CrowdStrike Holdings, Inc. (CRWD) Earnings Call Transcript & Summary
January 21, 2025
Earnings Call Speaker Segments
John Defterios
attendeeAnd welcome to this critical session here at Davos 2025, the 55th year of the World Economic Forum. Crisis to Confidence in Cyberspace, that's the mission of the 45 minutes we have together. I'm John Defterios. I'm a senior fellow here at the World Economic Forum. I'm a professor of business at NYU Abu Dhabi, and I spent my last 10 years of my time as a correspondent with CNN as Emerging Markets Editor based in Abu Dhabi and the connectivity we see from the Gulf here to Europe, United States and obviously, Asia. We want to welcome our viewers on the live stream here who are watching. This is an excellent session because in the last 2 years of the Global Risk Report for the World Economic Forum, we've seen that cybersecurity and cyber threats rank either 4 or 5 in the world, rightly so. But I would say, as a former journalist, it doesn't earn its fair share unless there's a crisis that happens. We kind of think it's business as usual. Companies are ready to respond, but with the on-take of artificial intelligence now and then over the next decade and then phasing into quantum computing, it's going to be more of our common vernacular, and I don't think the world is ready for that, and we want to address what it means. But at the center of our discussion today is not only dealing with cyber threats, but it's also the impact that cyber threat does have and then obviously, what impact it has potentially on a brand and reputation going forward. I want to thank the team that runs cybersecurity at the World Economic Forum. I've had a chance to work with them for the last 2 years. They hold an annual gathering for themselves in November. They've put out an outlook report in the last week, and we'll make reference to it here in the discussion. If you'd like to do social media and provide some feedback here on this session, the hashtag is WEF25, and we're going to be taking questions from the floor about 15 minutes out. We invite those watching us on the live stream to do the same. Let me welcome George Kurtz. He's the Chief Executive Officer and Founder of CrowdStrike Inc. Welcome to you. Oyku Isik is a professor of Digital Strategy and Cybersecurity at IMD Business School. She focuses not only on the response by leaders in the cyber space and technology, but also the impact it has on brands. So it's great to have you. And George Oliver, Chairman and Chief Executive Officer of Johnson Controls. The two of you, G1 and G2, as we said in our pre-meetings, have dealt with different incursions, and they've learned a lot through that exercise. I'm going to ask them about it, but also they can share their leadership and what was required after having a cyber threat. And Oyku, it would be great to have you weigh in on what it takes to be a leader today and how much should be devoted in terms of time and attention to cyber, and then what impact it does have on a brand. I think it's a phenomenal topic that they've undertaken here. To provide some context, we have a cyber report that was put out in the last week here for the World Economic Forum, and they also did polling from that cybersecurity gathering that they had at the end of 2024, which I'll make reference to for those watching on the stream and here -- and live in the audience. I want to reference a recent report from the World Economic Forum in collaboration with the University of Oxford. It defines cyber resilience as the organization's ability to minimize the impact of significant cyber incidents on its primary goals and objectives. So if we can bring that graphic up here. And what we're looking at here is the incident, absorbing it as a chief executive or as a company and then the recovery. You can see that the recovery stretches out almost on a flat line here. What we're looking for and what I'd love to glean from the panel is like that V-shaped recovery, the preparedness, the resilience that you try to build into an organization here. And I made reference to the Global Cybersecurity Outlook report in 2025. It was just released last week. Supply chain interdependencies represent the greatest challenge. The report identified 6 components, and if we can bring that up on the screen, please, that companies need to contend with in this world of cyber complexity; geopolitical tensions, which are on the rise, and we heard from the European Union President today talking about this fractured world and how to respond; cybercrime sophistication and many actors in play here; supply chain interdependencies, I've made reference to that initial survey; regulatory requirements, AI and emerging tech, which I talked about in my opening comments; cyber skills gap, which I think is interesting. Only 13% of companies feel like they have the right cyber skills internally. There's a shortage of talent worldwide. Women in cyber is a big issue, which I think Oyku could address. And then 33%, 1/3 of the company said cyber espionage and a loss of IP as their top concerns. I made reference to the fact that both CrowdStrike and Johnson Controls had cyber incidents. So I think it's excellent that you're willing to come on the stage and talk about it.
John Defterios
attendeeSo George, as a CEO, take us through it. So what would like to manage something that hits a company that has a very good reputation? Did the scale of the incursion surprise you? And then how did you deal with it as a CEO? And how did your organization respond and look at you and say, what do we do next?
