Letter to savers

CrowdStrike’s strategy: boosting subscriptions following the 2024 crash

Cybersecurity. Software from the group had caused computers across half the world to crash: today, its share price is at an all-time high. The challenge lies in maintaining profit margins

 Bloomberg

6' min read

Translated by AI
Versione italiana

6' min read

Translated by AI
Versione italiana

A journey to hell. There and back. That is how – from a stock market perspective – the performance of CrowdStrike’s share price over the past year can be described. The US company, which operates in the field of cyber security and is listed on the Nasdaq, literally plummeted in the second half of July last year. At the close of trading on 16 July 2024, it was trading at around $369. Then, on 5 August, its shares hit an intraday low of $200.8. This represented a 45.6 per cent drop. Subsequently, the share price recovered and is currently trading at all-time highs.

The blackout

Why? It so happened that CrowdStrike found itself caught up in one of the biggest digital blackouts not caused by cyber-attacks. Millions of Windows computers suddenly stopped working. Airports were paralysed. Businesses ground to a halt. Hospitals were left struggling. The cause? A software update – at least that is the officially accepted version – released by CrowdStrike itself.

Loading...

In particular, on 19 July – whilst many of the Redmond-based company’s systems were crashing – people were wondering what was happening. For a while, no explanation was forthcoming: it was unclear whether the ‘fire’ was in the ‘made in Microsoft’ product or in CrowdStrike’s software. It was only a few hours after the widespread outage – and numerous customer complaints – that a technical explanation was provided.

Following this, the Californian firm implemented a number of emergency measures: from publishing an online guide on how to remove the faulty file, to setting up on-site support teams to assist users, and even opening direct helplines for users themselves. Then, beyond the initial response, the cybersecurity firm offered additional support and compensation (for example, credit or contract extensions). Furthermore, CrowdStrike announced – and implemented – a review of its internal software testing and release processes, adding extra checks prior to each update.

TIPOLOGIA DI RICAVI

Loading...

Reactions

Of course! The problems weren’t resolved overnight. As the company itself indicates in its 10-Q filing for the last quarter, some parties have brought legal action against the cyber security firm. Among others – although not explicitly mentioned in the documents filed with the Securities and Exchange Commission – it is worth noting that Delta Airlines is seeking $500–550 million for flight cancellations, operational disruptions and other damages. The company accuses CrowdStrike – which rejects the allegation – of negligence in releasing the software update. But that is not all. On the reputational front – the tech firm itself, again in its 10-Q filing, refers to potential damage – it has come under pressure. The company’s allure has been somewhat tarnished.

The scramble to take remedial action

That said, however, it is undeniable that the company has managed – in terms of its stock market performance – to put last July’s turmoil behind it. Is this also reflected in its business performance? The group says yes: for the quarter running from early February to the end of April (the first quarter of 2025–2026), the company states that ‘the gross retention rate remains steady at 97 per cent’ and that there is ‘solid net retention’. Put another way: users have not abandoned the group. And that’s not all. The company highlights the upward trend in recurring revenue (ARR). To better understand this, it is first necessary to recall CrowdStrike’s business model.

In the world of cybersecurity, one distinction is as follows: on the one hand, there is what is known as ‘on-premises’ IT security; on the other, there is ‘cloud-based’ IT security. The former, in simple terms, means that the IT infrastructure (on which security is based) is located within the company. The latter, by contrast, requires the IT systems to be located externally, on servers outside the company and accessible via digital networks.

MARGINE INDUSTRIALE E DIVISIONI

Loading...

So: in the first scenario, the customer purchases the software (either as a one-off or a renewable licence) and pays fees for technical support or updates. Consequently, revenue is normally high at the outset but becomes less predictable thereafter. In the second scenario, however, each user pays a monthly or annual fee (subscription), often based on the number of protected devices and the security modules activated (antivirus, identity protection or cloud-based scanning). In such a context – clearly – revenue tends to be more stable and predictable.

