Updated CrowdStrike Thoughts

I took the weekend to contemplate the CrowdStrike news and potential fallout. After much consideration, I’ve evolved my thinking on how best to handle the news. While I had already taken off a large chunk of my position in normal trimming in June, I’ve decided to take more profits. The specific changes were sent to Max subs a few minutes ago. This name has treated me extremely well since the IPO, and I want to harvest more profit in the wake of significantly more uncertainty. In connection with this decision, I will be allocating that chunk of funds to a new name highlighted in section 2 (investment case included). These transactions will take place Monday morning.

1. Why the CrowdStrike Trim

There’s a great deal of uncertainty over the implications of Friday’s news. I’ve spoken with several industry contacts and “we have no idea what to expect” is the common theme. When a company is responsible for shutting down global transportation, hospitals and emergency systems, litigation is all but inevitable and that cloud will likely hang over this firm for quarters — not days or weeks. This is routinely being called the largest IT failure event of our lifetimes, and I don’t think that’s overly dramatic. Okta is still citing hesitancy among some prospective clients due to its own security failure nearly a year ago.

CrowdStrike is arguably the best endpoint security company on the planet. It thrives under 3rd party testing, boasts elite customer retention rates and routinely cleans up the messes of other vendors to win more business. This was not a security breach or a vulnerability in CRWD’s core infrastructure. It was an erroneous software update that needed more scrutiny and had a bug. Regardless of this, the development comes with awful press. To an unknown degree, it stains Crowdstrike’s  reputation of invincibility that it has built over more than a decade. This company was viewed as the perfect software vendor you never needed to worry about. That changed on Friday.

It is true that Microsoft Defender causes far more issues than CrowdStrike or any other vendor. Still, the world has accepted that. They’ve conceded inferior security for the world-class, highly convenient software bundle that Microsoft delivers alongside it. CrowdStrike doesn’t have that, and they need to be clearly, objectively better than Defender (like they have been and are) to keep winning. This doesn’t change the reality that Falcon has higher efficacy than Defender. But it will create noise, negative sentiment, bad press and litigation that could create issues in the near term. I do see that giving Defender, SentinelOne and Palo Alto a small leg up in competitive bids for new clients. That, to me, is what to worry about more so than a likely large, one-off fine. This could easily be a tiebreaker for some customers and a near term headwind to net new annual recurring revenue (NNARR). The key word is could, and that’s the real issue here. We truly don’t know what the actual ramifications of this will be. And? In the wake of extreme uncertainty, I like to be cautious.

None of this is to say that CrowdStrike can’t recover. I fully expect that to happen in the coming years. Still, I like the idea of broader diversification within what I view as the most compelling part of enterprise software (cybersecurity). That’s why my recent SentinelOne stake has actually become a larger position than CrowdStrike in the portfolio.  It’s also why I will be reallocating CRWD profits into a new Zscaler position:

2. Why ZScaler

CrowdStrike and SentinelOne are the best-in-breed endpoint platforms. Zscaler and Cloudflare are the best-in-breed network platforms. The two endpoint vendors routinely pull the network vendors into large deals and vice versa. This decision is my way of maintaining cybersecurity exposure while diversifying my allocation within the sector. It’s my way of enjoying all of the upside I see from long term, structural growth while diminishing the headline risk associated with owning one specific company. If Friday can happen to CrowdStrike, it can happen to anyone. 

This will function as a brief(ish) investment case that pulls from all of my previous research on the name to work through Zscaler’s business & prospects.

a. What Does Zscaler Do?

ZScaler’s Zero Trust Exchange (ZTE) is its latest and greatest, cloud-native network security platform. It’s the firm’s consolidated product suite for driving vendor consolidation, superior protection and lower cost. ZTE blazes a trail between users, data, apps and devices across eligible networks. Zero trust is exactly what it sounds like: never trusting a device or user. The exchange vets and verifies all traffic as it moves within a company’s perimeter. It does not allow bad actors to breach the most vulnerable piece of infrastructure and freely move about it thereafter without any subsequent verification. ZScaler ranks risk tied to each request for access or usage to assess needed levels of security for requests. That makes sure it’s only creating user friction when there’s actual security concern.

