George Kurtz
Analyst · Barclays Capital. Your line is open
Thank you, Maria and thank you all for joining us today. We delivered an outstanding second quarter, with rapid subscription revenue growth and record net new ARR generated in the quarter. We saw strength in multiple areas of the business, added $150.6 million in net new ARR and grew ending ARR 70% to exceed $1.34 billion. Our continued strong performance was driven by the groundswell of customers turning to CrowdStrike as their trusted security platform of record. We saw strong demand across the market which for us spans large enterprise, mid-market and SMB customers. Our success in gaining share in each of these market segments is reflected in our net new customer growth rate which on an organic basis accelerated in the quarter. In total, 1,660 net new customers chose CrowdStrike as their security partner, bringing our customer count to 13,080. The CrowdStrike brand is viewed as the gold standard in security. We designed the Falcon platform and our Security Cloud to add value and improve the security posture of any organization, regardless of size and sophistication. Customers new to CrowdStrike this quarter included a household name in the consumer security space; one of the largest nonprofit health care organizations in the United States; a Fortune 50 global insurance provider; and our security partner, Proofpoint, who we are excited to deepen our relationship with as both a technology and security partner. I'm also pleased to highlight that Workday, a cloud pioneer and leading provider of enterprise cloud applications for finance and human resources which CrowdStrike also uses, has now standardized on CrowdStrike Falcon across their multi-OS fleet. The threat environment remains fierce as expanding attack surface and inherent vulnerabilities in widely used operating systems, along with the complexity of active directory, leave companies of all sizes open to attack and provide a rich feeding ground for sophisticated and novice e-criminals alike. The lessons learned from recent attacks emphasize that a breach involves more than just malware which is why companies need to employ a holistic breach prevention strategy rather than overly relying on malware prevention, regardless if it's legacy or next-gen. As I have said before, nearly every breach you have ever heard of had two things in common: the victims had both a firewall and an antivirus solution which is why we built the Falcon platform from the ground up to stop breaches and not just prevent malware. With this mission, CrowdStrike has turned the tables on the adversaries and has become a trusted leader in security. Meanwhile, competitors fall further behind as they continue to blindly promote a strategy that relies on malware prevention versus a comprehensive solution focused on people, process and technology that stops breaches. According to recent data from our customer base indexed by Threat Graph, more than half of detections analyzed were not malware-based. Attackers are increasingly attempting to accomplish their objectives without using malware. They are exploiting the proliferation of vulnerabilities and abusing systemic weaknesses in identity architecture to get on the system and then moving laterally, thus making it more difficult for legacy and next-gen malware-focused products to be effective because they are not focused on breach prevention. To further demonstrate my point, I'd like to share a recent customer win with a Fortune 500 company that was using Microsoft's legacy security products that failed to rise to the challenges of today's adversaries and ended up unnecessarily costing them millions of dollars. This company experienced a long and difficult deployment process, particularly in low-bandwidth environments where endpoint performance was critical. Notably frustrated, this company began to evaluate alternatives when it was unfortunately hit by ransomware that encrypted their primary and backup data, causing weeks of business disruption and a financial impact estimated to be in the tens to hundreds of millions of dollars. This is when they turned to CrowdStrike. First, by bringing in our incident response team to remediate and stabilize their IT operations and followed by deploying Falcon Complete across their environment. Our approach to stopping breaches with the Falcon platform is foundational to CrowdStrike's leadership position in the market and the epicenter of restoring trust to the security posture of companies worldwide. Using AI, machine learning and an intelligent lightweight agent, the Falcon platform defends against today's most sophisticated threats with unmatched speed and simplicity. CrowdStrike's Threat Graph combines a massively scalable threat intelligence database with AI-powered analytics to detect, prevent, predict and mitigate advanced attacks and zero-day exploits. Threat Graph and Falcon's XDR capabilities continuously ingest massive volumes of live telemetry data from Falcon endpoints and other sources at scale. The Falcon platform processes approximately one trillion events per day from millions of agents, delivering unprecedented security insights. This empowers Falcon to benefit from crowdsourcing and economies of scale unlike any other solution on the market today which we believe enables our AI algorithms to be uniquely effective. The success of our platform strategy and growing leadership as the trusted security partner of choice is also reflected in our module adoption metrics which we have continued to increase quarter after quarter. Subscription customers that have adopted four or more modules, five or more modules and six or more modules increased to 66%, 53% and 29%, respectively, in the second quarter. We believe that our extensible Falcon platform, purpose-built to collect data once and reuse it many times to address multiple use cases not only provides