Not A CWRD'ed Trade
Let Your Winners Run, AI Is A New Game But The Rules Are The Same
Last October, I penned a Crowdstrike (CRWD) post, “Two Years & Two Buys Till Today: Time Told Truth & Today Tells Tomorrow”. It was a look back and a classic “Buy the FUD” on a perennial winner when Mr. Market decides that panic is the flavor of the day. The Microsoft (MSFT) outage and Delta Airlines (DAL) debacle was an operational gaffe, not a thesis changer. Lately with the SaaS-pocalypse, software and anything not hardware has been sold off as if their moats were vaporized in a hail of tokens and lasers. Feels like 2022 again where chunky total returns got slashed and investing seemed more like playing a video game than an elevated multi-modal discipline. But as we again learned since, it’s not.
The lesson and approach has stayed the same. This is NOT a CRWD’ed trade.
Let your winners run. AI is a new game but the rules are the same.
Outline:
The Elevator Pitch (3rd level thinking)
The Stage (4th level thinking)
Mr. Teece, Mr. Helmer and Mr. Mauboussin (4th level application)
Valuation, Performance & Limit Buy Rationale
The Bear Case
Discussion and Conclusion
The Elevator Pitch:
Summarizing the core argument for why artificial intelligence is a massive tailwind for CrowdStrike, rather than an existential threat. Remember that they were one of the first publicly traded native AI cybersecurity platforms whose counter-positioning stemmed from their push to prevent and intercept threats instead of the then industry-wide reactive approach.
In cybersecurity, AI essentially creates an arms race. While bad actors are absolutely using AI to automate phishing, write polymorphic malware, and launch faster attacks, in an AI arms race, the entity with the best and most voluminous data wins. But it’s not just that. First the typical elevator pitch then the deeper investing lens from where I stand gives us the underlying reasons.
Here is why CrowdStrike holds the high ground.
1. The Ultimate Data Moat (The Threat Graph)
AI models are only as effective as the data used to train them. You can’t just scrape the open internet to build a world-class cybersecurity AI; you need active, real-world attack telemetry.
CrowdStrike’s Threat Graph processes more than a trillion events per day across roughly 2 trillion vertices.. This creates an unparalleled, proprietary feedback loop. Every time an adversary tries a new AI-generated tactic against one customer, CrowdStrike’s AI detects it, learns from it, and instantly hardens the defenses for every other customer globally. Attackers simply do not have access to a training dataset of this magnitude.
2. Monetizing the Talent Shortage (Charlotte AI)
The cybersecurity industry is plagued by a severe shortage of human analysts. Alert fatigue is a massive vulnerability for enterprise Security Operations Centers (SOCs).
CrowdStrike isn’t just using AI under the hood to catch malware; they are productizing it. Their generative AI security analyst, Charlotte AI, automates the heavy lifting of triage, incident investigation, and response. By allowing lower-level analysts to operate at the speed and skill of senior experts, CrowdStrike makes its platform infinitely stickier and vastly reduces operational friction for its clients.
3. Securing the AI Gold Rush
As every Fortune 500 company rushes to build and deploy their own internal AI models, agents, and copilots, they are opening up entirely new attack surfaces—from prompt injection vulnerabilities to massive data leaks (Shadow AI).
Instead of AI just being a feature of their platform, it has become a new market category for them to protect. CrowdStrike is actively expanding its Total Addressable Market (TAM) by selling the exact tools enterprises need to govern and secure their own AI deployments. It absolutely speeds up the attackers, but it disproportionately empowers CrowdStrike. It transforms them from an endpoint protection vendor into an intelligent, automated gateway that enterprises literally cannot afford to rip out.
The Stage:
AI as the new technological process, enhances previous abilities and introduces wrinkles to known and new, situations. Whether it be fire, electricity, the steam engine, air conditioning, the internet, the mobile phone, the cloud or AI; these forces of creative destruction compel businesses (and humankind) to advance, bottleneck and/or fail. The major themes of disruption, moats and operation measurement have been covered in my other posts (anyone unfamiliar with the concepts should do that first).
From Open AI = Beta To The Power Of Reflexivity: “History never repeats itself, but the kaleidoscopic combinations of the pictured present often seem to be constructed out of the broken fragments of antique legends” - The Gilded Age: A Tale of To-Day, 1874. Technology disrupts, the path may seem novel but history has already used a version of this lens: this time is NOT different. Focus not on what’s new, but what is reliable and immutable. THAT is what endures and that is where you want to reap your rewards from a vetted, winning formula.