This zero trust approach routinely cuts infrastructure costs for customers. How? By shrinking the protection surface down to grant permission to one app, one user and one piece of traffic at a time. This vastly raises the precision bar for a successful attack from hackers. They can’t just pick on the weakest link. Permissions are based on client policy. This replaces an antiquated firewall and virtual private network (VPN) based philosophy in which every device & user within a perimeter gets perpetual and unconditional access. So? Zero trust is safer, cheaper AND allows remote employees to responsibly work from anywhere. Zero trust is rapidly replacing firewalls and VPNs for these reasons.

Zscaler Core Product Definitions:

  • Zscaler Internet Access (ZIA) protects internet connections. It’s the middleman between a user and a network that ensures proper authorization & access.

  • Zscaler Private Access (ZPA) offers remote, secure access to internal apps. This is an upgraded VPN by “connecting directly to the required resources without public exposure” — per Zscaler filings.

  • Zscaler Digital Experience (ZDX) ensures the high quality and always-on performance of cloud apps. It sifts through networks to identify sources holding back performance to be remediated. Also tracks user experience levels to guide any needed changes. 

More Sector Definitions:

  • Secure Service Edge (SSE) provides access to software for users regardless of where they’re working. Legacy vendors do this via firewalls while ZScaler (and others like Cloudflare) do so through the zero trust architecture to shrink the attack surface and bolster protection.

  • Virtual Private Cloud (VPC): These are subsections of public cloud environments. They offer users more autonomy with their network and apps. They also allow for secure connections between cloud and self-hosted (on-premise) environments with no public network exposure. This is especially key for highly regulated industries.

  • Virtual Desktop Infrastructure (VDI): Allows software to be accessed on remote devices. Zscaler’s Zero Trust Exchange (ZTE) ensures this is done safely and securely.

  • Firewall is a legacy form of network security that uses a fixed set of rules to authorize outbound and inbound traffic.

A True Platform Overcoming Continued Macro Headwinds:

Zscaler’s high-quality, cohesive network security platform has provided strong growth and profitability through a chaotic macro environment. Specifically, Zscaler’s suite offers a unique ability to consolidate point solutions across internet connectivity, cloud and app entitlement and security, user experience tracking, data loss prevention, workload protection, vulnerability management and remediation, risk scoring and (much) more. It can end the never-ending process of just spinning up more legacy firewalls and thinking that actually secures a network.

The desire to displace firewall-based systems has never been stronger… Zscaler provides the upgrade. Continued zero-day (new) exploits of competitors continue to bolster the appetite for displacing ineffective, costly systems with something that actually works. Phishing attempt activity is rapidly rising Y/Y, incumbents are failing to prevent lateral threat movement and Zscaler is taking full advantage. For some evidence, $1 million+ annual recurring revenue (ARR) customers last quarter rose 31% Y/Y and it expects demand to “stay strong.”

Despite continued recent budget scrutiny and macro anxiety, its approach is allowing customers to do more with less and turn operating expenses into efficiency gains and profit drivers. It’s worth noting: ZTE does routinely cost more than archaic firewalls. Still, the cost-to-value dynamic is far more compelling as Zscaler drives better coverage, better automation, easier usage, better interoperability and superior outcomes. Customers may pay more today… but they save more tomorrow. That’s how companies are bucking weak trends so far in 2024. Winning today requires that capability. And again, all of this success is despite macro difficulties. Specifically, its sales cycle has elongated from about 10.5 months to 12 months as of a few months ago.

Not Seeing The “Budget Fatigue” or Pricing Pressure Cited by Palo Alto:

On Zscaler’s last two earnings calls, it has been asked several times about pricing pressure and the competitive environment. This is likely due to Palo Alto’s pivot to “platformization” and its push towards free trials and product bundling. Zscaler sees no pricing pressures or the “budget fatigue” that Palo Alto cited. Why? Because of its superior zero trust architecture. Superior value breeds price elasticity of demand.

Another recent concern has been the rise of smaller, specialized network security providers, but Zscaler doesn’t see these players in competitive bids. And if they got large or real enough, Zscaler could simply use its strong balance sheet to buy them.