George Kurtz
executiveYes. So first, great to be here. Just to maybe reframe it, we didn't have an incursion, we had an outage. So July 19 was an interesting day, I guess, for us and the rest of the world, as you might imagine. And when something like this happens, you have to go back to your muscle memory, right? And we actually do work with a lot of companies that have cyber intrusions, and we have that muscle memory. So we activated our crisis response team. We knew what the issue was. We were able to roll back the issue really within probably 70 minutes, but there's complexities in the operating systems to be able to recover some of those systems, therefore, you had a much bigger outage. So once that was unfolding, then you kind of see the scale of it. And part of the challenge, I'm not sure everyone sort of remembers or has a good appreciation, but there was another technology outage, a different company that had an outage at the same time. So what we needed to do was we needed to deconflict what was our issue, which we know how it happened, and we rolled it back. And we had to deconflict that from what was happening with another service provider, right? Because all you hear is outage, so what's ours, what's theirs. In any event, we couldn't control that piece, but what we wanted to do was to be front and center. And there were 2 things that really came to mind. Number one, first, was the customer, putting the customer first. You can see the scale of our customer base, right? We wanted to make sure that we got to our customers, we were working with them to roll it back, and there's things that we did to automate the rollback for them. But just the complexities of the operating system, there were manual things that had to take place as part of that. We needed to be able to get out and educate and tell people what it was they needed to do. And the hard part is some of it required physical interaction. So you had to have key strokes and people have to type things in. And there's a lot that went into it, even though it was a relatively simple set of commands for people that don't understand what -- how to do that, it takes time, but you have to get that information out. So one of the key things for me was take care of the customers. And the second piece, as this was unfolding is, we needed to let the world know this wasn't a cyber attack because people didn't know, right? And this is where I basically said, "Look, I've got to get on TV." And this is within a few hours.
John Defterios
attendeeEven though people don't watch TV anymore, that's part of the challenge.
George Kurtz
executiveWe needed to be on the TV. Well, first thing we did was we got on Twitter.
John Defterios
attendeeYes, there you go.
George Kurtz
executiveAnd we announced it. And then we had continuous updates, right? And this is -- this sometimes can be hard because you've got teams of lawyers, teams of PR people, teams -- you go on and on as a big company, right? And you have to make a decision. And it's not easy in the first few hours without having all of the facts, and it's a bit of the fog of what's happening, again, what's ours, what's theirs, how do we make sure we get the right message out. But for me, it was really important to be able to get the message out. It wasn't a cyber attack. We knew what the incident was. We rolled it back very quickly, and then we were in the recovery mode working with customers. And I think that really helped to settle a lot of folks down. And then the heavy lifting of making sure that we can bring systems back online was an ongoing effort.
John Defterios
attendeeI'm going to circle back about your leadership because I want to bring in G2, as we said here. George Oliver, am I correct in saying you're going to retire pretty soon? What a way to go out, right? Because you had a very big cyber crisis. Is that the first major crisis you dealt with at Johnson? And then -- and I'd love to get the other George's input on this. As the CEO, like what's the first thought that goes through your mind when you get hit that hard? And I'd love to get Oyku's view on leadership, and how do you prepare for a new era of a challenge that probably wasn't in our vernacular 10 years ago?
