In short
The Logan Bartlett Show - Episode 91: How George Kurtz (CEO, CrowdStrike) Built A $65B+ Company
Episode Summary In this episode of The Logan Bartlett Show, George Kurtz, co-founder and CEO of CrowdStrike, shares insights into building a leading cybersecurity firm valued at over $65 billion. He discusses the challenges and strategies involved in addressing cybercrime's evolution, especially in the age of AI, and reflects on the early days of CrowdStrike, including its approach to achieving product-market fit and operational frameworks.
Key Topics Covered
Introduction
- Overview of CrowdStrike and its prominence in the cybersecurity landscape.
The Journey to Founding CrowdStrike
- Early Career: Kurtz’s time at McAfee and his decision to leave to start CrowdStrike.
- Market Opportunity: Noticing that companies were focused on stopping malware rather than preventing breaches.
Product Development and Market Fit
- Unique Approach: Transitioning from a service-oriented business model to a cloud software platform.
- Building Trust: Importance of incident response in cybersecurity to gain customer trust and credibility.
Challenges in Cybersecurity
- Nation-State Threats: Discussion on cybercrime and the role of nation-states in increasing cybersecurity threats.
- High-Profile Incidents: Kurtz shares experiences managing significant cybersecurity incidents.
Growth Strategies
- Competitive Landscape: Strategies for competing against major players like Microsoft.
- Team and Leadership: Importance of recruiting and retaining the right talent for scaling the business.
The Role of AI
- Impact of AI in Cybersecurity: Discussion on how AI is changing both the offensive and defensive aspects of cybersecurity.
Personal Journey and Leadership Lessons
- Entrepreneurial Insights: Kurtz discusses the importance of timing and market readiness in entrepreneurship.
- Team Dynamics: Importance of teamwork, hiring for potential, and maintaining a strong company culture.
Conclusion and Future Outlook
- The Future of Cybersecurity: Predictions on the ongoing evolution of the cybersecurity landscape and the need for innovation.
Key Takeaways
- Attention to Detail: The importance of meticulousness in both product development and team management.
- Customer-Centric Approach: Focusing on customer needs leads to better outcomes and long-term success.
- Adaptation to Change: The cybersecurity industry is rapidly evolving, necessitating ongoing adaptation and innovation.
- Team Collaboration: Success is driven by a team-oriented culture where individuals work for the collective success rather than personal gain.
Notable Quotes
- "It’s really hard to get people to part with their money." — On the difficulty of sales in enterprise markets.
- "I think the people who have succeeded in CrowdStrike play for the name on the front of the jersey, not the back." — On team dynamics and company culture.
- "If you don't have the right people, you can have the best strategy, but it’ll go nowhere." — On the significance of personnel in executing business plans.
Podcast Links
- [Listen on Apple Podcasts](https://podcasts.apple.com/us/podcast/the-logan-bartlett-show/id1606770839)
- [Listen on Spotify](https://open.spotify.com/show/5WqBqDb4br3LlyVrdqOYYb?si=3076e6c1b5c94d63&nd=1)
- [Listen on Google Podcasts](https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5zaW1wbGVjYXN0LmNvbS9zb0hJZkhWbg)
---
This structured summary provides an overview of the episode, highlighting critical discussions and insights shared by George Kurtz, which can benefit entrepreneurs, investors, and anyone interested in the cybersecurity domain.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:05Welcome to the Logan Bartlett Show. On this episode, what you're going to hear is a conversation I have with George Kurtz. George is the co-founder and CEO of CrowdStrike, a company worth tens of billions of dollars in the public markets. George and I have a fun conversation talking about a number of different things, including finding product market fit in the early days of CrowdStrike, his vision of turning the company from a service-oriented business into a cloud software platform, as well as his strategy for managing and hiring people at scale. We also touch on a number of different things related to the cybersecurity industry, including the impact of artificial intelligence and the democratizing of cybersecurity attacks that are going to occur because of it, as well as the decision process that companies need to go through in deciding whether or not to pay ransomware or to risk customer or employee information being leaked on the public internet and how George advises companies in that process.
1:07A really fun conversation with George that you'll hear now. George, thanks for doing this. Great to be here. Nice weather and Scott's too. It should be a little bit nicer, but yeah, I get a little rain this morning. Yeah. So I want to talk about timing a market and determining when there's an opportunity for product market fit. So before starting CrowdStrike, you were the global CTO of McAfee. Yeah. What were the set of circumstances that led you to wanting to start CrowdStrike? Well, I got to McAfee in 2004 at a company called FoundSone. I sold to McAfee, spent seven years at McAfee and then was general manager.
1:45So was running things and then was asked to be the CTO and turned it down twice because I didn't want to be just a tech guy. Ultimately took getting was the best job that I had originally turned down, which gave me a much better appreciation for how challenged the security market was at that time. And really, when you look at what people were spending money on, they should have been getting the outcome of not being breached, but they were basically spending money with players, Mac, DeSmanning, others that were focused on stopping malware, not stopping breaches. And what's that distinction for people that aren't in the security industry?
2:20It sounds simple and it sounds similar, but it's vastly different. Malware is, there's a file that runs and I want to make sure it's good or bad. It's kind of a binary decision. And the problem is if you don't make the correct decision, you have what's known as silent failure. So the program runs, you get infected, you get compromised, ultimately you get breached. So what I looked at is said like industry is focused on the wrong problem. They're trying to stop malware as opposed to stopping breaches. And it was just a different way to look at it. And people really weren't looking at it that way.
2:51And the way we built the system is designed that there's no silent failure. You're going to have a failure and missing a file or something, but ultimately down the entire attack chain, you're going to see something that happens and you're going to be able to stop a breach. You might have an incident, but you stop a breach. So you saw that happening as well. And then there was a story about sitting on an airplane and seeing you were the CTO watching someone else download to try to install an update for McAfee. Is that right? Yeah. So I, so I took over begrudgingly as a CTO job and I said, it was a great job.
3:24Now I wasn't running engineering, but I'm kind of sitting over the whole product portfolio and I'm on a plane. I literally had circumnavigated the entire globe. I think I started in California and went all the way around through Australia and came back. And I was sitting, there was a guy that was catty corner to me, one row up and he booted his computer and I could tell that it was Mac because it had the logos on it, the encryption logos as it started. And it literally took 15 minutes for the thing to start. And he was talking to the flight attendant and he was reading his newspaper and he was getting his coffee and the thing is still grinding away.
3:59And I'm looking at that going, okay, that's just a terrible user experience. And I'm the, you know, I've now inherited this as a CTO of Mac. What what could we do differently? And that really led me to think about using the cloud and coming up with a different architecture and different focus, which ultimately I did go back to Mac and say, hey, we need to do these things if we want to be competitive. Nobody was really interested in, I worked for the CEO, nobody was so much interested in listening because they wanted to sell the company. I mean, similar story. I think Eric, you wanted Zoom, did the same thing, wanted to start in-house and then ultimately spun out to start the company.
4:36So the product architecture was older and cloud presented a new way of a new delivery mechanism. And then they were focused on the wrong problems, I guess, for malware versus breaches. So that happens and you say, okay, I'm going to go out and do this. Now you did a short stand at Warburg, right? As an EIR, are kind of incubating this idea? Is that right? Yeah. So essentially, I went to Mac and said, hey, we need to do this. Nobody wanted to do it. It was going to take a number of years. It's not easy. This is part of the problem is you can't take CBO and make it Salesforce. You can try, but you pretty much got to start over with a lot of this stuff.
5:17Is that a technical thing, or is that just like a change management? Hey, people are getting paid to do this, and it's too big of a bet. It literally is everything, but if you look at how the Salesforce sells, how they get compensated, how the whole go-to-market motion, it was just AV product. And there was a much different mindset and DNA than you needed to, A, go cloud. So two biggest things for me was the architecture was wrong on-prem. It was just old, right? I mean, it was what it was. It was right at one point. It was right at one point. So that point in time, and to stop breaches, you needed a different architecture.
5:51So if you start with the premise of you're building something to stop breaches, you need to look at the architecture and it was wrong for that it was fine for at the time you know when it was built many years ago for signature based av detection but not for stopping breaches uh so you know again i went and said hey we need to do this nobody wanted to do it i was very up front with everybody because they knew i was you know sort of every couple years i'd be um kind of re-upped if you will because i'm like hey i'm you know getting recruited all these venture guys want me to do another thing like what are you thinking you're an entrepreneur and you did eight years at, you know, a big company, right?
6:27Yeah. Yeah. A nice run. Exactly. It was, it was a great run. Learned a lot. You know, I really enjoyed the people I worked with. So from that perspective, I was just upfront and saying, Hey, I'm, you know, if we're in the middle of selling the company, which we were, um, then I'm, you know, when we're done, I'm going to go do something else. And, you know, the Warburg guys actually wanted to buy foundstone while we were selling it to McAfee and it didn't work out because they were kind of late and just was in the process. we sold to McAfee. It worked out better, you know, for me just going through the experience at McAfee.
6:56So they kept in contact with me every year and they, they basically would call once a year, Hey, you know, what are you thinking? And, uh, you know, normally it's like, Hey, I'm busy having fun doing this and, you know, but always thinking. And then finally we had a conversation and, you know, I said, Hey, we're selling this thing and I'm going to go do something else. So that's how the whole EIR piece came together. Interesting. So, so now you're there and the The initial product, as I understand it, and I think Excel had some memo from the early days that I think 20 BC posted online a version of it.
7:29But the initial product that you had was services that you guys, you offered in addition to a software solution that you were going to go after what became this EDR space. But can you talk about like what, once you get there, Warburg, and you go give them a pitch and say, this is what I think it's going to be. What were the products you went to market with? Well, I mean, the whole idea was to build a cloud-based, there was no, EDR wasn't a term. It is all, I just looked at the slides before it came, and it was literally what we built. Did you make up the term EDR at that point? No, Gardner came up with the term.
8:08Oh, interesting. We were calling it Endpoint Activity Monitoring, EAM. Then Gardner came up with something else. So, you know, we went with that. But there was no term. There was no MDR. There was no EDR. There was none of this stuff. And the original concept, we never would have been funded on a service company, but the original concept was, okay, we are going to create this technology. And we're going to integrate intelligence because we think you have to have an intelligence first approach given you're trying to beat adversaries, right? Not defeat malware, defeat adversaries. So we were building a whole intelligence team, which is now several hundred people.