customers an advantage over adversaries and lowers TCO, it is a cornerstone to building a durable growth business over the long-term. As we innovate on the platform, customers can derive even more value from their CrowdStrike investment. Take, for example, a midsized health care organization who, despite their limited budget and security staff, was looking to bolster it's security in the wake of repeated attacks against their peers. This organization initially thought they only needed to add a SIEM solution but quickly realized the implementation and maintenance would be a burden to their current security posture. Whereas with CrowdStrike Falcon Complete, Falcon Zero Trust and Humio, they could transform their security posture, have round-the-clock monitoring, gain identity visibility and risk scoring and implement a highly-effective log management solution for less than the cost of purchasing a stand-alone SIEM product. This customer was also amazed by Humio's speed of ingestion and ability to query data in real time which they deemed critical, given the rise in malicious cyber-activity targeting the health care sector. Customer interest in Humio is very high as the ability to log everything and get answers in real time is a growing necessity. In Q2, we secured new Humio deals across multiple industries, including technology, health care, hospitality and financial services. Additionally, Humio is already off to a great start in Q3 with a seven-figure land and growing pipeline. The integration of Humio into our already market-leading XDR capabilities is on track and we are encouraged by the growth opportunities we see in this area. We look forward to showcasing more of our leading XDR capabilities at Falcon in October. I will now highlight several of our cloud modules that are gaining exceptional traction with customers as the threat landscape has intensified. First is Falcon Complete, our turnkey managed detection and response subscription. The heightened threat environment has put a significant strain on cyber-resources and has exacerbated the skills gap in the industry. Recent reports indicate that over three million cyber-jobs are unfulfilled which is more than double the current number of professionals currently working in the field. Falcon Complete combines the advantages of our Security Cloud, the technology in our Falcon platform and a team of threat hunters and responders to deliver gold standard security around the clock, at scale with superior economics to organizations of all sizes. This translates to stopping breaches that extend far beyond the prevention of malware and that leverage legitimate software or services, exploit systems configurations or abuse legitimate prudentials. In recent quarters, we have seen a significant increase in the Falcon Complete customer base which has grown approximately 2.5x year-over-year. Additionally, just last week, Falcon Complete was named a leader in IDC MarketScape for U.S. managed detection and response services. Within the report, Falcon Complete was recognized for strength in it's breach prevention warranty, fully remote, automated remediation, breadth of threat-hunting capabilities and strong machine learning and artificial intelligence capabilities for detection and response. The next module on the Falcon platform I would like to highlight is Falcon Spotlight which leverages the power of the cloud to provide real-time vulnerability assessment and AI to prioritize vulnerability remediation without impacting performance of the network or endpoint. Real-time vulnerability management is becoming a necessity for a proactive security posture, given the continued targeting of core functionality and vulnerabilities in the Microsoft ecosystem and increase in zero-day exploits such as the recent Microsoft PrintNightmare vulnerability. Demonstrating the power of Falcon's network effect, we leveraged the massive amount of data and intelligence available in our Security Cloud and our AI model to predict that this newly discovered vulnerability would be exploited by adversaries. Using this data intelligence allowed us to provide customers with real-time visibility into their exposure. Our ability to provide real-time vulnerability management significantly differentiates CrowdStrike and it's directly attributable to the fundamental architecture of our cloud-native Falcon platform that enables us to collect data once and reuse many. We believe our success to date with Spotlight is an excellent illustration of our ability to leverage the CrowdStrike Security Cloud to stop breaches and drive module adoption. Spotlight's ability to provide visibility in real time into PrintNightmare exposure without deploying new agents or scanning was a significant driver of no-touch trials generated through the CrowdStrike store. Spotlight has also become strategic in the sales process, with a number of Spotlight customers growing more than 150% year-over-year in Q2. Next, I will briefly discuss Zero Trust. The recent Kaseya breach which is reported to have impacted over 1,000 companies from a single breach, serves as a reminder to the far-reaching impact of a supply chain breach and the importance of a Zero Trust architecture. It is also important to remember that most ransomware outbreaks have a compromised identity component. Shoring up this threat vector is critical to stopping breaches and lateral movement. Customers are increasingly turning to a zero-trust solution to combat threat actors that leverage identity-based attacks and move laterally within their targeted environments. CrowdStrike has the only Zero Trust solution on the market today that combines endpoint, workload and identity visibility and behavioral analytics to secure environments and prevent lateral movement. Moving to cloud; more and more organizations are waking up to the fact that adversaries do not draw much of a distinction between