Well, CrowdStrike was in fact founded with a focus on the cloud, complemented by artificial intelligence (AI). The company itself states – in its 10-K filing – that it has developed ‘the first truly cloud-native platform – CrowdStrike Falcon XDR – (...) with artificial intelligence at its core (...)’. In this context, it is easy to see why Annual Recurring Revenues (ARR) and their performance are so crucial.

The accounting indicator

In this regard, the group notes that the ARR at the end of 2024–2025 stood at $4.24 billion, up 23 per cent year-on-year. And that’s not all. Growth continued in the first quarter of 2025–2026, with the figure exceeding $4.4 billion. So, is everything plain sailing? The reality, as always, is more complicated. First and foremost, some experts point out that the very duration of the subscription means that any loss of confidence in CrowdStrike’s solutions will only become apparent a little further down the line. If the growth continues in the second and third quarters, then it will mean that the issue has truly been resolved. Furthermore, other experts highlight one fact: over the last three quarters – that is, since the July incident – the rate of growth in ARR has slowed. In the third and fourth quarters of 2024–2025, net new annual recurring revenues stood at 153 and 224 million respectively (compared with 223 and 282 million in the same two quarters a year earlier). For the first quarter of the current financial year, however, the figure stands at 194 million, compared with 212 million for the same period in 2024–2025. Given this trend, however, it should be noted that the decline is gradually becoming less severe. The fall was over 31 per cent in the third quarter of 2024–2025, whilst in the most recent figures, the decline stands at 8.5 per cent. In short: the long-term downward trend appears to be slowing.

Loading...

But it is not just a question of revenue. There is also the issue of profit margins. The gross margin, again in the first quarter of 2025–2026, stood at 74 per cent, compared with 76 per cent a year earlier. This figure is the result of two factors. The first is the slight decline in operating margins within the subscriptions segment, where increased expenditure on share-based payments had an impact. The second, however, is the impact of the contraction in the gross margin for consultancy services. Here, on closer inspection, the effects were felt, on the one hand, by the rise in costs for remedial work following the 2024 blackout; and, on the other, by the higher costs associated with the company’s expansion programme.

SPESE OPERATIVE

Loading...

A growth initiative which, amongst other things, is banking on the so-called Falcom Flex. What is it? It is a flexible subscription model for the business platform which, rather than purchasing individual modules, allows customers to pay a pre-defined annual fee. After that, the user is free to activate any service on the platform within that budget. Clearly, on the one hand, the Californian company will offer a discount on the subscription (hence, too, the general slowdown in profit margins); but, on the other hand, this allows the hi-tech group to expand the range of solutions offered to individual customers, strengthening the relationship with them and reducing the churn rate. In this regard, it is interesting to note that – in the last quarter – the proportion of customers who have adopted eight or more modules has risen slightly to 22 per cent (it was 21 per cent in the previous quarter). Nothing earth-shattering, mind you! But clearly, the strategy is beginning to bear some fruit.

Yes, some results. Those reported – again in the first quarter of 2025–2026 – and with regard to future prospects did not appear attractive to the market. The company has forecast revenue – for the 2026 financial year – of between 4,743.5 and 4,805.5 million dollars. Non-GAAP operating profit, meanwhile, was forecast to be between $970.8 and $1,010.8 million. The outlook – together with the quarterly figures – caused the market to react negatively. So much so that the share price fell by 5.7 per cent following the publication of the figures.

That said, however, the shares have in fact reached an all-time high. In this context, according to Seeking Alpha, CrowdStrike’s stock market multiples are higher than those of its sector. In other words: the shares are expensive.

Beyond that, in such a scenario, it may be useful to consider technical analysis. “The shares, which are strongly correlated with the Nasdaq,” explains Silvio Bona, an independent chart analyst, “are trending upwards. Between mid-March and the end of April, they formed a double bottom pattern. Currently, based on the so-called Elliott Wave theory, we are seeing the third wave run its course.” Consequently, it is possible that “there will be a correction, which will help to ‘lighten’ the market before the final push”. From there, there should be “a final upward surge, but with relatively less momentum and divergence from other indicators”. Therefore: caution is advised.

Further reading

Share price performance

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti