CrowdStrike - Experts & Thought Leaders
Latest CrowdStrike news & announcements
A wave of cybersecurity firms have abandoned the Department of Defense-backed MITRE test as major companies join independent cyber testing program PIVOT, run by British company SE Labs. Participants in MITRE Engenuity ATT&CK Evaluations plummeted from 30 to just 11 last year. Meanwhile, CrowdStrike, Palo Alto Networks and Broadcom are among the participants confirmed for PIVOT, a 6-month testing program by SE Labs evaluating how effectively vendors can defend against the world’s most dangerous hacking groups and attack techniques. Testing critical cyber solutions “It’s a landmark moment for British cyber security, as the world’s biggest and best organizations choose to test their critical cyber solutions in the UK rather than in the US,” said Simon Edwards, CEO of SE Labs. “There are now very few tier-one vendors that aren’t testing within PIVOT.” “The requirements for cyber security have completely changed. There are autonomous AI agent attacks, such as those that affected Hugging Face, while the sheer economic scale of the JLR incident influenced the UK economy. Businesses need to know which solutions actually protect them against nation-state attacks, major ransomware campaigns and machine-speed threats, and that demands rigorous testing of defences.” PIVOT testing The PIVOT testing will see teams of trained ethical hackers from SE Labs impersonate nation-state cyber groups and other hacking circles responsible for the most disruptive cyber breaches in recent years, replicating attack types across ransomware, malware, phishing and beyond to stress test vendor solutions on their ability to detect threats from known attack groups and protect against them. Authority insights Adam Bromwich, Vice President of Engineering and CTO, Enterprise Security Group at Broadcom, said: "CISOs today need clarity and proof, not just promises. PIVOT emphasises full transparency and inclusion of major analyst firms to set a new standard for trust. For us isn't just about a score; it's about demonstrating Symantec and Carbon Blacks' real-world efficacy in an open, verifiable way that empowers customers to make confident security investments." Simon Reed, Chief Research and Scientific Officer (CRSO) at Sophos, said: “SE Labs’ PIVOT brings clarity to endpoint testing. It highlights who’s genuinely preventing and detecting threats, not just tuning for test conditions. As cybersecurity focuses increasingly on prevention and resilience for real-world protection, this independent assessment is critical to retain trust.” Independent scrutiny on test results The data from testing is shared with analyst firms for independent scrutiny ahead of publication to help vendors identify gaps in their security solutions and support product development against ongoing threat groups and attack types. The test portion of the program runs from July to October, with the final report released in January 2027. It comes amid the development of the Cyber Security & Resilience Bill, which will mandate designated essential services and digital service providers to report incidents within 24 hours to the regulator and NCSC and a full report within 72 hours, widen regulatory scope, and promote cross-border information sharing with EU authorities under NIS2.
Wipro Limited, a pioneer AI-powered technology services and consulting company, announces the launch of its Chief Information Security Officer (CISO) Command Center, in collaboration with CrowdStrike. The Command Center rewires enterprise security for frontier AI-accelerated risks to create proactive, risk-informed cyber resilience aligned to business priorities. The CISO Command Center reinforces Wipro’s consulting-led cybersecurity strategy by enabling enterprises to move from tool-driven operations to an enterprise-wide, risk-led operating model. The Center will be operationalized through Wipro Intelligence™ solutions – CyberTransformSM and CyberShieldSM – and supported by the CrowdStrike Falcon® platform. It will deliver integrated protection across endpoint security, cloud security, exposure management, and AI security, while unifying detection and response through a modern Security Operations Center (SOC). Remediating frontier AI risk “Cyber risk is intensifying pressure on boardroom decision-making. Threats that once remained dormant for months can now materialize within hours, driven by external triggers and AI-enabled exploitation,” said Amar Bysani, Global Practice Head – Cybersecurity and Risk Services, Wipro Limited. “The Command Center will work with enterprises to turn security signals into business risk intelligence, enabling them to sense, prioritize, and respond at machine speed.” Daniel Bernard, Chief Business Officer, CrowdStrike, said “AI is fundamentally changing both the threat landscape and how enterprises run defense programs. Together, CrowdStrike and Wipro are giving CISOs the AI-native security, intelligence, and services they need to turn risk into action at machine speed and transform security into a business advantage.” The offering is further strengthened by Wipro's membership in CrowdStrike's Project QuiltWorks, a global coalition focused on identifying, prioritizing, and remediating frontier AI risk.
As 2026 approaches, cybersecurity threats are evolving at an unprecedented speed. Small and medium-sized enterprises (SMEs) face rising exposure as perpetrators adopt advanced AI, expand commercialised cybercrime platforms, and intensify nation-state activity. Recent intelligence, including the CrowdStrike 2025 European Threat Landscape Report, highlights how attackers are becoming faster, more capable, and more varied in their methods, raising the stakes across the UK’s interconnected supply chains. Seven critical risks Below, they discuss seven critical risks that will shape the 2026 threat landscape. Vishing and deepfake-driven social engineering will surge AI will supercharge social engineering. Hyper-realistic deepfake voice cloning will make vishing attacks dramatically more convincing, enabling criminals to impersonate executives, suppliers, and public authorities with unprecedented accuracy. As these tools become widely accessible, SMEs, often with limited training and internal verification controls, will face a sharp rise in targeted social engineering campaigns. Identity protection will become a top priority amid rising SaaS and cloud adoption The rapid proliferation of cloud applications and SaaS platforms continues to outpace many organizations’ ability to secure them. Misconfigurations, fragmented access controls, and an expanding set of user identities create ideal conditions for attackers. Identity protection, including MFA enforcement, conditional access controls, and behavioural monitoring will become an essential foundation for modern cyber defense as attackers increasingly exploit identity-based vulnerabilities. Commercialised as-a-service cybercrime will open the door to more diverse attackers Cybercrime is now fully commercialised, with Ransomware-as-a-Service and Phishing-as-a-Service platforms enabling criminals of varying skill levels to launch sophisticated attacks quickly and cheaply. Many reports, including the previously mentioned CrowdStrike 2025, confirm the acceleration of these trends, noting that European organizations account for a growing share of ransomware victims and that both criminal and nation-state campaigns continue to escalate. As these platforms continue to evolve, SMEs, often serving as entry points to larger supply chains, will experience intensified targeting. Nation-state attacks will intensify as geopolitical tensions grow State-backed cyber operations are increasing in frequency and ambition. Critical infrastructure, logistics networks, healthcare, and essential supply chains remain high-value targets for nation-state actors seeking strategic advantage or disruption. With advanced reconnaissance, automation and AI-enabled attack methods now standard among these groups, the pressure on UK organizations has never been greater. This is a threat the UK must get ahead of; prevention is far more effective than the cure. Patch and vulnerability management will remain core to preventing breaches Even as threats become more complex, many successful attacks will continue to exploit unpatched systems and well-known vulnerabilities. Automated scanning tools allow cybercriminals to detect weaknesses within minutes of disclosure. Organizations with inconsistent patching, outdated systems, or weak vulnerability governance will be disproportionately exposed. Effective patch and vulnerability management remains one of the most reliable ways to reduce an attacker’s opportunity window. Threat intelligence will be essential to prioritising cyber workloads With expanding attack surfaces and increased alert volumes, many organizations, particularly SMEs, struggle to understand which threats genuinely matter. Actionable threat intelligence will become indispensable, enabling security teams and outsourced partners to prioritise patching, triage alerts, and focus resources on the most likely and most damaging risks. Reactive models are no longer viable; 2026 will demand intelligence-led, proactive security operations. Supply chain and third-party attacks will continue to rise Interconnected supply chains remain one of the greatest systemic risks. Attackers know that compromising a single SME can trigger cascading disruption across multiple sectors. In critical industries, such as pharmaceuticals, food distribution, energy and logistics, the consequences could be severe, even societal. As both criminal and nation-state groups increase their focus on supply chain infiltration, organizations must strengthen third-party risk management and invest in resilience across their entire ecosystem. 2026 will be a defining year for cybersecurity. To best withstand the challenges ahead, organizations must prioritise comprehensive identity protection that covers the whole business, including all cloud applications, configurations, workloads and infrastructure. This must be combined with an emphasis on patch and vulnerability management, intelligence-led security operations, and reinforced supply chain resilience. As far as AI is concerned, it’s vital to fight fire with fire: use the same tools cybercriminals use, and adapt them to fight the good fight. This way, businesses stand the best possible chance of steering clear of trouble.