From Power To Profit, Part I: Moats or operational staying power were introduced. AI disruption (or even the perception thereof) has demonstrated not only the fragility of even any segment leader, but here we will see that true strength of a Helmer Power is not just in the benefit, but also in the barrier.
From MEROI-torious: Parsing Out Expectations, A Mauboussin-fueled Missive: 2nd derivative metrics and fundamental analysis/first principles indeed lay out when disruption is real, potential or feared. Redefining cashflows and honing in on whether an approach is value additive or destructive as signal, not noise.
This is not an exhaustive look; just a high level discussion.
Mr. Teece, Mr. Helmer and Mr. Mauboussin
Great minds think alike. The three aforementioned gentlemen all address the correct situational analysis from complementary perspectives. Substacker Nikhs, who I have mentioned before because I think he is a greenfield thinker and solid writer, just penned a fantastic post, The Route Changes. In light of AI, it summarizes how and why disruption happens but also where the profit may lie. It is based off of the work of David Teece in his 1986 paper, Profiting from Technological Innovation. Here’s his summary slide:
He wrote this paragraph that captures the essence:
Teece’s insight was simple, powerful, and still underappreciated: innovation and value capture are not the same thing. The company that invents a technology does not necessarily earn the profits from that technology. Those profits often accrue to whoever owns the complementary assets required to commercialize it.
In a vacuum, a technology that drastically lowers the cost and time required to exploit software should compress the margins of legacy cybersecurity incumbents. Yet, applying David Teece’s framework of value capture reveals a different reality. The Teece Imperative dictates that when a core technology (in this case, AI-driven exploit generation) commoditizes, the economic value ultimately accrues to the owner of the complementary assets.
For CrowdStrike (CRWD), these complementary assets are the structural barriers that allow its competitive advantage to evolve into a “traveling moat.” Most business models today can be quite complex, hence these assets can be found in various layers and/or workflows within them. Just as Nikhs identifies “trust, workflow or data” being part of the value chain when an industry’s path changes, CRWD has its own architecture that benefits from similar themes.
A prominent tipping point for AI is cybersecurity was the Claude Mythos preview on April 7th, 2026.
The Claude Mythos Catalyst & The Teece Imperative
Claude Mythos Preview was a wake-up call for enterprise security unit economics. Anthropic’s Project Glasswing demonstrated that frontier AI models can bypass decades of human security reviews, finding critical flaws in hardened infrastructure like OpenBSD. The cost of generating a sophisticated exploit is approaching zero.
CrowdStrike CTO Elia Zaitsev is quoted saying AI has collapsed the vulnerability-to-exploitation window and that CrowdStrike is involved “from day one.”
If attackers can act almost immediately upon identifying a vulnerability, the traditional window for patching collapses. The market shifts permanently from a human-speed problem to a machine-speed problem. However, CrowdStrike, operating as a prominent launch partner in the Glasswing initiative, is not a victim of this shift—it is uniquely positioned to absorb it.
The Teece Imperative would note that AI’s second order effect is commoditizing the software coding element and collapses the detection/patching window, making many legacy vendor offerings functionally useless or inept. This not only results in margin compression but also demands a near infinite step change in response time.
Thus Teece would specify that an investor seek out cybersecurity firms with complementary assets (things of scarcity and value) benefitting from this. These would be, for example, data, orchestration and compliance.
The by product is not the melting “static moat” but a “traveling moat” able to adapt to the structural shock. This is the manifestation of competitive advantage (a.k.a moat).
Though Teece’s work is specific to technological disruption, Mr. Helmer does cover this for static and dynamic situations via his 7 Powers.
Helmer’s Powers: The Anatomy of CrowdStrike’s Barriers
CrowdStrike’s ability to ingest the Mythos shock relies on two distinct barriers, mapping perfectly to Hamilton Helmer’s 7 Powers:
1. Cornered Resource: The Threat Graph (The Observational Layer)
AI models require vast, high-quality, proprietary data to function accurately in edge cases. CrowdStrike’s Threat Graph processes trillions of security events daily across millions of endpoints. This telemetry acts as the ultimate observational layer. An AI model like Mythos is only as good as the context it is fed; without real-time, real-world execution data, vulnerability discovery lacks actionable prioritization. Threat Graph is difficult to replicate at comparable endpoint breadth, freshness, and operational integration. Therefore frontier AI labs must partner with CrowdStrike rather than displace it.