Its win rates remain stable and “very high.” It continues to command premium pricing thanks to superior outcomes justifying paying more than cheaper alternatives.

3rd party product recognition and happy customers are great evidence for gauging how valuable a product suite actually is. It’s one thing for Zscaler to say “we’re the best.” Talk is cheap. Independent confirmation is less cheap.

Gartner has named it a leader in SSE (already defined) for three straight years and Forrester routinely ranks it a leader in SSE, with Zscaler getting top scores on 11 different categories as of Q1 2024. CRN named Zscaler’s data protection suite as the “product of the year” in 2023. Its website contains a large library of happy customers boasting their success stories and its net promoter score (NPS) sits at 70+ vs. a software industry average of 30. NPS is wonky as it’s subjective and internally derived… but it’s not irrelevant. Most companies with awful customer service don’t talk about NPS. Not a coincidence. You can only fudge the number so much.

Whether it’s a sub 1 year payback period for a Global 2000 Telecom firm, a 5x ROI for a Fortune 100 Financial Services firm, a 3x ROI for a Fortune 100 Logistics firm or countless other examples, Zscaler provides tangible value even with premium pricing. Generally speaking, retention rates have also been quite resilient and stayed above 115% as of last quarter. This is despite a recent new business mix shift to new customer wins.

A Bit More on Competition and the Opportunity:

Competition is fierce. Palo Alto, Netskope, Cloudflare and maybe Fortinet are all strong competitors. The market is large, quickly growing, relatively insulated from macrocycles and so highly compelling. For context, network security is expected to grow well in excess of 10% for the foreseeable future, with the broad zero trust category compounding at a clip above 15% regardless of which vendor we look at. The regulatory climate is also favorable for nurturing that strong growth. The SEC is now forcing companies to openly disclose cybersecurity risk management. This should motivate more firms to embrace best practices like zero trust. The federal government’s mandate to embrace zero trust, paired with Zscaler’s Impact Level 5 (IL5) Department of Defense authorization merely adds public sector fuel to this fire. The broad array of firewall and VPN-based vulnerabilities now must be more openly disclosed (per SEC mandates). This is highlighting poor outcomes and product offerings from other vendors and is accelerating demand for Zscaler. 

Phishing attempts are up 60% Y/Y, more than half of Zscaler-surveyed respondents are struggling to prevent lateral threat movement (which zero trust accomplishes) and more than half are experiencing attacks. GenAI is merely removing friction associated with conducting large scale attacks, and there’s likely no slowdown in sight for this trend playing out. Security is highly important and the least discretionary bucket in enterprise software. Zscaler will need to continue to rev the innovation engine and successfully execute this go-to-market pivot.

Emerging Products — More Cross-Selling Potential:

Risk360 (debuted summer 2023) is Zscaler’s product for flagging, scoring and prioritizing vulnerabilities. This is how it ranks interactions to ensure safe encounters aren’t met with unnecessary user friction. It offers end-to-end risk quantification with intuitive next steps for remediation amid any pressing issues. With Risk360, companies get a birds-eye view of app, data and digital asset hygiene. It pulls from all ZIA, ZPA and ZDX data to provide superior data scale and context. As an aside, Zscaler recently purchased a firm called Avalor to help unify data ingestion and security with an AI-based approach to vulnerability ranking. This should be a welcomed addition to the Risk360 product.

Zscaler Business Insights (debuted early 2024) is more of a data analytics product and marks another way this company can bundle value for its customers. It offers broad visibility into a company’s ecosystem of apps and how frequently each app is actually used. This can reveal dormant or redundant subscriptions for easy cost savings. It also gives overarching insight on a company’s usage of its real estate footprint. They can visualize what office space is actually needed to power more potential cost savings.

Zscaler more recently extended its suite to Zero Trust for Workloads (late 2023) with key integrations including AWS and more. This takes a network-based approach to securing applications and servers in the cloud. This product doesn’t secure specific workloads/endpoints like CrowdStrike and SentinelOne do. It more so secures the communication and flow of data from one workload to another. All of its products center around networks. It can scrape and inspect all data and queries from remote devices and servers and is available for government clouds too.