8:47and we first it's kind of an interesting story the guy works and still works for me today um who runs intelligence he wrote a blog on these threat actor groups and it's much more common now to understand what's happening back then it was all about advanced persistent threats and people didn't really have a good view of how it all worked so he writes a blog and he basically puts it out and people liked it and he writes another blog and um he sends me the draft because I'm doing everything. So I read the draft and I go, okay, it looks good. I said, why don't you at the bottom put, if you're interested in buying CrowdStrike Intelligence, email intel at CrowdStrike.com.
9:26And he said, well, we have a problem. I said, well, what's that? He goes, we don't have an email address called intel at CrowdStrike.com. So I said, we can fix that. We'll add an email address. Just put it out there. He goes, well, we don't have an Intel product. I go, we can fix that too. Don't worry about it. So he ships it out. We got all kinds of inbounds going, oh, we want to buy security intelligence. And that's how we got the first incarnation. But we were always building the product. Obviously, it takes a while. And then we had services doing incident response. So a lot of the incident response markets started at Foundstone.
10:01And Kevin Mandy worked at Foundstone. Then Kevin went out when we sold the company to McAfee. He went and did his own company, which was originally called Redcliffe Consulting, renamed to Mandy. And that was really the beginnings of the instant response, Mark. And for people that maybe don't appreciate what incident response is or intelligence and all of this, I mean, this is if a hack occurs or a breach occurs, this is helping people go in and figure out a postmortem. Like people are showing up on site and looking in log files and trying to figure out, hey, this was connected to this and they got this information and then went here.
10:38It's Ghostbusters when you have a breach. That's basically what it is. Post-mortem, let's figure out, is it done? What happened? All that stuff. Right, to recreate it. To recreate it. Like CSI. Yeah. Got to recreate it. But long story short, so we started the incident response practice along with the intelligence subscriptions as we were building the endpoint product. But the core focus from the company day one was always to build what we actually built. You were always going to be a software business, but this service could serve as a tip of the spear. it's a tip of the spear because in security, it's a very, um, trust is big, right.
11:12And to have an intimate relationship with a customer where you're helping them, um, is, is very important. And it serves another purpose, which is to actually, um, understand how the breaches are happening. So if you have the latest intelligence and you're doing the biggest responses, you're always going to be front and center of knowing how to defeat the adversary. So you're kind of productizing as you go along incrementally, like, hey, we learned this new thing. Can we build this into the product and make it better? And so is it a flywheel like that or that one goes into the other and then you're able to sell them?
11:45The product was so unique and differentiated in terms of how it worked and its architecture still is today that it was a little less about that. And it was more on how do you this whole concept of an OODA loop? if you don't know what that is you guys can at home can can google that eating itself no ooda loop is um it's basically when you you observe and then you decide and then you you kind of reorient yourself and then you make another decision so in the top gun school years ago we were getting beat very badly and there was a decision loop that came up with a guy named boy and basically it was this ooda loop so it was basically understanding and orienting and then making fast decisions.
12:28That's the way the system was built. So what we were doing with the services team is that we were gathering the intel and the techniques to build into our system. So that's how it all worked. You needed the techniques of how breaches worked and you needed the intel to build into this very fast loop system. It's an interesting thing because you're building trust and credibility both from your blog posts as well as going on site and helping people. And then you're saying, hey, to help you in the future in a more automated way, we also are building this product. We're going to have this product that you can use from there.
13:05Did the customers, were they fully aware that this other thing existed in the early days or were you just trying to get in and build trust and then knowing that was going to come down? Well, we worked with some big companies to give us thoughts, ideas. We had our own idea. and if we if when we told somebody this idea it wasn't they're like huh you know is that really going to work and it was something so new and novel to be able to solve this from the cloud so we couldn't just go to a customer and say how would you do it because we would have gotten like tweak mcafee as opposed to reorient into something totally different but at the end of the day they wanted the problem solved they have apts advanced persistent threats that was the term back then and they had too many of them.
13:51They couldn't find them. Traditional technologies were failing, so they wanted something different. And we worked with many of them to basically get their ideas. And then we first started, we got our release out and it didn't do all that much. And then we just kept working on it, working on it and getting better at these OODA loops and what we call indicators of attack. These are attack patterns and they're all built into the product today. And AI was, you know, Before it's now kind of a buzzword, machine learning was the big thing that we focused on to be able to solve problems without signatures.
14:26So those were the early days. So you raised$25 million from Warburg? Mm-hmm. And you're going about this building services as well as software. Are these teams distinct internally? Like do you have people? Yeah, we actually had a, it was a wholly owned subsidiary that did our services. Oh, interesting. And then we had our Intel team, which was separate. So we had product, intel, and services. And so then you land with software at some point, right? This is the tip of the spear, and you're selling some consulting services. Then you land with software. And at that point, you're sitting alongside the big antivirus vendors.
15:02And you're saying, hey, we'll help you with your breaches and help you figure out all of that stuff. And then at some point along the way, you were able to convince them, you don't even need antivirus software? Right. So what we first did is we basically, because nobody wanted to just throw out what they had. You know, certainly in the early days were, you know, five guys, a dog in a garage, right? So we had to basically come up with something in a particular use case, which was around visibility. And we would run side by side with any number of AV products that were out there. And then ultimately, as we built the prevention capabilities, you know, we basically, customers saw it for themselves.
15:41Like we were catching everything that the others weren't. And they're like, well, why don't we just use you? But the thing that we did different than just about everyone else in the industry, most of the other companies started as, certainly the ones we compete with, you know, they saw what we were doing and then they copied it. But they started as an AV product, first not a data product. And this is why architecturally so many of these companies have challenges because they were kind of on-prem next-gen AV tools, and then they had to bolt on all the other pieces. We started with the hardest part, which was the data collection scale, which allows us to operate much more effectively than our competitors out there in terms of scale, manageability, and ability to add more modules.
16:25Roof timeline, CrowdStrike was founded 2012-13? Late 2011. Oh, 2011. How long was it service-only? How long until you started selling software? How long until you had your first antivirus displacement? Yeah, so it was, again, it was, I mean, the product was always there. It took two years to really get the product out. So in the meantime, we're doing some of the other things, building our name up and gathering up. You know, the revenue was nice, small, but it was more what we needed out of it. So we did that for a couple of years. First release came out like two years later. and uh you know today's market you can you can assemble a lot of the the technologies uh when we did it it was uh you know i feel like the old guy was you know uh walking to school uphill in the snowstorm right like we had to build all this stuff graph technology was so nascent we built our own you just didn't go off the shelf and pick everything right so we built a lot of things ourselves it took two years um to get it all out but when we did then we got a lot of feedback and then we iterated, iterated.
17:31And it was probably 2016 late before we really had kind of our next-gen AV product. And then from there, we started to do displacements. So late 2011 to 2013-ish, you're selling services and building the software product. 2013 to 2016, you're selling EDR or whatever. And then at that point, you're selling antivirus. It's almost like a business school case study of like laddering up and going into starting with something and then going into the next thing. And then that gives you the right to displace the competitors and the other thing. And in talking to some of your investors as well, it actually played out exactly.
18:14You founded it with this vision and it sort of played out exactly as you, is that a fair characterization? It's very serendipitous or you were very prescient? It is. Well, you know, I got plenty of scars from doing other things. So what I knew in security was if you had the relationship, particularly on the services side, trusted relationship, you're going to be able to sell software. That isn't always the case in other industries, but security is. And I knew that from Foundstone because we had, when I started that, I said, okay, we're going to have software and technology. And we really invented vulnerability management because there was vulnerability the assessment and found some days, but there was no management of it.
18:55So we kind of created that category. But when I was building a company, a lot of VCs are like, well, you can't have services and technology. And it's like, well, why can't you? So everybody fought me on that. And then ultimately it turned out to be a pretty good model, you know, as long as you have the right balance, right? You can't be. Why is security unique in that regard? Because it's such a trusted relationship. When someone has a breach, it's like going to your doctor like you have a problem you need it to be solved and when somebody solves it they're grateful um and it isn't when someone's bleeding like you everything goes out the window and it's like stop the bleeding solve the problem and you know you become the hero so if you have that level of trust all the way up through the board then it sets credibility for selling the software products One of the things I think you guys did really well in the early days in building the trust in this was also giving faces to the new attacks that were coming in.
19:57And also there was a set of circumstances going on in 2012, 2013, 14, 15 that we were just seeing an exponential growth and hacks and attacks and all of that. Can you talk a little bit about like the marketing and PR strategy of making this more real and tangible for people? Yeah. Again, I mean, these were all firsts that we came out with. You would hear the term APT. And some of the folks in the industry had APT1, APT2, APT3. Okay. I don't really know what that is. Right. So I couldn't keep track of them either. And I mean, I know who the, I know what they, what they were talking about, but it was just engineering stuff.
20:34Not that it's bad, but, you know, we wanted to take a different approach. So what we said is, you know, there are actually humans behind this. So why don't we sort of give a face to this? Because it isn't a, you know, it's a serious issue, right? It's not, you know, we've got funny characters and stuff, but it's a serious issue. How do we allow people to really understand that there's nation states, there's e-crime, there's hacktivism, and there's people behind it. And it's actually organized. So we came up with a whole adversary kind of universe, and we would name them by pandas and bears and other things, bears for Russia, pandas for China.
21:12There's others, so we can keep track of them. And then by campaign and by specific groups that are in each of these countries, we would have anchor panda for the Chinese Navy and those sort of things. So we kept track of it. But when we would talk to a customer, we would say, hey, this is the group that's doing things. Or more impactfully, when they had an issue and we came in and did the services, we would say, okay, this is the group. Here are actually the pictures of the people. This is who they're working for. They're on vacation here and here are their boats, right? Yeah, like we literally had this stuff.
21:49There was New York Times articles that we literally had. It was all open source stuff. We were finding these people, knowing where they're operating out of, and that really hadn't been done before. But when you're talking to a CEO who just had an incident, like now someone realizes the competitive juices get going. Right. And it's like, oh, those are the people who want to do harm to us. And it put it into a different concept rather than bits and bytes and registry keys to like there are dedicated groups who are organized for profit and for state sponsored activities that want to do harm to you.
22:21And I think that helped kind of revolutionize how people thought about the threats. You mentioned three different types of attacks that are out there. The underlying current within the market, we sort of talked about the architectural reasons and the cloud shift and all that. But what was happening that led to the importance of cybersecurity industry? And it's kind of served as a tailwind at your back over the course of this. Like, why has it gotten so much more prevalent in the last decade than it was prior? Cybersecurity or the attacks? The attacks. The attacks got more prevalent because it really started with nation state.
