This conference call transcript was computer generated and almost certianly contains errors. This transcript is provided for information purposes only.EarningsCall, LLC makes no representation about the accuracy of the aforementioned transcript, and you are cautioned not to place undue reliance on the information provided by the transcript.
3/5/2024
Thank you for standing by and welcome to CrowdStrike's fourth quarter and fiscal year 2024 earnings conference call. At this time, all participants are in a listen-only mode. After the speaker presentation, there will be a question and answer session. To ask a question during the session, you will need to press star 1-1 on your telephone. To remove yourself from the queue, you will need to press star 1-1 again. I would now like to hand the call over to Maria Riley, Vice President of Investor Relations. Please go ahead.
Good afternoon, and thank you for your participation today. With me on the call are George Kurtz, President and Chief Executive Officer and co-founder of CrowdStrike, and Bert Podbear, Chief Financial Officer. Before we get started, I would like to note that certain statements made during this conference call that are not historical facts, including those regarding our future plans, objectives, growth, including projections, and expected performance, including our outlook for the first quarter and fiscal year 2025, and any assumptions for fiscal periods beyond that, are forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These forward-looking statements represent our outlook only as of the date of this call. While we believe any forward-looking statements we make are reasonable, actual results could differ materially because the statements are based on current expectations and are subject to risks and uncertainties. We do not undertake and expressly disclaim any obligation to update or alter our forward-looking statements, whether as a result of new information, future events, or otherwise. Further information on these and other factors that could affect the company's financial results is included in the filings we make with the SEC from time to time, including the section titled Risk Factors in the company's quarterly and annual report. Additionally, unless otherwise stated, excluding revenue, all financial measures disclosed on this call will be non-GAAP. A discussion of why we use non-GAAP financial measures in a reconciliation schedule showing GAAP versus non-GAAP results is currently available in our earnings press release, which may be found on the investor relations website at ir.crowdstrike.com or on our form 8K filed with the SEC today. With that, I will now turn the call over to George.
Thank you, Maria, and thank you all for joining us today. CrowdStrike delivered an exceptional fourth quarter that far exceeded our expectations. It was another quarter of records. Record net new ARR of $282 million, continuing our acceleration trend, growing 27% year over year. Record operating margin of 25%, up 10 percentage points year over year. Record free cash flow reaching 33% of revenue, and a free cash flow rule of 66. Record gap profitability and record cloud identity and next-gen SIM ending ARR of greater than $850 million, together more than doubling year over year. These results illustrate CrowdStrike's substantial and widening competitive moat, exceptional business acceleration, and validated market leadership. Building on my founding vision, CrowdStrike is the only single platform, single agent technology in cybersecurity that solves use cases well beyond endpoint protection. Falcon is the easiest and fastest cybersecurity technology to deploy, and our single AI native platform makes vendor consolidation instant, frictionless, and natural. The feedback we receive from customers, prospects, and partners alike is consistent, eagerness to deploy the Falcon platform, ease of adopting more Falcon platform modules, and excitement from continuous innovation with new Falcon capabilities delivered weekly. Leaving stitch-together point products and PowerPoint platforms behind, CrowdStrike customers realize the benefits of superior outcomes and lower TCO. A recent IDC report echoes this. showcasing $6 of return for every dollar invested in the Falcon platform. That is ROI. Free is never free. Customers understand the difference between product pricing and the total lifetime cost of operating inferior technology. Given the Falcon platform's ROI and TCO savings, we believe we will continue to see favorable pricing dynamics. I'm thrilled with our performance, which is a testament to the execution and passion from the very best team in cybersecurity. Unified by our focused mission, we stop breaches. My gratitude to all CrowdStrikers on a job well done. Our execution and discipline across the business, coupled with overwhelmingly positive market feedback, gives me strong conviction in our fiscal year 2025 momentum which Bert will