Cybersecurity
8 min read

CrowdStrike One Year After the Outage: Damaged Moat or Buying Opportunity?

Research Team·Apr 24, 2025

The July 2024 software update that took down 8.5 million Windows machines was the most visible IT failure in years. Twelve months later, we examine churn data, net retention, and whether Falcon's platform advantage has survived.

The July 2024 content update that crashed 8.5 million Windows machines was, by any measure, the most consequential outage a cybersecurity vendor has caused in the industry's history — grounded flights, disrupted hospitals, and a very public reminder that endpoint agents run with kernel-level privileges for a reason, and that the blast radius of a bad update is proportional to how deeply trusted the vendor is.

A year on, the question is whether that trust has been rebuilt. Customer retention data suggests most enterprise customers stayed: switching an endpoint security platform is expensive and disruptive in its own right, and CrowdStrike moved quickly on remediation, credits, and process changes to its update pipeline. Net new business, however, has been slower to recover than renewals — the outage shows up more in slower growth than in outright churn.

The stock reflects that split verdict: essentially flat to slightly down on a trailing-year basis, a meaningfully worse result than cybersecurity peers like Palo Alto Networks put up over the same period, even as CrowdStrike's underlying revenue growth and gross margins have stayed intact. The market is pricing in a company that didn't break, but that lost some of the "obvious default choice" status that justified its premium multiple.

Our take is that Falcon's platform breadth — endpoint, identity, cloud, and now SIEM — is still a real advantage, and one bad update, however painful, doesn't erase years of product execution. The stock's underperformance relative to peers looks more like a re-rating of trust than a re-rating of the business, which is the kind of gap that closes as each subsequent clean renewal cycle passes without incident.

CRWDSecurityPlatformRecovery

More From Cybersecurity

All insights