customers.
+Added: While some new customers initially deploy our Falcon platform broadly across the organization, others elect to deploy only in selected business units and later deploy on additional endpoints and subscribe to additional modules.
+Added: Over time, we seek to deploy our solution enterprise wide for all customers.
+Added: The power of our land-and-expand strategy is evidenced by our 123.9% dollar-based net retention rate as of January 31, 2022.
+Added: • Leveraging Our Falcon Platform to Enter New Markets.
+Added: Because we leverage a single data model and open cloud architecture, we are uniquely positioned to continue innovating and rapidly deploying new cloud modules on our platform.
+Added: For example, Falcon Discover includes use cases outside of security, such as application license management, AWS spend analysis, and asset inventory.
+Added: Because our lightweight agent collects diverse endpoint data once for repeated use, we can expand our addressable market by rapidly adding new cloud modules that leverage this data.
+Added: We intend to continue to develop new cloud modules for broader endpoint use cases.
+Added: • Broadening Our Reach into New Customer Segments.
+Added: While we initially targeted large sophisticated enterprises, we have expanded our go-to-market efforts to include customers of all sizes with a dedicated inside sales team focused on smaller organizations.
+Added: We also released Falcon Complete in 2018, our turnkey solution that combines the most popular cloud modules of our Falcon platform with our remediation and response capabilities, to create a solution for customers with limited or no internal security expertise.
+Added: As a result, we can sell our Falcon platform to the largest enterprises or smallest businesses with any level of security sophistication and budget.
+Added: We continue to look for new ways to broaden our reach into new customer segments.
+Added: • Extending Our Falcon Platform and Ecosystem.
+Added: We designed our architecture to be open, interoperable, and highly extensible.
+Added: We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity, which allows customers to purchase CrowdStrike products and provides an ecosystem of trusted partners and applications for our customers to choose from.
+Added: In the future we plan to continue investing in the CrowdStrike Store to empower our partners by making it easier to build applications and to enable our customers to more easily discover, try, and purchase additional cloud modules from both trusted partners and us.
+Added: • Broadening Our Reach into the U.S.
+Added: Federal Government Vertical.
+Added: We are investing in the acquisition of customers in the U.S.
+Added: federal government vertical.
+Added: Our platform is authorized by several federal agencies via the Federal Risk and Authorization Management Program (“FedRAMP”).
+Added: To further meet the compliance demands of the federal government, customers can elect to deploy the Falcon platform in the AWS GovCloud.
+Added: We have also successfully been embedded into several strategic government-wide cybersecurity programs and contracts, such as the Department of Homeland Security’s Continuous Diagnostics and Mitigation Approved Products List, which serves to provide federal agencies with innovative security tools.
+Added: • Expanding Our International Footprint.
+Added: We are expanding our international operations and intend to invest globally to broaden our international footprint.
+Added: We grew our international revenue from $247.0 million for fiscal 2021, to $405.1 million for fiscal 2022, representing an increase of 64%.
+Added: We intend to grow our international customer base by increasing our investments in our overseas operations, including adding headcount in Europe, the Middle East, Asia-Pacific, including Japan and expanding current data centers overseas.
+Added: We have experienced significant growth, with revenue increasing from $874.4 million in fiscal 2021 to $1.5 billion in fiscal 2022, representing year-over-year growth of 66%, and from $481.4 million in fiscal 2020 to $874.4 million in fiscal 2021, representing year-over-year growth of 82%.
+Added: Subscription revenue grew from $804.7 million in fiscal 2021 to $1.4 billion in fiscal 2022, a 69% increase, and from $436.3 million in fiscal 2020 to $804.7 million in fiscal 2021, an 84% increase.
+Added: Our Annual Recurring Revenue (“ARR”), has grown from a $1.1 billion as of January 31, 2021 to $1.7 billion as of January 31, 2022, a 65% increase, and from $600.5 million as of January 31, 2020 to $1.1 billion as of January 31, 2021, a 75% increase.
+Added: We had net losses of $234.8 million, $92.6 million, and $141.8 million in fiscal 2022, fiscal 2021, and fiscal 2020, respectively.
