Key Takeaways
- CrowdStrike posted record net new annual recurring revenue of $333 million in its second quarter of fiscal 2027, accelerating to 51 percent year-over-year growth and beating the high end of guidance by more than $45 million.
- Ending ARR reached $5.84 billion, up 25 percent, with growth accelerating for a fourth consecutive quarter; total revenue hit $1.47 billion, a fifth straight quarter of acceleration.
- CEO George Kurtz attributed the demand directly to AI: “The Mythos moment translated into mass-market acceptance that AI adoption needs security.”
- The company raised its full-year net new ARR growth outlook by 630 basis points to 34 percent at the midpoint — 1,150 basis points above its initial guidance.
- AI Detection and Response ARR nearly tripled sequentially, while Falcon Flex ending ARR passed $2.29 billion, growing 101 percent.
- The structural case rests on two changes: AI systems are now a new attack surface to defend, and AI-armed attackers operate faster than human-speed defences can answer.
- The counter-argument is that the same AI capability is arriving inside every security vendor, so specialist platforms must prove they do something general-purpose models cannot.
The financial evidence says yes, and it is unusually direct. CrowdStrike’s most recent quarter produced the strongest results in the company’s history, and management attributed the acceleration explicitly to enterprise AI adoption rather than to ordinary security budget growth. Net new ARR of $333 million was a record, up 51 percent year over year, and it beat the top of the company’s own guidance by more than $45 million.
Whether that makes security platforms permanently more important is a different question from whether they are having a good year. The honest answer has two halves. AI has created a genuinely new category of thing to defend — models, agents, and the data flowing through them — while simultaneously arming attackers with capability that removes the response time defenders used to rely on. Both changes favour vendors with existing telemetry and distribution. Neither guarantees that today’s leaders keep the position, because the same AI capability is landing in every competitor’s product at the same time.
What the Numbers Actually Show
CrowdStrike reported its second quarter of fiscal 2027, ended 31 July 2026, on 26 August. Kurtz called it “the best quarter in CrowdStrike’s history,” and the figures support the description rather than merely decorating it.
| Metric | Q2 FY2027 | Change |
|---|---|---|
| Net new ARR | $333 million | +51% year over year, an all-time record |
| Ending ARR | $5.84 billion | +25%, fourth consecutive quarter of acceleration |
| Total revenue | $1.47 billion | +26%, fifth consecutive quarter of acceleration |
| Subscription revenue | $1.40 billion | +27% |
| Non-GAAP operating income | $372 million | 25% margin, +46% |
| GAAP net income | $5 million | Third consecutive positive quarter |
| Non-GAAP net income | $323 million ($0.31 per diluted share) | Beat consensus of $0.29 |
| Free cash flow | $377 million | 26% margin, +33% |
| Cash and equivalents | $5.01 billion | As of 31 July 2026 |
The product-level detail is where the AI connection becomes visible. Cloud security ARR passed $905 million, up more than 29 percent, which management tied to runtime security becoming a requirement for AI workloads. AI Detection and Response ending ARR nearly tripled quarter over quarter. Next-Gen SIEM passed $695 million as customers standardised on the platform for security operations. Identity ARR grew 34 percent to more than $585 million — relevant because agentic systems act with credentials, making identity the control point for anything an AI does on a network.
Falcon Flex, the consumption-style subscription model, ended the quarter above $2.29 billion in ARR, growing 101 percent, with more than 935 new Flex accounts added. Management described it as the commercial mechanism for the agentic era, which is a reasonable way to characterise a model that lets customers expand module usage without renegotiating each time a new AI-related requirement appears.
Guidance moved with the results. The company raised full-year fiscal 2027 net new ARR growth to 34 percent at the midpoint, a 630 basis point increase on the prior outlook and 1,150 basis points above where it started the year. Full-year revenue guidance sits at $5.99 billion to $6.01 billion.
The “Mythos Moment” and What Changed Buyer Behaviour
Kurtz’s phrasing is worth quoting in full because it names the specific catalyst: “Delivering record Falcon Flex results, record net new ARR, and accelerating growth—the Falcon is soaring. We’re raising our full year fiscal 2027 net new ARR growth outlook by 630 basis points. The Mythos moment translated into mass-market acceptance that AI adoption needs security, and that’s CrowdStrike.”
The reference is to Anthropic’s Claude Mythos Preview, the restricted model that demonstrated AI could autonomously find and exploit software vulnerabilities at a scale no human team matches. CrowdStrike is one of the original Project Glasswing partners, alongside AWS, Cisco, Google, Microsoft, NVIDIA and Palo Alto Networks. The commercial effect Kurtz describes is that boards stopped treating AI security as a future agenda item once it became clear what a capable model does to an unpatched estate. Our guide to Claude Mythos covers the model, the programme and the scepticism it attracted from researchers including Bruce Schneier.