Insights & Opinions from thought leaders at CrowdStrike
A larger proportion of cyberattacks in the first half of 2019 can be attributed to electronic criminals (eCrime adversaries) compared to state-sponsored or unidentified attacks. CrowdStrike, a cybersecurity company that provides the CrowdStrike Falcon endpoint protection platform, observes that 61% of targeted cybersecurity campaigns in the first half of 2019 were sourced from eCrime adversaries, compared to 39% from other sources. Technology was the top vertical market targeted by cyber-attacks in the first half of the year CrowdStrike Falcon Overwatch platform The eCrime portion more than doubled since 2018, reflecting an escalation of criminal players in search of more and larger payouts. The trend is among the information presented in CrowdStrike’s Overwatch 2019 Mid-Year Report: Observations from the Front Lines of Threat Hunting. Falcon OverWatch is the CrowdStrike-managed threat hunting service built on the CrowdStrike Falcon platform. Technology was the top vertical market targeted by cyber-attacks in the first half of the year, followed by telecommunications and non-governmental organizations (including think tanks). Other targets (in decreasing order) were retail, financial, manufacturing, transportation and logistics, gaming, entertainment and engineering. Hospitality disappeared from the list so far this year, although Crowdstrike expects an increase in intrusions aimed at the hospitality industry to put it back in the top 10 by the end of the year. Intrusion adversaries In terms of intrusion adversaries, the top players so far in 2019 are Spiders (eCrime) and Pandas (China). Regarding initial access techniques, the most common remain, in order of prevalence, valid accounts, spear-phishing and exploitation of public-facing applications. 2009 is proving to be an active year with a significant increase in eCrime and the inter-relationships occurring across different groups as they strengthen their organizations, forge alliances and expand their footprint. Need for a proactive security posture Basic hygiene form the foundation for a strong cybersecurity program Many of the techniques used by eCrime actors are easily defensible through strong security products and a proactive security posture, says CrowdStrike, which recommends the following measures to help maintain strong defense in 2019: Be attentive to basic hygiene such as user awareness, asset and vulnerability management, and secure configurations, which form the foundation for a strong cybersecurity program. User awareness programs can combat the continued threat of phishing and related social engineering techniques. Asset management and software inventory ensures that an organization understands it footprint and exposure. Vulnerability and patch management can verify that known vulnerabilities and insecure configurations are identified, prioritized and remediated. Multifactor authentication (MFA) should be established for all users because today's attackers are adept at accessing and using valid credentials. A robust privilege access management process will limit the damage adversaries can do if they get in and reduce the likelihood of later movement. Implementing password protection prevents disabling or uninstalling endpoint protection that provides critical prevention and visibility for defenders. Countering sophisticated cyber attacks As sophisticated attacks continue to evolve, enterprises face more than a "malware problem" As sophisticated attacks continue to evolve, enterprises face more than a "malware problem." Defenders should look for early warning signs that an attack may be underway, such as code execution, persistence, stealth, command control and lateral movement within a network. Contextual and behavioral analysis, when delivered in real time via machine learning and artificial intelligence, effectively detects and prevents attacks that conventional "defense-in-depth" technologies cannot address. "1-10-60 rule" in combating advanced cyber threats CrowdStrike recommends that organizations pursue a "1-10-60 rule" in order to effectively combat sophisticated cyberthreats. That is, they should seek to detect intrusions in under one minute; to perform a full investigation in under 10 minutes, and to eradicate the adversary from the environment in under 60 minutes. A source at CrowdStrike said "Meeting this challenge requires investment in deep visibility, as well as automated analysis and remediation tools across the enterprise, reducing friction and enabling responders to understand threats and take fast, decisive action."