+Added: We expect to continue to incur net losses for the foreseeable future as we continue to invest in our business, and in particular, our sales and research and development capabilities, to address our large market opportunity.
We have designed an innovative architecture from the ground up to overcome the limitations of existing security products and deliver cloud-based solutions.
7 unchanged sentences
We designed an intelligent lightweight agent that is installed on each endpoint or cloud workload.
−Removed: These agents incorporate identification and prevention of known malware, machine learning for unknown malware, exploit blocking and advanced behavioral techniques, to protect workloads across all endpoints while capturing and recording high fidelity endpoint data.
−Removed: Our agents continue to protect workloads running on endpoints even when offline.
+Added: This agent incorporates identification and prevention of known malware, machine learning for unknown malware, exploit blocking and advanced behavioral techniques, to protect workloads across all endpoints while capturing and recording high fidelity endpoint data.
+Added: Our agent continues to protect workloads running on endpoints even when offline.
The agent recommences transmitting data to our Falcon platform when the connection to the cloud has been re-established.
9 unchanged sentences
The graph data model allows the AI algorithms to identify relationships between events that are not directly related but which could indicate an attack that would otherwise remain undetected.
−Removed: We believe that our AI algorithms are advantaged by the rich proprietary dataset that we use to
+Added: We believe that our AI algorithms are advantaged by the rich proprietary dataset that we use to train them.
Threat Graph provides customers with complete real time and historical visibility and insight into events occurring on their endpoints for hunting and searching.
25 unchanged sentences
In addition to our Falcon platform and cloud modules, we also offer incident response and forensic investigatory services, technical assessment and strategic advisory services, as well as training to assist organizations that have experienced a breach or are assessing their security posture and ability to respond to breaches.
−Removed: • Incident Response/ Forensics Services.
−Removed: Our incident response services typically begin by deploying our lightweight agent to a customer’s endpoints to provide comprehensive visibility and determine if an attacker is currently in the environment, what assets have been compromised, and how much damage has been done.
+Added: • Incident Response and Forensics Services.
+Added: Our incident response services typically begin by deploying our lightweight agent to a customer’s endpoints to provide comprehensive visibility in order to determine if an attacker is currently in the environment, what assets have been compromised, and how much damage has been done.
+Added: The Falcon platform’s next-gen prevention capabilities, cloud posture management and identity protection offerings can also be leveraged to enrich the response team’s visibility and understanding of the attack as well as help to slow down and prevent an active attacker from moving at-will throughout a compromised customer’s environment, increasing the risk and potential damage to the customer.
We also provide customized remediation planning by providing a strategy to eject attackers out of the network, lock down credentials from further use, and ensure adversaries stay out.
1 unchanged sentence
After experiencing the benefits of our platform firsthand, many of our incident response customers become subscription customers.
−Removed: Among organizations who first became a customer after February 1, 2019, for each $1.00 spent by those
−Removed: customers on their initial engagement for our incident response or proactive services, as of January 31, 2021, we derived an average of $5.51 in ARR from those subscription contracts.
+Added: Among organizations who first became a customer after February 1, 2020, for each $1.00 spent by those customers on their initial engagement for our incident response or proactive services, as of January 31, 2022, we derived an average of $5.71 in ARR from those subscription contracts.
• Technical Assessment and Strategic Advisory Services .
Our proactive security services include technical assessment services designed to help organizations understand their cyber maturity levels.
−Removed: These services include cybersecurity maturity assessments, security program in-depth assessments, service organization control assessments, cloud security assessments, IT hygiene assessments and active directory security assessments.
+Added: These services include compromise assessments, cybersecurity maturity assessments, security program in-depth assessments, service
+Added: organization control assessments, cloud security assessments, IT hygiene assessments, and active directory security assessments.
We also advise customers on readiness and preparation through the execution of table-top exercises, live fire exercises, red team/blue team assessments, and advanced adversary emulation exercises.
1 unchanged sentence
We offer training and certification services to customers and partners on CrowdStrike technologies and cybersecurity topics to facilitate the adoption of CrowdStrike and to broaden and deepen their skills.