2. Switching Costs: The Falcon Platform (The Compliance & Orchestration Layer)
Enterprise security is inherently sticky. Once the Falcon agent is deployed across a Fortune 500 company’s infrastructure, ripping it out carries severe operational downtime and compliance risks. CrowdStrike serves as the system of record for endpoint security and regulatory adherence. This immense switching cost buys CrowdStrike the time and capital required to pivot its architecture to meet the new AI threat landscape without bleeding enterprise customers to disruptive upstarts.
Charlotte AI and the Traveling Moat
To counter the speed of automated offense, defense must also be automated. This is where Charlotte AI bridges the gap between CrowdStrike’s legacy endpoint protection and the agentic AI future.
Charlotte AI acts as the orchestration layer. It utilizes the intelligence gathered by the Threat Graph and the advanced reasoning capabilities of models like Claude Mythos to compress the time between detection and remediation. By automating defensive workflows—contextualizing threats, recommending compensating controls, and executing responses—Charlotte AI ensures that the value of CrowdStrike’s platform scales linearly with the complexity of the threat environment.
The moat “travels.” It is no longer tied strictly to cloud-native antivirus signatures; it has shifted to owning the AI orchestration workflow within the enterprise security stack.
Parts of the various layers as well as other seemingly small and innumerable aspects of CRWD’s operational fabric results in the Helmer Power that is the most persistent, if not well substantiated: Process Power. The Orchestration Layer is often the means to this end; however the benefit aspect of a Power (here aiding the business client) is usually distinct from the barrier aspect of the same Power (here a keystone to CRWD’s moat). Few, if any, of CRWD’s peers have as an extensive a separation in this respect. Recent events have bolstered my belief in that.
To clarify, the exploits discovered by the Claude Mythos preview in software code is not under CRWD’s purview, but the software writer. CRWD’s website addresses this with respect to Claude Mythos:
The Division of Labor
Model safety is the builder’s responsibility. Deployment governance is ours.
Anthropic develops frontier models under its Responsible Scaling Policy, evaluating capabilities before release and red-teaming for dangerous behaviors.
This work addresses what the model can do. It does not address what happens when the model runs inside an enterprise with access to customer data, financial systems, and thousands of users deploying the model without governance. When an AI agent connects to a CRM, queries a database, or triggers a workflow, it’s not a model safety question. That is a deployment governance question.
CrowdStrike secures AI where it executes. Discovery of every AI agent in the environment. Visibility into what those agents access and what they do. Protection of sensitive data flowing through AI workflows. Runtime protection for AI agents connecting to enterprise systems.
This explanation is all and fine; but came off to me as being too lawyerly to easily understand. Let’s try a different way:
The vulnerabilities Claude Mythos Preview discovered—such as the 27-year-old integer overflow in OpenBSD or the flaws deep within the Linux kernel—were structural logic errors in the foundational source code.
CrowdStrike’s core Falcon platform is an Endpoint Detection and Response (EDR) system, not a Static Application Security Testing (SAST) tool. It does not read source code during the software development lifecycle to look for logical bugs. Therefore, CrowdStrike did not “miss” the source code vulnerabilities. The entities that missed them were human security auditors, open-source maintainers, and traditional automated vulnerability scanners that analyzed those repositories for decades without flagging the flaws.
Yet this industry development had to trigger action from CWRD. The constancy of change and required adaptation is ever-present:
Synthesizing the latest iteration within the Teece Imperative sees that it is the barriers that are at play when disruption is at hand. Ceteris paribus or in stable times it is the benefits that shine. A great business is one that bolsters benefits AND barriers even when they are not needed so that deployment is ensured when they are. Every login, task, keystroke, workflow execution and interface deployment is another iteration for the CRWD platform to strengthen its traveling moat.
For advancing incumbents, technological pivots are another opportunity to strengthen their moat AND gain marketshare. When owning generational wealth makers, sector and/or market downturns are (eagerly) anticipated because the value proposition adds and strengthens the prospects of total return.