Unsurprisingly, Zscaler is also pushing product and innovation delivery within the realm of GenAI. There are two focus areas here: protecting clients as they work with GenAI and then using GenAI to improve its own suite. In terms of protecting clients, GenAI App Security is the product to discuss. This helps companies embrace usage of GenAI models and apps with security guardrails to eliminate risk of data leakage or vulnerabilities. It puts companies in full control of permissions within the volatile GenAI world to keep their assets and data secure. It offers a secure sandbox for developers to work with whatever models they want without excessive risk. Companies get the best of both worlds: security and freedom to play with this exciting new technology.

For Zscaler’s GenAI apps, there are a few to mention. It shockingly built a copilot for ZDX. ZDX Copilot automates the “detection and resolution of network performance issues.” A user can ask this tool a question to get rapid help on troubleshooting, IT tickets, security issues and insights for optimizing operations. Breach Predictor is another tool to mention here. It uses GenAI models to “anticipate potential breach scenarios.” It eliminates those scenarios before they even surface.

Zero Trust Segmentation (announced last quarter) localizes and separates networks. This further shrinks the eligible attack surface by treating individual stores/factories/buildings as secure islands to prevent open sharing across locations. That lowers the risk of lateral threat movement even further. To expand its presence here, it purchased Airgap Networks for its location-level network security tools. Finally, last quarter, Zscaler announced data security posture management (DSPM). This offers clients seamless tagging, categorization, and protection of cloud-native data across public clouds.

All of these newer offerings have pushed its TAM closer to $80 billion vs. roughly $20 billion when it went public in 2018. It’s one thing to create new products to expand TAM… but just building something new doesn’t guarantee traction or any added revenue. Zscaler is proving that its newer products can contribute to meaningful financial success. Last quarter, emerging products outside of core ZIA, ZPA and ZDX represented 25% of all business won. 1 out of 3 customers are already using Zero Trust for Workloads. GenAI customers are already delivering a 20% spend uplift for the firm. Risk360 and Business Insights are routinely included in 7 and 8 figure deal wins with Global 2000 brands; it’s only a matter of time before its newer segmentation, DSPM and more future debuts are too. All of this, along with the strong growth in $1 million ARR clients already discussed, shows me a platform play blossoming before our eyes.

Evolving Go-To-Market:

Like many other companies this year, Zscaler has made significant changes to its go-to-market processes. It hired Mike Rich away from ServiceNow (where he was its Americas President) as its new chief revenue officer. Rich just finished filling out his management team this past quarter. What is he changing?

First, Zscaler is getting more focused on building channel partnerships. Just recently, it announced deepening ties to AWS and Google Cloud, as well as a new GenAI partnership with Nvidia. It will also continue to lean more heavily on managed security service providers (MSSPs) and system integrators like Deloitte. That’s not changing.

Next, it’s pivoting to hiring industry-specific sales reps to more granularly serve customers. It’s making its go-to-market less monotonous and more customer-by-customer, with an added focus to understand specific needs. As part of this, Zscaler is shifting attention from general opportunities to specific accounts. It calls this its “Vertical Domain Expertise” program, which started in healthcare and the public sector. Following the successful start, it’s extending to more industries.

Changes here (including some tweaks to compensation to prioritize performance) led to some higher-than-expected sales attrition (some involuntary) for employees. Zscaler is now ramping up the pace of sales hiring to plug this gap. All of this was supposed to lead to billings volatility last quarter, but as we’ll see below, it delivered a strong result. It told us the same billings headwind that did not manifest in results will last into its next fiscal year. It thinks this headwind will shave a point or two off of FY 2025 billings growth. We shall see.

b. Financials

Demand:

Here’s how demand looks as of Zscaler’s most recent quarter. Its 46.4% 3-year revenue CAGR, like for most others, has slowed from 50% Q/Q and 52% 2 quarters ago. I’d also like to call out billings again here, which is a solid indicator for forward-looking revenue generation. Zscaler’s billings figure was a robust 7% ahead of expectations last quarter despite disruption from the changing go-to-market.