−Removed: CrowdStrike University is an online learning management system that organizes all CrowdStrike e-learning, instructor-led training and certification in one place, providing a personalized learning experience for individuals who have an active training subscription.
−Removed: Beginning the first quarter of fiscal year 2022 CrowdStrike University plans to offer proctored exam certifications through industry leading training partner Pearson Vue for its Falcon Administration, Incident Response, and Threat Hunting training programs.
+Added: CrowdStrike University is an online learning management system that organizes all CrowdStrike e-learning, instructor-led training and certification preparation courses in one place, providing a personalized learning experience for individuals who have an active training subscription.
+Added: CrowdStrike currently offers proctored exam certifications through industry leading training partner Pearson Vue for its CrowdStrike Certified Falcon Administrator (“CCFA”), CrowdStrike Certified Falcon Responder (“CCFR”), and CrowdStrike Certified Falcon Hunter (“CCFH”) programs.
Some of the world’s largest enterprises, government organizations, and high profile brands trust us to protect their business.
13 unchanged sentences
We also engage in paid media, web marketing, industry and trade conferences (including our annual Fal.Con conference), analyst engagements, whitepaper development, demand generation via digital and web, and targeted displacement campaigns.
−Removed: We employ a wide range of digital programs, including search engine marketing, online and social media initiatives, and content syndication to increase traffic to our website and encourage new customers to sign up for a 15-day free trial of the Falcon platform.
+Added: We employ a wide range of digital programs, including search engine marketing, online and social media initiatives, and content syndication to increase traffic to our website and encourage prospective customers to sign up for a free trial of the Falcon platform.
Additionally, we engage in joint marketing activities with our channel and technology alliance partners.
−Removed: In December 2017, we began to employ a trial-to-pay model in which we offer 15-day free trial access to Falcon Prevent to prospective customers directly from our website, a program that has continued to grow over time.
−Removed: In May 2018, we announced that Falcon Prevent was available for trial and purchase from the AWS Marketplace and have since
−Removed: expanded our modules available through the AWS Marketplace.
−Removed: In February 2019, we launched the CrowdStrike Store, a marketplace platform that enables customers access to third-party applications and add-on capabilities to extend the value of the Falcon platform.
−Removed: In 2020, we significantly expanded our technical and go-to-market alliances, including new partnerships with identity providers and business consulting firms in addition to launching new capabilities in the identity protection space.
Partnership Ecosystem
2 unchanged sentences
Our technology alliance partnerships focus on security analytics, network and infrastructure security, threat platforms and orchestration, and automation.
−Removed: We launched the CrowdStrike Store, the first open cloud-based application PaaS for cybersecurity and the industry’s first unified security cloud ecosystem of trusted third-party applications.
−Removed: In addition, we recently announced the launch of Falcon for Amazon Web Services (AWS).
−Removed: Available in the AWS Marketplace, Falcon for AWS allows customers to easily purchase and take advantage of the metered billing (pay-as-you-go) pricing option to scale their consumption as their business needs change.
+Added: We launched the CrowdStrike Store, the first
+Added: open cloud-based application PaaS for cybersecurity and the industry’s first unified security cloud ecosystem of trusted third-party applications.
+Added: In addition, Falcon for Amazon Web Services (“AWS”), available in the AWS Marketplace, allows customers to easily purchase and take advantage of the metered billing (pay-as-you-go) pricing option to scale their consumption as their business needs change.
Research and Development
4 unchanged sentences
We invest substantial resources in research and development to enhance our Falcon platform, and develop new cloud modules, features and functionality.
−Removed: We believe timely development of new, and enhancement of our, products, services, and features is essential to maintaining our competitive position.
+Added: We believe timely development of new, and enhancement of our existing products, services, and features is essential to maintaining our competitive position.
We work closely with our customers and channel partners to gain valuable insight into their security management practices to assist us in designing new cloud modules and features that extend the capability of our platform.
6 unchanged sentences
We plan to continue to dedicate significant resources to research and development.