The Mysterious Mr. Mauboussin
Though possibly the most interesting, this section will be the shortest. The lesson here is the same as it always is: context matters. Regular readers will expect the calculation and discussion of Return on Incremental Invested Capital (ROIIC) and Market Expected Return On Investment (MEROI). As covered in Aeluma (ALMU): Past Process, Pending Production, GaaP metrics are often not accurate reflections of business direction and performance.
As covered in the last post, CRWD has inched closer to GaaP profitability and been consistently FCF positive, which means that comparing these metrics over time can see some huge swings. Context is king here. As to how an investor would view these results, this is the setup:
Particularly with companies like CrowdStrike in the Growth stage (using Victoria Dickinson’s Cashflow Lifecycle Stages), items like stock based compensation (SBC), intangible investments and interest income should be redirected to the appropriate cashflows (or excluded when it comes to interest income).
For the trailing twelve months (TTM), assuming a WACC of 8.5%, CrowdStrike has the following metrics (apologies to readers, I am unable to release the actual calculation of these numbers due to pre-existing agreements). What I can say is a near identical approach was used here to my latest Aeluma (ALMU) post; where intangible investments, SBC and interest income were re-positioned in the 3 cashflow statements. BEFORE removing interest income, CRWD’s ROIIC was 19% (note the huge difference). Afterwards:
ROIIC: 13.2%
MEROI: 12.55%
A strong ROIIC in a challenging environment has demonstrated CRWD’s platform durability and resilience. Without explicit analysis, many of their peers have struggled here and is reflected in their stock prices. Though I penned most of this post last week, I am adding a chart from today. Take ZScaler’s (ZS) post earnings plummet on top of a trying year:

CRWD’s elite ROIIC just inches above a robust MEROI. This signals a high quality growth company whose investments are adding more economic value than their steady state ventures. The general market has acknowledged a high bar for expectations with a high MEROI. The most prominent bear case for me would be Mauboussin’s “Underestimating The Red Queen” effect: CrowdStrike must continue to execute at a feverish level just to be able to grind higher.
Valuation, Performance & Limit Buy Rationale
As a quantamental investor, the intersection of theory and numbers offer the richest lens. Even after the aforementioned analysis, other constructs regarding valuation and a smattering of technical analysis are used.
Looking back at nearly 7 years of buying CRWD now 10 different times, these are results that speak for themselves. My internal rate of return for all my CRWD buys and their comparative IRR versus the S&P 500 (SPY) as of the week ending 5/12/26:
Compounding at 40% annually and 30% above SPY has been a remarkable ride. The lesson here has been simple. Let your winners run and add to your fallen angels. In my October post, I quickly outlined why we added during the 2022 bear market and the Microsoft-related freak out that saw share prices pressured and story lines enfeebled.
I also posted my base and bull case valuations for CRWD at the time. Note in the buy grid below, the green circled prices are the add prices and expected return rates for the respective valuation case.
For the base case, the add on price was $346.20.
For the bull case, the add-on price was $417.69.
And from that post, here was my take going forward (bold is my emphasis):
“Though even at that, CRWD’s price already reflects the progress expected in December of 2026. Perhaps the market knows something we don’t. A superficial if not almost flippant thought, the AI boom will accelerate the Falcon platform capabilities or demand meaningfully. Or perhaps the animal spirits are a bit overheated. FWIW, the several times CRWD has reached this level, we have seen some mean reversion. For a long term investor, this matters little. Except that though the best time for a long term investment is today, there likely will be better times to ADD to the position.”
However the valuation, possible market complacency and increasingly volatile market dynamics may in some combination result in some downside around the upcoming earnings period . . .
I am not buying more CRWD today but this is not a call to sell or trim.
What followed is arguably another case of consilience. Check out the timing and valuation case buy prices:
My follow up CRWD article was timely, released a couple of weeks before then ATH of $550s
Followed 4 to 5 months later by a 35% price decline
My base case valuation add on price called the near term bottom within 0.4% of the low ($346.20 v $345.05)
My bull case valuation add on price ($417.69) was backed by volume based buying and now new ATHs (blue oval < I said just a “smattering” of technical analysis!)
So whether you believed in the base or the bull case, price met my levels, almost to the tee. Just saying that there is something to this consilience thing!