cover in more detail. The current macro environment remains stable and consistent with prior quarters. We expect continued deal scrutiny throughout this coming year. We remain focused on operational excellence while delivering market-leading growth at scale, assisting organizations of all sizes to consolidate and improve their cybersecurity. In contrast to the macroeconomic backdrop, the state of the threat landscape has never been more elevated. In CrowdStrike's recent 2024 Global Threat Report, we unpack the harsh realities of cyber today. Key findings include, first, attacks are faster than ever. What took adversaries hours has shrunk to minutes and seconds. Attack speeds will only accelerate. Second, the cloud is increasingly under attack. We tracked a 75% increase in cloud intrusion attempts. The cloud is today's battleground for cyber attacks. And third, generative AI is an adversary force multiplier. Gen AI puts advanced cyber crime tradecraft in the hands of attackers of all skill levels. Gen AI will dramatically grow the adversary population. The Global Threat Report showcases our threat intelligence leadership. We collect trillions of threat signals daily, creating one of the world's largest and fastest growing cyber threat data sets. From day one, we've been an AI company, training the industry's most effective and accurate AI models to prevent attacks based upon our data modes. Embedded in the Falcon platform is a virtuous data cycle where we collect cybersecurity's very best threat intelligence data, build and train robust preventative and generative models, and protect CrowdStrike customers with community immunity. Our team of data science PhDs operate this continuous and real-time process, constantly evolving Falcon's AI foundation to predict adversary activity and stay ahead of threats. Our ever-growing data corpus and unique access to cyber's freshest data at the source, alongside our technology and our human incident response, threat analysts, data science, and engineering expertise, together serve as a structural competitive advantage. Along with AI, cybersecurity is a top priority in my discussions with numerous boards. In today's environment of heightened cyber attacks, the latest SEC breach disclosure regulation only increases the pressure on companies and their boards. We regularly assist boards with regulation readiness by bringing cybersecurity from the backroom to the boardroom. This, alongside the severity of the threat landscape, makes effective cybersecurity an increasingly mission-critical necessity. That said, cybersecurity today is a frenetic vendor bazaar. Disjointed point feature copycat products clutter the market, attempting to band-aid symptoms instead of curing the illness. OS vendors use their market position to create a monoculture of dependence and risk, and in many cases, serve as the breach originator. Even worse, multi-platform hardware vendors evangelize their stitched together patchwork of point products masquerading as thinly veiled piecemeal platforms. And what organizations inevitably realize is that vendor lock-in leads to deployment difficulties, skyrocketing costs, and subpar cybersecurity. The outcome is shelfware and sunk costs. ELA and bundling addiction become the only way to coast customers into purchasing non-integrated point products. It's the organization trapped in these fragmented pseudo-platforms riddled with bolt-on point products that are the ones suffering from fatigue. In stark juxtaposition, what CrowdStrike customers tell us is that when you build the right single data-centric AI platform, deliver the right frictionless native solution, and architect the right go-to-market organization's purchase, because they need more, receive more, and understand how cybersecurity transformation saves them time and money. Our deal metrics validate this. First, record deal volumes. In Q4, we closed more than 250 deals greater than $1 million in deal value, more than 490 deals greater than $500,000 in deal value, and more than 1,900 deals greater than $100,000 in deal value. Deal counts grew by more than 30 percent year-over-year across all deal segments. Second, record platform adoption deals with eight or more modules more than doubled year-over-year. And lastly, continued rising win rates. In Q4, we saw steadily rising win rates across the board, validating our technological leadership over the competition. These results are driven by the following, the winning AI platform, the right solution, and our frictionless go-to-market motion. Let me begin with our winning AI platform. The secret to cybersecurity's leading platform is our single platform has one console and one agent. It solves an ever-expanding set of cybersecurity and IT use cases. Our single platform is open. Our single platform is data-centric, AI-native, and scalable, delivering immediate times of value. Key wins prove the value of the Falcon platform, which makes