−Removed: The market for our services is intensely competitive and characterized by rapid changes in technology, customer requirements, and industry standards and by frequent new product and service offerings and improvements.
−Removed: We compete with an array of established and emerging security solution vendors.
−Removed: Conditions in our market could change rapidly and significantly as a result of technological advancements, partnerships, or acquisitions by our competitors or continuing market consolidation.
−Removed: With the introduction of new technologies and market entrants, we expect the competitive environment to remain intense.
−Removed: Our competitors include the following by general category:
−Removed: • legacy antivirus product providers, such as McAfee, LLC, Broadcom Inc.’s Symantec Enterprise division, and Microsoft Corporation, who offer a broad range of approaches and solutions with traditional antivirus and signature-based protection;
−Removed: • alternative endpoint security providers, such as BlackBerry Cylance, VMware Carbon Black and SentinelOne, who offer point products based on malware-only or application whitelisting techniques;
−Removed: • network security vendors, such as Palo Alto Networks, Inc.
−Removed: and FireEye, Inc., who are supplementing their core perimeter-based offerings with endpoint security solutions.
+Added: We primarily compete with established and emerging security product vendors.
+Added: While the market for traditional endpoint and IT operations solutions has historically been intensely competitive, we believe that the architecture of our cloud-native, single agent platform fundamentally differentiates us compared to both next-gen and legacy competitors in the security industry.
+Added: Additionally, as we look to enter into adjacent markets and expand our total addressable market, we may face new competitors.
+Added: However, we do not believe any of our competitors currently have a true platform offering equivalent to the Falcon platform, which can be leveraged to win in legacy markets and define new categories.
+Added: Our competitors currently include the following by general category:
+Added: • legacy antivirus product providers, such as Trellix (formerly McAfee Enterprise), Broadcom Inc.’s Symantec Enterprise division, and Microsoft Corporation, who offer a broad range of approaches and solutions including traditional signature-based antivirus protection;
+Added: • alternative endpoint security providers, such as Blackberry Cylance, VMware Carbon Black and SentinelOne, who generally offer a mix of on-premises and cloud-hosted products that rely heavily on malware-only or application whitelisting techniques;
+Added: • network security vendors, such as Palo Alto Networks, Inc., who are supplementing their core perimeter-based offerings with endpoint security solutions;
+Added: • professional service providers, such as Mandiant and Microsoft Corporation, who offer cybersecurity response services.
We compete on the basis of a number of factors, including but not limited to our:
+Added: • ability to offer a unified and modular platform that enables rapid innovation, scaling, and deployment;
• ability to identify security threats and prevent security breaches;
10 unchanged sentences
As of January 31, 2022, we had 132 issued patents and 90 pending patent applications in the United States and other countries.
−Removed: Our issued patents expire between 2032 and 2039.
These patents and patent applications seek to protect our proprietary inventions relevant to our business.
7 unchanged sentences
Successful claims of infringement by a third party could prevent us from offering certain products or features, require us to develop alternate, non-infringing technology, which could require significant time and during which we could be unable to continue to offer our affected products or solutions, require us to obtain a license, which may not be available on reasonable terms or at all, or force us to pay substantial damages, royalties, or other fees.
−Removed: For additional information, see the section titled “Risk Factors—Risks Related to Our Business—The success of our business depends in part on our ability to protect and enforce our intellectual property rights.”
+Added: For additional information, see the section titled “Risk Factors—Risks Related to Intellectual Property, Legal, and Regulatory Matters—The success of our business depends in part on our ability to protect and enforce our intellectual property rights.”
We enter into both single and multi-year subscription contracts for our solutions.
−Removed: We generally invoice the entire amount at contract signing prior to commencement of subscription period.
+Added: We generally invoice our customers at contract signing prior to commencement of subscription period.
Until such time as these amounts are invoiced, they are not recorded in deferred revenue or elsewhere in our consolidated financial statements, and are considered by us to be backlog.
As of January 31, 2022, we had backlog of approximately $735.8 million.
−Removed: Of this amount, approximately $164.4 million is not reasonably expected to be billed in fiscal 2021.