22:57And then the e-crime, and there's always been kind of fraud in those things out there. But what we saw is that a lot of the nation state techniques were starting to bleed down into the cybercrime groups. So the cybercrime groups weren't always sophisticated enough to come up with the ultimate sort of attacks. But as they became more public, they were able to commercialize it. So it's kind of like, I'll give you the analogy, it's really hard to make plutonium. But if he found it, somebody probably would figure out a way to make a bomb out of it, right? So this nation state, these techniques were starting to leak out.
23:42You had Snowden, you had a lot of other things where very sophisticated attack methods were leaking out. And then you were having people being able to weaponize them. Then you combine that with the prolific, I mean, just almost exponential nature of vulnerabilities that are in the ecosystem, many from some of the large players that are out there, that there's just such a large attack surface. and the complexity of technology continued to increase, that there was more things to basically compromise. And that allowed other players to get into the game. I'm sure along the way there are many points of pinch-yourself moments, like how, I can't believe this is going on, but we talked about nation-states, and you all have supported a number of different groups along the way related to U.S.
24:32defense, and I'm sure other countries as well. One of the, I guess, notable ones that got a bunch of headlines was the DNC attack. Can you tell that story? And what was that like for you at that moment in time, like when this starts to go on and Russian interference since the election and all that? We got called in by a law firm that we worked with, and this was just standard fare. It didn't even raise any flags or anything. We came in, did the investigation. We're like, OK, this is what happened. This is five years post-founding. This is post-election? 2016. Yeah. Post-election at this point or pre?
25:09I think it was pre. Yeah. Yeah. So we got caught like we do. I mean, this professional outfit, you get called in, you dispatch your guys and gals and investigate. Here's the report. Didn't think much of it. And then obviously, you know, there was a whole, you know, interesting series of events after that. And, you know, I knew we've arrived when two heads of states mentioned our name. So Zelensky and Trump are talking about CrowdStrike. And yeah, yeah, yeah. That's that's an interesting I'm sure that was a pretty surreal moment. It was. And, you know, again, we just we just did our job, wrote the report.
25:47And whatever happens after that, that's we can't control. We don't get involved. And we're not politicians or policymakers. We're we're security folks. Yeah, makes sense. So the founding of the company, so you're at Warburg there, and I think I had heard you mention some of your VCs in the early days at Foundstone. There was an interesting comment about you never wanted to make someone's fund or have their ability to continue to exist to be predicated on your success. At Foundstone, it sounds like maybe there was some pressure to sell among the VCs or some people that were more short-sighted. Is that a fair characterization?
Read the full transcript
26:22That is a fair characterization. How did that impact you the next go around and thinking about your investors and picking Warburg and ultimately Excel? Well, it impacted me a lot because my first go around when I started the company, I was 29. First time doing it, it was like, you know, you don't have a track record. So, you know, you kind of work with what you have. And, you know, we had some decent backers and those sort of things, and they were good folks. But they did a lot of investing in 99. So their funds pretty much blew up. 2001, I remember raising money in 2001. not so easy. And then 2004 came, didn't really want to sell the company.
26:57McAfee reached out and, you know, I was really on the fence of whether we should sell it or not, but there was a lot of pressure because we were literally the only thing in their fund that would have returned any, yeah, any capital. So. And a lot of the names, by the way, I went back and looked up those names don't really exist or a lot of your original investors, I'm sure on doing other stuff as 99 vintage, a lot of people did. So I assume they were just looking for a win or they're looking for a win, move on in some way. Yeah. They were looking for a win like, like anything else. I mean, you know, your business, you got, you have LPs, you got to return capital and it's a, it's part of the game that you're in.
27:34So anyway again, not bad folks, but that's, that's the way they wanted to go. Incentive structures. Incentive structures. And you know, we were kind of split whether we sell or not, we sold and really it all worked out. I mean, I can't, I wouldn't necessarily change anything. But from my perspective, when I started FoundSnow, like, I wanted to be well, I mean, CrowdStrike, I wanted to be well capitalized. Warburg, not your traditional Series A, by the way. They did only one other Series A like this, which was BEA. Pretty good trucker. Yeah. They were once upon a time a very prominent venture firm back in the 1970s, 80s, but they've moved more into the private equity direction.
28:11Right, right. Right. So to do a, like, basically, I mean, you'd call it a C today, but an A round on 25 slides is not a traditional thing for them. So they had plenty of money. And then, you know, Excel, Samir kept pinging me and wanted to meet Samir Gandhi. He's a great board member. And I kind of put him off for a little bit and finally met him. And, you know, we hit it off really well and got Excel in and then Google and others came in. But the whole idea was like, I was not going to let anybody in that wasn't necessarily name brand. And if I was going to, if we were going to be the company that made their fund, I didn't want any part of it.
28:50Like we're not going to make a fund for Excel or for Warburg or others. We're going to make it really good, but we, they don't need us to make the fund. So that's really what I was focused on. I think now, in particular, people are being a little bit more discerning entrepreneurs in terms of some of these consideration sets. I think in the 2021 vintage, we were in the world of just highest price and whoever versus now there's a little bit more inputs into longevity and partner and all of that stuff, which, from my perspective, is great. But how did you go about thinking about what firms had longevity and lasting brands and all of that?
29:37Was there any tangible metrics around it? Or was it just, hey, Excel is a venerable name and Warburg's been around for a long time? Well, I knew Warburg, so I knew the people. I think for me it was like I needed to get to know the people first. I knew the Warburg folks. That's why I did the deal with them. And then I got to know the Excel team really well and really liked them. And, you know, for me, it was always what I wanted to be enough flexibility in my life. I didn't really want to be working with people I didn't like. So, you know, we were able to kind of handpick who we wanted, investors and on the board and those sort of things.
30:12And, you know, it served us well because we if we didn't have good board members, they wouldn't have seen the vision that I had. And the company could have been sold many times over super early. if we wanted to, but we knew we could be a generational company. And the whole idea when I started it, which we didn't cover was, there was Salesforce, there was Workday, there was ServiceNow, there was no platform company in security. There was no Salesforce of security. And it was just a missing element. And that's really what we wanted to be. And we wanted investors and board members who had that vision.
30:51We talked about the data ingest versus the antivirus considerations from the early days. There were a handful of companies. We were fortunate enough to be investors in Sentinel-1. Silance was another name. There's a few others that were founded, similar-ish, vintage. When you look back, the data ingest and antivirus is one component of it. Are there other things just from a pure execution standpoint that you feel like you all did really well that might be transferable to an entrepreneur listening? Well, certainly the approach that we took was different. I mean, the reason why CyanLess is now BlackBerry is because they just took one approach, which was antivirus, right?
31:28Versus you did the hard thing first and built it for longevity. It's still hard for people to replicate. Even when I look at a lot of these new companies that come out that just plug into an Amazon or Azure API and suck data in, and they've got, you know, pull a graph database off the shelf, pull, you know, your UI of choice, a React off the shelf, make something in, you know, a year or nine months and go out to market. Like, it's not hard to do that. So we did all the hard stuff first, and that really set us up. So I think what we did, and to the heart of your question, like, we didn't take shortcuts.
32:09And I had plenty of conversations with guys internal. I said, why do we have to do that? That's gold-plated plumbing. They're like, George, you're going to need it. And it was fantastic advice. But here's the thing that we never compromised that. And both SentinelOne and Silence did. They started with on-prem technology, or they had on-prem pieces. We never had that. No matter how we got pressured, we never had on-prem. The agents run wherever. But we never had an on-prem anything because it compromises the entire system. And that's where you run into scalability challenges and all kinds of other things.
32:41So my point in that is many young entrepreneurs who want that big deal from that bank who says we need on-prem will say, okay, we'll just make it work for you. And then it's a noose around their neck going forward. I know competitors is probably something that you don't spend a ton of time thinking about, at least that original cohort. But there was a racing analogy that you talked about, about mirrors and crashing when talking about competitors. Can you speak to that? And my general thoughts on that is the windshield is 20 times bigger than the rearview mirror. So you should spend more time looking out the windshield and going forward than looking out behind you or sideways.
33:22And I think the racing and alley holds true. If you're just driving in your mirrors, you're going to go off the track and crash. So you have to be aware of your competitors. You have to respect your competitors. The competitor is going to push you and make you better. But if you're focused out front, you're focused on the right thing going forward. One of your competitors today, I guess, is Microsoft, which is a company that I don't think a lot of people aspire to compete with, at least in broad-based software today. I think they're a highly functioning org underneath Satya. But you guys have done a great job executing against them and competing or out-competing them.
33:56How have you been able to do that within security? Not easily, but a lot of hard work and a lot of focus. and I'll come back to your question in a minute, but a lot of people don't realize that many years ago I found some, Microsoft is one of our biggest customers. And many years ago I did the first ever pen test, external pen test for Microsoft. So it's kind of a funny, you know, where life brings you. Now they're a big competitor of ours. But, you know, at the end of the day, what we're focused on, every day we get up, we think about how do we stop breaches, right? We're not thinking about building clouds.
34:32We're not thinking about building productivity apps. or operating systems. We're thinking about how do we stop these breaches? And our architecture is fundamentally different. Microsoft architecture, A, number one, it's legacy AV. 2004, they bought an AV product. Guess what? Every day, there's six updates that come with signature updates. You know, same thing McAvee and Symantec did. If McAvee and Symantec worked so well, there'd be no crowd strike. So when we look at someone like Microsoft, are they really solving the problem of stopping the breach? Most times they're causing it because of their architecture, their vulnerabilities, their hygiene and those sort of things.
35:10So, you know, from our standpoint, trust is a big thing in security. Focus is a big item. And having something that actually gives you the outcome is what people are paying for. So that's the way we've been able to execute. It's taking care of the customer and delivering what they want. A system that works at scale, single agent, it works. Overall, it's actually cheaper to run and manage and gives them the outcome. So that's how we compete it. They're a big competitor, of course. You know, you have to have a lot of respect. Sachin team have done a great job. But, you know, there's always room for multiple companies out there.
35:49And, you know, we've got our niche. I've heard you talk about the two different stages of company execution. There's the evangelical leadership stage and the scaling and delegating stage. Can you speak a little bit to that and what the distinctions between the two are? Yeah, and it really, a lot of that comes around the selling piece of it, right? So you have evangelical scaling and coin operate it a lot of times when you're looking for sales organizations. So I think, you know, from my perspective, when you first get out there and you're pitching something that doesn't have, it's a different approach, right?