We live in an information and data-led world, and cybersecurity must remain top-of-mind for any organization looking to both protect business operation critical assets. Businesses without proper cyber measures allow themselves to be at risk from a huge list of threats - from cybercriminals conducting targeted spear-phishing campaigns - like the 2018 Moscow World Cup vacation rental scam, to nation-state actors looking to collect intelligence for decision makers - no organization is safe from innovative cyber threats. Security solutions enterprises Organizations can then set the groundwork necessary to stop malicious activity and keep their business’ data safe The evolving threat space means organizations need to ensure they have the most innovative prevention and detection frameworks in order to withstand adversaries using complex and persistent threats. When implementing new security solutions enterprises must start by assuming that there is already a bad actor within their IT environment. With this mindset, organizations can then set the groundwork necessary to stop malicious activity and keep their business’ data safe. As there is no one silver bullet that truly stops all cyberattacks, organizations must adopt a multipronged approach to be widely adopted to stop adversaries. This must include tracking, analyzing and pinpointing the motivation of cyber actors to stay one step ahead through global intelligence gathering and proactive threat hunting. In addition, deploying new technologies leveraging the power of the cloud give a holistic view of the continuously evolving threat landscape and thereby secure data more efficiently. Traditional security approach In today’s landscape, the propagation of advanced exploits and easily accessible tools has led to the blurring of tactics between statecraft and tradecraft. Traditional security approaches are no longer viable when it comes to dealing with the latest trends in complex threats. To make defending against these threats even more complicated, adversaries are constantly adapting their tactics, techniques and procedures (TTPs), making use of the best intelligence and tools. CrowdStrike’s latest Global Threat Report tracked the speed of the most notable adversaries including Russian, Chinese, North Korean and Iranian groups. As the adversaries’ TTPs evolve into sophisticated attack vectors defenders need to recognize we are amidst an extreme cyber arms race, where any of the above can become the next creator of a devastating attack. Russian efficiency is particularly high; they can spread through an enterprise network in 18 minutes 48 seconds on average, following the initial cyber-intrusion. Sophisticated cyber weapons Actors tend to use a simple trial and error technique where they test the organization's network So, reacting to threats in real-time is a priority. Bad actors are extremely vigilant and committed to breaking down an organization’s defenses, and speed is essential to finding the threats before they spread. Actors tend to use a simple trial and error technique where they test the organization's network, arm themselves with more sophisticated cyber weapons, and attack again until they find a vulnerability. This has highlighted the need for tools that provide teams with full visibility over the entire technology stack in real-time in order to meet these threats head-on. Traditional solutions are scan-based, which means they don’t scale well and can’t give the security teams context around suspicious activity happening on the network. They lack full visibility when a comprehensive approach is needed. Businesses without proper cyber measures allow themselves to be at risk from a huge list of threats - like the 2018 Moscow World Cup vacation rental scam Malicious Behavior Through leveraging the power of the cloud and crowdsourcing data from multiple use cases, security teams can tap into a wealth of intelligence collated from across a vast community. This also includes incorporating threat graph data. Threat graphs log and map out each activity and how they relate to one another, helping organizations to stay ahead of threats and gain visibility into unknowns. Threat graph data in conjunction with incorporating proactive threat hunting into your security stack creates a formidable 360-degree security package. Managed threat hunting teams are security specialists working behind the scenes facing some of the most sophisticated cyber adversaries through hands on keyboard activity. Threat hunters perform quickly to pinpoint anomalies or malicious behavior on your network and can prioritize threats for SOC teams for faster remediation. In-Depth knowledge Security teams need to beat the clock and condense their responseIt is key for security teams to have an in-depth knowledge of the threat climate and key trends being deployed by adversaries. The TTPs used by adversaries leave are vital clues on how organizations can best defend themselves from real-life threats. Intrusion ‘breakout time’ is a key metric tracked at CrowdStrike. This is the time it takes for an intruder to begin moving laterally outside of the initial breach and head to other parts of the network to do damage. Last year, the global average was four hours and 37 minutes. Security teams need to beat the clock and condense their response and ejection of attackers before real damage is done. Next-Generation solutions When managing an incident clients need to be put at ease by investigations moving quickly and efficiently to source the root of the issue. Teams need to offer insight and suggest a strategy. This can be achieved by following the simple rule of 1-10-60, where organizations should detect malicious intrusions in under a minute, understand the context and scope of the intrusion in ten minutes, and initiate remediation activities in less than an hour. The most efficient security teams working for modern organizations try to adhere to this rule. As the threat landscape continues to evolve in both complexity and scale, adequate budget and resources behind security teams and solutions will be determining factors as how quickly a business can respond to a cyberattack. To avoid becoming headline news, businesses need to arm themselves with next-generation solutions. Behavioral analytics The solution can then know when to remove an adversary before a breakout occurs Behavioral analytics and machine learning capabilities identify known and unknown threats by analyzing unusual behavior within the network. These have the ability to provide an essential first line of defense, giving security teams a clear overview of their environment. With this at hand, the solution can then know when to remove an adversary before a breakout occurs. Attackers hide in the shadows of a network’s environment, making the vast volume and variety of threats organizations face difficult to track manually. The automation of responses and detection in real-time is a lifeline that organization cannot live without as adversaries enhance and alter their strategies. Adversaries continue to develop new ways to disrupt organizations, with cybersecurity industry attempting to keep pace, developing new and innovative products to help organizations protect themselves. These technologies empower security teams, automating processes and equipping security teams with the knowledge to respond quickly. Organizations can set themselves up for success by integrating the 1-10-60 rule into their security measures, giving them an effective strategy against the most malicious adversaries.