point product consolidation and vendor replacement a reality. A recent seven-figure win in a Fortune 1000 company highlights how our platform consolidates at scale. Falcon replaced an OS security vendor, a legacy AV vendor, and a next-gen vendor. We eliminated multiple Microsoft consoles and multiple agents to a single console, single agent, and single platform of Falcon. Our platform approach organically inspires customers to deploy Falcon Cloud Security as their first CSPM, CIEM, and ASPM solution. An eight-figure multi-year win in a Fortune 100 business where the Falcon platform displays five different products. With recent breaches costing them hundreds of millions, it costs too much to keep using ineffective cybersecurity tools. They purchased EDR, Next Gen AV, identity, file integrity monitoring, and vulnerability management, reducing the number of agents on their devices by approximately 50%. What used to require five installs is now done with one. There are countless similar stories. Our platform approach makes landing with multiple solutions at once easy and adopting increasing capabilities over time and organic experience. We collect data once and reuse it many times for today's and tomorrow's use cases. Our application of GenAI makes cybersecurity predictive and accessible for all skill levels. It's all on one platform, one agent, and one integrated workflow. Next, delivering the right solutions. Our market-leading cloud security, identity protection, and next-gen SIM solutions are in demand because they solve painful customer problems. These businesses collectively are more than doubling year over year. Each are IPO-able businesses and each play lead roles in Falcon platform consolidation. I'd like to start with our breakout cloud security solution where we are setting new records and winning at scale. Our cloud security momentum accelerated in the quarter with net new ARR growing nearly 200% year over year and more than $400 million in ending ARR CrowdStrike is one of the largest cloud security businesses in the market and was recently positioned as a market leader in Forrester's cloud security wave. Here are a few recent cloud security wins. An eight-figure multi-year win in a hyper-growth AI company. This company's endpoint footprint is in the low thousands. However, with its rapidly expanding cloud estate, This transaction marks our largest inside sales deal of all time. Falcon Cloud Security protects their LLM development and cloud environment. This customer uses CrowdStrike for CSPN, CIEM, DWP, and ASPN. From the SMB to large enterprises, our sellers and partners win with Falcon Cloud Security. A leading hyperscaler grew its use of Falcon Cloud security, praising our Linux capabilities. This large eight-figure transaction takes us deeper into the account where we're not only on every device, but now across large parts of their cloud. The win extends CrowdStrike leadership in securing the world's largest clouds. A global financial services giant replaced their Palo Alto Prisma Cloud products in a large seven-figure deal. The Palo Alto Cloud security products required separate management consoles and separate agents because cloud security is on a separate Palo Alto platform altogether. CrowdStrike was able to deliver an expected 70% time reduction in management, as well as more than $5 million in annual staffing cost savings. The patchwork of multi-product, multi-agent, multi-console, separate platform technologies resulted in visibility gaps, asynchronous alerts, and overall fatigue managing cloud security. Falcon's single platform with its integrated cloud security component was a win for the customer. Customers are starting to realize that CSPM doesn't stop the breach. It is a compliance and reporting tool. Cloud security has moved beyond CSPM. Customers are increasingly realizing that a holistic suite encompassing runtime protection is the only way to protect from active real-time threats. CrowdStrike built the first native single agent and agentless cloud security solution. We've taken cloud security beyond CSPM to include CIEM for securing cloud identity. ASPM for locating, controlling, and securing cloud applications, TWP to stop malicious behavior and breaches, and now we turn to securing the cloud data itself that flows in and out of the cloud. Turning our cloud security focus to data, we're incredibly excited to announce our intended acquisition of Flow Security. Flow stood out as the most unique technology amongst a sea of early startups by delivering the industry's first and only cloud data runtime security solution. Let me explain. The majority of companies in cloud data security focus on two things, discovery and classification. Here's where Flow stands apart. Runtime data discovery and classification. Data is analyzed, pre and post decryption, enabling precise, and instant results, real-time and continuous data visibility, a live view into data risk, not