George Oliver
attendeeSo I think it would be helpful to talk a little bit about Johnson Controls, so you get an idea of what our infrastructure is like and the journey that we've been on. So at Johnson Controls, we're about $28 billion globally. We operate in 100-plus countries. We're very distributed. And we're a company that has been made up of a lot of acquisitions with a lot of multiple systems that have come together into one. And so we've been on a journey on how do we take all of those systems streamline, get to one ERP, get to one operating system with similar type systems deployed. And we've been on a journey, and cybersecurity has been a key element of that. So as we're addressing technical debt, how do we make sure that when we look at our infrastructure, we have over 100,000 devices, 100,000 users and hundreds of thousands of applications? And so just to give a simple lesson, it's all about response. It's sensing at the device level. It's understanding access and understanding where the people that are coming into your network, where they're operating and then it's about applications and access to applications. So we're -- all of that was being built and making sure that we're resilient. So when we had the incident or the -- there's always incidents, and they're typically managed and contained. It's all about response. It's sensing and response no matter what level the incident is. And you'll find that whether it'd be a device or whether it'd be where someone's user credentials got compromised, there's going to be events. It's the ability to be able to sense and respond. So we did get an attack, and we're able to respond pretty quickly. It did impact some of our network. And what I would say the most important thing is being -- is planning for what is -- in the event that -- if you do have an event, not only from a technical standpoint, what's the response. But from a leadership standpoint, how do you respond? And what are your business continuity plans? And so immediately, it was on a weekend, you get notified that some of our systems were compromised and then you go to work. And it's easy to kind of try to self -- do a self-assessment or you can stand up and lead. And so that day, we had our full extended leadership team across the globe activated, really assessing to make sure we understood exactly what was compromised, what is our plan. And the -- as we work through that, we continued to operate. And so we continued to stay focused on customers. The other thing is this idea of as you -- as George said, as you learn, you'll maintain transparency with your constituents because that's -- from a trust and respect and maintaining relationships is important. So right from the Board to customers and making sure that as you're working with customers, you're keeping them informed relative to now where we are relative to being able to continue to support them with critical services. We're a building solutions company. So we do a lot of service, maintaining our customers' environment on a real-time basis. So that's important. So that really played out well for us. And then we sit up our leadership team on a daily basis and also engage partners. So when you have a lot of technology like we do deployed, we maintain strong relationships with all of our partners. And so we not only activated our internal team and leadership with our business continuity, but also engaged all of our technology partners to make sure that we: number one, understood and assess the incident and making sure that then we were working together to be able to effectively address it on -- what I would say on the critical path to make sure that we're positioned with speed to be able to mitigate the risk and ultimately, continue to operate. That's what we did. So I was extremely proud of -- it was a -- what I would say is -- and then we can talk a little bit more about this in the discussion, that cybersecurity is going to be part of the culture, and it's going to be embedded in everyone's behavior.
John Defterios
attendeeFor every company, would you suggest? Because you're a very connected company, obviously, CrowdStrike is the same...
George Oliver
attendeeWhen you go through -- because you always are training and you're always putting together processes so that you mitigate any risk and any exceptions. But as you get into any type of incident, you understand, okay, was it a device? Was it a user credential? Was it access that wasn't -- once you get into, then you make sure that you create redundancies and then automation and the work that we're doing with CrowdStrike is a lot of the sensing and then the automation, then you have intelligence not only from a device, but from a user standpoint. And then you can -- it's all about response. When you see something that's not right, how do you then respond? So part of that was when you go through this, then every leader in the company becomes an expert because not only are they -- they're involved previously, but really getting to that level of detail. And we have 100,000 colleagues across the globe, then from a leadership standpoint, making sure that they're totally aligned and behaving with their actions, whether it be their access or how they're using devices, so that they are ultimately making sure that all of the securities that we have in place are being fully consumed and put to work. And so for us, it was -- as we look back, it was a test of our culture, our ability to be able to respond and activate a global team and really continue to be able to operate the company, while we're mitigating the incident and ultimately, getting back to full operation. So I was extremely proud of the team, and really a lot of our partners stood up with us to make sure that every step of the way they were playing their role in supporting us to mitigate what we saw as being the contributing factors.
John Defterios
attendeeOkay. You raised a great point. It's a great leaving=off point to Oyku. First, can you spend 10 seconds to tell the audience what your specialty is because it will help us in terms of the context of your research, Oyku?
Oyku Isik
attendeeYes, of course. As a professor of IMD Business School, we actually exclusively do executive education. So first of all, it's a privilege to listen to two leaders talking about their experiences. This is what really makes a big difference. And my research is really on about chief information security officers and behaviors of organizations when it comes to dealing with cyber attacks.
John Defterios
attendeePerfect. Okay. Good. We have this case, where could have a prisoner's dilemma because you're in the game together, right? And you have this trust built up and then you face a strike, and then that cohort starts to look at you and say, "Okay, I put all my trust in you and there was a failure." And then there could be panic from that partner, or as George was explaining, everybody rallied to the cause. So what does your recent research advise future-looking CEOs? Because we know that threats are rising, and we'll get into this discussion about the developed and the developing world, right, and those vulnerabilities a little bit later. But -- and also that brand narrative that I addressed in my opening comments about rebuilding trust very quickly during an incident because we want that V-shape to rise quickly. Go ahead.
Oyku Isik
attendeeI love that visualization, the V-shape, and we talked about [ shrinking the V ], right?
John Defterios
attendeePretty good team that we work with.