I cautioned that my approach to CRWD would be more measured because of (perceived/actual) AI risk. Typically I would have set a limit buy (probably in the $350s). The last tranche I bought was a manually placed order in the $390s as I interpreted a bullish reversal on March 3rd, 2026. This was BEFORE the earnings report later that afternoon.
Unless we are significantly overweight a position, we will always eat our own cooking. It’s just part of conviction, commitment and the course. It’s been nearly a year since I posted “Welcome To My Audience Of One: It’s All About The Process” when I discovered that my Substack that I had planned just to quietly document my posts was no longer essentially private. The focus has not changed (much). Yes, it does feel different and I could not be completely honest in claiming that having even free subscribers has not changed how I write.
Nonetheless, one could have just set a limit buy after my last CRWD post and joined the large cohort of thus far well-compensated shareholders. This is a screenshot of my updated tranche tracker as of several days ago:
Lost in the AI hype are some of the darlings of yesteryear whose secular themes are as strong as ever. CrowdStrike (CRWD) and Fortinet (FTNT) are my two largest holdings in this space and both continue to execute at very high levels. Neither seem or remain for long a CRWD’ed trade as at times Mr. Market decides to essentially abandon or significantly discount a very high quality perennial compounder. Patience has paid off handsomely here.
The Bear Case
The bear case is not that AI makes CrowdStrike irrelevant. The bear case is that AI raises the clock speed of the entire security industry, forcing CrowdStrike to spend more merely to preserve its edge while hyperscalers and platform peers use their own telemetry to narrow the gap. In Mauboussin terms, the company may still be excellent while the stock embeds excellence-plus-continuation. That is the Red Queen problem: running faster can preserve the moat without expanding the spread.
From a pure numbers/accounting perspective, most of the bear case revolves around the large effect of SBC on top/bottom line metrics.
FY25 GAAP operating loss of $120.4M relies on $958.1M in Non-GAAP adjustments (predominantly stock-based compensation) to report $837.7M in Non-GAAP operating income
Part of the narrative and equity premium revolves around its Growth lifecycle stage and a mid-term expectation of actual GaaP profitability, a detour however slight would warrant a multiple re-rating
Keep in mind that with Mauboussin-based metrics, cash flow components are re-arranged to account for this. From the pre to post interest income adjustment where ROIIC went from 19% to 13%, we see that these adjustments can be not only material but also emphasize that the margin of error is fairly small. I believe a lot of this is priced into my modeling, as for the market it seems like it is right now.
The other prominent bear case condition goes back to the Microsoft-related outage in July 2024.
Delta Air Lines filed suit in Fulton County, Georgia (October 2024) seeking $550M in damages attributed to the July 19, 2024, software outage.
CrowdStrike filed a motion to dismiss on December 16, 2024.
SEC Form 10-K explicitly logs ongoing systemic risk: “The Company has also received inquiries from governmental authorities and other third parties related to the July 19 Incident.”
If the Fulton County court pierces the standard SaaS Terms & Conditions liability cap (which historically limits vendor liability to 12 months of subscription fees), CRWD faces unmodeled multi-billion dollar exposure across the Fortune 500.
Further Details:
The Filing: Delta formally filed its lawsuit in October 2024 in Fulton County, Georgia, seeking approximately $500 million to $550 million in damages. Delta alleges gross negligence, breach of contract, and computer trespass, claiming CrowdStrike deployed untested software updates that bypassed required verification procedures.
Court Rulings: In May 2025, a Georgia judge ruled that Delta could proceed to trial with its core claims of gross negligence and computer trespass. However, the judge dismissed Delta’s broader fraud claims regarding intentional misrepresentation.
CrowdStrike’s Defense: CrowdStrike has filed a countersuit. Their primary legal defense rests on standard SaaS contract law: they argue that under their Terms & Conditions, liability is capped at the value of the software contract (which CrowdStrike claims limits their exposure to “single-digit millions”). CrowdStrike also argues that Delta’s extended recovery was due to the airline’s own antiquated IT infrastructure, noting that competitors recovered much faster.
Status of Similar Legal Activity
Immediately following the July 2024 outage, a wave of class-action lawsuits materialized. However, CrowdStrike has successfully insulated itself from the bulk of these secondary suits in federal court:
Shareholder Class Action (Dismissed - January 2026)
A massive shareholder class action, led by the New York State Common Retirement Fund, alleged that CrowdStrike executives deliberately misled investors about the quality of their software testing and internal controls prior to the outage.