just at rest, but also in motion, with LLM-powered adaptive policies, data leakage prevention, the ability to block data exfiltration, including the data exposed through Gen AI services. Simply put, Flow is the industry's first and only cloud data runtime security solution. But we'll also enhance our native data protection module, which is off to a great start, already replacing legacy DLP products in Fortune 500 accounts. Customer frustration with legacy DLP is at a fever pitch, similar to the days of legacy AV where outdated products overstayed their welcome. We will now be able to offer a cloud-centric next-gen alternative, addressing a market currently shackled by ineffective legacy vendors, estimated to be an $8 billion TAM in CY28. With Flow, we will have the most comprehensive data protection from code to application to device to cloud focused on stopping breaches. Next, let's look at identity protection, which surpassed $300 million in ARR, more than doubling year over year. Q4 was also a record quarter of net new identity customer ads. With 80% of attacks involving identity vectors, we've made identity protection standard fair for modern cybersecurity because it is already integrated into our single agent. Other vendors attempt to offer identity protection through non-integrated afterthought features or simply lack identity protection altogether. Our identity threat detection and response module remains the market's only single agent solution that stops lateral movement, protects credentials, and secures where identities are actually born active directory. Wins from the quarter include a seven-figure deal with a mega cruise line using a next-gen product that can never be fully deployed. Upgrades and operations were a disaster. When I personally met with them, they were beyond frustrated with being the quality control testbed and tired of too many incidents that slip past their current vendor. Our identity solution delivered in one, not two agents, sets the Falcon platform apart. An eight-figure transaction with a major chip manufacturer added identity to their Falcon deployment. Trapped in a large Microsoft ELA, this organization realized Microsoft needed to bring in a startup to augment its current offering. This piecemeal approach to identity protection created a massive burden of deploying another unproven agent. The customer saw the immediate value of Falcon Identity. Our single agent and single platform approach reduced their Microsoft dependency. Lastly, let's discuss LogScale Next Gen SIM, an inflecting Falcon platform solution. We added record net new next-gen SIM ARR in Q4, growing over 170% year-over-year. As of the end of Q4, our next-gen SIM ending ARR is now greater than $150 million, selected by well over 1,000 customers. Our next-gen SIM is quickly emerging as the go-to Splunk alternative for all businesses looking to leave legacy SIMs. Following M&A consolidation in the legacy SIM market and mounting dissatisfaction with a slew of withering SIMs, the market is hungry for better technology, lower TCO, and instant time to value. In large-scale next-gen SIM, all CrowdStrike data is already resident, saving the expense and time of data transfer. Customers are looking to standardize on the right cloud-native data-centric platform for actioning their data. whether manually searching, using automated AI-powered queries, or trusting partners to manage their next-gen SIM Falcon experience. With pipeline already in the hundreds of millions, there's overwhelming interest in lock-scale next-gen SIMs. One of many noteworthy wins from the quarter was in partnership with Deloitte, which has a hyper-growth lock-scale next-gen SIM practice. Together, we closed a seven-figure multi-year next-gen SIM deal with a large European manufacturer displacing Splunk and Elastic and beating out Azure Sentinel. This customer now has 16 Falcon platform modules deployed. A major mobile computing company standardized a lock-scale next-gen SIM in a seven-figure multi-year deal, replacing a legacy SIM. We competed against Palo Alto's XIM, The customer was looking for an open architecture versus a closed vendor locked in approach to cybersecurity. The complexity of having to deploy many different Palo Alto products and multiple agents made CrowdStrike an even easier choice. Lastly, a Fortune 500 hospitality brand grew its relationship with us, again, displacing Splunk and Azure Sentinel in a seven-figure deal. In partnership with E&Y and their global LogScale NextGen SIEM practice, this customer grew their SIEM use cases by bringing in security and IT data more than before, retaining that data for years and benefiting from faster searches. LogScale NextGen SIEM was significantly faster than Azure Sentinel with a substantially lower total cost of operation, which helped drive this win. Our lock-scale next-gen SIM wins illustrate our sticky and growing data gravity within businesses of all sizes. I