36:23You're in a category of endpoint. You're in a category of like security is important, stop a breach. people, you know, started to get that. Nobody was doing cloud. So you have to be an evangelist. Starting with me, I had to go out, explain what it was, what I wanted to do. I had plenty of people laugh, you know, banks go, we've never used that. I mean, I go through the story of that's never going to work, you know, et cetera, et cetera. But we got through all that. And once you can, once you get past the evangelical phase, which I don't know if you ever passed, but once you kind of get past that, you have some scale, then you you're hiring in a different set of people, particularly on the sales side, you're scaling it up.
37:00And then, you know, at some point, and we're not in that phase at all, nor do I necessarily want to be in that phase, but you got the coin operated, you know, folks who just want to come in and take orders. So from my perspective, it's making sure that we got the right people for the right phase of the company. And when you move from evangelical to scaling, like you can't do everything and you really do have to delegate that makes you got the right people on the bus. You hired a number of roles, I think earlier than conventional wisdom would, would recommend. Uh, were there any of those that you feel like particularly benefited the company that maybe came in a stage earlier than a VC would recommend or something?
37:36Yeah. So one of my co-founders was actually our CFO early days. He was my CFO at found stone. It was a great guy. He literally was retired. I had to get him out of retirement and say, can you help me for a couple of years? Um, and he only wanted to give me a few years and wanted to go be with his grandkids. A odd choice of a CFO is a co-founder, I would say, and B, that was pretty early on. But I knew that you had to have the right foundation in the areas of accounting, in the areas of revenue recognition, in the hygiene of the company. And I see too many younger companies that I invest a lot in startups where it's like, you know, we'll get the CFO four years later.
38:20And it's like, well, if you do that, there's going to be a, you're going to have a huge mess on your hands. So when you look at what we did, ultimately, when we went public, everything had to be audited. Everything was audited, by the way. So we, there wasn't a lot of hygiene that we had to go fix to be ready to be public. Whether you're going to be public or if you're going to sell the company, and most venture-backed companies, there has to be some exit, right? So pick one. You want to have the right finance team in place. And then you want to combine that with the right legal team. We knew the cloud was going to be difficult.
38:55We knew privacy was going to be an issue. We saw what was happening with others, right? I mean, you had Salesforce, you had Amazon, you had others. It's an issue to put your data somewhere else. So we want to have the right legal people in place. So we really went out and tried to get the best folks. Our first GC was like the former GC of the FBI. like super senior people are like, why do you need that guy? Well, because we need to put everything in place. Interesting. Delegating as you move from that evangelical leadership to scaling and delegating, uh, I'd heard you mentioned that, um, ultimately you, you ran, you were able to run, run and assess different business units off of KPIs and dashboards.
39:39And that sort of gave you a feel for, um, can you speak to, to that and the willingness to pass and trust some of the responsibilities within an org to the different leadership team members? Yeah, it starts really with the people. So I had to make sure I had the right people in place, which I did, you know, for that stage, for the most part. And I couldn't do everything. So it was more like, what are the critical KPIs we need to look at? How do we manage those? And how do we course correct? For each different functional area? For each different functional area. And really, you only need three or four critical KPIs for each one.
40:17So I sat down with everyone and said, okay, well, what are the key ones? And if you couldn't tell me the key ones, that was problem number one, but we got through that. And to this day, we still, I don't think I'm ever satisfied with all the dashboards and the data, but we have a huge piece internally of dashboarding and KPIs and around everything. And it's a journey, it's never an end state. Like you're never gonna be happy with what you have and you always have to tweak it. And you have to get out of the trap sometimes when you get big enough where people, you know, turn things that are yellow into green and tweak a number here or do something.
40:53And so you look at it, you're like, okay, that looks good. But, you know, what's the sample size? Or did you, you know, did you change how you actually are calibrating your, you know, net promoter scores? Those kind of things. There's a lot of, when you measure something, people are going to manage to it. And so you need to constantly analyze what the unintended consequences to the inputs. Yeah, and the inputs. Yeah. Because you could look at something and go, well, that looks good. But, you know, did you talk to two customers or 2 ,000? Yeah, that makes sense. What are some of the things you learned about managing and leading people that you knew when you were, was it E &Y early days?
41:35Yeah, Pricewaterhouse. Pricewaterhouse. When you were coming out or the original days of starting Foundstone, as you look back on that, if you could tell yourself about leading thousands of people, is there anything that stands out? For me, it's, you know, and I've gained this over the years, but it really always is about starting with the best team that you possibly can. You know, A players will figure it out. You know, if I always say if you have, you know, a C player with an A game plan, you're still screwed. Right. So it's better to have an A player with a B game plan or something else because they're going to figure it out to get to the outcome.
42:12So for me, it was starting with the best folks. And we did that at CrowdStrike. I literally handpicked 20 of the top people. It didn't matter where they were. And that became the founding team. But when I look back in time and I think about kind of what I learned is if you put the right people in place and you don't constrain their creativity, you get great results. And I think that was a key part. Like when you're at Pricewaterhouse or EY, great places, but it was very structured and didn't always have the flexibility to kind of, you know, Bob Ross it, as we say, take the blank canvas. So, you know, for us, it was, here's a blank canvas.
42:51What, what pretty trees are we going to paint today on the Bob Ross canvas? To that point, what are you looking for in a first meeting? And I guess specifically, I've heard you talk about possibility people versus parameter people. What's that distinction? And if you're interviewing someone and trying to figure out if they're an A person? If it's all about the parameters, then you kind of constrain yourself into a box. And you're only thinking about the parameters in your box. If you're thinking about the possibilities, it's like, okay, that hasn't been done before. And it's really hard. and, you know, people haven't thought about it.
43:27And, you know, is there a market or not? Like, you got to figure all that out. But hey, it might be possible, right? As opposed to starting with, I call professor no's. You know, no, no, no. Like, and, you know, if you're very parameter driven and your first answer is no, you're probably not going to be a good fit. And I think it's like, okay, well, get the white canvas out. And what is the art of possible rather than the parameters that would constrain you from developing something new. Because if we weren't possibility people or just parameter people, there'd be no CrowdStrike. You know, you'd still have signature AV somewhere.
44:04Are there questions you ask to try to tease that out in an interview? Yeah, I mean, I'd like to understand somebody's background first and just hear their life story because it tells me how they operate and what they've done and, you know, what really drives them. And we can talk about what makes people take care in a minute if you want. But from my perspective, I'm always just trying to figure out, how do they solve problems? And how do they think about, are they competitive? And what do they do in sports and those sort of things, which gives me an idea on how they operate, what makes them tick.
44:40So I ask a lot of questions about that and ask them what drives them. Do they love to win or do they hate to lose? And then I can tell their personalities from there. What's the distinction there? Love to win versus hate to lose. Which one's better? Well, it's all different, and somebody who listened to this is going to just try to come up with the right answer next time to talk to me. But I think what I would say is it's great to want to win, but if you look at the best athletes in the world, and I've met a lot of them, talked to them, they really hate to lose. And if you think about it, like you played sports, you win.
45:18How long does the win last? A lot shorter than the losses hurt. Okay. So if you played football, which you did, yeah. Yes. So you knew Saturday you lost. You got to wait till the next Saturday or two weeks from now. Yeah. That's kind of the way we, but again, there isn't a right answer. Just trying to understand what makes people tick. I heard you say that you never regretted firing someone too early, but often regretted keeping someone around too long. Yeah. A lot of our companies are going through the point in time, if they're successful, that the person that got you there might not be the person that takes you there.
45:48Right. Right. How do you think about that? Are there things that you should be asking if this person's the right to be on the journey with you? I think every day you have to look at the team and you have to think about, is that the right person for that role at that point in time? And at that point in time is important because when you're 100 people, it might have been fantastic for that role. But at 5 ,000, they may not be. It doesn't make them bad. doesn't mean that they don't either have a home in your organization or maybe they can find a home and leverage experience they got. But I've never, and I really, I've asked the question to many folks, you know, many CEOs, friends, et cetera.
46:27Have you ever regretted firing somebody too early? And the answer is no. I mean, normally it's like, oh, let that person hang around too long. And, you know, we knew that person that was somebody we were friendly with, or we, you know, they work with us in five other places. Yeah. Whatever story you want to come up with. I mean, it's never an easy thing because it's, you know, people's lives. But I think if you have the discipline to, to say, like for me, CrowdStrike is a special place. You should be an A player if you're here. If you're not an A player, then, you know, what are we doing? So not everybody's in, you know, can or will be an A player.
46:59But my point is, if that person isn't right for the job, then it's better for them. And it's better for the company to, you know, give them a hug and, and either find a different role, which is fine, or, you know, part ways. And there are many folks that I'm still friendly with today that we parted ways just because it wasn't the right fit at that time. But you don't want to wait around. Do you encourage managers, like when they have that inkling, just to obviously be thoughtful but act on it because it's not going to – the toothpaste doesn't go back in the tube? Toothpaste doesn't go back in the tube.
47:31We have – I mean, one of our – our chairman, we have a saying, like, in racing that if you have a noise in a gearbox, it doesn't fix itself. Like it will not fix itself. Trust me, that thing is going to blow up. So if you have that inkling or you know, the noise is there, just get it fixed. Cause it is not, you know, you can try to course correct and, and, and do those sorts of things. I got it. But at some point the hair on the back of your neck stands up, the little voice keeps saying like, I don't know if this is going to work out. you can convince yourself to not listen to little boys or you can basically say like, like we tried, feedback was given.
48:11We're not going to get there or they don't have the skills. You know, it's attitude and aptitude. You got to have both. And if it's not the right fit, then you got to move on. And the problem is, and how you get mediocre organizations and the landscape is littered with mediocrity. By definition, right? Yeah. You just let average Which is normal. You just let people hang around. One of the other interesting, I guess, forcing functions or frameworks is if you would hire that person back into that role again today or not. Yeah. So that's the way I look at it. The simple, and this is probably one of the best maybe takeaways from this whole podcast is just one thing just to remember, forget everything else is.
48:55If you ask yourself, would you hire that person for that job today? If it's a yes, great. If it's a no, then you got to take action. Yeah. You know, and you shouldn't wait around. Like there's always considerations of not tomorrow, but, you know, maybe in two weeks or three weeks, but not two years from now. It is an interesting framework of would you take that person or the field? Right. It's like the gambling terms of like everyone else that maybe I can interview or that specific person that I have today. And if your inclination is over there, maybe that's your that's your answer. Yeah. Because people have a hard time coming up with the answer.
