This Is the Biggest Cybersecurity Threat of 2026 According to CrowdStrike
By The Compound
Key Concepts
- TAM (Total Addressable Market): The total market demand for a product or service.
- RAAS (Risk and Advisory as a Service): A model where financial advisors offer risk management and advisory services.
- ARR (Annual Recurring Revenue): A key metric for subscription-based businesses, representing the value of recurring revenue normalized to a one-year period.
- Rule of 40: A guideline suggesting a desirable balance between growth rate and profit margin (typically, the sum of these two should exceed 40%).
- Agentic AI: AI systems capable of autonomous action and decision-making.
- PAM (Privilege Access Management): Security practices focused on controlling access to sensitive systems and data.
- Zero Standing Privilege: A security model where users have no inherent privileges and access is granted only when needed for specific tasks.
- Falcon Flex: CrowdStrike’s flexible licensing model allowing customers to easily add modules and expand their security coverage.
- SOCK (Security Operations Center): A centralized unit responsible for monitoring, detecting, and responding to security incidents.
- Autonomous SOCK: A future state of security operations centers leveraging AI to automate tasks and accelerate response times.
The Evolving Cybersecurity Landscape & CrowdStrike’s Strategy (2026)
This discussion centers on the current state and future trends in cybersecurity, with a focus on CrowdStrike’s position and strategy. The conversation highlights the increasing sophistication of cyberattacks, the pivotal role of AI, and CrowdStrike’s recent acquisitions aimed at bolstering its capabilities.
I. Market Performance & Growth (2025 & Beyond)
CrowdStrike demonstrated exceptional performance in 2025, being the best-performing cybersecurity stock, with a 35% increase over the last 12 months – double the S&P 500’s performance and triple that of a major competitor. This success is attributed to strong ARR growth (62x since 2017) and consistently exceeding the “Rule of 40” (40% growth and profit margin). The company’s Falcon Flex licensing model is a key driver, enabling seamless expansion of services and increased customer adoption of additional modules. Free cash flow is also a critical metric tracked alongside ARR to assess business health.
II. The Shifting Threat Landscape: The Battle of the Agents
The primary shift in the threat landscape is characterized as the “battle of the agents,” where adversaries are increasingly leveraging Agentic AI to automate and accelerate attacks. The time it takes for an adversary to move laterally within a system has drastically decreased, from hours to now under 40 minutes (with instances as low as 51 seconds between initial access and pivoting). This acceleration is driven by adversaries utilizing Agentic AI to perform tasks autonomously, bypassing traditional command-and-control infrastructure.
A key change is the emergence of “autonomous malware” – malware that doesn’t require constant communication with an attacker, instead reasoning and acting independently based on its environment and objectives. This makes detection significantly more challenging. The core issue is that attackers are now “logging in” rather than “breaking in,” exploiting compromised credentials and session cookies.
III. Addressing the New Perimeter: Identity & the Browser
The discussion emphasizes that identity is the new perimeter in cybersecurity. Attackers are increasingly focused on compromising credentials, often through social engineering or stealing session cookies, to gain access to systems. Traditional PAM (Privilege Access Management) systems are insufficient, as they focus on build-time permissions rather than runtime behavior.
CrowdStrike’s acquisition of Signal addresses this by introducing continuous identity and zero standing privilege principles. This means users have no inherent access and are granted privileges only when needed for specific tasks, dynamically and temporarily. Signal simplifies complex identity rules, reducing errors and improving security.
Furthermore, the browser is identified as a critical blind spot, as 85% of the workday is spent within it. The acquisition of Sarafic aims to provide visibility and control within the browser, protecting against threats that bypass traditional security measures. Sarafic’s technology allows for secure browser access without requiring users to switch browsers.
IV. CrowdStrike’s AI Strategy: The Agentic Security Operations Center (SOCK)
CrowdStrike is focused on building an “Agentic Security Operations Center” (SOCK) – a fully automated security operations center powered by AI. This is likened to the levels of autonomy in self-driving cars. The company’s advantage lies in its decade of accumulated security data from Falcon Complete (its managed detection and response service). This data, combined with human learning and reinforcement, is used to train bespoke security reasoning models.
The key differentiator is the quality and specificity of CrowdStrike’s training data – it’s based on real-world incidents they’ve investigated and resolved, rather than generic information. This allows them to achieve significantly faster detection and response times, reducing the workload for security analysts.
V. Recent Acquisitions & Their Synergies
- Signal: Focuses on continuous identity and runtime security, addressing the challenge of compromised credentials and insider threats.
- Sarafic: Provides visibility and control within the browser, protecting against threats that bypass traditional security measures.
These acquisitions complement each other, creating a comprehensive security platform that addresses both identity and endpoint security. Falcon Flex facilitates easy adoption of these new capabilities.
VI. Data & Statistics Mentioned
- CrowdStrike Stock Performance: +35% over the last 12 months (double the S&P 500, triple a major competitor).
- ARR Growth: 62x since 2017.
- Time to Lateral Movement: Decreased from hours to under 40 minutes (51 seconds in some cases).
- Browser Usage: 85% of the workday is spent in a browser.
Conclusion
CrowdStrike is positioning itself as a leader in the evolving cybersecurity landscape by focusing on AI-powered automation, identity-centric security, and comprehensive endpoint protection. The company’s recent acquisitions of Signal and Sarafic are strategic moves to address critical gaps in the market and enhance its platform’s capabilities. The emphasis on leveraging a unique dataset of real-world security incidents to train AI models provides a significant competitive advantage. The company’s strong financial performance and commitment to innovation suggest continued growth and success in the years to come.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Stanford CS153 Frontier Systems | Building the Frontier Ecosystem
Stanford Online

'Halftime' traders debate the market setup for the next half of 2026
CNBC Television

The Close for Friday, June 26, 2026
BNN Bloomberg

'At these levels it's a very attractively priced asset': Sissons on Hermes
BNN Bloomberg

The Street for Monday, June 29, 2026
BNN Bloomberg

'Things are going to be okay, in Canada and the U.S.': Thorne
BNN Bloomberg

'What we really need to get back to is the fundamentals of business': White on '26 market landscape
BNN Bloomberg