We expect backlog will change from period to period for several reasons, including the timing and duration of customer agreements, varying billing cycles of subscription agreements, and the timing and duration of customer renewals.
3 unchanged sentences
We expect these seasonal variations to become more pronounced in future periods, with net new ARR generation being greater in the second half of the year, particularly in the fourth quarter, as compared to the first half of the year.
−Removed: In addition, we also experience seasonality in our operating margin, with a lower margin in the first half of our fiscal year due to a step up in costs for payroll taxes, new hires, and annual sales and marketing events.
−Removed: This also impacts the timing of operating cash flow and free cash flow.
+Added: In addition, we also
+Added: experience seasonality in our operating margin, with a lower margin in the first half of our fiscal year due to a step up in costs for payroll taxes, new hires, and annual sales and marketing events.
+Added: This also impacts the timing of operating cash flow.
Human Capital Resources
10 unchanged sentences
We have created a high performance talent model that pinpoints the top traits and qualities we look for in talent and that may already exist within the organization, then consistently use that model to develop interview questions, screen candidates, and make hiring decisions.
−Removed: We continue to market to and recruit technical talent in diverse communities by engaging as a high-level sponsor or partner of professional conferences and organizations such as Grace Hopper, Society of Women Engineers, Blavity Afrotech World, Hire Military, Black Girls Code, Thurgood Marshall College Foundation, and others.
+Added: We continue to market to and recruit technical talent in diverse communities by engaging as a high-level sponsor or partner of professional conferences and organizations such as Grace Hopper, Society of Women Engineers, Afrotech - Blavity World, Hire Military, Black Girls Code, Thurgood Marshall College Foundation, and others.
To attract high performers, we have a team dedicated to building and promoting our employer brand focused on creating a strong employer value proposition:
5 unchanged sentences
We provide robust compensation and benefits programs to help meet the needs of our employees.
−Removed: In addition to base salary, these programs (which vary by country/region) include annual bonuses, equity awards, an employee stock purchase plan, a 401(k) plan, healthcare and insurance benefits, health savings and flexible spending accounts, paid time off, family leave, family care resources, flexible work schedules, adoption and surrogacy assistance, employee assistance programs, tuition assistance and on-site services such as health and fitness centers.
+Added: In addition to base salary, these programs (which vary by country/region) include annual bonuses or commission plans, equity awards, an employee stock purchase plan, a 401(k) plan, healthcare and insurance benefits, health savings and flexible spending accounts, paid time off, family leave, family care resources, flexible work schedules, adoption and infertility assistance, and employee assistance programs.
We invest resources to develop the talent needed to remain a leader in cybersecurity.
1 unchanged sentence
Remote-First Distributed Workforce
−Removed: For CrowdStrike, the ability to work remotely is a deliberate strategy that we believe fuels rapid innovation and attracts the best and brightest around the world.
−Removed: Our culture is purpose-built around a remote-first way of working, creating a competitive advantage for both the company and its customers and minimizing disruption from localized issues such as natural disasters, political events, or health emergencies like COVID-19.
+Added: For CrowdStrike, the ability to work remotely is a deliberate strategy that we believe fuels rapid innovation and attracts the best and brightest around the world, regardless of their specific location.
+Added: Our culture is purpose-built around a remote-first way of working, creating a competitive advantage for both the company and its customers and minimizing disruption from localized issues such as natural disasters, political events, or health emergencies, such as the COVID-19 pandemic.
CrowdStrike has had a distributed workforce since its inception.
−Removed: Before COVID-19, 70% of our workforce, including nearly all engineering and technology teams, worked on a remote basis.
−Removed: 100% of our workforce is remote in response to COVID-19 and we do not have immediate plans to return to physical offices.
−Removed: Since the Company’s inception, we recognized that creating high-functioning, effective remote-first teams would require careful planning and system design to not only establish the culture but help it grow and evolve organically.
+Added: Even prior to the COVID-19 pandemic, roughly 70% of our workforce, including engineering and technology teams, worked on a remote basis.
+Added: During the pandemic, we quickly went
+Added: to 100% of our workforce working remotely.