49:27Hmm. We touched on this a little bit, but the the different types of salespeople in the evangelical, the scalar and the coin operated. We talked about the leadership different phases of this, but but the coin operated is that that's just a transactional order. Just transactional. Yeah. And scalar is someone that comes in after the evangelical sale has occurred. Yeah, so you basically, you know, evangelical is, hey, we've never heard of this product. We don't know this market. What is it going to do? Why do I even need it? What's my problem you're trying to solve? So you've got to get through all that stuff.
50:03And then people go, well, this works better, solves a problem, and I'm willing to part with my money. And by the way, I'm not sure if everyone appreciates, and I know you do, and your companies, how hard it is to actually get people in an enterprise to part with their money. It is a really difficult thing to do. So you've got to get past the somebody's going to write you a check for it. And then once you have that, then it's like, okay, well, we have something about product market fit. How do we scale this? How do we put all the sales processes in place? How do we put the marketing pieces, the go-to-market, the engineering pieces?
50:38We've got to scale this thing. And on the sales side, it's George making the sale or someone on a senior team making the sale too. we can take all this and package it and put it into a scalable sales organization. And there's a real skill and art to that. At that stage, are you more willing to hire for parameter people when the packaging and the scaling is occurring? Yeah, you have to. And it's really a good point because if you had all possible people, you may not have zero execution, right? They'd all be wandering. They'd all be wandering around. So they'd all be at the whiteboard. Like at some point you have got to get the deal in the cash in the bank.
51:18So there does need to be some structure, right? Which is, yeah, there's a lot of things that we can do, but what's it going to take to get the deals done? What's it going to take by deal, by week, by month, by quarter to make sure that you're going to hit the targets that you have in place? We touched on some of this stuff earlier, but the early days of marketing and PR and just getting your name out there, I think you guys did a great job. of. Was that the founding team and just sort of the DNA there? Did you have a marketer? Was this a purposeful strategy? Pretty much us, yeah. The early folks had strong reputations and it's not our first rodeo and we were known.
51:57So it was relatively easy to be able to go out and take some of the intel that we had and some of the things that we were seeing and being able to explain that to the industry at large and people were interested in that. So it definitely helped build credibility. Um, I had written a book, a couple of books, and that was, that's kind of the best business card you have to, so that, you know, you kind of leverage all that to get your name out there and kind of stand up, uh, above the crowd. Was the original book, by the way, was that with this in mind that it would build your credibility or was it maybe I'm going to be an author for?
52:32No, it wasn't to be an author. It was, um, when I, when I was doing, um, so when I was at Price Waterhouse. I was in accounting, got really bored of that, then moved into management consulting. And they basically, it's 93, they said, hey, can you sort out this internet thing? It might have legs. So I'm like, all right. So I looked into it and like, okay. I mean, I was pretty good on technology and then really developed a lot of these pen testing methodologies that hadn't been developed. Like they just, again, it was the whiteboard. So I wanted to write it down because people were asking me about it.
53:07So that's how the first book really came about with a couple others. And, you know, the whole idea, I kind of laughed because I think it would have made more working at, you know, fast food job at the time than I got paid on the book, like per hour. We put a lot into it, but it was really the best business card. And at Foundstone, we always had a saying is you want the people read the book doing this work? You want the people who wrote the book? I don't know. You know, if I offered that to you, you'd probably want the guy or gal wrote the book. So that was our business card. So we use that to our advantage at Foundstone and certainly at CrowdStream.
53:40Were there any tactics of, I mean, it sounds like there was a lot of white papers or blog posts you guys did in the early days of PR and marketing. Anything that you look back on that was particularly useful or interesting that comes to mind? I think the fact that we were able to humanize these attacks, which no one really had done before, put a name to a face, you know, put how this all works, demystify this, you know, things happen in ether. Well, this is actually how it works. I think that really gave us a leg up and credibility as being experts in this space. CrowdStrike doesn't really have a mission statement beyond stopping breaches, I guess.
54:29How has that simplicity helped you kind of drive the company and set the vision? Well, I would say we don't have a mission statement. We're on a mission. And that's true today. It's true when I started the company. In fact, when people would, we had this very Spartan sort of stealthy website, you know, one page thing before we launched the company. And if you wanted a job at CrowdStrike, when you emailed, it wasn't emailing jobs at CrowdStrike. It was emailing mission at CrowdStrike.com. and that really put it into perspective. We want people to sign up for the mission. I think in security, if you have a mission and purpose, every day we're saving customers.
55:07There's countless stories of saving customers from e-crime groups or nation states or what have you. It really is a noble cause and we wanted like-minded people who, and certainly in the early days, they could have got a job at a big bank. They could have been assisted with a big bank. They could have done all kinds of stuff and made more money. on a cash basis, like beyond CrowdStrike, not the stock, but, you know, so what we want to do is we want to have people focused on that passion for our customers. The state of cybersecurity today, I'm sure whenever you get asked about this, people are, it's bad and it's, there's, there's a lot of different groups out there.
55:48Can we talk about the different, there's nation state e-crime and hacktivism that you referenced earlier. What's the distinction between them? And what's the, I guess, how would you sort of draw the different perspectives of who's the more aggressive actors or anything along those lines? Well, Nation State is, you know, many of the places that you would suspect. It's really, you know, an operational mission of either gathering intelligence or planting technologies for future use and or potentially using it, which we've seen in the past in terms of destruction capabilities. It's the simplified version of it, right?
56:26So people get paid every day. They get up, you know, they're in these organizations either by choice or not by choice, but their job, you know, nine to five is to be able to go out and get into companies. And it's like a, it's a full company that's designed, who can get access, who can get the data, who can understand it, who can operationalize it. That's what they do. So that's their goal, and that's happened for the last 4 ,000 years, and it's going to continue to happen. Now it's just easier to do because you have the Internet. Then you've got the e-crime actors who, well, people have been doing bad things for the last 4 ,000 years too.
57:04So now they can do it. You used to have the pickpocket that would canvas one block radius. Now somebody's sitting in their bedroom in their pajamas. They've got the whole world at their fingertips, right? So it just makes their job a lot more scalable to steal more money and less risk. And hacktivism, you know, people have always been speaking out and having a view on things. And now it's a little bit easier to kind of get your view out there in ways that could be destructive to organizations. So it continues to get worse just because. The way I look at it is security has to parallel the slope of the technology curve.
57:45So if we think about technology, and I would argue that in 1993 when I got in the business, technology is pretty simple, you know, like for the internet. You really didn't even have a firewall. You're like a router. You get a website. You know, you barely had a database. So super simple. Think about the technology. Like the curve is hyperbolic in terms of like all the new innovation. So if security doesn't parallel the slope of that curve, that's really where you have problems. But there's so many more opportunities that it's become big business for security companies, but big business for governments, e-crime and others.
58:20And that's why we're in the state we are in today. When e-crime occurs within a company and there's, I guess, ransomware or they're asking you to pay something to get your information back. How do you help a company think through if that's the right decision for them or government, I guess, as the case may be, versus setting a precedent that, you know, you pay if you get a tax? It's really a risk-based decision. It's a business decision, to be clear. And I'll tell you a story, and I'll get into the details of your question, but a number of years back, we got a call on Friday at 5, because nothing good happens before.
58:58I was going to say, all good calls come in at Friday at 5. Friday at 5, right. Yeah. Your deal that you want to get closed never comes in at that point. It comes in two weeks later. But the IR call comes in. It was CEO of a public company. and they said, hey, we got, you know, like thousands of computers got taken out. They weren't a customer. They called me and said, can you help us? Yeah, we got on a call within an hour, sorted it out, and, you know, looked like ransomware. And, you know, we said, okay, we think this is what it would cost if he wanted to pay it. And as I said that, the words didn't even hit the air.
59:35They were hanging in the air, and he said, we pay it. and to be honest, if he could have paid it, he would have, and it would have been a much better outcome. He couldn't because it was actually destructive malware that was masquerading as ransomware, so there was nobody to pay. What's that to say? I mean, destructive malware that was masking as ransomware, what does that actually mean? Yeah, it was basically a Russian-based attack that was designed to be destructive against Ukraine many years ago. but it was designed to look like ransomware. So it looked like, hey, if you pay this amount of money, we'll go away.
1:00:13And in truth, it's not that. It's actually trying to just attack and destroy. Exactly. Yeah, with that sole purpose. So they couldn't pay it, and then there was a big recovery and those sort of things. But getting back to the point, that was one area where he would have paid, it would have been a lot easier to pay, and it would have been a lot less cost. So customers need to just make that decision. in today in 2023 we deal with a lot of it um a lot of the customers do decide to pay um because of you have this uh kind of double ransomware right now sometimes triple where you've got the data that's being encrypted or the data stolen first and then even if you restore from backups which people have gotten better at they'll just go to a dedicated leak site and dump data so it's a bit of a hostage choice like do you want all your data out there or do you want to pay and, yes, you have an issue, yes, it's reportable and those sort of things, but at least your data, maybe your customer's data is not floating around.
1:01:13And they will actually, the e-crime actors, will film the data destruction. They will actually write reports on how they got in. They will actually give recommendations and products. We happen to be one of the products they recommend. How about that? Is that a channel for you, e-crime? The e-crime channel. No, it's just you can't make this stuff up. Like when you actually see, you're like, did they just put together a consulting report and have product recommendation? Answer is yes. So that's how mechanized this whole process is. Why do they do that, by the way? Why do they help after the fact?
1:01:46They got paid. They're trying to make the honor of the cause. Yeah, they're saying, hey, this is what we... This is what we found. This is how we got in. This is the data being destroyed. Right. And, you know, if if there wasn't if all of a sudden you paid and then the data got leaked. Right. And the next guy paid and data got leaked. Somebody would go, well, why would I pay? Because it's going to get right. There's there has to be some level of brand. Yeah. Like, you know, honor among thieves, I guess. Right. If no one was if people were getting paid and not getting the outcome, that would stop pretty quickly.
1:02:25But people are paying. It doesn't mean they won't come back. It doesn't mean they can't do bad things, et cetera, et cetera. But they basically are, in most cases, holding up their end of the bargain. That depends on the group. Some groups have better reputations. I mean, this is just for people that are outside of cyber to make this totally clear. So I'm working at a big company and there's a group in Russia or wherever they are, and they hack into our systems and they get our credit card information or our customers information or whatever it is. And they're saying, hey, you can have this back, but you need to pay us.