Federal Judge Robert Pitman (Austin, Texas) dismissed the case in early 2026. The court ruled that while the update was flawed, plaintiffs failed to credibly demonstrate “fraudulent intent” or deliberate deception by management.
Consumer / Passenger Class Action (Dismissed & Appealed - June 2025)
Airline travelers stranded by the outage filed a class-action lawsuit against CrowdStrike seeking compensatory and punitive damages for the disruption, hotel costs, and lost time.
Judge Pitman dismissed this case in June 2025. The court ruled that consumer claims related to airline services and disruptions are preempted by the federal Airline Deregulation Act (ADA)—meaning plaintiffs must target the airlines directly, not the airline’s B2B software vendors. The plaintiffs have appealed the dismissal to the U.S. Court of Appeals for the Fifth Circuit.
The systemic, existential legal risk to CrowdStrike has largely been contained to the Delta Air Lines case. If the Georgia court ultimately pierces CrowdStrike’s contractual liability cap under the premise of “gross negligence,” it will set a dangerous precedent for the entire enterprise software industry. If the contract cap holds, CrowdStrike’s financial exposure to the 2024 outage is effectively neutralized. My non-legal professional opinion is that barring significant new developments and/or a politically motivated catalyst, there will be no material effect here.
Crowdstrike, What I Am Doing: Not A Buy Or Sell. Hold/Trim.
Gurufocus’ 2 stage reverse DCF has CRWD growing FCF at a CAGR of 42.5% for 10 years if it is fairly valued (discount rate of 11% and perpetual growth of 4%).
That does not pass the “sniff” test. We are talking about the first and most prominent native AI platform cybersecurity firm. Despite the significant capex and intangible investments as well as the attendant bottlenecks (memory, power etc) that all significant companies will face, could CrowdStrike defy economic gravity here?
Wait, say that again.
You’re asking about base rates? Meaning, has any other company grown this fast and this long before? Music to my ears.
Base Rate Breaker Or CAP Fader?
What’s the probability that George Kurtz & Co. can buck the base rate limit?
The short answer is 0%.
Statistically speaking, the base rate for a company of CrowdStrike’s current scale (roughly $4 billion in revenue and a $167 billion Enterprise Value) compounding Free Cash Flow or Revenue at >40% for a full decade is exactly zero. It has never happened in the history of modern public markets. Doesn’t mean it can’t happen but I won’t take that bet.
To understand why, we have to look at the definitive empirical research on the subject, Michael Mauboussin’s The Base Rate Book, and apply the unforgiving mathematics of the “Fade Rate.”
The Empirical Reality (Mauboussin’s Data)
In The Base Rate Book, Mauboussin and his team analyzed the growth rates of the top 1,000 global companies by market capitalization from 1950 to 2015. They tracked how many companies could sustain high growth rates over extended periods (3, 5, and 10 years) relative to their starting revenue base.
The findings are a brutal reality check for hyper-growth projections:
The 20% Hurdle: For companies starting with an inflation-adjusted revenue base between $1.25 billion and $2.0 billion, a mere 3.0% managed to sustain an annualized growth rate of just 20% for 10 years.
The Scale Problem: For companies starting with $50 billion or more in revenue, exactly zero companies sustained a 20% growth rate for a decade.
The 40% Illusion: When looking for companies sustaining 40% growth for 10 years, the sample size hits zero well before you even reach the $1 billion revenue mark.
CrowdStrike is entering this decade with nearly $4 billion in revenue. Statistically, expecting them to compound at 40% over the next ten years requires betting on an outcome that has a historical probability of 0.0%.
The Law of Large Numbers
To see why the base rate is zero, you just have to do the math on what a 40% CAGR implies over a decade.
If CrowdStrike compounds its current metrics at 40% annually for 10 years, the business multiplies in size by roughly 29x:
Revenue would grow from ~$4 billion today to $116 billion.
Free Cash Flow would grow from ~$1.2 billion today to $35 billion.
To put that in perspective, achieving $35 billion in Free Cash Flow would make CrowdStrike more profitable than almost any legacy enterprise software company in existence today, rivaling the cash generation of modern-day Meta or Microsoft. The Total Addressable Market (TAM) for cybersecurity simply cannot absorb that level of value capture by a single vendor without hitting the ceiling of global IT budgets.