Oyku Isik
attendeeExactly. Exactly. And there are 2 things that George talked about the muscle memory. I love that as a reference because that only happens if you think detailed enough of scenarios and if you practice enough, right? And George talked about how it's part of the culture and how quickly you were able to continue working, right, servicing your customers. So first half of that V, absorbing the incident. That's a great example of that. So you were prepared, the culture was there, so you were able to -- despite the incident, were able to operate. And the other one, the significant part of the resilience, is that we actually can practice this enough so that we can, after absorbing, recover from the experience. So I think there were 2 really good examples of long-term thinking, and answering your question, the necessary shift from more traditional, short-term cybersecurity thinking to a long-term resilience building thinking is, I think, with these 2 examples is greatly represented here.
John Defterios
attendeeGood. But who would have thought 5 years ago that the brand would suffer if you don't respond? I mean George was saying, "Look, I was ready to communicate." Both of you said, "I had to communicate to my partners, my customers." And then you had to say, "I need to get ahead of the curve here." Go ahead, Oyku.
Oyku Isik
attendeeBecause -- you talk about trust, right? How do we build trust? And the first question that comes to mind, especially -- there are, of course, anecdotes we can learn from when it comes to doing research. It all comes down to, how do I quantify trust? What you mean trust? Is it the financial health of the organization? Or are we talking about finding your way to measure the reputation of the organization? What we know from -- if we look at trust from financial health perspective, to be honest, we don't know much. We only have very little research on this because it's very difficult to collect reliable data at large scale to really understand, and the research are all over the place. But when you look at trust from a reputation perspective, then we know for sure. Minor incidents -- we tend to actually forget, organizations do recover from minor incidents relatively quickly with minimal stock value impact. But for major incidents, we do have evidence that it really takes quite a bit of time to recover back. But I want to add something here that most people don't think about, which ties back to preparation, is that what type of incidents we're talking about makes a difference, and we know this from research. So if it's an internal cyber threat, in the perspective, the trust on the organization really decreases. If this is an external threat, there's a threat actor, then really it is less of a trust issue on the services of the organization.
John Defterios
attendeeExcellent.
Oyku Isik
attendeeIf it's negligence, then the question arises around the culture of the organization, for instance.
John Defterios
attendeeGood. Both of your comments led me to believe if you had to do this again, what would you have done differently? And there's always that question that comes up because you have businesses that need to sell cyber safety and security and fortifications. And when do you know you have the right tools? Go ahead, George.
George Kurtz
executiveWell, you never want to be in a position, but you have to prepare for it, right? And this is what we're talking about. We help a lot of companies go through incidents, and we drill ourselves. And this particular one, it's hard to put this in the playbook of what happens, right? But we used the same, again, muscle memory to be able to roll things out and activate our teams. I think as you go through any of these, there's always areas where you can pick at and go, "Okay, we could have done that better or we could have communicated this." Or you come up with various scenarios. But I think, by and large, something like this, in any incident, if you are upfront, if you're transparent, if you communicate not only one time but frequently, and this was a big part of our response was we immediately said internally and then we've said externally, "We will tell everyone as much as we know as soon as we know it." And basically, we had a whole portal that we stood up, right? And then as we knew things, you just went to the portal and you got updated, right? So I think that really served us well. And what I would...
John Defterios
attendeeHas the business been hurt as a result of it? Now would you say the CrowdStrike brand suffered?
George Kurtz
executiveI think the trust is even up more. I mean I've -- walking around Davos, I run into CEOs of many of our companies, and they say -- I had one organization say, "We actually use CrowdStrike in our [indiscernible] as a prototype for how you should respond." It was just last night. So I think, again, everyone's going to have their own opinion, but I think our customers have looked at it. And I think anyone in business or IT realizes things happen, and it's really how you respond. And we want to be known for our response to this, not necessarily the incident that actually happened. So that's the way we would look at it. And again, could we do things better? I'm sure. But I think overall, with trust and transparency and communication, we did the best we could with what we had in front of us.
John Defterios
attendeeOyku?
Oyku Isik
attendeeMay I quickly add here?
John Defterios
attendeeYes, of course. Yes.
Oyku Isik
attendeeBecause we really do know that during the incident, communication is the biggest differentiator. And being transparent, honest and owning up to it does make a big positive impact on the image of the organization. But I wonder what you think about the possibility that in your case, product stickiness and vendor lock-in, how much that play in, right? Clearly, for smaller organizations, this may lead to customers leaving, but I wonder if you -- if there was a way for you to kind of measure the impact of that?
John Defterios
attendeeOyku, that's a great question. We are going to look at the vulnerabilities of SMEs in our next round, so I'm glad you brought it up. Go ahead, George.