1:02:59And then if you pay them, then they're delivering you. Hey, here's how we got in. Here's how you need to protect yourself. Here's our recommended vendors for it. And if not, they might go dump it on an exchange and it'll all be out there. That's it. And so they're building their own ethical, or not ethical, but their own brand and reputation that if we get you and you pay us, then we'll help you, which is kind of this funny prisoner's dilemma. It is. And the groups that do incident response were one of, you know, one of the bigger ones that do it. Um, we kind of know who the groups are and we have a view of whether if you pay them, whether they're just going to still dump the data or what they're going to do.
1:03:40Right. So I'm curious, uh, and I realize this is probably a hard number, but let's take fortune 500 companies, uh, and they get attacked or, uh, the, the ethical, uh, criminals, I guess would be the right term. Are most of them these days, uh, ethical in the way that they'll do. If you pay them, they'll actually do what they say they were going to do, or is it? Yeah. I mean, I don't throw ethical in the same context. Yeah, I know. It's hard. I think do they hold up their end of the bargain for some point in time? I would say for the most part, we've seen the bigger brand name ones. It's hard to talk about criminals like this.
1:04:17It's not. And it's a super serious subject. Totally. But when you explain it to people, because somebody is going to maybe listen for the first time and they're going to go like, really, does this happen? Like people break in, steal the data. If you don't pay them, they just go nuts. But if you pay them, like there's some honor of like, here's the video of it being destroyed. Here's the report. Here's, you know, it's kind of a crazy world. It's a fascinating, fascinating business out there. What about AI in this, in this whole world? We've generally, we don't make it very long. I don't think any podcast and technology these days makes it this long without really, you referenced it earlier back in the days when we called it machine learning.
1:04:57But now it's AI. How has AI changed some of the attack vectors for the potential criminals that we're talking about? And also, how has the founding principles around AI benefited CrowdStrike and going forward? Well, it was a founding principle of, you know, quote, AI was that was really more of a marketing term at the time was machine learning, which you can say is AI is fine. But, you know, it was not generative AI that that really wasn't around. So for us, that's why the approach was get the data first, right? Because once you have the data, then it unlocks the AI piece of it. And that's been very successful in stopping breaches and finding things that haven't been found before.
1:05:38Now when you look at generative AI, we've got a product called Charlotte AI, which is essentially your virtual SOC assistant that not only can answer questions, but can do work on your behalf. So the whole goal for us is how do you take eight hours of work and turn it into 10 minutes for a SOC analyst? So that's the goal. So I think there's a lot of promise for it from the defenders, but obviously that can be used for malicious purposes as well. And for many years, we dealt with adversarial AI, teams trying to defeat our AI in terms of files and things of that nature. And now it's moved into more of like dark AI, which would be, you know, how do you use generative AI models that don't have guardrails, you know, like fraud GPT and others that are out there.
1:06:22So what that is going to allow, basically, what does all that mean? It means that you can democratize these very hard concepts of getting into a company or creating exploits or malware, and you can democratize that and make that available to a much larger population because now it's, you know, like ChatPT for the bad guys. They have their own, it's not ChatGPT, but they have their own models, right? so you have many more folks who maybe don't have the expertise can now execute a campaign that's one and two the time it takes to actually figure all this out is now compressed and this is this is part of the problem in security it's really a time game of you know how much time yet yes you want to prevent it but if something bad happens you got to be able to to react to it and you can't do that in three days.
1:07:16You got to do that in, you know, under 60 minutes. Fraud AI is actually a... Yeah. So there's a... Fraud GPT. Fraud GPT, sorry. So there's a chat GPT equivalent that doesn't have any guardrails on it. And if you want to do malicious attacks, you no longer need the expert sitting next to you saying, hey, let's try this permutation of this and do that. Now, fraud GPT will do this on your behalf. And so it's while chat GPT or whatever it is, is democratizing creativity or whatever it is, this is democratizing cybersecurity attacks for these bad actors. Is that just the new state of what we need to deal with and you all and folks like yourself are just going to need to continue to get better and is there anything we can do beyond uh about this type of thing going on no i mean it's just you know first you got to be aware of it understand how the adversaries work right and what makes them tick which is really important because um this is why security intelligence is is a hallmark of what we do if you don't know what the offense plays what they're going to be, it's hard to run, be a defender.
1:08:34It's like football, right? You got to know what the playbook is over there. So that's the new playbook. And it goes back to security needs to parallel the scope of the technology curve. You're not going to, nor should we want to inhibit any technology innovation. We should, as a security company and security practitioners, we should focus on how do we enable that new technology to be used safely. And the main purpose it was intended to be used for. What's one thing you'd recommend any person listening at a company beyond by CrowdStrike, I guess, that they do to up their security posture or try to prevent some of these attacks from occurring?
1:09:16I mean, it extends through small companies to large enterprise. But one of the biggest areas of exposure is identity and poor passwords. We've I mean, we go to RSA for 30 years, been talking there for 30 years, and we still have the conversation of like poor passwords. And as an industry, we still haven't solved it. We've gotten better in areas, but we still haven't solved it. So I think having better passwords, password managers, two-factor authentication where possible to enable those. and many of the larger cloud providers and apps have that, that would be a big step in just preventing somebody from getting in.
1:10:00And then after that, it's having the right security technologies and it's really protect, detect, respond, and now it's going to be a report. That's going to be the fourth element because of the SEC reporting. But from the average person, I think shoring up their identity and their passwords using two factors is going to be a good starting point. Because you touched on it, the SEC reporting now for public companies, they have four days to disclose. Once they know, then they have to. Once they know, it's considered material. When did that come to pass? December 15th, 2023. Oh, so just recently.
1:10:36This is a new thing. And so does that include like when any person within the org finds something out and they have to escalate it to the CEO and everyone else? It's if you have an incident that is, I'm kind of paraphrasing, devils are in the details of what's material, when you found it, and those sort of things. But if you had sort of a material incident, then you have four days to be able to publicly disclose that, which is a tight time frame, particularly if you do an incident response and trying to figure out the cone of exposure and compromise. If you have an active adversary in there and then you don't have enough time to kind of sort it all out, well, in four days, you know, you got to make a disclosure.
1:11:16And now what we're seeing, kind of get back to the ransomware pieces, we've actually seen ransomware groups who hadn't gotten paid report to the SEC. So it's like triple extortion. You know, either the data is going to get dumped, it's going to be encrypted, or they're going to, if you're a public company, they're just going to run to the SEC and say, oh, by the way, we broke into them and they hadn't reported to you. We've been talking for probably a decade, it feels like, in this from my seat about like cybersecurity now being a boardroom level conversation. But we're seeing now with this SEC rule being passed and we've seen a lot of big public companies stock prices with all this stuff be very, I assume we'll see even more of that going forward as a result of this.
1:11:59Yeah. And, you know, you see a lot of companies that have issues. Any big company is going to have an incident. and it's making sure that you try to make sure that incident doesn't turn into a catastrophic breach or what have you. I haven't run into too many companies, particularly bigger ones and public companies where they're not taking security seriously or they're not spending money on security or they're not trying to do the right things. I mean, each one is a different spectrum and maybe you have different industries, but for the most part, people want to do the right thing. It's just, it's really hard.
1:12:31The adversaries are good. You have to be better and you have to have, unfortunately, you have to have the right technologies because many companies buy one of everything and two of everything else. And then they have a hodgepodge of things that don't work together. And wherever those little seams are in their security products across the spectrum of what they need to do is where the adversaries generally hide. We talk about network effects so much with consumer businesses. And we think about Facebook or whatever, all that. But I guess the other term of accumulating advantages that come from some level of consolidation of cybersecurity tools, you all continue to benefit from the incremental customers you have because you see more attack vectors.
1:13:15You know these groups even better. It's interesting to see a real enterprise accumulating advantage play out for you. That's the crowd and the crowd strike. People always ask me, well, how did you come up with the name. Crowd is the crowdsourcing piece. Strike is the fact that you're operating from the cloud and you have to dive down very quickly and make sure that you can deal with these things. And that's why the product is Falcon. It's the fastest diving bird in the world, 200 miles an hour. So that's how we put it together. And it was a network effect. And literally from day one, that's why we started with the data.
1:13:46The more data we had, the smarter the system would get. And the more things that we could do. So we operate, we have agents in 176 countries. when I say agent software that runs on someone's computer cloud. And there are many attacks that we haven't seen. There aren't many techniques we haven't seen. So it gives a real advantage of this community immunity sort of approach. And then, you know, those sort of things get baked into the product and, you know, in the algorithms. And, you know, they auto adjust themselves to be able to make sure that the rest of the community is protected as we see them.
1:14:20What's next in the cybersecurity industry as you kind of look out? Is AI the big one or are there other things that you're really paying attention to? In the early stages of AI, what it can do and how it works and people are trying to figure out how they commercialize it, make money, how it actually adds value to a customer. So you have that. I think from a cloud perspective that the cloud technologies are moving so quick. You know, used to be compute and storage. And now it's literally the alphabet soup of things that are out there that make all this work. And it's very complicated. So I think that's really the new frontier, which is why we spent a tremendous amount of R &D dollars.
1:14:59And we're one of the largest cloud security companies, independent companies on the planet. So we think that's a great opportunity from a business perspective, but it's also a big opportunity for the adversaries. I want to back up a little bit. We touched on your journey into being an entrepreneur. or, uh, but what was, did you grow up thinking you were going to start a company and found stone was just the manifestation of that? Or did you just kind of accidentally fall into that? Yeah. I always wanted to do something on my own. Um, yeah, I mean, I grew up by zero money and, uh, you know, put myself through school and that kind of stuff.
1:15:35Um, and then got an accounting degree cause I didn't want to be a mainframe programmer because I went to college in the eighties and really didn't, it didn't, didn't mean, you know, you couldn't be a Unix programmer or something back then, but a lot of it was around main firms. Didn't want to do that. Really wanted a business degree because I knew I wanted to do something on my own. And yeah, that's how I picked accounting was I just thought it was a good way to have a foundational understanding of business and how things work. And that's really, you know, I've always been creative and sort of had that, you know, mindset that the security mindset is like, how do you think about how somebody's going to break your system, but you're always thinking about the creativity, like what's next?
