The cybersecurity expert proving that software isn’t dead
Five months before two frontier OpenAI bots went rogue and hacked another AI company, the ‘SaaS-pocalypse’ came for cybersecurity software companies. Everyone assumed AI would destroy everything, yet Rathbone Global Opportunities Fund Manager James Thomson saw what others didn’t: a stock with a bright future made rosier by AI. It’s already doubled in value.
AI makes cybersecurity a growth market
|
Early this year, the market decided that software was doomed. Anything with ‘subscription’ in its business model got dumped in what has been called the "SaaS-pocalypse". So, will AI make traditional software redundant? The valuations of these software-as-a-service companies assume this is virtually a certainty. I’m not so sure. Some are likely to fail, but some will survive and could even thrive.
CrowdStrike, one of the world's leading cybersecurity companies, was swept up in the panic simply because it sits in the same index basket as the software it was being lumped in with. That, to me, was histrionics. So in February we bought it near its lows, although we couldn’t know that at the time – it could just as easily have gone lower. We just thought it was a fantastic business, going incredibly cheap. Since then it has doubled in value.
Why security is the bill nobody stops paying
Let’s leave the wild price moves aside though, and talk about the business, because that's what matters. That’s why I was happy to buy even when others didn’t.
The share of IT budgets spent on security has risen over the past 20 years from about 4% to 15%. And that is set to accelerate due to AI. In January, a KPMG survey found 40% of global companies plan to increase cybersecurity budgets by more than 10% in 2026 (46% said the same thing about AI budgets, but that’s arguably from a much lower base). And despite hundreds of billions of dollars thrown at the problem each year, breaches have risen over the last five years. Global security spending is running at roughly $200 billion this year, according to research advisory Gartner, and is forecast to reach $322bn by 2029. When the burglars get cleverer, you don't cancel the alarm. You upgrade it.
And AI is a hefty part of the increase in sophistication. CrowdStrike has monitored a 90% year-over-year increase in AI-enabled hacks, including agentic bots and automated phishing expeditions. This has rapidly reduced the time between the initial hustle, the breach, and the subsequent theft or ransomware deployment.
A glaring example of this ramp-up in AI capability and the risks it brings was delivered in the last few days. OpenAI admitted that two of its bleeding-edge AI models had escaped a sandbox environment designed to restrict them from the internet and hacked into another company to steal information it wanted to use to fulfil a training task.The speed and the sophistication astounded the CEO of the target, Hugging Face, an open-source AI tools platform. Yet the business had the ability to detect and observe the hack as it was happening.
The twist is that companies are drowning in tools. The average large business juggles 80-plus separate security products, many of which don't talk to each other. Exhausted by this, firms are now consolidating onto one or two platforms that do everything. There are two clear winners: CrowdStrike and Palo Alto Networks. Our preference was CrowdStrike.
A machine that sells to itself
CrowdStrike was built from scratch for the cloud, offering customers a single piece of software (an ‘agent’) that sits on every laptop, server and phone. Rivals – including Palo Alto – often bolt three or four systems together; CrowdStrike does it with one. When companies are looking for less complexity, we think this difference resonates massively.
Not only that, but having one agent makes it easier and more efficient to roll out updates and easier to sell customers extra features later. Of course, this does come with risks – with only one agent, any mistakes affect everyone all at once. That’s part of the reason why CrowdStrike’s faulty update in July 2024 caused worldwide mayhem – the other reason is that it focuses on ‘end-point’ protection: the devices we all use every day.
As is often the case, risk and opportunity come hand in hand. This end-point focus is at the sharp end of cybersecurity, with around 70% of attacks coming through those individual devices. And with so many devices under its remit, CrowdStrike is privy to a goldmine of data. The more data you have, the faster you can spot and stop an attack. And that is what its customers are paying for. Little wonder the lifetime value of a CrowdStrike customer is 4.2 times the cost of winning them, versus 2.7 times at Palo Alto.
The clincher is how CrowdStrike grows. Roughly 80% of new business comes from existing customers buying more. It offers 31 different modules, so there's an enormous amount left to sell. This recurring business growth is turbocharged by its ‘Falcon Flex’ model (launched in 2023), which customer pays a certain fee for credits to be used across whichever modules they want to use.
By the end of its last financial year, CrowdStrike passed $5.25bn in annual recurring revenue (ARR – the predictable, subscription income it can bank each year), up 24%, with Falcon Flex alone at $1.7bn and growing over 120%.
The rewards: doing the maths
We didn't buy this cheaply on paper – mid-teens times next year’s sales is a punchy price (the S&P 500 hovers around 3x). But if CrowdStrike never won another customer and simply sold every module to the clients it already has, that $5 billion of ARR could theoretically quadruple to $25bn. Pair that with the fat free cashflow margins this business throws off, and you can sketch a path to very strong profits. Management's own north star is $20bn of ARR within a decade. That's the kind of resilient, repeatable, recurring growth I hunt for.
The risks (because there always are some)
First, valuation: after this year's recovery, a lot of good news is now already in the price, and expensive stocks take the elevator down when sentiment sours.
Second, competition is ferocious – last year Palo Alto splashed $25bn on Israeli identity security business CyberArk, and Microsoft is investing heavily in bolstering its own cyber business.
Third, the elephant in the room: in July 2024 a faulty CrowdStrike update crashed millions of computers worldwide. Crucially, no data was compromised – it was a process error, the software shut itself down defensively rather than letting anyone in – and the company actually has more partners now than before the outage. But it's a reminder that when you're this mission-critical, mistakes are magnified.
Great businesses rarely go on sale, and when they do it's usually because the crowd has confused a wobble with a catastrophe. CrowdStrike is exactly the sort of durable, hard-to-imitate compounder I want in my fund – bought in a moment when many others lost their minds, held for the long haul.
Click here to find out more about the Rathbone Global Opportunities Fund.