can confidently say lock-scale next-gen SIM is one of the fastest growing SIM solutions on the market today. Our pace of innovation has never been faster. We're incredibly excited to announce that Falcon for IT and Charlotte AI are generally available. As our customers look to solve increasingly complex IT challenges across their heterogeneous environments, Falcon for IT excitement is palpable. Our customers are also excited about the Gen-I productivity gains from Charlotte AI, where over 80% of our beta users believe they will save hours to days of work each week using Charlotte AI. The third and final driver of CrowdStrike's growth at scale is our frictionless go-to-market. I'm a big believer that customers don't buy what they don't need and should never be forced to do so. At Falcon, we announced Falcon Flex, a flexible licensing model where we enable customers to use the products they want when they want over the course of a multi-year subscription term. Falcon Flex drives customer stickiness, enabling larger lands and helping us expand with customers adopting more Falcon platform solutions faster. A recent noteworthy Falcon Flex deal was a multimillion-dollar transaction with a Fortune 500 technology company that leveraged Falcon Flex to go all-in with Falcon, consolidating and displacing legacy IT hygiene products, point cloud products, and legacy DLP products. The right platform, solutions, and go-to-market make us the partner ecosystem's leading choice. Some partnership highlights include Accelerating momentum with Dell. Since announcing our Dell partnership last year, we've transacted more than $50 million of total deal value together with customers in every segment and geography. We're in the early innings of where this partnership is going, and I'm thrilled with the momentum that we have with Dell as they standardize new offerings, such as their own MDR service on Falcons. Our MSSP business is growing by triple digits year over year, fueled by the right technology, strategy, and partners. MSSPs increasingly want the platform, not part of the platform, to power cybersecurity transformation. MSSPs are bringing Falcon to tens of thousands of SMBs who lack the staff and time but still need the outcome of the industry's best cybersecurity. Our AWS Marketplace business continues to accelerate at scale, surpassing $1 billion in sales. The AWS Marketplace continues to be one of the fastest growing routes to market. A vast majority of our Marketplace business also transacts through resellers and SIs, where we've unified partners and cloud marketplaces for ease, speed, and end customer value. The Falcon platform is validated, tested, and certified. Industry analysts regularly recognize Falcon and our leadership. Here are two recent examples. First, the Gartner's EPP Magic Quadrant. Our placement speaks for itself. CrowdStrike's positioning as highest in ability to execute and furthest to the right in completeness of vision in this year's Magic Quadrant solidifies our unequivocal market leadership, ahead of Microsoft and every other vendor profile. Second, the Forrester way for cloud security placed CrowdStrike as one of only two leaders in the entire cloud security market, ranking highest for vision and innovation. In conclusion, CrowdStrike's single agent, single unified data-centric platform, and our mission to stop breaches sets us apart. Since starting the company, we brought cybersecurity to the cloud. We pioneered AI for cybersecurity, and we've quickly become the de facto security platform that disrupts, displaces, and consolidates other vendors. I couldn't be more excited about the year we completed as well as our bright future. CrowdStrike's contribution to cybersecurity goes beyond technology. It's the power of the crowd. We are cybersecurity's community. When cybersecurity professionals apply for jobs, CrowdStrike certification is the required skill set. In the reseller and ISV ecosystem, CrowdStrike is at the top of the line card. In SOX across every vertical and geography, CrowdStrike is the security operating system. It's CrowdStrike that's on the screen. When talking about the threat landscape, CrowdStrike pioneered commercial threat intelligence that governments and companies of all sizes depend on. It's CrowdStrike that delivers billions of new threat detections every month to stop the breach. It's CrowdStrike that is the search bar of security where analysts complete millions of XDR queries daily. It's CrowdStrike that created cybersecurity's first dedicated GenAI stock assistant to make every user a power user. It's CrowdStrike where more than half a million cybersecurity defenders log in every day to protect society by stopping breaches. The technology, the crowd, the mission, this is what makes CrowdStrike cybersecurity's definitive platform. With that, I'll turn the call over to Bert.
You're reading a preview of the CRWD Q4 2024 earnings call.
Free account.