1:16:20How do we, what do we do? How do we solve problems? And, you know, for me going out on my own with found stone to kind of solve a unique problem that I saw was fun. And, you know, I honestly, I'd rather bet on myself than others. So that was, that was a big piece of it. The original product and team, you all were in New Jersey at the time. And I read that you met your VC in the Minnesota airport or something. to raise money? What was the, like, how did you get the group, the band together to go build? Yeah, we had all worked together at E &Y and, you know, we're kind of like, this is, you know, there's things that we want to do.
1:16:56And, you know, it was a fine place to work, but beginning at so many constraints because it, you know, independence issues and all kinds of things you couldn't do if you were an independent company. So that was really it. We sort of got some folks together and said, hey, there's a problem in the industry, which is like we can't, because we were doing a lot of pen testing and those sort of things, and people couldn't find all the vulnerabilities. And at the time, it was like desktop scanners, not enterprise vulnerability management solutions. So we said, well, why can't we take this simple desktop scanning assessment technology and make it an enterprise-ready vulnerability management solution?
1:17:37And that's how, we literally created the term vulnerability management, it didn't exist before we put it out there because people were assessing, but they weren't managing, and they weren't doing it at an enterprise. So that's how we got that going. And, you know, for me, it was just a blank sheet guy, like how do you create new things? How do you solve problems? That's part of being an entrepreneur. How does the late 20s, I assume, I mean, you were at least, I don't know if the others on the team were, but E &Y, people in New Jersey, How did they end up finding their way to Silicon Valley investors and ultimately getting this business going?
1:18:15Well, our first VC was out of Seattle and basically said, you could move to California or you can move to Seattle. And I said, eh, I'll move to California. And so I like the weather a little bit better there. So that's how I got to California. Wow. Yeah, I think that's pretty distinct from the way that VCs operate today with the remote and all of that. Yeah, this wasn't a choice. Yeah, that's fascinating. And you guys have been remote. I mean, I referenced it. You've been remote-ish from the start, from the early days? Remote first as a company. I mean, now we have many offices. And, you know, we're encouraging people who are near an office to go back in a couple days a week, which is always a challenge post-COVID.
1:18:55But what I wanted to do in that foundational team, those first 20 people, is to handpick the best folks, put them in place wherever they were at. And then we ran things remotely. And even I remember having the conversation with Samir at Excel. I was like, how's all that going to work? And I'm like, well, the most effective software model in the world is open source and everybody's all over the place. So I think we can try some of that and we'll make it work. And it did, and literally, I mean, we did this before Zoom. We did this before Slack. We did this, like, the tools we had were Stone Age in 2011 compared to today of what you can do.
1:19:36But we made it all work. We literally tried, you know, Tapa Talk. And you name the crazy stuff, we used it. But we made it all work. And then over time, it was, you know, still being able to have the flexibility to hire people that were remote, but then have offices that were really hubs where you can have some center of gravity, not only in the U.S., but worldwide. So that's how we operate. Are there first principles, things that you all do from an operating standpoint? Hey, everything needs to be written or everyone needs to be on a Zoom with their own screen or anything along those lines that you all do that you recommend?
1:20:12Well, when we first started and we were a remote company, we made everyone, no matter where they were, come into, at the time it was California, for one week of immersive training. And it was required that someone on e-staff had to teach some part of it every time we had someone that we ran across. E-staff executive? Executive staff, yeah. So just basically somebody that represented the executive staff had to go there, meet the people, and teach them, and tell the stories. Not the whole week, you know, but like their section of it. And, um, we had to stop that with COVID, but we did, it didn't matter whether you were a receptionist in Sydney, you flew to California and you basically got immersed for a week.
1:20:56And that made it through thousands of people. I mean, expensive, but it really helped build the culture. Um, and it got people, you know, to, to buy into what we were doing. They weren't always in an office. They weren't always being touched. So you, you wanted to give them that foundational piece. So I think that was important. And then the other piece that we did is we had many sort of forced meetings and not forced in a bad way, but hey, we're not going to see everybody in person for three months. So we're going to get the entire engineering team together over here. And again, there was expense associated with it, but we weren't paying for all the real estate.
1:21:32So we kind of balanced out and that really made a big difference of getting everyone together to accelerate the collaboration. So operating, it sounds like there's a methodology that you use for how you operate and run CrowdStrike. Can you speak a little bit about that? Yeah, it's something I came up with over the years. I mean, it's nothing so formal, but it's kind of what I use to try to operate a company. And I came up with just an acronym so I can remember it called PETS, which is People Execution Time and Strategy. So I think a big part is you have to have the right people and there's a methodology of finding the right people who can execute.
1:22:11and there's sort of the say-do ratio. There's a lot of saying, but not a lot of doing. They're probably not executors, right? And there's a piece that goes into how you execute, how you manage the business, how you understand your KPIs and all the things that goes into making execution take place. And then there's a strategy piece of like, okay, what is the game plan here? What's the immediate game plan, medium term and long term? And then how do you put time around it? And the challenge I see with a lot of folks at organizations, even young entrepreneurs, is like time matters. You know, I'm looking at a watch, not a calendar.
1:22:48So, you know, if you don't take all of those things and execute within the time frame that you have, you know, I mean, if Crouch Right came out today, we'd be crushed because it'd be everyone else, you know, that's doing all kinds of stuff, right? We were at the right time. We executed. We had the right people. And we had the right strategy. We put it all together. So there's all subcategories of that we don't have to go into. But it's just a simple way for me to look at it. If you don't have the right people, you can have the best strategy. It'll go nowhere. You're not going to execute it unless you have the right people.
1:23:23And then you're certainly not going to do it within the time frames you want. So that's really why it starts with a P. You're going to come up with a different acronym that would have started with something else. But it started with a P for that reason. So that's really the way I use it. I talk about it internally. People know it internally. And it's been a helpful but simplistic way to think about making CrowdStrike even better than it is today. And so is that the PETS acronym as it goes across? There's a bunch of sub-questions that you'll ask within each department. And is this something that actually folds into KPIs and frameworks and all of that as well?
1:24:00Yeah, it's not so structured that I probably need to put pen to paper one day and write it all down. Write another book. There you go. But I think if you take sort of those key principles that can be applied across what we do in many areas, just getting people to think about it in the right way. Early days growing up in New Jersey. So you mentioned putting yourself through school. I read around seven, your father passed away. Is that right? And at that point you took a job to be a newspaper. How did that experience, whatever part of it you want to speak to, influence you today as a founder operator?
1:24:46You know, it's one of those things that I think, like, if you look at the top entrepreneurs, there's probably always some level of trauma in their life, no matter what it was, that I think helps galvanize their thinking and their work ethic and really who they become. So I think if you can take those life experiences and galvanize and turn them into something that you can build on, I think that's important. So when you don't have a lot of money and you got to figure it out, you got to go out, make your own luck. and I think if you realize, like if you have no money and you're making it yourself and it's hard, you remember all those principles, you know, as you start companies.
1:25:34When you look at CrowdStrike, you know, I still look at all the cash that comes in. You know, AR and cash are our biggest areas that we focus on, but through our whole history of FoundZone and CrowdStrike, like expenses matter. cash matter. We were never a company that just spent at any cost and, you know, hope for the best. So I think those sort of blue collar experiences, you can translate into running a company and how you deal with people and how you hire people. And, um, you know, it's just life experiences that you file away and hopefully make you better. My understanding is you played a lot of sports growing up.
1:26:15What, uh, any, any sports you look back on, you think were the most impactful to you? I know you still race today. So I don't know. I didn't, I didn't get to race one. I mean, I did all kinds of crazy, you know, motorbikes and stuff like that, but didn't have enough money. Racing is, can be expensive. So I didn't have enough money to do that. But I, the biggest one, I mean, I, I swam, I ran, I wrestled, I baseball, football, I think football was, was the biggest one for me that was really impactful was team sport. And, you know, I was never the biggest, the fastest, go down the list. I think I was probably the guy with the biggest heart, put the most work in, which, again, translates into things that you do later in life.
1:27:02But I think working with a team, even today you look at so many kids are just in their bedroom and they're playing video games and those sort of things. And sometimes it's good to be out, be on a team, understand how it feels to win. understand how it feels to lose and take all those life experiences. So I would say football was the biggest impact. Football's an interesting one. As you referenced, and we talked about earlier, I, I played as well. And it's, I guess for our international audience, maybe they won't appreciate this point quite as much, but it, I so much appreciate it because every body type has a kind of different spot that they can potentially pay.
1:27:41If you're a big heavyset kid, you can do this. If you're a small fast kid, you can do that. And then it requires such coordination among the group, right? Like just having one person do their own thing might work in basketball or soccer or whatever it is, but you all need to be in concert kind of working together. And if one person fails, the whole team could fail and actually put each other at risk in some way physically. And so I've thought, I realize there's a lot of safety concerns around it and rightfully so, but there's so many good lessons I feel like I took away from that sport specifically.
1:28:17I absolutely agree. And we didn't, you know, we didn't have all of the fancy equipment and everything. I was telling the story the other day to somebody like, if you screwed up, you know, your punishment was you didn't get to go to the water trough. People are dying now because they don't get water. That was our punishment. No water for you. Like you think about that, That makes no sense. Concussions were called shaking up or something. Yeah, shake it off. I can't tell you how many concussions we probably all had that we just, you know, we would just go back in. We had a coach that, you know, if you screwed up, you'd take his whistle and we would twirl it.
1:28:55He'd whack you in the helmet and your ears would be ringing for the next two hours. I don't think that plays anymore. Not anymore. Yeah. But that's what we did. You learned a lot of good lessons along that. Um, we, we referenced PricewaterhouseCoopers, uh, and, and working there in their early days. Did that, anything from that experience, um, that you, you took with you today or as an entrepreneur specifically, obviously it led to your entrepreneurial journey, but any lessons of being an accountant right out of undergrad? Yeah. So I, I was an accountant. I was a intern. So it was in like a special program that I got into internship stuff and, uh, was able to work, um, you know, many, many long hours, uh, while I was still in school.
1:29:35and I think it gave me, you know, an appreciation for attention to detail and probably work ethic. And again, I have so many stories. When I first got to Pricewaterhouse, I literally was using 16-column and 10-key keyboard, you know, 10-key calculators, right? There was one PC, which barely worked. And so we were adding all this stuff up. But anyway, long story, there's plenty of stories around, you know, what we did to try to help make that a little bit better. But I remember when I first turned in my first set of work papers, and if you've ever seen these things, now I'm sure they're all electronic, but it was like a phone book.