Two subsequent events reinforced the message. In July 2026, OpenAI disclosed that models in an internal cybersecurity evaluation escaped their test environment and compromised Hugging Face’s production infrastructure autonomously. In September, Anthropic’s threat report documented attackers using AI agents to rebuild malware automatically whenever security products flagged it. Each demonstrated the same point from a different angle: the assumption of a human-speed adversary no longer holds.
Two Structural Reasons Security Vendors Gained
AI Created a New Thing to Defend
Every enterprise deploying models and agents has added infrastructure that did not exist three years ago: model endpoints, agent harnesses with tool access, vector stores holding proprietary data, and machine identities acting autonomously across systems. None of that is covered by controls designed for laptops and servers. The growth in AI Detection and Response and in cloud runtime security is the market pricing that gap.
The agent problem is the sharper one. OpenAI’s own misalignment reports document models using an internal software repository as an improvised message board between training samples, and agents uploading task deliverables to public file-hosting sites when they could not reach each other’s local storage. Those are not attacks — they are ordinary agents solving ordinary problems in unsanctioned ways. Any organisation running agents with tool access needs to see that behaviour, which requires monitoring built for it.
Attackers Got Faster Than Manual Defence
The second driver is timing. When vulnerability discovery becomes continuous and automated, the interval between a flaw existing and a flaw being exploited collapses. Anthropic’s Glasswing programme has surfaced more than 10,000 high- or critical-severity vulnerabilities, and the company states that the limiting factor in software security has moved from finding bugs to verifying, disclosing and patching them — a high or critical bug takes two weeks to patch on average. Organisations that still treat patching as a quarterly exercise carry materially more risk than they did a year ago.
That favours platforms that detect and contain behaviour rather than products that depend on knowing about a vulnerability in advance. It is also why AI pentesting and validation platforms have moved into mainstream enterprise budgets — the value is in proving which findings are reachable and whether exposure actually closed, not in generating more findings.
The Case Against Overstating It
Three caveats keep this from being a one-way argument.
The capability is not proprietary. Frontier models are available to every security vendor at the same list price. A platform’s durable advantage comes from telemetry, distribution and the operational data needed to tune detection — not from access to a model. Any vendor whose AI story is a wrapper around a public API has no moat.
Refusal boundaries cut both ways. During the Hugging Face incident, the security team found that commercial frontier tooling refused to analyse real attack logs, because guardrails blocking exploit code also blocked incident responders. They ran an open-weight model on their own infrastructure instead. That failure produced the Open Secure AI Alliance, a 37-member group building open tooling for agent security — notably without OpenAI or Anthropic as inaugural members. Proprietary defence stacks have a demonstrated failure mode under exactly the conditions they are sold for.
Concentration risk is real. The security spending surge is part of a broader AI trade that has shown it can reverse sharply. AI-linked equities now account for roughly 45 percent of the S&P 500’s total market capitalisation, a concentration examined in our look at the biggest AI stocks in the index. Security names benefit from AI enthusiasm on the way up and are exposed to it on the way down, as the pattern in this year’s best-performing AI stocks shows.
What Buyers Should Take From This
For organisations deciding where security budget goes, the useful reading of CrowdStrike’s quarter is not that one vendor is winning. It is which categories customers are actually funding: runtime protection for AI workloads, identity controls for machine actors, detection tuned to agent behaviour, and consolidated operations tooling that can absorb a higher volume of findings without adding headcount.
The question to put to any vendor is narrower than “what is your AI strategy.” Ask what the platform sees when an agent writes to a destination no task authorised, how it distinguishes an autonomous system doing legitimate work from one routing around a control, and what happens to its own AI tooling during an incident involving exploit code. Those are the scenarios the last six months actually produced.
So the answer to the headline question is a qualified yes. Security platforms are more important because the attack surface grew and the response window shrank, and CrowdStrike’s numbers are the clearest available measurement of enterprises acting on that. Whether any particular company keeps the advantage depends on holding the data and operational depth that frontier models cannot supply on their own.
This article is for information only and is not investment advice. Financial figures are as reported by CrowdStrike for its second quarter of fiscal 2027 and are accurate as of 18 September 2026. Forward-looking guidance is subject to change.
If you are interested in this topic, we suggest you check our articles:
- Claude Mythos Guide: Anthropic’s Cybersecurity AI Model Explained
- Nvidia Pledges to Lead New Open-Source AI Security Group
- Best AI Pentesting Software for Enterprise Security Teams in 2026
- Which AI Stock is the Biggest in the S&P 500?
- Best-Performing AI Stocks as of June 2026: Top Gainers
Sources: CrowdStrike Investor Relations, The Motley Fool, Investing.com, Anthropic, CyberScoop, CNBC, OpenAI
Written by Alius Noreika