Looking ahead, here’s how Zscaler’s expected forward 2-year revenue CAGR compares to peers and other high growth software names:

  • CrowdStrike 28.6%.

  • SentinelOne 28.5%

  • Zscaler 27.4%

  • Cloudflare 27.4%

  • Datadog 22.7%

  • Palantir 20.8%

  • Snowflake 23.8%

  • MongoDB 15.5%

  • Palo Alto 15.0%

Revenue estimate trends are strong for 2024 and weaker for 2025 due to the same evolving go-to-market discussed later:

Margins & Profitability:

Zscaler consistently crushes profit expectations. It’s also extending the useful life of some servers, which diminishes input costs and helps its gross margin a tad. Operating leverage is expected to slow next year as comps get tougher and it ramps the pace of hiring.

Looking ahead, here’s how Zscaler’s expected forward 2-year EPS CAGR compares to peers and other high growth software names:

  • Zscaler 35.4%

  • Palantir 26.5%

  • CrowdStrike 26.3%

  • Cloudflare 26.3%

  • Datadog 19.0%

  • Palo Alto 18.2%

  • Snowflake 0%

  • MongoDB Negative

I fully expect its actual growth rates to be faster considering its great track record of outperforming profitability.

Liquidity & Valuation:

Zscaler’s balance sheet is wonderfully pretty and simple:

  • $2.25B in cash & equivalents.

  • $1.14B in senior notes.

  • Diluted share count rose 6% Y/Y; basic rose by 3.4% Y/Y. 

  • Share count has compounded at a 3-year clip of 2.95%.

Here’s how Zscaler’s NTM P/E divided by its 2-year earnings CAGR (PEG ratio) compares to this same group of peers (lower is cheaper/better):

  • Zscaler 1.74x

  • CrowdStrike 2.74x

  • Palo Alto 3.08x

  • Palantir 3.16x

  • Datadog 4.10x

  • Cloudflare 5.93x

Overly Simplistic Modeling:

c. Team & Risks

Team:

Founder/CEO Jay Chaudhry:

  • CEO and Chairman of AirDefense from 2002-2008. This was purchased by Motorola.

  • Vice Chairman and Chief Strategy Officer of Secure Computing (related to McAfee) from 2006-2007.

  • CEO, Chairman and Founder of CipherTrust from 2000-2006. This was purchased by McAfee. CipherTrust invented the email security gateway.

  • CEO, Chairman and Founder of CoreHarbor from 2000-2003. This was purchased by a company owned by AT&T.

CFO Remo Canessa:

  • With Zscaler since 2017.

  • CFO at Illumio from 2016 to 2017.

  • CFO at Infoblox from 2004-2016. Purchased by Vista Equity Partners at a 33% premium to the stock price. Completed a successful IPO as their CFO.

  • CFO at NetScreen from 2001-2004. Completed a successful IPO as their CFO and sold to Juniper Networks.

CTO Syam Nair:

  • EVP of Product Engineering and Tech at Tableau, Einstein and the Salesforce Marketing Cloud.

  • Direct of Products for Microsoft Azure’s CosmosDB.

EVP of Business & Corporate Development at Zscaler Punit Minocha:

  • VP of Business Development at Palo Alto from 2010-2012.

  • SVP of Corporate Development, Data Center and Cloud at Trend Micro from 2002-2010

  • Direct of Business Development at Intel from 1997-2000.

4 Biggest Risks I See Beyond Continued Strong Execution Never Being a Certainty:

  • We are in the very early stages of its tweaked go-to-market approach. There’s no guarantee that it will work.

  • Google and Zscaler work closely together. Google is considering buying a cloud security platform called Wiz. That could create disruption in their cloud security relationship.

  • Following Friday’s event, a push away from one overarching platform to embracing more point solutions is possible. That could be seen as a way to make any future issues less impactfully negative. There could easily be stricter regulatory controls following this event as well.

  • And headline risk is a big one. If this past week taught us anything, it’s that even the strong security vendors mess up and are exposed to potential headline risk. Quantifying this risk is very hard, but negative impacts from it are highly likely.

Reply

Avatar

or to participate