The Fade Rate and the MEROI Conclusion
This brings us back to the Market Expected Return on Investment (MEROI) framework.
In corporate finance, the “Fade Rate” dictates that high returns on capital act as a magnet. They attract vicious competition, pricing pressure, and technological disruption (like the AI arms race we discussed earlier). Because of this gravity, extreme growth rates and high ROIICs inevitably fade toward the cost of capital and the average GDP growth rate over time.
When the market prices CrowdStrike at a $167 billion EV, it is not actually modeling 40% growth for 10 years—because institutional models know that is impossible. Instead, the market is modeling a very slow fade. It is betting that CrowdStrike’s Competitive Advantage Period (CAP) will stretch (or fade) longer than a standard software company, allowing them to compound at 20-25% for a few more years before gracefully gliding down to that terminal growth rate of ~8%.
So what kind of CAP is priced in? This where the bear thesis shows its largest claws.
To determine CrowdStrike’s Market-Implied Competitive Advantage Period (CAP), we must deconstruct their $161.07 billion Enterprise Value using Michael Mauboussin’s Expectations Investing framework.
The goal of calculating the CAP is to answer one question: How many years of elite, moat-defended hyper-growth is the stock market currently pricing in?
We calculate this by splitting their Enterprise Value (EV) into two distinct buckets: the Steady-State Value (what the company is worth if it never grew again) and the Future Value Creation (the premium paid for expected future growth where returns exceed the cost of capital).
Here is the summary (not all numbers/methodology):
Step 1: Calculate the Steady-State Value (SSV)
The SSV assumes CrowdStrike maintains its current purified cash-generation capability but zero future growth is achieved (i.e., ROIIC eventually equals WACC, adding no new economic value).
Using our Purified NOPAT of $908.5 million and an 8.5% Cost of Capital (WACC):
SSV = Purified NOPAT/WACC = $10.69B
Step 2: Isolate Future Value Creation (FVC)
The remainder of the Enterprise Value is entirely dependent on CrowdStrike’s ability to successfully deploy capital at a rate higher than its 8.5% WACC.
FVC = EV - SSV = $150.38B
The First Red Flag: The market is attributing 93.4% of CrowdStrike’s valuation strictly to future, unearned growth. You are paying $10 billion for the company’s operations as it stands today, and $150 billion for the assumption that the operational route (and results) never changes.
Step 3: Calculate the Net Present Value of Annual Value Creation
Next, we calculate exactly how much intrinsic value CrowdStrike creates in a single year of its Competitive Advantage Period.
To do this, we take the capital they invested (Purified IIC) and multiply it by the spread between their Purified ROIIC and their Cost of Capital. We then divide by WACC to find the present value of that newly created perpetuity.
Purified IIC: $600.0 Million
Purified ROIIC: 13.16%
WACC: 8.5%
NPV Added (Year 1) = IIC x (ROIIC-WACC/WACC) = $328.9 million
For every year CrowdStrike operates in its current high-growth, high-return state, it adds roughly $328.9 million in present value to the firm.
Step 4: Solving for the CAP (N)
If the company is generating $328.9 million in Present Value per year, how many years (N) does it take to justify the $150.38 billion FVC premium?
Because the market’s implied perpetual growth rate (8.29%) is almost exactly equal to their cost of capital (8.5%), the discount factor applied to future years effectively neutralizes. The PV of the value added each year stays remarkably flat.
N = FVC\NPV Added per Year
N = $150.38 billion/$328.9 million
N = 457 years
The Forensic Conclusion
If CrowdStrike maintains its current trajectory—investing $600 million incrementally at a 13.16% purified return—the market is pricing in a Competitive Advantage Period of roughly 450 years. Even if you aggressively accelerate their near-term reinvestment rate to assume they deploy tens of billions of dollars at that 13.16% return over the next decade (a highly unlikely scenario given the TAM limits of cybersecurity), the math requires a CAP of >22 to 25 years of uninterrupted hyper-growth before fading to a standard GDP terminal rate.
As we established with the base rate data, the probability of a company CrowdStrike’s size sustaining that profile for even 10 years is statistically 0%. The valuation requires the moat to travel flawlessly across the AI disruption, untouched by competitors, for a quarter of a century.
