Fireside Chat, Interview, Conference Presentation
George Kurtz CEO/Co-founder, CrowdStrike
- George Kurtz viewed CrowdStrike's IPO not as a conclusion ("checkered flag") but as a "green flag" signaling the beginning of sustained growth, leading to him visiting 130 customers globally within the first 100 days post-IPO to maintain momentum.
- CrowdStrike achieved over $100 million in new Annual Recurring Revenue (ARR) pipeline and closed deals during the "100 days, 100 customers" post-IPO initiative.
- Kurtz identified a market gap where traditional antivirus firms focused on stopping malware rather than preventing breaches, prompting the 2011 founding of CrowdStrike with a "pure cloud" vision and a refusal to build on-premises versions.
- Despite early resistance from major financial institutions like Goldman Sachs and Swiss banks who demanded on-prem solutions, CrowdStrike maintained its cloud-only architecture, eventually converting these skeptical clients into major customers after demonstrating the necessity of cloud scalability.
- To achieve immediate time-to-value, CrowdStrike developed patent-protected installation technology that allows software deployment without requiring system reboots, reducing installation timelines from two years to roughly one month for large enterprises.
- Current threat actors are categorized into three distinct groups: nation-states focused on information gathering and potential disruption, e-crime groups generating revenue through ransomware and business email compromise, and hacktivists driven by geopolitical events.
- In the last year, CrowdStrike identified and stopped 77,000 active "hands-on-keyboard" intrusion attempts, including complex supply chain attacks similar to the SolarWinds incident involving compromised COM100 software.
- Kurtz's investment philosophy emphasizes hand-picking Tier A investors who prioritize the company's long-term success rather than fund exits, a lesson learned from his 1999-founded company where investors pushed for a sale to maximize fund returns despite the market crash in 2000.
- The company's culture is described as "mission-centric" rather than adhering to a formal mission statement, focusing on the objective to "stop breaches," exemplified by incidents where CrowdStrike staff remotely secured power for customers hiding in Ukraine during active conflict to save lives.
- Kurtz cites a "hatred to lose" rather than a "love to win" as his primary competitive driver, a mindset he instills in sales and leadership teams to ensure rapid recovery from setbacks and sustained focus on victory.
- During his seven-year tenure at a major tech company post-Foundstone sale, Kurtz gained critical insights into operational failures, using those negative examples to define CrowdStrike's approach to employee treatment, channel consistency, and technology architecture.
- CrowdStrike's first 20 employees were personally handpicked by Kurtz, with one co-founder (originally "Employee Zero") famously requesting the title "Tool Using Mammal" on business cards to ensure the title accurately reflected his pragmatic utility.
- The company has grown to over 6,500 employees while maintaining a development focus on small, AI-driven agents that do not slow down systems, addressing the industry-wide issue of performance-heavy legacy security software.
- Kurtz authored the bestselling security book Hacking Exposed: Network Security Secrets and Solutions and has been featured in major media outlets including CNN, Bloomberg, and Fox News prior to his 2019 IPO.
- Foundstone, Kurtz's first company, was founded on the premise that security knowledge was nascent and that the emerging World Wide Web presented an untapped opportunity for protection software.
- CrowdStrike's "100 days, 100 customers" strategy set a new standard for IPO roadshows, where investors now explicitly inquire about post-IPO customer engagement plans to gauge founder commitment.
- Kurtz notes that the company's ability to stop zero-day vulnerabilities was demonstrated in a "hand-to-hand combat" style engagement where they identified unknown attacks on a customer by analyzing keyboard cadence and tool usage patterns.