George Kurtz
executiveYes. I think when you look at this, I mean, we're a public company, we've talked about our retention rates, right? They're 97-plus, which is fantastic. So even after the incident, I think when you -- to your point about the product and the stickiness, I mean the good news is we've got the best product in the market. So customers like it. And I'll just tell you a quick story with a customer, who is a large financial services company, went through what happened, why it happened and why it won't happen again. And they said, "Look, you've got 10 years of trust deposits in the bank, 10 years of trust deposits. And on the 19th, you had a withdrawal. But net, you're positive. Net, you're way positive.
John Defterios
attendeeThat was nice of a financial services company to say it. [indiscernible].
George Kurtz
executiveBut they went to -- this system went to the Board and said, "If it wasn't for CrowdStrike, they recovered pretty quickly. If it wasn't for CrowdStrike of 10 years of protecting them, it would be a much different story." And this is, again, building trust over time. And I think that has really helped us out with a great product.
John Defterios
attendeeRight. We're -- I don't want to get into Midwestern values, but the company is based in Milwaukee, Wisconsin and very -- and for those who knows -- know America, that's where they value it. I'm from the West Coast, so it's a little bit different mindset of like blue sky thinking.
George Oliver
attendeeI would like to contribute to the last question about the 2 things that come to my mind because we -- cybersecurity, of course, is a top priority across all companies. And then it's more about how is that then built into your operating system so that all of the key metrics, response times, if there's any exceptions around sensing of devices or any as far as the strategy around user access, really, the CEO, at least should understand that. I mean understanding what their network is, how that's configured. And then from a cybersecurity metric, they should be embedded in their operating metrics across the company. And that allows every leader to really understand how they lead cybersecurity, right? Typically, I think historically, it's been more of an IT type metric. So I would say: number one, making that front and center, really understanding your infrastructure and network, how that's made up with devices, users, applications. And then the whole strategy is sensing and then reacting when there is anything unusual in the most simplest form. And the second is, and I think this is where George comes in, George 1 comes in, I purposely -- and I'm an engineer, so I can consume technology and we're going through all of the reviews and felt that we had all of the best technologies and capabilities deployed. What I learned was the technology development is so rapid, and now with the threats being much more sophisticated because of AI and other capabilities, that being first on the state of the industry. And so I spent time with a number of other CEOs in the cybersecurity to make sure that I fully understood as far as our -- the work that we have done to build our security, I understood then how does that compare to what you'd consider the next-generation kind of best-in-class. And I think that's helped the organization so that as we're prioritizing where we're now deploying resources and the like, it's, I think, pretty clear that everyone know why we're doing what and when.
John Defterios
attendeeOkay. And my question on values, what did you learn about the values of your organization during the crisis?
George Oliver
attendeeWell, I mean, for us, as we've gone through a transformation, it was a test of leadership. And when you're the CEO, it's -- when you get that notice that you've got an incident and then you quickly scope it, it's significant. You can reflect in. But I think what happened was we immediately did what we all did best, was lead and engage right from the day it happened to...
John Defterios
attendeeYou panicked?
George Oliver
attendeeBusiness continuity, daily understanding, okay? How we're going to operate? Where we had some challenges, how we're going to operate around? And it was seamless. Meaning, every day, every business leader with their teams, the workarounds or some additional capabilities that we could activate. And so that was a real-time learning shared kind of a standup meeting just as you're assessing and acting. And I think from that standpoint, you then have the -- now the combined knowledge and you're acting real time and you're communicating, you're communicating to customers and ultimately, employees and partners. And what you want to do is instill confidence that, okay, everyone's going to have an event. How do you manage that? How do you respond? What is the leadership that you demonstrate? And I think, for us, as we've worked with a number of partners and advisers working through this, we've got high grades. And our team was prepared, reacted and continue to run the company fairly well while we're mitigating the risk.
John Defterios
attendeeOkay. Good. I want to bring up the next set of data here. We have about 16 minutes left. Looking at this cyber inequity, and that would be from a large company that has budget and can play with this into your supply chain with smaller organizations that probably don't have the budgets to -- and that's the trust that we wanted to talk about. But I also would like to have you address the developed versus the developing world, right? Because everybody likes to tap that growth of emerging markets, but do they have the capabilities to be your partners? So if we can look at the surveys here, the key challenge, 54% of large organizations highlight supply chain challenges as the greatest barrier to achieve in the cyber resilience. How do you test your supply chain, is one question I want to have you consider. And then furthermore, 71% of cyber leaders at the annual meeting in November of the WEF cybersecurity group, small organizations have already reached a critical tipping point when they can no longer adequately secure themselves against the growing complexity of cyber risk. SMEs of course, represent about 50% of growth or 50% of jobs around the world no matter where you are in the economy. So George, what are some examples and lessons how to successfully rebuild trust with the stakeholders? But how about everybody in your supply chain, how do you make sure that they're up to snuff? I think it applies to both of you. And then, Oyku, you can weigh in with the research and recommendations on that.
George Kurtz
executiveWell, I think when you look at supply chain, this is one of the areas you saw the stats of risk. And I know we talk about it a lot, the interconnectedness of the world. I don't think it's fully appreciated. It's almost -- when you have these visuals, $1 bill is really thin, but $1 billion of them goes up to the moon kind of a thing. Like you really don't know how interconnected the world is until you have an issue. And when you look at supply chain, which is one of the biggest areas of risk right now, you've got small companies. They make one little part, one little bolt, one little something for a spacecraft or the government or what have you, and they're all connected. And typically, what we find when we do incident response for companies is there's a lot of large companies that do the right thing. They spend the money, and then it's a third party. And you don't hear about the third party because they're 10 people or 100 people. Nobody wants to talk about it. They want to talk about the company that has an incident. So that's one of the biggest areas. I'm sure you can reflect and comment on that. And making sure that, that is locked down is incredibly important. And overall, just assessing where the real risk is and where the dollars need to be spent, from a smaller company perspective, they have a lot of risk, right? And they have a lot of risk, whether that's ransomware or whether it's supply chain into a large organization. And this is why AI and even managed services are so effective because you can basically -- and even a small company, we can bring the same technology that we bring to the largest banks to a small company at a very efficient cost price point. So that's the way we do it.
John Defterios
attendeeThere's the other threat of the deepfake. Like somebody takes over your Board, they hold the Board meeting, and they kind of hijack your narrative for 24 hours if you're not careful, right? So that's complexity for a leader. Is it not? Oyku, what's your...
Oyku Isik
attendeeAbsolutely.
John Defterios
attendeeAnd this whole idea of trust, you could be completely bought into a deepfake, and it's a -- it changes the game quickly.
Oyku Isik
attendeeAnd I think sometimes I still do hear from leaders of SME, small organizations, that makes me think that there's still lots of awareness work to be done there as well. One manager of an SME shared about a ransomware incident they experienced and how this experience brought the team together that made them a team. At the end, almost thankful for the experience saying that I had zero preparations in place before I experienced this. Now I am a team, really a team with the rest of my organization. And we actually have processes and policies in place to deal with this. So it makes me think that maybe sometimes still this thinking, "Oh, I might be flying under the radar can still be a thing for SMEs. But coming back to leadership skills, I think it still applies whether a large corporation or SME still being able to decide under pressure, having emotional intelligence and composure, being honest and accountable, all these characteristics, whether for international corporations or SMEs, I think the same."
John Defterios
attendeeGood. George, you mind, Oliver dealing with this issue that you're a global company and there's vulnerabilities of a developing world that they want to grow, they even admitted they don't have the skill sets inside your short of the [indiscernible].
George Oliver
attendeeWe have a very complex supply chain. It's global. We have all-size suppliers. We do try to mitigate risk by having multiple suppliers, dual-sourced and regionally developing suppliers. So there's all kinds of supply chain strategies. But what I would say, what we've learned is that as we're assessing suppliers, we go through supplier assessments, and then you can tell when you go through an assessment the ones that actually understand it and are proactive in what they're doing to protect their infrastructure and maybe ones that are not. And -- so we have role to play that, number one, we now make sure that's part of their assessment. And then as we can educate and help and assist, then we obviously, make our teams successful to do that. And I do agree with George that when I think if -- with the ones that maybe don't have the depth and expertise within their company, then it's going to be very difficult for them to manage themselves. So I do believe -- and I think what we're trying to do, and I get lots of inbound calls from other CEOs as far as how we dealt with it and how we responded, and I think the biggest thing is this, we want to help everyone, right? You want to -- we all want to make sure that we're all learning through this journey we're on, helping other companies, helping suppliers. So there's a huge education that we're -- I think everyone is going through because this is becoming much more sophisticated, and then demanding it. And what will happen is you're going to have to -- either suppliers are going to have that core capability or not. And if that's going to propose any significant risk to our ability to be able to continue to execute, then we'll probably have to look at other -- which we do on a real-time basis.
John Defterios
attendeeYou do the screening then on...
George Oliver
attendeeOn the suppliers. And so even though everyone seems to want to get down to the resources, you can't afford not to put the resource to work because that's -- think of it as more insurance than it is once you have an event, then all of that is for not anyways.
John Defterios
attendeeI want to open the floor -- thanks, George -- open the floor to questions. If you have any, just raise your hand and we can get a microphone into your hands. And don't be shy. I'll give it a breather. I've got another question at hand here. State actors, man, it's getting pretty nasty out there, right? And they wouldn't call out different countries, but they do often now, right? So U.S. accusing China or Russia. The fight in the Ukraine has become a cyber warfare as well. That's a pretty easy way to disrupt if you reach into U.S. Treasury Department, right, or the Federal Reserve. How nasty will this game get now with AI coming on quantum computing power? How do you see that?
George Kurtz
executiveWell, it's already nasty. I think most people really don't see the -- below the iceberg, right? And when you respond to these things...
John Defterios
attendeeThat's a perfect way of putting it, by the way.
George Kurtz
executiveWhen you respond to these things, you see how prevalent it is. And when -- you only hear about it when it bubbles up to something that can be sensationalized. But China is very, very active in these areas. One of the things that they're really focused on is operational preparation of the environment. So being able to prepare in case of conflict, say, South China Sea as an example, and this is a huge issue for certainly the U.S. government and other governments, right? And if these sort of things happen, there's a lot of capabilities there. But I think the heart of -- we can talk about different countries and adversaries for the next hour. So I think the heart of your question is, what does it all mean and how bad does it get? Well, we think about this -- we think about adversaries in maybe 3 categories, and I can think about it as a pyramid. So in the top part of the pyramid you have nation-state actors. In the middle band, you've got e-crime. And in the bottom, you've got hacktivism. And then at the very top, you've got the most sophisticated actors. And then what we see is that their techniques trickle down into the center band, which is e-crime. So you don't have to be a true expert actually to be able to execute an attack. Now when you talk about Gen AI, you've now democratized all the smart things that have been done by the nation states and now you make it available to like a multiple of adversaries that are out there. And even if you don't know what you're doing, a, you can buy these capabilities, but we see it now where an adversary maybe is not all that sophisticated. They buy a kit, they can break into a company, an access broker. And then they actually have one of the Gen AI tools to create scripts to actually bypass the technology. So that's the biggest thing that we're going to see. It's going to compress the speed. We talk about response, right? You had so much time, now it's going to even get shorter. We track breakout time. It keeps getting smaller. And it's going to democratize how many more people can get in the game of being an adversary.
John Defterios
attendeeInteresting. Oyku?
Oyku Isik
attendeeJust to add to that, because I do realize also in the classroom that most executives do not really know how accessible these things are and that you can still inflict damage even though you're not an expert in this, right? So the accessibility, growing Cybercrime-as-a-Service market is something that we really need to continue talking a lot about. And we know that even more damage is possible with AI. Research shows us what's possible already. And so there are things that we can start preparing for even though we don't see them out in the wild yet. So there are many different resources we can turn to, to start preparing and scenario planning for these things.
John Defterios
attendeeYour thoughts...
George Oliver
attendeeI would say -- similar to George, I think it's really just playing offense, meaning that we can be as sophisticated as they can be with AI. We now -- we do believe, and my assessment, the technology community is making incredible progress. So technology is available today to solve -- to really be proactive to mitigate any significant risk. And so I would just suggest that how do you now take that technology and be really proactive using AI and being -- thinking like the bad guy because I think that allows you to be agile in taking all of your data, whether it be around your devices, around users, around applications and become really sophisticated in how you ultimately then -- because like as George said, it's all about response. When you see anything unusual with a user or with a device, immediately shut down. Because they're going to find a way in. What you want is a sensing and response that they're put in the closet, as I say it. And so it stops the progression as they get into your network. That is probably what's most critical. And I would say, based on my experience, really understanding the technology and then understanding how you get this defense-in-depth around all of your critical elements of your network, which then allows you to be able to create their response on anything that's unusual, that could potentially be more of an impact. And I think, in doing that, we'll be as good. And then through service providers, you have good intelligence relative to what the broader landscape looks like. And so that sharing, relative to how we're proactively deploying now the technologies, I think, is very helpful.
John Defterios
attendeeGreat. We have questions here on the floor? Please, one here. And just if you can direct it to somebody. If you have one in specific, just let people know who you are.