If you are building a short thesis, your strongest argument is that AI and agentic security will accelerate CrowdStrike’s fade rate, forcing their growth metrics to revert to the historical base rate much faster than the market’s $167 billion valuation assumes. You also stand by the base rate history, that no company has compounded capital that fast for that long.
The two main unanswered aspects of the bear thesis is that AI could introduce a value proposition that is materially/economically different (machine learning collapses company costs and operating leverage ramps up) and that companies on the inflection point of GaaP profitability do not need a huge change in unit economics to justify lofty valuations. Seems to me here that a good portion of BOTH aspects need to occur to justify today’s valuation.
Speaking of valuation, CRWD is currently trading at the highest band it has seen in my modeling and is approaching a major extension in my technical analysis ($671). That said, the uber bull case (GaaP profitability, AI as a catalyst and additional optionality) right now has fully fleshed out price target of ~$1,100 a share. I will try and release an updated memo when cleared to do so, but our last tranche in the flagship portfolio was bought in March; I would probably need to see price ~$500 or below to add more.
Discussion & Conclusion
CrowdStrike illustrates how incumbents with deep structural barriers survive technological regime changes via the Teece Imperative. By possessing the necessary complementary assets—the observational scale of the Threat Graph and the high switching costs of the Falcon platform—CRWD ensures that the commoditization of AI vulnerability discovery accrues to its own bottom line. With CharlotteAI bridging the operational gap, I fully expect CrowdStrike to continue its sector domination. The integration of frontier AI is not a disruption to their business model; it is simply the next layer of their traveling moat.
Helmer’s Powers breaks down the anatomy of the moat into layers; a cross-section if you will with the benefits and barriers. Teece’s complementary assets in the form of data, orchestration and compliance are also included, demonstrating these theories exist in a spectrum of perspectives. The existence of multiple Powers is evidence of CrowdStrike’s robust architecture of adaptability, resilience and longevity.
Mauboussin metrics even within a dynamic context still qualifies the firm as a perennial compounder of superior quality. This is the most informative quantitative screen for growth and early maturity companies. If the numbers reflect a deterioration in fundamentals or the segue to an older stage, a multiple re-rating can be swift and harsh. Often times the numbers or concerning trend will precede the price fall.
Valuation was covered lightly and historically based, FWIW. A well-followed FCF positive firm on the brink of GaaP profitability and a history of outperformance is expensive for good reason. Despite aforementioned challenges, CrowdStrike has continued to excel as it has in the past, thus a mean reversion analysis was done. But instead of a GTC (Good Till Cancelled) limit order, I manually entered a buy order when it was in its acceptable valuation band AND there was bullish buying activity noted. CRWD owners who buy within historical ranges can see remarkably stable internal rates of return. My oldest tranches have IRRs in the 30s. More recent buy IRRs are elevated due to Mr. Market’s regular ill-advised selloffs and a mechanically depressed time denominator.
The bear case rests on three main prongs: potential fallout from the Delta Airlines lawsuit, a valuation that demands a history making level of capital compounding and a competitive advantage period based in pure fantasy. The lawsuit appears to be toothless but warrants tracking. The valuation and CAP numbers, AI and profitability inflection potential aside, are obvious concerns. Also consider too that some of CRWD’s peers have and will be decimated with this technological change and there is a scarcity premium also being factored in. I am a holder here nonetheless.
Artificial intelligence should be the technological revolution of our lives. Through Twain’s kaleidoscope of change, the future is just another version of the past. Stick to what has worked. Stay away from what has not. I will continue using these operational constructs as my lens and the foundation to continued strong and sustainable returns.
Stay the course. Vet the FUD. Let your winners run.
Thanks for reading,
AlphaDoc
Disclosure: I am long CRWD, MSFT and SPY.
General Disclaimer: The information presented in this communication reflects the views of the author and does not necessarily represent the views of any other individual and/or past, present or future employers. It is provided for informational purposes only and should not be construed as investment advice, a recommendation, an offer to sell, or a solicitation to buy any securities or financial products.
While the information is believed to be obtained from reliable sources, its accuracy, completeness, or timeliness cannot be guaranteed. No representation or warranty, express or implied, is made regarding the fairness and/or reliability of the information presented. Any opinions or estimates are subject to change without notice. The author’s opinion is subject to change at any time without prior notice or update.