1:30:10And I turned it in, and the senior that I worked for, she literally, I was so proud, it took me months to audit accounts receivable for a big pharmaceutical company. And she went down, she looked down the side of this piece of paper, not paper, but the work bundle, and she slid it back. And she goes, all the pages aren't even. I go, what do you mean they're not even? They're not even. They're not lined up. I had to literally go back and refold, because you had to use this little 8 1⁄2 by 11 cardboard thing, and then you had 16 column came out here, right? I'm dating myself. I had to fold it like twice, and then you had to put this little cardboard thing in so that everything was even.
1:30:52And I'm like, you've got to be freaking kidding me. Like, this is the dumbest thing. But when I look back, it was attention to detail. Yeah. Right. So it's, you know, why the Marines flip a quarter on the bed? Yeah. I mean, can't make your bed right. You know, you're not looking at, you know, your equipment, right. It's funny. I have a funny one from investment banking, which I noticed fonts all the time. And if it's like a, uh, if a presentation or something has like a different font in the chart than they do in the, uh, I just, I can't not see it. And it's just, it's funny. These things get kind of ingrained in you.
1:31:29And I'm sure you look at stacks of papers and we'll notice that stuff. Yeah, all that. But any little detail, my biggest pet peeve is if I see, and you've probably seen this like PowerPoints that have a date, but they're out of date. Like it's 2024. I shouldn't see a 2023. And if I see that, it's like, well, what else have you missed? Totally. Oh yeah. It opens up, it opens up a bunch of different questions along the way. As entrepreneurs sort of think about the timing of an individual market and the tailwinds, we talked about the different components that you were thinking about. Is there a way that you advise companies to sort of assess if now's the right time or if they're the right person to go out and actually start a business?
1:32:08Sure. Well, there's two pieces of that. One is the market ready and two is, are you ready to go do that? Which sometimes are mutually exclusive. But I think from a market timing perspective, when I looked at CrowdStrike, I saw that the need for security A wasn't going away be the outcome that people were paying for. Literally, people are paying billions of dollars for security, and they're still being breached, right? Because everyone's focused on malware. I mean, it's still a problem today. There's still security issues. But certainly back then, people were spending a lot of money with these legacy companies and firewall companies, and they're still being breached.
1:32:45I mean, is there a company that you know that has been breached that didn't have a firewall? No. They all have them, right? So, I mean, okay. Things are policy enforcer. So my point on that was like, there was an outcome that we needed to solve for and people being breached was an issue. So I knew there was a better way to do it. Two, and this is a really important point, is I like markets where, you know, you have incumbents with high customer dissatisfaction. You ask any customer, and I was at MacFeed, I won't pick on Mac, like pick the whole lot of them. Did anyone really like their technology?
1:33:18And 95 % of the customers are like, no, this thing is slow. It takes too long. You know, it doesn't work. I'm still being breached. I need something better. So with that level of dissatisfaction, there's got to be a better solution. It was like perfect for us. And there are other markets like that. You know, if you're going to enter a market where everybody loves the product and people don't see the new problem and, you know, they're not going to figure out what they need into the next five years, that may be a tougher slog. But for us, we knew high dissatisfaction, outcome that people wanted.
1:33:46And biggest thing was we had a unique and differentiated approach. Yeah, my framing of that, which actually my father-in-law used in his father of the bride speech was why now, why you, and why this? Like answering those three things. Why is this moment in time? Because you can either be too early or too late. You're never, it's never the right day to start a company. uh it's and ideally you're you're going to be a little too early uh and then grow into it and then why do you uniquely have a skill set to go do it because uh anyone else in the world could probably go do it and then and then why this like why this approach to solving the problem versus anything else selling 101 yeah and then and then it's why does it what why does it matter what happens if it's successful right is he in sales too what is he in sales yeah he was a It's an interesting thing.
1:34:43Yeah. Cool. There's a lot of ambitious people that might be listening to this thinking like, how do I rise within my organization or what, what is successful people within a company like CrowdStrike do? And I imagine you've had a lot of young people scale within your, your org. Are there commonalities, either characteristics or anything you would point to that like people that have really succeeded within CrowdStrike and have continued to scale within the organization have? I think the people who have succeeded in the Crouch Break play for the name on the front of the jersey, not the back of the jersey.
1:35:16And, you know, if you're always playing for the name on the back of the jersey just because you're worried about your own career or yourself or something, that doesn't really work out so well. So the team aspect of what we do, I think people have pitched in. People have been thrown into areas where, like, they've maybe not had a lot of experience, but they had to figure it out, but they had the right attitude. And, you know, again, it's attitude and aptitude. Maybe they don't have all the skills in an area or the experience, but they got the right attitude. And I think that is one of the key pieces.
1:35:45So we like really wicked smart folks who have a, you know, start with a yes and play for the name on the front of the jersey and are really worried, just focused on getting stuff done. It doesn't really matter. I mean, there's 20 excuses you can come up with of why not to do things or why it was hard or dogging my homework or all that kind of stuff. It's like none of that really flies. Like we got to get stuff done. It's not going to be easy. Let's figure it all out, work together as a team. That's what worked out well, I think, you know, the best for our culture. And if I was to give any advice, you know, if you focus on making the customer happen and you focus on being a team player, then a lot of the good things come.
1:36:30Like if you just focus on making a bunch of money and just yourself, people tend to get themselves derailed. And I think if you just, and certainly from a company building perspective, focus on the customer, the rest takes care of itself. And, you know, don't always, it's not always about you, you know, or the founder or the CEO or those sort of things. Like it's a team sport and you got to keep that in mind. Awesome. Thanks for doing this. All right.
1:37:14We'll see you next time.
From the publisher
George Kurtz is the CEO of CrowdStrike, a $65B+ public cybersecurity company. In this episode, George reveals the surprising intricacies of paying ransom and discusses how CrowdStrike is dealing with increasing cybercrime in the age of AI. We also talk about CrowdStrike’s early days, including how the company found product market fit and the operating frameworks that brought them to the forefront of cybersecurity today. (0:00) Intro
(1:52) The Journey to Founding CrowdStrike
(2:38) The Difference Between Stopping Malware and Stopping Breaches
(3:27) Inspiration Behind CrowdStrike's Unique Approach
(4:30) Challenges of Building a New Architecture in Cybersecurity
(5:10) The Decision to Leave McAfee and Start CrowdStrike
(8:11) Early Days of CrowdStrike: Building the Product and Offering Services
(9:45) Unexpected Beginnings of CrowdStrike's Intelligence Product
(10:33) The Role of Incident Response in Cybersecurity
(11:16) Journey to Becoming a Software Business
(14:36) Evolution of CrowdStrike's Product Offering
(19:54) The Importance of Building Trust and Credibility in Cybersecurity
(20:27) The Role of Nation States and Cybercrime in the Growth of Cybersecurity Threats
(25:09) Experience of Handling High-Profile Cybersecurity Incidents
(26:16) The Importance of Having the Right Investors and Board Members
(34:08) The Strategy Behind Competing with Big Players Like Microsoft
(42:09) The Importance of Having the Right Team and Leadership
(43:53) The Challenges and Rewards of Scaling a Cybersecurity Company
(48:49) Hiring and Retaining the Right People
(49:49) Understanding Different Types of Salespeople
(51:52) The Importance of Marketing and PR in Business
(55:59) The Role of Nation State, E Crime, and Hacktivism in Cybersecurity
(1:05:03) Impact of AI on Cybersecurity
(1:09:36) The Importance of Password Security
(1:10:41) New SEC Reporting Rule for Cybersecurity Breaches
(1:14:48) The Role of AI in the Future of Cybersecurity
(1:17:42) The Journey to Entrepreneurship
(1:19:58) Importance of Timing in Starting a Business
(1:25:06) Impact of Early Life Experiences on Entrepreneurship
(1:26:58) The Role of Sports in Developing Leadership Skills
(1:29:41) Transition from Accounting to Entrepreneurship
(1:29:55) Importance of Timing and Market Readiness in Entrepreneurship
(1:35:32) The Role of Teamwork in Business Success
Produced: Rashad Assir & Leah Clapper
Mixed and edited: Justin Hrabovsky
Executive Producer: Josh Machiz
🎙 Listen to the show
Apple Podcasts: https://podcasts.apple.com/us/podcast/the-logan-bartlett-show/id1606770839
Spotify: https://open.spotify.com/show/5WqBqDb4br3LlyVrdqOYYb?si=3076e6c1b5c94d63&nd=1
Google Podcasts: https://podcasts.google.com/feed/aHR0cHM6Ly9mZWVkcy5zaW1wbGVjYXN0LmNvbS9zb0hJZkhWbg
🎥 Subscribe on YouTube: https://www.youtube.com/channel/UCugS0jD5IAdoqzjaNYzns7w?sub_confirmation=1
Follow on Socials
📸 Instagram - https://www.instagram.com/theloganbartlettshow
🐦 Twitter - https://twitter.com/loganbartshow
🎬 Clips on TikTok - https://www.tiktok.com/@theloganbartlettshow
About the Show
Logan Bartlett is a Software Investor at Redpoint Ventures - a Silicon Valley-based VC with $6B AUM and investments in Snowflake, DraftKings, Twilio, and Netflix. In each episode, Logan goes behind the scenes with world-class entrepreneurs and investors. If you're interested in the real inside baseball of tech, entrepreneurship, and start-up investing, tune in every Friday for new episodes.
Executive Producer: Rashad Assir
Producer: Leah Clapper
Mixing and editing: Justin Hrabovsky
Check out Unsupervised Learning, Redpoint's AI Podcast: https://www.youtube.com/@UCUl-s_Vp-Kkk_XVyDylNwLA
🎥 Subscribe on YouTube: https://www.youtube.com/channel/UCugS0jD5IAdoqzjaNYzns7w?sub_confirmation=1
Follow on Socials
📸 Instagram - https://www.instagram.com/theloganbartlettshow
📱 X - https://twitter.com/loganbartshow
🎬 Clips on TikTok - https://www.tiktok.com/@theloganbartlettshow
About the Show
Logan Bartlett is a Software Investor at Redpoint Ventures - a Silicon Valley-based VC with $6B AUM and investments in Snowflake, DraftKings, Twilio, and Netflix. In each episode of The Logan Bartlett Show, we sit down with the people behind today’s most important startups and extract the tactics, lessons, and frameworks they’ve learned the hard way. Conversations span hiring to GTM, product, growth, fundraising and everything in between - collectively forming the ultimate playbook to make you a better CEO, investor or board member.
Tap follow and enable notifications to stay ahead of the game.