Roshan Navagamuwa
analystSure. Roshan Navagamuwa with AIG. George, good to see you. The question is directed, maybe starting with you. You actually triggered this story when you're talking about nation-state actors in terms of threat actors, right? Just your thoughts on what you think is a corresponding public-private partnership opportunity, maybe a more kinetic partnership opportunity when you're thinking about defense and kind of routine?
George Kurtz
executiveWell, that's always the big question of what can be done. And when you look at the private sector, we do work with law enforcement all the time. We explain what's happening. We found -- I mean, we didn't even talk about North Korea and some of the things that they're doing, which is really interesting. But what can be done? And I think we started with the public-private sharing of information with things like JCDC, where you have these fusion centers and they can share all this information, which is great. But then like what is the next step? How can governments be more active in shutting this stuff down? There was a recent example with one of the ransomwares or kits, I forget which one it was, where they -- basically, the government's kind of defanged it, right? They went out and they were able to -- you probably remember which one it was. But those are the kind of things that we look at. And then how do you disrupt their infrastructure? You have to remember, the infrastructure is actually fairly not costing dollars, but time to be able to set up and they want to reuse that, right? So if you can burn their infrastructure every time, it makes it that much more difficult for them to keep wash, rinse, repeat. We see what happens, and it literally is wash, rinse, repeat, just go down the list of companies. So I think that's where it can be much more interesting and more offensive where you can disrupt that, I think, in a controlled fashion.
John Defterios
attendeeOkay. In 30 seconds, if you can, George Oliver, are governments prepared? Because I know they take it very seriously at the White House. For example, they have a cybersecurity desk and they liaise between National Security and Natural Economic Council. They take it seriously, but they can't potentially keep pace with private sector. Just a minute, if you can, and then I'll go get Oyku's final thoughts. Thank you.
George Oliver
attendeeWell, I mean, on that, I don't want to assess the governments. I think at the end of the day, there's different levels of sophistication and resources that are deployed across the globe. I think for all of us, making sure that there's transparency relative to what is happening so that then they ultimately are putting their resources to work to ultimately correct the -- to protect the broader environment. So I think it varies, right, I mean, across the globe.
John Defterios
attendeeYes, I do have those concerns, and I've shared it with the WEF about the Global South in terms of they have to deal with energy transition and climate change and dealing with something like this, you're trying to grow, feed your populations and deal with cyber threats, right? And we've seen the attack...
George Oliver
attendeeI mean I think -- I mean what I'm finding on -- internally with our own resource that we're putting a significant amount of resource and we're finding that, from a technology standpoint, we're leapfrogging some of the older, less effective technology now with the new technology. So you can do it very efficiently as you're now continuing the journey to really be proactive with the technology that's being deployed.
John Defterios
attendeeGreat. Oyku, in 40 seconds, any final thoughts on this? And what you learned out of this from 2 leaders in the space?
Oyku Isik
attendeeI guess we heard that's a leadership imperative before anything else, right?
John Defterios
attendeeYes, it is an imperative.
Oyku Isik
attendeeThere's a very big technology side to this, but clearly, culture and leadership and awareness creation in the organization is still the pushing power behind this. And I think it's a very interesting thing to look into how can we be more proactive rather than defending ourselves, how can we proactively engage and disrupt the operations of cybercrime network on one hand, right? On the other hand, I'm thinking, from an information sharing perspective, bringing SMEs up to speed, what kind of incentives can we create out there to -- so that it doesn't end up becoming only an issue of protecting myself? And how can we incentivize investing in resilience, is also a good question that I have in mind.
John Defterios
attendeeThat's great. Our session was From Crisis to Confidence in Cyberspace. I'd like to thank the panel, Akshay Joshi, your team, Felipe, Juliano, thanks a lot for all the support leading up to it. I appreciate those who are online. I would highly encourage those in the audience here and online to take a look at the annual report, which came out a week ago. It addresses this wholeheartedly, and you'll see where we got the data that we shared on screen here. I appreciate your candor, by the way. Most CEOs have had something -- an incident, if you will, wouldn't sit up and face the music. You did it when the incident happened, but you're also willing to share the lessons learned, which I appreciate. Can we give a nice round of applause to our panel. Thank you.
George Kurtz
executiveThank you.
George Oliver
attendeeThank you.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete CrowdStrike Holdings, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to CrowdStrike Holdings, Inc. earnings transcripts and 251,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.