targeting data on an endpoint versus a cloud environment. As an innovator in cloud security and operator of one of the largest clouds, organizations are turning to CrowdStrike to protect their cloud estates. I'd like to share with you a recent customer win that demonstrates how cloud-native organizations can leverage the Falcon platform to achieve best-in-class security that empowers their business model instead of clashing with it. A cutting-edge enterprise AI platform company and a member of the Forbes Cloud 100 was experiencing stability and scaling issues when trying to use a competitor's cloud security offering that was built through M&A. As a company on a mission to reduce their own customer friction and deliver actionable intelligence, they felt it was critical that their security partner could match their speed and scale in the cloud instead of slowing them down. With these requirements in mind, this cloud innovator selected CrowdStrike for it's ability to provide a fully integrated and fully managed cloud solution through a single pane of glass with a single team. This customer purchased Falcon Complete with Cloud Workload Protection and Falcon Horizon to fully manage both their traditional endpoints and cloud workloads. This new customer found immense value in Falcon's cloud offerings across their EC2 and AWS Fargate infrastructure, making CrowdStrike the perfect partner to scale with their business. To summarize the power, breadth and value the Falcon platform provides and the importance of building trust with customers, I will share two more customer wins with you. The first is with a large media company that was using a legacy provider and was hit with a severe ransomware attack that quickly spiraled across their business. They called on CrowdStrike's services who leveraged both Falcon EDR for visibility as well as our new module, Falcon Forensics which automates the data collection and accelerates incident analysis to help them quickly locate the root cause and take back control of their environment. Following remediation of this breach, this new CrowdStrike customer was eager to transform their security posture and adopted 11 Falcon modules, including Falcon Complete, Discover, Spotlight, Falcon X Recon, Cloud Workload Protection and Falcon Zero Trust to proactively secure and fully manage their workstations, cloud workloads and identity layer as well as provide visibility into their IT assets and vulnerabilities. Next is the customer win I spoke about earlier with one of the largest nonprofit health care organizations in the United States. Given this company is a nonprofit, budget really matters but not at the expense of breach protection. This customer was looking to refresh it's endpoint strategy and move away from their existing vendor, Cylance, given it lacked the focus, efficacy and the customer service they have been promised. Without a security partner they could trust to protect them, they felt vulnerable as incidents were not identified or remediated at the speed required to stay ahead of today's threat actors. The competitive bake-off initially included multiple next-gen and legacy vendors. The low-cost next-gen product was quickly eliminated because the CISO realized the overly prevention-focused approach was too similar to legacy tech. Ultimately, this customer chose CrowdStrike as their trusted security partner, given Falcon's low false positive rate, manageability at scale, ease of use and performance that stood out prominently over all others. Additionally, our frictionless deployment was once again a key differentiator as Falcon was deployed across nearly 400,000 endpoints in just a few weeks. Moving to our partners; as we have discussed before, we are a partner-first company and believe the rapid expansion of our partner ecosystem is a direct reflection of our growing leadership position. Partners naturally gravitate to market leaders as it helps them bring in new customers and likewise, customer choice helps propel vendor prominence within the partner community. Our leadership position is driving strong engagement with all partners of all sizes which is contributing to our growing presence among the highest levels, including Boards and CIOs. For the first half of fiscal 2022, our partner-sourced ending ARR nearly doubled year-over-year. Investing in our partner ecosystem continues to be a key priority. In July, we teamed up with Telefonica Tech to bring the power of the Falcon platform to their hundreds of thousands of customers across Europe and North and South America. Coupling CrowdStrike Falcon with Telefonica's next defense MDR offering, our joint customers now have trusted and proven next-gen endpoint protection and world-class services. We are also excited to announce a new strategic alliance with Verizon. Through this collaboration, the CrowdStrike Falcon platform will be positioned as part of Verizon's business security portfolio to provide comprehensive endpoint and workload protection that spans prevention, detection and response capabilities. Verizon Business will be able to manage CrowdStrike through their managed detection and response and CRM services. And we are thrilled to team up with them to help joint customers stop breaches and reduce cyber-risk. In summary, I couldn't be more confident in our leadership position and opportunities for growth. I do not see another vendor in the market with our vision platform or ability to execute at scale. Our leadership as a trusted security platform of record and strong financial performance stands as a testament to CrowdStrike's dedication to innovation, protecting and delivering value to customers and transforming the security industry. I'd like to thank every CrowdStriker for all that they do day in and day out to make us the best in the business. With that, I will turn the call over to Burt to discuss our financial results in more detail.