CrowdStrike (ticker: CRWD, trading currency: USD) has a strong business model, but its economic engine is less pristine than it was pre-outage. The core still looks like a good business; the key question is whether trust damage becomes a lasting drag.
CrowdStrike’s DNA is straightforward: it sells recurring subscription cybersecurity software on the Falcon platform, then expands customers into more modules and adjacent workflows. The economic logic is excellent: one lightweight agent, one data layer, many products. That creates high switching costs, strong gross margins, and a classic land-and-expand motion. Professional services exist, but the real money is in subscriptions.
This is mostly a win-win model. Customers buy better security, simpler tooling, and often vendor consolidation. CrowdStrike benefits because every additional customer and telemetry stream improves detection quality and makes the platform more valuable. That is a real data/network-effect business, not a fake one.
The business is still headed upward, but with a scar. The FY2026 10-K still describes a platform gaining breadth across endpoint, identity, cloud, and next-gen SIEM. But the latest 10-Q for the quarter ended July 31, 2026 is blunt: the July 19 incident has had, and is expected to continue to have, an adverse effect on sales, customer and partner relations, reputation, and results. That does not mean the model is broken; it means the model now has a trust overhang.
So: no obvious product obsolescence, and no sign the core category is declining. The real deterioration risk is not technology; it is slower new-logo wins, more pricing concessions, lower net retention, and longer sales cycles after a self-inflicted reliability failure.
If I could track only a few numbers, I would watch: ARR growth, net new ARR, subscription revenue growth, gross retention / net retention, module adoption per customer, and free cash flow margin. If ARR and retention stay strong, the engine is intact. If they crack, the moat is weaker than it looks.