+Added: We have recently started to open offices again following the local guidelines, but have continued to encourage employees to follow local guidance on COVID-19 protocols to protect the health and safety of themselves and of those around them.
+Added: Since the beginning, we recognized that creating high-functioning, effective remote-first teams would require careful planning and system design to not only establish the culture but help it grow and evolve organically.
We have designed our processes, systems, and teams so that people can perform their jobs without needing to be physically present in the same room or even in the same time zone.
4 unchanged sentences
We strive to create an environment where everyone feels seen, heard, and empowered to succeed.
−Removed: Through employee resource groups, internal development programs, allyship training, speaker series, and networking opportunities, we are empowered to come together to create a workplace that reflects the diverse communities around us.
+Added: Through employee resource groups, internal training and development programs, allyship training, speaker series, and networking opportunities, we are empowered to come together to create a workplace that reflects the diverse communities around us.
Setting a diverse workforce up for success requires a commitment to the practices of inclusion in everything we do.
17 unchanged sentences
Podbere 56 Chief Financial Officer
−Removed: Colin Black 57 Chief Operating Officer
−Removed: Michael Carpenter 45 President, Global Sales and Field Operations
Shawn Henry 59 President, CrowdStrike Services and Chief Security Officer
22 unchanged sentences
from McGill University.
−Removed: Colin Black - Chief Operating Officer
−Removed: Black has served as our Chief Operating Officer since January 2017 and as our Chief Information Officer from November 2015 to December 2017.
−Removed: From May 2012 to November 2015, he served as Chief Information Officer for Kratos Defense and Security Solutions.
−Removed: Inc., a provider of advanced engineering, security, surveillance, and information technology services.
−Removed: From August 2008 to May 2012, he served as Chief Information Officer for Cymer, LLC.
−Removed: a developer and manufacturer of lithography light sources used in the semiconductor industry.
−Removed: Since November 2017, he has also served as a board member, and until November 2020 as Secretary, for the CrowdStrike Foundation, a nonprofit established to support the next generation of talent and research in cybersecurity and artificial intelligence through scholarships, grants, and other activities.
−Removed: Black holds a B.S.
−Removed: in Electronics Engineering from the University of Glasgow.
−Removed: Michael Carpenter - President Global Sales and Field Operations
−Removed: Carpenter has served as our President, Global Sales and Field Operations since November 2016.
−Removed: From February 2014 to September 2016, he served as President of Global Sales and Field Operations for Tanium Inc., an endpoint security and systems management company.
−Removed: From December 2012 to January 2014, Mr.
−Removed: Carpenter served as President.
−Removed: Americas Sales for Intel Security Group, a global computer security software company.
−Removed: Carpenter holds a B.A.
−Removed: in Accounting from the University of Massachusetts Lowell.
Shawn Henry - President, CrowdStrike Services and Chief Security Officer
3 unchanged sentences
Henry has served as a faculty member specializing in cybersecurity for the National Association of Corporate Directors, an organization providing training and education for private and public company directors.
−Removed: Since June 2015, Mr.
−Removed: Henry has served as a cybersecurity and national security analyst for NBC News.
+Added: Henry previously served as a cybersecurity and national security analyst for NBC News.
+Added: Since November 2021, Mr.
+Added: Henry has served as a director of ShoulderUp Technology Acquisition Corp., a blank check company that completed its initial public offering in November 2021.
+Added: Henry also serves on the board of directors of the Global Cyber Alliance, a nonprofit organization dedicated to making the Internet a safer place by reducing cyber risk, and on the advisory board of several organizations, including Hofstra University’s School of Engineering and Applied Science.
Henry holds a B.B.A.
2 unchanged sentences
Corporate Information
−Removed: Our principal executive offices are located at 150 Mathilda Place, Suite 300, Sunnyvale, California 94086, and our telephone number is (888) 512-8906.
+Added: Our principal executive offices are located at 206 E.
+Added: 9th Street, Suite 1400, Austin, Texas 78701 and our telephone number is (888) 512-8906.
Our website address is www.crowdstrike.com.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.